How to Build Cybersecurity Skills within Your MSP/MSSP – John Strand
In this video, John and his team discuss cybersecurity training and the importance of building core skills for managed service providers (MSPs). They explore how MSPs can assess and improve their cybersecurity readiness, emphasizing the need for practical, fundamental skills over expensive, advanced training. The conversation also highlights the benefits of fostering a culture of continuous learning and engagement among employees to enhance cybersecurity capabilities.<ul><li>The webinar emphasizes the importance of affordable cybersecurity training, particularly for MSPs (Managed Service Providers) operating on tight budgets.</li><li>A focus on fundamental security skills is crucial for MSPs to effectively protect their clients, with emphasis on core skills such as network security, threat hunting, and vulnerability management.</li><li>Backdoors and Breaches is presented as an educational tool to help MSPs understand and improve their incident response capabilities.</li></ul>
Guests
Video Transcript
Yeah. All right. We are live. Coffee's. Coffee's pretty good in my basement, But is it Costa Rican coffee? Like John has, He's got it right from the source, baby. He probably just goes outside and plucks it and roasts it right off the tree. Yeah, That's right. That's right. Well, we are live and welcome everybody. Happy Monday to you all. Um, Boise, Idaho. Isn't that where Mackenzie is? Mackenzie? Uh, it from Microsoft's in Idaho. I wanna say Danny. She's indeed. But, um, yeah.
So before I get started and introduce John, just a quick few housekeeping things next week, uh, I'll make sure I do a better job communicating. Gary, we are live from your event, correct? On Tuesday? On Tuesday, yes. Uh, Tuesday afternoon Phoenix time. Okay. Oh Wow. Do you, do you have a time, time yet, specifically on, on when or? Yes. Somewhere. Somewhere in the afternoon And Yeah. Yeah. It, it's, it's after I, I think it's around, um, two ish. Two ish. Okay.
Two Eastern, 15 some, somewhere in there. Uh, no, uh, they're, I think they're on Mountain Time now, right? They're they're one of The ones, yeah. Mountain Time. Okay. They don't switch. Okay. So we'll set up some kind of broadcasting via cyber, uh, Crowdcast. That's the Goal. Yes. All. Yeah. And I'm assuming all the technical stuff will be your responsibility. Yeah, yeah.
No, we have an AV team, so, uh, hopefully, and we'll have, uh, we'll have over 500 people in the room listening live as well. That's awesome. Fantastic. Okay. Um, I'll put this in chat shortly, but, um, Wes, I know you and James Carroll have, uh, a really cool event on Wednesday, uh, around pen testing. Something near and dear to John's heart. Um, but we're gonna be talking about that. I'll put that in chat shortly.
The last thing that I have, believe it or not, Gary, is um, the right of boom is, uh, got 21 spots left. Um, that's it. Um, we're technically sold over based on some, you know, vendor packs that have been purchased, but we're gonna, we're gonna keep a little extra, uh, gunpowder as they say, uh, in the holster, but, uh, but we'll have 500 there as well. I don't think it's exactly how they say it, but, uh, how, How do they say? Yeah, you're gonna keep some dry powder. Dry powder. Thank you.
Yeah. Keep some dry powder. I don't wanna nitpick. No, no, no. Don't you never do that to me. Well, you just gotta, you gotta pick between the lesser of two weevils. That's too obscure. But Andrew, if people want to come, they should, they should sign up now, because I'm sure we'll fill those last spots at Sch n Fest, Um, when we're Yeah, yeah, yeah, yeah.
I, it's, it's, it's, um, it's, it's really cool, um, how, how it's all coming together, Gary, and it's gonna, you know, go from yours, uh, next week to ours in about a month. So, alright, getting on into it. There's Phyllis 'cause she's first up, so let me bring her in. Um, John, it's awesome to see you again. I think it's been probably, what, four or five months, uh, since, uh, since we've had you with us maybe a little more.
Um, you're gonna have a really big presence at write a Boom, not only you and John Hammond doing the pre-Day event, which is really quality all of so Much work going into that. Yeah. So much work, hours, hours, months of work going into that training. Um, but, uh, but you're also gonna do back doors and breaches live in the evening, which is gonna be awesome. And then you have an, uh, your main stage session, um, and you've got a lot of folks coming in from the BHIS Antis Siphon team as well.
Um, for those that don't know you, John, um, you, uh, have a few companies and most notably what we're bringing you on here today to talk about is cybersecurity training. So can, for those that don't know you, can you maybe just give a little history of how you got into cyber and then how, you know, after 15 years of teaching at Sands Mm-Hmm. Um, have really built an amazing company with Antis Siphon. Yeah. So, originally got my start in computer security at the Department of Interior.
Um, if you want to Google something horrifying, you can Google Department of Interior, uh, versus Cobell, um, uh, long class action lawsuit. That's really where I got my start. Um, got out of that and went over to Northrop Grumman, did classified stuff, which sounds a lot cooler than it actually was. I was basically working in a skiff where the floors are dirtier. Um, but did that for about five, six years.
And then I got out and started teaching with the Sands Institute, started Black Hills Information Security, uh, retired from the Sands Institute after about 15 years and grew B-H-I-S-I think we are now at a hundred full-time employees, and we do about 675 security assessments per year. And the big thing is Antis Siphon. Um, we're really trying to come up with a company that does affordable security training.
And one of those areas of outreach, of course, is in the MSP space to try to get as many people trained as possible. 'cause as we said in the past, this is truly the cyber front lines in the MSP space. Very, very cool. John. Um, I don't know if you have a copy handy, but if not, I will put a link in the description. But what's really cool is, uh, in the newsletter, and, and, and what I sent out to everybody is you have a new InfoSec survival guide, which is really, really cool. Yep.
And you have, again, I will post this next week, you teach, um, getting started in security and Mitre attack. And because you have certain levels like people, you have a pay what you can model. But if people pay a hundred bucks or more, they're gonna get a copy of the survival guide. So, uh, It's not So we, we took your advice, Andrew, and we decided you were wrong. Oh, of course. Well, why don't you join Gary's camp? Everybody can welcome To my world.
Gary's like, Gary's like, um, so not only are they gonna get the survival guide, but they're also gonna get, um, um, additions of bear versus bear in ar zine and maybe a deck of cards too. So we're gonna be handing out a number of things. So if you spend a hundred dollars, you get that. Um, I think if you spend over $275, you get six months of the cyber range. We could talk all about that later.
But, um, really the goal is just to make it as affordable as possible for MSPs to train their people. Because I know for a fact there's a number of MSPs that are on shoestring budgets and honestly terrified looking forward into the future and how they're going to compete in the world where computer security is absolutely front and center in so many different ways. So we're trying to meet people where they're at and what they can do. Cool.
So this cyber call is dedicated to getting folks, uh, around building their cyber skills in 2023. And, uh, Phyllis, I know you're gonna kick us off, but one of the great quotes, John, that I think you and I were together on it write a boom 2022, we heard was someone stood up and said, Hey, um, you know, I'm concerned about losing my employees if they're trained, you know, get, you know, a lot of skills they're gonna get plucked. And someone else stood up and said, you know, here's our mantra.
You know, what if you, uh, train your employees and they leave and what if you and don't, and they stay. Um, yeah. So the person, the that MSP, which is a, has, has, has a great culture, invests a lot in their training, keeps their people with about 55 employees. They keep their people very happy. They, their people have been offered far higher salaries. But again, it's culture. Um, I, I just, uh, I thought it was a great quote.
So Phyllis, um, thanks for joining us, um, on her Day off, On her day off. What's, yeah, I mean, she gets time and we get to pay her time and a half today. I mean, federal government service for 25 years, jump off to a small nonprofit. We love our federal holidays. Come on. Yep. Yeah, yeah, yeah. Well, in the SMB space, um, and the MSP space, there are no stinking holidays, as they say, Phyllis. So no Rest for the weary, huh? No, no. Yeah. So, um, take it all, take it away for us folks.
Yeah, sure. So, um, thanks for having me. And, um, hello John. Um, as you know, um, many small medium businesses look to MSPs to support their it, um, and more and more, um, we're seeing MSPs as witnessed by the MSPs on this call. They're being asked to provide cybersecurity services, solutions, et cetera, to their clients. Um, while this could be outsourced to a third party, you know, many organizations are doing it inhouse.
So if an MSP is serious about offering these services and building up these capabilities, how should they start? Um, one of the things I always try to get MSPs to understand that are just getting started in security is there's a lot of distractions, right? You can go to like the most cutting edge reverse engineering training at Black Hat. Um, you can go to a very expensive like, you know, six day training at sans and you're always trying to play the game of what's my return on investment?
So if I spend a lot of money getting someone trained on reverse engineering malware, or if I spend a lot of money getting someone trained on network penetration testing, where's my return on investment on that? How do I get to that the fastest? And what I recommend, rather, is really focusing on the core fundamentals and working with Andrew and, and even working with Wes and things like that over the past few years.
If we look at the MSP space, the the line people that are working day to day are really, really, really in desperate need of core skills, right? We have a class called SOC Core skills, which is core windows core networking, core Linux core network threat hunting basics and fundamentals to get them ramped up. And this class is core security, which is what are some of the things that your MSP should be doing for their customers? Not really expensive.
We're not saying, Hey, the best thing you should do for your customers is you should go out and buy ArcSight licenses for all of them. That's not all that valuable at the end of the day, right? Even though I'm sure an ArcSight rep would disagree with me vehemently on that, but what are the things that you can do that are some of these core fundamental things? And a lot of those things will get to you, the various implementation groups, much faster for the CIS controls.
And, and it doesn't have to be hard, you know, Phyllis, we've talked about this in the past, people make things far more difficult than they actually are. And it's my hope that if you take a class like the getting started in security, you realize this isn't rocket science. There's lots of things available to make this easily accessible for your own company and for your customers. And it really opens up a whole bunch of business lines for your company as well. That's awesome.
And I agree, and it's, you know, really progress, not perfection, really just getting started, um, with one of your courses and, you know, the bar to entry is so low with your price point. So I think that's awesome. Um, you know, so many organizations, you know, maybe thinking like, how can I get started? How do I know, um, what the skill level of my employees, how ready we are as a company? So if they wanna learn cybersecurity and offer these services, how is it that they should get started?
What is it that they should be doing to really assess how, um, how ready they are? This is, this is actually something I've been thinking a lot about, right? So how do you create roadmaps and self-assessments and some of those things? And one of the MSPs I talked about or talked with at IT Nation Connect, it was kind of shocking how they approached it. They said, we just had a conversation. We had an all hands meeting, and we said, what are some of the skills that we need to have?
Where do we fill our deficiencies? Are, here's the different classes that are available. This is the cost. And what their employees, they basically charted their own course. And I, and I thought that that was interesting, right? Because so much of what we discuss is really from a top down perspective, you know? Mm-Hmm. Management's gonna make the decision and we're all gonna move in this way, and you can do that, right? I think that that's absolutely a viable way of running things.
But as soon as I had that conversation with that MSP where they're like, we had a conversation with all of our people and they looked at all the options and of course, antis, siphons pay what you can model, it was kind of funny. What he said was, you know, one of my employees said, if it sucks, we're out no money. Like the risk is just non-existent there. And they basically had a conversation and they started moving in that direction.
I think what's cool about that is it gets ownership and buy-in from the rest of the employees. So you're setting that goal, you're setting that big objective and that mission statement for your MSP rather than it being dictated. So sitting down and having a conversation, I think is probably, are You suggesting that business leaders might listen to their people who are actually doing things? Yeah, I know nothing about that.
As a business owner, um, you know, I think that we all run into that problem, right? And I think that a lot of people that are quote unquote leaders, that's a lot of stress to be honest with you. Because when you're trying to chart a course for a company, and I know what it's like to live on very, very, very tight margins, you know, that a simple mistake can actually be catastrophic. And that's really, it's reassuring for me.
We do it at BHIS with conversations and things like that, when people will kind of have that kind of collaborative ownership of the mission and where we're going. It helps. And you know, I'm talking a lot now, but one of the simple things that I've been doing lately is making sure I talk as little as possible, um, in the meetings with my people. And that was like, that gets into long conversation I had on the floor, uh, in Florida when we are talking about it.
But I think that that's a really good approach to try to get more buy-in because it isn't just an issue of flinging your employees at training, then they get trained. Um, it's, they gotta be vested in it as well. And the more that they're vested in it, the more they're gonna get out of it. Right.
And, you know, also that could help with the retention, um, question that, you know, Andrew talked about in the beginning, you know, with employees, um, if you feel like as an employee and never a business owner, you know, there is a little bit of an obligation and self pride in the company. You wanna see the company succeed. You wanna work in a good workplace where you feel management and senior leaders are listening to you. So I think that's, that's a great idea and a great suggestion.
Um, Of course, I heard, I heard one just a quick quote on that. I heard somebody once say, many people don't leave for more money. They leave poor management behind. That's right. And I know if you're not getting paid anything that, you know, you gotta make a living wage. But I think that that's very true. Yeah, absolutely. Um, so, you know, we're having, um, a conversation about cybersecurity skills, but you know, we, in the cybersecurity business, we love, we love lists.
So, you know, I know you have a, um, what are the top 10? Or perhaps you have like the top 11 things that MSPs should know and why? So we basically set out with, um, like I said, as a penetration testing company, right? I sat down, of course with the critical controls, um, and it, a little bit of my background. Um, I was in the room when the, the first edition of the controls came out while they were still the SANS 20 controls. Mm-Hmm.
Um, so I was there helping like Ed scotus, Eric Cole, Steven Northcutt Al, and um, Alan Poller, and um, of course the rahs with that. And one of the things that we spent a lot of time talking about is how exactly do we make the idea of a compliance framework applicable? Because as you know, a lot of these compliance frameworks, they're like 700 pages of gibberish, right?
Like, I remember I was reading one the other day and they were talking about shared object, reuse and memory for your operating systems. That's, that's B two level in the Orange T six series from 1982. So that, that kind of carried over and that creates a lot of confusion. So we went through and we said, okay, if you're looking at the 20 critical controls, right? And you're basically boiling it down to saying what is the specific control that would've stopped us in this particular pen test?
We went through and we mapped it, we came up with 10 things, um, just 10 things that would really stop a pen test or an attacker. Now that doesn't mean a lot of other things like education, awareness and governance aren't important. But from the technical aspects, doing something like application white listing, you know, doing software inventory going forward and doing good sim management, vulnerability management, those types of things kept reappearing again and again and again and again.
And we said, look, we gotta come up with something like, you're coming into this, it's triage and it's so hard for an MSP if they're trying to get started in compliance. And like, well, the first thing you gotta do is have a good audit and inventory of all of your software and all of your hardware. We created that as control number one and two.
And the reason why we created that as control number one and two is we, 'cause we thought it was so incredibly fundamental, important, like core to everything that everything else was almost impossible without it. And I hate to say this, but we were wrong. Um, we were right from the fundamental perspective, but we were wrong because starting out a company trying to do inventory, that's an MSP, that's on very tight margins.
Starting with that, it's next to impossible, uh, for them to get that and get their feed on. I thought you were gonna say you started with it 'cause it was the hardest one for 'em to do. Yeah, well, you know, uh, see, but that, okay, so that's what happens when you're in Gilded Towers and information security and you think everybody has a budget of Chase or Wells Fargo, right? You know, there wasn't a lot of conversations 'cause we didn't know about, uh, like this world as much as we used to.
So by doing like the 10 things, it's like, look, this is triage. You have to do these things to stop the bleeding, get the bleeding stopped, and then come back and start hitting the rest of these controls is absolutely essential. And even in the classes we even set, so whenever I talk to customers and they're like, how are we ever gonna do inventory of all of our systems? Like how do you do this? How do you inventory your software?
How are you gonna do this, John, you have no idea how much work it is. It's like, well, yeah, I do. But simple things like putting in Zeke sensors and proper locations that can actually automatically inventory your software and create profiles for all your different systems, basically showing people that no, no, there are ways to do these things, but you have to start with some of these fundamentals first to stop that bleeding from the triage perspective is so incredibly important.
So, like I said, good passwords using application allow listing, which sounds horrible, but it's not that bad. Um, internet filtering, even with something as simple as DNS filtering, doing vulnerability management, all of these things are covered in the course, but they're really where people do need to start as far as like pure triage, get that blood loss stopped, and then move back and hit implementation group one and then implementation group two.
And also I think, I think a lot of you would agree with me, implementation group two sounds like it's twice as much work as implementation group one. It's really not. Um, you, anybody can get to implementation group two. You absolutely can. Yeah. Thanks for that. I mean, I do have to say, um, I, I like the distinction you make from like, triaging the bleeding. I think that, um, also, you know, those two things still are fundamental. The, um, um, heart there.
Oh, of course they're, And you know, we're really trying to say, um, change that messaging like, don't be perfect. But again, it's that progress, not perfection. Because so often I do hear why are those one and two, they're so hard. And I'm like, I get it. It is super duper hard. Um, we don't want you to be perfect. You're not gonna get a pass or fail. It's, let's just get started.
And I'm, I'm curious, John or Phyllis, if either of you've seen the css, new cybersecurity performance goals, the CPGs, they just released those like a month ago for that, this exact reason of like, okay, we recognize the CSF is massive, it's confusing. Where do we start? What's the most effective? And they released, like, I think there are eight of them of like what the most important goals are. Mm-Hmm.
I dunno if you've seen 'em or not, but I, I thought that was a good distillation of kind of what we're talking about here of like, let's give people a boost on like where to start when it comes to each particular framework. I think it's wise, especially for SMB. Yeah, we saw, I think that's on that they've been trying to do that. Oh, go ahead Phyllis. I'm sorry. No, go ahead. Sorry.
Oh, I was just gonna say, I think honestly if you look at all the moves that CI has been doing over the past four years, it's really been focused on the concept of triage. Um, there's some things I disagree with where they're like, you need to patch these 100 vulnerabilities. And I'm like, you should be patching all of them. Um, but they're playing the triage game. They're playing the triage game constantly. And I, I do like that direction.
I mean, yeah, we looked at that, um, a lot of those things map quite honestly to IG one, so we felt Yep. Um, pretty happy about that. And um, some of the things are a little, um, OT specific, which is still fine. Um, and, um, I do like, you know, and they had some things around governance, which I also think is important. But yeah, I, I like to see, um, that CISA is trying to, um, kind of pair down their guidance, et cetera.
What we would like to see though, at the federal level is kind of united, let's settle on one type of guidance versus every agency putting out their own so as not to, cause have you seen that confusion? Have you seen that XKCD comic where two people are standing around and there's like, there's, there's 42 different standards that are all competing with each other. So we're gonna create a new standard that supersedes all of those standards. Right?
And the next panel says there are now 43 standards. It's just, yeah, I, I, that's a whole nother conversation that requires beer and no cameras, but I agree. Right. Um, and so, you know, my last question is, in your experience, especially as a, um, all your years at Sam's and now offering, um, this, um, you know, pay what you can type of training, what do you think makes a good student? So how should um, MSPs be investing?
What kind of time, what kind of money, you know, what's really, um, set expectations? I know, you know, when I was at the NSA, it was always like, training's a priority, but is it really, 'cause everyone is so busy getting their day job. So I think it's important, um, for us to really set those expectations for business owners, for employees.
Um, 'cause I will say, you know, a lot of times that training really does fall off the tail 'cause everyone is so busy and there's always like that asterisk yes, you can train with supervisory approval, right? That's kind of like, get outta jail card as the mission warrants it. So, And, and that's a really hard question. Like, I'm gonna give you two answers, right? I'm gonna give you the motherhood apple pie answer. I'm gonna give you kind of a hard answer.
You know, the motherhood and apple pie answer is training should be for everyone and we should sprinkle it around and we should all have sunshine and rainbows and life will be so wonderful if we all get training. The reality of the situation is there are people that'll react better to training in your organization than others, right?
You're gonna have some people in your organization that'll just tear it up and they're gonna eat it and they're gonna love it and it's gonna improve them as human beings. And there's other people that you'll invest the time and effort on and there's gonna be nothing that comes of it, right? So it's interesting because, uh, years ago before Edward Snowden, I was out in the tunnel, um, out in Honolulu, um, military base.
And I was talking with the Air Force commander out there, I can't remember her name. Um, but it was the same question, right? She was looking at cyber skill sets across the entire base. And her thing was, I don't wanna send everybody through training. I just don't, I want to be able to identify the people that have the skills associated with the training that I'm going to invest. In short, I wanna put my money or my investment and my return on investments going to be higher.
So I'll give you a couple of things that you can look at for that, right? The first thing that I would recommend looking at is looking into cyber ranges that are free and sitting down and saying, look, we're I'm gonna give you access to a free cyber range. Why don't you all check it out and then come back to me? You're probably gonna have, let's say half your company, we'll actually spend time playing around on that cyber range at all.
And maybe half of those are gonna put a lot of time and effort into it. That's a way that you can identify people that are probably going to react the best computer security training, right? And that's just an example. There's a lot of different ways, but you have to look at your team and say, what, which of these people in the organization are going to react the best to this training? And once again, it goes back to the pay what you can training.
It doesn't cost anything, and it's recorded and it's on demand. You're gonna have some employees that'll blow through it and be like, ah, yeah, I didn't see the rest of the videos. And you're gonna have other people that are like, I went all the way through it. I did all the great, you've just identified that individual in your organization that you can start putting some more effort into. And then that opens up other business lines for your company. And I can talk more about that as well.
So, Yeah, sure. Thanks Gary. Yeah. So I, I, I have some questions for you, but I'm, I'm going to ask you one that's not that I didn't think of ahead of time. Okay. Uh, So you have a couple different businesses do different things. Why this, why are you doing it? It's not the, I mean, as someone who gets people to watch video trading, it is not for the faint of heart. Um, so what, what is, and it's not the thing you can spend your time in to make the most money. I know that.
Um, so what is it, John? So a couple of things, right? Whenever I started doing training, I found something that I absolutely love to do. And when I was teaching with Sands, I found my vocation in my vocation getting in front of a group of people talking about something that I love and not necessarily a transfer of technical skills. Because the reality is when you're training, you're not transferring technical skills.
You're basically trying to infuse people with the passion to change their lives. And that sounds really, really, really like hippie dippy. And I should be selling like weird, it Doesn't sound that way to make Inside of the street, but that was something that was very core to me. And BHIS was an offshoot of that. So we had all these people, like, I loved what you talked about, I love the direction and we wanna do business with you.
Uh, 65% of the work that we get at Black Hills Information security is reoccurring customers coming back year after year after year. And that's just how we've grown over time. And for a service company that's really huge. So that's worked out really, really, really well. However, it hit a point, um, with the Sands Institute where I was traveling too much, I was away from my family. It was having bad impacts on my health and bad impacts on my family relationships.
And I couldn't be away for 12 to 15 weeks a year. So I re I retired, right? And then Covid when it hit, um, I had just started doing, look, there's a bunch of people that are unemployed. I'm gonna do some training for 'em and see how it goes. The fact is I don't necessarily need the money anymore. Like, and that's kind of what you're talking about, right? Like, I can do other things to make money, right?
And if I'm looking for, and the biggest way that I can contribute is trying to train as many human beings as possible in trying to fix the cyber skills shortage, to try to work in the MSP space for the people that are frontline with no budget whatsoever and make the single biggest impact that I can to help. This is it.
And that there's something really, really nice about going to bed and being able to sleep knowing that you've given it all that you possibly can to try to help as many people out as possible. Yeah. That's awesome. Uh, re really good. And it's good for people to kind of understand, I think where you're, where you're coming from and what your motivation is on things and, uh, yeah, having a worthy goal and, uh, and being able to be fortunate enough right. To do it for the right reasons.
So, uh, uh, really good. I, I commend you. So, um, question I had is, um, a lot of, uh, the people that are listening, they're at all different levels, but I think as a group, the average MSP, they're trying to get those basics. They're trying to get to IG one is there to do that. Is there one or two skills that they should focus on to help them prepare so that they can, does that make sense? Is there any like speci like skills rather than training maybe, you know? Yeah.
Um, so one of the skills, and this is, this is a horrible thing to say, but just simple Googling and researching is something, uh, look, so whenever I was more involved with the controls a long, long, long time ago, and I see it now, there's a lot of trying to explain to people, look, this isn't that hard. And on one side you have this isn't that hard. And on the other side you have vendors that are like, come buy this really expensive thing and it'll basically do this control for you.
And it's hard, right? If you're coming into this space. So being able to have that core research capability to say, okay, if I'm being told that I need to implement something like application, allow listening, which is pretty darn advanced in many of the different controls that are out there, how can you do that in a way that it's sane, yet very effective and doesn't require a tremendous amount of uplift to do that successfully? Yeah. And being able to dig on those things is really critical.
In my soc course skills class, I spent a lot of time telling the students kind of how I learned about what I learned. And that was going to the hardening guides at the Center for Internet Security a long, long, long time ago, right? Or the NSA snap guides or the DISA STIGs or any of these different things. If I was in charge of securing something, I would get these guides, go to all those different configuration places to learn that technology, then I would actually try to secure it.
And I try to instill that in my students in the intro to SOC class and the intro to security class. So being able to dig trying, and this sounds horrible, just RTFM, there's all these manuals out there. Read the fine manual and go through it. And like the CIS guides, I mean, think of anything, all the tool like Ariba portals, you can get a guide on how to harden that. Apache, there's a guide for that. Oracle or databases, all the major databases, they've got guides for that.
So there's all of this guidance and there's all of this stuff that's available to help people out. You just gotta go and you gotta dig it out. And that's what I think a lot of people miss, is they don't understand there's so much help out there today to get them in the right direction. Yeah. If they have the inclination and they're willing to invest the time, uh, yes. Into it. So I want to go, so, uh, CIS right, focuses heavily on, uh, left of boom, what are, yeah, the opposite question.
What are some of the skills around right of boom around, you know, incident response, forensic, those kind of things. Oh, Oh my gosh, uh, vlogs, where are your logs? Where's your data? And you know, I I I'm gonna push back on the CIS as left of boom. Um, whenever we're doing an incident on an app or a server or a service that we don't, we've never encountered, we go right to the CIS guides. 'cause the CIS guides will literally tell you, this is where authentication logs exist.
This is where access logs exist. This is where error logs exist, right? And then we turn around and go right to our customers and say, we need these logs asap. So you gotta be thinking if you are an MSP, what are your eyes and your ears, right? Your network traffic logs, your endpoint logs, your application logs, your service logs. So when you get into that write of boom situation, how can you react as quickly as possible?
So whenever you're going through like our intro to security class, we put a tremendous amount of emphasis on hands-on, oh, Steven Kellogg just mentioned that on hands-on so people actually see an attack and then learn how to react to that attack, get the proper logs. Like, you know, looking at CIS monologues is a huge thing so that they're ready for that incident. And by the way, this is great for two reasons.
One, it's gonna reduce the cost for you doing MSP work and it opens up additional business lines for IR services, which you can charge significantly more for. Yeah. And that's one of the things we're trying to get across so much is really focused on, if you're an MSP, stop looking at computer security as a cost center. It is an opportunity for all of these small MSPs to start competing at a higher level. 'cause I honestly believe the MSPs have these amazing skills.
It's all duct tape, bailing wire, and all this really cool engineering that they've learned nuts and bolts. And if they just learn a little bit of security, they can now start competing in spaces that they never competed before and start making revenues that they never thought were possible in security space.
John, John, if I could just make a anecdotal comment just real quick, Gary, it's like I hear Aaron Cherin in my voice, the founder of Purge Now, founder of Roost, and you know, when he broke into security, he was, um, he came from the Linux world or, or unit We, was it Linux or ux? I apologize one half, but No, both. Both, yeah. Yeah.
And, and he, he really understood automation and he really understood it, but was initially like a little bit, um, uh, uh, uh, you know, concerned that he wouldn't be able to like, wow, these are security guides got people Mm-Hmm. They were gods and I'm, what he found out very quickly was that he actually, when he applied what he knew in it to security, he actually leapfrogged so many people. And so it's nice to hear you say that.
Uh, I, I think maybe there's this my mystification, if you will, that oh my gosh, I don't know security, but the foundational things that so many MSPs know, I think really will serve them. If that, if that makes sense. Yeah. I I seriously think it's just me showing a couple little tweaks and like how you can do things slightly different. And I mean, as far as like the technical skills, the ability to dig and troubleshoot blood, sweat, and tears, MSPs have got that in spades, folks.
Like it's, and I've had some people in the security space already, I haven't talked to you about this yet, Wes or Andrew, but I've had people in the security space that are already like, look, I'm getting MSPs that are starting to bid on some smaller contracts at the state local level. And like, they're literally mentioning like, your training, like you're literally cannibalizing your own people. And my, my take on that is good. Uh, look, if you can't compete, you can't compete.
And, um, you know, I I I think the security industry, and this is a horrible thing to admit, has kind of been looking down on the MSP industry for far too long. And if I have some security people that are afraid of MSPs starting to compete with them, I think that that's a damn good thing for everybody involved. John, to your point on that, I saw a, this is about a year ago, but it wasn't one of the big four, but it was one of like the big 10, one of the ones you'd heard of before.
And they were, they were badmouthing MSPs around security. And I'm like, the only reason they're even writing this big blog post on why you shouldn't trust MSPs for security is because they've been threatened by them. And sure there are some really bad MSPs, but there's also some really great performing ones that do come in at a price margin that's affordable for a swath of the industry that the Big 10, big four can't, they just can't service. And, and they're seeing this as a threat.
So you're exactly right. Well, and I, I don't wanna get too into it, but look, I've been exposed to a number of different products and services that are really doing well in the MSP space, and I spent a lot of time looking at them, like you mentioned Perch, and you could throw ts in this as well. Tres isn't known all that well in the security space. They're coming up against, you know, uh, let's, uh, let's pick on CrowdStrike, right? And they better CrowdStrike better up their game.
'cause companies like Huntress are coming up and they know how to work in a space with people that have very limited resources. And there's nothing but good things that are gonna come from that in the industry as a whole with that competition. Is it gonna suck for some people? Absolutely. Is it gonna make us all better? Absolutely. Well said. Yeah. Yeah. Back to you. Yeah.
I, I have another question, but I, I'm just, I wanna, I'm wanna make sure I circle back to what you said in terms of that, um, you know, maturity, security maturity is good business. Um, you know, I see it, I'm lucky enough to see the, you know, the books and all the statistics on 300 MSPs every quarter, right? And I see the ones that are further down the line with their security maturity.
They sell more, they make more, their average customer size, their average e every one of those metrics is so much higher, you know, than, than the average. But I think one of the challenging things is it's hard to have security maturity without business maturity. Like if you work at an enterprise, you don't have to have business maturity, you just have to have a budget and tasks and be able to go and, and implement that.
But if you work at an MSP, you have to be able to run your business at a mature way, or it's not possible to develop and implement consistency in your MSP or for your customers. And that's the challenge I think we're running up against. And, you know, hopefully being able to get access to, to training, you know, cost effectively will be one of the tools to start to move people, you know, in, in the right direction. I dunno, does that make sense? Sense? Yeah, it does.
And this gets into one of the problems that, that isn't just in the IT industry. It's in business in general, right? Like, I can pick you a company that's going to fail in the next five to six months by who they put in their executive leadership.
If they hire someone into their executive leadership and they're an IT company and they're like, previously the CEO that they just brought in was working in the farm and ranch industry, and they increased the sales in that area by 150% or some crazy thing or whatever, they're going down in flames because the management and the executive leadership doesn't an understand what they're actually doing.
And I've seen that, and I've dealt with that, uh, for years in this industry where I work with executives and they're like, I don't know anything about it, but what I do know is raising dogs, and I want to tell you how that helps this. And I'm like, that makes no sense. They're two completely different things. Yeah.
So that is one of the things I love about the MSP space is so many of the people that are kind of at the top, they're like, well, this is Bill, bill built this company that's a $50 million company out of his garage. And you know, you look at Bill and he is got like this weathered face with scars and he, you can tell Bill's seen stuff, man. Bill's seen stuff. Yeah.
And I think like, like you said, for a lot of enterprises, they have people that are making decisions and they just have a budget with no experience and background. Yeah.
And that's another one of those things while I do, It's interesting, that's an interesting one, Ripe for moving up the chain because of so many companies are looking at running their own IT infrastructure, running their own IT security infrastructure, and they don't see any reason why they need to be spending the money on six, seven people doing it just for their company when they can bring in that expertise from the outside. And we're just seeing that more and more all the time.
That's a really interesting view of how, uh, of how you're looking at it. That's awesome. I I just had one last question earlier, uh, at the top of the show, Andrew was talking about training people retaining talent. It's really tough and security talent even, you know, even more so it's, it's just a common thing across all the MSPs I work with.
Can you just share a little bit about, we, he, we mentioned culture, but what that means, like how do you get people to want to, that are good to wanna stay with with you? Because like you have to do it every day. Yeah. I'm gonna say this, it's a lot easier keeping security talent now than it was, uh, like a few months ago. Like the entire IT security industry has just like had massive hemorrhaging. Um, it's not good. Just gimme a second.
I gotta yell at somebody who took my power charger from my computer and my computer's going dead. So hold that thought just for a second. Go ahead. At least there's no, uh, chickens this time. Uh, roosters, roosters, roosters, Gary is, you know, yeah. He's got a guy on a bike pedaling to make electricity. Gary, I was curious about your question because, because again, uh, a John, you got, You've been doing training for 10 plus years now. Yep.
It's not easy to get people to adopt and, and, and what, what are you looking for because I, I know you asked John, I'm curious from your perspective, you know, what is it that you're trying to convey in those sessions and Yeah, I mean, uh, this is kind of what I'm working on right now for my keynote for next week, which ni fest about really what I've learned you like, just like John, you know, I'm in the business of trying to get people to change.
It's the hardest thing to be able to do and realize what personal things hold them back and make them unable, you know, to do that.
But, but, but if I fast forward to it, I'll, I'll tell you, um, the people I've got to watch for a decade, and I've watched them mature as people and business people when, when, just like, when other things have come along, when the changes in security came along, Andrew, they, they, you know, they were able to look at it, understand it, see the opportunities, make a plan, implement it, and they're the ones that are, you know, reaping all, all the rewards.
So I almost see kind of like what I do is getting people ready, uh, operate, you know, in their business so they can take stuff like John's doing and actually use it right. To propel their business forward. 'cause eventually, you know, my theory m mss p struggle with two things selling and doing anything, Gary, I repeat that quote all the time. I'm like, my friend Gary says, people just laugh. Yeah, that one's pretty classic. Um, but no, it's a lot easier to retain talent.
I'm not joking than it was a little while ago. But I think if we're talking about talent is, we talked about this at the very beginning. We need to get people on board on the mission. Like we wanna build our company, we wanna start up these services. Who wants to head up pen testing? Who wants to head up ir? And then really letting the employees that want to do those things actually run with it. And if somebody has some level of ownership, they're far less likely to leave the company.
I see that all the time where people are like, yeah, I could leave and I could make more money, but I really like what this company is doing. I love the culture, I love what management's doing, and I love how they're working with me, John. Yeah. Except most entrepreneurs think they can order pizza better than everyone else. John.
What, what, what I do notice though is like, you know, you have a massive YouTube following and like, I noticed you put your people, I two, two things that strike me about your culture off the top is one is fun. Your people have fun. I mean, in, in what would be a, you know, again, a serious field of security.
But, um, they, I noticed they have fun and I noticed you let them, when you talk about let them lead, like, you know, they're out there, um, you know, before A-B-H-I-S talking security, uh, uh, event that you have, like, you're allowing them and you let them lead, um, the discussion, you let them lead the content. I don't know if, did we fully lose John? I think he's coming back. He's reconnecting. He's reconnecting. So, yeah. Yeah, that's interesting. Get let people Yeah.
Let him get out in front a little bit, right? Yeah. It's really interesting. If you ever watch their podcast Dari, um, on YouTube, they, they, they, they all are laughing, they're all having fun. Um, and they're all highly intellectual, obviously in security and all dealing frontline with stuff. But he's not sitting there saying, do this, say that. Don't do this, don't do that.
They just, you know, I mean, I think it's interesting just 'cause, you know, the US government oftentimes has, has issues. I work in offices with highly talented people, um, who know technology very, very well. Um, and you know, some people jump off, but you know, a lot of people do stay tied to the mission. Mm-Hmm.
Um, you know, I find that especially in government and, you know, it'll be interesting to see like, you know, for MSPs, do people stay there for the mission or they've been there a long time, et cetera. Um, or are people just leaving because of money? Or maybe there is, you know, an issue with culture or things like that. I'm curious what everyone's thoughts are. Finding People is still hard in general.
MSPs pre pandemic retained their people pretty well, and then we saw a big spike in turnover during, you know, during, uh, you know, 2020 and 21. But it has stabilized, uh, now. Hmm. And I think people now, but still finding good people, um, it, it is still, is still difficult, But it, it is a cycle. Right.
Gary, like you're saying, like, in other words, you talk about the MSPs that are leaders, you know, they're, their metrics are, they're, they're charging more, they make more, hence their people can be compensated better. I mean, it is a self-fulfilling wheel or po like Yeah. If you're not growing, it's pretty hard to keep, give people opportunity. Right.
Um, you know, uh, I know every day when I walk, when I ran my first MSP, when we walk through that door, uh, with another deal, it was like, you know, this is opportunity for people. Like if we don't grow, uh, people can't get promoted, right? We can't launch new things, we can't invest in new things. And so it's like taking pride, you know, taking pride in that Andrew Mm-Hmm.
And, uh, at, at an amazing time in, in, in our industry right now, uniquely, like this time right now, what's happening with SMB technology is going to be in business books, being taught in schools, whatever they're gonna look like, you know, uh, a couple decades from now because it is literally that historic, very few markets, uh, grow this fast and gonna do it for a, a number of years. It's, it's, it's ridiculous.
As I try and get John back up and, and I keep prompting him here, hopefully we can get him back. Um, is, um, you still think we're early, you know, in the, you know, use a baseball game analogy, you feel we're still early, aren't we in the, in like how far this can go? Yeah. And I feel like most of the changes that we're gonna experience in this industry are, are ahead of us. They're not behind us.
We've seen some of the drivers pop up in the past two or three years, but the impact and the effect of many of those drivers, they haven't really fully come to make us change our, our business model. Right. And security's one of them. Uh, but it's coming. There he is. Hey, can you hear me Okay? We gotcha. Right? I, I, I'm gonna with, with that, I'm gonna hand over to you, Wes, so you have some time, man. Sounds good. Yeah. Joe, thanks for joining. I guess you're on your phone.
Yeah, I am my backup man. Yeah, That works. Again, you gotta be careful with teenagers stealing your, your power cables. Yes. Such things happen. We, we have the same problem in my house. Where did that high, high pen charger go? Yes. So I wanna talk John A. Little bit about, uh, the ethos of training. 'cause there was a lot of really good discussions going through in the chat when we started getting into, um, the how and the why and the mission behind behind training.
I wanna pull out Anne's comment in particular. So Anne made a really great point. She's like, Hey, in my experience, a lot of people get really excited about training. Like, this is awesome. I've got, you know, all this I can seize upon. And then either, either fizzles out or it just sort of becomes difficult for them to want to continue to have the, the want to the gumption to get through it. Right.
What kind of, um, what kind of advice do you have on helping people stay engaged, stay on top of it? Do you just force it? Do you reward it? What do you think? I would recommend setting goals for the organization as a whole. You know, what are you trying to achieve? And then tracking it.
The other thing that I would recommend is, one of the things we've been doing with Andrew is whenever we do training, we meet with them once a month so they can ask questions so they can keep that training going. You know, it's like a flywheel. You gotta keep putting energy into it to keep it going. And we're, we're trying to get away from the just one and done training and just moving on to something that's more consistent and sticky. That's good. Yeah, that's good.
And, and I think, um, I, I think that's great. Where, and especially one thing leads to the next and they've got progression pathway and it ties back to their own success. Like I found, I found training to be ultimately really important when they get through something and they're like, that really helped me. Like, I actually did better. I made some revenue off this. I more comfortable in a client conversation.
Um, my career pathways I've progressed in maturity has come through this training and it ties directly into those. Um, I think that's where the, the stick to comes as well. Absolutely. And that's what we've seen already with MSPs coming back and saying that they were implementing this. Um, at IT Nation, we had this one guy that came up and he is like, we're implementing this and it works great because we can steal business from other MSPs. And I was a little bit horrified.
I was like, that wasn't exactly what I wanted you do here. I'm like, that's great. Do free vulnerability assessments, find everything that the other companies do wrong, and then we steal companies from them and then we charge more. I'm like, so that's that Capitalism 1 0 1. Like you gotta be willing to, if you're gonna compete, don't be, Don't be appalled Until you see their actual results. Yeah. Okay. Because that might be their theory. Let's Ask 'em how much they sold in the past year. Yeah.
Yeah. Uh, okay, so here's another, uh, along those same lines, uh, I feel like we're, when you think about kids coming out of high school or even, um, college cyber readiness, it seemed like, you know, in the mid two thousands it was impossible to find anybody's security. So you had to train 'em up. You had to hope they had a technical skillset you could learn on the go. You look at like schools now, they're doing, they're not perfect, but they're doing a better job with some of that.
But I, I'm con I constantly end up talking to college kids all the time. And I'm like, how many of you guys are following John Hammond? And like, every hand goes up, which is the coolest thing ever. Right. And now John, totally Different than it was, right? Yes. That's my point.
I love that we're getting to, I think the volume of security talent is, is higher, but I also think the quality is getting better too, because we've got so many mediums by which people can go and learn for formal education pathway. But you, you just jump on YouTube and listen to John just dive into the latest tri hack. Me and I, I, I love that we're in this era now and I just wonder what your comments are on, on all that.
You know, it, it was really, security training used to be something that was super elite and it was ran by a bunch of a-holes. So if you look at like 99, 2000, 2001 beginning of Defcon and Black Hat, the lot of the attitude was the RTFM read the effing manual, you're a noob, you don't know what you're talking about. It was very put down and there was a lot of gates.
And that's kind of where I came up and coming up in that, it was really, I realized after about five, six years was driven by insecurity. And a lot of the people that I saw in that space, if I actually got to know them personally, going out and having dinner with them were in almost neurotic, insecure people. So it was detection that they actually put in place and a number of people in the industry started opening it up around 2008 and tried to make it a little bit more accessible.
And that was a huge seed change. That was a big change in the industry. Uh, one of the people that I, you know, I miss horribly is Dan Kaminsky, who didn't talk with anybody about information security things. And he passed away recently and he was one of the best in the industry. Um, and Barnaby Jack was another great one that we lost too soon, right? I'm thinking of nothing but dead people. That's horrible. But, uh, there was a number of people that were very open in sharing, right?
And now it's almost like if you have that attitude, you're almost regulated to the wilderness immediately because they expect John Hammond, right? They expect IPSec, they expect these people to be just not just really good technically, but also good human beings and that that is a really big improvement in the industry as a whole. I completely agree with that. And, and that's what I've seen too, and I think it's so encouraging for the future of our industry.
So I'm, I'm so glad you you said that. That's really good. Um, I wanna talk about back doors and breaches for a little bit. I think a lot of folks know what that is. I actually have my card deck right over there. And I was at, I was in Boise, Andrew at, um, that, that Boise security conference. And I had the deck with me and somehow we got into the topic. I'm like, Hey, this deck right here. I'm like, I personally got this from John himself. They're like, no way. Really?
I'm like, yeah, I was use that right A boom. And he's giving away like, candy That's gonna go to my head. Go on, right? Well, They, they just thought it was the most incredible thing. But talk to us about, uh, why, um, uh, well maybe this it, first of all, what is back doors and breaches and can, can MSPs use it with clients? Is there like a scenario they can use it with like maybe non-technical? Absolutely. Or slightly technical people.
So back doors and breaches is a card game based on incident response. There's a hack and then you have to use cards to figure out what that hack was. It might a little bit of oversimplification, but that's what it is. And it's all contained in about 52 card cards, right?
So we built this game up to try to train people on the overall methodology and the concept of IR and learning what are the different components they can work with in order to identify different attacks and respond appropriately the procedure cards as well. But we also got the cards in play to understand what the different attack methodologies are. Initial attack and compromise, pivot and escalate, command and control, persistence. Those are the different things that attacks.
Now you brought up something I think is interesting and a lot of people don't do, but they should be doing. How can you use this to win more work and get more money outta your customers? So one, you can do a and website back doors and breaches dot. So once again, play backdoors and breaches.com allows you to play this virtually over a shared web, like right here on Crowdcast or Zoom with your customers or other people.
And what this helps you identify what are the weaknesses and the different things that are missing in your IT infrastructure. And you can sell this to the customer. For example, you can say, look, we're not doing, we don't have a really good endpoint product. We're just running McAfee or Symantec and absolute garbage. And you can see if we don't have a good EDR, how that impacts our ability to act to an incident or our sim running a full sim stack for you as a customer.
This is something that we really should be doing. And the companies can actually tie that to insurance requirements. So they can say, we don't have a good EDR, we don't have good sim, we don't have good back strategy in your organization. And to be honest, if there is a ransomware attack, your insurance company is probably not going to pay out directly tie it to that impactful thing that they're seeing in the news all the time. So back doors and breach tie all of that together.
Simple game package. Love it. And, and John, correct me if I'm wrong, it was at one point the bestselling game on Amazon for a little bit. Wasn't it like a car game or something? Did we lose John again By Satan? I don't mean Jeff's particular just Satan's on the board of directors.
But um, we reached it and we were number one on educational games for about two weeks and then I started looking at Amazon's cut and they were taking about 65 cents per dollar that we made and it was just a nightmare because their house was damaging our products and shipping 'em. So we now ship it out of our own website, the Spearfish General store. That's awesome. Wes, go ahead Please. Uh, the all I heard initially was Satan was on your board of directors or something.
I was like, okay, then we got the rest of it. So, uh, yeah. Um, John, we're outta time so I just wanna give you a minute, um, to please plug yourself, where can people find more about you and where you're teaching next? Can you give us some links or a Twitter page or something like that? We can go follow you on. Okay. Um, I'm on Mastodon at InfoSec Exchange as strand js. I am also strand js on Twitter. But the big thing is I got a class starting up next week, register for it, come hang out.
I can, has a link on the website that you can click and take it right to it, but no, it's pay what you can and even if it's about money, so, so come hang out. It's, it's really all about trying to get as many people in as possible and trained as possible and just having a good time. And as Andrew always says, it's pay what you can not pay what you want. Yeah, yeah. Yeah. Good point Gary. Yeah, Right. Don't abuse it. Yeah. Yeah. Don't abuse it. Um, John, awesome having you with us.
Um, we will certainly, I'll, I'll certainly plug it again. Uh, I'm trying to get, you know, more MSPs involved and engage the ones that have, and there's been lots of comments here have done really, really well, um, getting trained by you and your team. So thank you for all the content and training that you do. Um, just close us out. How many MSPs would you say have been through a course at this point? I would say we're probably over a thousand now. That's awesome. Yeah. That is awesome.
We Stopped, we stopped keeping track a while ago, Like 30 or 40,000 more to go. Yeah. To get that way there. Alright, well again, John, thanks so much. It was awesome having you again, everybody, I will communicate effectively better than I did this week. But Gary, we will be with you, all three of us, Phyllis. Yeah, check Your email, we'll have the link. Yeah. And we'll be with you in Phoenix for your event next Tuesday. So we'll have a one-off if you will, cyber call at your event.
Can't wait. Have a great day everybody, and a great week. Take care. Happy MLK day. Thanks Phyllis. Bye. See.


