The best response to a nightmare client call starts before the phone rings. Each customer should have a current business-impact profile, incident contact tree, decision authority, escalation route, trusted backup communication channel, and agreed update process. The ten scenarios below are practical exercises, not a ranking of how often incidents occur. For each, gather verified facts, identify who owns the next decision, and follow the customer’s incident plan and authorized responders.
Prepare the response before an incident
Keep a customer-specific response sheet accessible to the people who may take the call. It should identify:
- Critical business processes and systems, plus the operational impact if each is unavailable.
- Primary and alternate customer contacts, incident decision-makers, and after-hours escalation details.
- Which MSP team handles intake, technical investigation, containment coordination, recovery, and customer updates.
- A trusted out-of-band channel to use if email, identity systems, or managed tools may be affected.
- Who can authorize disruptive actions, such as isolating systems or choosing a recovery point.
- How often updates are due, who approves external statements, and where incident records are maintained.
CISA advises organizations to prioritize incidents by mission impact and maintain an incident response capability. Its incident response plan guidance and Cybersecurity Performance Goals support planning roles, escalation, and response processes. Adapt those arrangements to each customer’s environment and contract rather than assuming the MSP has authority over every system or decision.
1. “We think we have ransomware.”
Ask and establish
- Which people, devices, sites, and business services are affected?
- What has stopped working, and what business operations are currently disrupted?
- What is directly observed—such as an on-screen note or encrypted files—and what is still suspicion?
- When was the activity first noticed, and what actions have already been taken?
- Who is the customer incident lead, and which internal or external responders must be engaged?
Next action
Escalate through the agreed incident route, preserve a factual timeline, and coordinate any containment with the authorized incident lead. CISA’s StopRansomware Guide recommends coordinated isolation and out-of-band communications, such as phone calls, during ransomware response. That is not a blanket instruction to disconnect every system: the right action depends on the incident, business impact, and response authority.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
- 7 Rings Checkbook Portfolio with Retractable Handle
- ENOUGH ROOM FOR ALL YOUR ESSENTIALS! –Size 14.5"L x 12.5"W x 3"H With a wide spine, tons of pockets, a separate document folder w/strap, and a 3-ring binder, this portfolio has enough room to throw in just about anything you need!
- 7 Ring Check Holder for Standard Business check Book, TRANSLUCENT ID HOLDER – Personalize Your Padfolio With Your Own Business Card.
- High Quality Heavy Duty Vegn Leather Brief Case with -Smooth Zippered Closure with Stylish and simplistic cover perfect for any business professional
- Including a paper notepad and Black Gift Box
2. “Everything is down.”
Ask and establish
- What is unavailable: one application, a site, network access, identity services, or the whole environment?
- Which locations, users, and business processes are affected, and when did the disruption begin?
- Are there signs of malicious activity, or is an operational failure more likely based on known facts?
- What workarounds are available, and who owns decisions and status updates?
Next action
Triage scope and business impact before treating the outage as a single technical fault. Assign an incident coordinator, an investigation owner, and a customer-update owner; escalate security indicators through the incident plan. CISA’s tabletop exercise packages help organizations practice prioritization and response roles.
3. “Your remote tool or MSP account may be compromised.”
Ask and establish
- Which account, remote-access tool, or management system is in question?
- What evidence prompted the concern, when was it discovered, and what activity is confirmed?
- Which customer environments or accounts could be reached through the affected access?
- Can responders still use a trusted channel and a clean administrative path?
Next action
Use the MSP’s escalation process and assess potential customer impact under the shared incident plan. Do not assume the issue is limited to the provider: compromise of an MSP can create downstream risk for multiple customers. CISA’s joint advisory on securing MSPs recommends limiting third-party access to the responsibilities assigned to it. Review which access may need to be restricted or investigated with the incident lead, and coordinate customer notifications through the agreed process.
Rank #2
- 7-ring black binder Breiefcase Portfilio 7 Rings Checkbook Portfolio with Retractable HandleDesign for 3-To-A-Page checks with Side Stub
- Design for 3-To-A-Page checks with Side Stub - Hold Three- Size 12-1/2" x 3" Check Per Page
- ENOUGH ROOM FOR ALL YOUR ESSENTIALS and Capacity To hold hundreds of checks ! –Size 14.5"L x 12.5"W x 3"H With a wide spine, Zipper pockets and Smart Phone Holder.
- Reinforced Retractable Handle for easy transportation and durable for everyday use
- High Quality Heavy Duty Vegn Leather Brief Case with Black Gift Box, perfect for any business professional
4. “The backups are missing, damaged, or won’t restore.”
Ask and establish
- Which systems and data need recovery, and what is the most recent recovery point known to be usable?
- When was the last successful backup or restore test, and what evidence is available?
- Who operates the backups, who can authorize a recovery choice, and which dependencies must come back first?
- Is there a suspected security incident that could affect backup integrity or access?
Next action
Confirm backup ownership and recovery decision rights, then follow the customer’s recovery plan. If the MSP or another third party maintains backups, CISA’s ransomware guidance recommends verifying backup practices and formalizing security requirements. Do not promise a recovery time or claim a recovery point is usable until the customer’s environment and available evidence support it.
5. “Someone sent money or credentials after a suspicious email.”
Ask and establish
- Was money sent, credentials entered, or sensitive information shared? When, and through which account or payment method?
- What message or request prompted the action, and is the email or account still accessible?
- Who is responsible for financial, identity, security, and business decisions at the customer?
- Has anyone already contacted a bank, payment provider, or other relevant party under the customer’s procedures?
Next action
Escalate promptly as a potential business email compromise or credential-theft incident. Preserve the known facts and route financial or identity actions to the customer’s designated decision-makers and appropriate specialists; do not make payment or account decisions on the customer’s behalf without authorization. CISA’s MSP security advisory identifies business email compromise among the attack methods organizations should account for in response planning.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Rank #3
6. “A user clicked a link and now accounts are acting strangely.”
Ask and establish
- Who clicked, which device and account were involved, and when did it happen?
- What unusual behavior is visible—unexpected sign-ins, messages, prompts, or account changes?
- Did the user enter credentials, approve a prompt, or download or run anything?
- Could normal email or managed systems be untrusted for coordination?
Next action
Record observations without asking the user to investigate further, and route the report through the customer’s incident process. If ordinary accounts or email may be affected, switch coordination to the trusted out-of-band channel. CISA’s tabletop materials include phishing scenarios, and its ransomware guidance describes using alternate communications when normal channels may be compromised.
7. “Client or employee data may have been exposed.”
Ask and establish
- What data may be involved, where was it stored, and what evidence indicates exposure?
- What people, systems, or organizations may be affected, and what is confirmed versus still under investigation?
- Who at the customer owns incident decisions, privacy, legal review, and communications?
- What facts, timestamps, and actions can be preserved accurately?
Next action
Activate the agreed incident and communications plan, promptly involve the customer’s designated decision-makers, and preserve an accurate record of known facts. Bring in appropriate legal and privacy specialists through the customer’s process. Notification duties and deadlines depend on jurisdiction and circumstances, so do not state a universal legal deadline or make external disclosures without the responsible parties’ approval. CISA’s ransomware guidance addresses stakeholder coordination and notification planning.
8. “Our critical business application has stopped.”
Ask and establish
- Which business process depends on the application, and what is the operational consequence of the outage?
- Who and what locations are affected, and what changed before the service stopped?
- Are dependencies such as identity, network, hosting, or a third-party service also unavailable?
- What workarounds exist, and who can approve recovery or service-restoration choices?
Next action
Prioritize by business impact, map dependencies, and escalate to the application and infrastructure owners named in the customer’s plan. Keep a single owner for customer updates and a record of decisions. CISA’s incident response and tabletop guidance supports mission-impact prioritization; the actual dependency map and escalation contacts must be customer-specific.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.9. “Should we shut this system off right now?”
Ask and establish
- What is happening on the system, and what evidence suggests an immediate threat?
- What business service depends on it, and what could be disrupted by shutting it down?
- Who is calling, what authority do they have, and who is the designated containment decision-maker?
- Can the response lead be reached through a trusted channel before a disruptive action is taken?
Next action
Connect the caller with the response lead and follow the customer’s decision rights and incident procedures. Isolation may be appropriate in a ransomware event, but CISA recommends coordinated action; a caller’s urgency alone does not establish who can authorize it. Rehearse this decision path in advance so the live call is not the first time roles are tested.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
10. “The CEO wants an answer now, and customers are asking questions.”
Ask and establish
- What facts have been verified, and what remains unknown?
- Who is authorized to brief executives, employees, customers, regulators, or the public?
- Which communication channel is trusted, and when is the next update due?
- What response actions or decisions are pending, and who owns them?
Next action
Give a concise status based on verified facts, label open questions clearly, and set the next update time in line with the agreed plan. Route external statements through the customer’s responsible communications personnel; do not speculate about cause, scope, or recovery time. CISA’s ransomware guidance recommends regular stakeholder updates and planned communications. Australia’s Cyber.gov.au guidance for managed service providers also addresses communicating under pressure.
Turn the calls into a rehearsal
Run short tabletop exercises with the customer’s decision-makers and the MSP staff who would take the call. CISA offers tabletop exercise packages, including scenarios involving ransomware, insider threats, and phishing. Use a scenario to test whether people can find the right contact, establish what is known, move to a trusted channel, identify the decision-maker, and deliver the next update. Record gaps in the plan and assign owners to close them.
Also review third-party access boundaries, backup responsibilities, and shared response roles. CISA Director Jen Easterly said in the May 11, 2022 announcement of the joint MSP advisory: “Securing MSPs are critical to our collective cyber defense, and our interagency and international partners are committed to hardening their security and improving the resilience of our global supply chain.” That shared-risk perspective is why MSP and customer response arrangements need to be explicit and practiced.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minute

