Skip to main content
Right of Boom
January 30, 2025

May 18th, 2020

Guests

Andrew Morgan

Video Transcript

All right. We're live With special effects and all. Yeah, pretty fancy. Andrew. Special effects. I like that a lot. Looks like we lost him there just for a second. But, uh, part of us being live, right, is to kick off the cyber call, and that was very cyber. Wow. Good job, Andrew. Thank you. Thank you. I didn't know you didn't tell us you added some special effects for the call. This is getting a lot of production value now.

You know, I'm like, each week I'm like, I'm gonna get this better and better and better, and I've got everything set up over here on this computer. Well, turns out you need that computer. Uh, you don't want to have that one on too. But anyway, welcome back. Code three, um, being joined today, as always by Gary Pika, Kyle Hans Lovin, and ideally, if we can get the technology correct here. Uh, Senator West Spencer, hopefully coming up on stage shortly. Um, we've got a fantastic lineup today.

Um, I'm gonna keep things brief on headlines. Gary, uh, there he is. Keep things brief on headline. Um, but then, uh, Gary, a lot of people wanna talk about with, uh, work at home environments and sprawling networks. Does packaging and pricing change? So that's what you're gonna be talking about, Kyle. You're gonna be talking about zero trust, which I think is gonna be fantastic. Um, we are gonna then move on to, uh, have, um, Jennifer Vander weer come on up and join us and talk about CMMC.

Uh, her firm specializes in it, and she knows an extraordinary amount. Uh, so if you, uh, play or wanna play in the, in that space, uh, you're in for a real treat. We'll move on to Chris Lair, who will be talking about distributed environments, um, and why they're important. And last but not least, we'll have the CISO of Marco on, uh, Mike Burgard to discuss, um, the, some critical vulnerabilities that he's been dealing with for work at home environments.

So, with that, let its crack right on into it. Um, Gary, leading up into you, and Wes, I'd love for you to comment on this. I was looking at, uh, hacker News, and I'll share this 'cause there's this PowerPoint template in it, and it talks about cybersecurity, uh, go figure and coronavirus.

And interestingly, it talks about how CISOs, you know, in the enterprise are dealing with two, you know, very, um, challenging things right now, obviously, like SMBs and MSPs, distributed environments, work at home environments. Um, and I'll talk about the three points that they talk about, but then increase in investment in the boardroom, right? And, um, Wes, I'm gonna ask you in a moment to talk about this, because this is something that you dealt with in your past life as a practitioner.

And, you know, they, they, here's what's going on in their world. And, and it, it struck me that, Gary, because this is really what we're gonna talk about today in your segment, that what the SMBs didn't have to deal with, you know, just a few years ago. It's collapsing, it's regulations, compliance, et cetera. And what they're dealing with, just like the enterprise are, you know, mass scale work at home environments, right? And credential theft.

Um, you know, the fact that now all of a sudden, how do you monitor, you know, it's one thing for a soc security operations center to monitor, you know, the environments that under the corporate environment. But now all of a sudden you have all these remote connections, right? And then that's the second thing. And then, uh, which makes it extraordinarily hard. And then, last but not least, um, employees using personal devices to access network information, you know, corporate assets.

So before we go to you, Gary, Wes, you know, here's the challenge. They're, they're dealing with all these things. They need more investment dollars. Um, same conversation. The MSP and MSPs out there have to have, love your comments on it, and we'll hand it on off to Gary. Yeah. Uh, I'll say quickly, the best way to get a security budget approved is to have a breach. I hate saying that, uh, but let's be honest, that is the truth.

One of my mentors, uh, uh, CSO at, uh, Aetna, uh, Jim Roth always says, Is that your recommendation? Unfortunately, it's true, right? And I heard him say, Hey, trust, he said this on stage in front of, I don't know, 2000 people. He said, the best way to get your board's attention is have a breach. He goes, trust me, I've done it three times in a row. Uh, but the second best way to do it is certainly to use current events. I mean, there's no question about it.

So, you know, this should be something that you talk about. The last thing you want a board or a decision maker in, like, in your client base to say, well, why didn't you tell me about this before, after the fact? So use what's going on, whether it's a regulatory change, whether it's some kind of security landscape thing that's going on, like we have with the pandemic, use what's in front of you to sell so important. Yeah. You know, so I, I had kind of two thoughts that I wanted to bring up.

One is to piggyback off what Wes said. Um, we've been trying to change how SMBs think about security. And it's, and it has come a long way, right? 'cause there has been so many breaches and so many of 'em are public and those kind of things. This is a big current event, but this is coupled at the same time with an actual change in the technology landscape. Like you said, people are sprawled right now. Um, a lot of MSPs have changed.

You know, they had certain rules and, and guidelines set up and they, and they broke 'em now, and they let people use home equipment and things happen quickly. So I think there's two things. In order to leverage it, you have to go back with recommendations. The recommendation could be some project you need to do, right? Or it could be a change in your process, your technology stack. And you have to be able to go there and price that and match it up with value.

And if you don't know how to do that today, that is job one. Like, we have to be able to afford to be able to deal with these security changes. So just, I, I, again, we could, I could spend two hours on this, but I only have two minutes. So let's, lemme give two overall thoughts.

One is, if you're focused on adding more capabilities, that means process, you know, labor services or tools to your core offering, then you want to use what I always preach as using a seat as your unit of measure and figuring out those, what the average seat cost is for those. Okay? If it's above that, then you're gonna have to come up with some unit of measure.

And Wes, for some people, it's why they work with an MSSP, because the MSSP already has the costing in the unit of measure you own, you have that and then can go to your customers with it. Does that make sense? Oh, yeah. That, that makes total sense. And I think that's exactly the thought process that most people have, right? On the money, Gary. And just remember, we, that anything you're doing, we want to be at 70% gross margin on our managed service offering.

So anything else you're doing, it may not be at 70%, but you just have to know what those gross margins are. And if we're cannibalizing our own gross margins, and sometimes there's a good reason to do that, you want to do it with your eyes wide open, right? And so messaging first understanding, okay, how do I have to change what I need to do to secure those customers? Now, how do I go with both knowing my cost, a price and value so that you can get out and you gotta do it right now?

Customers are listening right now with different ears than they had eight weeks ago. Excellent. Gary, I put a, if you wanna just talk about it real quick, I put a, a link in in there for everybody about your price calculator. Do you wanna just share what that is about real quick? And Yeah, if you go to that link, true methods.com/price, you can download a calculator. This will help you overall price, your managed service offering.

And as you make changes to it, both with labor and tools, you can put those and it'll tell you, help you calculate your per your, um, per cost. And also show you based on your target price per seat, what your gross margins are. Okay, fantastic. We're right on time, Kyle Zero trust. So obviously we, we've got the conversation about what we can do, what we can upsell, and along comes another buzzword, uh, ironically for the enterprise.

If you take a look, zero trust was a word that got kicked out in 2010. It was a research analyst named John Kinder. Uh, and he, he was at Forrester and said, look, we really need to adopt a zero trust network or a zero trust architecture. And the enterprise sales folks went hog wild. They immediately said, you should not trust anything inside or outside of your network. Everything must be verified before coming in.

And maybe that's something you could do if you have a supply chain like Bank of America. But here in SMB, uh, where we're, you know, catching up almost 10 years later, you know, it really, really boils down to can we really truly afford, do we have the resources to not trust anybody or not verify anything until it gets done? And I think we all know the answer is no. What I wanna do is I wanna pull back some layers in case you've never heard of Zero Trust or it's something new to you, right?

You know, you might hear, should I buy a zero trust firewall, or is this endpoint agent gonna allow me to have zero trust? I'm gonna encourage you to not chase those buzzwords. And more along the lines, think of a trust but verify mentality, right? That's, that's the s and b flavor of zero trust, where look, in real world, we should do as much as we can to verify things before we trust them in their networks.

And that type of mentality is something, if you boil it into your options and the way that you're actual pricing your products, whether it's using Gary's calculator or using your gut intuition, or however you decide to offer these things up, this approach is a differentiator. So, um, I'm gonna always use the Castle mentality, right? The old school castle mentality was, I had a firewall that was my Castle Walls, you know, within it, I had a couple nights that guarded the front door.

Maybe that's my antivirus or anti-spam. But the whole zero trust model was you need to trust what's happening inside your castle walls too, in case somebody happens to get in. And so, where I'm gonna go with this is use these simple men, uh, the simple, uh, you know, analogy to say, look, we're now in a trust but verify type of world.

We're in a situation where maybe you want to use your own marketing words that are zero trust, but I would just make sure that I encourage to you that zero trust doesn't truly mean you can't. Right? You know, and someone just, Mike just threw in the comments here. So start with zero trust, then you go to confirm trust.

That's a realistic way you could do your best way to say, you know what, this thing's in the network, these network traffic, these, you know, authentications happening over remote desktop, whatever's happened at work from home. Think about how well true zero trust would've worked if you had to move, uh, to work from home. You would've had all those laptops and you would've said, nah, I can't use 'em. But the reality those customs had, or sorry, those customers had to be productive.

So you had to work in a situation where, you know what, we're not gonna trust these, these laptops, and then later we're gonna try to confirm as best as we can and harden. So anyways, I know that's a little bit of different mantra than most people are familiar with. And if you haven't heard of Zero Trust before, I wanted to open that up.

Wes, I know you're talking a little bit later about something that's gonna be, you know, relevant to Zero Trust specifically in regards to, you know, some of the, uh, I, I, I guess the, the easiest way to talk about it isn't necessarily just yours, Wes, but also solace about risk mitigation. Jennifer's gonna be talking about CMMC and how the government has taken a look and said, look, you're gonna have to add some, some much better checking and implementation and security within your networks.

So hopefully this topic that I mentioned in is something that transcends not just this moment of be aware of Zero Trust, but there's actual ways that you can start using this trust but verify mentality immediately. Yeah, you're right on the money, Kyle. The, what I would say is like, when you think about Zero Trust, it's, it's sort of like a zen, it's like a philosophy, it's a mantra, right?

It's just like the way a software company like Perch or Huntress is like, oh, you know, we're, we're like a agile shop. What does that mean? How does it work for you? It's different for everybody, right? But you're exactly right. And when you think about like a company like Perch, I mean, we've been built zero trust from the beginning with identity as our edge, right? That's just the, the fortune of being a very young 4-year-old company allows for us to do those things.

So when the pandemic hit, we're like, okay, well, I just work from home, I just need an internet connection and I'm good to go, right? Uh, so we have those advantages. You can take the Zero trust model and use it to defend, not just like, Hey, it's the secure way to go, but it's the efficient way to go, right?

Like you take, for example, an old school file server, you have to VPN into, and all your data is on premise that makes sense to somebody as a huge roadblock, as a, as a client and a decision maker inside your, your client base of like, Hey, you know, there's a better way to do this that you get both security advantages from, and business resiliency and efficiency advantages too. So I really like that, Kyle. It's good. Yeah, and think about it.

We've been talking a lot the past couple weeks about a culture of security, right? And so I think this plays into that, which is you have to, you have to know what that means to your customer, right? Kyle, like when you're describing it, what it means, what expectations you're setting, which is really important, those expectations with the customers. And then you have to be able to, you know, have a process that backs it up. And, and you have to have a value proposition.

You gotta connect all those things. That's why I think that word culture is really good. And this plays one part in it. And like Wes is saying, it could mean different things in, in different cultures. So I know we're, we're right at our time, I threw a handful of links for those that have never even heard, want to dive into. I, I gathered my three best links I could find on the internet that encompassed the purpose behind Zero Trust.

However, there's still a big gap between taking Enterprise Zero trust and applying it to the actual MSB flavor. Andrew, I see your question about trusting different applications. So kudos to you. And maybe along those lines, you Can't, Kyle, you have no Experience talking about that kind Of stuff.

So for those that are, you know, just watching and not looking at chat, the question was how do you trust, uh, you know, how can we implement zero trust when you don't trust an application that we depend on, right? Any of the remote management tools, this is a real question. I I don't think that's, you know, uh, fanning the flames whatsoever. I think it's something that we as a community are gonna have to figure out.

And the last link I'm gonna share is, ironically something that got posted to the internet this week, which was on bleeping computer. It was another MSP coming out to the internet saying we're compromised because it got in through our remote, uh, management tool. The actual blog has been taken down, but the cache link is still there. So I'll put that in chat for you to marinate on as we're thinking about Andrew's question. Yeah. And, and Kyle, I didn't mean to make light of it.

I was laughing because how many times do you try to do the right thing, but get the wrath is I guess really why I was laughing. Yeah, You, you and I both know, it's all the, it's every time. So, okay. Um, Wes, do you mind on this one if I me move you over? I'll bring Jennifer on up and then I'll flip it around with you and Kyle. Okay. Bear with me. Alright.

Really good stuff, Jennifer, Since we're bringing Jen on there, I mean, I, I just read these things and it seems like on the daily, it started out with, I work for a small size MSPA few days ago our network got hacked. It was ransomware. What, what a way to start out your, like Thursday or Friday. Well, we are doing fantastic on time. This is keep getting better and better, and that's after I did my max headroom below. Everybody's setup up. Jennifer, welcome.

And I actually didn't mute myself this time and mess up our whole audio thing either, Jennifer. So, welcome. Um, you know, Jennifer, um, always wonderful to have you here. Just brief intro maybe if you could, to the folks out there about you and F1, and we'll get right on into, you know, CMMC and you know, why people should care and monetizing. Sure. Um, again, uh, I'm the president of F1, uh, solutions here in Huntsville, Alabama.

Uh, we are over 20 years, um, uh, servicing the marketplace in North Alabama. Uh, about seven years ago, we saw this weird thing called HIPAA coming out and said, Hey, what's this? Our clients are starting to ask us about this. Maybe we should know a little bit more about data security than what we do. And, uh, over the years, created our own, you know, security division, uh, which i, I run. Um, and over those years, of course, DFARS came out, uh, with government contracting.

And then most recently, what is coming out this year, uh, CMMC. So we, uh, we built a pretty successful, um, MSP business, uh, have over 6,000 endpoint under management. Um, and we have, um, uh, built a, a what I think is a pretty, pretty strong, um, security offering as well, whether it be risk assessments, pen testing, or whether it be some of our compliance and service products that we've bundled into our, um, off offerings as well. So, I will make the disclaimer.

Uh, Andrea, I think you know me by now, I'll always make this disclaimer. I am not A-C-M-M-C expert. Uh, no one is, it doesn't actually exist right this second, but the first auditors, the handpicked auditors, beta auditors are being, uh, certified this month to go through the Pathfinder program to, uh, start the first, um, audit. So, um, just wanna make that clear. Uh, I know enough to be dangerous, um, but I definitely don't wanna present myself as an expert right now.

You know, you know, quite a bit. We'll just say this is like an investment, uh, summit here that what you're hearing don't use as financial advice, but go ahead. Yeah. So, um, just a, a little bit of update on, on CMMC, uh, which is ironic 'cause right now, this moment Katie Arrington, um, is giving a, uh, webinar. So I guess, uh, we'll look in an hour and see what, uh, new, uh, newness came out. But, um, CMMC is a pretty awesome opportunity for a lot of you out there.

Um, I recognize this last year when a lot of my clients were starting to ask about it, and I just thought it was, you know, amazing. So what it is, is, uh, you know, the Secretary of Defense did not, um, like where we were going as far as our data protections for our Department of Defense contractors. Um, they came out and said, well, shouldn't DFARS be, um, enough to, to manage this?

The problem is, it was a self-audit, and whenever you do a self-audit, it's, you know, it, it, it's problematic just to say the least. So, uh, going through that, um, uh, the Secretary of Defense decided to come out, uh, or actually, um, engage on fixing this issue. So Katie Arrington, uh, developed the, uh, cybersecurity Maturity Model Certification, CMMC. Um, and what this is, is basically is gonna be a, um, a new program, a new set of controls.

The controls are already released, they're already online. Um, it'll be a new, uh, set of controls that use NN 800 dash, um, 1 71, but other controls, so I say it's 1 71 plus. So you have some, um, CIS controls, you have some RMM controls, you have a whole bunch of other controls in there.

The reason why this is so cool, unlike hipaa, uh, where you still can self-audit under, unlike hipaa, where doctors really tend not to wanna spend the money to put into cybersecurity, A DOD contractor will have to submit their third party validation one through five maturity rating before they can ever get a contract awarded to them in the future.

So the timeline of this right now is controls have been developed, they've been released, uh, auditors, the, uh, credentialing for auditors has been somewhat decided upon, not, not a hundred percent, but somewhat. Um, the committees have been set, the board members have been set, and those programs are going forward.

The handpicked, um, uh, third party auditors are going through their certification program right now to beta, um, to make sure that it's worthwhile to let the rest of us go through it. Um, and then once the, um, Pathfinder Group is, uh, gone through this is a special group that basically has said, okay, you're the first ones we're going to, um, we're going to assess, um, after that, uh, group is assessed, um, then they're gonna start rolling out training for the auditors.

Um, and then they're going to start also rolling out the requirements within RFPs that don't currently exist today. So right now, there is not an RFP that has CMC language, your prime contractor, your client's prime contractor may be asking for it, but it's not in their contract. They're just getting you ready for it. Um, today, no one is CMMC certified. Um, uh, so yay. Um, but it, it will be, it's coming. So, a couple more details.

I'm trying to do this quickly, uh, just to stay in the timeline. You're doing, you're doing great, Jennifer. Okay. You're doing great. Um, so they have, uh, Katie Arrington has said that they're going to release this in the fall, um, September, October-ish dates, I'm not quite sure yet. Um, but, uh, they're gonna start releasing it on 10 main prime contracts, um, that will affect one, uh, 1000 subcontractors. Um, and they're not saying who they are, so we don't know which, which ones they are.

So what will have to happen is that your clients, if they're a DOD contractor, will eventually, whether it's this year or down the road, they will eventually have to be able to, uh, attest third party to all the controls within CMMC category one through five that they're aiming for, for their contract. CUI data will be given out at level three, so most are targeting for level three for right now, uh, which has some really fun stuff. Level four has some fun stuff.

In fact, we just became a hunter's client because of some of the fun stuff that's, uh, that's required. Um, but, uh, I would say that, um, it's, uh, it's a really great opportunity as an MSP for those MSPs out there that are listening. Um, if you are managing a customer that is a DOD contractor, you will be able to, um, you'll have to be, uh, CMMC certified as well. Um, so it's an opportunity for you to get your own CMMC certification.

So you can use that from a marketing standpoint to say, Hey, we are actually certified to level three as well. And then while you're going through the controls, you'll be able to pick through the products and services that you'll be able to roll back out to your clients, um, to satisfy those, uh, topics. Excellent. So, Gary, Jen, I know both of you have backgrounds in sales.

Uh, a lot of people would think, when you hear Jennifer talk, that she obviously crushes it in cybersecurity, definitely has a lot of operations experience, but when you have two solid folks in sales, uh, here representing CMMC, or you know, discussing CMMC, there's something the audience should take note, which is this means opportunity. Yeah, yeah, AB absolutely. And listen, here's the part again, we get back to, we tie it back to operationalizing these things and making that opportunity.

Part of it is creating, you can create some fear, uncertainty, and doubt, and you can leverage this change to open new accounts. Um, but also there's some additional things, right, that, um, Jen's describing that you need to do. So you need to maybe make sure you understand that and you're pricing things appropriately as well. Well, when we went through our preliminary, um, review of it, we started literally making a checklist of, oh, we need to have, you know, active threat hunting.

We need to make sure our DNS filtering is in place. We need to make sure this is in place. We need, make sure that's in place our socket stem. What are we doing for that? We had to go through and checklist these items. Now, I don't wanna say cybersecurity is checklist, we all know that's not the case. But when we're talking from a, a marketing and from a how to monetize the standpoint, it's does be that's the first place to start. Yeah.

And so, going through the controls, letting the controls guide you on the products and services that you implement for your own organization as well as, um, your customer's organization, Gary, I is right on. I, I, I couldn't agree more with you. Yeah, absolutely. And this is one area with DOD what we've seen, the price really isn't an issue because it's inherent in their business model, right?

So it's not that way for a lot of other businesses, but when you work within, you know, any regulated industry, and this one goes, you know, these contracts are huge. They can't afford to lose one. And so they're not trying to cut corners and save a couple dollars. They want the people that are gonna do it, right? Because it not only affects their costs, but it affects their revenue. So when we have something that we can tie to top line revenue, it's Katie Bar the door. Fantastic.

Jennifer, thank you so much for coming. Great job on As and you're welcome. Anytime. Uh, that would be great. I, it'd be great to just do a, a webinar on CMMC with you, Ryan Bonner and Kyle and, and, and, and Gary. It'd be a lot of fun. Good. Um, I'm gonna move you over to the audience and pull up Chris Laer. Andrew, while you're doing the, the, the rigamarole, I'm gonna jump off the video, allow Wes to come on here as well. Okay. Fantastic. All right. Can you hear me? We can.

What you got for us today, Chris, How are you, ma'am? I'm doing good, Gary. How are you doing? Good. You sound solemn, but, or is that just kind of the kind of get ready or are you fighting a cold? Oh, man, it's all good, man. I went to the dentist today, so maybe that's why I'm so, uh, somber. Had to do all the wait in the parking lot, skid sterilized, all this kind of crazy stuff before you go in there. All right. It's good that they sterilized you, my friend. Welcome as always, Chris.

Not enough. Yeah, thanks. So we were gonna talk about distributed environments. And again, for those of you that may not know Chris, um, he runs a fantastic incident response firm, uh, called Solace. They were, um, acquired by CFC insurance. Um, he's worked, I would say arguably more of the MSP breaches out there than anybody. Um, and, uh, with that, you have, I guess, some, some great experience and unfortunately some great experience, Chris. So why don't you take it away for us.

Yeah, no, thanks Andrew. I appreciate it. And, um, you know, happy Monday to everybody. So, a couple things I just want to go over real quick. Uh, just we, we have seen some more MSP attacks in the last couple weeks. Uh, nothing new there and how they're getting in. Um, you know, either through some remote connection of some sort that we've talked about a number of times, uh, they, uh, we're seeing different groups do it, so it's not just particular one group.

So, uh, just know that we do, we have seen a case recently where it was simply data, uh, looked like they got in kind of a similar way that a ransomware group did, but they didn't encrypt anything. They purely stole data and have been basically extorting the victim, you know, as a result of saying, Hey, I'm gonna release the data unless you pay me type deal.

So that's become kind of a, a little bit of a interesting issue and that it's gonna kind of segue into what I'm gonna talk about in a second is kind of knowing where your data is. Because a lot of this particular case, and just like a lot of our ransomware cases now where these groups are stealing data, and we do have a doppel payment case, which is the same way is that, you know, the question comes about is, Hey, do you know where the data is that's of concern?

And can you tell us where that is so we can focus on that and try to determine if that's the data they stole or something else, right? And so, you know, we've had recently one case where they really know their data. I said they, we know exactly where we keep our sensitive data. It's in, on this server and these folders, and that's where we got our concern with. And then pretty much everything else, then they had a good idea. But that's the exception to the rule.

Most of the time people say, wow, we don't know what's, where it's been out there forever, and that type of thing. And so there's just a lot of work that has to be done. And depending on your particular legal case, uh, it could involve some e-discovery work, which can take some time and it just, it's very, very expensive. And you say, well, who cares? Some people say, well, who cares how expensive it is? I have an insurance policy.

Well, it does matter because you have X amount of it a limit, and, uh, if you reach that limit, you're gonna be in trouble. So, uh, you know, we've talked about it before, we'll talk about it again, you know, know where your client's information is and they need to know where it is. Especially. So that comes into this thing where we've had a number of cases, I'd say over the last few months, where people have been able to operate, even though they've had a successful ransomware attack.

And one of the prevailing pieces of that is, is their key systems are not on their network. So I don't think this is necessarily a security design, but they have some cloud-based applications. And so, and they, and, and their cloud-based applications, they might have five or six of them with five or six different providers.

So when they've been hit with a ransomware attack, sure they have Excel spreadsheets and Word documents that are really important, but in the end, they have their key applications that their cus you know, their employees can use to service their customers are are up. And so I, I've been thinking about this a lot and say, well, well, how could you turn this into a architectural discussion with your clients, right?

So you're trying to figure out ways of minimizing risk, and you're trying to think of some creative ways to do so. And maybe with the work from home, people are starting to see the benefits of the cloud. And you know, a lot of the solutions that we talk about here, especially the one where guys wear purple shirts, can support collecting information from those, uh, cloud provided systems.

And so I think it's an excellent opportunity to talk to them about this and talk about it from a incident response perspective and even the disaster recovery perspective. And so it's not one, it's not the same conversation you have saying, I wanna move all your stuff into Azure. I wanna move all your stuff in AWS or I wanna move all your stuff into my own cloud that I wanna provide you.

I think it's really thinking about this strategically and saying to yourself, uh, if I'm in my client's shoes, are there a number of things that I can move off to different providers and kind of distribute that risk? Which most of the time, um, and I would say in the vast majority of the time in the SMB space, the attackers are not going to try to go and go after all these disparate cloud-based applications.

Now, I know that doesn't translate exactly into those same MRR line items that you're accustomed to. I know that you're gonna look at it from maybe being a little bit less efficient from a management perspective, or that even, I remember when I first came on to, uh, solace, I was like, dumbfounded by the lack of, you know, motivation to move clients to Office 365. And I'm like, it doesn't make any sense. They go, well, we make good money on an MRR managing exchange servers.

Why would we want to give that up? And I'm like, 'cause you don't wanna be in that business anymore. So I think we're here at a good point. And you have the work from home.

You have a number of other things that are staring at you in the face to have these conversations, and you can pull this kind of security conversation in and say, Hey, this is also a good model to go by to, you know, kind of distribute your risk so then you're just not caught dead in the water with all of your, uh, all your eggs in one basket, per se, sitting on a file server in the back of the CEO's office. Gary, you you got, I, I caught, I I wanna hear your, what you got here.

Well, I'm just laughing first because look, I have a saying that says every big wave hit shore. So back in my early MSP days, uh, when SPA licensing came out, we had every customer, uh, on, uh, you know, our exchange spa, our margins were unlimited. It was all margin. But there comes time when the margin you is relative to what's right for the customer and the risk. And so MSPs have to know what their long-term role is, and we can't fall in love or build our model on, on those things.

And not enough people are talking about what Chris is saying today, which is besides all the tools and process, just the design of the architecture in reducing risk and having things distributed. And sometimes that's counter to our, our efficiencies or margin and we to put that into our pricing model. But I, I don't, I think that everyone needs to be thinking that way today. Yeah. Yeah. That's, Yeah, I, I, I think the way that I like to sell security is by telling stories.

And I think this is a really good lesson we learned from Chris. Everyone on this call is like, man, I just heard from a leading expert in ransomware and incident response. Talk to me about this story of why I need to change my infrastructure strategy, right? So like, if, again, if I'm a business owner, I don't have time to be thinking about how you're gonna do it, when and why. All I need to know is, whoa, there's a lot of risk over here.

And you've seen examples of this where me changing to this gives me better efficiency, as we mentioned before, but also better security. It makes so much more sense. And so I love the way that Chris is using that to share stories. Uh, that's such a good way to get non-technical decision makers to truly buy in and understand. And so, uh, really good stuff, Chris and I, I very much agree that's the way you go. And by the way, we're all tying this back, aren't we?

I mean, this is all coming back to that same theme, uh, that we talked about at the very beginning of Zero Trust falling into all of this as well. So this, all this all goes together. And I'll just tie it up by saying, if right now you aren't working with every one of your clients to build a roadmap, and as part of their security, you aren't thinking about what Chris is saying today, which is what do we want their environment to look like in, you know, 12 months, in 24 months?

'cause some of it's not maybe immediate stuff, right? But if that's not part of your roadmap, then you're not doing everything that you can to secure your customers. So, um, yeah, this is one of the best points we've had, Chris. That's awesome. Yeah. Great. Thank you so much, Chris. And I'll, and I'll Chris as I, you know, lead, you know, bring you back to the audience. Thanks.

And I hope you come back again soon And bring something, this is the best thing so far, but we're expecting something better next week. So no pressure Anytime. Um, he's awesome. You know, it's Gary, it's, and, and Wes, it's almost like, you know, people are, it's the same mentality I was talking about this weekend quite a bit. Um, and you know, we're gonna go back to the way things work. We're not, it's, and it's, I think it's the same thing with where are we going, right?

You know, it's about what, where are we today, but where are we going? And, and, and needing to know that. So, And it's thought and it's cycles. It's not just answering tickets or doing a project, right? It is, again, to come back to that work culture. It is you now, you're really starting to see the value of this weekly call. It's painting a picture week by week, right. About how you have to change your mindset. Exactly. Awesome.

Speaking of, uh, mindset, I, I got mind changed by Mike Beard, uh, this past Friday when, uh, you know, he told me about his former swat, uh, capability and, and duty former, you know, you, you wouldn't know it by, uh, talking to him, but Mike is, uh, got quite the, uh, rugged pass. Mike, welcome. Mike's the CISO of Marco, and, um, just a wealth of information.

Mike, you know, you and I were chatting earlier this week about, again, no shock, but the distributed environments of work from home and how all of a sudden, you know, you guys have really been focused in on a lot of critical vulnerabilities in these home environments. Can you take it all? Take take us home from here and, and let us know what you've been working on. Yeah, no, thanks. Um, yeah, happy to be on.

So I think it fits right into what we're talking about with Zero Trust again today, right? The, we look at all the amount of resources that just moved out of corporate networks into home environments. Um, you know, as brought up earlier today, we've got customers now that are using, in some cases their own equipment to connect back into the network. We've got corporate devices that were literally picked up and moved out to a home environment. It really does range across the entire environment.

So, um, one of the things that was said last week, and I, I apologize, I forget who commented on it, but, uh, they, they got me thinking about, hey, the amount of data that's being driven out of the home environment now we've gotta account for that too. And, and I'll tell you at Marco, we're seeing this demand from our customers where they expect that their home environment now is made just as secure as their corporate environment.

Whether it's, um, you know, dropping a Meraki a little, a little Z one Z three in, in the environment, or if it's continuing to do VPNs, whatever else. But at the end of the day, they've all got equipment in their homes, right? They've got NETGEAR routers typically, or Linky, whatever that case may be.

And the conversation that, uh, that I had sprawl out of this with a few folks at, uh, at, uh, the Purple shirt guys, I guess as Chris put it at Perch and other places, um, you know, we've got a lot of vulnerabilities on those things re regardless of what it is, and I'm a big believer, I follow us certs, weekly bulletins. Last week while we were sitting on this call, I was looking through it, most of the highend critical vulnerabilities were from Netgear.

Right now, this week it's a different list, but, uh, you look at, uh, look at the impact that that has, it's huge. And the fact that you're opening the front door in a lot of cases to these home devices. So how we monitor those, how we trust those really does become paramount to how we go forward. And Andrew, you just said it, we're not going back to how it was.

So we do have to account for this, and I, I think it's gonna cause a little bit of that paradigm shift, and we are gonna have to become experts. And having that zero trust model, it changes, you know, again, keeping it on vulnerabilities, it changes that conversation. We hit that last week. I talked to a lot of MSPs and, and their, their answer for vulnerability scans is, Hey, we're gonna run Nessus or something like that. We're gonna scan a subnet, move on. Well, guess what?

That just went out the door too. I can't scan a subnet anymore and actually pick up all those devices at home. I need something that does have more of an agent based solution, and we are seeing things adopt to that. But, uh, I wanted to pivot a little bit and, and look at, you know, my home home network. I'll just give my home network out. I do run Meraki, so I get a nice weekly little report. I've got 48 devices on my home network.

I guarantee you, I'm not unusual in that aspect anymore with home automation and some of the things that come with it. Um, you know, I wanted to pivot it towards Wes. Gary, what are some of your thoughts on, you know, just from a vulnerability and a data perspective, all of our tools are gonna start seeing these things as my TV starts scanning my, my laptop from a subnet scan. You know, what does Perch looking at from this? How have you seen that move? How are we combating it?

Yeah, I'll jump in first. So, you know, internet of things, we've been talking about this for a while. I think we've known this is gonna be a systemic threat. I mean, eventually you're gonna get the call because grandma's, uh, Keurig maker was involved in a, like a DDoS attack. You're have to answer that question on why it won't, uh, brew her coffee because it's too slow. Um, but, you know, kidding aside, certainly iot is a threat.

Um, you know, you look at all the botnets that are out there, very often we will see, um, some botnets. By the way, if you wanna look at one that we saw, uh, this was a year ago now, check out Ksn, I'll put a link in the chat in a minute. Um, but it's an IOT based botnet that we discovered and saw some of our devices communicating out to. So it is important, we do need to be very clear about patching and have regimens and, and capability around all that, especially work from home.

Uh, but again, this paints back, doesn't it, Mike? Uh, the importance of that zero trust. I mean, what if you operate with, I'm gonna assume that Netgear router is compromised. I'm gonna assume that Samsung TV is listening in on me, right? So how am I gonna operate from core work home environment, assuming I'll cycle at a coffee shop? Same kind of idea, right?

That zero trust model and that philosophy works through those environments to say, I'm gonna assume those are untrusted entities, untrusted, endpoint, and how am I gonna work through all of that? And so we don't have time to dive into the specifics of it, but that's the philosophy. The, the only thing I'll add is, uh, this is not something we had, we were, look, this existed eight weeks ago, but it's not something we had to think a lot about.

And so now I think it's core to every SMB and every MSP has to start thinking about this. And it's probably not a way you can, you know, get to zero trust, but you're gonna have to make some of the decisions that Mike said, which is people are gonna have to start making different investments in terms of tools and what they're using at these home environments, or they're gonna accept a lot of additional risks.

And, you know, you're gonna end up getting hacked by your, you know, nest, you know, unit or something. It's, it's crazy, As you've said many times, Gary, you can't put put the genie back in the bottle. And I think this is one of those cases where, you know, the way in which we package price, et cetera, is, is changed. It's, and it's not going backward, you know? So. Awesome. Really good. Mike, did you wanna say something? Close it out.

Yeah, no, I just, I, I guess I, I would add my 2 cents from Marco as the CSO perspective would be, you know, make sure you're double checking your contracts. I think that's first and foremost, now's the time to do that. We charge by the hour. If somebody calls in and needs help on their Netgear, I mean, that's, that's what we're gonna do. It's not included in our all, all la carte buffet. And, um, that's how we go from that perspective.

And then the second thing, they're Gonna hear what he just said, if you're gonna do all these things that you weren't doing before, and you're just, and I know a lot of people are, Mike, they're just, you know, they're having charged for a lot of this and they're getting buried thinking that it's a hump. But if it's this is gonna continue, your gross margins just got completely changed without you realizing it. Right? Exactly.

And the second thing I would add, again, just to think about from a vulnerability management perspective, uh, that landscape has grossly changed in the last eight weeks. Uh, you know, we look at a lot of our subnets went from being maybe a slash 24 to probably 50 slash 20 fours. If it's a 50 person environment, the amount of network devices and the tack surface has grown respectively. So that's all I had, but no, thanks for allowing me to join and Well, that was, that was great Mike.

It was always great and great to have you. And I hope you'll come back and, you know, you did mention there's 40 some odd devices you didn't mention what applications or what sites you're hitting, so maybe we can pull, pull you back next time. Alright, thanks Mike. I'm gonna bring up Kyle and we'll wrap things up. Take care. All right, Kyle Back. Great. Really great call today, Andrew. Thanks man. Well, hey, you guys make it great.

I'm just here, you know, opening up a double device over here and making myself sound silly. So yeah. And hey, while we're waiting for everyone that's in the chat, uh, if you've got a topic you want us to dive in and cover next week, fire it over. We want to hear from you. Yeah, Yeah, Wes, and maybe I could start off with that.

'cause one, we have one question for Gary as we round out from Jeff and, um, we did have a recommendation, so I'm gonna bring that up and maybe one of you guys guys would want to take that. Gary, the, the question coming came in from Jeff, about 70% gross margins on Mr. RR agreements. He, he's got gross question mark, what about profit margins? Yeah, so what you wanna do with an MSP, again, all businesses work right on gross margin and then you know what comes out under that gross profit line.

So really what you're trying to do is create at least 70% margin, and that includes your, your, your cost of good sold. That would be your, all of your labor and all of your tools. So that's kind of the guideline. Again, trying to take everything else that you have, you know, sales administration, all, all those other things and put them into your margins.

We're lucky to be in a business that if you drive gross margins, that's so much of our cost that your net profit, you'll get into that 20 to 30 plus percent range with scale. So we teach people to focus on that gross margin by product category, and we're lucky enough to be in the business that everything else takes care of itself. Perfect. Thank thanks for that, Gary. And, and, and yeah man. So, uh, Jen, one of the questions on a future webinar was about, you know, came in from Ben.

Um, Ben, thanks for this. Uh, he asks about security around mobile devices. It seems to me, uh, which kind of flows around from what Michael Gar was just talking about, that, uh, you know, a large, uh, it's a large vulnerability without any real standards. Um, isn't this one of the unlock windows that, uh, bad actors can exploit in, in other words is what he's saying. So what are your thoughts, Wes, Kyle, on that? Yeah, in turn to Kyle on this, I mean, there's so much attack service, right?

I was actually going through NCAs, which was that link that Mike, uh, provided there, which has all the kinds of exploited vulnerabilities and things that are there. There's just a lot of attack service. I mean, so much. So I noticed there was like four on my Netgear, so I went and ripped mine out of my house while we were talking. Uh, it was just easy. So thanks Mike for, uh, schooling me on, uh, on the cyber call.

Uh, with that said, I just remind myself that this is a process that you have to have behind. If you're just willy-nilly looking at one of these or once a Monday thinking about it, it, it has to become part of your operational tempo. It has to be something that you're planning around. So hackers are gonna hack at the end of the day, your job is to stay ahead of it as best as you can use automation.

NCAs list alone had like 10 or 15 security products that were vulnerable on that list from the majors. I think I saw Juniper on there, I saw RSA, some Cisco stuff, you name it, everybody's has vulnerabilities. But making sure you have some sort of system that's repeatable, that's how it's gonna keep, uh, you know, yourself ahead of somebody like me that would be attacking you on that shady side. So that's what I did.

I, I learned what I learned today and I put it into action, and that's now gotta become a process, Start pulling plugs. Gary, you know, um, uh, why don't you, uh, take us home and, and, and again, um, you know, great, great job. I I know a lot of people really wanted to hear about packaging and pricing with this, you know, new world, uh, of, of distributed environments and, uh, um, really appreciate you always being here for us.

Yeah, I, I just, I want the closing thought today is, uh, again, hopefully people are listening every week and you're getting this picture painted about where we are. But the main takeaway I want people to have is, look, you gotta have some time as a business leader right now, if you're an MSP, you have to have some time blocked on your schedule every week to think about these things from a big picture. 'cause they're big, they're, these are big deals, right?

They're about how we go to market, about how we're dealing with distributed environments, how we think about our customer's infrastructure and the way that it is set up over time and, and how we make these recommendations. So you have to make this something that is part of your culture and part of your meeting rhythms every week where you're not gonna be somewhere different in a quarter or two quarters. And you need to be, Yeah. Great. Well, well said. Uh, I have something I wanna wrap up with.

Wes, do you have anything you wanna closing comments? No, just for sake of time. I, I do not Kyle. Nope. No. Hey, I'm gonna send every, you know, the, uh, I hope you guys are liking the, um, the, the research roundup that I send out each week. I'm gonna keep that coming. Um, and um, one of the things that I heard, Gary, and, and, and I dunno if I shared this with you, but it, it again flows into this. Tim Ferriss is a probably the best podcaster out there.

And he had, uh, he, he interviewed a guy named Nick, and I'm gonna butcher his last name, but I'm not gonna say it. He owns Alinea and five of the top restaurants in the U us as well as something called doc, which is a direct com, um, talk, which is a direct competitor to OpenTable. This guy planned and, and really executed well.

He's completely changed around a business that's a $350 a head fine dining, a top dining establishment to now take out food at 35 a head hitting top margins, you know, sales and margins better than he is ever had. My point being is that, to, to your point I'll close with this, is that, you know, he took time, he completely had to change his business model to survive and thrive. And the majority of restaurateurs are not going to, I hope Ms.

P and MSPs realize this is a pretty much a chasm or a fork in the road as they say, Gary. And they're either gonna go one way or the other. Um, would you agree? And Yeah, absolutely. This is gonna, you know, from security and an overall business model standpoint, this is going to be a big widening and um, we're already seeing it, Andrew, we're seeing about a third of the, we talked to probably 200 besides our customers, a couple hundred customers and a couple hundred prospects a week.

And already we're seeing the divide in terms of where people are, who's struggling with this at a time when you can't be struggling. 'cause there's so many changes like the security front that you need to be offensive rather than defensive. So yeah, it's time, it's time to, to work on your business and have some business skills right now. Sure. Everybody. Hey, who joined us today? Thank you so much. Thank you everybody out there. It's so great to, to be with you all.

And again, please share this out with everybody how, you know, our, our our help us increase our attendance and everything. So with that, have an awesome week. Take care everybody. See everyone. Great job. Thanks. Care.

Related Videos