Security1 distinct publisher3 min readPublished
Acronis counts 143 ransomware victims among MSPs, IT-service firms and telecoms in 2025, with phishing at 52% of initial access and unpatched software at 27%. Its own checklist puts the burden of proof on the tenant, not the platform.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The instruction to verify immutable, offline and air-gapped as three separate controls [4] arrives without definitions for the second and third, so the test is the buyer's to write. The source does give its shape: evidence from the exact tenant, workload, storage configuration and service tier being sold [5]. That question lives in the contract, not the platform architecture document. Who holds delete rights over one tenant's recovery points, in which storage configuration, is a per-contract answer.
The entry-point numbers argue against spending the next dollar on storage. Phishing accounted for 52% of initial access cases in the Acronis data and unpatched vulnerabilities for 27% [2], which puts 79% of entries in two categories and leaves 21% for everything else [1]. The same report counted 143 victims among MSPs, IT-service providers and telecom operators across 2025 [1], roughly one every two and a half days [2]. Immutability touches neither dominant vector, and the source says so when it notes that immutable backup does not detect data theft and does not replace incident response [6].
Recovery time is where the six outcomes become measurable. The source defines it as the total of detection, triage, containment, clean-point selection, restoration and validation [9]. Six terms, and a datasheet restore rate speaks to one of them [3]. Clean-point selection is the term that decides whether the restore was worth running: the guidance is to take the latest recovery point that predates compromise and passes validation, with the incident team confirming that it does [10]. Automation can remove repeatable waits, but an incident commander should approve mass isolation, credential resets and failover [12].
Double extortion is where the backup-only plan runs out. Immutable copies preserve recoverability, but the data attackers already took stays taken, and breach-notification duties remain due [7]. Catching exfiltration before encryption means correlating endpoint, identity, email, Microsoft 365, DNS, proxy and egress telemetry [8], which is a different purchase from storage, and it is the layer the checklist assigns to EDR, XDR and a staffed 24/7 service rather than to backup [15].
Read the six outcomes [3] as a specification you hold a vendor to, because the piece carrying them also sells Acronis Cyber Protect Cloud with Acronis MDR as the single multi-tenant platform that delivers them, down to an "Explore Acronis MDR" prompt [14]. The part that survives the sales copy is the drill record: log achieved RPO and RTO after each rehearsal along with every delay, then revise the runbook from that rather than from estimated restore speed [11]. The same document concedes that no tool guarantees recovery in every attack, while a rehearsed path keeps open the option of recovering without paying [13]. Producing that log, per tenant, for last quarter is what turns the vendor's numbers into the MSP's own.
Ranked by verification strength, evidence, and original report placement.
The article promotes Acronis Cyber Protect Cloud with Acronis MDR as bringing prevention, detection, 24/7 response, backup and recovery into one multi-tenant platform, and includes an "Explore Acronis MDR" prompt.
The checklist says ransomware protection for MSPs should deliver six tested outcomes: reduce exposure, detect activity before encryption, provide 24/7 response, preserve isolated recovery points, recover cleanly, and operate consistently across tenants.
The source states that immutable, offline and air-gapped describe different controls and that each one must be verified separately.
For each control, the source says an MSP should demand evidence from the exact tenant, workload, storage configuration and service tier being sold.
Immutable backup protects recovery points from alteration or deletion; it neither detects data theft nor replaces incident response.
Immutable backup is not enough against double-extortion ransomware: it can preserve recoverability but cannot retract data attackers already stole or remove breach-notification duties.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 2, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
Thousands of credentials survived five years of pentests inside Jira ticket comments1 distinct publisher
build
A UDP packet is now enough: IKEEXT RCE moves from patch queue to fire drill1 distinct publisher
build
TerminalFix delivers its first stage through the clipboard of the person it targets1 distinct publisher
security
ShinyHunters dumps 12.9 million Carhartt records after a refused $3.3 million ransom1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One vendor, one document
Every number in this story — 143 victims, 52% phishing, 27% unpatched — traces to Acronis's own threat report as restated in an Acronis-branded checklist, with no sample size, counting rule or link for a reader to pull. The rest of the piece is prescription rather than finding: sound prescription, but the kind that needs no evidence because nobody disputes that immutable and air-gapped are different words. Strip out the product names and what remains is a well-argued opinion with a single unaudited statistic bolted to the front.
Nothing measures uptake
The story names Acronis Cyber Protect Cloud, MDR, EDR, XDR and Disaster Recovery without once saying how many MSPs run any of them, at what tier, or on what storage. The one tally it offers counts ransomware victims, not customers — that is threat telemetry pointed at the market, not evidence of anyone adopting the remedy. We would rather report the gap than convert a victim count into an adoption signal.
Modest overreach, unusually honest copy
Vendor content usually overshoots harder than this. Here the caveats work in the reader's favour: no tool guarantees recovery, immutable backup cannot un-steal data or cancel breach notification, coverage is subject to tier and licensing, and the buyer is told to demand tenant-specific proof and a live production test. The gap that remains is narrower and specific — an unverifiable statistic used to size the threat, and six 'operational jobs' that happen to align exactly with one company's bundle, so the checklist doubles as a scorecard its author is confident of passing.
A checklist that ends in a buy button
Follow the sentences and the commercial line never breaks: the threat data is Acronis's, the reference architecture maps EDR, XDR and MDR onto Acronis EDR, Acronis XDR and Acronis MDR, the runbook routes clean-point validation through Acronis backup scanning and Disaster Recovery, an 'Explore Acronis MDR' prompt sits mid-article, and the FAQ answers 'what is the best ransomware protection for an MSP' by naming the same bundle. The advice can be good and the placement still be marketing; readers should price both.
Single-threaded
One publisher, one vendor, one document, and no independent reading of the only checkable facts in it. Our confidence in the prescriptive material is decent — a hostile reviewer would still endorse testing immutability, offline and air-gapped separately — but confidence in the numbers is thin, and there is no second source in this story to raise it.