Welcome to MSP 1337 - Cybersecurity Maturity Journey | Guidance and Best Practices for MSPs!

Episodes

35
June 22, 2021

Gas Prices and Meat Shortages

As the podcast series has grown to more than 30 episodes it is starting to feel like Deja vu. We have topics to choose from that will likely go on indefinitely but is there a pattern to this madness as we work together to go on the offensive. The threat actors are still getting away with huge ransoms tied to poorly implemented configurations, protections not properly installed alongside people who still click on the link or use weak passwords. Join me this week with the return of Eric Hanson of...
34
June 15, 2021

Hope For Ransomware

Is there hope in the fight against ransomware? In this week's episode, I sit down with Greg Edwards of CryptoStopper to discuss ransomware and other exciting topics. It is long past due that we get proactive and take the fight to the bad guys. There is hope and it isn't a single product or service but more an approach. If you haven't met Greg Edwards you are in for a treat as he talks about his journey as an MSP fighting what seemed like a losing battle with ransomware and how a change in how th...
33
June 8, 2021

Do you Know Your Client (KYC)

Recently Common Controls Framework put out a survey that asked respondents questions about how well they know the people in their client's companies and the people that work there. I thought I would really like to understand what went behind the questions and what the survey results looked like... So I reached out to Dorian Cougias, CEO and founder of Common Controls Framework. After several conversations about the schemas and research that goes into a KYC exercise, we were able to put together ...
32
June 1, 2021

Performing Tabletop Exercises

A recent post on Linkedin asked whether you do Table Top Exercises internally or with your clients? It hit me right between the eyes. We talk about the need to do them, and I am guilty of not getting past the conversation stage, so I decided to sit down with the guy who posted the question. Join me this week as I sit down with Art Gross of Breach Secure Now to talk about tabletop exercises and how we don't have to make it complicated.
31
May 26, 2021

Student Perspective on Cybersecurity

This week I sit down with a former student, Matthew Schroeder, to talk about his take on cybersecurity. What inspired him to pursue a path in cybersecurity and the opportunities that await. While we do go down a rabbit hole or two, it is important to know that we are really focused on sharing our cybersecurity passions and answering some questions around automation and people. Did I mention people? Thanks again to our sponsor Pinpoint Solutions, LLC, and our partner MSP-Ignite for making this h...
30
May 18, 2021

Privacy, Consumerism and SASE

People and Privacy, From one office of twenty or thirty employees to twenty offices of one employee per home office. 2020 was difficult for all of us as we adapted to new working conditions both at home (most of us) and at the office or school, where you might have to follow vastly different protocols to stay safe. This week I am joined by Raffi Jamgotchian of Triada Networks to talk about privacy and an increasing request for Secure Access Service Edge (SASE). We uncover that while security in...
29
May 11, 2021

Security Awareness Training

Over the past twenty-plus episodes, we inevitably get around to talking about people. In episode 22, "Cybersecurity Still Comes Down To People", only reinforces the need to hear what my guest, Craig Taylor of Cyberhoot has to say. We talk about educating the unwilling when it comes to cybersecurity but it is so much bigger than that. Join us as we discuss the finer points of vendors who provide products that aren't set to a security state as a default, Frameworks that might include the need to p...
28
May 4, 2021

Evaluating Vendors (Part 2 of 2)

Last week we talked about vendor evaluation from an MSP perspective and this week we talk about it from a client or end-user perspective. Join me as I sit down with Jon Munford of New London Community School District to continue the vendor evaluation discussion. It may come as no surprise but there are three checklist times that are an exact match with last week's episode. Thanks again to our sponsor Pinpoint Solutions, LLC, and our partner MSP-Ignite for making this happen.
27
April 27, 2021

Evaluating Vendors (Part 1 of 2)

In this two-part series we are taking a look at vendor evaluation from the perspective of an MSP and then next week we will look at it from the perspective of a client. While checklists are important one thing that comes up frequently is to make sure that when evaluating a vendor that you are in the right state of mind. What problems are you trying to solve? Is this a need or a want? Join me once again as I welcome Charles Love to this episode as we unpack evaluating vendors and their approach ...
26
April 20, 2021

An Emerging Pattern.

Having gaps in your cybersecurity is inevitable, but plugging gaps with products and services doesn't necessarily make you more secure. It may put your business at a greater risk of compromise. I had the opportunity to sit down this week with Rick Mischka of Short Arm Solutions and one of The Cyber Pro Podcast hosts to talk about some of the emerging trends from the many interviews on their show that focuses on 10-12 questions about cybersecurity. There was one consistent pattern that emerged......
25
April 13, 2021

Overcoming Policies

Policies are a hot topic as insurance companies ask to see them, clients of clients ask to see them and even our peers are asking to see what policies we might have in place. Join me this week as I sit down with Joe Ambrosole of Net Connect as we discuss the importance of having policies and how to overcome some of the biggest obstacles as we work through them to get employees' and even clients' buy-in. A big thanks to our sponsor PC Matic, Endpoint Security built on a zero-trust/default deny p...
24
April 6, 2021

Protected and Secured

Sitting down with Marcus J. Ranum, Author of "The Myth of Homeland Security" and credited with a number of innovations in firewalls and intrusion detection systems, as well as being a co-founder at Tenable. We take a look at some of his predictions that date back to 2004 and earlier. We also look at Cybersecurity through the lens of reliable systems. If the system can be relied on then one would argue that it is probably secure. Ultimately it comes down to a properly motivated Systems Administra...
23
March 30, 2021

Vulnerability Assessment or Penetration Test?

Whether you are required to adhere to regulatory compliance or have voluntarily picked a framework to map your cybersecurity strategy and you inevitably come to crossroads with a vulnerability assessment or a penetration test. Join me this week as I sit down with Kenneth May of Swift Chip Inc. as we dissect when it is appropriate to go beyond a vulnerability assessment. The repercussions of a penetration test when a policy or guideline is not in place. If you are wondering about vulnerability as...
22
March 23, 2021

Cybersecurity Comes Down To People

LinkedIn as a social networking platform is an extremely powerful tool. I was given some advice recently, by Corey Munson of PC Matic that I should connect with ProCircular. I followed Corey's advice and randomly selected an employee to connect with. I managed to connect with the founder Aaron Warner and it was a podcast at first chat. We discuss in this episode everything from the Microsoft Exchange hack to Mass spectrometers. You don't want to miss this episode as we highlight several key oppo...
21
March 16, 2021

Cybersecurity Solutions Still Alienate The SMB

In this week's episode, I sit down with Stel Valavanis of onShore Security to discuss Cybersecurity tools and solutions from the perspective of an MSP. Stel brings a lot of insight as he has been an MSP who focused on the SMB and now an MSSP focused on the Mid-market and enterprise. We take a look at the challenges and potential opportunities in the SMB space, we find that there is still hope, as it is not all doom and gloom. While we don't have all the answers to bring the SMB into the fold we...
20
March 9, 2021

Transitioning to MSSP or MSsP

One MSP’s journey and transformation into an MSSP or as I like to call it MSsP. Join me as I sit down with Chad Lauderbach of Be Structured Technology Group and hear first hand what it takes.
19
March 2, 2021

Defining The Why...

We have talked about compliance and frameworks. We have talked about products and services and the gaps they fill to improve our security posture. We have even spent time mapping those products and services to the controls they satisfy but, have we defined the why (knowing the risks) which is where it all needs to start. Join me as I sit down with James Bowers of Input Output as we talk through the why.
18
Feb. 23, 2021

The Great America Recovery

For the first time in the MSP 1337 podcast series, I get to sit down with a friend and colleague from across the pond. An opportunity not to be missed as I sit down with Ian Trump-Thorpe to discuss the Great America Recovery. 2020 Was awful for many of us and as we roll into spring 2021 there is a definite opportunity to rebuild our infrastructure. Join Ian and me as we take a look at the past, present, and future of cybersecurity and how it impacts the MSP. Thanks to our sponsor vCIOToolbox.com...
17
Feb. 16, 2021

NIST Domains: MSPs Strengths and Weaknesses Across The Five Domains

MSPs have always provided to their clients' products and services that fall into the domains of Detection and Protection as well as Identification. That said, there are two categories in the NIST domain that have often been given little to no attention... Respond and Recover. Join me this week with Steve Alexander of MSP Ignite to discuss the finer points of Response and Recover.
16
Feb. 9, 2021

Evolution of an MSP: From Infrastructure to End Users

The past decade and beyond the MSP has always been about managing the technology infrastructure of their clients. As the evolution of an MSP has gone from a business model that was largely break-fix has become over time a per-user model. Our products and services have largely been tied to enabling our clients to do what they do best. In more recent years it has become increasingly tied to adding protective layers for our client's employees through products and services ranging from VPNs and 2FA ...
15
Feb. 2, 2021

Navigating a Terrain Unlike Any Other

A brief trip down memory lane to simpler times... Looking back 3-5 years we took on the likes of ransomware and malware with additional tools and products that made us look, dare I say, pretty good to our clients in keeping them safe as we avoided paying ransoms by recovering from backups or preventing the spread to the rest of the client's network or even warding off would-be attackers. Fast forward and 2020 seemed to take many MSPs and their clients by surprise. Join me this week with Bryan Su...
14
Jan. 26, 2021

Don't Drink From The Same Cup

When drinking from the same cup or bowl doesn't make sense. Adding redundancy and capacity in the event there is an outage, not so much for your client but for you, the MSP. This week we welcome back Eric Hanson of Inland Productivity as we discuss different options for redundancy.
13
Jan. 20, 2021

Getting Started with CIS Top 20

I recently had an opportunity to sit down with a long-time friend and colleague, Jason LeDuc of AccessIT Group, and discuss CIS Top 20 and a walk-through of the critical 6. We spend a few minutes on each control, and that while there is no "easy button," it doesn't mean this has to be difficult. Stay tuned through the end to hear about which control is as important, if not more important, than all the other controls!
12
Jan. 12, 2021

Cybersecurity in K12

This week I had an opportunity to sit down with Corey Muson of PC Matic and talk about Cybersecurity in the K12 space. MSPs have a huge opportunity to come into the K12 space and help the Tech Directors and other K12 staff navigate a space that is uncharted territory for many. Join us as we share insights and opportunities to help K12 staff defend against the threat actors who are now targeting this demographic.