What happened
In early August it was confirmed that attackers had exploited a flaw in N-able N-central, a platform IT providers use to remotely manage their customers' computers. According to The Hacker News and Rapid7, it was possible to bypass the login and take over the server.
The US agency CISA added the vulnerability to its catalogue of actively exploited flaws, after real intrusions at customers. This is not a theoretical risk. It happened.
Why it concerns you, even if you have never heard of N-able
Almost every IT provider uses some form of remote management. It is how we install, patch and troubleshoot without driving out to you every time. The tool has different names at different providers, but the principle is the same: a small agent on every computer, with high privileges, controlled from a central server at the provider.
That means your security is never better than your provider's security. You can have everything in order on your side and still be affected, because somebody else was affected first. It is uncomfortable to say as a provider, but it is true.
Five questions to email your IT partner this week
Ask us too. A provider who gets annoyed by the questions is answering them indirectly.
- Which remote management tool do you use, and where does the server run? You have a right to know what sits on your computers.
- How fast do you patch it when a critical flaw appears? The answer should be in hours, not "we usually keep up".
- Do you have multi-factor authentication on the console itself? If the admin tool is protected by a password alone, the rest of the conversation is pointless.
- Does the contract say you will notify us if you are breached? Many contracts cover your incidents, but not the provider's.
- Can we see the logs of what you have done on our machines? Transparency is not distrust. It is hygiene.
What we recommend
Remote management is a legitimate and necessary tool. The alternative, nobody keeping your computers updated, is worse. But it is permanently a single point where a lot can go wrong, and anyone claiming their particular product has solved that is overstating it.
What you can do is choose a provider who answers the questions above straight, patches fast, and writes down what applies. With us that is part of Managed IT: documented, with your visibility, and with no binding period. Want an independent review of what your current providers actually have access to? Book a free consultation.