Technology Resources for Cybersecurity, IT, + Cloud | CompassMSP

Your IT Provider Was Breached: What to Do in the First 24 Hours

Written by Emily Zaczynski | Aug 31, 2026, 11:14:04 PM

You just learned that your managed service provider was breached. Your first reaction is probably a mix of confusion and dread, because the company you hired to protect your systems is now the source of your risk. Take a breath. This situation is serious, and it is also survivable if you move in the right order over the next day.

The scale of this problem is easy to underestimate. In its most recent annual study, Verizon found that third-party involvement in breaches doubled to 30 percent of all breaches in a single year. When you outsource your IT, you concentrate your risk in one vendor that holds the keys to nearly every system you run. That is exactly why attackers target providers in the first place.

This guide walks you through the first 24 to 48 hours as the customer sitting downstream of the breach. Most incident-response advice is written for the provider, not for the business that depends on it. You need a plan built for your side of the relationship.

What a provider breach actually means for you

A breach at your provider does not automatically mean your systems are compromised, but it does mean you have to treat that possibility as real until proven otherwise. Providers connect to your environment through privileged tools, remote access software, and administrative accounts. If an attacker controls those tools, the attacker can reach whatever those tools can reach.

Recent history shows how quickly a single provider compromise spreads to customers. In 2021, attackers exploited a flaw in Kaseya's remote management software and pushed ransomware through roughly 60 providers to as many as 1,500 downstream businesses, according to guidance published by CISA and the FBI. The customers of those providers did nothing wrong on their own networks, yet they still had to recover.

Your job in the first day is to answer three questions. Was your data exposed? Can the attacker still reach you? What do you owe your customers, partners, and regulators? The steps below help you answer each one.

How to tell whether your own data is at risk

You cannot see inside your provider's systems, so you have to reason from what you can control and observe. Start with a simple exposure map. Write down every system your provider can touch, every account they hold in your environment, and every dataset they process or store on your behalf. That list defines your worst-case exposure.

Next, look for signs of trouble on your own side. Review recent sign-in activity for provider-managed accounts, watch for unexpected password resets or multi-factor prompts, and check for administrative changes you did not request. Cases like this land in the news regularly, and one recent example shows how a small slip at a provider becomes a customer-wide problem. Clorox alleges that attackers called the help desk that Cognizant managed, posed as employees, and walked away with credentials that reached Clorox's identity systems and internal network. A single reset request became a company-wide incident.

Related Article: What the FBI's Silent Ransom Warning Means for Small Law Firms

Do not accept a vague "your data is fine" from your provider as the final word. Ask for the specific basis of that claim and the evidence behind it. You need facts, not reassurance.

Do not accept a vague "your data is fine" from your provider as the final word. Ask for the specific basis of that claim and the evidence behind it. You need facts, not reassurance.

Your first calls, in the right order

The order of your first calls matters more than most people expect. Make them in this sequence.

  1. Call your cyber insurance carrier first - Your carrier maintains relationships with vetted forensic firms and breach counsel, and many policies require you to use approved vendors to preserve coverage. Your carrier can also direct evidence preservation from the start, which protects both your recovery and any future claim. If you call your provider first and let them run the response, you may lose both.

     

  2. Call outside breach counsel second - A qualified attorney helps you handle the response under legal privilege and keeps your obligations straight from the beginning. Your notification duties often turn on details that counsel is trained to spot early.
  3. Contact your provider third, with specific demands - By now you know what to ask for. The next two sections cover exactly what to require and what to do on your own network.

Why you should not let your provider investigate itself

Your provider has a conflict of interest in its own breach. The same company whose controls may have failed is not the right party to judge whether those controls failed. An independent forensic team, chosen by you or your carrier, gives you an honest account and preserves evidence properly.

This matters because many organizations lack the internal capability to investigate a serious intrusion, and they discover that gap at the worst possible moment. That blind spot has a name and a cost, which we cover in our breakdown of the DFIR gap that undermines cyber resilience. Line up independent forensic support now, before you need it, so you are not negotiating scope while the clock runs.


What to require from your provider right now

Ask your provider for specific, documented answers. General statements will not help you meet your own obligations. Require the following.

  • Raw sign-in and audit logs for every account they manage in your environment, in original form rather than summaries.
  • A written timeline of when the breach began, when it was discovered, and when you were notified.
  • A clear scope statement that describes exactly what their compromised tools could reach in your environment.
  • Confirmation of which of your datasets they store or process, and whether any of it was accessed or exfiltrated.
  • A written commitment to preserve evidence and to cooperate with your independent forensic team.
  • Disable or tightly restrict provider accounts that you do not need active during the investigation.
  • Force password resets and re-enroll multi-factor authentication for any account the provider could access.
  • Rotate shared credentials, API keys, and service-account secrets that the provider held.
  • Tighten conditional access and administrative permissions so that a stolen credential reaches less.
  • Increase logging and monitoring so that you can spot follow-on activity quickly.
  • The Kaseya incident turned one software flaw into ransomware across roughly 1,500 companies that never touched the vulnerable system directly.
  • The Clorox lawsuit against Cognizant traces a nine-figure loss to help-desk staff who handed over credentials without verifying identity. Cognizant has separately notified affected individuals in a data incident and offered identity-theft protection, which shows how these events reach real people.
  • The Reliable Networks breach exposed personal data for more than a million individuals and pulled its customer, BerryDunn, into litigation.

If your provider cannot answer these questions with specifics, that gap is your risk to manage, and you should escalate accordingly. That documentation matters most when a breach becomes a dispute over who is at fault. Consider what happened to BerryDunn, a consulting firm whose IT provider, Reliable Networks, was breached in 2023. The intrusion exposed sensitive personal information, including names, Social Security numbers, and health data, for roughly 1.1 million people. Affected individuals then brought claims against BerryDunn, and the firm in turn placed responsibility on the provider it had hired. When two parties point at each other after a breach, clear records determine who answers for what.

Steps to take on your own network

You control your environment even when your provider controls the tools inside it. Take these actions to limit the attacker's reach.

Take these steps in coordination with your forensic team so that you contain the threat without destroying evidence. Speed helps you, and so does care.

How to handle communications

Resist the urge to send a detailed public statement before you have facts. Early over-commitment creates problems you cannot walk back. Keep internal leadership informed with what you know and what remains unconfirmed, and give realistic timelines rather than optimistic ones.

Hold external communications until counsel confirms what you are required to say and to whom. Your legal notification duties depend on your industry, your data, and your contracts, and those duties often set both the timing and the content of what you disclose.

Your legal notification duties depend on your industry, your data, and your contracts, and those duties often set both the timing and the content of what you disclose.

How to lower the risk of a repeat

Once the immediate crisis passes, turn to prevention so that the next provider incident does you far less harm. A few durable moves make the biggest difference.

Review the security controls your provider actually runs, and require evidence rather than assurances. Every CEO benefits from a working knowledge of baseline expectations, which we lay out in our guide to the minimum security standards every CEO needs to know. Hold your provider to those standards in writing.

Scrutinize any provider that monitors your environment around the clock, because the quality of that monitoring varies widely. Our list of 10 red flags to watch for when hiring a 24/7 SOC provider gives you a practical screen. Watch the tooling layer above your provider as well, since flaws in remote management software have driven several major incidents.

Prepare for new categories of attack as well as familiar ones. Attackers now probe the AI tools that businesses adopt, and prompt injection has become a real threat, which we explain in our article on how to stop prompt injection, the biggest AI security risk for small businesses. A provider that stays ahead of emerging risks protects you better than one that reacts late.

Breaches that show how fast this escalates

The cases above are not outliers. They form a pattern that every business dependent on a provider should understand.

Each case reinforces the same lesson. A breach at your provider is a breach you have to answer for, so you need a plan that assumes it can happen to you.

When you need help fast

You do not have to manage a provider breach alone. Experienced advisors can direct your forensic response, help you meet your obligations, and get you back to normal operations sooner. Learn how our team supports businesses through exactly this scenario on our cybersecurity advisory page, and see our dedicated incident response support for help in an active crisis.