Data Governance & LLMs – Are Guardrails Possible?
AI Guardrails: The Next Frontier for MSPs
AI is reshaping the business world at lightning speed—and Managed Service Providers (MSPs) are on the front lines. As employees increasingly adopt AI tools like ChatGPT to boost productivity, often without IT oversight, new challenges around data governance and security are emerging. This rapid shift has created a blind spot known as “shadow AI,” and MSPs are now being called upon to guide clients through this evolving landscape.
AI adoption is no longer a matter of choice—it’s a competitive necessity. Clients aren’t asking if they should use AI, but how. With this urgency comes new security risks, as AI’s ability to access and manipulate data challenges traditional protections. MSPs are expected not only to secure these systems but to advise on implementation and policy as well.
Among the most pressing concerns are logging AI activity, reviewing automated workflows, and ensuring that systems don’t have excessive access privileges. Without proper guardrails, organizations risk data leaks, unauthorized actions, and a lack of accountability. MSPs must take a proactive stance—offering training, oversight, and structured guidance to help clients stay ahead of threats.
Beyond security, there’s a broader opportunity at stake. AI is transforming how businesses operate, and MSPs have a chance to redefine their value. By owning client relationships, moving beyond basic IT support, and helping customers rethink their strategies around automation, MSPs can position themselves as indispensable partners. The core of what they offer may evolve in the next few years, and those who adapt early will have a clear advantage.
To succeed, MSPs must understand threats like prompt injection and automation misuse, prioritize strong data governance, and begin tracking new indicators of risk such as AI refusal rates and workflow activity. Developing AI-specific incident response procedures will also be critical as these technologies become more embedded in daily operations.
Ultimately, AI security presents a major opportunity. Clients are looking for leadership, and MSPs who invest in this space now can become trusted experts. The time to build that expertise is now—before competitors beat you to it.
Guests
Video Transcript
Please. All right. Welcome. Welcome. Um, gosh, in, gosh, Gary, we are gonna be in the second half of 2025. Before we know it, like in the blink of an eye, this is just absolutely cruising at warp speed this year. Um, I don't know if you guys see it, um, from your lens, but it's just pretty staggering. And one of the things we're gonna talk about at going at warp speed today, um, is, is ai. So welcome everybody. Um, uh, Well, Andrew, we'll be slowing down.
You can't see it, but behind me, in my studio here, I'm actually building something this slow time down that I'm working on, On, is that right? Yeah. Hurry up. Oh, Oh. Once I invent it, we'll have plenty of time. Yeah, perfect. That's fantastic. Um, okay, let me just kind of do a quick sound and, and, um, visual check. Uh, welcome everybody. Can you guys all hear, see us okay before we get rolling? Yep. Good to, okay. Fan. Fantastic. Yeah, Bob Miller is certainly in the house.
Um, so, so let me, uh, kick things off. We're going to, we got the, a small crew today. There's a lot of people that are traveling that normally we would have on, um, you know, uh, but, but, um, let me, um, set the stage here. And in today's topic, you know, data governance and LLMs, I put, you know, our, our guardrails possible and, you know, so today is one, I mean, we've already even having a spirited talk before we even came on.
Um, so, you know, whether you've rolled out, you know, AI tools and I'm air quoting, large language model tools internally or, you know, advising clients on, on adoption of, of this technology. You know, one burning question, and I, and I'll share with you why this should be the burning question, is what are the guardrails, or what kind of guardrails can we use to improve, um, AI security?
And, and specifically it's gonna be around, you know, the data governance side of this, um, AI adoption, as we know, is accelerating. In fact, you know, it's, it's being pushed in the channel aggressively. I don't know if you, you, Gary, if you saw this, but I recog I I logged into Office 365 recently and the UI completely even changed. I did you? Mm-hmm. Did you guys see that? Yes. Where you no longer just, you know, your apps are really relevant and prevalent.
It's, oh, it's, you know, here's copilot Right. Sitting in front of you, so, right, right, right. We're kind of being, and I'm like, well, where, where did, where did Outlook go? You know? Yeah. And so, um, so the last thing I, I just want to share here, Gary, I'm gonna turn it to you to, to kind of start talking to Bob about this. I just wanna share my screen too, you know, and some people commented, like when I said our guardrails possible, and people are like, oh, you know, yes they are.
And I'm like, well, I'm, and certainly interested to figure out this whole piece out. 'cause this is the Verizon data breach report. And this, as we know, you know, Verizon certainly looks at many different size companies, but they certainly have a very good purview into enterprise. And even with enterprises that have, um, you know, governance in terms of how corporate, um, you know, information and corporate and access to their LLMs is achieved.
Um, you can see here that the majority of people are just saying, you know what? Screw it. I'm gonna get my job done more effectively. Um, and 72% here, garra, I don't know if you see this visual, but, um, is this coming through okay to everybody? Yeah. Yeah. We see it. You know, 72% are saying, you know what? Screw it. I'll just go personal. So, so, um, anyway, with that kind of backdrop, Gary, I'm gonna turn it over to you as we kind of di dig in here on, on this, uh, on this topic.
So, uh, over to you, my friend. Yeah. Look, this is one where, this is like a, just a start of a conversation. Yeah. Like, in the time we have today, we can't really, we can maybe frame out some things and, and usually we like to give some answers here. I think we're just gonna ask questions more and talk about the questions more than give the answers. 'cause all of us, that includes our audience, we're all guessing at a lot of things right now. Right?
Um, but I think we're gonna need answers way sooner than we've needed answers to other questions about security and other things. Because this is moving, you know, much faster. I feel differently even about the impact, you know, in general on the economy, but also on MSPs. I feel differently today, Andrew, than I felt 60 days ago, right? Mm-hmm. And so that's, that's moving fast.
So, Bob, let, let's level set a little bit what we mean by AI or LLM governance issues and how MSPs are getting pulled into some of these governance challenges. Yeah, we were talking, you know, Gary, we were all talking before about how things are changing from an MSP standpoint, right? And the, the reason we're being forced to do that is because of the chart that Andrew just got through showing, right?
I mean, the, the amount of adoption and the pent up demand, um, that's out there from an enterprise standpoint is overwhelming, right? I mean, it, it, how long Gary's the cyber call been, you know, about, Hey, how can we get people to buy cybersecurity? Right? It's been that way for a long time. You don't have to sell people on the idea of using ai. That's not, that is not something you have to spend time selling people on.
They're, they're trying to pull you by the nose and say, Hey, we got to go. Right? And so They don't, they almost don't have a choice, right? Like, right, right. You're either getting ahead or you're falling behind. Yes. Right? And I, I always called it a herding instinct. The, the herd is headed this way, so we better figure out how to play a part. And in the case of MSPs, they're gonna get, they're gonna get pulled along where they, they like it or not.
So, you know, when the majority of our MSPs out there are smaller MSPs, the point is, is how they get drawn into this is because these, these companies are dependent on them. We're already being dependent on to give them security advice, right? I mean, that's something that's already been established. Um, and they ask us, even if they don't do it, they at least ask us, right? So they, they depend on those kinds of things.
But now we're getting pulled into this, okay, well, hey, how's AI gonna impact my organization? What should I be worried about? Right? And, and, and you guys are the ones that help keep control of my infrastructure and help me with all those kinds of access controls. And, you know, you're the MSP, you know how to do ARB b and what that means and all those kinds of things. Well, now we got this 800 pound gorilla that can basically get to all of our data at light speed.
You know, how do we, how do we control that 800 pound gorilla that's gonna be wind up sitting in our network? And you're the MSB, you're the smart people. So why don't you tell us, which is drawing us in, right? I mean, it drawing us into How that works. I'm, I'm sure the government will update CMMC for this within 15 or 20 years. Yeah. Yeah. When the AI are running, it tells Us everything, Bob. And, and another point too is even let, let's just wave a wand.
Let's just say you could put governance around copilot. 'cause majority of us are all in this space. Microsoft, let's just say that you could, yeah. Yeah. What the data's clearly saying is, is employees are like, look, I wanna get my job done more efficiently. I'll just do chat GPT with Gmail real. I mean, isn't that really what the data's saying? Yeah. No, but I mean, you, you, you gotta remember it was the same way, um, before cybersecurity was a thing, really. Right?
We put, like, we just put access points everywhere or connect everybody up to the ethernet and just do s**t, right? We, you would just go, um, so I mean, it's the same way except the order, the order of magnitude of what can be done now is so much higher because the technology is so much more advanced. We're just seeing the same behavioral pattern. Like, look, I can't wait for all the rules to get into place. I got to go. Right? I can't get left behind.
So it's a cultural philosophical thing, right? And I spent so much time looking into this because I was building scenarios for the IR game to show 'em the risks, right? What can happen, you know, if you don't have these things configured correctly and you don't consider these governance issues. And so that really got me deep into, okay, well what can you do today Right this second? Because like Gary's point now, we're having to kind of make this s**t up as we go.
There's not like a playbook for all this just yet, right? So, no, but that's how we're getting pulled into it. No two ways about it. Yeah. And, and it's funny 'cause I even see like how I'm talking to, you know, our peer members on one side, right? I'm spending now more time telling them to go, like, they have to figure out how to be first to be more efficient, to understand how to make not just support, but their whole business more efficient before the competition.
Then they're gonna figure out how to get their customers there. 'cause either we're gonna bring their customers there or someone else who currently doesn't have the same relationship with them that we do is gonna come from the outside and do it. But the other side of it is, all of these things we're talking about today, Bob, right? Which is how do they go fast, figure it out, and then, you know, contemplate a different type of security risk. That's that we don't have guardrails, right?
We don't have a framework, uh, like lit a literal framework around how to do it. Yeah. Well, I mean, you know, and, and, and with cybersecurity, uh, you know, you had programs and you knew how programs worked, and you could see programs and you could, you could reverse in ager you could tell what the hell's going on. You had some knowledge of the underpinnings of how this works.
When you get into, you know, when you look at an AI model in general, it's just an array of nodes and vectors that make absolutely no sin. When you get into it down at the binary level, there's nothing familiar about it. There's literally nothing Ted about it. Yeah. People creative will say they don't know how it works. Exactly. And if they don't know how it works, you know, we're not gonna know how it works.
That's just kind of, that's the, I think this is the fundamental shift that has happened is, is that we're going from a known quantity, something that we could actually reverse engineer to an area that we just don't have the ability to understand because of the size, scope, and scale of it. And now we're gonna try, instead of being able to understand it at that granular level and control it, we're gonna have to figure out how to put fences around it to keep it from running over us, right?
I mean, we're more in, we're gonna be more in defense than offense in a lot of ways. So what are some of the red flags, um, that maybe, you know, that you can watch for, to tell a client if they, if they think they're heading into trouble in this area? Well, yeah, so even, so, let's just stick with our, the ecosystem that's 80% out there, right?
I mean, at least there are, when you, when you have these AI assistants and they're in the system and they're running, there are certain flags that you can kind of keep an eye on, right? Like directory read all or five file, read all parameters that you can start at least paying attention to and look and see if there's a behavioral change and the frequency and the, you know, the density of the request and logging on multiple levels.
This is, right now, our trick today is gonna be, we're gonna have to log and rot these logs into, if you don't have a sim, you're gonna, you're gonna need to get a partner who has a sim, you're gonna need something that can evaluate the volumes of data. They're gonna be coming outta these logs at more like Lightspeed. You're not gonna be able to play the old, Hey, let's open a ticket and try and figure out what's going on thing. It's, it, it, the train will have left the station.
So we're gonna have to get more, we're gonna have to get much more intelligent about which areas of the operating stack are we gonna have to watch for the logs for, and which parameters, like director, read all file, read, all those kinds of things that we're gonna have to pay a lot more attention to, because the volumes go up dramatically depending on, you know, what they're doing, what, you know, with these AI assistants. Yeah. Andrew, go ahead.
Bob, do you feel, do you feel, you Know, and I don't know if this is the, you know, quick bandaid, but because the browser is kind of the lead into these systems, right? I'll go, I'll get around is is, is browser security and being able to see, you know, what's happening there at really kind of the, the, the tip of the spear? Is that gonna be a bigger piece for MSPs to be able to have to monitor and maybe limit what browsers, what they can do?
YYY you have to remember, I mean, it, it's a paradigm, a little bit of a paradigm shift, because you know how we always talk about perimeter defense, right? At one point we had perimeter defense from a cybersecurity standpoint, what you're referring to with a browser is perimeter defense against the use of ai, right? You're trying to, you're only gonna be able to control that window of gnta and come outas, you know what I mean?
That that really is the only slice you're gonna have under control at a browser level. So if, I mean, the way to get past browser controls now is there is are a mile long. So I don't know that those are gonna be, those could be a layered, let, let's just put it this way. That's the equivalent of being a layered defense, right? Maybe you could, maybe you could look at controlling, you know, certainly your browser configurations should be tight regardless. Let me put it this way.
Outside of ai, your damn browser security should be primary because it's something you can control. You know what I mean? It's something that's, that we all know a lot about. Um, but once it gets past that, you know, the, you know, the cat's outta the bag. And when you talk about, you know, in terms of enterprises API usage and, and the ability to abuse these AI assistance via APIs, which do not, are not even, you know, they don't go through a browser, right?
I mean, they have nothing to do with a browser. Yep. Those are, those are, those are issues too. And to make 'em powerful, that's what they have to do. Yeah. To, to get the volume and the speed. Like that's the power comes from. Right? Right. I call this, so my, my scenario that I built was an AI cloud compromise scenario, right?
But I, I affectionately call it the AI smash and grab, because instead of them having to go through your network file by file, director by directory looking for sensitive s**t, they could just ask the AI system, Hey, scrape up everything on all of my contracts and their account numbers and everything, and bundle it up in this nice little ball and then write me a little PowerShell script.
So, and send it all of this email address and dump that if you're, if you're ill configured, if you're not configured correctly mm-hmm. And you don't have these protections in place, that's just how fast that's gonna happen. I mean, it is gonna be a drive by. Right? And before you even know they're in there, they're gonna be gone. So those are, those are elements that we have not had to deal with before.
You know, the ability for people to get, they don't have to download 20 gigs to get two gigs or one gig of useful information. Now they can get the one gig or the, the a hundred, the megabytes of it that they really want and be gone before the, the, you know, before the dust cells. Right? Yeah. Yeah.
You know, Andrew, um, in, in thinking about your question about, you know, browser security, like, I, I think we definitely, we're seeing like so many startups like you and I know a few of them, right. You know, around it, you know, that tells you. Um, but I, I, I, I, one, I, I think that's only a sliver, right? Like the Bob described, that's only a sliver of the one layer when it comes to ai.
And the other thing is, it's gonna take time, like I think browser security because it impacts how the user works. We're going to, it's all the way back to MFA, again, the same kind of education, the same type of evangelization that we had to do because it impacted directly the productivity of a user. And the same thing's gonna happen with browser security. So it's, it's a, it's, it takes time. You know what I mean? Andrew? Yeah.
We, and we moved the needle from 31% to 37% in, in two years with a Dodge. Yeah. I'm joking around sarcas. But that's, it's still, it's even, that's still a, a tough hurdle. But I, which I think is what you're saying, Gar. Yeah. Yeah. I agree. So, so I, I'm trying to read Keith's question here. Can you see what he means? What does he mean? Um, you mean about, you know, being a service provider versus business results?
Well, I, I, I think if, I think if you saying, you know, what I was reading from it is, look, if, if you're, you're the difference between a service provider and a, and a valued partner, right? Is which end of the conversation you come in on, do you come in on it when they ask you about it? Or do you come in on it when you go in and start explaining what's really happening, what they need to be familiar with, right? Are you taking the lead and you understand it enough that you can be proactive?
Or are you just being reactionary? That's what I take away from It. Yeah. Look at, at the minimum right now, regardless of your operational maturity level or where you are with, uh, your understanding of AI or even your security posture. Yeah.
If you are not having this kind, if you're not talking to the decision makers at every one of your customers and getting their view of how they see ai, what it means to their business, whether they've thought about the security concerns, where they think, you know, the biggest impact will be, do they feel risk, you know, in terms of how fast, if you're not having that conversation with every one of your customers today. I, I, I mean, that's the first thing you can do.
And you learn more about, you learn more from those conversations as a starting point as to what to do and how to spend your time and how to communicate with people. Yeah. But it also doubles down, Gary, with something you've talked about many, many times, is what level of relationship do you have in that organization? 'cause it's one thing to have that conversation at a mid-management level, it's a totally different conversation to have it at an executive level. Yeah.
So, uh, Bob, Andrew was talking about the Verizon report. Like 72% of individuals now are, you know, going in through their gen AI systems, through their personal, you know, uh, log on stuff, so they're not controlled by the company. So with that, you, you started to touch on this, but how do we rethink access controls and data loss, you know, know prevention, like in a world where with, you know, we're, we're, we're living in More wild west, Not more, not less shadow it now Because of Yeah.
Yeah. Well, I mean, it's, and what's interesting is it's hard to tell what's shadow and what's not. That's the problem, right? Yeah. But, and bottom line though, I mean, what we're gonna have to rely on is the same thing we should have been heavily relying on for cybersecurity in general, right? And that is just, you know, the, our arb B, right? Having the right kind of, you know, um, access control in place, role-based access control.
And more so now with ai, you gotta really start depending on, um, data labeling policies. You know what I mean? Now, this is where, this is where it gets, this is where the rubber kind of meets the road, but it is also the biggest hurdle that we have, not from an, uh, MSP or organization or, or, um, provider standpoint. But most enterprises data is in s**t shape. It is, you know, it, it's mixed. It's, you know, commingled, you know, at the base.
They, they don't usually have really clean databases with certain types of data well-defined in certain areas of their, you know, of their ecosystem. But you have to have that, you have to have that if you're gonna apply any sort of useful data labeling policies as it relates to that data. And, and why is that important? Because who needs to see that data? Depends a great deal on what type of data it is and where it is stored, right?
So we, you know, there's a, there's going to be, I will tell you this, there's gonna be a lot of service provider work just trying to straighten out the, the data layer for a lot of these enterprises. 'cause they're gonna have to get their data squared away before, before you're able to label it and secure it. Now. Now, the bad part about it is it doesn't have to be that way for them to use it. They can use it in the s**t shape, you know, the s**t shape it's in, honestly, right? Yeah.
Because, you know, the, the agents will go root around and they will draw inferences from collecting that all in one place and, and doing that. But you won't never be able to apply a rational sort of governance layer on top of that if that stuff is all co-mingled and not labeled correctly. So that puts a lot of pressure. It's the organizations are gonna keep going and they're not gonna wanna stop to clean it up, but they're gonna need to stop and clean it up in order to mitigate their risk.
So to your point, Gary, there's gonna be some big, what's going to happen is they're just gonna go and some big as events gonna happen, right? That exposes the, you know, the, the universe in some way or another. And then we're all stopping and talk about it for a few minutes before somebody changes their mind. So you, you know, I mean, I can see the cycle. This is the same cycle we go through with cybersecurity, right? We're gonna see it. Yep.
And, and also, Bob, if you look at like, you know, Microsoft, they're, you, correct me if I'm wrong, but, you know, in order to get things like purview, you have to, it's, it's an upcharge, right? Yes, yes. And, and they haven't, historically, it's not easy to do multi-tenancy with Microsoft. So A hundred percent, right? Yeah. Right. And, and, and then, you know, is it, you know, does that, are, are, are they in essence trying to push you into an EE five?
Like, so, like, if there's a lot of considerations here, just we, we've struggled as, as an industry. And, and like you said, all companies struggle with data inventory. Yeah, A hundred percent. But now, but now it, it's, and there's a lot more at stake, you know, for this, right? It seems. Yeah. Well, there is. Now I wanna make sure that people at least have something to start, go looking at so that they can understand what I'm saying.
You know, the AI assistant, you could actually put some policy rules around it about what its scope is. So you can make it, you know, you can put the scope of reader only, or you can put the scope of a scope contributor. These are roles that you can, that control the directory, read all access file, read all access.
I don't know, I have not done all the command lines to go and make that all happen, but I have seen multiple times across all the Microsoft, um, information, those are areas where you can actually go apply some policies to keep that, uh, AI system in your ecosystem from running. While I wanted make sure and put that out there, because I want 'em to have a place to go start looking at kinds of things that they can do.
Um, but to your point, data governance is gonna rely on data labeling and being able to do that, no question, to be effective. So, yeah. So Bob, let's, let's switch over. We've been talking left of boom. Yeah, let's move over, right? Of boom. I, I know that, and ir, ir games are something you spend a lot of time on. Yeah. So thinking about it from this perspective, like what procedures, logs, monitoring, communication, trees, like all those things Yeah.
Um, placed before an, before we have an AI breach. Yeah. Yeah. Well, I mean, it changes the game, you know, again, when I, no pun intended, but it does change the game of incident response when these get involved because of the, the nature of them. Even the incident response firms are still trying to catch up with what it, you know, how do they go forensically, figure out what the hell's going on. You know, when an AI assistant's really heavily engaged in, in, in an incident, right?
So again, all of these, you need to have playbooks, you know, specific to AI incident response. You're gonna need to think in terms of, and again, we talked a little bit about the logging is a critical thing. So let's talk about the types of log Azure activity logs, right? For the virtual machines and containers, you know, the creation and, you know, any of the changes that are going on, watch those at the Azure level.
But you need to combine that with the Microsoft graph level so you can, you know, trace AI and copilot sort of usage. You need to be watching those kinds of things. And then the purview logs are content access, right? And data movement and DLP triggers, all of those things combined are the logs that you're going to need to be able to extreme and keep track of to be able to help you in terms of working what could be, uh, you know, an AI focused incident in this situation.
But the playbooks, you know, how you're gonna sh are you gonna shut it off, right? If it's a main part of your process, uh, workflow, which is going to be automation's close to your heart, Gary, you know, this is gonna be the thing, right? They're gonna use these engines to drive automation, and in some case, infer what the next step in the workflows are. You need to be able to throw a switch to turn that off at some point if things are happening and don't know what's going on, right? Yeah.
That's a different type of playbook. And when do you turn it back on? If you think everything's okay, another thing you gotta really understand as it relates to that, right? And then all of the, you need to have a, you're gonna need an organization, you're gonna need a governance crew. Think of it as an AI change management team, right?
So when you're gonna monkey with workflows and you're gonna be using automation through AI assistance, you really need people to look at that workflow and understand what it's doing before you flip the switch and say, yeah, just go. Everything's cool. Right? Because you're gonna need to be able to tell, okay, where's the off switch? How are we watching it? Who's got the ball when we need to shut it down? Those are all yeah. Different things as it relates to workflows that you're using this for.
So a pre-approved emergency lock procedures, that's something you need to be aware of. All these are escalations on legal and pr. There's a discussion about, okay, what happens if you're an MSP and your AI runs off and does something and, um, you know, exfiltrate something, how is that treated differently than if one of your actual humans does the same thing? Yeah. Big questions we gotta answer, right? Yeah.
You know, it's funny, just in general, when we think about all this, we always talk here about, you know, the advantage that the bad guys have, right? Like, we, we gotta be right every time. They only have to be right once. So to take and harness the things we're talking about today, uh, you know, from a black hat standpoint, it's much easier, much more focused.
Do one thing, test it, roll it out, speed things up, find new ways, like you said, of it, you know, targeting, pulling together the information. But on our side, uh, it, it, it just, you know, now extrapolates the number of questions and, and, and defenses and layers. Yeah. It's, uh, yeah. It's a challenge. You, I mean, again, that's why monitoring and monitoring these things, you know, monitoring these log, have these things logged, first of all, monitor 'em.
'cause they'll be so hypercritical, right? But you're gonna have to make decisions quickly. That's the thing. Because an hour or two of somebody running amuck in, you know, in this, in this situation, if you're not configured correctly, yeah. I wanna say, I mean, if you're configured correctly, then you have the layers of defense to be able to this not be a nightmare scenario for you, just, just like every cybersecurity profile for an organization.
But you gotta put the time and the effort in to do that, you know? A hundred percent because it's gonna be over with before you figure out what's going on if you're not careful. Yeah. And on the other side, right? So technology companies, the, it's funny because the app providers on one side, they could create more risk in making you more efficient.
But on the other side, like the security companies are using, you know, are going just as fast to use AI to try to, it's really just speed and the ability to look through all of these new things. And you said the reaction time has to be that much faster. Yeah. And we're gonna have to rely on automation, you know, to be able to, to, to keep track with it. You're absolutely right. A hundred percent. Alright, Andrew, I'm gonna throw it over to you. Alright. Hey Bob.
So let you know, getting away from the buzzwords a little bit, and we look at, you know, KPIs, can MSPs use, or what are some simple, you know, KPIs, KPIs, MSPs can use to monitor, you know, safe and compliant usage of AI in their stack isn't even possible. Yeah.
I mean, there are, um, and again, there's, there, there are people who know a lot more about it than me, but I, at least the, the, the, the work that I've done and the understanding that I've gained is by looking at, there's a thing called an AI inference refusal rate, believe it or not. And that's when you ask an AI to do something and it refuses based on it's, you know, it's, it's definition of what is a good prompt and what is a bad prompt, that's a thing. Mm-hmm.
So you can actually monitor those refusal rates because to Gary's point, some of this is gonna be trial and error by bad guys, right? And so they're gonna be firing a lot of stuff at it that gets a big no from the agent, and then they'll, they're gonna keep working until they get a big yes. Right?
So the, the referral that those at ref the refusal rate is actually a pretty cool KPI to be able to kind of track and say, okay, well suddenly I had a spike of 500%, you know, in the refusal rate on this. And unless you've got an internal employee doing something magical, then this, this is worth knowing about, right? Then the, you know, the frequency of the API calls another great metric to be paying attention to.
Obviously something that you're gonna, you, you're gonna wanna keep your track on. Um, because that gives you a good indication if you see spikes outside of behavioral norms. And you can do something about that, you know, the number of a I generated workflow workflows, because here's the thing, AI can be used to generate AI workflows. You know what I mean?
So now you gotta be careful about, in the world of virtual machines, if you see 500 new virtual machines crank up and they're all doing a Bitcoin mining, then that tells you something. Well, it's the same sort of possibility inside of the scope of the a the AI sphere where you have the AI generating a lot of AI generated workflows. Well, you can kind of watch about how many workflows that you have in operation and, and the volume of them. Again, at least it's something, right?
I mean, I, I admit a lot of this is like looking through the window into the house where things are going on, but it's better than not being in it is better than not being in the same neighborhood at all. Right? I mean, so, um, and then you can do some alerts on activity, you know, that behaviorally, right? Baselines are outside the scope of what you normally see. You know, you can detect anomalies, drift AI drift is another thing, believe it or not, about how the AI behaves.
Um, because by the way, I mean, we could talk an entire another episode about the types of ways that you can manipulate AI engines to get different results if you're trying to do that, which is a whole nother thing, right? Yeah. We're just talking about dealing with the production In Europe. I know they're further ahead. Yes.
Like they're already have a, a panel and they're already putting things around the fact that you need to, in, in certain industries, you, you need to be able to document your drift. Yeah. A hundred percent. And you need to store baselines and you need to actually have your models in a, in a, in a, in a repository. You know what I mean? Snapshots of it so that, because unfortunately that's gonna be the only way. It's like backups.
We're back to the backup world, backup back up your engine, you know what I mean? And have it at a snapshot in time Yeah. And an immutable backup that nobody can monkey with, because if something bad happens or somebody poisons your model, you gotta have the ability to go back to a point where It wasn't Yeah. Because it's gonna be like, you think about it, like in healthcare, in defense, uh, in, in, uh, you know, utilities.
It's, it's there already in all those things like critical infrastructure. Yeah. Yeah. Agreed. Hmm. Bob, that's a, that's a, some of the, some of the metrics you just threw out, man, you'd be cool if you built a little white paper on that. I think the MSPs would find that really fascinating.
And, and you know, if, if I'm saying, Hey, I'm a a a a company that's gonna do copilot only, and then, you know, I am one of those people that's gonna get around it can are you saying like, Hey, hey, your traffic flow, you know, you're monitoring traffic on the network, you can pick that stuff up if you do have the correct telemetry in place to follow it. Is is, am I Well, let, let, let, well, let's talk about it in the two possibilities.
It's somebody using a third party engine on net right inside of your network and then somebody using a third party engine off net, right? Right. Um, on, on net you have the ability to control that. You should, you, you could easily control the existence of independent models on net. So that part you can handle. It's when they're off net, that gets to be the tricky part, right?
And when they're off net, all you can rely on, the only thing you rely on is data governance policies about what can be taken off net to be viewed, or what connections are allowed to be had from off net. We're gonna be stuck back at that, what we would probably call the stone age of, okay, we're not gonna allow these sets of data to be accessed by somebody on A VPN or whatever because, not because, but because it could be misused and put through an engine.
You're gonna have to consider it at that level. Right? This is, this gets into, we were doing control, I think it's control six of CIS just a week ago. But this is where, you know, so much of access controls comes in, like just, you know, you talk about layers, Bob, isn't this the one of the most foundational things of who has access, right? Yeah. To what things and, and from an account perspective, are we commissioning and decommissioning accounts based on roles and, and things of that nature?
Man, the, the level of you getting your ass kicked has just gone up exponentially is these things get adopted, right? Because if you've got a rogue account and someone gets those credentials and they happen to have access, the the fallout can be orders of magnitude worse. I mean, it can, right? I mean, because they, they just having, you know, with all of these, uh, modular, uh, cps right?
Being put built into the Microsoft ecosystem where everything's got an MCP module, which you could just think of it in terms of a p****d off API connection, right? It, it's an API connection with a little AI attached to it. And, and if that doesn't scare the snot out of you, it should, right? So you don't even have to really know how to talk to the damn thing.
It'll figure out how to talk to it and it'll figure out how to hand you stuff that opens up you, those labeling policies and, and, and access policies are gonna be so critical. And to your point, maintaining and controlling your access control lists and the people who are in it is taking, it's, I don't know how to explain it anymore to people. This is hypercritical and you're gonna have to pay attention. So Yeah.
And, and you can, those label policies and Derek, uh, Derek's talking about, I can see 'em running in the chat. You have to, you, you got, they will work. You just have to put 'em in place and understand how they are. And they're nontrivial. You have to, you know, it's, I remember when we first had routers that we could put, you know, policies on, it took a little while to figure out how to do it correctly.
It will do the same thing at a data level, uh, data layer problem or data labeling level. But you're gonna have to, you're gonna have to get good at it, whether you like it or not. You're gonna have to get good at it. Yeah. I mean, Gary, I mean, in some respects, do you see this, um, from a, a maturity level for MSPs that there will be ones that really take advantage of this and separate the way they have with security and automation? Yeah. I, yes.
I mean, let's lump AI and automation together for our conversation. So, um, uh, we're already seeing it, Andrew, the beginning of it. Yeah. Yeah, yeah. Yeah. I agree. I was, I was having, I was having dinner with, uh, joy Theand last night, and, you know, the, the types of projects that Summit se like as an example, summit seven, which, you know, is at the thro, you know, throat of CMMC, right?
From, from the biggest of big, um, it's a really interesting what the ones that have the, the right maturity and level. So not to suggest that no one else can do it, but it, it's, the opportunity is what I'm saying is, is tremendous. Yeah. And the opportunity is tremendous. But I, I think it's going to, at least initially, it's gonna be taken advantage of by, you know, pretty small percentage, uh, of providers based on just where they are today and their, their even ability to, to get there.
Mm-hmm. Yeah. And it's gonna take, and it's gonna take a big, you know, investment. Like, I feel like most of the platform companies that are out there are understanding it, recognize it, and starting to, you know, they can afford Right. To make those investments. They can amortize it over, you know, more customers and, and seats. Yeah. Yeah. And what Derek's saying, by the way, I remember we did our data flow with Brian, uh, you know, Brian Weeks, Brian Blakely data flow is a hundred percent.
I think where you start. We, we had those conversations and something maybe we should bring back Gary, 'cause that those were great, um, sessions. Yeah, Yeah. Um, so Bob, what about, you know, the most common common blind spots you're seeing in how, you know, small businesses are deploying or embedding ai, um, especially ones MSPs might be able to, you know, help fix?
Well, I mean, it, the, the, you're gonna go, the easy ones are gonna be just what we've been spending a lot of time talking about, lack of logging, right? AI specific logging. That's something that, um, MSPs, once they understand what needs to be logged, that's pretty straightforward to help people get, you know, get that done. You know, also understanding, you know, unreviewed or persistent AI workflows, okay. Who put those workflows in play?
Was it, was it, was it a human that put that workflow in play? Or did, uh, the, the AI assistants put those workflows in play? And, and how did that happen? And what's the inventory of 'em? That's a, if you do not pay attention to that, then that is a very easy way for someone to take advantage. It's a great attack vector, really. Um, you know, granting excess or tenant wide permissions, you gotta look, it's a permission thing going after making sure the AI assistant does it.
All of those services that are a part of the ai, um, assistant, you need to make sure that you, you, you don't grant them just excessive ability to get all of your network or tenant wide access, right? You need to, that's a place that you can kind of spend some time. And then obviously the absence of, you know, control access for certain types of ai, AI actions, right?
You can put, you can, you can do a few policies that minimize how bad it can be if you just understand that that policy layer and how it interacts with the AI systems, those are things that are easily things that I think an MSP could get their mind around and actually start tomorrow in, you know, introducing into organizations that are using AI and just going at it full tilt.
You know, at least that gives some, and by the way, and we talked about this, if you're an MSP and you do not see this as an evolutionary step that is about to occur in our real, in our reality from a provider standpoint, then you're already in danger of, uh, you're already in danger.
You know, you're already, you're, you're dodo bird and to some extent already, if you do not realize what has happening right in front of you, because the, the pace of change on this is gonna be going so fast, it's gonna be very hard to catch the bus once it's left the station. So, you know, Andrew, uh, you know, Bob, I remember, you know, we had built my IT process for standards and alignment, you know, you know, prior to CIS and standards that are out there.
And I remember in the beginning, you know, how hard it was to like, we're putting standards together by, you know, looking different places and, and, and then things would happen and we would change the standards, you know, and then later it's like, okay, here's an industry standard. Somebody else, like cumulatively did, did a bunch of work, but we're at that beginning stage now, like where we were before there was standards. Yeah. And so that's a problem. Yeah, I agree.
I, um, I, I mean, I, I did a, I did a, a little, uh, webinar with 50 C level people about AI security and, and when I was explaining to 'em things like, well, you need to have, you know, you need to have an AI security assessment, which, you know, I just, I threw that term out there, but I knew it was a combination of data, data policy and privacy and cybersecurity combined, right. Is sort of what would make up a, you know, rational assessment.
And when it was over, I got called by half a dozen 'em saying, Hey, I wanna get that AI security assessment. I said, well, wait a minute, it doesn't exist. Wait a minute. So what I, what I did up first? Yeah, yeah, yeah. But to your point, so what I did is I called Tim Golden and the crew over and Brian Blakely over at Compliance score guard. I says, Hey, look, this was about eight weeks ago.
I says, we need to build an AI security assessment, you know, that comes after like a copilot assessment or readiness assessment. We need an AI security assessment. So this is the next thing in an MSP can get involved in evaluating the security levels, you know, for an organization. So we've a, we actually started that and we're waiting to get back together to get it, but we got our first cut of it.
But to your point, Gary, is that yes, we have to all depend on each other to figure out how to, how to get into this game in a, in a constructive way. And the only way we're gonna do that is working with each other because it's too big a problem. Yeah. For any one or two people to try and go tackle. But the standard, the, the assessment won't be good until you use it and then it doesn't work. Yeah. That's the only way it's gonna be good. It has to s**t the bed. Well, yeah.
You got, you get, yes. You gotta break a lot of eggs. Make an omelet. Yes, a hundred percent. Do you, you know, Gary, just your outta curiosity, do you feel insurers might use this as a means to get around, uh, potentially payouts? Like for example, hey, you didn't put in good access control here, hence why, you know, this occurred. Um, I mean, I feel like they're always trying not to pay, but I think in with this, I look at it more like they're gonna need to adapt their requirements.
Like they have to say, like, they didn't ask you a question about it. Right? Like they, now they really go after things that you said that you had X, y, Z in place and it turns out that you didn't, and that's why you got breached. So I think they're probably working really hard right now to evolve their requirements to cover this. And that's a tough thing for them. Like, they have more risk than they did three months ago, Bob. Yeah, a hundred percent.
And, and you know, the interest, they don't even know the right questions to ask at the cybersecurity level, much less the AI level, right? I mean, they don't, they don't have like, Hey, you need to meet these requirements and prove that you went and did this, or we won't cover you anymore. They just say, Hey, give us, check the boxes on the stuff that you, you know, that you're doing so that we know you're okay. So it that all of that is evolving at likes be Gary's, right?
I I would they use it as an excuse? Well, is it a day with a y in it? Of course, somebody's gonna use it as an excuse, right? But the bottom line is, is that this, again, it's just the way the universe is going. So they're gonna have to suck it up and figure out how to ride the, the bus. It'd be better if they started interacting a little more with us as service providers so they understood the problem scale better. That's, that would be a change.
How about talk to the people who are getting their face matched in all the time about what's the right thing to do? Yeah, that would be good. Yeah. Interesting. Um, so Bob, what about, you know, how MSPs might wanna explain AI misuse, um, LLMs making sensitive data, you know, that a business owner, right, or a board could understand. Yeah.
Um, you know, because a lot of what we're talking about today, everybody on this call, our audience understands, you know, things like data labeling, access control. Like how do you, how do you bring it down to their level? Well, yeah. And this is, you know, again, hopefully you're fortunate enough to be one of the MSPs that can have strategic conversations, you know, with your enterprises.
And if you can, then it is going to be a chore for you to explain that AI in and of itself represents a completely different animal from a, from a cultural and and intellectual standpoint. You gotta understand that, that these are engines that can do a lot of work based on the instructions they're given, right? And you have to kind of keep it at just about that simple level. And then explain what I mean by that is that you can do things like prompt injection. What's that?
Well, you ask it to do something, but somebody else sneaks something in, in front or behind you to alter what's gonna happen, you know, in the, in the end, what's really gonna happen, right? So you just have to know that. So you're gonna ask it a straightforward question. Well, somebody's gonna put a not straightforward question to get something out that they want on front, in front or behind it. That's basically prompt injection, right?
And then you're gonna have to use a lot of pictures, right? This is gonna be one of those times when you're gonna wanna break out some pictures and say, look, here's where this sits in our ecosystem at a business level, not a network diagram or a technology diagram, but just a business level. This is where this sits in the universe for you. These are the kinds of things that can be done with it.
Like misusing it is pretty straightforward if you don't have the permissions or automation is misused. Again, if you don't, that's, you have to explain it in terms of this device has the ability to do a lot of work in a very short period of time and do it pretty well. But that means it could do it for the wrong reasons or the right reasons, just that fast. So when it's used for the wrong reasons, these are the, these are the, these are the ramifications of something like that occurring, right?
Yeah. And so you, you just have to be very clear and use very simple analogies, um, about, Hey, you know, this where it sits in, I, I would not make a, I would try to have one basic diagram. I wouldn't try to do a whole lot more than that because it's gonna blow their minds to begin with. Yeah. Let, let, you're, you're how you just, this would be a good clip, Andrew, to put out, right?
Because what Bob, kind of the talk track he just described, which is, you know, kind of showing something simple, using example that they can understand in a non-technical way that makes sense to them so that they can understand this risk and that they're currently living with it, right? Mm-hmm. Well, almost the, the guardrail analogy, right? Gary, what do you wanna allow in and out of your business? And do you, do you care what goes in and out, right, Gary? Yeah.
Or you're gonna put some guardrails around that. So, um, well, good. Hey, Bob, I'm gonna let, um, let me just see, I think I have one more, but I wanna make sure you time to ask Bob, uh, Gary, some business questions. I think it's really important, but, um, I guess, I guess, you know, maybe, you know, policy, any, any top things that you would kind of outline if you were talking policy? Yeah. Real quick. Yeah, I can do something real quick.
So you, you know, if you're an M MS P, you need to have an AI usage policy. You need to write it, you need to understand which why, first, understand why you need it, but then write it acceptable. Use approved tools, prohibited behaviors. You need to define those things. You know, you could just think about it in terms of a usage, but just like we have an IT usage policy, you need to have an AI usage policy, and you need to draw those rails for your organization sooner than later, right?
And then AI access control and role policies that needs to be well-defined inside of your organization so that you know that you limit the scope of what AI assistance can do inside of your provider network for obviously reasons. And you're gonna, we, you're gonna want to air, since when Microsoft enables stuff, it's all promiscuous until you go back and tighten it up.
I, you know, one little, one little gift from me to Microsoft, how about just having it tightened up to begin with, and then we have to go take the reins off a little at a time instead of leaving that wide ass open. But I understand why they're doing it, but as a provider, you don't have that choice. You need to make sure that you are, your access control and your role policies are well defined.
And then the monitoring, it's that logging, making sure you got Azure logging, graph logging, purview logging, that's all important. Those, you get those procedures in place. We're, We're talking about the basics, but every single software company on the planet is working on a gentech. It, it, so what about when everyone starts to get there and you start to have all these different agents, You know what I mean?
We could talk another hour about that, but you're, you are hitting on a nerve because these are, we, you know, we talk about third party compromises all the time, don't we? I mean, we spend a lot of time talking about that.
Well, think about it in terms of third party agentic ais, where you're, you're gathering up agents who people specialize in, because the idea for an agent is it does something very straightforward and simple in limited scope, but does it extremely well, which means people are gonna start marshaling these agents right into a bigger system of agents to get a, in, get the, get a job done that they're trying to get done. Well, what does that do?
That starts incorporating the risk of third party, third party compromises on agents, right? And their behavior and, and affecting their inference. You know, think, I'll give you a quick example. If you, if you build a company whose, um, product is you, you notify people about what dosages of medicine to give people based on the telemetry that you receive from the organ, the health organization. You define dosages and everything else. I mean, real time, right? Well, think about that.
If you use any agent down in there that winds up being compromised, that in, you know, that it's been changed to infer that, Hey, when you ask for a, I really want b, you know what I mean? Anything like that, right? Just imagine what that could look like, you know, from a, from a ramification standpoint. I was, I was, Bob, I I'm hoping we can get Ivan Fernandez on here if he's listening. Chime in. He, he, he's awesome. He, he was talking to me about how he used ent ai.
He's just, he's fascinated by it and how good and bad it can be. And he, I'm gonna very high paraphrase what he did, but he said, search LinkedIn for 20 CEOs that just started their position in like the last, I don't know, it was like the last month. And then go look for their public email addresses. Don't give me anything like Gmail or anything like that, and then find out if de IM is enabled or not. So, and and it literally, it says this for nefarious reasons.
No, he is like, oh, this is for research. And it literally built a script for him on Yeah. All different, I mean, so it's, it's really fascinating in a good and a bad way about what these systems can do. Yeah. So, Gary, let, let me get, give some time to you, Bob, so you Can Yeah, I got him This question. So, Yeah. So Gary, you know, you're always talking about like roles and process first, right? I mean, that is, that is something that you speak all to all the time.
Can you give us like your business logic on how these MSPs need to be thinking about their business from an operational perspective in terms of go to market as it relates to all of this? Yeah. So let me, let me like zoom out a little bit and tell you how I kind of look at it as I think about working with MSPs. You know, with AI Automation one, they gotta think about their, they do gotta think about their own business, not just being efficient, more efficient in support.
First you gotta get there before other people get there, but in your business operation. So those two things is what I'm encouraging everyone to do because, um, Bob, you mentioned it, a lot of what we do today, like all the changes that have happened in our industry have built on top of the same car frame, which is projects, tickets, alerts, user support. Like that's what we've done since what I got into this business in 1996. Everything else kind of been dumped on top.
Well, that car frame is not gonna be there in probably three years, is my guess. And I always say, you gotta change the car while the car is rolling down the highway. That's when we had a car frame, right? Well, without a car frame, I, I, I don't know. We might need to be building a new car in the garage and do a pit stop to take the new, new car out. And so I think, you know, working on that, so is, so that's how I think MSP business is gonna change.
And every other time, because we had that frame, that foundation, when people say, oh, the cloud's gonna wipe out MSPs, the, the security's gonna wipe out a lot of MSPs. I never thought that it would because we had that foundation. It just left some behind in terms of growth and profitability this time I think there could be a reshuffling of the deck for the first time.
'cause nothing's ever gone to the very heart and core of our value and our relationship and how we market and how we deal with customers. Yeah, I agree With you. That's the first dramatic why this is gonna be dramatically different in the next three to four years than all the changes in the past 15 years Yeah. That we've experienced. I don't know that MSPs are thinking in that way. Well, they better start.
Gary, can you just define, like, I, I think I understand what you mean, but reshuffling the deck, do you mean like, Hey, if I don't understand the impact of automation, what it can do to my internal roles and what companies can do without me? Um, is that, is that am can You Yeah, I don't think companies are gonna be buying us for the same reason.
I don't think what the, you know, Andrew, I'll give you a little sneak peek this, I'm gonna do a keynote on this a couple weeks at Flow, uh, the, the Roost the Roost event. But we've seen it with other industries where I think we get confused over what business we're in. It's easy to think that we're in the, you know, security business right now. Um, and that was, you know, support and security is never the business we've been in.
It's been the things we've had to do to provide what customers really want. They want to know, they wanna run their business and they wanna run it better. What they need from us in a few years is gonna be much different. And what they, what we provide today is not gonna be as necessary when both those things are happening. It means the business is changing very fast. And this is led by customers, not by us. In the past we've led most of the technology changes.
We brought it and the reason SMBs go slower is 'cause sm 'cause MSPs are slow to change, but, but when it's driven by the customer, we don't have a choice, Andrew. So, so it's almost like a full, these are maybe bad analogies, but to sum it up real quick, Gary, it's how, like something like an Uber, something like an Expedia and, and, and those, those industries just disruptive. Yeah. Like Disruptive. Yeah, exactly. We don't want to be taxis. Do you know what I mean? Yeah, yeah.
And, and, and it happens, and when it starts to happen, it's going to happen over a few years. It's not gonna take a decade, right? Mm-hmm. Like, I think we'll be in another place, you know, four or five years from now, I think we're gonna be a much different business. So one, how do we stay on top of it? Uh, the, usually the people that are advancing first win. Because as you start to make those advancements, you need to find ways of replacing that value first, right?
And that comes to the second piece is understanding right now about AI and automation where SMBs, where our customers are, because we can get 'em there. Like we have the basic tenants or, or can, uh, adopt them to get them there. But if not, somebody else will. And it'll probably be somebody that is not dealing with them today who specializes in this. That's what happened in the enterprise, the big consulting companies. They just couldn't afford to come down to the SMBs.
But someone will figure it out and they'll have a big disadvantage because we already have the cost of sales, we own the customer, right? So we have a big advantage with it. So there those two things. And then the third one is what we're talking about today. As we do this and have to do it quickly, we gotta make sure we're understanding the changing security parameters around this.
And just like in the beginning when we had to go from an MSP to a either an MSSP or a security first MSP, whatever we want to call it, it, uh, remember when we had Tyler Sanders on, um, Andrew, yeah. And one thing he said was what changed for them is they put somebody in charge, right? Mm-hmm. They had someone who, uh, both in communicating with the customers and developing their policies, uh, was responsible.
Like they had their first, you know, uh, VCO and, and then their culture chart to change so that in, in their current delivery roles, security was baked in. I think the same thing's gonna happen to happen here. We're not gonna train our whole team to be experts on AI any more than we were on security.
Like it takes time, but we're gonna need to get a resource at some point that can both communicate with the customer and be able to build the culture and work closely like with the security team in order to do that. I know, Bob, does that make sense? No, A hundred percent. No. I mean, it, it's exactly how we're gonna do it.
I mean, you have to, you, you're not gonna, like you said there, by the way, even if you went out today to try to find a bunch of AI experts, there's not a bunch of AI experts. So we're gonna, it's gonna some take some time, right? For us to build that, that, that talent set. So I but it, this falls right into what I had as a next question anyway. It's like, Gary, how can we make, I, we wanna make a case for MSPs, right? That AI security is kind of a differentiator op or opportunity for them.
Not only to, to be able to go talk about it, but also include things like AI governance questions and stuff like that in their, their their, their quarterly reports, right? Their qbr. What's the best way we can make a case for an MSP to start that process? Like now, I, I I, you know, you mentioned an audit.
I, I look at it a little differently 'cause I, I look at ongoing alignment and I would say start building these kind of questions right into, if you're first off, if you're not doing any type of technical alignment today, uh, I mean you gotta be in security alignment. You gotta be thinking about that. Now you gotta start to add, right? These type of reviews regularly, Bob, because what customers understand is, hey, here's the box for security. Here's the box for AI that we have.
Here's where you are. Let me talk to the places where you're out of alignment, what your risks are based on what I know about your business and the things we have to do to get you into alignment. That might be a different service, it might be a different product, it might be a change that they don't like in the way they have to do business with their end users, whatever it is.
But I think we have to use the same process we use with security, which is we have some standards we align our customers, we see where they're out of alignment. We have a business conversation with them. Yeah. Makes perfect sense. I I, uh, one other angle I think, and I I'm interested to get your opinion on this, right, is um, you know, there's, there's also this opportunity for people, you know, MSPs to go in and document these approved versus shadow AI approaches to do in business, right?
Just like you need a device inventory, there's an opportunity for them to go in and find out if they do have people using independent AI agents versus the ones that are corporate. So, you know, how, how does that help when you get, I can tell you, what do you think that does if you have that inventory? What do you think that does as far as helping in an auditor or a breach? Oh my god.
Well, for, I, I think well immediately with customers, like that's impactful when you give them that kind of information. It's kind of like, I remember when we first started tracking where people were going on the internet in the beginning and we gave, you know, we showed them one report and shut our mouth, you know what I mean? And they're like, oh my God. Like the leading website was like wwf, you know, eBay was number two and then all their line of business apps were below it.
So I think the same type of thing is that, um, when we start to show them, you know, some of what's really happening that they don't know about. Yeah, I think it's impactful. And I, and I'm hoping that's something we do, Bob before a breach and before we, before we get to that point. But one of the big things is, look, I still see people asking me questions and using terms like account managers versus VCIO or they're v Ccio os.
But when I'm asking them questions about what they know about their customers and their apps or who they deal with, whether it's a decision maker, they're not there, Bob. And like it was hard with security. Like you still have a lot of people who are saying, my customers don't want to invest for that reason. They haven't got to the right person and had the right business conversation with this. You can't get anywhere.
Like if you are not evolving to that relationship with every one of your customers, nothing we've said today is gonna matter. That's right. You're gonna be dealing at a very low level implementing the security things as a vendor, hands 'em to you that you're gonna resell. Like that's where you're gonna be left. And that's the other thing, Andrew, that's different with this, this is a business, this is pure business security was like technology in business. But this is more on the business side.
It is. And too many MSPs, Bob, they're not there with their customers. Yeah. Yeah. I agree. Gary, this is this, this, this is, like you said, this is about productivity. This is about, you know, competitive advantage, right? Money. It's about money. Let's just be straight. That's what it's about. Well, and yeah. And money and because Of the result Yeah. Is money. Yeah. Right? So anyway, And survival of businesses. Yeah. Yeah. It's not just the MSP business. It's gonna get reshuffled.
It's a lot of businesses that are gonna get reshuffled. It definitely in the next five to seven years, like our economy's gonna look much different. And so it affects us and it affects all of our customers. We need to be the right questions. We wanna win on the transition, and we wanna show our customers how to win on that transition. Yeah. I got one last thing and I'll say, I just wanna say this one last thing. Just imagine for a minute, if electricity was free, what would that do?
This is gonna have the same impact. This is gonna end up having a similar impact. Yeah. Think about that. That's, that's a good analogy. What if electricity is, look, this is probably one of the biggest things, right? Since electricity, but electricity needed infrastructure and it had a cost. So it took a long time. It happened over time. Mm-hmm.
This one, you know, in, you know, probably three years cumulative of the smartest people in the whole earth are going to be in our everyone's pocket for free. Yep. Sure. That's, that's the prediction. Like three or four years, it'll get to that point. Yeah. Yep. Well, fantastic. Bob, thanks for coming on. This was really good Gareth. Thanks for sharing your business perspectives. Always on everybody. Thanks for tuning in. Yeah, we like to give answers usually, but today we gave more questions.
It was a good one though. It was excellent. So until then, we'll see you next week. Make it a great week. Be safe. Take care.


