In this episode of The IT Experts Podcast, we share one of the most honest and eye-opening conversations we have ever had about a ransomware attack and the devastating impact it can have on an MSP. Ken Roulston joins me to openly discuss the events that led to a real world cyber incident which ultimately cost more than £500,000, challenged every part of the business, and tested the resilience of the leadership team in ways few business owners ever experience.
This conversation is not designed to create fear. It is designed to create awareness. Every MSP owner believes they have the right security in place, the right backups running and the right processes protecting both their own business and their clients. Ken’s experience demonstrates why confidence must always be backed up with verification, discipline, and continual improvement.
Ken shares the full story of how a successful acquisition appeared to strengthen the business before a ransomware attack turned everything upside down. What began as a routine business trip quickly became one of the most stressful weekends of his career. A private data centre belonging to the newly acquired business had been compromised, leaving more than forty client environments inaccessible. As the investigation unfolded, it became clear that the attackers had gained access through one of the least protected customer environments before remaining undetected for several months.
One of the biggest lessons from this ransomware attack is that strong technology alone is never enough. Human error, incomplete backup verification and inconsistent security standards combined to create a perfect opportunity for attackers. The discussion explores how backup systems appeared to be functioning correctly while failing to produce recoverable data when it mattered most. It is a reminder that testing your disaster recovery process is every bit as important as performing the backup itself.
Ken explains the difficult decision to negotiate with the attackers after discovering there was no viable way to restore the systems independently. He openly describes the emotional pressure of balancing legal advice, customer expectations, and the financial impact while attempting to recover critical business systems. It is an extraordinary insight into a situation that many MSP owners hope they will never face, although every provider should prepare for the possibility.
As the recovery began, the challenge shifted from retrieving encrypted information to rebuilding more than forty client environments from the ground up. The team worked around the clock for weeks to restore services, rebuild trust and move customers onto more resilient cloud infrastructure. Despite the enormous disruption, the business retained the majority of its recurring revenue and emerged with valuable lessons that continue to shape how Ken advises MSPs today.
Throughout the episode we explore the practical actions every MSP should take immediately. Ken highlights the importance of enforcing minimum security standards across every client, verifying backups regularly, maintaining isolated recovery environments, and investing in your own cybersecurity with the same commitment you expect from your customers. One of the strongest messages throughout the conversation is that MSPs cannot afford to become complacent. Your clients’ security directly affects your own business, making security standards a shared responsibility rather than an optional service.
We also discuss how ransomware attacks continue to evolve as cybercriminals become increasingly sophisticated. With artificial intelligence accelerating both defensive capabilities and cyber threats, MSPs must continually review their security posture, educate their teams, and ensure every client understands the importance of maintaining modern cybersecurity standards. Building resilience is no longer about reacting to incidents. It is about creating systems, habits and leadership that reduce risk long before an attack occurs.
If you are responsible for protecting client environments, leading an MSP or planning future growth, this episode offers valuable lessons drawn from genuine experience rather than theory. Ken’s willingness to share one of the most difficult periods of his career provides an opportunity for every MSP owner to strengthen their own business before a ransomware attack forces those lessons upon them.
The conversation serves as a powerful reminder that preparation, leadership and continual improvement remain the strongest defence against an ever-changing threat landscape. Every MSP can learn from this experience and use these lessons to build greater confidence, stronger security and a more resilient business for the future.
Connect with Ken Roulston through LinkedIn.
Make sure to check out our Ultimate MSP Growth Guide, a free guide that walks you through a proven process to take your MSP from stuck to scalable, without working even more hours. It’s 44 pages rammed with advice, insights and inspiration to help you decide what support is available to you now if you want to grow and scale your business. Click HERE to get your copy.
Connect on LinkedIn HERE with Ian and also with Stuart by clicking this LINK
And when you’re ready to take the next step in growing your MSP, come and take the Scale with Confidence MSP Mastery Quiz. In just three minutes, you’ll get a 360-degree scan of your MSP and identify the one or two tactics that could help you find more time, engage & align your people and generate more leads.
If you’re serious about growth and want to explore what this could look like for your MSP, you can book a Right Fit Clarity Call with us HERE.
OR
To join our amazing Facebook Group of over 400 MSPs where we are helping you Scale Up with Confidence, then click HERE
Until next time, look after yourself and I’ll catch up with you soon!
IAN: In this episode of The IT Experts Podcast, we share with you the real details behind an MSP ransomware attack.
INTRO: Welcome to The IT Experts Podcast, the only podcast to help MSPs scale to 1 million, and if already there, get to five and go faster. At the end of the day, isn't it all about building a business that works for you rather than you for it? I hope you enjoy the show.
IAN: So good morning, good afternoon, good evening. Welcome to The IT Experts Podcast. Great to see you again. And today we've got a bit of a sobering podcast for you with our amazing friend of the MSP Growth Hub, Ken Roulston.
IAN: How you doing, Ken?
KEN: I'm good, thank you.
IAN: Ken, through the conversations that we've had with Ken, who's... I'll get him to explain who he is and who he helps in a minute, but his amazing legacy in the channel. We're going to talk to you today about a situation, very unfortunate situation where Ken's previous business was hit by a ransomware attack. And the purpose of this isn't to scare you. The purpose of this is to bring to real life and to help you understand how it feels when that horrible event happens. And we all sit there, we talk to many MSPs, it's not a matter of if, it's a matter of when. And you sit, and MSPs go, "And I've got my security stack in place. I've got this in place. I've got that in place." And we don't want anybody who listens to this podcast to be affected by this. So we're going to share Ken's story today, which is going to be be very deep, I think, and very interesting on exactly what happened. But before we get cracking, Ken do you want to share with the audience who are you, what do you do, and who do you help?
KEN: Okay. I've worked in the IT services industry now for 47 years. Started off as an engineer, moved into sales, then into management. Ran an IT break-fix business during the '90s, and then in 2009 I started an MSP from scratch. Bought two businesses put them together, and then over the next number of years acquired four more companies. So we got up to the point whereby in 2023 we were turning over about 17 million of revenue, had 120 staff, and we got bought by a larger MSP player based up in Manchester. Since then, I've been working with a number of vendors giving talks at different events primarily on my area of particular interest, which is M&A. Helping organisations grow strategically through acquisition, helping them through that journey. So I work with a number of MSPs around the UK and Ireland specifically in that regard, either on a retainer or a project basis. Yeah that's the, was the enjoyable fun side of the MSP. The bit that we're going to be talking about today, I've described to many people as the worst period of my life for reasons which will become obvious. But yeah I'm happy to do it on the basis that I do feel that a lot of MSP owners are potentially complacent and not necessarily fully aware of the risks that they are undertaking in running their business. So happy to do whatever you need and throw whatever questions at me you want.
IAN: Yeah, sure. And, I think straight off the bat, we only know you, Ken, as the successful, fun go-giver that you are. And I think today we're going to, as you said before we got cracking, you we're going to rip up some memories that may not want to come through, but for good use for the listeners here today. So, Talk us through what was going on in the MSP? What was the size of the MSP? What was happening? What was the environment like before the attack took place?
KEN: Okay. That's a very interesting place to start because in June 2021 we had just completed our last acquisition, which was a company based in just Southwest London. It was a business that we decided to acquire because it had a very strong capability in cloud. It was running its own private data center but it had developed skills in Azure and was starting to move some of its clients across into the Azure world. So we saw a good opportunity to acquire a business that had high levels of profitability, had a good customer base had a strong track record. And we knew that by acquiring that business, we were going to be adding significant value to our own company because we would increase the EBITDA, it would fill in some of the gaps in our portfolio. So as of June '21 the roses were definitely red and life was good. What then happened w-was that we had been approached by a couple of organisations who were interested in acquiring us and subject to us completing that acquisition. And then I remembered very well, I went across from Belfast, where you can tell by my accent I'm from and arrived at Heathrow on a Tuesday morning switched on my phone for it to blow up essentially in my hands, not in a Israeli attack type of way, but in terms of the amount of messages and calls that I was getting. So...
IAN: Other attacks are available.
KEN: Yeah, indeed. Yeah, essentially I got a, my initial message was the private data center that belonged to the company that we acquired in June '21 appeared to be down. None of the customers were able to access anything. Didn't sound good. But I was literally on my way to two meetings that day with companies who were potentially interested in acquiring us. And had provided sort of an outline of the valuations which were definitely of interest. So I suddenly found myself sitting with people talking about selling the business and how wonderful our business was, but at the same time, in the back of my head, I knew that there was a problem back at the ranch, but I wasn't sure how serious it was. By the end of the day, it was fairly obvious for a number of reasons, that we had been hacked. The private data center I should say, of the company that we acquired had been hacked. Thankfully, we had not yet integrated that network with our main systems, so it was still standalone. So it didn't affect all of the other systems that CMI had in place, but it did affect all of the customers, which was 42 major customers using that data center to differing degrees. But essentially what it turned out was that none of the 42 businesses had any IT capabilities apart from email. Everything else was run out of the data center, which was effectively wrecked by the hackers. And we then got the message through to say that we had been hacked and that we could buy the key to unlock all of the data and get our systems back I see for an amount of money which was initially, I think their first offer was about a million. We went back to them and said, we can't justify a million. And we saw something funny in their message, which made us think, "I don't think they've got the right company." And we went back to them and s- pointed out that, I don't think you've got the right business here. And they said, "Oh, apologies for that. No. With you it'll be half a million." They'd actually were dealing...
IAN: Oh, my word.
KEN: They were dealing with somebody else at that same time. So they brought it down from a million to half a million.
IAN: Oh, you got a discount then.
KEN: We got a discount. So that of course was something that we didn't want to do for obvious reasons. So we spent the next couple of days trying to see what we could do to recover our systems to see if we could back up or use our backups. But through a variety of circumstances, and I can explain a wee bit more, not particularly technically, a wee bit more about how it all happened. But one of the key things that we found out was that we didn't have any backups or at least.
IAN: Oh, wow.
KEN: To the point we didn't have any working backups the situation came about because once we had got through the whole thing, and obviously there's a bit more to talk about, and we were able to look back through various records, we found that the attack had started through one of the smallest customers that this business that we acquired had. A very small sort of two-man outfit who didn't really buy into IT, didn't necessarily value it, hadn't taken up any of the recommendations but had been allowed to continue to run their systems relatively unprotected. Only for them to be hacked a few days after our announcement was made public about us making the acquisition. So it looks and still appears to us to be a case whereby the hackers had identified that we may be a good target to get some money out of because we were in the business. So they targeted the company we acquired, targeted and got into the least capable user, but didn't, they just left what they did there. They didn't push the button on until September when we were a few weeks away from our financial year-end, and of course, that was the worst possible time potentially for us to get hit. So they unveiled it or launched it I say in mid-September. So we had gone through the whole situation and found that, what had happened was due to human error on the company's part that we had acquired, the backups that they had been using were providing some problems. And between June and September, they had started to move away from using tape backup to Microsoft Blob and were in the middle of that transition but failed to verify that the backups were actually working. So not only was the primary backup not complete also the secondary backup, which was offsite. So we found ourselves by the Friday of that week in a situation whereby we knew we couldn't restore the systems, we couldn't recover the data, and we felt we had no option but to effectively pay the ransom. That was something that none of us wanted to do. We decided that we would take some legal advice. We actually spoke to somebody who was high up in the cybercrime division of the Met police who said officially his position and their position is do not pay the ransom. But unofficially pretty much said, "Look, doesn't look like you've any other options. You're going to have to do it." And our concern, of course, was, we pay the money to these people, which of course had to be done through a cryptocurrency,
IAN: Yeah.
KEN: Not normal bank transfer, which led to another whole issue. But we pay the money only for them not to provide the key, and then we find ourselves in a situation whereby we've laid out money and we still don't have our data. So that, over that Friday meant that I spent some time through a colleague doing stuff on the dark web with these people was able to negotiate the price down to 300,000. So got a further discount for good behaviour. And we basically said, "Okay we will pay you the money." This got to late on a Friday afternoon after the point in time when banks are able to transfer money normally. And of course, we didn't necessarily have the money sitting in our own account but we needed to get the money, so we found mechanisms to pull the money together which was problematic because moving large sums of money around outside normal working hours on a Friday evening fell into the banking system's traps of money laundering all the rest of it.
IAN: I bet it did.
KEN: And we were getting repeated issues coming up about, who's this money going to? What's it for, et cetera. So it literally took us all that evening and all that night to get to a point where by around about nine o'clock the next morning, the Saturday morning, the money was finally in a position to be transferred. We then held our breath. By the Sunday, we got word that the money had been received and that they were releasing the key. So we thought okay, it's been rough, but at least now we get the data back and we can move forward. Because you can imagine at this stage, clients were down three or four days. The IT wasn't working.
IAN: Yeah, no access.
KEN: And they weren't very happy it's fair to say. So we got the key and what we found was that we were able to get just about all, not all, but most of the data back. But what we found out was that not only did they steal the data, but when doing it, they trashed all of the systems, virtual systems that we had running within the data center in order to extract the data. So what we were faced with on the Monday morning was having to rebuild 42 environments from scratch. Anybody who runs an MSP or understands, what's it that involves, it's not a simple process. It requires a lot of work, not only to get the basic bones of it built, but to get it configured and tailored and tweaked. That has maybe been years' worth of amendments made to get it to the operational level it was at prior to the event.
IAN: Wow.
KEN: So the story goes on, and apologies for waffling on, but-
IAN: No, no. Keep going.
KEN: But what that kicked off was three weeks of literally working around the clock, having our staff working around the clock working through all of these different customer sites to get them back up to an operational state. And of course, another three weeks of downtime on top of the three or four days' worth of downtime only made the customers ever so slightly more irate. And of course, lots of flak was flying from every source, legally and so on. And we had to get involved with the ICO. We were involved with the Met Police. So it was a very challenging period.
IAN: Yeah.
KEN: But-
IAN: So-
KEN: But-
IAN: Yeah, go on.
KEN: But the good news is after three weeks we got everybody up. We did lose a few clients through the process. Thankfully from our viewpoint, some of the smaller clients. But what we did was we retained 85% of the revenue, recurring revenue we had from our client base. And what's more, we got them all onto three-year contracts based on us moving them to Azure as a matter of priority which is what we then set about doing. So the three weeks to get them back up and running was the next part of the process. So it went from three days initially to three weeks, and then it was three months probably to get everybody signed up and not signed up, but get everybody across into Azure and away from that old platform, which had been working for 14 years without a hitch. Everybody was quite happy with it, and then all of a sudden, bang, it all went mad.
IAN: Thank you for sharing that, Ken. That was just, that must have been your longest weekend of your life, is that key going to come? Where are we going to get this money from? Who's judging us? Yeah. And that's, that's nothing else but net profit, right? And that takes a long time to recover from that. That doesn't sit around doesn't, that sort of money doesn't sit around lightly. It must have been extremely scary as well communicating with people that you have absolutely zero minus trust on whether or not they're going to say the right thing, do the right thing, even give you the information back.
KEN: Absolutely. But an interesting point, which is actually quite funny, is that when they did provide the key on the Sunday, they also provided us with a week's worth of customer service facility to help-
IAN: Oh, fantastic.
KEN: With any issues we have. Now in fairness, there was very little that they could do to help us at that stage because they'd done all the damage that there was to be done, and they weren't in any position. But it was the fact that they offered this. Now, I should have said that one of the reasons why we decided to move ahead was that this particular r- ransomware group, which we believe was Ukraine based, interesting enough at the time, but may have been Russian, not entirely sure were a well-known hacker in the industry. And when we spoke to the head of cybercrime in the Met, or I'm not sure his exact title, but somewhere of that level and we mentioned our concern about paying out this money only for to get nothing back. He said that he felt confident that we would get the key because this group was well known and therefore they had a reputation to maintain. And they didn't want to get a bad reference by not actually fulfilling their commitment. In an ironic way we were probably attacked by one of the better hackers in that sense because they didn't want to blot their copybook by not delivering on the service and on their commitment.
IAN: Quite incredible, isn't it? I'm sitting here thinking, that got your customer service there. They've got their they're in communication with you, do you find them on Trust the Trader or trustahacker.com? And it's like, it's just an absolutely crazy situation.
STUART INTERRUPT : Hey, just a quick one from me for everybody that's listening. Stuart here. If you're serious about growing your MSP, but you're not sure what help's right for you, then just grab our Ultimate MSP Growth Guide. It's a really simple way to check out what's out there for support that could really help you work. There's no fluff, there's no filler, just facts. Or alternatively, if you want to meet us face to face and see how we do things up close, come along to one of our events. They're regularly put on. They're all in the links below. Go check them out. And now it's back to the show.
IAN: Thanks, Stuart.
IAN: What is interesting with this, Ken is that If you're an MSP and you're sitting here right now going, yeah, we do backup, so we're safe, what would you say to them?
KEN: Yeah. God. It's one thing doing a backup, it's another thing verifying that what you're backing up and what you've got is actually usable and that it's secure. The first point about verifying it is an obvious thing, and the guys that were in that business who were running that part of the business thought that whenever they saw whatever was coming up on the screen that the backup was working. But they never actually tested it out, and what came to the fore was that it was backing up some of the data but not all of it. But the way it was backing it up meant that none of the data was actually usable. Because it was backing it up, and technically, as I'm not the person to do this, but in a way where it was like stripe sort of backup, where it was taking bits of data from different folders, but nothing complete. So that was, so that would be the first thing is always make sure that if you're doing any backups of your own systems, and of course this is good advice for your customers as well, is make sure that you're verifying and checking that the backups are actually working.
IAN: Yeah. Yeah.
KEN: In terms of this, the second aspect of it, the way I've tried to describe this situation to people, it's a bit like somebody being given the key, the master key to a hotel. They can use that master key to get through the front door which was getting through from the naive user's business into the private data center. So the key that they had unlocked a mechanism to get around the systems that were in place. Now, I have to say, the systems that were in place were actually fair and reasonable. The ICO gave us a clear bill of health for the protection that was in place. But as we say to anybody, or as I used to say to anybody, you can never provide 100% risk-free guarantees when it comes to security, even on your own systems. So these guys were clever enough to find the way around our internal system. So once they got into the hotel with that master key, they were literally able to go into every bedroom with that master key and take any valuables out of the room which is the data. But try-
IAN: Undetected?
KEN: Undetected, and trash the room at the same time. And then of course, imagine the, this analogy going along the lines that you store a lot of your valuables in a safe. The safe was also accessible, and then the backup safe was also deemed to be accessible because it wasn't Sufficiently isolated from the main backup system. So there was lots of lessons. One, verify, that you're doing the backups are working. Make sure that your secondary backup is sufficiently isolated and regularly updated to ensure that if something goes wrong-
IAN: yeah.
KEN: The primary backup, at least the secondary backup is available. It essentially, in, in many respects, even though, as I said, the ICO gave us a relatively clean bill of health, the hackers were clever enough to get around our systems and do considerable damage. The backup issue was our fault. It was a human error issue which is, when it comes to cybersecurity issues and human error is the biggest risk.
IAN: Yeah.
KEN: And that was obviously the situation with us. I should say that also the title of the presentation was about, the 500,000 hit, half a million hit, and I've said the ransom was 300,000. The other 200,000 came from the costs that we had to incur to rebuild the systems, the overtime that we had to pay, the compensation that we had to pay out to some customers, the legal fees additional systems that we had to put into place. Hard costs, never mind the soft costs of all the time and hassle and distress that it caused for everybody in the business.
IAN: How big was the business again at that time that was affected?
KEN: That bit of the business was doing about 5 million of revenue.
IAN: Okay.
KEN: At that point in time.
IAN: Yeah.
KEN: I'd say with about 42 active managed service clients, so you can tell from that, that each of the clients were on, in the main, fairly significant. They were-
IAN: Yeah, pretty good. Pretty good clients.
KEN: Housing, social services, businesses, solicitors.
IAN: All the wrong people. All the wrong people.
KEN: So the people who rely on their IT a lot.
IAN: Yeah. So Every time I hear, that there's been an event or a hack or compromise, we talked a lot about the backup, but the ultimate problem here is that they, you allowed one of the clients, customers to be non-compliant and to hand the master key out, didn't we? That's kind of the problem here. I remember years ago when I was at college, someone said to me, " what's the main fuel for a gas fire?" And I said "it's gas, isn't it?" He said, "No, it's not. It's electric, because electric lights the gas." And it was like, "Okay, that's interesting." So the real problem is not the fact that the backups didn't work. That was, like, cock-up number two. The real problem was the fact that, I say you, but the business allowed, somebody to be running a non-compliant security. And this is where I'm now going to be pointing everybody I have this conversation back to, if you're not minimum Cyber Essentials Plus and taking this seriously, and all your clients as well, you need to go and listen to this podcast.
KEN: Yeah.
IAN: Because it's a scary environment. You're letting somebody hand out the master key to your kingdom, aren't you?
KEN: Absolutely. And the core CMI business at that stage the mothership, for want of a better term, had a very strict policy of all of its customers needing to have a baseline of security for us to provide them with the service. Because we were still in the early stages of integration, we hadn't got round to enforcing that policy on all of the customers of the company we acquired.
IAN: Yeah.
KEN: But absolutely, since that, and when I've given this presentation or talk at other times, and every client that I meet, every MSP that I talk to, I say, "You've got to make sure that your clients have got the best level of security in place."
IAN: Yeah.
KEN: Whether it's Cyber Essentials or even a higher level, but, you are putting your business at risk if you allow them to effectively not take on board that recommendation.
IAN: Yeah.
KEN: And, you need to be prepared to walk away from clients who don't effectively take that on board, because security is scary. It's going to get even more scary, I believe going forward with advances in technology and AI and all the rest of it. So it is just something that you cannot be complacent about, and you have to absolutely make sure, even though it may be uncomfortable, you need to force your clients to make sure that they've got the the basic at least the basic levels of protection in place that meets the minimum sort of thresholds.
IAN: Do you believe that they targeted you because they knew the size of the business and what was going on with the acquisitions, and they knew that you could pay a significant sum of money?
KEN: Yeah. We were advised that this organisation was very professional in its ways of approaching things. It would have picked up on the fact that we had done that acquisition and immediately gone searching into the our accounts and probably the accounts of the company that we acquired, and therefore determined what sort of level of compensation, that we were able to pay without necessarily, I'm going to say, the company that we acquired, if they'd been hit with a half million bill, it would've sunk them. We had the capacity to effectively, to pay it and stay in business, albeit with severe dent to our profitability as a result. So yeah, these guys that are doing this are clever. They are not stupid people. And they're not stupid, neither technically nor commercially. They know what they're about, and they're one step ahead of most of the rest of us at any given point in time, if not further. So yeah, from what we understand, the timing of it and of them accessing that user site when they activated the the widget that kicked things off, yeah we're fairly convinced that they were tracking us and were fully aware of who we were and what we were doing, even though they sent us their own ransom note when it came to.
IAN: Well, That's just an administration error, Ken. You should leave them about-
KEN: It was an, it is an administration error. In fairness they were able to correct that issue and send us the right one.
IAN: How did they communicate with you?
KEN: It's all done through the dark web. And I, to this day, haven't got a clue how that worked. But my technical director, he was able to manage it and, yeah, we had to sit around his machine in an isolated context just to work on this communication channel.
IAN: Obviously now we know a little bit more about how it actually happens. We hear about it in presentations from vendors, but this is like real life, and I'm sure that everybody is just bolted in just going crazy. This is just mad. You can feel it and you can hear it, the frustration and the pain that you went through. But okay, it's an illegal business, but it's a business all the same. And they, there's no point in them hacking someone who's, if they turn up to a 5 or 6, 700,000 pound MSP and said, "I want half," 300 grand, they're going to go just take it, mate, because I'm shutting the business down." So what would you say to, so they obviously want to be, a good customer for them would be someone who we're going to charge them X amount of money that's going to be relevant to what we think that they could get hold of, that A) we're going to get the cash, and B) it's not going to completely crush that business. So for a smaller MSP, that could be 20 or 30 grand. What would you say to an MSP who's under a million pound who's sitting there going "Well, do you know what, they're just not going to bother with us because they're only going to want a small amount of money"?
KEN: That would be very naive because these guys, run their systems in a very efficient way, very automated way. And to them it's all about, it's a numbers game. If they can get to, 100 MSPs relatively easily, they'll do it, no matter what size they are. Of course they'll adjust the ransomware demand to a level, as you say, that, that is within that scope of ability to pay. But yeah, they'll quite happily take a lot of small clients along the way, as well as the bigger fish, because it's a very low cost of sale from their viewpoint. They deploy a bit of software, it goes off there, finds its way through a system. So to them, the same amount of work is involved in hacking into a small business as a larger. Okay, the rewards are less, but, it would be naive to think that a small business isn't going to get attacked because we, any MSP is a gateway to lots of other customers.
IAN: Yeah.
KEN: And it's, if targeting one MSP, they can effectively affect 20 or 30 end users as a result of that's easier for them to do, to hit one MSP than to go to 20 or 30 small end users are smaller again, yeah, no I can't give it any more succinctly than you've just got to assume it's a, not a matter of if, it's a matter of when. You're going to get attacked. So you've got to make sure that you've got your systems in place, your backups protected. You got to have your cyber insurance covered off too, because that was the other thing that the owner of that business was relatively, again, maybe Naive might be the word, who felt that, like a lot of people do, why pay insurance because they never pay out? But if we had the insurance cover in that business that we or should have had we would at least have had some redress. Might not have got it all back. We would have had some redress. Of course, we had it in the mothership business.
IAN: Yeah.
KEN: it was too late at the point in time it happened. We were all distracted by, the issues of talking to customers, updating processes, getting the staff on board. The first 90 days of any acquisition, you tend not to make many changes. You tend to be listening and learning, and that's what we were doing. We were only getting around to starting to integrate when, of course, the situation hit. Again, so I would say, don't be complacent, don't be naive. Put all those mechanisms in place to at least mitigate the issue as and when it does happen.
IAN: That's absolutely brilliant. Thank you, Ken, for your openness, your vulnerability the honesty around this and we, we're doing it to help share with everyone. What are some of the you just mentioned there, get your systems in place, get your backups protected, et cetera. What would be the three absolute non-negotiable actions, specific actions that every single MSP should be doing, this year, if not now, if not as soon as they get off this podcast, to help mitigate themselves from being in this position? What does making sure your systems are in place look like in terms little bit deeper?
KEN: We've touched on most of these points, I think, already. But the first is make sure that all of your customers have a baseline security-
IAN: great point, yeah ...
KEN: in place.
IAN: Is that Cyber Essentials Plus, or is that Cyber Essentials, or is that just, does it not matter?
KEN: Look, it I think every MSP probably has slightly different views as to what level of security they're comfortable with. But you've got to have the basics. You've got to have at least Cyber Essentials in place in, in all of the customers. Ideally, Cyber Essentials Plus, but some businesses may want even enhanced levels of protection beyond that.. But, there are businesses out there that are running with antivirus software thinking that's them covered.
IAN: I'm sure it yeah.
KEN: It's madness. So that would definitely be the first thing. The second point, and again, we've touched on, is, which is at the other end of the of the situation, is, if it does happen, make sure your backups, you've got backup, tested them, and that they are capable of restoring your systems in the event of something happening.
IAN: Yeah. How often would you do that? What would be a frequency that you would recommend? Is that daily thing? Is it a weekly thing? Is it a, I suppose it's how much data do you want to lose, right?
KEN: Yeah. Look, it's going to, again, vary from company to company. Of course, it should be done as much as possible on a real time basis.
IAN: Yeah.
KEN: If at all possible. But that may not be feasible due to cost and overheads and et cetera. But as frequently as is humanly. Again I can't dictate that. I'd say ideally it's real time. Anything is less efficient. But, certainly, there used to be the old father, grandfather, son, father, grandfather type way of storing data and it's that type of approach. You need to be, doing daily backups of course and weekly backups and monthly backups, but it's the verification of those that can take the time.
IAN: Yeah, Yeah. Got it. Got it.
KEN: That's a, falls, into disaster recovery,
IAN: Yeah, yeah ...
KEN: processes and so on. In terms of the third one this is probably, goes into the heart of this system is, assuming somebody does get through the front door for whatever reason, through one of the users, you've got to, don't be cobbler's children. Many MSPs talk a very good story when it comes to cybersecurity, and they tell their clients to put this, that, and the other layers of security in and wrap the various layers of the onions but they don't do it themselves, so I think, you're never going to be 100% capable of stopping a very good hacker getting through because they will-
IAN: Yeah.
KEN: Always find a mechanism. But you've got to do your absolute most to protect that system, and that means making an investment into your own security to a level whereby, you are eating your own dog food in terms of what you're promoting . That may be painful in terms of cost might be painful in terms of the impact it has on, your day-to-day working. But I'm telling you, you just do not want to go through what my, what I and our staff went through because quite honestly, it was the worst period of my life. And I think a number of my colleagues would say exactly the same thing.
IAN: Agree with that. Yeah.
KEN: Yeah. I wouldn't wish it on my worst enemy.
IAN: No. Thanks once again. For all those MSP owners out there listening to this, hopefully it's struck a chord. Get your teams to listen to this podcast. Do that analysis on what, Ken was talking about. Are you keeping safe with your clients keeping you safe? Are you making sure that you're running that level, the backups and then putting those tripwires and those alarms so if anybody does get the master key, you you pick it out. As always, Ken, thank you for your your time putting this together to help the community. Lots of learning. I don't think there's anything more to say. Apart from what a shame, it was horrible to hear, but, it's happening and it's happening even more, isn't it?
KEN: It's going to... I honestly believe it's a personal view, that AI is going to make cybersecurity even more of an issue going forward because these bad actors, they will use AI to its fullest capability. Situations today that we take for granted will be severely under threat going forward. So-
IAN: Yeah.
KEN: The days of providing just basic managed services are probably coming to, a natural sort of ceiling. But what businesses now need to do is really focus on making sure that they're developing their cyber capability to add more value to their companies.
IAN: Absolutely. Absolutely. I look forward to catching up on our next episode, which I'm not sure when it is. It's very shortly. I think it, hopefully it should be a little bit more jovial. But anyway, Ken, thanks again for your time, and look forward to catching up with you soon. You take care.
KEN: All the best, bye-bye.
NEXT WEEK TEASER: And if you've ever wondered what it feels like to be part of the UK's most powerful MSP community, then in next week's show, we lift the lid on our May 2026 client intensive event. We interview Stuart and the other coaches. We share with you the frameworks that we went through. We told you what's working right now, what's not working right now, and the biggest takeaways these clients had from taking action by stepping away from their business and focusing on it for two whole days. You're going to absolutely love this show. Don't forget to check it out next week.
OUTRO: Oh, but one last thing just before you shoot off. And if you're curious about how this episode links with the ability to scale your MSP to a million or, or if you're already there, accelerate to five, then we want to invite you to come and take the MSP Mastery Quiz. And in just three minutes, you're going to get a 360 degree scan of your business where you can identify the one or two tactics that can help you find more time, engage and align your people, and help generate more leads in your MSP. It's really simple. Just click on the link in the show notes. And if you have enjoyed this episode, we'd love to get some feedback from you by means of a rating, review on Spotify or iTunes or your podcast platform of choice. We really appreciate every single one of them. Now you can go and enjoy the rest of your day, and we look forward to catching up and connecting with you soon. All the best now.