ConnectWise is the longest-running, market-leading software platform for technology solution providers (TSPs). The ConnectWise platform is used by more TSPs around the world than any other software provider. Here at the inTEC GROUP, we use ConnectWise every day to manage and maintain the excellent relationships we have with our loyal clients. Many of our own clients also use the ConnectWise platform in their businesses.
You may be aware of the recent REvil attack on Kaseya VSA and the SolarWinds incident last year. It’s important to us that we are kept informed about ConnectWise security standards, practices and resources, and how they are securing their products today – and in the future. We requested an update on cyber security from the ConnectWise team. Please see their response below.
____________________________________________________________________________________________________________________
As a provider of RMM, PSA, Security and other mission-critical products, keeping our partners secure will continue to be our highest priority.
Four areas relevant to the Kaseya incident and the recently published guidance from the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) are: Mandatory MFA, Admin Access Restrictions, Web Application Firewalls (WAF) and Removing Anti-Virus Exclusions.
- Mandatory Multi-factor Authentication (MFA): Currently, all agent-based products have mandatory MFA. Several other products have MFA as a configurable option. We plan to move all products to a mandatory MFA model by the end of 2021 and will be soon rolling out resources, education, and communications to help our partners make this transition.
- Restricting Access to Admin Interfaces via IP limitations: Today, ConnectWise Control supports IP restrictions. Automate, and all other products will implement IP restrictions by the end of Q3, 2021.
- Web Application Firewall (WAF): This is under evaluation in Q3, 2021 for our various products to execute both with and without the IP limiting features.
- Removing Anti-Virus exclusions: AV exclusions for all products will be eliminated by the end of Q3, 2021.
Here are some additional practices and programs already launched:
- SOC2 Type 2 Certification: All products are SOC2 Type 2 certified and are re-certified every six months.
- Cloud Environment Monitoring: Product cloud environments are monitored 24/7 by our SOC for suspicious/malicious activity.
- Vulnerability Management: All products are subject to multiple security assessments including automated testing in the delivery pipeline, internal red-teaming, external penetration tests, and Bug Bounty.
- Malware Protection: Cloud infrastructure is protected using advanced endpoint detection and response capabilities.
- Delivery Pipeline: ConnectWise subjects its development and delivery pipeline to threat modeling to improve security against supply chain attacks.
- Disaster Recovery: Data backup and disaster recovery programs are in place across all cloud environments. Access and encryption controls are established to safeguard data back-ups. All recovery and data restoration plans are tested and updated regularly.
For the latest information and security updates from ConnectWise, please visit their Trust site here.