A client leaves its managed service provider, hands IT to the owner’s nephew, and gets hit with ransomware two weeks later. Now they want to sue the old provider for failing to protect them. Silas says the MSP must be punished. Daniel says it isn’t the MSP’s fault. They argue it the way they always do, until Vivian points out they’re both sure about a story with four facts in it.
The situation reached us secondhand and can’t be verified, so it’s presented as an anonymised case study: no provider, client or person is named. Nothing in this episode is legal advice.
In this episode
- Why “two weeks” is both the strongest and the weakest fact in the case — the global median dwell time is 14 days, so the attacker could have arrived on either provider’s watch
- 30% of ransomware now starts with an attacker who was already inside (“prior compromise”), double last year’s share — and why that is a fact about an environment, not a verdict on a vendor
- The CISA advisory that says disabling a provider’s own accounts at contract end is commonly overlooked, and the long list of doors that stay open when it is
- The three documents that decide a case like this: the contract, the record of what was recommended and declined, and the offboarding record
- A composite scene of an MSP owner and her lead technician working out whether the offboarding was ever finished
- What providers and business owners should do before they are the one holding that letter
About the show
All Eyes takes one question the industry is arguing about, puts two people who genuinely disagree in a room, and does not let either off easy. Hosted by Vivian Calloway, with Daniel Ramos and Silas Wray, who argues the other side for a living. New episodes most Tuesdays.
🔊 This podcast uses AI-generated voices. Every voice you hear is AI-generated, including the host. Daniel Ramos's voice is his own, cloned with his written consent. We disclose this at the start and end of every episode. Read exactly how we use AI →
Sources cited on air
- Mandiant (Google Cloud), M-Trends 2026 — median dwell time; “prior compromise” as an initial ransomware vector
- Sophos, State of Ransomware 2026 — identity-based attacks; inconsistent MFA coverage
- Sophos, 2026 Active Adversary Report — median time to attempted Active Directory compromise; out-of-hours encryption (via Help Net Security)
- CISA, advisory AA22-131A — protecting against cyber threats to managed service providers and their customers
- Clifford Chance — analysis of the UK ICO penalty against an IT supplier acting as processor (£3,076,320)
- Daniel Ramos, The Blast Radius: Incident Response for Managed Service Providers (Intelligent Automation, 2026) — offboarding paths, liability caps and the limits of contractual authority