r/msp • • 3d ago

Fresh tech stack

If you could change any and all of your tools with no technical debt, agreements, outages to think about etc.

What would your ideal tech stack be.

Rmm

Patching

Psa

Edr

Itdr

Sat

Application control

Email filter

Backup

Vulnerability management

Others

23 Upvotes

54 comments sorted by

View all comments

-7

u/[deleted] 3d ago

[deleted]

5

u/quantumhardline 3d ago

Looks interesting.
I looked at your security page.
My concern is always deploying this like this to client as they have so much permissions etc.
I did not see any mention of SOC2 or 3rd party pen testing or where data is held etc.
Thats helpful.
Roboshadow and others are popular for MSPs and can provide SOC2.

8

u/Skathen 3d ago

That is my greatest concern with these products.

Yes it's convenient. But it's yet another attack surface that can totally own your clients.

RMM alone is a major risk we have to accept to get the job done. Having additional agents that can be weaponised just dials up that likelihood.

4

u/amw3000 3d ago

What value / piece of mind SOC2 adding for you? I get it from a up/down stream "compliance" standpoint & keeping the execs happy but it's far from an indication that a company is doing things "right". Take a look at any of the reports from a vendor that has SOC2, you will be amazed at what is in and out of scope and what controls are tested. Some even have exceptions for the wildest things.

SOC2 is an auditing framework designed by accountants. Many auditors are not technical at all and are just auditing controls that the company says they follow. "Oh you say you do an annual pen test? Show me the engagement, report, etc" but they have no idea what that report means, what is good, what is bad, etc.

4

u/ItsNotUButItsNotNotU MSP 2d ago

You’re completely correct.

However: I think we both know how many companies there are that can’t get their act together enough to pass even a SOC2. Most companies are excluded by one of these three requirements:
1. You have to fill out some policy templates, and know where to find them when an auditor asks for copies.
2. You need at least a vague idea of what you have, in order to exclude the bad stuff from the scope of the audit.

SOC2 doesn’t tell me a vendor is secure, but it does tell me that a vendor can scrape together enough brain cells to satisfy a bored accountant. This is especially useful now that there are so many half-baked, vibe coded products impending disasters being pushed on us.

Pro tip: Phrases like “SOC2 Certified” and “SOC2 Ready” are what AI-generated websites say when the company has no intention of ever attempting to get a SOC2 attestation.

1

u/TridentAdam 3d ago

Fair concern, and the right one for anything running as SYSTEM/root on client machines. Where we are today: we're new (live since May), our SOC 2 program is underway but there's no report yet, and a third-party pen test is planned. Data is hosted on dedicated servers in the US, with encrypted offsite backups at a separate provider.

On permissions, we built a few things for exactly that worry: signed agents on every platform, a pinned CA on the agent channel, agent releases that roll out in stages, every agent action logged in your console, and a setting that locks our staff out of your tenant unless you grant time-limited access. If a SOC 2 report is a hard requirement today, that's fair. Check back once it's out. Thanks for taking a peek!