Acronis Recommends Eight Security Controls for RMM Platforms to Mitigate MSP Risk
Guidance outlines patching, privileged access, recovery, and tenant isolation best practices for Remote Monitoring and Management tools.

Key Takeaways
- RMM platforms provide privileged access across customer environments, making their security configuration critical.
- Acronis has identified eight security controls for MSPs to test when evaluating RMM software.
- Key control areas include patching, privileged access, recovery, and tenant isolation.
- The guidance focuses on preventive measures and risk assessment rather than reporting active exploitation.
- Organizations should use this guidance to audit and improve their RMM security posture.
Quick answers
- What happened?
- Acronis has published guidance identifying eight security controls that Managed Service Providers (MSPs) should evaluate and test when using Remote Monitoring and Management (RMM) software. The recommendations address critical areas including patch management, privileged access controls, incident recovery, and tenant isolation, aiming to reduce the risk of unauthorized access and lateral movement through compromised remote management tools.
- Which products are affected?
- RMM software
- What should defenders do?
- MSPs and organizations using RMM software should review and implement the recommended controls, including regular patching, strict access controls, tested recovery procedures, and tenant isolation strategies.
Acronis has outlined eight security controls that Managed Service Providers (MSPs) should test when evaluating Remote Monitoring and Management (RMM) software. Given that RMM platforms provide privileged access across customer environments, their security configuration is critical to limiting overall risk. The guidance covers several key areas: ensuring timely patching of RMM agents and consoles; enforcing strict privileged access controls and just-in-time access principles; establishing and testing incident recovery procedures; and implementing tenant isolation to prevent lateral movement between customer environments. Additional controls likely include network segmentation, logging and monitoring configurations, and secure deployment practices. The advisory emphasizes that these controls are preventive in nature and should be regularly assessed as part of an MSP's security posture evaluation. No specific active exploitation of RMM platforms was reported in connection with this guidance; the focus is on risk mitigation and best practices. The guidance serves as a framework for MSPs to audit their RMM deployments and reduce the attack surface associated with remote management tools.
Security Details
The advisory provides best-practice controls for RMM security configuration. No specific CVE or active exploitation is reported; the guidance is preventive and configurational.
Affected products
RMM software
Mitigation
MSPs and organizations using RMM software should review and implement the recommended controls, including regular patching, strict access controls, tested recovery procedures, and tenant isolation strategies.
Sources
BleepingComputer
How to secure RMM software: 8 controls MSPs should test
Oct 6, 2026 · 14:00
Original link
Related Security News

Microsoft Outlook to Block MSIX Attachments Starting November
Microsoft has announced that starting in November 2026, Outlook Web and the new Outlook for Windows will block .msix and .msixbundle attachments. The move is intended to mitigate abuse of the MSIX packaging format in phishing and malware delivery campaigns, though details on the exact blocking mechanism and impact on legitimate deployments remain pending confirmation.

Google Suspends Open Source Bug Bounty Program Amid AI-Generated Report Surge
Google has temporarily halted submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) due to a significant increase in AI-generated vulnerability reports. The suspension is intended to manage the influx and protect the program's integrity for legitimate researchers.



