Managed Service Providers (MSPs) rely on remote monitoring and management (RMM) software to maintain unattended administrative access across thousands of customer devices. This high level of privilege makes the management plane an attractive target for adversaries. Compromising a single administrative account or server can drastically expand an attacker’s blast radius beyond a single endpoint, turning trusted management tooling into a vector for wide-scale compromise. According to BleepingComputer, assessing RMM security requires testing concrete operational outcomes rather than relying on a vendor’s feature list.
Recent incidents demonstrate the severe risks associated with management plane vulnerabilities. For instance, CVE-2026-86218 forced N-able to ship an emergency hotfix for a maximum-severity pre-authentication remote code execution flaw in its N-central RMM platform, leaving approximately 1,500 servers exposed online. This followed multiple rapid patches within a five-week window. Similarly, the Microsoft SharePoint ToolShell zero-days (CVE-2025-53770 and CVE-2025-53771) compromised at least 85 on-premises servers before patches existed. Furthermore, the Cybersecurity and Infrastructure Security Agency (CISA) has repeatedly warned that ransomware groups actively abuse legitimate RMM tools to pivot into downstream customer networks. MSPs must therefore evaluate how their tooling handles account compromises, infrastructure visibility, and incident containment.
## Evaluating RMM Security Controls and Testing Methodologies
To ensure operational resilience, security teams should test eight critical controls during RMM platform evaluation and deployment:
- Asset Discovery: An organization cannot secure devices it cannot see. Platforms should continuously discover and inventory endpoints, servers, network devices, and software assets. Introduce test devices into an isolated environment to measure how quickly the RMM platform discovers, classifies, and assigns appropriate security policies.
- Automated Patch Management: Unpatched software remains a primary initial access vector. Evaluate how the platform prioritizes updates, handles deployment failures, and supports rollbacks when updates break functionality.
- Privileged Access Management: Technician accounts require strict protections. Verify the implementation of multifactor authentication, role-based access controls, and strict separation of duties to ensure users cannot perform actions outside their assigned operational scope.
- Alert Noise Reduction: High alert volumes contribute directly to operator fatigue. Test how well the platform provides sufficient context to distinguish routine telemetry from actual security incidents.
- Scripting Governance: Automation improves efficiency but introduces substantial risk. Evaluate execution visibility, approval workflows, and auditing by introducing test scripts during evaluation.
- Workflow Integration: Operational and security workflows should function seamlessly. Technicians must be able to transition from detection to investigation, containment, and recovery without losing contextual data.
- Recovery and Backup Validation: Security encompasses recovery as much as prevention. Verify that restored systems return to a fully patched and secure state, utilizing integrated anti-malware scanning where available to validate recovery points.
- Tenant Separation: In multi-tenant environments, strict isolation of permissions, policies, reports, and administrative actions is vital to prevent cross-contamination between client environments.
Prioritising Remediation and Risk Mitigation
Defenders must audit their exposure to internet-facing management interfaces immediately. Ensuring that RMM servers are never exposed directly to the public internet without adequate zero-trust network access or VPN controls is critical. Organizations should also review active technician sessions, enforce strict multifactor authentication policies, and validate that audit logs are shipped to an immutable external storage location for continuous monitoring. By rigorously testing these eight controls, MSPs can significantly reduce their attack surface and prevent management platforms from becoming entry points for sophisticated threat actors.
Related: Frontier AI and Autonomous Zero-Day Discovery in Open-Source Software, AI Agents Break Sandbox Boundaries in Third-Party Cyber Tests