Skip to main content
Right of Boom
September 25, 2024

Modernizing IR Planning

As the cybersecurity landscape continues to evolve, Managed Service Providers (MSPs) must stay ahead by rethinking how they handle incident response (IR). Traditional document-based IR plans—often just Word files collecting dust—are no longer effective in today’s fast-moving threat environment. A recent workshop with cybersecurity experts Chris Laer from Solace and Noam from Exigence highlighted the urgent need for MSPs to adopt a platform-based approach to incident response.

Static IR documents lack interactivity, are difficult to maintain, and offer limited value during tabletop exercises. They can’t support real-time collaboration, automate workflows, or provide the audit-ready reporting needed for compliance. A modern platform-based IR solution changes all that. It enables always-accessible planning, real-time collaboration with clients and partners, automated scenario testing, role-based access, and comprehensive reporting.

The workshop emphasized the importance of starting with a thorough Business Impact Analysis (BIA), helping MSPs and clients identify critical systems and dependencies. Incident response isn’t just about technology—it’s about business continuity, SLAs, and data privacy. Communication also becomes more seamless with platforms, ensuring all stakeholders stay aligned in real time. Most importantly, this shift offers a major monetization opportunity. Offering IR planning, tabletop exercises, and compliance documentation can be packaged into recurring services for clients.

MSPs are encouraged to assess their current response strategy, explore available IR platforms, and begin integrating these tools into their service offerings. With training, marketing, and smart packaging, IR as a service can drive both better security outcomes and business growth. In a world of increasing cyber threats, a modern IR platform isn’t a luxury—it’s a competitive advantage.

Guests

Andrew Morgan
Chris Loehr

Video Transcript

All right, we are live. Uh, welcome everybody. I'm just gonna give it a few minutes here as we let everybody start to come in and, uh, give it about, you know, two, three minutes here. Um, and, uh, no, while we're, while we're waiting for folks to come in, um, why don't we, uh, get the, get the, um, PowerPoint up, make sure we got it in the right position here. And I can kinda, oh, there's net Yeah. With the, with the g No multi explanation.

I, I'm, I'm trying to figure out is it the private message? Should I reply to her privately? How do I reply that Everybody sees Yeah. So, so interestingly, Hey, Joshua. Um, uh, so, so interestingly, the, um, this platform, unlike Crowdcast, only the host can, um, respond and chat. You actually have to go, um, yeah. So you're, no, you're talking to me and Chris. Right? So how did Ned do that? So they're out in YouTube land. That's Right. Oh, okay. Yeah, yeah, Yeah. They're out in YouTube land.

So, no, if you actually were to throw this up on YouTube, you would, you would have to, you would have to respond in a separate instance of you watching YouTube. Okay. That's, I don't wanna break anything, so I'll stay here. You're fine. You're fine. Stick with the, stick with the script. Now stick. Exactly. Fair enough. All right, so let's get, let's, uh, bring Welcome everybody again. Um, Chris, they're saying your, your, your solace background is backwards. Oh.

I mean, oh, I forgot that this does that. So let me flip that real quick. Thank you for letting me know that Is mine. Okay. Yeah, you are. Yeah, I'm okay. Well, you actually, exigence is going, I guess it depends on which way you read. So, um, it's, it's, they're, I think they're both reversed, so, Yeah. Yeah. Yours is probably wrong too. Oh, okay. I see. Mine is also reversed because we created it for Zoom and Teams. Yeah. It's interesting. All right.

So Noam, let's share out, if you would, this the, uh, PowerPoint. We'll jump right on in here. Very nice, Chris. Yeah. I'm just going to video, uh, go in your settings video real quick and just uncheck mirror camera. No. Okay. I wish that was mine. Angie, that's a, uh, that's a, um, Uh, virtual background. Virtual background, yeah. From, uh, from the folks here at Restream. Okay. All right. I think, um, we should be good, even though people are still saying we're backwards.

I think we're good now. A Andrew, you see my share, right? That's okay. All right. No, can you share that out now? Oh, it's not, not showing. No, you have to, um, see, there we go. So You were sharing. Okay. So it just takes a lot of time. Fine. I get it. I'm sharing now. Let's try this again. Okay. All right. Okay. And now, perfect. All right. All right. How about all you there at home? Can you guys see the PowerPoint? Okay. Just make sure that your view is good as well. Perfect. Alright.

Alright. So welcome everybody to, um, the, uh, modernizing, modernizing ir. Can you imagine if I had to say that 10 times, Chris, that would not come out very good. But modernizing IR workshop, uh, my name's Andrew Morgan, uh, founder of Write a Boom, and the cyber call. Really appreciate you all joining in. And this is another great workshop that we're doing for the community. And, um, if we could flip, I'll just go through a quick agenda.

We'll do some intros and we will start jamming right away. So, um, as I said, we'll, we'll start off with some intros and from there, um, Chris is gonna set the stage a little bit. You know, I don't know if any of you were here with us. I think NET was for certain, um, ADI great to see you, um, last week when we did the BIA and, and Chris, you know, we've talked for years about the influence and the importance of bia not only on disaster recovery, but creating an effective IR plan.

And you see this time and time again in both areas when you're doing your work, um, as, um, somebody in incident response fair is, uh, and, you know, you something that you can spot very quickly from the good and bad. Oh, definitely.

I mean, when you get in a situation, especially if it's caused an outage, um, you, you know, very quickly, if anybody even has spent 30 seconds or 30 days on A BIA, and typically you're doing what I call lightning BIA or you're trying to talk them through trying to figure out what needs to come up first, second, and third. So it, it's, it is a, it is a crucial element.

If you're doing an IR plan without BIA provided information, you're, you're, you're not given the IR plan, the respect it's due. Yeah. And then, and it's kind of just like a template, right? For lack of a better word, Chris. It's, it's just a, yeah, I have an IR plan, but it's really not informed. Yeah. It's, um, yeah, it's exactly right.

So the, um, yeah, so the IR is just, the IR plan is just a template in the, in the, and when I tell people, and then you, uh, you probably, if you've ever seen me speak before, I tell people from an IR plan, the perspective, the technical side's, the easy part. It's the business side, the legal side, and all those types of things. And that's where the BIA is so important. Yeah. Uh, in defining that stuff.

Because if you don't have that stuff, you usually will see an IR plan that's just full of ze uh, zest recovery type stuff, or business continuity, technical stuff, and not the stuff that's needed to get the business up and running. And One of the things we talked about actually in the BIA too, Chris last week, was the people part. Like the, when the, what happens when the ultimate decision maker happens to not be in the office when something bad happens, who's, who's the backup to it?

Who has the rights to, you know, say and do certain things, right? Just the redundancy, not just in systems, but redundancy in people. Yeah. It's people in the roles, right? I mean, and, and sometimes and often you ignore the titles when you assign responsibilities in incident response situation.

Um, you know, there's plenty of people in the MSP community that I will tell this to their face is that as an owner of the MSP, you're probably the worst person to be in charge because there's so many emotions going through your head and type of stuff. So you may say, Hey, even though I'm, I should be the person in charge and making all these decisions emotionally, I'm not, I'm not the right person for this.

So you may pull somebody in that you trust that has, uh, a little bit more emotional capacity to deal with the situation. And, and the same thing goes with roles across the board. You may have like a, an incident response coordinator person in there, and that person is, you know, probably your, your, your most organized person that can coordinate with people and communicate with people. Clearly.

You don't want to take your top engineer and make, uh, make that that girl or guy the person having to organize stuff. You want them doing the work that they need to be focused on. So understanding the people, the roles, and ensuring that you have depth behind those roles. I mean, when we run tabletops for people, especially MSPs, one of the things that we usually do is we identify that one person everybody goes to and we pull them out of the scenario.

We say, that person's unavailable, they're in the hospital, or they're on vacation overseas and they can't, they can't be involved. Or they got abducted by aliens. Gotta come up with all sorts of fun stuff there. But the point about it is it's so important the people part of it. And if you, and that's not just internal people, but that's external people too.

So you need to understand if you have people that you need, if you have a board or your clients have a board, you don't need the whole board involved, but you probably need a person from the board. So, for example, when I do I instant response table tabletops with banks, regulators, and the auditors now requiring during those tabletop sessions to have someone at the board present and participating in those sessions. So I think the same thing goes for you.

Um, we have a lot of situations where people have multiple principles in a company. Let's say there's three and two of them are actively involved and one of them is pseudo retired or retired. And, um, that person gets brought in just because they're a decision maker and has absolutely no clue what's going on.

So those are the types of things you need to be thinking about in these IR plans, is the people, the roles that they're gonna play, the people you need to have there, the people that need to practice and rehearse this stuff. 'cause when the real situation happens, you want to be as prepared as you possibly can be. Yeah. Absolutely. Um, so, so Chris, you know, one of the big things we're gonna talk about too is a, a platform versus a document.

And, you know, I remember early on, even gosh, eight plus years ago when you and I first started talking about this, even PSA as documentation. Like there, there's real repercussions, right? For when you use the wrong thing. Uh, when it comes to IR planning and or the real thing, can you kind of just give us a high level of what we're gonna be talking about there? Yeah. So today what we're gonna talk about is the fact that, and a, a plan is, has to stretch beyond just a piece of paper.

Uh, especially with an instant response plan. Uh, you know, what I tell people is disaster recovery. People are more sympathetic and empathetic to disaster, natural disasters, or even a fire or something of that nature than they are with a cyber event. And so, um, the, it needs to be, um, nurtured and handled differently in IR plan. It needs to be an active type plan. And if you just have a Word document that sits on a share sits in SharePoint or somewhere, it's just gonna grow dust.

Whether that's virtual dust or physical dust, it doesn't matter. People aren't gonna give the the attention that it deserves and make sure that it's up to date and reflects the current needs of the business.

And so today what we're gonna focus is on is how can you make, uh, instant response planning, testing, and actually the, the actual incident itself, uh, a more, um, a better experience and using a platform where people can collaborate and work together and easily access it and, uh, continue to nurture it. That's what we're gonna talk about today. Yeah. Really cool.

And in the words of Clark Harshbarger, the, uh, uh, director for, for CrowdStrike's ir, I, I think the one piece of that he talks about having though is, is like a piece of a piece of paper though for your calling, like your calling tree Chris, right? That, that, that's different of like who we're gonna call versus our IR plan. Yeah. And we see that a lot.

You know, it's, uh, interesting when we almost every, especially the small business cases that we work, uh, an MSP is involved and it's, it's interesting to find out that a lot of people don't have that call tree readily available to escalate something quickly. And, uh, it, it should just be right there. And, um, or, or they have something, but it's old. It may be the time that, that the client was onboarded or something of that nature. And so it needs to be really two ways, right?

The, the MSP needs to have the call tree for all their clients, and at the same time, the client needs to make sure that they have the call tree and escalation for the MSP and anybody else that they have.

But, but Clark's exactly right, and I can definitely, uh, attest to what he's saying is that you do, there are some things that you gotta have a quick sheet, whether that's a laminated card that you, that you have or something very readily available that you can reach out and contact people in different ways to make sure you get ahold of somebody every time. Yeah, absolutely.

So then, Chris, we're going to talk about tabletops and, you know, whether, you know, you're doing a tabletop, you know, that we're trying to get better at, like, as an MSP, you know, we think back doors and breaches as an example, right? Mm-hmm. They're experiential, but, and why is it important from an experiential perspective to have something like a platform when you're doing a tabletop? 'cause you, this is a service that you have monetized readily.

Um, and, and this is a service we hope MSPs will begin to monetize readily. This is a very critical piece. And as somebody that works directly with and for an insurance company, um, something I think we're gonna start to see more and more of correct. As a, as a requirement. Yeah, that's correct. So what, what I would tell for people that, that this platform gets you just right off the bat, it gives you a, a point of stickiness for your clients, right?

It's one thing to write something up on a piece of paper and deliver it to 'em, or maybe refresh that. Uh, but the platform, uh, almost forces your clients to use it in a, in a collaborative way. And so you, when, when we show this to you today, you're gonna see where you're, you're gonna have a platform, all the information around the plan, the scenarios, and everything's gonna be right there in your face.

And what this also allows you to do is keep track of your tabletop tests, schedule tabletop tests, and then you can add more tabletop tests. So you can use the ones that are, are actively being created and added in there. You can create your own tabletop, uh, test as well. But it, it, it keeps it there. And I think, um, it keeps it, uh, I'm not gonna use the term entertaining, but I'll use the term engaging for your clients. That your clients know that it's there, they're part of it.

They're seeing things happen real time. It's not just kind of a verbal event that you're doing, which seems like just kind of a, a, a, a, a weak version of, um, of, um, I don't know, rehearsing a play. You're actually going through and, and seeing what the plan says, and you're going through the steps and recording the steps of the platform.

And the good news also about that is, is if you do have a client that ever needs to show proof that they have an IR plan in place and they've done a test, all that's gonna sit in that platform there. So it's something that you can monetize and that you have tangible evidence there of its value to your clients, which is much more, um, which is much different than again, having a Word document or something like that.

Chris, I just wanna point out, 'cause early in the chat here, they're mentioning like, I'm in Tampa. Mm-hmm. Right? We're having category three come through here. No. So I'm gonna just ask No, no, no. This isn't just about always about cyber correct.

Like, I mean, if all of a sudden, um, I'm in business here in somewhere on the west coast of Florida in the panhandle, and I'm down for two days, I've got obligations and SLAs to customers where I may not, you know, I, I probably wanna make sure I know how to handle that situation and have run through that. Is that also a use case? Sure. It's a platform you can build all kinds of plans into. It could be a cyber incident response or a DR or a weather condition, uh, plan and, and test it out.

And when you need it, it's gonna be available for you to, to run it. Yeah. Alright. Well, and, and in, in, you know, following that, Chris, we, we did talk about, you know, monetization is a big piece and then, you know, the trends, we'll talk about what we're seeing today.

Um, you got, like I said, a, a, a pretty good handle, um, in your, what, 10 plus years, I know way more working in, you know, IT and security, but really with the, the trends you're seeing with MSPs and, and the, the incidents they're involved with, um, and, and, um, the either direct or or indirect through clients. So we'll be taking a look at that. Yeah, I'll, I'll just add one thing in there.

You know, this, when I come from the banking world and we were, we, we were tasked with doing instant response planning and testing, uh, alongside disaster recovery testing and even pandemic testing. And it's funny about the pandemic testing is all the tests and everything we do, none of them were prepared for something like covid.

And I would say from an incident response perspective, when you're doing these types of things, 10, 15 years ago, there just wasn't any real world stuff to lean on, right? You didn't, you couldn't reach across the street and go, Hey, I heard you went through an incident and you know, can I take some lessons off you? They just didn't happen that often. Mm-hmm. The ones that did happen were the really big companies, right? Like Heartland or TJX and all those types of things, right?

And so you still, there was just very little information. Today's world, you in a weird, strange way. And I'm not promoting the fact of attacks, but there are plenty of examples out there and people going through this stuff that you can learn from.

And so there's really no excuse to have a, a good plan that covers the different, different facets and to have it in a platform like this because, uh, there's so many examples and so much content out there for you to use and leverage to, to do a plan for yourself as an MSP, but also to help your clients put together plans for themselves. Very cool. And then lastly, after we get through everything, if we have time, we'll tell you a little bit about Exogen Solace and that writeup boom.

Here we have our event coming up and we have a little offer for everybody. So Chris, let me let you kick it off from there. Yeah, sure. Thanks. So, yeah, so today we're going, um, yeah, for those of you don't know me, um, I'm with Solace. We're a cybersecurity and incident response provider based in Austin. Uh, I'm, uh, I'm in, in, in San Antonio. Uh, we do have a team in the UK and a team in Australia. So we definitely have that global reach.

Now, uh, a few years ago, we were acquired by an insurance carrier based out of London, uh, called CFC. And they're one of the largest writers of cyber policies and one of the pioneers of cyber insurance policies, uh, in the marketplace today. So, uh, we see, uh, what I tell people is we see the bloodshed every day, and we try to help people avoid having that bloodshed. So happy to be here and share this.

Um, as many people know, uh, prior to that acquisition, we also had an MSP portion of our business, uh, that got sold off and, uh, is now part of, uh, of Integris. Uh, so I still, uh, work side by side with MSPs all the time. Uh, incredibly involved with MSPs, uh, love the industry, love every, what everybody's doing in the industry and wants to see it thrive and help everybody, uh, make money and avoid mistakes. So that's, that's, that's what I am.

And next we'll go to Nome, who, who's who he can talk about himself. So Very quickly about us, um, no one from Exigence software company out of Israel providing MSPs, MSPs, but also enterprises with incident response planning and tabletops and, and, and actual incident response platform. Um, we've been doing this for a few years, and the last year or so we've been very focused on MSPs and MSPs also to help, um, bring a better plan to you and your clients.

And, and by the way, I'll just say if you mi like, we're gonna be talking a little about this thing modernizing, uh, IR today, but if you are coming to write a boom, you guys each year do a pre pre-day for a select, I think there's, we only got room for about 50 people, and then you take 'em all out to, um, uh, Topgolf, right? No. So if they really wanna get an immersive tabletop led by Chris, and I know personally Chris, you charge thousands of dollars to do these.

So, um, if you guys are coming, stay tuned, will that'll be up on the site soon to, to register for that. So with that, Chris, take it away. Yeah. So let's just jump right in here. So, um, we, we talked a little bit about the evolution of IR and where it's gone. So I know for some of you, this may be a little bit of an eye chart, but this is what we see out there today. I mean, we see obviously still tons of people out there with no plan at all.

We see people with plans that just have technical steps in there, but they haven't done testing. We see people that have technical plans, uh, and have done some testing, and a lot of MSPs that we help are in this situation right here where they've done some testing. But if you even look at their plan for their own incident response, it's very, very tech heavy with little emphasis on, on, on the business. Uh, and then we see some stuff with some business involvement, uh, and some testing.

And then we start to see things where it's much more, uh, involved whether you have business side, uh, and it's tested and those types of things. And what we're really trying to get to is, hey, let's get this into a more of a living platform, uh, a document that's, uh, or not a document, but a plan that's nurtured, uh, as often as it needs to be. And my general rule is, is that should be at least looked at annually or anytime there's a material change in the environment.

Uh, and anything you do more than that is, is good, and I keep doing it. Uh, but what we wanna see is, is a plan that's nurtured, it's tested, it's improved, and there's just, um, there's a good process around it that continues to allow that, that planning and testing process grow and, and, and be better and better every time it's performed.

Um, so we, we've talked about it and it really is, Hey, look, if you're gonna jump into IR planning and you haven't done a BIA do, the BIA, so hopefully many of you, if not all of you watched last the the last week segment on the BIA, and, uh, if not, you can go back and review that. But the important part of it is, it's so important to understand what things need to run in the business at what time.

So in some businesses, something may be the most important three weeks out of the month, and then one week outta the month, maybe another system takes precedence. Uh, so those are the things that you need to be thinking about there. You also, especially in these situations, these dependencies are incredibly important.

So you can say something needs to be up right away, but if it's on it's dependent upon something that needs to be up tomorrow, that can't come up until tomorrow, then you're gonna have to wait. So knowing the BIA and having it in place, so you can use it as a material input into the IR plan is important. And these bullet points right here explain kind of the facets that we wanna see there.

Obviously, business continuity, insurance side cannot ignore the insurance side, and if they don't have insurance, that needs to be noted in the plan, uh, communication, and that that gets, that's getting more and more complex as we go forward, right? You have to worry about communication within your team, with your extended staff.

You know, we have remote employees now, so communication's a little bit more challenging when we're dealing with remote employees, making sure they get stuff done timely. If you have employees, and a lot of MSPs out there are using resources offshore, how you communicate to them when you communicate, those are the important things that you need to know, uh, around what, what legal is there, what, what legal is gonna help you.

And from an insurance perspective, what legal things may find outside. So, for example, you may have situations, most of the situations with ransomware, one of the first questions that comes up now is, what contractual obligations do you have with anybody that you have contractual relationships with that may force you to notify them? And what is the verbiage around that? And so sometimes we, the people don't know the answer to that question.

Well, often they don't know the answer to that question, and they have to collect those contracts and get them in council's hands. Every once in a while. They will have either, uh, internal counsel, general counsel, or they'll have third party general counsel that actually does know that stuff.

So they'll bring them into the fold so they can say, yes, we have 10 clients that even at the indication of an event, we must notify them within 24 hours where we have other clients, we don't have to notify at all. So it becomes really important. And compliance, compliance is, is, is important too. And to throw another example out there, we've had a few cases lately, uh, that involve, uh, the victims are law firms in the state of Florida.

Well, the Florida Bar Association has requirements if a, if a law firm is, is the victim of a cyber attack. So you have to look beyond just the kind of standard compliance stuff that we all think of. There could be industry related compliance stuff that is state, state specific that now you have to comply with.

So those are all the things that have to go in, uh, to the incident response planning process now, because you just do not want to have to learn those things and figure out the answers to those things on the fly in the midst of an event. So we can go to the next slide. So the word document, and we've been talking about this and, and, but here are the benefits, uh, with the platform, uh, that's, that's readily available. It's accessible at any time. You have rule-based security in there.

So that's very important. So you can have people that just have the ability to, to read. There's people that can edit, uh, and obviously people with, with more access from an administrative perspective. Uh, this platform is multi-tenant designed. So what, what's we're gonna show you today is a platform where you as an SP should, you'll be able to figure it out very quickly. It's intuitive.

You can build out your clients in there and you can assign, uh, roles to each to individuals within your clients at the client level. Um, the platform makes it much more easier to deal with than a Word document where you have to deal with formatting and updating the table of contents and all that kind of stuff. Or, you know, inserting images and all that kind of stuff.

The platform makes it much easier for you to go to a specific part of your plan and edit that specific part of the plan, jump around where you need to jump around and those types of things. Uh, the same thing with the tabletop test. You'll see that as well here. And Go ahead, Andrew.

Yeah, Chris, I was just gonna ask, you know, coming back to the BIA, the importance of it in relation to doing the tabletop is, you know, we, we've been talking like we had Brian Blakely on earlier this week on the cyber call, really having a strong business led conversation. And he was, you already mentioned, like looking at contracts, data privacy, SLAs, things that you signed up for that a lot of times the business forgets about how important it is.

It, you know, when they see, you know, you're running through a tabletop and you're really focused on the, the business portion of this, not the technical portion, Chris. Yeah, the, we know the plumbing has to come back online. We, we get that, but for them to see the customer, to see that, wow, we're, they're really focused on, you know, the thing that may drives the most revenue in our business, the thing that impacts our customers and SLAs the most.

How, how, how important is that to tie the, the importance of this together for the customer and, and the value of it? Yeah, it's, it's so important to understand those, those, those pieces of this. So we, we come across a lot of times where we have people that are smaller companies, but they have very large customers and they're very dependent upon, and there's usually some active communication mechanism between those two entities to transfer files or to access whatever.

And so what happens is, is they, they, they have to notify this big client that they've been compromised or that they may be compromised or whatever, but they have a requirement very early on to tell 'em something. And, and, and we come in and we're there to contain the situation and do all that type of stuff, but to their client, that's not good enough. So a lot of these big companies, they have their own security teams and they're quite large.

And so we may get on a call sometimes with five to 10 people. And so the smaller company that's the victim here is trying like, heck just to get their business back up and running, and they've done all the right things to get it back up and running, but the big, their big customer is still not convinced.

And so we have to jump through a lot of hoops and get on a lot of phone calls and do we have to do attestation letters and all sorts of things in place to, to get those mechanisms up and moving again for the, these, these organizations, none of that's ever documented. And those things, they don't realize until, you know, unfortunately, the proverbial poop hits the fan.

And I think it's one of those things that, um, you, it's, it's worth having the conversation with those entities to say, okay, we have this requirement. Let's talk about hypothetically, if we went through this situation, what are the expectations from you customer to allow us to restore business with you? This happens a lot in healthcare.

Healthcare when we have, uh, hospitals or whatever the case may be, they have a lot of medical equipment there that's maintained by the third party who provided that equipment. And that third party will not even touch anything until the hospital proves that it's secure to them. Because now their argument is, we don't want to get infected by the same thing you got infected by, which is kind of, if you looked at the situation, it's not even possible to happen, right?

But that's the, that's kind of the front they put up, right? And a lot of times they just want to know IOCs in indicators of compromise and that type of stuff. But it's, it's, it's the business stuff, right? You gotta connect all those dots and all the things that you're dependent upon and all the things that drive revenue in the business and understand what happens to those things when a cyber event occurs.

Well, And just, just one last exclamation point for, for the folks here, Chris, is the ramification or potential ramifications for, you'd said, Hey, you know, one of the MSPs has a, you know, like you said, a client, maybe they may not be the largest client, but they have massive customers, let's just say, um, in this example, let's just take breach notification and, and, or certain data privacy things, but let's use something easy like breach notification.

What are the ramifications for not doing that properly with a big contract, a big customer, and then all of a sudden, like you say, the customer isn't stupid, right?

They eventually find out you're offline, um, and you didn't meet the perver, you know, the what, what you signed that contract for to do business with, what, when, when all the said and done and the lawyers start lawyering, what, what is, is it can be a loss of contract, and this is what I want everybody to hear in changing those business conversations about, let's take a look at really what's in that contracts you have with your biggest customer, Right?

So we've seen situations where from a, from a just you have some data was compromised and the state has its requirements for notification. However, the contract that, uh, the victim has with someone else, that contract has language in there stipulating that their customer can dictate what that language says outside of what the minimum that the state requires.

So you might think from, purely from a legal or statutory perspective that you are required to do this type of notification, provide this amount of information, and provide credit monitoring or whatever it is for three years.

But you may have some contractual language that says, Hey, but if that, but if it's information that belongs to us and that's information that's impacted, we have the ability to override what you're doing and go above and beyond what the, what, what the state law says to do. And so that's why it's important to understand these types of things. And then there's also sometimes there's even upstream from them.

And so their information, the information that was impacted might actually belong to someone else who then they have a contractual relationship to deal with. So this whole issue around who owns the data, where the data goes, who has to notify whom, who has control over that, how quickly that can happen. There's a, you know, and I'm not an attorney, but there's just a lot of things that could go on with that.

And most of the time, and maybe that I, maybe I don't use the term most, I'll say a lot of the time what we find out is the data that's impacted is data that shouldn't even be around anymore. It's just stuff that's been lingering around. No one took care of it, no one deleted it. So they didn't even account for it when they were even thinking about what they had to do.

And it's not until they go, holy moly, we had this, we had this data from a company that we acquired 10 years ago and we never deleted it. And that data even goes back farther from the time that we acquired them. And so understanding that those changes of events and then getting in front of those and, and figuring out, do you have a lot of inconsistencies between your contractual obligations, because that makes it very hard to plan for and very hard to manage during a situation like this.

Mm-hmm. Really good, Chris, thanks. Mm-hmm. Yeah. So on, uh, um, yeah, so I know there's some questions real quick. So, uh, we're gonna jump into this, uh, and yeah, they'll See the situ. I was just trying to explain there what the situation room is, and, and we'll, you'll get an actual visual of this, um, as Chris starts to, you know, set the stage for an actual tabletop that we're gonna walk through. Yeah, the cool thing about this platform is it's a, it's incredible.

It's the whole life cycle, right? The plan, the testing, and if you're actually having an incident managing the incident in there. So, you know, when we, when we're at the, the right of boom, when we're actually at the actual events, you know, we go, we have more time and we go into some more detailed type scenarios.

But today we're just going to go through a typical BEC scenario, uh, business email compromise scenario, which in our world, we see as many business email compromise, uh, situations as we do ransomware events. So just to put that in perspective. And, uh, we're just gonna go through a real simple scenario, talk through it, and then we're not gonna go through and input all the stuff in the platform like we would during a live session.

But what we will do is kind of talk to it and, and how it works in there. So in this particular situation, you have a correct customer that has called in and reported that emails are being sent to customers via one of their employees 365 accounts. They have done some work on their own to determine that the emails are emanating from that account and not a spoofed email. So what they're saying is, Hey, look, we know these emails are definitely coming out of this 365 account.

This isn't a situation where somebody spun up a different domain that looks and smells like the actual domain and doing it from there. Excuse me. So in this particular scenario, the customer does have an IR plan, you're actually going to walk them through this process of declaring an event. And, uh, this is something you want, uh, you don't want to own as an MSP.

So one of the things that I want to try to articulate to everyone here is, and I think seeing most of the people that chimed in that I know as you understand that this is a collaborative, but then it's got joint responsibility. And in no way do you wanna be the sole owner of a cyber incident for a customer. And we still see that happen today. We do get calls where people are like, Hey, we had something happen a month ago. Our MSP got involved.

They took over, they took control of the situation, said it was resolved, but come to find out a month later, it wasn't resolved. Our data's out there in the dark web and we had no idea. So you definitely want this to be shared responsibility, like a number of people have mentioned today in the comments. So we can go to the next slide. So, yes, so your customer in this particular situation does have cyber insurance, and they wanna open a claim.

Uh, the carrier told 'em that they're gonna have an IR firm and a breach firm contact them shortly, and that call in ensues. So, um, what's gonna happen is, from an MSP's perspective, in this scenario, your, you have a person that's your kind of assigned security analyst in this thing. Uh, the IR firm's gonna want global admin rights, which is pretty standard. Uh, they're going to collect all the logs from there.

That's if the, uh, the logs are enabled, which I hope for everybody on this call that you're making sure that is on your customer's tenants. Um, and then the attorney's gonna jump in and start asking a bunch of questions. So in an email compromise situation, uh, obviously a lot of times money is the main factor in what gets lost. Somebody's figures out a way to redirect funds somewhere else. Uh, but that's, that's, we care about that.

But what, but in what we're caring about more so is what's in that mailbox is because if people just lose money, insurance is gonna reimburse 'em for that, and they go on. But if there's actual some type of confidential information in that mailbox, then we're gonna have a bigger problem on our hands and have to go through that process. So that's why we have attorneys involved and all that type of stuff.

So even for us, there's a lot of business email compromises that we don't perform investigations on, because there's really no reason. I mean, it's, it's easier to figure out what happened, money was lost, and that was it. The only time we really have to get involved when there's some kind of privacy issue, uh, that's, or, or some potential privacy issue involved. And that's what this scenario kind of covers. We can go to the next one.

So we, uh, the IR firm in this particular situation, uh, they're gonna pull everything they need and then they're gonna get out. Uh, there's no reason for them to linger on and, and for anybody to have any more global admin access than that's necessary. Um, and then, uh, then they can instruct you in this particular situation to go ahead and revert if those steps did not in this particular scenario, they didn't.

But in most times, when an MSP is involved, uh, they've already taken the steps to, uh, kill any forwarding rules, uh, and kill anything else that was done by the threat actor and kind of revert everything back to the way it needs to be, uh, and making sure multifactor is enabled and all those, all those types. Um, so now let's go ahead and jump into the, um, let's go ahead and jump into the platform and we'll kind of show you kind of how all this kind of works in there.

Um, so, so here's the platform and the important part about this is, is what you're seeing here is the MSP, the backend for what only the MSP side sees, right? So when somebody gains access to this, they're gonna gain, no one's gonna show this to you. Uh, they're gonna only see what they need to see from their client level.

Um, but from an MSP level, this is where you're gonna have the ability to set up all your customers and to add anybody that needs to be added on behalf of them, their company, into that. So here's a just a bunch of examples of of multiple clients that are in here. So you as an MSP would add any of your clients that want to do incident response management, uh, with you.

And so, uh, what's nice about this platform is there's a number of templates that have already been created that you can leverage, and here's a good example of those, and you can choose those, uh, any of those and build on top of them. And Chris, not just incidents response management, but maybe, maybe just preparation, right? Just It can be anything to be honest with you. I mean, that's exactly right. I mean, you can build any plan or anything in your Exactly right.

Well, and, and what I, what I think the big thing is, I, I, on the margin, I think more MSPs are in the business like nets here, she's way more gonna be doing vcso and tabletop type services than probably full-blown ir, you know, I'm, I'm sure there's a DAC, you know, I know their company well, and that you can chime in and chat here. There's a DAC, right? Hey, we'll handle, you know, a certain thing about A BEC and if we can get the guy out and et cetera, et cetera.

But more so the, the, what I'm seeing companies and and MSPs really gravitate to, and the ones that have the acumen and, and can really take their, their VCSO services, this is an area that they can really start to build a nice business model with, because we're seeing, again, on the margin, non-recurring revenue, Chris, start to, for the first time in a while, start to slope downward. Mm-hmm. So we look, we need to look at other areas where we can add value into the business.

Yeah, and I think, I mean, what you said is all right, and adding value to the business, and I think what this does, um, indirectly or, and maybe in some cases directly, you learn going through this process with your clients, you're gonna learn even more about their business, and you're gonna be more engaged, and you're gonna be showing value that's going to be helping their business.

Whether it's, you know, you know, to get out of a bad situation or just to be a better, a more mature operationally company. This is what you're gonna help 'em on. And, and the one thing that we highlighted here is that response plan approval. That means that you get some acknowledgement from your client that this response plan is approved, and you can set that frequency up that they have to approve that.

So you get an acknowledgement from them that they approve of this plan, uh, whatever frequency. So that's, that's a record that you have that they've reviewed this plan, and then they, they accept it, which is, uh, which is really nice because if you can't prove it's being done, it's just like not being done in the eyes of a court.

Y Chris, this, you know, this just popped in my head, but, you know, I remember I'm dating myself after 25 years in the channel, but, you know, you know, really when security awareness training started to come, you know, more in vogue, right? It took time. Mm-hmm. Right. You know, initially it was only for certain regulated customers. 'cause it's like, it was like, you know, logging and sim hey, only these customers get it, right.

And then it became more ubiquitous, um, you know, are, are you starting to see, for example, the need because of the, you know, amount of, you know, social engineering business email compromise that, you know, if you're not doing this kind of stuff, it's almost negligent in nature these days. It's almost like security awareness training. Like, hey, when this happens, what do we do? What's our process? No, it's exactly right.

I mean, it's no different than having plans in place for some kind of financial issue, right? Um, I mean, there's so many companies that have been doing, you know, risk management around their finances or even their people and that type of thing. And that's become common, common nature, just like you talked about with cybersecurity awareness training. But in this particular situation, yeah, we are starting to see it be a little bit more adopted.

Uh, but we see that happen with, with larger companies more so than smaller companies. So when you're getting into the, the hundreds of employees or over a thousand employees, companies are more focused on this. And we're even hearing, uh, hearing that they're even funding those types of things, more so now than they ever have been, but still seeing a slower adoption than I would like, uh, with the smaller organizations out there. Um, but it, it's, it's improving.

But I think it's, uh, that's why we need the MSPs to really push it and push the importance. And I think this is one of those things where the MSPs live by example, because you're going to eat your own dog food here, and you're gonna be able to explain that to 'em and see why, if it's so important. It's, it's that important to you. It needs to be that important for them as well. Yeah, absolutely. Yeah. So again, this is kind of the, the background.

This is where you set your customers up there is the ability to, you know, add your customer logos in here to, to jazz it up a little bit, which I think is always nice, make it more personable for them. And then you can kind of see, uh, below where you have the d different sections for doing tabletops in the actual scenarios themselves.

So, and when you set up a customer, um, we, we, we don't need to go through that, but, um, the platform has done a good job of, of walking you through that process. So this is not something that you're gonna have to feel your, feel your way around the situation. Uh, it takes you through step by step what you need to do. So here we're going directly into this really important customer that, uh, film set up here. He's a very creative guy with his naming scheme, but, uh, here we go.

So we are in the dashboard now. Yeah. First here, here's his response plan. Yep. Teams, roles, the forms, the framework, everything is, is in here automated. Yep. It's all automated. So this is exactly what it is. And, and so you're gonna have your members, you can, there's built in groups, you can create your own groups, and then there's roles. And what we've done here is created the most common roles in there.

But again, this is this platform, to use the term customizable is an understatement. So it is where you can add different roles if you need to. You can add backup roles. So like, if you have enough people have backup roles, one of the things you wanna do though is you want to, to make sure the roles match the capacity of a particular situation. I've seen people do IR plans for an organization that may have five people, but there's like 20 roles. There's not 20 people to fill 20 roles.

So you gotta, that's why it's, the beauty of this platform is to customize it in a way to where the plan can be understood and actually executed by your client and yourself in that situation. And then you can call out the fact that we are not gonna have this role internally and that we're gonna have it externally. Or somebody might have to, one person might be assigned two roles.

So that's why I want people to kind of make sure we see just too often people want to take just standard template and apply it to everybody, like one size fits all, and that doesn't work. And so the beauty of having this platform is you can change that and structure in a way to where it matches each of your client's capabilities. Um, same thing here.

So, uh, we, we have based, uh, a lot of the framework and everything off what we have found that's in use out there, whether it's published by NIST or other publications. And, uh, even myself has gone in and, and tried to tweak this to where it just makes more sense for, uh, what I would call the typical client out there. But again, you can change things up based on what you feel makes sense to you and your clients. Um, but that's what happens in this section.

So this right here is, um, this right here is the situation room, which was talked about a little bit earlier in the chat. And the situation room is what you would see, uh, get populated in a tabletop exercise, but also it would be the same thing that would be populated in an actual event. And so one of the, uh, and again, this is set up in a way to where, number one, it helps guide you and walk you through those steps that you have put forth in your plan. That's number one.

Thing number two is, because this is an interactive platform, there are questions and answers that when you go through the process and you answer those questions and answers based on the response, it will generate what the next step needs to be. So it's not like if you had a Word document and you had to go through and read a bunch of stuff that doesn't, oh, that section doesn't apply, that section doesn't apply here. We've taken all that out.

So you can actually go in there and, uh, again, if it's a BEC, it's gonna be a certain set of questions. If it's a ransomware event with no data exfiltration, it's gonna be a set of questions and it's gonna have a separate, it's gonna have, based on this particular situation and this response, these are the next set of questions like, who's counsel? Who's the insurance, and all that type of information.

Kristen, What's really cool about it too, no, if you could show the team on the right there, what, what happens, you know, in, in an incident and why experiential or things that are experiential I think are so important is, you know, if you're doing a real tabletop that, you know, and, and there's pressure involved too, right? I don't suggest that the first one, Chris, but you know, if you are working with a big client and they have external breach counsel, right?

They have their cyber insurance carrier, you know, they may have you involved Chris, from an IR perspective to see all these teams that aren't on the same, same domain. Mm-hmm. Right? Interacting together. Certain people can see certain things, certain people can't. But to not only see this collaborative scenario happen, which without something like this is virtually impossible to do something cohesively.

Um, but then everything from document, whether you're using Slack or some type of messaging to creating a zoom to pull all the players together, because when the, you know, what hits the, you know, what you can tell us firsthand, Chris, it's not pretty. Yeah, it's not pretty.

And to be able to bring those people together in one place, and you're not having all sorts of emails flying around different directions, and you don't have people saying, well, I wanna do it this way, or I wanna do it that way. You remove all those obstacles, you remove all that interference, you remove all that noise, it's all right here.

And so, and just like you said, you can assign, and based on the role is based on what, what they can do and what they can see, because there are, um, there may be, uh, certain information that certain parties don't need to be privy to. And then there, then there's certain parties like your attorneys that need to be privy to everything. And so that's the beauty of this.

The other thing that's really cool about this is, uh, something that you can't pull off with a Word document or any other way is at the top right there where it says timers and timers are set within the plan. And so you say, Hey, look, we have, we're gonna declare an incident. There's a timer. We're gonna decide as a company that we have an hour or three hours or whatever the case is, to gather information, to determine, to declare an incident. You can set a timer for that.

You can set a timer for how long it's gonna need to take for you to contact an insurance carrier and get information back. That's the beauty of this. You can set as many timers as as little timers. There are timers based on conditions and so on and so forth in this platform. And the other thing that Andrew mentioned was there's integrations as well. So you can, you can take integrations with Slack and with teams, and you can incorporate what gets fed into this platform from those things.

So let's say you're having a team conversation, you can have, you can tell, you can have the platform pick out specific parts of a conversation in the chat and have it posted in here. So if somebody says something in chat, it's very important gets put in here. So everybody that has the access to read that can see, okay, that's an important part. And it's just, it's just clearly documented in here.

So if you were to go into this platform, you could run an incident without a plan and you can do that. But the beauty of having the plan in this same platform and running, whether it's a tabletop or an actual event, is everything's gonna flow just like documented the way that you want to documented anywhere, Chris, um, we've been taught many of us over the years, Hey, everything documented in your PSA, why is that bad when it comes to this kind of stuff? Well, yeah, that's a great one.

So, uh, with a lot of PSAs, and I can't speak for them all, but, but I know that many of them, uh, when you, there's information that, that is confidential that you don't need floating around in a, in a PSA and it's very hard to control who can see what in A PSA from your organization. So as an MSP and you have a client that's maybe under attack and you're operating with, with that under that, there's probably the number of employees in your company that are not involved in that.

So them having access and seeing that stuff probably is none of their business, and that's very hard to do with A PSA. Also, there just may be information that you just don't want sitting around in that MSA that's, that's better situated for a platform like that.

But the, probably the biggest thing about PSA and what I've learned, and I think the PSA vendors are getting better at this, is when you delete something in A PSA, it's not really deleted, it's marked deleted, or it's filtered out from being a view, but the data still lives there. And what, when.

And so you, it's just not a very, uh, reasonable platform to use, uh, for these types of events where you're dealing with some very critical information, a lot of times confidential information, and a lot of stuff that could be interpreted and or misinterpreted, uh, in a court of law. So having it all tightly controlled here in one spot where all the parties have access to it, makes it just that much more simpler than trying to make a PSA work for this.

But Chris, isn't it also the danger of discoverability from opposing counsels and things of that nature you have to be careful of as well? Yeah, because, you know, today's today's rule and it's constantly getting challenged, but, um, unless the attorney is, is privy to those communications, it's quite possible that it's discoverable. Yeah.

And so, and so in a PSA type of environment, it's not, not really a good idea to give an attorney access to the PSA, so they can be part of that ticket or range of tickets or whatever series of tickets in there. So being able to have the attorney privy in here and seeing all the communication, everything in here ensures that the attor, it makes the attorney feel better that they're seeing everything that they, they wanna see and be privy to.

If an attorney finds out that there's side, side channels and those types of things going on, it'll make them very uneasy. And, uh, you don't want uneasy breach attorneys involved in a situation you wanna be as, uh, you want to come across, especially as the MSP as cooperative as you can be. Cool. Yeah.

So just to kind of go back in here, we, we talked about this, that, uh, in this particular situation, uh, all the things that the threat actor did were, were able to be cleaned out and, um, in, in the, in the mailbox, put in a, a, a secure position to where the employee can then regain access and, and begin work again. Um, so this, this ties back to one of the things that we were talking about earlier. Um, so this was a cyber event in this particular situation.

There's some contractual obligations that they have, and having these findings is very important. So before I get into the next part, here's one thing that kind of is, uh, we, we still see today is in, when you have somebody that knows what they're doing from a forensics perspective, the forensics report is going to only have things that have evidence to back them up.

There's not gonna be any speculation, there's not gonna be any guessing, there's not gonna be any statements that says something like, well, we've seen a similar situation a year ago and this is what happened. So we think that's what happened here. That doesn't happen in a true forensic report. The forensic report is gonna be very fact-based.

And so what needs to happen is that that forensic report a lot of times is, uh, what the attorney relies upon to then in turn give their advice to the victim of what needs to happen. And so, uh, in this particular situation, uh, in this scenario, they were able to connect to the mailbox and sync that mailbox all the way down. Uh, that means everything in that mailbox was compromised.

Uh, in, in this particular case, the, the attorney was experienced and had everybody kind of prepared that this could be a potential likelihood. And so what the next step means is they have to go through a data mining process. And the reason why I baked this into this, this scenario is because a lot of people, because they don't have any experience going through this before, they think the forensics is the data, data mining process, but it's not. The forensics is just there to stay.

What happened when it happened and how it happened. The data mining is the more extensive process, and it can take a much longer meaning that you have to get a third party involved that fo that focuses on data mining. And they pull all this information down and they go through a process of both automatic and manual identification of confidential information, usually stuff that's regulatory, PII.

And then they go through a process of identifying those individuals, de-duplicating the data, making sure that people aren't listed more than one instance, and then giving that back to the attorneys. So the attorneys can then understand who needs to be notified and to what law. 'cause remember, if that person lives in a state now different than the state they lived in, the state where they live now is what prevails.

And so whatever notification needs to happen legally, uh, will, will, will be the one related to that state. So that's why all this data, main data mining takes place. So the little underlying theme here is, is talk to your customers and make sure that, uh, as hard as it is that they mailboxes aren't this giant, uh, file box of the old data that's gonna bite you in the butt if somebody gains access to it.

So the the nice thing about this platform, again, is you're gonna go through a tabletop scenario, just like I went through. You're gonna go through the process and you're gonna be able to notate areas for improvement, and you're gonna be able to, to provide that in there. Additionally, when you do a tabletop test at the end, it, it'll gen, it can generate a report for you, and that summary report can be used as, again, as evidence that the tabletop test itself was performed.

And so we're gonna focus on all, uh, that's what that platform focused on. So I don't know, uh, I know we're running low on time, but no, if you want, you got a, you wanna jump in there and just show 'em kind of the wrap up portion of the platform? Yeah. Let's see if I can do it quickly. Just go to something, um, once it's resolved, there is a report that gets, part of it is populated based on information.

The incident part of it, of course is, is, uh, investigating lessons learned of things happened after the incident. You can also select tasks to come into here and select your relevant elements from the timeline. And then once you're done with a report and the post-incident analysis and lessons learned, you can either export just the reports or by, or export also the entire page with the entire timeline as as complete evidence of, of this tabletop or incident.

Yeah, so, so you as a an MSP, when you're performing these exercises for your clients, you don't have to go and type up a separate Word document. Everything's already done. So if you did your part and documented things in the platform, and at the same time your clients were interactive during that tabletop test and they documented things in here, made it incredibly easy for you to create that report and deliver that to 'em as the evidence that that was done.

And, and it also uses generative AI to create a summary of the incident that is very, or tabletop there is useful as well. Yeah. So in 2024, you can't do anything without Exactly. Some in corporations ai. And that's been, that box has been checked here as well. Exactly. And in multiple places. Yeah. So, yeah. So that's good. We can, we can go, um, again, we hope everybody, uh, got some value out of this outta this platform.

I know, Andrew, if you've seen other questions pop up that I haven't been able to catch or anything like that, or No, You're good. You're good Chris. Uh, but great, great job, both you and Nom. Um, you know, again, I'm, it's, it's great to have people start to, you know, this is, it's something that is so imperative, I think, to changing our relationship with our customers, right?

Bis, incident response planning, tabletops really driving the conversation about the business and, and, and, you know, we have to evolve as MSPs. We talk about this week in and week out on the cyber call and, and we're seeing the MSPs that are doing it continue to start to break away, right, Chris? And that, and that's the thing. We want everybody to have this opportunity.

Um, So yeah, and you know, it, there's again, just like, yeah, it is benefits to their customers, but it's benefits to you, right? I mean, you're gonna have a repository of this information, so if, if, if this done right across your customer base, you're gonna know things about your customers. That's gonna, that's not, maybe not as easy for you if documented in other places.

You're gonna know there, you know, there's the ability to attach things in here so you can attach their cybersecurity policies into this, into the plan. So you'll have that inventory of those things. So you'll know, Hey, my customers, they have this insurance policy with this carrier. You'll know all that stuff.

And this platform just makes that much easier for you to do and, and focus, again, we've been talking about instant response, but there's, uh, you can use it for other types of planning the same way. And, and Chris, just again, coming back to the whole relationship with the customer in, in a sale, in a competitive situation, right?

You have a prospect, um, and there's another NSP or two or three MSPs in there when, when you understand the amount of, you know, roles, process, effort to go through bia, incident response planning, understanding really what drives the business, their data security, their privacy, and you are having that conversation and someone's like, yeah, but you know, the competitor's $2,000, you know, a month less than than you, you know, you, you sit, you're, we, they're, they're basically allowing you to weaponize the conversation.

Exactly. Like, Look, basically, I, I can tell you right now for that price, they can keep the plumbing, the water going through the pipes, but there's no way that they're gonna be able to focus critically on the business. There's just not enough money in it. That's exactly right. And they're not gonna be able to, to know your business enough to where they can focus on help you help the customer focus on areas of their business that they need to be more secure than need to be better prepared.

You might even find that there's opportunities for other services, backups, different types of backups in this thing when you go through, through this process with your clients. So it's kind of, the opportunities are somewhat endless, um, for you when you start to do these types of things with your clients. And you could definitely show this. You could have a mock one of these things done for a prospect and show 'em, Hey, this is a differentiator for us.

This is the stuff we think about that our competitors across the street don't. Yeah. This is, this is why we do this, is this is why we charge what we charge. 'cause we are taking into consideration your business not Right, just blinking lights. So, exactly. Yeah. So, um, did you get a chance to tell everybody about Solace real quick and, and exigence and, and I know we gotta wrap up here quick, so Chris, Yeah, I think, uh, just solace, you can always reach out to us, uh, www.solacesecurity.

com, uh, reach out on LinkedIn to me, um, I'm Chris Laer, all one word. Uh, again, we have, uh, global coverage. We are always happy to help anybody that that needs our help, whether it's, you know, unfortunately in an incident situation or if you want opportunities around, uh, using, leveraging some of our managed security services for your clients, we do have partner programs available for you to, to leverage and would love to have someone on our team discuss that with you at any time. Yeah.

You work a lot with MSPs. Uh, yeah. You need feet on the ground and, and then it becomes, have seen firsthand, Chris, you know, they helped out in an incident and get a large recurring revenue deal out of it, so, exactly. Right. Something that, um, yeah, thank you David. Appreciate it. Um, and then nom, So, uh, if you're interested to learn more about the product, see a demo and get a free trial, please reach out to me directly. Here's my email or on LinkedIn as well.

And, um, let me know that you came through this webinar so you'll get treated extra, extra. Uh, well, Yeah, if you don't come through this webinar, he treats people Exactly. I, yeah, exactly. You can tell he's ruthless. And then, um, for, for sitting through, through, and, and, and again, I, I look at this as I love the MSPs that invest time and make their businesses better. We, we dedicate so much enablement through the cyber call cyber cast, Chris, for years we've been doing stuff.

So, um, it's a little special for you all. Um, we have, um, uh, the, um, early bird ending at the end of this month. Uh, we'll do a little extra something for you here to save an extra 50 bucks as well. Um, that's valid through the 27, so You better be there. That's all I'm gonna say. It's, um, it's, it's gonna be a, a great event. Again, it's gonna be different in a great way. So whether you've never been there or you've been there one year or two years, it doesn't matter.

You need to be there. It's gonna be fantastic. I know some of you get scared about Las Vegas, don't worry. We will insulate you from that. Uh, it'll be a great event. So you take advantage of this offer and be there. Oh, thanks Chris. All right, everybody, have a fantastic week and look forward to seeing you all very soon. Take care.

Related Videos