January 25th, 2021 – 21 Questions you should ask your MSP
In this video, industry experts discuss the evolving landscape of cybersecurity for MSPs and the challenges of integrating security-first practices into streamlined IT service delivery. They explore the importance of adopting compliance frameworks, the role of dedicated information security officers, and the necessity of third-party validation to ensure robust security measures. The conversation also touches on the impact of compliance requirements, such as CMMC, on MSP operations and the potential need for industry adaptation to meet these new standards.<ul><li>The webinar discussed the importance of adopting an 'assume breach' mentality for MSPs and their customers, emphasizing the need to be prepared for potential security breaches among vendors.</li><li>The conversation highlighted the challenges MSPs face in balancing security with operational efficiency, particularly when deciding between integrated and best-in-class security tools.</li><li>The webinar emphasized the importance of MSPs developing and maintaining robust cybersecurity frameworks, possibly requiring dedicated cybersecurity roles, and the necessity of third-party validation to ensure compliance and security standards.</li></ul>
Guests
Video Transcript
All right, well, welcome. We just, uh, eclipsed 2,500. I don't know if you saw that, folks. Uh, but, uh, I, I looked down this morning, Garrett, and there was 2,500 there. Um, speaking of 25, 11, there's, uh, Wes. Wes, how are you? Hey guys, how's it going? My hotel wifi finally decided to work. There he is. Man, that sounds a little raspy. Yeah, it was my Do you need a nose swab? I'm good. Alright. Tao Covid edition, everybody. Yeah. I'm the most sequestered person, you know. That's true.
You are. Um, fantastic. Well, awesome. Um, so, uh, just, uh, a few things. First off, I wanna welcome, uh, Ryan heor from Steel Root Managing Partner there. Um, welcome all of you. Thank you so much for joining us. As always. Um, few quick things and then we'll get right on into it. Um, number one, I'm gonna put up a poll question while we get going here. Is that visible, by the way, can you let me know on MSPs? Okay, thanks. We, okay, so poll questions up. A few announcements, Gary.
We have collectively everybody here. We've got the Cyber Resilience Summit slash roadmap coming up. We should have a landing page in the next few days. I talked to Gary Junior. Yep. Um, that's gonna be a, a, a two day event, two business sessions each day. It's not gonna be one of these long drawn out things. We're gonna be talking about, um, bringing, uh, back, um, you know, uh, assume breach mentality. Looking at Sunil Hughes, uh, in documentation. Where do you live?
You know, where is your MSP today? We're gonna go through a, uh, uh, uh, tabletop building your, um, incident response plan, taking it to market. And then we're gonna do two technical tracks. You know, you've heard us do capture the flag events, et cetera. We're gonna do them a little different this time. Pretty excited about this. We're gonna have Jason Slagel, uh, from CNWR, who's, uh, a guru when it comes to this stuff.
And, uh, the, uh, from the perk sock, Bryson Medlock, who's, again, Fanta fantastic at this kind of stuff. What we're gonna do is we're actually gonna walk through Vulnerabilities and, you know, how to discover them, how to exploit them, and then we're also gonna do web exploitation on day two. So it's not gonna be like, you know, 1, 2, 3, go, who's gonna win? They're actually gonna walk through and teach.
And I did some polls on this, um, Ryan, Gary Wess, and, uh, much more well received by the MSPs, uh, instead of competing. So I'm excited about that. One other thing, if I could, um, I saw this, uh, I just want to add, I put it in the Cyber Nation. If you're in the cyber nation, you'll see it. But really cool, uh, FR Secure is offering, and I just put it in chat, uh, a free, um, mentor program for C-I-S-S-P, uh, for all the do. They're gonna walk through all the domains.
It's free training, check it out. Um, uh, full disclosure, I'm not, they're not a client of mine or nothing. So I saw it and I thought it could help you guys if you're interested in those things. Lastly, Gary, you know, you were talking off screen that, you know, our MSPs, and this is kinda leading into starting this, are gonna be educated, you know, why are we doing this?
Um, you know, the, the, you know, the article that caught, well, let me let you just kind of really quickly share what captured your attention about this article Ryan wrote, and I'm gonna put a link in here, ask Ryan a few questions and we gotta add it. But can you, can you tell me what you heard and why it came about? Just more of the same. You know, I was reading about the latest, um, you know, breach in, in, in terms of the, you know, security vendors, um, and with, uh, SonicWall, Right?
So I think Ryan said this is like the fifth one. There's been, you know, in pretty recent. And so I'll be putting out a message to my customers, my true, my peer members and true methods members that, like, you know, we've been talking about using an assumed breach mentality for your MSP, for and for, you know, your customers.
But I'm saying we have to assume that all the vendors we deal with have been breached, and we have to make our plans and design our security posture with that po, you know, like more likely today scenario. Um, and they may already already be breached, right? Right. We know that with SolarWinds they were in since March. And so, you know, I would like to hear from Ryan and Wes, like, that's a big statement to make.
And, and I'm not sure what the solution is, other than I'm saying awareness is always the first step, right? And I think that that's the awareness. Now. We were only thinking about us and our clients with some vulnerability with, with our, with our vendors. But now I think we have to assume more broadly the potential there. Yeah. Um, no, good. No doubt.
And I know Wes is gonna take, get, get into that a little bit from the vendor side, uh, Ryan maybe too, but Gary, um, you were also taking the position that, you know, what's critical about Ryan's article here that we're gonna get into is that Oh, yeah, our clients are gonna get edu whether we like it or not. And this is what, tell, tell us your thoughts there. I'm gonna put a, I'm putting a URL in here. This is from C insurance. Go ahead, Gary.
Yeah, so real quick, I, I, I asked, um, Andrew, if he could get Ryan to come on a future call, because I saw, saw Ryan's article about 21 questions that you should be asking your IT provider, your MSP, and it, it, it, it kind of got viral within my community, my True Methods community.
And I, I did a couple follow up messages around it and to say that, listen, you need to look at this, and you need to be, be prepared to answer questions because the industry now is gonna be educating your customers the SMBs on what questions they need to ask, and they're listening.
So I, I just think that when I saw that, that having Ryan here today about how we developed it, how we got there, share with them, how I'm seeing it used in different ways when we get that far that I see some of, you know, my, my True Methods members using it and, and kind of what it means. I think it's a turning point almost again, in the industry. Yeah. Um, so I put a link in there, Gary, if you get a take, take, take a gander. Anybody take a, take a look at it. And that's actually from CFC.
Um, basically, you know, they're the, they're the carrier and they're educating. And then when you look at the policies, uh, yep. And the renewal policies, and then we've talked about this with Justin, uh, remu. But, um, I was on the phone the other day, uh, literally last week with another MSP and the degree of scrutiny now for third party providers by the cyber carriers. It's not just, are you doing a vulnerability management?
Yes, no, it's submit external scan, submit, internal scan application scans. It's this thing is, you know, again, not trying to be, you know, like hyper, hyper do hyperbole here and get everybody again in a frenzy. It's just the reality. And I posted, last thing I'll say is I posted a video of Wes today, um, when we were doing a, a webinar where he starts to talk about regulation.
And Wes, uh, you know, can you just gimme a people that might not have watched that video yet on LinkedIn, just a snippet of what typically happens and why. Yeah. Um, so go watch the video, I guess is the best way to say it. Really good, simply. But, um, yeah, you know, I think, uh, I, yeah, I, I think these are all we, Gary, one thing that you're famous for is use every situation as an opportunity to educate and have an open conversation with your clients. That is what they expect us to do.
We wanna be that VCIO vcso role for them, which means that we've gotta have these open conversations about all this. So whether it's using the, um, currently the, the, uh, the breach stuff that we're talking about today, or the stuff that's been in the news for the past three weeks, these are all opportunities for us to have those open conversations and also get our agenda across of the things that we really do need to communicate that's best for them and best for us.
And so, just go watch the video and you can see more about it. Just, that's a quick teaser for it, but this is more important than Ever Before. That's awesome. I'm chuckling because of the years I spent with you, Gary. What, man, if you had an inside sale, if you had your MSP today in your inside sales engine, would you not just be hammering of, wouldn't you want to compare what your current MS P ab? Absolutely. Yeah. Yeah.
You know, what I was saying is, um, and we're gonna talk about this when we do the sales portion of our upcoming, uh, you know, event, is that this is the first time since I've been doing this. We're always trying to educate SMBs. So, you know, from a, a thought leadership standpoint, but this is the first time with these changes in security that, one, they understand it, and two, they're listening.
So this is, again, we talk about the risks, but like, uh, what Wes said, this also has so much opportunity around it at the same time, if we do it right. Yeah, absolutely. Okay. So with that, Ryan Austin, to have you with us, um, you run a great MSP out of Massachusetts. Could you tell us just a little bit about yourself and the company? I'll ask you a few questions to set the stage, turn it over to Gary, and we'll, we'll let this thing rip. Absolutely. And thanks for having me.
Long time listener. First time caller as it were. Um, yeah, so my company, steel Root we're a, a managed services provider in the Boston area, and most of our clients are defense contractors. So we've got kind of a, a niche specialization on companies subject to federal cybersecurity requirements. Um, as far as myself, uh, started the company in 2017, before that, held roles at various, uh, software vendors before that IT operations for, for a number of years at a, a university.
Yeah, Well, not just software vendors. You come from one of the behemoth in data security, so you know, a thing or two about cyber. So cyber, uh, you're being a tad modest there, Ryan. So look, um, talk to us about the article. As I recall, um, the story goes, you have a good friend or a friend, uh, I don't know how good or not, but you have a friend in a, in a highly regulated industry, due to some reasons you didn't want to take the business.
Not that it was bad business, but just, you know, you said, you know what, I'm gonna recommend you look at an MSP elsewhere. And the response was, Hey, Ryan, that, that makes sense. How do I go about vetting them? So talk to us a little bit how this all came about, Came about. Sure. Yeah. This was probably about a year ago, I would say. I've got a, a professional acquaintance.
Um, we worked together on a, a, a nonprofit project, and I can't recall if they were replacing their MSP or getting a new MSP, but he said, Hey, can you help me ask the right questions? When I get these candidates in the room, what can I ask to know? You know, whether or not they're full of crap when it comes to security. Um, as you said, they, they operate in a, a highly regulated industry, lots of sensitive data.
So security was important, but, you know, they're not IT practitioners, they're not security practitioners. Didn't know what to ask. So I said, yeah, I'd love to. And I, I sat down and just started bulleting out some ideas.
And over the course of a week or two, um, before I knew, I had a, a couple pages of bullets for 'em, and I said, this is probably more info than you were looking for, but, um, here kind of the, the, the general areas that I would be asking a service provider to, to vet whether or not their security posture is enough to protect my business. That was kind of the genesis of, of that article. Right.
So then what made you take the article and, you know, turn it, sorry, what made you take the questions, turn it into an article? And I think some of the responses you got from MSPs were kind of like, made you start scratching your head a little fair. Yeah, that's fair. Um, these bullets kind of sat on a Word doc on my desktop for a while, and, uh, every time I looked at it, get a little guilty. 'cause I, I knew there were things in there that I was not doing.
So, um, one of my themes of professional development for myself and my, my company last year was to really put into practice some of these things that we preach and, and make sure that, um, you know, as much as we can be, we're a above reproach in that regard. So put together an article. Uh, we've kinda an outside firm that helps us write some of this stuff up.
Uh, it got placed and, and when it did, uh, some of you may be part of the, the Reddit subreddit, MSP community, um, I posted the link in there and, and some folks immediately jumped down my throat being like, who is this for?
'cause the, the article is written as if, um, here's some questions you can use to, to ask your MSP, uh, and we can dive into this in a little bit more detail, but I think it's pretty clear for those of us with customers that, um, many of our customers wouldn't know how to parse out some of these answers.
So, as I was discussing it with other practitioners, I realized, you know what, these are questions for us, for the, the owner operators of MSPs, um, to make sure that, that we're doing the right thing for our customers. And, you know, there's that saying that, you know, you 0.1 finger and three more point back at you.
I definitely feel that, you know, I, some of these questions, I definitely didn't expect this article to get this much traction, but as it did, I was like, oh, shoot, what did I write in here? And am I doing all this myself? Right, right, right. Well, good for you for doing it and good for you for, um, holding yourself accountable, Um, and, and sharing it with the community. I mean, I think this idea has to change.
Like we're kind of all in this together now, and as always, in the 25 years I've owned MSPs, or as I like to say, I'm currently between MSPs right now. Um, the success of an MSP is, is solely based on your command of the business and ability to choose the right priorities and execute on them. If you do that, you'll reach any goal that, that you set regardless of, you know, the external factors, and there's a lot more external factors.
So, uh, Ryan, I just, I wanted to start by just, you know, commending you by, you know, putting that out there and it made an impact, you know, on, on people. I can tell you that. That's Awesome. Thank you. Yeah. Gary, I'm gonna hand it to you, but in doing so, you know, again, go back to, you know, all the way back to oh five, uh, to oh five, you know, and you and I first met and all you, you, you had command and you ran an awesome MSP, but it was never inward looking like we have to today.
I mean, it's a completely different ball game, and I know we've talked about this, but yeah. In setting that stage, I'd love to hand it to you and, and, uh, take it on. Take it from here. Yeah. I think about how different it was, even building the second MSP, um, which, uh, I guess you might've saw, uh, that was, uh, apex and I guess got, uh, public today that was acquired, uh, it was acquired by, um, thrive. Yeah. So had a successful exit and, um, how different that was.
And then I thought about, um, I just did a message, an audio message podcast for my customers called a clean sheet of paper. Hey, what if you could start your business today with a clean sheet of paper? And Ryan, that's kind of what you have been able to do, right? Because you're fairly, you know, new in this, so you had all this knowledge and you'd be able to start, you've been able to start with a clean sheet of paper.
So, um, first thing I want to ask you is, you know, with, uh, has what's changed since you published that article? Like, what have you learned? I know you said from writing it, you learned the fingers were pointing back at you. So I'd like to hear what changes you make as you wrote that and became more self-aware. That would be part one. And then part two is when you saw the response, what did it tell you about what's happening in the industry? Yeah, good question.
Um, I, I think in terms of what's changed, it, it definitely renewed our commitment and accelerated our commitment to putting in place the, the practices that we tell others to, right? That the phrase that kept coming back to me after this article came out was, please secure your own mask before attempting to help others. Hmm. And to your point, too, about a, a blank sheet of paper, it's like we, we started our business in 2017, and my partner and I had this, uh, one technical goal in mind.
We said, can we launch a security focused business and never have a domain controller? Um, so we did that, and it took a couple years for technology to catch up to the point where the things that a traditional domain controller does for us around security, we can meet in other ways. But, um, I, I totally sympathize with that transformation that has to happen, especially, you know, if you've run a, a successful MSP for the last 10, 20 years.
Um, I know that even in the few years that I've been in business, the tooling has changed dramatically. And so of the capabilities. Um, but, but to your question, I think what's changed for us is, um, we've committed to some of the, maybe the more difficult or time consuming or unbillable aspects of, uh, security and governance that, that I was, uh, espousing and trying to make sure that, that we're doing all those things internally. Does It mean you have to charge more?
Have you figured out that you have to charge more? Yeah, good question. Um, yes, yes, I think is the short answer. Uh, being a young MSP, we're not super mature in our, our metrics to, to know like, precisely how much more we've had to charge. But definitely our bill rates have gone up. Uh, the rates for our stack of tooling have gone up as we've added new components. Yeah. You know, uh, I get to see benchmarking for, you know, almost 150 companies now in our peer groups.
And we had the meetings last week over four days, and both sets of group, you know, one thing I told them was, look, I can look at your seat price and your profitability, and I can almost put you into two, three categories. People that definitely are not secure and can't secure their customers, those that have a really good chance and probably are already doing it. And the ones in the middle that have to make a choice which way they're gonna, uh, which way they're gonna go.
So that's continues to be a big, uh, issue. What did the response from that article have? Like what did it tell you about what's happening in the industry right now? Like, you know, people kind of picked up on that, MSP's picked up on it, have used it, changed it, like the concept of it. So what does that tell you? Yeah, I mean, not a single, uh, end user customer client has, uh, responded to that article.
So it's been unanimously other MSPs saying, uh, shoot, either I'm, I'm glad you're holding our feet to the fire 'cause this is something I know we need to do. Or more often asking questions about how do you do X, Y, and Z in your small business? I know you're also a small business. How do you actually practice some of this stuff?
Um, so to me, I think it's pretty clear it's that, I mean, everyone here knows you don't have to go very far to see why Cybersecurity's important customers are starting to understand why it's important.
Um, and it's a matter of us as the service providers to make sure that a, not only that we're recommending the right tooling and practices, but that, um, more importantly, we're doing those things on behalf of our customers because, like it or not, they're gonna inherit our cybersecurity maturity or immaturity.
Uh, uh, I'm just looking, I'm, I'm watching chat here while I'm listening to you and Ed said something they've been asking themselves is, if I were to start a new SMB right now, what I hire RMSP, and I almost think about it, people ask me for recommendations all the time. And man, I hate to recommend anybody now just for, you know, for all of these, uh, you know, for all these same reasons. Um, but it's interesting that more MSPs hooked onto that.
And again, Ryan, the way that I see them using this is they're taking, you know, maybe they're using it to develop their own questions, five questions, eight questions, and then they're using it, um, in their thought leadership to their prospect base to educate their prospects, um, to kind of, and they're getting more people to raise their hand from it.
So I don't know if you ever thought about it in that way, but they're taking it and using it to educate their prospects and hoping that they can answer those, you know, they're probably putting the questions that they can actually answer on it. Sure. And it's not 21. I do the same. Um, yeah. I'm still waiting for the day that one of our customers or prospects comes at me with those questions. Right. Um, yeah, no, that, that's a good point too.
And obviously there's a, there's a sales, uh, story to be told here too, especially if it's a competitive situation. I think it's probably the strongest differentiator among MSPs right now is, uh, cybersecurity. So it, it makes sense to turn those questions as a, a mirror both for yourself and that the customer can hold to you as well.
Listen, I could ask Ryan questions for the next 40 minutes, but I'll, I'll, and I have, if we have time, I'll circle back to you a few things, but I, I think at this point, based on the timing of it, I'll, I'll hand it over to, to Wes. Well, that's so kind of you, if I can only come off mute. So, um, Brian, I read that article too, back when you first wrote it, and I was like, this is freaking awesome. Like, I love it.
And one thing you said that I think is right, uh, is it, it's mostly for MSPs to read, right? Uh, we know that probably lots of clients are not gonna come across and read that. It's sort of like a physician Healy self reference if, if anything else, or like, it almost feels to me like, uh, and take this in a good way. 'cause this is a compliment, but it's like the, the clickbait, you know, like 10 things that like doctors don't want you to know and only doctors go and read that, right.
To fi find out, well, what is that thing? Sure. But it's useful for us because you're asking the right questions. And, um, I'll be honest, like there are certain industries that absolutely will ask questions like that, right? Like banks, for example. Mm-Hmm. They, they have been forced by their regulators to get into like deep due diligencing of their vendors, of which MSPs are now under those crosshairs. And so, um, there's so much relevance in the article. It's really, really good.
And so I guess my question, my first opener is, um, I do like how you start with compliance frameworks of mapping to it. I mean, we've been talking about that ad nauseum all through 2019, but can you dive into that a little bit more? Like, it's not just, you know, the client coming to you and being like, Ryan, do you map to a control framework, but like, how do you dive into that more? Like, how do you illustrate value to a client in that?
Is it just popping up a big Excel spreadsheet of showing all the things that you map to? Um, how do you actually use that as a competitive advantage or as a way to communicate value? Like how do you actually make that valuable? Yeah, great question. So my dream state, this is not something that I've done, but what I'd like to do is have, uh, such a robust set of documented procedures that I can go to a client and say, alright, client, we're, we're pretty far along the sales process.
Let's go under NDA, I wanna show you something, right? And then pull this up on the screen and say, um, when you access, ask us to do X, Y, and Z, here are the, the policies and procedures that we hold ourselves to, right? To demonstrate, um, this is not a, an an ad hoc process for us, but we take these things really, really seriously. And when I think about governance, right, for an MSP and what does that look like?
I want to know how does that MSP embed these ideas of risk management, uh, and situations situational awareness into how they operate as a company. Um, and that's hard 'cause you can't really see that externally, right? It's, it's hard to know, like, what are the indicators of good governance? Uh, and I put at the beginning of the article, knowing full well that it's, uh, probably the hardest thing to do, but it's also step one. But I think it, we can probably all relate.
It's the thing that we're all like, yeah, I'll get back and rebuild that after I figure out what tool I'm selling for X, Y, and Z or after I implement, you know, x, y, and Z security practice. But, um, I just know, like if I were a customer, right, trying to assess governance at an MSP, I'd want to ask a question like, when someone from my team submits a ticket to the help desk to open a port on the firewall, what happens? Right? Walk me through that process.
Is there some sort of internal validation approval documentation that needs to happen? Or am I gonna get a ticket closed notification and now the port's open? Right? And, and those are governance questions. Wes, can I just ask something real quick here that, you know, Ryan, one thing that's really interesting that, not only that, but like, is even before that, is there a way to check identity for that phone call? 'cause that's a piece that we're, you know, we did a poll on the cyber nation.
That's a huge piece that most MSPs are missing right there. Hmm. So just No doubt. Go ahead. We, sorry. So, you know, Ryan, one of the things that you're getting my brain going on some of this, and, and, and, uh, one thing I wanted to follow up on is, is this is, uh, so my wife went and got her car tires changed on, on, on her car, right? And, and I'm going somewhere with this, right? And she ended up going to a vendor that, uh, she paid way more than she would've had to have paid.
Uh, but one of the things that when I was like, you paid that much. And she's like, yes, but, and she gave me this big list of like, here are all the things that they do for free through the interims. It's like, if I get a flat tire, if I have all these like, problems that come up, free inspections, you know, you name it. And they're like, you can just bring your car in anytime. And this is a big, long 10 point checklist, or 20 point or whatever it was, of all the things we do no cost.
And you and I both know she's probably not gonna ever go back there again until it's time for new tires. But it was the sales, uh, tactic of we are covering you end to end. And Ryan, I have to think that there's some value in when you adopt framework and you communicate that clearly, you get to say to that prospect, we are adopting you into this. Hmm. In fact, we're not gonna take you without it.
And so, yes, we're a little bit higher per seat than our competitors down the road, but we bring you into all of these things that we're doing. You inherit the things that we're doing as well. Uh, there's sort of some advantage to that, right? I mean, isn't that a, a huge piece of how we can use compliance frameworks to communicate value? Oh, right on. I love that analogy.
And, and so in our world, where we are, uh, where our clientele are mostly DOD contractors, and we're looking at DFARS and CMMC, um, I, I'd say maybe 30% of our, our customer bases does not have those requirements.
But what we did is we said to them, uh, sorry, we've got this upgraded security package that, that you are opted into, um, by continuing to do business with us, knowing that it includes some things just like the, the tire salesman or whatever, um, things like application allow listing that some of our clients may never do if they don't have to. Uh, but it, it does allow us to say, uh, you're, you're bought into a, a, an ecosystem and a, a vendor that takes security very seriously.
We want to do all of these things for you. Uh, and I think it gives the customer just like your wife some assurance that, okay, I picked the right company to cover me if these contingencies come up. You know, and I'll jump in real quick. You know, Wes, what's funny is the MSPs we work with that have the most, you know, mature security postures are the ones that kind of share with all their customers that no matter what they do, they're not secure. And this is why we approach it.
And the ones that have less of a security posture try to convince customers that they're secure. It's an interesting correlation. I'm gonna call that the, uh, the peak of paradox. But Gary, don't you think that's an ego thing? Like again, you know, more self-aware, you know, being, you know, protective of, you know, what they don't know because of ignorance and things like that.
Part of it, and I think part of it is just what we've been talking about this past year, which is when you do the work that we're talking about and you realize how much it is, it's like a thread. You keep pulling, you have the confidence, uh, to, to be able to say like, to a customer, like this is where we are.
Like I told our peer groups, if one more person says to me, go back to their customers for a price increase, and, and what do I do when the customer says, I thought you were already doing that. You know, I'm, my head's going to explode. It's just like, yeah, we were doing everything a year ago. We were supposed to do, can I tell you what's changed in a year? Yeah. Like, this is not an M ms P, just an MSP issue. Like their risk pro profile has already changed. They can't blame you for that.
Call Russian. Ask them, tell them. Yeah. Well, I think, and you, as you said, Gary, never before, has selling at a higher price been a competitive advantage, Right? Yeah. I think that's right on. Yeah. So Ryan, another question. Oh, go ahead. If you wanna finish that thought. Oh, no, just real quick. I, I, and I often use this, someone else gave me this, but talking about compliance, but the same thing I think is true of cybersecurity.
It's like, um, getting to your baseline in the compliance world, like checking the boxes, right? That's step one because compliance and cybersecurity, you're like having a baby. It's like, it's not over when the baby's born. Now you've got care and feeding for the rest of the time that you have a business, right? So I Love That's a great analogy. That's a great analogy. Yeah. Gets more expensive. Yeah. Oh it does. Yeah. Wait until they get to college, right? Yeah.
Well, yeah, just on the, So, uh, let me change gears for a minute. And I, I wanted to hone in on, so I just picked some of the, the things that you mentioned, some of your 21 questions that really just attracted my attention. The other one that really got me going was this idea of, you know, a dedicated information security officer. And, you know, Gary Peak and I were, I don't, Gary, if you remember it, one of the IT nations.
You had asked this question like, how many of you have at least one FTE devoted to some like non-revenue generating role? And like, not many people raise their hand. And that's changing a little bit for sure. But, uh, we, we still, you know, I love that idea of like a dedicated, whether it's a chief information security officer, it's just a director of security, whatever the title may be.
But Ryan, how does a smaller growing MSP get to that phase where they can have somebody that's just dedicated to FO focusing on cybersecurity for their MSP and for their clients? Is that something you have to step into? Is that a shared dual hat role? At what point can you begin to do that? Just gimme some thoughts and wisdom on that. Yeah, I'm, I'm trying to work this out for myself right now. So we're a small company. There's 17 of us, right?
So, um, adding a an FTE to just do cybersecurity internally is the goal. I would love to do that. We're not doing that today. Today. It's a fractional responsibility. Um, what it came down to for us after looking at it, at least in this phase of our growth, is not that it has to be someone's full-time job, but it has to be someone's job. Someone needs to, uh, you know, be measured on their, their fulfillment of their responsibilities in this role. And it can be someone that's customer facing.
It could be someone in leadership as long as they are allocated the bandwidth and measured on, on how they do this kind of thing. Um, Oh, go ahead. I was gonna say one thing that came up, this came up in discussions in some special projects in our peer group this week, and they're kind of that same path you're talking about. You have to be careful what you call them. 'cause they're not really gonna be like a, they're not, it's not gonna be Wes or Ryan Weeks.
Like you're just not gonna attract and retain that. It almost has to be just someone who's responsible for that journey to see that it goes in enforcing it. I would think, I don't know. I think that's right. I mean, hopefully you've got someone on your team with cybersecurity expertise and or experience, I should say in some level. Like find the most senior person there and, and see how much of their time you can allocate towards being better internally and, and grow it from there.
Yeah, it's good. And, and these are questions, I think in 2021, we should start to think about is how do I grow my MSP into a role where there are at least some dedicated coverage in thinking purely about the security governance and structure for me, my own organization, my own MSP and all of our clients, right? Rather than just haphazardly doing it, piecemealing it, expecting the technical analysts to be the ones that run it, because those are not the folks that run it.
Those are the, well, they're, they're tactically they run it. But just thinking strategically of, of, through all of this, we, we've gotta get there. To that point, I think ideally the goal in mind should be to have somebody dedicated towards it. But we also recognize not every MSP is there right away. In fact, a lot of the folks that are on this call are younger and beginning their practice. And so it's something you've gotta earn into. And it's okay to share those roles initially.
Probably the owner at least should be somebody that should really be focused in that, uh, because they're the ones that have the ability to push that through. But eventually it should be somebody that's purely dedicated to thinking all about security.
And this is where, you know, the way enterprise will handle this is they, they talk about that separation of duties between those who practice security and those who practice it should be in distinct units because those that practice it, if they're also doing security, there can be a little bit of that fox guarding the hen house in, in many cases. Sure. And so how do we get there as an MSP, right? These are definitely things we should be thinking about in, in 2021.
Um, Ryan, my last question for you, and this is, um, you can go any direction you want on this and then I'll see my time over to to others, but give us an update on CMMC. Uh, this, we, we've been talking about this a lot through 2020, but you guys are very focused on it. Any updates, anything you've noticed, anything happening that are just newsworthy of the past maybe month or two that you'd like to share with us? Sure. Let me think about that.
I, there's a lot going on and, um, a lot of of my comments and critiques are, are probably more in the weeds than, than most would want to go. But, um, I think one big question from the community was, is this change in the presidential administration going to affect the rollout? Um, and I feel pretty confident in saying it at, at this point that it's probably not going to, uh, at least in a substantial way. I, I see the CMMC model, uh, moving forward.
It's in motion, um, in terms of timing and expectations. It's like we've got these certified provisional assessors. We've got the first few organizations that are gonna be these third party assessor organizations, or C3 PAOs as they're called. They, they're being accredited. Uh, the DOD has signaled now this handful of contracts that are likely going to include the CMMC requirement in 2021.
What we don't know is any type of practical on the ground examples of what an assessment's gonna look like. 'cause none of them have happened yet. So in 2021, we'll just be closely watching these, uh, these Pathfinder contracts, see what an assessment looks like. Uh, I think the majority of my customers will not see A-C-M-M-C assessment until 2022 at least. But there's still a lot of, uh, in my view, unanswered questions about how this assessment goes down.
And, uh, we'll be watching that really closely to learn some lessons. Awesome. Awesome. Great. So Ryan, thank you for joining and thanks for, uh, the insights here. I'll turn this over to, I think, Ryan Weeks. Yeah, Thanks, Ru. So I wanna pull together a few things that we've talked about, right? Wes said something about like deep due diligence, right?
And we're talking about you, you talked about having this robust process inventory that you could show and, and really, you know, it talks about supply chain and needing to vet the security of your supply chain. So this all kind of culminates in this, like, how do you prove that you are secure? How do you prove that you're doing reasonable things? And and I like the idea of like, you know, there's, there's some internal documentation or collateral that we have.
I think that's definitely step one. But then step two is, you know, this this accountability piece of, um, you know, as we all know, I could go to a vendor and say, Hey, do you have x, y, Z in place? And they could give me some answer. That's a partial truth. Um, and it's hard for me to see through that unless they've actually been validated independently by some other person to, uh, to, to, to prove that they're doing that to a certain standard or to a certain level of quality.
So how does this, you know, as you're on this journey of like, you know, um, you know, doing what you preach, uh, how do you think that third party validation, um, piece plays into how you're, how you're holding yourself accountable and how you're gonna communicate to your customers? That's a really good point. I mean, yeah, from a controls assessment validation perspective, um, that's, that's the logical next step in, in your maturity journey, right?
So it's like, um, I know for a, for myself, I'll just speak for myself, but I think the same is true for a lot of MSPs, at least those that I work with. Um, we have a lot of work to do before we're ready to do things like, um, you know, red team exercises or, uh, to get a, a third party standard to come in and audit and certify me at, at a, at a particular level. So it's like you start with the known things, right?
And then once you get to this level of maturity where you're ready to peel back the curtain and, and see where, where some of like the, the nuances of controls where I think I've implemented something, but the assessor's gonna have findings, um, that, that's clearly the next level, uh, in that journey. Yeah. So I, I think that's super important. And just another proof point to show to the customers.
Not only have we implemented these things, but um, here's the third party organization that came in and held us accountable. Yeah. And maybe just a pro tip for, or MSPs on the call, many of those auditors will actually do a pre-assessment engagement called the GAP assessment. And so it's kind of like a, hey, this is like we're, this is like the Thursday night run through before the Friday night game, right?
This is like, you think you're a hundred percent ready, let's run you through the gap assessment and um, you know, and actually see if you're ready. And those generally are lower effort, lower cost than the actual engagement. So you don't actually need to be a hundred percent there. Hmm.
Um, and I love those gap assessments 'cause we actually use them internally when we're seeking new compliance standards to drive improvement, to drive increased focus on things or, um, you know, align resources. And so that's something that you can do. Um, you know, I I I, I actually, I've, I've thought about this idea of creating a set of questions that MSPs should be asked by SMBs, but it never felt kind of right for a vendor to be doing that.
So I, I've always stepped back, but I, I love the fact that you did it and I think it's gonna necessitate a lot of changes to procedures and policies.
What, what are like the first, you know, what was like the two or three biggest fundamental policy and procedure changes that this is necessitated for you For, for us personally, it's kind of happened concurrently with, um, and to your last point too, kind of the same ball game, um, us preparing for ourselves to go through A-C-M-M-C level three assessment at some point.
And the, the big thing that get introduced there versus what we were doing before is that CMMC wants to see this process maturity, um, which is, looks like a whole bunch of documentation. So for example, you know, from day one when we first drafted, you know, version zero of steel Roots internal policy and procedures, we thought we had pretty good coverage over the, the major security domains or whatnot.
Um, and what has really happened to, to change my understanding in the last six months or a year or so, is, um, I was not aware enough of the, the gaps in policy and procedure until I ran into something where someone didn't know what am I supposed to do here. Uh, it's pairing that with, uh, the CMMC framework has been useful for us because it's a standard that we use a lot to say, where are our gaps on these 17 different security domains?
So what that's looked like is a whole lot more, uh, document creation, uh, testing out of, of procedure and, and starting to get some of the stuff drafted. Yeah. I, I pivoting off of that, I think there's, there's still some confusion about CMMC versus something like NIST 801 71. Like is, are they the same? Are they different? Is it easier, is it harder? Um, are people actually like picking it off? Is it fundamentally changing the way you need to have conversations?
Like what is this doing in the SMV space? Like is it causing confusion? Is it changing behavior? And, and how are you adapting to that? You know, just give us a sense of what you're seeing, All the above, lots of confusion, uh, for on those exact points that you mentioned, and just how is this gonna affect me? When do I have to do something? How much is it gonna cost me? How long does it take? All those kind of things. Um, but I'd say it's definitely driving change.
And I saw Andy Sauer earlier in the chat saying compliance is one of the best things to happen to, to MSPs when it comes to trying to sell cybersecurity because it's like the big stick in the carrot or stick equation, right? Um, so among my client base, can we just say it's the best thing that ever happened to about 10 or 15% of MSPs? There you go. If your client has compliance requirements, you're, you're in a nice place to to, to do and you can deliver it and you can deliver. Yeah.
Which is a, that even further shrinks the, the percentage, right? No, that's, that's a good distinction. But, um, for these clients that have this requirement, it's an existential threat. Uh, so it's like, do you like this revenue that's coming in from the DOD? Yes, you do. Okay, well, you need to change your behavior otherwise it's gonna go away. Um, so for companies that have requirements like that, I do see it as a, a big behavioral change impetus.
Ryan, can I, can I ask Ryan a question to your question there? Do you mind Ryan? Weeks? Yeah, no, it's fine. So are you seeing, you know, Wes brought this up a while back about like hipaa, Ryan, are you seeing anyone that just goes, Hey, you know what, I see the cost. It's not that, you know, it's we're we're out, or, you know, it's even though it's a big portion of our business or we're out.
Like are you seeing any of those behaviors the way doctors' offices either sold their practices or, you know, maybe they're getting near retirement, they're like, I'm done. What are you seeing any of those things already? I don't know that I've seen anyone put any of that, uh, rhetoric into practice yet because it hasn't really hit them in the face. But certainly a lot of people are talking about that.
I'd say if you have these requirements and they are onerous requirements and it only affects a fraction of your business, you're gonna have to have a hard conversation around whether you wanna stay in the game or not. Um, I think that will look like a lot of consolidation over the next five years, uh, in, in my customer base. So for, for better or worse, um, those are, those are gonna be some tough things that folks will have to deal with. I think it's something that, The same thing.
So MSPs, yes, don't specialize in this, but just have a couple customers. They have to make that decision whether they just transition out of those customers even though it hurts, because the effort it'll take, they either gotta get all in and really start to leverage that, or they gotta just stay in their lane. Gary, I mean, do you see the same thing if, if we become regulated MSPs? Do you see the same thing happening? You know, what do you see playing out if that were the case?
Yeah, look, I'm asking the question now. I put something in chat. It's not just the fact if your prices are too low, maybe you can't secure people. Like we're reaching that point for all the reasons that Ryan's and Wes had said today about what this takes with some dedicated resources.
Uh, have we already reached a point where even before we get to that point, Andrew, that scale is an issue, that there's a certain level of scale that MSPs are gonna have To have to even be able to, to play in the game of the next, you know, within the next, you know, couple years. So, um, and that's before we get to the point where there's more, where there's more regulation in this thing.
So absolutely, I think the timing of that, n none of us know everything seems to take longer, um, unless the law gets passed and like we saw like GDPR may made a pretty big change in a lot of things, right? It had a lot of ripples, you know, pretty quickly. So that's the one thing we're not sure of. And, uh, like Ryan said, I don't know that it'll happen through the current administration, but you never know. Yeah. Well, Gary, I'm gonna Ryan Hedo ask a few questions to you guys.
I know you've got a hard stop, Gary, at 1 55. Yep. Um, Ryan, uh, Hedo, is it possible to ask Gary his question first just in case he he needs to, to jet out and Absolutely. So Gary, I've got a prepared question for you here, so forgive me for reading off the screen, but I'm interested to get your feedback here. So, um, something that, that I've talked about a lot with, with my business partners is this classic debate between the best in class tooling and integrated tooling, right?
Um, our pursuit of being, quote unquote security first has led us away from integrated solutions, um, sometimes because we couldn't use them for compliance purposes, but in favor generally of things like zero trust concepts, segmentation, managing different solutions for different customer use cases. But my question is this. So as a result, we have built in so much friction into our operational processes, slows us down, increases our costs.
Do you, from where you sit, think that there's some sort of trade off between putting security first and running a streamlined IT service delivery organization? Or is it a tooling issue? Uh, it, it's both, but a hundred percent okay. And if you really think about it, you know, part of it is, you know, if you look at the tools, uh, for security in the channel and you compare that, what tools are available in the enterprise, right?
There's a huge gap and I don't really see the gap closing that quickly, right? So every one of my most security first MSPs, they have to walk that fine line between, there's only so much they can charge, but to, to really secure. They're doing the same things with some, you know, different types of tools that's creating the same type of friction. And sometimes it even creates more security issues, right? Because definitely because you can't have the same policies in your arms around something.
I mean, sometimes a less secure tool with better policies, and it's better than a more secure tool that's one of four or five. So, um, you've uncovered, um, and so what I'm gonna say is everyone I know who's gotten down the line, like, you know, kind of where you're headed, they're all facing the same thing. The average MSP hasn't gotten far enough, you know, to, to uncover this yet. Um, and I, I don't know what the solution is, Ryan.
'cause you know, we're in an industry where, um, you know, we have four big vendors, right? That, um, control a lot of things. And I mean, Ryan Weeks, I don't, I'm you're on this, but I'll say it, I, I don't know that their, their job is to be the most innovative, uh, companies for this, right? They, they have other things that are that priorities. So, um, yeah.
And so I don't, I don't have an answer where it's gonna end Ryan, but, um, I, I'm confirming that everyone's gonna have to make these tough choices. I certainly feel that. Yeah, absolutely. And in case I have to jump off while you're asking all the people's questions, um, this was really good today. Um, you're awesome and, um, I'll do something I don't normally do. I, I had ask you a question, are you currently in a peer group, an industry? We're group. We're not, we're not actually. Okay.
So we'll probably have to follow up and, and I think you might be a good fit for, uh, people that are doing the same kind of things that you're, uh, you're talking about. But, um, and we definitely gotta have you back on, on, on, on a, on a future one. 'cause this was really good for people to hear where the rubber meets the road. Thank You so much, Ryan. When I met you two years ago, what was the fir one of the first things I said to you on the phone call with you and your partner?
I think it was, are you in a peer group? Well, no. Do you know Gary Pika? One of those two? Yeah. Well, um, Ryan Weeks maybe if I could. I think it's a, an interesting segue. So, um, one of, one of the biggest struggles that I've had, especially so, so we've been using the, the SolarWinds and central RMM platform and obviously with SolarWinds in the news so much our customers, you know, they don't want to hear that. It's not Orion that we use.
They just wanna hear, when are you gonna get this outta my environment? 'cause it sounds like a big liability. So I, I would love to hear Because all the other ones are completely secure, so that's Exactly, yeah, No, I know. But you know, once, once something gets in enough headlines, there's kind of, it's got the life of its own.
But, um, I'm so curious about the evolution of RMM because it's a, it's an indispensable tool for MSPs, but, um, and, and it's really, it was, it was purchase, uh, report last year that really opened my eyes when they coined that, that term buffalo jump. But I've got one location where privilege access to all of my clients can be accessed.
Um, if you had to look into your crystal ball and think about how does RMM evolve in light of things like increased concern about supply chain attacks, um, increased focus on things like zero trust concepts, um, what do you think comes next? Yeah, it's a great question. It's, it's honestly one that's been plaguing me and keeping me up at night for, for years, right?
Um, from the moment RMM breaches started, um, you know, it's just been an onslaught of like this, this, this kind of nagging question of what is an RMM and what is it not and what should it be and what should it not be? Um, and I think, you know, my, my my general sense is that there's still a lot of just fundamental things that a lot of RMMs don't do well from a security perspective. Right. Um, and that need improvement.
Um, you know, we made a lot of improvements to kind of authentication, authentication, security, both pre and post authentication security. Um, uh, one of the, you know, one of the first vendors to require MFA. Um, but I think you look at other RMMs, especially up market RMMs like, um, you know, like Tanium or something like that, where it's, it's an RMM, but it's really become more of a security tool.
Like more my, you know, when I was looking at Tanium back in my enterprise days and financial services, my rep told me more, Tanium deployments get brought in because of the security nature of the tool than the it nature of the tool, right? And so I think there's still this very broad gap on where RMMs are in their maturity of becoming more security centric in how they think and approach problems. And, and really to me, it's just a giant missed opportunity.
And in a way, I'm cracking egg on my own face, right? Um, there is so much more than RMMs could be doing to, to help MS P secure their environment from a process perspective, from an inspection perspective, um, but also an integration perspective to do things like, um, you know, conditional access Yeah. Or, uh, things like that. So like, I, I think we're gonna get there. I think the evolution is gonna be slower than we would like.
Um, but, you know, because I think there's, there's two problems. One, the top 1% of MSPs are asking for this stuff, right? And there's, when you're a product person and you're thinking about, okay, I can do something that's gonna, you know, sell more RMM seats, or I can build this innovative thing that solves this problem that every MSP has, there's still this question of, if I build it, will they come Mm-Hmm. Are they ready for it? And I think we're, we're just getting into that.
Like we're just dipping our toe in that water of like, we're starting to even be able to have that conversation about what RMMs need to be in the future, and, and getting that sense that there's an opportunity there. And like, I, I can tell you, I'm, I've, since I've been thinking about this for years, I have so many well-cooked ideas of what we can do from an RMM perspective that I'm really just waiting for the market to say, yes, please. Let's go, let's do it. Interesting.
Do You see, see it as an iterative process on top of our existing model of RMM or a whole new paradigm? Yeah, no, I don't, I don't think, I mean, you might see, you know, maybe it's like the perch type of thing. You get someone comes in and it's just totally disrupts. Um, you know, there's a, there's a few players that have that capability, um, and the RMM space. But I think for the most part, part of the thing that's holding it back is a lot of MSPs need that core RMM functionality.
And so I, I think you're more likely to see an iteration on existing technologies than you are a disruptor. But again, I've, I've been wrong before and I'm a crappy crystal ball reader, so, um, Unless you'd like to, and Ryan, unless you'd like to do a startup, and we'll try to solve it. Yeah, I know, right? I gotta take all these and do it, Be on board. Um, and I don't have, I can stay a little longer. Okay. Good. Ryan, weeks, that was really, really great perspective, man. Awesome. Yeah.
Agree, agree. Yeah. Thank you for that. Well, my last question prepared here at least is, is for Wes. So, um, oh no, Wes, I, I spent a lot of time thinking about this, this idea of like co-managed services where I can bring in a vendor to, uh, augment from a services perspective, some things that my team may not have expertise on. Um, and I, and I know this is, this is a part of your wheelhouse too, but as you know, uh, I see it all the time.
Some MSPs are better prepared than others to actually manage these solutions, right? So you've got on one end of the spectrum, you've got those who, their knowledge ends when they install the product, and then they're just waiting to be pinged on alerts all the way down to, uh, people who are gonna hire dedicated staff for particular, uh, vendor product and develop some super deep competencies on it from where you sit on the vendor side.
Um, what do you think about, or maybe if you could just riff on the role of MS. P centric vendors to develop and then articulate or train their, their customers on the shared responsibility. Like, how can you, or should you be training MSPs on how to maximize the value of your solution, if that makes sense? Yeah, I have way more to say than time allows, so I'll try to get it into the important pieces.
But a good sign of a vendor that truly understands the MSP space is somebody that has an articulated vision for how the co-management should work. And, uh, ways that allow that to be scaled through and through. Like, we learned this in the early days of perch. Like we would tell people, Hey, think of PERCH as like a, a managed product more than anything else because while it is a product, you get people that come with it.
And we learned really early on, uh, our best partners by and large are those that absolutely know their role to play in IT and the value they have to do and, and play on top. Like, you can't, and I'm just using PERCH as an example, but many other vendors this way, you can't just deploy it and leave it and walk away.
Like, especially when you get beyond prevention and you go into things like identity, you go into things like detection response, those are like classes of tools, uh, that it, it's, it does require some expertise and some understanding. And that co-management really does mean that you've got to be involved in all of this. And you know, that, that's why at Perch, like we, we hired and moved over Mike Brands who does specifically like customer, uh, education kind of stuff.
Like that's all he does all day long at Perch. And we hired a second person, Eric Hanson, to do the same thing because we just kept running into these. If we can definitely teach the EMSP to Phish, they will be so much more effective by learning how to do these things on their own. And that comes into onboarding, that comes into user, uh, training that even comes into like their ability to message and turn value out of, uh, of perch itself.
Like David Powell Perch all often says, you know, M-S-M-S-P vendors are just raw materials, but the, the MSP partner themselves are what turns that into finished goods. And so what perch does a co-managed sim, it's still a raw material. And if a partner walks in thinking they can take that raw material and just hand it over to, you know, their, their client, they immediately see value out of it. Very rarely does that happen.
It takes you as the partner understanding as the co-management piece of this, I turn this into a finished good. And I don't care who that is. I don't care if that's anyone else that plays in the SIM space or any other tool. That's a totally different piece. Those things all play in or have a piece to play in that. And so, you know, if I'm at MMSP, one thing that's going through my mind is I'm thinking the vendors that we partnered with, how are they helping me with all of that?
Are they giving me the tools and the knowledge so I can go fish and I can teach the other people in my MSP to go fish if they're doing a good job of that, that shows they're truly a partner, if they're lacking some of those things, um, that, that's an issue, right? Because I ultimately have to turn what I'm doing into finished goods to communicate value to my clients. So I can say more on it, but I, I do think that's, that's a great question, Ryan. Right on. Thank you.
And David Powell, man, you want some analogies@davidpowell.com. Ryan will Means a walking allergy Ted lasso of MSP analogies. He's been doing it a long, long time. Uh, that was a good point. He Even has the southern accent for the, the Ted lasso. You got that right, Gary. Alright, well, um, so in closing, first off, um, Ryan, thank you so much for joining us. That was awesome. I, and, and thanks everybody for staying on for a while with us. We'll wrap it up here.
Um, we'll Have a, I think we're off to a great start for this year. I think we start, we started off with the bang today. Yeah, yeah, yeah. Absolutely. Gary. Um, any closing comments for you? And I'm glad you got to stay with us through, throughout it. Uh, yeah, yeah. You know what? I wish we had another half hour. I made so many notes. I'm gonna keep them and maybe try to, uh, come back with some, some stuff.
So many, so many points about business and vendors and just some of the realities we're dealing with came up today, um, that I didn't have time to, you know, we, we ran to the end here, but just wanna say thank you to, uh, to Ryan and great job today from the whole team. Yeah. Thank you all so much. Really appreciate the opportunity. Yeah. Wasn't anything, uh, from you? Nope, nope, nope. Thanks guys. This has been a lot of fun. And Ryan Weeks be well, stay safe.
All right everybody, we'll see you next week. Take care everyone. Thanks again. Thanks Ryan. All.


