Your IT provider says your firm is protected from ransomware. But what does that actually mean? For a financial firm, “we have EDR” or “your backups are running” isn’t enough. You need to know what your managed services provider (MSP) is actually doing to reduce your risk and whether it is prepared to respond when something goes wrong. In Omega Systems’ 2025 research, 23% of financial services leaders said ransomware was the attack type they felt least prepared to recover from.
Here’s what to ask your MSP – and what good answers should look like.
Is my IT provider monitoring for ransomware 24×7?
Ransomware does not wait for business hours, and neither should your security monitoring. Ask whether your IT provider has people watching your environment 24×7 and what happens when they see something suspicious. A security tool can generate an alert at 2 a.m., but someone still needs to investigate it and decide whether it requires action.
This is a real gap for many financial firms. Omega’s research found that 57% of financial firms are not monitoring threats in real time.
For a small registered investment adviser (RIA) or wealth management firm without an internal security team, that gap can be especially significant. If an attacker gets in overnight, who notices?
Does my MSP protect endpoints, identities, and the network?
A compromised Microsoft 365 account, an unpatched laptop, or an overly permissive connection can give an attacker a way into the environment – and once they have a foothold, they may look for ways to reach more valuable systems. Your MSP should know where those paths exist in your environment and have controls in place to limit them.
Ask about:
- Endpoint detection and response (EDR)
- SASE, MFA, and identity controls
- Email and phishing protection
- Vulnerability management and patching
- Network security and segmentation
- Threat detection and response
Consider a wealth management employee who enters their Microsoft 365 credentials into a convincing phishing page. If that account has access to more than it needs, the attacker may be able to use it to access email, impersonate the employee, or reach other systems.
A compromised account or device shouldn’t be enough to open the door to the rest of your environment. That’s why your security controls need to work together.
Can my IT provider detect an attack before ransomware is deployed?
Your provider should be looking for signs that something is wrong before files start getting encrypted: unusual logins, compromised credentials, suspicious processes, privilege escalation, lateral movement, and other indicators of compromise.
Omega’s research found that 35% of financial firms said it would take a week or longer to detect and contain a breach, while 6% said it could take a month or longer. For a private equity firm, hedge fund, or asset management firm, that could give an attacker a lot of time to move through systems containing sensitive financial or deal information.
Ask your MSP: “What would tell you that someone is already inside our environment?” You should get a specific answer.
Has my IT provider tested our backups and recovery plan?
Backups only help if they can actually be restored. Your IT provider should test backups regularly, protect them from being compromised alongside production systems, and know how your firm would restore critical systems after an attack.
Ask:
- How often are backups tested?
- Are backups isolated from production?
- How quickly can critical systems be restored?
- When was the last recovery test?
- What happens if ransomware reaches the backup environment?
This is particularly important for firms with lean internal teams. A family office, for example, may rely heavily on its IT provider to manage recovery because there is no large internal infrastructure team to take over during an incident.
If the answer to “Can we recover?” depends on finding out during the attack, you are not prepared.
Does my IT provider have a ransomware response plan?
When ransomware hits, there is no time to figure out who does what. Your managed IT services provider should have a documented incident response process that defines who investigates the threat, who contains affected systems, who communicates with leadership, and how recovery begins.
Ask your provider to walk you through the first few hours of a hypothetical ransomware incident. Who gets called? What happens first? How are affected systems isolated? Who makes the recovery decision? If you want a better picture of what that response actually looks like, see our guide to the first 72 hours of a breach.
The goal is not to have a plan that looks good in a document. Everyone involved should know what to do when the plan has to be used.
How can I tell if my IT provider is keeping up with our security risks?
Your firm’s security needs change as your technology changes. New cloud applications, remote access, employees, vendors, and legacy systems can all create new attack paths. Your provider should regularly assess vulnerabilities and tell you what needs attention – not simply wait for something to break.
This matters for firms of every size. A growing RIA may add employees and applications faster than its security controls are updated. A private equity firm may need to manage access across portfolio companies and third parties. A wealth management firm may have employees working remotely across multiple locations. Your MSP should know what has changed in your environment and whether those changes create new risks.
What should I ask my IT provider about ransomware protection?
Start with these questions:
- Who is monitoring our environment outside business hours?
- How quickly will we know if ransomware activity is detected?
- How are endpoints, identities, email, and networks protected?
- When was our last backup recovery test?
- When was our last ransomware or incident response exercise?
- What happens during the first two hours of an attack?
- What security gaps have you identified in our environment?
- Which gaps are still open, and what is being done about them?
The answers will tell you much more than the list of products included in your IT contract.
Ransomware Protection Requires More Than an IT Contract
Your managed IT provider should be able to tell you what it’s watching, what happens when it finds something suspicious, and how your firm would recover if ransomware does get through. For financial firms, the stakes are high – 88% of executives believe a successful cyberattack could trigger investor withdrawals, raise investor concern, or result in lost AUM. If those answers are vague, it’s worth taking a closer look at what you’re actually getting from your IT partner.
At Omega Systems, we bring IT and cybersecurity together to help financial services organizations close critical gaps, harden their defenses, and prepare to respond when an attack occurs.


