Full Report
RMM platforms give MSPs privileged access across customer environments, making their security controls critical to limiting risk. Acronis outlines eight controls MSPs should test when evaluating RMM software, from patching and privileged access to recovery and tenant isolation. [...]
Analysis Summary
# Best Practices: Securing Remote Monitoring and Management (RMM) Platforms
## Overview
Remote Monitoring and Management (RMM) platforms are high-value targets because they provide administrative "unattended" access to thousands of downstream endpoints. These practices address the risk of "living off the land" attacks, where legitimate management tools are weaponized to deploy ransomware or steal data across multiple customer environments.
## Key Recommendations
### Immediate Actions
1. **Enforce Mandatory MFA:** Enable Multi-Factor Authentication for every technician account without exception.
2. **Audit Public Exposure:** Identify if your RMM server is exposed to the public internet; apply emergency hotfixes (e.g., for RCE flaws like CVE-2026-86218) immediately.
3. **Validate Tenant Isolation:** Perform a "cross-tenant" check to ensure a technician assigned to Client A cannot view or execute scripts on Client B’s infrastructure.
4. **Baseline Inventory:** Run a discovery scan to identify "shadow" endpoints that are not currently under management.
### Short-term Improvements (1-3 months)
1. **Implement RBAC (Role-Based Access Control):** Move away from shared "Admin" accounts. Create granular roles (e.g., "Patch Tech," "Read-Only Auditor") and test that they cannot perform unauthorized actions.
2. **Scripting Governance:** Establish a mandatory two-person approval workflow for creating or modifying automation scripts.
3. **Patch Prioritization:** Configure the RMM to prioritize patches based on exploitability and risk rather than just release date.
4. **Alert De-duplication:** Fine-tune alert thresholds to reduce "noise" and prevent technician fatigue from masking genuine security incidents.
### Long-term Strategy (3+ months)
1. **Unified Security & Recovery:** Integrate RMM with backup solutions to ensure that system restores include automated malware scanning and immediate patching before the system goes live.
2. **Continuous Discovery Loops:** Automate the process where any new device connecting to a client network is automatically classified and assigned a security policy.
3. **Full Auditability:** Establish a centralized logging system that records every command executed via RMM, providing a tamper-proof trail for incident response.
## Implementation Guidance
### For Small Organizations (MSPs)
* **Focus:** Discovery and MFA. Ensure you aren't missing billable/scannable endpoints and secure the "front door" of your management portal.
* **Tactics:** Use built-in RMM templates for basic security policies.
### For Medium Organizations
* **Focus:** Scripting controls and RBAC. As your team grows, the risk of internal error or account takeover increases.
* **Tactics:** Implement a "peer review" process for all new automation scripts before deployment.
### For Large Enterprises
* **Focus:** Integration and Recovery Integrity.
* **Tactics:** Use APIs to feed RMM alerts into a SOC/SIEM. Automate the validation of backups to ensure "clean" restores that are patched against the vulnerability that caused the initial breach.
## Configuration Examples
* **Policy Assignment:** Configure "Auto-Assignment" rules so that any device tagged as "Server" is automatically placed in a high-frequency patching group with mandatory 24-hour reboot cycles.
* **Scripting Restrictions:** Disable the ability for technicians to run "One-Click" PowerShell or Bash commands without a logged ticket number or secondary approval.
## Compliance Alignment
* **NIST CSF:** Aligns with *ID.AM* (Asset Management) and *PR.AC* (Identity Management/Access Control).
* **CIS Controls:** Specifically Control 4 (Secure Configuration of Assets) and Control 5 (Account Management).
* **CISA Advisories:** Follows guidance from AA23-025a regarding the abuse of RMM software.
## Common Pitfalls to Avoid
* **Ignoring Alert Fatigue:** Failing to prune alerts leads to technicians ignoring "Low" or "Medium" warnings that may signal the start of a breach.
* **Unvetted Scripting:** Running community scripts without a code review can introduce vulnerabilities or backdoors.
* **Restoring Vulnerabilities:** Restoring a backup that still contains the unpatched vulnerability that led to the incident, leading to an immediate re-infection.
## Resources
* **CISA RMM Security Guide:** hXXps[://]www.cisa.gov/news-events/cybersecurity-advisories/aa23-025a
* **Acronis Cyber Platform Documentation:** hXXps[://]www.acronis.com/en-us/products/cloud/cyber-protect/rmm-solution/
* **CVE Database:** hXXps[://]cve.mitre.org/ (Search for RMM vendor-specific flaws)