IT Vendor Breach: What CISA Advisories Reveal About Supply-Chain Attacks on Small Business
Attackers are no longer always trying to break through your front door. They break through your IT firm’s door instead — then walk straight into your environment through the trusted connection your vendor already holds. The 2024 and 2025 CISA advisory record, combined with public incident response disclosures from the past 18 months, makes this case with uncomfortable clarity. An IT vendor breach is not your IT company’s problem to absorb in isolation. It lands on your business — operationally, legally, and reputationally.
Table of Contents
The IT Vendor Breach Pattern CISA Is Documenting
CISA’s 2024 advisory catalog is not subtle about this threat. Advisory AA24-038A, released in February 2024, detailed how the Volt Typhoon actor — a People’s Republic of China state-sponsored group — spent years pre-positioning inside U.S. critical infrastructure by first compromising small and medium-sized network infrastructure vendors and managed service providers. The intrusion path ran upstream to downstream: compromise the vendor, inherit the vendor’s access, move laterally into client environments without triggering standard perimeter alerts.
That advisory built on the landmark 2023 joint advisory AA23-025A, co-authored by CISA with the NSA, FBI, and Five Eyes partners. That document named managed service providers as a primary attack surface, documented the specific techniques threat actors use to abuse remote monitoring tools, and explicitly warned that a single compromised provider could give an attacker simultaneous access to dozens or hundreds of client organizations. CISA’s full advisory library and guidance are available at CISA.gov’s Managed Service Provider resources.
By mid-2024, CISA had issued a further batch of advisories under its Known Exploited Vulnerabilities catalog showing a deliberate pattern: vulnerabilities actively exploited in tools that IT providers commonly use for remote access, patch management, and network monitoring. These are not random targets. Attackers are studying the vendor ecosystem and selecting entry points with the widest downstream reach.
The 2025 advisory record has continued in the same direction. CISA’s Secure by Design guidance, updated in early 2025, specifically calls out the managed service provider supply chain as a systemic risk requiring vendor-level accountability — not just client-level controls.
Why IT Vendors Are the Target of Supply-Chain Attacks

Think like the attacker. Breaking into a single well-defended company requires significant effort and yields access to one environment. Breaking into the IT company that manages 50 clients yields access to 50 environments — with administrative credentials already provisioned and trusted by every endpoint in those environments.
The economics of that trade-off are obvious. But there is a second, more troubling dynamic: the access an IT vendor holds is often the highest-privilege access in a client’s entire environment. Remote monitoring tools run as system-level processes. Patch management platforms can push code to every workstation. Backup systems hold copies of everything. An attacker who controls your IT vendor’s toolset does not need to find a way in — they are already in, with keys to every room.
The FBI’s 2023 Internet Crime Complaint Center report documented over $12.5 billion in cybercrime losses that year — the highest figure on record at the time. Business email compromise alone accounted for nearly $2.9 billion of that total, and a substantial share of those incidents traced back to compromised outsourced provider credentials as the initial access vector. The 2024 report, released in spring 2025, showed losses climbing further, with vendor-chain intrusions remaining a dominant pattern.
Small businesses are not incidental victims in this landscape. They are the intended downstream target. Larger enterprises have resources to build vendor risk programs, conduct annual third-party audits, and contractually mandate security standards on their vendors. Small businesses rarely do. That gap is the attack surface.
Real Incidents, Real Downstream Damage From an IT Vendor Breach
The Kaseya VSA incident of 2021 remains the most documented case of this attack pattern at scale — but it is far from the last. The REvil group exploited a zero-day in a remote management platform used by hundreds of IT providers. Within hours, ransomware was executing on the endpoints of those providers’ clients — businesses that had never heard of the platform being exploited, had no visibility into it, and had no ability to respond independently.
More recent incidents have followed the same playbook with varying degrees of public disclosure. In late 2023 and into 2024, multiple incident response disclosures documented intrusions that began inside IT provider environments and were detected only after client data had already been exfiltrated. In several cases, the dwell time — the period between initial compromise and detection — exceeded 90 days. During that window, the attacker had unrestricted access to client environments through the provider’s own tools.
ConnectWise disclosed critical vulnerabilities in its ScreenConnect remote access product in February 2024. CISA added those vulnerabilities to its Known Exploited Vulnerabilities catalog within days and explicitly warned that threat actors were actively exploiting these flaws to reach the clients those providers served. Within two weeks of the disclosure, multiple incident response firms had documented real-world exploitation in the wild targeting exactly this vector.
These are not hypothetical scenarios. They are documented, timestamped, publicly attributed intrusions in which the IT vendor was the door and the client was the house that got robbed. Each IT vendor breach reinforces the same conclusion: if your provider is compromised, you are compromised.
The Trust Problem No One Talks About
There is a structural problem in how small businesses think about IT vendor risk, and it is rooted in a reasonable but dangerous assumption: because your IT firm handles your security, their own security must be sound.
That assumption is not always warranted. The IT provider market is fragmented, and entry barriers are low. A two-person shop with a stack of vendor licenses can market cybersecurity services the next morning. There is no federal licensing requirement. No mandatory audit. Most clients have no visibility into whether their IT vendor has ever had a third party evaluate their own controls.
CISA’s guidance addresses this directly. The agency’s Cybersecurity Best Practices for Managed Service Providers publication recommends that clients ask their IT providers to demonstrate how they protect the tools and credentials used to access client environments, review provider contracts for explicit security commitments, and treat a provider’s security posture as an extension of their own — because under any realistic threat model, it is.
The accountability gap is significant. When an IT vendor breach occurs and client data is exfiltrated, the regulatory obligation to report that breach falls on the client, not the vendor. Under HIPAA, for example, the covered entity carries breach notification responsibility even when the intrusion originated inside a business associate’s environment. The client faces the regulator. The client faces the litigation. The vendor may face contractual liability, but the operational and reputational damage lands squarely on the business whose name is on the door.
At Xact IT Solutions, we treat this accountability reality as the foundation of how we operate. Our own security controls are audited annually by Versprite, a CREST-accredited assessor, against the CIS Critical Security Controls framework — because our clients should not have to take our word for it. That audit is not a marketing exercise. It is a recognition that our clients inherit our posture, and they deserve to know what that posture actually is. To learn more about how we approach this responsibility, visit our cybersecurity services page.
Defense Posture: What Good Looks Like
If your IT vendor’s security is part of your security perimeter — and the CISA advisory record says it is — then the defense posture question expands. It is no longer enough to ask whether your own environment is well-configured. You need to know what standards your IT vendor holds themselves to, and how they prove it. Preventing an IT vendor breach requires accountability at the provider level, not just the client level.
Here is what a defensible posture looks like on the vendor side:
- The provider uses multi-factor authentication on every administrative account, every remote access tool, and every client portal — without exception and without workarounds for convenience.
- The provider operates on a least-privilege model: technicians hold access only to what they need for a specific engagement, not standing administrator rights across all client environments simultaneously.
- The provider can demonstrate that their remote access and management tools are current, patched, and monitored — with a documented process for responding to vendor disclosures like the ConnectWise event in under 24 hours.
- The provider undergoes independent third-party security assessments, not self-attestation or vendor-supplied compliance checkboxes.
- The provider maintains documented incident response procedures with client notification timelines — contractually committed, not verbal assurances.
- The provider maintains separation between their internal business network and the tools used to access client environments, so that a compromise of their internal systems does not automatically open a path to client infrastructure.
On the client side, a defensible posture includes:
- Asking your IT vendor for their most recent third-party security assessment summary before you sign or renew a contract.
- Reviewing your contract for explicit breach notification language — who tells you, how fast, and in what form.
- Ensuring your backup and recovery environment is logically separated from your production environment and from your IT vendor’s management plane, so a compromise of the vendor’s tools cannot simultaneously destroy your recovery capability.
- Asking what happens to your administrative credentials and access accounts if you terminate the vendor relationship.
- Understanding which third-party platforms your IT vendor uses to manage your environment and how those platforms are secured.
For a deeper look at the managed IT controls that underpin a secure client-provider relationship, explore our managed IT services page.
Questions Every CEO Should Ask Their IT Firm Right Now
These are not technical questions. They are accountability questions. A competent IT firm should answer all of them without hesitation. Vague, defensive, or nonexistent answers are data. The risk of an IT vendor breach grows in direct proportion to the gaps in your vendor’s answers.
- Has your firm undergone an independent third-party security assessment of your own internal environment? If so, when, and who conducted it?
- What multi-factor authentication controls protect the accounts and tools your technicians use to access my environment?
- Do your technicians have standing administrative access to my environment, or is access provisioned per engagement and revoked afterward?
- If a critical vulnerability is disclosed in a tool your firm uses to manage my environment, what is your documented patching process and your timeline commitment?
- If your firm’s own systems were compromised, how would you notify me, and within what timeframe?
- How are my credentials and access accounts isolated from those of other clients you manage? Could a compromise of another client’s environment create a path into mine?
- What contractual commitments do you make around the security of the tools you use to manage my environment?
These questions are not adversarial. They are what any CEO should ask a vendor who holds privileged access to their business infrastructure. The IT industry has not always expected clients to ask them. That needs to change.
The Bottom Line
The CISA advisory record from 2024 into 2025 documents a threat landscape that has moved well beyond perimeter attacks and phishing-only intrusion paths. Threat actors have studied the IT provider ecosystem and found a reliable, scalable method for accessing dozens of small business environments through a single point of compromise. The economics favor the attacker. The structural accountability falls on the client.
The answer is not panic. It is clarity. An IT vendor breach is a breach of your business — operationally, legally, and reputationally. That reality means holding your IT vendor to the same standard you would hold any vendor with unrestricted access to your facility: documented controls, independent verification, and contractual commitments you can actually enforce.
The IT firms that understand this build their own security programs as rigorously as they build their clients’. They invite external audits. They document their incident response procedures. They structure their access controls so their tools cannot be weaponized against the clients who trusted them. That is not a premium offering. It is the baseline the current threat environment requires.
If you want to understand how Xact IT Solutions structures its security program — and whether your current IT vendor can answer the questions above — Book a Free Cybersecurity Strategy Call. It is a 20-minute conversation with our team. No obligation, no pressure — just clarity on where you actually stand.
Get a Second Opinion
Sometimes the best thing you can do for your business is have someone outside your current vendor relationship take a fresh look. That’s what a strategy call gives you — 20 focused minutes with our team and a no-strings-attached read on what we’d recommend.