A data disclosure at Pax8 is reported to have affected around 1,800 managed service providers. As an MSP ourselves, incidents like this land close to home — they’re a reminder that the tools and platforms the security industry relies on are targets too.
The Foresight take
MSPs sit in a position of trust, with access to many clients’ systems. That makes the platforms MSPs use an attractive target, because one compromise can ripple outwards. It’s a responsibility we take seriously.
It’s why we’re deliberate about vendor selection, least-privilege access, and monitoring our own supply chain — the same discipline we ask of our clients. When you choose an IT partner, it’s fair to ask how they secure their own house, not just yours.
Why this lands close to home
Managed service providers occupy a position of deep trust, with privileged access into many clients’ systems at once. That is exactly what makes the platforms MSPs themselves rely on such attractive targets: compromise one widely used tool and the effects ripple outwards to everyone who depends on it. As an MSP, we read incidents like this not as someone else’s problem but as a reminder that the security industry’s own supply chain is squarely in scope, and that trust has to be earned and maintained.
Choosing a trustworthy IT partner
It is entirely fair to ask an IT provider how they secure their own house, not just yours. Look for multi-factor authentication on every management and administrator account, least-privilege access so routine work never uses all-powerful credentials, active monitoring of privileged activity, deliberate vendor selection, and a clear commitment to tell you promptly if something goes wrong. We hold ourselves to that standard — the same discipline we ask of our clients — because an IT partner’s security is part of yours.
The best time to ask these questions of a provider is before you sign, not in the aftermath of an incident.
Source: ITPro, 16 January 2026.