COMMENTARY: MSPs play an essential role in IT operations for organizations worldwide, providing a convenient, cost-effective way for businesses of all sizes across all industries to cut through the complexity of managing their own technology deployments. One forecast from Grandview Research estimates that the MSP market will increase by a massive 13.6% CAGR from 2023-2030. But as MSPs boom, they’re also becoming a bigger target for cyberattacks.It makes sense that hackers would target MSPs. If you can breach an MSP, you can gain access to their clients’ valuable data and applications. That’s precisely what happened to Kaseya in 2021 and Tigo Business in 2024. There’s even a ransomware group that’s been prioritizing attacks on MSPs.There are a number of factors that leave MSPs vulnerable to attack and quite a few things they could do better. But I want to focus on one issue in particular that’s flown under the radar and has major repercussions: MSPs’ reliance on third-party agents.So, how do security issues caused by third-party agents manifest in the real world? The recent SolarWinds Web Help Desk (WHD) breach provides a perfect example. This flaw allowed attackers to exploit hardcoded credentials (CVE-2024-28987) to access WHD endpoints, potentially allowing unauthorized users to modify data or access sensitive information. It was introduced 100% by an agent-based tool.
Third-party agents kneecap security efforts
One of the most underestimated vulnerabilities in MSP environments is the use of third-party tools that rely on agents installed on servers or end-user devices. Third-party platforms often require the use of agents installed directly on client systems. These agents are essential to the operation of the software. But they create entry points for attackers if they’re not regularly updated, patched, or properly configured – and there’s little transparency showing how effectively and frequently most vendors are doing each of these. The issue is exacerbated when agents incorporate suboptimal security practices, such as using hardcoded credentials or outdated security protocols. At a high level, there are three major security issues with third-party agents:- A bigger attack surface: Every agent running on a server or endpoint becomes another possible way in for attackers. If an agent is vulnerable, the whole environment can be compromised.
- Difficult maintenance demands: Keeping agents secure requires frequent updates and patches, but even the most diligent MSPs can fall behind. A delayed patch or missed update can leave systems open to exploitation.
- Trusting another entity: Leveraging a third-party agent means you’re handing over a huge amount of trust to someone else, with little control over whether or not they make costly mistakes.




