February 1st, 2021 – MSPs building cyber maturity/resiliency through frameworks
In this video, Justin Showalter and the team delve into the importance of cybersecurity frameworks for MSPs, focusing on CIS and NIST CSF. They explore the challenges and benefits of implementing these frameworks, discussing how they enhance security posture, reduce noise, and provide peace of mind for both MSPs and their clients. The conversation also touches on the potential for future regulations in the MSP space and the strategic approach MSPs should take to stay ahead of the curve.<ul><li>The webinar discussed the importance of implementing cybersecurity frameworks, with a focus on CIS and NIST frameworks, to improve security posture and compliance for MSPs and their clients.</li><li>The integration of security measures and frameworks into MSP offerings can lead to better client acquisition, retention, and reduced risk, positioning MSPs to meet future regulatory requirements.</li><li>The discussion highlighted the growing trend of MSPs partnering with MSSPs or building in-house security capabilities to manage increasing security demands and risks.</li></ul>
Guests
Video Transcript
Okay, welcome. Week 35. Gary, wanna kick us off? Hey. Awesome. Well, and there's Wes all decked out. Ryan, welcome as always. Hey, special guest Justin Schutter. Justin, thanks for joining us. Thank you for having me. I appreciate it. Yeah, it's awesome. Uh, it's really good to have you. So, a few quick announcements, we'll get right on into it. So first thing is, uh, number one, I'm gonna have a few poll questions. I'll put one up now for you guys and gals, if you could take a look.
Um, by the way, can you let me know, is that visible now to you guys? I created them and hit Is it, is it hit? Is it available? Can you see? Uh, you looking for the poll? Yeah. Is it available? Yep. Starting available. Perfect. Okay. Um, announcement. We finally have a landing page for the Cyber Resilience Workshop. It's below Ryan and Gary, at least I have Gary and Ryan at the the, in the, uh, Brady Bunch Squares at the bottom. Um, it's there. We also have an agenda link already to it.
Um, so it, it's looking really good. We are, uh, very excited about it. And, uh, so please, uh, share that out. Tell others. Um, and, uh, we'll get going. Oh, there's Miss Phyllis. She's here. Hey, Phyllis. Welcome. Uh, Phyllis Leaf, uh, senior director of controls from CIS. She's gonna be taking notes and watching. So be on the best behavior guys and gals. Okay. Um, Yeah, Andrew, we're gonna, we're gonna have a rocking couple days with the resilience, uh, workshop. And it's not all day, right?
We did it so people can get some stuff done and they can get to these two days covering really everything from what you need to do, all the way to go to market. Yeah, yeah, yeah, absolutely. Yeah. We're gonna look at, at a high level, Gary, we're gonna look at where's your MSP today in terms, and we're gonna look at Sun Neil's framework, sun Neil use framework in terms of what your offering is, what gaps you may have.
Then we're gonna really look at, um, we're gonna bring back Mike Beard, um, and people love this, his, um, incident response plan. So, uh, if we assume breach mentality, we're gonna need an incident response plan. We all have to operate from that way. From now on, we'll move into Wes and Chris LA's infamous and Famous Tabletop, and then Gary, we'll take all that together. And you, Matt, Solomon and Mike Beard are gonna talk about go to market. So it's gonna be real exciting. Yeah, Man.
Last thing I'll say is on each day by the way, we are going to have, um, a technical track. Big difference, by the way. Um, instead of a CTF that's competitive, um, we are gonna have, um, Jason Slagel and Bryson Medlock actually teaching, uh, vulnerabilities, uh, vulnerability management exploitation, and then the big one, which is web vulnerabilities in the OAS top 10 and some tools you can use. So that is gonna be fantastic. Okay. Setting the stage here. Justin.
Um, last week on the cyber call, I put a poll out and, um, I was really interested in terms of what people wanted to learn about in 2021. Um, by the way, Gary, I was so off on this, I thought people wanted to learn technical stuff, and all along, I've done a few different polls, 70% people said, implementing frameworks. Um, and I mean, I'm also encouraged. Yeah, yeah, no, absolutely. Hopefully we've had some influence over pointing people in that direction. Yeah, yeah.
Well, you've been a, a big, uh, standards person for a long time, Gary. You've said it once or twice in your life. Um, so, um, um, Justin, um, jumped on about four months ago when, um, Phyllis Lee and the good folks at CIS, um, started their beta project with something called the CSAT Pro CS SAT's been around forever. You can do it, it's phenomenal. You can go right to their website, do it for free.
But CSAT Pro is a multi-tenant version to be able for an MSP to go out and implement CIS controls across all their customers. Justin jumped right in. And so Justin, let's just start off. You could give a little overview about yourself and Blade, and then let's talk a little bit about your perspective on those. So let's start off with you and, and the company first. Sure. No, uh, first of all, let me again, um, thank you for inviting me.
I'm, I'm happy to hear, uh, be here and thanks for the opportunity to talk. Um, I think by default, at the heart of it, blade Technologies is just a traditional MSP. Um, you know, we do remote support, VCIO services, cloud services, you know, office 365, Azure, things like that. Um, we have a project side of the house, um, for both our fully managed clients and our, you know, our TNM uh, clients as well.
And probably within the last, well probably since the big, the pandemic started, we've really focused on getting a, a proper cybersecurity offering out there to our clients. Um, we started back in 2004 as a traditional break fist, uh, break fix. Uh, and then over the years, put in our first RMM, I wanna say probably around 2008, um, started offering VIO type services, uh, in 20 14, 20 15, and really started getting into the security side of things, probably 20 17, 20 18.
Uh, started off small little things here and there, but as the industry has grown, um, I wanna say 2018 is when we really started hearing about the MSPs and you really started seeing the, the movement towards IT security for MSPs to do that stuff. We really started watching it and trying to keep up with it. And, uh, and we are where we are today.
Um, and then as a side business, we have another, uh, uh, I have a sister company that we work with, uh, one of my other business partners that does, uh, digital forensics and, uh, litigation support. So, um, we've been doing IT security for a little while, um, and frameworks for several years now. That's very cool. So, um, appreciate the overview and, um, you've taken it to the extent of getting your C-I-S-S-P. This is not something you guys take, um, you know, kind of haphazardly, so, right.
When, when it comes to, you know, CIS and CSF, you're blending and doing both, um, share with, share with us just a hair about that, about why, and, you know, how they, to both compliment each other a little bit. Sure. Yeah. No, it, so we've decided to go internally, we're doing the CIS controls. Um, we're going in, we are in currently in the process of going through implement up to implementation group two.
Um, but for our clients though, we are doing the n cybersecurity framework, CSF, um, part of the reason why is because, um, CIS is much more technically driven. There's a lot of technical controls, there's not very, there's not a lot of governance in, in policies and regulatory stuff in there. Whereas that is, and it doesn't have a lot of policies and procedures baked into it. Whereas the cybersecurity framework does have that.
And then that's why we're like, we feel as if our clients need a little bit more, they need some of the technical stuff, but they also need some of that governance around what they do with their day-to-Day business as well. Very cool.
So, um, I'm gonna hand off to Gary shortly, but, um, what I'd like to ask, because I think there's, you know, people when I look at, you know, the, the, the results, you know, give or take, you know, it's a little skewed to the upside that yes, they are implementing frameworks, but call it 50 50, for lack of a better word. Um, where should people, you know, if you use the term, start with the end in mind, Justin. Sure.
As people listen today, if they're not, if implementing frameworks, what advice one or two things might you tell people? Because Right, it can be, it can seem daunting. You know, when you pull open something I love, by the way, CIS especially IG one. 'cause if you're not IG one, you, you might wanna pack it up, and I'm right. Partly kidding around, but partly serious. But what, what, what things might you say? Yeah. And that kind of depends on where you are in your journey.
Um, if you're starting from scratch, I probably would say that you look at the cybersecurity framework, but that's not to say that the CIS isn't bad as well. I mean, that IG one, everyone should be doing, if you're an MS P as you said, you should be doing IG one. That's all the basic stuff. But as a company, you also need to have policies and procedures around your stuff. And I'm not saying every MSP needs to go to implementation group two.
I mean, that's a big haul, that's a big jump from one to two. But you definitely need to have an understanding of the cybersecurity framework because not only does that, but it ties into, you know, uh, 1 71 and 53 and all the other governmental stuff. So if you come across any of those kind of contract works, you know, for government type stuff, especially with CMMC coming up, you're gonna have to have an understanding of that as well. Yeah. Very cool.
So Gary, um, you know, it, it's, it's interesting and it's gonna seem like I'm giving you tons of platitudes, which I, I, I like to do 'cause you're awesome. But, you know, when I go back to, you know, you in 2 0 9, thinking about, um, standards and alignment, you were thinking about it from probably a different perspective, but the importance of standardization. And it's interesting, really what we're talking about these days.
'cause you know, yes, it's very security focused, but it's around standardization. So, so with that, I thought it'd be really apropos to kind of hand it off to you to, to the next line of questioning. Yeah. I mean, back, uh, way back, even in my first MSP, you know, we base it on implementing standards. And back then it was a matter of being efficient. It wasn't such a security risk. Um, you know, we had over 7,000 end users under management, and we only had 1400 support tickets a month. Okay.
So, I'm guessing when you have those kind of ratios, your clients are also more secure. But, um, Justin, first thanks for being here, man, really appreciate it. The first question I wanted to ask you is, did you have before the security standards? Mm-Hmm. And before the changing landscape, did Blade have a proactive approach already, like I'm describing that we had Sure.
You know, did you have some, did you have, um, you know, your own standards or was this something that really just started when you started dealing with, you know, the changing landscape? Sure, sure. So we, as I said, probably 20 14, 20 15, we started, you know, doing the VCIO services of like, as a lot of other MSPs do. Um, and, you know, we were, um, we were true methods clients, and we came up with our questionnaire.
And I think in that questionnaire, what we decided to do is, like, to start off with, we said, okay, what are best practices our clients need to have, not only from, you know, the foundational work of, you know, patch management and stuff, but what other security things do we started to do? And we kind of cherry picked a little bit from, um, the CIS back then, uh, and the, uh, NIST whatever things from NIST that we had at that, that point in time.
We just kind of cherry picked them and we kind of put 'em in our standards document and our review and our annual process document. And it kind of started there. But, um, I think we found that there was no good way to, there was no good way to track that. Like, okay, how do I, you know, yes, you, I see it, you know, here's where you were last year, but there was no formalized process.
And I think, um, my business partner, Scott Schafer and I, who do the co compliancy work here in the office, we really started doing it around I think 2018. Uh, I think ConnectWise came out with identify, and then we used that as our, that was the, that was the thing that kind of just wrapped it all together. And not saying that that's the only one out there, but that's what we used to help really formalize that process for the cybersecurity framework for our clients. So, that's awesome.
So let me ask you this. I'm gonna talk about your clients for a second, not what, what you're doing for yourself. Sure. Side. Um, how do you get paid for it? I mean, how do you do it? Do you do it as a project? Do you do it on onboarding? Now you say it's annual. Um, you, you're trying to track where they're in out of alignment. So is it, is it baked into your offering? Is it a LA car?
Like, that's a big question everybody has is, is to, right, you deal with this and you are gonna ask me questions later on too, so Yeah. More, but I wanna know kind of how you've approached it so far. So the way we've approached it is with our managed clients, we kind of bake it in, not necessarily as if, okay, we're going to, we don't do it at onboarding, we don't do it necessarily as a project right away. We try to get a, an understanding of where they're at on that journey.
You know, like, okay, where have you had any other managed service providers before? Technology service provider, where are you at? Okay. Um, and then during those quarterly meetings and those annual meetings, we say, okay, here's where you are at, here's when the document. And we then we try to bring that process along for them at that point in time, because it's a lot to swallow.
I mean, especially for medium, small to medium has businesses and anybody who's not in a, uh, co compliancy type framework for them to try to, I mean, it's difficult for MSPs even, but even people who are non-compliance, non-regulated to try to swallow an entire framework, it's difficult. And it, and it's a journey more than anything else. Uh, it just takes time. And, and who does it, like what's the role or department that's responsible for doing this across your growing customer base? Sure.
So for myself as a, as A-V-C-I-O, I do it with my managed customers. Uh, and then for our non-managed customers, we, myself and, uh, my other business partner, Scott Schafer, we are in the compliance side of it because we're both CI SS ps. He's also, uh, a CS csa, A CS I, so he's got the alphabet suit after his name. Um, so he's really more around the auditing side of it. He understands like, okay, here's what the auditors are looking for, here's how to get through that kind of audit.
Um, and then I help take it, you know, translate those questions into solutions on how do I check the most check boxes, or how do I integrate that into your existing environment. Um, I will say though, that we do not certify any of our clients.
I mean, we're not a certifying body, um, but we look at as if we are the, we help them with the pre-audit more than anything else, because I'm gonna, I'm gonna help you get through, through your pre-audit with before your big accounting firm or somebody else comes in, uh, to certify you in, in rubber stamp you. So that way it's a much easier, uh, process for them at that later date. So, um, you've seen all the work you've done internally and with your customers, right? Mm-Hmm. Like it Mm-Hmm.
It's a lot of work. Is that fair to say? Yes. Yes. Um, how has that impacted, you know, you, you already said how it's impacted your conversation with your customers, you know, they feel how, you know, they, they feel your competence with this and take recommendations. But what about a new client acquisition? Has it changed your sales process? The fact that, you know, what it takes to do this, um, you know, the time, the money, the effort, you know, the risks, uh, that are out there.
Has it, has it changed your sales process? Well, I'll definitely say that it's changed in the sale from a sales staff perspective. I think that we'd always had the challenge, like other MSPs have to, well, is have had as well, is that be able to communicate that. So when we came up with our cybersecurity offering in the last year, um, myself, Scott Shafer, and we sat on and we helped develop it with our sales team. And so we really educated them.
I mean, we're fortunate in that aspect that, you know, we're both CISSPs and we understand some of that other stuff, but we educated our sales staff and so that they understood. So now they can talk the talk and walk the walk, per se. Like, they can go to a client and say, oh, well, yes, I know this now because I've been through this. I know exactly what it is you feel into this tier or that tier or whatever else it is to help fill those gaps or where they're at.
So, um, for new sales, I would say it's definitely easier when, you know, we, we get a lot of clients now that when it get cyber security insurance themselves, um, okay, we can understand that, uh, or assess some sort of assessment, uh, and it just makes that easier. It makes that getting that new business for them a lot easier. It's a lot easier for us to just be like, oh, there you go. This is what you need. So is it getting easier?
And this is what I'm hearing from, you know, my customers I work with that are more mature. Um, is it getting easier in the sales process for them? Like, once a prospect is qualified, is their close rate going up, like creating separation from the other MSPs? Is it getting a little easier based on It is getting easier, yes. Yeah, man. Yes. It's definitely getting easier because we are now comfortable with it.
I mean, not to say that we weren't comfortable before, but there's a lot of, well, I'm not really sure how to do this, or there's still some hes hesitancy about what's needed or, you know, whether it's a point solution or some sort of our overall service that the clients need. Yeah, we're all, we're very comfortable now, and it's taken time. Don't, don't make, I don't want people to make me to think that this is easy.
I mean, it's taken years to be able to get through this, but, uh, we were there at one point in time, just like everybody else. It's taken time to get there, and once you do, you get comfortable, then it becomes a lot easier, just like anything else. Okay. Well, I, I wanna monopolize the time. I'm gonna go ahead and hand it. I, because I could talk to you the whole time here. Sure. Yeah. But I gotta ask you one more question. Sure.
Um, so, uh, your average MRR, if you take your recurring revenue, divide it by all the customers, you have the average spend customer over this time period when you're doing more, has that number gone up? Does the average customer spend more per month with you? So we're doing a little bit differently where some of our managed customers are. We're, we're kind of different. We're not shoving it down their throat or we're not building it into our stack right now.
Um, I think right now we're offering it as an additional service to what our, our core, our core services are. So we're saying, okay, if you wanna do a security, add-on, you know, it's X number of dollars per user per month, um, and then you get this tiered. If you wanna do a little bit more, then, you know, we have, we make it look as if, um, I want to do better, I have to do better, and then I have a lot of compliancy. So we have different tiers, and yes, we're starting to see traction.
We're seeing people like, you know, I wanna do better or I have to do better. And there we see traction in, in different tiers in getting people to, uh, to get on those, uh, and to pick up those kinds of services. Okay. I'm gonna, I'm gonna go ahead and, um, hand it over to Ryan, but um, maybe at the end ask me a question about that. Sure, Sure, sure.
Yeah, so I think piggybacking off of that, right, there's a question about buy-in A lot of MSPs struggle to get their SMBs to buy into security spend or security improvements, you know, with the exception of the heavily regulated are, and you, you think, you alluded this a little bit, you're seeing upticks in customers acknowledging they need it. You know, where do you see that coming from? Is that the VCIO service driving that awareness and then coming, you know, aware of it?
Is it, you know, just, uh, external market pressure kind of making them aware of that? Like, you know, and, and how are you trying to drive this, you know, you have this package sure. You're trying to, you know, get, you know, get it sold into these non-regulated SMBs. How, how are you, how are you doing that? So I think it, it's kind of combination of multiple things. It's, it's market pressure. It's the, and it's the ransomware events that it happens to people.
And, um, hey, you know, my best friend, my cousin, somebody else got ransomware, and hey, I need to, how do I stop that? I don't want that to happen to me. Or they have an event themselves. It could be something small like, you know, business email compromise or something else. So it kind of depends, um, from that aspect. But, uh, we're, we do have the VCIO services that are pushing it as well, but it's just an overall, in general, I think the market is starting to shift. It's starting.
I think people are starting, companies are starting to see value in being more secure. I think some of the messaging is starting to get out to a certain extent. Um, and that's just, it's, it, it's just starting to naturally come about on its own, and we're not forcing it per se. Yeah. So I think Phyllis said that IG one has 43 safeguards. A lot of those, I'm assuming you're automating within your tech stack. Yeah. But some of them might not be.
And you know, those ones that aren't, we would consider control gaps. Are you getting a lot of resistance to the, the costs or the business impacts, or the change management implications of some of those non-automated, transparent, um, uh, you know, non-transparent, non-automated type of gaps that have to be closed? Sure, yeah. Yeah. It's, and really we are, and I don't think that's different from any other, it doesn't matter what market place you're in, you know, we're in St.
Louis and, uh, you know, obviously our city's unique compared to other cities around us. But I think any MSP that works in the s and b space, they're going to have cost pressures. And especially during the pandemic or any other time. I mean, let's be honest, some MSB or some small to medium sized businesses are just looking to check a checkbox and they wanna do it as cheap as they possibly can.
I mean, it's unfortunate we really wish people would want to, want to, want to do better, but it's a, it's a, it's, I gotta check a checkbox because, um, I have an insurance application, they're making me do this. I wanna lower premiums or it, you know, we've seen a lot of things in the last year or two where, uh, their vendors or third parties that they work with, uh, have said, Hey, we need to make sure that you do these kinds of things that we're not, we're not gonna do business with you.
So it, those are the two driving forces out of it. But then the compliancy ones are a lot easier. They know they have to do it, so therefore it, it makes that conversation obviously 10 times easier in that regard. Yeah. So you're, you're working on, I you're working on IG two, but you've attained IG one. Yep. Those Are, those are largely kind of self attestations, right? Like we can sell Yes. Tests that we've, do you see this moving for you in a direction of external validation?
Like having an auditor come in and actually, you know, paying them to do a custom C-I-S-I-G one audit or doing something, you know, maybe tangentially related like a, a SOC two, um, type one or type two. Like, where do you think this leads you in terms of the kind of prove it aspects, which both holds you accountable and gives you some marketing collateral to your prospects and your existing customers? Yeah, no, definitely.
Um, we will be getting the third party attestation, uh, to say that we're IG two now. We are not ready there, we're not there yet. As I said, I think we still have some controls that we need to put into place. And, um, not every single control applies to us. I mean, like, we don't do any software development, so therefore we can, I think it was a control 18, and we can just say, you know, it doesn't apply, so therefore we, we can get out of that one.
But, um, you know, we are also doing this not only to competitive advantage, but I also, as I kind of referring back to some of our clients, they're asking us, what standards do you all do? Like, okay, do you apply? Do you, you know, we have clients they know they're asking their vendors for the third party, uh, access to their system. So what, what do you guys do? Do you assign to this standard ISO or CIS or, or nist? And we wanna be able to say, yes, we do. We're we want to get ahead of this.
We don't want to just stand by and say, uh, I don't know. We kind of, no, we do this, and then we can hand em that piece of paper and shows that. So, uh, SOC two probably not, probably not gonna go that far. Um, I know that Ci S's work is starting now the process of doing revision eight on all their controls. So we're gonna kind of wait and since we get done with ours, see where we are at between the gaps between seven and eight, and then kind of address from there. Okay.
Um, I have a bunch more questions, but I'll, I'll, I'll, I'll leave it down to one more. Okay. Um, when you started on this journey, you had to pick a framework Mm-Hmm. Right. And there are dozens of frameworks that you could choose from. And, and you mentioned too, NCIF, uh, NCSF and the CIS framework. How did you decide which one you were gonna implement and, and, and, you know, to what extent was its impact on your internal operations a component in that decision?
So in looking at CIS, um, and CSF, I think we decided internally that we were gonna go the CIS route because it's far more technical in nature. Um, which would be easier as a technology company be easier for us to implement. Now, there has been a lot of changes in processes. There's been a lot of changes in, um, technologies that we've had to bring on. There's a significant investment. It's not an easy jump from one to two, especially for an organization our size.
But, um, I also don't want, you know, we decided it not only to get ahead of it for the curve or our clients asking which one do we do, but, um, I also don't want to end up on the, uh, you know, s Saturday morning news saying, Hey, late technology got breached. I don't wanna be on the newspaper. I don't wanna be, I think it was, it as, uh, west Coin, the Buffalo jump. I don't, I don't want to be one of those.
So there's multiple things and we don't, we wanna make sure that we're protected, we're doing it right, protecting our clients access, and also making sure that we, uh, can show that we, we do what we say we we eat are on dog food. You know, we prove it. And here it is. Yeah. So there, there's a question flying back and forth in chat, um, which is, how much does it cost you to attain this? Right? And so that's one factor in deciding the framework.
Did you actually understand your all in costs prior to no implement implementing? And like, no. And I think MSPs probably want, you know, they don't, maybe they want the actual number. Sure. Give them a range. They would be happy with that too. Like, is it, you know, give us a sense of how much it actually costs you to, uh, attain IG one and what you think it's gonna cost you to attain IG two. Sure.
IG one, I think we had a lot of stuff in place already, so I don't think it, it was anything that, any additional costs that we already had in place. I mean, you know, if you looked at the, the, the frameworks, you know, we're doing ms, as I said, MSPs are doing most all the stuff that we need to do for IG one, whether it's the RN and the inventory. We had some policies and procedure in place for, uh, because of HIPAA and some other stuff. But it's that continuous monitoring.
It's the seam, it's the, um, uh, I mean it's gonna, it, its cost is probably, I'm gonna throw out a number off the top of my head, over a thousand dollars a month. Easy extra on top of, of what I needed to put into place, maybe depending on when we're fully done, maybe almost $2,000 a month. I mean, but there's a cost, there's association that we wanna make sure that we're doing it right and that we're doing it right for our customers as well.
Um, There's 2000 a month per for you, or 2000 per customer For us. Yeah. Because In general, to get there, uh, you know, there's a, there was a bunch of labor. I mean, most people tell me Yeah. And we're not, and that's not including our internal time. Yeah. Yeah. I mean, we have hundreds of hours of, um mm-Hmm. I think that's where, yeah, there, there's that soft cost that you never, you can never really recuperate. Yeah.
So I would say, um, you know, most people tell me anywhere from 1500 to 2,500 hours over the course of the time they're doing this, Nick, it might take 'em a year or two years, um, you know, as they go, but just in, in the changing their posture. So yeah. And then that, and then we're talking about what do you gotta build in for your customers? 'cause now you have to have more deeper built in, and that is not that, that one you need gross margin on. Yeah, right.
One, there's one thing I wanna highlight here for some of the MSPs that are thinking about frameworks, right? We're also talking about a thousand to $2,000, but that was fixed based off of the time period that Blades decided to attain that within, right? You spread that co cost out longer if you're willing to take longer to obtain the compliance, right? Correct.
So there are different levers that you can pull to reduce the net amount of time per month, the net spend per month, et cetera, on those. You, you just gotta, you gotta figure out where your balance is for that, Right? And, and I don't, I don't, I don't want people to understand, like, it's not, there's a monthly reoccurring cost for services and things that we've had to pick up.
I mean, as I said, we, uh, there's also, but it, and then, but it's really the soft cost and the time more than anything else that's really, that I can't give you an estimate on. And it's not per client. Um, that's our cost to cover our things that we've had to pick up.
So, but the thing is though, some of those same services that we are bringing on place that we will now flip and use for our clients, for, uh, our cybersecurity offering, so then that's how we help defer some of that cost or spread that cost out across all of them. So it's not just, you don't just do it on yours and then like, hope to wait. No, you, it's kind of that balancing act.
You bring some on you, you do some things, and it, I'm not saying everybody go out there and spend the money right away and then they will come that that's not it at all. Um, it's, it's difficult. It's not easy, but we decided to make that change about a year ago when we, you know, we're pushing forward with it and that, and I'm also, I have no, we haven't even done third party citation, so I don't even know what that cost yet is. Great, great questions. And, and, and great.
You know, by the way, great. Thank you. Uh, Justin, I know we're gonna come over to Wes here, but by the way, Mike Beard had a great comment. The CSO of Marco out there, really good chat going on, Phyllis. Is, is, is, uh, uh, given a, a little bit of schooling on ig, one, ID two, et cetera, and some links, we need to have her back soon. Yeah, we are. Absolutely.
Um, Wes, as I hand it to you, one thing that I'm thinking about and, and, and we're seeing more of this, but Justin, I gotta hand it to you. You know, I think a lot of MSPs, if they don't start doing what you're doing, are gonna be caught off guard in one way, shape, or form. Maybe it's a third party, um, questionnaire coming in from a cyber carrier for, you know, a very, uh, a big MRR client, right? Gary like mm-Hmm.
You know, a reg, highly regulated client that's, you know, a considerable amount of your MRR that's gonna now look back at you is the MSP. So I think it's really cool to hear what you're doing. So with that, Wes, let me let you take over. Yeah, for sure. So, um, uh, Justin, before I jump in with you, one good question, Shiva just asked in chat, and I'm gonna turn this over to Ryan Weeks, who just went on mute, you're gonna have to come off mute, is he was just asking, do you see the day coming?
Are we already in this day that MSPs need to have internal compliance personnel? And Gary, I want your thoughts on this as well, because we've had a lot of discussion around this, um, uh, from your side of the house too. So Ryan, take that one. Yeah, I just dropped in chat. Um, I, I think we're already seeing movement in that direction, right? A lot of mps are starting to bring in at least information security capability.
It's, it's frequently kind of a deck that, that understands security, right? But I think over the next two years, you're gonna start to see dedicated security staff and inps. We're already seeing that in the larger higher ed MSPs, um, you know, more, more net customers, um, net larger customers. But we're starting to see that come kind of down, you know, downstream as well. And my other thing is, I, I do think that at some point we're gonna get hit with some sort of regulation.
I don't know that it's gonna be direct against MSPs or the IT channel specifically, but I think we're gonna get sucked in tangentially to something else. And we're gonna find ourselves in a position where, because of our relationship to some of these critical industries that, um, you know, whether it's probably gonna be sort of supply chain regulation for critical industries, that's gonna require that, um, there's some sort of specialist on staff.
And so I think if you're not thinking about it now, you should really have a plan within the next two years because the likelihood that it's gonna become required is, you know, in my, in my opinion, is more likely than not. Yeah. Yeah. Gary, any thoughts? Again, whether it's insurance, whether it's supply chain as, as Ryan's saying through SolarWinds and those incidents, what, what are you thinking? Yeah, a hundred percent.
Um, I agree with, with Ryan, and really the big question is like what Ryan alluded to. You're already seeing, um, more dedicated roles around compliance. You're starting to see, you know, more knowledge, security knowledge come in at the top. Um, and the big question is for, you know, the people that have less than 10 employees, maybe they can attract that talent. Um, how do they get there, right? How, how do they go? Do they, you know, do they partner with with someone else?
'cause they, their need is exactly the same and their customer's needs are exactly the same. Yeah. And so I think that's really the big question that I have over the next like, two years. Yeah, that's great point. Um, you know, not to plug around wheres, but, but the data state of ransomware report, um, we added a question this year, our MSPs partnering with MSPs in order to drive down their risk profile. Uh, four, almost five out of 10 MSPs said yes. Hmm.
So like, we're already moving in the direction of trying to find third party expertise. I think that maturity journey that MSPs are on in the next two to three years, they're gonna return, they're gonna move that capability from being outsourced to, to being inside their own MSP. And so I think that's another driver of that kind of change that we're gonna see. Yeah, Very good. Yeah, that, that really is my thoughts as well. Justin.
I've got a couple questions queued up for you, but I, that's my thoughts as well as MSPs are going down this journey and just looking at what are the resources we have built into our organization ourselves, what industries are we currently serving and serving well that cause us to really know those regulations, that compliance mapping and how to deliver a service portfolio that matches what that organization, that industry as a whole needs.
And then it's not unnatural for a small or midsize or beginning MSP to come to the conclusion of, I've gotta go with partners on this journey. I'm just not at the point now where I can build in and bring in my own in-house compliance team, or even a person that drives that. They're not always cheap to bring those people in. No.
And so it does make sense that you may say, look, I'm gonna partner with some others, even if it's like a full MSSP or you know, third party CPA firms that are doing some things on the side. Like that makes sense in some cases. Um, but I do think it best serves MSPs to really understand.
This is something David Powell at at perch talks about a lot, is just understand the risk profile of the clients that you're, that you have under your umbrella and even those that you're wanting to grow and ex attract and expand into. And those are the things that we'll begin to lead how that journey looks for you. And it's different for every partner for sure. Some go through it differently than others, some grow into it, some outsource it, then bring it inhouse.
Some always keep it outsourced for sure. Um, and this kind of gets to that question that I've been burning in my mind a little bit. Oh, go ahead. Can I add one thing? We, um, what I wanna say is whether you partner, uh, whether you start to build more capabilities, you know, both of those are expensive, right? But so is the increasing risk that you and your customers, in other words, the costs have already gone up. You can recognize it in risk, right? For you and in your customers.
You can recognize it by adding capabilities, you know, outsourcing or some combination, but you can't escape it is the point I want to make. Oh, yeah, I Agree. Yes, exactly. Already here. Exactly right. And even following what Joe's saying is, you know, some organizations kind of, you know, saying, Hey, we gotta do it ourselves, right? This comes back to this idea, and we've talked about this on the call a lot, is that you, you can't just, I can transfer risk, but I can't outsource it.
I still own it as an organization. And MSPs you own risk too, and you inherit the risk of some of your clients, actually every client that you bring on. And so there's interplay between all of this that must be considered because we all know when something happens, the first person that's gonna get their fingers pointed at is you. Uh, that's just the reality that happens all the time.
Um, Justin, um, so something I wanted to ask you about, and we've had good conversation about the cost of the igs and appreciate you being transparent and kind of where Sure, your thoughts are on the whole thing. But here's, here's a question for you, maybe a comment first. So, um, I've taught a lot of information security courses in college, and I remember one time I was teaching risk and I had my students like build out just a basic Excel spreadsheet with some amount of like, quantified risk.
And I wanted them to come back to me through a project of like, give me an outline of the different areas and the ways that you're addressing like three or four, you know, certain risks that your CISO is asking you to address. And I remember one client came back and he said, uh, he had a really good outline to, uh, address some of these things at the end of the day. Um, you know, his, the cost for him addressing those risks were into like the hundreds of thousands.
And I kind of paused for a minute and I said, Hey, uh, did you ever bother to ask me or to look at the revenue of that organization? He's like, no. And I said, remember, this is a small and midsize. And he is like, oh, yeah. And I'm like, you just assumed to solve for these risks, half the revenue of the entire organization. And he was like, oh, I see what you mean. That's a problem. Right.
And I guess my, my my point of saying that, or my reason for asking you is, is simply this, is that, um, when it comes to risk assessing, like one thing that if I'm the CEO of Blade, what I would ask you is, Hey, nevermind the cost to implement all of this. What's been the result that we've gotten?
What's been the, is is the play here that we have better retention, we have slower burn of clients, that we have less incidents, therefore we're more efficient, better revenue growth and generation of new clients. Like, what have you seen going through this journey at Blade that you would say it makes it worth it to put these risk reduction through security frameworks? Um, that's a good question. I'd say Probably for us it's been more of, uh, one, it's just peace of mind.
I mean, you know, it's, uh, we don't, as I said, we don't end up in the news or the newspaper or across the, I don't know, what is it, uh, channel E two E, another Ms P gets breached. Um, but it's definitely, it, it's generated. And I think Gary says it's the noise, the noise drops down. You definitely notice a lot less noise, things become calmer. Um, I, I don't have a metric per se, at least. I mean, know if somebody else has come up with a metric, I mean, please contact me.
I'd be love to, to get be a part of it. I mean, I, we haven't been able to get, have any metrics around it, per se. It's just more, unfortunately, it's just been more of a gut feeling than anything else. But if things are moving smoother things, the noise gets weight generated a lot less. It's just that it's more of a, a piece. I don't really know. I don't have a, uh, a technical way to describe it, unfortunately.
Yeah, no, and, and that illustrates part of the problem that we have for sure, right? Of how we actually measure cybersecurity. Gary, is that where you were going with that? I say, um, if you wanna know how it shows up in business results at the end, if we have time. Um, I, I get to see a bunch of numbers every month through our peer group. So I'll, I'll tell you how it manifested itself in 2020 at the end. Yeah. Okay. So that's good.
And Justin, here's another question for you that, um, you, we were talking about this last week and, and something you said I thought was really good, I wanna make sure this really comes across to our audience here, is talk to us about the difference between CSF and CIS. We've hinted at this a little bit in the promo that, um, that Andrew put up on LinkedIn earlier this morning.
We hinted at some of that, but I want you to go in depth a little bit more is when you started looking at the two, there's definitely a difference between the two. They cross map as Phyllis said. But what is, how would you explain to people that are in this audience that are like, I don't even really know the difference between the two. Is it just put a finger in the wind and just pick one? Is it just flip a coin and I pick one?
Or is there true actual differences between the two that have been beneficial for Blade? Sure. So I would look at it from this way. Um, so the CIS is a private organization that has come up, uh, through the out years, has, uh, developed their top 20 critical controls. And it, and it's morphed into, uh, implementation groups. Um, whereas the NIST National Institute of Standards came out by a federal agency.
So with all your federal agencies, you're gonna have a lot more, uh, GRC governance, risk and compliance, and there's gonna be a lot more policy and procedure heavy. Um, do you have a policy for passwords? Do you have a policy for this? Do you have procedures for this? Do you have a, so the NIST cybersecurity framework really is much more heavily reliant upon policies and procedures.
It's not to say that it's technically, you know, from a light in the technical standpoint, but because it's from a government agency, there's a lot more policy procedure, uh, risk and governance and, and compliance inside of it. Whereas, and Phyllis may correct me, but I feel as if the CIS is much more technically driven, and it's a little bit lighter on the policy and procedures.
So that is where the cross mapping of IG one and CSF does happen, and you can see, okay, this maps to this and that goes to here. But then we come back around and say, okay, not everybody, all clients need to have some sort of policies and procedures, whether it's a password policy or everything else, but we also believe all of our clients should have a DR policy and an IR policy. Now, don't get me wrong, those are huge things to do. Those are not simple tasks and they take time.
But there's a lot of other policies that are in the CSF that anybody can put into place. Um, and that's where we decided that our clients need a little bit more structure, a little bit more policy and procedures versus just pure technical, um, because that's, get asked that on insurance, you get a third party vendor stuff and insurance questionnaires, you get those asked if you have those kinds of things. Yep, absolutely. Andrew, are you gonna say something?
I was just gonna say, and it's funny what Phyllis said, because I'm gonna say, you know, I, I think what's what I've seen, you know, in, in the beta group of, of CIS, it's, and we got probably 20 MSPs in it. Um, it's very prescriptive. And, and, and again, they're not competitive west. You've, you made a really good point. These frameworks are not competitive, but often with MSPs, you know, especially if you haven't been doing it or this is your, your, you know, foray into doing it.
MSPs are much better, I've seen over the years. Gary, I'd love your thoughts to, to get into something that's prescriptive, you know, and, and then, you know, you can, and of course with the government, Wes, and we were joking about this, they will never say, do this, it's yours. Meld it however you want. Oh, yeah. It's Almost too vague. So, Yeah. And that's just part of the, the nature of like, so I've dealt with federal regulators for a good portion of my life. Right?
And that's exactly right. There's one thing federal regulators are scared of. It's the word antitrust. Uh, they do not want to be seen as someone that's pushing the envelope in, in favor of one piece of technology or one vendor. And, and I'm not saying they've been perfect at that. Sometimes there is an over push in certain areas. Like you might see them talk about law aggregation in sim, for example, too much, but, or not enough.
It could be, but, but my point is they try to steer clear of that, which is why the CSF is very much built towards governance. Uh, that's what we call GRC, you know, all like, how, how does the, how does the framework work to build the actual structure of the security program itself? But that leads MSPs to wonder, okay, I get it, but how do I build it out? Like, what do I actually do? What do I put in place? What do I need?
And, and I hear that a lot, like even looking at the journey of a lot of MSPs in the hundreds of conversations that I have, it comes back to people. They, they want that prescriptive model. They want someone to tell me what goes into it, what do I need to be focusing on? Because that's a big piece of it. It's actually not the beginning of the security journey, but it's a critical piece of it, which is what CI CIS is here to solve for and even see that with, uh, with Phyllis's comment.
So I mean, Justin, does that kind of correlate with you guys too? Is that the journey that you guys went down to and ultimately led you to understand the differences between the two? Yeah. Yeah, I definitely, and it's, uh, as I said, that's why we chose the CIS internally just 'cause it's much easier as a technical organization for us to be able to hit technical milestones. Okay, I need this, I need this, this point, or this one solution to cover these.
So it's a lot easier for it to wrap that around. But we, just, like a lot of other organizations, we need policies and procedures put into place too. So we, that's where, back from when I, earlier I said we kind of, when we first started doing this, we kind of picked and cherry picked, we picked little pieces here and there.
And, um, I, we still believe though the clients need policies and procedures in place, regardless of whether or not they're, they're trying to go for federal or something else like that, you still need to have some governance put into place. So that's where sometimes the NIST cybersecurity framework actually ends up being a better fit, Um, y Yeah, good point.
And one thing you've just mentioned, you, you talked about, uh, internally how you use CIS, but that begs the question of externally, what does all of the output look of look like in the, in the, um, in, in the flow back to the clients? Do you guys more CIS focused with the clients? Or how does the external side of what Blade does, how does that look?
Yeah, so we're definitely in the external side of it, it's, I mean, in our external dealings with our clients is definitely cybersecurity framework. Just because of the, because of the policies and procedures in, in wanting those clients to get to that point and having those things in place. Because every, realistically, every business needs them, whether they want to or not. Um, you know, every client, every customer, every s and b, it doesn't matter what size actually needs a DR plan.
I don't care if it's a two page sheet, but at least have somebody have an idea of, okay, if something happens, what to do, uh, a two or three page instant response plan, something, have something written down so when, you know it hits the fan, you know, you can like, okay, at least I have something I can, you know, I have a general idea.
And I mean, that's not other things too, but I said, you know, uh, policies and procedures on anything, you could be, um, I don't know, there's, you can, there's hundreds of policies you can put into place, but that's why we do that. And everything externally facing is cybersecurity framework. Got it. Okay. So maybe my last question, I'm going off script again. Um, I'm gonna put you on the spot a little bit, and I hope this is okay.
Uh, let's say you're talking to me and I'm a client, um, doesn't matter the industry, you can pick Sure, but I'm not really that familiar with frameworks. I'm not familiar. Like I know what cybersecurity's about. I already want to invest in it. Like that's, you, you've gotten through that hurdle with me. I'm ready to put some money in or whatever.
But how would you explain, like from Blade to me as a client, how you guys produce value through frameworks, whether it's C-I-S-C-I-S, any of those, or CSF, any of those together? How would you communicate the value? Just talk to me as I'm a client for a minute. Sure. So the way I would communicate it to our, the way we communicate it to our clients, or if I were to communicate it to you, would be like, we try to stay away from them, fear, uncertainty, and doubt.
It's the, you know, listen, we're trying to get you in a better place. We're trying to get you to a point where you don't end up on, um, you're not down for two weeks. Um, you know, it's, yes, you're gonna have to invest some money and to better secure your environment, but you can sleep at night. You can say, Hey, listen, you know what you're not gonna be worried about if God forbid something happens, you know, you're gonna be protected from whether it's an antivirus or if it's a business.
You know, Andy Spam from business comp, uh, email compromise or some, you know, something. 'cause we all know it. Security is not bulletproof. There's always a chance for something to get through. But we're gonna put things in place in that, you know, uh, defense in depth concept that if something does happen, you are going to be protected or you can get back up and running in a much quicker, uh, much smoother manner. Um, it's going to take us some time. We're not gonna be there tomorrow.
We're not gonna be there next week. It could be one month, two months, it could be a year. But this is a journey that you are going on. Um, as we've said on this phone call or this webinar several times, it security is not a, uh, destination. It's a journey over time and it's constantly evolving. Uh, it's changed from what it was two years ago to what it is today.
Um, I think Wesley, you actually had an excellent video you put out last week about, um, what the things we had in place two years ago. As far as, you know, protection doesn't necessarily apply today. And things have changed and the environment has changed and it's constantly evolving. Um, so what I put into place today is, could be changed in 18 months to two years, but we'll be there and help you with that and we'll help you, uh, keep up to date with those changes.
Wes, can I, can I just Say something as well? Yeah, please. What? And, and, and Justin, you know, it's interesting, our, our industry, you know, if we were, again, I'm not saying to use this analogy 'cause some people go, don't use medical analogies, don't use insurance analogies. But we wouldn't think twice of if, if you were a doctor talking to a client and saying, look, I, I need to assess you. I need, I need to know your cholesterol.
I need to know this and that, Hey, we found these things and now we're gonna do this next assessment or this next test. We found, found some irregularities in your heart. We found some irregularities on your network. We're gonna do a pen test. I'm not saying one for one, but I'm saying it's interesting because as an industry frameworks are relatively, you know, again, maturity wise, new, you know, Gary, right?
I mean, how we haven't been doing security frameworks and assessments for, you know, 2000 4, 5, 6, Gary, we, we've started to just come about. What's that? You haven't been doing assessments since then. Yeah, right, right. But you know what I'm saying, right? We weren't embracing some, uh, you know, as a, as a whole, like the enterprise was, you know, uh, an 800 series assessment.
But, um, it's, it's relatively new and that, and anyway, it's just, you don't get, you don't get health, you don't get health insurance, you don't get life insurance, you don't get cyber insurance without doing these things. And I think we're gonna have to shift our mindset and belief on what has to occur with our clients. What, what are your thoughts? Me? Who are you asking Gary? I think you're asking Gary, right? Yeah, yeah, yeah. Look, a hundred percent.
You know, and my, I wrote down some thoughts that I wanted people to come away with today, and I want 'em to hear the main thing why I'm so happy we have Justin on hearing the level of command that he has over the frameworks. He's able not just to know what they are, but he explains them conceptually and how they use them in different ways in the organization. And, um, uh, and the fact that he did his own company first.
I was just talking to, um, uh, one of our customers, a a friend of mine that, uh, we both know Andrew in, um, uh, Keith Bart. Oh yeah, sure. And he was saying one of the big things is their company, their MSP is, is a customer and they assign the same resources, the same product the same time. Ev like, like did they do for alignment? And they consider them the most important customer because there's this line you have to get to and, and I just wrote it down.
I think I, I don't, I'm not gonna call it this, I'm gonna give it another name, but it's a good concept. The ask tell line, right? Um, when you go from asking your customers whether they would like, you know, two factor authentication to telling them that they're gonna have it, right? You go from asking to telling. And the way that you get over that line is you develop enough command that you, it's easy for them to see that their costs have already gone up.
Do you want pay and risk or do you wanna pay it in a way that we can control? Hundred percent? You know what it is? It's an excellent, right? That's it. That's t excellent pointy. Justin, you had a few questions. Um, you know, I'd love for the MSPs to hear your questions that you have maybe. Sure. Gary and Wes and Ryan. So let me let you, So yeah, I did have a question for Gary.
And, um, my question is this, is that as MSPs as we've all gone through this journey, you know, I started in 2004, so, um, we've included backups over time. You know, things have become a part of our stack or part of our standard solution, uh, you know, antivirus, anti-spam backups, things like that. And supposedly, you know, that security is the new thing, but is it really, I mean, we've already doing all kinds of security things already. They're already in our stack, majority of these MSPs.
So is security really still the new thing? And then at what point in time do MSPs take over what MSPs have done to allude, I think what Wes had said earlier, or even maybe it was you, that that skillset's gonna come in, it may not be day one, it may not be a year, maybe two years. But then what does the MSS ps have to do? I know there's probably some on this phone call, do they become even more, um, what's the word?
I can't, like specific, do they really become targeted even more to a specific industry or what happens? Like what, what, what do you see? Yeah, so in general, we see this not just with security, but we see with other things that are specialty, they're done by just certain types of companies, then they become, you know, spread across SMB and then the MSPs do 'em, they charge you extra form and then they become part of the stack. You named a bunch of it.
And so what you see happening right now is you're seeing more and more of the things that people, you know, looked at as a security offering two or three years ago. It's now just part of the stack and there's higher level stuff that, that you mentioned that that still is that still above whether they do it or whether they outsource it. So I, I think the role of the MSSP and the role of the MSP are both gonna change. And really, Justin, it's confined by the business model.
Like what are you gonna put in your core offering, and then what else do you want to be able to offer? And how much of that do you wanna do yourself or do you need some help with from a, from a third party? And what you mentioned, one challenge I'll give you is, I'm not saying you should be including all your stuff, you know, in, in, in your offering, but without seeing it. You tell me you have three levels of security add-ons.
I'm gonna guess that level one needs to just be part of your offering. Go bundle it in and raise your price and then look at two and three and ask yourself if is, do they need both? If so, can we just have a core offering and can we just have one thing that goes beyond that and simplify things, you know, for your team and, and for your customers. So, and I'm telling you that with not knowing anything more than what Sure, no, I understand. Set on today.
And that kind of helps us decide where we need to go and also where we need to look outside and it'll drive the MSS piece to, you know, they're gonna lose certain part of what they do and they're gonna have to drive to find value in other areas. Great question. Yeah. Excellent. Did did you have another Justin? Yeah.
And this questions is more for, I think more for Wes, but, and, and I know it's been discussed a couple of times and in other various things, but do you see, because you came from a regulated federal, you know, um, with the banking industry, do you ever, and maybe Phyllis can comment in, in the chat, but will MSPs ever be, have any sort of regulatory compliancy or whether from a federal level or something else in the state, do you, I think I, I remember a conversation one time.
It'd take, you know, a, uh, to become a beautician, you have to have more, you know, you have to have a license. Whereas a an MSP, all I have is a business card. I forget who said that, but do you see regulatory, uh, pressures coming on top of us at some time point in time down in the future? Yeah. The, the one who said that, at least that I've most recently seen, and it was really good and well said, was Chris Roberts, I follow him on LinkedIn. He is, uh, somebody I know fairly well.
If you don't know Chris, follow him. He's a super awesome guy. And he was talking about that. And I get his point, right, his point is like, look, there's no barrier to entry to get into becoming an MSSP or even an MSP and that, that causes some problems, of course, when security, uh, issues occur, compounded with the fact that MSPs are under attack like never before, which is why perch talks about buffalo jumps being, you know, so important.
That's all it's culminated into what we've seen with our friends at SolarWinds, right? I mean, if not them, someone else, right? It's certainly not picking on them, but just to say, we now know what's happened with all of this. And so I guess here's my thoughts. Here's some ways to think about this. So first of all, it's all recognized that we already are under the crosshairs of regulators. Um, insurance organizations, everybody, we're already under this crosshairs.
And so, just as one example, if you work with banks, you have some amount of, um, consideration by regulators. They are being asked questions in the examination cycles. Banks are, Hey, do you work with an MSP? How, you know, have you vetted their controls? What's in place? What are you looking over for them? Give us evidence that you're actually measuring the security program maturity of your msp. That's already happening today.
MSPs that are in this chat are nodding their heads saying, yes, I go through that rigmarole at least once every 12 to 18 month cycles with my banks. It's a chore, but it's worth it in the long run. And let me just read this to you. This comes from F-F-I-E-C. So this is like the conglomerate of banking regulators listen to this.
So they name themselves the, the, uh, FRS, the FDIC, the OCC, each individually and and agency collectively have statutory authority to supervise third party services that enter into contractual agreements with their regulated financial institutions. Period. So what are the banking regulators saying? They are saying, we have authority to regulate you should we so desire, and this does happen. You look at some of the larger MSPs and MSPs that are out there, they are actually regulated.
They have financial regulators in their door. Why? Because they serve banks, they serve other fis. And so it's just illustrating this to say, we're going to see that continue. Now, are we going to see like dedicated, focused regulators? Like you're gonna see like, I don't know, some, some organization that spun up inside the federal government saying, we are the ultimate authority in regulating MSPs. Maybe, maybe not.
Um, are we also going to see, you know, insurance organizations finally stand up and say, enough is enough a la PCI, are we going to see industry standards come across? Probably we're going to see that. And what measured effects will that have or it remains to be seen. We just are still gathering data. There's still a lot we don't know. Um, cybersecurity changes so quickly.
It's, it's such a liquid, um, a, a threat compared to things like CarX or, you know, airplane crashes or motorcycle crashes that we just don't have the same finite data on. So yeah, it's coming. We need to be ready for that. We would all be better to be prepared for that and going down that journey. Because here's the thing, you look at all modern regulatory frameworks in cybersecurity, guess what they do? They cross map to CIS and CSF. They do.
And so if you already go down this journey, now when those regulations come into place and you're starting to have to go through and adhere to those things, you're gonna be like, well, lemme just pull out yep, doing this, this, this, this, this, this makes it much, much easier. So build it now because it's going to pay off dividends both now and in the future. So, so, uh, I wanted to pull in Phyllis to kind of cap us off. Phyllis. Um, we're at the top of the hour. Awesome to see you.
Any comments and thoughts, uh, on Justin's question? He we'd love your thoughts on, you know, yeah. So yeah, I would say I agree, um, with Wes, what we've seen in legislation as far as safe harbor laws at the state level for a couple states, for small medium businesses or small medium enterprises, if you implement and, and we follow of course, controls, controls or CSF, you get safe harbor, right? Because they understand that small medium enterprises are the backbone of the country.
That's how, you know, people are getting, um, compromised via supply chain. Someone mentioned CMMC, I mean, it's coming down the road. What it's going to look like, how it's going to look is, is another question. And you know, we, at CIS we have closed ties to government, to nist. We're trying to, we're trying to look at that and say, can we get CIS controls in there? Something practical. Um, uh, but I do, I agree, it's, it's coming eventually. What'll it will look like? I don't know.
But you see the demand signals out there at the state level and probably, um, we think it'll probably be coming at the federal level eventually. Excellent. Wait, oh, I really appreciate you coming on, Phyllis. We will have you back here. Gary, you wanna close this out? Um, any closing comments and thoughts aside from make sure you show up for Cyber Resiliency Workshop? Of course. Go ahead. Yeah, come, come, come to that.
But no, Andrew, um, listen, I think about where we are on these calls and the kind of conversations and, and just the feedback and the comments we're getting compared to six months ago. And I feel like we're all together, you know, maturing as a a community and that's what this is about. And, uh, you know, what I tell my customers is we, you know, we're gonna, we need to be out in front on this.
Um, you know, we're, we're either, you know, um, we're gonna be the steamroller or we're gonna be the patient. Yeah, very good point. Ryan, I saw you shaking your head when Wes said, Hey, you know, they all cross math. Any closing thoughts and comments from you? Yeah, I mean, I can un I can't emphasize how important it is to, you know, once you've attained one. And I think there's another point here of like, really pick one. Don't try to, I'm gonna try and do NCSF and CIS in parallel.
Pick one, do it well, then do your mapping and gapping against the next thing you wanna achieve and go from there. But like Wes said, whatever is gonna come down the pipe is gonna be mappable to what you already have if you've attained some standard. And you're gonna be in a much better position to understand how to attain that if you've achieved something already that you can map to it. Otherwise, you're gonna be forced to start this from scratch. So why not get ahead of that curve? Yeah.
Great advice, Wes, closing thoughts? Uh, no, we're out of time. So thank you Justin. Shout out to you specifically. Thanks for joining, sharing us your knowledge. Appreciate it. We are very, very fortunate to have you. Thank you for joining. Thank You. Yeah, Justin, really appreciate you coming on and I know we're out of time. Phyllis, wonderful to see you. Everybody. Have a fantastic week. We'll see you next week. Take care everybody.


