Pen testing · SaaS & technology
Penetration Testing for MSPs & IT Consultancies
Penetration testing for an MSP or IT consultancy examines the RMM console, remote-access tools and GDAP paths into client tenants, the exact surfaces recent supply-chain attacks have used against this sector. The trigger is usually a client asking for the firm's latest report, a cyber-insurance renewal requiring one, or a decision to test before attackers do. We test the firm's own infrastructure the way it would test a client's, then hand back findings the firm can act on and show.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
What penetration testing has to reach inside an MSP's own stack
Testing a normal SMB network misses most of what actually matters here: the console that reaches every client, not just the office Wi-Fi.
The RMM platform itself
ConnectWise, Kaseya VSA, NinjaOne, Datto RMM, N-able or Atera, tested for the authentication and authorization weaknesses that have turned RMM platforms into supply-chain entry points across the industry.
Remote-access and screen-sharing tools
ScreenConnect, Splashtop or TeamViewer sessions, tested against the exact class of authentication bypass that made CVE-2024-1709 a mass-exploited vulnerability within days.
GDAP and CSP tenant paths
Whether a compromised technician account can pivot from the firm's own Microsoft 365 tenant into delegated administration on client tenants, and how far that path actually extends.
PSA and documentation vault exposure
ConnectWise PSA, Autotask or HaloPSA, and IT Glue or Hudu vaults, tested for whether ticket histories and stored credentials are reachable by an attacker who gets a foothold anywhere in the stack.
The firm's perimeter and remote workforce
VPN, firewall management interfaces and technician endpoints, the same categories a client engagement would test, applied here to the firm's own office and remote staff.
Regulatory map
Why penetration testing is now expected of the firm, not just sold by it
No regulator mandates a pen test by name for MSPs specifically. The expectation arrives through contracts, insurers and government guidance instead.
AA22-131A's hardened remote-access expectation
The joint CISA/CCCS advisory tells MSPs to harden remote access and monitor for anomalous activity, and testing is how a firm demonstrates that hardening actually holds rather than asserting it does.
CCCS baseline controls as the benchmark
The 13-control baseline many MSPs deploy for clients includes vulnerability management expectations a firm should be able to demonstrate against its own environment, not only its clients'.
Cyber-insurance underwriting questions
Renewal applications increasingly ask when the firm last tested its own remote-access and RMM tooling, and an answer of "never" affects both premium and available coverage.
Client MSA audit rights
Security schedules in client contracts increasingly include a right to request evidence of the firm's own security testing, not just a description of its process.
What goes wrong
What penetration testing on an MSP is actually looking for
Testing here is built around the specific ways this sector's own tools have already failed, not generic web-application findings.
The Kaseya VSA precedent
A zero-day in Kaseya's own VSA platform let REvil push ransomware to roughly sixty MSPs and up to fifteen hundred downstream businesses in July 2021, proof that RMM platforms are worth testing before a vendor's own patch cycle catches up.
ScreenConnect's authentication bypass
CVE-2024-1709 and CVE-2024-1708 were mass-exploited within days of disclosure, and testing verifies whether the firm's own remote-access instance would have survived that window.
Credential stuffing against tools without MFA
The infostealer campaign behind the 2024 Snowflake-linked breaches ran on stolen passwords and missing multi-factor authentication, a pattern testing checks for directly on RMM and PSA logins.
GDAP privilege escalation paths
Whether a lower-privileged technician role can be escalated into broader delegated administration across client tenants, a finding generic penetration testing outside this sector never has reason to look for.
Our pen testing for msps & it consultancies
What our penetration testing covers for an MSP or IT consultancy
The same rigour applied to any client engagement, turned on the firm's own environment.

Vulnerability exploration
Testing across the RMM console, remote-access tools, PSA platform and GDAP-connected tenant paths to identify where exploitable weaknesses actually exist.
Response capability observation
Insight into how the firm's own detection and alerting respond during simulated attack attempts, surfacing gaps in monitoring before a real incident does.
Defensive improvement guidance
Directional findings on where hardening, patch cadence, access segmentation, MFA enforcement, would close the gaps testing identified, ranked by exploitability.
Standards and expectation awareness
Context on how results relate to the CCCS baseline controls, client MSA commitments and insurer expectations, so findings translate into language the firm can use externally.
How the engagement runs
How a penetration test runs against an MSP's own environment
Scoped to avoid disrupting active client tickets while still reaching the systems that matter most.
Step 1
Scope the engagement
We agree which systems are in bounds — RMM, remote-access, PSA, GDAP paths — and set a testing window that avoids peak ticket volume.
Step 2
Test in a controlled manner
Testing simulates real attacker techniques against the agreed scope, with rules of engagement that protect live client sessions running through the same tools.
Step 3
Deliver findings the firm can act on
A report ranks issues by exploitability and impact, distinguishing what needs fixing before the next client audit from what can wait for the next cycle.
Step 4
Retest and report
Once remediation is complete, we confirm the fixes hold and produce the report clients, insurers or auditors actually ask to see.
What it costs
What drives penetration testing cost for an MSP
Cost tracks the number of systems in scope: how many RMM and PSA platforms, how many client-facing GDAP paths, and whether the firm's own network and remote workforce are included alongside the core tooling.
Testing is priced per engagement rather than as a subscription, and firms facing an insurance renewal or a client audit often schedule it to land just ahead of that deadline. We scope cost after reviewing the firm's stack and the systems a client or insurer actually wants evidence about.
MSPs & IT Consultancies: Pen testing questions, answered
Yes, and for this sector that's usually the point of the engagement rather than an afterthought. Testing scoped to the RMM console, PSA platform and remote-access tools like ScreenConnect or Splashtop targets the exact systems that have produced this niche's defining incidents, rather than treating the firm like a generic office network.
It depends on the policy and the coverage tier, but renewal applications increasingly ask when the firm last tested its own environment, particularly the RMM and remote-access tools it also manages for clients. An annual cadence is common practice even where a policy doesn't spell out a fixed frequency, since insurers price risk on recency as much as on the existence of a report.
A report scoped to what that client's contract or questionnaire actually asks about, typically a summary of findings, severity ratings and remediation status rather than the full technical detail, which stays internal. If the firm hasn't tested recently, that request is usually the moment to schedule one rather than improvise an answer.
Production, where that can be done safely within agreed rules of engagement, because a staging environment rarely reflects the actual configuration, patch level and integrations attackers would encounter. Where production testing carries real client-impact risk, we scope carefully around active sessions rather than defaulting to a staging copy that would understate the findings.
A normal SMB engagement stops at the edge of one company's network. An MSP engagement has to account for GDAP-delegated paths into client tenants, a PSA system full of other companies' ticket histories, and an RMM console that functions as a single point of failure for every client behind it.
GDAP paths are typically included, because the question that matters most isn't whether the firm's own tenant is secure in isolation, it's whether a compromise there can escalate into delegated administration on a client's tenant. That path is exactly what generic testing outside this sector has no reason to examine.
More for msps & it consultancies
Other services for this niche
- Privacy & security for msps & it consultancies — overview
- Virtual CISO
- Virtual Privacy Officer
- Incident Response Planning
- Privacy & Security Policy Development
- Privacy & Security Training
- Vendor Security Review & Questionnaire Support
- SOC 2 Readiness
- ISO 27001 Readiness
- HIPAA Readiness
- M&A Privacy & Security Due Diligence
About this service
Answers & guides
- How much does a penetration test cost (and what affects the price)?
- How do we prepare for a customer security questionnaire?
- What is multi-factor authentication, and do I need it?
- How can I protect my personal and business information from cyberattacks?
- How Often Should You Pen Test Your Web App?
- Vulnerability Scan vs Penetration Test: Why You Probably Need Both
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.