https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2022 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Channel Partners 101 (CP 101)
  • Events
    • Back
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2022 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Channel Partners 101 (CP 101)
  • Events
    • Back
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

Channel Partners Event Coverage


Shutterstock

Risk, Threat, Vulnerability Assessment

RMM Platform Vulnerabilities Proving to Be Devastating to MSPs

  • Written by Edward Gately
  • August 6, 2020
Most MSPs have not added the tools or extra layers of security to know before it is too late.

Cybercriminals are exploiting remote monitoring and management (RMM) platform vulnerabilities to launch ransomware attacks on MSPs and their customers.

Earlier this year, Asigra warned its global network of MSPs about an RMM platform ransomware threat that puts solution provider and end-customer applications and data at high risk. ConnectWise also has been rushing to address RMM vulnerabilities that threaten the company and its MSP customers.

During a Channel Partners Virtual presentation titled “RMM Vulnerabilities that Are Devastating Service Providers,” Sept. 8, Jason Ingalls, CEO of Ingalls Information Security, will lead a panel discussion on the impact of RMM vulnerabilities.

Panelists include: Chris Noles, president of Beyond Computer Solutions; Eric Pinto, senior director of channel and product strategy for SOCSoter; and James Wroten, founder of Need Computer Help.

In a Q&A with Channel Futures, Noles and Pinto give a sneak preview of what they plan to cover during the presentation.

Channel Futures: Why are we seeing so many RMM platform vulnerabilities?

Beyond Computer Solutions' Chris Noles

Beyond Computer Solutions’ Chris Noles

Chris Noles: The attackers know that RMM tools and MSPs have access to multiple businesses if they can exploit the MSP and its RMM tool. It is a turnkey business for them.

Noles and Pinto are two of the dozens of industry speakers who will “take the stage” at Channel Partners Virtual. Our online trade show is Sept. 8-10. Don’t miss out on this one-of-a-kind event. So register now!

Eric Pinto: As a platform, remote management solutions provide threat actors with a direct conduit into dozens – if not hundreds – of small business environments. This makes them ripe for malicious activity. There are any number of reasons why service providers might miss a known or established vulnerability. Much of this is rooted in awareness and having the infrastructure in place to implement remediation strategies quickly. Just because someone reports a vulnerability, it doesn’t mean systems are compromised — yet. However, the clock is ticking. The scenario becomes not if, but when.

CF: Is it almost too late by the time you discover an RMM platform vulnerability?

CN: Without the proper tools to monitor for this, yes. Unfortunately, most MSPs have not added the tools or extra layers of security to know before it is too late.

CF: What sort of damage has occurred and can occur from these types of vulnerabilities?

CN: The worst-case scenario could be catastrophic. If an MSP’s RMM tool gets compromised, the attacker could gain control of an MSP’s RMM console. There, they could remotely log in to every client of that MSP organization and encrypt live data and the backups with ransomware demanding that ransoms be paid for every client. This could put an MSP and all of its clients out of business. Or it could at least create costly downtime, loss of reputation and hundreds of thousands of dollars in legal fees. Unfortunately, there are cases where this has happened to multiple MSPs.

If the case involves a health care client, then Health Insurance Portability and Accountability Act of 1996 (HIPAA) violations could easily cost hundreds of thousands of dollars. We’ve even heard of cases where attackers target patients from health care organizations that a compromised MSP was managing. These patients have been threatened by the attackers to have their medical records published unless a ransom is paid.

SOCSoter's Eric Pinto

SOCSoter’s Eric Pinto

EP: The longer a system’s vulnerabilities persist, the increased risk of compromise. Depending on the severity of the concern, a vulnerability will affect the service provider (internally). But it could also create access downstream into their entire customer portfolio. With or without a data breach, the impact and potential damage to the relationship could be huge. If a security breach results in access to sensitive materials, this could require the service provider to announce publicly exactly what has happened — and their role in the it. The resulting damage to the business may be irrecoverable.

CF: Are there things organizations aren’t doing that they should be doing to protect themselves from these vulnerabilities?

CN: Absolutely. Most MSPs are good about telling their clients to enable multifactor authentication (MFA), but so many of these MSPs don’t …

  • Page 1
  • Page 2
Tags: MSPs Best Practices Business Models Channel Partners Event Coverage Networking RMM/PSA Security Specialty Practices Strategy

Most Recent


  • Black Hat expo hall 2022
    The Gately Report: Black Hat USA Edition with Cisco, IBM, CISA, More
    Black Hat USA has come roaring back since the COVID-19 pandemic.
  • Making Waves
    7 Channel People Making Waves This Week at Microsoft, Rackspace, RingCentral, Avaya
    Hackers targeted one UCaaS firm by impersonating the company's IT department.
  • Welcome Mat
    Okta Names Splunk Vet New Global Channel Chief
    Okta's global channel chief left the company in June.
  • Mergers acquisitions m&a goldfish crackers
    Latest M&A: IBM, Vonage, Nokia, GoTo, Nitel, Ensono, Huntress, More
    One cybersecurity company's $22 million July acquisition was its largest to date.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • people in masks, we miss your face
    Channel Partners Conference & Expo 2021 Preview: We’ve Missed Your Faces!
  • MSP 501 logo
    Don't Wait to Get Ranked Among the Best MSPs in the World
  • Channel Partners circa 2006
    Flashback Friday: Images from the Last 20 Years in the Channel
  • IMB splitting
    5 Hot Stories: Zoom, VMware Challenged in Market Share

Upcoming Events

View all

MSP Summit

September 13, 2022 - September 16, 2022

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Galleries

View all

The Gately Report: Black Hat USA Edition with Cisco, IBM, CISA, More

August 12, 2022

7 Channel People Making Waves This Week at Microsoft, Rackspace, RingCentral, Avaya

August 12, 2022

Oracle Cloud & AT&T, AWS Lead Cloud News Roundup

August 12, 2022

Industry Perspectives

View all

How to Take Shared Responsibility for Securing Cloud

August 11, 2022

Seize the Application Modernization Opportunity

August 2, 2022

A Growth Mindset: Your Organization’s Strategic Differentiator

August 1, 2022

Webinars

View all

Outsmarting RaaS: Implementation Strategies To Help Your Clients Before, During, and After a Ransomware Attack

August 23, 2022

Why it is Important to Upgrade Aging Servers and How to use Live Optics to Upgrade Efficiently

August 25, 2022

Executives at Home are Not Alright: An Intro to Digital Executive Protection

September 8, 2022

White Papers

View all

Work Goes Remote – (and Other Top ITOps Trends)

May 25, 2022

The New Bottom Line: How MSPs Can Meet the Healthcare Crisis While Evolving Their Businesses

April 19, 2022

How to build a Security Operations Center (on a budget)

April 4, 2022

Channel Futures TV

View all

ThreatLocker Preaches Zero Trust, Addresses Industry Competition

ScienceLogic Debuts New Partner Portal

August 9, 2022

Vonage a ‘Single Communications Stack Provider’ for Partners, Customers

June 27, 2022

IBM, Partners and the $1 Trillion Hybrid Cloud Opportunity

June 26, 2022

Twitter

ChannelFutures

.@splunk vet Bill Hustad named @Okta's new #channelchief. dlvr.it/SWXmws https://t.co/ILQesul0Cz

August 12, 2022
ChannelFutures

The Gately Report: #BHUSA edition with @Hacker0x01, @Cisco, @SaltSecurity, @CISAgov, @ExtraHop, @IBMSecurity, more.… twitter.com/i/web/status/1…

August 12, 2022
ChannelFutures

Channel People Making Waves Include: @kencarnesi, @szebenisz, @vasujakkal, @brettsmith52, @DaveMichels… twitter.com/i/web/status/1…

August 12, 2022
ChannelFutures

Nancy Henriquez, VP of Sales & Marketing at MSP 501 award-winning @synetek, touches on the importance of gathering… twitter.com/i/web/status/1…

August 12, 2022
ChannelFutures

.@Equinix's new hire is a familiar face in the telco channel. dlvr.it/SWXV6v https://t.co/jIg0LrZ4DO

August 12, 2022
ChannelFutures

Missed the news this week from @OracleCloud and @ATTBusiness? We've got it here. Plus, news from @AWSCloud and… twitter.com/i/web/status/1…

August 12, 2022
ChannelFutures

Huge channel-impacting acquisitions in the past month. We've got details on @IBM, @nokia, @GoTo, @EnsonoIT,… twitter.com/i/web/status/1…

August 12, 2022
ChannelFutures

Boost privacy by design with #shiftleft mindset and add #security to cloud deployments from start, says… twitter.com/i/web/status/1…

August 12, 2022

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2022 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X