A Qualitative Synthesis of Cyberattack Trends in Managed Service Providers: Analyzing Multi-Tenant Vulnerabilities and Mitigation Strategies
Abstract
1. Introduction
1.1. Objective
- To analyze and synthesize a curated dataset of recent MSP cyberattacks (2020–2025): By utilizing an OSINT-derived, qualitative methodology, this study aims to identify and categorize a taxonomy of recurring threat vectors.
- To recommend contextualized, MSP-specific mitigation strategies: By directly mapping observed attack patterns to actionable defensive frameworks designed to reduce the blast radius of downstream client compromise, balancing security requirements with MSP operational constraints.
1.2. Research Gap and Contribution
1.3. Methodology
1.3.1. Search Strategy and Data Sources
1.3.2. Inclusion and Exclusion Criteria
- Target: The initial compromise must have directly targeted an MSP, its centralized management infrastructure (e.g., RMM, remote gateways), its hosted cloud environments, or any shared operational platform that triggered an overall cascading effect on multiple downstream clients as a direct result of the MSP breach.
- Impact: The attack must have demonstrated a downstream impact, directly or indirectly compromising multiple MSP client organizations (specifically SMBs).
- Timeframe: The incident must have occurred and been publicly disclosed between 2020 and 2025.
- Data Richness: Recognizing that full technical disclosure of corporate cyber incidents is rare, incidents were included if there was sufficient actionable intelligence available across multiple sources. This required, at minimum, verifiable public reporting on the general attack vector (e.g., exploitation of a known vulnerability, credential compromise), the suspected threat actor, and a confirmed downstream operational impact.
1.3.3. Incident Selection and Data Extraction
- Identification: An initial broad-spectrum search of surface web indices, CISA advisories, and threat intelligence repositories using the Boolean strings defined in Section 1.3.1 yielded 345 unique records related to IT service provider security events between 2020 and 2025.
- Screening: Records were screened for relevance to the MSP delivery model, resulting in the exclusion of most of these records (n = 235). Primary reasons for exclusion at this stage included duplicate reports of the same event (n = 120), “advisory-only” publications or general security tips that did not describe a specific incident (n = 85), and direct enterprise breaches where no MSP intermediary was involved (n = 30).
- Eligibility and Final Selection: The remaining 110 candidate incidents were evaluated against the inclusion criteria (Section 1.3.2). A total of 82 incidents were excluded because they lacked sufficient technical data, such as undisclosed access vectors (n = 62), or lacked confirmed downstream impact on SMB clients (n = 20).
1.3.4. Coding and Analysis Workflow
1.3.5. Thematic Synthesis and Trend Identification
- Phase 1 (Line-by-Line Coding): Building on the initial extraction in Section 1.3.4, the researchers performed a detailed review of each incident report to identify specific technical findings (e.g., “CVE-2023-4966 exploitation” or “RMM script deployment”).
- Phase 2 (Development of Descriptive Themes): These codes were grouped into descriptive categories based on their technical commonalities, such as “Initial Access Vectors” and “Downstream Impacts.”
- Phase 3 (Generation of Analytical Themes): In the final stage, the researchers moved beyond the descriptive data to infer the broader “Analytical Themes” that characterize the modern MSP threat landscape. This led to the synthesis of the four dominant trends detailed in Section 3 and further contextualized in Section 4: (1) Exploitation of Centralized Management Infrastructure, (2) Abuse of Privileged Access and Identity Mechanisms, (3) Multi-Tenant Architectures and Cascading Failure, and (4) Ransomware as the Dominant Attack Outcome.
2. Case Studies of Recent MSP Managed Attacks (2020–2025)
2.1. Cognizant Maze Ransomware Attack
2.2. REvil MSP Supply Chain Ransomware Attack
2.3. NetStandard MSP Cyberattack
2.4. Lumen Technologies Cyberattacks
2.5. CTS Cyber Attack
2.6. HTC Global Services Data Breach
2.7. Südwestfalen IT Ransomware Attack
2.8. Tietoevry Ransomware Attack
2.9. Tigo Business Attack
2.10. Vertel Managed Service Provider Ransomware Attack
3. Findings/Trend Synthesis
3.1. Exploitation of Centralized Management Infrastructure
3.2. Abuse of Privileged Access and Identity Mechanisms
3.3. Multi-Tenant Architectures and Cascading Failure
3.4. Ransomware as the Dominant Attack Outcome
4. Discussion
4.1. Observed Trends and Risk Factors
4.2. Mitigation Strategies for MSPs
4.2.1. Zero-Trust Architecture
4.2.2. Multi-Factor Authentication (MFA) and Privileged Access Management (PAM)
4.2.3. Patch Management and System Hardening
4.2.4. Endpoint Protection and Continuous Monitoring
4.2.5. Employee Awareness Training and AI Phishing Mitigation
4.2.6. Network Segmentation and Tenant Isolation
4.2.7. Third-Party Risk Management and External Security Audits
4.2.8. Incident Response Planning and Managed SOC Services
4.3. Empirical Evaluation Agenda
- Quantitatively measuring ransomware propagation speed across segmented versus unsegmented multi-tenant testbeds,
- Assessing the operational latency introduced by Identity-Aware Proxies (IAPs) and JIT PAM on helpdesk SLA metrics, and
- Conducting randomized controlled trials of AI-phishing awareness training specifically targeting “helpdesk spoofing” among MSP technicians.
5. Conclusions
Author Contributions
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Conflicts of Interest
Abbreviations
| MSP | Managed Service Provider |
| SMB | Small- and Medium-Sized Business |
| IR | Incident Response |
| SOC | Security Operations Center |
| SLA | Service Level Agreement |
| DBIR | Data Breach Investigations Report |
| FTC | Federal Trade Commission |
| CISA | Cybersecurity and Infrastructure Security Agency |
| ENISA | European Union Agency for Cybersecurity |
| RMM | Remote Management Tool |
| IOC | Indicator of Compromise |
| VSA | Virtual System Administrator |
| RCE | Remote Execution Code |
| ICO | Information Commissioner’s Office |
| CVE | Common Vulnerabilities and Exposures |
| RDP | Remote Desktop Protocol |
| ZTA | Zero-Trust Architecture |
| MFA | Multi-Factor Authentication |
| PAM | Privileged Access Management |
| VLAN | Virtual Local Area Network |
| VXLAN | Virtual Extensible Local Area Network |
| VRF | Virtual Routing and Forwarding |
| EDR | Endpoint Detection and Response |
| XDR | Extended Detection and Response |
| IT | Information Technology |
| OSINT | Open-Source Intelligence |
| IAPs | Identity-Aware Proxies |
| JIT | Just-in-Time |
References
- Cybersecurity and Infrastructure Security Agency. Protecting Against Cyber Threats to Managed Service Providers and their Customers. CISA, AA22-131A. 2022. Available online: https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-131a (accessed on 7 February 2026).
- Waltermire, K.; Perper, H. Improving Cybersecurity of Managed Service Providers (Supporting Small- and Medium-Sized Businesses). NIST. 2019. Available online: https://csrc.nist.gov/pubs/pd/2019/10/08/improving-cybersecurity-of-managed-service-provide/ipd (accessed on 19 December 2025).
- Bachlechner, D.; Thalmann, S.; Maier, R. Security and Compliance Challenges in Complex IT Outsourcing Arrangements: A Multi-Stakeholder Perspective. Comput. Secur. 2014, 40, 38–59. [Google Scholar] [CrossRef]
- Sivesind, C. Report: Why Managed Service Providers Are Now Ground Zero for Attacks. Available online: https://www.secureworld.io/industry-news/managed-service-providers-ground-zero (accessed on 29 January 2026).
- Amir, E.; Levi, S.; Livne, T. Do firms underreport information on cyber-attacks? Evidence from capital markets. Rev. Account. Stud. 2018, 23, 1177–1206. [Google Scholar] [CrossRef]
- Lydon, L. Corporate Under Reporting of Cybercrime: Why Does Reporting to Authorities Matter; Royal Holloway University of London: London, UK, 2022; Available online: https://www.royalholloway.ac.uk/media/20531/laurelydonisg.pdf (accessed on 15 March 2026).
- Kshetri, N.; Voas, J. Supply Chain Trust. IT Prof. 2019, 21, 6–10. [Google Scholar] [CrossRef]
- Wang, X. On the Feasibility of Detecting Software Supply Chain Attacks. In Proceedings of the MILCOM 2021–2021 IEEE Military Communications Conference (MILCOM); IEEE: San Diego, CA, USA, 2021; pp. 458–463. [Google Scholar] [CrossRef]
- Peisert, S.; Schneier, B.; Okhravi, H.; Massacci, F.; Benzel, T.; Landwehr, C.; Mannan, M.; Mirkovic, J.; Prakash, A.; Michael, J.B. Perspectives on the SolarWinds Incident. IEEE Secur. Priv. 2021, 19, 7–13. [Google Scholar] [CrossRef]
- Oz, H.; Aris, A.; Levi, A.; Uluagac, A.S. A Survey on Ransomware: Evolution, Taxonomy, and Defense Solutions. ACM Comput. Surv. 2022, 54, 238. [Google Scholar] [CrossRef]
- Connolly, L.Y.; Wall, D.S. The rise of crypto-ransomware in a changing cybercrime landscape: Taxonomising countermeasures. Comput. Secur. 2019, 87, 101568. [Google Scholar] [CrossRef]
- Khan, G.M.; Khan, S.U.; Khan, H.U.; Ilyas, M. Challenges and practices identification in complex outsourcing relationships: A systematic literature review. PLoS ONE 2022, 17, e0262710. [Google Scholar] [CrossRef] [PubMed]
- Lacity, M.C.; Sauer, C.; Willcocks, L.P. (Eds.) Outsourcing and Offshoring Business Services, 1st ed.; Springer International Publishing: Berlin/Heidelberg, Germany; Palgrave Macmillan: London, UK, 2017. [Google Scholar] [CrossRef]
- Qi, C.; Chau, P.Y.K. Relationship, contract and IT outsourcing success: Evidence from two descriptive case studies. Decis. Support Syst. 2012, 53, 859–869. [Google Scholar] [CrossRef]
- Thomas, J.; Harden, A. Methods for the thematic synthesis of qualitative research in systematic reviews. BMC Med. Res. Methodol. 2008, 8, 45. [Google Scholar] [CrossRef] [PubMed]
- Cognizant Security Incident Update. News|Cognizant Technology Solutions. Available online: https://news.cognizant.com/2020-04-18-cognizant-security-update (accessed on 7 February 2026).
- Cluley, G. IT Services Giant Cognizant Hit by Maze Ransomware Attack. Hot for Security. Available online: https://www.bitdefender.com/en-us/blog/hotforsecurity/it-services-giant-cognizant-hit-by-maze-ransomware-attack (accessed on 7 February 2026).
- Zitter, L. Incident of the Week: Cognizant Attacked by Maze. Cyber Security Hub. Available online: https://www.cshub.com/attacks/articles/incident-of-the-week-cognizant-attacked-by-maze (accessed on 7 February 2026).
- Vakulov, A. Managed Service Providers in Cyber Attacks. Cyber Security Hub. Available online: https://www.cshub.com/attacks/articles/managed-service-providers-a-gateway-for-cyber-attacks (accessed on 26 January 2026).
- Cybersecurity and Infrastructure Security Agency. CISA-FBI Guidance for MSPs and Their Customers Affected by the Kaseya VSA Supply-Chain Ransomware Attack. CISA, AA21-185A. 2021. Available online: https://www.cisa.gov/news-events/alerts/2021/07/04/cisa-fbi-guidance-msps-and-their-customers-affected-kaseya-vsa-supply-chain-ransomware-attack (accessed on 7 February 2026).
- Vijayan, J. Customers of 3 MSPs Hit in Ransomware Attacks. Dark Reading. Available online: https://www.darkreading.com/cyberattacks-data-breaches/customers-of-3-msps-hit-in-ransomware-attacks (accessed on 28 January 2026).
- Kovar, J.F.; Fairfield, C.J. Apparent Cyberattack Hits MSP NetStandard|CRN. CRN. Available online: https://www.crn.com/news/managed-services/msp-netstandard-sees-hosted-services-compromised (accessed on 7 February 2026).
- Abrams, L. Kansas MSP Shuts Down Cloud Services to Fend Off Cyberattack. BleepingComputer. Available online: https://www.bleepingcomputer.com/news/security/kansas-msp-shuts-down-cloud-services-to-fend-off-cyberattack/ (accessed on 7 February 2026).
- Zurier, S. Exchange Vulnerability May Have Led to Attack on NetStandard MSP, Researchers Say. SC Media. Available online: https://www.scworld.com/news/exchange-vulnerability-may-have-led-to-attack-on-netstandard-msp-researchers-say (accessed on 7 February 2026).
- Williams, D. Top 5 MSP Cyberattacks in 2023/2024|BlackFog. BlackFog. Available online: https://www.blackfog.com/top-5-msp-cyberattacks-in-2023-2024/ (accessed on 27 January 2026).
- Lahiri, A. Lumen Faces 2 Ransomware Attacks, Working with Experts to Evaluate and Minimize Impact-Lumen Technologies (NYSE:LUMN). Benzinga. Available online: https://www.benzinga.com/news/23/03/31512889/lumen-faces-2-ransomware-attacks-working-with-experts-to-evaluate-and-minimize-impact (accessed on 27 January 2026).
- National Vulnerability Database. CVE-2023-4966 Detail. NIST, 2023. Available online: https://nvd.nist.gov/vuln/detail/CVE-2023-4966 (accessed on 7 February 2026).
- Cybersecurity and Infrastructure Security Agency. Guidance for Addressing Citrix NetScaler ADC and Gateway Vulnerability CVE-2023-4966, Citrix Bleed. CISA, 2023. Available online: https://www.cisa.gov/guidance-addressing-citrix-netscaler-adc-and-gateway-vulnerability-cve-2023-4966-citrix-bleed (accessed on 7 February 2026).
- Williams, D. LockBit Ransomware Affiliates Leverage Citrix Bleed Vulnerability (CVE-2023-4966)|BlackFog. BlackFog. Available online: https://www.blackfog.com/lockbit-ransomware-affiliates-leverage-citrix-bleed-vulnerability-cve-2023-4966/ (accessed on 27 January 2026).
- Gatlan, S. Cyberattack on IT Provider CTS Impacts Dozens of UK Law Firms. BleepingComputer. Available online: https://www.bleepingcomputer.com/news/security/cyberattack-on-it-provider-cts-impacts-dozens-of-uk-law-firms/ (accessed on 27 January 2026).
- Williams, D. The Top 10 Ransomware Groups of 2023|BlackFog. BlackFog. Available online: https://www.blackfog.com/the-top-10-ransomware-groups-of-2023/ (accessed on 27 January 2026).
- Antoniuk, D. Massive Ransomware Attack Hinders Services in 70 German Municipalities. The Record. Available online: https://therecord.media/massive-cyberattack-hinders-services-in-germany (accessed on 27 January 2026).
- Robb, B. The State of Ransomware in 2023|BlackFog. BlackFog. Available online: https://www.blackfog.com/the-state-of-ransomware-in-2023/ (accessed on 27 January 2026).
- Labus, H. Tietoevry Ransomware Attack Halts Swedish Organizations. Help Net Security. Available online: https://www.helpnetsecurity.com/2024/01/22/tietoevry-ransomware/ (accessed on 25 January 2026).
- Paraguay Ciberseguro Reporta Ataque de Ransomware a una Telefonía Local. Última Hora. Available online: https://www.ultimahora.com/paraguay-ciberseguro-confirma-ataque-de-ransomware-a-telefonia (accessed on 28 January 2026).
- Acronis Threat Research Unit. MSP Cybersecurity News Digest, 24 June 2025. Acronis. Available online: https://www.acronis.com/en/tru/posts/msp-cybersecurity-news-digest-june-24-2025/ (accessed on 7 February 2026).
- Hollingworth, D. Exclusive: Aussie MSP Vertel Confirms Space Bears Ransomware Attack. Cyber Daily. Available online: https://www.cyberdaily.au/security/12262-exclusive-aussie-msp-vertel-confirms-space-bears-ransomware-attack (accessed on 7 February 2026).
- Richardson, R.; North, M. Ransomware: Evolution, Mitigation and Prevention. Int. Manag. Rev. 2017, 13, 10–21. [Google Scholar]
- Sun, G.; Chen, C.-C.; Bin, S. Study of Cascading Failure in Multisubnet Composite Complex Networks. Symmetry 2021, 13, 523. [Google Scholar] [CrossRef]
- CrowdStrike State of Ransomware Survey. CrowdStrike, Survey. 2026. Available online: https://www.crowdstrike.com/explore/crowdstrike-content/2025-report-crowdstrike-ransomware-survey (accessed on 28 January 2026).
- Australian Cyber Security Centre (ACSC). Investigation Report: Compromise of an Australian Company via Their Managed Service Provider. ACSC, 2018. Available online: https://www.cyber.gov.au/sites/default/files/2023-03/msp_investigation_report.pdf (accessed on 7 February 2026).
- 2025 Data Breach Investigations Report. Verizon Business. Available online: https://www.verizon.com/business/resources/reports/dbir/ (accessed on 28 January 2026).
- Gallagher, S. The Sophos Annual Threat Report: Cybercrime on Main Street 2025. Sophos. Available online: https://www.sophos.com/blog/the-sophos-annual-threat-report-cybercrime-on-main-street-2025 (accessed on 28 January 2026).
- Danielson, L. The State of MSP Cybersecurity: Attack Trends and Key Statistics. Huntress. Available online: https://www.huntress.com/msp-guide/msp-statistics (accessed on 28 January 2026).
- Syed, N.F.; Shah, S.W.; Shaghaghi, A.; Anwar, A.; Baig, Z.; Doss, R. Zero Trust Architecture (ZTA): A Comprehensive Survey. IEEE Access 2022, 10, 57143–57179. [Google Scholar] [CrossRef]
- Rose, S.; Borchert, O.; Mitchell, S.; Connelly, S. Zero Trust Architecture; NIST SP 800-207; National Institute of Standards and Technology: Gaithersburg, MD, USA, 2020. [CrossRef]
- Shore, M.; Zeadally, S.; Keshariya, A. Zero Trust: The What, How, Why, and When. Computer 2021, 54, 26–35. [Google Scholar] [CrossRef]
- Grassi, P.A.; Fenton, J.L.; Newton, E.M.; Perlner, R.A.; Regenscheid, A.R.; Burr, W.E.; Richer, J.P.; Lefkovitz, N.B.; Danker, J.M.; Choong, Y.-Y.; et al. Digital Identity Guidelines: Authentication and Lifecycle Management; NIST SP 800-63b; National Institute of Standards and Technology: Gaithersburg, MD, USA, 2017. [CrossRef]
- Garbis, J.; Chapman, J.W. Privileged Access Management. In Zero Trust Security: An Enterprise Guide; Garbis, J., Chapman, J.W., Eds.; Apress: Berkeley, CA, USA, 2021; pp. 155–161. [Google Scholar] [CrossRef]
- Souppaya, M.; Scarfone, K. Guide to Enterprise Patch Management Planning: Preventive Maintenance for Technology; NIST SP 800-40r4; National Institute of Standards and Technology (U.S.): Gaithersburg, MD, USA, 2022. [CrossRef]
- Ross, R.; Winstead, M.; McEvilley, M. Engineering Trustworthy Secure Systems; NIST SP 800-160v1r1; National Institute of Standards and Technology (U.S.): Gaithersburg, MD, USA, 2022. [CrossRef]
- Kaur, H.; Sanjaiy Sl, D.; Paul, T.; Kumar Thakur, R.; Kumar Reddy, K.V.; Mahato, J.; Naveen, K. Evolution of Endpoint Detection and Response (EDR) in Cyber Security: A Comprehensive Review. E3S Web Conf. 2024, 556, 01006. [Google Scholar] [CrossRef]
- George, D.A.S.; George, A.H.; Baskar, T.; Pandey, D. XDR: The evolution of endpoint security solutions-superior extensibility and analytics to satisfy the organizational needs of the future. Int. J. Adv. Res. Sci. Commun. Technol. (IJARSCT) 2021, 8, 493–501. [Google Scholar] [CrossRef]
- Gyunka, B.A.; Christiana, A.O. Analysis of human factors in cyber security: A case study of anonymous attack on HBGary. Comput. Inf. Syst. 2017, 21, 10–18. [Google Scholar]
- Chandramouli, R. Secure Virtual Network Configuration for Virtual Machine (VM) Protection; NIST SP 800-125B; National Institute of Standards and Technology: Gaithersburg, MD, USA, 2016. [CrossRef]
- Cybersecurity and Infrastructure Security Agency. Advanced Persistent Threat Compromise of Government Agencies, Critical Infrastructure, and Private Sector Organizations. AA20-352A. 2021. Available online: https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a (accessed on 7 February 2026).
- Bailey, T.; Brandley, J.; Kaplan, J. How good is your cyber incident response plan. McKinsey Bus. Technol. 2013, 31, 16–23. [Google Scholar]
- Vielberth, M.; Bohm, F.; Fichtinger, I.; Pernul, G. Security Operations Center: A Systematic Study and Open Challenges. IEEE Access 2020, 8, 227756–227779. [Google Scholar] [CrossRef]

| Year | Target | Attack Type | Access Vector | Impact | Actor | MSP Traits | Source | Source Confidence |
|---|---|---|---|---|---|---|---|---|
| 2020 | Cognizant (Global) | Ransomware and Data Exfiltration | Unconfirmed credential compromise/internal access | Disruption of IT services for multiple clients; data exfiltration | Maze | Centralized IT delivery; privileged access; global client base | [16,17,18] | Very High |
| 2021 | Kaseya MSP Clients | Supply Chain Ransomware | Zero-day vulnerabilities in Kaseya VSA | Cascading ransomware across hundreds of systems; disabled backups | REvil | Automated deployment; multi-tenant architecture | [8,12,19,20,21] | Very High |
| 2022 | NetStandard (USA) | Suspected Ransomware | Unconfirmed Exchange RCE (CVE-2021-31206) | Hosted cloud services offline; localized outage | Unknown | Managed cloud services; multi-tenant environment | [22,23,24] | Medium |
| 2023 | Lumen Technologies | Ransomware and Intrusion | Internal network intrusion | Reduced performance, temporary outages | Unknown | Segmented service environments; centralized management | [25,26] | Very High |
| 2023 | CTS (UK) | Exploitation/Ransomware | Citrix Bleed (CVE-2023-4966) | Disruption of legal operations across 80–200 firms | Unknown | Multi-tenant architecture; elevated privileges | [25,27,28,30] | Very High |
| 2023 | HTC Global Services | Ransomware and Data Exfiltration | Unconfirmed Citrix Bleed (CVE-2023-4966) | Exposure of sensitive corporate/client data | ALPHV | Elevated privileges; multi-tenant environment | [25,27,28,31] | Very High |
| 2023 | Südwestfalen IT (Germany) | Ransomware | Not publicly specified | Outages across 70+ municipalities | Akira | Shared infrastructure; operational dependency | [25,32,33] | High |
| 2024 | Tietoevry (Sweden) | Ransomware | Not publicly specified | Disruption of payroll/HR across public sector clients | Akira | Critical service dependency; multi-tenant | [25,33,34,38] | Very High |
| 2024 | Tigo Business (Paraguay) | Ransomware | Unconfirmed exploitation of unsecured RDP | Encryption of 330 servers; 300+ clients offline | Black Hunt | Weak access controls; large client base | [19,35] | Medium |
| 2025 | Vertel (Australia) | Ransomware and Data Exfiltration | Credential compromise/remote access exploitation | Potential exposure of SQL databases/client data | Space Bears | Centralized service management; multi-tenant aggregation | [36,37] | Very High |
| Observed Attack Pattern (Section 3) | Proposed Control (Section 4.2) | MSP Implementation Detail | Expected Effect on Blast Radius |
|---|---|---|---|
| Abuse of Privileged Access and Identity Mechanisms | Zero Trust, PAM, and Phishing Awareness | Identity-Aware Proxies; Vaulted Just-in-Time (JIT) admin credentials; training against AI helpdesk spoofing. | Prevents lateral movement across tenant boundaries if an MSP tech account is compromised. |
| Exploitation of Centralized Management Infrastructure | Patch Management and XDR Monitoring | “Security-first SLAs” overriding uptime for edge devices; Cross-tenant telemetry ingestion. | Enables early detection of simultaneous multi-client encryption; patches edge-gateways faster. |
| Multi-Tenant Architectures and Cascading Failure | Network Segmentation and Tenant Isolation | Strict logical isolation between the RMM host, corporate network, and client subnets. | Contains ransomware to a single subnet; severs the supply chain pivot point. |
| Supply Chain and Third-Party Compromise | Vendor Audits and Incident Response/SOC | SBOM visibility demands; automated RMM “kill-switch” orchestrated by the managed SOC. | Sacrifices temporary uptime to sever infected upstream links before malware pushes downstream. |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Neupane, S.R.; Shrestha, N.; Sun, W. A Qualitative Synthesis of Cyberattack Trends in Managed Service Providers: Analyzing Multi-Tenant Vulnerabilities and Mitigation Strategies. Information 2026, 17, 378. https://doi.org/10.3390/info17040378
Neupane SR, Shrestha N, Sun W. A Qualitative Synthesis of Cyberattack Trends in Managed Service Providers: Analyzing Multi-Tenant Vulnerabilities and Mitigation Strategies. Information. 2026; 17(4):378. https://doi.org/10.3390/info17040378
Chicago/Turabian StyleNeupane, Shiva Ram, Neeraj Shrestha, and Weiqing Sun. 2026. "A Qualitative Synthesis of Cyberattack Trends in Managed Service Providers: Analyzing Multi-Tenant Vulnerabilities and Mitigation Strategies" Information 17, no. 4: 378. https://doi.org/10.3390/info17040378
APA StyleNeupane, S. R., Shrestha, N., & Sun, W. (2026). A Qualitative Synthesis of Cyberattack Trends in Managed Service Providers: Analyzing Multi-Tenant Vulnerabilities and Mitigation Strategies. Information, 17(4), 378. https://doi.org/10.3390/info17040378

