Case Study: How One Marketing Agency Turned a Cyber Crisis into a Recovery Success

Tags: cio services, cybersecurity, it strategy, managed services

KEY TAKEAWAYS

  • A cybersecurity incident at an Ontario marketing agency exposed a weaker IT foundation than leadership believed it had.
  • The fix was a transition, not a cleanup: assess, rebuild on Microsoft 365, then govern the environment through scheduled reviews.
  • The signal to watch for is not a breach. It is a provider who cannot show you a recent restore test.

Mike Pearlstein is CEO of Fusion Computing and holds the CISSP, the gold standard in cybersecurity certification. He has led Fusion’s managed IT and cybersecurity practice since 2012, serving Canadian businesses across Toronto, Hamilton, and Metro Vancouver.

Cyber crisis recovery is the work of restoring operations after a security incident and then closing the gaps the incident exposed. For this agency the second half mattered more. The incident was contained. What it revealed was an environment nobody could document, a backup nobody had tested, and a technology plan that had never been written down.

Introduction

An Ontario marketing agency lost several days of normal operation to a cybersecurity incident. According to the assessment that followed, the deeper problem was the environment itself: undocumented, fragile, and never tested for recovery. This is the story of the transition that came after. Source: Fusion Computing client engagement record, 2026.

The agency had long-standing client relationships and a small internal team. Fusion Computing was brought in after the incident to answer 3 questions: what failed, what could be recovered, and whether the environment could be trusted going forward.

This case study is based on a real Fusion Computing engagement. Client details have been anonymized, and certain technical details have been generalized for privacy.

The Challenge: A Fragile Environment and Too Much Assumption

According to Statistics Canada, about 1 in 6 Canadian businesses (16%) were impacted by cyber security incidents in 2023, and large businesses remained the most likely to be hit at 30%. Small firms sat lowest at 14%, which is exactly why so many of them assume the problem belongs to somebody else.

Dusty Ontario marketing-agency server rack with the door half open, exposed cabling and an asset list taped to the frame
A dusty rack with exposed cables is what a fragile environment actually looks like before a breach.

After the incident the agency needed clarity more than cleanup. Fusion Computing was engaged to assess the situation, and the review surfaced five issues that raised operational risk:

  • Backup and recovery readiness fell short. The agency did not have the verified, testable recovery capability leadership assumed was in place.
  • No practical disaster recovery roadmap existed. Recovery steps were not documented in a way that supported a fast, structured response.
  • The virtual server environment had grown fragile. Complexity had accumulated, which made maintenance, troubleshooting, and recovery harder than they needed to be.
  • Documentation and governance were thin. Nobody could see how systems were configured, who had access to what, or how resilience would be maintained.
  • Technology planning had gone reactive. The environment had evolved through incremental fixes rather than a roadmap tied to business goals.

What is an MSP transition, explained in plain terms

An MSP transition is the controlled handover of an IT environment from one provider to another. Done properly it runs in 4 steps: discovery and documentation, administrative access moved under new control, backups validated, and only then a change to the architecture, whether that lands on Microsoft 365 or stays on-premise.

The distinction matters most right after an incident, when everyone wants visible progress. In our experience the first two weeks should look boring: inventories, access reviews, restore tests. That is the work that makes the next six months uneventful.

Warning Signs Your MSP May Be Underperforming

According to the Canadian Centre for Cyber Security, its Baseline Cyber Security Controls v1.2 apply an 80/20 rule for small and medium organizations, mapping to ITSG-33 Annex 4A Profile 1. If your provider cannot walk you through those baseline items in plain language, that is your first warning sign.

Wall of yellow sticky notes in an Ontario agency boardroom, each hand-labelled with an MSP warning sign
A wall of sticky notes is what a real MSP warning-sign register looks like before an incident.
Six Warning Signs Your MSP Is Underperforming. Six warning signs any Canadian SMB can audit in its current MSP relationship. One, the SLA is never reported or measured. Two, tickets sit unanswered without acknowledgement. Three, there is no documented incident response plan, no named roles and no tested runbook. Four, there is no scheduled business review, so the relationship stays reactive. Five, security tooling has not been refreshed in years. Six, the backup has never been test-restored, and existence is not proof of recoverability. Six Warning Signs Your MSP Is Underperforming. Three or more, and it is time to evaluate alternatives. 1 SLA never reported or measured. Ask for last quarter's SLA report. 2 Tickets sit without acknowledgement. Priority drift, broken queue management. 3 No documented incident response plan. No named roles, no tested runbook, no tabletop. 4 No scheduled business review. Purely reactive, no roadmap, no lifecycle plan. 5 Security tooling years out of date. Signature antivirus only, no managed detection. 6 Backup never test-restored.

The agency’s situation was not unusual. Our engineers found the same five patterns whenever they review an environment that has been managed without much rigour:

  • No recent verified restore test. A backup dashboard is not proof that recovery works.
  • Weak or outdated documentation. No current network diagram, asset inventory, permissions record, or vendor map means your provider is working blind too.
  • No regular business reviews. Managed IT should include scheduled conversations about lifecycle planning, budget, risk, and upcoming change.
  • Recurring issues that never go away. Repeated email, performance, or permissions problems usually signal weak root-cause ownership.
  • No clear answer on security basics. If nobody can explain MFA status, endpoint coverage, backup scope, and admin access in plain language, that is the answer.

Book a Consultation

Fusion Computing’s Approach

Rather than preserve a design leadership no longer trusted, Fusion Computing proposed a structured rebuild around resilience, simplicity, security, and operational clarity. It ran in 3 phases: assess and stabilize, modernize onto Microsoft 365, then govern the result through scheduled strategy sessions rather than ad hoc calls.

Printed recovery runbook open in a binder on an Ontario agency conference table with tabs labelled assess, rebuild and govern
A binder of runbook tabs is what real post-incident work looks like.
Three Phases, Assess, Rebuild, Govern. The three phases Fusion Computing ran for the marketing agency. Phase one, assessment and stabilization. A full cybersecurity assessment and environment review mapped systems, user access, dependencies and operational gaps, and immediate work focused on reducing business risk. Phase two, modernization and rebuild. The legacy virtual server design was retired, collaboration workloads moved to Microsoft 365, security controls were strengthened, and documentation was written. Phase three, governance and strategic oversight. Ongoing virtual CIO sessions were established to guide decisions on risk, lifecycle planning, vendor accountability and growth. Three Phases. Assess, Rebuild, Govern. No migrations until the environment was documented. Phase 1. Assess and stabilize. Cybersecurity assessment. Systems and access mapped. Dependencies documented. Immediate risk reduced. Goal. Leadership can see the current state. Phase 2. Modernize and rebuild. Legacy server design retired. Microsoft 365 collaboration. MFA, endpoint, email security. Backups built to be validated. Goal. A simpler estate that can be supported. Phase 3. Govern. Scheduled vCIO sessions. Risk and lifecycle planning. Vendor accountability. Budget tied to a roadmap. Goal. A better operating model, not just uptime.

Phase 1: Assessment and Stabilization

The first step was a full cybersecurity assessment and environment review. Fusion mapped systems, user access, dependencies, and operational gaps so leadership could see the current state clearly. Stabilization work then focused on reducing business risk while the long-term plan was written.

Phase 2: Modernization and Rebuild

With the environment assessed, Fusion designed a cleaner, more supportable foundation:

  • Retire the legacy virtual server design in favour of a simpler, more resilient operating model.
  • Migrate core collaboration workloads to Microsoft 365 to improve access and continuity while reducing dependency on aging infrastructure.
  • Strengthen security controls, including MFA, endpoint protection, email security, and a backup strategy built around validation and recoverability.
  • Write the documentation, so leadership could see assets, access, dependencies, and operating standards.

Phase 3: Governance and Strategic Oversight

Fusion did not treat the rebuild as the end of the engagement. Ongoing vCIO strategy sessions now help leadership make deliberate decisions about risk, lifecycle planning, vendor accountability, and growth. The goal was a better operating model, and the stable environment is what that produced.

“One of our staff had their credentials phished through a fake Microsoft login page. Fusion’s monitoring picked up the suspicious login, from overseas, at 2 in the morning, and locked the account before whoever had the password could do anything with it.”

Thomas W., Professional Services, Toronto. A separate Fusion client, describing the monitoring layer this rebuild also put in place.

Business Outcomes

The agency ended the engagement with a more stable estate, stronger recovery readiness, and executive visibility it did not have before, across the 5 posture changes below. We have deliberately kept this section qualitative. The engagement record documents posture changes rather than a measured before-and-after metric set, and publishing numbers we did not measure would be worse than publishing none.

Printed before-and-after posture sheet on an Ontario agency owner's desk with several rows highlighted in yellow
A printed before-and-after sheet is the only outcome an owner actually keeps after a recovery.
Five Posture Changes, Before and After. Five posture changes recorded in the engagement, stated as before and after rather than as metrics. Recovery moved from assumed to validated and documented. Documentation moved from thin to a written asset, access and dependency record. Infrastructure moved from a fragile virtual server estate to a Microsoft 365 collaboration foundation. Security moved from unclear baseline coverage to defined identity, endpoint and access controls. Planning moved from reactive fixes to a scheduled strategic review cadence. Five Posture Changes, Before and After. Stated as posture, not as metrics we did not measure. Before. After. Recovery assumed. Recovery validated and documented. Documentation thin. Assets, access, dependencies written. Fragile virtual servers. Microsoft 365 collaboration base. Security baseline unclear. Identity, endpoint, access defined. Planning reactive. Scheduled strategic reviews.

Leadership also came away with a working definition of good managed IT. It covers accountability, documentation, planning, and risk reduction, and issue resolution is only the visible part of it.

What a post-incident rebuild needs: the transition checklist

Every transition Fusion Computing runs after an incident needs the same 6 items closed before any migration begins. Use this as a checklist against whichever provider you are talking to, and ask for evidence on each line rather than reassurance. The evidence is the point.

  • A dated restore test, with the systems and the recovery time written down.
  • A current asset and access inventory, including who holds administrative rights.
  • Administrative access transferred deliberately, with the old provider’s access revoked on a known date.
  • A written incident response plan with named roles and a contact list that has been read aloud once.
  • A security baseline you can recite: MFA coverage, endpoint protection, email filtering, patch cadence.
  • A scheduled review, so the roadmap survives the first busy quarter.

Rebuild vs repair: how to compare the two options

Repair keeps the existing design and fixes what broke. Rebuild retires the parts that made the environment hard to support. The comparison comes down to one question: can the current design be documented and recovered by somebody who did not build it? If the answer is no, repair only buys time.

This agency chose rebuild because the virtual server estate had accumulated complexity nobody could explain. A firm with a simpler footprint and one undocumented gap can often repair instead. I would rather scope that honestly than sell a rebuild by default, so if you are weighing the two, get in touch and we will tell you which one your estate needs.

Why does This Case Study matter?

Most businesses do not change providers because of one catastrophic event. They change because confidence erodes. Documentation stays thin, strategy never happens, the same issues resurface, backup confidence is assumed rather than proven, and security stays vague. This engagement shows what the alternative looks like when a business decides it needs structure.

According to the Canadian Anti-Fraud Centre, Canadians reported more than CA$704 million in fraud losses across 112,000 reports in 2025, with spear phishing second at CA$67.9 million. The CAFC also estimates that only 5% to 10% of fraud connected to Canadian victims is ever reported to it, so the visible number is a floor.

Scope matters when you read threat reporting. The Cyber Centre’s National Cyber Threat Assessment 2025 to 2026 names ransomware the top cybercrime threat to Canada’s critical infrastructure, not to SMBs specifically. For an agency holding client creative assets and personal information under PIPEDA, the practical risk is still downtime and disclosure.

If you rely on an outside provider and you are not confident in your documentation, backup recoverability, security controls, or roadmap, an independent view is worth the afternoon it takes.

Not sure whether your current IT provider is giving you the visibility your business needs? Fusion Computing has run managed IT and CISSP-led security for Canadian businesses since 2012. We review your environment, recovery readiness, documentation, and vendor accountability so you can decide from a position of clarity. Call 416-566-2845 or talk to our team.

Talk to Fusion

Frequently asked questions

These four come up in almost every conversation I have with an owner who is thinking about changing providers after an incident. The answers below reflect how this transition actually ran rather than a generic onboarding brochure, so use them to press whoever is pitching you.

How can I tell whether my current MSP is really managing my environment?

Ask for evidence, not assurances. A strong provider can show current documentation, explain your security baseline, name who holds privileged access, and produce the date of the last tested restore. Vague answers on any of those 4 points are the warning sign, and they are usually the cheapest thing to check first.

What should I ask before switching MSPs?

Ask how the provider handles discovery, documentation, access transfer, backup validation, security baselining, vendor coordination, and executive communication. You want a structured onboarding sequence with dates against each of those 7 items, not a promise to take over support and sort the detail out later.

What happens to our data during an MSP transition?

Data protection belongs at the start of the transition, not the end. That means confirming backup scope, reviewing administrative access, validating recovery assumptions, and agreeing a controlled change plan before any migration begins. In this engagement all 4 steps were closed during the assessment phase.

Can Fusion modernize a legacy server environment?

Yes. Fusion Computing moves businesses off aging, fragile, or overly complex infrastructure into a supportable model built on Microsoft 365 collaboration, identity hardening, and modern endpoint management. That is the same 3-part pattern used in this rebuild, and it is documented before it is executed.

For the wider picture, see the cybersecurity services hub and the managed IT services overview. Related engagements include a GTHA dealership IT overhaul, a cannabis-retail compliance build, and the Prolift startup launch. Browse all case studies for the full set.

Fusion Computing has provided managed IT, cybersecurity, and AI consulting to Canadian businesses since 2012. Fusion’s CISSP-led team supports organizations with 15 to 200+ users across Toronto, Hamilton, and Metro Vancouver.

93% of issues resolved on the first call. Named one of Canada’s 50 Best Managed IT Companies two years running.

100 King Street West, Suite 5700
Toronto, ON M5X 1C7
(416) 566-2845
1 888 541 1611