You just learned that your managed service provider was breached. Your first reaction is probably a mix of confusion and dread, because the company you hired to protect your systems is now the source of your risk. Take a breath. This situation is serious, and it is also survivable if you move in the right order over the next day.
The scale of this problem is easy to underestimate. In its most recent annual study, Verizon found that third-party involvement in breaches doubled to 30 percent of all breaches in a single year. When you outsource your IT, you concentrate your risk in one vendor that holds the keys to nearly every system you run. That is exactly why attackers target providers in the first place.
This guide walks you through the first 24 to 48 hours as the customer sitting downstream of the breach. Most incident-response advice is written for the provider, not for the business that depends on it. You need a plan built for your side of the relationship.
A breach at your provider does not automatically mean your systems are compromised, but it does mean you have to treat that possibility as real until proven otherwise. Providers connect to your environment through privileged tools, remote access software, and administrative accounts. If an attacker controls those tools, the attacker can reach whatever those tools can reach.
Recent history shows how quickly a single provider compromise spreads to customers. In 2021, attackers exploited a flaw in Kaseya's remote management software and pushed ransomware through roughly 60 providers to as many as 1,500 downstream businesses, according to guidance published by CISA and the FBI. The customers of those providers did nothing wrong on their own networks, yet they still had to recover.
Your job in the first day is to answer three questions. Was your data exposed? Can the attacker still reach you? What do you owe your customers, partners, and regulators? The steps below help you answer each one.
You cannot see inside your provider's systems, so you have to reason from what you can control and observe. Start with a simple exposure map. Write down every system your provider can touch, every account they hold in your environment, and every dataset they process or store on your behalf. That list defines your worst-case exposure.
Next, look for signs of trouble on your own side. Review recent sign-in activity for provider-managed accounts, watch for unexpected password resets or multi-factor prompts, and check for administrative changes you did not request. Cases like this land in the news regularly, and one recent example shows how a small slip at a provider becomes a customer-wide problem. Clorox alleges that attackers called the help desk that Cognizant managed, posed as employees, and walked away with credentials that reached Clorox's identity systems and internal network. A single reset request became a company-wide incident.
Related Article: What the FBI's Silent Ransom Warning Means for Small Law Firms
Do not accept a vague "your data is fine" from your provider as the final word. Ask for the specific basis of that claim and the evidence behind it. You need facts, not reassurance.
Do not accept a vague "your data is fine" from your provider as the final word. Ask for the specific basis of that claim and the evidence behind it. You need facts, not reassurance.
The order of your first calls matters more than most people expect. Make them in this sequence.
Your provider has a conflict of interest in its own breach. The same company whose controls may have failed is not the right party to judge whether those controls failed. An independent forensic team, chosen by you or your carrier, gives you an honest account and preserves evidence properly.
This matters because many organizations lack the internal capability to investigate a serious intrusion, and they discover that gap at the worst possible moment. That blind spot has a name and a cost, which we cover in our breakdown of the DFIR gap that undermines cyber resilience. Line up independent forensic support now, before you need it, so you are not negotiating scope while the clock runs.
Ask your provider for specific, documented answers. General statements will not help you meet your own obligations. Require the following.
If your provider cannot answer these questions with specifics, that gap is your risk to manage, and you should escalate accordingly. That documentation matters most when a breach becomes a dispute over who is at fault. Consider what happened to BerryDunn, a consulting firm whose IT provider, Reliable Networks, was breached in 2023. The intrusion exposed sensitive personal information, including names, Social Security numbers, and health data, for roughly 1.1 million people. Affected individuals then brought claims against BerryDunn, and the firm in turn placed responsibility on the provider it had hired. When two parties point at each other after a breach, clear records determine who answers for what.
You control your environment even when your provider controls the tools inside it. Take these actions to limit the attacker's reach.
Take these steps in coordination with your forensic team so that you contain the threat without destroying evidence. Speed helps you, and so does care.
Resist the urge to send a detailed public statement before you have facts. Early over-commitment creates problems you cannot walk back. Keep internal leadership informed with what you know and what remains unconfirmed, and give realistic timelines rather than optimistic ones.
Hold external communications until counsel confirms what you are required to say and to whom. Your legal notification duties depend on your industry, your data, and your contracts, and those duties often set both the timing and the content of what you disclose.
Your legal notification duties depend on your industry, your data, and your contracts, and those duties often set both the timing and the content of what you disclose.
Once the immediate crisis passes, turn to prevention so that the next provider incident does you far less harm. A few durable moves make the biggest difference.
Review the security controls your provider actually runs, and require evidence rather than assurances. Every CEO benefits from a working knowledge of baseline expectations, which we lay out in our guide to the minimum security standards every CEO needs to know. Hold your provider to those standards in writing.
Scrutinize any provider that monitors your environment around the clock, because the quality of that monitoring varies widely. Our list of 10 red flags to watch for when hiring a 24/7 SOC provider gives you a practical screen. Watch the tooling layer above your provider as well, since flaws in remote management software have driven several major incidents.
Prepare for new categories of attack as well as familiar ones. Attackers now probe the AI tools that businesses adopt, and prompt injection has become a real threat, which we explain in our article on how to stop prompt injection, the biggest AI security risk for small businesses. A provider that stays ahead of emerging risks protects you better than one that reacts late.
The cases above are not outliers. They form a pattern that every business dependent on a provider should understand.
Each case reinforces the same lesson. A breach at your provider is a breach you have to answer for, so you need a plan that assumes it can happen to you.
You do not have to manage a provider breach alone. Experienced advisors can direct your forensic response, help you meet your obligations, and get you back to normal operations sooner. Learn how our team supports businesses through exactly this scenario on our cybersecurity advisory page, and see our dedicated incident response support for help in an active crisis.