Remote monitoring and management (RMM) platforms are central to how managed service providers operate, but they also concentrate risk. Because these tools grant privileged access across many customer environments, a compromise of an RMM platform can have cascading effects. BleepingComputer reports on guidance from Acronis that outlines eight controls MSPs should test when evaluating RMM software.

The controls span several areas, including patching, privileged access management, recovery capabilities, and tenant isolation. The idea is to test these controls before deployment rather than assuming they work by default. Acronis's list is meant to help MSPs assess whether a given RMM product can limit the blast radius of an attack and support business continuity.

The source is a single vendor's perspective, so it should not be treated as an exhaustive or neutral checklist. Still, the emphasis on tenant isolation and recovery reflects broader industry concerns about supply-chain attacks targeting MSPs. Readers should compare these recommendations with other frameworks and their own threat model.