Welcome to MSP 1337 - Cybersecurity Maturity Journey | Guidance and Best Practices for MSPs!

Episodes

52
Oct. 19, 2021

Pre/Post Boom

What have you done to prepare for ransomware or other incidents that can cause repercussions that impact your business? Do you have a plan in place for post-boom or after an event has happened? This week I am joined again by Eric Hanson of Inland Productivity Solutions to discuss Protect and Detect. What are the tools and services in place for protecting yourself and your client?
51
Oct. 12, 2021

Cybersecurity for SMB MSP

Businesses come in all shapes and sizes, and when it comes to cybersecurity, there is no one size fits all. I sit down with William Mulcahey of M6 Managed IT to discuss what it means as a smaller MSP. Some good questions, and while not all of the questions necessarily have answers any of us want to hear, hopefully, it gives some guidance on where to start.
50
Oct. 5, 2021

Cyber Insurance. A no brainer!

Sitting down with Jeremiah Grossman of Bit Discovery and Jeffrey Smith of Cyber Risk Underwriters to talk about the need to have cyber insurance. What it covers and how relatively inexpensive it is compared to not having coverage at all. Advocating for everyone to buy insurance (cyber insurance). Knowing that the cost of insurance in many cases is far less expensive than trying to satisfy one more security control. Looking at the risk and probability will help you determine how much coverage you...
49
Sept. 28, 2021

Hoodies vs Suits

A few weeks back I attended Blue Team Con in Chicago. Based on one fo the sessions that discussed the culture challenges and shortages of qualified candidates I asked the founders of Blue Team Con to join me to discuss the challenges of finding talent and what to look for. Why are hacker (hoodies) conferences always filled by young people? Why are other events that focus more on the blue team security defense side attended by those in business attire (suits) and seem to be an older age group? Th...
48
Sept. 21, 2021

Power is out... now what?

We recently talked about BCDR and making sure there is a plan in place that is communicated. It felt like we left a few things out so this week I sat down with Charles Love again to hash out some of the procedures. Join us as we discuss Tolerance, Expectations, and Categorical identifiers and how each have their own deliverables to ensure the best outcome for all involved. No internet for 15 minutes? No Power for 2 hours? What happens if the power is going to be out for 4 hours or all day? Just ...
47
Sept. 18, 2021

Business Continuity (BCDR)

I don't think there are any MSPs who aren't dealing with backups of data for their clients, whether it is for onsite data or cloud services it has become par for the course. In this episode I sit down with Charles Love of ShowTech Solutions to talk about pitfalls and obstacles we face with our clients when trying to appropriately size and position a BCDR solution. We even talk about the risks and security that go into deciding which vendors or solutions to use. CIS v8 Control 15 anyone? Thanks ...
44
Sept. 7, 2021

Adding an "s" to MSP (Compliance and Me)

Security and Compliance go hand in hand, but we live in a world where cybersecurity obligations are still driven by what our clients might require of us. You don't have to become an MSSP to prioritize cybersecurity in our own businesses and our clients. We don't have to be experts in cybersecurity controls, but you need to participate and guide your clients on the controls they need to address. As you work towards or maybe have already added an "s" in MSsP, are you providing guidance and helpi...
44
Aug. 31, 2021

Finger Pointing

Power outages, slow internet, ransomware, and many other scenarios cause a finger to get pointed at someone. I know I have had a few fingers pointed at me and I know that I have also done my own share of finger pointing. In recent discussions with other MSPs I came to the following conclusion... Finger Pointing doesn't help! Eric Hanson of Inland Productivity and I sit down to discuss ways to reduce the finger pointing during crisis to get the client back online and working as quickly as possib...
43
Aug. 24, 2021

Recent Breaches in the Media

With T-Mobile, AT&T, and now even Microsoft reporting breaches questions start to come up as to what can be done. Why is this happening? Don't these companies focus on securing our information? I have also noticed that many of the answers coming from these large companies is a bit cold and lacks any real empathy towards their customers who have now become potential victims. Join me as I discuss this with Chad Holstead from BKS and our take on what can be done as an MSP and how taking a proactiv...
43
Aug. 18, 2021

O365 Cybersecurity Tips and Tricks

We have all had an opportunity to work with a Microsoft product or two in our careers. This week I sit down with Charles Love to recap some recent O365 challenges we both faced and better prepared for future migrations, upgrades, and enhancements. Cybersecurity and O365 don't play nice out of the gate with each other, but that doesn't mean we can't get it locked down appropriately. We cover licenses and product types as pertains to different compliance frameworks and regulations. We discuss MX R...
42
Aug. 11, 2021

HIPAA Compliance?

It seems we have covered different cybersecurity frameworks and the challenges MSPs face to become compliant, but until now we haven't talked specifically about HIPAA compliance. As an MSP you might find that you are a Business Associate and not knowing doesn't let you off the hook. Join Bryan Sullo and me as he fires questions about HIPAA compliance and I try to answer as many of them as I can. If we leave something out please let us know.
41
Aug. 3, 2021

Cyber Insurance. Am I Covered?

It seems that more often than not we talk about Cyber Insurance. The last two episodes we talked specifically about risk and going back to December 2020, Episode 8, we talked about cyber insurance and ransomware with Frank Bauer of Vade Security. A recent voicemail from Eric Hansen of Inland Productivity Solutions prompted a discussion around Cyber Insurance. Here are the key discussion points: 1. Do I have enough insurance? 2. If I make a claim will my insurance company pay? 3. My clients do...
40
July 27, 2021

Prospect Scorecard

Last we we discussed client risk and even a bit about our own risks. Throughout our discussion I kept thinking we need a way to score our prospective or existing clients to help determine those that bring us more risk. There is one person I know that is meticulous in how he manages the onboarding process and so I am happy to say Charles Love is back to give us some tips on how to create a client or prospect scorecard.
39
July 20, 2021

Risky Clients

Most of us can relate to a client grading system. We grade client's prompt bill payments, how they treat our techs, demands, or requests that sometimes seem outlandish or impossible. In our ever-changing world of managed services, we are now layering on security service offerings that have potential consequences that may include ourselves when declined. Join me this week as I sit down with Jim Harryman of Kinetic Technology Group to discuss client risk and how to address it. Our goal is that ou...
38
July 13, 2021

Zero Trust

If you haven't seen the NIST definition of Zero Trust, then you have come to the right episode. I sit down with Bryan Sullo of Clock Tower Technologies to discuss what Zero Trust really means to those of us who operate in the realm of an MSP. As we go in circles on zero trust, we begin to unpack the cybersecurity stack and compare it to balancing a checkbook. I'm not sure we have the full comprehensive answer, so if you have ideas or suggestions related to this episode or a topic you would like...
37
July 6, 2021

Imposter Syndrome

Do you ever feel like you aren't the expert? You are meeting with a prospect or an existing client, and you suddenly doubt your abilities... If you have ever been there and felt like you were just weren't good enough and what do the clients or prospects think when we don't have an answer. Join me as I sit down with Joshua Smith, former business partner, and a cybersecurity expert himself, as we navigate imposter Syndrome. This is a vulnerable episode as we admin some of our challenges early on ...
36
June 29, 2021

Communication Etiquette and Protocols

Starting with Communication and what is appropriate? We will discuss the different types of communication and when they should be used to have effective communication. When to use Chat, when to use email, when to use phones, and text messaging. This leads us down the path for incident response and other more urgent communications are getting to the right person and read. I sit down this week with Matthew Schroeder a grad student at Lindenwood University to talk about communication protocols and...
35
June 22, 2021

Gas Prices and Meat Shortages

As the podcast series has grown to more than 30 episodes it is starting to feel like Deja vu. We have topics to choose from that will likely go on indefinitely but is there a pattern to this madness as we work together to go on the offensive. The threat actors are still getting away with huge ransoms tied to poorly implemented configurations, protections not properly installed alongside people who still click on the link or use weak passwords. Join me this week with the return of Eric Hanson of...
34
June 15, 2021

Hope For Ransomware

Is there hope in the fight against ransomware? In this week's episode, I sit down with Greg Edwards of CryptoStopper to discuss ransomware and other exciting topics. It is long past due that we get proactive and take the fight to the bad guys. There is hope and it isn't a single product or service but more an approach. If you haven't met Greg Edwards you are in for a treat as he talks about his journey as an MSP fighting what seemed like a losing battle with ransomware and how a change in how th...
33
June 8, 2021

Do you Know Your Client (KYC)

Recently Common Controls Framework put out a survey that asked respondents questions about how well they know the people in their client's companies and the people that work there. I thought I would really like to understand what went behind the questions and what the survey results looked like... So I reached out to Dorian Cougias, CEO and founder of Common Controls Framework. After several conversations about the schemas and research that goes into a KYC exercise, we were able to put together ...
32
June 1, 2021

Performing Tabletop Exercises

A recent post on Linkedin asked whether you do Table Top Exercises internally or with your clients? It hit me right between the eyes. We talk about the need to do them, and I am guilty of not getting past the conversation stage, so I decided to sit down with the guy who posted the question. Join me this week as I sit down with Art Gross of Breach Secure Now to talk about tabletop exercises and how we don't have to make it complicated.
31
May 26, 2021

Student Perspective on Cybersecurity

This week I sit down with a former student, Matthew Schroeder, to talk about his take on cybersecurity. What inspired him to pursue a path in cybersecurity and the opportunities that await. While we do go down a rabbit hole or two, it is important to know that we are really focused on sharing our cybersecurity passions and answering some questions around automation and people. Did I mention people? Thanks again to our sponsor Pinpoint Solutions, LLC, and our partner MSP-Ignite for making this h...
30
May 18, 2021

Privacy, Consumerism and SASE

People and Privacy, From one office of twenty or thirty employees to twenty offices of one employee per home office. 2020 was difficult for all of us as we adapted to new working conditions both at home (most of us) and at the office or school, where you might have to follow vastly different protocols to stay safe. This week I am joined by Raffi Jamgotchian of Triada Networks to talk about privacy and an increasing request for Secure Access Service Edge (SASE). We uncover that while security in...
29
May 11, 2021

Security Awareness Training

Over the past twenty-plus episodes, we inevitably get around to talking about people. In episode 22, "Cybersecurity Still Comes Down To People", only reinforces the need to hear what my guest, Craig Taylor of Cyberhoot has to say. We talk about educating the unwilling when it comes to cybersecurity but it is so much bigger than that. Join us as we discuss the finer points of vendors who provide products that aren't set to a security state as a default, Frameworks that might include the need to p...