In 2026, supply chain attacks have become one of the most feared threats in cybersecurity, and for good reason. When attackers compromise a vendor with privileged access to multiple environments, they do not just breach one organization. They can potentially breach every client that vendor serves.
For managed service providers (MSPs), that reality cuts both ways. They are both a high-value target and a potential pathway into dozens of client environments. For many MSP owners, the phrase “supply chain attack” is enough to keep them awake at night.
Recent headlines have only heightened those concerns. The 2021 Kaseya breach spread ransomware through roughly 60 MSPs to as many as 1,500 customers in a single attack. It remains one of the clearest examples of why attackers increasingly target MSPs. MSPs need to ensure those opportunities stay locked down.
Why supply chain attacks are so dangerous
Kevin O’Connor, a cybersecurity practitioner and researcher at EQTYLAB, an AI governance and cryptographic attestation firm, summed up the risk. “MSPs cannot treat vendor risk as a questionnaire problem. If your RMM, backup platform, identity provider, or remote-access tooling is compromised, you have effectively handed one intrusion path to every customer you manage.”
The consequences are systemic, he said. “Too many providers still sell a stack of security products without proving they can see, segment, revoke, and investigate the trust relationships behind it. That is not managed security. It is managed exposure.”
Mudita Khurana, a Staff Security Engineer at Airbnb with more than a decade of experience in application security and vulnerability management, told SmarterMSP how that exposure unfolds in real time. “An MSP compromise can happen just like any other breach. An attacker might use social engineering or phishing to steal credentials, take over an active session, or exploit a known vulnerability in an internet-facing server.”
Once inside, attackers move toward central systems that store customer information and maintain trusted connections to client environments. “A remote management tool may have an agent installed on every SMB employee laptop and may also be allowed to run commands or install software. If an attacker gains control of that system, they can use those connections to infect SMB devices. Because the activity comes from the MSP, the SMB already trusts it, allowing the attack to go undetected.”
The damage becomes even greater when MSPs use shared administrator accounts or lack strong access isolation between clients. “The attacker can reach multiple SMBs and infect more machines at once. That is what makes the MSP’s blast radius so large.”
Trusted access is the real vulnerability
Jose Lejin P J, an IEEE Senior Member and Principal Member of Technical Staff at Salesforce with more than 50 U.S. patent filings in cybersecurity and AI, said many breaches stem from poor security practices rather than advanced attack techniques. “The pattern is rarely a clever zero day in the client’s own app. It is trusted access.”
The most common failures involve identity and remote management controls. “MFA missing on the admin path, shared jump boxes, standing privileged accounts, and weak logging on the MSP side are what turn a vendor incident into a client incident.”
(Writer’s Note: In conversations with MSP owners for this and other articles, many pointed to how Barracuda XDR can help. Continuous monitoring across client environments can flag suspicious behavior from trusted connections, including lateral movement following a compromised RMM or backup platform.)
O’Connor also highlighted the accountability gap that follows. “MSPs are expected to answer for the security failures of vendors they selected but did not truly scrutinize. ‘We use a reputable partner’ is not a risk-management program. Before granting broad access, MSPs need to understand a platform’s privilege model, breach-notification obligations, logging, data handling, and how to disable access quickly when something goes wrong.”
Questions every MSP should ask vendors
Kevin Walker, founder and senior cybersecurity consultant at Black Swan Cyber Security Solutions, has spent more than 30 years in IT and has seen firsthand why MSPs are attractive targets. “I think MSPs have to accept that we’re an attractive target to cybercriminals. Compromise the right MSP account or platform and an attacker has not found the keys to one business. Potentially, they have found the keys to dozens, and it does not take an incredibly sophisticated attack to get there.”
Walker’s advice for building a practical vendor risk program is straightforward. “A small business is not realistically going to investigate every company sitting five layers beneath every piece of software it uses, but it should at least understand where the important dependencies are.”
His starting questions for any vendor review are direct:
- Which suppliers can access your systems or data?
- What can they actually see or change?
- Do they have administrator access?
- Is MFA enforced?
- Are they using individual named accounts rather than shared logins?
- Who inside the business owns that supplier relationship?
- How quickly could you remove their access if something went wrong?
From there, Walker recommends ranking vendors by the risk they present. “Concentrate first on suppliers with privileged access, sensitive information, or a service the business would struggle to operate without.”
Those critical suppliers deserve a deeper review. MSPs should understand how vendors would report a security incident, what happens to data when a contract ends, and which key suppliers they depend on. “That last question is easily missed. You may have done plenty of due diligence on the company you’re buying from, but it could depend entirely on another cloud platform, software developer, or service provider you’ve never heard of.”
Make vendor reviews an ongoing process
Walker is firm about the limits of one-time assessments. “A supplier questionnaire completed two years ago tells you what somebody said two years ago. Their systems may have changed. Their ownership may have changed. Your use of their service may have changed.”
That is why he sees a recurring service opportunity for MSPs. Vendor risk management should be an ongoing process, not a one-time compliance exercise. “Start with an initial review. Identify important suppliers, what information they hold, what access they have, and how critical they are to business operations. Then revisit that review quarterly or every six months.”
The client deliverable should remain simple. “A short report showing what matters, what has changed, and what needs attention is far more useful than handing an SME a complicated risk score and a 40-page document nobody will read.”
Trust starts with your own security
Lejin sees the opportunity in a similar way, but he adds one requirement MSPs cannot ignore. “This is a genuine offering if you are willing to be audited yourself first. Clients are right to ask who is watching the watcher.”
He recommends a quarterly vendor and access review instead of a one-time PDF. That review should inventory third parties, rank them by blast radius, ensure unused admin paths are removed, and evaluate what would happen if an RMM platform became unavailable or hostile.
MSPs should also include the same standards in their own contracts. That means dedicated accounts for each client, no shared passwords, MFA, logging, and a 24-hour breach-notification obligation. “The work is recurring because vendors and access change every month.”
Walker brought the discussion back to the concern that keeps many MSP owners awake at night. “If you don’t know which suppliers can log in, what they can see, and how you’d cut them off at 2 a.m., you don’t really have third-party risk management. You’ve just got a list of invoices.”
Photo: Zoomik / Shutterstock
