IT administrator securing RMM software dashboard with security controls and multi-tenant management interface

Securing RMM Software: 8 Critical Controls MSPs Must Test

Why Securing RMM Software Is Critical for MSPs in 2026

Securing RMM software has become one of the most pressing concerns for Managed Service Providers (MSPs) operating in today’s threat landscape. Remote Monitoring and Management platforms grant privileged access across multiple customer environments, making them high-value targets for cybercriminals. When attackers compromise an RMM solution, they don’t just breach one organisation—they potentially gain access to every client connected to that platform.

A new report from Acronis has outlined eight essential security controls that MSPs must rigorously test when evaluating or auditing their RMM software. This guidance arrives as threat actors increasingly target the supply chain, recognising that compromising a single MSP can yield access to hundreds of downstream businesses.

Source: BleepingComputer – How to secure RMM software: 8 controls MSPs should test

What Happened: Acronis Releases RMM Security Framework

On October 6, 2026, cybersecurity vendor Acronis published detailed guidance aimed at helping MSPs strengthen their RMM platform security posture. The framework identifies eight specific controls that should be tested and validated before deploying or continuing to use any RMM solution.

This guidance responds to a concerning trend: RMM platforms have been exploited in numerous high-profile attacks over the past several years. Threat actors recognise that these tools provide legitimate administrative capabilities—including remote code execution, file transfers, and system configuration changes—that become devastating weapons when misused.

The framework emphasises that MSPs bear responsibility not only for their own security but for the security of every organisation they serve. A single vulnerability in an RMM platform can cascade into a multi-tenant breach affecting dozens or hundreds of businesses.

The Eight Essential RMM Security Controls Explained

Acronis has identified eight critical areas that MSPs must evaluate when securing RMM software. Each control addresses a specific attack vector that threat actors commonly exploit.

1. Patch Management and Update Controls

RMM platforms must have robust mechanisms for receiving and applying security patches. MSPs should verify that their vendor provides timely updates and that the platform supports automated patching without service disruption.

2. Privileged Access Management

Privileged access controls determine who can perform administrative actions within the RMM platform. Essential features include:

  • Role-based access control (RBAC) with granular permissions
  • Just-in-time (JIT) access provisioning
  • Multi-factor authentication (MFA) enforcement for all administrative accounts
  • Session recording and audit logging

3. Tenant Isolation

Multi-tenant RMM platforms must maintain strict isolation between customer environments. A compromise in one tenant should never allow lateral movement to another. MSPs should test whether the platform enforces proper data segregation at the infrastructure level.

4. Recovery and Resilience Capabilities

When incidents occur, MSPs need the ability to rapidly restore RMM functionality. The platform should support:

  • Automated backup of configurations and policies
  • Disaster recovery procedures with defined RTOs and RPOs
  • The ability to quickly revoke compromised credentials across all managed endpoints

5. Network Security Controls

Communication channels between the RMM platform, MSP infrastructure, and managed endpoints must be secured. This includes encryption in transit, certificate pinning, and the ability to restrict connections to known IP ranges.

6. Logging and Monitoring

Comprehensive audit trails are essential for detecting suspicious activity. The platform should log all administrative actions, authentication attempts, and configuration changes with sufficient detail for forensic analysis.

7. API Security

Many RMM platforms expose APIs for integration with other tools. These interfaces must be secured with proper authentication, rate limiting, and input validation to prevent abuse.

8. Endpoint Agent Security

The agents deployed to managed endpoints represent a potential attack surface. MSPs should verify that agents use signed binaries, support tamper protection, and can be remotely disabled if compromised.

How Does RMM Compromise Impact Businesses?

When threat actors successfully compromise an RMM platform, the consequences extend far beyond the MSP itself. The business impact can be catastrophic for all connected organisations.

Ransomware deployment at scale represents the most common outcome of RMM compromises. Attackers use the legitimate remote access capabilities to push ransomware to every managed endpoint simultaneously, bypassing traditional security controls that would flag unknown remote access tools.

Data exfiltration becomes trivially easy when attackers control the RMM platform. They can silently extract sensitive information from multiple organisations without triggering network-based detection mechanisms.

The financial implications are severe:

  1. Direct costs from incident response, legal fees, and regulatory fines
  2. Reputational damage that can destroy an MSP’s business entirely
  3. Liability exposure from affected clients seeking compensation
  4. Increased insurance premiums or loss of cyber insurance coverage

For Australian businesses, these incidents may also trigger mandatory notification requirements under the Notifiable Data Breaches (NDB) scheme, adding regulatory complexity to an already challenging situation.

Actionable Recommendations for MSPs

Securing RMM software requires a systematic approach that addresses both technical controls and operational procedures. MSPs should implement the following measures immediately:

Conduct a Comprehensive RMM Security Audit

Evaluate your current RMM platform against all eight controls outlined by Acronis. Document any gaps and create a remediation plan with specific timelines. If you need assistance with this process, consider engaging OziTechs’ vulnerability management services for an independent assessment.

Implement Zero Trust Architecture

Adopt a zero trust approach where every access request is verified regardless of source. This includes:

  • Implementing MFA for all RMM platform access
  • Segmenting network access based on least privilege principles
  • Continuously validating device health before granting access

Establish Incident Response Procedures

Develop and regularly test incident response plans specifically addressing RMM compromise scenarios. Ensure you can rapidly revoke access and isolate affected systems across all customer environments.

Review Vendor Security Practices

Request security documentation from your RMM vendor, including SOC 2 reports, penetration test results, and their vulnerability disclosure policies. A vendor unwilling to provide this information should raise immediate concerns.

Frequently Asked Questions

What is RMM software and why is it a security risk?

RMM (Remote Monitoring and Management) software enables MSPs to remotely access, monitor, and manage client systems. It becomes a security risk because it provides privileged access across multiple environments—if compromised, attackers can leverage these legitimate capabilities to deploy malware, steal data, or disrupt operations across all connected organisations simultaneously.

How can MSPs protect their RMM platforms from attacks?

MSPs should implement the eight controls outlined by Acronis: robust patch management, privileged access controls, tenant isolation, recovery capabilities, network security, comprehensive logging, API security, and endpoint agent protection. Regular security audits and penetration testing are also essential to identify vulnerabilities before attackers do.

What should businesses ask their MSP about RMM security?

Businesses should ask their MSP about the specific RMM platform used, what security controls are in place, how access is authenticated and logged, whether tenant isolation is enforced, and what incident response procedures exist if the platform is compromised. Request documentation of recent security assessments or certifications.

Key Takeaways

  • RMM platforms are high-value targets that provide attackers access to multiple organisations through a single compromise
  • Acronis has identified eight essential security controls MSPs must test and validate
  • Privileged access management, tenant isolation, and recovery capabilities are critical focus areas
  • Australian businesses face regulatory obligations under the NDB scheme if breaches occur
  • Regular security audits and vendor assessments should be standard practice

Conclusion: Prioritise RMM Security Now

Securing RMM software is no longer optional—it’s a fundamental requirement for any MSP operating responsibly in today’s threat environment. The eight controls outlined by Acronis provide a clear framework for evaluating and strengthening your RMM security posture.

MSPs that fail to address these risks expose not only themselves but every client they serve to potentially devastating attacks. The cascading nature of RMM compromises means that a single security failure can result in hundreds of simultaneous breaches.

Don’t wait for an incident to force action. If you’re uncertain about your RMM platform’s security posture or need help implementing these controls, speak with our security team at OziTechs. Our Australian-based cybersecurity consultants can help you assess your current environment and develop a comprehensive security strategy that protects both your business and your clients.

Tagged , , , , , .