GlassbreakGlassbreak

How should an MSP respond when its RMM platform is compromised?

Glassbreak Team · Published 2026-07-26

An RMM compromise can turn a normal administration channel into an attacker distribution channel. The immediate goal is not to keep using the tool more carefully; it is to establish a trusted response path that does not rely on the affected control plane.

First 30 minutes

  1. Open an out-of-band responder channel.
  2. Freeze non-essential RMM changes and preserve available logs.
  3. Verify the incident through an independent source.
  4. Identify tenants, agents, credentials, scripts, and integrations that may be exposed.
  5. Retrieve client contacts and emergency access through an independent system.
  6. Assign an incident lead, technical lead, client lead, and evidence owner.

Prioritise client action

Group clients by confirmed exposure, business criticality, and the availability of alternate administration. Avoid treating every installed agent as identical when the available evidence points to a narrower scope.

For each affected client, record the action, approver, timestamp, evidence, rollback condition, and next update time. Keep those records outside the RMM and outside any identity provider suspected of compromise.

Prepare before the incident

Maintain an independent inventory of client incident contacts, emergency administrator credentials, remote-access alternatives, critical services, and approved containment actions. Exercise the plan without using the normal RMM session.

Glassbreak is designed to sit alongside the daily RMM and remain available when that operational stack is unavailable or untrusted. Start with the MSP vendor-failure readiness approach, then assess the same dependency principles with the Microsoft 365 outage assessment.

Frequently asked questions

Should an MSP immediately uninstall the RMM agent everywhere?
Not automatically. Preserve evidence, understand the control-plane risk, and use a reviewed containment plan. A rushed fleet-wide action can destroy evidence or interrupt critical services.
Where should emergency credentials be stored?
In an independently available system whose identity, hosting, and recovery paths do not share the RMM's failure domain.

Stay Updated

Get product updates and security insights. No spam, unsubscribe anytime.

We respect your privacy. See our privacy policy.