How to secure RMM software: 8 controls MSPs should test

Cybersecurity professionals have been sounding the alarm about the vulnerability of remote monitoring and management (RMM) software for some time now. These platforms, used by managed service providers (MSPs) to manage thousands of customer devices, are a prime target for attackers due to their privileged access capabilities. Recent incidents have highlighted the risks associated with compromised RMM software, including data breaches, ransomware attacks, and unauthorized access to sensitive systems.

The problem lies in the fact that RMM software provides unattended administrative access across multiple devices, making it an attractive target for attackers. A single compromised account or server can lead to a significant blast radius, affecting not just individual endpoints but also entire customer networks. For instance, in September 2026, BleepingComputer reported that N-able shipped an emergency hotfix for CVE-2026-86218, a maximum-severity pre-authentication remote code execution (RCE) flaw in its N-central RMM platform. This vulnerability had exposed around 1,500 servers online.

Another incident in July 2025 demonstrated the risks of exploiting zero-day vulnerabilities in Microsoft SharePoint. The “ToolShell” zero-days (CVE-2025-53770 and CVE-2025-53771) were exploited before a patch existed, with at least 85 on-premises servers compromised. One attack targeted the management plane, while the other showed how quickly customers are exposed when patching lags behind exploitation.

To mitigate these risks, MSPs need to ensure their RMM software is secure and effective in protecting customer data. This requires testing and validation of key security controls, which we will explore below.

So, what should every MSP be looking for in their RMM platform? According to Acronis, a leading provider of cybersecurity solutions, including RMM as part of its Cyber Platform, there are eight essential controls that must be tested:

Firstly, endpoint discovery and inventory is crucial. An effective RMM platform should continuously discover and inventory endpoints, servers, network devices, and software assets. During evaluation, introduce a new device into a test environment to assess how quickly it is discovered, classified, and assigned the correct policy.

Secondly, risk-based patch management is vital. Unpatched vulnerabilities remain one of the most common attack paths. Evaluate how the platform prioritizes updates, handles deployment failures, and supports rollback when issues occur. A controlled patch deployment can reveal operational gaps that might be easy to miss during a product demo.

Thirdly, access controls and privileged administration are critical. RMM security depends heavily on the security of technician accounts. Look for multifactor authentication, role-based access controls, and separation of duties. Create restricted technician roles and verify that users cannot perform actions outside their assigned responsibilities.

Fourthly, alert prioritization and operational visibility are essential. The challenge is not too few alerts but too many. An RMM platform should provide enough context to help technicians quickly distinguish routine issues from events requiring investigation. Testing duplicate and security-related alerts can help measure whether the platform reduces or contributes to alert fatigue.

Lastly, recovery readiness is just as important as prevention. Evaluate how backup, patching, remote access, and incident response processes work together after an incident. Recovery testing should include verifying that restored systems return to a secure and fully updated state.

In conclusion, MSPs cannot afford to underestimate the risks associated with compromised RMM software. By testing these eight essential controls, they can ensure their platform is secure and effective in protecting customer data. Remember, security is not just about prevention but also recovery.


Source: Bleeping Computer — 2026-10-06