MSPs’ access to credentials across dozens or even hundreds of customer environments can turn a single compromised login into a multi-client security incident, putting credential management, technician access and offboarding practices under growing scrutiny.
Chris Skipworth, CEO of MSP-focused password management provider Passpack, spoke with Channel Insider about where credential security breaks down inside MSPs, why informal access practices create systemic risk, and the controls providers need to demonstrate as customers and cyber insurers demand greater accountability.
Credential sprawl makes MSPs high-value security targets
It is said that MSPs are “credential-rich targets.” What does that actually look like in practice across a typical MSP environment?
Think about what an MSP actually does. At any given time, they’re managing login credentials across dozens, sometimes hundreds, of client environments, shared across a team of technicians who all need access to do their jobs.
That’s a large number of credentials, a large number of people with access to those credentials, and a large number of entry points for an attacker.
The challenge is that the operational model of an MSP, serving multiple clients, onboarding new ones regularly, scaling headcount, naturally generates credential sprawl. The question is whether there’s a disciplined system in place to manage it, or whether it’s being handled informally.
What’s the biggest disconnect between how MSPs think they’re managing credentials and what’s actually happening day to day?
I think many MSPs believe they have a handle on this because nothing has gone wrong yet. But “nothing has gone wrong” isn’t the same as “this is secure.”
Smaller MSPs, in particular, tend to manage credentials in fairly ad hoc ways: spreadsheets, shared documents, and credentials held by a single senior technician, creating a single point of failure.
The gap between the assumed level of control and the actual level of control can be significant, and it often only becomes visible when something goes wrong.
Can you walk us through a realistic attack path? How does a single compromised credential turn into a multi-client exposure?
If an MSP is using the same credential across multiple client environments, which does happen, a single breach in one corner gives an attacker a foothold across the whole client base. There’s also the question of how credentials are shared, both internally among the MSP’s team and externally with clients.
Unsecured sharing, whether by email or through an unmanaged team channel, increases the attack surface at every point. One weak link in that chain is enough.
What are the most common failure modes you see? Which causes the most damage?
Shared master passwords that give too many people access to too much; no consistent policy around password strength; credentials stored in email threads or documents that weren’t designed for secure storage.
The shared credential problem is particularly serious because a single breach becomes a systemic event rather than an isolated one. But in terms of sustained, invisible risk, poor offboarding is the one that tends to be most underestimated, and I’ll come back to that.
Ownership and offboarding expose gaps in MSP access controls
Who typically owns credential security inside an MSP? Is there usually a clear person or policy, or does it tend to fall through the gaps?
It depends heavily on size and structure. Larger MSPs tend to have clearer ownership because they’ve had to build processes to operate at scale. In smaller MSPs, credential security can become everyone’s responsibility in theory and no one’s in practice.
People develop their own individual systems, there’s no standardised policy, and there’s no one whose job it is to ensure it’s being followed consistently. Someone needs to own this, not just set a policy once, but actively monitor and enforce it across the team.
You’ve pointed out that offboarding is a specific pain point for both staff and clients. How does poor offboarding create credential exposure that MSPs often don’t notice until it’s too late?
When a technician leaves, or when an MSP ends a client relationship, credentials frequently remain active simply because nobody has systematically revoked them. Without a formal process and a clear audit trail, you can’t always be certain what access has been left open.
The exposure isn’t immediately visible, which is exactly what makes it dangerous. By the time it becomes apparent, the damage may already be done.
Mature credential management requires enforceable MSP processes
What does “mature” credential management actually look like inside an MSP in terms of the day-to-day workflows and policies that separate organizations that have this under control from those that don’t?
The clearest indicator is when credential management is embedded in standard operating procedures rather than treated as a separate concern.
That means consistent password policies enforced across all client environments, least-privilege access so people can only reach what they actually need, and the ability to grant or revoke access quickly when circumstances change.
Mature organisations don’t just have these controls; they can demonstrate them. That’s what separates a security posture from a security assumption.
Cyber insurers and customers are raising credential security expectations
Cyber insurers are tightening underwriting requirements beyond MFA. What credential controls are they now looking for, and how does that affect MSPs specifically?
MFA is now a baseline; insurers expect it, but it no longer differentiates you. What insurance carriers are increasingly focused on is the broader picture: privileged access controls, zero trust principles, and phishing-resistant MFA specifically, because standard app-based tokens can be compromised through social engineering.
The other critical issue for MSPs is coverage denial. If a claim is made and an MSP cannot provide evidence that the controls they said they had were actually in place and enforced, the insurer can deny the claim.
That’s the scenario nobody wants to be in, and audit trails are a significant part of how you protect against it.
Are MSP clients starting to ask harder questions about how their service providers handle credential access? And how does that change the conversation MSPs are having with prospects?
There’s growing awareness that clients’ own security posture is only as strong as the posture of the providers they rely on. I’d expect that scrutiny to increase.
For MSPs, it changes the nature of the sales conversation; credential security used to be something handled internally and rarely discussed with clients.
Increasingly, prospects want to understand who has access to their environments, how that access is managed, and what happens when the relationship ends. MSPs who can answer those questions clearly are in a stronger position than those who can’t.
What’s the one misconception about credential security that’s still driving the riskiest behaviour inside MSPs?
“This is too much hassle to set up properly, so we’ll deal with it later.”
There’s always a trade-off between convenience and security, and a lot of risky behaviour persists not because people are unaware of the risk, but because addressing it feels like overhead.
The problem is that the cost of a breach, in downtime, client impact, reputational damage, and potential insurance complications, far outweighs the cost of getting it right upfront.
The organisations that understand that tend to be the ones who’ve either been through a security incident or watched what happened to someone who has.





