Hackers Want to Move to Bigger Scores

What separates the bank robber from the burglar or the pickpocket? More risk, more planning, and the potential for a far bigger reward. There’s a reason why Hollywood mostly produces heist films where a bank vault and/or jewels are the target as opposed to a some iPhones and a TV.

For criminals of any sort, heading “upstream” is generally going to make for better rewards. That’s why MSPs are quickly becoming primary targets for cybercriminals. Our research found that attacks on MSPs have doubled in the last 18 months. Right now, it appears hackers see the MSP community as an opportunity to attack many businesses at once—meaning MSPs must do all they can to not be the weak link in the supply chain.

Supply chain shift

Why are hackers shifting their tactics? Small businesses have small IT budgets so the investment in security can’t be the main priority. Many of these businesses simply don’t understand standard security frameworks and rely on MSPs to guide them.

It follows, then, that an MSP is a more difficult target than an SME—so why bother? The pandemic may have been the catalyst for this change. Businesses that may never have considered remote working had to adapt quickly. Many turned to MSPs so they could do this in a structured and safe way. And in helping to secure these businesses, MSPs painted a big target on their back.

By taking control of an MSP, an APT (Advanced Persistent Threat) group can gain access to a much larger number of systems—MSPs can serve over a hundred clients and taking over their remote access and data privileges makes a hacker’s job all too easy. This popular strategy is a form of supply chain attack, where a bad actor infiltrates a system from a third party. While the MSP is compromised, they’re not the main target, so an APT will sit in their system and use it like a command center and quietly encrypt or steal data from small businesses.

The numbers show how popular (and effective) this approach can be. Our research found that almost all MSPs have suffered a successful cyberattack in the past 18 months. In fact, 90% have seen an increase in the number of attacks since the start of the pandemic. On top of this, one-third have been successfully attacked in the last quarter alone.

The effect of the pandemic has changed the equation in favor of taking on a trickier heist for bigger rewards.

Fighting back

It is crucial that MSPs fight back against this trend and not allow it to take hold. Today, it seems pretty much every business is under a near-constant assault of cyberattacks. If MSPs gain a reputation for being a weak link, businesses are less likely to trust them with this important task. The fact that the international cybersecurity alliance Five Eyes has issued an advisory aimed at MSPs to keep business secure should show just how important this issue has become.

There are, however, simple measures some MSPs are failing to take that would limit their exposure to risk. Our research revealed that a significant minority of MSPs are not following best practices when it comes to security hygiene.

For example, while almost all MSPs implement multi-factor authentication (MFA) for their customers, only 40% of MSPs—not even half—use it themselves. Even fewer MSP customers, one-third, are actually using MFA. MSPs that are not using this type of authentication are putting their systems at risk from phishing and other password-based attacks, giving hackers exactly the sort of access they require for a supply chain attack. Not only does this leave customers at risk, both from direct and supply chain attacks, it will make it tougher to convince a business to adopt extra authentication measures if its security partner does not. However, MSPs report they have plans to migrate 95% of customers to MFA in the next five years, with most being done in the next two years.

There are also a minority of MSPs failing to automate maintenance. Eighty percent of MSPs are automating patches and 85% are automating backup (both reassuringly high numbers), but it implies that 20% and 15%, respectively, are not. MSPs not automating these vital tasks, particularly patches, are leaving their own networks open to attack as well as their customers’ networks, and without the proper backup in place, it’s impossible to “roll back” from any compromise.

MSPs gained a great deal of trust thanks to their efforts during the pandemic in helping their customers roll out remote working at an exponential pace and keeping them secure throughout. But this success comes with a price—they are now targets for hackers looking to hunt bigger game, no longer satisfied with taking down single businesses for small rewards. MSPs cannot afford to let the trust they’ve accrued be eroded by being an easy target and failing to protect their own systems—their future success relies on reinforcing their reputation as a reliable, safe pair of hands.

Lewis Pope

Lewis Pope is the Head Security Nerd at N-able. Lewis began his IT career as a freelance PC technician before spending six years growing a break-fix business into an MSP. Over the last three years, he has helped N-able's partners make that same journey. As a Systems Security Certified Practitioner (SSCP), Lewis also helped MSPs further mature their security practices—so they can meet the challenges of the ever- evolving cybersecurity landscape with confidence.

Is It Time for a VMware Alternative?

Wind River • 22nd May 2025

Companies have options when it comes to replacing VMware as their cloud platform, to address rising costs, support concerns, and a shrinking partner ecosystem. If you are ready to contemplate a different vendor, here are five reasons why Wind River Cloud Platform should be on your short list of VMware alternatives.

AI Leads as VivaTech Unveils Top 100 Startups

Viva Technology • 14th May 2025

Viva Technology has unveiled the first edition of its “Top 100 Rising European Startups for 2025,” spotlighting the most promising young companies shaping Europe’s tech future. Germany, France, and the UK lead the ranking, which highlights high-growth startups across 13 countries. Artificial intelligence dominates the list, with 15 companies spanning AI agents, models, and infrastructure....

Birmingham Unveils the UK’s Best Emerging HealthTech Advances

Kosta Mavroulakis • 03rd April 2025

The National HealthTech Series hosted its latest event in Birmingham this month, showcasing innovative startups driving advanced health technology, including AI-assisted diagnostics, wearable devices and revolutionary educational tools for healthcare professionals. Health stakeholders drawn from the NHS, universities, industry and front-line patient care met with new and emerging businesses to define the future trajectory of...

Why DEIB is Imperative to Tech’s Future

Hadas Almog from AppsFlyer • 17th March 2025

We’ve been seeing Diversity, Equity, Inclusion, and Belonging (DEIB) initiatives being cut time and time again throughout the tech industry. DEIB dedicated roles have been eliminated, employee resource groups have lost funding, and initiatives once considered crucial have been deprioritised in favour of “more immediate business needs.” The justification for these cuts is often the...

The need to eradicate platform dependence

Sue Azari • 10th March 2025

The advertising industry is undergoing a seismic shift. Connected TV (CTV), Retail Media Networks (RMNs), and omnichannel strategies are rapidly redefining how brands engage with consumers. As digital privacy regulations evolve and platform dynamics shift, advertisers must recognise a fundamental truth. You cannot build a sustainable business on borrowed ground. The recent uncertainty surrounding TikTok...