Managed Service Providers, or MSPs, are increasingly setting aside dedicated funds for ransomware payments, with a recent report from CyberSmart revealing that 45 percent of MSPs have created a specific budget for this purpose. This practice continues despite growing pressure from insurers and government entities to refrain from paying ransoms, which can inadvertently support criminal activities. The report from CyberSmart indicates that 36 percent of MSPs choose to protect themselves with cyber insurance instead. Alarmingly, 11 percent of MSPs do not have any budget allocated for ransomware payments or insurance, leaving them vulnerable in case of an attack. Additionally, MSP leaders cite artificial intelligence as their top concern, surpassing ransomware and malware threats, highlighting the evolving landscape of cybersecurity challenges they face.
A recent study by AppOmni reveals that while the majority of organizations believe they have a strong security posture for their Software as a Service applications, a significant number have experienced breaches or security incidents in the past year. The survey found that 75% of organizations reported falling victim to a SaaS data breach, yet 89% felt they had appropriate visibility of their environments. The study highlights a troubling disconnect between perceived security and actual risks, with 57% of respondents citing data breaches as their primary concern. Notably, 41% of incidents stemmed from permission issues and 29% from misconfigurations, indicating a pressing need for improved security hygiene.
Why do we care?
Almost half of MSPs say they’ve got a ransomware payment fund. Really? That number feels padded. My bet—it’s less “dedicated reserve” and more “we’ll figure it out when we’re hit.”
Here’s the problem: budgeting for ransom normalizes paying criminals. That’s not strategy—it’s surrender.
Meanwhile, 75% of SaaS users suffered breaches last year, but nearly 90% think their security posture is solid. That’s delusion. Misconfigs and permission mess-ups are killing them.
For MSPs, this is your lane: stop focusing on paying ransoms and start fixing basic hygiene issues in SaaS environments. That’s where you prove value—and keep clients off the breach statistics. You should be preparing to tell criminals to bug off, not be paid off.

