Welcome to MSP 1337 - Cybersecurity Maturity Journey | Guidance and Best Practices for MSPs!

Episodes

52
Nov. 15, 2022

Risky People

Risk has been at the top of mind for several episodes as of late. So much so that it seems to show up in my Flipboard news feed and suddenly a LinkedIn post popped up by David Schultis, of Red Panda, talking about Risk to UNLV students. Join us for a conversation around Risk and educating people who often are the risk.
51
Nov. 8, 2022

Advisory Services

Within every MSP we have roles that involve Account Management and in some cases have even evolved the title to vCIO or other name. The challenge in many cases is how to charge for this role? Should it be a standalone service offering? Is it just the tip of the spear or the whole spear? I sit down with Brian Doyle of vCIOToolbox.com to discuss this challenge and opportunity as it pertains to how we provide advisory services both internally and to our clients.
50
Nov. 1, 2022

Risk Management Plan

In talking about risk we often don't address risk management plans at all. In this episode I discuss with Jim Harryman of Kinetic Technology Group, all things risk. It often starts with a Risk Assessment and we step through what that might look like and how to begin building out a plan within your organization.
49
Oct. 25, 2022

Monitoring Cloud Services

I always have wondered why we assume our end users know how to use the technology we provide them. The age old argument of 10% of the product's capability is actually used. I sit down with Charles Love to talk about all the interesting things that go on behind the scenes with end users. We spend a lot of time on a specific vendor or two but these are just to provide good examples.
48
Oct. 18, 2022

Beyond Zero Trust My Browser

I couldn't let it go... The browser or browsers have the potential to be the trojan horse. I sit down with Jim Harryman of Kinetic Group to discuss what we can do within the browser to ensure a more secure posture with resources to protect the user experience. If you remember in part one of, "Zero Trust Your Browser" we talked about how much power the browser has. In this episode we focus on reining it in.
47
Oct. 11, 2022

Four Truths of Cybersecurity

You can't secure others if you don't first secure yourself. Security should be just as important at home as it is at work and you take responsibility for your actions. I sit down with Scott Augenbaum to discuss what is in his book, "The Secret to Cybersecurity." Spoiler alert there is no secret. We have a great conversation and I think everyone who listens will find some takeaways that will cost little to nothing to implement.
46
Oct. 4, 2022

Zero Trust Your Browser

Regardless of which browser(s) you use how often do you patch them. Do you maintain the extensions and restrict what is and isn't sync'd. I sit down with Kenneth May of Swift Chip to discuss how we need to do a better job creating whitelist/blacklist on apps within the browser. Educate the end user on the vulnerabilities created by adding extensions or not relaunching the browser when updates are pending. It is Cybersecurity month and I think you will find this episode will give you some serious...
45
Sept. 27, 2022

Onboarding and Offboarding

In cybersecurity we don't spend as much time as we probably should in the area of onboarding and offboarding. Initiated by the HR department or in smaller companies perhaps handled by the company owner to bring in new employees and then of course when an employee exits the company what does that process look like. Is this process documented and is the workflow the same for onboarding as it is offboarding? This and many other questions associated with people and their role within a company as the...
44
Sept. 20, 2022

Going Beyond RMM and MDM

A continued discussion on RMM and MDM tools. How they differ and how they overlap. In this ever evolving threat landscape they are both extremely important. In this episode Jim Harryman and I will review some of the historical reasons behind why we have them in our environments but we will really be focused on how they help us now and in the future as BYOD and Cloud computing factor in to our end user and device management.
43
Sept. 13, 2022

Four Years Post Breach

Over the past two years I have gotten to know Brian Weiss and much of our conversation has revolved around how he continues to improve the security posture of his company. This is largely tied to an event that took place back in March of 2018 that crippled 1/2 of his then client base. In this milestone episode 100 we recap his journey when we checked in on him for episode one almost two years ago and how the world has changed in the last four years.
42
Sept. 7, 2022

MDM, Not Just for Mobile Devices

As solution providers we spend a lot of time with different tools and services to support our clients. I sit down with Charles Love of ShowTech Solutions to discuss how RMM and MDM (DM) go hand in hand in managing the assets placed under our care.
41
Aug. 30, 2022

Vulnerabilities and Exploits

Vulnerabilities and exploits happen to be very common in today's threat landscape and not all vulnerabilities are actionable. I sit down with Wes Spencer, of Fifth Wall, to provide insights to solution providers on how to communicate with their vendors and their clients in a way that is actionable and with credibility. As the saying goes, "You are either part of the problem or part of the solution."
40
Aug. 23, 2022

Data Protection, a Moral Obligation

I think most of us would agree that protecting data is a very big part of the job as a Solution Provider. Joshua Smith and I tackle this conversation when it comes to the costs associated with protecting that data and what it means to lead and follow in an ever evolving threat landscape.
39
Aug. 16, 2022

What are Integrator Groups?

As Solution providers (MSPs), a security first mindset can at times be difficult. We know that our responsibilities to our staff and clients is about reducing the probability of being an easy target. Cybersecurity isn't easy but it get's easier when you do it with others. Chad Holstead and I discuss what it means to be part of an integrator group that has agreed upon a set of standards or controls to improve their security posture.
38
Aug. 9, 2022

Recap of Channelcon22

As we recover from a week in Chicago with our colleagues and friends I thought we should take a minute to recount some of the highlights. I sit down with Lenny Giller of Reliable Technology Services to get his perspective on MSP-Ignite Pre-day and some of the tracks we had an opportunity to attend. I think clearly the message is to get involved with CompTIA ISAO, get involved with the community and share with each other lessons learned. Cybersecurity is one step at a time.
37
Aug. 2, 2022

Lessons from a CISO

The role of an MSP as trusted advisor or vCIO has evolved over the years and more recently it seems the added responsibility of security officer is added to the mix. In my conversation with Craig Buesing who is the CISO to the Secretary of State of Colorado, we spent a lot of time talking about cybersecurity is a collaboration. You can't do it by yourself and it is the collaboration and knowledge sharing that makes us all more secure.
36
July 26, 2022

Good, Better, Best

One week until ChannelCon and MSP-Ignite Pre-day. This week we have Dave Sobel, "Host of the Business of Tech Podcast." While Dave and I have been known to go down a few rabbit holes in past conversations, we manage in this episode to focus on three main points: Cyber Tax is a real thing and should be openly discussed with your clients, Tech Debt is a challenge for both vendors and MSPs, and victim blaming doesn't change what has happened.
35
July 19, 2022

Red Team + Blue Team = Purple Team

Table top exercises, Security Awareness Training, and vulnerability management are all ways that we look to improve our security posture. Join me as I talk to Kevin Ireland of Hack The Box regarding teaching your team to participate in red team exercises.
34
July 12, 2022

Economy of Scale

ChannelCon is right around the corner and we are still discussing the culture shift to a cybersecurity first mindset. I sit down with Joshua Smith of Varonis to talk about how culture shift and doing the right thing are same problem different scale. Whether you are a vendor or an MSP it still comes down to People, Process and Product (technology). We step you through four key steps to begin the shift within your organization.
33
July 5, 2022

Cybersecurity and Cannabis

With the theme of, "Doing the right thing," on our show I had the unique opportunity to sit down with Harry Brelsford to talk about the need for cybersecurity in the Cannabis dispensary vertical. While this is a very specific niche and is definitely not as mature as many other verticals it was an eye opener for me and I hope you will find opportunity for strength and maturity in cybersecurity. Harry very neatly breaks down security into three categories that really helps give perspective on area...
32
June 28, 2022

Is 2FA The Right Thing?

As we continue our discussion around "Doing the right thing", I sit down with Eric Hanson of Inland Productivity to specifically discuss 2FA. There are so many layers in any security stack but there always seems to be a lot to talk about when it turns to 2FA. Plenty of humor included in this episode!
31
June 21, 2022

Almost A Victim...

When doing the right thing could have turned out so different. I sit down with Jessica Millhiser of Systems Gal to discuss a recent event with one of her clients that could have turned out very differently. Business Operations is her specialty and what we found in our conversation is that if you aren't weaving cybersecurity into your business processes you are just asking for a breach.
30
June 14, 2022

Cybersecurity Baseline

As we continue the discussion surrounding,"Do The Right Thing" it was brought to my attention that I had something in a town hall that an MSP disagreed with. Join me as I sit down with Matt Horning of BlueTree Technology as we sort out our disagreement and align on a cybersecurity minimum that we agree is necessary for all of our clients.
29
June 8, 2022

Do The Right Thing (see something, say something.)

When you travel, especially when you fly, you see the statement plastered everywhere, "If you see something say something." You are told not to watch someone else's bags etc. Well, when it comes to cybersecurity is it really any different? Eric Hanson and I go through an exercise that looks at this concept applied to cybersecurity. Inconvenience, obstacles, or other anomalies if ignored allow us to continue to be efficient and get our jobs done. How do we balance and appropriately call out conce...