A mid-size medical practice lost more than $700,000 and exposed 12,000 patients' protected health information because their IT company built an environment that worked but was never secured. Open RDP. A departed employee's active account. No MFA. No monitoring. No cyber insurance. The attacker didn't need to be good. The door was open.
A 300-employee building supply distributor lost $1.4 million when a compromised warehouse laptop walked through an always-on tunnel to their MSP-hosted servers. One MSP hosted the servers. Another managed the laptops. The EDR caught the attack on Day 0. Nobody was watching. Three contracts, three denials, and a gap nobody owned.