Category
CybersecurityJoin thousands of security professionals who receive Craig Peterson's Insider Show Notes and cybersecurity updates.
One screen can reach into every computer in your office. This month, anybody on the internet could walk into a widely used one as the administrator, with no password. Then the emergency fix did not hold. Here is what IT provider security really means for your business.
See Where Your Business Stands →
A plain-English computer security scan. No card needed to see your results.
The problem: Most owners think about IT provider security as “do we have somebody.” The real question is narrower and much harder to answer: the software your provider uses to manage your machines is itself a target, and when it springs a leak, every one of their clients springs a leak at the same moment.
The straight answer: This is not a reason to fire anybody. Plenty of good providers patched this inside a day. It is a reason to know one specific thing instead of assuming it. I will show you exactly what happened and give you the sentence to say when you call them.
Hey folks! If an outside company looks after your computers, I want to explain something about how they do it, because most owners have never had it explained and it changes how you think about IT provider security.
They do not drive to your office every time something needs doing. They use one program, a master console, that quietly runs on every machine you own. From that one screen they can install software on your computers, run commands on them, see what is happening, and take remote control of any of them whenever they need to. It is how one small team can look after forty businesses at once. It is genuinely useful, and I am not going to pretend otherwise.
But look at what that means. That console is a key ring holding a key to every door in your building, and copies of the same for every other client they serve. Which makes it the single most valuable thing in the neighborhood for a criminal.
On August 1, the company behind one of the most widely used of these consoles, a program called N-central, put out an advisory saying that anybody on the internet could walk into it as an administrator. No password. No trick. The lock was simply not doing anything.
And criminals were already inside. Security firms watching the attacks saw something worse than random poking around. The intruders went straight for domain controllers, which are the machines that hold the master list of who is allowed to log into what across a whole company. Then they set up quiet ways to get back in later, so that even if the front door got fixed, they would still have a way through.
Sources: N-able advisory, August 1, 2026; Huntress and Arctic Wolf incident reporting, August 2026.
An emergency fix went out on August 2. One day. That is genuinely fast, and the vendor deserves credit for the speed.
Here is the part almost nobody outside the industry heard. That fix did not fully close the hole.
The patch handled part of the problem and left a way around the rest. The leftover gap was serious enough that it got its own tracking number, and a second fix had to go out on August 6. In plain terms: if your provider patched promptly on the second, did the sensible thing, and moved on with their week, they were still exposed. Being fast was not enough. You had to be fast twice.
This is the thing I want you to take away about IT provider security, and it has almost nothing to do with whether your provider is any good. “We patched it” and “we went back and checked whether the patch was enough” are two completely different habits. The first one is normal and reasonable. The second one is what actually kept people safe this month. Most shops do the first. Far fewer do the second, because doing the second means somebody has to be following the story after the ticket got closed.
And the numbers say plenty did not. As of August 3, better than one in four of these consoles that companies run on their own hardware had not been patched at all. Not patched once. Not patched twice. Sitting there.
I want to be careful here, because I have friends who run these shops and most of them are good people working hard. This is not me telling you your IT company is asleep. Plenty were on it inside a day, and some were on it twice. The point is that you currently have no way of knowing which kind you have, and you are the one carrying the risk either way.
Let me translate this out of computer talk and into the only language that matters, which is what it does to your company.
It skips every defense you paid for. This is what makes it different from a normal break-in. The console is supposed to be able to install things on your computers. So when a criminal takes it over, everything he pushes out looks like routine maintenance from your own IT company. Your antivirus does not flag it. Your staff does not question it. It arrives wearing a uniform.
It hits everything at once. A phishing email catches one person and one machine. This reaches every computer under management at the same moment. There is no slow spread to notice and no first victim to warn the others.
It is the fastest known road to ransomware. Ransomware is software that locks up your files and holds them for money. Going after domain controllers is the classic first move before locking a whole company, because once you control who can log into what, you control everything. That is exactly the direction the intruders were heading.
And then there is the bill nobody budgets for. Not the ransom. The days you cannot open, the customers who quietly do not come back, and the insurance claim that gets picked apart because somebody asks what you were doing to prevent this. I have watched businesses survive the payment and nearly go under from the two weeks that followed.
My own father fell for a phishing email. That is a fake message built to trick you into handing over a password or your money. More than three decades in this field, and it still reached the person I most wanted to protect. The hosers got into his computer from far away and started hunting for his financial papers. My step-mother noticed something was wrong and called me. I stopped them before they reached his bank logins. We were lucky. We caught it in time. A day slower and it would have been a very different phone call.
Here is why I bring that up in a story about IT provider security. My dad had somebody looking out for him. Me. And it still nearly happened, because having somebody is not the same as somebody actually watching at the moment it counts. That is the whole lesson of this month. More than 35 years at this, since 1991. FBI InfraGard trainer. Not one client I manage has ever been hit by ransomware. That is not luck. It is the second habit, the going back to check, done every single time.
You are right, and I am not going to talk you out of that. You should not have to audit your provider’s tooling. That is genuinely their job, and the good ones do it without being asked. If I made you feel like this is one more thing on your plate, I did this badly.
So let me shrink it to something that actually fits on your plate. You do not need to understand any of the technology in this article. You need one sentence, once, and then you can go back to running your company: “There was an N-central problem the first week of August. Did we patch it, and did we patch it the second time?” A good provider will answer that in about four seconds and be glad you asked. If the answer is vague, or if it turns into a conversation about how complicated it all is, you have learned something useful for the price of one phone call.
1. Ask the two-patch question. The exact sentence is in the box above. Do not soften it into “are we all set.” Ask whether it was patched, and whether it was patched the second time. The specificity is the whole point, and it tells you more about your IT provider security than any contract will.
2. Ask who else can reach into your machines. Most businesses have collected more remote access than they realize. The IT company. The software vendor who set up your line-of-business system. The copier company. The camera installer. Every one of those is a key to your building sitting in somebody else’s drawer. Ask for the list. If nobody can produce one, that is the finding.
3. Turn on real two-step login for the administrator accounts. Not just for staff email. For the accounts that manage things. Use an app like Duo rather than text-message codes. It will not stop a flaw like this one, and I will not pretend it would, but it is the single best barrier against the far more common version where somebody simply steals an administrator’s password.
Let me ask you a few plain questions, and just answer them in your head. You would never hand a key to your building to somebody without knowing who they are, would you? You know exactly who has the alarm code. You would notice tomorrow if a spare key went missing off the hook. That is not paranoia, that is just how you run a careful business, and you have run it that way for years.
Now hold that next to this. There is a program on every computer you own that can install software and take control at any moment, and you probably could not say today whether it was patched twice in the first week of August.
Both of those are true about the same person, and they do not sit comfortably together. That discomfort is not a sign you have been careless. It is the gap between how carefully you handle the keys you can see and how invisible the digital ones are. Nobody handed you a key hook for those. There was never a moment where somebody sat you down and said, by the way, this exists and here is what to ask about it.
So here is where that leaves you. You can decide it is probably fine, which it probably is, and carry the small itch of not knowing into the next story like this one. Or you can spend a few minutes and simply find out, and never wonder about it again. One of those ends the question. The other reschedules it for next month. Acting is not the nervous choice here. Acting is the thing that lets you stop thinking about it.
You should not have to audit anybody’s tooling. You should just be able to know where you stand. That is the whole idea here, and you do not have to do it alone.
Book a call, on us. We scan your computers and fix the single most important thing first. You will not pay a dime, and you decide what happens next. If your current provider is doing right by you, you will find that out too, and that is worth knowing.
Not one client we manage has ever been hit by ransomware. That is not luck. That is someone actually watching the doors.
You run your business. We keep it running.
Book My Scan →
A few minutes with a real person, straight talk on where your business stands. No pressure.
Want this kind of plain-English security news every week? Sign up for Craig’s Insider Notes at CraigPeterson.com.
#ITProviderSecurity #ManagedServices #SmallBusinessCybersecurity #Ransomware #ForwardToSafety
Tagged with:
Join 10,000+ cybersecurity professionals