Skip to main content
Right of Boom
January 30, 2025

Preparing for DDOS & Selling Right of Boom Services.

In this video, Stephen Legg and Ryan Eichler discuss the growing threat of Distributed Denial of Service (DDoS) attacks and how businesses can prepare for and recover from them. They delve into the importance of frameworks like CIS in establishing a robust cybersecurity posture and highlight the opportunities for Managed Service Providers (MSPs) to expand their services upmarket by offering comprehensive security solutions. The conversation also touches on the evolving landscape of cybersecurity threats and the need for businesses to adopt a proactive approach to risk management.<ul><li>The webinar highlighted the importance of collaboration among cybersecurity teams and companies to address and mitigate threats like DDoS attacks and vulnerabilities in software.</li><li>The discussion emphasized the need for businesses, especially MSPs, to adopt security frameworks like CIS to build a resilient cybersecurity posture and protect against evolving threats.</li><li>There is a significant opportunity for MSPs to expand into the 100-1000 employee market by offering comprehensive cybersecurity services, focusing on recovery and resilience in addition to traditional IT services.</li></ul>

Guests

Andrew Morgan

Video Transcript

Welcome everyone. Episode one 16 here. Uh, Gary wanna talk to us about the Phillies? Yeah. World Series baby. Awesome. Where do you wanna talk to us about the Eagles this week? Uh, It really could be both right now. It's crazy, uh, here in Philadelphia, but it's a good week. We got a bunch of baseball games and we got a football game on Thursday. It's great. All right, well, uh, we have an action pack cyber call today. And so, uh, forgive me up front. I may be looking down at my notes at times.

We had s scheduled originally and we ha we'll have 'em on. At a quarter pass, we'll have Steven Legg and Ryan E are talking about, uh, DDoS attacks and the exponential growth of those. Patrick May even hang out. No pressure, uh, if, if, if, if, if so, 'cause, uh, of his days there. I'll have to see if I can have enough windows. I actually, I may not be able to Patrick as I count. Um, the other thing is, uh, quick announcements. Gar, um, okay. In all seniors, just write a boom.

I checked as when I logged into here, I was two spots finally. Now for John Hammond, John Strand, preday. Um, and that will close. Um, John, thrilled to have you guys doing that. I, we were on a kind of a pre-call plan. It's gonna be awesome. Um, and then we did a cyber cast, uh, this past week on security, um, awareness, and now gonna be education skills thanks to Ryan, right? Phyllis, um, no longer training skills, uh, but it's seriously one of the best ones that's sponsored by Thin.

We'll have that out to you in all the major podcast channels. Okay, let's get right on into it over the weekend. Uh, if you haven't seen it, um, there is a great article, which I will put in chat once the conversation gets going. It was broken by CRN, uh, it's why we have John Hammond and John and, and Patrick Beggs here today with us.

Um, I'm really excited as a community to bring you both on because to me, uh, when we've talked many, many times on the cyber call, Wes, about security teams, uh, not competing, that, that, that as companies we would compete fiercely, but when it comes to security, we would work together to elevate the whole community. And, and, and this is what we saw this past weekend, although I'm sure a long time in the making. Also, I see Jason Slagel out there.

Huge kudos out to him for putting tremendous amount of effort into this as well. So, John, start us off a little bit, if you will. There was a tweet, right? And, and kind of take us through the chronology of what happened from there. Alrighty. Well, hey, yeah, thanks for the tee up, Andrew. Super excited and happy to chat about this. Uh, can you hear me okay? Audio good? We can hear you Fine.

I did a disservice to you tell us a little about yourself and your 500,000 plus people on YouTube just real quick and then get into it. Oh, great. So people know who you are. Alrighty, thank you. Thank you. No, hey, I'm a fellow nerd. I'm a geek, uh, uh, security researcher over at Huntress. Uh, on the side when I have free time, uh, I'll try to squeeze in and hey, some cybersecurity education and training on a, on a YouTube channel that I have with some silly stuff.

Uh, but hey, love to be a part of it. Love to be in the front lines, love to be on the keyboard, and, uh, super happy to be here with you all. Awesome. Thanks, John. All right. Take it away. Yeah, But back to the story here. Uh, so we caught wind of just a simple tweet over there on the Twitterverse. Uh, a user, an individual I believe over from, uh, code White, GMBH. Um, his handle in his alias was recos.

Uh, he had just teased a couple screenshots of a hey, penetration testing or web like assessment, vulnerability scanning, utility to, uh, explore and experiment with the R one soft server backup manager software. Uh, there was and is a vulnerability in the ZK library, which is some of the code and hey, software that originally that product is built with that had a vulnerability in auth authentication bypass. Uh, we thought that was a little bit peculiar.

Uh, hey, you know, there's, there's some potential for, for serious impact there. So we wanted to kind of pull that thread just a little bit more. Uh, and we were able to replicate that authentication bypass and then expand and further the potential damage there. But hey, we wanted to go make sure everyone was akay and all on board with this. Uh, so we tried to reach out to friends over at ConnectWise.

Great to have Patrick part of the conversation, uh, and do the responsible disclosure to make sure we can address this vulnerability and fix it, get a patch out and about and improve and bolster the security landscape. Very cool. Very cool. So Patrick, um, what a little bit about yourself real quick, and then what happens from there. Sure. Real quick about myself, I've been with ConnectWise Andrew as you know, since, uh, February of this year. Um, long history in cyber for the past 20 years.

Uh, I was in the government for quite a long time. Last job there was, uh, head of operations at, it's called the End Kick, um, fast forward cyber operations experience in places like Bank of America, AWS most recently head of cyber operations for all of Cognizant Technologies.

Um, really, you know, John hit the nail on the head on, on on the summary of exactly, you know, kind of how this, how this transpired and, and in great detail of, of what the issues were, what with it and when, you know, it was, I'm not gonna try to get too far ahead of ourselves, but the collaboration as fast as it happened and as efficiently as it happened, I was beyond impressed.

And I've spent a career working on public private partnerships and also operational collaborations between large commercial organizations. Um, quickly got their folks on, on, on between emails and calls, uh, really working out the details of it, but also really kind of step by step walking through how we are going to responsibly handle this as well. So, um, could not have asked for a better experience when it comes to getting the right folks together. Right.

Regardless of what company you, to your point, it just, you know, having them, and I know they were geeking out, man, lemme tell you, uh, I got some feedback from some folks on my team, and I know they're gonna be at IT Nation next week. So I'm looking forward to those guys, actually, and gals meeting in person. So thank you. Very Cool. Yeah. Very cool. We, Wes, starting with you. Did you have, I have a few more questions, but did you have anything on your mind to, to ask?

Um, no other, well, actually, you don't have to, you don't have to. I'm just, the only thing I just wanna go around only to know is, uh, what am, so I know Slagel was involved in working on this. Any other MSPs that were, were active. I think that's a third piece of the puzzle. It's pretty cool.

I will offer, uh, without naming names or getting into super specifics, um, but once we had created our own proof of concepts to, hey, explore and poke at this and, and fire down this remote code execution exploits, uh, we thought, wow, okay. We, we, we've tested and validated this in our own local internal lab, uh, but we'd like, hey, to really validate this in, in the proper way.

So we work with some of our own partners in a absolute, hey, total transparent, absolute, whatever they're comfortable with, and having their understanding permission and authorization. Are you willing to let us see this in your environment with everything that you're comfortable with? Uh, and we are super duper grateful for a couple of the partners that did come outta the woodwork to let us play with that.

Uh, and hey, I think that at least offers like, well, we've done the due diligence on this. Sure, we've got our own cheesy home lab environment, but we've seen this out and about. And, uh, it has the impact, I think, worth bringing all the attention that we're bringing to it for. Yeah. So, Patrick, there's a question real quick. Uh, and you know, that, uh, sunny asked what, just to be confirmed, which CW application, if you could be specific.

'cause I think there's some legacy that you guys have taken on since a lot of your acquisitions, Right? Well, having, I'm having technical difficulty here. Hold on a second, guys. Okay. John, do you, do you wanna talk while he's doing right? Hold on. I can't see. Hold a second. I can swoop in if need be, but I'll let Patrick Yeah, Please. Why don't you go ahead while Patrick's fixing Sure thing.

Uh, so from our understanding, hey, we uncovered this as R one server backup manager, se, uh, R one Soft, I believe was hey, taking up by Continuum. And then, hey, that also got jumped into ConnectWise, uh, and I believe ConnectWise offers what they call ConnectWise recover, which is the online, hey, cloud managed rendition of this. So let me make the absolute point. This vulnerability is patched, it is fixed.

There is a security release up and available already pushed down for those cloud online. Hey, ConnectWise recover instances. Um, but for those folks kicking on whatever specific R one soft instance that does need a little bit of, hey, manual intervention to turn the gears and hit the knobs, right. Sorry, Andrew, I was having, I was only hearing Patrick, what could you say? I didn't understand. I didn't get the context of the question. Um, and Yes, that's okay.

We, and we've pushed the patch to our cloud environments, wanna stress to folks with, uh, as John said on the prem side, you know, please definitely go ahead and update, update that on, on R ones soft. Yes, it was, uh, an acquisition from Continuum, uh, for a number of years ago. So, um, yep. Part of our legacy environment for sure. So thank you for Got it. Yeah. Sorry about the technical Difficulties. No, don't worry. Gary, did you have anything?

Again, don't have to, just want to give you a chance. No, I'm good. I'm listening. It's good. Okay. Fair enough. Phyllis. Phyllis, you're on mute if you can hear me. And, and Andrew, I'm gonna, I'm gonna jump just kind of throw out there as well, and it's something we had talked about before is, you know, really trying to, and we have a nice blueprint for it here as to really talk about more operational research, collaboration, right?

Um, you know, creating, you know, really, you know, hopefully bringing to folks together that really just wanna talk about problems, right? And expose some of the challenges that they're working on without, you know, giving away the, the store per se. But I think we have opportunities, and this is a, again, good blueprint to show that, uh, you know, folks getting real smart people in the room to, to just look at problems, right?

It's, it's, you know, it's only gonna help us as a community, as an ecosystem. So, Pat Patrick, I had, um, and John, you, you may know this, we had Jim Manco on a few times, and I'm just wondering, you know, again, it kind of came and went like a lot of things too. It's like, you know, uh, we over, Jim Lippy said to me today, I love this quote. We overreact in the short term and underreact in the long term, hence a lot of the issues right, that we have in security.

But I bring up Jim Manko just to ask, do you think someone with his expertise in AppSec, like the time is right, where we could maybe get the big vendors together to support like a community effort of teaching his courses to the greater good? Um, because when you ask most sec software vendors in our space, do you have an AppSec program? The answer is typically no. So I just wanted to get your thoughts maybe starting with you, Patrick. Yeah, I mean, absolutely.

It's one of the, when I came in February, there was, you know, we had, we had application security as a, as a operational control. But really, you know, the uplift on that has been my number one priority at ConnectWise. Um, and how we're, how we're addressing, you know, you know, our day-to-day, uh, cyber operational capabilities, would love to talk about, you know, some of the, you know, concepts of operations that we've implemented.

We've created product security teams now that are embedded within each of our products. Now, Nick Nolan, who runs that group, has folks embedded, uh, versus, you know, kind of over watching their, they're, they're within those organizations that they're recommending the right practices, um, from beta all the way down to release. So, Very cool.

Yeah, I'd just like to, you know, Wes, any comments you might have, but in, in chat, you know, you guys, w would you like to see our vendors like step up, like maybe have this guru, like a Jim Manco come in and start like seeing their, like, yes, we've been trained, we, we've been certifier, we've done certifications, or we're moving toward a B SIM type, um, AppSec model framework. Um, anyway, John, your thoughts on this in closing as we have you for a few more minutes, maybe.

Hey, I, I'm all for it. I, I'm a proponent and advocate for any way that kind of we can keep coming together. Uh, it, it was really, really cool even, hey, over a weekend, right? When we're kind of burning the midnight oil, trying to get this thing, uh, handled the best way that it can be. We got on a call at 7:00 PM on a Sunday, 'cause hey, we wanted to get this messaging aligned together, and we wanted to get this properly addressed and offered to the community.

Uh, I think as you mentioned, hey, whether you got, oh, competing vendors or whatever shenanigans, we might wanna say, it's, it's cybersecurity and it's a team sport. We're all in the same fight. Mm-Hmm. Uh, I think ultimately it boils down to just that. So whatever we can do to keep that on upwards, uh, let's do it. I think this is a great example, and I'm excited for more close knit collaboration here. Absolutely. Yeah. Very cool. Looking forward to seeing both of you at, uh, IT Nation.

And again, thank you for coming on. Um, I, any, any quick questions, I'll take a look here to see if there's anything. Phyllis, did you have anything real quick before we, uh, we let them go? Um, No, I mean, I, I think it's great. I guess I'm curious, so what was the turnaround on the patch or the fix Pretty darn quick. Yeah, yeah, yeah. Within less than a week timeframe went from identification to Yeah. The test. Uh, it was, I again, that's awesome. I was blown away.

I'm not trying to, I'm trying to, you know, not to focus internally per se, but the, the, the product team, our security team, and I'll again, help with John and his team. It, it was really fast. Yeah. Hey, please let me offer that. Kudos. Uh, you guys did a phenomenal job and, and we're super happy to see it. Yeah. Yeah. Very cool guys. Alright, um, I'm gonna move on to part two. John Patrick, thank you so much for coming on again.

Really, really appreciate what you've done and kind of be a, uh, exemplar, if you will, of what's possible for our industry. It's great to see. Thank you. Thanks guys. Yep. Okay. All right. So let me go get our two guests real quick. Um, Gary, any entertainment that you'd be able to offer us in in the interim would be always greatly appreciated. Probably seen the Phillies fight song. They have a fight song. Do baseball teams do that kind of thing? Uh, I guess some do.

Phillies don't really have a popular one like the Eagles And Nats had Baby Shark for a while. Yeah, that's true. I set up for that. What, what is a Philly like, I know that's where you're from, but what does that mean? Yeah, just the Phillies. Is that like the Tampa Bay Philadelphia? Yeah, exactly. I know one thing. We don't have to change the name. That's true. That's Great. So that's good. Yeah. That is Good. That is good. Gary, You're hysterical, dude. You're, You're crack me up, man.

Alright, part two, let's get on into it. Um, let's see, part two. I prefer part two. Part Two, uh, okay, uh, again, I'll put something in chat momentarily on this DDoS. Um, uh, it's called Faja. Uh, we're gonna introduce our guest momentarily. I'm gonna motor on through this since it's already 17 pass. But basically, uh, what caught my eye, um, was the exponential growth of, uh, something that was on bleeping computer of this botnet DDoS, um, uh, attack, uh, named fja.

Um, and I'll, again, I'll put the article in there. There's some amazing research out there by, in the tech insurance space, no less. We of the DDoS cost, uh, the DDoS attack cost to SMB. Um, just to give you a sense of it. Uh, and the, the increase, I'll just give you a few quick, quick tidbits here. CloudFlare, uh, in their study, um, year over year DDoS attacks are up 164% quarter over quarter right now, 135%.

Um, and, uh, they also found the growth of these DDoS attacks that the, the number of packets right, has increased quarter over quarter, uh, by 300%, uh, I'm sorry, year over year, 300% now, quarter by quarter, 645%. So the, the, the growth, uh, and the impact of these really, we, we see originating out of the, the war in the Ukraine, however, we are now seeing them precipitate down into areas like healthcare and the larger organizations. So, Wes, does that make sense to you?

Just kinda as I set the stage, It, it does make sense and I'm, it's interesting, right? Like, look, I'm looking at that same data that you're just sharing and it's pretty significant. I, I'm, I'm que I'm curious from MSPs yes or no in chat, have, over the past 12 months, have you been, has your MS P been directly affected by a denial of service attack, not just an outage, right? Something going down, but an actual true denial of service attack or an outage cost by one?

I'm, I'm curious to know yes or no in chat. The reason I'm curious is I do think it's a threat, and I remember this being like a significant threat for me at my bank, that we talked about this significantly in the 2000, you know, 12 days and the DD four BC guys and all that kind of stuff before ransomware hit it stride, but look at all the nos, right? And so my nose is not that, I'm not saying that is indicative of it not being important.

I'm just curious if we have a little lag time before some of this begins to hit down market. And we'll talk with our guests about that, Andrew, but I, I think we get a lot of nos and it's interesting. Yeah. Yeah. And, and again, Gary, you know, I'm not, again, this isn't like a, I I'm predicting doom and gloom, but I remember when SolarWinds, and you're like, people were like, Gary, imagine if that was an RMM tool.

Imagine if, and what did you say When Not Yeah, you literally, it was one response when, when, when. And, and so there's a poll in there. Again, we have hundreds on, and I'll only get like, I don't know, 50 response response cracks me up. But I'd love for you to just hit yes or no. Are you prepared? Are you preparing for this? Okay. So let's get into it.

Uh, in talking about something like this, I wanted to really bring on an expert, and that is I'm gonna introduce Steven Legg from, uh, CEO and co-founder of Antigen Security.

Let tell about itself, Ryan Eer, who sat in your all's shoes built, um, a company called Interra in the Chicago region from basically being an MS tree, the MSP, and, and staying in left the boom type things, preventative controls, those types of services like most MSPs do, but into a full-blown, uh, incident response firm as well. So he's seen both sides. He's g the, the company tremendously and is now, uh, head of MSP and MSSP at a company called Illumio.

So Steven, without further ado, both of you, thank you for your patience with what happened today. Welcome to the show. Tell us a little about yourself and antigen and we'll get right on into it. Hi there. Yeah, great. Pleasure to meet you and, and really happy to be disrupted by John Hammond of all people. Uh, that was a great conversation. Um, so I'm my name as you mentioned. I'm Steven Legg, uh, CEO and co-founder of Antigen Security.

We are a channel first community driven, research focused DFIR and managed security distributor, the partners with cyber insurance carriers to create intelligence driven solutions that reduce every facet of cyber risk. Basically, that's, that's our focus is research, applying that research to what we bring to market with our MSP and cyber insurance partners. And that's kind of the crux of who we are and what we were founded to do. Awesome. Garrett, did you have something?

Yeah, The parts I understood of it are awesome. Sorry. Alright. That's okay. So I wanted watch cybersecurity gear. I think that's what he was. Yeah, yeah. No, it was pretty right. I got, yeah, I mean, defer, you know, is, is on the forensic side and ir, but, um, Ryan, you, I wanted to have you on because from the sales side, you're one of the best I've seen in security how you position framework. You are awesome talking right and left of boom with customers.

So tell us a little about yourself and we'll get into some sales conversations with you in the latter part, uh, with Gary. So welcome. Sure. Yeah. Uh, great to meet everyone. Ryan Eclair, uh, currently working at Illumio, uh, Gary, we've met multiple times. Uh, I'm a I I've worked with Tony Williams closely in, in three companies. He always says every time I call him, I'm gonna leave a year later, which has, uh, remained to be accurate. Uh, but huge fan of the methods.

Just as a comment, we appreciate The business. Yeah, we, uh, Good to see you. You too, man. The, uh, the previous company I was at in Terra, uh, which I was in the CEO seat, um, when I started there, we were a, uh, more upmarket MSP, uh, working with, you know, larger financial institutions. Uh, we were in a lot of co-managed situations where our customers were starting to demand that we provide security services. And I will say, I admittedly went about it all wrong.

I did probably what a lot of folks do is, you know, the, the big question I started to ask myself was, is our product dictating our strategy or is our strategy dictating our product? Uh, and and that was a hard lesson for us. I was the typical CEO who went to exchange and a vendor was giving away a car. And I'd be like, well, that looks like a great product. Come home, send it to the account managers, try to throw it against the wall and see if it would stick.

And, and that was our security strategy just open with you guys. We went out and hired a real ciso uh, 12 years in the business, uh, cost us close to a quarter million a year, very, very solid. And he, he turned that all upside down at us. He is a, uh, I still work with a huge advocate of using security framework to sell. Uh, so we adapted CIS controls internally. We then moved those out to our, I know, I know we have a fan on the call.

We then mandated our customers move into the CIS framework. And then we went through the exercise of mapping our product back to those controls. Um, and quickly I realized that we did not fit in the MSP bubble anymore, um, because we were starting to sell up against MSSP. So I did what every security vendor does. I said, we're not an MSP, we're not an MSSP, we're an SSP, and that's an extended services provider. And if an MSP and an MSSP had a baby, that would be us.

Um, so that, that quickly took us to market. The, the final comment I'll make on what got us serious about security, Andrew, was we, um, right before Covid hit, got a call from an instant response firm that asked us to go help do recovery work for a hospital in Chicago. Long story short, a year later we had 80 people doing recovery work, uh, for forensics companies all over the world full time.

When we started getting frontline exposure to what goes wrong, it, it took us two seconds as a leadership team to say, this is no longer optional. And if you don't want it, I wish I could curse on this. I dunno if we can, but get the F out. Like you're not gonna be our customer.

So our go to market in terms of how we address this conversation with our current customer base, and I'll talk later about getting upmarket and landing those security only deals, was here's what we did as an MSP to ensure we're not a liability to you. Here's what we're asking you as a customer, mandating you as a customer to do for yourself to ensure you're not a liability to yourself as well. Back to us, and we did the hard cut about three years ago. A lot of people thought we were crazy.

We sent out a letter and said, if you do not put in E-D-R-M-D-R-M-F-A and segmentation, you will no longer be a customer of ours. Uh, we got over 90% adoption. We lost one account, which we were very happy to lose. And, and that's really how we got it. Get got Going. Alright, Andrew, we got our clip. We got our clip for the week. You can post on LinkedIn. We Do, we do. But Gary In the show Yeah, Gary, but, you know, uh, Ryan's way to sell, you know, is, is, is is kind of home cooking in Philly.

Right? That's how you sell, get There. It's true. I mean, it's, it's, it's true methods framework for security. I, I learned from Gary. I mean, it's, it's basically saying we're selling from a point of framework, not from a point of opinion. And I will say cybersecurity is the last thing you as an Ms. P want to be proprietary on. Not, but you're looking, Ryan, something happened to you that doesn't happen to most MSPs.

If if anyone picked it up, you happen to be dealing with customers who demanded it of you. And as MSPs, not enough of our customers demand it of us. It's, and the onus is on us. So, uh, that was interesting that you said that. Yeah. Yeah. Very cool. So, Wes, let me let you kick things off and, uh, talk to Steven. All right, sounds good. I, yeah. So Steven, so let's, let's talk about, uh, let's talk about DDoS. Um, we, I think we all know what it is at a high level, right?

Bunch of sources hitting us with a bunch of traffic taking us offline, right? But talk to us about like the modern version of this, what's happening around us, kind of what it is beyond that. And you're on mute by the way. You may need to un hitt the mute button. I just noticed that. Yep. Uh, thanks for calling it out. So yeah, at a high level, distributed denial of service really is what you're describing. Uh, but that's really just one flavor of it.

Modern DDoS could come in the form of web requests, IOT devices, uh, printers. In some cases. It really depends on the nature of the business and the victim organization we're talking about as to what is being denied, uh, or, and how that's being accomplished. But in general, it's, it's to level set. It's, it's any time where you using a flood of activity to bring otherwise legitimate systems down, uh, and keep them down for ransom. Okay.

And do you see just an offshoot of that question, do you see, we always talk about how ransomware is not really the threat, it's just sort of like the, the, the end result, right? How do I push pain on somebody to force them to pay up? Do you see an evolution in which, uh, distributed denial of service becomes a mechanism, uh, in, in, in replacement of ransomware? Or do you see it always coming in concert with ransomware? What's your thoughts, uh, on how threat actors may operationalize it?

So generally speaking, the folks that perpetuate denial, distributed denial of service attacks, the threat actors are a little bit different than some of the ransomware gangs. They, they drink from some of the same troughs, but they're not in the same business, if that makes sense. So I, I would say that one is not exclusionary or, or, um, representative of the other, they both kind of exist in tandem and in parallel in the world. Okay. Hey, Wes, can I just interject this? Yeah.

And Steven, you may have seen this in this article I just posted for everybody. What's interesting about it, we did a segment on dark utilities. I'm not sure if you've heard of them, Stephen. Not important. You, you have, and, and you know, obviously it's like this modern day RMM being rented at very low price to threat actors. Mm-Hmm. You can sign up. Wes is a customer. Um, kidding. I am. Um, but this botnet is also being rented. Mm-Hmm.

And so I'm just curious, you know, kind of just dovetailing on Wes' question, I mean, it, it, it, is it a far reach to say that we could see this come down market to, when I say down market to our co-managed customers, per se? Yeah, you're definitely gonna see it in that corporate, uh, mid-market space for sure. That's, that's really kind of the tip of the iceberg in terms of victim organizations that fit a certain profile.

You're gonna see it in like banking, healthcare, uh, transportation, really anybody that has that, that is delivering services to customers that depend on business systems that are communicating with the internet in some way. So we, we've seen it with like transit systems. We've seen it with, with airports recently, right. Utilities, um, and a number of other kind util utilities. Yeah. A number of other high profile victims like that.

But, but those organizations tend to start living and, and culminating in that like corporate mid-market space. Um, so a little bit above SMB, uh, uh, and, and you know, well below kind of that enterprise level and the types of attacks that you see in s in corporate mid-market, uh, firms are a little bit different than what you see in enterprise. There's enterprise are more, tend to be like SaaS companies, folks that are very large, uh, targets that are, that are ripe for that kind of thing.

And, and for obviously, so mid-market firms are often denial of service attacked in ways that renders them unable to respond if they don't already have a security architecture in place that's designed to deal with it. And they haven't asked, you know, those questions internally of their, of their staff and systems. Got it. Got it. So another question, Steven, for you, when you saw the NOS rolling at the beginning, uh, did that surprise you that MSPs have not been directly impacted yet?

And if it does or doesn't surprise you, maybe a follow on question, um, what, what do you think the next, I don't know, 12 to 24 months look like? Do you think you'll we'll see more shifts to Yes. I think that MSPs are being increasingly targeted by denial service gangs that are doing this regularly and professionally. Um, they're, they are however smart about the size and reach of organizations.

So again, you're gonna see it more in like, uh, MSPs that serve mid-market or that serve high risk verticals, right? 'cause they know that those MSPs are more likely to be in a position to need to pay if they can actually successfully bring them down. And that's why it's important for those MSPs to make sure that they have, you know, their systems and, and practices appropriately positioned to defend against it. Okay.

Wes, to that point real quick, so Ron, uh, is it, is it safe to say not safe to say, but Ryan could, I'm sorry, Steven, could you project like Reas, you know, companies that, you know, um, investment, you know, advisors and, and you know, we have a lot of MSPs that even work with, you know, hedge funds and those hedge funds, you know, from an employee count may not be large, but obviously from a transaction perspective, maybe Mm-Hmm. Is that where you could see it maybe down market per se?

Uh, I would say only, uh, registered investment advisors and hedge funds that are operating with some kind of software or hosted component. Um, it's very often those organizations are not as targeted by denial of service gangs. They're more targeted by ransomware actors because they can often collect a large ransom from encrypting a very small amount of machines or data. Data. Got it. Got it. Cool. So I wanna go into that article that Andrew shared, uh, up in chat just a little bit.

It came out just recently. We've known about faja, however you say them, um, since like April. Right. But what stands out to you in terms of their iteration and, and also their growth? Like what, what, what's causing all the growth as well, Stephen? So there's a lot of speculation in this space, and, and I'll share what I consider to be my opinion on it.

Um, what we've seen a lot since a lot of the sanctions and other actions that have come out of, uh, the US government and, and especially with like the Ukraine, the Ukraine conflict, uh, in Eastern Europe, um, going on, we've seen a lot of shell games played, um, in the both ransomware and analysis service, uh, gangs that are out there and operating.

Um, and it's likely that the folks that were involved in FAIA had another brand prior to that, maybe even, they were a collective of several different denial of service gangs that came together to, to orchestrate and grow this. And that's why we're seeing now them operating with impunity because the, the, the legal end of it hasn't caught back up yet with them, right? So they're operating without any sanctions.

There's, there's really nothing stopping people from paying and, and they've come up with a business model now that they can push out to, uh, affiliates and, and get other folks involved in. Got it. Okay. Got it. And it seems like a lot of these, um, especially ones that are like IOT driven, I remember all the way back into the Mariah Botnet, for example, use those reflection attacks.

It looks like, it seems like a lot of, that's hard to stop in the sense of like, you have all these vulnerable iot devices that serve as, um, members of these, these attacks, and they're not patchable and end users don't know how to patch 'em and won't patch 'em. It just seems like this is a pervasive problem that's gonna exist for quite some time, don't you think? It is, but it, but it, it, how you prepare for it and how you address it really depend on the type of organization you are.

You know, if you're like an, uh, a mid-market, MSP, and you're working with most of those like mid-market corporate entities or, you know, in healthcare or another high risk vertical, that would be a target for denial of service attacks.

You really, it just comes down to looking into things like, you know, denial of service options that your ISP carrier has, making sure that you have services like CloudFlare, Fortinet, NetScout, F five, Akamai, you know, something to, to keep you online under, under that assault.

Um, and also things just like, uh, engineering your systems to have multiple, you know, internet connections that are maybe not always used, but you can flip a switch and, and continue operating under those under those circumstances. Those are all really good responses, uh, to that. Okay. And then my last question before Phyllis is looking at that, I'm pulling the poll results back up. It looks like we're at 62% nos as far as being prepared.

Um, what, so other than like, you know, looking at like an Akamai, CloudFlare or something like that that you just mentioned, anything else that you would recommend from a preparation planning strategy perspective, Steven? Yeah. So really it comes down to your, your network architecture and how you're, um, allowing communication in and out of your, your organization.

It comes down to having, if you're gonna have on-premise hardware, co-located hardware, having, you know, firewalls that can fail over with multiple ISP connections, active, being able to, you know, align those actions quickly and, and operationalize them so that you're not, you know, spending days to flip that over or something, right? Have it pr have it practiced, prepped, and ready to go and, and build it.

Just like, you know, we would recommend with security in general, build it with, with that defense in mind, right? That's the, the best thing that any organization that's actively dealing with those attacks directly can do.

And for, for downmarket folks, for smaller organizations, it means, you know, know that you have another option if one of your key providers is denial of service attack, you know, have, have an alternative, have a backup for some of your critical functions so that if it does happen, you're not, you know, out in the cold and your customers. Awesome. Really great advice. Really, really, really, This sounds like this so far.

Sounds like something that would be very difficult for the average MSP to take action on. It's challenging because it requires multidisciplinary understanding of both the security impacts of that, but then as well, the kind of network planning and architecture and not, and not every MSP has, you know, expertise in that particular area, you know? Yeah. Across, you know, 20, 30, 40, 50 different architectures as customers. Exactly.

It's, But, but what's interesting, but what's interesting too, Gary, we do need to think about, I, and I think Steven's getting into this on the tool set side for, for MSPs, because, you know, what if, uh, one of these gusts hits a big, you know, uh, a SaaS provider for one of our major rms or PSAs, like, you know, again, are we prepared, right?

Again, not, I'm not trying to perpetuate fud, but what's our, what's our continuity plan if we don't have, you know, that architecture in place, what are we doing? Do we have offline stuff that we can still function, you know, Well, Andrew, just, And in most cases, the answer is no for core things. What's, yeah, what's that, Ryan, I just said this, this to me is where framework is, is key.

So if you look at, I'm just gonna keep shamelessly plugging CIS all day, but if you look at, they break things into IG one, IG two IG three, right? It, it would be common practice for you as the MSP to say, we are internally going to adapt IG three. We have SMB customers that are IG one, we have mid-market customers. ig, do you get what I'm saying?

So I think the, the thing that MSPs have to start looking at differently because they pose such a risk to their customer environment, is that security stack is not something that can be standardized, which is counterintuitive, quite frankly, Gary, to everything you taught us, standardized, standardized, standardized, when it comes to security, it, it's not all the same.

So it's not uncommon to have multiple MDR, you know, providers, multiple EDR providers do segmentation differently, upmarket the down market. And I think that's the thing to be thinking of is, is looking at, although your MSP could be sitting there with 30 employees, and I understand no one wants to hear, spend more money, but you may wanna look at yourself as that IG three more, you know, mid-market upmarket company from a security posture for you yourselves.

And then take a subset of that down to your customers, Or, or quite frankly, Gary, you and I have had this conversation, Hey, if we were, you know, a decent sized MSP today, would you have multiple RMMs? And we do know companies that do, you know, it's, so anyway, it's things like this that we have to start, you know, considering, uh, in, in an attack like this. Um, A hundred, a hundred percent.

I mean, in another conversation, I, I'll talk about it, uh, about how I look at some big, you know, big MSPs that I'm involved with, right? That have, you know, 60, a hundred thousand, you know, endpoints and definitely giving up some efficiency for security through segmentation or multiple vendors. Yeah. Yep. So, Phyllis, uh, talk to us about nist. I mean, CIS I'm kidding. I'm kidding. I'm kidding. No, that's why Ryan's here. I know, I know. Currently.

I said that's about the happiest I've seen Phyllis since I've known her. That's Right. That's right. Um, so Steven, you gave us some tips on like how to, you know, prepare and things like that. I'm curious on the other side, um, how do you see the best way to recover? What is it that organizations can do, um, to recover quickly? Let's say, you know, you do have all these customers relying on you, you are an MSP, you need to recover.

What does that look like For Well, well, if it, as with most things security related, it's complicated, right? It depends a lot on what you have in place before it comes along. Um, and, and I heard the words business continuity planning and disaster recovery. Uh, and then those things all align with framework, uh, to, to Ryan's point, um, the, the best things you can do are, you know, have those measures in place before the attack occurs. Right? Obviously, that seems really, really obvious.

But as an incident response person that comes in and finds all, all the time, we, we come across cases where people don't have backups that they've tested. They don't, you know, they don't have an immutable strategy. They don't have, you know, EDR or segmentation in place. They don't even have, you know, multiple high availability firewalls. Uh, when, when they're a, a SaaS provider, in some cases, we see it all, right? We see what doesn't work.

So the, my biggest advice is have the conversation at the executive level within your organization before those circumstances happen. That's the best, uh, weapon you have to combat this. Um, and that, and coming out of that will come the conversations about architecture and planning and what, what alternative solutions you might need to have in place or have available and, and how to actually turn them on. Right?

It's, it's one thing to identify them, it's another thing to know, uh, that they actually work and will work in the way that you want when the day bad day comes. Right. Phyllis, can I say something real quick to Ryan Weeks? Wes, you remember this and, and Gary probably do too.

Ryan's uh, uh, at write a boom testing the B-D-R-B-C-D-R at scale and, and how, you know, so really few have done it, or, you know, and, and, and he talks about, you know, so the exponential piece of this, uh, Eric Woodard is masterful right. In talking about this. Um, so it's just, I'm, I'm glad to hear you say things like this, Steven, to, to bring it back to life. I mean, That's mainly what kept coming up in that interview, right?

In multiple things, uh, things they had put in place didn't scale. Mm-Hmm. Right, right, Right. Absolutely. It was awesome. One customer had an issue at worked. Right, right. There. There's something I always say to people about, whether it's instant response planning or business recovery, disaster continuity. If you have a plan that's not been tested, you have a theory, it's not a plan. You hope it works Dar like Darwin. Yeah, exactly. But you know what?

I've heard that over and over again, even from like big, huge companies. Like I always like to, um, talk about the target thing. 'cause I went to a talk for the woman who was on the board, and she was just like, you know, one of the first things they did was they fired the CEO because they had never run through their disaster recovery plan. And when they had to, no one knew what to do. It was, you know, she was like, upfront it was a failure of leadership. Like they were just in shock.

And so it is running through that disaster recovery plan. Um, you know, does your leadership know what to do? Does everyone know what their role is? And, um, you know, practicing that, because you know, when it happens, um, you have to have that training and you have to know what to do. So, yeah. So that's great. Um, Yeah, I always attribute it to muscle memory. If you haven't, if you haven't done it before, you're not gonna have the muscle memory.

You need to actually execute it effectively, under heightened circumstances. 'cause you, it's just not gonna, that's what tabletops are so ex or so important. Exactly. Yeah. So, yeah, really good point. So, Ryan, welcome. I mean, one of my favorite guests thus far. I think your favorite guests, I don't wanna say that We've had wonderful people on here Until now. So welcome.

So, you know, when you're running your M-S-P-M-S-S-P, you know, what were the, um, major attacks that you were dealing with a couple years ago? Were any of them DDoS and, and how did you deal with that? Uh, I'll start by saying I am conceptual. I do not claim to be technical. So if I say anything wrong, leave me alone in the chat. Um, no. So from an attack perspective, uh, we, we primarily started seeing ransomware.

I mean, I don't, I can't remember particular examples of DDoS, um, even in some of our larger client environments, but just a, a lot of ransomware. Okay. And then, oh, I can't hear him. Can you? Yeah, yeah, I can. Yeah. Okay. Yeah. You okay? This will make the interview really fun. It'll, It'll make it more interesting. Yeah. Here's, can you hear us Phyllis? Yes. Can you hear me now? You can, Yes, I can hear you now Ryan. I apologize. Okay. That's okay. Okay.

Um, and so, um, you know, obviously you're a fan of CIS framework, but, you know, um, at the beginning of the call, Andrew said, you are great at, um, selling as well. Um, which I think is awesome, because that's often what I hear from MSPs is, you know, how is it that I can monetize security and how do I sell that? My customers aren't asking for it, so how am I supposed to, you know, sell this to them? You know? Can you give us insights and how is it that you do quote unquote sell security?

Is there any framework that you use? Yeah, so I'll, I'll, I'll take a step back quickly and just paint a picture of massive opportunity for MSPs. So we're on here saying you need to invest more in security. And I want to say that MSPs have a massive opportunity up market in the a hundred to a thousand employees, which is typically avoided. The reason for that is in that space, most companies with internal IT departments are procuring services from both security providers and MSPs.

Uh, and if anyone's ever been in one of those situations, there's a whole lot of uncomfortable and unsuccessful finger pointing that goes back and forth between trying to hand an incident from an MSSP to an MSP. So the, the first thing I would say to you is, you, you look at, um, incident lifecycle and you go from, you know, detection, response recovery, resilience, MSPs and MDR providers where a lot of, who a lot of mid market companies use do not do recovery and resiliency, right?

So they have a disjointed effort. MSPs, bread and butter. Y'all have been doing recovery and resiliency your, your entire existence. So with the right security stack in place, you can sell up market in your pitches that you manage the entire instant lifecycle. As fast as something is detected, you respond with recovery and resiliency. So that for us, uh, started to become a game changer and long term security became our land and IT services became our expand.

We, we kind of shifted it completely because we were able to go in, and this is where I say you can't standardize and the sales process is going to be different. And we would sell one thing, maybe we'd sell an MDR implementation, right? And we were doing the, the resiliency and recovery on the end, and then all of a sudden internal IT department would get fired and we'd easily step in for the IT side of the house. So when I tell a lot of MSPs this, they kind of turn their head to the side.

'cause most folks don't think to go up market, but I, it is so underserved. We still know that 80% of ransomware happens between organizations of one to a thousand employees. And we know there's all these, uh, I'll call it benefits outside people putting pressure on these markets to move. Insurance carriers are putting clear pressure that they expect on the enterprise. Downmarket on the SMB regulators, uh, frameworks are all introducing controls for SMB that are very similar to enterprise.

So step one as always is, you know, do it yourself before you ask anyone else to do it. Implement these controls for you, your MSP to your customer, and then get out there and, and start landing those larger deals, those deals. I like, I love math, but I mean, if you think of selling a security only offering at $67 per user per month at 250 seats, one per quarter, you just change the trajectory of your organization from an MRR perspective.

Where I want to spend time on Gary is where I'll, I'll just put this out there. The markup on the product does not need to be the same of that of IT services. So we have data in the security space with a, we'll call it a good stack that you're gonna see one incident per every a thousand endpoints under management every 45 days. That is very different than a user who's gonna pick up the phone and call and you're gonna get that half a ticket per month and, and things like that.

So that's what I would warn you when you go up market, don't be surprised if your margins are a little skinnier on the product themselves, but any of that recovery and resilience time is gonna be billable. So that's a long way of not answering your question of how to sell it, which I'll get to now. That's fair. In terms of selling security, I would encourage everyone to figure out, very similar to the IT side of the house, what is your introductory assessment for us? Three years ago?

I do not even know if this would still be current. We did that through the form of active directory assessments. Everyone's active directory is s**t and screwed up. I, Andrew, I don't know if I'm allowed to curse on here. You can tell me after that. Oh yeah. That, that's benign. Keep going. Okay, good. Um, and, and that was our foot in the door then to do, you know, a remediation project and then sell some sort of recurring revenue out of every, every one of those projects.

But all of our sales positioning was educational based around security framework. So we put framework first. I will tell you, um, at Illumio, I run our commercial sales team. You know, I've, I've got a lot of folks reporting to me, 80% of our meetings in the 250 users to 2,500 user space, when we ask 'em if they're using IT framework are either saying they're evaluating or they have implemented. Right? So this is becoming common practice.

The internal IT director in an upmarket company has the same frustration that your customers do. Meaning the internal director goes to a conference and gets excited and goes to the executive team and throws another product at the wall, right? So the education opportunity for MSPs around framework to mid-market, I think is tremendous. Do a webinar for internal IT po folks who are traditionally your enemy, right? Who now become your friends.

'cause you're gonna train them on CIS controls and teach them how to talk to their board. So I just, I was gonna say something real quick, Gary, and you, you probably heard, you know, you guys gotta listen to Jim Lippy, who you know, was the first CEO of Thrive and now the CEO of SaaS alerts. And he talks about the MSP time machine, and we'll have him on some point talking about this, but what he's learned as a SaaS company is very similar, Ryan, to what you're saying in security.

And Garrett probably touch on this, where it's like, you know, it's different where if we can get our f our foot in through a, a, some type of security control mm-Hmm. Well, that's what a SaaS company does, right? They land and expand. So it's just really interesting your approach and How you did it. Yeah. I, I, not that I'm supposed to be interviewing, but I, I do think that the security sale is a different mindset, right?

Like, we're just trying to land versus not necessarily always having that perfectly predefined, here's every product, every service. What, what are your thoughts of that as opposed to the IT operations side? Yeah, it's a, it's a different approach. Again, I, I agree with Jim, and Jim and I have talked a lot about this, what you can do and what you're describing is a lot more like a software company operates Mm-Hmm. Right?

So they're looking to get new logos and that, you know, through your process over time, you're going to be able to, um, have, you know, a negative net churn. Yeah. Because you're gonna, you're gonna have those additions and in some cases you may not want the MSP business. 'cause the piece of the business that you have, the, the $10,000 a month you have, uh, uh, that you're describing is at a higher margin with low noise. Yeah. Mm-Hmm. So it may not be as attractive.

You might not even be pushing to get and do the, you know, the support desk for 500 people. Yeah, I, I was gonna say. Yeah. Yeah. So can I just real quick, Steven, you work with a lot of MSPs, is you've seen too the, in the successful ones versus not? Yeah. So what's interesting is what ri the phenomenon that Ryan described really plays out directly that way.

Almost always as MSPs go up market, you know, they're, they're getting thinner margins, but, but also as they go up market, even above that thousand seat, uh, footprint, in, in some cases, they're, they're able to, to get more margin out of it because they're able to bundle with that land and expand additional security services that are equally quiet or, or, you know, not noisy. Uh, and provide them that same kind of efficiency of scale as they rise through the account. You know?

And the difference, the difference here, Andrew, is when you go in the way that Ryan described, you go in like helping them with, uh, controls. They learn a lot about who and what you are and your value. Mm-Hmm. Unlike the MSP business where when you go in and do backup only, or RMM only, they learn nothing about your value. And that's why it hasn't worked in the general MSP. So this is a different kind of sale. Right. Uh, 'cause people say, well, Gary, but you said not to do that. Well, no.

I say only do it if they're gonna learn something about you and the real value that you bring. That's how you expand. Well, and that's, and that's really the, the crux of it. Right. And Ryan mentioned something really important that is a very key distinction within that conversation. The conversation fundamentally you're having in a security sale is a conversation at the executive level or the board level. It it's about cyber risk for the organization strategically.

You know, what, how are these things gonna affect you? Are you prepared? Do you know what they're gonna cost? Okay. These things can help you. This framework will help you understand how to solve that problem. It, it really, it, it's a huge jumping off point of value as Gary mentioned. And as, As Gary, it's awesome. As Gary as we go to you. Like, it just makes me think so much of Brian Blakely because now we can get into business conversations too. Right.

You know, the, the business impact analysis, the critical business operations and, and, and systems that support how you make money. Right. And Listen, it's totally different. As I, like, again, as I talk to so many MSPs and we just had our peer meetings a couple weeks ago, like, Ryan, where you are and you're thinking around this, you're, you're, you're way down the line. Mm-Hmm. And then some people are nowhere. Everybody else is somewhere in between.

And as they go up that continuum, what we see is top line goes up faster. Most of those companies have grown their recurring revenue by 50% over the past two years at least. Yeah. And they're still up 5% NOI for the first three years if we're, Yeah. Yeah. So it's, uh, it's amazing. Well, first off, I, I have a couple questions, but we're gonna run out of time. Uh, Andrew, I, I, can we get Ryan back? Yeah.

Because I think we need, we have more if he's, if he's willing to I've love To, I've got like 30 invitation, so this is great for my LinkedIn, you know, we'll keep it going. Yeah. 'cause I'm not, and I, like, I'm not gonna, I'm not gonna get to too much. So I just want to ask you one, one question that's really important.

The, I think the big, the big issue that most MSPs have when they have to start to begin to sell the right of boom, the preventative, the resilience compared to what they're good at, which is the prevention or the reactive, that's where the, they're having trouble making that. So how do you change that conversation to bridge that gap? Does that make sense? It, it does. And and we struggled with that early on too. Uh, I would tell you, we started relying heavily on our, the SaaS partners.

We did choose to help us with those conversations. That was a huge way for us to learn. And we realized that they did a, they, they approach those subjects a lot differently. We, they, they talked a lot about incident lifecycle, which is honestly a, a very introductory, easy conversation to have. It's like, walk me through it, Mr. Customer, when something happens, what do you do? What happens internally like that? That's such, And they almost never know the answer, right? Correct.

And then we get to go, here's what should happen. Right. So if you, what I would tell people, you cannot get down into the, I think Gary, just, you can't get pulled down into the technical weeds in these conversation, right? We we're staying at a conceptual business level and we're talking about basic, I mean, if you think of security, for the most part, every product you put out there is reactive. So the questions are centered around what are you doing based on the reaction, right?

And, and helping them understand that lifecycle. And then you can easily have one slide that basically, and we used to do this. We, we would show, here's our, here's the vendors we have in this category, and when it comes to recovery, here's what we, you know, and we would just map that out for them so that we're demonstrating them the succinct flow of when something goes wrong, here's what happens. When something goes wrong, here's what happens. Right?

And then, you know, tabletop exercises and things like that. Um, we were one of the few that actually did BCDR plans when I first started at the last company we charged for them. Which I was like, what? We need them to do it, so we gotta, you know, that, that was interesting. Um, but, But they will pay. They, they absolutely, yes.

But here's, Yeah, I, this is where I empathize so much with MSP owners because I am speaking from a perspective of a customer that I know will pay, yet they may service a customer that would never pay. Right. Which is why I encourage people to start drifting up market with security, because you'll find they have a lot more in common than, than your, the mix of your customer base in the SMB space, right.

Where you're having to like convince people to be serious where, you know, if you have an organization, and this was a paradigm shift for me. I mean, I remember, uh, Gary, I started, my first MSPI worked with was Dan ic, right? Yeah. PC Miracles back in the day when I was sitting there doing my a hundred dials a day, if they had an internal IT department, we would pretty much flag them and be like, Nope. Yep.

Hard pass to Now I would encourage, if they have an internal IT department, I'd be like, ding, ding, ding, ding, ding. Like, I know that these guys with their three man distributed team cannot handle every aspect of cybersecurity. Right. So it, it, it's just, I I really feel like it's shifted where those enemies have become your friends. Those are the people. And what's nice is there's so much more available than like the practice administrator of a law firm.

They're people who have their head down in front of their keyboard all day. If they have an opportunity to go sit in a webinar and very Easy to get to, They're gonna come. Yeah. You know, so, and I think we're, you know, the owner led sales right now, if you have more technical owners, like they jive really well with those internal IT folks because they're, you know, they've seen a lot of those same things. So I, I think to your point, you know, you can't get in the weeds.

You, you need to present it as, I would really literally show, here's IT operations, here's security operations, here's our MSP, here's how we sit in the middle and handle both sides of the fence for you. You know, and, and talk to 'em about it that way. Because when you actually, you're not gonna confuse people and you say, okay, so you know, it's very common when a, a company has 500 employees that they have some sort of MDR, maybe they're working with Red Canary.

When Red Canary gives you an incident, what do you do? If it's 3:00 AM just tell me. You know what I mean? And then off of that there, it just presents so many sales opportunities. Yeah. Gary, can I just say something real quick? Oh, go ahead. Go. I was just gonna say real quick, so I put in the cyber defense matrix because what Ryan's saying on incident lifecycle and how there aren't products write a boom. I mean that is the slide.

If you use that and then show where the products sit real quick, you can p piece apart for somebody, for somebody in security up market or the IT team. Right. So anyway, we'll definitely have Ryan. Yeah, Just one comment. 'cause I saw chat that I'm talking a lot about up market, not down market. So here would be my 30 seconds down market for the SMB, the days of suggesting cybersecurity are over, I would love to sell against you if you're suggesting, right.

Because you're gonna get torn to pieces. So the down market play comes back to choosing a subset of proven security framework to determining a subset of those things that map to products that are mandatory, enforcing your customers and not giving them the option like Gary's taught us to sell all along. Yeah, absolutely. That would be my recommendation down market. A hundred Percent. It's not a negotiation. Yeah.

And why I wanna have Ryan back on is, you know what Ryan's discussing up market, a lot of people can learn from that and they're in a position. But listen, if you have less than 15 people in your MSP, you might not be there. It just takes a certain level of scale to get there. But all of those concepts can all be moved down. And the core of how you need to have conversations are the same. The services you offer, what you deliver, what you outsource, that part will be different.

But the concept, and you could almost hear it in everything Ryan said today, and when you can talk in those kind of black and white terms backed by framework, your customers will not say, no, I watch it every single day. It's just that a lot of people aren't there yet. So they give their customers a choice And some customers will always say no. Yep. Yeah, it was awesome. You can hear the certainty too, Gary. That's what sells absolutely as well. Yeah. Super, super happy for you Ryan.

Super proud of you. Hey, thanks, you too man. Appreciate it. Yeah, we'll have you, definitely have you both back. Um, okay. I know we're at the top of the hour plus one. Um, really appreciate everybody's involvement today, the chat as always. Um, and uh, we'll get into a hardcore cyber call around selling, um, with that. So Steven Ryan, thank you Ryan, both awesome today. Thank you. Thanks everyone. Thank you very much for having us. Yep. Yeah, it was a pleasure. Yeah.

Thank you so much you guys. Wes, thanks Phyllis. Thanks Gary. We'll see you all next week by the way. Next week we will have, um, Mackenzie Brown from Microsoft Dart, um, and then we'll see if we can circle back and get Ryan back. So she is our leading our incident response panel at Write a Boom. So until then, everybody take care. Thanks.

Related Videos