How MSPs Can Secure RMM Software: Eight Controls to Test

· Original article ↗

Summary

A sponsored checklist advises MSPs to test eight security controls in remote monitoring and management software, including access restrictions, patching, script governance, tenant separation, incident response and recovery.

Key points

  • RMM tools provide unattended administrative access across customer environments, making a compromised account or server a potential route to many downstream devices.
  • CISA has warned that ransomware actors abuse legitimate RMM software to access customer networks.
  • Test endpoint discovery and risk-based patching, including deployment failures and rollback.
  • Verify MFA, least-privilege technician roles, separation of duties and auditable administrative activity.
  • Test alert handling, script approvals and execution logs, and whether security integrations preserve context through investigation and remediation.
  • Check that recovery restores systems to a secure, updated state and that policies, permissions and records are isolated between client tenants.
  • The article recommends testing difficult scenarios, such as an unmanaged device, unauthorized script, compromised test endpoint and recovery after an incident.

Article Details

Defense Focus
Test whether MSP remote monitoring and management controls limit privileged-access risk, preserve customer-tenant separation, and support secure recovery.
Detection Methods
  • Introduce a new test device and verify its discovery, classification, and policy assignment.
  • Generate duplicate and security-related alerts to assess prioritization and escalation.
  • Create and modify test scripts to check approval, auditing, and execution visibility.
  • Simulate an incident to test continuity from investigation through containment and recovery.
Data Sources
  • Endpoint, server, network-device, and software inventories
  • Patch deployment results and failure records
  • Technician activity and access-control audit records
  • Script approval and execution logs
  • Monitoring alerts and incident records
  • Backup validation and recovery-test results
Defensive Actions
  • Prioritize patches by risk, test deployment failures, and verify rollback.
  • Enforce multifactor authentication, restricted technician roles, and separation of duties.
  • Require approval and auditability for privileged scripts.
  • Verify that client policies, permissions, reports, and administrative actions remain isolated.
  • Test restores and confirm that recovered systems are secure and fully updated.

MITRE ATT&CK

CVE

Vendors

Products

Industries

Related Articles