Desk live·
ForensicPost
Ransomware/Analysis/File 25-0603b

Outsourcing IT Is Sound Advice and the Route to Twenty Compromises at Once

Outsourcing IT is the correct advice for a small organisation and the mechanism by which twenty of them are compromised at once. The corpus has to hold both.

Constructed geometry · not a chart of case data
TargetManaged service model
ActorMultiple
D. Kennedy & S. Rosler12 min readConfidence: medium2 sources reviewed

This file sits between the small-organisation argument at 25-0610b to 25-0616b and the MSP incidents at 25-0601b and 25-1110b, because the two point in opposite directions.

The Advice Is Right

A twenty-person firm cannot staff patching, monitoring, backup verification and incident response. It cannot afford the retainers that made Nevada’s recovery work at 25-0921. It has, per 25-0612b, a survival threshold below the cost of most security products.

A managed provider supplies all of it at a price the firm can pay. Telling small organisations to outsource IT security is not a compromise position — it is the only realistic path to any capability at all.

And It Manufactures Exactly The Structure This Corpus Criticises

The concentration theme is the largest in this database. One vendor, many downstream victims: Marquis at 25-0814, PowerSchool at 25-0105, Episource at 25-0605, SitusAMC at 25-1112b.

An MSP is that by construction, with administrative access rather than stored data. The failure mode is worse than a data breach — the provider can execute code on every customer, which is what happened at 25-0601b.

The Corpus Does Not Have A Resolution

The obvious answers fail. "Choose a better provider" requires small firms to assess security capability, which 25-0814 established that seventy-four regulated banks could not do. "Diversify" is unaffordable. "Do it yourself" is the position the outsourcing solved.

What might help is narrow and unglamorous: providers scoped so that compromise of the management platform does not automatically mean code execution everywhere, customer-side approval for mass actions, and the platform inventory the corpus has demanded at 25-1207.

None of that removes the concentration. It limits what an attacker can do with it, which is the same conclusion this desk reached about consent grants at 25-1121b — where the authorisation is legitimate, the control has to be on what the authorisation permits.

And Regulation Reaches The Wrong End Again

The UK Bill at 25-1124 extends scope to managed service providers explicitly, which is the correct target and arrives with the designation problem this desk filed there: criticality is emergent, and a regional MSP serving forty small firms will not appear on anybody’s list until afterwards.

Graded medium: this is an argument about an unresolved trade-off, not a finding.

This is an analysis file

It sets out a tension between the small-organisation and concentration findings in this database. Sources support the underlying incidents. Corrections: corrections@forensicpost.com.

Sources
  1. Why cybercriminals are targeting MSPs firstIT Brief UK
  2. What recent ransomware campaigns teach MSPs about supply chain securityLevel
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary