51% of cyberattacks in the MSP sector lead to unplanned expenses to fix security gaps

31% of the MSPs that spotted an attack report losing a competitive edge compared to 20% across other industries surveyed.

Netwrix has released additional findings for the managed service providers (MSP) sector from its annual 2024 Hybrid Security Trends Report based on a global survey of 1,309 IT and security professionals.

It reveals that 76% of MSPs spotted a cyberattack on their infrastructure within the last 12 months, similar to the results among organisations overall (79%). Among those that were attacked, every second MSP (51%) had to deal with unplanned expenses to fix the security gaps. Moreover, 31% experienced a loss of competitive edge, and 27% faced compliance fines compared to 20% and 17% across other verticals.

For the MSP sector, each second security incident in the cloud (49%) was associated with user account compromise, while 46% of attacks on premises were ransomware or other malware attacks. In contrast, these types of attacks were less common among other industries.

"Our team has had significant success in handling user account compromises and ransomware attacks using Netwrix 1Secure,” says Rory Cooksey, Director of Growth at WheelHouse IT. “Its robust monitoring and alerting capabilities allow us to detect and respond to threats swiftly, ensuring minimal disruption to our clients' operations. The comprehensive visibility and control provided by 1Secure empower us to confidently address and mitigate these security challenges, maintaining the highest level of protection for our clients."

“MSPs largely rely on software-as-a-service (SaaS), platform-as-a-service (PaaS), and infrastructure-as-a-service (IaaS) solutions. These are usually accessible to both MSPs and their clients, significantly limiting the implementation of network-based restrictions like IP address filters. As a result, attackers target such cloud-based solutions because they might be easier to infiltrate, and one successful breach gives keys to many kingdoms”, says Dirk Schrader, VP of Security Research at Netwrix

“The service provider is a promising target for ransomware gangs. On one hand, MSPs can hardly afford downtime and would be more eager to have the operations back up and running, which increases the chances for ransom payout. On the other hand, breaching a service provider can be just a step toward the real target in a supply chain attack. MSPs should adequately assess the risks and rely on threat intelligence to make their security decisions,” says Ilia Sotnikov, Security Strategist at Netwrix. 

Evolve IP launches Microsoft Operator Connect

Posted 15 hours ago by Phil Alsop
Evolve IP has launched Microsoft Operator Connect across its partner ecosystem, marking the next phase in its strategic approach to Microsoft Teams...
Data resilience is increasingly viewed as important for organisations operating in the AI era, as executive concern over outages continues to grow.
As UK IT leaders face increasing pressure from complex AI-driven infrastructure, many plan to enhance observability spend and consolidate tools for...

Keepit report reveals state of SaaS recovery readiness

Posted 4 days ago by Sophie Milburn
The Keepit Annual Data Report 2026 shows varying disaster recovery maturity across organisations and highlights the importance of structured testing.
Despite a decrease in ransomware incidents, evolving technologies and global tensions signal a complex risk landscape for organisations in February...
MSPs are encountering governance challenges as they expand AI services, with a growing focus on standardised approaches to data protection frameworks.

AI advances in N-able's SOC solutions

Posted 4 days ago by Sophie Milburn
N-able introduces AI-driven detection features for its security operations centre (SOC) aimed at improving the identification of advanced cyber...

Advania UK strengthens leadership with key appointments

Posted 1 week ago by Sophie Milburn
Advania UK strengthens its leadership team with the appointment of Sabrina Harris as CFO and Tara Allison as CMO.