Welcome to MSP 1337 - Cybersecurity Maturity Journey | Guidance and Best Practices for MSPs!

Episodes

28
May 31, 2022

Is Affordable Cybersecurity a Myth?

I have often wondered if we tend to lean towards insurance instead of doing a better job of prevention and protection because it just costs too much. I sit down with Ismael (Izzy) Amado of IT Ninjas to prove how affordable much of cybersecurity really is. Culture change is hard but at the root of cybersecurity, success is people and process. If you are struggling with getting clients or your own employees to take cybersecurity seriously then this episode might just help you push through.
27
May 24, 2022

Cyber Insurance World Is Changing

With insurance renewals coming for many school districts in July are you able to satisfy the questionnaires? There might be a few curveballs in this conversation. I sit down with Corey Munson of PC Matic to talk about some of the changes that are happening in the space. New requirements that now include specific vendors. New vendors to choose from, limit caps, etc. are all impacting the ability of Tech Directors to successfully answer all the questions.
27
May 17, 2022

I'm Responsible For What?

Ever had a client say, "I thought you were already doing that?" I recently had a challenge with a vendor product that I had provided an audit for the client to check the security controls and ensure the client had it optimized. The questions I ask Jim Harryman of Kinetic Technology Group are all around how to clearly understand what we are responsible for whether it is with our vendors or clients.
26
May 10, 2022

Configure and Implement Securely

What should we talk about this week? I have been back and forth with topics recently that involve getting started with cybersecurity and have moved into vendor management and other areas of focus that all revolve around one key theme... Reducing risks and protecting ourselves and our clients. Join me as I discuss with Charles Love of Showtech Solutions, configurations and implementation of products and services. Where does the responsibility of vendor stop and MSP responsibilities kick in. What ...
25
May 3, 2022

Strategic Planning

We don't know what will happen tomorrow or the next day. We do however have responsibilities to our clients and our employees and there are things we can do to plan for events that we don't have control over. Join me with Steve Alexander of MSP-Ignite as we discuss how to plan so we don't end up in the knee-jerk scenario that so often is the first response.
24
April 26, 2022

Vendor Managment Challenges

As MSPs you are all dealing with managing or providing support services that involve working with 3rd party vendors. In this coversation Eric Hanson and I discuss the challenges of vendors where those who have authority to make decisions on critical infrastructure leave or are no longer in the role that would required them to manage that vendor relationship. This is not a new topic but is often an avoided topic as it pertains to MSPs working with Internet, cell phone and other vendors in support...
23
April 19, 2022

Knee Jerk Reaction or Calculated Decision

Endless topics to discuss and yet we still find ourselves talking about many of the foundational things we should all be doing in our businesses. We can only be accountable for our own actions regardless of the decisions of our vendors or our peers. Who are the vendors I work with today and what happens if they are gone tomorrow? This and many other questions are discussed with Jim Harryman of Kinetic Technology Group. As we evaluate our vendors and the services we offer we discuss having a pred...
22
April 12, 2022

Cybersecurity: I'm Stuck

We all struggle with different areas of cybersecurity and there is no perfect solution. That being said we shouldn't get paralysis analysis either, it isn't new and it isn't going away. Most of us started implementing cybersecurity tools and services long before MSSPs existed and have in many cases satisfying controls of the different frameworks anywhere from 10% to 60% and didn't even know it. Join Jim Harryman of Kinetic Technology Group as we navigate areas in which MSPs can continue to impro...
21
April 5, 2022

Cybersecurity - How To Start.

The conversations and requests coming from MSPs is still about how to get started. Hopefully, this conversation will help you find your path. Join me as Charles Love and I navigate the getting started in Cybersecurity. Even if you have already started down the path of improving your cybersecurity posture there is always room to improve.
20
March 29, 2022

Even Small Municipalities need MSPs

Whether it is a small municipality, a school district, or even your local fire department, there is always a need for 3rd party resources. I sit down with Corey Munson of PCMatic to talk specifically about how MSPs can provide a huge benefit to small government entities. We aren't talking about addressing the basic print or internet connectivity issues but more about the challenges we all face in cybersecurity. Whether it is the mayor of a small town in rural Iowa or the one computer at city hal...
19
March 22, 2022

Why Are ISACs and ISAOs Important To Me?

Last week was CompTIA's Communities and Councils Forums and I thought who better to bring on to the podcast than Wayne Selk the new VP of CompTIA's ISAO. Join us as we break down the differences between ISACs and ISAOs and how MSPs can take advantage of what these different entities have to offer as we navigate cybersecurity.
19
March 15, 2022

Cybersecurity Maturity Starts With Leadership

I sit down with Stelios Valivonis of onShore Security to talk about cybersecurity and the need for dedicated leadership. People, Process, and Procedures are critical to any organizations quest to improve their cybersecurity posture. Stel and I step through some scenarios that we have seen together and some ideas on how to succeed with client resistance to change.
18
March 8, 2022

Going Beyond Cyber Insurance

There is no shortage of questions coming from Cyber Insurance providers that put an MSP in a difficult position to answer the questions truthfully and the intent of the questions. In this episode, I sit down with Aaron Frazier of American Technology Specialists to discuss how to approach this complex topic with clients and prospects to help satisfy specific questions through enabling technologies—as always, talking to Aaron with ATS is enlightening.
17
March 1, 2022

Encryption: At Rest & In Transit

Cyber insurance questionnaires are a dime a dozen these days, yet our ability to correctly answer the questions can still be daunting. A Yes/No question doesn't have a Yes/No Answer. You want to answer truthfully, and you also want to ensure that you get the coverage you need. Join me as I sit down with Jim Harryman of Kinetic Group to find some approaches to answering these questions that are both truthful and at the heart of the question's intent...
16
Feb. 22, 2022

Formerly vCIO?

Over the years the role of an Account manager has evolved and taken on many different names (vcio, BSM, vCTO etc.). Today I sit down with Mike Stewart of Anchor Networks to discuss how much this role has changed. Cybersecurity plays a big role in planning and identifying gaps within a prospect or existing client that it can be a daunting endeavor. Join us as we provide some guidance for any vCIO to be successful in discussing cybersecurity with prospective and existing clients.
17
Feb. 15, 2022

No Magic Bullet

We all no there is no magic bullet when it comes to cybersecurity but that doesn't mean it has to be complicated either. I sit down with Eric Hanson of Inland Productivity Solutions to talk about Incident Management, Incident Response and many more plans, policies and programs that are often reduced to acronyms that get very confusing. One of the key things we talk about is getting to the root of the questions our clients, insurance companies and our client's clients are asking before we try to ...
16
Feb. 9, 2022

HIPAA Compliance And M&A

Each week we focus on cybersecurity and there is no shortage of topics. This week I sat down with Nelson Gomes of Medicus IT to discuss HIPAA compliance and Mergers and Acquisitions. As we onboard new clients or deal with clients who are going through M&A then you will definitely want to tune in. We talk about the need for Security Risk Assessments (SRA) and the risks associated with ingesting a new client.
15
Feb. 1, 2022

Drinking From A Fire Hose?

Over the past few weeks, Governance, Business Basics, and Vendor Sprawl have had one standard and constant theme... We all feel like we are drinking from a firehose. We all know we need to focus on governance, risk, and compliance, but we all suffer paralysis analysis. Chad Holstead of BKS and I had a great discussion about getting started with cybersecurity governance. We are all drinking from the firehose; as our conversation progresses, we quickly conclude that we are better together than alo...
14
Jan. 27, 2022

Tools with Intent

We have all implemented tools with the intent to solve or address all kinds of different challenges. After they have been implemented, are they working as expected? I sit down with Brian Weiss of ITECH Solutions to talk about just that. We covered a lot of ground regarding getting tools dialed in and where they need SOC services, and additional layers of security might require 3rd party resources. We also uncovered that not all clients make sense to onboard with today's threat landscape. Surpri...
13
Jan. 18, 2022

Back To Basics

We recently started a journey down a path that talks about Governance for SMB, picking the right tools/software to run your MSP, and of course, don't forget you can only pick just one... This week I had the opportunity to sit down with Jessica Millhiser of J Mills Consulting to talk about business fundamentals. Almost all of our episodes have focused on Cybersecurity, and I had an aha moment over the weekend; you can't have a security-first mindset if you don't have the fundamentals dialed in. I...
11
Jan. 11, 2022

New MSP Perspectives on Cybersecurity

We often take for granted the products and services we use to help reduce overhead and Full-Time Resources (FTE). I sit down with Ismael Amado of IT Ninjas to talk about starting a new MSP right before a pandemic and how important a security-first approach is. Just because the products and services you use aren't associated with cybersecurity doesn't mean they don't directly impact your cybersecurity maturity.
11
Jan. 5, 2022

Governance for SMB

Almost every time I do a security maturity assessment I find that companies are the least mature in Governance. The areas that seem to need the most attention are Policy and Compliance which is to be expected since that is the area we least like to focus on. In this episode, Sarah O'Kelley from onShore Security and I discuss the differences between governance and leadership and how cybersecurity plays into the leadership and health of an organization.
9
Dec. 28, 2021

Three Pillars of Cybersecurity

As we prepare for 2022 and the opportunities and challenges it is sure to bring I thought we should take a minute to focus on people. Consumers vs employees, two sides of the same coin, but very different parameters placed on how they interact with the digital world. Join me as I discuss People, Processes, and products, and services with a focus on people. This is a bonus episode as we wrap up the year. Thanks to Joshua Smith of Varonis for taking the time out of his busy schedule to share. I'd...
9
Dec. 21, 2021

What To Do About Log4j

I think everyone at this point has heard someone talk about Log4j. Even my 8th grader has heard about it as it was featured on CNN10. This week we are doing a special episode featuring Ryan Weeks, in-house CISO for Datto. This is an episode that every MSP should listen to as it focuses on what MSPs should be doing as it pertains to log4j. How an MSP can be proactive and reduce their threat surface and more importantly create a culture within their company to build out vulnerability management an...