February 8th, 2021
In this video, industry experts discuss the challenges MSPs face in managing hardware and software asset inventories. They explore the complexities of maintaining accurate records and share insights on implementing effective processes and policies for better cybersecurity practices. The conversation emphasizes the importance of frameworks like CIS controls to guide MSPs in improving their security posture and meeting client expectations.<ul><li>The importance of hardware and software asset management is emphasized as foundational for any security strategy, highlighting that you cannot secure what you don't know exists in your network.</li><li>The discussion underscores the need for policies to set expectations and provide authority for actions within an organization, establishing standards and procedures that must be followed.</li><li>Frameworks like CIS's Implementation Group 1 are recommended as starting points for organizations to systematically improve their security posture and defend against common cyber threats.</li></ul>
Guests
Video Transcript
Welcome, welcome from the Tampa Bay, home of the Tampa Bay Buccaneers. What do you think, Wes? Hey, man, that, like I said, that Tim Brody, what a heck of a quarterback to tell you. So Gary, hard to mess with. Gary, you, you come and move from Philly and, and you come to Florida and look what happens. Yeah. Awesome. Bringing that. Good luck. Hey, I'm just saying, uh, Tampa won the, uh, hockey sports ball. We won the football sports ball and we should have won the baseball sports ball.
So, uh, not so bad. I know we're a bunch of, uh, retiree community. I know we're becoming the New England of the South, I guess. Alright, so we'll get right on into it here. By the way, we're gonna have Mike Beard join us. Um, I'm just gonna share out my screen momentarily. Just a few quick announcements. Number one, um, cyber resilience workshop. Gary, we haven't done Didley yet in terms of promoting this really, and we're already north of 200. Yeah. Um, for this, this is gonna be awesome.
We're gonna look at the business side of things. Uh, we're gonna have Ryan West, uh, Mike Beard, Chris la, um, Matt Solomon, and then technical days with Bryson Medlock and Jason Slagel. Um, if your technical team wants to understand vulnerability management, exploiting vulnerabilities, top 10 web vulnerabilities, um, there's gonna be a giveaway, uh, sponsored by Cyber Phish. You're gonna be able to win some time with Jason Slagel. So anyway, um, register down below, below Gary and West.
There's a link there. Gary, anything you wanna say about it by chance real quick before I move on? No, just that we have, uh, awesome minds, uh, great content. It's gonna be, it's gonna be really, really good. And the timing is right, we're, it's just an extension of what we're doing here in a bigger format where we can really push forward everybody's thought process and security posture. Absolutely. So, by the way, welcome Phyllis Lee, senior director of controls from CIS.
So great to have you with us as always. Thanks. Great to be here. Yeah. And, um, so I'm gonna share out my screen real quick, Wes, keep me honest here in terms of what we were hoping to do. And while I do that, um, I'm gonna put up a first poll for everybody. There's only three. Um, but I'm putting up a first poll for you guys to think about, guys and gals. And, um, let me just share out my screen just a few resources and things that we want you to consider for today as we set the stage. Okay.
So, number one, let me make sure you guys can see me. Okay. Can you guys see my screen okay? Yep. Got it. Yeah. Yes. Okay. So one of the things we wanted to share with you today, as we look at security controls specifically, you know, last week we talked about frameworks. And the reason we wanted to go into security controls and peel back the onion just a little bit, is, you know, I was talking to Wes and Phyllis and I said, you know, we really haven't, is there a course out there on this?
You know, yes, there is if you're, you know, in the enterprise and you're taking a sans course or something of that nature. But how should you approach controls? And Wessel's gonna kind of, you know, kick it off shortly about, you know, something that you would think is simple. Like, what's your inventory, what's authorized and unauthorized? Same thing on hardware and software and, um, what are your policies? But we wanted to show you the relationship between the two, why it's important.
And then Gary's gonna be talking from the perspective again, of the business side of this whole equation. How do you standardize on this? What roles are there specific to it? How does it impact your cost of sale, et cetera. So this happens to be, uh, the CSAT from CIS, it's a hundred percent free. You can do it on your own organization today.
Um, I'm going to be, uh, if I could use such a crude word, but I'm kidding around pimping out, uh, Phyllis's and CISs CSAT Pro, which is the multi-tenant version. And when I say joking around with that, but there's a, um, we're doing a beta and a potentially a tools only multi, it's a multi-tenant. It's a pools only approach, um, in their membership. So if you want more information on that, let me know. You can email me, uh, andrew@thecybernation.com.
Um, and then one of the things, as I listened to a YouTube this weekend on sans course, there's a great, and I'll put this in the chat, a great research. Now it Sounds like, it sounds like an exciting weekend, Andrew. It was, you know, I was doing that and, and, and, um, and a little bit of, um, a little bit of a football gar. It doesn't get any better, but this, um, resource called audit scripts has a fantastic, um, uh, free, um, free resources, for lack of a better word.
One of those resources that I came across in this, in this was this mappings. And it was, it was phenomenal. And I hope I'm looking at the right thing here. Bear with me guys. Uh, lemme just bring this up for you all. So a lot of times everybody wants to know, um, what, um, how does something map to another thing? And of course, this isn't coming up right now, sorry guys. But, um, let's see, is this it? No, continue.
Anyway, um, I'll try and get to it, but basically it literally maps every single framework, global framework to CIS. Um, and, uh, I really wish I could show it to you guys, but gimme one second. And there it is. Hopefully I can show this to you. Always fun working on a Mac. Nope, I'm not gonna. All right. So enough of that. Um, all right, so let me stop my sharing and we'll talk more about it. I'm gonna get Mike Beard on here with us.
But Wes, um, you know, when we were talking about this, um, and we had Justin on last week, we were very, you know, very, you know, high level talking about how he uses different frameworks, CIS to secure his M-S-P-C-I-S, more so for his customers on the policy side, but then, I'm sorry, C-F-F-C-S-F.
But can you walk us through, Wes, what, you know, something simple like seemingly simple as you were a bank practitioner and you have an auditor, um, in terms of the F-F-I-E-C sitting in your office saying, Wes, you know, are you patching everything? Kind of walk us through that, if you would, and why is it not as seemingly easy, um, as it might seem in terms of, Yeah. Okay. I can, uh, yeah, I can get us kicked off. And, and first let me say hey to everyone in chat and, uh, watching today.
Happy Monday. I don't know about you, but shout out and chat if, uh, this is your favorite way to get a week kicked off. I know it is mine. I'm glad these are on Monday, actually, because, uh, it's, it's the one thing that gets me excited and charged up and get into the week. So, uh, I want to hear back from you guys too.
And, and the other thing too, I wanna get you guys used to, um, chatting today, I will say one thing that I think we're good at it in cyber call is really trying to play off what you guys want. Like we've always needed our mission here to, um, educate, to share knowledge, to share best practices, bring folks on that are doing some innovative things like that is what we are all about doing.
And so, um, want you to give us some good feedback today because we're looking for it in some specific areas. So keep your, uh, fingers warmed up and, and ready to go. So, Andrew, to answer your question, um, as all the chats are, are pouring in, which is good. Yeah.
So, um, you know, you asked me that question like in my experience as a banker, like what's it like and, and why, especially with, uh, control one, why we start with physical assets and then control two follows right into software assets. And this is one thing we've said a lot on the call before, but I'll just remind it for the new folks that are with us today, is you simply can't secure what you don't know is in your network, right?
Good example of that is, I remember when I first started at, uh, at, at f and b at the bank, I remember getting a report from my regulators of a very, very large bank service provider. Thousands and thousands and thousands of employees. And, um, inside of that report, the reason they shared it with the, the customers of that bank provider was because they had some very negative, um, and glaring issues in their last, um, federal examination.
And what it started with was they had entire networks that had never been vulnerability scanned. In fact, these networks had never even really been known to the, the security teams at this, uh, big provider. I'm trying really hard not to say their name. I hope it doesn't slip out. Um, and it's, that's an egregious thing because the examiners said, you know, quite simply, look, if you're not even aware that you have networks that are alive, how can you possibly secure them?
How can you possibly do anything about it? And this, by the way, led to a very significant breach that they had, um, about six or seven years ago. So it just illustrates for us, like one of the conceptual beginning points to information security is, what are your assets? What am I actually trying to secure?
And I think this gets exponentially more difficult for MSPs because they're bringing in all of these client networks and they're inheriting the good or the bad that they brought in from previous IT management that that's come in, um, from, you know, internal it from shadow it, all of this stuff is a real challenge. And I remember, um, Andrew, like working with my examiners, that was one of the very first things that they would start day one.
So they would come in for two full weeks every year and sit down with us and grill us over a lot of stuff. We had a lot of document prep ahead of time. But one of the things they always started with right outta the gate is, show me your hardware inventory. Show me everything that's in it. Show me the last scan. Show me the details and assets around it. Show me how you classify it. Show me what it does. Very significant stuff. That feels tedious, but I know why the examiners are doing it.
Because they want to eab establish the playing field of like, do you at least know what you're trying to protect? If you have no idea what's there and have no good way to show me, then we're, we've got some other issues we're gonna have to work on, Andrew. And so that's a huge part of this. And that's why CIS Phyllis, I think you'd agree that's why it starts with, uh, control group one, or I'm sorry, control one being all about hardware and then software coming into, in, into group two.
Um, so maybe Mike Ard a question for you to open up. You know, you've been a former banker and I trust you as a CISO as much as anybody I can think of. You know, do you see the same thing? Is this like a huge key foundational piece and do you think it's easy for MSPs or is this actually a hard piece to kind of master? Hopefully my audio working. You're on. I think you're on mute, Mike. No, I can hear him. He, he, he's on the other mic again. Do you have a headset or Something?
Well, while we're waiting for him, because I can, um, Ryan, weeks, you want to take that question? Yeah, you'd have to ask it to me again though. Yeah, sure. I can ask you again. So, you know, this whole control one of hardware assets and, and building the inventory, all that kind of stuff, do you think that's a real struggle for MSPs? Is that a, is that a hard thing to accomplish or is it as easy said is done? I I think there, it's, it's everything's on a scale, right?
There's some that's easy for some that it's hard for, for, um, one of the things that we did, uh, a year and a half ago was we went out to several MSPs and, and embedded with them for multiple days in order to understand what their challenges were in building security programs and then protecting themselves against ransomware threats. And we started with, you know, pre-work before we even showed up. Please share with us your hardware, software, asset inventory.
And, um, what we got back was not a hardware or asset inventory. And when we started talking to them, we were like, what about this system? What about this system? Do you have something that does this? Do you have something? And like by the time we were done with the, you know, the half hour q and a on asset inventories, six x seven x, the number of resources on those lists, right?
And so I think it is an area that MSP struggle with, but like you said, you cannot begin to secure something that you don't know you have. And so it's, you know, it's kind of like, you know, you have to plan for success. You have to do the work to enumerate not just one time, but creating process to sustain that inventory so that you have that continuous awareness, continuous improvement based off of that updated awareness.
But it, it's, it's just impossible to build a security program, uh, that, that addresses the right risk if you don't understand what you have. Yeah. That's good. Um, Gary Peek, I know you had some questions for Phyllis around this, right? Yeah, well I was just, I was, I'm just, as you're talking, I'm thinking about stories, right? Popping into my, popping into my head.
And you know, one thing I was thinking about is, you know, one of the standards or, or, or best practices we recommend to people I is, um, a check on their, on their inventory and a check on their, um, software and tools. And they always think they're gonna come back a hundred percent. They don't even know where their tools are, are, are, are, are loaded. They come out about 85%. So that means 15% across their client base are things that are in some way unmanaged, right, in, in different ways.
'cause they have a, a stack of things.
So I I, I find that like super interesting and a lot of times when I hear about some security things and I ask about it, that's one of the reasons that we get like something happened on the machine or something that they didn't know was there, you know, so what I want to say with Phyllis, when you're dealing, you know, in, in your experience with this, what are, what do some of the best people put in place, the ones who are, you know, getting this right and avoiding some of the things that Wes and Ryan are talking about, like how are they getting there, Right?
And I mean, I I, I wanna beat the drum. Everyone says controls one and two are the hardest things, right? Hardware asset management and software asset management. Um, you know, the number one question that many organizations have to answer are, you know, is it patched? Is it up to date? And so when we talk about hardware asset management and software asset management, it's not just an IP address. It's these attributes that you wanna collect around it.
Because later, um, you wanna answer some questions if there's an incident or, um, you know, something bad happens. So for example, you know, even us on the controls team, when we think about what controls or sub controls or safeguards need to be in the document, we think, can it, number one, is it a mitigation? And you look at controls one and two and they aren't a direct mitigation to an incident happening.
But what ends up happening is when you go back and you say, oh, how do I patch this box? Or does this box have, um, critical data on it? You really need to know some, um, attributes around that. What version of software am I running? Where is it running? Um, you know, as far as your hardware assets, what's its role more than its IP address? Some people wanna know what kind of data is on there.
So organizations that really, um, can recover, which they're very few or quickly understand, um, what happens after an incident really have, uh, drilled down to the attributes around hardware and software inventory, which It seems so basic. It seems so basic. And it's, and it's such a big issue today still, right? Oh yeah. Oh yeah. It's huge. I mean, I mean, how many, and I came from former government, how many people, how many CIS admins can say, is it patched? Is it up to date? Right?
Like, there's no standard way to express the version of software the organizations are running on their network. So it's very difficult, um, for, for organizations to figure that out. I mean, the department of head of defense has spent hundreds of millions of dollars just trying to answer that question.
Uh, I don't know if we have Mike, but I'll go to Ryan 'cause you're, you're going where I was kind of gonna go, which was a lot of MSPs, they, their first line or sometimes their only line of defense on this is their RMM and that can't, at least today's RMMs, maybe they'll be different in a year or two. Um, but today, that doesn't get you there, right, Ryan? No, I mean, it, it's such a small portion of your hardware assets, right?
You can get some of your software inventory and some of your hardware inventory and, and, you know, hardware assets from there. And you could, you can do a lot of damage, don't get me wrong. You could, you could probably fill in 60, 70% of your asset register with your RMM, but you're still gonna miss things like SAS software, um, that you're using. You're gonna miss things like mobile devices that might not be RMM managed your networking equipment. That's not RMM managed.
Any other sorts of appliances that might exist within your network. Um, there's just a lot of things that when you really start to examine inventory fall outside of what you might manage, uh, with your RMM, um, so, you know, you, you're gonna have to get creative about how you identify those things. The, the, the best thing that from personal experience, right? When I get the data and said, I need an inventory, right?
I said, gimme the cam table from all of the switches, and then I want go, I want to go through and I wanna prove that we know what every single one of these MAC addresses are on our network. 'cause like your network is pretty much your authority in terms of what hardware assets exist within it. And then you're gonna need to augment that understanding with any SaaS services or cloud services.
You know, if you're using like Azure, you're gonna have to augment that with like Azure, um, API calls or inventory. And so, you know, it's more important just like, where do I have the assets? And then start thinking about what types of of tools do I have or processes do I have to get to get a full insight into this? RMM is one of them, but it is not, it is it No way. The the main one. Yeah. And so you end up, people will cobble together different pieces that do different pieces of that.
And then just that complication of it, right? Um, creates some risk. Uh, at least that's what I, what I see. And then just think about all the things that have been rattled off Andrew, so far, just in the first 20 minutes of this. Um, now you're not someone who is, you know, a a a mid-market enterprise company with a thousand users. You're an MSP with a thousand users, which means you have 50 customers.
Like, think about operationally how much time and effort has to go in to, and most people try to do some of this at onboarding and then six months later they have six month old, uh, information. 'cause it's not really part of a process. So, and I wanted to get to Mike's take on this of just kind of sharing with people if as Mike is on just kinda sharing with people, like just getting through these first couple controls is like a commitment.
It takes some roles and, and process and someone's gotta be accountable across the customer base. Yeah, absolutely. Mike, do we, can we try again with you? How are we now? New laptop windows default settings. So Mike Beard, CISO of Marco with us here. Mike, you Mike, thanks so much, uh, for, for joining. And I know you've got some great question, Gary.
I know you've got some real specific feelings on this and, and I'm glad Gary, you teed up this whole hey dude, because I think a lot of MSPs think it's just RMM and there's so many facets to this now, Mike, just to kind of hand to you everything from free software, virtual machines, um, you know, uh, uh, you know, um, oh, I was gonna say, I'm drawing a blank on the now. They're Spread out now. They're everywhere. These assets are all over the world now. Yeah, yeah. A absolutely.
Um, and, and shadow it. So Mike, your, your, you know, your thoughts 'cause you handle this both internally for a very large MSP and then externally. So please, Yeah, no, thanks for having me on. So, I I, I'll be upfront, I missed probably the last 10 minutes trying to get this audio thing worked out.
But my, you know, here in RMMI guess my first thought, whenever, whenever I talk to other MSPs, be it peer group conferences, et cetera, all too often I think we rely on the RMM tool as the catchall in our space. Um, and to be frank, it does a good job of what it does, but it doesn't do everything right.
We're gonna get the Windows assets, the MAC assets, those types of things, but that shadow IT concept, uh, you know, here in West talk about, let's spin up another subnet and go, it's not designed to go after things like that. You need a different tool set to look for different VLANs different networks within the environment. As soon as we take things elsewhere, that's a just a, it's a different tool set altogether.
And, and that's, um, I think the world's reacted to how did enterprises do it largely with SolarWinds, right? And we, we've caught that recently that that was one of the tools used to do so. And there just aren't many tools out there that compete against SolarWinds, for example, um, in, in the large space, right? So we know that the large space struggles with it and they typically try and solve it one way. Let's pivot that. How do, how do we go after it?
Because that's absolutely a problem that we as an m ms P faced and we face that internally as well. Um, we, to be frank, we, we've addressed this problem pretty recently. It's not one that I'm gonna say we're, we're great at, we're evolving just like everybody else, but where we're at in our evolution, we're now incorporating a couple of new tools and, um, vulnerability management detection's one of 'em.
So that's one way that you can go after this problem because that does a really good job at scanning subnets. It goes after networks. Um, the right vulnerability management tool will allow you to then classify those assets. And anybody that's been through a, a third party NIST CSF or CIS audit and you're looking at more advanced maturity, you have to actually be able to classify those assets as well. So you need tools to do that. RMM tools don't really do that today.
Sure, you can put a tag on something that, hey, this is a critical thing, but a tag is not classification, right? So there are differences in that maturity as well. And, and that's why we've now incorporated cyber CNS for example, into our, um, into our stack that allows us to do one vulnerability management detection, but two really go after those assets in a, in a more meaningful way. Um, so, so that's how we manage ongoing.
And I think I, I heard Gary or or Ryan talk about this too, but it also changed our assessment approach as well where initially we'd go through, we'd fire off rapid fire tools just like everybody else in the industry does. And that does a pretty good job. 'cause that does scan networks and it does some additional things over and above and beyond what the RMM tool does. But again, it wasn't catching everything.
And that's where now we're evolving to where we're using different, we're using multiple tool sets to do assessments. Cyber CNS is one that we're using because that does do a pretty good job of picking up iot type devices. Um, we're, we're complimenting those things and, and ultimately one of the key things is are you validating that the tools that you're using come back with the same numbers?
I can't tell you how many times we'll deploy something and it'll be, hey, the RMM agent says that, you know, we're managing 53 workstations. The vulnerability tool says there's actually 75. And then we'll run another tool that says there's actually 67. Right? When we get those three sets of different numbers, she, Ellis is shaking her head up and down, which one's the right, which one's the source of truth, right?
That, now if I look at that and I've got three different sets of numbers, is there overlap there? Hopefully there's a lot of overlap there. But even there, the one that has the most things, it may not be the same set of systems as the other two tool sets. Like it might have found something else. So what are we doing to reconcile that? That reconciliation process really is one of the most important pieces.
'cause what we'll find is some tools pick up things like door badge readers and even some of the vulnerability tools out there don't know what they are, right? It might completely miss it if it doesn't respond on the network or something like that. And then I guess I, I'd leave it off with that. There is still that, there is still that just that knowledge mindset, right? So part of your onboarding process, I'm pretty sure here Ryan, talk about this. Just asking those questions, right?
Like making sure that your question scope is expanded to, Hey, do you use proximity cards? Anybody have a badge card to get into a door kind of a thing? That's a, that, that should be a sign, right? If the answer is, oh yeah, I use that all the time to get into the back door, alright, now I need you to go see is it network connected or is it still an old digital system? Whatever. But those are some things that can give you that, that are keys, right?
They're clues as to what else might they be using that might be on a network somewhere that you don't see. Because all too often, again, we will come in and we'll find that those types of things are still running on a linky or NETGEAR switch in the back closet as well. That's all isolated, right? They're, they've fully isolated that system out and then the IT guy went and connected the network cable across into their corporate network 'cause he wanted to administer it easier. Yeah.
Mike, can I just ask one question and then I'd love phyllis's take too on this just, but Mike with work from home, has that even like thrown even another wrench into the whole, you know, thing? Oh, for sure. Um, again, that, that reconciliation process, right? How many assets do I actually have? Do I actually control it?
It's made that more challenging because as soon as somebody goes off network and hey, there are MM agent, maybe it's even installed, it's just not working, not checking in, it's really easy to lose visibility into that system. And that can snowball real quick. Um, right. Typically if we lose access to one agent, it's not uncommon then for antivirus to drop off 'cause it's not getting patches and and whatever else. And now all of my numbers are off and that's, that's a bad thing, right?
For, for me, the MSP because I've got a probably a security commitment, a lot of contractual commitments to that customer. I'm also probably no longer billing because they, they fell off, right? So it's, I'm not, you know, hopefully I am, there's a other, obviously other ways to grab that information, but it messes up a whole bunch of things real quick. Yeah.
Phyllis thoughts and Gary, I'll turn it back to you after, but I saw, you know, Phyllis was certainly shaking her head on this kind of stuff. Yeah. So I was shaking my head because trying to find, you know, high fidelity data on what's on the network is, is is what, you know, many organizations spend, um, you know, like the Department of Defense in particular, hundreds of hundreds of millions of dollars trying to figure out what version of software am I actually running, right?
Um, because then you wanna know where do I need to patch? Where's the critical data, et cetera, because data is kept in different parts, right? Like, you know, if you look at Windows, not everything registers itself in the same place on the registry. And I think work from home is, is very challenging. I think when you talk about, um, having a hardware asset inventory and software asset inventory, I mean, there's also a rollout, an enrollment program associated with that.
And a, you know, hey, you know, is it Patch Tuesday? Not Patch Tuesday? What does that mean? Um, for, um, you know, perhaps EDR or whatever on your host. And so what ends up happening is that I think many organizations were used to this traditional, I'm gonna take my laptop into the home office and we'll do this other check for, for something. It's 'cause I'm required to do that at a certain cadence.
Um, but now that you're home a hundred percent, you know, you have to think about all these different policies. Like can you print something out at home? You know, what does that mean? Um, does your home printer become part of the enterprise?
I have a friend who's a lawyer and she had to tell her other people like, you cannot print, um, these cases out on your home printer because that's evidence, like evidence stays on your laptop in your vp, you know, you know, you VP n into the home network, et cetera. So, um, I think, you know, work from home is not just the technical part of updating and all this stuff, but there's also this policy end of it that shows, um, what are those requirements for the updating, et cetera.
And how is it that we enforce that, um, technically Sure. Hey Gary, we got a business question. Can I throw it your way? Yeah, go ahead. Yeah. So Jason asked, which I think is a really good one. Um, you know, what do you guys think about clients that pick and choose what they wanna have managed? How do you respond? You know, like, Hey Gary, I don't want, you know, we don't need to worry about that. You know, et cetera, et cetera. Take, walk us through that, Gary, I'll take it a step further.
Clients will either tell you what, what they want to have managed or not clients to tell you, um, how they want you to support them. Like, Hey, I just, you know, read up my, you know, uh, my virus protection, so I wanna use that for the next year. It's like, no, right? Because, uh, it's not about virus protection. It's like our job is 50% process on that and it doesn't work that way.
And so I think we've reached a point, Andrew, where before it was just like, listen, from the very beginning I've said no to those things. 'cause I would rather have one good customer than five, you know, less fit customers. But it's different today. I just think you, you can't let customers, no matter what they say, they're going to expect something different than what you can deliver in those scenarios. They're gonna, they all think they're secure.
So if they're not taking our recommendations, they're not letting us manage things the way we want. If they're not willing to pay us what we need to pay. 'cause everything you just heard so far in the first half of this call, um, has to be done by somebody who doesn't do support tickets and who's not billing projects or running your tools, right? For, for, for, for a lot of it, right? And so who does that? How do they do it? How do we get paid for it?
We've talked about it, you know, on, on many of the calls before. But, um, the long answer to a short question is those days are gone, Andrew, of being able to take those customers. Well, not only that, but you know, we've had Justin on before, for those of you that know Justin Ry, um, we're sure we'll have him back again. But Gary, it's the same thing.
Like in a court of law, the, the defense attorney's gonna sit there and go, okay, so how did the architectural firm know that that's not the right way to do things? You are the, you know, you are the expert and, and yeah, I got you involved in one today where they need expert witnesses. Yeah, right. It's happening every day. I, and you know, they're emailing me like, you know, I'm, I'm just a radio host And what am I, I'm a broker now And a managed service legend. Yeah.
And I'm a and I'm a broker. Yeah. Call this, call this guy. So anyway, Gary, go continue. Please. Yeah, yeah. So I, I, I just think with all of this, I want you to hear it in two ways. I want you to hear all the great minds on here telling you what people went through or what they did, the importance of this just starting at the first couple controls. Then I want you to constantly be thinking about it across your customer base, at your own, at your own MSP.
And how are you gonna operationalize this? How are you gonna do it? And how are you gonna do it in a way that you can do it consistently, uh, and not, you know, go in and spend the time and just do things in onboarding and then have six month old data. Unless it's someone who's accountable for it, you can't do it. And again, there's a cost to it, Andrew. Yeah.
It also, and Mike, you know, maybe I could get your take on this about, you know, a lot of MSPs are always looking at tools, changing tools. Gary, your your take on this too, but man, when you look at the fact that you really need process around this, Gary and peop again, and you always equate it to, you know, MRR seats under management, how many people you need to do this, but wow, way more process intensive here. Um, than it is, Hey, let's try to change another tool. Mike, thoughts on that.
When, and, and Gary, you, you as well, but Yeah, I, I wanna hear Gary's take first 'cause I, I've got something I wanna say, but I wanna, I wanna feed on that. Yeah. So I, I'll just real quick, I'll just give a different perspective, which is the math Okay. Uh, on it. So let's just say your tool stack, if you figure it out this way, and you should, is anywhere from 12 to $18, uh, you know, per seat, it's probably 25 to 30% of your overall seat cost.
What you need to do with some dedicated proactive roles, uh, is probably gonna be almost the same. So they're almost equal. And now they're gonna be the lion's share. They're gonna be 70 that, uh, you know, your labor and tools without support are gonna be 75%. So think of it in that way, Andrew, that you have to know that math or there's no way to go to market or back to your customers and be able to have a conversation.
'cause if you don't have the roles and resources and you aren't getting paid for it, you won't do it Right? Because you have to do everything else. Right? Right, right. You Have to do everything. You can't not do everything. You can't not do tickets, you can't not do the projects. You said you can't not run the tools you already brought. Like you can't not do those things. So that's why we're here today and that's why we're dealing with all the things that we're dealing with. Go ahead, Mike.
Yeah, no, the perfect setup actually, I would say process is the other piece. And you alluded to that the, the process really is the magic sauce that comes into it. The, the tools don't matter. And I think I said that a couple months ago, right? The tools really are just widgets changing from one widget to another. They're, the grass is always greener, I think tends to hit our industry pretty common.
Um, you know, I use one vendor today, let's maybe look at another vendor 'cause they do something that the other one doesn't. If you don't have the processes down, it doesn't matter which vendor you go to. So process maturity is absolutely what I would be focusing on. And then it goes back to, to what Ryan put in the comments. I I can't hit that one as well with follow the frameworks, right? Sell on the value of the frameworks process and process integrity is 100% a part of the frameworks.
So ensuring that we've got that down, then the rest typically falls into place. It helps you sell it, it helps you operationalize it, and it helps you deliver it. Ryan, go ahead. 'cause you, you had said something there. I'd love to hear it. Yeah. Hey, Ryan. Uh, yeah, I mean, I think the question was around like how do you sell that to the business side of the MSP, right? And like, this is every security person's challenge everywhere from, you know, wherever you are, right?
Is, is how do I help them understand the complexity of the thing that, that they don't understand? And, and unfortunately you have to put it in terms they understand, which is dollar terms or market opportunity or Right. Think about, think about the question from a business perspective, not from a cyber perspective. If I accomplish this framework, what would it do for the business?
It would reduce our cyber risk profile, which means less liability, less, um, you know, lower potential damage, um, you know, better potential recovery times. And it would be something that could differentiate us in the marketplace that we could use as collateral that we could use to acquire new customers. It could set us up for a team of some other type of compliance in the future that, um, allows us to enter a new market of SMBs.
Um, and having those kind of business conversations around the value of the framework. That's how you're gonna get business. Buy-in. You're not gonna get business buy-in because saying, we suck at doing asset inventory. Someone will just look at you and say, so go do better, Right? Yeah. Just so go, go fix that, right? And you're like, well, no, there's a hundred other things. And they're like, okay, yeah, there's always, there's a hundred things that we have to decide every day, right?
You really have to break that down for them in a way they understand it. Like a hundred percent cannot agree more with process people and process number one, technology number two, right? If you don't have a process, whatever you're doing is not repeatable. If it's not repeatable, you do not have maturity. Yeah.
Uh, so I, you know, I always tell our, you know, I train our true methods members when they're talking to customers and prospects to explain to 'em that, listen, your cost have already changed. Didn't your vendor tell you that you're either paying, you can pay me to do it in this way, or you can assume the cost and risk. So I wanna say that same thing now to everyone who's listening as an MSP, your costs have already changed.
You can either pay them in the way that Ryan is talking about with process, or you've already assumed that cost in terms OO of risks for you and your customers. Yeah. I mean, sometimes it's as easy as putting a dollar figure on it, right? Like there is, um, there's a piece of quantitative risk data that came out about the a hundred largest data breaches. And, and of course most MSPs aren't gonna really be in that kind of realm of things.
But it's interesting because 80% of all losses happen between 10 or a hundred K and $10 million. Um, and so, you know, there's extreme losses and then it breaks out extreme losses, which is north of 10 million. Um, but like if you just look at that and you could, and you had, you had some actual data to ground the risk conversation in or just table topping, what, how long would it take us to recover? You'll talk to another MSP that has had a ransomware incident, understand their costs, right?
How much did this cost you in the end, putting a dollar figure on that and then trying to, to, you know, would you rather pay for this every single time it happens or pay for this once to reduce the likelihood of this thing happening at all, right? And putting it in those terms is really, and you're gonna have to do some legwork to get that data and to have that conversation. But I promise you that's gonna be, you know, a good conversation.
And if it's not, you know, you do need to understand that the business is allowed to accept risk even if it doesn't make sense. Hey, hey Phyllis, can I ask you a question that came in the chat? She asks, um, about ms. So she says, do we have M-S-P-M-S-P framework and process guidance we can utilize to have a strategic conversation?
So I'm gonna ask this to you, Phyllis, because I think that's part of what we're trying to, um, you know, share here around, you know, something like, um, CIS especially, you know, not only for the MSP, but you know, the multi-tenancy for their all their clients. And then Wes, maybe we can pivot to you. I think the framework really depends on, you know, who the end customer is.
Um, you guys have done some great work around CMMC as an example and mapping, you know, your solutions to that control. But Phyllis, your thoughts, and by the way, Phyllis, maybe we could even just quickly touch on control eight point coming out because it might shock some MSPs what a new, um, SubT control is, is living in there. So take it away. I think this will be a little interesting, Right? So there, there really isn't, um, to my knowledge an MS P specific framework.
And honestly, I don't know that, um, that's really necessary other than like, you know, MSPs, the way you implement it could be different, right? So I would, I I'm not a believer in, um, that everyone is a special snowflake and you can go through the NIST 800 dash 53 and individualize your program. I think the majority of us are subject to the same thing and we can implement, um, a lot of the same best practices on our network. And that's where the controls come from, right?
The CIS critical security controls, we have experts from all different verticals who come together and try to come up with this com, you know, um, prioritize list of things that you can do based on a lot of it based on attack data, um, that we see in the community. So we really try to back our choices by data.
It is true that if you were to have an ISAC or I, or an isal, for example, if, um, I know, um, I've talked with PCI and the small credit card vendors have a top five attacks, you know, that they should be looking at. And, you know, you, you could possibly customize it that way if you have that kind of data. But I would say for the most part, um, looking at a broad framework should be, should be good enough for, for, um, starting, uh, what was the second part of the question?
The second part was You just version eight. Oh. And what we're gonna see, because I was really, So, um, I'm in the throes of finalizing the next version of controls. One of the major thrust behind updating the controls was this knowledge acknowledgement of, you know, we're no longer have, you know, the boundary, everyone's moving towards cloud, we have remote. So the controls main document now includes cloud and um, mobile devices.
Um, one of the things that we've done is added a whole control on service providers. And that is really a nod to the fact that so many people are outsourcing their it. And how is it that you manage a third party service provider? What kind of program do you need in place to make sure that you're managing it appropriately? And it really is all about process. Yeah, right? Um, what is it that you need in your service level agreement, et cetera, et cetera.
Not necessarily those details, but make sure that you have it, check it annually, et cetera, et cetera, whenever your contract is up for renewal. So, um, you know, and this was suggested to us by the editorial panel, you know, it wasn't us, it was them saying, you know, everyone's moving to cloud, we need to give this guidance. Right. Really interesting.
Wes, any, you know, you, you've been, uh, off camera there, so you know, you, you typically have the best view out all of us, so I'm kind of curious what's going on, but, and Ooh, Andrew, I think I just lost everything you said. You might be on mute. There we go. Hey, Andrew, I lost, I did not hear what you said. Can, can you hear me okay? Yeah, I can't. I got you lagging A He's lagging a little. You're lagging a little. Andrew. I, I, sorry.
Um, yeah, Wes, I was just wondering if you could give some perspective on, on this as well. Um, on, on maybe what specific piece, Andrew? Uh, hold on. You, can you hear? Well, let me, Yeah, I can hear you. Yeah, yeah, yeah. I can go off script. I, if you need to a little bit, I want to ahead come back to, okay. I want to come back to, to one piece.
Um, so, you know, I think, I think these questions around like, how do I get my clients to truly want to buy in and believe like this is the direction we need to go, right?
That's a risky, worrisome conversation that I think any MSP that's listening is thinking about here of like, do I really want to go all in, start going down the CIS control group pathway, teach my technical employees, educate my sales team on why this matters, and how to pitch it only to have a bunch of clients say, no, don't like it, not doing it. And I've built my stack around it, my solution around it, my, my, my pricing and packaging and my margins are built around it. Like, that's scary.
I don't know if you've thought about that before or not, but, you know, I think about that at Perch. Um, occasionally I'll talk to a partner that's new to Perch and they'll ask me a question like, Hey Wes, you know, why don't I just spin up my own sim, maybe my own elastic search and you guys just manage it for me. My answer's always like, Hey, I'd love to do that.
Um, but the cost of me doing that, I mean, if you want me to send you a bill for that, it'll probably be about 30 to 50 times higher than what purchase currently charging. Like really? For real? I'm like, yes, we've built our pricing and our efficiencies all based upon how we operate as a group together, bringing you guys all into management into one platform for us. And that's when they go, ah, okay, I got it. I see.
I'm like, so I'm not saying no, like I can go help you find a, you know, another MSSP partner that can co-manage in a situation like that, but you'll never get the value and cost delivered that way. Um, and just saying that confidently of like, I I hear you, it just can't be done. Um, it, that goes a long way with, with a conversation.
And I think for us as, as MSP's talking to our clients, they, sometimes they're asking these questions not because they're attacking, they're just really trying to get their mind around all of this. They're going through those hurdles like thinking for them. Like all of a sudden costs have changed for us. All of a sudden threats seem different. And I'm just trying to figure out what this means for me and what this does for me.
And so I truly think having that conversation with your partner to say, look, this is the direction that we've gone now. This is the way that threats now exist and look in today's modern age and you know, you don't have to understand everything about the direction we're going, but we simply can't afford to secure you and ultimately deliver you it value where you can do your job and not have to worry about all this without going down this road.
This is just a requirement many times, I don't wanna say every time, but many times a client will hear you and they'll say, okay, fine. I just wanted to ask the question. Right? They just wanted to know. And I think going through that, those middle exercises in our minds is really valuable to us to have that practiced answer that comes back with that confidence and command that gets them comfortable with why, you know, because I think we're often afraid of that. Gary, don't you think the same?
Yeah, I was just typing the comment here to say that today's content, just this call today alone, you could have this conversation appropriately back to customers and prospects about this one little piece of it, right? And then extrapolate out about how much more has to be done. Um, you know, as you go further, you know, down that stack. And to be able to say to 'em, listen, this is all stuff I didn't have to do, uh, a year ago.
Maybe I should have been doing it right, but the risks weren't there. Now I have to. Or you say to a prospect, this is all the stuff that has to be done. Your vendor isn't doing it, they're not gonna do it, and they can't do it at that price. So again, Andrew, every week we talk about these things, this happens to be one conversation. You know, not the only one, but one easy one that you can repurpose to customers And prospects starting today. Yeah, no doubt. Can you hear me okay now, Gary?
Any better? Yeah, better. Okay, good. You know, Wes, can we shift a little bit on, on just to touch on policy here and, and, 'cause we really wanted to talk about the implications of something like yeah, one control like hardware. And we were talking about, you know, and, and love beard's take on this too as an MSP, what's authorized and what's unauthorized like as an MSP, right? Phyllis, I know we've talked about this, right?
How do you, you know, how do you go into a customer and say, Hey, no, ma no, no, that's not gonna happen. We don't manage that. So Wes, take, take that First. Yeah, so, you know, one of these days we probably, this can be more of a boring topic, but I know Mike's gonna agree with me. This is, policy is really important because policy sets expectations, policy sets, approvals from your clients, from the board if they exist, from whoever has executive oversight of the organization, right?
Like, put yourself in the shoes of the CEO or if you have a client of yours that does have some kind of steering committee or board, they're, they're the shot callers, right? And the, the policy is where you draw the lines in the sand and you set the standards and it says, it shall be done this way. That's why they're really, really important. And I remember having conversations with my examiners and they would often say to me like, Hey, it's not my job to approve what's in the policy.
It's my job to look and make sure that you actually have that policy in place and that you're following it as the board has approved it. Like, that's a big deal in the policy, right? So you should never have something in your policy, for example that says, you know, we shall have no breaches. Like that's not enforceable, right? Or something ridiculous. Like, employees will not use the internet for their own personal use. Like that doesn't, sorry, we're, it's not in the nineties anymore, right?
And so, um, you know, policy is important to set those standards and to communicate with those standards should be, and then give us the dictated authority to be able to follow those things through.
And so that's even why when you look at the CSAT that Angie, you first showed your screen out on this and you, I don't know what we paid, but even there in following the controls is an opportunity for you to go and trace back those controls to say, Hey, it's great that we have it implemented, but is it documented in policy in some form or fashion? You don't have to have a policy for every control group. It's more about making sure the overarching policies you do have give guidance into that.
Mike, don't you think the same or what else would you add to that? Yeah, no, you hit it and I think there's a misunderstanding of what policies have. And, and you just set the stage for that, right? Policies should give authority to somebody to go do something. They should set standards or say that standards should be set that we should fall within. And then they should establish that procedures need to be set and followed. And, and that really is the, the core elements of policies.
I think all too often we look at policy as the golden book that tells you everything, right? And that's, that's actually not the case. A a policy to your point. It needs to be things that are enforceable and consistently followed and A alive, that's it. And a alive and a alive. Most MSPs treat policies the same way they treat their business plan, that they work on it once and put it until next year. That that's exactly it.
So yeah, and that's, that's the key to success I think, is that, you know, create those policies, make 'em, make 'em living documents, adapt to changes within those policies, and then, um, you know, have a good supporting infrastructure to follow it. Hey Andrew, I don't, I dunno if we'll have time today, but maybe next week I'd like to see a poll of how many people have at least one technical role in their business that is dedicated, proactive.
I'm not even saying all security, just dedicated, proactive, no support tickets, no billing dedicated to all the things we're talking about. So maybe next week we can open up with that. Um, and I think it'll be interesting. Yeah, I'll get it out there. I just put a, I just put a poll question out, Gary, just in, you know, in general, would you guys like to have a cyber call on policy? You know, granted it's, it's dry mark, um, uh, Stein and um, of Coan and, um, hi and the CEO there.
Um, Brian, um, drawing a blank right now on Brian's last name, but he's on five or six MSPs and they've matured and I think for the last six, seven years. All they do now is, um, they work with MSPs, but they focus in the mid-market on compliance and, and helping organizations from like 10 million on up, um, uh, you know, prepare for audits, um, and help them, you know, map and write policy. Um, might be an interesting one.
Again, if you guys and gals could vote, it will tell me whether we should do that, but they would be a great one to, to, to bring on with us. Um, Ryan, any thoughts? It's good to see you chuckling and, and, and, you know, but uh, was there anything thoughts around policy? Obviously you've gotta deal a lot with it as a public company. I know. So Yeah, I mean, uh, listen, policy is not fun, but at the end of the day, right, you don't need to think of policy as a 200 page document.
You need to think of it more as a framework of the right, the right thing to do. Right? Not like, you know, when I get in my boat and I drive over to Long Island, I don't, I don't have an exact route, but like the buoys are there to keep me from, from hitting a rocky Shoals, right? So like, it, it's more about those navigational ways than like an exact path. But there are a lot of tips and tricks that we could cover in how to make policy interesting.
How to use it to influence change for your business. Um, right. And I think there's like a policy for where you are today, policy for where you want to be and using those two different perspective, like we could do a whole bunch of stuff on policy to make it fun and interesting and, and to use it to drive some, some of those people process technology conversations that you're gonna Have to have. Great. Um, look, I know we have a few minutes left here. Phyllis, I really appreciate you coming on.
Do, can you chat a little bit about, um, you know, the controls, what, what your hope is, you know, maybe doing something tools only. 'cause you know, we, we've been working in a beta group with MSPs. I'd love to extend that and get more MSPs involved in, into, you know, utilizing a multi-tenant approach and a standard. But maybe just share a little bit about what you guys are doing with CSAT Pro. Uh, what's going on at CIS and, You know. Yeah, sure.
So, CSAT Pros, our paid version for csat, which we call hosted, we're very imaginative, CSAT hosted. Um, and that's, that's the free version in our cloud instance. And, you know, we had gotten a lot of requests from, um, really big companies and governments saying, Hey, we really like csat. We wanna do our self-assessment against your controls, but we don't want our data, uh, in the hands, in your hands. Um, not that we look at the data, but we do get a summary of data.
There is an industry average that's provided as part of the tool. So, um, we took that demand signal, we created CSAT Pro, which is on-prem. Um, you do need a subscription for that. Now the, the secure suite subscription CIS is a nonprofit. And so this is a way that we are self-funded is we sell secure suite memberships. And typically that's around our benchmarks, which is, which is our, um, configuration guides. And so we have some tooling around that.
However, because we have had the demand signal for controls only memberships, organizations may already have tooling on their network for, um, benchmarking, uh, configuration guides, et cetera. And so we are working with our business services to have a controls only membership. And hopefully that will be, um, at a better price point for, um, small consultants who wanna consult on controls as well as, you know, the MSPs. Awesome.
And I put my, suppose I put my email in chat if, if you're interested in learning more, getting involved, um, with the beta, um, right. Also, um, you know, Wes, Phyllis and I are working on a control, and again, I'm air quoting a Control a Day podcast, you know, short, um, pithy where we talk about, um, how to implement a control, the specific control, what it's about, how it maps the policy compliance. Um, possibly have a few sponsors at the end, not part of it, but you know that.
And so if you think that that's a good idea, uh, Jennifer, awesome senior you is always, um, let us know as well. Um, Gary closing, closing thoughts on, on today and um, always great to have you with us. Yeah, really good. Uh, call today and the things that we're talking about and that we're gonna talk about around policies, like that's where we have to put our stake in the ground. 'cause a lot of the other things, the tools, their capabilities, they're gonna change dramatically.
There is more money pouring in the solve security problems right now with startups than anything I've seen in 25 years. Like there's un all this, you know, trillions of dollars of dry powder. A lot of it right now is being aimed, uh, at security. And so as that happens, the things that we're talking about on these calls are, are that's the standard. That's what we're gonna be left with moving forward.
So it's super important that we understand that and then we'll be able to take advantage of the technology as it changes. Yeah, really good point. Mike, thanks so much for joining us. Any, any closing thoughts for the MSPs out there and how they might be looking, you know, at, at controls and, and and frameworks from your perspective and process? 'cause you, you've made some really good points. Yeah, just pick something and start somewhere. Um, everybody's journey starts a start.
You gotta start it today, right? The sooner you can go on the better, uh, know that it's not a destination, you're always gonna be on it. And I know that's very cliche, but it is very true. Um, and, and I think implementation group one is a really good how to get there roadmap. So if you've gotta start somewhere that is a really good technical guide of getting you from point A to point B doesn't get you to point CDEF, but it'll get you to point B real quick. Yeah.
And Michael, you say that everybody the minimum, like that's the minimum. Like if you're not there, you gotta figure out how to get their ASAP this year. Yeah, IG one and, and, and Phyllis just real quick, good, Mike. No. Yeah. If you're not a landscape company of three people, you should be doing IG one today. Yeah. And, um, and you know, Phyllis Mitre attack, not that, if you know about it, great. If not, that's okay. But what percent of the top attacks is IG one going to take care Of? Right?
So, um, implementation group one, um, can defend against the top five attacks as, um, as described by the Verizon data breach report, which is, you know, malware, ransomware, which we pull out of, um, malware web application hacking. I think there's like some criminal, I forget the categories, but if you look at the Verizon data breach report, so we created the Mitre attack patterns for the five top attacks, right?
Or we got them from else other sources such as MSIs sac, and then we mapped implementation group one, um, to the attack techniques to see if they were mitigating against those attack techniques. And they were so, um, you know, this idea of how is it that you show, why would you have security? We often get that question, how do I justify spending dollars on cyber to my board? I'm a big transportation company, all they care about is uptime.
I'm a manufacturing company, we're just worried about, you know, these other things. And so we came up with, um, updating our, um, community defense model to show, you know, the value of implementing, um, sub controls or safeguards on the network. Fantastic. Wes, you're always short on closing comments. You li you're like, it's the top of the hour. I, I I want something besides that today. Okay, fine. Um, I am one minute late to my next meeting, so I'll wait in 15 seconds.
So let's keep this conversation going. We really did want feedback from you guys. I think we got a lot of it from the poll questions and answers. Um, but there's a number of things that we need to continue the conversation on, not just around training, but, um, Phyllis even mentioned those that are interested in a control only membership. I think they have some interest there. Guys, we are very fortunate to have Phyllis join us from CIS Phyllis. There's a lot of ways you could spend your hour.
Um, so to spend it with us does mean a lot. And personally, I wanna thank you and CIS for caring about MSPs and caring about the s and b industry as a whole. Um, it's taken many years for us to get there and I love that CIS is seeing that as well and carrying that torch. Um, so, so this has been very helpful with your collaboration. Thank you so much. Yeah, great. Well said. Great. Anytime. Well said. Yeah. Awesome.
Phyllis Ryan, Uh, I'll just, you know, agree with what Mike said, pick a framework, pick somewhere to start and just do it. Yeah. And just get started. Don't, don't worry about the whole thing at first. Just, you know, you know, pick your framework and just start somewhere. Right? And, and for the most part with what we talked about today, inventory that's gonna be applicable to every single framework. So like, don't worry about, oh, is CIS or CSF or blah, blah, blah.
Just, just start somewhere and you'll learn as you go. Yeah. But don't, don't expect that you have to be an expert before you get started. Just jump in. Very fair. Fair. Phyllis last, last, last point from you and we'll wrap up. No, I agree. Get started. Um, that, that's the number one thing feedback we've had is how do we get started. That's why we came up with IG one, which is those 43 sub controls. Just, you know, and, and again, whatever framework you choose, start small.
You don't have to implement, you know, hundreds of controls right away. Fantastic. Again, Phyllis, thank you so much for coming on, Mike. Thank you so much, Garrett. Awesome seeing you as always my friend. Everybody have a fantastic week. Bye now. Bye.


