Skip to content
ISO 9001 ISO/IEC 27001 Proxmox Gold Partner Data in Italy
Rackone
Cyber Security

Managed security services

Rackone, Acronis Platinum Service Provider, designs and runs managed security services for companies and public bodies, measured by the restore and not by the copy: immutable backup, tested disaster recovery, endpoint protection and a path towards NIS2. One platform, one technical point of contact.

Immutable anti-ransomware cloud backup
Disaster recovery, tested regularly
Endpoint protection
NIS2 compliance path
  • 700+ active customers
  • 24h support, every day
  • GDPR data kept in Italy

Multi-layer protection

Managed security services, layer by layer

Managed security services are cyber security services run on an organisation's behalf by a specialist provider: the technology, processes and training that protect its data, systems and people from attacks, errors and failures, and let it recover when something breaks. Rackone builds them mainly on Acronis, as Acronis Platinum Service Provider, and runs them with its own systems engineers.

01

Acronis Cyber Protect Cloud

Backup and disaster recovery as a service (BaaS and DRaaS), EDR, XDR and MDR in a single agent and a single console, with Microsoft 365 security, activated and managed by our systems engineers. Italy's national cybersecurity agency (ACN) has qualified the platform as a cloud service for the public administration.

02

Immutable cloud backup

Copies no ransomware can encrypt or delete until the retention period ends, in Italy at the Acronis data center in Rome or in the European Union, as you choose. List-price plans from 50 GB to 5 TB.

03

Disaster recovery

Server replication and restart in an Acronis data center, in Rome for Italy, as a service (DRaaS). Configurable RTO and RPO, and an automatic monthly test that starts the recovery servers on an isolated network.

04

Veeam Backup

Veeam Backup & Replication for virtual and physical environments, on premises or with a copy replicated to the Rackone cloud.

05

NIS2 path

Free assessment, gap analysis and a compliance plan for Legislative Decree 138/2024, the Italian NIS2 law, with the documentation needed to demonstrate it.

06

Endpoint protection and MDR

EDR and XDR on servers and PCs detect an attack and stop it; with managed detection and response (MDR), the analysts of the Acronis SOC monitor the alerts around the clock.

07 · New

GenAI Protection

Visibility and control over the use of generative AI in the company: it blocks the sharing of sensitive data and harmful prompts.

08

Microsoft 365 and Google Workspace backup

Mail, OneDrive, SharePoint and Teams copied outside the tenant up to six times a day, with single-item restore. Google Workspace too.

09

Entra ID backup

Microsoft Entra ID users, groups, policies and configurations, restorable to a point in time with their relationships intact.

The method

Cyber security services: prevent, detect, recover

The Clusit 2026 Report, by the Italian association for information security, counts 507 serious incidents in Italy in 2025, 42% more than in 2024: 9.6% of the 5,265 recorded worldwide. With numbers like these, the odds of an attack matter less than the time it takes to recover. Protection is therefore built in three phases, and every service covers one.

Phase
What it does
Rackone services
Prevent
reduces the attack surface and human error
patching and vulnerability management, Microsoft 365 tenant security, anti-spam, WAF, BitNinja, SSL certificates, generative AI control
Detect
sees an attack in progress and stops it before it spreads
EDR and XDR, MDR with the Acronis SOC, 360 Monitoring
Recover
restores data and services as they were before the incident
immutable cloud backup, Microsoft 365 backup, Veeam, disaster recovery (DRaaS), Proxmox Backup Server

A backup that has never been restored is not a backup: the last phase decides how long an outage lasts, and it is where we start.

Prevention

Protection for websites, servers and email

Many attacks come in through an exposed door: a website, a server, a mailbox. These services close it before the backup is needed.

01

Multi-layer ransomware protection

Mail filtering, endpoint protection and cloud backup in sequence: ransomware that gets past the first layer meets the second.

02

BitNinja

Protection for Linux servers and VPSs against scans, brute-force attacks and malware, with several modules working together.

03

Web Application Firewall

Filters HTTP traffic between the website and the internet and stops SQL injection and XSS before they reach the application.

04

Anti-spam and anti-virus for email

A cloud gateway that filters email before the mailboxes: spam, phishing and infected attachments stay out, also in front of an existing mail server.

05

360 Monitoring

Website and server monitoring with metrics, blacklist checks and alerts, to detect a problem before it reaches the users.

06

SSL certificates

Certificates that encrypt website traffic and state who is behind it, from domain validation to extended validation (EV).

07

Physical and virtual firewall

Filters traffic between the company network and the internet, and between network segments: an on-premises appliance or a virtual firewall in the cloud, with the rules maintained over time.

08

Server hardening

Turns the factory configuration of Proxmox VE hypervisors, operating systems and exposed web servers into a defensible configuration, with a documented baseline verified over time.

How we work: from the assessment to a tested restore

  1. Assessment: a map of what is protected today, where the backups are, which systems are exposed and how long recovery takes.
  2. Design: priorities, protection levels for each system and recovery objectives set by you: how much data you can lose (RPO) and how soon you must be running again (RTO).
  3. Activation and monitoring: our systems engineers configure the services, monitor them and step in, around the clock.
  4. Restore tests: at agreed intervals we check that the data really comes back, and you receive a written report. Acronis disaster recovery also supports an automatic monthly test, which starts the recovery servers on an isolated network, without touching production, and reports the result.

The starting point is the existing setup: if the current backup holds up, the assessment states it, and we step in only where a layer is missing.

A night support desk, with a headset and monitoring charts on two screens

Business continuity is never improvised.

Talk to a certified Acronis specialist.

NIS2 compliance: what it asks of your company and where to start

NIS2 is the European directive on the security of network and information systems (Directive (EU) 2022/2555), which each member state transposes into its own law, with its own deadlines. In Italy that law is Legislative Decree 138/2024, in force since 16 October 2024: it covers medium and large companies in the sectors listed in its annexes, and some entities regardless of size. Companies outside its scope often meet it anyway, as suppliers to an entity in scope.

For organisations in Italy listed as NIS entities in 2025, the national cybersecurity agency (ACN, determination 379907 of 19 December 2025) sets two deadlines:

  • Notification of significant incidents to CSIRT Italia, from the ninth month after the notice of inclusion: a pre-notification no later than 24 hours after discovery, a full notification no later than 72 hours.
  • Basic security measures, applied no later than eighteen months after the same notice.

The Italian decree also requires management bodies to follow cyber security training and to promote it among staff. Tested backup and restore, patch and vulnerability management, incident detection and training relate to these measures: our services help you meet them and document them, while compliance remains the responsibility of your organisation.

Request an assessment

Why entrust your cyber security to Rackone

  • Acronis Platinum Service Provider and Acronis Authorized Cloud Aggregator: the highest tier of the Acronis programme for service providers, on a platform we aggregate ourselves, with no extra commercial layers.
  • ISO 9001 and ISO/IEC 27001: two certificates issued by WCS, valid until 30 March 2029.
  • A systems engineer, not a ticket: requests go to the engineers who run backups and restores every day for more than 700 active customers, companies and public bodies.

Data sovereignty

Your data stays where you choose, under European jurisdiction

An Italian company, with our own data center in Venice and an Edge network of partner data centers in Italy and Europe, and no transfers outside the EU: you always know where your data resides and who can access it, in line with GDPR and NIS2.

Data centers in Italy GDPR EU jurisdiction ISO/IEC 27001 certification issued by WCS, Worldwide Certification Standards
Data sovereignty explained

Partner programme

Are you an MSP? Become our partner.

Resell cloud, Proxmox and cyber security under your own brand: a reserved price list, Italian infrastructure and a technical team that works alongside you, never in competition with you.

  • White-label and single invoicing
  • Reserved price list with dedicated margins
  • Priority technical support, 24h

Frequently asked questions about managed security services

Where do I start to secure my company?

Securing a company starts with an assessment: what is protected, where the backups are, which systems are exposed and how long it takes to recover. The plan that follows sets the priorities and almost always starts from a tested restore, the phase that decides how long an outage lasts.

Is a backup enough for ransomware protection?

No, a backup alone is not enough for ransomware protection: it takes an immutable backup, which an attack cannot encrypt or delete, and a restore tested before the day it is needed. Endpoint protection stops the attack while it is under way, and mail filtering blocks infected attachments before the mailboxes.

Does NIS2 apply to my company?

No, NIS2 does not apply to every company: in Italy, Legislative Decree 138/2024 covers medium and large companies in the sectors listed in its annexes and some entities regardless of size, and ACN notifies inclusion in the list; elsewhere in the EU, national law sets the scope. Companies outside it often meet NIS2 as suppliers to an entity in scope. For organisations in Italy, the free NIS2 assessment establishes it.

What is the difference between backup and disaster recovery?

A backup is a copy of the data, from which files, mailboxes or whole servers are restored; disaster recovery is the ability to restart the systems at another site when the main one is unavailable. Backup limits the data lost (RPO), disaster recovery the downtime (RTO): a company that cannot stop needs both.

I already have antivirus and backup: can I start from those?

Yes, managed security services can build on the existing antivirus and backup: the assessment checks whether they hold up, that is whether the copies are immutable and the restore has been tested. If they hold up, the assessment states it, and we step in only where a layer is missing.

Where is backup data stored?

Acronis cloud backup data is stored in Italy, at the Acronis data center in Rome, or in the European Union, as you choose, always under the GDPR, and it is not moved without your authorisation. The Italian site serves organisations that must keep the copy in Italy under a contract or an internal policy, and the contract names the data center. With disaster recovery, the systems restart in an Acronis data center, in Rome for Italy.

How much do managed security services cost?

The cost of managed security services depends on the scope: how many servers, PCs and mailboxes to protect, and with which services. Cloud backup has list-price plans with a monthly fee; the Microsoft 365 security modules are priced per user or per workstation; the other managed services are priced after the assessment, because the price depends on what there is to protect and how quickly it must be running again.

Can a company outside Italy use Rackone's managed security services?

Yes, Rackone's managed security services are available to companies anywhere in the world: backups stay in Italy or in the EU, as you choose, and our team answers in English at the same contacts as for Italian customers.

The right protection for your company

Share what needs protecting and the risks that concern you: we propose the priorities, including when the current configuration is already adequate.

Talk to an expert

No obligation · A systems engineer replies, not a salesperson

Call Talk to an expert