KEY TAKEAWAYS
- A cybersecurity incident at an Ontario marketing agency exposed a weaker IT foundation than leadership believed it had.
- The fix was a transition, not a cleanup: assess, rebuild on Microsoft 365, then govern the environment through scheduled reviews.
- The signal to watch for is not a breach. It is a provider who cannot show you a recent restore test.
Mike Pearlstein is CEO of Fusion Computing and holds the CISSP, the gold standard in cybersecurity certification. He has led Fusion’s managed IT and cybersecurity practice since 2012, serving Canadian businesses across Toronto, Hamilton, and Metro Vancouver.
Cyber crisis recovery is the work of restoring operations after a security incident and then closing the gaps the incident exposed. For this agency the second half mattered more. The incident was contained. What it revealed was an environment nobody could document, a backup nobody had tested, and a technology plan that had never been written down.
Introduction
An Ontario marketing agency lost several days of normal operation to a cybersecurity incident. According to the assessment that followed, the deeper problem was the environment itself: undocumented, fragile, and never tested for recovery. This is the story of the transition that came after. Source: Fusion Computing client engagement record, 2026.
The agency had long-standing client relationships and a small internal team. Fusion Computing was brought in after the incident to answer 3 questions: what failed, what could be recovered, and whether the environment could be trusted going forward.
This case study is based on a real Fusion Computing engagement. Client details have been anonymized, and certain technical details have been generalized for privacy.
The Challenge: A Fragile Environment and Too Much Assumption
According to Statistics Canada, about 1 in 6 Canadian businesses (16%) were impacted by cyber security incidents in 2023, and large businesses remained the most likely to be hit at 30%. Small firms sat lowest at 14%, which is exactly why so many of them assume the problem belongs to somebody else.

After the incident the agency needed clarity more than cleanup. Fusion Computing was engaged to assess the situation, and the review surfaced five issues that raised operational risk:
- Backup and recovery readiness fell short. The agency did not have the verified, testable recovery capability leadership assumed was in place.
- No practical disaster recovery roadmap existed. Recovery steps were not documented in a way that supported a fast, structured response.
- The virtual server environment had grown fragile. Complexity had accumulated, which made maintenance, troubleshooting, and recovery harder than they needed to be.
- Documentation and governance were thin. Nobody could see how systems were configured, who had access to what, or how resilience would be maintained.
- Technology planning had gone reactive. The environment had evolved through incremental fixes rather than a roadmap tied to business goals.
What is an MSP transition, explained in plain terms
An MSP transition is the controlled handover of an IT environment from one provider to another. Done properly it runs in 4 steps: discovery and documentation, administrative access moved under new control, backups validated, and only then a change to the architecture, whether that lands on Microsoft 365 or stays on-premise.
The distinction matters most right after an incident, when everyone wants visible progress. In our experience the first two weeks should look boring: inventories, access reviews, restore tests. That is the work that makes the next six months uneventful.
Warning Signs Your MSP May Be Underperforming
According to the Canadian Centre for Cyber Security, its Baseline Cyber Security Controls v1.2 apply an 80/20 rule for small and medium organizations, mapping to ITSG-33 Annex 4A Profile 1. If your provider cannot walk you through those baseline items in plain language, that is your first warning sign.

The agency’s situation was not unusual. Our engineers found the same five patterns whenever they review an environment that has been managed without much rigour:
- No recent verified restore test. A backup dashboard is not proof that recovery works.
- Weak or outdated documentation. No current network diagram, asset inventory, permissions record, or vendor map means your provider is working blind too.
- No regular business reviews. Managed IT should include scheduled conversations about lifecycle planning, budget, risk, and upcoming change.
- Recurring issues that never go away. Repeated email, performance, or permissions problems usually signal weak root-cause ownership.
- No clear answer on security basics. If nobody can explain MFA status, endpoint coverage, backup scope, and admin access in plain language, that is the answer.
Fusion Computing’s Approach
Rather than preserve a design leadership no longer trusted, Fusion Computing proposed a structured rebuild around resilience, simplicity, security, and operational clarity. It ran in 3 phases: assess and stabilize, modernize onto Microsoft 365, then govern the result through scheduled strategy sessions rather than ad hoc calls.

Phase 1: Assessment and Stabilization
The first step was a full cybersecurity assessment and environment review. Fusion mapped systems, user access, dependencies, and operational gaps so leadership could see the current state clearly. Stabilization work then focused on reducing business risk while the long-term plan was written.
Phase 2: Modernization and Rebuild
With the environment assessed, Fusion designed a cleaner, more supportable foundation:
- Retire the legacy virtual server design in favour of a simpler, more resilient operating model.
- Migrate core collaboration workloads to Microsoft 365 to improve access and continuity while reducing dependency on aging infrastructure.
- Strengthen security controls, including MFA, endpoint protection, email security, and a backup strategy built around validation and recoverability.
- Write the documentation, so leadership could see assets, access, dependencies, and operating standards.
Phase 3: Governance and Strategic Oversight
Fusion did not treat the rebuild as the end of the engagement. Ongoing vCIO strategy sessions now help leadership make deliberate decisions about risk, lifecycle planning, vendor accountability, and growth. The goal was a better operating model, and the stable environment is what that produced.
“One of our staff had their credentials phished through a fake Microsoft login page. Fusion’s monitoring picked up the suspicious login, from overseas, at 2 in the morning, and locked the account before whoever had the password could do anything with it.”
Thomas W., Professional Services, Toronto. A separate Fusion client, describing the monitoring layer this rebuild also put in place.
Business Outcomes
The agency ended the engagement with a more stable estate, stronger recovery readiness, and executive visibility it did not have before, across the 5 posture changes below. We have deliberately kept this section qualitative. The engagement record documents posture changes rather than a measured before-and-after metric set, and publishing numbers we did not measure would be worse than publishing none.

Leadership also came away with a working definition of good managed IT. It covers accountability, documentation, planning, and risk reduction, and issue resolution is only the visible part of it.
What a post-incident rebuild needs: the transition checklist
Every transition Fusion Computing runs after an incident needs the same 6 items closed before any migration begins. Use this as a checklist against whichever provider you are talking to, and ask for evidence on each line rather than reassurance. The evidence is the point.
- A dated restore test, with the systems and the recovery time written down.
- A current asset and access inventory, including who holds administrative rights.
- Administrative access transferred deliberately, with the old provider’s access revoked on a known date.
- A written incident response plan with named roles and a contact list that has been read aloud once.
- A security baseline you can recite: MFA coverage, endpoint protection, email filtering, patch cadence.
- A scheduled review, so the roadmap survives the first busy quarter.
Rebuild vs repair: how to compare the two options
Repair keeps the existing design and fixes what broke. Rebuild retires the parts that made the environment hard to support. The comparison comes down to one question: can the current design be documented and recovered by somebody who did not build it? If the answer is no, repair only buys time.
This agency chose rebuild because the virtual server estate had accumulated complexity nobody could explain. A firm with a simpler footprint and one undocumented gap can often repair instead. I would rather scope that honestly than sell a rebuild by default, so if you are weighing the two, get in touch and we will tell you which one your estate needs.
Why does This Case Study matter?
Most businesses do not change providers because of one catastrophic event. They change because confidence erodes. Documentation stays thin, strategy never happens, the same issues resurface, backup confidence is assumed rather than proven, and security stays vague. This engagement shows what the alternative looks like when a business decides it needs structure.
According to the Canadian Anti-Fraud Centre, Canadians reported more than CA$704 million in fraud losses across 112,000 reports in 2025, with spear phishing second at CA$67.9 million. The CAFC also estimates that only 5% to 10% of fraud connected to Canadian victims is ever reported to it, so the visible number is a floor.
Scope matters when you read threat reporting. The Cyber Centre’s National Cyber Threat Assessment 2025 to 2026 names ransomware the top cybercrime threat to Canada’s critical infrastructure, not to SMBs specifically. For an agency holding client creative assets and personal information under PIPEDA, the practical risk is still downtime and disclosure.
If you rely on an outside provider and you are not confident in your documentation, backup recoverability, security controls, or roadmap, an independent view is worth the afternoon it takes.
Not sure whether your current IT provider is giving you the visibility your business needs? Fusion Computing has run managed IT and CISSP-led security for Canadian businesses since 2012. We review your environment, recovery readiness, documentation, and vendor accountability so you can decide from a position of clarity. Call 416-566-2845 or talk to our team.
Frequently asked questions
These four come up in almost every conversation I have with an owner who is thinking about changing providers after an incident. The answers below reflect how this transition actually ran rather than a generic onboarding brochure, so use them to press whoever is pitching you.
How can I tell whether my current MSP is really managing my environment?
Ask for evidence, not assurances. A strong provider can show current documentation, explain your security baseline, name who holds privileged access, and produce the date of the last tested restore. Vague answers on any of those 4 points are the warning sign, and they are usually the cheapest thing to check first.
What should I ask before switching MSPs?
Ask how the provider handles discovery, documentation, access transfer, backup validation, security baselining, vendor coordination, and executive communication. You want a structured onboarding sequence with dates against each of those 7 items, not a promise to take over support and sort the detail out later.
What happens to our data during an MSP transition?
Data protection belongs at the start of the transition, not the end. That means confirming backup scope, reviewing administrative access, validating recovery assumptions, and agreeing a controlled change plan before any migration begins. In this engagement all 4 steps were closed during the assessment phase.
Can Fusion modernize a legacy server environment?
Yes. Fusion Computing moves businesses off aging, fragile, or overly complex infrastructure into a supportable model built on Microsoft 365 collaboration, identity hardening, and modern endpoint management. That is the same 3-part pattern used in this rebuild, and it is documented before it is executed.
For the wider picture, see the cybersecurity services hub and the managed IT services overview. Related engagements include a GTHA dealership IT overhaul, a cannabis-retail compliance build, and the Prolift startup launch. Browse all case studies for the full set.

