Security Stop-Press : Supply Chain Attacks Hit Two In Five MSPs

New research shows that 43 per cent of MSPs and their customers experienced a cyber incident linked to a supplier or third-party vendor during the last year.

CyberSmart’s 2026 MSP Survey found that MSPs are increasingly being targeted because their access to customer systems can provide a route into multiple organisations. More than half of supply chain incidents involved the MSP as well as the customer.

The survey also found that only 45 per cent of MSPs continuously monitor third-party risk. CyberSmart CEO Jamie Akhtar warned that “a single weak link can have far-reaching consequences for customers, suppliers and partners”.

The findings come as MSPs prepare for the UK’s Cyber Security and Resilience Bill, which will increase scrutiny of supply chain security.

Businesses can reduce their exposure by reviewing supplier security, limiting third-party access, and monitoring supply chain risks on an ongoing basis.

Tech Insight : Problems With Windows 11 Updates Reported

Many MSPs have been reporting that Windows 11 updates are increasingly causing upgrade failures, BitLocker lockouts and unexpected behaviour, and here we look at what may be going wrong, why it is happening now, and what can realistically be done to prevent it.

The Pattern Many MSPs Are Seeing on the Ground

It has been reported across organisations supported by MSPs that Windows 11 feature updates and security patches are failing in ways that feel inconsistent, hard to predict and difficult to explain. In practical terms, this has included devices that meet Microsoft’s published requirements not receiving updates at all, updates failing part way through installation, and systems rebooting directly into BitLocker recovery screens.

What has made this particularly frustrating is that many of the affected machines appear otherwise healthy. For example, disk space is available, policies are applied correctly, and in some cases manual upgrades succeed. At scale, however, manual intervention doesn’t translate into a sustainable approach, particularly when large numbers of devices behave differently. As a result, for MSPs, Windows updates are increasingly becoming a visible support issue rather than a background maintenance task.

Issues Acknowledged

This experience appears to align with wider reporting beyond MSP communities. For example, back in November this year (2025), Microsoft acknowledged issues with specific Windows 11 security updates that caused devices to enter BitLocker recovery mode after installation. These incidents affected supported business versions of Windows 11 and prompted follow-up guidance and remediation updates.

Updates That Refuse to Install or Fail Without Warning

One of the most frequently reported problems is Windows 11 feature updates either not being offered to eligible devices or failing without presenting a clear error message.

A recurring technical factor appears to be the EFI system partition (a small hidden disk area that helps Windows start). Many devices originally deployed with Windows 10 were created with EFI partitions of around 100 MB. While this was sufficient under earlier Windows servicing models, it is increasingly inadequate for modern recovery and update processes.

For many now it seems that when Windows attempts to stage a feature update and can’t write the required boot or recovery components to the EFI partition, the update may fail silently or be blocked entirely. Windows Update does not always highlight this limitation clearly, so investigation often focuses on policies, drivers or hardware compatibility, when the underlying cause is actually related to disk layout and boot configuration.

It’s been reported that this lack of visibility has added complexity to diagnosing update failures, particularly in mixed hardware environments.

Why BitLocker Is So Often Involved

BitLocker, a built in Windows tool that encrypts a device’s data to protect it if lost or stolen, has featured prominently in many reported update issues, not because encryption itself is malfunctioning, but because of how closely it is now integrated into the Windows boot process.

For example, many Windows 11 devices ship with BitLocker or device encryption enabled by default, especially where users sign in using Microsoft or Entra ID accounts during setup. While this improves baseline data protection, it also means that updates interact directly with encrypted boot components.

In mid November, Microsoft confirmed that certain Windows 11 security updates could trigger BitLocker recovery prompts after installation, even when no obvious configuration changes had been made. Users were presented with requests for 48 digit recovery keys, leading to a noticeable increase in support calls where keys were not immediately available.

In some reported cases, recovery environments were also affected, with peripherals such as USB keyboards and mice not responding at the recovery prompt. Microsoft subsequently issued emergency fixes to restore recovery environment functionality, underlining the seriousness of the issue.

Windows 11 Upgrades and the End of Windows 10 Support

These update problems are occurring against the backdrop of a wider transition to Windows 11. Windows 10 reached the end of mainstream support in late 2025, prompting many organisations to accelerate upgrade plans. While extended security updates remain available in limited scenarios, Microsoft has positioned Windows 11 as the primary supported desktop platform going forward.

As a result, businesses that delayed upgrading are now moving in larger numbers, often across device fleets that include both new and older hardware. This has increased the volume of feature updates being deployed and exposed edge cases that may not have appeared as frequently during earlier, more gradual upgrade cycles.

Windows 11 itself has also followed a faster cadence of servicing updates, particularly during the rollout of later builds in 2025. While this approach enables quicker responses to security issues, it also increases the likelihood that update related problems will surface in real world environments before they are fully resolved.

Why These Issues Are Becoming More Common

These problems are becoming more common due to a combination of increased platform complexity, faster update cycles and stronger default security settings within Windows 11. For example:

– Growing platform complexity. Windows 11 is required to operate securely across a broad range of hardware, firmware versions and security configurations. Each update must account for UEFI behaviour (how the system firmware controls the boot process), TPM states (the status of the security chip that stores encryption keys), Secure Boot, encryption, device drivers and third party security software, all interacting simultaneously. As default security settings have been strengthened, the tolerance for inconsistency has narrowed. Relatively small changes in update handling can have disproportionately large effects once deployed at scale.

– Faster update cycles. Microsoft now releases updates more frequently than in previous Windows generations. While this improves responsiveness to vulnerabilities, it reduces the amount of time updates spend being exercised across the full range of business configurations before wide deployment. MSPs often encounter these edge cases early because they support diverse environments rather than uniform device fleets.

– Encryption as a default state. With encryption now widely enabled by default, the consequences of update failures have changed. When issues occur during boot related updates, devices may refuse to start without recovery credentials rather than reverting automatically. This has raised the operational impact of update failures, even where the underlying issue is relatively contained.

What Has Helped Reduce the Impact

Across wider industry reporting and real world experience, several patterns have now emerged around which measures have helped limit disruption when Windows 11 update issues occur.

For example, testing feature updates and major security patches on a small number of representative devices has helped surface issues early. Staged deployment, rather than immediate broad rollout, has allowed problems to be identified before they affect larger user groups.

Centralised storage of BitLocker recovery keys has also proven critical where recovery prompts occur, reducing downtime and support escalation. In environments where EFI partition limitations are known, addressing these during rebuilds or hardware refresh cycles has reduced repeated update failures.

Alongside these technical measures, clearer explanations of how modern Windows updates interact with security features and boot environments have become more important as businesses try to understand whether issues are isolated incidents or part of wider platform behaviour.

What Does This Mean For Your Business?

It seems that recently reported Windows 11 update problems are not just the result of a single fault or a sudden drop in quality, but the outcome of a more complex platform colliding with faster release cycles and a large, overdue upgrade push away from Windows 10. For MSPs, this has changed the nature of updates from something that could largely run in the background into an operational risk that needs closer attention, clearer communication and better preparation. For Microsoft and hardware vendors, it highlights how small changes at the boot or recovery level can have wide consequences once deployed at scale.

For UK businesses, the practical takeaway is that disruption linked to updates does not automatically indicate neglect or mismanagement. For example, many of the issues now being seen are tied to how modern Windows versions handle encryption, recovery environments and legacy device layouts during upgrades. Understanding that context matters, particularly as more organisations complete their move to Windows 11 and rely on it as their primary supported platform.

When update problems do arise, speaking to your IT support provider is often the safest and most effective first step. This is because they are best placed to confirm whether an issue is local or part of a wider pattern, to recover access without risking data, and to put measures in place that reduce the chance of repeat disruption. As Windows continues to evolve, that relationship between businesses, their IT support companies, and the platform itself is becoming more important, not less.

Tech Insight : 45% Of MSPs Keep Cash To Pay Off Hackers

A new survey reveals 45 per cent of managed service providers (MSPs) are setting aside cash to pay ransomware demands, as fears over AI-fuelled cybercrime continue to mount.

MSPs Under Pressure as Ransomware Attacks Surge

The finding comes from the CyberSmart MSP Survey 2025, which examined the security posture of 900 MSPs across the UK, Europe, Australia, and New Zealand. According to the report, nearly half of those surveyed now maintain a dedicated pot of money in case they are hit by a ransomware attack, a tactic where cybercriminals encrypt a victim’s data and demand a payment for its return.

Counter To Guidance

This approach appears to run counter to guidance from insurers, governments, and law enforcement agencies, which consistently urge organisations not to pay. However, the growing scale and frequency of attacks, often powered by artificial intelligence, appear to be forcing MSPs to adopt a more pragmatic (if controversial) strategy.

“Organisations shouldn’t rely on ransomware payments; rather, they should partner with organisations that can help proactively secure them,” said Jamie Akhtar, CEO and co-founder of CyberSmart.

Be Prepared

The report’s findings highlight a deepening sense of vulnerability among MSPs, many of which provide outsourced IT and cyber-security services to small and medium-sized enterprises (SMEs). With AI-generated phishing emails, malware, and deepfakes becoming increasingly sophisticated, the pressure to be prepared for the worst has never been higher.

More Breaches, More Budgets, More Confusion

CyberSmart’s research revealed that 69 per cent of MSPs had suffered two or more cyber breaches in the last 12 months, while 47 per cent reported being hit three times or more. These incidents are not just one-off events. For example, many are the result of supply chain vulnerabilities, such as the May 2025 breach where the Dragonforce ransomware group exploited a remote monitoring and management (RMM) tool to compromise multiple MSP clients.

Faced with mounting threats, MSPs are reacting in different ways. For example, 36 per cent now rely on cyber insurance as their primary defence, while 11 per cent (worryingly) have neither cyber insurance nor a ransomware fund in place, leaving them financially and operationally exposed if attacked.

Guidance Not Clear

It seems that part of the problem is that official guidance around ransomware payments remains fragmented and unclear. While governments generally discourage paying ransoms, enforcement is inconsistent outside the public sector. “What your business is advised to do will largely depend on where you’re based and who’s advising you,” CyberSmart noted in its commentary.

This has led to a patchwork of interpretations, with some MSPs feeling they have little choice but to maintain a reserve, despite the moral and strategic risks involved.

UK Government Moves to Ban Ransomware Payments for Critical Services

In July 2025, the UK government announced proposals to ban ransomware payments for public sector bodies and operators of critical national infrastructure (CNI). The measures, introduced by the Home Office following a public consultation, would apply to organisations such as hospitals, councils, schools, and water providers, sectors where operational downtime can endanger lives.

“Ransomware is a predatory crime that puts the public at risk, wrecks livelihoods and threatens the services we depend on,” said Security Minister Dan Jarvis. “We’re determined to smash the cyber criminal business model and protect the services we all rely on.”

Private Businesses Would Need To Notify Government Before Paying

Under the proposals, private businesses would not be banned outright from paying, but would be required to notify the government before doing so. This would enable authorities to offer advice, check for potential sanctions breaches (such as paying Russian-linked gangs), and gather intelligence to disrupt criminal networks.

Cybercrime’s Business Model Under Scrutiny

The rationale behind the payment ban is to undermine the business model of ransomware gangs, which rely on victims caving in quickly to avoid reputational damage, data leaks, or prolonged disruption. However, experts have warned that banning payments, especially only for certain sectors, may not have the desired effect.

“Ransomware is largely an opportunistic crime, and most cyber criminals are not discerning,” said Jamie MacColl, a senior research fellow at the Royal United Services Institute (RUSI). “They’re unlikely to develop a rigorous understanding of UK legislation or how we designate critical infrastructure.”

Others suggest the ban could increase the stakes for victims. “If the best solution is to just turn around and say to the hackers, ‘We’re not giving in to your demands anymore,’ don’t be surprised if they double down,” said Rob Jardin, chief digital officer at NymVPN.

The British Library, one of the most high-profile public victims of ransomware in recent years, chose not to pay after an attack in October 2023 devastated its systems. “We are committed to sharing our experiences to help protect other institutions and build collective resilience,” said Chief Executive Rebecca Lawrence.

AI Attacks Are Changing the Game

Perhaps the most striking shift in this year’s CyberSmart survey is the rise of artificial intelligence as the top concern for MSPs in 2025. AI overtook ransomware itself, with 44 per cent of respondents citing it as their biggest worry, compared to 40 per cent for traditional malware and ransomware threats.

This change reflects a growing trend in how attackers operate. For example, AI tools are now being used to write convincing phishing emails, build more evasive malware, and even create deepfake audio and video to impersonate executives or support social engineering attacks.

In 2024, 67 per cent of MSPs reported falling victim to AI-enabled attacks, a figure expected to rise in 2025 as generative and agent-based AI tools become more widely available to threat actors.

However, many MSPs feel ill-equipped to counter these evolving threats, with a lack of user-friendly, AI-specific defence tools still a key issue. “MSPs are being asked to do more, with fewer tools at their disposal,” the report concludes.

Customer Expectations Are Rising, But So Is Investment

The research also showed that 84 per cent of MSPs now manage their clients’ cybersecurity infrastructure, or both their cybersecurity and broader IT estate. This shift reflects growing client expectations for MSPs to provide end-to-end protection which are the kind of expectations that often come with greater scrutiny.

According to the CyberSmart research, 77 per cent of MSPs said potential customers are now evaluating their cyber credentials more carefully, especially in the procurement stage.

To meet demand, it seems that MSPs are now investing heavily. For example, 81 per cent have increased spend on hiring security specialists, and 78 per cent have upped budgets for cyber defence tools, training, and client services. Compliance is also high on the agenda, with 60 per cent hiring regulatory specialists and 64 per cent enhancing capabilities to align with frameworks such as NIS2 in the EU and the UK’s upcoming Cyber Security and Resilience Bill.

According to NCSC Director of National Resilience Jonathon Ellison, such steps are critical: “Ransomware remains a serious and evolving threat, and organisations must not become complacent. All businesses should strengthen their defences using proven frameworks such as Cyber Essentials.”

MSPs Prepared Yet Vulnerable

Despite the high rate of breaches, MSPs remain surprisingly confident in their security posture. For example, CyberSmart found that 76 per cent rate their cyber confidence as above average or higher. That said, only 20 per cent described their confidence as complete, suggesting that many know there’s room for improvement.

Looking at this research, for businesses relying on MSPs to manage their security, the message appears to be that while many providers are stepping up their game, others are still reacting to threats in ways that may not align with long-term best practice.

Co-op CEO Shirine Khoury-Haq, who oversaw the retailer’s response to a Scattered Spider ransomware attack, captured the sentiment well, saying: “What matters most is learning, building resilience, and supporting each other to prevent future harm. This is a step in the right direction for building a safer digital future.”

What Does This Mean For Your Organisation?

For MSPs and their clients, the emergence of ransomware funds could be seen as a move from aspirational resilience to operational realism. Despite official advice against paying cybercriminals, it seems that many MSPs clearly believe they cannot afford to be unprepared. With 69 per cent already breached multiple times in a single year and AI accelerating the scale and complexity of attacks, the temptation to hold a contingency reserve is understandable. However, this pragmatic stance may also entrench the very business model that governments and law enforcement are working hard to dismantle.

The UK’s proposed ransomware payment ban for public bodies and CNI highlights just how far official thinking has moved towards systemic deterrence. However, the exclusion of private businesses from that ban, and the option for them to pay under notification, risks creating an uneven response that may ultimately frustrate enforcement and dilute its impact. As Jamie MacColl pointed out, most ransomware gangs operate opportunistically and will not necessarily distinguish between regulated and unregulated targets. This raises questions about whether partial bans can realistically alter attacker behaviour.

For UK businesses, especially SMEs dependent on MSPs for protection, the findings raise difficult questions. For example, while many providers are making serious investments in tools, people, and compliance, others are still relying on reactive strategies that may offer short-term cover but little long-term assurance. The increasing scrutiny on MSPs is likely to intensify, particularly as clients seek partners who are both cyber confident and operationally transparent. Businesses must now evaluate not only whether their MSP has a ransomware plan, but also whether that plan reflects best practice or a compromise born of confusion.

For regulators, the lack of clarity and consistency around ransomware responses remains a core problem. Guidance alone is proving insufficient. A broader and more unified framework, alongside mandatory reporting, may be needed to help ensure MSPs, their clients, and their insurers are working from the same playbook. For now, the reliance on private ransomware funds points to a cyber landscape still dominated by tactical survival rather than strategic coordination.

Tech News : Headaches For MSPs As Microsoft Unbundles Teams

Microsoft’s announcement that it will sell its chat and video app Teams separately from its Office product globally is likely to cause considerable headaches for IT departments and managed service providers.

Why Unbundle? 

Teams is to be unbundled and sold separately globally (it’s been unbundled in the EU since last October) in response to an antitrust lawsuit and to avert the possible associated fine.

An antitrust lawsuit against Microsoft over its bundling of Teams with its Office suite in the EU was initiated based on a complaint from competitor Slack Technologies in 2020. Teams was originally bundled with Office 365 as a replacement for Skype back in 2017 and became popular during the pandemic.

However, rival Slack (now owned by Salesforce) alleged that Microsoft was illegally tying its Teams application to its dominant Office productivity suites, thereby leveraging its market dominance to stifle competition unfairly.

The European Commission said at the time: “Microsoft may grant Teams a distribution advantage by not giving customers the choice on whether or not to include access to that product when they subscribe to their productivity suites.” 

This led to The European Commission investigating Microsoft over its amalgamation of Office and Teams since 2020 and then to Microsoft separating Teams for Office 365 In October last year in the European Economic Area and Switzerland.

Pressure 

Continued pressure from the regulator and the desire to (understandably) avoid a fine that could potentially be up to 10 per cent of its global revenue has now led Microsoft to announce that it will now be unbundling Teams and selling it separately, globally.

How Much?

Starting from April 1, customers can either continue with their current licensing deal, renew, update or switch to the new offers. Unbundled Teams will be available for new customers as a standalone app for $5.25, whereas Office packages without Teams will range between $7.75 and $54.75.

It’s worth noting that these figures may vary by country and currency and Microsoft hasn’t yet disclosed prices for current packaged products.

Trouble For MSPs 

Unfortunately, although the move may be good news for Microsoft’s rivals, it’s not a welcome announcement from the perspective of the many managed service providers (MSPs) who are resellers of Microsoft’s packages and products. Indeed, for MSPs it is likely to mean headaches in several key areas, such as:

– Service delivery and integration. Unbundling may disrupt how MSPs bundle services, demanding changes in delivery models due to the deep integration of Teams with Office applications.

– Billing and subscription management Separate billing for Teams and Office could complicate financial operations, requiring more administrative effort to manage distinct subscriptions and compliance.

– Training and support. A standalone Teams setup might increase support queries and necessitate updated training materials, placing additional demands on MSP resources.

– Client satisfaction and retention. Crucially, the change could confuse clients who are accustomed to (and expect) the convenience of integrated packages, potentially affecting their satisfaction and loyalty (during the adjustment phase), lowering the barriers to exit from their supplier.

– Market competition. Facing competitors offering more cohesive solutions, MSPs may need to reevaluate their offerings and pricing to stay competitive.

What Does This Mean For Your Business? 

This is not an unexpected development, given Microsoft’s unbundling of Teams in the EU last October, continued regulator and competitor pressure, and the threat of a massive fine. It’s good news for Microsoft’s competitors like Slack, however, for Microsoft, some say that even this concession and change in its product strategy may not be enough to avoid a fine.

The complications and unsettling effects it could have on UK business customers could also cause some considerable problems for the UK’s many MSPs. For example, they may find themselves having to navigate a more complex service landscape, facing challenges in service integration, billing management, and customer support. This could mean that MSPs will have to now monitor the impacts carefully and adjust their strategies to minimise the likely negative effects on their business and client relationships.

This could mean having to adapt current offerings and trying their best to ensure seamless integration and support for both Teams and Office applications independently – an extra challenge in an already difficult market.