Cybersecurity Risks Lurk in Remote Monitoring and Management Software Used by IT Service Providers
A recent spate of high-profile security incidents has highlighted the vulnerabilities inherent in remote monitoring and management (RMM) software used by IT service providers. These platforms, which grant technicians unattended administrative access to thousands of customer devices, have become a prized target for attackers seeking to exploit privileged accounts or servers with far-reaching consequences.
The issue is not just about individual endpoints; it’s about the entire management plane. Compromise one account or server and the blast radius extends far beyond a single device. This was evident in two recent incidents: N-able had to ship an emergency hotfix for a maximum-severity pre-authentication RCE flaw in its N-central RMM platform, which affected around 1,500 servers exposed online. Another incident involving Microsoft SharePoint zero-days demonstrated how quickly customers can be exposed when patching lags behind exploitation.
The US Cybersecurity and Infrastructure Security Agency (CISA) has also warned that ransomware actors are abusing legitimate RMM software to reach downstream customer networks. This makes it essential for IT service providers to understand what happens when an account, endpoint or management workflow is compromised.
To mitigate these risks, IT service providers must test their RMM software against a set of critical controls. Effective RMM platforms should continuously discover and inventory endpoints, servers, network devices, and software assets. For example, introduce a new device into a test environment and assess how quickly it’s discovered, classified, and assigned the correct policy.
Another crucial control is risk-based patch management. Unpatched vulnerabilities remain one of the most common attack paths, so evaluate how the platform prioritizes updates, handles deployment failures, and supports rollback when issues occur. A controlled patch deployment can reveal operational gaps that are easy to miss during a product demo.
Access controls and privileged administration also play a critical role in RMM security. Look for multifactor authentication, role-based access controls, and separation of duties. Create restricted technician roles and verify that users cannot perform actions outside their assigned responsibilities.
Reducing alert noise is another essential aspect of effective RMM management. The challenge is not too few alerts but too many. An RMM platform should provide enough context to help technicians quickly distinguish routine issues from events requiring investigation. Testing duplicate and security-related alerts can help measure whether the platform reduces or contributes to alert fatigue.
Automation, while improving efficiency, also expands risk. Scripts can perform privileged actions across large numbers of devices, making governance critical. MSPs should evaluate approval controls, auditing, and execution visibility by creating and modifying test scripts during evaluation.
Recovery readiness is another often-overlooked aspect of RMM management. Evaluate how backup, patching, remote access, and incident response processes work together after an incident. Recovery testing should include verifying that restored systems return to a secure and fully updated state.
Lastly, strong tenant separation is essential for IT service providers using RMM software. Verify that policies, permissions, reports, and administrative tools are separated between customers, and assess the auditability of these separations.
By implementing these controls and regularly testing their RMM software, IT service providers can mitigate the risks associated with this critical management plane and protect themselves against potential security incidents.
Source: Bleeping Computer — 2026-10-06