Recommendations for our side?

As an MSP, we have a broad range of clients. Some have had data breaches, while the rest actually listen to us, there have been no problems with them.

Now, we have a customer, who literally had a ransomware attack. Didn’t spread via their M365 thankfully, because we have full control on that and the customer doesn’t retain a GA account. Unfortunately, a few months later, they are adding services left and right and want GA rights back. I’m inclined to give them back, but want them to sign a liability waiver. Would this be the best course of action?

The customer is always right :slight_smile:

Just make sure you have a reliable tested immutable backup solution in place, then give them a formal quote for future implementation of the restore if ever needed with highly emphasised downturn period

Make it expensive, they will either back down from ga rights, and if they don’t… it will be a highly profitable potential month for you!!!

Negative. They declined backups.

**They also didn’t have the best backups for their files either, as it took them about a month to restore to a semblance of something working.

Sometimes you have to let the client go

Having a robust backups is one of top lists of services that the client needs to agree to.

I have had to fire clients before. The money is not worth the aggravation and the liability sometimes. If they don’t follow your recommendations what is the point?

Wow, that kind of stress (and health consequences) is not worth any monies

1 Like

Literally fire them.

I’ve been in that situation. Signing a waiver is a good stop-gap, but quite honestly it’s worked better for me at the MSA/SOW level. In assuming the customer has rights to the tenant, a 3rd party can recommend sequestering of privileged access, but getting them to agree at the MSA/SOW layer may take away some of the friction of an ad hoc liability release. You can even reference it in the documentation / email providing confirmation.