MSP Supply Chain Risk: What a Vendor Breach Really Means for Your Business
When ransomware operators breached Kaseya's VSA remote-monitoring platform over the July 4th weekend in 2021, they didn't just compromise one company -- they hit an estimated 1,500 downstream businesses through roughly 60 managed service providers in a single stroke. That attack is now a standard reference point in security briefings, but the pattern it revealed has only gotten worse heading into 2026: small and mid-size businesses are increasingly compromised not because of anything they did wrong, but because a vendor several links up their supply chain got breached first. Recent industry incident reports consistently find that a growing share of breaches affecting SMBs originate through a third party -- an MSP, a cloud application, a software vendor, or a connected IoT device -- rather than through the target company's own network perimeter. If your business relies on outside vendors for IT, software, or physical security systems (and virtually every business does), that exposure is now yours whether you've audited it or not.
The mechanics of MSP supply chain risk are what make it so dangerous. A managed service provider typically holds privileged, persistent access into every client network it manages -- remote monitoring and management (RMM) agents, domain admin credentials, VPN tunnels, and often unrestricted access to backups and email systems. That access is the entire value proposition of managed IT: it's how an MSP patches systems, resolves tickets, and monitors for threats without someone physically visiting every site. But it also means a single compromised MSP credential, or a single vulnerable RMM tool, becomes a skeleton key into every one of that MSP's clients simultaneously. Attackers understand this math better than most defenders do. Compromising one fifteen-person MSP with 200 client contracts is far more efficient than compromising 200 businesses individually, and threat actor groups have increasingly built their operations around exactly that arithmetic.
It isn't only MSPs. Software supply chain attacks -- where attackers compromise a legitimate vendor's update mechanism or codebase to distribute malware to every downstream customer -- have become a preferred technique precisely because they bypass the target's own defenses entirely. The 2020 SolarWinds Orion compromise, which affected an estimated 18,000 organizations through a poisoned software update, remains the textbook case, but similar techniques have shown up repeatedly since in build-pipeline compromises, malicious npm and PyPI packages, and compromised browser extensions. For a California SMB, the exposure isn't limited to the big-name vendors either -- it's every SaaS tool, every accounting platform, every property management system, and every scheduling app with a login connected to your business, each one a potential entry point if that vendor's own security posture is weak.
Physical security and building systems have quietly become part of this same attack surface, which is often the most overlooked piece. Network-connected cameras, door access controllers, and building automation systems frequently run on manufacturer firmware that's rarely patched and often shipped with default or weakly secured credentials. The 2016 Mirai botnet turned exactly this class of device -- consumer routers and IP cameras -- into one of the largest DDoS platforms ever recorded, and security researchers have continued to find similar vulnerabilities in commercial-grade access control panels and camera systems years later. When those devices sit on the same flat network as your servers and workstations, a compromised camera isn't a nuisance, it's a foothold. This is part of why we've written before about how cyber and physical security are converging into a single risk surface rather than two separate departments' problems -- an IoT device installed by a low-voltage contractor and a laptop managed by an IT vendor now need to be governed by the same security policy, not two disconnected ones.

Multifamily and affordable housing operators carry a particular version of this exposure because their technology stack is inherently multi-vendor by design. A typical property runs a property management platform like Yardi, AppFolio, or Entrata, a separate access control system, a camera platform, a resident Wi-Fi provider, and often a regional or national IT vendor overseeing all of it -- each one a separate supply chain link, and each one a separate point of failure if that vendor is breached. Add HUD, LIHTC, or state compliance reporting obligations layered on top, and a vendor-side breach doesn't just risk operational downtime, it risks a compliance and disclosure obligation the property owner may not even know they've inherited until the vendor discloses it publicly, often weeks after the fact.
Due diligence on vendor risk has become a formal requirement rather than a best practice in more regulatory frameworks every year. NIST's Cybersecurity Framework 2.0, updated with expanded governance language, explicitly calls out third-party and supply chain risk management as a core function organizations need to document, not an afterthought bolted onto a vendor contract. CMMC Level 2, which applies to defense subcontractors handling controlled unclassified information, requires organizations to assess and manage the security posture of their own suppliers as part of certification -- meaning your compliance can be undermined by a vendor's failure even when your own controls are sound. California's CPRA rules add another layer for any business handling consumer data, requiring contractual and practical assurances that service providers protect that data adequately, which is a meaningfully different bar than simply trusting a vendor's marketing claims.
Vetting vendor security in practice comes down to a short, concrete list of questions most businesses never ask before signing a contract: Does the vendor carry cyber liability insurance and can they produce proof? Do they enforce phishing-resistant multifactor authentication on their own staff accounts, especially any account with access into your systems? Do they segment client environments from one another, or does one compromised credential expose every client simultaneously? Have they undergone an independent audit -- a SOC 2 report, a penetration test, anything beyond a self-attestation questionnaire? And critically, do they have a documented incident response and notification process with a specific timeline, so you're not finding out about a breach affecting your data from a news article? Most SMBs never ask a single one of these questions of their MSP, software vendors, or security integrators, largely because nobody at the business owns vendor risk as a distinct responsibility.
The remediation isn't necessarily fewer vendors -- for most businesses that's impractical -- it's fewer blind spots across the vendors you keep. That means maintaining an actual inventory of every vendor with system access or data access, tiering them by the sensitivity of what they touch, and applying least-privilege principles even to trusted MSPs and integrators rather than handing out domain admin by default. It means network segmentation so that a compromised camera, door controller, or vendor VPN tunnel can't move laterally into finance systems or backups. And it means monitoring vendor access the same way you'd monitor an employee's -- logging what an MSP's RMM tool actually does on your network, not just trusting that it's benign because it's supposed to be there.
This is precisely the gap between a commodity IT vendor and a properly managed security posture, and it's where the choice of MSP itself becomes part of your supply chain risk calculation rather than the solution to it. Mytek Pros' managed IT engagements are built around documented least-privilege access, segmented client environments, and continuous monitoring specifically because we know our own access model is itself a piece of your attack surface -- not just a convenience we're selling you. As a licensed low-voltage contractor (License #1116987, DIR registration PW-LR-1001158430) and BICSI-certified, DBE/DVBE/MBE-certified MSP, we design network segmentation into cabling and Wi-Fi projects from day one so that cameras, access control, and IoT devices never sit on the same flat network as core business systems, closing off the exact lateral-movement path that turns a single compromised device into a full breach. If you're evaluating your current IT vendor's own security posture, or trying to understand what a proactively segmented, monitored network should actually cost against what you're paying now, our free Managed IT Cost Estimator gives you a real per-user benchmark to compare against your current contract. Call (619) 353-5702 or email inquire@mytekpros.com to have us map every vendor touching your network and tell you honestly where your exposure actually sits.
Questions about it services? Get in touch or explore our IT Services.
