How to secure RMM software: 8 controls MSPs should test
Summary
MSPs (Managed Service Providers) rely on RMM (Remote Monitoring and Management) software to access customer environments, making the security of these platforms paramount. Acronis has outlined eight essential security controls that MSPs should rigorously test when evaluating RMM software. These controls focus on critical areas such as patching, privileged access management, recovery capabilities, and tenant isolation to mitigate risks.
IFF Assessment
The article provides guidance on best practices for securing critical IT management tools, which is beneficial for defenders.
Defender Context
RMM software is a high-value target for attackers due to its broad access to client systems. MSPs must diligently assess and implement robust security controls for their RMM solutions, including regular patching, strict access management, and effective tenant isolation, to prevent compromise and protect their customers' data and infrastructure. This focus on securing RMM aligns with broader trends in supply chain security and third-party risk management.