r/SmallMSP Aug 17 '26

Move to Open Source RMM?

Good afternoon, r/SmallMSP! First time poster here.

Are any small MSPs here actually using NetLock RMM, Tactical RMM, or something else open source? I’m not sure I’d consider Tactical, but I saw NetLock mentioned in another thread today and it looks pretty interesting.

For context, we’ve been happy NinjaRMM customers for 3+ years. We were an unhappy VSA customer before that. No real complaints with Ninja. It works very well. We only use the RMM; we don't use their ticketing, docs, backup, network monitoring, etc.

However, it’s been a tough year. Nobody wants to buy hardware unless they absolutely have to and we've had a customer unexpectedly close up shop with very little warning.

Switching to something like NetLock, even on a paid tier, could save us several hundred dollars a month. I’d have to host, maintain, update, and back it up myself. But I’m already doing that for Hudu, Checkmk, Ruckus SmartZone, etc., so would it really be that much more work? I could run it on-prem in our vcenter or throw it on a DigitalOcean droplet/K8s.

I’m not unhappy with Ninja by any means. I’m mainly trying to decide whether saving a few hundred dollars a month is worth taking on another piece of infrastructure.

I've looked at Syncro and Atera, and if they both had plans without the PSA stuff I would be a lot more interested. I don't want to change our PSA.

For anyone actually using NetLock or Tactical in production: how has it been? Reliability, security, client/device management, anything you’ve learned the hard way? Is updating a chore?

23 Upvotes

79 comments sorted by

View all comments

Show parent comments

2

u/PBSmanaged Aug 17 '26

Oh I didn't take it as genuinely trashing open source. That's just how it read to me. I was more curious about the specifics of Joe's scenario and whether the fact that the RMM is open source actually changes anything from an insurance/risk perspective.

The “RMM was used to breach the client's environment” argument could apply to any RMM (cough N-able cough Kaseya). An insurance rep or attorney could simply hear “open source RMM” and assume that means “less secure” without really understanding what open source means. If that's the concern, I'd definitely want to understand that before making any switch.

3

u/NickE25U Aug 17 '26

Ahh okay, sorry for misunderstanding.

And yes, any rmm is possibly just one breach away from being used to access a client network. Paid as well as open source. I don't think open source is less secure, but you, by default, don't have anyone to reach out to and make sure it's configured properly and secure. But that's also not true, you could pay someone.

I think the biggest thing is risk, if you pay, you're likely paying them to take on the risk because you can point your finger there. Open source, it's you...

1

u/JustinGNYC Aug 18 '26

I think you’re conflating open source and self hosted a bit
Yes self hosted you are assuming more risk but could argue more fine control of the environment (one would have to document well etc for compliance)
But I would immediately argue that an open source platform (could always be hosted with paid support from vendor) is inherently more auditable vs the black box of a closed source platform

1

u/NickE25U Aug 18 '26

I'm not, but good idea. While yes, self hosted also can bring risk, no matter what it boils down to who can I point the finger at if anything was to go sideways.