{"id":25968,"date":"2026-06-29T09:20:44","date_gmt":"2026-06-29T13:20:44","guid":{"rendered":"https:\/\/www.sherweb.com\/blog\/?p=25968"},"modified":"2026-06-29T09:20:44","modified_gmt":"2026-06-29T13:20:44","slug":"msps-backup-vendor-risk-2026","status":"publish","type":"post","link":"https:\/\/www.sherweb.com\/blog\/security\/backup-recovery\/msps-backup-vendor-risk-2026\/","title":{"rendered":"Backup isn\u2019t enough anymore: What I\u2019m hearing from MSPs about risk, lock-in and cyber resilience in 2026"},"content":{"rendered":"<p>The best part of my job is that I get to spend a lot of time talking with MSPs.<\/p>\n<p>I get to chat not just about <a href=\"https:\/\/www.sherweb.com\/blog\/security\/security-stack-for-msps\/\">tech stacks and products<\/a>, but about how businesses are running day to day: the good, the bad and the ugly. I see a wide range of MSPs \u2014 different sizes, different verticals, different levels of maturity. Lately, I\u2019ve noticed something interesting.<\/p>\n<p>Even MSPs who are doing \u201ceverything right\u201d are starting to ask new questions, especially around their backup, continuity and disaster recovery offerings.<\/p>\n<p>Not because their current backup tech stack stopped working, but because the world around backup has changed.<\/p>\n<p>Instead of hearing: \u201cWhich backup platform should we standardize on?\u201d<\/p>\n<p>I\u2019m hearing things like:<\/p>\n<p style=\"padding-left: 40px;\">\u201cAre we too dependent on one vendor?\u201d<\/p>\n<p style=\"padding-left: 40px;\">\u201cWhat happens if our primary platform changes direction?\u201d<\/p>\n<p style=\"padding-left: 40px;\">\u201cCan we confidently answer our clients\u2019 compliance questions?\u201d<\/p>\n<p style=\"padding-left: 40px;\">\u201cDo we actually have options if something goes sideways?\u201d<\/p>\n<p>Those are healthy questions. And they\u2019re coming up more often for a reason.<\/p>\n<h2>1. Vendor consolidation brought simplicity and trade<strong>&#8211;<\/strong>offs<\/h2>\n<p>Vendor consolidation has reshaped the MSP landscape. Larger platforms, broader portfolios, tighter integrations. On the surface, that feels like progress.<\/p>\n<p>And in many ways, it is. But I\u2019ve also seen the other side of that coin.<\/p>\n<p>An MSP standardized across a single ecosystem \u2014 backup, RMM, PSA, security. When that platform has an outage or an issue, the MSP isn\u2019t just troubleshooting backups. Monitoring can slow down. Ticket workflows can be impacted, and overall visibility decreases.<\/p>\n<p>No one did anything \u201cwrong\u201d, there just weren\u2019t any alternatives.<\/p>\n<p>That\u2019s what people mean when they talk about concentration risk, and it\u2019s why \u00a0<a href=\"https:\/\/www.sherweb.com\/blog\/security\/msp-security-framework-2026\/\">frameworks like NIST CSF 2.0 and SOC 2<\/a> are putting more emphasis on third-party and supply-chain risk.<\/p>\n<p>Savvy MSPs are looking at multi-vendor marketplace models, like the Sherweb approach of partnering with vetted providers. This enables MSPs to distribute risk across best-of-breed solutions while maintaining architectural consistency through a single orchestrator. This approach reduces dependency on any single vendor&#8217;s financial health, product roadmap or post-acquisition integration challenges.<\/p>\n<h2>2. Contract flexibility and economic agility matter more than ever<\/h2>\n<p>Another theme that comes up a lot is contracts and commercial agreements. I am hearing a lot from folks looking for flexibility over unit pricing.<\/p>\n<p>Many MSPs only realize how locked in they are when they try to make a change. It could stem from a client\u2019s compliance requirements, a recovery need shift or a workload that no longer fits the original design.<\/p>\n<p>I\u2019ve been in conversations where an MSP knows a tool no longer fits a client\u2019s <a href=\"https:\/\/www.sherweb.com\/blog\/partner\/msp-compliance-best-practices-for-success\/\">compliance or recovery needs<\/a> \u2014 but switching would mean:<\/p>\n<ul>\n<li>Waiting out a multi\u2011year term<\/li>\n<li>Absorbing minimum commitments<\/li>\n<li>Migrating data under pressure<\/li>\n<\/ul>\n<p>Contract flexibility is a part of cyber resilience, not just finance and commerce. The ability to adapt without penalties is becoming just as important as the tools themselves. Look for backup and continuity solutions with month-to-month or annual renewal terms that enable MSPs to optimize their tool stack in real time, align costs with active usage and maintain negotiating leverage.<\/p>\n<h2>3. Cyber resilience maturity: Move beyond backup to recovery-first architecture<\/h2>\n<p>Thanks to the change in the threat landscape over the last decade, nobody I talk to is pretending that ransomware isn\u2019t real or that recovery is optional. What is changing is how backup is evaluated.<\/p>\n<p>Backup used to be about storage. Now that\u2019s changed to <strong>cyber resilience.<\/strong><\/p>\n<p>The shift from &#8220;backup&#8221; to cyber resilience reflects maturity in how MSPs and their clients approach recovery and business continuity. Immutability, air-gapping and validated recoverability are now the conversation leaders, and this is no surprise.<\/p>\n<p>A scenario I hear often:<\/p>\n<p>An MSP had backups. They restored successfully. But the restore brought more problems. That\u2019s not technically a backup failure \u2014 that\u2019s a recovery design challenge.<\/p>\n<p>What seems to work best is acknowledging that not all workloads are the same:<\/p>\n<ul>\n<li>SaaS data behaves differently than servers<\/li>\n<li>Cloud workloads recover differently than endpoints<\/li>\n<li>Identity recovery has its own risks entirely<\/li>\n<\/ul>\n<p>Matching the right recovery approach to each workload isn\u2019t overcomplicating things. It\u2019s simply meeting reality where it is. MSPs need to architect diverse resilience strategies rather than relying on a single appliance-based vendor whose recovery stack may not support modern threat scenarios.<\/p>\n<h2>4. AI and data governance are everyday conversations<\/h2>\n<p>AI is already part of the tools we use, and that\u2019s not slowing down. What is slowing MSPs down is <a href=\"https:\/\/www.sherweb.com\/blog\/microsoft-ecosystem\/office-365\/msp-security-strategy-for-ai\/\">governance<\/a>. I often hear:<\/p>\n<ul>\n<li>Where is the data stored, and where is it transited through?<\/li>\n<li>Who has access to it?<\/li>\n<li>Can we clearly explain this to an auditor or client?<\/li>\n<li>Are we comfortable with how AI is being used behind the scenes?<\/li>\n<\/ul>\n<p>For MSPs supporting regulated industries \u2014 defense, manufacturing, healthcare, finance \u2014 these aren\u2019t theoretical concerns. SOC 2 and ITAR don\u2019t leave much room for ambiguity.<\/p>\n<p>During compliance reviews, MSPs are the ones being asked to document data residency and access controls for backups. Vendor responses are often unclear; this leads to the MSP being the one left explaining the gap.<\/p>\n<p>This is where choice and transparency really help. Being able to align different vendors to different governance and sovereignty requirements makes those conversations much easier \u00a0and much more confident.<\/p>\n<h2>Final thoughts<\/h2>\n<p>Modern MSPs face a convergence of pressures: accelerating threats, stricter compliance mandates, AI governance complexity and clients demanding both resilience and flexibility. Legacy, single vendor backup strategies, especially those tied to post-acquisition integration cycles and inflexible pricing, are no longer working. This creates single points of failure, limited agility and increased overall risk.<\/p>\n<p>Sherweb&#8217;s marketplace model, anchored by vetted partners like <a href=\"https:\/\/www.sherweb.com\/backup-continuity\/acronis\">Acronis<\/a>, <a href=\"https:\/\/www.sherweb.com\/backup-continuity\/commvault\">Commvault<\/a>, <a href=\"https:\/\/www.sherweb.com\/backup-continuity\/afi\">Afi<\/a>, <a href=\"https:\/\/www.sherweb.com\/backup-continuity\/keepit\">Keepit<\/a> and more, offers MSPs a different way: the operational simplicity of a unified relationship (single billing, centralized support, shared enablement) combined with the resilience benefits of a diversified, best-of-breed architecture.<\/p>\n<p>I will leave this blog with 5 actionable next steps for MSPs to consider:<\/p>\n<ol>\n<li><strong>Audit your vendor concentration risk: <\/strong>How dependent are you on a single platform provider&#8217;s pricing, roadmap and stability?<\/li>\n<li><strong>Evaluate your contract flexibility:<\/strong> Can you scale down, pivot or exit without punitive costs?<\/li>\n<li><strong>Test your cyber resilience maturity:<\/strong> Are backups immutable, tested and specific to the workload?<\/li>\n<li><strong>Map your compliance posture<\/strong>: Do your backup solutions support SOC 2, ITAR or emerging AI governance requirements through NIST AI RMF?<\/li>\n<li><strong>Consider marketplace optionality:<\/strong> Does your vendor strategy let you architect for client fit, or are you locked into a one-size-fits-all?<\/li>\n<\/ol>\n<h2>Want to compare notes with other MSPs?<\/h2>\n<p>If you&#8217;re rethinking your backup and resilience strategy, you don&#8217;t have to figure it out alone. Conversations like these are what the <a href=\"https:\/\/info.sherweb.com\/cybermsp-community\/\">CyberMSP Community<\/a> is built for. Join to connect with other MSPs and stay ahead of what&#8217;s coming.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The best part of my job is that I get to spend a lot of time talking with MSPs. I get to chat not","protected":false},"author":198,"featured_media":25969,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1166],"tags":[617,1128,1180],"class_list":["post-25968","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-backup-recovery","tag-backup","tag-vendor-risk-management","tag-cyber-resilience"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.9 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Why MSPs are rethinking backup vendor risk in 2026 | Sherweb<\/title>\n<meta name=\"description\" content=\"MSPs are asking sharper questions about backup vendor risk, contract lock-in and recovery. Here are 5 steps to build real cyber resilience.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.sherweb.com\/blog\/security\/backup-recovery\/msps-backup-vendor-risk-2026\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Why MSPs are rethinking backup vendor risk in 2026 | Sherweb\" \/>\n<meta property=\"og:description\" content=\"MSPs are asking sharper questions about backup vendor risk, contract lock-in and recovery. Here are 5 steps to build real cyber resilience.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.sherweb.com\/blog\/security\/backup-recovery\/msps-backup-vendor-risk-2026\/\" \/>\n<meta property=\"og:site_name\" content=\"Sherweb\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Sherweb\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-29T13:20:44+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.sherweb.com\/blog\/wp-content\/uploads\/Hero_1200x480-13.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1800\" \/>\n\t<meta property=\"og:image:height\" content=\"720\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Mandy Sun Volpe\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@SherWeb\" \/>\n<meta name=\"twitter:site\" content=\"@SherWeb\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Mandy Sun Volpe\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/backup-recovery\\\/msps-backup-vendor-risk-2026\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/backup-recovery\\\/msps-backup-vendor-risk-2026\\\/\"},\"author\":{\"name\":\"Mandy Sun Volpe\",\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/#\\\/schema\\\/person\\\/65c15de734b07ded94d9c129b54c3e54\"},\"headline\":\"Backup isn\u2019t enough anymore: What I\u2019m hearing from MSPs about risk, lock-in and cyber resilience in 2026\",\"datePublished\":\"2026-06-29T13:20:44+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/backup-recovery\\\/msps-backup-vendor-risk-2026\\\/\"},\"wordCount\":1137,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/backup-recovery\\\/msps-backup-vendor-risk-2026\\\/#primaryimage\"},\"thumbnailUrl\":\"\\\/blog\\\/wp-content\\\/uploads\\\/Hero_1200x480-13.jpg\",\"keywords\":[\"Backup\",\"Vendor Risk Management\",\"Cyber resilience\"],\"articleSection\":[\"Backup &amp; Recovery\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/backup-recovery\\\/msps-backup-vendor-risk-2026\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/backup-recovery\\\/msps-backup-vendor-risk-2026\\\/\",\"url\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/backup-recovery\\\/msps-backup-vendor-risk-2026\\\/\",\"name\":\"Why MSPs are rethinking backup vendor risk in 2026 | Sherweb\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/backup-recovery\\\/msps-backup-vendor-risk-2026\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/backup-recovery\\\/msps-backup-vendor-risk-2026\\\/#primaryimage\"},\"thumbnailUrl\":\"\\\/blog\\\/wp-content\\\/uploads\\\/Hero_1200x480-13.jpg\",\"datePublished\":\"2026-06-29T13:20:44+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/#\\\/schema\\\/person\\\/65c15de734b07ded94d9c129b54c3e54\"},\"description\":\"MSPs are asking sharper questions about backup vendor risk, contract lock-in and recovery. Here are 5 steps to build real cyber resilience.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/backup-recovery\\\/msps-backup-vendor-risk-2026\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/backup-recovery\\\/msps-backup-vendor-risk-2026\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/backup-recovery\\\/msps-backup-vendor-risk-2026\\\/#primaryimage\",\"url\":\"\\\/blog\\\/wp-content\\\/uploads\\\/Hero_1200x480-13.jpg\",\"contentUrl\":\"\\\/blog\\\/wp-content\\\/uploads\\\/Hero_1200x480-13.jpg\",\"width\":1800,\"height\":720,\"caption\":\"Why MSPs are rethinking backup vendor risk in 2026\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/security\\\/backup-recovery\\\/msps-backup-vendor-risk-2026\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security\",\"item\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/category\\\/security\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Backup &amp; Recovery\",\"item\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/category\\\/security\\\/backup-recovery\\\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"Backup isn\u2019t enough anymore: What I\u2019m hearing from MSPs about risk, lock-in and cyber resilience in 2026\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/\",\"name\":\"Sherweb\",\"description\":\"More than a cloud marketplace\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/#\\\/schema\\\/person\\\/65c15de734b07ded94d9c129b54c3e54\",\"name\":\"Mandy Sun Volpe\",\"url\":\"https:\\\/\\\/www.sherweb.com\\\/blog\\\/author\\\/mandy-sun-volpe\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Why MSPs are rethinking backup vendor risk in 2026 | Sherweb","description":"MSPs are asking sharper questions about backup vendor risk, contract lock-in and recovery. Here are 5 steps to build real cyber resilience.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.sherweb.com\/blog\/security\/backup-recovery\/msps-backup-vendor-risk-2026\/","og_locale":"en_US","og_type":"article","og_title":"Why MSPs are rethinking backup vendor risk in 2026 | Sherweb","og_description":"MSPs are asking sharper questions about backup vendor risk, contract lock-in and recovery. Here are 5 steps to build real cyber resilience.","og_url":"https:\/\/www.sherweb.com\/blog\/security\/backup-recovery\/msps-backup-vendor-risk-2026\/","og_site_name":"Sherweb","article_publisher":"https:\/\/www.facebook.com\/Sherweb","article_published_time":"2026-06-29T13:20:44+00:00","og_image":[{"width":1800,"height":720,"url":"https:\/\/www.sherweb.com\/blog\/wp-content\/uploads\/Hero_1200x480-13.jpg","type":"image\/jpeg"}],"author":"Mandy Sun Volpe","twitter_card":"summary_large_image","twitter_creator":"@SherWeb","twitter_site":"@SherWeb","twitter_misc":{"Written by":"Mandy Sun Volpe","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.sherweb.com\/blog\/security\/backup-recovery\/msps-backup-vendor-risk-2026\/#article","isPartOf":{"@id":"https:\/\/www.sherweb.com\/blog\/security\/backup-recovery\/msps-backup-vendor-risk-2026\/"},"author":{"name":"Mandy Sun Volpe","@id":"https:\/\/www.sherweb.com\/blog\/#\/schema\/person\/65c15de734b07ded94d9c129b54c3e54"},"headline":"Backup isn\u2019t enough anymore: What I\u2019m hearing from MSPs about risk, lock-in and cyber resilience in 2026","datePublished":"2026-06-29T13:20:44+00:00","mainEntityOfPage":{"@id":"https:\/\/www.sherweb.com\/blog\/security\/backup-recovery\/msps-backup-vendor-risk-2026\/"},"wordCount":1137,"commentCount":0,"image":{"@id":"https:\/\/www.sherweb.com\/blog\/security\/backup-recovery\/msps-backup-vendor-risk-2026\/#primaryimage"},"thumbnailUrl":"\/blog\/wp-content\/uploads\/Hero_1200x480-13.jpg","keywords":["Backup","Vendor Risk Management","Cyber resilience"],"articleSection":["Backup &amp; Recovery"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.sherweb.com\/blog\/security\/backup-recovery\/msps-backup-vendor-risk-2026\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.sherweb.com\/blog\/security\/backup-recovery\/msps-backup-vendor-risk-2026\/","url":"https:\/\/www.sherweb.com\/blog\/security\/backup-recovery\/msps-backup-vendor-risk-2026\/","name":"Why MSPs are rethinking backup vendor risk in 2026 | Sherweb","isPartOf":{"@id":"https:\/\/www.sherweb.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.sherweb.com\/blog\/security\/backup-recovery\/msps-backup-vendor-risk-2026\/#primaryimage"},"image":{"@id":"https:\/\/www.sherweb.com\/blog\/security\/backup-recovery\/msps-backup-vendor-risk-2026\/#primaryimage"},"thumbnailUrl":"\/blog\/wp-content\/uploads\/Hero_1200x480-13.jpg","datePublished":"2026-06-29T13:20:44+00:00","author":{"@id":"https:\/\/www.sherweb.com\/blog\/#\/schema\/person\/65c15de734b07ded94d9c129b54c3e54"},"description":"MSPs are asking sharper questions about backup vendor risk, contract lock-in and recovery. Here are 5 steps to build real cyber resilience.","breadcrumb":{"@id":"https:\/\/www.sherweb.com\/blog\/security\/backup-recovery\/msps-backup-vendor-risk-2026\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.sherweb.com\/blog\/security\/backup-recovery\/msps-backup-vendor-risk-2026\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.sherweb.com\/blog\/security\/backup-recovery\/msps-backup-vendor-risk-2026\/#primaryimage","url":"\/blog\/wp-content\/uploads\/Hero_1200x480-13.jpg","contentUrl":"\/blog\/wp-content\/uploads\/Hero_1200x480-13.jpg","width":1800,"height":720,"caption":"Why MSPs are rethinking backup vendor risk in 2026"},{"@type":"BreadcrumbList","@id":"https:\/\/www.sherweb.com\/blog\/security\/backup-recovery\/msps-backup-vendor-risk-2026\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.sherweb.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Security","item":"https:\/\/www.sherweb.com\/blog\/category\/security\/"},{"@type":"ListItem","position":3,"name":"Backup &amp; Recovery","item":"https:\/\/www.sherweb.com\/blog\/category\/security\/backup-recovery\/"},{"@type":"ListItem","position":4,"name":"Backup isn\u2019t enough anymore: What I\u2019m hearing from MSPs about risk, lock-in and cyber resilience in 2026"}]},{"@type":"WebSite","@id":"https:\/\/www.sherweb.com\/blog\/#website","url":"https:\/\/www.sherweb.com\/blog\/","name":"Sherweb","description":"More than a cloud marketplace","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.sherweb.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.sherweb.com\/blog\/#\/schema\/person\/65c15de734b07ded94d9c129b54c3e54","name":"Mandy Sun Volpe","url":"https:\/\/www.sherweb.com\/blog\/author\/mandy-sun-volpe\/"}]}},"tag_names":["Backup","Vendor Risk Management","Cyber resilience"],"_links":{"self":[{"href":"https:\/\/www.sherweb.com\/blog\/wp-json\/wp\/v2\/posts\/25968","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.sherweb.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.sherweb.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.sherweb.com\/blog\/wp-json\/wp\/v2\/users\/198"}],"replies":[{"embeddable":true,"href":"https:\/\/www.sherweb.com\/blog\/wp-json\/wp\/v2\/comments?post=25968"}],"version-history":[{"count":2,"href":"https:\/\/www.sherweb.com\/blog\/wp-json\/wp\/v2\/posts\/25968\/revisions"}],"predecessor-version":[{"id":25971,"href":"https:\/\/www.sherweb.com\/blog\/wp-json\/wp\/v2\/posts\/25968\/revisions\/25971"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.sherweb.com\/blog\/wp-json\/wp\/v2\/media\/25969"}],"wp:attachment":[{"href":"https:\/\/www.sherweb.com\/blog\/wp-json\/wp\/v2\/media?parent=25968"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.sherweb.com\/blog\/wp-json\/wp\/v2\/categories?post=25968"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.sherweb.com\/blog\/wp-json\/wp\/v2\/tags?post=25968"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}