8 Key Controls for Securing RMM Software in MSPs
Remote monitoring and management (RMM) software is a critical but vulnerable component of managed service providers’ (MSPs) infrastructure. Effective RMM tools should enable endpoint discovery, automate patching, control privileged access, reduce alert noise, contain incidents, protect recovery points, ensure tenant separation, and provide auditability. Acronis, which offers RMM as part of its Cyber Platform, has developed a checklist for securing RMM software based on its experience across thousands of customer environments. MSPs should evaluate RMM tools based on these outcomes rather than just feature lists. RMM software is a prime target for attackers due to its broad administrative access across customer devices. Recent incidents, such as vulnerabilities in N-able’s N-central RMM platform and Microsoft SharePoint zero-days, highlight the risks. CISA has also warned about ransomware actors abusing RMM software to access downstream networks. The article outlines eight essential controls for MSPs to test, including endpoint discovery, risk-based patch management, access controls, alert prioritization, secure automation, integration with security operations, recovery readiness, and tenant separation. Each control is designed to address specific security gaps and operational risks. Acronis’ RMM software integrates these capabilities into a unified platform, reducing the need for separate tools and streamlining workflows. The article emphasizes the importance of testing these controls in real-world scenarios to ensure they reduce operational risk as MSPs manage more endpoints.
Read the full article
Continue reading at BleepingComputer →This is an AI-generated summary. Read the original for the full story.