Also on CyberFence: CyberFence's industry directory for other professions · CyberFence for Teams for business VPN with BAA and SSO .

IT technician working on server rack in blue-lit data center corridor

Managed service providers hold a uniquely dangerous position in the cybersecurity landscape. An MSP technician has privileged administrative access to dozens, sometimes hundreds, of client networks — their servers, endpoints, cloud environments, and security tools. That access is enormously valuable to attackers. Compromising one MSP employee's credentials doesn't yield access to one company. It can yield access to every company that MSP manages.

Ransomware groups figured this out years ago. The Kaseya VSA attack in 2021 used a single MSP management platform to deploy ransomware to over 1,500 businesses downstream. REvil, LockBit, and other ransomware operations have repeatedly targeted MSPs specifically because the access-to-victim ratio is dramatically higher than attacking individual companies.

A VPN is not a complete security program. But for MSP technicians connecting to client environments from home offices, on-site visits, co-working spaces, and hotel rooms, it is one of the most direct protections available against the credential theft that typically initiates these attacks.

Why MSPs Are Targeted More Than Their Clients

The attacker logic is straightforward: MSP technicians have privileged remote access to client environments using tools like ConnectWise, N-able, Kaseya, and similar RMM platforms. Those credentials are used constantly — from laptops, from home networks, from on-site visits at client locations where they connect to the client's guest Wi-Fi, from airport lounges while traveling between client sites.

CISA issued a dedicated advisory on MSP targeting (AA22-131A) co-signed by the FBI, NSA, NCSC-UK, ACSC, and other international cybersecurity agencies — an unusually broad joint advisory reflecting the global scale of MSP targeting. The advisory specifically identified remote access exploits, credential theft, and exploitation of RMM software as primary initial access vectors for attacks on MSPs.

The pattern is consistent across documented incidents:

  • Attacker obtains MSP technician credentials (via phishing, network interception, or credential stuffing)
  • Attacker uses legitimate RMM software to access client environments without triggering alerts
  • Attacker deploys ransomware, exfiltrates data, or establishes persistent access across multiple clients simultaneously

Each step in this chain has a defensive countermeasure. The credential theft step — the one that typically happens on networks outside the MSP's perimeter — is where a VPN provides direct protection.

The Specific Risk: RMM Credential Interception

MSP technicians authenticate to RMM platforms, PSA tools, client portals, and cloud management consoles constantly throughout the day. When those authentications happen over an unencrypted connection on a public or inadequately secured network, the credentials are exposed to interception through several mechanisms:

Man-in-the-Middle on Client Site Networks

MSP technicians frequently connect to client networks to perform on-site work. Guest or employee Wi-Fi at a client's office is not the same as the MSP's own secured network. On a poorly configured client network, an attacker with physical access or a rogue device on that network can intercept credentials as the technician authenticates to their RMM platform or other tools. AES-256-GCM encryption through a VPN closes this gap before any credential ever touches the local network.

DNS Hijacking Redirecting RMM Login Pages

On networks where an attacker controls DNS resolution, they can redirect a technician's browser to a convincing fake version of their RMM platform's login page. The technician enters valid credentials, which are captured, and they're forwarded to the real login. Web Shield DNS protection resolves this by encrypting DNS queries through CyberFence's servers rather than the local network, preventing hijacking before the redirect occurs.

Credential Theft in Coffee Shops and Airports

MSP technicians on the road regularly handle urgent client issues from whatever network is available. A client server going down at 11 PM means connecting from a hotel to resolve it. Connecting from an airport lounge while waiting for a flight means accessing client environments through public Wi-Fi. Each of these connections, unprotected, exposes credentials to the attacks documented in the CISA MSP advisory.

Protect every technician, every connection

CyberFence encrypts all traffic with AES-256-GCM before it leaves the device. Web Shield DNS blocks phishing and malicious domains. Zero logs. US-operated. One subscription covers every device your technicians use — Windows, macOS, iOS, Android.

Try CyberFence Free

The Compliance Dimension: What MSP Clients Expect

MSPs serving clients in regulated industries — healthcare, finance, legal, government contracting — increasingly face requirements around their own security posture as a condition of the business relationship:

HIPAA Business Associate Agreements

An MSP managing IT for a medical practice, dental office, or healthcare organization is a HIPAA Business Associate. The BAA requires the MSP to implement appropriate safeguards for ePHI, which HIPAA's Security Rule applies to data in transit. An MSP technician accessing a healthcare client's network over an unprotected connection from a hotel room is potentially transmitting ePHI over an unencrypted channel — a HIPAA Security Rule violation for which the covered entity and the BAA-bound MSP share liability.

CMMC for Defense Contractors

MSPs supporting defense contractors subject to CMMC requirements inherit security obligations for the systems they manage. CMMC Level 2 and Level 3 include specific controls around remote access, encrypted transmission, and access control. An MSP technician without a VPN connecting to a defense contractor client's environment from public Wi-Fi may be creating a non-compliant access path that puts the client's CMMC certification at risk.

SOC 2 Type II

Many MSPs pursue SOC 2 certification to demonstrate security posture to prospective clients. SOC 2 Type II examines whether controls were operating effectively over time. Remote access security — including encryption of connections to client environments — is directly relevant to the Confidentiality and Security trust service criteria. Auditors examining an MSP's remote access practices are looking for evidence of encrypted connections, not assumptions.

What the CISA MSP Advisory Says to Do

CISA's joint advisory on MSP targeting (AA22-131A) provides specific technical recommendations. Several directly map to what a VPN provides:

  • "Secure remote access applications and enforce MFA" — A VPN with AES-256-GCM encryption secures the transport layer for all remote access, regardless of which application is being used.
  • "Protect internet-facing services" — When a technician accesses client environments through a VPN, their source IP is the VPN server's, not their hotel room's — making client-side access controls more consistent and predictable.
  • "Monitor for unauthorized use of remote access tools" — Consistent VPN exit IP addresses make anomaly detection easier. An access attempt from an unexpected country becomes visible against a baseline of consistent VPN server IPs.
  • "Implement defense-in-depth" — Network-layer encryption is explicitly listed as part of the defense-in-depth posture recommended for MSPs.

Building a VPN Policy for MSP Teams

The protection is only consistent if every technician uses it every time. That requires a clear policy, not just a recommendation. Here is a practical framework:

  • VPN on before RMM open. Make VPN connection the first step in every technician's workflow before any client system is accessed. This can be enforced through policy or through split-tunneling rules that route all RMM traffic through the VPN.
  • Every device covered, not just company-issued laptops. Technicians using personal devices for emergency client access need VPN protection on those devices too. A single subscription covering all a technician's devices eliminates the coverage gap.
  • On-site client networks treated as public networks. Client guest Wi-Fi and even client employee networks are outside the MSP's control. Default to treating any network that is not the MSP's own office network as public, requiring VPN for all work activity.
  • Kill switch enabled. A VPN connection dropout during an active client session should halt traffic, not expose credentials on the local network. Kill switch configuration should be part of the standard VPN setup for every technician device.
  • Web Shield DNS blocking active. Phishing attacks targeting RMM credentials often use lookalike domains. DNS-level blocking of known phishing and malicious domains provides a technical enforcement layer that works even when a convincing phishing email gets through inbox filtering.

MSP-Specific Considerations for VPN Selection

For MSPs specifically, a few VPN characteristics matter beyond the standard criteria:

  • Zero-logs policy: MSP technicians access client networks that may themselves be subject to privacy and confidentiality obligations. A VPN that logs which client systems were accessed creates a record that could itself be a liability. CyberFence's zero-logs policy means no activity records are created or stored.
  • US-operated infrastructure: For MSPs serving government contractors, healthcare organizations, or financial institutions, routing sensitive administrative traffic through US-operated VPN infrastructure under US data handling standards matters for compliance posture.
  • Cross-platform coverage: MSP technicians work across Windows and macOS laptops and increasingly use iOS and Android tablets and phones for remote access. A single subscription covering all platforms ensures consistent policy enforcement across the team.
  • HIPAA-appropriate encryption: AES-256-GCM encryption satisfies HIPAA's Transmission Security standard for ePHI in transit — relevant for MSPs with healthcare clients under BAAs.

The Cost-Benefit Calculation

The average ransomware payment in 2026 is measured in hundreds of thousands of dollars. Business interruption, incident response costs, reputational damage, and client notification costs routinely add multiples of that figure to the total impact. The CISA advisory documents that MSP compromises have resulted in simultaneous attacks on multiple clients — meaning the downstream impact of a single MSP credential theft can be measured against a portfolio of client relationships, not just one incident.

A VPN subscription for a team of 10 technicians costs less than a single hour of incident response from a specialized cybersecurity firm. The risk it mitigates — credential interception on uncontrolled networks that is the documented primary access vector for MSP-targeting ransomware operations — is concrete, well-documented, and actively exploited.

CyberFence for MSP teams

AES-256-GCM encryption, Web Shield DNS blocking, zero logs, kill switch, US-operated infrastructure, and HIPAA-appropriate transmission security. Available on Windows, macOS, iOS, and Android.

Monthly $7.99/mo per device or Annual $88.21/yr ($7.35/mo, save 8%). One subscription covers all a technician's devices.

Start Your Free Trial

Want to go deeper? Read how CyberFence protects other regulated industries , the CyberFence Teams product page , or CyberFence plans and pricing .