When a ransomware attack strikes your business, backups are only part of the story. Who actually knows where they’re kept? Who knows how to run the recovery process, step by step, under pressure? And who’s allowed to talk to customers and the press, and do they actually know what to say? That’s the uncomfortable truth behind crisis management: the technical fight is only half the battle, and it’s often not the half that determines whether an MSP walks away intact or spends the next year dealing with recriminations and lasting damage to its reputation. Complexity, urgency, exhaustion, and fast-moving facts make it easy to stumble, and the gap between a well-drilled response and an improvised one usually shows up in the moments nobody planned for.
That’s exactly the territory Jen Ellis, cybersecurity policy expert and crisis communications advisor, explores in the MSP GLOBAL 2026 session “Surviving a Cat-astrophe: The Art of Crisis Management as told through LOLcatz / Cat Memes.” Using humor as the hook, she will pounce upon the points where crisis response actually breaks down: alignment, legal exposure, regulatory pressure, and the delicate art of communicating without triggering panic or losing client trust.
In this interview, Jen Ellis walks through why MSPs need to prepare for the non-technical side of a crisis just as seriously as the technical one, and what a small or mid-sized MSP can realistically do in the next 90 days to get crisis-ready. Because nothing says “we’ve got this under control” quite like your incident response plan being a group chat named “HELP.”

Your MSP GLOBAL session is called “Surviving a Cat-astrophe: The Art of Crisis Management as told through LOLcatz / Cat Memes.” Behind the humor, what do most organizations still misunderstand about what actually happens in a cyber crisis?

MSPs often have a sophisticated understanding of the technical environment, endpoints, platforms, identity, networks, vendors, and controls but a much less developed understanding of the human environment operating within it. People in cyber systems are not rational actors calmly processing perfect information. They are making decisions under pressure, under uncertainty, and often under cognitive stress and load. In those conditions, people rely on heuristics, that is, mental shortcuts, and those shortcuts can be exploited. In cybersecurity, attackers often hack the shortcut, not the system. Urgency, authority, familiarity, fatigue, fear, optimism bias, and confirmation bias all shape behavior. Therefore, from a cyberpsychology perspective, the MSP is not just managing infrastructure. It is managing human decision-making in a high-speed, high-risk cyber environment, and ecosystem.

Many MSPs prepare for incidents as a technical problem first. From your experience in crisis response, where do the non-technical parts—alignment, decision-making, legal, regulation, and communications—usually break down?

Any or all of the above can become a trap or weak spot. The whole point is you need to integrate and anticipate all these factors. You need the right expertise involved to address these points. Unfortunately, even with a perfect technical response, if you mess up your communications or regulatory requirements, you will still find yourself in a world of recrimination, and pain.

MSPs find themselves in a unique and sensitive position: they are trusted by many clients, often with privileged access across multiple environments. How should an MSP communicate during a crisis without creating panic, losing trust, or saying too much too soon?

That is indeed the question, and in truth there is no template or golden rule to answer it. You need balance and judgement. Come to the session to learn more about what that means!

When ransomware or another major incident hits, who needs to be in the room from the first hour—and what roles should be clear before the crisis starts?

OK really, I’m not going to write out my talk for you, but I would say you’ve already hit on many of the key stakeholder functions in your questions.

You work across security experts, technology providers, civil society, and government. How can MSPs get better at translating technical facts into language that executives, customers, regulators, and insurers can actually act on?

In general, avoid jargon, or hiding your message in complicated technical language. Identify what your audience cares about, prioritizes or needs, and use language that speaks to those things. Meet them where they are and help them understand the relevance of what you’re describing. It’s not about proving how smart you are, it’s about demonstrating your understanding of their needs and concerns.

What should a realistic crisis exercise look like for a small or mid-sized MSP that does not have a large legal, communications, or incident response team?

Sadly, being small doesn’t get you out of having to communicate or meet legal requirements (well maybe some of the latter). The whole purpose of preparedness exercises is to help organizations think about how they will meet the needs of a crisis, particularly the needs or aspects they don’t deal with every day. This doesn’t mean small or mid-sized MSPs need full-time comms or legal staff, but it does mean they need to start thinking about how they will cover those bases. Is it through cyber insurance? Is it creating a contingency fund to pay for specialist counsel when needed? Are there volunteers or nonprofits you can leverage? Is it identifying self-help materials and learning the expectations yourself in advance.
Again, this isn’t a one-size-fits-all thing; it’s about figuring out what will work for you when the time comes and also knowing what it is you’ll actually need to cover.

For an MSP that wants to become more crisis-ready in the next 90 days, what are the first practical steps: the plan to write, the conversations to have, and the habits to rehearse before the cat-astrophe arrives?

COME TO MY TALK!!! No really, this is absolutely something I will cover.
Yes, come to her talk! Jen Ellis will be speaking at MSP GLOBAL 2026, taking place October 21–22 at PortAventura Theme Park near Barcelona, Spain, with the session “Surviving a Cat-astrophe: The Art of Crisis Management as told through LOLcatz / Cat Memes.”
Join the global community of MSPs, MSSPs, resellers, systems integrators, IT leaders, cybersecurity experts, and digital enablement specialists for two days of intelligence, networking, and real-world security insight.
Sign up to our newsletter here and receive a FREE code to register for MSP GLOBAL, saving €399!




