How to secure RMM software: 8 controls MSPs should test
· BleepingComputerSecure remote monitoring and management (RMM) software should let an MSP discover endpoints, automate patching, control privileged access, cut alert noise, contain incidents, protect recovery points, separate customer tenants and prove all of it.
Acronis, which delivers RMM as part of Acronis Cyber Platform, built this checklist from securing endpoint management across thousands of customer environments.
MSPs comparing RMM tools should test these outcomes directly rather than choosing by feature-list length.
Why RMM is part of the MSP attack surface
RMM gives technicians unattended administrative access across thousands of customer devices, which makes the management plane valuable to attackers: compromise one privileged account or server and the blast radius extends far beyond a single endpoint.
Two incidents show both sides of the problem. In September 2026, BleepingComputer reported that N-able shipped an emergency hotfix for CVE-2026-86218, a maximum-severity pre-authentication RCE flaw in its N-central RMM platform, its fourth hotfix in five weeks, with roughly 1,500 servers exposed online.
In July 2025, BleepingComputer covered the Microsoft SharePoint "ToolShell" zero-days (CVE-2025-53770 and CVE-2025-53771), exploited before a patch existed, with at least 85 on-premises servers compromised. One attack targeted the management plane; the other showed how fast customers are exposed when patching lags exploitation.
CISA has also warned that ransomware actors abuse legitimate RMM software to reach downstream customer networks. MSPs therefore need to know what happens when an account, endpoint or management workflow is compromised.
8 controls every MSP should test
1. Endpoint discovery and inventory
An MSP cannot secure devices it does not know exist. Effective RMM platforms should continuously discover and inventory endpoints, servers, network devices and software assets. During evaluation, introduce a new device into a test environment and assess how quickly it is discovered, classified and assigned the correct policy.
2. Risk-based patch management
Unpatched vulnerabilities remain one of the most common attack paths. Evaluate how the platform prioritizes updates, handles deployment failures and supports rollback when issues occur. A controlled patch deployment can reveal operational gaps that are easy to miss during a product demo.
3. Access controls and privileged administration
RMM security depends heavily on the security of technician accounts. Look for multifactor authentication, role-based access controls and separation of duties. Create restricted technician roles and verify that users cannot perform actions outside their assigned responsibilities.
4. Alert prioritization and operational visibility
The challenge is rarely too few alerts. It is too many. An RMM platform should provide enough context to help technicians quickly distinguish routine issues from events that require investigation. Testing duplicate and security-related alerts can help measure whether the platform reduces or contributes to alert fatigue.
5. Secure automation and scripting
Automation improves efficiency but also expands risk. Scripts can perform privileged actions across large numbers of devices, making governance critical. MSPs should evaluate approval controls, auditing and execution visibility by creating and modifying test scripts during evaluation.
6. Integration with security operations
Operational and security workflows should work together seamlessly. When a threat is detected, technicians should be able to move quickly from investigation to remediation and recovery without losing context. Simulating an incident is often the best way to identify integration gaps.
7. Recovery readiness
Security is as much about recovery as prevention. Evaluate how backup, patching, remote access and incident response processes work together after an incident. Recovery testing should include verifying that restored systems return to a secure and fully updated state.
Acronis Cyber Platform can pair RMM with backup and anti-malware scanning of recovery points, where included in the service package, so a restore is validated for integrity and outstanding vulnerabilities before a system goes back online.
8. Tenant separation and auditability
For MSPs, strong tenant separation is essential. Verify that policies, permissions, reports and administrative actions remain isolated between client environments. Detailed audit trails should support compliance reviews, customer reporting and incident investigations.
Close security gaps. Simplify IT management with Acronis RMM.
Discover devices, assess vulnerabilities, and automate patch management with a secure, AI-powered RMM built for MSPs. Natively integrated with cybersecurity and data protection, Acronis RMM helps reduce manual work through AI-assisted scripting, proactive monitoring, and secure remote access.
Manage endpoints, cybersecurity, backup, and recovery from a single console.
Unified platform or separate tools?
Separate products may provide deep specialist capabilities. A natively integrated platform can reduce agent count, console switching and reconciliation work.
The practical test is workflow continuity: can technicians move from discovery to patching, investigation, containment and recovery while preserving client, device and incident context?
Consolidation is not automatically better. MSPs with mature integrations should compare the operational benefit of a unified platform with the flexibility and specialist depth of their existing tools. The decision should be based on tested outcomes, security controls and service requirements, not feature count alone.
How Acronis maps to the checklist
Acronis RMM is delivered as part of Acronis Cyber Platform. It shares the same console and agent with adjacent cybersecurity and data protection services.
Available capabilities and licensing vary by service package, so MSPs should map the exact configuration to each control rather than assuming every EDR, XDR, MDR, backup or disaster recovery capability is included.
Control
Relevant Acronis capability
Validation note
Discovery and inventory
Device Sense™; hardware and software inventories
Confirm supported discovery methods and policy assignment.
Patch management
Automated patching; AI risk scoring; fail-safe patching
Confirm application coverage and configuration requirements.
Identity and access
Multifactor authentication; role-based management; granular roles
Test least-privilege scope and audit records.
Alert handling
Anomaly-based monitoring; auto-response; shared platform context
Test tuning, grouping and escalation workflows.
Scripting
Self-defense; two-step approval; audit logs; secure credential storage
Test production script changes and execution history.
Incident response
Native integration with Acronis EDR and Acronis XDR
Verify entitlements and containment workflow.
Recovery
Backup integration; anti-malware scans; fail-safe patching
Verify storage, package and recovery requirements.
Tenant boundaries and evidence
Multitenant management; role-based access; reporting
Confirm per-client segregation and exports.
Quick answers
What should an MSP look for in secure RMM software?
Look beyond monitoring and remote access: strong identity controls, tenant separation, endpoint discovery, safe automation, patch management, auditable technician activity and integration with security and recovery workflows.
Platforms like Acronis Cyber Platform answer this by keeping those functions on shared infrastructure rather than requiring separate integration work.
How should RMM integrate with EDR, backup and disaster recovery?
The tools should preserve enough client, device and incident context for technicians to move from monitoring to containment and recovery without rebuilding the case in each console. The recovery path should also remain usable if the management workflow is compromised.
Bottom line
RMM security is not only about uptime and remote access. Before scaling, MSPs should pilot deliberately difficult scenarios: an unmanaged endpoint, a failed patch, an unauthorized script, a compromised test device, a restricted technician account and a restore that still needs updates.
Testing these eight controls shows whether a platform can reduce operational risk while technicians manage more endpoints.
Sponsored and written by Acronis.