Research this month shows MSPs are increasingly concerned about supply-chain security threats. It reflects a clear shift in attacker strategy: why break into one organisation when you can compromise a trusted supplier and reach dozens at once?

Why it matters

Supply-chain attacks are efficient for criminals and hard for victims to see coming, because the malicious activity arrives through a channel you already trust. Everyone is somebody’s supplier, and somebody’s customer.

The answer is shared discipline: vet your suppliers, limit the access you grant them, monitor for unusual behaviour, and expect your own customers to ask the same of you. We help clients tighten both ends of that chain.

Why MSPs are a prime target

Managed service providers hold privileged, trusted access into many client networks at once, which makes them an efficient prize: compromise one provider’s management tooling and you can potentially reach every organisation it looks after. High-profile incidents have shown attackers deliberately targeting the remote-management and monitoring platforms MSPs rely on. That is precisely why the questions clients now ask their IT partner — about MFA, access control and monitoring — are entirely reasonable, and why a good provider welcomes them.

What good discipline looks like

On both sides of the relationship the principles are the same: grant suppliers the least access they need and no more, protect every management and administrator account with strong multi-factor authentication, monitor for unusual behaviour on privileged accounts, and set clear security expectations in contracts. Customers should expect transparency from their MSP, and MSPs should expect the same scrutiny of their own suppliers. We hold our own tooling to that standard and help clients apply it to the vendors in their chain.

Ask your own provider directly how they protect their management tools and how they would notify you of an incident: a confident, specific answer is a good sign, and a vague one tells you something too.

Source: ITPro, 12 June 2026.