Skip to main content
Right of Boom
January 30, 2025

Cyber Insights from MSP & MSSP

In this video, industry experts discuss the latest trends and best practices in cybersecurity, specifically focusing on phishing simulation, incident response, and the importance of effective communication between MSPs and their clients. The conversation highlights the significance of adapting to evolving cyber threats, emphasizing proactive measures and the integration of technology to better manage security risks. Throughout the video, viewers gain insights into the critical role of collaboration, continuous education, and innovative solutions in strengthening cybersecurity defenses.<ul><li>The importance of attending industry events to gain perspective on trends and best practices in cybersecurity.</li><li>The role of cybersecurity awareness training and phishing simulations in improving security posture.</li><li>The significance of integrating effective processes and controls in managing cybersecurity risks, particularly in phishing scenarios.</li></ul>

Guests

Andrew Morgan

Video Transcript

For you. Oh my gosh. All right. Welcome. Welcome everybody. A lot of zany things going on in the background, especially with Chris's velo bed. Chris, good to see you always. And, uh, well, that there's a story behind that also. Um, but welcome everybody to Week 71 West. We are 25 away from 4,025. That that means that of the hundreds of people that are on today. Go share this out on social media. This That's right. Share It. Say, come join Andrew.

I want, I wanted to share with you that I was, um, I was at the Kaseya event last week, and, um, one, there's a lot of people out there still that don't know about the cyber call, right? But those that did are huge, uh, advocates. I mean, so many people just came up and said, it's like one of the best hours like that. I get so much out of everybody. And, um, so it made me feel good, and I wanted to pass that on, that we're, uh, I think we're doing some good. Yeah. Yeah.

That's a huge testament to you guys. And, and thank you for all you do. Um, Gary got about 30 minutes of updates, so, uh, but you know, really and seriously, Gary, real quick, give us an update on what it's like being out in a big event. Um, while you do that, I'm gonna put, uh, just a URL again, the cybersecurity training, uh, getting started with, uh, security and Mitre attack is coming quickly. I put the URL in, but Gary, give us a quick update and then we'll set the stage. Yeah.

So, um, first off, it was great to be out. Um, the energy at these events, you can just tell that everybody really wants to be together at this point. Uh, MSPs were engaged. Um, I think all the presenters had a lot of pen up, you know, uh, energy. Mm-Hmm. And so, um, and, and the message I'll send to all that I sent to all MSPs is this is a historic time that we're in right now, right? Not the past, not the pandemic where we are right now, and where things are, are heading in the future.

And you're not gonna figure it out two places for sure. You're not gonna figure it out sitting in your office alone, and you will, I promise you, you will not figure it out inside of a service ticket, right? So you gotta get out and you gotta engage, and you gotta have more perspective about our industry right now, about what's happening with m and a, with security, with SMBs and techno their technology revolution. Or you're not gonna be able to make the best decisions that you could.

So get out there. Great. It's actually an awesome segue to today. Um, you know, you know, week after week, we have some incredible cyber talent on, um, you know, a John Strand or a j you know, a, um, you know, the, I was thinking of you je I'm thinking I'm butchering his name from Sands or Sunil, you, you know, we have these who's, whose type people on, and there's a lot of MSP slash MSS ps doing some incredible stuff, uh, in the channel.

And that is what we are dedicating today to, um, we're gonna start off, um, with the awesome work, um, that Kelvin is doing. And, um, Gary, I'm gonna let you lead, lead this off. Um, I put a few poll questions in. Uh, I did wanna give a huge shout out, um, to Huntress because of them sponsoring 50 spots to John Strand's upcoming training. You have to register for Hackett, you have to be there. They will select them. Um, but, uh, that was, uh, a pretty, pretty cool thing.

Um, huge shout out to all the vendors and sponsors to this, Ryan, Gary, Wes, and I'll list off all of them if we have time. Gary, you want me to do that now, by the way? You can, if you want, Andrew, go ahead and list them off your show. No, let's, I, I will, I promise I'll list them. Hey, Andrew. I will say this though. Um, yeah, I've already given out a few free passes and a couple of the MSPs, Carl in particular, Carl Bickmore, is like, heck yeah, thanks.

He's like, I already sent two of my, my people last time. I'm already sending more people again. So a free pass is not only nice, thank you. But he was like, this thing is awesome. It's good enough to where, like, we're definitely sending more people. So if you've been on the fence of like, should I do this or not? The the cost is so low. There's literally, like I can see of zero reason why you wouldn't do it. Nothing but good feedback. I, I would agree.

And I, and that feedback came from some really mature security postured, MSPs and some, a lot less people that are much earlier on in their journey. And it was universal that it was great. Um, again, raising the poverty level, right? Security, cybersecurity, poverty level for MSPs and Andrew, the only thing we have to promote this is 'cause you wanna help MSPs. None of us on here have a horse in the game, uh, in terms of whether you do that training or not, other than your wellbeing, right?

Yeah, absolutely. And then to your po to your point, uh, the price, you know, this is John Strand, a guy that used to get paid seven to 10, or not him, but Sands get seven to $10,000 for a week of his training. The same guy. Um, all right, so I will talk about the vendors, but right now I do want to let Gary talk to Kelvin. Then we will move to Chris. We'll bring up Felicia. Yeah, she's out there.

Felicia hit, you know, just say hello if you are their session at Hackett, and then we'll move into Jason Slagel, the very timid and shy, um, uh, red Teamer and, uh, uh, owner of CNWR. So, Gary, why don't you, yeah, Well, first, yeah, before I get into that, um, Ryan, maybe you can just, um, mention, uh, a little bit about how, uh, DattoCon was the set looked, the set looked amazing.

By the way, Ryan, before you go, your threat team was awesome last week with, uh, Javier from black, um, black Point Cyber, uh, what you guys did with those threat profiles is awesome. So go ahead, Ryan. How about you? Yeah, I mean, uh, it, it, it was, it was kind of like dataCon, but not, right. It was, uh, definitely missing that in person vibe. But, um, uh, yeah, I, I thought the event was, was incredibly well, uh, orchestrated.

Um, it was hard because we had planned three days worth of content and then we had to figure out to shrink that down into six hours. Hmm. But I think what it did is it forced us to really, really figure out what the thread of the entire event was, and just bring that really bright line to the front. And, um, you know, and then the keynote I gave, um, you know, I could post a link to it. Um, there were kind of two things that were really essential for me.

One was this kind of notion that if you're not on a path to cyber resilience, you're getting left behind. And, and not only that, that path not, you know, the path you're on leads to catastrophic risk, but that not only does cyber resilience kind of avoid that catastrophic risk, there's a, there's a potential large sales opportunity, revenue opportunity in that for you. And it, it's the opportunity cost decision there just boggles me. Like, why wouldn't you make that decision?

Um, and kind of doubling down on this message of like, if you're not implementation group one, you know, in the next six months you are officially behind. Um, and I think those threat profiles you mentioned, you look through those threat profiles, we mapped every TTP to its defensive control and CIS 99% of them are implementation group one controls, right?

Um, so it's just crazy to me when you think about knowing your enemy and building a threat and form cyber defense implementation Group one gets you a lot of the way towards really defending against the tactics used by some of the most sophisticated threat active groups in the world. So, um, yeah, I loved it. It was a blast. I was totally exhausted, uh, by the time it was over and needed to take a week off, but I'm back and ready to do it again. Yeah.

And, and Andrew, just again, following up and I'll get to the questioning. Um, so, uh, one of the sessions I had last week was about cybersecurity sales, like mastering it. Got to ask people in the room some questions. And what I'm like, what we've been talking about, now that I'm with people, I'm sensing the gap is widening.

There are people that have figured this out and I can tell because, you know, they're at 200, 250, 300 bucks a seat, and they're still people that are under one 50 and they're stuck in their model. And like, again, we gotta get people going.

What Ryan's talking about, which is the number one step we talk about is secure yourself, your house, protect your house, and what you'll learn from that, we'll help you figure out and have conviction to all of your customers and prospects of where they need to be. You are not saving them money right now. You're not saving them money by not charging them enough to do it, right? Yeah. And Felicia, really good point.

Like, how can you do it less for, you know, she put out there 300 or whatever, whatever you, Whatever it is. Yeah. Depending how you package price, what you include, what you sell extra. But the point is, it's gotta be more. And I like to say we care too much about our customers not to charge him enough, man. Yeah, absolutely. Well, as Deepak to Donny said on his business card, back when we had business cards, Calvin, I promised the last thing, but I love this. Take it, take it easy.

Take your time. I'm loving this, the banter. So he's like, um, if the card said, if you think hiring a professional is expensive, wait till you hire an amateur. That's really good. Yeah. isn that great. Again, their costs have already changed. It has nothing to do with us. We're just helping them, uh, maintain and manage those costs in a way that won't be catastrophic to their business. So, alright, We gotta get, we gotta get to 15 minutes. I have one more announcement. Go.

So in those threat profiles that, um, my, my team and Javier walked you through last week, um, you'll actually notice that a lot of, uh, almost every single threat profile has a safeguard from safeguard control Class five, which we just released, the CIS safeguard five crowd, um, cyber cast on. So that's true. Uh, now that these threat pro profile profiles are out there, you have the CIS framework. The podcasts actually support this.

So you have the threat profile, you can go listen to the podcast as you're developing those safeguards and implementation is one. And you, you actually have all the research you need now to kind of really support and understand the what and the why. Thanks For mentioning that. I put, I just put the cyber cast. I've had MSP say this was you by the way, you, Wes, Ryan, you, Wes and Phyllis were phenomenal in this one. And, um, special shout out to keeper for the sponsorship as well.

I'm sure we could. And I put all the sponsors by the way, that helped with the, with the Level Up secure, the John Poe, John Strand security. All right, Gary, I think we're finally underway. Yeah, I'll by way post Kelvin's links to get this 'cause this is awesome. Alright, go ahead. Okay, so finally, Kelvin, should we chat? Yeah, sure. Go ahead. Why don't you just start off telling everyone about what the cyber drain partner portal, uh, portal is.

So, um, trying to compose what the cyber drain partner portal portal is in one sentence is, is is very difficult because it's like this complex, um, um, orchestrator of moving parts, but Use two sentences then. Yeah, Exactly. In, in, in essence, it's a multi-tenant way of managing your M 365 environments and making sure the right standards are applied to those Microsoft 365 tess that you have under your administration.

Uh, so, uh, an example is, um, you want to make sure audit logging is enabled everywhere and on your tenants. This is something that runs the PowerShell scripts in the background to make sure that audit logging gets enabled everywhere and stays enabled. It redo everything every couple of hours. So you make sure that even if someone changes the setting, it'll be changed back again in the future.

So there's, there's this rollback mechanism if someone changes something that they're not supposed to change, but it's also, um, an assistant that helps, uh, engineers or, uh, help this technicians or however you want to call them, to make sure that they are able to do their work easier and more fluently. Um, if you look at the current Microsoft 365 landscape, administering all those tenants is very difficult.

You have to log into one portal, jump to another portal, then you have to log in again, then you have to use MFA, uh, to, to log to do global administration stuff. And then you can, uh, uh, and then you can finally start, for example, uh, creating a chat mailbox for a user.

And with the, with this, uh, CIPP as it's called the, uh, cyber Brain Improve Partner portal, you can just do that all in one click instead of having to go through all of those steps, jumping through all of those hoops to get to that tenant. So administration becomes a lot more easy and more streamlined, but still secure behind your own, um, uh, um, Azure AD authentication provider and all that kind of stuff. So it just becomes a lot more simple to administer everything. Nice.

So, um, does this replace any tools in the stack or is it something additional? There are a lot of other tools that try to do this, but either they've priced themselves out of the market or they're not looking at the workflow that MSPs actually have. Because that's the main reason I started doing this. I started doing this because, um, the partner portals that currently exist or the, the, the other, uh, vendors that do this, that currently exist have made it super complex.

A help desk technician can sit down, log in, make some changes, they have to go through 12 wizards, six screens. It's pretty much the same as if you would use the normal partner portal. So it doesn't bring that added efficiency. Yeah. And a lot of other vendors like the RMM vendors, they haven't really caught up the RMM and PA vendors, they haven't really caught up yet to the entire cloud management model. And they're investigating it, but they're actually really late to the market.

So this, this was more of a, a sort of a wake up call to them too, to just show them like, Hey, this is a guy that, I'm a guy that made it in free weekends in my spare time, just to show it was possible. And then, yeah, pretty much became a hit. Alright. Uh, Wes, Ryan, me, I think we could all send a note to somebody, right? Say everybody should get Yeah, everybody should get, get moving on this.

You know, I, before I ask my next question, I just wanna share like this, what you mentioned about tools and people understanding how MSP's workflow is, like this has been this way forever. And when John Strand was on, you know, he mentioned a lot of different things, and this is free and you can do this. I'm like, yeah, I hear you. You deal with enterprise companies. Like we have a 50 companies, 20 companies. My, you know, my first MSP had 160 companies.

The level of complexity, uh, to get tools that are awesome no matter what they cost or if they're free and making 'em work for us is a long way from home. So I'm glad that you, uh, and it's one of the challenges, right? We have in general, but with security, I is, it takes time for any of this technology to be put into a usable way, uh, you know, for, for MSPs. So, um, can you walk us through some of the, a little bit more of some of the key functionality? Like what, what Yeah, Absolutely.

So You think is like where people get the, the quickest time to value if they, if they were to go and do this? Yeah, so we actually recently, we are developing a lot of things, uh, over time and we're still developing the product very quickly.

So there's this rapid base of new features, and just today we released the user offboarding wizard, which just with one click allows you to remove licenses, uh, make a shared mailbox out of the user set there out of office, um, make sure that administration is updated, that those licenses have been removed, um, even delete the user, give someone else someone else access to their files, all with one click of a button. So you just do a couple of check boxes.

You say, okay, hey, remove this user and poof, from there on, uh, it, it all happens. So that, that's one of the, the biggest time savers, I guess, that you could have. But there's also things like, um, adding applications to all Intune tenants a lot, uh, of MSPs are starting to use Intune, but have trouble with it because you cannot add from your current tenant. You can't add, uh, one application to all your subtenants.

So if you have 200 clients, you'd have to click at least 5,000 times just to get that application in. And with the CIPP, you can just select that application, say, push this to all the tenants, and it happens. So, um, I had one more question for you. Um, it wasn't that I was just thinking about why, why are you doing this? So, like I said, vendors have been lagging behind for a very long time, and I've been discussing this with a lot of our m vendors.

I work closely with them for my cyber drain blog. Um, I, with a lot of my scripts that are published in, um, their, the, these vendors products, and I work with them to tell them like, Hey, this is what MSPs need. And still they're lagging behind. Or they're saying things like, Hey, development is impossible for Microsoft tooling where it's very hard. You need a super, super highly skilled development team extra on the side. And I was like, yeah, but that's not true.

'cause look, I can make this. It was mostly just to cause a little bit of disruption in the market and help people understand that, that we all need to move forward as an industry cloud management and cloud only is what we're going towards, which has implications on security. And if you have, uh, a multi-tenant way to administer that security, it helps everyone in the entire landscape. Yeah.

Listen, uh, I I just wanna say, I, I appreciate, you know, what you're doing with this and you know, I, I won't get into it now, but there's a lot of reasons why there isn't more innovation. I mean, if we have time on another call, I can kind of take you through my perspective about what it is. But these are the kind of things that have to happen, uh, to spark innovation.

'cause ultimately, this is the thing that the big companies that I call 'em the now, the new distributors, um, need to be doing because that's the only way that it gets out to the masses. So, exactly, exactly. This is something that their value add should be. Absolutely. So really good job of having awareness and helping people. So what I, I left the spot there, Ryan and or Wes, no pressure, but did you have any questions for Calvin or anything?

Uh, before and Only thing I'm itching to know personally, Kelvin, can I integrate with CIPP via like an API? Um, there's no public API, um, but just send me a message and we can discuss on Okay. Something that we can work on with vendors. There's some other vendors that have already asked too. I'm still working on a model for that. Okay. I have ideas, so I'd like to talk to you. Yeah. Okay, Cool. And, uh, Ryan, anything from you?

Man, No, I'm, I'm kind of being a bad, bad host today and I'm trying to work on a board deck while I'm also posting Stuff. Okay. Um, no, nothing comes to mind right now, but if something pops up, I'll let you know. But, But Kelvin it awesome work, man. And this is where innovation comes from. It comes from a need that's not being solved. And, um, I mean, just seeing the comments alone from everybody using it and like, yeah, nice. The, the reaction to it has been insane.

I think the last, so I, it's been released for about two weeks now. Two weeks-ish, let's call it that. And we already have a hundred active users. We have, um, a lot of people implementing it. But the, the surprising thing to me was that as soon as I made this open source, we had like 10 contributors, people fixing small typos, but also really developing new functionality. I, I really, it, it's no longer just my project.

Um, another, uh, MSP Gavin Stone, who's known from the Gavin Stone blog, he also is helping develop the product more and more. So it's really beautiful to see that the MSP community community comes together and starts fixing this. So I, I just wanna put in guys, gals out there. I'm putting in Kelvin's, uh, GitHub, basically, you know, if you wanted to, um, sponsor him and, and kind of give back, that's that link.

So if you're using it, I would suggest giving, you know, giving him some, um, support, um, because, uh, that's, I'm sure he's gonna turn around and use whether he needs to hire some, you know, people, developers to assist him. But this is, this is an ongoing project. Yeah. So Calvin, thank you for all you do for the community. It's awesome to have you on. Thank you. Thank you. Yeah, absolutely. Alright, so Kelvin, I'm going to move you over back to the absolutely.

Audience and let us know, you know, when big stuff is coming, we'll have you back on and give everybody an update. And, um, I'll bring on Felicia who's doing an event or a presentation with, uh, Chris, uh, at the upcoming Hackett event. So I am gonna go find Felicia, but, um, Wes, I believe you are up, if that's correct, with, uh, Felicia and Chris? Yep. I think so. Alright, Felicia, I'm getting you on right now. And Chris, tell us about the bed, um, you and Gary about That.

Oh, so I, you know, what I do is I, I roam around on my Twitter feed and pictures just pop up, you know, people post random stuff and I'll use it for my backgrounds if I like it. Right. So this was from a, uh, uh, it didn't say what specific year in the seventies, but from a Montgomery Ward catalog in the seventies. So I said, what better place would this background be? But for the cyber call, I mean, it's like, perfect. So that's what I did. I I figured it'd inspire people.

I mean, you had, you have Kelvin at first, and then you have this bed second. If you're not inspired by this time, then you might as well just Yeah. Yeah. Man, retire. True. Yeah. Look, I I guarantee you Ryan's board deck would be crashed. Yeah. Right. If it weren't for this bed, his board deck's gonna be the best board deck. Yeah. He's using it as the back 'cause of that bed right there. Yeah.

And he should, man, I mean, it's, there's no board deck spot inspiration, like Board picture send me tag or the, or the, whatever the image file is, I'll work it into my deck. Yeah, yeah, yeah. I'm sure the chief risk officer got in with that Starting things off. All right. Wess, you are up. I'm, I'm sure Felicia is nearby there. Yeah, she there. She popped in and she disappeared and left us with looking at the key. I dunno what that means.

Um, but who knows what it's, Well, there was a demand for another rabbit. That's what happened. Okay. Everybody wanted to know what happened to Sable. True. Okay, here's Sable. 'cause Sable was in the promo. Hi Sable. So this is Sable. My level of stress today automatically just goes down where I see little cute bunny rabbits everywhere, so. Yep, that's right. That's awesome.

Uh, Chris, and, and actually, so Felicia, I need to know from both, are you guys doing this presentation together at Hackett? Is this both of you together? The dark web dumpster diving? Yep. So talk to me about it, Uhhuh. That's exactly what it's all about first time, because everyone loves a good dumpster dive. Uh, so, so, so, uh, in fact, that's probably where you found the bed cover from Chris. So tell us about the talk guys. Well, yeah, no, I mean, uh, Felicia, you're on there first.

Well, I, you, you have first Go. Well, the thing that I'm really interested in this particular event is, uh, I wanna, wanna see how far Chris is willing to go with whatever he chooses to disclose, because most of the time, you know, he has to be very reserved, you know, Mr. Hush hush secrets and then dropping the truth bombs every now and then, right. You know, shedding, shedding some light on some complex topics for us.

So, uh, I'm interested to see how far, uh, he is willing to go with, with the truth bombs on the, the dark web hunting.

And from my perspective, the things that I'm particularly interested in is the impact that I've seen occur really the last 12 months here is how all of these things interrelate to the cybersecurity insurance, you know, risk assessments, the, I did a podcast on how to avoid cybersecurity, uh, insurance fraud, and that was a really hot podcast and I got a lot of good feedback on it.

And now there's a bunch of other people that are, you know, another, other MSPs that are trying to do that same thing for their customers. So this is all good, but I think it's gonna be, uh, so from my perspective, the, the whole dark web thing and how that interrelates into these topics that are associated with, uh, what everybody is facing right now on the cybersecurity risk, especially I see it in the supply chain. I see banks coming forward and saying, Hey, you've got a loan with us.

We require you to have these is policies. The state of Wisconsin just recently passed, where you now have to have, uh, an incident response plan. I think the threshold is you have to be like a $10 million company, but then the insurance company says you gotta have an insur an incident response plan. And then, you know, your big customers say you have to have an incident response plan. So, you know, guess what, everybody tabletop exercise time. Right.

You know, so it'll be interesting, I think to see how the, the dark web monitoring and, you know, the, the, the issues on the dark web, how we relate those through to the, the compliance side pieces on the, on the insurance. It's not, it's not just cyber insurance. We're seeing requirements on e and o. Mm-Hmm. So, I mean, that's like, you have to have your e and o like you don't have a, you don't really have a choice. So, uh, yeah. And like you said, more regulation every day.

It's not going backwards from here. Gary, just real quick, and, and not to get off topic, but I'm glad Felicia mentioned cyber insurance because, um, you know, we're gonna hear more about this. It's starting to get out on some of the channels, but some of the bigger carriers are literally, if you're a managed service provider, guess what? No renewal. So a lot is changing.

Andrew, maybe again, we have so much content, but one, uh, we're doing a special project this quarter with our peer members, uh, called the, uh, cyber insurance Deep dive. Justin helped us out, uh, with it, but maybe at some point it's something we can do publicly. Yeah, yeah, yeah. Absolutely. And Chris, I really need you to press on Spencer to get back to me. 'cause this, this is getting to be a hot topic, so. Alright, go ahead Wes. And, uh, just Well introduced yesterday. Yeah.

So, uh, yeah, be careful man. His ravens, his ravens lost bad. So that may be what's causing him to slow down a little bit. Go ahead Wes. No, you're good man. So tell, so your part of the presentation, whatcha gonna be talking about, give us a little, uh, tee. Yeah. So, so you know, it's gonna be a good time, right? It's, it's gonna be, um, a little bit different.

Uh, so Dave over there at Huntress is gonna be alongside of us and throwing, you know, kind of driving the thing, throwing some things out there. And I think, you know, what I get from the dark web and you know, there, I, it's, it's so valuable today. So there's a lot of work we do. Um, we have lots of sources and threat intel that we get from the dark web and we're able to call up policy holders ahead of time and say, Hey, something's going on in your environment.

You might not have been hit by ransomware yet, but it's coming up. And so we get involved in, in a proactive way, it's not a claim because nothing's happened per se, uh, but we get in there, help 'em understand if they can indeed have isolated, contained and eradicated it.

And, you know, we just had a case in the last 10 days that we were able to do that and successfully get in there and prevent something from occurring just because information was found in the dark web, uh, that led to this discovery. So it's got its benefits, right. Uh, you know, a lot of times when we get on calls and we talk about this dark web, it's a very difficult thing to explain because it's full of everything out there. And so a lot of this is not just gonna be on the cyber stuff.

We'll throw some stuff in there. You know, I might say that I might have an in-law out there somewhere that, um, is involved in the dark web quite a bit and has nothing to do with cyber attacks. So, uh, he's, he's given me a lot of information on, on what he does in there. And so I might throw some of those things in there as well because it's pretty interesting, uh, what goes on there. But, um, you know, the, I, it's, it's, it's not gonna be slide heavy.

Uh, there's just a handful of things in there. It's just gonna help drive the conversation and then we'll go from there. But it should be lots of fun, lots of examples. Um, you know, it should be, it, it just should be a great time. Well, I think one of the things that I really wanna work into that conversation too is what is the responsibility of the IT service provider?

So the big conversation I've been having with all my clients for at least the last year and a half here, is, who the hell does the MDR? Okay, who has the authority to do high host isolation? 'cause to tell you what, we're not picking up the phone and we're not asking for permission. We're just gonna host, isolate you right now if that's what we feel like is the appropriate course of action.

And there's this whole discussion about the separation between, okay, we're looking at dark web data, you know, we're looking at the network analytics, we're looking at the endpoint analytics, we're seeing all this telemetry. If you've outsourced that to a soc, does the SOC have the authority to trigger host isolation?

Well, if that's not part of the relationship that you have with the soc, then maybe you ought to reconsider that action, right, Wes, you know, because yeah, I mean, it, it goes into, um, and this is I think, a big discussion I saw both in MSP geek a week ago or something like that.

I think you had seen some of that too, Felicia, of like, what kind of customizability do I need between my SOC and my, my own operations and who's gonna have controls on what and what things can I automate to make things happen, you know, in, in certain ways based on, on my own, like risk profiles and thresholds. And the challenge with vendors is they want to, I'm a vendor, is they wanna squeeze you into their own SOPs so that they can operate efficiently. But it doesn't always work, does it?

And I'm sure for you, Felicia is an MSP, that's where some of the frustrations and pain points you really have to work through. All right, Well, I, I don't wanna name names on soc, but let's just say there's a SOC that, uh, that I know some folks use who they might get like an email from that soc 15 minutes later. They're, you know, they're getting an email some notification. So really the workflow here is, is something that I think people need to be desperately analyzing.

There's too much of this outsource and then just like, mm. Give it up. Right? Drop it. Yeah. And that's not, that's not an effective model. I don't care what soc you're utilizing. So the question here is what is the response time that is, is gonna happen? And then, you know, who's doing what? So is the MSP, do they actually have the technical capabilities to look at those alerts and analyze what the SOC has said in terms of a recommendation? And again, who has authority to lock it down?

I talked to Mr. Hansel van recently and he's talking about, um, no, we're just gonna lock him down. You know, I'm like, Kyle, you go right ahead, man. 'cause that's, I think that this is reflective of, uh, Hackett 2020 1.1, you know, addition one we brought up Matt Lee and I, we got into a bit of a hot discussion and we were like, no, if, if we are responsible for patching those systems, I'm gonna decide it's noon.

That system is getting patched now because it's that kind of a criticality, right? And I think now the paradigm has to be asked, where is it in your contract that says we have the right to host isolate you anytime. Yeah, Felicia, I don't just jump in there, guys. If go back and listen to Eric Tills on some of the things that he's, if, if your MSAs or your sows do not specify what Felicia just said, I would highly go back.

Uh, I'm not an attorney just going by what Eric has said, who has been in this space for 20 some odd years and work for one of the largest MSPs built one of the largest. So anyway, please, if you're gonna, if you're gonna Andrew know what you Yeah, I'm sorry. I feel like you just stumbled over something that I've been feeling like again, uh, Felicia said, you don't outsource responsibility, right? To a soc. You maintain your responsibility.

It's one of the tools, uh, capabilities you've chosen to use. And so it's the reason why we see more mature MSPs getting those relationships in place and being able to leverage 'em. And people that are less mature in their, uh, in, in their, in their cyber maturity right now, even that is harder to do because they don't have the process, uh, you know, uh, in, in place.

So there's work that an MSP has to do before they're even prepared to properly have their customers get all the benefit from these kind of relationships. You know, it's interesting too because, I mean, not all customers are the same, right? I mean, in co-managed situations a lot different than if they don't have internal it. And so you have to be thinking about that.

And I will tell you, I mean, um, I mean, I could spend a week just talking about, you know, the last six months and all the different cases that we've seen and heard and, and, and just the things that, the attitudes that are changing amongst clients about things and what isn't. So, I mean, Felicia makes a good point. I mean, I think a year ago, a lot of cases people might have pushed back a little bit more on you being disruptive without letting them know and that type of thing.

And, and, and now people are, are a a little bit more willing to say, Hey, look, yeah, you guys do whatever you need to do to, to, to prevent something or to stop something. And so, uh, and I think maybe the I, Chris, We don't have a week, we have an hour probably in the next two weeks where you could do that. Yeah, yeah. I, I have a case right now as an example that's, that's the sites are not connected whatsoever. Each one has the same variant, but a different, a different instance.

And then one of the sites also has a, another variant and they all got popped at the same time. And so again, was that as a result of somebody just publishing access on the dark web and, and, and two different entities went at it? Is it one entity using two different variants?

I mean, we don't know, but I mean, it's, it's, it's really coming, you know, it's really interesting what's happening in today's world and, and these people and, and, and dealing, dealing with these, uh, attitudes I guess you would call it, and these philosophies that these companies have about this stuff. Um, it really comes down to educating them. I mean, this dark web thing is, I think it's a great thing for MSPs just to talk about and educate.

You don't need to be a dark web expert, but you need to talk about how it kind of works out there. And it's not just a, you know, it's an ecosystem is how I call it. And then, then you can talk about, hey, we need to maybe make some changes to our contract language about what we need, what we can do going forward, and what you're gonna allow us to do. And, um, and kind of do it willingly, uh, and, and not, uh, be upset when we we turn something off in the middle of the night. Yeah.

Chris, I remember the early days of Perch back when we were just in IDS and a bunch of our sock guys all came out of Alert Logic. And so Alert Logic was sort of on those Gen one MDR really, um, lightweight sim or whatever. And, uh, they had an IDS and IPS component too. And I remember when they came on board at Perch, like, we cannot and shall not, and we'll never do IPS. I'm like, why not guys?

And they're like, do you have any idea the number of support calls that we get people blaming us first? Well, you're the IPS, it must have blocked something, fix the problem. And they're like, it wasn't us. And he, he's like, we drowned in those things. And you fast forward to today, like that was 20 16, 20 17. You fast forward to where we're at today. I still think you, we do have a lot of clients that value uptime over incident and they would rather still have uptime.

But that is changing, right? That language and expectation understanding is changing, but it's still on us to be the ones to, to communicate and say, look, if we have a suspected incident, I'm the one that has to handle the fire of recovering all of that. I am going to take action before I do something.

Like if I'm an MSP, I'm having those conversations with my clients because they need to understand that education component of like, we're gonna support you as quick as possible, but if there's a spec suspected incident, we have to do something first. Mm-Hmm. Um, and, and then, then we can lead into the tools like we saw Soar just mentioned in the chat over here, that's like way beyond today's discussion, but like, then we can rush into like, where do the tools fit all this?

We still are at this expectation level of, of our clients, of them not understanding why we might do something like that. Yeah. And then it also goes to say, you know, we have to do this, and up to this point then we're gonna say, hand it off. And, and that's the, that's the other kind of challenge too. It's, you know, having conversations with MSPs, they're like, look, I'm not gonna do anything. I'm just gonna tell the client to call cyber insurance and they deal with it.

And I don't think that's the right answer as well. I think there are steps that you have to take ahead of time. No one's gonna slap you on the hand or on the wrist or sue you for, for, for taking the right steps. Um, it's, it's, there's, there's a, there's a fine line, right? I mean, I don't even think it's that fine.

I think think we, and then we have these other MSPs that are just, they're like, Hey, we're just gonna do the whole thing and wipe servers and, and restore and then call insurance. And we're like, why? And so, and it's too, too little, too late. And so, um, having a better understanding as an MSP is always important. We preach that here, but having those ongoing conversations with your clients about those things you're gonna do, and setting those expectations ahead of time is super key.

So there are no surprises. Yeah, you, you said it, I mean that's the most important thing. What you end it with right there, Chris, is that you have to make sure you're on the same page with your clients. Like what do they expect's gonna happen and then your plan better match that so that when something does happen, you know Exactly. And they know exactly what you're gonna do and what you're not gonna do. Exactly. Yeah. Lemme take that one step further, Gary.

So something that I've been working on the last two years here is this whole continuity of data. So lemme explain this because it's, it's right along this whole thing of what should the MSP do be doing? Uh, my business actually supports other MSPs. We do a lot of large co-managed it, and we also have some direct clients. So sometimes I'll get these phone calls from MSPs that we're supporting.

I'll be talking to the business owner and they'll say, oh yeah, we just redid our whole tech, you know, security stack and dah dah dah, you know, I'm like, well, what about these? You know, what are you doing to prove that the services you're providing to your clients, you're actually doing them. Where is your weekly non-ad administrator, a testable proof getting published automatically into A GRC that says these systems are patched. Where's your automatically generated vulnerability reports?

Do you have a GRC? Do you publish that into a place that your clients can simultaneously see? Because that's what I'm doing. I'm sending it into a portal where if I need to give their insurance company an account, I can give them an account into it. The insurance company can go in there and say, Hey, we can validate that QPC is doing what they say they're supposed to be doing because we have that full, it's automatically getting published in there.

My team is not having to generate any reports manually. We're not manually validating that MFA is there. So if, if Poo hits the fan and you're sitting there trying to prove to the insurance company, well, let's see. On this cybersecurity risk assessment questionnaire, you said you had MFA, well, wait, we inventoried all of the places that people authenticate into.

Then we had an information security policy that actually says, this is what we're gonna do to generate access for everybody into those systems. We have this inventory for it, we have an enforcement mechanism for MFA, and then we have a reporting system that weekly reports that proves that MFA is on all of those accounts. And there's an IS policy that says that there's a human being that's gonna look at that report.

There's a, there's an alert that gets generated, goes into their mailbox, they look at that, that report, and it is their job. So takes take like CMMC level three, sort of, you know, attestation separation of duties and put this crap on steroids. Because if it is your MSP, it's your retirement, it's your income, it's your house, it's the future of your children, it's the future of your employees. It's all the rest of your other clients.

If you're not managing risk for your business effectively, you're gonna take it all down in flames. And you've got to be able to prove, prove, prove, prove, prove proof. And it has got to be a testable and automatically generated. And they're not doing it each. That sounds, that all sounds expensive. That's why she said 300 a c Yeah, and I'm pretty busy 'cause I have a lot of tickets backed up for today. Well, I, I right now have three fully certified information security officers on my team.

We're not playing. We are not playing. So, hey Wes, maybe 1, 1 30 seconds left here. I wanna bring up Jason, so we have enough time With him as well. We, we got way off track quickly, didn't we? But I'm glad we got, we were on track. This is before we got on track right. Direction. Um, can we, can we jokingly hate on dark web scanning as we close out and then come back to it? Yes. So it can be used in a lot of trunk slamming.

Um, you know, it can be used in a, it's chuck In the truck man, Chuck in The truck. That's right. That's right. So Felicia, how do we, how do we properly use it? Um, and I know that there's a sales element to it and I'm okay with that, but like, how do we actually use it in the right way? So there's a little service that, uh, a company by the name of Aine has, Aine has a beautiful, wonderful service called Delete Me. I would strongly recommend everybody go out there and get it.

It will basically take your public profile and reduce it to as much of a manageable level. And I think it's like 120 bucks a year. I have evaluated LifeLock. I don't personally recommend it. I have used delete me from aine for years and I've recommended it to all my clients. And it's, it's great. So that's, that's on a personal level, which you can do.

That's what I recommend to literally all the staff of all the clients, certainly all the executives, in order to reduce their kind of publicly public information persona. Um, some of the other things that they can do is, uh, they can stop making donations directly in their name. They can donate to third parties that will donate to the, okay, you know where I'm going with this.

Um, now then the other conversation I've had with clients is saying, great, we've got this dark web data, but now what are we gonna do it with? It We need to have an IS process that says that someone is gonna look at this stuff, they're gonna look at the data on that thing. We're gonna have a conversation with the end user and say, are you still using that, that password anymore? Well, if you are for shame, let's assess risk on that.

But then more than anything else, the thing I care about, are we doing cybersecurity awareness training, phishing testing, phishing training? Do we have incident response plan? Are we doing tabletop exercises? Are we enforcing MFA everywhere? Because the dark web data by itself is only part of a correlative threat matrix. It isn't really the same sort of like proactive prevention I think we all know is really the efficacious strategy, which is all the other things I talked about.

So I think it's an ancillary, it's not what I lead with. Well said Andrew. So yeah, no, I was gonna thank Chris and Felicia. Um, Felicia, you gotta work on A great segment. Can can you, can you maybe up it a little next time? Yeah. A little docile for us. Yeah, maybe, Maybe a few more buns. Well, Well you, you know, I mean I'm all intensity all the time. I love it. And uh, that's, that's one of the reasons that I've done my radio show for all these years.

Because if people don't appreciate the level of intensity, they don't call 'em, that's fine. 'cause we wouldn't get along anyways. 'cause I'm not gonna dial it back. We love you Felicia. I don't know. I don't really, I'm a little threatened by someone who's more fired up than me. I'm not used to that. Alright, lemme get Felicia. Thank you Chris. Thanks Felicia. Success on the presentation and thanks for coming. Thanks Chris. Alright, lemme go find, uh, Mr. Al.

Yeah, We're firing off cylinders today. I found, I found Slagel. He is right here. Oh, Putting on the badge, baby. Oh, there he is. Oh yeah. And Ryan is on. So, you know, um, now we're going to the other end of the spectrum. Gary, you know, we, we had passion. We had fired up. Now we're going with timid and coy on the other end of the spectrum. Yeah, the bearded end of the spectrum. Where's there, there, where'd it go?

I found, I Found at first, I, I, at first I thought, I thought he also was holding a bunny. Yeah, No, no. I, but I do have the dumpster that are diving in. It's over there somewhere. So I didn't get to, uh, introduce any of the guests today, but since I just thought about it, Jason, quick overview of you. Thanks for coming. And uh, Brian, I'll let you get right on into it. Yeah. I'm Jason Segel, uh, vice president of operations, CWR, uh, we're an MSP in Toledo. Yeah, we'll, we'll go with that.

Yeah. And you work with some big clients too, right, Jason? Yeah, We got some, uh, we do some enterprise E level stuff too on top of the little MSP stuff, so, Yeah. Yeah. Cool. Ryan, how's your presentation coming? Ryan's got his presentation and I've got this like ConnectWise CTF. Right. So we're both like distracted at the moment. Ryan, you wanna run it by us and we'll let you know what we think. Yeah, Why don't you just share your screen, Ryan.

We'll, we'll we'll tell the board what we think. Yeah, I'll just, I'm just asking for 40 more heads. No big deal, so, oh, No problem. Um, yeah, so, uh, I mean, back back to Jason. Let's make this about Jason. So, um, my understanding is your Hackett session is entitled Gone Fishing for Malware and Macros. Yeah. Tell us a little bit about more what we should expect and why we should listen. Uh, so John and I are, I mean, super excited to present with John again 'cause he is awesome.

Uh, and man, I could use him right now with the CTF crap I'm doing. Uh, but, uh, we are talking about phishing, right? And, and, uh, we're gonna talk about all things phishing. We're gonna talk about simulation, we're gonna talk about, uh, what happens if you get fished. And then in the end, uh, I've got some not super, super ridiculous demos, uh, but some pretty cool demos, uh, where we're gonna, uh, play with meta exploit and macros, right?

And, you know, we're gonna kind of play some like cat mouse game where I'm gonna do a thing and then I'm gonna make John, uh, analyze the thing and talk about how he could defend against it. And we're just gonna keep iterating on that, uh, and, and get a little bit harder, uh, no black hat level stuff, right? But, uh, stuff MSPs probably haven't seen before. Cool. So phishing, uh, that's a, that's a, that's a mild deep topic in itself.

Um, we just had a lot of conversation around effective response processes, but before responses, kind of understanding your susceptibility to Phish. And so that kind of leads us into phishing simulation or simulation technology that you can get from vendors. Um, do you think MSP should be relying primarily on vendor provided phishing simulation technology to determine their susceptibility? Or do you think that there's something more than that, that they should be doing?

Uh, I don't, I don't think most MSPs are smart enough to do anything else. I'm just gonna say it. Uh, I mean, there's some MSPs that are watching this call that I think are, are smarter than that. Uh, I ran, uh, I got a little story I'll tell tomorrow. I don't want to completely give it away, but, uh, it's, if, especially if you're trying to simulate like looking like Microsoft 365, it's harder than you think it is. Uh, and there's a lot of cat and mouse game, right?

So, uh, while I do think MSPs, uh, understand their threats and if their goal is to make people click on stuff that they might otherwise click on, they can definitely help craft campaigns, right? Like I got, when we first started doing this, uh, I got almost everyone in our company by basically faking a bonus spreadsheet, like with the right people's names on it, saying like, attached is your bonus, like spreadsheet with your bonus information in it right around the end of the quarter.

And I think I had like 65% of our organization clicked on it, right? So I think there's some stuff you can do like that to try to be like sneaky and mean about it, right? But generally, I think you're gonna be working with a vendor and maybe helping craft campaigns. You're not gonna be trying to set up your own anti or phishing simulation and training stuff. Yeah. Yeah.

I think there are some things that you can do that are, that are sneaky and not, like, not like the really advanced, like email phishes, but even simple things like spoofing a calendar and invite from the head of HR with a link in the calendar invite, right? Like when we did that one for our employees the first time, uh, my, my heart sank. Um, yeah. You know, with the, the click rates. But like, you have to do those things because that's how people learn. That's how they get better.

Um, so yeah, I think you have to do phishing simulation, but I guess my argument would be phishing simulation given what vendors provide you is very vanilla. Yeah. That's your best case click rate. You don't understand your worst, your worst case click rate because the, if you're under a targeted attack, those are gonna be very customized to your business. Yep. Um, like you said, they're people's names may be in a spreadsheet and um, they're gonna know some things. So Yeah. Interesting there.

Yeah. Um, I mean, uh, spear phishing is definitely a thing, right? Yeah. It's like, you know, if they want you right, then they're gonna be crafting the messages specifically, uh, to it. Like the most, the, we've been pretty lucky that, you know, the technology we use has stopped a lot of it. But the ones that we've had several clients get hit by are the stupid gift card ones, right? And the, and the people, they, they do a little LinkedIn search, right?

And so they know who the CEO is, they know who they need to be targeting and, you know, they register like a lookalike domain. They register, they take a lookalike email and they email and uh, you know, just the gift card scams there have been, you know, relatively successful because they're not, they're entirely conducted over email. There's no links, there's no documents, there's no anything, right? It's like, I just need you to send you these gift card code to this email address.

Uh, so yeah, it's crazy. Do you, do you see phishing simulation and awareness training actually making a difference in your customers? Uh, yeah. Well, I mean, I see getting fished as being effective at our customers. 'cause man, those customers suddenly are reporting everything that looks like it could even smell like anything. But, uh, yeah. I mean, there, there's a certain amount of it, right?

Like there's, I think it's a fine line you walk because if you do it too much, then people get like immune to it, right? And they get like burned out by it and it's like, oh, that's just another flipping training I have to go through. Right? I think that, uh, I think that the vendors that are out there now, they suffer from it being boring. Right? And, and they, and, and people don't understand. But I mean, it's effective. We have people that report things now.

They're like, this looks suspicious. And they'll forward it over and we'll be like, yeah, no, that's actually good or no. Yep. You caught that. Uh, yeah. And yeah, I mean, it's a thing. Yeah. Can you just, why don't you just tell All your customers that no one's giving them gift cards? Yeah. Just make that assumption. No, they don't want, they're, yeah, that is true. That is true.

'cause they'll get a, then they'll get an email from their sales account team and one of their legitimate vendors offering them a gift card to attend a sales Pitch meeting Yeah. To, to attend a webinar. 'cause that never happens. Yeah. Right? Yeah. Um, attackers mimic real life behavior. So Yeah. My feeling on simulation and awareness training is, it, it kind of helps you maintain a certain percentage of susceptibility and never fully inoculates you. Yeah. Right.

There's always a chance of a breakthrough infection. Yep. Um, Yeah. I mean, there's two classes here, right? It's like the, uh, the dumb ones we're trying to protect against and Right. Like, that's the equivalent of just locking your front door. Right? And, and you know, if we can get the, the 90%, the ones that are just blowing out numbers, uh, then we do good. Right?

But then there's the ones that are, they're targeted and they know exactly what they're after and man, simulation and protection, it's, it's going to, it's not gonna protect against that. Yeah. My thing is, listen, And, and this is where, if I can say something Jason, like this is where process comes into play too, right? Like, if you think about off channel and non-fishing based social engineering attacks, like you mentioned gift cards or wire fraud, aach h fraud, all these kind of things.

Like, and we talked about this in cyber call before, but a lot of that also comes down to like, you know, um, processes around AP controls. Who, who and when can they be made and how are they done with an off channel call back mechanisms sometime to confirm these are things that, like we had processed in place, a lot of that attack surface is reduced. Yeah. I mean, we get, we get phishing phone calls.

Like we had a company call here pretending to be like the Ohio Department of Taxation, and they knew a lot of information and they were, they were trying to become, they were trying to get like account numbers and stuff out of us and we're like, Nope, I'm just, I'm not having this phone call. It got, it ended up getting transferred to me. I'm like, I'm not, I I I need you to gimme an account number. And they're like, well, you know, you gotta tell us the account number. I'm like, Nope.

I'm like, I'll call you guys back. I hung up, I called the Department of taxation and they're like, Nope, you're fine. No one's calling you. Right. So, you know, it's there, there needs to be a lot of this is process, right? It's like, you know, you, you need a, uh, we, we have a thing now that we're implementing, right? Like anything over a thousand dollars needs a po, right?

So like at least there's a PO in the system and we get far enough along the line that, you know, no one's gonna go buy $5,000 worth of gift cards because they're gonna need to be a PO to do that. Yeah, yeah, for sure. You know, I think speaking of processor of phishing simulation, right? Like, um, one of the things that I found really effective is, and I do this at Datto, everyone at some point, including me, is, is going to fall for a fish because it's human nature, right?

We're battling human nature. And you can't change human nature. You can manage it to a certain extent, um, but you know, everyone's gonna have a bad day. You need to be sure you know, how you're gonna respond when you have a bad day. But if you, if you click repeatedly multiple times, if you fail three phishing simulations, you get in-person live, we call it phishing graduate school.

You go to phishing graduate school with a member of our security team and we have a 100% no click rate post-graduate school because we customize one-on-one interaction with those people. Um, and so I think like you can use phishing simulation effectively, but it's more about how you use the data that comes out of it Yeah. Than expecting that the simulation itself is going to be what protects you. Yeah.

I mean, and that goes back down to like something that you've been talking about this entire time here. You can't do that at a hundred dollars a seat, right? Like, I literally can't spend enough time to craft like a specialized training for you if I'm charging you a hundred dollars a seat. Right? And, and so that's why I think you're starting to see a lot of these companies. Like you just, were considerably above that now.

And it gets higher every single time we do it because I understand risk more and more and more. It's, it's like, man, I need more money to do that. Andrew, Gary interject. Joe, Gary, you were trying to say something, but I think you're on mute. Do you remember? He's muted. Yeah. No, it was just a story about the time that someone from Microsoft called me. Oh, yeah. Yeah. And I got on with the guy, I'm like, that man, how do you feel about yourself? Like, this is your job.

Like you probably have a family and stuff, but you're spending your day just, you know, lying to people. And, and, and we ended up getting into like a conversation Do that there's, there's a bunch of YouTube channels out there. That stuff I, yeah. I I tend to watch a good amount of it. Scammer, payback and some of the others. Yeah. That's awesome.

And, and even remember that one guy, I don't think it was scammer payback, but one of them got, he himself has his whole YouTube channel deleted Yeah. Jim Browning because he, he got an email from YouTube support, thought it was real, followed through, authorized him and poof. Yeah. That was Jim Browning, I think his name is. Yes. Jim. Yeah. Yep, yep, yep. Wes you have, uh, a bunch of aliases on YouTube. We even found and Instagram, right?

We had one that did, you know, gets more followers than you Do. Yeah. There's a fake West Spencer on Instagram. Yeah. Full, full of bots. It's I think two underscores between Westminster instead of one. It's got like 30,000 followers. I'm like, holy crap man. It's just all their bots. You Fix it all. They're Just bots. Yeah. Yeah. You know, one thing, Jason, we did, um, at the bank, so my CFO was really, really good at this stuff, like detecting like nasty stuff.

And, uh, he was, so one thing that we would do often, you know, you can see the CFO is any bank by call reports. And so people would look him up, they'd see who Paul Scott was, and they would email him like, it's legit. And he would send it over to me. And we actually had a fake email. Well it was a really email address, but it was fake. We stood it up, it was like accounting@mybank.com domain. And we, I would actually reply and I'd be like, great. Yep, we'll get that through.

Just give us the wire detail and of course it's a mule. So then I would take that wire detail and I would reach out to that other bank and I'd say, Hey, you got a mule, here it is. And they would go burn it down. And then I would go write the scammer back, be like, Hey, that didn't go through. I'd make up. I got wire code 4 0 2 8, uh, error code. They don't know what it means. I don't know what it means. And I do you have another one?

And I just get them to burn through until they finally give up. And um, we, we turned it into a fun game. Uh, and, and so there, but again, all that comes back to process. Yep. Yeah. Yeah. I like to turn into a game. We used to try to see how long, uh, my last security team, we used to try to, we would have them forward the phone calls to us and we would try and see how long we could keep the scammers on the phone like a tar.

Um, because the longer they were trying to work with us, the more they weren't victimizing someone else. I had a team view. So we literally just sit there and, and mess with them for hours. It's, It's fun when they team you into my Cali box. I don't know what to do with it. All right. Alright. I think we're Outta time. We are. Hey, so, uh, Jason, always good to see you, my friend. Yeah. Thanks for all you do for the channel. Um, follow Jason, go see his, uh, presentation.

He'll be with John Hammond. Uh, Felicia. Uh, Chris, thank you so much. And Calvin, thanks for all you're doing, uh, Gary West. Ryan, awesome to see you. Great to have you all back and we'll look forward to seeing everybody very soon. Next week. Make it a great day. You later. Thanks, guys. Care. Bye.

Related Videos