When Your IT Provider Gets Hijacked: What to Ask About RMM Security
William “BJ” Pote
CEO, eTop Technology
In an incident documented in detail by Sophos, a managed service provider got hit in a way that should change how every business thinks about outsourced IT. The attackers didn’t break into the MSP’s office, didn’t crack a password, didn’t phish an employee in the usual sense. They exploited vulnerabilities in SimpleHelp — the remote monitoring and management tool the MSP used to maintain its clients’ computers. Once inside that tool, they pushed malicious installers to the endpoints the MSP managed. Multiple downstream client networks ended up encrypted with DragonForce ransomware.
The MSP didn’t choose to attack its own clients. The MSP was the way in.
This is the supply chain attack pattern that’s been quietly growing for the last few years and accelerating in 2026. Attackers have figured out that compromising one MSP can give them a foothold inside dozens, sometimes hundreds, of small and mid-sized businesses simultaneously. Your firewall didn’t fail. Your email security didn’t fail. Your IT provider’s tools were turned against you.
If you’re a business owner who outsources IT, this is the threat model that should be keeping you up at night, not generic phishing emails.
How the attack actually works
Every managed IT provider uses some form of remote monitoring and management software, commonly called RMM. It’s the tool that lets a technician install updates overnight, troubleshoot a frozen workstation without driving to the office, or push security software to a hundred laptops in one click. RMM agents run with full administrative rights on every machine they touch. That’s the whole point.
Now imagine an attacker getting access to that RMM platform. Not to your server. To the platform that controls thousands of servers, workstations, and laptops across many companies.
The path in is usually one of three:
- A vulnerability in the RMM tool itself. ConnectWise ScreenConnect, SimpleHelp, Kaseya, and others have all had critical authentication or path-traversal vulnerabilities in the last two years. When CISA adds one of these to its Known Exploited Vulnerabilities catalog, it means attackers are already using it in the wild. Patching windows are measured in hours.
- Stolen MSP credentials. A technician’s username and password gets phished, or worse, reused from a breach somewhere else. Once an attacker has those credentials, they don’t need to exploit the tool. They just log in.
- A supply chain compromise inside the RMM vendor. A trojanized software update goes out from the vendor itself. This is what happened to Kaseya in 2021 and what we keep seeing variants of since.
Once inside, the attacker uses the RMM exactly the way a legitimate technician would. They push a script. The script installs ransomware. The ransomware encrypts files. Because the activity came from the trusted RMM agent, traditional endpoint protection often lets it through. The tool that was supposed to be your IT department’s best friend is the delivery vehicle for the attack.
Why this is growing
Three things changed in the last two years and the trend lines are not slowing down.
MSPs are a force multiplier. A criminal group can phish a thousand small businesses one at a time, or it can compromise one MSP and reach a thousand small businesses in an afternoon. The economics favor the second approach.
Most SMBs don’t audit their MSP. Outsourced IT is often a “set it and forget it” relationship. The contract gets signed, the technicians do their job quietly, and nobody at the client side ever asks how the MSP itself is secured. That’s a problem because your security posture is now stapled to your MSP’s security posture, whether you realize it or not.
The tools themselves keep getting found vulnerable. This is not a knock on RMM vendors. They build complex software and complex software has bugs. But it does mean that the tooling underneath your IT support is itself a moving target that needs constant patching and monitoring.
The eight questions to ask your IT provider
If you take nothing else away from this post, take this. Send these to whoever runs your IT. The answers are revealing. Sometimes the silence is more revealing than the answers.
1. What RMM tool do you use, and how do you patch it?
You want to hear a specific product name and a specific cadence. “We use ConnectWise Automate and ScreenConnect. We apply critical patches within twenty-four hours and validate against CISA KEV daily.” If the answer is vague, ask again. If they don’t know which RMM they’re running, you have a bigger problem.
2. Is multifactor authentication required on every technician account in your RMM?
The answer must be yes, with no exceptions for any technician at any time. If they say “most of our techs have it on” or “we’re rolling it out,” you’re at risk today. The gold standard in 2026 is phishing-resistant MFA — FIDO2 security keys, passkeys, or certificate-based authentication. Number matching on push notifications is a worthwhile hardening step against MFA-fatigue attacks, but it isn’t phishing-resistant. SMS codes are not enough.
3. Do you monitor the RMM platform itself for unusual activity?
A good MSP treats its own RMM like a piece of critical infrastructure, not like a productivity tool. They log every script execution, every package push, every remote session. They alert on patterns that look like attacker behavior. They know who logged in last night and from where. If they don’t, the RMM is a black box and attackers love black boxes.
4. What’s your incident response plan if your own RMM is compromised?
This is the question that separates the mature shops from the rest. A good MSP has thought about this and has a documented playbook. They can tell you how they would detect it, how fast they could disconnect agents from affected endpoints, and how they would communicate with clients. If the answer is “well, that’s never happened to us,” push harder. The right answer is “here’s exactly what we’d do.”
5. Are your technicians using their personal email or company email to log into client systems?
You’d be surprised how often the answer is the wrong one. Technician accounts in the RMM should be tied to a managed corporate identity with conditional access policies, not a Gmail account that one of the techs has been using for years.
6. What endpoint detection and response (EDR) tool runs on the machines you manage?
Even if the RMM is compromised, a properly configured EDR can stop the ransomware payload before it runs. Look for products with behavioral detection, not just signature-based antivirus. Microsoft Defender for Business, SentinelOne, CrowdStrike, and Huntress are common answers. The right product matters less than the right configuration and an actual human watching the alerts.
7. Who’s watching the alerts at 2am on a Saturday?
Ransomware attacks happen at 2am on a Saturday because the attackers know that’s when nobody’s watching. The right answer is a 24/7 security operations center, either run by the MSP or contracted to a specialist. Around-the-clock coverage is a real operational investment, which is exactly why it’s worth confirming rather than assuming.
8. Can I see your most recent third-party security audit?
This is the one that ends the conversation politely for shops that have nothing to show. SOC 2 Type II, an annual penetration test, or a CIS Controls assessment is what you’re looking for. It doesn’t have to be perfect. It has to exist.
What to do with the answers
I’ll be direct: we’ve been on the receiving end of these exact questions from prospective clients vetting us before signing a contract, and we think that’s exactly how it should work. A good MSP welcomes the scrutiny — we’ll answer every one of these questions in writing for any client or prospect who asks, and being asked to do it keeps the whole industry honest.
If the answers you get back are incomplete, that doesn’t necessarily mean you need a new provider tomorrow. It means you’ve found the agenda for your next vendor meeting. The threat model has shifted: the “trusted IT vendor” model assumes the vendor is hardened, and in 2026 that’s something to verify, not assume.
A few things you can do on your side of the relationship regardless of who runs your IT:
- Make sure you have your own offsite backups. If the worst happens and your network gets encrypted through your MSP’s tools, the backups your MSP holds may also be encrypted. An immutable backup outside the MSP’s control is the seatbelt for this attack. Our take on the difference between backup and disaster recovery goes deeper on this.
- Carry cyber insurance and read the exclusions. Some policies are starting to exclude or limit coverage for incidents that come through an MSP supply chain unless specific controls are in place. Read the application questions carefully. Make sure the answers on your application are still true today.
- Document who has access to what. If your MSP has an admin account on your firewall, your Microsoft 365 tenant, your file server, and your line-of-business app, you should know that. Quarterly access reviews are not optional.
The bigger picture
The traditional security playbook for small business focused on the perimeter, then on email, then on endpoints. The threats kept finding the next weakest link. In 2026, for businesses that outsource IT, the weakest link is increasingly the IT vendor itself. Not because MSPs are negligent. Because they’re a high-value target with a long blast radius and attackers have noticed.
The good news is that the hardening is achievable. Phishing-resistant MFA on every technician account. Patching the RMM the same week the patch comes out, not the same quarter. Real-time monitoring of the RMM platform. EDR on the endpoints with humans watching the alerts. A documented incident response plan that includes “what if it’s us.” This is the standard a serious MSP holds itself to in 2026.
If you’re not sure where you stand, the answer isn’t to panic. The answer is to ask the questions above, get real answers, and act on what you learn.
We work with businesses across the Inland Empire, and we’re happy to answer every one of these eight questions about our own setup — that’s table stakes. If you want a second opinion on how your current environment would hold up against the attack pattern described above, book an intro call — qualifying businesses receive our $2,500 IT Risk Assessment complimentary. We’ll walk through your environment and your exposure honestly. No sales pitch until you’ve seen the findings.
William “BJ” Pote
CEO, eTop Technology
eTop Technology has spent over 15 years in IT and over 12 years serving the Inland Empire as a trusted managed IT provider. We host the Business Tech Playbook podcast and are passionate about helping business leaders make smarter technology decisions.