Security Program Controls/Technologies, Security Operations, SOC

RMM abuse emerges as a top cybersecurity risk for MSPs

Remote management and monitoring (RMM) abuse is rapidly becoming a significant cybersecurity threat for managed service providers (MSPs) and their clients, with a recent report indicating a 277% year-over-year increase in its use and a 45% involvement in endpoint-related incidents in early 2026, as first reported by Channel Insider.

Huntress' "Tragic Quadrant" research highlights that attackers are increasingly exploiting trusted tools like RMM, authenticated sessions, and mailbox rules rather than relying on novel techniques. RMM platforms, essential for MSP operations, offer persistent access that can be difficult to distinguish from legitimate activity. The report also notes that identity threats, including mailbox manipulation (24.6% of observed threats in 2026) and AiTM attacks (18.9% in 2025), are bypassing traditional multi-factor authentication.

While AI is accelerating familiar threats and improving phishing lures, its direct role in widespread damage is currently considered less impactful than RMM abuse and identity compromise. The findings suggest MSPs should focus on strengthening defenses around existing technologies, tightening controls over remote tools, enhancing post-authentication identity monitoring, and securing authenticated sessions and mailbox configurations.

Source: Channel Insider

You can skip this ad in 5 seconds