Skip to main content
Right of Boom
January 30, 2025

Data Flow Diagrams, the hidden secret to knowing your network

In this video, a group of cybersecurity and MSP experts discuss the importance of creating data flow diagrams to better understand and secure your network's architecture. They delve into the intricacies of mapping out the relationships between various tools and systems used in an MSP environment, highlighting the need for awareness of potential vulnerabilities and API integrations. By illustrating real-world examples, they emphasize the necessity of keeping these diagrams up-to-date and integrating them into change management processes to protect critical data and minimize security risks.<ul><li>Data Flow Diagrams (DFDs) are crucial for understanding data interactions within an organization, especially for MSPs (Managed Service Providers) dealing with complex systems and multiple integrations.</li><li>Mapping out DFDs can help identify potential security risks and vulnerabilities, allowing organizations to implement better security measures such as MFA (Multi-Factor Authentication) and role management.</li><li>Understanding the integrations and connections between various tools and platforms is essential for MSPs to manage and reduce their API footprint and improve cybersecurity posture.</li></ul>

Guests

Andrew Morgan

Video Transcript

Staff right now. Yeah. Home. Alright, well, welcome everybody. We're just doing our fantasy football picks for next week. Lot of, um, talking, going on here as the, uh, resident Philadelphia, Gary Pika and the Eagles. We'll be matching up against the flair and his Dallas Cowboys. When is that Chris coming Up? That's Monday night. That's a, that's a week from now. And that's, uh, Gary's like the most polite Philadelphia Eagles fan in the history of Philadelphia Eagles. True.

Well, It's not Monday night yet, Chris. Yeah, It's not Monday night. Dude, when I start texting you, you might not say the same thing. That's all good. All right. Welcome everybody to week 66. Um, joined with two really awesome folks. Uh, Chris Laer, solid security. Chris, welcome. Hey, thanks for being here. Yeah, and let be here. Tim, Tim Fernet, or rna, depending on if you're in Louisiana or outside. Tim, welcome. Hi, good to be here. Thanks. Thanks for joining us, Gary.

Good to see you as always. Thank you. Good to be here. Good. And Ryan, great to have you as always. Hey, and, and let the record show that Wes is not here. So let the record show that. Yeah. Wes had come up. So, uh, let's get right on into it. We're doing data flow diagrams today. This is something that, you know, Ryan has mentioned from time to time, and we felt we wanted to do something a little risky and risky. Um, we're gonna be building a data flow diagram live today.

We've got about 30 minutes to do it. We need your help. But in setting the stage, part one, we're just gonna talk a little bit about data flow diagrams, how they might be used for an MSP, what are they? Um, give you an example or two, and then we'll get on into actually building one. Um, so with that, um, Chris, for those that may not know you, I think most people you, you've been on with us and, and you've, uh, become a resident expert here. Quick overview and then I'll go to Tim.

Yeah, Chris, Larry, E-V-P-C-T-O of solid security. We do, uh, cybersecurity and it's in response work for people pretty much throughout, uh, Canada and the us. And Chris, I'm having you on also as the voice of the MSP. And what I mean by that is, at one point your division before getting bought, you owned an MSP, you spun it off and sold it.

So, to, for an anonymity sake, as we start to build out a DFD, I didn't wanna, you know, say, Hey, Tim, tell us all about your infrastructure and your systems and what APIs connect to. What, um, we didn't wanna expose an MSP, um, Tim, welcome. Tell us a little bit about yourself. Sure. Tim Fornet, I'm a CISO at an MSP called Raider. Uh, we're in Lafayette, Louisiana.

Uh, we're about 50 employees, so I don't know if that's small, medium or, or what, but, uh, you know, we, uh, just glad to be here and, uh, here to listen and add where I can. Yeah, thanks for always contributing. And by the way, Tim, the beard is looking mighty dapper today, so I just wanted to let you know that the covid beard is Just keeps scrolling. Ryan, can you set the stage a little bit for people that do not know what a data flow diagram is?

We're gonna use the term DFD, um, what it is, why it's important. Yeah, so a data flow diagram is essentially a visualization of all of the inventory data that you have available and interaction points between the various different components within your inventories. For example, I have a hardware asset and a piece of software and a piece of data. How do the three of those things interact?

And so what it really helps you understand is not really a network diagram, but it helps you understand where data is, how it's in your environment, how it gets processed, how it moves through various systems.

And these become absolutely critical later on when you start to do, um, kind of really advanced cybersecurity things like, um, threat models, risk assessments, um, you know, it starts to integrate into all sorts of other functions like change management, business continuity, and crisis management, and all sort of incident response. Like shouldn't really do incident response if you don't have a data flow diagram. Um, so really just absolutely foundational in my opinion.

Um, before you go try to secure anything, you should start by building a data flow diagram of the thing that you're trying to secure. Alright. And then Gary, you know, let's say an MSP gets a little command on this, and again, they, a lot of MSPs out there may not know what we're talking about by the end of today they will. How might that impact, you know, you talk a lot about putting a wedge in prospecting and things like that. What are your thoughts?

Yeah, so when you're working on what people are gonna see today, uh, it's process, right? Um, whether it's with a prospect or even with customers the same, it's the same process. You want to use samples to be able to explain to people, um, why if it's a prospect, why they have risk today that they wouldn't have.

So a sample data, float diaphragm, a diagram, a sample, um, you know, strategy roadmap, a sample, uh, view of standards and alignment, these kind of things, um, really start to separate you and with customers. They show the things you're doing today that maybe you weren't doing a year or two ago, and why you both have to make this investment, uh, in order. So it's easier just like standards, it's easier to tie process and standards to results than just when it's nebulous. Yeah.

Does that make sense? Yeah, it's a great answer and uh, it, it certainly will set the stage certainly more for when you are also talking about maybe different solutions on, Hey, here's your most critical data, here's why we're talking about it. You know, so giving some context to, you know, why you want a preventative control.

And then it's clear that if you, if it's in a prospecting standpoint, it, it's, um, uh, it's clear to them what you're doing is different to what you're experiencing today. That's the wedge. Yeah. Right? That the reason that your customers get different results is because of this and a lot and a lot more. Yeah. Very true. Chris, um, talk to us a little about, um, from an incident response standpoint, if you could wave a wand, would, would people have a DFD?

And why is it important from your perspective? Yeah, there, there, there's a couple perspectives from an, from an IR perspective, definitely having that diagram. I mean, we ask people every time, do you have a diagram that shows what's connected to, to where and whom and every time? No. Um, it's unfortunate, but it's, especially, it's important in today's world.

And we'll get into that in a little bit about who's connected to what, especially when you come down to regulated data, we've had a lot of cases, uh, where people are receiving data feeds from different entities. And if you were able to identify those entities where you're receiving data, those would be the entities you'd be most concerned about notifying, uh, when you have a breach. So there, there's just a lot of value there.

And the other thing I like to tell people is, is when you diagram something, uh, when you're forced to diagram something, it forces you to make, make something make sense. If that makes, so like I always say it's the audit test. Mm-Hmm. Auditor needs to see something on a diagram. And if you've created something so complex that you can't really properly diagram it, or a third party can't really, like an auditor can't really know what's going on, then you probably made it too complicated.

And so that's why I like, you know, having that diagram there is just kind of more of a, a test of complexity, if you wanna put it that way. Yeah. It's the old auditor's Role. If it's not documented and it's not written down, it didn't Happen. Yep. And if you can't explain it, that's just as bad. So. Alright.

So part one, part one, and setting the stage here, Ryan, I'm bringing up, um, let's see if we can all see mural, which I think we can, and I'm just going to go, let's see, we got lots of stuff here, so bear with me folks. I'm looking for here it is up top. We're, we're first gonna use simply an example. It went black, it went black real quick for some reason. Yeah. It it's all black. It's black, you can't do it. Yeah, we just see the cursor. Okay. Bear with me, try again.

You Saw it and then at the right as you got up to the, to the Uber diagram, it went black. Went Black. Okay. Let's try again. Let's try this again. I might have to just pull it down. Maybe it's outta real estate or something. So bear with me guys. Okay, that looks good. There you go. Yeah. Perfect. So part one, we're going to use an example for two reasons. One, we want you to see what a data flow diagram looks like. They obviously are their standard, uh, shapes and, and things of that nature.

But more importantly, we wanted to use an example that as consumers you all are aware of. And then from there we'll move into an example that an MSP deals with around customer onboarding. So, Ryan, not that we need to maybe, you know, go, you know, line by line here, but we kind of articulate why this is important. Why would an Uber wanna do this? Yeah.

So I would say these kind of pinkish orange-ish circles in an MSP's world or an SMBs world would be the assets that they're protecting, whether it be software, vendor solutions, um, hardware assets, et cetera. And the arrows between those blocks are the relationships between those things. And a data flow diagram, the, the largest amount of value is actually in mapping the relationships. Um, I've been through exercises with MSPs on a, on a whiteboard actually.

It was like, it was a glass conference room wall, four, three foot panels wide mapping out their entire ecosystem. And by the time it was done, it was a rat's nest of relationships. And they were like, we have never seen this written down before. We have a lot of work to do. Um, and so just taking those things you already know you have from your inventories. So especially if you're moving down the CIS VA controls implementation group one, right?

You've started with your inventories, pulling that out and then starting to add the relationship information is really what this is. And the Uber example, right? It makes sense. We have, um, we have customers and we have drivers, right? And then those, those people take an action or they, they engage in some process. And then that process is actually what creates a relationship between multiple, um, either multiple processes or multiple assets.

And so really that's all we're trying to capture with the data flow diagram. Pretty simple. Excellent. And I think, you know, making this even more simple, if you've ever taken a database engineering course, right? A relational database engineering course is effectively the same thing. I have tables and I have a schema that tell me this data in this table relates to this other table in this way. Think of it just like a database map, right?

You're just just mapping out different pieces of information and how they're relate to one another. So Ryan, I have a question for you. Yeah. Um, I, I'm going to guess that, you know, based on how MSPs do business, like whether you, you are a, um, small, medium or large MS p probably the level of complication and the reason to do this is the same for everyone.

'cause even, you know, an MSP that's, you know, uh, would be considered on the smaller side, they have a lot of the same is like relationships, right? They do. In fact, one of the things we found, we did, uh, we did something called the information security analysis program, uh, back in 2019 pre pandemic. And we went into this hypothesis that small MSPs had different security challenges than large MSPs. And we disproved our hypothesis. What we proved was small MSPs have the exact same issues.

Large MSPs have large MSPs just have them larger, right? They have more tools, they have more integrations, just more, and it's, it's basically the same, like, you know, it's just a spectrum, but you, you all have relatively the same set of five to 10 tools and those all integrate in relatively the same way. And that is unfortunately where most of the risk comes from, is in that core five to 10 tool set.

And that's actually what we're gonna explore when we do the building the data flow diagram by hand in, in a little bit. Ryan, I can't see you guys 'cause I'm, I guess sharing, but what I would say, what we found out is it's actually, you know, five to 10 maybe core tools, but then the ancillary tools MSPs have even a, what we consider a, you know, 20 employee Ms. P, there could be 40 different solutions tying APIs into those. So stay tuned on that. Yeah. Um, okay.

I think, I think I said Andrew, we did a little benchmarking and the average, um, was like 27 tools Yeah. Across, Across our peer group. Yeah. And that's, and I would say that's, that's common from what I've seen of a medium sized SP right? Maybe 20, 30 people across sales and tech, um, and maybe some business leaders. Like 20 to 20 to 40 is usually right for about a medium sized MSP, um, 10 to 20 is almost like table stakes free, even a small MSP.

Yeah, I think, I think Ross had a good question that came up right now was, you know, who does the mapping prospect MSP, when does this process occur? And, and what, and what we're saying here is, is like, we're about to jump into this diagram, but we're gonna preface is that there, there is the data flow diagram that you're gonna have in place and documented as an msp and you're probably gonna have multiple ones, right?

So you're gonna have, you, you, you need to have data flow diagrams for yourself. So it's very similar to when we talk about IR plans, right? We say you gotta have an IR plan for your, as you as an MSB that gets popped. But you may have to have a separate is, uh, uh, plan for client or clients or whatever the case may be. Data flow diagrams is not gonna be one giant diagram, in my opinion. That's, that's onerous and, and tough to do.

But having some typical data flow diagram, which we're gonna get into in a second to be able to share with your customer, your new customer or whatever, just to show the relationships and what's going on there. Now, if you want to get into more of a professional services stuff and start documenting things, and you're asking, well, do we charge something like that? My my point is, is that depends.

But my my point is, is doing a data flow diagram with your, with your, with your new customer is gonna help you understand all the moving parts as well. And so it's, it's, it's almost like a documentation process that you should do. Uh, how you charge for that or whether you charge for that is, is up to you. And Chris, You know, Go ahead, Andrew. I was gonna say to Ross's point, you know, should the customer be engaged? I think that was part of the question. Is that correct, Chris? Uh, yeah.

'cause it flowed down, right? Uh, he just says, is this a chargeable event? Um, who does the mapping? Yeah. So obviously you're gonna have to get input, right? Because a lot of these things, you're not gonna be able to run the tool that's gonna give you all the discovery on that. It's not that simple.

Yeah, my my argument is your lead tech should be in this meeting because you're gonna have a lot of questions about, well, what things have access to what and, and your, your knowledge might be outdated. And so I've been, I've been in data flow diagram exercises with MSPs with their business owners where they're like, yeah, I don't know, we need to talk to Soandso. And by the fifth time, uh, 20 minutes in where they're like, we need to talk to Soandso.

I'm like, is Soandso available to come in and sit with us and do the diagram? And they're like, yeah. And the next thing you know, they clear their plate for an hour and a half and we're building a diagram that they've never seen before. So your lead tech, they might actually need to be fingers on keyboard logging into things, looking at integrations, and like, your lead techs need to be in on this.

I, I'll tell you what it triggers when you do that, it triggers a lot more questions that are, are really relevant. And so in the incident response situations, and, and, and there are a few that very recent that I can cite as examples where they've had these relationships with somebody that's providing them some type of data, usually in the form of some file, right? A CSV or something, nothing fancy.

And they get those files daily and they process, well, they know they get files, but one of the que one of the answers they don't, aren't able to answer is what are all in those files? And when we find out there might be a hundred fields in these files that they're getting, and they might get a thousand records a day or whatever the number is, it doesn't matter. And they only need like four fields. And you're like, okay, so the other 96 fields or whatever you don't need.

And they're like, uh, well, we don't even know what those fields are. So they have no idea because they've just, it goes back years or whatever the case may be. And we'll kept in almost every one of these cases we've had, it has healthcare. Well, the person who's receiving the files, who's usually the victim, the fields that they need have no diagnostic information or none of that stuff.

However, all the fields that they're re all the, the, the files that they're receiving have those fields in them, and they don't even realize it until after they get popped. And then the attorneys start to ask 'em these questions, they're like, holy moly, we have diagnostic information on all these people that go back. I mean, I have somebody right now we're dealing with the data goes back to the year 2000. It's a six man operation. I asked them how many unique patient records they had.

I figured, Hey, it can't be that many. 1 million. And and what's the cost per record these days, Chris? Oh, I don't even, uh, what is it now? I mean, 1 65 according to, Yeah, various, I was gonna say one 50 and two 50. But I mean, that's the deal.

And so think about having to, if you're a 6 million operation, having to do notifications on millions of people, and if somebody had sat down with them ahead of time and actually started asking these questions and they could visualize it, then they would probably have that oh, crap moment right then and there. But unfortunately for them, their oh crap moment was after they got popped with ransomware. Got it. So Chris, can you guys see the new customer onboarding? Yeah, It looks great.

All right. So, so we're gonna go from, okay, Ryan, set the stage using Uber. Chris, next thing is we're gonna talk about, you know, using an example that all MSPs can relate to, which is onboarding a new customer to then the last half hour, we're gonna go to a different system and actually build some stuff on the fly. And I think it's gonna be really eyeopening when we get to part two here, the number of systems.

And as Ryan point out, the integrations, the APIs and the threat vectors they pose. So with that, go ahead, Lynn. Yeah, sure. So, so this is a real just quick high level example, uh, of just kinda saying, Hey, look here, a new customer, here's kind of the moving parts we have in your environment.

And so we're gonna come into your environment and whether or not you're, you're taking over for another MSP or not, it's these types of things and you're showing, you know, you're not getting too detailed because again, you want your, whoever you're, whomever you're speaking with, uh, to be able to understand that. So making the di the diagram, what I call consumable, is a very, very important part of this process.

So as you can see, have a new customer here, and we have some simple data flows of in and out of where data's going and what type of data it is. And so, again, you can make this thing really complicated and junk it up, but the idea is to say, Hey, look here, we're gonna be connecting you up to these particular systems on our side of things, and these particular systems are gonna be doing these particular things for, for us and for you.

So it gives you an example of like, explain it to them why they put a trouble ticket in and, and when they put a trouble ticket in how things work. And you also are gonna get other trouble tickets from other systems because from an automation perspective, from the things that you're monitoring. So you can show 'em in this diagram, explain your business processes that you're doing to support them, and you can show where all this data's kind of moving in and out.

And then you can kind of, and these are just the major points. Yeah, the PSA, the RMM, you know, we didn't include stuff like EDR and that kind of stuff. Again, we can get kind of crazy. And then there's some 365 stuff on here as well, kind of in those, those blue hexagons down there. And so the idea here is that once again, say, Hey, here's what's going on. Here's where data's going to and from in and out, those types of things.

And just so they can kind of understand how things are moving around and what data is going where, and being stored where. Chris, I think what's also important here is I think more and more MSPs are going to be asked about what systems are touching their networks. Um, you know, we've got CISA making it loud and clear as quote unquote in their latest document on risks MSPs posed to your business.

And, you know, depending on that customer, whether they're regulator or not, this would go a long way. And being able to also articulate how you do secure your RMM differently as an example. Thoughts on that Chris and Ryan? Just and, and me and Tim too. Love, love your input. Yeah. Tim, you wanna, you wanna take that one since you've been quiet for a little bit? Yeah, sorry.

Um, yeah, I mean really it, it shows, I think what happens is once you start to go through this process, you think about where the data is and where it's flowing, and then more things start to pop in, you know, so you'll see, you know, someone's mentioned like their documentation platforms and reporting. So those things you may not be thinking about whenever you first start to build this diagram, but then you, it puts it in there.

You start to, to identify, Hey, I've got this other system for documentation. I've got this client portal, I've got this thing that sends alerts to this other tool. And you know, when you start off with something very similar, then you start to realize where everything is and where your exposures are. Yeah. That's excellent. So with that thought, I'm going to flip back here. Scroll up a little bit.

I'm going to come over and put up a poll that Ryan challenged everybody because, um, take a look at just a few of these systems that you may have and are there APIs that might be went black Again? Andrew. Oh really? Yeah. Then paid to black Try. I think it's if you maximize it or something. Okay. One second. Let's see. It's black. Yeah. Do you have it in, uh, presentation mode? Maybe I would take it out. If it is One second. Try it again. Bear with me guys.

Today's cyber call is sponsored by Action, by the way. So I'm putting up, please look at this poll that just went up and please answer it if you would, because this is gonna be really important, um, coming up here, uh, to, um, your threat vector. So lemme try and share again here. The pressure's on, I know. Alright, So Chrome, let's try this. Tell me if this is any better And no, uh, try this one more time. While you're doing that, can we talk through the poll? Yeah, please, Gary.

So, um, Uh, well this was good. Okay. Did you reduce your API footprint by 10%? So it's good. Uh, Ryan, you can feel good that we got yeses so you can feel good about that. Um, didn't get as many yeses as we should have, right? But, um, at least 16 people here, 30% of the people. Uh, the other thing on the data flow diagrams, Andrew, 80% don't utilize them. And so what I was thinking was, you know, think of all the polls we've done, no data flow diagrams.

80% of the people weren't asking their customers anything about their cyber insurance. After last week's call, I had a conversation with an MSP, they didn't even know what ms. Uh, HTML was. So they don't have any threat intelligence. So we keep adding on all these things. Andrew, I hope this is coming through and this is a great example. Today. We, we got work to do, man. Yeah, absolutely. Can you guys see this now? Yes, it looks good. Okay. So this is gonna be a working session.

Ryan, if I click over to this window, can you still see it? Yeah, can you hear me? Yeah, now we can. I've been having mic issues for the past 10 minutes And if I, if I move this up and down, can you see it? Yeah, it looks good. Okay. So I don't have visualization of Tim. Maybe you and Chris can help the comments and Gary. Sure.

I'm gonna be moving this based on Ryan as he and Chris walk you guys through this exercise, but, so I have to stay on this window so I can make sure, because if I stay looking in the upper window, I can't actually move this for Ryan. So, Ryan, go ahead. Yeah, so the example we just walked through would be what I would call a zoom in data flow diagram. There's a very specific business process for which we wanna have a data flow diagram.

When it comes to your PSA and your RMM, you're gonna have a number of, uh, processes that you're gonna wanna do Zoom in, data flow diagrams on. What I tend tend to do with MSPs, and, and my team would laugh right now because I say this all the time, the first diagram I want to do is the one I call explode the problem. Um, you wanna put as much down about your environment, your systems, and how they interrelate as possible.

And then eventually we're gonna get to a point where it's so painful that we have no choice but to do a zoom in, right? Oh, man, I have 40 things connecting to my PSA guess what time to do zoom ins on PSA. Why are all those 40 things connected? Are they all for the same process? Are they for different business processes?

That's an indication that you need to do a zoomin, but what we're gonna do right now is the highest level data flow diagram, um, that we can, so what I wanted to do is take five minutes, um, we're using an app called Mural for this. Um, it's a free tool. You, I I answered the question, the questions. You can use Microsoft PowerPoint, you can do Google Slides. I've literally written data flow diagrams on a sheet of paper and pencil and taken a picture of it before. Like, it does not matter.

Do not let the tool stop you from doing this exercise, right? In fact, if the tool is getting in your way of doing it, it's not helpful. Throw the tool out and do the exercise without it, and then go back and import it into the tool later, or have someone else do it. So what I wanna do is I wanna spend the first five minutes on inventory data. RA and I spent 10 minutes earlier today kind of brainstorming what are some of the common components that an MSP might see in their ecosystem.

And so I kind of, you know, I kind of bucketed them into like hardware, asset inventory type of, uh, controls, um, some software inventory potential, um, SaaS vendor type of controls. You have a large security vertical there on the third set. And then kind of this, I'll call it more like your e-commerce, your business process, um, type of vendor relationships there. So what I wanna do in the next five minutes, tell me what we're missing.

What is a tool that is missing from this list that you feel is in the large percentage of MSP's inventories? Tim, Chris, you, uh, keeping an eye, Gary? Yeah. Yeah, we are Probably a 22nd or so delay on chat, so I'm sure people are responding for whatever reason. Uh, Crowdcast has that slight delay. No, that's all right. Yeah, I think, um, one of the things that we could put on here that's not necessarily customer facing, but still, uh, MSP is whatever they're using for an HR tool.

So we have QuickBooks on there, but there's probably an HR tool that can be put on there as well. Yep. I love the outsourced, Like a Paychex, Chris and adp. Yeah. Outsourced. That's good. Outsourced, uh, support or knock. It's really good. I, I've seen that in probably one out of two or three MSPs where I've done this. So, um, Somebody said, Sam, we have that at the top. We have AV on there. Yeah. Rapid fire quoting tool. Yeah, quoting tool's. Good. CPQ is in here somewhere.

I Actually have it over Here. Maybe like a chat tool like Slack or Teams Collaboration tools. That's a Collaboration. Awesome. Great. Great call up. And your phone systems like, I guess it would fall under there, but, uh, you know, your unified collaboration, your, your, Your phone, just your voice. Yeah. Lots of Juicy data in there. Someone mentioned dashboards. There's a bunch of dashboards out there like that plug into everything. Yep.

I mean, we've got that on the second column, but I think it's worth notice, uh, mentioning that you may have multiple of, a lot of these, you know, you may be using Bright Gauge for some dashboards, power BI for others. And so it's important not to, to just say, I've got this one tool and this is what it does. Looking at multiple ones. So I have M 365 here. I was kind of keeping that as a placeholder for like email, but there's, I guess there is an email security layer here that you could have.

Someone said, uh, zoom, How about your diagram software? Let's Good meta with this. Yeah, lucid, uh, Tim, Jason about that. Hey, why not? Um, Okay. Oh, I just have One. I'm gonna put, I'm gonna keep Zoom in the collab tools. Um, Yeah, somebody mentioned CRM. So, uh, you know, your CRM and then your, uh, social media accounts. I don't know if you have That IP now, right? They have a separate CRM from PSA, Gimme an example of a separate CRM hub. HubSpot. HubSpot. HubSpot. Yep. It's number one.

Definitely seen that. Yeah, I don't know how many use Salesforce, but that's, you know, Salesforce and Fusionsoft Soho. Uh, bandwidth connectivity. So like your, your ISP, uh, a lot of MSPs use tools with their, uh, ISP brokers and things like that. So ISP management. Mm-Hmm. Okay. Should we keep going? I think we, oh, vulnerability management. That was one that I thought of earlier that, that Tim G mentioned. Yeah, somebody mentioned their bank. I think it's, that's a good one. Yeah.

Yeah, Ryan, I got one when you get a sec. Yeah, go for it. So I'm thinking like, let's just choose no before or conce, but with no, before you know how it's, you basically, it integrates with your active directory. So at an API level, even though it's like, Hey, we're doing security awareness training and phishing simulation, if that API key got compromised, couldn't that be a big threat? Again, if, if it's in your vendor inventory, it should potentially make its way onto a data flow diagram.

So totally valid. I mean, that's a good point Ryan's making. There is, it should be in your inventory, so you should document whether or not it connects or it doesn't connect. Yeah. Uh, so there's no doubt, right? You have a vendor listing, let's just say it's 200 vendors. You should have something that corresponds with, with, with some, with every one of them. And if they don't, if they, if there's not a connection, so be it, but diagram it anyway, that there is no connection there.

And that's a good Sounds, that's a good point to add on as well, is, you know, and doing these with some of our clients, you know, there may not be an automated process to, to connect data from one piece to another, but they're manual processors. And, and when you have these interviews and discuss, you know, Hey, where does your data go? You know, you may have a user say, Hey, I, I, I, you know, get this email and then I go to this web page and type in the information they sent me.

And that information is just as, just because an automated process isn't doing it, that information is still just as valuable and just as important to document. And you, these are things that you may not ever, you know, notice on your own. Okay? So this is, we have more here than we can reasonably use in the next half hour, but like this exercise we just spent, what, five minutes and we threw out what's the name of a tool we use, what's the name of a tool we use?

And we just started making a list. Congratulations, you just started building an inventory. Right? Now, the next step of having the inventory is starting to put things down on paper. And the place I always love to start is the absolute center of the MSP uh, practice, which tends to be your PSA and your RMM. Everything tends to spider off of those two. Those tend to be your most heavily integrated platforms, uh, at MSP with a few exceptions, but for the most part, that's true.

So we threw a quick example in here, might be slightly hard to see where we have the CPQ system, which is a common integration between your PSA, right? And then from a process perspective, you will do an order from a distributor, right? And then that'll generate an invoice to the customer. So that is, um, in a, in a true like Zoom in, uh, fashion, that's like a zoom in on a specific process for PSA.

But in general, for the, the high level one, I'm just gonna move this off over here for now because all we need to know for the high level one is that there's a CPQ integration with the PSA, right? So let's take, and I'm gonna avoid kind of doing the, um, or maybe if Tim wants to do it, maybe he can, you know, build us a little MSP network, um, over on the bottom right hand side. Um, uh, but let's look at other things that are commonly integrated with our PSA, right? So gimme some help here.

We commonly have document management platforms that are integrated with our PSA, right? Absolutely. Yeah. You're gonna have, uh, that quick, that QuickBooks. Usually people have stuff going from your PSA to your QuickBooks. Yep. Right, right. So now we need to pull over, It's right there in the middle. Third column. I, Tim, you are working on that, uh, network bud. Um, trying to figure out the, uh, interface here. Okay. Yeah, you, There's a slide on the left. Yeah, there you go. Gonna, Okay.

So we Can drag them. If you, uh, if anybody watching this has a motion sickness, uh, you're on, you're on on this, Chris, we'll send out Dramamine virtually. I'm, I'm, I'm just gonna start moving stuff around, so my name goes in there too. All right. So now we have a PSA integration with QuickBooks. What else is Add? CRM? So if we put the CRM over there, uh, the CRM, right? So we can have our CRM, Are we connecting all these together? Yeah. Com quoting would be common.

Um, keep yours in the lower right. Oh, okay. For now. So that lower Left? Yeah, pull over. Um, what about warranty master scale pad? Doesn't that tend to integrate with our It does. Yep. Okay. So that one should go in here. And we're, we're already starting to run outta space on our diagram of all the things our PSA's integrated into and No concerns about APIs. Correct. Uh, there, Ryan? Um, I mean, I don't know why any MSP would be concerned about the level of API integrations they have.

Um, Well, I mean, it's a good, it's a good question because, you know, from, you know, we, we've been through the trenches on this, right? And you used to have just these integrations between PSA and the vendors, right? And then you start to have, but some, some of these systems have a third party that is the, where the API sits, or the third party is where, where stuff goes. So there's some type of broker or something involved in the middle.

So at this point, I think in the exercise, the way Ryan's doing is just identifying the moving part, the the entities that are involved with the, the systems. But then, yeah, you're gonna dig deeper into how the hell things happen, Right? So then, uh, external knock, right? That tends to have access to our PSA, right? Yeah, absolutely. Mm-Hmm. Um, Ryan would, would co-managed be a box, so the co-managed customers that might have service ticket queues that actually are in literally your PSA?

Absolutely. I mean, anytime you're giving a customer access to your platforms, they should be an entity that goes on the diagram. Again, it's in their opportunity to zoom in, what specific workflows are they working on and how are they accessing that platform? What privileges do they have? Are they doing it through an integration through the native interface with roles and permissions, et cetera. So, um, so maybe we have some co-managed, uh, SMDs here.

Um, It's more typically the larger, like the mid-market ones. Um, and Tim and Chris, please feel free, or, or Gary, you know, Gary, you probably had some, uh, at the, with DDS where they might have access, literally literal access, just like your employees do. Yep. Um, Yep. Absolutely. Definitely. So what about, uh, our, our e-commerce platform, is that integrate with our PSA typically Like a connect booster? Tim, as an exam? I'm sorry, Ryan as an example? Yeah.

Does that tend to integrate directly with PSA or indirectly? Directly Right here. Okay. So we, we get the point on the PSA. Let's, let's change our attention to RMM. What integrations do RMM typically have? Yeah, Your AV it usually controls that. So we have av, it's kind of, uh, Remote control. That's a good one. Yeah. Oh, that's interesting. We didn't have that on the list. I can't believe we forgot that.

Yeah, somebody mentioned that in chat after we got started, the next phase, but that's a big one. Yeah, Yeah, Yeah. Your splash tops, your screen connects your, yeah, that's, that's huge. Um, what about your, some of your password management solutions? Do they, is that where they're gonna integrate as well? Um, There's not usually a ton of integration there. Not Typically. Uh, you might see some of that with A PSA, um, but not typically there.

We, we have ours integrated, basically just with Azure AD for identity providers. How about, um, there's a box in here somewhere for network monitoring and management. Yes. The oex the logic monitors of the world. Yeah. It's a common thing that we integrate, right? Yep. Um, Chris, gimme an example of a, of an RMM integration that you've seen compromised at an MSP.

Well, I mean, obviously we had the, the ones from we a couple years ago where you had the, the PSA situation with, uh, K ConnectWise. Um, trying to think of some others that would be an integration issue. Oh, here's, here's a great one. Um, where's our S-S-O-M-F-A bucket?

Well, you know, and I, I think one of the, one of the interesting integration ones that you, you have it on here, but this is where, you know, it hasn't happened as much, but we've had tons where, you know, the RMM, the, the AV because of the integrate, because it integrated with the RMM, the AV had certain directories whitelisted as a result of that, and the attackers took advantage of that.

So this is where you want, you know, when we're doing all this stuff and you start to understand these integrations, this is where you wanna understand the value versus the risk of an integration.

And I think AV has always been that one, especially since we've had these, these Buffalo jump type of attacks where you say, Hey, this is a great, there's some efficiencies we get out of this integration with av, but at the same time, the AV may have, again, some bypasses or some white listing or something of that nature that creates more risk than the value you get out of it. It's actually a pretty great tool, Andrew. Um, it's a good find. Um, all right, so now I wanna make this a rat's nest.

Let's add in a really complicated tool like breakage. What does breakage have access to? Access? You want the integration PSA, Uh, Documentation, Right? Well, let's say, so we have a BDR platform, right? Let's take a, let's say our BDR platform commonly integrated with our PSA case. There's issues with our backups, we need to know about it.

But then, hey, well, so yeah, this thing's integrated with the BDR, but it's, it's also integrated directly with the PSA and it's also integrated directly with the RMM. So we need to have an arrow from there to there. Why? When we look, if someone wants to even like look at their, the URL on and they have an integration, it's pretty much anything in your MSP that is significant. Yeah, yeah.

Basically my point is like, when you add in a breakage here, and breakage is just one example, I mean, I'm not picking on breakage. This is gonna start to map to everything because it is one of those tools that you're giving access to every single one of your platforms in order to help you monitor it and manage it, right? So it's kind of an add-on, uh, kind of level of visibility to your RMM. So I want you to just keep that in mind. I'm not gonna draw all the arrows.

I'll draw enough and make it uncomfortable, um, for us. But, um, yeah, it's, it's definitely scary. Um, so what do, what do we think is big that we're missing here? Oh, we, we don't have our email on here. Where does our email integrate? You know, Brian, while you're doing this, you know what I'm thinking to myself, you know, we asked, uh, you know, we put up a poll question and, you know, 78% of MSPs aren't using these.

Um, if we did that same poll of bad guys, what percentage of them do you think have data diagrams for the average MSP? You think they have? So Andrew and I were talking about this. There's a, there's a step in the attack process called reconnaissance. And my question to you is, what do you think the attackers are doing during reconnaissance? They're doing this. They, they have a better diagram of your network and your integration than you do. It's really intuitive, Gary.

That's exactly what we're talking about. So what else, um, does our CPQ tool commonly has email integration, right? Yeah. I mean, pretty much You are. I mean, the HubSpot's gonna have it. C m's gonna have it, EV has an integration with it. 'cause it needs to send us alerts, right? Everything needs to send us email alerts. Why?

Yeah, Just one thought because you just mentioned like C-P-Q-P-S-A and for example, um, well, so think about adii, um, a, a good like, you know, PAX eight who's awesome that you know, that you can, you know, get information, you know, real time about, you know, your, you accounts, right? For Office 365. But think about, Chris was mentioning third party. Um, would that be one you'd wanna, you know, again, put out there to go, okay, well, how are they accessing and what APIs are talking?

Uh, yeah, for sure. Let me, um, okay, I think we're gonna wind down on this. 'cause I think the point is made right at this point, uh, insult injury. Um, Andrew, maybe save a copy, put it in, um, cyber Nation. Yeah, absolutely. Gary, what are your thoughts? As you know, I kind of posed to about a pro, you know, our, our quarterly, uh, event, like where we could maybe do an, you know, collaboratively with the MSPs.

Yeah, I would probably wanna do some prep stuff so we wouldn't have to do everything on the fly. But, you know, I'm thinking about it from two perspective, like a deep dive like this for, for the MSP, they're gonna find immediate value in. But also thinking now about this process with each of the customers and, and answering the questions that somebody asked today. Well, do we charge for it? Do we not, who does it?

What does this line up with with other things, other roles need to do where it fits the best? So I I, I'm thinking about it from both perspectives. Yeah, I, I like that too. I mean, just the simple thing, again, we took the healthcare example that Chris gave. If you have a healthcare client and you're just kind of mapping out a simple DFT for them and asking 'em how many records they might have, do they even know? Do they know who has access?

Does a third party Yeah, like if you scroll down real, real quick while they're working on this, Andrew, below the data flow diagram, I even, and there's some good stuff here that Ryan did, but even below that, uh, to the left, I think right here it's nice and big. This is where I just did one, and this can help you just think about things to get it started, right? Is, and this came, comes up a lot in the banking, is this fourth party risk.

And that's where you guys were talking like PAX eight's a good example. So you have your 365, but then you have your CSP requirements with PAX eight that have some access. And so when you're talking to your, your customers, you might just be talking about your, you know, you may not wanna get in the systems, you may just wanna talk about the parties involved. And so you just start, you know, mapping out the parties, right? And this one's I, I did it is just real simple, right?

You, they have a partner. So right to the right of the customer is the partner. Well, they might have multiple partners, like in the healthcare examples I gave you this particular company, uh, they did some, they do some type of invoice audits for healthcare facilities.

So they have, when they, when these healthcare facilities go out and buy equipment, uh, there's some sales tax and stuff that can be audited and sometimes they can get some refunds based on if they were overcharged sales tax or they shouldn't have been charged sales tax, so on and so forth. So they get all this information and, and again, they had more information than they needed.

Well, they have multiple partners and some of those partners are active, and some of 'em, they haven't done work for 10 years, but they still have data on them. So that's where you wanna find these things out. And then at the same time, and I put some, that's why just use this little icon of a question mark around fourth party is, is like, you know, for us as an MSP, you know, who are the fourth parties, right?

I mean, we know that we're, we're, we're leveraging so and so, but do they have somebody that's watching their stuff? I mean, that happens a lot. Like who's your vendor's? MSP as crazy as that sounds from a banking side, it gets asked all the time. We want to know those connections. That's, that's how Target got burned. And they always get brought up as an example. And I think they'll get brought up as an example all the time.

And so, so this is just, if you're trying to figure out how, where do I start and that questions come up, where do I start? You know, how do I get the juices going, whether it's in your organization or it's with your client, that's, you just start talking about the parties involved. And then you can start digging into, well what, what are parts of those parties? Are they OnPrem? Are they cloud? You know, blah, blah, blah, blah, blah.

Because you wanna know if if you're, if you're partner that's US based leverages outsourcing in the Philippines for something else. So you want to know those types of things. Chris, you mentioned one thing that I'd like to again bring up maybe to Ryan, but, and you as well, is we didn't mention things like an Avalara that, 'cause you said tax information. Mm-Hmm. Well if, if that, if Avalara got compromised, boy, you have a lot of tax information about that MSP do you not? Well you do.

And I'll, I'll give you another example. 'cause we've had quite a few of these. So, um, it's been a couple of years, but we had, um, a lot of, uh, CPA firms, they'll get these notices in from the IRS or whomever said, Hey, look, we found something in common with your, uh, they have, uh, their tax prepare id, right? So when your CPA, they have like, um, a number, a little ID that they put on when they prepare your taxes.

And so the IRS notifies say, Hey look, we got all these people that are claiming they have fraudulent returns. So somebody did a return, got money back, and it wasn't them. And they said, we tracked it all back down to, you know, a tax prepare id, uh, T-P-I-N-I think in, in your organization. They're like, man, you know, we must have been breached. We must have been breached. Well, it wasn't the CPAs that were breached.

It was, there's a, there's a processing company that these CPAs use to, then they, when they're done with the returns, they send all the returns to this company and this company then sends them to the IRS or whatever the case may be, is, so there's a, it's kind of like a somewhat of a piece of software, but it's also, so to the CPAs, they just thought it was a piece of software, but really it was a third party processor that was processing it.

And it was the third party processor that actually got compromised. And so when we started to dig and research, lo and behold, yeah, I mean that third party processor, you know, announced a year ago that they had been breached, sent notifications out to everybody. But of course, what did they do? They just throw 'em in the trash. So I mean, that's a great, that's a great question you bring up Andrew.

'cause that's a real world example here where people just blindly have been using that vendor for years. And in this case, they actually were notified of the breach, but they didn't take action on it. Ryan, I want you to take over, but Chris, quick question to that. Mm-Hmm. Let's say I, that did happen a year ago. I wasn't using the fir this, you know, pretend it's Avalara just, or, or you know, in this case as a new client, do they have to disclose that to me?

I signed up today and if not, what process again should I have in place? Should I be asking This? Yes, no, it's a great question. And the, and the answer is no.

Meaning like, like there, there's no obligation for them to tell you unless, you know, you start asking those questions from a vendor due diligence standpoint or you do your research, and I know we've talked about vendor due diligence and other ones, but that, you know, doing your research and, and just doing simple osint, open source intelligence searches on companies usually will reveal something about them.

And so, uh, they have no obligation to tell you unless you were a customer at the time. So you need to do your research or just ask that question upfront. Are there any, you know, previous breaches in the last five years, uh, of your, of your company? And if so, can you explain what happened? Got it. Ryan Floor's yours here. And we're Right. Can you pull in the threat models? Um, I don't, I don't know if anybody else can see it. It's kind of hidden behind our faces for me. Can you See it Okay?

Maybe zoom out a little Bit. It just needs to be moved up a little bit and zoomed in. Okay. Bear with me. Um, Zoom, zoom Out. Zoom out, right? Yeah. Uh, Well, no, no. Well you wanna, you wanna see the threat models within the diagram or you just wanna focus on the Threat models? No, I want the diagram. I wanna see the diagram and the threat models kind of on top of each other side by side. How about now? Uh, it's kinda ugly, but we can work with it. Yeah, let me just, All right.

So like, now we have a data flow diagram, right? And granted this might not be a hundred percent accurate to your MSP. So what do we do with that diagram? What I do with MSPs when I sit down with them is I say, show me your data flow diagram. They don't have it. We do this exercise, we literally take an hour, sometimes it's three hours depending on the MSP and we build it and then we go and we threat model it. And so I ask myself, what are the ways that MSPs are getting compromised?

Well, one is, uh, MX. So first question, does my RMM have MFA enabled? Yes or no? Does it have MFA enabled for everyone? Because I've seen a lot of people where this co-managed external NOC also has access to the RMMs, but they use a shared account because they use a shared account. They can't do MFA. And so the very simple question like that go through every single user in your RMM should have MFA, right?

And then it answers the question, well, does everything else that the external NOC have access to, um, MFA and how are they gaining access to these platforms? We didn't talk about the deployment model. Is the PSA on-prem or in the cloud, if it's on-prem, is there a VPN into the MSP network? Does that VPN limit them to just the PSA platform or does it give them access to the entire corporate network of the MSP?

That's an attack vector into the MSP, so the external not can become a potential access vector to your r and for compromise. Um, obviously credential theft is a big one as well. I've seen PSAs that have strong integrations with RMMs. Attacker gets into PSA, there's a drop from PSA to RMM, single click bypasses, all the normal security processes because you're already trusted in the PSA. So I have MFA in my RMM, but not on my PSA and the PSA just drops me right into the RMM boom.

Now I have access to the entire MSP environment. Um, the other thing I would say is this RMM. So we, we focused a lot on building out the relationships around the PSA. You'll find that RMM has just as many if not more when we start doing this. So the next question you to ask yourself is what API keys am I using for all these integrations? Do I have a single P-S-A-A-P-I key that I'm using for every single integration? If so, what happens if that key gets compromised?

Will I know which vendor it got compromised from and how do I know how these vendors are stored in these API keys? And I don't know the answer to this, so I'm not throwing shade, but if I logged into breakage and breakage has access to 15 different platforms that I use that are highly sensitive or what I would call critical vendor, can I view the API key? Can I copy that out of the breakage interface? Okay, well, maybe not, maybe I can't do that.

But do we know how breakage stores those API keys on the backend? What happens if breakage, uh, had a network compromise Then? And are you logging this, these accesses, Right? Yeah. So there's, there's a ton of different, once you start to under understand the threat model, right? Like what are the five most common ways RMS get compromised? What's the most common way in IT documentation store has been, uh, leveraged against an MSP?

You can take that piece out of this diagram, zoom into it, all of the relationships that it has, and you can start to figure out how do I put better walls, MOS alligators, dragons, canons around my sensitive piece of information? But you can't really start to have that conversation until you have the diagram because this, while it looks complicated, is not as complicated as it actually is in your real environment.

So sit down, like again, we just, you know, I, I'm not an MSP, I just sit at a Holiday Inn last night. So like, you know, go sit down in a tool and just start banging out what are the relationships look like. Wow, my PSA has way too many arrows. I need to zoom in on that. I need to see, well, why is it integrated with all these things and what level of access do these things have and how do they interrelate? And what would happen if someone got access to my PSA?

Um, am i, am I managing roles and permissions correctly? Am I doing data governance here? Not storing passwords, not storing network access credentials, like remote access VPNs and things like that. You can't really begin to do threat models and really understand your risk and then start filling out those to-dos, right? The to-dos. Um, I definitely filled in there.

Um, the three things I would say is when was the last time you had MFA confirmed and every single platform that has an integration with one of your critical tools like breakage, the most common finding I see in MSPs is we don't have MFA on breakage. It's on, um, or our IT document. We have it on our IT document station store or PSA and our RMM. That's good enough. What about all these integrations?

We've seen attacks where integrations between vendors have actually led to MSPs being compromised. So again, reducing your number of integrations is huge from an attack perspective. And so when I say all these things on these calls, it's because I've been through these exercises with MSPs. The level of integrations is bonkers. Do you wanna have a fighting chance? Reduce the number of integrations. Gary, you're always fantastic. Wrapping us up before you do.

Chris, Tim, thanks a million for coming on. I, uh, I know this was different for everybody. I know we gotta do more. Um, but Ryan, thanks for that. Gary, bring us home with what we did. Look, if you've been on the last seven, I'll say just the last seven or eight cyber calls as an MSP, if it's not clear to you yet, we are not in the same business we were a year ago.

And if your company looks a lot the same in terms of how you go to market, what you charge, how you put a firewall around proactive roles and all the things we talk about every single week, you're falling further behind, right? I'm saying let's go. People Really well said. Chris, any closing comments from you? I been the chat. I would just say, Hey, this is, I think it's a great exercise.

Yeah, it's a little change of pace from what we're used to, but I think it's it's very good and it's an eyeopener. And I wanted to say that just the one thing I want to would say is keep a revision history because the, uh, when it gets into the legal issues, being able to tell this story can be very important. And so, and it can also demonstrate progress with your clients as well. Yeah.

And as you start doing change management in your MSP, that's where you start to keep these diagrams up to date as relationships come in and go out. And as things change, as things get integrated, there should be a change management process for that that keeps these diagrams up to date and helps you kind of, when you put them in the diagram and you've done these risk assessments, you're gonna automatically start looking at it and go, oh man, I just added another exposure here.

I need to do a risk assessment. Wow. That's right, Tim, thank you. Yeah, I mean, any thoughts? Yeah, I mean, as, as we've said in, uh, cyber call many times before is you can't protect your assets until you have identified them. And, uh, we've identified, you know, we know how to identify devices, we know how to identify people. Identifying data requires a little bit more nuance. And I think that's really where we're going with this call is how do we do that?

How do we make sure we're identifying all the data that an organization has? Yeah. Whether it's internal or external, and knowing where it's going is, is how you find it. Yeah. I, I know we're over, but the last call out is, the next step on top of this, other than those zoom ins, is to start to overlay some sort of data governance on top of this. What data exists? Where at what risk level, right? If you have like high, medium, low risk, where's your higher risk data?

Where's your medium risk data? Where's your low risk data? Where does it change from being low risk to medium risk based off of a data enrichment, right? Maybe data in your CRM is high, but it doesn't become high until it goes into the CRM and gets merged with seven other data sources. Ryan's like when I start talking about peak omics, like he's off the chain right now. Well, in volume too, right? You could have, you could have five high records, but you could have 120,000 medium records.

And so knowing how much is where, and it can be very, very helpful too. I mean, a lot of mistakes get people made is like, yeah, we delete data over here, but we just keep yeah, accumulating and accumulating somewhere else. And that's where it gets, that's where they get bit And uh, that's the thing is this accumulation. So how important is it for you to have this, this device over here, this database over here that's got all of your data that you log into once or twice a year? Get rid of it.

Yeah. Good stuff. Alright guys. Fantastic. Did we get overtime when we run over, did we get paid overtime time? You do. You do. But I need your PII to do that, Gary, which is high, highly sensitive. So I'm gonna pass. Great job everybody. Great call. Thanks. See you guys.

Related Videos