Ninety minutes. That is how long it took a threat actor inside Progressive Computing's RMM tool to encrypt all 2,500 endpoints the MSP managed, and Robert Cioffi found out when his director of operations told him every single client was ransomware. In this episode of How to MSP, Andrew Moore talks with Robert Cioffi, CTO and Co-Founder at Progressive Computing, about being one of the managed service providers caught in the July 2, 2021 Kaseya VSA supply chain attack. Robert walks through the hallway conversation, the moment he froze, and the forensic timeline that showed the threat actor in at 10:49 a.m. and every endpoint encrypted by roughly 12:30 p.m. The recovery took 27 companies, most of them competitors, working 18 hour days for 17 calendar days. His conclusion is that community is the layer of the security stack you cannot buy. What you'll learn: • How a zero day in an RMM platform encrypts 2,500 endpoints across 80 clients and four time zones in 90 minutes • What an MSP owner actually does in the first hour when there is no runbook and the fixer in you goes blank • Why recovery at that scale is a capacity problem, not a technical one, and who you restore first • What a real cyber liability policy gets you, starting with breach counsel • How MSP911 and CyberRISE give an MSP in the middle of an event someone to call Mentioned in this episode: • How to Win Friends and Influence People by Dale Carnegie, Goodreads • The Go-Giver by Bob Burg and John David Mann, Goodreads • Pink Floyd on Spotify, open.spotify.com/artist/0k17h0D3J5VfsdmQ1iZtE9 • Progressive Computing, progressivecomputing.com • CyberRISE, cyberrise.org • MSP911, msp911.org • Huntress, huntress.com • Axcient, axcient.com • Kaseya, kaseya.com • ConnectWise, connectwise.com • IT Nation Evolve, itnation.connectwise.com/evolve • Pax8, pax8.com • CISA alert on the Kaseya VSA supply-chain ransomware attack, cisa.gov • U.S. Department of Justice on the sentencing of the REvil affiliate, justice.gov About the guest: Robert Cioffi is CTO and co-founder of Progressive Computing, the Yonkers, New York MSP he started in 1993 and has since rebuilt to more than double its pre attack size. He facilitates two IT Nation Evolve peer groups and is a founding board member of CyberRISE, the nonprofit behind MSP911. Read the full show notes: https://www.ridgeviewadvisors.com/blog/every-client-encrypted-in-90-minutes-how-this-msp-survived Key topics: MSP ransomware attack, Kaseya VSA supply chain attack, REvil Sodinokibi, MSP incident response, MSP cyber liability insurance, MSP disaster recovery, RMM security, MSP peer groups, MSP911, MSP business continuity About How to MSP How to MSP is the weekly podcast for Managed Service Provider owners and operators who want to grow, scale, and exit on their terms. Host Andrew Moore — Founder of Ridgeview Advisors — interviews MSP operators, advisors, and investors on the topics that actually move the business: EOS implementation, valuation and exit strategy, sales and marketing, service delivery, M&A, financial benchmarks, and operational excellence. Watch full episodes on the How to MSP YouTube channel. How to MSP is produced by Ridgeview Advisors and hosted by Andrew Moore.