Cybersecurity for MSPs: What Managed Service Providers Need to Know
A practical cybersecurity guide for MSPs, covering privileged access risks, penetration testing, Cyber Essentials and Cyber Essentials Plus.
Cybersecurity for MSPs: What Managed Service Providers Need to Know
Managed service providers (MSPs) occupy a unique position in the cybersecurity landscape. They are responsible not only for protecting their own organisation, but often for managing the IT infrastructure, identities, devices and security systems of dozens or even hundreds of other businesses.
That makes MSPs an attractive target for cyber attackers.
Cybersecurity for managed service providers (MSPs) is the practice of protecting the MSP itself, its customers, and the systems and privileged access used to manage those customers' IT environments.
An MSP may have privileged access to customer networks, Microsoft 365 tenants, servers, endpoints, backups and cloud platforms. If an attacker compromises that access, the consequences can extend far beyond the MSP itself.
For this reason, cybersecurity should be treated as a core part of an MSP's operations rather than simply another service offered to customers.
Why are MSPs attractive targets?
An attacker targeting a single business has to compromise that business.
An attacker targeting an MSP may potentially gain access to many businesses through a single successful compromise.
This makes MSPs particularly interesting to threat actors.
Common reasons include:
- Privileged access: MSP technicians often have administrative access to customer environments.
- Remote management tools: RMM platforms can provide extensive remote access to customer systems.
- Centralised credentials: MSPs may manage large numbers of customer accounts and privileged identities.
- Valuable information: PSA platforms, documentation systems and ticketing systems can contain sensitive customer information.
- Access to backups: MSPs may manage or administer customer backup infrastructure.
- Security tooling: An MSP may have administrative control over endpoint protection, email security and other defensive systems.
- Supply-chain impact: Compromising an MSP can potentially provide a route into multiple downstream organisations.
The result is a different threat model from that of a typical small or medium-sized business.
An MSP is not simply protecting its own network.
It may be protecting the keys to many other networks.
Understanding the MSP attack surface
An MSP's attack surface extends well beyond its public-facing website or office network.
People
People are often the most important part of an MSP's security model.
This includes:
- Technicians
- System administrators
- Helpdesk staff
- Management
- Contractors
- Third-party engineers
Every person with access to customer systems represents a potential route into those systems.
A compromised technician account can be significantly more valuable to an attacker than a compromised account belonging to a typical end user.
Technology
MSPs commonly operate a large collection of management and security platforms, including:
- Remote Monitoring and Management (RMM) platforms
- Professional Services Automation (PSA) systems
- Microsoft 365
- Remote access solutions
- VPNs
- Backup systems
- Endpoint management platforms
- Password managers
- Documentation platforms
- Security and monitoring systems
Each system introduces its own accounts, credentials, integrations and permissions.
The security of the overall environment is therefore dependent on more than just the security of the MSP's corporate network.
Customer access
MSP technicians may have access to highly privileged customer systems, including:
- Domain administrators
- Microsoft 365 administrators
- Servers
- Network infrastructure
- Cloud platforms
- Firewalls
- Endpoint management systems
- Backup infrastructure
This access should be carefully controlled and regularly reviewed.
Third parties
MSPs may also rely on a range of external suppliers, such as:
- Security vendors
- Cloud providers
- Software suppliers
- RMM and PSA providers
- Subcontractors
- Specialist security companies
These relationships form part of the MSP's broader supply-chain risk.
The biggest cybersecurity risks for MSPs
Compromised privileged accounts
An attacker does not necessarily need to discover a sophisticated technical vulnerability.
They may simply need to obtain the credentials of someone who already has the access they need.
A compromised administrator account could potentially provide access to multiple customer environments.
This makes privileged identity security one of the most important areas for an MSP to address.
RMM compromise
Remote Monitoring and Management platforms are incredibly useful to MSPs because they provide centralised visibility and remote administration.
However, that same functionality makes them attractive targets.
If an attacker gains control of an RMM account or management platform, the platform itself could potentially become an attacker-controlled mechanism for accessing customer systems.
RMM security should therefore be treated as a critical security control, not simply an operational IT consideration.
Weak MFA
Multi-factor authentication is an important defence against stolen credentials, particularly for privileged accounts.
However, not all MFA implementations provide the same level of protection.
MSPs should consider where MFA is enforced, which authentication methods are permitted, and whether privileged accounts are subject to stronger authentication and access controls.
MFA should be enabled wherever possible, particularly for administrative and remote access.
Poor separation between customers
Customer isolation is another important consideration.
If a technician can move easily between multiple customer environments using a single account, credential set or management platform, a compromise could have a much greater impact.
Least privilege and tenant isolation help limit the blast radius of a compromise.
Access should be granted because it is required, rather than simply because someone might need it eventually.
Supply-chain attacks
MSPs are an obvious example of supply-chain risk in cybersecurity.
An attacker may decide that compromising an MSP is more valuable than directly attacking one of its customers.
This means an MSP needs to consider not only how it protects itself, but also how a compromise of its systems could affect its customers.
How should MSPs protect privileged access?
Privileged access deserves particular attention.
Some practical measures include:
- Multi-factor authentication wherever possible
- Separate privileged and standard user accounts
- Least-privilege access
- Conditional access policies
- Privileged Access Management (PAM)
- Password managers
- Strong authentication methods
- Session controls
- Regular access reviews
- Removal of dormant accounts
- Rapid removal of access when staff leave
- Monitoring of privileged activity
One principle is particularly important:
Technicians shouldn't have permanent access to everything simply because they might need it one day.
Where practical, privileged access should be limited to what is required for a specific role or task.
Temporary or just-in-time access can also help reduce the amount of privileged access that exists at any given time.
What should an MSP monitor?
Good cybersecurity is not simply about deploying an EDR product and assuming the problem is solved.
MSPs should have appropriate visibility into important security events across their own environment and, where appropriate, their management infrastructure.
Examples include:
- Authentication events
- Unusual login locations
- Impossible-travel detections
- MFA changes
- New administrator accounts
- Privilege changes
- RMM activity
- Unusual remote sessions
- Configuration changes
- Backup deletion or modification
- Endpoint security alerts
- Changes to security policies
The objective is to identify activity that could indicate compromised credentials, unauthorised access or an attacker attempting to establish persistence.
Should MSPs penetration test themselves?
Absolutely.
An MSP securing its customers does not automatically mean that the MSP itself has been independently security tested.
Penetration testing can provide an independent assessment of whether vulnerabilities in the MSP's own systems could be exploited by an attacker.
Depending on the MSP's environment and risk profile, this could include testing:
- Internet-facing infrastructure
- External attack surface
- Internal infrastructure
- Remote access systems
- Web applications
- APIs
- Customer-facing portals
- Management infrastructure
The management infrastructure deserves particular attention.
If an MSP's RMM, customer portal or other centralised management system is compromised, the potential impact could be considerably greater than a compromise of an isolated system.
Penetration testing should therefore form part of a broader security programme rather than being treated as a one-off exercise.
What about testing an MSP's customers?
MSPs do not necessarily need to perform every specialist security assessment themselves.
Working with an independent security provider can allow an MSP to offer customers additional security services while retaining the existing customer relationship.
Depending on customer requirements, this might include:
- Penetration testing
- Cyber Essentials
- Cyber Essentials Plus
- Vulnerability assessments
- Web application penetration testing
- API security testing
- Remediation testing and retesting
This can be particularly useful where an MSP does not have the specialist skills, certification or capacity to perform the work internally.
The MSP remains the trusted technology partner while bringing in independent security expertise where appropriate.
Cyber Essentials and MSPs
Cyber Essentials can be particularly useful for MSPs and their customers because it provides a recognised baseline for protecting organisations against common cyber threats.
Cyber Essentials focuses on implementing essential technical controls designed to reduce exposure to common attacks.
Cyber Essentials Plus goes further by adding independent technical verification to assess whether those controls are actually implemented and operating as expected.
For MSPs, helping customers achieve and maintain Cyber Essentials certification can become part of a broader security and compliance offering.
However, it is important to understand that Cyber Essentials and penetration testing serve different purposes.
Cyber Essentials is not a replacement for penetration testing.
Cyber Essentials provides a baseline of security controls, while penetration testing involves an authorised attempt to identify and exploit vulnerabilities within a defined scope.
Both can have a place within a mature cybersecurity programme.
Building a security-first customer offering
MSPs can also use a layered approach when helping customers improve their security.
A typical security journey might look like this:
Baseline
Cyber Essentials
↓
Technical verification
Cyber Essentials Plus
↓
Continuous visibility
Vulnerability management
↓
Deeper assurance
Penetration testing
↓
Ongoing improvement
Remediation and retesting
This approach recognises that cybersecurity is not a single product or assessment.
Different services answer different questions.
Cyber Essentials asks whether essential controls are in place.
Vulnerability management helps identify and prioritise weaknesses over time.
Penetration testing asks whether vulnerabilities and weaknesses can actually be exploited within a defined scope.
Retesting then provides additional assurance that identified issues have been addressed.
For an MSP, this can become a valuable part of a broader customer security strategy.
Questions MSPs should ask their security partner
If you are an MSP considering working with an external penetration testing or cybersecurity provider, it is worth asking some important questions before entering into a partnership.
Are you independent?
Independence can be important when providing an objective assessment of a customer's security.
Who actually performs the testing?
Ask whether assessments are performed by appropriately qualified and experienced security professionals.
What standards and methodologies do you follow?
A professional security provider should be able to explain the methodologies and standards used during assessments.
Do you provide remediation advice?
A penetration test should not simply leave a customer with a list of vulnerabilities.
Useful reporting should help the customer understand the risk and what needs to be done.
Can you perform retesting?
After vulnerabilities have been remediated, retesting can help confirm that the fixes are effective.
How quickly can you schedule an engagement?
This matters particularly when your customer has a deadline for certification, compliance or contractual requirements.
Can you work under our branding?
Some MSPs may prefer a white-label or co-branded approach, while others may want the security provider to deal directly with the customer.
It is worth establishing what model the provider supports.
Can you deal directly with our customer?
Some MSPs want to remain the primary point of contact. Others may prefer their security partner to communicate directly with the customer's technical team.
There is no single correct model, but expectations should be clear.
Do you offer partner pricing?
If cybersecurity services form part of your customer offering, commercial arrangements matter.
A suitable partner programme should make it straightforward for the MSP to introduce specialist services without creating unnecessary friction.
What happens when our usual security partner isn't available?
This is an important question that is sometimes overlooked.
Your preferred security provider may be fully booked when a customer needs an assessment urgently.
Having a secondary specialist security partner can provide useful additional capacity when scheduling becomes difficult.
A security partnership should complement the MSP
The best security partnerships should not compete with the MSP's existing customer relationship.
The MSP already understands the customer's environment, requirements and business priorities.
A specialist security provider can bring additional expertise, independent testing and specialist services where required.
That can allow the MSP to offer customers a broader security proposition without having to build every capability internally.
At Plainsight Security, we work with organisations and MSPs to provide independent penetration testing, Cyber Essentials Plus audits and other specialist security services.
Our MSP Partner Programme is designed to make it easier for managed service providers to bring these services to their customers while maintaining the relationship they have already built.
Whether you need additional capacity, specialist penetration testing expertise, Cyber Essentials Plus auditing or an independent security assessment, a specialist partner can help fill the gaps without requiring the MSP to do everything itself.
Final thoughts
MSPs have a particularly important role in the cybersecurity ecosystem.
They are trusted with privileged access to the systems that keep their customers operating. That makes protecting the MSP itself just as important as protecting the services it provides.
A strong MSP security strategy should therefore consider:
- Privileged access
- MFA
- Least privilege
- Customer isolation
- RMM security
- Monitoring
- Vulnerability management
- Penetration testing
- Supply-chain risk
- Regular security reviews
Most importantly, security should be treated as an ongoing process rather than a one-time project.
An MSP that can demonstrate strong security practices is not only reducing its own risk. It is also helping protect every customer that trusts it with their IT.
Put this into practice.
Cyber Essentials, Cyber Essentials Plus, and penetration testing — fixed-price, plain English, and built to stay out of your way.