Key Incident Response Procedures Every IT Managed Service Provider Must Master
In a breach situation, MSPs must be prepared to act quickly to help clients restore operations and reduce business downtime.
In September 2025, IronGate observed two confirmed LockBit 5.0 incidents, marking the sixth anniversary of the LockBit affiliate program. This resurgence follows a quiet period after Operation Cronos in early 2024, a multinational law enforcement operation that disrupted LockBit’s infrastructure. The latest version introduces a revamped affiliate model with improved incentives, aiming to attract new cybercriminal partners. LockBit continues to employ double extortion tactics, combining file encryption with data theft and public leaks to pressure victims.
Threat Actor Profile: LockBit 5.0 Ransomware
Attack Lifecycle
Initial Access
Execution & Evasion
Persistence & Anti-Forensics
Impact
Recommended Mitigations
Contact us today to learn more about our Digital Forensics and Incident Response (DFIR) services.
![]() |
Steve Ramey has spent the past two decades helping clients protect, investigate, and respond to events involving their digital interests. |
In a breach situation, MSPs must be prepared to act quickly to help clients restore operations and reduce business downtime.
Take these important actions now to mitigate vulnerabilities in NetScaler ADC and NetScaler Gateway products
Vulnerable organizations should follow the recommended actions from ConnectWise, plus several other key precautions