The fictional company: Meridian Building Services

Illustrative scenario, fictional company profile
CompanyMeridian Building Services (fictional)
Employees520 across 4 locations
RevenueApprox. $65M annually
IndustryCommercial facilities management
IT infrastructureHybrid: cloud plus on-premises servers
Core systemsMicrosoft 365, ERP (on-premises), CRM (SaaS), file servers
IT team3 internal IT staff, no dedicated security function
Security toolingStandard AV, Microsoft 365 basic licensing
BackupsNightly backups to on-premises NAS, some cloud backups

Meridian is mid-sized in every meaningful sense. Not large enough to have a dedicated security operations centre. Not small enough that an incident would simply shut everything down cleanly. The IT manager, Paul, knows the environment well but works primarily in reactive mode: help desk tickets, hardware replacements, Microsoft 365 administration. There is no formal incident-response plan.

This profile is not a worst-case description. It reflects a common configuration for UK and North American mid-market businesses in 2026.

What modern ransomware actually does

Most descriptions of ransomware stop at encryption: an attacker encrypts your files and demands payment for the decryption key. That description was largely accurate in 2017. It understates what current ransomware incidents typically involve.

Modern ransomware attacks are often multi-stage intrusions that combine credential theft, network reconnaissance, privilege escalation, data exfiltration, and only then, encryption. The encryption event that employees notice is frequently the final act of an operation that has been running for days, sometimes weeks.

The stages, described in defensive terms:

Initial access. Attackers get their first foothold in the environment. The Sophos Active Adversary Report 2024 found exploited external vulnerabilities were the leading initial access vector (32%), followed by compromised credentials (29%), and phishing (21%). Many of these entry points are not zero-day exploits. They are unpatched systems, reused passwords, and exposed remote desktop services.

Persistence and reconnaissance. Once inside, attackers establish persistence so they survive detection or reboots, then map the environment: what systems exist, what data is accessible, where backups are stored, which accounts have elevated privileges.

Privilege escalation and lateral movement. Attackers seek accounts with broader access, particularly domain administrator privileges. From one compromised endpoint, they may move to dozens of systems. This is the stage where attackers reach file servers, backup systems, and the ERP database that contains the company's most sensitive data.

Data exfiltration. Before encryption, many ransomware operators copy sensitive data to attacker-controlled infrastructure. This creates the basis for double extortion: the company faces both a ransom demand to recover access to encrypted systems and a separate threat to publish or sell the stolen data if payment isn't made.

Encryption and disruption. The final stage is the visible event: files are encrypted, systems become inaccessible, and ransom notes appear across the environment.

How fast can this happen?
Secureworks found the median time from initial access to ransomware deployment fell below 24 hours within a single year of tracking, with more than 50% of engagements seeing ransomware deployed within 24 hours of initial access. CrowdStrike measured an average attacker breakout time (from initial foothold to moving to another system) of just 48 minutes. The window for defenders to detect and contain an intrusion before encryption begins is narrower than many organisations assume.

The incident timeline: what happens at Meridian

The following timeline reflects how ransomware incidents have been documented to unfold, based on published incident-response research from Mandiant, Sophos, CrowdStrike, Secureworks, and CISA. It is an illustrative scenario, not a report of an actual incident.

Days –14 to –3
Before the attack, the intruder is already inside
Attackers obtained credentials for a Meridian employee's VPN account, likely purchased from a credential broker or obtained through a previous phishing campaign. They have logged in several times during off-hours and are mapping the internal network. The standard AV has not flagged anything unusual. Paul hasn't received an alert.
Day –2
Data staging, attackers locate the most valuable assets
Attackers identify the ERP database server, the shared finance drive, the client contracts folder, and the backup server. They begin copying data to a remote staging location. Several gigabytes of data leave the network during what looks like a routine backup window. No alert fires.
Day 0, 3:00 AM
Encryption begins
The ransomware payload is deployed across the environment. It encrypts files on every accessible share: the finance drive, the contracts repository, the HR records folder, the operations data. The backup server, connected to the main network, is also encrypted. The ERP database server is targeted. By the time the first employee arrives at the office at 7:45 AM, the encryption is nearly complete.
Day 0, 8:05 AM
First reports come in
The finance assistant tries to open a spreadsheet. It won't open. She tries another. Same problem. She calls the help desk. At the same time, two sales team members in different offices report that their shared drive shows nothing but strange files with long alphanumeric names. One file is labelled README_HOW_TO_RECOVER.
Day 0, 8:30 AM
IT thinks it's a technical glitch
Paul the IT manager initially assumes a storage issue or failed update. He tries to log in to the file server. His credentials work, but the directories are unreadable. He restarts the server. It doesn't help. He checks the ERP system. It won't start. He opens the README file.
Day 0, 8:45 AM
The ransom note
The note explains that files have been encrypted, that data has been copied, that there is a payment deadline, and that a "negotiation portal" exists on a dark web address. The demand is $850,000 in cryptocurrency. Paul calls the COO.
Day 0, 9:30 AM
Emergency response begins
The COO, CEO, and Head of Finance are briefed. An external IT security firm is called in. The first priority is containing the incident: disconnecting affected systems from the network to stop any remaining encryption or further data theft. Some systems are shut down abruptly, which will complicate forensic analysis later.
Day 0, Noon
Scope becomes clear
The incident-response team has now identified that file servers, the ERP database, the backup server, and at least 40 employee endpoints are encrypted. Microsoft 365 (cloud-hosted) is unaffected. The SaaS CRM is unaffected. But nearly every on-premises system is down. The company's operations are effectively on pause.
Day 0, 3:00 PM
Legal counsel engaged
The company's lawyers are called. They immediately raise questions around regulatory notification obligations, insurance policy requirements, and how to document the incident properly. The cyber-insurance company is notified. The insurance carrier's preferred incident-response vendor is also contacted.
Days 2–3
Forensic investigation and containment
Forensic investigators work to determine the initial access vector, map the attacker's path through the environment, identify what data was accessed or exfiltrated, and establish whether any attacker access or persistence mechanisms remain. This work takes time and cannot safely be skipped before recovery begins.
Week 1
Phased recovery begins
Identity infrastructure is restored first. Clean cloud backups are used to recover some data. The ERP vendor is engaged to restore from a backup taken 11 days before the incident. Operations continue in manual mode for several days. Not all systems are restored in week one.
Weeks 2–4
Legal, regulatory, and reputational consequences continue
The legal and regulatory response is ongoing. Data protection authorities are notified. Some affected customers are informed their data may have been compromised. Insurance claims are processed. Security improvements are scoped and implemented. The IT team is still rebuilding endpoints in week three.

Day 1: the business starts breaking

By 10 AM on Day 0, Meridian's employees understand that something is wrong. By noon, most of them cannot do their jobs. Here is what each function experiences. The precise impacts will differ between organisations depending on architecture, systems, and what is affected.

Finance
  • Invoice processing has stopped
  • The accounts payable system is inaccessible
  • Pending payments cannot be authorised
  • Payroll scheduled for Friday is at risk
  • Budget spreadsheets are encrypted
  • The Head of Finance is working from memory
Operations
  • ERP is down: no job scheduling, no work orders
  • Operations managers are calling clients manually
  • Contract details are unavailable
  • Purchasing system is offline
  • Dozens of service calls are managed on paper
  • Supplier relationships are strained
IT
  • All three IT staff are in response mode
  • Help desk calls are unanswered
  • Server environment is being assessed
  • Backup integrity unknown
  • Forensic work is just beginning
  • External responders are asking for access credentials
Sales and Customer Support
  • SaaS CRM is accessible (cloud, unaffected)
  • But customer documents and contracts are encrypted
  • Quotes cannot be generated from the ERP
  • No response to customer enquiries requiring account history
  • Customer-facing staff are working from notes and memory

Email (Microsoft 365) and the SaaS CRM remain available because they are cloud-hosted and not connected to the on-premises environment. This is one of the few things working in Meridian's favour. For companies where core operations run entirely on-premises, the disruption would be more complete.

The executive crisis meeting

At 2 PM on Day 0, the CEO, COO, Head of Finance, IT manager, legal counsel, and the external incident-response lead sit together. This meeting is where ransomware becomes visibly a business problem rather than a technology one. The questions facing the room are not technical.

What systems are encrypted and which are clean? How long until basic operations can resume? Has customer data been compromised? What are the legal obligations if data has been stolen? Does the cyber-insurance policy require specific actions before recovery begins? Should law enforcement be contacted? What do employees need to be told, and when? Who authorises the communications? Who is speaking to the ransom demand?

These questions cannot be answered quickly by an IT manager working alone. Many of them require decisions that sit at the CEO and board level. And many of them need to be answered before recovery work can begin, not after.

The lesson from documented incidents
CISA's ransomware guidance consistently notes that organisations without a pre-existing incident-response plan take substantially longer to make and execute initial response decisions. The executive crisis meeting at a company with a tested response plan typically lasts 30 minutes, produces clear decision ownership, and enables parallel workstreams. Without a plan, it frequently becomes a four-hour session that delays containment.

The backup test: the moment that changes everything

There is a moment in almost every ransomware incident that determines the trajectory of recovery. It is the moment when someone checks whether the backups are actually usable.

Meridian had backups. The IT manager had been running nightly backups to a NAS device and had started some cloud backups earlier that year. The discovery:

The on-premises NAS was connected to the same network the attacker traversed. It is encrypted. Fourteen months of on-premises backups are gone. The cloud backups are intact, but they cover only certain systems, not the ERP. The ERP backup that does exist is 11 days old. That gap means 11 days of transactional data, invoices, work orders, and records are gone.

The distinction that matters: having backups and having recoverable backups are not the same thing. A backup that was never tested, stored on an accessible network, or not updated to include newer systems provides false confidence rather than genuine resilience.

What backup assessments commonly find
Organisations frequently discover during incidents that some systems were added to the environment without being added to the backup schedule. Database backups may exist but require recovery credentials that are not documented. Recovery time from backup may be estimated in hours but take days in practice. Offline or air-gapped backups are the strongest protection against ransomware affecting backup data, but require deliberate architectural decisions made before an incident. Recovery Point Objective (what data can you afford to lose) and Recovery Time Objective (how long can you be down) should be defined and tested well before the backup is ever actually needed.

Data theft and extortion

By Day 2, the forensic team has identified evidence that several gigabytes of data left the environment before encryption. This is the part that changes the legal and regulatory picture significantly.

The encrypted files might be recoverable from backups, imperfectly. But the data that was copied to an attacker's server cannot be un-copied. The company now faces a second threat: the attackers' claim that they will publish the stolen data unless paid separately, regardless of whether the encryption ransom is paid.

What data was taken matters enormously. If the stolen data includes employee information, the company has data protection obligations. If it includes customer account details or personally identifiable information, affected individuals may need to be notified under GDPR in the UK and Europe, state data breach notification laws in the US, or equivalent regulations in other jurisdictions. Notification timelines vary: GDPR requires notification to the relevant supervisory authority within 72 hours of becoming aware of a personal data breach if it poses a risk to individuals.

None of this is resolved by paying the ransom. Paying does not guarantee data deletion. Multiple documented incidents have shown that companies which paid received no confirmation of data destruction and later saw stolen data published regardless.

Should the company pay the ransom?

Meridian's leadership now faces a demand for $850,000. No one can give them a simple answer. The decision involves factors that vary by organisation and incident.

Factors pushing toward considering payment: The backup situation is worse than expected. The ERP restoration will take at least two weeks. The company has cyber-insurance with a ransomware provision. The business interruption is already significant and every additional day without the ERP costs money. The attackers have data they are threatening to publish.

Factors pushing against payment: FBI and CISA guidance consistently advises against paying ransoms because payments fund criminal operations and do not guarantee file recovery or data deletion. Paying does not remove the attacker from the network if persistence mechanisms remain. Some ransomware groups do not reliably provide working decryption keys. Paying may create future targeting risk. Depending on the attacker group, sanctions may make payment legally prohibited. Sophos 2025 data found 80% of organisations that paid were attacked again within 12 months (Fortinet 2025 data).

The Sophos State of Ransomware 2025 report found that 46% of affected organisations paid a ransom, making it the second-highest rate in six years. Of those that paid, 53% paid less than the initial demand through negotiation. This is a real, documented decision that many organisations make. The framing "never pay" understates how difficult the decision actually is in practice.

Who should be involved in this decision
Legal counsel (particularly sanctions and data protection obligations), the cyber-insurance carrier (some policies have specific provisions around ransom payments), incident-response specialists (to assess whether payment would actually produce working decryption keys and what negotiation has achieved in similar cases), and law enforcement contacts. FBI field offices have ransomware specialists and advise organisations to report incidents, which can support the investigation without requiring an immediate commitment on payment. CISA's Ransomware Guide provides current official guidance.

Week 1: containment and recovery

Before any recovery work begins, the incident-response team needs to answer a critical question: has the attacker's access been fully removed from the environment? Restoring systems into a compromised network can result in re-infection within hours. Many documented incidents have involved organisations that restored from backup and were re-encrypted because persistence mechanisms remained in place.

The first week of response at Meridian involves parallel workstreams:

Investigation: Forensic analysis of compromised systems, identification of the initial access vector (confirmed as a compromised VPN credential), mapping of attacker movement through the environment, determination of what data was accessed or exfiltrated, and preservation of evidence for potential law-enforcement or legal purposes.

Containment: Full credential reset across the environment, disabling or removing persistence mechanisms identified by forensics, network segmentation to isolate clean systems, rebuilding the most critical servers from trusted sources.

Recovery sequencing: Systems are brought back in priority order. Identity infrastructure comes first (Active Directory or equivalent), then core network services, then critical business applications, then data recovery from clean backups, then employee endpoints. This process typically takes days to weeks, not hours.

The business runs in manual mode. Finance teams work from printed records and email. Operations staff coordinate by phone. Customer commitments are managed case by case. This is operationally exhausting and directly impacts revenue.

The hidden cost of ransomware

The ransom demand is the number that makes the news. It is rarely the largest cost.

Illustrative cost breakdown, hypothetical scenario
The figures below are illustrative estimates for a scenario resembling Meridian Building Services. They are NOT industry averages or benchmark figures. Actual costs vary significantly by organisation, incident scope, insurance coverage, regulatory jurisdiction, and recovery approach. Use them to understand the cost categories, not as planning targets.
Cost category Illustrative estimate Nature Notes
External incident response$180,000–$300,000One-timeForensics, IR specialists, containment
Business interruption$150,000–$400,000One-time2–3 weeks of degraded operations, lost revenue
System recovery and rebuild$80,000–$160,000One-timeServers, endpoints, software licences
Legal and regulatory$50,000–$120,000One-timeLegal review, notification costs, regulatory response
Security improvements$60,000–$150,000RecurringMDR service, backup redesign, identity hardening
Ransom payment (if paid)Variable, $0 to $850K+One-timeDoes not guarantee recovery or data deletion
Reputation and customer impactDifficult to quantifyLong-termCustomer churn, contract impacts, insurance premium increases
Total (excluding ransom, reputation)$520K–$1.13MIllustrative rangeBefore ransom, before customer impact. Clearly hypothetical.

For context: the Sophos State of Ransomware 2025 global survey of 3,400 organisations found a mean recovery cost of $1.53 million globally excluding the ransom payment itself. For US organisations specifically, the US-edition report found the mean recovery cost was $1.91 million, also excluding ransom. These figures are global survey means and include organisations of various sizes, not specifically mid-market companies, so direct comparison to a specific scenario requires caution.

What would have changed the outcome?

Return to Meridian. Not every control prevents every attack. But several specific gaps directly worsened the outcome.

Multi-factor authentication on the VPN. The initial access was a compromised credential. If the VPN required MFA, a stolen password alone would not have been sufficient for access. This is consistently among the highest-ROI security controls for this attack pattern. CISA's guidance on ransomware prevention identifies MFA as a primary preventive control.

Endpoint Detection and Response (EDR). Standard antivirus did not alert on the attacker's activity during the pre-encryption phase. An EDR solution with behavioural detection would have had a higher probability of flagging the lateral movement, credential access, and staging activity before encryption began. The Sophos State of Ransomware 2025 found that 44% of organisations were able to stop the attack before data was encrypted, a six-year high, partly attributed to improved detection tools including MDR and EDR adoption.

Isolated and tested backups. The on-premises backup server was on the same network as the rest of the environment and was encrypted along with everything else. Offline, air-gapped, or cloud backups with immutable retention would have preserved recovery options that were lost in this incident.

Privileged access controls. The attacker reached domain administrator level and was therefore able to access everything. Limiting which accounts have administrative privileges and requiring separate credential sets for administrative tasks (a principle called least privilege) would have constrained the attacker's reach.

An incident-response plan. The first several hours of the Meridian response were consumed by decisions that could have been pre-made: who leads the response, who is contacted, what gets isolated first, who talks to the insurance company, who handles communications. None of those decisions require an emergency meeting to resolve if they were documented in advance.

When managed cybersecurity services make sense

Meridian has three IT staff. None of them are security specialists. They are not watching security logs at 3 AM when the encryption begins. They are not running threat hunts through the environment looking for pre-encryption attacker activity. For a company of this size, building that capability internally is typically not cost-effective.

Managed Detection and Response (MDR) is a category of outsourced security service that provides 24/7 monitoring, threat hunting, alert investigation, and active incident response by security analysts. MDR providers maintain security operations centres, employ specialist threat hunters, and have response capabilities that most mid-sized businesses cannot build internally.

A key distinction from traditional managed security services: MDR providers typically take active response actions, not just alert escalation. When a threat is confirmed, an MDR provider can isolate an endpoint, block a malicious process, or contain a compromised account, not simply send an email telling the IT team an alert fired.

Managed services make the most sense when an organisation lacks 24/7 security monitoring, does not have the internal expertise to investigate security alerts or perform threat hunting, has experienced incidents or near-misses that indicate a detection gap, or operates in a regulated industry where security controls need to be verified against a standard.

Managed services are not a guarantee against ransomware. No single control prevents all incidents. But faster detection materially reduces the impact: IBM's 2025 Cost of a Data Breach research found that organisations with high levels of security AI and automation detected breaches 100 days faster and saved an average of $2.2 million in breach costs compared to organisations without that capability.

Cybersecurity and managed services companies to consider

The following companies are established providers of managed detection and response and related cybersecurity services, relevant to mid-sized businesses in 2026. This is not a ranked list or a paid placement. All capabilities are verified from official company documentation as of mid-2026. Pricing is custom and quote-based for all listed providers.

CrowdStrike Falcon Complete
MDR / Full-Stack Managed
Best suited forMid-market to enterprise organisations already running or willing to run the CrowdStrike Falcon platform
Service model24/7 MDR combining Falcon platform detection, OverWatch threat hunting, and analyst-led response with full-cycle remediation including endpoint restoration
CoverageEndpoint, identity, cloud workloads, and third-party telemetry integration
Recognition4.7/5 across 480 Gartner reviews. 100% detection in 2025 MITRE ATT&CK Enterprise Evaluation. Leader in Forrester Wave Q1 2025 for MDR services.
StrengthFull-cycle response including endpoint restoration. Analysts actively contain and remediate threats without requiring the client team to execute response actions. The OverWatch threat hunting component operates continuously across all Falcon customers, providing threat intelligence breadth that individual organisations cannot replicate.
ConsiderationFalcon Complete requires the CrowdStrike Falcon platform. Organisations already on a different EDR vendor will face a platform change. Enterprise pricing is on the higher end of the market. The July 2024 platform outage (unrelated to the MDR service itself) remains a reference point in vendor evaluation conversations.
Sophos MDR
MDR / Endpoint + Multi-Vendor
Best suited forSMB to mid-market organisations, particularly those with Sophos endpoint products, but also those wanting vendor-agnostic coverage across their existing security stack
Service model24/7 human-led detection and response with Collaborate or Complete modes. Collaborate mode alerts and advises; Complete mode takes active response actions including threat neutralisation and root cause removal.
CoverageSophos and third-party environments. Sophos states 350+ integrations across security tools, allowing ingestion from non-Sophos platforms including Microsoft Defender, CrowdStrike, and others.
Recognition4.8/5 across 1,031 Gartner ratings. Leader in Gartner Magic Quadrant for MDR services.
StrengthBreadth of third-party integrations makes Sophos MDR practical for organisations with mixed security tooling who don't want to replace their entire stack. The Complete mode provides full response authority without the customer team being in the critical response path.
ConsiderationResponse depth and speed in Collaborate mode depends on customer team availability, which is the mode some buyers select for cost reasons. Confirm which mode your contract covers and what response actions are included before signing.
Arctic Wolf
Managed Detection and Response / SOC-as-a-Service
Best suited forMid-market organisations without dedicated internal SOC teams, particularly those wanting a high-touch, advisory-oriented security operations model
Service modelConcierge Security Team model: each customer is paired with a dedicated team of analysts who develop deep familiarity with the specific environment. 24/7 monitoring with guided and active response capabilities.
CoverageEndpoint, network, cloud environments, and log sources. Vendor-agnostic, works with existing security tooling.
Recognition4.9/5 across 788 Gartner ratings, among the highest in the category.
StrengthThe dedicated Concierge Security Team model means analysts understand the customer's specific environment over time, reducing false-positive noise and improving detection accuracy. The high-touch model suits mid-market organisations that want an operational security partner rather than a monitoring tool.
ConsiderationResponse authority is guided rather than fully autonomous. The customer team participates in response decisions. For organisations that want fully automated or analyst-led containment without customer involvement, confirm the specific response model in contractual terms.
SentinelOne Vigilance (Singularity MDR)
MDR / XDR-Native Managed
Best suited forMid-market to enterprise organisations already running SentinelOne EDR/XDR who want managed coverage on top of the Singularity platform
Service modelTiered: Vigilance offers monitoring and response guidance; Vigilance Elite/Respond adds active containment. Available with the Singularity platform across endpoint, cloud, and identity.
CoverageEndpoint, cloud workloads, identity. Supports third-party telemetry at higher service tiers.
RecognitionSentinelOne published as a Leader in Gartner Magic Quadrant for Endpoint Protection Platforms. MDR service ratings vary by tier.
StrengthHigh automation depth in the underlying platform reduces analyst response time. The AI-native Singularity platform performs autonomous threat responses at speed, with the MDR layer adding human oversight and investigation for complex scenarios.
ConsiderationOptimal value requires running SentinelOne endpoint agents. Organisations on a different EDR will face a platform decision. Tier selection (Vigilance vs Vigilance Respond) significantly affects what response actions the provider takes independently.
Rapid7 MDR
MDR / SecOps Platform
Best suited forMid-market to enterprise organisations wanting MDR combined with vulnerability management and application security visibility
Service model24/7 detection and response through the Rapid7 Managed Threat Complete service. Combines MDR with exposure management and application security monitoring in a unified SecOps platform.
CoverageEndpoint, cloud, infrastructure, and network. Integration with Rapid7's InsightIDR SIEM and InsightVM vulnerability management.
RecognitionGartner Peer Insights rating of 4.6/5. Included in Gartner Magic Quadrant for MDR services.
StrengthThe integration of MDR with vulnerability and exposure management means that security gaps identified during monitoring can be proactively addressed, rather than waiting for the next scheduled assessment. Useful for organisations that want their detection partner to also help reduce their attack surface.
ConsiderationFull value requires using Rapid7's platform products alongside the MDR service. Organisations with deeply established SIEM or vulnerability management tools from other vendors should evaluate integration depth and potential duplication before committing.
Secureworks Taegis MDR
MDR / Threat Intelligence-Led
Best suited forMid-market to enterprise, particularly regulated industries where threat intelligence and detection engineering are strategic priorities
Service modelMDR delivered through the Taegis XDR platform with 24/7 analyst coverage. Combines proprietary threat intelligence from Secureworks Counter Threat Unit with platform detection and response.
CoverageEndpoint, network, cloud, and identity across the Taegis platform. Multi-vendor telemetry ingestion supported.
RecognitionSecureworks Counter Threat Unit is a well-established threat intelligence and incident-response organisation with documented research on ransomware groups and attack patterns.
StrengthDeep threat intelligence integration from the Counter Threat Unit means detections are informed by active threat actor research. The intelligence-to-detection pipeline is a differentiator for organisations facing sophisticated or targeted threats.
ConsiderationTaegis MDR pricing is higher than some mid-market alternatives. Verify that the threat intelligence depth provides proportionate value for your organisation's threat profile relative to more cost-competitive options in the same category.
Huntress
Managed EDR / SMB and MSP Focused
Best suited forSMB and lower mid-market organisations, particularly those working through MSPs (managed service providers) who want endpoint protection plus managed response at an accessible price point
Service model24/7 managed endpoint detection and response with active, pre-authorised response actions. Also covers Microsoft 365 identity threats (compromised accounts, suspicious sign-ins, inbox rule manipulation).
CoverageWindows/Mac endpoints and Microsoft 365 identity. More focused coverage than broader XDR platforms.
PricingPublished rate of $8.99/endpoint/month makes it one of the most transparent and accessible MDR options for smaller organisations.
StrengthPurpose-built for the SMB and lower mid-market segment, with pricing and deployment model designed for organisations that work with MSPs. The Microsoft 365 identity coverage addresses a common attack vector (compromised accounts, business email compromise) at the same price tier as endpoint protection.
ConsiderationCoverage scope is narrower than enterprise MDR platforms. Cloud workload and network visibility require other tools. Best suited for organisations where endpoint and Microsoft 365 are the primary threat surfaces, with complementary tools covering other environments.
Expel
MDR / Bring-Your-Own-Stack
Best suited forSecurity-mature mid-market and enterprise organisations with established security tooling who want expert MDR on top of their existing stack rather than a replacement platform
Service modelBYOT (bring-your-own-technology) MDR. Expel ingests telemetry from existing security tools rather than requiring a specific platform. 24/7 monitoring with automated and analyst-led response, including auto-remediation for certain threat patterns.
CoverageVendor-agnostic across 300+ security tool integrations. Endpoint, cloud, network, identity, and SaaS.
Recognition4.6/5 across 145 Gartner ratings. Strong transparency in reporting and detection methodology.
StrengthThe BYOT model is the clearest differentiator: organisations keep their existing security tooling and Expel adds detection and response capability on top. This avoids vendor consolidation costs and is particularly suitable for organisations with established security investments they don't want to replace.
ConsiderationDetection quality depends partly on the quality of telemetry from existing security tools. Organisations with immature or limited existing tooling may find more value in a platform-inclusive MDR service that also upgrades their detection capabilities.
Red Canary
MDR / Detection Engineering Focus
Best suited forTechnology-forward mid-market and enterprise organisations with internal security teams that want to improve detection quality and extend coverage without replacing internal analysts
Service modelEDR-agnostic MDR focused on high-fidelity detection. Red Canary ingests from multiple EDR and SIEM sources, applies detection engineering, and delivers confirmed threats rather than raw alerts. Active response options available.
CoverageEndpoint (EDR-agnostic, 300+ data sources), identity, cloud, and network.
NoteRed Canary publishes an annual Threat Detection Report (most recent: 2025 edition) documenting the top threat techniques observed across its customer base, which serves as a useful indicator of detection methodology and research quality.
StrengthFocus on detection engineering and threat intelligence means Red Canary consistently publishes research on attack techniques and detection logic. For security teams that value transparency into how detections are built and tested, this is a meaningful differentiator over services that treat detection logic as a black box.
ConsiderationBest fit when the customer has internal security analysts who will engage with the detection intelligence Red Canary produces. Organisations without internal security expertise may derive more operational value from a more hands-on managed service model.
eSentire Managed Detection and Response
MDR / Zero-Trust Response Model
Best suited forMid-market to enterprise, particularly organisations in regulated industries (financial services, healthcare, legal) where compliance context shapes security requirements
Service model24/7 MDR with an emphasis on mean time to contain as a service commitment. eSentire MDR combines automated threat response with Atlas XDR platform and Security Operations Centre analyst teams with average response under 15 minutes to confirmed threats per company documentation.
CoverageEndpoint, network, cloud, identity, and application layers. Multi-vendor telemetry supported.
FocusParticularly recognised in regulated industry deployments and for organisations needing evidence of security control effectiveness for audits and compliance frameworks.
StrengthCompliance context integration means eSentire MDR can help organisations demonstrate control effectiveness to auditors, not just respond to threats. For regulated industries where security monitoring directly supports compliance evidence, this alignment can reduce duplication of effort.
ConsiderationVerify current pricing structure and contract terms for your specific organisation size. eSentire pricing has historically been at the higher end for mid-market organisations. Compare the compliance-specific value against alternatives at lower price points for your sector.

How to choose a managed cybersecurity provider

  • Is monitoring genuinely 24/7 with human analysts, or is it alert-forwarding during business hours?
  • When a confirmed threat is identified at 3 AM, what response actions can the provider take without waiting for your approval?
  • Is incident response included in the base contract, or is it a separate retainer with additional cost?
  • Which endpoint, cloud, identity, and network platforms does the provider natively support, and how well does it integrate with your existing stack?
  • What is the mean time to respond to a confirmed threat, and is this a contractual SLA or a marketing figure?
  • Does the provider support your compliance requirements (SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR) and can they provide evidence of monitoring for audit purposes?
  • If ransomware is detected mid-deployment, what is the specific response sequence, which actions does the provider take, which require your authorisation?
  • Are there per-endpoint or per-GB ingestion charges beyond the base price that could make the service significantly more expensive at scale?
  • Can the provider demonstrate references from organisations of similar size and sector?
  • What does the onboarding and coverage tuning process look like, and how long until the service is operating with full context of your environment?

What CEOs, CFOs, and COOs should know

Ransomware is an operational continuity risk, not an IT problem. The following points are what every non-technical executive needs to understand before an incident occurs.

Recovery can take far longer than expected. 18% of affected organisations in the Sophos 2025 survey took more than a month to fully recover. If your ERP has been encrypted and your backup is 11 days old, the operational impact is measured in weeks of disrupted operations, not hours.
Business interruption typically costs more than the ransom itself. The mean global recovery cost of $1.53 million (Sophos 2025, excluding ransom) reflects downtime, people time, device and network costs, and lost opportunity. The ransom is one line item in a much larger bill.
Backups need to be tested regularly. Having backup infrastructure is not the same as having recoverable data. If backups have never been tested against a realistic recovery scenario, the incident will be the test.
Ransomware incidents trigger legal and regulatory consequences. If personal data has been accessed or stolen, there are notification obligations. Those obligations have timelines. Legal counsel should be part of the initial incident response team, not a week-two afterthought.
Cybersecurity decisions affect insurance premiums and coverage. Cyber insurers are reviewing security controls at renewal. MFA, EDR, and backup controls are increasingly prerequisites for coverage, not differentiators. An incident may affect your ability to renew at the same terms.
Incident response should be planned before the incident. The organisations that recover best from ransomware are the ones that had an incident-response plan, tested it, and knew who was responsible for which decisions before the attack happened. CISA's Ransomware Guide is freely available and provides a practical starting framework.

The companies that recover fastest from ransomware are not necessarily the ones that spent the most on security. They are the ones that prepared for failure before it happened: tested backups, MFA enforced, an incident-response plan that was actually used in a tabletop exercise, and an external response relationship already established before it was urgently needed.

For verified managed cybersecurity agencies and IT security providers across the categories covered in this article, TechRadiant's verified IT managed services index covers providers evaluated on documented delivery outcomes. For the broader IT resilience picture that ransomware connects to, see TechRadiant's guide to business continuity planning and IT resilience audits in 2026.