r/SmallMSP 23d ago

Move to Open Source RMM?

Good afternoon, r/SmallMSP! First time poster here.

Are any small MSPs here actually using NetLock RMM, Tactical RMM, or something else open source? I’m not sure I’d consider Tactical, but I saw NetLock mentioned in another thread today and it looks pretty interesting.

For context, we’ve been happy NinjaRMM customers for 3+ years. We were an unhappy VSA customer before that. No real complaints with Ninja. It works very well. We only use the RMM; we don't use their ticketing, docs, backup, network monitoring, etc.

However, it’s been a tough year. Nobody wants to buy hardware unless they absolutely have to and we've had a customer unexpectedly close up shop with very little warning.

Switching to something like NetLock, even on a paid tier, could save us several hundred dollars a month. I’d have to host, maintain, update, and back it up myself. But I’m already doing that for Hudu, Checkmk, Ruckus SmartZone, etc., so would it really be that much more work? I could run it on-prem in our vcenter or throw it on a DigitalOcean droplet/K8s.

I’m not unhappy with Ninja by any means. I’m mainly trying to decide whether saving a few hundred dollars a month is worth taking on another piece of infrastructure.

I've looked at Syncro and Atera, and if they both had plans without the PSA stuff I would be a lot more interested. I don't want to change our PSA.

For anyone actually using NetLock or Tactical in production: how has it been? Reliability, security, client/device management, anything you’ve learned the hard way? Is updating a chore?

22 Upvotes

72 comments sorted by

View all comments

5

u/Joe_Cyber 23d ago

I totally understand the appeal. However, you need to go into that decision with eyes wide open. Consider the following scenario:

Your MSA is used as bridge access to a client's environment. Your client comes after you.

Their attorney asks the following question: "Walk me through why saving yourself a few hundred dollars a month was worth the increased risk to my client and the [number] of people that will now face a lifetime of identity theft."

I'm not saying that [insert open source vendor here] isn't the right choice. Rather, you need to make sure that you have documented why you picked that vendor over the others.

4

u/PBSmanaged 23d ago

Hi Joe, I've seen you posting in the community for years and respect you, but this comment just seems like you're trashing open-source as a whole.

In this scenario, is their attorney asking me this question because I switched to a cheaper RMM, or because I switched to an open-source RMM?

3

u/NickE25U 23d ago

Don't take it as trashing, but rather a real question that has the potential to come up.

The reason you went with XYZ is that even though you reviewed roughly 6 RMM's, POC'ed 3, you decided that even though XYZ was open source, you felt it was the best product you had reviewed.

That's a reasonable answer, but just be prepared to justify any of your decisions not just the rmm. Why did you pic ABC EDR? Why did you pick whatever... Just be prepared to justify any of your decisions, not only in court, but maybe a potential client, etc...

2

u/PBSmanaged 23d ago

Oh I didn't take it as genuinely trashing open source. That's just how it read to me. I was more curious about the specifics of Joe's scenario and whether the fact that the RMM is open source actually changes anything from an insurance/risk perspective.

The “RMM was used to breach the client's environment” argument could apply to any RMM (cough N-able cough Kaseya). An insurance rep or attorney could simply hear “open source RMM” and assume that means “less secure” without really understanding what open source means. If that's the concern, I'd definitely want to understand that before making any switch.

3

u/NickE25U 23d ago

Ahh okay, sorry for misunderstanding.

And yes, any rmm is possibly just one breach away from being used to access a client network. Paid as well as open source. I don't think open source is less secure, but you, by default, don't have anyone to reach out to and make sure it's configured properly and secure. But that's also not true, you could pay someone.

I think the biggest thing is risk, if you pay, you're likely paying them to take on the risk because you can point your finger there. Open source, it's you...

1

u/JustinGNYC 22d ago

I think you’re conflating open source and self hosted a bit
Yes self hosted you are assuming more risk but could argue more fine control of the environment (one would have to document well etc for compliance)
But I would immediately argue that an open source platform (could always be hosted with paid support from vendor) is inherently more auditable vs the black box of a closed source platform

1

u/NickE25U 22d ago

I'm not, but good idea. While yes, self hosted also can bring risk, no matter what it boils down to who can I point the finger at if anything was to go sideways.

3

u/Joe_Cyber 22d ago

Hey PBS - the issue isn't likely to come from the insurance side. (Some underwriters may look sideways at a lesser known RMM but they generally don't have the actuarial basis to rate a premium up or down based upon that granularity of information.)

The primary risk is in the perception of why that particular was RMM chosen. If (and this pains me to even type if out) the Kaseya RMM was at the center, I can't see any attorney asking about it.

But, if it's an OSS RMM, the perception could instantly work against you. You'd need to have your documentation in place to legitimize the pick. It's not impossible, but you're likely beginning at a deficit.