Glossary / Ransomware
Ransomware
Malware that encrypts an organization's data and demands payment for its release — increasingly paired with data theft and a public-leak threat ("double extortion") that applies pressure even if backups make the encryption itself recoverable.
Classic ransomware encrypts files and displays a ransom note demanding cryptocurrency payment for the decryption key. "Double extortion" added a second lever: attackers exfiltrate sensitive data before encrypting anything, then threaten to publish it regardless of whether the victim restores from backup — which is why "we have good backups" stopped being a complete answer to ransomware risk on its own.
Common initial-access vectors are well documented and unglamorous: phishing emails, unpatched vulnerabilities, exposed remote-access services like RDP, and reused or stolen credentials. Patch management and MFA are consistently the two most-cited preventive controls because they directly close the most common entry points, not because they're novel.
MSPs are targeted both directly and through their clients, and for a specific structural reason: an MSP with broad remote access into many client environments is a single point of compromise that can unlock many doors at once. Supply-chain ransomware attacks that use a compromised MSP tool as the entry point into every one of its clients are a well-documented pattern, which is why the security of the management tool itself matters as much as the security it's meant to deliver.
How Nexus handles this
Nexus's own remote-management channel is built against exactly that MSP-as-single-point-of-compromise pattern — outbound-only, Ed25519-signed jobs, and a default-deny capability registry rather than broad standing access. Its M365 backup writes to a bucket the customer owns with every object hash-verified, so a ransomware event against production doesn't also mean the backup was silently corrupted.
More terms
MSP (Managed Service Provider)
A company that remotely manages a client's IT infrastructure and end-user systems on an ongoing, proactive basis — usually a flat-fee contract, not break-fix billing.
RMM (Remote Monitoring and Management)
Software that lets an MSP monitor device health and perform remote management tasks — patching, scripting, remote control — across every client site from one console.
PSA (Professional Services Automation)
Software that runs the business side of MSP operations — ticketing, SLAs, billing, contracts, and client records — the system of record most MSP work flows through.
Ready to see it in the platform?
Join the design-partner cohort and we'll show you exactly where this lives.