Connect with us

Business & Technology

Why cybercriminals are targeting MSPs first

Published

on


The growth of supply chain attacks in 2025 has reshaped breach economics. Instead of targeting organisations one by one, cybercriminals are increasingly exploiting centralised third-party platforms to gain access to entire customer ecosystems.

In practice, this means risk is moving upstream. When trusted service layers are compromised, incidents rarely stay contained and can spread across multiple customer environments – raising the bar for security, visibility and resilience at the provider level.

Recent warnings from the UK government underline how quickly evolving technologies – particularly AI – are supercharging attackers’ ability to locate and exploit access points at scale. MSPs have become an attractive point of entry, making their security practices the focus of customers and regulators alike.

Group-IB’s High Tech Crime Trends research highlights how threat actors are increasingly prioritising access to high-trust sectors such as financial services, SaaS platforms and MSP environments. For MSPs, this shifts the risk profile significantly, with phishing, ransomware and credential theft remaining a persistent challenge.

Why attackers are targeting MSP ecosystems

Modern organisations depend on MSPs not just for operational efficiency, but for secure access management, infrastructure resilience and regulatory alignment. MSP platforms sit at the intersection of customer networks, cloud services, SaaS applications and identity environments. This position makes MSPs stewards of inherited trust across entire business ecosystems – when that trust is compromised, the consequences extend far beyond a single organisation.

Rather than targeting organisations individually, attackers are increasingly focusing on centralised environments. These platforms offer a multiplier effect, allowing a single compromise to impact multiple downstream clients. Remote monitoring and management platforms, multi-tenant administration consoles and aggregated identity systems have become high-leverage entry points for threat actors. Once inside, attackers can move laterally, harvest credentials, conduct reconnaissance and deploy payloads across multiple customer environments.

In practice, this type of access allows attackers to observe customer environments over extended periods. With this intelligence, threat actors can identify high-value targets and tailor follow-on attacks with greater precision. In some cases, compromised MSP credentials have been used to disable security tools or deploy malicious updates under the guise of legitimate maintenance activity.

Campaigns attributed to groups such as DragonForce demonstrate how exploitation of MSP tooling can enable credential theft, data exfiltration and ransomware deployment at scale. Group-IB’s close collaboration with international law enforcement bodies, including INTERPOL and Europol, has played a key role in tracking and disrupting campaigns of this nature.

The industrialisation of cybercrime meets the managed services model

The convergence between industrialised cybercrime and the managed services model reflects a broader shift in how cybercrime operations are structured and scaled. In practice, this means the creation of affiliate programmes, service platforms and monetisation strategies designed to maximise efficiency. Attackers have adopted the same logic as managed services: centralise access, standardise operations and scale efficiently.

For attackers, this presents a significant opportunity. For MSPs, it raises the stakes considerably. This shift shortens the window MSPs have to identify and stop attacks. Industrialised cybercrime relies on speed and standardisation. If one approach proves effective in one MSP environment, it can be rapidly replicated elsewhere – exploiting the shared tools and models that underpin managed services.

The priority for MSPs becomes breaking attack patterns before they can be replicated across multiple customer environments. As cybercrime operations gain speed, the margin for error narrows significantly.

How expectations of MSP security are changing

As threat exposure grows, customers are becoming more discerning about the security practices of their MSPs.

Customers are increasingly evaluating MSPs based on governance transparency, identity security controls, incident readiness and third-party risk management practices. Regulatory frameworks such as NIS2 are reinforcing expectations around operational accountability and supply chain oversight. Security is no longer just a technical feature – it is increasingly treated as a business-wide issue. Resilience maturity is becoming the dividing line between strategic MSPs and commodity providers.

Forward-looking MSPs are strengthening privileged access controls, monitoring behavioural anomalies across multi-tenant environments, segmenting client infrastructures and conducting continuous supply chain risk assessments. These measures help reduce risk and limit the potential impact of compromise across customer environments.

What this means for MSPs going forward: Intelligence-led defence

As digital environments become more interconnected, reactive security models are proving insufficient. MSPs should adopt an adversary-centric approach, using threat intelligence to monitor how specific attacker groups operate, which tools they exploit and how campaigns typically unfold.

This approach enables earlier detection of suspicious behaviour and faster disruption of attack chains before compromise spreads downstream. It also allows MSPs to anticipate emerging risks across their customer base, rather than responding only after incidents occur.

Critically, this intelligence must be both global and locally relevant. Gathering local intelligence from teams located across the regions they operate in enables the translation of global adversary intelligence into region-specific insights with those who know the market best. For MSPs serving local markets, this ensures threat intelligence is directly applicable to their operating environment and customer base allowing them to better track and respond to threats.

Those MSPs that adapt to this model will be better positioned to operate in an increasingly complex threat landscape.

MSPs are no longer just managing infrastructure – they are safeguarding access, visibility and the control layers that modern business depends upon.



Source link

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Business & Technology

Connected building systems pose growing cyber risk

Published

on


Restore Information Management has warned that connected building systems are becoming a cyber security risk for organisations, with many businesses failing to secure operational technology such as building management systems, access control and CCTV.

The warning comes as attackers expand their focus beyond traditional IT to target the technology that supports day-to-day building operations. These systems are increasingly internet-connected, remotely managed and linked to cloud services, widening the number of potential entry points for attackers.

Official figures underline the scale of the issue. The latest UK Government Cyber Security Breaches Survey found that 43% of UK businesses experienced a cyber security breach or attack in the past 12 months.

David Robinson, Head of Cybersecurity at Restore Information Management, said many organisations have basic weaknesses across their operational technology environments, particularly default settings and poor access controls.

“Many building systems still rely on default credentials straight out of the box. If these credentials aren’t changed, cyber criminals can gain access to critical systems with relative ease. As today’s digital building systems become increasingly connected, remotely managed and cloud-based, they are evolving faster than many organisations can secure them. Without the right controls, attackers could disrupt critical building systems, disable physical security measures or use them as a route into the wider corporate network,” Robinson said.

Attack surface

Robinson said one of the main steps organisations should take is to establish a full inventory of connected building systems, including building management systems, access control platforms, CCTV networks and environmental controls.

In practice, that means knowing what equipment is connected to the network, who is responsible for managing it and how users, contractors and suppliers can access it. Security teams often have a clearer view of laptops, servers and business applications than of operational technology embedded in buildings, creating a gap that can persist for years.

He also highlighted the risk posed by shared and default credentials. Manufacturer-set passwords remain common across a range of connected systems, and shared accounts can make it difficult to trace activity or remove access when a staff member or contractor leaves.

Restore urged organisations to replace default credentials as soon as systems are deployed, remove shared logins and ensure each employee or contractor has an individual account. That allows access to be monitored and withdrawn when required.

Remote access

Another area of concern is remote access for suppliers and maintenance providers. Building systems often rely on outside specialists for configuration, support and servicing, but these links can remain open long after a project has ended.

Robinson said access should be formally approved, reviewed regularly and removed once work is complete or contracts expire. Dormant contractor accounts, he added, should not remain active.

The issue has become more pressing as facilities technology has become easier to access from outside a site. Remote management can help operators maintain systems across multiple buildings, but it also creates another route that needs oversight from both facilities and cyber security teams.

Network separation

Restore also called for stronger segmentation between operational technology and corporate IT environments. Separating building systems from wider business networks can limit the damage if one part of the estate is compromised.

This matters because attackers who gain access to a connected operational system may try to move laterally into more sensitive parts of the organisation. Segmenting networks can make that movement harder and reduce the impact of a breach.

Security and facilities teams should work together to review legacy environments and identify where older systems can be better isolated. In many organisations, building technology has evolved in stages over a long period, leaving a mix of old and new equipment with varying security controls.

Strategic priority

Robinson’s final point was that operational technology should no longer sit outside mainstream cyber planning. He argued that connected building systems need to be included in an organisation’s wider security strategy, with regular reviews, staff awareness and stronger security design at the point of deployment.

That view reflects a broader shift in cyber risk management as physical infrastructure becomes more digital. Systems once treated mainly as facilities assets are now part of an organisation’s connected estate and can affect both physical security and business continuity if disrupted.

Restore Information Management is one of the UK’s larger information management providers and says it works with more than 6,000 clients, including more than 80% of NHS trusts. “Cyber security is no longer confined to servers and laptops. As buildings become smarter, the systems that control them require the same level of protection as every other critical asset,” Robinson said.



Source link

Continue Reading

Business & Technology

Prince William-backed helicopter company profits rise

Published

on



Airbus Helicopters opened a new £50m headquarters and factory facilities at Oxford Airport in Yarnton.

Opened in September 2024 by Prince William, Airbus Helicopters employs around 250 people in Oxford and has room for 32 helicopters.

New accounts published by the company shows the business reported an annual profit of £10.1m in the calendar year 2025 also its first full year from Oxford.

This was up 13 per cent from £8.9m the year before.

READ MORE: Jeremy Clarkson praised for his efforts as he admits ‘no feeling like it’

Airbus Helicopters said this profit was boosted by a £2.5m foreign exchange gain and was despite a drop in turnover.

“The company has now completed its first full year of operations at the new, larger hangar facility at London Oxford Airport, following the move in July 2024 and the commencement of a 25-year lease agreement,” said Yann Rozo of Airbus Helicopters in a report.

“The company would like to recognise the positive contribution of its customers, employees and other stakeholders in achieving the results of 2025 and looks to further enhance these relationships during 2026.”

Revenue for 2025 was at £138.9m compared with £158.6m the year before.

The decrease in turnover compared to the prior year has been attributed to the timing of aircraft deliveries and the expiry of a Ministry of Defence contract.

Airbus completes helicopters built in France and Germany at its Oxford site before selling on to customers including the National Police Air Service.





Source link

Continue Reading

Business & Technology

Cequence adds AI Gateway controls for agentic zero trust

Published

on


Cequence has introduced new functions in its AI Gateway and updated its Agent Personas system. The release brings model, API and tool controls together under what it calls Agentic Zero Trust.

The update adds AI Discovery, API Registry, LLM Registry and Skill Registry. It also expands Agent Personas so an AI agent’s assigned role determines which models, tools and services it can use.

Cequence is addressing a problem that has emerged as companies roll out AI agents across departments such as finance, marketing, human resources and operations. Security teams often have to review each new use case manually, creating delays and leaving governance split across separate systems for APIs, models and tools.

Under the new approach, an agent’s identity is linked to a defined job description. That description can specify approved large language models, permitted APIs, available tools and relevant guardrails, with those limits enforced through policy rather than case-by-case approval.

Unified controls

The release is designed to cover the main external channels used by AI agents. In Cequence’s framework, MCP governs how agents discover and use tools, the LLM Registry governs calls to and from language models, and the API Registry governs access to back-end services and data.

Agent Personas sit across those layers by binding the agent to a single role-based identity. Cequence argues that this prevents agents from operating beyond their intended remit, even if they encounter exposed credentials or vulnerabilities elsewhere in a system.

The announcement comes amid wider concern over how autonomous software agents are controlled once connected to enterprise applications and data. Companies have adopted scanners, gateways and prompt filters, but many security leaders still lack a single record of which agents are in use, what they can access and how they can be shut down if controls are breached.

Cequence also cited a recent incident disclosed by OpenAI in which two models escaped a sandboxed evaluation environment, crossed the open internet and breached Hugging Face production infrastructure. It used that case to argue that sandboxing alone does not constrain an agent if no policy binds it to a specific job.

“Most vendors look at agent governance and build another approval queue. We looked at it and built the persona instead,” said Shreyans Mehta, Chief Technology Officer and Co-Founder, Cequence. “An agent’s job should automatically determine what it can touch, without relying on a security team to manually map policy by hand every time someone wants a new use case. That’s what makes broad adoption safe and scalable. The agent gets exactly what its job requires, and nothing more.”

What is new

AI Discovery is intended to identify agents, LLM providers and MCP servers already operating inside an organisation by drawing on existing SIEM logs, including systems that did not go through a formal approval process.

According to Cequence, API Registry allows agents to call approved APIs without holding the underlying credentials. Instead, agents authenticate through a single AI Gateway access key, either through a web-based invocation tool or proxied endpoints.

Skill Registry is aimed at security and platform teams that want a pre-approved set of reusable functions for agents. Once a tool or workflow is vetted, it can be reused across different agent deployments without repeating the same review from scratch.

LLM Registry extends that logic to model access. Cequence said it brokers credentials across major LLM providers so agents do not hold a provider API key directly, while built-in data loss prevention checks prompts and responses for blocked content, including encoded payloads and non-approved Unicode characters intended to evade filters.

The registry can also apply model rules at team level, such as steering routine work to lower-cost models while reserving more advanced models for engineering tasks. It also provides token-level usage visibility, plus rate and spending controls linked to the persona behind each request.

Policy mapping

A central part of the release is the claim that policy enforcement can now be automated because the tools, APIs and skills available to an agent are formally catalogued. Without that catalogue, policy decisions have often depended on manual judgment.

“Automatic policy mapping was not possible until now, because there was nothing consistent for a policy engine to reason over,” said Abraham Jeevagunta, Vice President of AI Products, Cequence. “Before API Registry and Skill Registry, every tool and API a persona could be bound to was uncatalogued, so mapping policy to persona was a manual judgment call every time. Now, that record exists and the policy engine can read it directly. It is what lets a business user stand up a correctly governed agent without ever touching AI Gateway’s policy model themselves.”

The new functions are available as part of AI Gateway for existing Cequence customers. Cequence said its platform currently protects more than 10 billion daily API interactions and 4 billion user accounts.



Source link

Continue Reading

Trending