Est.
FeaturesLong read

Lateral Threat Propagation Risks in Shared MSP Infrastructure

One compromised MSP becomes a backdoor to every client it serves.

Editor at Large · · 11 min read
Cover illustration for “Lateral Threat Propagation Risks in Shared MSP Infrastructure”
Features · September 15, 2026 · 11 min read · 2,512 words

Signing with an MSP means inheriting its entire attack surface, not just its help desk. One compromised MSP environment can spread through every client the provider touches, and no single SMB on that client list can see it happening or stop it from the inside. That's the arrangement most small businesses never actually read into their contract.

MSPs hold privileged access to dozens, sometimes hundreds, of client environments at once. That's not an accidental byproduct of the business model. It's the entire prize. One stolen credential, one unpatched RMM tool, one misconfigured API token, and an attacker isn't looking at a single payday. They're looking at a client list.

ConnectWise's 2025 MSP Threat Report lays the logic out plainly: attackers use MSPs as a gateway to reach every SMB customer downstream, chasing several smaller payloads instead of one big one that draws government or media attention. Quiet is exactly what a ransomware crew wants, until the moment it isn't. The report also found that 78% of MSPs surveyed worry a serious attack could put them out of business entirely, which tells you how much weight sits on one provider's shoulders.

The SMB downstream has no window into any of this. It can't see the MSP's patch schedule, its credential hygiene, or its monitoring gaps. The attacker, meanwhile, gets full lateral reach the moment it's inside. Full access on one side, zero visibility on the other, and that gap is what the rest of this piece pulls apart.

How credential compromise becomes the master key across every client the MSP serves

Credentials are where this usually starts. MyCena's MSP Credential Risk Report 2025, citing IBM Security's 2024 X-Force Threat Intelligence Index, found MSPs experience credential-related breaches at rates 340% higher than other sectors, with 89% of incidents tracing back to compromised privileged access.

The ratio makes sense once you think about the job. A typical company grants elevated privileges to a small slice of its staff. An MSP needs privileged credentials for a large chunk of its technical team, spread across dozens of client domains, often at the same time. Researchers call this credential density risk: more privileged accounts touching more environments means more doors, and more doors means more locks that can fail.

Shared credential practices make it worse, and this is where most MSPs get it wrong. Plenty still use one shared administrative login across client environments, usually because it's faster to onboard a new client that way. It's efficient right up until someone needs to figure out who actually touched what. Shared logins break basic least-privilege practice, and they make individual attribution close to impossible after the fact. Speed at onboarding is not worth losing the ability to trace who did what six months later. Any provider that still runs this way has made a bad trade and doesn't know it yet.

Acronis reporting, cited by MSPGlobal, documented a case where one hijacked Microsoft 365 session token gave attackers silent control over multiple client tenants at once. One token, several companies exposed. Valid account abuse and credential theft made up 15% of MSP attack vectors in 2025, meaning attackers increasingly just log in. No noisy exploit, no malware signature to catch. They walk into the RMM dashboard as a recognized user and go to work.

Then there's the dormant access problem. When an MSP employee leaves, or a client contract ends, credential revocation has to happen across potentially hundreds of client systems. That process is often manual, and manual processes miss things. An orphaned access path can sit open for months, even years, waiting for someone to notice. MyCena's report found supply chain attacks targeting MSP credentials up 742% since 2022, a figure that reflects how aggressively this vector has been exploited.

None of this is the client's mess to clean up. A credential failure at the MSP level is structural, invisible from the client side, and yet the client absorbs the consequences anyway.

What lateral movement through shared infrastructure actually looks like in practice

The DragonForce ransomware campaign is a clean, documented case of how this plays out. Per ConnectWise's CRU Monthly Threat Brief from May 2025, attackers chained three vulnerabilities in the SimpleHelp RMM platform in sequence: a path traversal flaw to pull files, a privilege escalation bug to bypass authorization checks, then an arbitrary file upload to plant their tools. That chain moved attackers from MSP infrastructure into multiple client networks at once.

The tool built to manage clients became the tool used to compromise them. That's the supply-chain pattern in its purest form, and it flips the entire value proposition of an RMM platform on its head.

Multi-tenant architecture compounds the risk. Multiple clients share underlying systems, and separation between them is often logical rather than physical, enforced by configuration rather than built into the architecture itself. One misconfiguration, and the blast radius of a single tenant's exposure stops being an edge case. It becomes structural, which is the part most SMB owners never think to ask about.

A single unmonitored identity event or an unpatched endpoint can open a lateral path in minutes. Log aggregation across shared MSP systems frequently lacks clean tenant boundaries, so when something does go wrong, investigators struggle just to figure out which clients were touched and for how long. Authentication failures are the quietest version of this: a misrouted login, a reused token, a shared configuration crossing a trust boundary it shouldn't. No alarm goes off. Nothing breaks loudly. It just happens.

The entry points back this up with hard numbers. Reporting on MSP attack patterns found unpatched RMM and remote access tools accounted for 27% of attack entry points in 2025, up from 23% the year before. Edge device exploitation, VPNs and firewalls specifically, jumped from 3% to 22% of exploitation targets over two years, an eightfold increase. ConnectWise's CRU logged more than 84,000 alerts targeting edge device vulnerabilities across MSP-managed environments in 2024, and roughly 60% involved flaws disclosed that same year. The patches existed. They just weren't applied in time, and that's the part that should sting: this isn't a zero-day problem, it's a discipline problem.

On top of that, the CRU documented a rise in purpose-built "EDR-killer" tools through 2024, designed to blind endpoint defenses, hold persistence, escalate privileges, and move sideways through a network. Once those tools are in play, the client's last layer of visibility is gone before anyone even knows to look for it.

Why the SMB client is the last to know when their MSP's environment is breached

Most MSPs run shared monitoring across every client they serve. Per-client detection often exists as a setting layered on top of that shared system, not as something structurally separated from the start. Industry reporting consistently points to alert fatigue as a persistent pressure across MSP operations, meaning the humans watching the dashboards are already stretched thin before an actual incident hits.

Dwell time makes this worse. CrowdStrike's 2024 Global Threat Report found an average eCrime breakout time, the time from initial access to lateral movement, of 62 minutes industrywide. MSP-specific detection timelines running into months aren't documented in that particular report, but the gap between breach and discovery still gives attackers room to do reconnaissance, dig in, and quietly plan strikes against individual clients before anyone notices.

Here's the part that matters most for the SMB owner: no alert fires when the MSP itself gets breached. The client finds out downstream, usually after ransomware has already deployed or data has already left the building. That order of events, breach first, notice much later, is the whole problem in one sentence.

Drive-by compromise made up 22% of all incidents ConnectWise's CRU reviewed in 2024, and newer social engineering tactics reach end users through channels an MSP's perimeter tools were never built to inspect. The CRU's documentation of the PDFast campaign, from May 2025, showed malware sitting dormant for one to 21 days, averaging around 10, before it activated command-and-control. Ten days of looking clean on every scan run across the MSP's entire client base.

Verizon's 2025 DBIR found third-party involvement in breaches doubled to 30% year over year. An MSP relationship is exactly this kind of third-party exposure: invisible in the client's own logs, right up until it isn't.

What MSPs and MSSPs are actually responsible for, and where security accountability stops

Strip away the acronyms and the distinction is simple. An MSP keeps the lights on: uptime, ticket response, systems that work. An MSSP watches the doors: how fast a threat gets spotted, how fast it gets contained. Confusing the two is the single most common mistake buyers make in this market, and it's an expensive one.

An MSP's core mandate is IT operations and system availability. Security monitoring isn't automatically part of that deal unless it's written into the contract, and most SMB owners assume they're covered for a lot more than their agreement actually says. That assumption is the gap attackers count on. Buyers think they bought security when they bought uptime, and nobody corrects them until something breaks.

An MSSP's job description looks completely different: 24/7 SOC monitoring, threat detection and response, incident response leadership, running the security tool stack itself (SIEM, SOAR, XDR, EDR), vulnerability management, coordinating penetration tests, security awareness training, compliance program management, and threat intelligence. Different job, different people, priced differently for a reason.

The mistake most buyers make is comparing monthly invoices without comparing what's actually inside them. A cheaper contract can quietly exclude after-hours monitoring, forensic investigation, containment work, or anyone leading incident response when things go sideways.

Securafy's Cybersecurity Buyers Guide 2026 lists red flags worth checking against any provider: vague SLAs with no measurable numbers attached, a resold security tool dressed up as a service, no client visibility into their own environment, no alignment with cyber insurance requirements, reactive-only operations, hidden fees that surface after the contract's signed, no independent security credentials, and weak communication standards when incidents happen.

The one question that cuts through most of the marketing: does this provider run an actual security operations center, or is it reselling a tool with a support line attached? IBM's 2025 Cost of a Data Breach report puts the global average breach cost at $4.44 million, with an average of 241 days to identify and contain one. The distance between what an MSP watches and what an MSSP actively hunts for gets measured in exactly those days, and those dollars.

Why small businesses are not accidental victims in MSP-linked attacks, they are the intended downstream target

Attackers aren't stumbling into small businesses by accident. They've done the math, and small businesses come out as accessible, not beneath notice.

Verizon's 2025 DBIR found third-party involvement showing up in 30% of breaches, double the prior year's figure. The MSP relationship is that third-party vector, sitting quietly in the middle of the supply chain.

Ransomware showed up in 88% of SMB breaches per that same DBIR, against 39% for large organizations. That gap isn't small. Ransomware has become disproportionately a small-business problem, not an enterprise one, and The economics of MSP-linked attacks make smaller organizations the natural downstream target.

The economics explain why. An MSP serves dozens of SMBs off one set of credentials and one shared toolkit, so compromising that single point is the efficient path to many small payouts. That's exactly the model ConnectWise's CRU describes attackers favoring over one loud attack on a large target that draws unwanted attention. And the RMM tool built for remote management is the same tool that, once an attacker owns it, can push ransomware to every client on the list at once.

MyCena's MSP Credential Risk Report 2025 put the average cost per MSP breach at $4.88 million in 2024, well above the global average of $4.45 million. That cost doesn't stop at the MSP's door. It cascades straight into the client environments sitting downstream.

Questions an SMB should be able to answer about how their MSP actually isolates and monitors their environment

Security posture can't be judged from a sales pitch. "Industry-standard security" isn't an answer, it's a phrase people use when they don't have a specific one. The real diagnostic comes from asking about structure, not adjectives.

On isolation and architecture: is client data structurally separated per tenant, or is that separation something configured and manually maintained? If one client's environment gets compromised, what actually stops lateral movement into the next one? Are RMM credentials and admin tokens unique per client, or shared across the provider's own staff accounts?

On monitoring and detection: does the provider run a 24/7 SOC, or does security monitoring stop when the office closes for the day? What's the documented process if the provider's own infrastructure gets breached, and how fast do clients get told? How quickly does the provider patch its own RMM platform and edge devices, given that unpatched tools accounted for 27% of MSP attack entry points in 2025?

On credential hygiene: what's the actual process for revoking access when staff leave or a client relationship ends? Is MFA required on every administrative path into the client's environment, including the RMM console itself? Are privileged credentials rotated and unique, or reused across accounts?

On accountability: does the SLA commit to uptime, or to security response times, because those are two very different documents wearing the same name? Does the contract spell out incident response duties, forensic support, and notification timelines? Is there a SOC 2 Type II audit covering access control, and can the client actually see the results?

If a provider can't answer these with specifics, that silence is itself the answer.

What an integrated security platform does that a shared MSP environment structurally cannot

Shared MSP infrastructure creates a lateral movement risk no individual SMB can detect, control, or contain from outside the provider's walls. That's the structural reality the rest of this piece has been building toward, and the fix isn't a better MSP contract. It's a different architecture altogether.

An integrated platform changes the shape of the problem. Device management, identity protection, endpoint defense, and compliance run as one system built around a single company's environment, not spread across dozens of tenants managed by a third party with its own priorities and its own blind spots.

Isolation stops being something configured after the fact and becomes something built into the architecture from the start. When the controls belong to the business itself, a breach at some outside vendor's infrastructure doesn't automatically become a breach in that business's own environment.

Most SMBs don't have a security team, and that's the honest starting point here. The real question isn't how to build a security operations center from scratch. It's how to put consistent, continuously enforced controls in place without months of setup work or a security hire most small companies can't justify on the budget line. A platform that deploys in weeks and enforces controls automatically sits in a different category of investment than a shared infrastructure model, where security is one line item competing for attention against uptime and ticket volume, and usually losing.

Sources

  1. connectwise.com
  2. MSP Credential Risk Report 2025 - MyCena
  3. Monthly Threat Brief: May 2025 | ConnectWise
  4. Cyberattacks on MSPs in 2025: what’s new and how to respond
  5. Report: Why Managed Service Providers Are Now Ground Zero for Attacks
  6. securafy.com
  7. acrisure.com

More in Features