Welcome to MSP 1337 - Cybersecurity Maturity Journey | Guidance and Best Practices for MSPs!

Episodes

18
April 25, 2023

A Doozie of a Story

Domain Registrations and an extra invoice that has a bit of sticker shock... This and more with Charles Love of ShowTech Solutions. We have talked about doom and gloom in the past but this story is one that I am already losing sleep over. I'd love to hear your thoughts on this one.
17
April 18, 2023

Fireside Chat - CIS Control 1 Hurdles

If you haven't met me, you know that my passion is to help others with improving their cybersecurity posture. In an effort to make a bigger impact, I have brought Matt Lee of Pax8 on to the show as a special guest to talk about the noise our MSP audience is dealing with. In this episode we talk about some of the challenges we have heard MSPs struggle with and we think this will help our friends and colleagues get past asset inventory in a meaningful way.
17
April 11, 2023

Suddenly Gone

We are all to familiar with our own mortality. In this episode we talk about the scenarios that can arise when a key person in a company holds all of the keys and is suddenly taken from us. While there is some morbidity to this episode and it helps us tell the story, it should make you pause and consider what if a key person in the organization is just un reachable? Have you done a tabletop exercise? You don't want to miss out as Sarah Goffman paints a pretty painful picture that I am sure all o...
16
April 4, 2023

Security Without Cybersecurity?

As a podcast we pride ourselves in the focus of cybersecurity topics. This is an episode focused on Cybersecurity without talking about cybersecurity. Crazy, I think Ian Richardson of Richardson and Richardson make it almost twenty minutes in before we really do talk about anything tech related. Risk anyone?
15
March 28, 2023

State of Cybersecurity

CompTIA's research team Seth Robinson and Carolyn April join me in discussing some interesting research trends that cover 4 pillars or steps that I like to refer to as the 4 Ps. Policy, Process, People, and Product. Be forewarned that much of the research is coming from the end-user perspective, but I think you will find the insights are very much important and relevant to the changes happening in our industry and the new opportunities presented as we go into the second quarter of 2023.
15
March 21, 2023

Protecting Friends and Family

Cybersecurity challenges exist in every aspect of our daily lives. Join me as I discuss with Dom Kirby of Pax8 an approach to cybersecurity with friends and family. Technology helps but it doesn't solve it all.
14
March 14, 2023

Explaining Cybersecurity to a 5th Grader

Ever wonder why your prospect or client gets a confused look on their face? You try to describe the new service offering or features that have been added to improve the security or efficiencies of their task force but they just don't seem to understand what you are trying to tell them. Join Charles Love, of ShowTech Solutions, and myself as we talk about some ways to change the approach to solutions that will be met with much less resistance and are much easier to understand.
13
March 7, 2023

Cybersecurity Maturity Without Technology?

If my organization has no technology can I still be secure? Matt Topper of Connectwise and I explore Cybersecurity with an approach that says you can prove a mature cybersecurity posture without technology. Technology is shiny and often can be a distraction from a focus on business functions and what we should be trying to protect. Stick around until the end as we may in fact find that technology is still a very important component of a mature cybersecurity-focused business.
12
Feb. 28, 2023

MSPs, Controls & Safeguard Capabilities

With Communities, Councils, and Forums just a few weeks away, I thought we should tee up the Unfiltered Fireside chat between Matt Lee of Pax8 and myself. In this precursor, you will hear our two different approaches to achieving the same outcome. There might be some references to, "The Yellow Brick Road," and maybe a reference to the children's game, "Chutes and Ladders." This is a fun banter between two friends that you don't want to miss. Enjoy!
11
Feb. 21, 2023

Social Media and Threat Landscape

We talk a lot about social engineering and its potential impact on our employees, our businesses, and even our family and friends. What we often fail to talk about is our responsibility to ensure that our employees, clients, family, and friends are educated about the dangers. What can we do to reduce risk without strict and aggressive tools that block or prevent staff from using social media? We all know they will likely still need to use email and despite our efforts, bad emails still get throu...
10
Feb. 14, 2023

Frameworks and Privacy Updates

We are beginning to see a pattern in frameworks updating or adding additional privacy controls. Whether they are long overdue or not is neither here nor there as they are now being stood up. From CCPA becoming CPRA, ISO 27001 adding new safeguards, and others all looking to improve privacy. I sit down with Sarah O'Kelley of Choice Cyber to discuss how data protection and en emphasis on privacy. Great discussion... Thank you Choice Cyber for the wonderful insights.
9
Feb. 7, 2023

Emergency Response Team (eRT) is What?

Have you ever dealt with a client, prospect, or perhaps an internal event that caused harm to your business or others? If so I am sure you can relate to feelings of shame, and embarrassment and I am sure many sleepless nights as you work to recover as quickly as possible. I sit down with Miles Jobgen of CompTIA and Robert Cioffi of Progressive Computing to talk through a real-world experience and how the CompTIA Emergency Response Team came to be. The Genesis of ensuring that a business doesn't ...
8
Jan. 31, 2023

Setting Expectations

There is some buzz circulating about the upcoming CompTIA Cybersecurity Trustmark, Compliance with frameworks, and how to get started as a solution provider. I sit down with Matt Lee of Pax8 to discuss the opportunities presented to Solution Providers who submit their organization to comply with a framework. Similarly, the new Trustmark from CompTIA while not a framework on it's own has taken on safeguards from multiple frameworks to give direction and a path toward cybersecurity maturity.
7
Jan. 17, 2023

Pig Butchering & Other Scams

I sit down with Kevin McDonald of Alvaka to talk about the three main scam types out there and what they look like. While we might not be able to prevent all threat actors from prevailing, we can make it more difficult and in many cases, our quick actions can reduce the likelihood of someone else falling victim to the same attack. If it is too good to be true then it probably is!
7
Jan. 3, 2023

2023 What can we expect?

Not to follow in everyone's footsteps on predictions... I waited to publish until January 3rd 2023. I had an opportunity to sit with Steve Alexander, Facilitator and founder of MSP-Ignite, to talk about his hope and predictions for MSP-Ignite members. I threw in a few of my own just to push some buttons but I think you will find some surprises in this episode. Please contact me if we missed something or if you have an idea for the next show topic!.
6
Dec. 27, 2022

Looking Back on 2022

Looking back on 2022 with Joshua Smith of Reliaquest and Charles Love of ShowTech Solutions on looking back on the highs and lows of 2022 and what we hope for in 2023.
6
Dec. 20, 2022

Policies and Controls, Compliance vs Security?

I brought Jim Harryman back to finish the conversation on policies and controls. We left out a few key pieces.
5
Dec. 13, 2022

Preparing for an Audit.

Whether you have decided to get prepared for an ISO, SOC2, or other audit can be a daunting task. Listen to the journey and all of it's ups and downs that Jim Harryman goes through to get a SOC2 certification and all of the different things done to prepare.
4
Dec. 6, 2022

The Aftermath

The impact of an incident is often unknown until we enter into the aftermath. How it happened can't always be answered but the goal post incident is to determine what can be done to prevent this in the future. How do we prepare to reduce the impact of a future event when we don't know in advance what that event might be? Join me as Chad Holstead and I revisit an all to recent event and how his team was able to piece together the events that led up to a user in the client company having their ide...
2
Nov. 29, 2022

Building Confidence

How do we create better relationships between vendors and solution providers? How do we get vendors to lean into their partner success? How do I build confidence in those relationships? This and more as I sit down with Kevin Lancaster of Channel Program.
1
Nov. 22, 2022

What About My Backups?

We spend a lot of time and energy to protect our businesses and our client's businesses from threat actors, natural disasters and even user error. I'm pretty sure we don't spend enough time focusing on the backups of the data that we are trying to protect. Join me as I sit down with W. Curtis Preston of Druva to discuss his passion around business continuity and backups. Be sure to listen for the URL thrown out to download a free ebook, "Modern Data Protection. (an O'Reilly publication)"