https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • Analytics
    • Artificial Intelligence
    • Cloud
    • Data Centers
    • Desktop
    • IoT
    • Mobility
    • Networking
    • Open Source
    • RMM/PSA
    • Security
    • Virtualization
    • Voice/Connectivity
  • Strategy
    • Back
    • Best Practices
    • Business Models
    • Channel 101
    • Channel Programs
    • Channel Research
    • Digital Transformation
    • Diversity & Inclusion
    • Leadership
    • Mergers and Acquisitions
    • Sales & Marketing
    • Specialty Practices
  • MSSP Insider
    • Back
    • Business of Security
    • Cloud and Edge
    • Endpoint
    • Network
    • People and Careers
    • Training and Policies
  • MSP 501
    • Back
    • 2020 MSP 501 Rankings
    • 2020 Hot 101 Rankings
    • 2020 MSP 501 Report
  • Intelligence
    • Back
    • Our Sponsors
    • From the Industry
    • Content Resources
    • COVID-19 Partner Help
    • Galleries
    • Podcasts
    • Reports
    • Videos
    • Webinars
    • White Papers
  • EMEA
  • Awards
    • Back
    • Excellence in Digital Services
    • 2020 MSP 501
    • Top Gun 51
  • Events
    • Back
    • CP Conference & Expo
    • Channel Partners Evolution
    • Channel Evolution Europe
    • Channel Partners Event Coverage
    • Webinars
  • Channel Mentor
    • Back
    • Channel Market Intelligence
    • Channel Educational Series
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • Analytics
    • Artificial Intelligence
    • Cloud
    • Data Centers
    • Desktop
    • IoT
    • Mobility
    • Networking
    • Open Source
    • RMM/PSA
    • Security
    • Virtualization
    • Voice/Connectivity
  • Strategy
    • Back
    • Best Practices
    • Business Models
    • Channel 101
    • Channel Programs
    • Channel Research
    • Digital Transformation
    • Diversity & Inclusion
    • Leadership
    • Mergers and Acquisitions
    • Sales & Marketing
    • Specialty Practices
  • MSSP Insider
    • Back
    • Business of Security
    • Cloud and Edge
    • Endpoint
    • Network
    • People and Careers
    • Training and Policies
  • MSP 501
    • Back
    • 2020 MSP 501 Rankings
    • 2020 Hot 101 Rankings
    • 2020 MSP 501 Report
  • Intelligence
    • Back
    • Our Sponsors
    • From the Industry
    • Content Resources
    • COVID-19 Partner Help
    • Galleries
    • Podcasts
    • Reports
    • Videos
    • Webinars
    • White Papers
  • EMEA
  • Awards
    • Back
    • Excellence in Digital Services
    • 2020 MSP 501
    • Top Gun 51
  • Events
    • Back
    • CP Conference & Expo
    • Channel Partners Evolution
    • Channel Evolution Europe
    • Channel Partners Event Coverage
    • Webinars
  • Channel Mentor
    • Back
    • Channel Market Intelligence
    • Channel Educational Series
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Digital Service Providers
  • Cloud Service Providers
  • CHANNEL PARTNERS ONLINE
 Channel Futures

Channel Partners Event Coverage


Shutterstock

Risk, Threat, Vulnerability Assessment

RMM Platform Vulnerabilities Proving to Be Devastating to MSPs

  • Written by Edward Gately
  • August 6, 2020
Most MSPs have not added the tools or extra layers of security to know before it is too late.

Cybercriminals are exploiting remote monitoring and management (RMM) platform vulnerabilities to launch ransomware attacks on MSPs and their customers.

Earlier this year, Asigra warned its global network of MSPs about an RMM platform ransomware threat that puts solution provider and end-customer applications and data at high risk. ConnectWise also has been rushing to address RMM vulnerabilities that threaten the company and its MSP customers.

During a Channel Partners Virtual presentation titled “RMM Vulnerabilities that Are Devastating Service Providers,” Sept. 8, Jason Ingalls, CEO of Ingalls Information Security, will lead a panel discussion on the impact of RMM vulnerabilities.

Panelists include: Chris Noles, president of Beyond Computer Solutions; Eric Pinto, senior director of channel and product strategy for SOCSoter; and James Wroten, founder of Need Computer Help.

In a Q&A with Channel Futures, Noles and Pinto give a sneak preview of what they plan to cover during the presentation.

Channel Futures: Why are we seeing so many RMM platform vulnerabilities?

Beyond Computer Solutions' Chris Noles

Beyond Computer Solutions’ Chris Noles

Chris Noles: The attackers know that RMM tools and MSPs have access to multiple businesses if they can exploit the MSP and its RMM tool. It is a turnkey business for them.

Noles and Pinto are two of the dozens of industry speakers who will “take the stage” at Channel Partners Virtual. Our online trade show is Sept. 8-10. Don’t miss out on this one-of-a-kind event. So register now!

Eric Pinto: As a platform, remote management solutions provide threat actors with a direct conduit into dozens – if not hundreds – of small business environments. This makes them ripe for malicious activity. There are any number of reasons why service providers might miss a known or established vulnerability. Much of this is rooted in awareness and having the infrastructure in place to implement remediation strategies quickly. Just because someone reports a vulnerability, it doesn’t mean systems are compromised — yet. However, the clock is ticking. The scenario becomes not if, but when.

CF: Is it almost too late by the time you discover an RMM platform vulnerability?

CN: Without the proper tools to monitor for this, yes. Unfortunately, most MSPs have not added the tools or extra layers of security to know before it is too late.

CF: What sort of damage has occurred and can occur from these types of vulnerabilities?

CN: The worst-case scenario could be catastrophic. If an MSP’s RMM tool gets compromised, the attacker could gain control of an MSP’s RMM console. There, they could remotely log in to every client of that MSP organization and encrypt live data and the backups with ransomware demanding that ransoms be paid for every client. This could put an MSP and all of its clients out of business. Or it could at least create costly downtime, loss of reputation and hundreds of thousands of dollars in legal fees. Unfortunately, there are cases where this has happened to multiple MSPs.

If the case involves a health care client, then Health Insurance Portability and Accountability Act of 1996 (HIPAA) violations could easily cost hundreds of thousands of dollars. We’ve even heard of cases where attackers target patients from health care organizations that a compromised MSP was managing. These patients have been threatened by the attackers to have their medical records published unless a ransom is paid.

SOCSoter's Eric Pinto

SOCSoter’s Eric Pinto

EP: The longer a system’s vulnerabilities persist, the increased risk of compromise. Depending on the severity of the concern, a vulnerability will affect the service provider (internally). But it could also create access downstream into their entire customer portfolio. With or without a data breach, the impact and potential damage to the relationship could be huge. If a security breach results in access to sensitive materials, this could require the service provider to announce publicly exactly what has happened — and their role in the it. The resulting damage to the business may be irrecoverable.

CF: Are there things organizations aren’t doing that they should be doing to protect themselves from these vulnerabilities?

CN: Absolutely. Most MSPs are good about telling their clients to enable multifactor authentication (MFA), but so many of these MSPs don’t …

  • Page 1
  • Page 2
Tags: MSPs Best Practices Business Models Channel Partners Event Coverage Networking RMM/PSA Security Specialty Practices Strategy

Related


  • Cybersecurity Roundup
    Democrats to Take Charge of Federal Cybersecurity in Election Aftermath
    Democrats will have their hands full when dealing with federal cybersecurity.
  • Opportunity Knocks
    SolarWinds MSP President: Rebrand Will 'N-Able' Partner Opportunity
    The "new" name is resurfacing from the high-profile 2013 acquisition of N-able, maker of the N-central software platform.
  • Spinoff Company
    IBM Names CEO of New Managed Services Spinoff
    The former IBM CFO is well-known to those within NewCo.
  • Channel Partners Virtual Banner Header CF
    Don't Wait for Fall's 'Homecoming' Channel Event — CP Virtual 2021 Is Coming Soon
    Content for Channel Partners Virtual doesn't take a backseat to what you get at our live events.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • Pax8 Buys Wirehive as 'Customer of 2030,' Needs Extensive Cloud Help Now
  • Netwrix-Stealthbits Merger Kicks Off 2021 Cybersecurity M&A
  • Today's Dynamic Networks Need a Converged Approach
  • MSP 501 Profile: Monroy IT Services with a Minority's Perspective on the Channel

Galleries

View all

New, Changing Partner Programs: AWS, Tech Data, Avaya, Verizon

January 11, 2021

Industry Perspectives

View all

Help Your Customers Mitigate Malware: Viruses, Worms, and Trojans…Oh My!

January 15, 2021

SMBs’ Cybersecurity Risk Awareness Is Rising

January 13, 2021

Your Cloud Data Is Protected, But Is It Portable?

January 12, 2021

Webinars

View all

Blueprint for a Scalable MSSP Practice in 2021

January 21, 2021

Who’s Behind the Mask? Hacker Personas Explained

January 26, 2021

How Managed Hosting Providers Thrive with the Alternative Cloud

February 24, 2021

White Papers

View all

Why Subscription Business Model

January 15, 2021

The Ultimate MSP Guide to Sales Efficiency

January 14, 2021

Eight Reasons Why MSPs Need IT Industry-Specific Sales Tools

January 14, 2021

Upcoming Events

View all

Channel Partners Virtual

March 2, 2021 - March 4, 2021

Channel Partners Conference & Expo

November 1, 2021 - November 4, 2021

Videos and Fastchats

View all

FASTCHAT: How SOAR Eliminates Security Challenges and Elevates Service Provider Revenues

January 6, 2021

Happy Holidays from Channel Partners & Channel Futures!

December 21, 2020

FASTCHAT: How Old, Unpatched Technologies Are Creating New Security Threats for MSPs and Their Customers

December 3, 2020

Twitter

ChannelFutures

In the latest 'It's 501 Somewhere', @channelsmart (Janet Schijns) talks about what it takes to be a true leader.… twitter.com/i/web/status/1…

January 18, 2021
ChannelFutures

.@IBMServices snaps up #MSP Taos for #hybridcloud expertise. dlvr.it/RqggQR https://t.co/Fy3uPDtLNw

January 16, 2021
ChannelFutures

.@LenovoBusiness launches its thinnest #ThinkPad to date @CES, revamped ThinkBooks and #ThinkReality glasses.… twitter.com/i/web/status/1…

January 16, 2021
ChannelFutures

Help your customers mitigate #malware @Tech_Data #cryptolocker #antivirus #ransomware #cybersecurity… twitter.com/i/web/status/1…

January 15, 2021
ChannelFutures

Advantages of the Subscription business model for MSPs and IT Resellers @kaspersky dlvr.it/RqgDJn https://t.co/ay694fudp3

January 15, 2021
ChannelFutures

Cloud #distributor @Pax8 launches in UK with leadership team in place. dlvr.it/RqfJWx https://t.co/RsKDCowM5V

January 15, 2021
ChannelFutures

bit.ly/3oO2vFY twitter.com/Craig_Galbrait…

January 15, 2021
ChannelFutures

The Ultimate MSP Guide to Sales Efficiency @zomentum dlvr.it/Rqc63q https://t.co/rHIVLkR01K

January 15, 2021

MSSP Insider

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Channel Partners Online

Want more? Find more channel news and analysis on our sister site, Channel Partners.

Media Kit And Advertising

Want to reach our audience? Access our media kit

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Online
  • Channel Partners Events
  • MSP 501
  • MSSP Insider
  • IoT World Today
  • Webhostingtalk

WORKING WITH US

  • Contact
  • About us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2021 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X