Skip to main content
Right of Boom
January 30, 2025

Beyond Asset Mgt – Why MSPs must take notice now!

In this video, Wes and Ryan discuss the complexities and critical importance of IT asset management, extending beyond traditional asset inventory to encompass aspects like third-party risk management and business impact assessments. They highlight how these foundational practices are essential for managing risks, enhancing cybersecurity resilience, and ensuring business continuity. Throughout the discussion, they emphasize the significance of proactive roles in MSPs, encouraging viewers to integrate these practices into their services for better risk management and customer trust.<ul><li>IT Asset Management (ITAM) is critical for MSPs because it goes beyond just managing physical assets; it involves understanding third-party vendors and their vulnerabilities, making it complex but essential for security.</li><li>Business Impact Analysis (BIA) is vital for MSPs as it helps prioritize recovery processes during incidents and ensures that business-critical functions are restored in the right order.</li><li>MSPs must rethink their service offerings to focus on proactive roles and processes, integrating advanced security measures and ensuring comprehensive asset inventory management to improve resilience and risk management.</li></ul>

Guests

Andrew Morgan

Video Transcript

Here we are. Most Important podcast there is. Welcome everybody. Little back talk. Uh, how's everybody's Weekend? Father's Day. Welcome to Cyber Call, uh, 54. Uh, we are at, uh, just barely at knock on the door there, folks at 2,900 that have attended or been in the community. Uh, thanks again for all the support. Um, today we are gonna be looking a little beyond asset management and uh, we'll talk about that. Um, real quick, some uh, uh, announcements up top. I put 'em in there.

Um, when I ask Wes a question, um, I'm gonna be do a little a touch of typing. Got a poll or two to put up. But, um, uh, let's see. Gary, quick question. How are we doing on registrations? A lot of people, uh, coming in looking at the security content and uh, yeah, Absolutely. If anyone's done it and, uh, talk with my team and has any feedback, let us know. But, uh, yeah, registrations are are cruising, so, um, I'm happy we're helping people. Awesome. Fantastic.

Okay, so Wes, I know you are at IT Nation Secure. Um, I know you're limited on time, you're in your hotel room. For those of you all out there that are wondering, gosh, Wes, you, your, your Hue is so different. Uh, Wes, uh, give us a little sense of what's going on and we'll get into the first question.

'cause I know you only have a limited amount of time with us, So I, I have my nice camera back there, but in typical MacBook Pro fashion, uh, there's no USB port and guess who forgot his, uh, USB adapter to Thunderbolt this guy. So we're, uh, on old school because, uh, thank you Apple and thank you my memory. Uh, but yeah, we're here at IT Nation, uh, in Orlando and it's gonna be super fun.

Uh, I, I already see some, I've seen some people here, Matt Lee, I was talking to Tim Fornet, uh, Carl Bickmore, a bunch of people that are already here that I've, I've seen and said hey to. So super awesome. Awesome. Okay, so let's get right on into it. Wes, let us know if you do get a little bit of extra time if he doesn't. Ryan, I'm gonna ask you a few additional questions and you too, Gary.

So, uh, um, so Wes, um, in terms of IT asset management, or just let me take, you know, we think a, it a m right? IT asset management, we think RMM and, you know, I mean, I think that's kind of been ubiquitous of what MSPs do and think about when managing not only their own environments, but their customers.

Can you give us kind of a, like a high level overview of, you know, why it goes a lot beyond that and you know, why it's such a critical security control, something that seemingly is a little bit boring, but it affects everything? Yeah. Help us, Wes. 'cause last episode, we got our assets handed to us. Oh. Oh, I can't abide by these dad jokes. Gary. It's Happy Father's Day is, uh, already. Come on now. Uh, yeah, so it, it's vitally important.

It, we know this, we know that like it's one of the most foundational and yes, boring concepts that's out there, IT asset management. And it's one of those things that we think we have at mastered until we don't. Oh, yeah, Tim, I see that too. We just hit 2,900, so we are a hundred away from 3000, which is super cool. Whoever person number 2,900 is, thank you for joining the cyber call with us. Uh, so, you know, it's a nuanced thing. It's like the zen of security.

The more you get into asset management, the more you realize you don't really have grips on it. Let me give you an example of this, Ryan, you hinted at this last week and I thought it was really good. You were talking about how when you're talking about third party risk management and some big thing comes out, which of your vendors are susceptible to it and which of their vendors are susceptible to it? And how do we know and what's a remediation process and what's even in place?

And just one example of like, IT asset management is not just like what's in your physical building, it's not just what's in the cloud. It's not just what's in your client's networks. It's in what's, you know, the the third party vendors you use and your clients use.

And so I would go so far as to say, Andrew, that I think IT asset management is harder for MSPs than any other industry I can think of because of the nature of, um, not just third party, uh, requirements, but also the nature of all the industries that you serve as an MSP and the, the tool sprawl that's out there. It's colossally difficult.

And the other thing I'll say as well, Andrew, is federal government's picking up on this, you know, going back to the, the executive order from President Biden, you see the same thing in the xo. You see them talk about, you know, the software bill of materials and whatever that's gonna look like, right? But you know, what goes into how SDLC processes work and what, what we use inside, it's, it's not just an RMM scan, like a vulnerability scan and an RMM uh, patching cycle. And off we go.

It's so much more nuanced than that. And honestly, Andrew, if breaches don't happen from this, breaches get worse because of this. At a minimum. What I mean by that is maybe it's a phishing attack to let someone in the network, but from there, once they have a foothold to find something that you had no idea was running in there, um, is is the, the chances of that just skyrocket and make it much more difficult. So yeah, Andrew, it's such a difficult thing for us in it. Yeah. Awesome, Wes.

Um, so let's talk about business impact analysis first, if you could just sort describe what it is, you'll hear the term BIA, not everybody that's an MSP has even done one or even knows about them. It's not uncommon, by the way, if you don't, I'll also quickly search. Wes, you did you put together a quick business impact analysis, a spreadsheet of how MSPs can approach this?

Talk to us also about, you know, once, once they get a definition of, of that, you know, why, for example, you need more than just your hardware and software. You know, talk about data, data flow diagrams and things of that nature. Yeah, sure. So, so bis a few things about that. Uh, we did produce a a, an example one that, that I kind of curated. It's, it should be in cyber nation. Uh, when Mike Ard and I did our incident response stuff with through methods, uh, we, we produced one there.

So you should be able to go and find it. So the reason these are important, I first got exposed to these in banks, and lemme just tell you the lesson I learned going through this at a bank. So my examiners were like, Hey, you know, one of the things we'd like for you to, to work towards and they produce guidance around all of this is inside of your incident response processes. We want to know, we wanna see a BIA and we wanna see what this whole thing looks like.

And so, um, we had one and I dusted it off the shelf and took a look at it. I'm like, well, this thing is like woefully old. And what it describes is not just the analysis of business impacts you like that, uh, but it really gives us a guidepost in the middle of recovery. Whether it's a small, you know, I lost a branch or it's a systemic outage from a buffalo jump attack or a fire, or in our world, a, a a, you know, a hurricane. I was thinking the word.

Um, it doesn't matter what the event is when the big event happens and we have a major declared disaster, what comes first? What comes second? What comes third? And what are, how do we know that those things come first, second, and third? The last people that should make that call oftentimes are the IT guys there. I said it, the people that should be making that are the business owners that understand the processes. Let me give you an example of this.

So we were going through our BIA and I started querying, um, subject matter ex experts in our, in, in our bank. And we were looking at lending systems, for example. And so I start firing out all these questions and I get back an answer from our operations manager that handles all of the backend operational stuff. And she gave me a whole list of like, look, this is like from a regulatory perspective, we must do this reporting at this time in this. Like there's no option.

We have to produce this out to our regulators or, you know, customer notifications, especially in terms of things like mortgage processes and things like that. She's like, I don't care if there's a fire, I don't care if there's some hack of some kind. None of that matters. I must do this event at this point in time. And I'm like, boom, I'm so glad somebody told me these things. I had no idea as the IT guy. Like no clue at all that this was how all this works.

And so I say that to say part of the BIA, there's a lot that goes into it, but part of it is giving you an understanding of what's priority and, and how do I know what must be recovered, what prerequisites are in place, uh, what kinds of like resources are required, uh, whether it's cloud on-prem, it's people that are required, whatever. It really gives us this mapping of what it takes to do recovery, Andrew.

And um, it's such an eye-opening experience that's a lot of micromanagement to really get the first BIA created. But then what's it's in place, the updates there in are much, much easier. Um, and I will tell you, maybe the last thing I can think of is like MSPs that work with a lot of, like banks and others that expect bs man y you, you'll keep them forever. When you start doing exercises like that with them, they're gonna be like, wow, this MSP understands me.

I would never go to a competitor because they make my life really, really nice. Yeah. Wes, you, you kind of went into the next question, which was great for truncating your time, but, uh, I was asking about real world examples, but if you're an MSP, you know, you as a practitioner can pull that right outta your, outta your head and go, Hey, here's, here's how we used it. Here's a real world example.

Have you been in any conversations or when you did tabletop exercises as an example, uh, with, you know, like Bogar Mike, beard Marco where you know it actually it came up and, and, and or how could you help an MSP curate that conversation? There's Mike. Yeah, we should bring Mike on to talk about Mike. I dunno if you can join where you're at. I know he's here in Orlando too, but if we can bring, yeah, let's bring him up if we can. But while we're waiting on that, um, so here's my thoughts.

I don't run into a ton of partners, uh, that, that have really gone deep down the, like the BIA trail for example. I think a lot of us are still, and you saw this in the survey results last week, remember Andrew, we asked some survey questions around, you know, where the IR everyone's at in the IR world. And I would say we're still in a maturing pathway into this. We still have a long way to go.

Uh, and so you should still be focusing on, you know, a rock solid airtight, um, IR program at your MSP before you jump into A BIA. Not to say it's not important, but you know, first things first in this world. And so I think where most of us are still there and the challenges that you're gonna have around A BIA is outside of regulated industries, you're gonna run into a lot of 'em that are gonna be like, I'm not spending time on that. You're my IT guy. Go away. I just want things to work.

Go away. Um, banks, healthcare, totally different. So there are ways you can reverse engineer A BIA without like making the end user feel like you're forcing 'em to go through some exercise they don't understand.

Um, I would, you know, in my QBR I'd be like, Hey, we've been thinking a lot at our MSP about, you know, disasters and you know, if there were a big disaster, name your big disaster area, earthquake, flood, fire, whatever, it's a cyber attack and say, you know, do you guys have any idea, like from a restoration perspective, you know, what systems we need to recover first, second, and third? And what's most critical to you both from a revenue perspective?

You know, you gotta be a Stu Chris Laer says this, you gotta be a student of your clients. You gotta know enough about them to know are there regulatory requirements? Are there, you know, business operation requirements that you're aware or not aware of, or you've gotta know these things.

And so ask them these questions that can be, are really try to siphon out from them what it is that they say so that you can go back and say, holy cow, they said this system is like the most important system that they use. And I haven't touched that thing in a year. I don't know anything about it. And you know, Microsoft 365 has blown away, but they're like, yeah, you know, I could deal without email for a week. It would really hurt us, but we could be okay without it.

But this system over here, like our CNC machine that actually builds the things that we sell, that's critical. You know, we got enough backlog of a month of work, we'd be okay. You know, you gotta have these conversations to really understand it. And so you can actually turn it into a business driven conversation that makes 'em think, I can't believe I've got my IT provider asking me questions like this. This is really good.

Um, without telling, well, we're doing a BIA and we need your suggestions. Full spreadsheet for a while. You know, you, you can, you can really do some work there. Yeah. Excellent. Gary, did you have, did you have anything yet or No, I'm just, I I'll just say simply everything that West just said about your customers, same for your prospects. You sit in front of a prospect and say, Hey listen, your current provider, um, when the last time you did a review, how often do you review of your bis?

Right, right. What do you mean? Well, did they have a conversation about this? Like, you know, you start to talk about data, you know, uh, data flow. You start to, you know, ask him questions about how long they, you know, if you were, what are your critical, like how long if you were without this, what would it mean to your business?

And just in those few things, that conversation that he just had with a, with a customer of an SP turn those into questions with the prospect and you're creating separation in 20 minutes. Yeah. Yeah. Great job Wes. So Wes, um, me talk to us in, in, in your last question here, we, we, we might have knocked this out for you in just perfect amount of time, everybody give everybody 15 minutes of their life back on the on for the first time on the Cy cy call, Gary.

But um, Do you have a GoPro you can put on so we can go with you? That's awesome. Yes, Actually let's do that. So like, how might you know this enable our ability to do something, you know, just kind of simple in terms of like a ransomware, um, you know, assessment, impact assessment.

And by the way, is that, is that something different than a full-blown tabletop or can you kind of truncate those things and say, you know, it's almost like a combination of, uh, you know, co a conversation around resiliency. Like, okay, let's talk about you have been breached, or, you know, how do, how can they maybe pull that together in that, in a truncated version? Less So? I'm assuming you're talking about like from in the conversations with the client, right? Right.

And so, you know, let me tie this back. I remember the very first time LA and I did a tabletop, it was at an IT nation event like two and a half, three years ago, something like that. And I expected it to be a really eye-opening event, but I didn't expect it to be like what it was. I mean, people, I mean, you could just see if I could say it, a hint of panic in people's eyes of just how unprepared they actually were.

And part of that is because we hear these ransomware stories and we went from thinking, ah, 10 K to pay a ransom on one machine to oh yeah, ransom everywhere could be expensive, but we don't really anticipate the full impact of having all of our systems offline. For example, one simple example, like I think people existentially get this, but it's not until you practice it in theory or see it in real life of my RMM is gone.

Like, how am I even supposed to connect to all of my clients that are everywhere? Like, how am I even supposed to like begin recovery processes when I can't even connect to a single client of mine? Am I gonna roll trucks to every single one of 'em? Oh my God, I think I have to, like, these are things that like, just, that's one example of like these horror stories of what it really takes to be offline. And so I say that to say we, we need to educate our clients on the same thing.

You know, like my old colleague and good friend David Powell is always saying things like, you know, um, they don't care until they care and they think it's too expensive. And I think all these things, right? But the reality is when you get them to understand the impact of what a, a ransomware event actually does, completely knocking off all ability to make revenue for a day, a week, a month, that's significant, right? And they don't think in those terms.

They just think ransomware shuts a machine down and pay a ransom. That's as far as they go. So it's our job to walk them through what these things look like so they can really understand. Yep. That, wow, I'd never thought of that before. We are, we do need to talk about how we quickly recover and how we get back to resiliency is is Ryan, you're always talking about.

So, um, Andrew, that's, that's the guidepost is just as you as an MSP, we're shocked by that in your, in you walking through incident response as you're maturing down your security journey, it's now your job to take that story to them and help them do the same thing. Got it. So Wes, I appreciate you jumping on. Um, I'd love to ask you a few more questions I wish you could stay with and stay with as long as you can do a GoPro.

I think that's, I May go, yeah, I may go into client mode and just listen on my phone. Okay. Fantastic. But thank you guys for having me so much. Have a great event and, uh, excellent. Thanks.

So Ryan on Wes, so Ryan, um, you and I were kind of talking in preparation for this and I, I love the way, you know, I'm, I'm excited about, you know, you kind of bringing all of this together for the MSPs and just how this, I know you used the term spider web, which I'm gonna bring up, but I, I thought one of the interesting thing was, um, if you could just kind of walk through, like you were, you were talking about, you know, the, uh, exchange, um, situation.

But, and I know I'm kind of going off on tangent here, but I was just fascinated how you're like, like look, look beyond how just its assets, look at vendors vulnerabilities, third party, fourth party. Can you kind of like you, like I said, you use that term spider web. I was just wondering if you can kind of articulate that for everybody. Yeah, I mean the, the place I'll start is again, we can go back to CIS go back to the CSF, go back to any security framework. Step one is always inventories.

And everybody looks at that and they roll their eyes and they're like, Ugh, that's a lot of work for very little benefit. I already know enough. Why don't I just get started with the things I know. And, um, you know, as, as, as you know, I've probably said before on the cyber call, I, I'm allergic to a false sense of safety. And so to me, you don't do anything until you understand what you're trying to protect.

And, you know, as we were talking about preparing for this, I was like, we need to stop having the conversation around like the standard conversation around IT asset management. And we need to make it really real for people. We need to talk through cases where it asset management really helps you manage risk and be more resilient.

And that's where BIS come in, because how do you really do a business impact assessment if you don't really understand the systems that are involved in the delivery of a service that you're providing or that your customers are providing and you're helping them, uh, to secure. Um, and so, you know, I used Exchange as an example, right?

And I continue to be, uh, honestly deep deeply perturbed by the fact that not a single MSP asked me Datto, uh, whether or not we used exchange, whether or not we were compromised, how we knew if we were or were not compromised, um, not a single one. And, uh, you know, we, uh, I had my team put out a, you know, put out a blog article about like, there's a very real problem with lack of third party risk management and IT channel.

Um, and you know, going back to Microsoft Exchange, let's make it very real for you. How before the Microsoft exchange of vulnerability occurred, how many of you knew for sure you were certain, given the strength of your asset management and inventories that none of your customers had exchange running in their environment? And a lot of you'd be like, well, I knew 'cause there were no exchange servers in RMM.

How do you know there wasn't an exchange server running on a Dell computer in the corner, right? How, how do you know? Right? There's a framework I use, um, with, uh, whenever I'm trying to help someone build a capability, it's a very simple framework. Tell me what, you know, tell me how you know it and then prove it to me. What do you know? How do you know it? Prove it, right?

The three, it's, um, and, uh, and with Microsoft Exchange, uh, you know, we, we knew where we had exchange and because we were monitoring for vulnerabilities, because we have an inventory of the software that we run, we can feed that list into our vulnerability management program and we can determine, oh, look, here's a really critical vulnerability that just came out with a piece of software that's used in our environment. How is, how is this vulnerability exploited? Okay?

And then let's map that onto our understanding of that asset, that software asset in our environment, right? And when you think about Microsoft Exchange, that that really should show up twice in your inventorying activities. It should show up once as exchange, which is a piece of software that you run, which has a version and it probably has an owner and it probably has a set of systems that it runs on. But then you have Microsoft, Microsoft is a vendor that should be in your vendor inventory.

And when you're, you know, and, and this is where I kind of spidered out in a conversation with Andrew, like, and the vendor inventory is really important because when I monitor for risk to da, I'm, I'm have it plugged into my vulnerability management and threat intelligence programs. Tell me whenever there is something targeting a, a vendor that I use, uh, or a vulnerability or some, some, some breach related information.

And so Exchange came up and I'm like, okay, well I, I know that I have Microsoft as a vendor for me. Um, I need to know who, who in my tier one, like we, we have a tiering system for our vendors who, of my tier one vendors, which are the people that, um, have access to certain systems or that provide, um, staff in privilege roles or that have, uh, software that we use as, as part of, you know, a critical part of our business.

Um, I need to go out to all of those tier ones and I need to understand their risk exposure to this vulnerability. Um, and, and we did that, and we did that within 24 to 48 hours of it being dropped. And, um, you know, and then, and then we, we have automatic monitoring set up for these vendors and, but I couldn't have, Brian, you, You would consider for an MSP, the r their RMM vendor would be tier one, just so I'm clear. Well, you would consider tier one, right?

But yeah, there's a lot more than just your RMM in tier one, right? It's tier one is really the level of any vendor that if they were compromised, would very likely, uh, cause your business harm, potential loss of customers, uh, or lead to some sort of, uh, you needing to provide, um, your customer's notice that there's been a data breach, right? And that they might have some regulatory requirements around notifying their customers, right?

Because at the end of the day, while, while, you know, most MSPs are thinking, Datto is our third party risk, we're fourth party to your customers. And so all of this stuff is really super connected. And like, I can't build that vulnerability management program. I can't build that threat informed monitoring program. I, I, I can't secure my assets, uh, against these exploits. I don't have these inventories. Like the inventories is the foundation to everything we do and the processes we build.

It doesn't matter if I have the process and I have the technology, if I don't have the inventory, the inventory is the, is the, the data that is the foundation of the decision that I make in every process I have. So I, and I'll, I'll end with this, and Gil, you asked me another question, but, um, I told you, like I, I've hired, I've hired some amazing experts, right? We just, we just hired a guy for business continuity and disaster recovery came from KPMG, did back office BCDR for KPMG.

I hired a guy from MIT Lincoln Labs, did third party risk management. The first thing I have each of them doing is inventories. And, and like when I interviewed them, I'm like, just so you're clear, you're, you're fine with the first three months of your employment being working on inventories, right? And they all said yes. And I said, and I was like, cool, what? Why are you so willing to do that? And they're like, 'cause it's a waste of my time.

If I'm not operating on the right, I'm not actually helping you manage risk if I don't have the right inputs, right? So yeah, you have RMM and you're deploying it and it's patching and it's config managing and it's deploying antivirus and all these things. But what good does that do you, if it's only doing it on 70% of the assets that it should also, by the way you do that inventory, that's a lot more seats or assets that you could potentially be managing, that's a revenue for you, right?

And so, like, you know, I don't, I know this is where I probably wanna hand it off to Gary later to talk about like, the value of these things in terms of the sales process, but to me, you, you just, you can't secure your environment or your customers if you don't understand the software, the suppliers, the hardware that, like, just all of it, it's all interconnected and you're not gonna become resilient if you don't have those foundational data points.

And so it's not about having a process that you can show an auditor that says, yes, I know every machine that's connected to my network here. I check the box for asset management. It's really about, you can't really do risk management if you don't know these things. And that's why it's the first thing in every framework. Yeah. So one of the things, Andrew, real world, when people deploy my IT process, right? And they're gonna do standards.

One of the things we suggest in Build In is like, it's a, it's a centralized services review. So they're actually going, because, you know, they're adding customers, they have 40 customers, and from a central location, they get new customers, they deploy things. And you know, day one, usually they, they, they got it pretty covered.

And you know, on average the feedback I get is the first time they go through it, they realize that, you know, there's anywhere from 10 to 15% undiscover things that they didn't know about.

So it just goes back to, in the real world, what Ryan was saying, it's like, well, okay, you're doing, you know, you're, you're looking at all these advanced, you know, uh, endpoint features, but if you just had virus protection and it was on everything you probably, that would get you further ahead than having some advanced toll that you have on 75 or 85% of what you have. Gary, just for clarity for everybody out there, could you just explain what you mean by centralized services?

I know if you're a true methods member and you've been with you for a while, you know what that means, but could you just Clarify? Yeah. So that would be like your stack. So the things that, the tools that you're managing centrally across your entire customer base is your centralized services. And it's just like everything else with an MSP, like, you know, you set up your backup and disaster recovery. Every one of them works the day you install it.

Every firewall is secure, hopefully, uh, the day, you know, when you walk out the door after you install it. But everything changes. And that's the same thing with managing assets. Hopefully you have a good process when you start off, but I gotta tell you, if you don't have some way of auditing that on a regular basis, six months later, you have six months old data. Gary, you made me think of something, Ryan, on a, a quick audible here.

Uh, and maybe for both of you, Ryan, to you first 'cause of business continuity, uh, it's obviously a big product line for you guys. You know, Chris Lair talks about situations where, you know, comp MSPs don't have in place a process to look at, you know, data growth or data sprawl. You know, they might get A-A-B-D-R for that handles I'm, you know, give you a visual, this much data, right? Whatever that is. X terabytes, a ransom happens.

But they weren't keeping up with it and they realized that the vaulting wasn't, you know, happening correctly 'cause it was exceeding the amount of data they could hold, et cetera, et cetera. Chris ran into the very real problem, and it was Gary in your term, they were trying to suck peanut butter through a straw, and literally it was impossible. They could not restore.

So, I know I'm digressing, but I think there's a really interesting kind of segue, I hope people think it's an interesting segue. 'cause again, it's, I don't, I don't know how many people are doing that and because again, it's data flow, it's growth, data growth, et cetera. So what are your thoughts there, Ryan, on that? And Gary, I, I'm not even sure if there was a question in there, but, um, like How to do it Yeah. You know, should MSPs be doing it? A and how should they be doing it?

And Gary, then maybe from your perspective, role and process perspective. Yeah, I think, like in my mind there's a, there's a maturity scale for these types of things. And, and oftentimes we, we get consumed by what good looks like and where we are relative to good. And it's so far away that we couldn't possibly even spend time on that right now because it's so daunting.

And that's why, you know, the end is every cyber call, the thing I say when Andrew says, Ryan, any parting words, I'm like, just get started. Just do something right? In this world with MSPs, you know, you're potentially leaving revenue on the table by not doing this stuff and doing it consistently with your customers. So that should be motivation one. But like, you wanna stay in business, you wanna know that if you have a security incident that you're ready to respond, right?

Um, I can't remember, um, I was on a call with a CISO that was giving another group of CISOs a readout of a ransomware attack that they experience, and he said, um, you know, one of the things we did is we deployed CrowdStrike to every single server in the environment. And I asked him, how did you know every single server in the environment in order to deploy CrowdStrike to, right? And he's like, yeah, no, you're right.

Our asset inventory was only about 90%, and it caused us days of delay because we were finding other systems that the attacker was resident on that we didn't have the tools on because it wasn't part of our inventory in our automated deployment. And, and so like, you know, we talk about these things like, like, like, okay, I've done the inventory, I'm done. It's a continuous care and feeding process.

And with the data flows, I mean, you and I went down a whole different rabbit hole with, with the data flows. I mean, Andrew and I spent like an hour and a half Friday night just shooting the s**t on this. And it was, it was fun. Um, but with data flows, you can't build a data flow diagram if you don't understand the systems you have, the data you have and how it moves through your systems. This goes back to we all Have a different idea of fun.

I'm just saying, Well, yeah, you know, um, I, I love talking about this stuff. I'll talk about it anytime of day or night. Um, but you know, again, you know, the MSPs I've talked to, I'm like, talk to me about the solutions you use to, you know, to facilitate your business. And they, they create an inventory. And then I'm saying, okay, how do you capture leads? How do you send leads? How does this piece of information, does anything consume information out of this software?

Does it go anywhere else? And by the end of an hour interview, the, their data flow diagram has quadrupled in size and like, and that all goes back to asset inventory. Oh yeah, no, we forgot that we have that asset and that that's a thing. I'm like, okay, so that's an asset that should be over here in your SaaS vendor inventory. Is that vendor on your third party inventory? Oh no, we forgot to put that vendor there.

Okay, so that's a vendor, you know, where do we, how do we classify that vendor? And so as we do these, what we call cyber resilience exercises with MSPs, they leave these two day exercises with what we actually help them tier their vendors, create their software list, create their, like, I can't even begin to help you until I understand your assets. That's how serious I'm about this stuff.

When I said I'm gonna go in and help MSPs figure out how to secure themselves, I start with inventories because I can't even build the data flow diagram without the inventory. Gary, um, I'm gonna jump to one of your questions because I think it's applicable here. But like, are MSPs gonna have to rethink their stack?

And what I mean by that is, you know, we, we, as you know, yes, you, you've got some of the top MSPs that are in the, you know, 200 and higher, you know, we, we know that's happening. But with the elasticity of a budget, right?

Let's just say we can only get so much, are are our MSPs gonna have to rethink, like, I've got all these things in my protective, you know, controls, you know, just pull up a Sunil use, uh, the cyber defense matrix and you know, you just plot everything and it's almost all of it's in protectable, right? Very little detective, hardly anything respond, recover. Are are, are we gonna have to, as an industry rethink where we're, you know, knowing we need to look at resiliency?

Are we gonna have to rejigger some of this stuff? A a hundred percent part of it is just by what Ryan is saying. I see. You know, we do, um, we have a tools matrix now in our, in our benchmarking. So I see the number of tools and a category of tools across a hundred, you know, almost 200 now, uh, uh, MSPs every quarter.

And you know, how they, how effective is it when most of 'em haven't built in the rolled process and, and the pricing to their customers, uh, to do the things that Ryan's talking about. So now the tools aren't effective, uh, and the technology's not effective if they don't have command over that, they know that, um, everything is, is covered. Um, then once you get those tools, you're obliged to run 'em. You have to do it, you have to have those costs.

So how do you go ahead and set up to do the things that are right of boom? 'cause a lot of, it's a lot less tools oriented. It's a lot more of, of how we started this call with, um, you know, with Wes and this right here that we're talking about and the conversation, the way you hear Wes and Ryan talking today is exactly the separation that I am seeing happen in our industry. People that are moving to understand it and how to explain the value to customers and prospects.

Um, the, their, you know, their problem is just execution. Now, they, they're gonna add customers and they're gonna make money. And those that aren't are really stuck, Andrew. Yeah, that make sense? Yeah, no, it does. It does. It just makes me think that, you know, again, if you think the errors of cybersecurity, again, which Sunil talks about, right? Identifies the eighties, protect is the nineties detect is the year two thousands.

Like we're, we're, we're really stuck back and, and building our tools. And, and I'm gonna put up this before we're done today. I took this segment of a interview, Ryan did I I call it 53 seconds that every MSP should share with their prospects and their customers that Ryan did. But he basically talks about that youi either are breached and don't know it, or you're gonna be imminently breached.

And how you need to look at not your cyber program as I think historically, and I'm paraphrasing line here, we all look at our cybersecurity as protective. You know, put in this, put in this, put in this, it'll protect, protect, protect. When we have to now start, and I know we've been pounding this on the cyber call, so I apologize, but your, your end clients, I think you get a lot of value.

A little quick video where we gotta start thinking of we are breached, which then comes back to the whole inventory thing. So what things do we need to put the most controls the most resiliency around to have a minimal impact to you and your customers? So Listen, people, we're not gonna get there with tools and tickets, you know, and look, even looking, I'll say this, um, present company included. 'cause Ryan works for a company that has a PSA as.

Now, do I, um, you know, people are running on PSAs right now that were designed for a business that was 15 years ago, dude, right? And so everything is focused on time entries and like, come on man, you, you get on, you listen to what we're talking about on the cyber call. We gotta change our priorities. You gotta change the conversations with employees and customers and prospects. Uh, we have to have a business model, an economic model that allows us to do that.

You know, you heard me before, back when we were on the road that I used to ask people how many people have at least one role that's completely proactive. I can't wait pretty soon to get back on the road and after everything that's happened, I can't wait to get a couple hundred people in the room and ask the same question again to see if I get a different answer this time. Um, spoiler alert, I'm not optimistic. You gonna ask 'em if they have know if their clients have cyber insurance too?

I am, I am gonna also ask them that. Alright. All right, so let's get back. And then Now, because of Ryan, I'm gonna go next. I'm gonna go into their asset inventory, Okay, Ryan, um, maybe talk, I'll combine these two. Um, I would gather, and again, I'm not here here to chastise anybody, most MSPs don't know what open source solutions are in their stack. And especially when we get into security, there's a lot of 'em.

So if you could talk, maybe talk that first and then kind of maybe just combine it into the executive order about bill of material and why is that gonna be actually a really helpful if that did happen? Yeah, so I think for, yeah, we, we can talk about, um, open source in, in kind of two ways. One is like the traditional, like very engineering centric idea of what open source is. And then we can also talk about it in like the shadow IT context.

Um, and I think for MSPs it's probably more important in the shadow IT context because I think very rarely are you doing things where you are leveraging open source technology. Um, however, if you're using a vendor, um, like Datto, uh, we use a lot of open source technology to deliver our products. And so does Kase, right? RapidFire tools comes to mind. There's a, there's a open source piece of software under the hood of that thing, right?

And so open source one, you wanna understand what software people are installing on their assets, again, assuming they have administrative privileges and the rights to do that, which most people have. Um, unfortunately. So you can't manage your software risk if you don't understand open source because it's a large, um, contender for, um, shadow IT. And, and that creates software risk and inventory risk around that, right? Um, but from a vendor perspective, right?

One of the things that, that kind of came to light is, you know, I had to, I had to reach out to all my vendors and say, do you have Microsoft Exchange? Do you, do you run this for your business? Um, and there's this idea that came out, um, really as a result of this, of Solar Storm, um, and getting a better handle on the supply chain for government, which is the call for anyone that provides software to the government to include an sbo MA, uh, uh, a software bill of materials.

And really what this is, is it's a structured blob that I can pull from any vendor for any of their software that tells me it's basically the recipe card for their software, all the ingredients that go into it, and the version of all of those, uh, ingredients. Um, and what I can then do is I can pull that blob, I can store that, I can process that, and now I can start monitoring for vulnerabilities in the software that my supply chain has.

And so instead of needing to ask people and chase them for responses and hope I, you know, hope I've cataloged all their responses correctly, I can automate that assessment. And that's really huge. And so I, you know, I've referred to what's happening in the Ms P space this year with the supply chain breaches is a crisis of confidence.

Um, and, and frankly, you should be, you should, you should be losing some confidence in your vendors because a lot of vendors out there are not doing the right things when it comes to security and not has been made painfully clear, right? And so, I, I'm not saying you shouldn't be worried, you absolutely should be worried, but as vendors, we need to figure out how we're going to regain your competence.

And so I think this, this trans this level of transparency that's gonna come with these software bill of materials is gonna be huge. 'cause it's gonna let MSPs start to really understand the risk that a, a new vendor product might introduce into their environment. 'cause it's not just gonna be a new proprietary thing that I pay for and a new vendor that I have to yell at. It's gonna be that plus I'm gonna have some control and some understanding over what risk that's actually presenting to me.

And oh, by the way, I can now leverage that information in my pre-acquisition diligence of that vendor. Why am I gonna pull in a vendor that's not using the latest, most secure components that doesn't update their upstream open source libraries? Um, you know, and people will probably point to me and be like, Hey, you were a month late. I'm delivering 2004 for the BCR fleet. And I'm like, cool. Yeah, you're right, egg on my face.

But yo, that project took 12 months and like, it was really complicated and like we were working on it for a year beforehand, right? But like you found out about that after the fact. Wouldn't it be cool if when you were buying it, you were like, Hey, your BCDR uh, devices that you're selling are still running 1604 tu that was end of support in April. What's going on? Um, we'll be like, yeah, you know, we, we were, we're we're running some extra QA diligence. We ran into a couple things.

We fixed 'em, it's gonna take an extra month to roll out, right? That's the type of question and conversation you wanna have during your diligence process. Without these bill of materials, you don't even, you don't even have the opportunity to have that conversation. And so I'm excited about where that goes. There's a lot of arguing over what's the format and what's included and what's not included, and, you know, so a lot of detail still there to be kind of, um, figured out.

But I think that's gonna be huge. Um, and again, that, that's an inventory that you can create, right? If everybody's publishing these test bombs, you just create these inventories of all these components and versions and now you can start to look at, you know, use like CBE details or, you know, whatever vulnerability management platforms you have to look and see whether or not there's vulnerabilities in those, in those pieces of software.

And then start holding your vendors accountable, which again, really makes me incredibly sad. Like the number of MSPs that ask us questions about what we're doing outside of standard diligence, um, that like follow up and say, Hey, what, you know, where are you on the Microsoft Exchange? Where are you on, you know, when the whole super micro spy chip thing was going on? Um, that, you know, the response has been pretty dismal.

And so that tells me there's a lot of room to improve and part of the problem is inventories. Hmm. Gary, um, you know, what I just heard, and I'm gonna ask, you know, to kind of ask you some questions here. What I just heard was maybe a a, a good separating question is if, if you, if I was interviewing you as a prospect and a business owner, say, Hey Gary, I got a question. Do you any of your employees potentially use software you don't know about?

And is there any chance there's any software that could be open source that you don't know about? I I'm just wondering if that might be a, a, again, a wedge where like, gosh, I I'm not, you know, if they go, oh, they, they don't. Well, how do you know how, how do you know that no one's done anything outside your purview? But, um, with that, talk about how, you know, I, if I'm an MSP out here, I'm thinking, okay, how am I going to incorporate this, right? How am I gonna operationalize this?

Um, again, I'll, I'll use Ryan's advice. And the same thing, like a lot of the people who come to us, they've never really had a proactive role of process. And when they're implementing like myy process, it's the first step and it's exactly what Ryan described. They're overwhelmed 'cause they have 30 clients and there's now all of these things to do in terms of alignment, documentation, and we just tell 'em, let's get started. Guess what?

You are not gonna get from where you are to where you realize you need to be in the next quarter no matter what. Let's put a plan together where you're further ahead in a quarter and then another quarter, let's push it ahead from that. Let's start, let's at least start, part of it is just getting a discipline where you have resources in your organization, a person or part of a person who is focused on the kind of things we talk about here, right?

Asset, inventory, documentation, um, uh, standards in alignment, those kind of things. And once, once you have the seed of a proactive, um, practice in your business, you can make, you know, you can, you can make progress, but until you have something that resembles that, Andrew, you're, it's really hard to get any of this done. All the things that Ryan is saying, you gotta start somewhere.

You are where you are, your team is, you have the tickets, you have, you have the prices to your customers you have today, what's my favorite saying, you gotta change the tires while the car is rolling down the highway. Unless you win the lottery or independently wealthy, you just can't pull the car off the road for a year and do a frame off restoration and then put it back on the road. Right?

Gary, again, you know, they, here, here's something you and I've talked about 50,000 times on the cyber call, but I'm gonna bring it up. What you just said is so applicable to sales. My point isn't to go into a sales conversation, it's what you, you know, I got the pleasure to work with you for five years is the same conversation. I want to add X amount of, you know, of, of dollars in mul, you know, MRR this month. Okay, well, you know, are, what are you doing today?

Well, we get leads, you know, we, we, we get referrals. Well let me ask you how many, how many cus how many contacts are in your database? We just have our customers, right? But is it the same Anything?

You know, what they, because it 'cause sales is proactive the same way what we're talking about, anything that's proactive as MSPs and business owners we like re like we like to manage the tickets and alerts 'cause they come to us, we don't have to go out and get them and then we spend our time figuring out how, you know, how to do that. So when things, uh, when we have a job like VCIO, like sales, like these things around security, right? Uh, we call and they're proactive.

You have to manage proactive roles differently than you manage reactive roles. Got it. Managing tools, you know, again, that's what, that's what you're talking about. Yeah, no, absolutely. I think, you know, when I, when I think about the things we've spoken about today, whether it was business impact analysis, whether it's tabletops, et cetera, um, just curious if you could give some thoughts for everybody here.

How are you helping, you know, I know you have a huge, you know, a hundred like 800 total in the, in in the program, but then 200 in your coaching model, how are you helping them incorporate that into their go to market, if you will, and their packaging pricing? Yeah, so what we're trying, what we try to do for everybody through our, not just our peer, but our training, we're always trying to have them see how things are connected.

That when they are doing the right things right and they're doing these proactive things for the right reasons, whether it's talking to customers or prospects, they're able to change that sales conversation in one where they can command the prices that they need. And, and, and also we're making sure that when they go to market, that they know what all of their costs are not just for tools, but for each role and function.

So that that's how you start to use maybe a higher price than, than a competitor as the reason why someone would buy from you or, or, or more recently I like to call it weaponizing your competitors' low price. Got it. And, and should, should the MSPs be thinking of things like, again, let's just pull up building an instant response and a tabletop exercise, something that's in the res, you know, resiliency area.

Um, are these now non-recurring or, or you know, are you thinking, how are you thinking and can you help everybody start to think about, you know, is this project or is should this be built into your stack, so to speak? Okay, so what I'm seeing is in the beginning, 'cause people don't really understand what their ongoing costs are to, to manage and maintain this.

They're doing, they start off doing them in some type of a project, but ultimately the people that are more mature now what they're doing is they have like an advanced security offering and they'll bundle some of the things that you're talking, uh, about maybe with some other technology.

Maybe that's where they put their sock and seam and they're literally now going to those 25% of the customers that are, that they're able to have this conversation with that are security conscious and they're, they're able to go out and have this package and maybe it's a minimum of 1500 bucks a month and it's 40 to $50, you know, per seat, separate from their managed service offering, their, their core offering. And so I think if we, what I tell them is don't get stuck not doing it.

'cause you don't have enough information to do the packaging and pricing. If you're in our peer group, we'll share with you what everybody else is doing. I mean, I'll tell anybody what they want to know.

We're not trying to hoard information, but if you don't feel you have all the information to package and price it, get started with it and, and do it, uh, you know, package it in, in in a way that's, even if it's non-recurring in the beginning to just start doing it and you will figure it out once you have command over what it takes. And ultimately where you want to end up is, okay, if I have a resource that's gonna do these four or five things, how many customers can they manage?

And on average how many seats across those customers? And right then as soon as I can project that out, Andrew, I know my ballpark cost per seat for it. Yeah. So I'm gonna ask the audience something and you kind of simultaneously, would you guys like it if Gary, we mentioned this, Gary brought on a, a few of his members that are different maturity levels, yes or no? Yes.

And, and you know, kind of, we use the cyber call so you can actually hear from other MSPs on how they started to, you know, build this kind of stuff into their practice. And if you as an MSP out there feel like you're down the road aways and would like to share what you're doing, we'd love to have you on as well. I'd give one or two people maybe That would be, uh, I would love to have, um, Mike, Mike Beard come on for that as well. He's put, put a lot of effort into this. Yeah.

He'd Be a good person to, to, to, you know, me and him and one or two people, like not too many and just have a conversation about this. Um, I've done it with my members, like, uh, we have these peer office hours every couple weeks and they're really great conversations. Everybody really values them. Yeah. Okay. That'd be, that would be awesome. Um, so Mike, I, I know you're out there. Hopefully it's next. Tease me seeing if Gary wrote a book. The text would be in red.

No, I hope you, I hope though it starts out in red, but the last chapters are in green. Yeah, there you go. Right. Um, because We're making money on it. Very good. Gary, do you think we, we might be able to pull that off for next week just to kind of continue this? Uh, I have to check schedules with people, but maybe we'll take a couple weeks, like, uh, don't hold the gun to my head, but we can definitely get it scheduled. Okay. That'd be great. Yeah, it looks like people want that.

I guess something else I'm gonna bring to you that I think would be good maybe for next week. Okay. Okay. Fantastic. Alright, so with that folks, we'll wrap up a little earlier here. Ryan, do you wanna, you know, leave, leave people with what you always wanna leave with them? Uh, yeah, I mean, there's, there's so much more to say on this. Uh, I think I shared with Andrew, I, I once talked to a peer group for three hours about asset management and why it was important.

Um, and uh, and like I really just can't emphasize enough that you just have to get started. It doesn't have to be complicated to begin with. You just have to pick an activity to do. Right? Someone in the chat brought up, how do I build a data flow diagram? That's a great objective because it's gonna send you on the path to discovery, it's gonna make you challenge what you know and how you know it and what you can prove, which is ultimately what you're after with your inventories.

And so I would do that. I would do just a simple activity and, and let it go from there. And, and those simple data flow diagrams might turn into business impact assessments and you might discover more things and that might need lead to more revenue. And so, you know, you gotta do these things like you, you can't do the rest of the CIS controls and neglect the inventories. You're doing yourself a disservice and you're gonna feel safer than you are. Yeah.

Speaking of data flow, maybe we bring Brian Blakely on and that could be the cyber call next week too. We'll have to battle that out. Gary. Gary, any closing comments? Uh, n no, other than, uh, I wanna say I hope that people end these calls. Maybe your initial reaction is we have so much to do, but I hope when you end it, it's like, okay, you already have more knowledge and experience than you did an hour ago and you have more perspective than you did an hour ago.

And everybody's going through the same thing. There are different points of their maturity, but this is a reality together that we all have to deal with. And, um, we're all gonna, we will all be better off for it unless we're not. All right. Well, till next week, everybody have a fantastic, uh, week ahead. We'll look forward to seeing you next Monday. Have a fantastic one. Take care everyone. Thanks folks. Thanks guys.

Related Videos