Secure RMM Software: 8 Controls Every MSP Should Test
Secure remote monitoring and management (RMM) software helps managed service providers (MSPs) discover endpoints, automate patching, control privileged access, reduce alert fatigue, contain incidents, protect recovery points, isolate customer tenants, and document administrative activity.
Acronis, which offers RMM through the Acronis Cyber Platform, created this checklist for evaluating endpoint management security across thousands of customer environments.
MSPs comparing RMM tools should validate these capabilities in a test environment instead of choosing a platform based only on the length of its feature list.
Why RMM is part of the MSP attack surface
RMM platforms provide technicians with unattended management access to thousands of customer devices. That makes the management plane a valuable target for attackers. If a privileged account or RMM server is compromised, the impact can extend far beyond a single endpoint.
Two incidents illustrate the risk. In September 2026, BleepingComputer reported that N-able shipped an emergency hotfix for CVE-2026-86218, a maximum-severity pre-authentication remote code execution flaw in the N-central RMM platform. It was the fourth hotfix in five weeks, and approximately 1,500 servers were exposed online.
In July 2025, BleepingComputer covered the Microsoft SharePoint “ToolShell” zero-day vulnerabilities CVE-2025-53770 and CVE-2025-53771. The flaws were exploited before a patch was available and compromised at least 85 on-premises servers. One incident targeted the management plane, while the other demonstrated how quickly customers can be exposed when patch deployment lags behind active exploitation.
CISA has also warned that ransomware attackers abuse legitimate RMM software to reach downstream customer networks. MSPs therefore need to understand what happens if technician accounts, managed endpoints, or administrative workflows are compromised.
8 RMM security controls every MSP should test
1. Endpoint discovery and inventory
MSPs cannot protect devices they do not know exist. An effective RMM platform should continuously discover and inventory endpoints, servers, network devices, and software assets.
During an evaluation, introduce a new device into a test environment. Measure how quickly the RMM platform detects and classifies it, identifies its installed software, and assigns the appropriate policy.
2. Risk-based patch management
Unpatched vulnerabilities remain one of the most common attack vectors. Evaluate how the platform prioritizes updates, handles failed deployments, and supports rollback when a patch causes problems.
Test managed patch deployment rather than relying on a product demonstration. This can reveal operational gaps involving application coverage, maintenance windows, failure handling, and recovery.
3. Access control and privilege management
RMM security depends heavily on the security of technician accounts. Test multi-factor authentication, role-based access control, and separation of duties.
Create a limited technician role and verify that users cannot access devices, policies, scripts, or administrative functions outside their assigned responsibilities. Also confirm that privileged actions are recorded in an audit trail.
4. Alert prioritization and operational visibility
Most MSPs do not struggle with too few alerts; they struggle with too many. An RMM platform should provide enough context for technicians to distinguish routine issues from events that require investigation.
Test duplicate alerts, security-related alerts, alert grouping, escalation, and tuning. The goal is to determine whether the platform reduces alert fatigue or adds to it.
5. Secure automation and scripting
Automation improves efficiency, but scripts can also perform privileged actions across large numbers of devices. Strong governance is therefore essential.
Evaluate authorization controls, approval workflows, credential handling, script modification tracking, execution visibility, and audit records. Create and modify test scripts during the evaluation to verify how changes are controlled.
6. Integration with security operations
Operational and security workflows should work together. When a threat is detected, technicians need to move from investigation to remediation and recovery without losing client, device, or incident context.
Simulate incidents to test integrations with security tools, containment actions, remediation workflows, and escalation processes. This is often the fastest way to identify gaps between RMM and security operations.
7. Recovery readiness
Security is not limited to prevention. MSPs also need a reliable recovery process after an incident.
Assess how backup, patching, remote access, and incident response work together. Recovery testing should verify that a restored system returns to a safe and fully updated state.
When included in a service package, Acronis Cyber Platform can combine RMM with recovery-point backups and anti-malware scanning. This helps verify restore integrity and identify unresolved vulnerabilities before a system is brought back online.
8. Tenant isolation and auditability
Strong tenant isolation is essential for MSPs. Policies, permissions, reports, and administrative actions should remain separated between customer environments.
Detailed audit trails should support compliance reviews, customer reporting, and incident investigations. Test whether activity and evidence can be viewed and exported by client without exposing data from another tenant.
Discover devices, assess vulnerabilities, and automate patch management with a secure, AI-powered RMM built for MSPs. Acronis RMM is natively integrated with cybersecurity and data protection and helps reduce manual effort through AI-assisted scripting, proactive monitoring, and secure remote access.
Manage endpoints, cybersecurity, backup, and recovery from a single console.
Should MSPs choose an integrated platform or separate tools?
Individual products may offer highly specialized functionality, while a natively integrated platform can reduce the number of agents, console switches, and coordination steps required by technicians.
A practical evaluation should focus on workflow continuity. Can technicians move from discovery to patching, investigation, containment, and recovery while preserving client, device, and incident context?
Integration is not automatically better. MSPs with mature integrations should compare the operational benefits of a consolidated platform with the flexibility and specialist depth of their existing tools. The decision should be based on tested security controls, workflow results, and service requirements—not simply feature count.
How Acronis supports the RMM security checklist
Acronis RMM is delivered as part of the Acronis Cyber Platform. It uses the same console and agents as neighboring cybersecurity and data protection services.
Available features and licenses vary by service package. MSPs should map the exact configuration to each control rather than assuming that EDR, XDR, MDR, backup, or disaster recovery capabilities are included automatically.
| Control | Related Acronis features | Verification memo |
|---|---|---|
| Discovery and inventory | DeviceSense™; hardware and software inventory | Review supported detection methods and policy assignments. |
| Patch management | Automatic patching; AI risk scoring; fail-safe patching | Review application coverage and configuration requirements. |
| Identity and access | Multi-factor authentication; role-based management; detailed roles | Test least-privilege scope and audit records. |
| Alert processing | Anomaly-based monitoring; automatic response; shared platform context | Test tuning, grouping, and escalation workflows. |
| Script creation | Self-defense; two-step approval; audit log; secure credential storage | Test production script changes and execution history. |
| Incident response | Native integration with Acronis EDR and Acronis XDR | Review entitlements and containment workflows. |
| Recovery | Backup consolidation; anti-malware scan; fail-safe patching | Review storage, packaging, and recovery requirements. |
| Tenant boundaries and evidence | Multi-tenant management; role-based access; reporting | Check isolation and client-specific export capabilities. |
Secure RMM software: frequently asked questions
What should MSPs look for in secure RMM software?
Look beyond monitoring and remote access. Important capabilities include strong identity controls, tenant isolation, endpoint discovery, secure automation, patch management, auditable technician activity, and integration with security and recovery workflows.
A platform such as Acronis Cyber Platform can address these requirements by keeping related functions on shared infrastructure instead of requiring separate integration efforts.
How should RMM integrate with EDR, backup, and disaster recovery?
These tools should preserve enough client, device, and incident context for technicians to move from monitoring to containment and recovery without rebuilding the case in each console.
MSPs should also confirm that a recovery path remains available if an administrative workflow is compromised.
Conclusion: test RMM security before scaling
RMM security involves more than uptime and remote access. Before scaling a platform, MSPs should test difficult scenarios, including unmanaged endpoints, failed patches, malicious scripts, compromised test devices, restricted technician accounts, and restores that require updates.
Testing these eight controls can show whether an RMM platform helps technicians manage more endpoints while reducing operational and security risk.
Source: www.bleepingcomputer.com


