Last month, this site flagged a critical authentication-bypass flaw in N-able’s N-central, a remote monitoring and management (RMM) platform widely used by IT support firms to manage client systems. At the time it was an active exploitation warning: patch now, ask your provider if they had. This week, the warning has become the thing it was warning about. Microsoft Threat Intelligence has confirmed that a group tracked as Storm-1175 is now using that same N-central weakness to deploy a new ransomware strain called StormEncryptor, hitting healthcare, professional services and finance organisations across Australia, Britain and the United States.

This matters for UK SMEs for exactly the reason it did last month, only more urgently: you almost certainly don’t run N-central yourself, but if your outsourced IT provider does and hasn’t closed the gap, that provider’s compromised console is now a confirmed, live route into every client machine it manages — including yours.

What’s changed since last month

The distinction matters. A vulnerability disclosure is a “you should probably fix this” moment; a confirmed ransomware campaign exploiting it is a “this is happening to real businesses right now” moment. Storm-1175 has previously used the Medusa ransomware against the same sectors before pivoting to StormEncryptor, and its pattern is fast: initial access through the RMM flaw, rapid data theft, then encryption, often before a slower-moving MSP has time to notice and respond. Researchers still estimate a meaningful share of reachable N-central servers remain unpatched a month after the original disclosure, which is exactly the gap this group is now moving through.

What makes this pattern particularly awkward for small businesses is the delay between disclosure and consequence. Most SME owners read a vulnerability warning, mentally file it under “IT’s problem,” and move on within the day. Ransomware groups, by contrast, often wait exactly this long on purpose, giving the initial wave of urgent patching time to fade before targeting whoever didn’t follow through. A month is not a safe gap. It’s often the gap an attacker was counting on.

The one conversation to have again this week

If you asked your IT provider about N-central patching a few weeks ago and got a confident answer, it’s worth a short follow-up: “Given the StormEncryptor reports this week, can you confirm you’re still fully patched and are actively monitoring for unusual activity on the console itself?” If you never had that conversation the first time, have it now — the cost of asking is one email; the cost of not asking is inheriting your provider’s breach as your own.

Businesses that outsource IT entirely often assume “we pay someone for this” is itself a security control. It isn’t. It’s a dependency, and dependencies need occasional checking, not blind trust. This is precisely the kind of gap independent monitoring from a firm like KeepSafe is built to catch — watching for the signs of compromise on your own systems that neither you nor your provider may spot until the ransom note appears.

Beyond this one platform

N-central is the specific product in the headlines this week, but the underlying lesson applies to every RMM, ticketing, or remote-access tool your provider uses on your behalf. If you don’t already know, ask what other third-party software sits between your provider and your systems, and whether any of it has had a serious vulnerability disclosed in the last few months. You’re not expected to become a security expert overnight, but a business that has never asked the question at all is in a weaker position than one that’s at least started keeping a short list of what it’s relying on.

The takeaway

A patched vulnerability that stays patched is a non-event. An unpatched one, a month later, is now attached to a named ransomware strain hitting real businesses in your sector. If you had this conversation with your IT provider in August, have it again this week and ask specifically about StormEncryptor. If you didn’t have it at all, today is the day.