Multi-CloudCIO BriefingsRetrospectives

CIO Brief: Remote Support Vendors and Nation-State Risk

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from December 2024, written in 2026 with the benefit of hindsight.

The short version: At the end of 2024, Chinese state hackers accessed US Treasury computers through BeyondTrust, a company whose software lets IT staff remotely support users. The attackers stole a single digital key from the vendor and used it to reach customers.

Why remote support vendors are high-risk

Remote support tools let technicians see and control computers. That's essential for IT — and exactly what attackers want. When the vendor's own systems or keys are compromised, attackers can reach many customers at once.

The business impact

  • Direct access to employee computers and the data on them.
  • Nation-state interest in government and critical-sector targets.
  • Supply-chain exposure you can't fully control.

Questions to ask your team

  • Which remote support and remote access tools are used on our computers — by IT and by vendors?
  • Do technicians need MFA and approval to start remote sessions?
  • Are sessions recorded and monitored?
  • How quickly could we disable a remote support tool if the vendor were compromised?

What good looks like

A short list of approved remote access tools, strong sign-in protection, session approval and recording, monitoring, and a plan to shut off access quickly.

The decision

Ask for an inventory of remote access tools on company devices. Unapproved or unused tools should be removed — each one is a potential back door.

us treasury breach beyondtrust impactUS Treasury / BeyondTrust2024

More on this story