Welcome to MSP 1337 - Cybersecurity Maturity Journey | Guidance and Best Practices for MSPs!

Episodes

7
Dec. 7, 2021

The Little Things

In our quest to provide the best services to our staff and our clients, it is easy to get caught up trying to solve very large problems. I think we are programmed that way as we like the feeling when we overcome those big challenges. I discuss with Jim Harryman of Kinetic Technology Group how what may seem insignificant or small can directly improve the cybersecurity posture of the infrastructure we are responsible for. Thanks to Eric Hanson of Inland Productivity Solution and a few other unname...
6
Nov. 30, 2021

Why Peer Groups Matter

The month of November has focused on incremental changes that MSPs can make to improve their security posture. I sit down with Jay Tipton to discuss why joining a peer group is one of those incremental changes. If you know Jay you know he has been through a lot this last year. The combined consumption of energy drinks (cases) and countless hours (over 500) invested in recovering from ransomware has given Jay some great insights and wisdom to share with all MSPs.
3
Nov. 23, 2021

You Can Only Pick Three

What if you could only pick three security products/services to include in your offering? I sit down with Charles Love of Showtech Solutions to discuss the three picks. Surprise alert... We don't pick the same three.
4
Nov. 16, 2021

Overcoming objections

We are all dealing with objections when it comes to convincing our clients to take cybersecurity seriously. I sit down with Eric Hanson of Inland Productivity Solutions to discuss the opportunities and challenges of positioning cybersecurity products and services with new and existing clients. Join us as we address some of the top objections.
3
Nov. 10, 2021

MSP Relevant Framework Adoption

Now that we are in week two of the cybersecurity program we thought it would be helpful for MSPs to have something that they can map their program too. I sit down with Jim Harryman of Kinetic Technology Group to discuss their journey to baseline security with SOC-2 and other frameworks that can help MSPs of all sizes be successful with their cybersecurity maturity journey. Our goals are to give any MSP a level of confidence with supporting evidence of their cybersecurity maturity growth.
2
Nov. 2, 2021

Getting Started

Paralysis Analysis are commonplace among MSPs, Businesses large and small when it comes to taking on Cybersecurity. As we come off Cybersecurity awareness month we are tackling cybersecurity and incremental approach to implementing a cybersecurity program. Join me as I discuss a where to start approach with Charles Love of Showtech Solutions.
1
Oct. 26, 2021

Ounce of Prevention = Pound of Cure

After we talked about the pre/post-boom I thought we should cover the security services side of being an MSP. Join me with Joshua Smith of Varonis as we talk about understanding what it is that we are trying to protect. Do we understand the risks? Are we talking to the right stakeholders? We are now in season two and just in time for the holidays... Do you know where your data is? Do you have the right tools in place? Thanks to our sponsor MSP-Ignite for making this episode and all of Cybersecu...
52
Oct. 19, 2021

Pre/Post Boom

What have you done to prepare for ransomware or other incidents that can cause repercussions that impact your business? Do you have a plan in place for post-boom or after an event has happened? This week I am joined again by Eric Hanson of Inland Productivity Solutions to discuss Protect and Detect. What are the tools and services in place for protecting yourself and your client?
51
Oct. 12, 2021

Cybersecurity for SMB MSP

Businesses come in all shapes and sizes, and when it comes to cybersecurity, there is no one size fits all. I sit down with William Mulcahey of M6 Managed IT to discuss what it means as a smaller MSP. Some good questions, and while not all of the questions necessarily have answers any of us want to hear, hopefully, it gives some guidance on where to start.
50
Oct. 5, 2021

Cyber Insurance. A no brainer!

Sitting down with Jeremiah Grossman of Bit Discovery and Jeffrey Smith of Cyber Risk Underwriters to talk about the need to have cyber insurance. What it covers and how relatively inexpensive it is compared to not having coverage at all. Advocating for everyone to buy insurance (cyber insurance). Knowing that the cost of insurance in many cases is far less expensive than trying to satisfy one more security control. Looking at the risk and probability will help you determine how much coverage you...
49
Sept. 28, 2021

Hoodies vs Suits

A few weeks back I attended Blue Team Con in Chicago. Based on one fo the sessions that discussed the culture challenges and shortages of qualified candidates I asked the founders of Blue Team Con to join me to discuss the challenges of finding talent and what to look for. Why are hacker (hoodies) conferences always filled by young people? Why are other events that focus more on the blue team security defense side attended by those in business attire (suits) and seem to be an older age group? Th...
48
Sept. 21, 2021

Power is out... now what?

We recently talked about BCDR and making sure there is a plan in place that is communicated. It felt like we left a few things out so this week I sat down with Charles Love again to hash out some of the procedures. Join us as we discuss Tolerance, Expectations, and Categorical identifiers and how each have their own deliverables to ensure the best outcome for all involved. No internet for 15 minutes? No Power for 2 hours? What happens if the power is going to be out for 4 hours or all day? Just ...
47
Sept. 18, 2021

Business Continuity (BCDR)

I don't think there are any MSPs who aren't dealing with backups of data for their clients, whether it is for onsite data or cloud services it has become par for the course. In this episode I sit down with Charles Love of ShowTech Solutions to talk about pitfalls and obstacles we face with our clients when trying to appropriately size and position a BCDR solution. We even talk about the risks and security that go into deciding which vendors or solutions to use. CIS v8 Control 15 anyone? Thanks ...
44
Sept. 7, 2021

Adding an "s" to MSP (Compliance and Me)

Security and Compliance go hand in hand, but we live in a world where cybersecurity obligations are still driven by what our clients might require of us. You don't have to become an MSSP to prioritize cybersecurity in our own businesses and our clients. We don't have to be experts in cybersecurity controls, but you need to participate and guide your clients on the controls they need to address. As you work towards or maybe have already added an "s" in MSsP, are you providing guidance and helpi...
44
Aug. 31, 2021

Finger Pointing

Power outages, slow internet, ransomware, and many other scenarios cause a finger to get pointed at someone. I know I have had a few fingers pointed at me and I know that I have also done my own share of finger pointing. In recent discussions with other MSPs I came to the following conclusion... Finger Pointing doesn't help! Eric Hanson of Inland Productivity and I sit down to discuss ways to reduce the finger pointing during crisis to get the client back online and working as quickly as possib...
43
Aug. 24, 2021

Recent Breaches in the Media

With T-Mobile, AT&T, and now even Microsoft reporting breaches questions start to come up as to what can be done. Why is this happening? Don't these companies focus on securing our information? I have also noticed that many of the answers coming from these large companies is a bit cold and lacks any real empathy towards their customers who have now become potential victims. Join me as I discuss this with Chad Holstead from BKS and our take on what can be done as an MSP and how taking a proactiv...
43
Aug. 18, 2021

O365 Cybersecurity Tips and Tricks

We have all had an opportunity to work with a Microsoft product or two in our careers. This week I sit down with Charles Love to recap some recent O365 challenges we both faced and better prepared for future migrations, upgrades, and enhancements. Cybersecurity and O365 don't play nice out of the gate with each other, but that doesn't mean we can't get it locked down appropriately. We cover licenses and product types as pertains to different compliance frameworks and regulations. We discuss MX R...
42
Aug. 11, 2021

HIPAA Compliance?

It seems we have covered different cybersecurity frameworks and the challenges MSPs face to become compliant, but until now we haven't talked specifically about HIPAA compliance. As an MSP you might find that you are a Business Associate and not knowing doesn't let you off the hook. Join Bryan Sullo and me as he fires questions about HIPAA compliance and I try to answer as many of them as I can. If we leave something out please let us know.
41
Aug. 3, 2021

Cyber Insurance. Am I Covered?

It seems that more often than not we talk about Cyber Insurance. The last two episodes we talked specifically about risk and going back to December 2020, Episode 8, we talked about cyber insurance and ransomware with Frank Bauer of Vade Security. A recent voicemail from Eric Hansen of Inland Productivity Solutions prompted a discussion around Cyber Insurance. Here are the key discussion points: 1. Do I have enough insurance? 2. If I make a claim will my insurance company pay? 3. My clients do...
40
July 27, 2021

Prospect Scorecard

Last we we discussed client risk and even a bit about our own risks. Throughout our discussion I kept thinking we need a way to score our prospective or existing clients to help determine those that bring us more risk. There is one person I know that is meticulous in how he manages the onboarding process and so I am happy to say Charles Love is back to give us some tips on how to create a client or prospect scorecard.
39
July 20, 2021

Risky Clients

Most of us can relate to a client grading system. We grade client's prompt bill payments, how they treat our techs, demands, or requests that sometimes seem outlandish or impossible. In our ever-changing world of managed services, we are now layering on security service offerings that have potential consequences that may include ourselves when declined. Join me this week as I sit down with Jim Harryman of Kinetic Technology Group to discuss client risk and how to address it. Our goal is that ou...
38
July 13, 2021

Zero Trust

If you haven't seen the NIST definition of Zero Trust, then you have come to the right episode. I sit down with Bryan Sullo of Clock Tower Technologies to discuss what Zero Trust really means to those of us who operate in the realm of an MSP. As we go in circles on zero trust, we begin to unpack the cybersecurity stack and compare it to balancing a checkbook. I'm not sure we have the full comprehensive answer, so if you have ideas or suggestions related to this episode or a topic you would like...
37
July 6, 2021

Imposter Syndrome

Do you ever feel like you aren't the expert? You are meeting with a prospect or an existing client, and you suddenly doubt your abilities... If you have ever been there and felt like you were just weren't good enough and what do the clients or prospects think when we don't have an answer. Join me as I sit down with Joshua Smith, former business partner, and a cybersecurity expert himself, as we navigate imposter Syndrome. This is a vulnerable episode as we admin some of our challenges early on ...
36
June 29, 2021

Communication Etiquette and Protocols

Starting with Communication and what is appropriate? We will discuss the different types of communication and when they should be used to have effective communication. When to use Chat, when to use email, when to use phones, and text messaging. This leads us down the path for incident response and other more urgent communications are getting to the right person and read. I sit down this week with Matthew Schroeder a grad student at Lindenwood University to talk about communication protocols and...