Welcome to MSP 1337 - Cybersecurity Maturity Journey | Guidance and Best Practices for MSPs!

Episodes

30
July 21, 2026

The Foundation Beneath Good Cybersecurity

In this episode of MSP 1337, episode 300, Chris Johnson sits down with Matt Lee for a candid fireside chat on one of the most misunderstood topics in business and cybersecurity: governance. Using relatable examples, from concrete truck deliveries to vacuuming a floor, Matt breaks down why governance isn't about policies, paperwork, or compliance checklists. It's about setting clear goals, assigning accountability, managing risk, and ensuring everyone works toward the same outcome. The conversati...
29
July 14, 2026

Cybersecurity Has A Noise Problem

Most organizations don't have a security tool problem, they have a signal-to-noise problem. Chris and Tatum Treadwell dive into the realities of securing decades-old technologies against modern attackers, the rise of AI-enhanced social engineering, and the growing challenge of alert fatigue. The conversation explores why education, human judgment, and meaningful action matter more than flashy marketing claims, offering MSPs a practical perspective on building resilience in an increasingly comple...
28
July 6, 2026

Your Phone is the Weakest Link

Everyone talks about email phishing, ransomware, and endpoint security, but one of the most dangerous attack vectors is sitting in your pocket. In this episode of MSP1337, Chris Johnson sits down with Mark Kreitzman of Efani to expose the growing threat of SIM swapping, mobile account takeovers, and the hidden security gaps traditional carriers have failed to solve. They explore why mobile numbers remain a critical trust anchor for banking, MFA, and identity verification, how carrier business mo...
27
June 30, 2026

Measuring What Matters in Cybersecurity Maturity

The cybersecurity industry loves to sell tools. What it rarely talks about is the hard work required to make those tools effective. In this episode, Jim Harryman joins Chris to challenge the idea that technology alone creates security. They discuss why mature organizations focus on governance, accountability, documentation, policies, review cycles, and operational discipline long before they look for the next shiny solution. If you've ever mistaken a technology purchase for progress, this conver...
26
June 23, 2026

Your Passport Isn’t the Problem, Your Security Habits Are

Planes, hotels, and conference stages aren’t what put you at risk, it’s what you bring with you. In this episode, Dawn Sizer of 3rd Element dives into the real reasons traveling professionals become easy targets: weak policies, poor communication, unsecured devices, and total blind spots around personal data exposure. From conditional access headaches to rideshare risks and AI policy chaos, this is a practical, no-excuses look at how security breaks down in the real world, and what you need to f...
25
June 16, 2026

From Reactive Security to Continuous Intelligence

This episode explores how cybersecurity is evolving from point-in-time assessments to continuous, intelligence-driven operations. Galina Kho of Cyberbay shares how predictive analytics, crowdsourced ethical hackers, and AI are reshaping how organizations understand and manage risk. We discuss how to scale security without adding headcount, why human expertise remains essential, and how governance and trust underpin effective security ecosystems. The result is a clearer model for modern cybersecu...
24
June 9, 2026

Taking Advantage of GTIA Resources for Lasting Business Impact

In this special episode of MSP 1337, CJ is joined by Brooke Lee (Rev.io) and Stacey Whitley (GTIA) to unpack how ITSPs can translate industry engagement into measurable outcomes. Attending events is easy, but most organizations struggle to turn what they learn into real operational outcomes. Brooke and Stacey share how their collaborative event recap initiative is helping bridge that gap by distilling key takeaways from major channel events into practical, accessible insights. More importantly,...
23
June 2, 2026

Simplifying Risk Assessments for Real Cybersecurity Impact

In this episode, Josh Hohbein of CentrexIT breaks down a practical, MSP-centric approach to risk assessments that moves beyond complex, consultant-driven reports and toward clear, actionable business outcomes. He shares how combining vulnerability scans, client interviews, and system configuration reviews, anchored in a cyber maturity model, helps MSPs translate technical findings into meaningful risk conversations, especially during onboarding. The discussion highlights the importance of owners...
22
May 26, 2026

Vulnpocalypse Isn’t Coming, It’s Already Breaking Your Patch Cycle

In this MSP1337 fireside chat, you and Matt Lee unpack the idea of a “vulnpocalypse”, a rapidly emerging reality in which AI-driven tools are accelerating vulnerability discovery at a pace organizations can't keep up with. While much of the industry is focused on the fear and hype, the conversation shifts to what actually matters: operational response. You highlight that the shrinking gap between proof of concept and active exploitation is forcing a fundamental change in how MSPs and organizatio...
21
May 19, 2026

Governance, Risk, Compliance (GRC), and the MSP Wake-up Call

In this episode, Chris Johnson sits down with Eric Shoemaker of Genius GRC to unpack one of the most misunderstood shifts in the MSP space: the move from tool-driven cybersecurity to standards-aligned governance, risk, and compliance programs. Eric explains why Genius GRC isn’t a software platform and why that distinction matters. Together, they explore how early automation wins (like continuous access reconciliations) impressed auditors but didn’t replace the need for real governance, document...
20
May 12, 2026

The New Reality for MSP Security Operations Center Services

In this episode of MSP1337, Chris Johnson is joined by Jeff Majka, founder of Security Bulldog, to unpack why MSP‑delivered SOC services are at a breaking point, and how AI and automation are forcing a reset. They explore why traditional tiered SOC models and white‑label thinking no longer scale, how ungoverned AI adoption collides with zero trust, and why speed and decision quality now matter more than raw data or CVE counts. From ticket overload and false positives to exploitability, continuou...
19
May 5, 2026

Guardrails, Drift, and Evidence: Cybersecurity Maturity is Continuous Improvements

Chris Johnson sits down with Ido Green of Espresso Labs to explore how AI and local agents can reduce cybersecurity noise, offload Level 1 work, and continuously enforce compliance, without losing human control. They discuss guardrails for safe automation, multi-vendor telemetry, drift detection, evidence collection at scale, and why “reporting gaps” isn’t enough if you can’t execute remediation and preserve proof. The episode closes with a roadmap for frameworks, partnerships, and insurance-rea...
18
April 28, 2026

Selling Cybersecurity to Skeptical Clients and Prospects

A sit-down with Hamid Ganadan, author of “Not Buying It: The Art of Selling to Scientists, Doctors, and Other Professional Skeptics,” on how MSPs can sell to skeptical, highly educated buyers. This is an exploration of the psychology of decision-making, shifting prospects from skepticism to curiosity, leading with feelings over facts, crafting insights that differentiate offerings, and timing data to validate rather than trigger doubt. Hamid shares practical scripts, a lead follow-up case study ...
17
April 21, 2026

Compliance is the floor, not the ceiling

In this episode of MSP 1337, Chris Johnson sits down with Jim Harryman to break down why passing audits doesn’t equal real security, and why MSPs get into trouble when frameworks turn into checklists. Drawing from firsthand experience with SOC 2 Type 2, CIS Controls, and the GTIA Cybersecurity Trustmark, Jim shares practical lessons on evidence quality, shared responsibility, inherited security, and the dangers of assumptions. They unpack why SOC 2 excels at governance but leaves technical gaps...
16
April 14, 2026

Cybersecurity Maturity Beyond Tools

Most MSPs don’t fail at cybersecurity because of missing tools; they stall because they miss the maturity inflection point where governance must replace tactics. In this episode, we break down what actually defines cybersecurity maturity, contrasting technical frameworks with governance-driven models that reflect real organizational behavior. Using the GTIA Cybersecurity Trustmark’s four-level maturity lens alongside Josh’s five-step cybersecurity maturity journey (built from cyber insurance an...
15
April 7, 2026

E&O, Cyber Insurance, and the Illusion of Risk Transfer for MSPs

In this episode, we unpack one of the most misunderstood topics in the MSP industry: insurance. From Errors & Omissions to cyber insurance, we break down what these policies actually cover, and more importantly, what they don’t. The conversation challenges the assumption that buying insurance equals risk transfer and explores how liability really plays out across MSPs, clients, and third‑party vendors. We discuss why cyber insurance typically protects only the insured entity, how E&O applies to...
14
March 31, 2026

Why Communication, Not Cybersecurity, Is the Real ITSP Problem

Clear communication is one of the most overlooked and most costly challenges in IT service providers. In this episode, Chris sits down with Amy Reczek, communication and presence expert, to unpack why misalignment happens between leadership, teams, and clients, and how understanding the “why” behind communication changes everything. From ineffective meetings and virtual body language to intent versus impact, this conversation dives into the human gaps that tools and systems can’t fix, and what I...
12
March 24, 2026

Installing or Configuring Is Just Not Enough

The critical importance of going beyond just getting technology to work, addressing the underlying security, scalability, and proper implementation, rather than just fixing symptoms. Eric Hansen, of Inland Productivity Solutions, emphasized the importance of starting troubleshooting at the very beginning, even when engineers claim they've already done everything. He discussed their hiring process, which prioritizes people skills and problem-solving abilities over technical expertise, using unsol...
11
March 17, 2026

GTIA On Location Interview: A Fishing Expedition and Cybersecurity Maturity

A real-world phishing incident. Real financial impact. Real lessons for MSPs. In this episode, we unpack a phishing attack that led to unauthorized access to an Azure subscription and significant financial loss for an MSP client. The conversation goes beyond the incident itself to examine where policy gaps, weak controls, and unclear ownership increased liability, and what changed when the MSP committed to cybersecurity maturity. Joined by Chad Holstead, we walk through how pursuing the GTIA C...
10
March 10, 2026

Suspended, Hacked, or Outbid - Cybersecurity and Marketing, Can They Co-exist?

Google Ads can disappear overnight, and for millions of businesses, it has. In this episode, John Horn of Stub Group breaks down the growing cybersecurity risks behind Google Ads account suspensions and why 39 million accounts were shut down in 2024. We explore Google’s automated, all‑or‑nothing enforcement model, how website vulnerabilities, phishing attacks, and account takeovers trigger suspensions, and why recovery is often harder than prevention. The conversation also dives into the impact...
9
March 3, 2026

Operational Maturity Meets Cybersecurity

Cybersecurity maturity isn’t earned in audits, it’s earned in the operational moments where governance either shows up… or it doesn’t. Today’s conversation with Mike Stewart of Anchor Networks goes deep on MSP maturity. How leadership tone, culture, and repeatable decision systems turn policies into actual behavior. We cover why security awareness must be frequent (not annual), why “the why” behind policies matters, and why AI is now a governance challenge as much as a technical one—especially ...
8
Feb. 24, 2026

AI Governance and the MSP Maturity Model

Managed Service Providers are being pushed to “get compliant fast.” In my discussion with Bruno Leqoc, we reframe the challenge. Compliance isn’t security, and lasting compliance depends on security maturity first. Highlighting how AI policy can extend existing governance frameworks, why Microsoft Secure Score is a practical readiness indicator, and why foundational controls (MFA, patching, device management/remote wipe) must come before certifications and GRC tooling. In this episode, we also e...
7
Feb. 17, 2026

Governing AI in a High Risk World

Exploring the fast-moving intersection of AI governance, ethics, and cybersecurity, examining how organizations are struggling to adopt AI responsibly while keeping pace with innovation. The conversation highlights a growing disconnect between enthusiasm for AI tools and the absence of clearly defined use cases, governance models, and security guardrails. As AI capabilities rapidly expand, Dr. Adeel Sheikh Mohammed emphasizes that organizations must move beyond checkbox compliance and adopt a s...
6
Feb. 10, 2026

Do Phishing Simulations Really Work?

Phishing simulations are one of the most debated tools in cybersecurity awareness, but do they actually work? In today’s episode, we’re joined by David Shipley, former soldier turned cybersecurity researcher and founder of Beauceron Security, to unpack what the data really says about phishing simulations, human behavior, and why zero clicks has never been, and will never be, the goal.