The MSP as Attack Vector: Understanding and Preventing Supply Chain Attacks

Share this post on:

Key Takeaway: The MSP is not just a target. It is a vector. A single breach of an MSP can compromise every client simultaneously. The MSP that holds clients to security standards it does not apply to itself is a liability to every client it manages. Apply the same controls to your own infrastructure that you require of your clients.

The MSP is not just a target. It is a vector. A breach of a managed service provider does not compromise one business. It compromises every business that MSP manages. This is the supply chain attack problem, and it is the reason that MSPs have become one of the most attractive targets for sophisticated threat actors in 2026.

The SolarWinds attack of 2020 demonstrated the model at scale: compromise the software that IT providers use, and you gain access to thousands of organizations simultaneously. The lesson has not been forgotten by attackers. It has been refined. The MSP supply chain attack is now a documented, repeatable playbook that threat actors execute against providers of every size.

Why MSPs Are High-Value Targets

The economics of attacking an MSP are straightforward. A single MSP with 50 clients represents 50 potential breach targets accessible through one set of credentials. The attacker who compromises an MSP’s RMM tool, PSA, or remote access infrastructure does not need to breach each client individually. They have access to all of them simultaneously.

The specific attack surfaces that make MSPs attractive targets:

RMM tools. Remote monitoring and management platforms have privileged access to every endpoint under management. An attacker who gains access to an MSP’s RMM console can deploy malware, exfiltrate data, or disable security controls across the entire client base. The 2021 Kaseya VSA attack demonstrated this at scale, affecting hundreds of MSPs and thousands of their clients simultaneously.

PSA systems. Professional services automation platforms contain client credentials, network documentation, and contact information for every client. An attacker with access to an MSP’s PSA has a roadmap to every client environment.

Remote access tools. The tools MSPs use to provide remote support, ScreenConnect, TeamViewer, AnyDesk, and similar platforms, are persistent access mechanisms. An attacker who compromises these tools has the same access the MSP’s technicians have.

Email and identity. MSP technicians receive password reset requests, security alerts, and access requests from clients. An attacker who compromises an MSP technician’s email or identity can intercept those requests and use them to gain access to client environments.

The MSP’s Own Security Posture

The uncomfortable reality is that many MSPs hold their clients to security standards they do not apply to themselves. The MSP that requires clients to have MFA on all accounts, EDR on all endpoints, and documented incident response plans should have all of those things in their own environment. Many do not.

The CISA advisory on protecting against cyber threats to MSPs is explicit: MSPs must apply the same security controls to their own infrastructure that they recommend to clients. This includes MFA on all remote access, privileged access management for administrative tools, network segmentation between the MSP’s internal environment and client environments, and regular security assessments of the MSP’s own infrastructure.

The MSP that cannot pass the same security assessment it administers to clients is a liability to every client it manages.

The Specific Controls That Matter

MFA on everything. Every account with access to client environments must have MFA enforced. This includes RMM consoles, PSA systems, remote access tools, email, and any other platform that provides access to client data or infrastructure. No exceptions. The technician who disables MFA for convenience is creating an attack surface that affects every client.

Privileged access management. Administrative access to client environments should be time-limited, logged, and reviewed. Standing admin credentials that never expire are a persistent attack surface. Just-in-time access, where administrative privileges are granted for a specific task and revoked when the task is complete, significantly reduces the window of exposure.

Network segmentation. The MSP’s internal network should be segmented from client environments. A breach of the MSP’s internal network should not automatically provide access to client environments. This requires deliberate architecture, not just good intentions.

Vendor security assessment. Every tool in the MSP’s stack is a potential attack vector. The MSP should assess the security practices of its major vendors, including RMM, PSA, backup, and remote access providers. Vendor security questionnaires, SOC 2 reports, and penetration test results are the evidence that a vendor takes security seriously.

Incident response plan for the MSP itself. The MSP that has an incident response plan for client breaches but not for its own breach is not prepared. The plan should address: how to detect a breach of the MSP’s own infrastructure, how to notify clients, how to contain the breach, and how to restore operations. This plan should be tested, not just written.

What to Tell Clients

Clients increasingly ask about MSP security practices. The question “how do you protect your own environment?” is a legitimate due diligence question, and the MSP that cannot answer it specifically is not inspiring confidence.

The honest answer includes: the specific security controls the MSP applies to its own infrastructure, the results of the MSP’s most recent security assessment, the MSP’s incident response plan for a breach of its own systems, and the notification process the MSP would follow if its own infrastructure were compromised.

The MSP that can answer those questions specifically and honestly is demonstrating the kind of operational maturity that clients should require from their IT provider. The MSP that deflects or provides vague answers is telling clients something important about how seriously it takes its own security.

The Cyber Insurance Dimension

Cyber insurance carriers are increasingly scrutinizing MSP security practices as a condition of coverage. An MSP that suffers a breach because it did not apply basic security controls to its own infrastructure may find that its insurance claim is denied on the grounds that the breach was preventable.

The MSP attestation letter, which certifies the security posture of a client’s environment to the client’s insurance carrier, creates a parallel obligation: the MSP should be able to certify its own security posture to its own insurance carrier. The MSP that cannot do so is carrying uninsured risk.

Frequently Asked Questions

What is an MSP supply chain attack?

An MSP supply chain attack is a cyberattack that targets a managed service provider in order to gain access to the MSP’s clients. By compromising the tools and infrastructure the MSP uses to manage client environments, attackers can access multiple organizations simultaneously. The Kaseya VSA attack in 2021 and the SolarWinds attack in 2020 are the most prominent examples.

How do I know if my MSP has been compromised?

Signs of MSP compromise include: unusual activity in your RMM or PSA console, unexpected changes to user accounts or security settings, alerts from your EDR about unusual processes or network connections, and communication from your MSP about a security incident. The MSP that detects and discloses a breach promptly is demonstrating the kind of operational maturity that protects clients. The MSP that discovers a breach through a client complaint is not.

What should I ask my MSP about their own security?

Ask whether they have MFA enforced on all accounts with access to your environment. Ask when they last had a security assessment of their own infrastructure. Ask what their incident response plan is if their own systems are compromised. Ask whether they carry cyber insurance and what it covers. The answers will tell you whether your MSP is applying the same standards to itself that it applies to you.

About Brent Lacy: Brent Lacy is a technology advisor and the voice behind Rewired MSP. He helps MSPs operate with greater maturity and helps business owners make IT choices that make them more secure and more efficient. He is the author of Rewired MSP: Mastery, Scalability & Performance, vCIO Rewired: Virtually Conquering IT Obstacles, and Near Miss: Preventable IT Failures Threatening Your Business Security.

Related Reading

Sources

Author: Brent Lacy

Brent Lacy is the founder of Rewired MSP and author of three books on managed services, vCIO strategy, and cybersecurity. He helps MSP owners build trust-based, scalable businesses through documented processes, strategic leadership, and client-first culture.

View all posts by Brent Lacy >

Leave a Reply