How MSPs Can Secure RMM Software: Eight Controls to Test

Summary
A sponsored checklist advises MSPs to test eight security controls in remote monitoring and management software, including access restrictions, patching, script governance, tenant separation, incident response and recovery.
Key points
- RMM tools provide unattended administrative access across customer environments, making a compromised account or server a potential route to many downstream devices.
- CISA has warned that ransomware actors abuse legitimate RMM software to access customer networks.
- Test endpoint discovery and risk-based patching, including deployment failures and rollback.
- Verify MFA, least-privilege technician roles, separation of duties and auditable administrative activity.
- Test alert handling, script approvals and execution logs, and whether security integrations preserve context through investigation and remediation.
- Check that recovery restores systems to a secure, updated state and that policies, permissions and records are isolated between client tenants.
- The article recommends testing difficult scenarios, such as an unmanaged device, unauthorized script, compromised test endpoint and recovery after an incident.
Article Details
- Defense Focus
- Test whether MSP remote monitoring and management controls limit privileged-access risk, preserve customer-tenant separation, and support secure recovery.
- Detection Methods
- Introduce a new test device and verify its discovery, classification, and policy assignment.
- Generate duplicate and security-related alerts to assess prioritization and escalation.
- Create and modify test scripts to check approval, auditing, and execution visibility.
- Simulate an incident to test continuity from investigation through containment and recovery.
- Data Sources
- Endpoint, server, network-device, and software inventories
- Patch deployment results and failure records
- Technician activity and access-control audit records
- Script approval and execution logs
- Monitoring alerts and incident records
- Backup validation and recovery-test results
- Defensive Actions
- Prioritize patches by risk, test deployment failures, and verify rollback.
- Enforce multifactor authentication, restricted technician roles, and separation of duties.
- Require approval and auditability for privileged scripts.
- Verify that client policies, permissions, reports, and administrative actions remain isolated.
- Test restores and confirm that recovered systems are secure and fully updated.
MITRE ATT&CK
T1190 · Exploit Public-Facing ApplicationThe article reports exploitation of Microsoft SharePoint "ToolShell" zero-days before patches existed, with at least 85 on-premises servers compromised.T1219 · Remote Access ToolsCISA warned that ransomware actors abuse legitimate RMM software to reach downstream customer networks.
CVE
CVE-2025-53770In July 2025, BleepingComputer covered the Microsoft SharePoint "ToolShell" zero-days (CVE-2025-53770 and CVE-2025-53771), exploited before a patch existed, with at least 85 on-premises servers compromised.CVE-2025-53771In July 2025, BleepingComputer covered the Microsoft SharePoint "ToolShell" zero-days (CVE-2025-53770 and CVE-2025-53771), exploited before a patch existed, with at least 85 on-premises servers compromised.CVE-2026-86218In September 2026, BleepingComputer reported that N-able shipped an emergency hotfix for CVE-2026-86218, a maximum-severity pre-authentication RCE flaw in its N-central RMM platform, its fourth hotfix in five weeks,
Vendors
AcronisSponsored by AcronisMicrosoftIn July 2025, BleepingComputer covered the Microsoft SharePoint "ToolShell" zero-days (CVE-2025-53770 and CVE-2025-53771), exploited before a patch existed, with at least 85 on-premises servers compromised.N-ableIn September 2026, BleepingComputer reported that N-able shipped an emergency hotfix for CVE-2026-86218, a maximum-severity pre-authentication RCE flaw in its N-central RMM platform, its fourth hotfix in five weeks,
Products
Acronis Cyber PlatformAcronis, which delivers RMM as part of Acronis Cyber Platform, built this checklist from securing endpoint management across thousands of customer environments.Acronis EDRNative integration with Acronis EDR and Acronis XDRAcronis RMMSimplify IT management with Acronis RMM.Acronis XDRNative integration with Acronis EDR and Acronis XDRMicrosoft SharePointIn July 2025, BleepingComputer covered the Microsoft SharePoint "ToolShell" zero-days (CVE-2025-53770 and CVE-2025-53771), exploited before a patch existed, with at least 85 on-premises servers compromised.N-centralshipped an emergency hotfix for CVE-2026-86218, a maximum-severity pre-authentication RCE flaw in its N-central RMM platform, its fourth hotfix in five weeks, with roughly 1,500 servers exposed online.