Skip to main content
Right of Boom
January 30, 2025

Social Engineering | OSINT & Creating Compelling Sales Conversations

In this video, James, Eric, and Wes discuss the intricacies of cyber insurance and the role of pen testing in assessing organizational vulnerabilities. They delve into the challenges of interpreting insurance questionnaires, the effectiveness of security measures, and the importance of validating cybersecurity controls. The conversation highlights the evolving landscape of cyber threats and the need for businesses to proactively address potential risks through comprehensive security strategies.<ul><li>Cyber insurance questionnaires are becoming longer and more complex, yet they often lack specificity about important security practices like social engineering defenses.</li><li>MSPs are increasingly being approached to assist with filling out these questionnaires, highlighting a need for better understanding and communication of cybersecurity measures with clients.</li><li>There's a growing trend of insurance companies acquiring or partnering with MSPs and cybersecurity firms to enhance their assessment capabilities and reduce risk.</li></ul>

Guests

Andrew Morgan

Video Transcript

All right. Welcome everybody. Week 1 0 4. Somebody's got, Uh oh Echo. Oh, no. Oh no. Oh no. Who is it? Somebody? I'm guessing it's James. Nope, not, not me. I screens something happen there. Anyway, somebody is gone. Browsers open. It's gone. Now let's try that again. Welcome the two week one. Oh, let's do groundhogs Day 1 0 4. Alright, this is gonna be a great one. Um, so, um, let me just kind of set the stage here. First off, there's a poll up. Second of all, welcome everybody.

I hope you are all had a cool weekend. It's, you know, record, obviously high temperatures around the entire nation and the world. I think at this point I'll turn off my dinging and dying in a second. Close all my mailboxes, but yeah, it's only what our hundred 40th call. You'll eventually get it. Andrew. I, I, I doubt that. I think you have high expectations. Gary, I'm gonna send you a checklist, a pre-call checklist. That's right.

Um, alright, so, hey, I, um, before I introduced James, I, uh, kind of in setting the stage, I reached out to James and was talking about the last few cyber call that, um, sessions we had. And, you know, as you guys know, we had one with Eric, um, and an MSP on the liability and potential risk MSPs incur by filling out cyber security or, um, cyber insurance questionnaires with on behalf or with the partners. Last week we started to get into, you know, phishing and threat intelligence.

And to me a lot of that goes a little bit hand in hand because I was sharing with James, you know, are you getting, you know, calls more because of the cyber insurance questionnaires. And we got into this kind of funny conversation where in James' Humorous way, he's like, I don't get it. Yeah, they're getting longer. 7, 8, 10, you know, um, pages.

But the first two ways I'm gonna get into in an organization, you know, if I'm doing social engineering and doing some kind of pen testing engagement, they don't really even ask. So we're gonna get into that today. Um, and, uh, some ways in which, you know, you can create compelling sales conversations. I'll leave that in the last part with Gary, um, and James. So James, it's awesome to have you.

You've done some really proud of in such a short order, you going out on your own, uh, really creating a phenomenal business. Tell us a little about yourself, uh, your background and, and hack it. Yeah, no, awesome. Glad to, uh, glad to finally make it on here. I'm super stoked. We got the, I think we had the all star and probably the most handsome lineup of ever all time on the cyber call. I think, I think everyone's gonna agree with me there. You'll Be here next week as well. Awesome.

Awesome. Oh man. But a little bit about me. I mean, so I started, I mean, I started really hacking before I even knew what it was like, you know, back in 2009, um, two, actually 2006, I was playing a video game called Halo Two. And what I figured out is like I could basically turn off people's internet through a denial source attack. And I was 16 years old and then here I was this punk punk, 16-year-old kid Dawson Colleges trying to win Halo.

And then, you know, when I graduated high school I was like, this is like, so a guy actually came and talked to my college and I'm like, dude, this is a career. Like I can make a career out of doing this kind of stuff. And that's, that's really kind of where it all started, right? I worked as a pen tester, worked my, my way up from a junior to a senior guy.

And then, you know, now I'm kind of more in the role where I'm building a team of really the best pen testers in the world and, you know, trying to help MSP secure their infrastructure, secure their clients, partnering with them and, you know, really trying to, uh, trying to make hackers lose, right? I think that's what we're all trying to do, Right? Yeah. Yeah. Very, very cool.

Um, James, um, what's next on the speaking circuit for you before we, you know, we get going here with you and Eric chatting a little bit. Yeah, no. So I got, I'm doing a channel con in Chicago. I'm speaking on Thursday. I'm doing, uh, okay. When you saw Andrew, how would hack you, which is really good. I had a, they gave me a 30 minute slot. I'm, they're gonna have to like, you know, like speak really fast and drink a ton of Red Bull or cut it down. I'm not sure which one I'm gonna do that.

Um, but it'll be really good. And then I'm doing a, a presentation for Iowa Bankers next week going out to Des Moines. One my favorite cities. 'cause the food there is just absolutely amazing. Um, I don't, they have some dessert there. It's like a Des Moines thing. I can't think of the name of it. The last time I had, I fell in love and gained like 30 pounds. Um, then I'm talking about De Moines before. That's a, that's a new one on me, but, well, I'm trying to think what it was called.

I'm trying to think what it was called. I posted on LinkedIn. It had this really quirky name to it and it was just amazing. It's life changing, honestly. Gary knows somebody that could figure that out Real quick. Gary, can you get on that? I'm sure you, you could get us an answer. Yeah, I'm already texting. Oh, okay. Yeah, there you go. Then we're doing, uh, we're doing the channel pro SMB form in Charlotte next week as well. So we got, we got a good, uh, a good speaking lineup coming up.

We'll be a lot of fun. I'm looking forward to it. Fantastic. Again, thanks for joining us, James. Alright, um, Eric, special guest with us today. Thanks for joining us on the panelist side. Um, quick, uh, intro for you, for those who don't know, and then just jump right on into the questions, if you would. Yeah. So, uh, so thanks for having me back, Andrew, Wes, and Gary.

I really appreciate it and I appreciate even more that I'm sitting on the other side of the table this time and I get to ask the questions instead of be peppered with the questions. So I'm, uh, definitely looking forward to the next hour or so. And, uh, and James, uh, James, welcome. Um, and, uh, looking forward to, to, to sharing some time with you. So, um, and for, for those of you who don't know me, um, I, uh, I'm the founder of Tech gc. Um, I'm an attorney.

I exclusively represent MSPs, MSPs and software companies. Uh, I've been doing it for a really, really long time. Um, for purposes of, of full disclosure, James is a, a client of mine as well. Um, one of my at least top 50% favorite clients. Um, but, uh, but no, I really, uh, I really enjoy working, uh, working with him.

So, um, so to kick it off and, and as Andrew mentioned just a few minutes ago, you know, we've been speaking on the cyber call for the past few weeks about cyber insurance and the applications and how that applies to, to us as MSPs. Um, so James, are you seeing an uptick in the number of MSPs that are reaching out to you for these pen tests?

And is it because of, or, or ancillary to, um, the questions that, that either they're getting or their customers are getting on their cyber insurance questionnaires? Yeah, sure. No, I mean, candidly, you know, like five years ago, I, I think I, I remember seeing the first ever questionnaire, cyber insurance questionnaire from an MSP. Their customer reached out. They were like, Hey, we're applying, I think it was through Chubb, right?

One of the mainline carriers out there, like they wanted, I felt this questionnaire and I'm like, I never heard of this in my life. And they shoot over to me and I'm like, this is actually kind of a cool thing, right? Like they're, they're applying for cyber insurance, they're doing some kind of underwriting, right? Who would've thought they have to quantify risk when you're doing cyber insurance?

So they reached out with a questionnaire and, you know, honestly, ever since then it's been, it's, it's, it's grown our business, right? And, you know, the, the kind of, uh, the kind of flow that we see as a customer needs cyber insurance, they reach out to a broker carrier, um, and that carrier, okay, well you have to do something. You have to fill something out and then look at this questionnaire. And they're like, I don't know what any of this stuff means.

And they give it to their MSP and MSP's like, yeah, you're doing some of this, but you're not doing all of it. And that's where we, we come in as their partner to come in and help 'em fulfill some, or fill some of those gaps. And, you know, I actually, I I share a funny story with you. Last week I had a customer reach out to me and like, Hey, we're trying to fill out this insurance questionnaire and, uh, we think we did it right. Can you look at it?

And for like all the requirements of like training and contest just put not applicable. Like, no, that's not really, that's not really how this works. Like, you just can't, you can't put NA and send it back and, and hope it goes away. But yeah, it's been, you know, we've seen a massive, uh, uptick of people reaching out saying, Hey, what does this stuff mean? Because I don't even know what the testing is. Yeah. What does this mean? And, and how can we get this fulfilled?

So, so that's a good segue to to, to the next question. You know, Mo most MSPs don't even know what it is or what it means when they call you up and say, Hey James, I need a pen test. Go ahead and do it. You know, why is that a, a, a tough question for you? Oh, yeah. It's, it's, you'd think it'd be a blessing, right? It's like, oh, I just, I need hand pass. But a lot of people don't even know where to start, right?

And like, part of it is, is the vagueness in these questionnaires and like the questionnaires from, you know, we get 'em from two ends, right? One's from cyber insurance, which is a lot. The other's from, um, you know, let's say Bank of America is doing work with a, with a marketing company and they say, Hey, here's a questionnaire to say, you know, how are you protecting our customers? Right? The questionnaires are actually surprisingly pretty similar.

Um, but it'll, mostly a checkbox on that is, Hey, do you do pen testing? And you know that, well, if you don't, you have to get, you have to get, and I'm gonna paraphrase a pen test done. So they reach out to us like, okay, well what's the scope of this? Like, right, is it gonna be external, it's gonna be internal, gonna be web application, is there any social engineering aspects involved?

Um, and sometimes like, okay, well if you want everything, do you just want us to focus on the systems that are touched by, you know, let's say they're store credit card data or something like that. You want just on that network or just on those systems. And a lot of times insurance companies just don't really have the answer to that. Like, I've had a customer reach out and they go, well, what do you mean by pen test? Like, what do you want in scope?

And their answer was something along the lines of like, we want, uh, an assessment of the vulnerabilities. It's like, okay, well, which, which, which ones? Right? Like, what part of the network do you want us to test? What do you want us to look at? So it's a really vague question. And um, you know, you get a couple different clients, right? You get some that are like, well, I just wanna check the box.

I'm trying to get away with the least amount of work that we can do, which, you know, are, are amazing. Uh, and then you get the other ones that are like, Hey, we wanna do absolutely everything. We wanna do everything there. Yeah, I was just gonna say, thanks for saying that. Ja. James, is there any chance your battery might be going in your thing? It's really choppy on your audio side, or can you go without it? Uh, just a quick, Yeah, let me, I'll see if I can mess with this. Okay.

Eric, bit Troubleshooting. Yeah, I was just gonna say one quick piece of commentary, Eric, I wanna see your thoughts on this too. Um, is the, I I don't think insurance is really, they're still so control focused. Like, there's still so much looking at like, we wanna see MFA everywhere. We want to see security awareness training, we wanna see managed EDR, all good things.

But I don't think, I think one of the reasons they're just data gathering for pen testing, but they're not doing anything with it. It's 'cause they themselves are like, wait a second, how are we gonna handle an intake of a whole bunch of findings from a pin test that we don't have the analysts to be able to staff and be able to like, determine the, the, the what we should do about it, right? So we're still at a problem where cyber insurance doesn't even have the maturity themselves yet on this.

Don't you agree, Eric? Yeah, Wes, I mean, you're absolutely right. And, and a lot of times they don't know what questions they're asking and, and that's where, but, but you know, we, we talked about this a couple weeks ago on the, on the cyber call. That's where MSPs get in trouble because they'll try to interpret what's being asked and, and they will in good faith answer what they think is being asked. But maybe that's not exactly what the insurance company had in mind.

So what I'm encouraging my clients to do is push back, right? If it's vague, push back. If you don't know, push back. Don't guess that that is the absolute worst thing you could do is guess, put an answer down and then all of a sudden you've got another traveler situation where they wanna deny Coverage. Yep. And I, and I think it's really important. Wes, great, Greg, really glad you brought that up.

And Eric, you didn't say this up front, but I think it's really important for people to know, um, you're not just an attorney. You owned an MSP, so you can see this from both sides and the liability that's at stake here. Yeah, no, definitely. You know, there were, there were not many, many nights. I slept very well as an SP owner, you know, for, for these very reasons. Uh, you know, there they're at MSPs are being asked to take on a ton of liability.

Um, and this is just one more arena where, where that happens. Um, and, you know, that's what my job is, right? I I, I coach my, my MSP clients through, you know, you, you can't get rid of the liability, but, but, but how do you mitigate it? Um, and, uh, you know, don't be afraid to, to ask the questions. Yeah. Yeah. I, that's the wise advice right there. Push back. And James, I see you're still on mute.

I don't know if you're that it worked out or not, but that's the right advice there is push back, ask questions, get clarity. Don't guess. I saw an insurance application the other day, they reached out to me on, and they put windows, uh, I think I windows 2008 for their managed EDR. I'm like, no, this doesn't work. This Doesn't work at all.

You know, like you've seen we that the majority of a big percentage of MSPs, they're still not having a cyber insurance conversation with every one of their customers. And to me, what that means is what the risk is, you don't want to be having these conversations after your customer comes to you. Yeah. And you're putting, and and I'll talk about it with James, but then you're put into a bad spot of why weren't you having some of these other conversations. Yeah, no doubt. Time. Doubt.

I mean, Gary, oh, I was gonna say, Gary, I can't imagine if you owned an MSP today and you know, the boiler room, if you could talk about BDR real quick and how you look at that. I mean, you guys would be like, that would be maybe one of your openers, correct? You know, in your top, in your warm two 50. Yeah, a hundred percent. And it's, it would be the reason why someone would meet with you. Um, it's a reason why they would make a change, which is not an easy thing to get people to do.

But it's also the reasons why my customers would be paying a lot more today. Mm-Hmm. Yeah. Time. At the end of this call, let's do a quick role play with Gary and, and have him sample for us how he would message cyber insurance in a pitch. 'cause I think that's really important. Yeah, I think I got that, James. Let's see. See how you, how you, so now Yeah. Is this better? Way better, Better Thousand times. Yeah. You know, you know what it is.

It's like, it, it probably sounded a lot robotic or whatever. That's like my alter ego coming out, believe it or not. Like, sounds like that. So James, diving on, diving a level deeper into just a generic pen test question, right? A lot of times on these insurance questionnaires, they, they talk about security awareness training or phish phishing simulations or, or, or something like that.

But what are they missing in, in, in terms of what are the important pieces that they aren't asking for that, that we as MSPs should think about? Yeah, no, there, there's a, there's a good amount, right? And like, when I think about it, you know, and the question as I've read and what I've heard from people that are applying, it's, you know, the concern is, is on the action, the concern is on the result, right? So they'll ask the question, Hey, are you doing x? Are you doing Y?

But they're not really concerned with, is it effective, right? So for example, I'll read, I read an insurance questionnaire last night and it was like, Hey, do you do fraud training? Okay. And it was a question like, well, what is fraud training? Is fraud training? Are you talking about anti-money laundering? Are you, you know, are you talking about cyber, are you talking about employee awareness or are you talking about social engineering?

Um, and they're never really, okay, well, if you do, what are the results? Do you test to make sure the trainings are effective? Do you do phishing campaigns against your employees? And if so, right, show us the results or the level of improvement over the past two years, right? Is it effective and not just, are you doing it, is it effective? Like when we like, as like cybersecurity practitioners and professionals, that's what kind of we're focused on, right?

We wanna know is the defenses you have in place is everything you're doing to protect your employees is effective. Um, and for me, just from what I've seen from the cyber insurance, uh, perspective, that's hasn't been a, a pressing item for them. Yeah. Yeah. What about, it's getting choppy, we're getting from the audience. James, is there any chance you can do it with it? I would say he's a young guy. Maybe we should just text with them. Yeah. Is it, is it the dial up modem?

Maybe that's causing the problems. 1200 Bo Thanks guys. We, we appreciate you bearing with us. Let's see if we can, uh, Is it it better at all? I changed the two. A different outage. Yeah, so far so good. Oh, Sorry. I'm using my webcam mic now. Okay, let's try that. All right, we'll try that. So, so James, last question I have for you.

And, and, and I don't wanna put words in your mouth, but, but my understanding is that if, if cyber insurance is going to come into play, meaning there's been some sort of a, a covered security incident, a lot of times it's gonna be caused by a social engineering issue, right? But I don't see social engineering questions that much, um, on cyber insurance applications. So what are your thoughts there in terms of what you see, what you think they should be asking for, what they're asking for?

Um, just curious as to your thoughts. Yeah, no, I mean, you're a hundred percent right in the fact that it's not being asked. And, you know, when you think of social engineering, it goes beyond just phishing. You know, we're talking about phishing, we're talking about smishing, which is the SMS phishing. The, the big uptick we've seen recently is phishing based on social media, so like LinkedIn phishing.

And what we're seeing is that as, as, um, spam filters get better, as those protections get better, attackers say, okay, well if I want to send someone a word macro or an Excel macro, it might not get through spam filter, but I can probably send as attachment on LinkedIn or Microsoft teams or you know, Instagram or you name it. Um, so even seeing that becoming a big issue and in terms of our cyber trends questionnaires focused on that, absolutely not.

Um, in terms of, you know, kind of piggybacking what I said the last question, are they concerned about the effectiveness of training? Right? Does your training program have the elements to train against smishing against phishing against everything else? Not really, right? It just says, do you have a program?

Um, so, you know, I think in the next couple years you're gonna see, especially LinkedIn phishing, like we've seen cases of just doing forensics of, of, uh, people that, you know, fake recruiters reaching out and doing all sorts of things like that. It's, it's really, Eric, it's really interesting because, you know, when we talk about, like, we've had, we've talked about control validation and things, and it's like, yes, you could have that control in place, but is it doing what it should do?

Which then gets oh, yeah, the actual simulation, you know, getting into adversarial emulation. It's really, you know, Wes, it's, it's interesting where this could be heading, isn't it? Because the Yes. No questions and even validation of telemetry. Yeah, it's on, okay. Big deal. Yeah, no, I, no other commentary other than agree. Yeah. Cool. Eric, you have any, any others, any other thoughts and, and or questions on your side?

No, I, uh, I, I think what, what you have to say, James is, is great, right? And you know, to me it, it blows my mind that, that the insurers aren't asking some of those results based questions. I, I think if I'm an insurer, that's what I wanna know, right? I don't want to, I don't know if I do care that you had a pen test, but that's not the only thing I care about. I wanna know what, what came of it. And, uh, and no one, at least no one that I've seen is asking those questions.

Yeah, no, I mean, I actually had a, a couple weeks ago, it, it was a couple months ago, I had a customer that was filling out insurance questionnaire, I think it was an insurance or a vendor questionnaire. And part of that questionnaire was, uh, performing a pen, two different pen tests two weeks apart, right? So you do one week, one, you give 'em the report, they wait till two weeks and you do another one.

And me being, you know, who I am, like, okay, cool, they're probably concerned with, you gonna do one, you're gonna remediate and then you're gonna do the other one to prove that the remediations were successful, which is what we do all the time. They actually reached out to the insurance vendor and they said, Hey, like, do you want remediation? Do you want anything? They go, no, all we care about is there's two scans that are done two weeks apart. Yeah.

They check, all I want you to do is do, yeah, check out. All I wanna do is scan week one, we're gonna do absolutely nothing with it and do a scan week three, and then we're gonna give it to the vendor. We're gonna give it to the insurance company. And they accepted it, like, yeah, you're good to go. You did what we wanted you to do.

And I'm like, that's just, so, it's almost criminal, like how, like that they're not requiring like, show me proof of remediation, show me proof that, that everything's affected. It was just, it just, honestly, it kind of blew my mind. Yeah.

It's, it's a horrible situation right now because insurance is, is grasping at straws on how do we measure, you know, they, they're doing questionnaires, they're data gathering and, and even to answer some of the questions in the comments, like, you know, off ball questions that they put in there. At some point, some questions in the questionnaire are decision criteria questions, other questions are just data gathering. And so they're still trying to gather this data.

And one of the things they, I guess they've been convinced on is that, and I'm just gonna call names out like the BitSight, corvus, security scorecards of the world, that they have their place as a vendor. In my very opinionated stance, they don't have a place in measuring your cyber insurance applicability because all they're doing is they're looking at external stuff like, you know, hacker cadence, external osint stuff, which we'll get into.

Like they're just looking at high level stuff and oftentimes they're not even looking at the right infrastructure, or they're looking at a tiny percentages publicly facing, and yet they're making in like decisions on this. It's a really bad situation for them right now. It's not gonna, if they keep going that direction, it's gonna get worse. Not better, that's for sure. Yeah, good stuff. It's almost like we forget, like as MSPs, our commitment is to the customer, right?

First insurance company second. So we're talking about how we have to deal with this with insurance companies, but ultimately, you know, we've been talking about the fact that every customer needs to understand that they're living in an assumed breach world. And the real risk here is actually to the customer and their business. And I, I just feel like sometimes we, wes we go at it the opposite direction. Yeah.

We, we do Gary, because we're afraid of like, what does that world look like if I don't have a claim, if I can't make a claim on something that happens, or a subrogation eats my business alive. So we look at it from that defensive viewpoint. You're right.

And I do think, I, you know, I talked to MSP after MSP and those that are security framework aligned and mature around this, they're the ones that actually don't struggle as much with putting this, the, the insurance puzzle pieces in place because they find, oh, we're already doing a lot of this. If I can pick someone out. I had a great conversation with Eric Woodard, uh, MSP, um, that's been on the cyber call before, and they are now very close to completing IG two for all of their clients.

And so when you talk to him about the cyber insurance hurdles, he's like, yeah, but we're comfortable with this because we've already brought our clients down this journey in a really mature way. And so I, I agree, Gary, But he's the exception to the rule. I mean, I looked over some of his packaging a, a, a month or so ago, and he has yet another defined role that he has in that he sells and, and, and can get value for around it.

But, you know, we spent time together last week, Wes, you talked to a lot of MSPs just like me, more than not, are a long way from home right now, right? Yeah. I had a conversation, and Wes I'll kick it over to you after this, but it goes in line with, I was talking to Brian Blakely on Friday afternoon, and you know how he talks to customers and prospects.

His, his, he comes out of it almost like all the time, like a mini tabletop, you know, he talks about how they make revenue, okay, if these critical systems that support your revenue functions were down, what would it mean? Right? What would it mean to your organization? What people would it impact? What customers would it impact? How would it impact them? Did it impact SLAs, contractual, and, you know, like, are you contractually now in trouble?

Like he walks through all these business side of things and then layers in controls and obviously around how the business runs. Uh, there's nothing, like, I'm telling you, I've said this before, Andrew, when I heard Brian do that at Write a Boon, I mean, such a mind opening experience to hear that, to think that is the direction of conversation we have, because that takes us past it and into risk alignment, which is the most critical thing for us, right? Uh, totally love it. Yeah.

So, uh, James, I'm at the beach, as you can see, wonderful place. And who doesn't want to talk at the beach about open source intelligence, right? This is a very common thing. Very regularly, people walked up. I will be literally right out there as soon as we're done with this, and I guarantee you two or three people come up and wanna talk about Osint with me. Yeah. Right? So let's talk about this for a minute.

We, we, you know, we know Osint is, is definitely helpful in some ways in defense in our organization, right? A lot of times if you get what you pay for it, right? So it's free, it's noisy, it's not always very tailored. It goes stale Really quick, we know that. But one of the things we don't talk about a lot is how bad guys use scent. Can you kind of give us from a pen testing perspective how a threat actor would use open source intelligence? Yeah, for sure.

So, I mean, if you've ever been to, uh, any of my talks at trade shows, I always like to, I always explain to Osint, like I'm a, I don't watch TV a whole lot, but there's one show I love, which is called you, it's on Netflix. It's what this guy, if one of you guys watch it, Joe Goldberg, um, he essentially uses osint to stalk potential, uh, love interests. And then at the end, he ends up killing them, which of course we don't, we don't kill anyone.

But he stalks them, finds out what they're interested in, right? And then he uses that to kind of play a persona to, you know, befriend them and do all sorts of things there. That's really, you know, how criminals use as well. And that's, honestly, we use it exactly how criminals use it. Like when we assess an organization, we want it to be as a real world as possible. Um, but, you know, just some things that, that we've done. I mean, like, uh, there is an MSP that we worked for.

This was, this was earlier, uh, this year, and they were using, I don't know what solution it was, but it was a password reset solution that allowed security questions to be answered, to reset the password. So we found someone that worked there, they were young, they were, you know, just outta college 22 years old. And, you know, typically, you know, fresh outta college students, they're really big on social media platforms. I don't even know half the platforms they use now.

Like I, I always like to think, I know it's like VSCO and all this crazy stuff. Like I, I don't, I don't know, like new stuff pops up all the time. Um, so we go on there and we're looking around and I'm like, all right, lemme see what her questions are. Do we reset her password? And I was like, what's the name of your favorite sports team? And like, what's the name of your dog?

And within like 15 minutes, I was on her Instagram and I found a picture of her with her dog dressed up in Alabama jersey. And I was like, oh, hanging with my pal Spike hashtag roll Tide. And I'm like, okay, well let's look at these questions. What's the name of your dog? Spike? What's the name of sports team Alabama? Right? And just like that, I was able to reset a password. Um, and this stuff happens all the time. And it's not just, you know, password resets.

When you think about targeting someone with a sophisticated spearfishing email to get, you know, a macro in and get a Cobalt strike beacon running on that machine, you know, you gotta do your research, you gotta your homework. Like if you find an executive that went to Cornell and they're part of a fraternity and you know, they donate a lot of money, um, you know, that's all really good information you can use to some like fake newsletters or donor appreciation events.

And hey, here's the agenda, it's a PDF or a Word doc and you download it. Um, that's exactly how attackers are using it.

And you know, even like, especially like with the social media related phishing, we're seeing this more and more and more like, I mean, I'm part of a bunch of different Facebook groups just on my interests, and it's amazing to me how many people are scamming people, like just straight up scamming that out of money, getting PayPal based on like, oh, I see you're selling this and you're from this town. I'm from this town too. Oh, do you go to this diner? Oh, me too. Right?

They're befriending them, getting that trust, and they're using, Hey, I wanna buy it, but I'm out of town. You know, we can meet up in two weeks. I really need it today. Can you ship it to me? I'm traveling. This stuff happens all the time. Um, and they're getting better, right? They're only getting better. It's, you know, it's really kind of a, you know, a race almost an arms race of who can get better first, is it gonna be the attackers? Is it gonna be the defenders?

And as one gets, you know, as one increases, the other increases always a race. Um, but yeah, we're seeing, you know, for scent, I mean, it's the staple of every cyber service that we offer. It's a staple of every criminal in their offerings as well. Yep. That's a good point. When I used to teach, I used to teach, um, college classes in, um, cybersecurity.

And, uh, one of the things I would do in my network security course, we were doing like a lot of the offensive stuff is I gave my kids a project where they had to pick a public company and just do open source recon. So I'm like, you can't do no port scans, no connecting to them. But anything else short of that is fair game.

And so I make them, it's like a two month long project, and it's astounding to see some of the data that you can gather on a company, let alone an individual when you, when you focus on that, right? And we all know we have things that will all yolo click on, right? Like, you could send me something about crypto that's really enticing, I'm gonna yolo click. You send something about a boat to Gary, he is gonna yolo click. Like we, we all have our weaknesses, and that's part of the human element.

So I totally, um, agree. I definitely agree with all that. So, um, my, my other question for you, James, was, um, I love analogies, and I've heard you use this one before, and I just wanted you to like share it more broadly on a cyber call today is this analogy around, um, you know, the scrutiny that we put through in life insurance. You know, what's your age? How much wine do you drink, how much do you smoke? What's your health history?

We look at all this stuff, you know, to really make a decision based upon, you know, what are we gonna do for this potential, um, client around life insurance, right? But cyber doesn't seem always the same way. Can you kind of share this analogy a little bit deeper with us? Oh, for sure. Yeah. No, this, this might, this might be an answer that's all over the place just because it's, it's something I have a lot experience with. I have a lot of friends and relatives that do insurance, right?

And they sell insurance. So I'm, I'm familiar with that underwriting process. And really when you think about it, at the core, it is an underwriting issue, right? So for example, if I go out today and I call Prudential and I say, Hey, gimme a 5 million life insurance policy, the first thing they're gonna do is they're gonna say, we gotta assess this guy's risk. And what they mean by that is, how likely is this guy to die before his life expectancy?

So they're gonna go and do a blood draw and a physical, and they're gonna say, okay, James Carroll, his arteries are full of, you know, big max sauce and IPAs. He is gonna be, you know, he's, he's a huge risk. Like, I don't see this guy making it past 45 and they're either gonna decline me or they're gonna mark that up. Um, and you think about it, right?

When you think about like, okay, the average person with life insurance with a 5 million hour policy, their chance of dying before life expectancy is probably pretty low. And the amount of scrutiny they put you through to get that compared to a cyber insurance policy where if you want a 5 million cyber insurance policy, you fill out a questionnaire and your chance of collecting on that within the next 10 years are a hell of a lot higher than a healthy guy dying in 10 years, right?

So when you think about it that way of, okay, what's their chance to collect, what's their chance of actually utilizing this policy? It's so much greater in cyber insurance, but yet the underwriting compared to other lines of insurance, like, like life insurance is so less rigorous. Um, and I think it's something that I read a, I read an article, it was like, for every dollar cyber insurance companies bring in, they pay out like three or $4.

And you know, I think, you know, at the end of the day, it comes down to a risk and an underwriting and, you know, a lot of it's resources, like for example, life insurance, they have something called the, the, the m it's the me, MIB, the Medical Information Bureau. So that means if I apply for a policy today with Prudential, then next year with Northwestern, they actually store all the answers to my questions in this database that all insurers have access to.

So if I lied on one and didn't lie on the other, they're gonna come back and say, Hey, James, what's going on here? You answered differently on these two different applications. They all work together to help underwrite that risk. I don't believe anything like that exists right now in the cyber insurance world, but if it did, right, I think it would provide a lot of valuable insight into who's secure, who's not, how can you properly underwrite this risk?

And cyber insurance does serve a huge business need. I think it's something we need. Um, so I think it's really something that needs to get a, a handle and a grip on to, to help reduce, you know, the amount of, the amount of claims that are being processed every single day, Wes. Yeah. Well, I mean, the big variable there is that the, uh, actuary tables on death are pretty accurate. Yep, yep. Right.

Wes, what's interesting, and I was, I was speaking of a very large insur insurance company in the top 10, and they were saying, this is being driven by, by the reinsurers, more so, right? Because they're not used to losing money. And it, do you think part of the nebulousness of the questionnaires is they're, it, they're another step removed. They're just like, Hey, start throwing stuff at this and, and, and get us better information to reduce our, our risk, the, you know what I'm saying?

Yeah, yeah, for sure. I mean, the reinsurers and, and I'm still, you know, I'm, I'm not an agent. I've only been playing around, I call it am in the insurance space for just some time now, but yeah, the reinsurers are the ones that insure the insurers, right? And so, uh, I, I can guarantee you there's not a lot of depth of discussions around cyber hygiene and maturity that exists between the carriers and the reinsurers, I'm sure of this.

And, uh, I also think that, um, you know, there's one metric that they look at that they care about the most, and it's loss ratios, right? Right. And so if you have it, it, it's very simple for them, right? If you have loss ratios over 15%, you've got a bad product. Um, and so with cyber insurance at, you know, somewhere between 60 to a hundred percent loss ratios, like James was saying, um, this is not good. And this is why you've seen that pullback, right?

And you've seen erratic decisions that happen, uh, from all of this. I can just tell you, we've talked carrier after carrier, and some are like, we're just pulling outta this particular industry altogether. We're just doubling our, our quote premium for this industry, right? Just because of these knee-jerk reactions that exist. And so, um, yep. That's what we call a hard market, Andrew, is exactly what you described, and that's what we're in the middle of right now.

You take a look at Beasley, for example, I don't know if many people know Beasley doubled their revenue this past year. The reason they doubled the revenue is they doubled their rates. Uh, and so you're seeing this, I mean, it, it, it won't double forever. It won't just continue to double. Um, but yeah, we're in a tumultuous erratic market right now. It will not be Solved. So lemme ask you a question. They're pretty smart and they have a lot of math, and they're doubling their rates.

Um, we're in the same boat as MSPs. Why aren't we doubling our rates? I wondered if you'd go there. I set you up, didn't I? I knew that was coming, But you're right, Gary. You're right. I mean, because they're saying the same thing. Hey, threats are going like crazy. We're not gonna just continue to do this at a loss. We can't. Right? So you're, you nailed it. Yeah.

Why are the same customers that are allowing their insurance companies to double and triple the rates not allowing us to, and we're the ones that are actually standing between them and bad guys. It makes no sense. Yeah. Yeah. As I Like to say, good god, man. Yeah. Yeah. Yeah. And isn't it a confirmation bias, Gary? 'cause we're used to, if an insurer says, Hey, your roof insurance, because we took these losses 'cause of these hurricanes, so we're doubling, you know, insur home insurance.

We just, we do it. But if, you know, as MSPs, we have too much, I think a lot of times our own as people in general, not just MSPs. We have our own Head. So listen, as a group, MSPs are so afraid of increasing price or value to, to their customers. I, I'll, I'll let, we was hysteric a quick story about, uh, when, about last week at, uh, at Build It. Okay, cool. So James, here's, you know, I run into, can I just say this? I, I don't have a lot of respect for a lot of PIN test firms.

I just don't, and you, you're an exception to that, right? Because I run into a lot of them and I can't, it's very difficult for me to truly measure what's their quality. What are they doing? I've engaged, which I won't name them, I've engaged firms in my bank before that I was just very unhappy with and the quality of what came out of the report. And I'm very frustrated because I'm like, you, you looked like you lined up.

And even in my technical interview that I did with the PIN testing firm, I thought I, you know, I thought you guys were much more mature than just checking a black box in my network and running a bunch of automatic scans, right? You, you claimed all this manual stuff that you would do, and clearly you didn't. I see this all the time. It's really frustrating.

I think one of the things I look for from a PIN testing firm is they actually wanna dive into the hygiene a little bit of the company even before they engage. Do you guys do that? Like, do you, you know, someone says, Hey, I need a pin test because my third party's requiring it. Do you actually jump into like, well, what are you guys doing about like, patching and, and all the things around? Like, do you, do you dive into a lot of those questions prior? Yeah, for sure.

And it's always, it's always kind of funny, right? Because I, we, I used to have this running joke with, with a lot of the guys that used to work for me is like, like, Hey, I'm the, I'm the kickoff. I'm the scoping call. The moment you on the call that comes the first 10 minutes, you can figure out what that GIE is, right? Because you start asking those questions like, Hey, what are you doing for patch management? You know, what are you doing for, you know, higher fire? Right?

What are you doing to make sure that people can't get in the network when they're not supposed to? And a lot of 'em, you know, they just, they just don't, they're like, oh yeah, we, you know, you know, for example, what's your s layer on critical vulnerabilities? Well, they have to be patched within 15 days. Then they go on there. I'm like, Hey, this is like MS 1701 oh, which is from 2017 and it hasn't been patched. Like, what happened?

Oh, well, you know, we had this exception and we're doing this. And you hear that kind of stuff all the time. And you know, I'm gonna touch on your point about, you know, pen test companies not doing what they say or they're supposed to do. You know, part of me, and I'm a little bit of an optimist here, part of me blames the company, but part of me also blames the industry because there is a big lack of formalized methodology within pen testing. Yep.

You know, you can go to us and get a pen test and you can go to some other company, get a pen test, and on paper, right, it looks 80% similar. But when you get the report, it's completely different. Right? And you get, you know, you're gonna have the companies out there that, Hey, do pentest and just do a s scan, kick you the result. That's always gonna be out there.

But, you know, even going deeper than that, like, you know, what are some, you know, you know, there's the PA framework, there's the Lockheed Martin Cyber Chill Killan, there's Mitre attack, right? They all serve different, different niches in the industry, but, well, which one can we adopt? You know, like I live in New York state and we have car inspections. If I go to, you know, one place in another place, that inspection is going to be exactly the same.

'cause a formalized process and methodology that's followed. And I think until there's a widely adopted one in pen testing, that will always be a problem. Um, you know, we're, uh, just us as a, as a company, we're always trying to be as thorough and as methodical and, you know, creating a repeatable process as we possibly can. But I can't say that every other company's doing that, which is, I think why it's such a huge problem. I agree. Uh, really wise words there.

I wanna see Mitre work towards, I'll just pick them out. 'cause they'd be the perfect organization to work towards a, you know, a true, um, uh, framework, right? So I select the inputs of what I want tested in scope, and then I follow this framework, and then I should get these kind of outputs that come from it. Man, that would be great to just have a universal taxonomy. Like I totally agree with you. Yeah, for sure. Even like, like for example, an internal pen test.

Some people will say, okay, well, it's just patching. Can I exploit vulnerability? Some people say active directory involved, right? You know, and like, just in terms of scope, like what are we gonna include? Is that a separate service? Is that, is that part of that service? Right? There needs to be some kind of formalized process and really just adopted methodology and services of, Hey, this is what this contain, this is what this entails. Yeah.

Last question, James and Eric, I actually want you to chime in on this one too. I, I've already put you on the hot seat once and put you back on the hot seat again. A second time Beginning. I'm off the hot seat. Yep. I mean, you can't get off it, my friend. Let's talk about m and a for a little bit inside what we're seeing in the insurance circles, right? So we've seen companies, for example, I'll pick out my friend Chris Laer, right? IR firms that are doing right of boom activities, right?

Incident response, those kinds of things we've seen like CSC acquire solace to extend that capability of ir, ir, uh, or other right of boom kinds of things, response, recovery, all that. We're also seeing sometimes firms even purchasing MSPs, which I think is really interesting around like left of boom things, you know, identity, uh, protect and some pieces of detect, right? And so why are we seeing that? Any thoughts around what's happening in that m and a space?

Are they just trying to like solidify the supply chain that they have ownership over? Or what do you think is going on with, with all that? What are your thoughts? Yeah, so, uh, the, the short answer is yes, I am seeing it. Um, I'm seeing insurance companies acquire MSPs, um, MSPs for that very reason, right? To, to get to the results that, that James was talking about. Um, because short of filling out a questionnaire, you're never gonna get there, right?

If instead an insurance company can send in its own MSSP, um, into a, uh, either a, a potential insured or a target, um, that's how they get comfort, right? And, and that's how they can frankly make money and set fair premiums, um, by having that information. So, so yes, I, I do see it. And James, same Question. And Andrew, we've seen it, right? Oh, go ahead, Gary. We, I'm so gonna say, Andrew.

We've seen that, we've seen examples that people have sent us right about their insurance saying, listen, if you want our policy, you also have to add these services on. They're another five or 600 bucks a month. And it's pretty compelling, right? And hard for an MSP to deal with. Yeah. Well, look, I mean, I think the harbinger for this is probably going back five years or so when Aon bought, you know, a massive MSSP called Strass Freebird. I mean, so we're seeing it.

We've seen it up market now, we're starting to see it come down market. And Gary, you've talked about many times we're early in the inning, you, you think we're early here and there's still, you know, recession aside, there's a lot of money out there looking to find homes. Is it fair? Absolutely. There's a lot of what I call dry powder, uh, still out there. Yeah. Interesting. Yeah.

So, Gary, Gary, before I, or I turn it over to Gary, I just wanted James, your thoughts on that whole, what we're seeing in the market as well between all that and, and you, I mean, who knows? Hack it cyber could even be a source of acquisition from, you know, an insurance carrier, IR firm, something like that in this whole, uh, sphere, right? Yeah, I mean, for sure. I, I definitely see it in the realm of possibility, right?

In terms of, you know, like, you know, the way I think of it is, you know, basically they're gonna outsource their underwriting to a pen testing firm. Like what's the true risk, you know, at the end of the day, how susceptible are they to being hacked? And, and you know, the, the answer to that is, well, we don't know until we try to hack them, right? Um, so I could see that happening.

You know, the way what I see might happening instead, or maybe sooner than that is, uh, is, is, uh, uh, insurance companies partnering with offensive security and pen trust, pen testing firms to then do that. Like, if I draw that, that comparison back to life insurance, insurance companies don't own nurses. They basically outsource nurses to like, you know, port a medic and all these other places that come to your house and do all the stuff.

Um, then they have their own guys that, you know, pull the matter records. So I think that might be, you know, to an extent, maybe more cost effective way for them, for them to do that. That, but I wouldn't, I definitely would not put the acquisition of, of offensive security consulting firms outta the realm of possibility.

The thing that's really confusing to me is like, a lot of these big companies, like you look at State Farms and the axes of the world, they have their own internal red teams, you know, they're in a different business line than, you know, the insurance offering.

They do internal policies and controls and things like that, so they have that ability, but it just seems like they haven't, they haven't blended that, okay, well, let's reach out to our internal resources that know a lot about this to say, Hey, how can we help? And how can we, you know, really, you know, assess this risk better? Um, which is really interesting to me. Yeah, you're, you're getting me thinking because, you know, we have CVSS scores for vulnerabilities, right?

I think I can see why a cyber insurance firm would, it's not antitrust, it's not like cornering the market, but I could see why they'd wanna standardize with certain PIN testing firms that say, Hey, we know what you do. We've interviewed you, we understand your skillset, and these are the inputs we want from that test. And so, you know, mm-hmm. Just like we've standardized vulnerability scoring, what if we could standardize some of the output scoring that a PIN test firm could, could see?

We have to really work through and think through what does that look like? But I think there's a lot of value in that, for sure. Yeah. Why, while you were, while you were talking to James, I already texted a few people and I, I raised like $3 million for us to work on that. Wes, Let's go do it, baby. I'm all in. It must be nice to have those kind of connections, you know, like, I, I just, Gary, I don't have that kind of juice. You know, When Gary, when he calls you pick up Gary.

Gary, before you start, um, I'm gonna just put in a, a question here for James to see from Sonny. It's kind of like a living off the land question. I threw it in a chat. But, um, you know, do you think there's a correlation, like, you know, for example, you know, obviously we, you know, we've heard a cobalt strike, which is, you know, was a, you know, commercial tool.

Um, is there some correlation here or is it more automated, you know, scanning, you know, like they're, they're, they're doing more bot type work. Talk to us what your thoughts are on that. Yeah, sure. No, I, I think it's mostly, you know, I think that, I think it's phase, right? I think for the most part, attackers use automated scanning and enumeration to find the targets, right? So Google Dorking, right? Things like that to find the low hanging fruit.

Once they find that and they move it over to the manual and say, okay, let me now go in here and try to get, you know, a cobalt strike beacon or something like that. So I think it's a blend, and I think it really depends on the different, uh, the different type of hacker, right? So like the ones that are going after political interests or things like that, they're gonna be a lot more quiet. They're gonna, you know, like, you know, the supply chain attacks, they're not gonna wanna get detected.

The majority of attackers are just, you know, hitting websites and brute forcing credentials all day long. And they don't really care about getting, getting picked up and credit to 'em, because a lot of places won't pick that up. They just don't have the monitoring and tools in place to do that. Um, so I think it's a blend, you know, and we're seeing like, even like Cobalt Strike is still a very viable tool.

It's something that we use as well as hackers use hackers, of course, use the craft version of that. We actually pay for it. Um, but there's other frameworks out there like Brute Rotel, which is, you know, a competitor to COBAL Strike now I think it's made in Poland or some, or some country in Europe. But, you know, that touts antivirus evasion, which is something that, you know, cobalt strike, how the box doesn't do well.

So they're always getting better tools and, you know, perfecting their trade craft. Um, so yeah, it's a little bit of both. It's a little bit of automate, it's a little bit of manual and you know, it depends on what, on, on who their target is going to be. Yeah. And, and I'll even add to that, you know, you look at Connie when their, um, playbooks were leaked, they're well known for just following playbooks. They're well known for saying, you know, let's, let's not reinvent the wheel.

Let's teach our bad guys how to do this, this, this, this, and this, and don't deviate from it. So absolutely commercial tools can be a part of that stack and very commonly are. And also it just, sometimes it's easier to hide when you live off the land. We know that, Gary, you joke around a lot about the process of these organizations, but it's pretty compelling, isn't it, the how organized these organizations are.

Yeah, they're, again, they're, they're better funded and, and better organized, uh, than unfortunately than we can be. And remember as MSPs, SMBs, I mean, this is one thing that we need to do. We talk about security here. Don't forget, we have a whole nother business we that we run. We have to do support, we have to do projects. Like we have a whole, we had a whole business going before we had to commit so much to do this.

It's security is an MSP's part-time job, but it's the bad guys, full-time job. Like just by nature, that makes it, you know, not a fair fight. Yeah, yeah. Very, very good. You know, um, James, first off, this is really great, man. Thank you so much, uh, for being here. You work, you know, you work with MSPs and you have a channel program. Talk to us about like how important that is to your, your business model. Yeah, no, it's, it's honestly, it's critical.

Um, it's, it's the majority of our business, the Lion Share business is working with MSPs and, you know, we kind of, you couldn't Find a better market. Yeah, right. We couldn't, we couldn't. That was, I, I searched high and low. I'm like, you know, I don't know, maybe I'll work with like a bunch of Chick-fil-A and then I'm like, I know a lot about Chick-fil-A naturally, you know, They're closed on Sunday, They're closed on, which is nice. I won't get any phone calls on Sunday.

And I'm like, you know, I kind of, I kind of wanna take a risk here and work with the MSPs of the world. Um, yeah, that, that's really the lion's share of business. And you know, what we kind of identified is like, you know, we were, we, we, you know, we came across a lot of MSPs and we did work for customers that are using MSPs. And what we noticed is that a lot of MSPs shared frustration.

The fact that, you know, someone, their customer get a pen test, this pen test gonna come in, drop a report on them, make them, you know, look bad and say, Hey, this is all this stuff wrong. And then run away and say, here's how you can fix it. Right? And that really does nobody good. Um, and what we needed is we, and what we need is we need proper alignment there. And we, I call our, in my infinite wisdom, I call our partner program align. A-L-L-I-G-N has an ally and alignment.

'cause I'm super creative like that as Andrew knows. Um, so we went out called it that. And it's really a testament to what we do, right? Is we wanna align the industry and the customer and the MSP to making that customer more secure. That's really what the end goal is. We wanna leave making them more secure than they were pride in them working with us. Um, and that requires alignment in everyone to say, Hey, we're gonna do what it takes.

We're gonna find, you know, what we're gonna do is we're gonna find issues, problems, vulnerabilities, things that need to be implemented, things that need to change, right? We're gonna write a report and then we're gonna work with that Ms. P to say, okay, this is the plan going forward. Let's, let's, let's make a remediation plan. Let's see how you can implement, see the level effort that's involved with doing that, and then let's present that to the customer together, right?

So this way you have a problem, now you have a solution, you know what to do. You know, you, you know, you know exactly what can be done to fix it, what that effort is, you'll do it. And then we come back and retest it to make sure it was done properly. Um, and you know, it sounds, when you, when I think about it, it sounds really simple, but honestly it's something that the industry lacked. Um, and that's really what we specialize in. So do you have MSPs you work with that now?

This is just part of what they do for every one of their customers and it's part of what the validation and how they take customers on their security journey? Correct? Yeah, no, that, that's exactly what it is. So, you know, a lot of these customers are reaching out and, you know, you know, we have some MSPs that they, they partner with us and they say, Hey, as part of our security stack, you know, our advanced security offering, we're going to, we're gonna do a pen test with that.

And what it really does is it is it helps, uh, it'll help identify where money can be spent. And we see this all the time with IT organizations, um, answering to CFOs, which I'm not a huge fan of naturally. Um, but it happens out there. And the CFO's always like, Hey, what are we gonna do? You know, how can this money be spent? Where do we really need to invest time, money, and energy?

And the result of a test that we can perform will be, Hey, you know, you might wanna say we need new av, your a, your avs good, right? We try to do all these different shell code runners to try to data it and, you know, all this fancy stuff we really need work isn't patching, right? We really need to work as re reconfiguring your active directory force. 'cause there's crazy trust and users of access to everyone shares. You can just spend time and energy there.

So we're, we're doing a lot of that. Yeah. Interesting. So it, like, I feel like we're reached a point where we're MSPs are gonna get this relationship with their customers, or eventually they're gonna have to answer that tough question. Either someone else is gonna do a pen test or they're gonna hire someone like you because the customer said for whatever reason they needed it. And the customer's gonna ask 'em that hard question, well, why aren't we doing any of these things? Yeah. Right.

And that's a tough spot to be in, right? It it, it, uh, after the fact It's very tough. Yeah. Like the last thing you want is for the customer to roguely hire a pen tester to come in and then they're like basically trying to audit your work, right? And, and, and at the end of the day when that happens, nobody wins. You know, It's like it becomes adversarial when really the whole thing is to try to make customers better. Right? Exactly.

It creates a bunch of unneeded friction, you know, and that's something that we used to see all the time and you know, like we've been on the, that end of it too, right? Like, I've had customers, you know, hit our website, email us, we'll do a pen task and um, put a report together like, oh, well that's our MSP's fault. And I'm like, well what did you, you know, and the live is like, what do, what do you engage the Ms P to do? Well, they just do patching. So how can you blame them for av?

How can you blame 'em for all this other stuff if, you know, maybe you, you know, that's your responsibility or it's a co-managed environment and really, like, that's the friction you always try to avoid. It's like, hey, at the end of the day, we need proper alignment. That alignment is to make you less, less susceptible to hackers and intrusion. When we have that alignment, everyone's gonna win. Yeah.

And you know, listen, I, I was telling a story last week, uh, in my presentation, um, in North Jersey. And I said, when I first, like back in 2009 when I first started talking to MSPs about where we had to go back then, I was telling people like, Hey, everyone's gotta get to an average seat price of at least $150. At the time people had a conniption, you know, and now as of my last, you know, meeting with my peer groups, I'm telling them it's 300 now.

And so I feel like James, we need, in order to get there and show value, we need, we need as many tools as possible so that customers see their security, where they are in their journey and their risks the same way that we see 'em. There's no other way to get 'em there, but we have somehow have to get them seeing this, this the same way that we do. 'cause if they did, they wouldn't care whether we charge them 300, 3000 or 4,500 a month. Right? Right. For sure.

And like, it's funny 'cause part of it's like, you know, like I always think like growing up, like my mom would tell me something, I'd be like, yeah, I'm never gonna do that. And then I have someone else tell me, I'm like, you know what, maybe I'll do that now. And you see that all the time with, with customers, right? Like the, the IT department will tell 'em, or people tell 'em all day long, Hey, you need to add two factor. Like, ah, we don't need to do that, that, that's, that's nonsense.

Then we come in and we guess a pass we get admin access. Like, well because he said it, we're gonna do it, right? Yeah. And you see, and it's like, it's so true. Not just in pen testing, right? Just across the board and in security sometimes it's like you need, you need a third party come in and tell you to do that stuff.

It's our, what I've tried to tell the MSPs, if your customers aren't making the right investments in, in their IT infrastructure for security or aren't willing to pay you the right amount ongoing for you to manage that, it's not the customer's fault. They always blame the customer. It's your fault, it's your job to use whatever third parties, whatever tools, whatever we have to do to get them there. That's our responsibility.

Gary, it's almost like, but it's funny what James just said, you know, you need a third party. It's like, you could use it as a wedge to a customer. Do you want like a third party pen tester to be the person to tell you this? Or do you want the third actor to be the one to tell you this? Yeah, I kinda opt for the one that's on the safer side wearing the white hat. Yeah. James, I, one question I really wanna get to before we run out of time, um, is about sales.

Um, so you work right with your customers in helping them on how they would present to their customers, why they would want to do this, make the investment, the benefits of it. Can you just take us through, it's, it's the part MSP struggle with? Yeah, no, and we, and we see a couple different aspects, right? Like, uh, our bigger MSPs, like the national MSPs with pre-sales engineers and, you know, all the staff is, they're, they're typically really good.

You know, they're familiar with pen testing, but a lot of our medium to smaller, uh, MSPs, they just haven't been exposed to this before. It's not like, you know, they're offering a new firewall or a new antivirus. It's just a completely a service completely outta left field.

Um, so what we'll do is, you know, we're obviously on a lot of those sales calls and we're talking through the, you know, asking the customer the right questions and trying to figure out, you know, what the business driver is or what they might want in scope or if there's a compliance requirement, and walking 'em through that process. Okay, what is it that you need? Um, and that's, you know, that's the typical kind of initial sales process for any of this.

And, you know, in terms of MSPs, um, you know, offering this to their customers, what questions they need to ask, really, the, the question that I always say is, okay, do you wanna basically get hacked by a white hat hacker before a black hat Hacker's gonna do that? Do you wanna find those deficiencies before someone else does? Um, and you know, a lot of our MSP's customers, you know, they're, you know, it's a mix of, um, mostly non-technical people with some technical people.

And a lot of times just the non-technical people don't understand, um, the deficiencies or the vulnerabilities or the things a hacker could find that maybe, you know, NMSP isn't always looking for. Right. And a lot of it's a cultural thing as well. Like people, you know, I, I did work for a customer last week, 14 character password policy, right? Great password policy. You always see eight eight's terrible. They're using 14.

But, uh, a bunch of the, a bunch of the employers using password 2022 is the password, right? Really bad password, right? But on paper it looks great. And if you talk to anyone in the company, like I talked to the ciso, he's like, yeah, no, I came in here, I I did a transformation 14 character password possible. Like yeah, 60% of your users are using password 2022 and all your domain admins hasn't been changed in six years. They're all using like temp 1, 2, 3, 4 as the password.

Um, it's a lot of those things that we'll find, um, that normally thinks about until you have someone come in and then try to do these kind of things. What's the top when, when an MSP is trying to get their customer base there that you're working with? What's the, what's the number one objection that they get? Yeah, a lot of 'em, you know, it is funny because it's changed over the years. And initially it was, which is scary. It was, they would never target us.

We're just a small law firm in Indiana, right? And now it's like, no, they will target you. 'cause you are a small law firm in Indiana, right? The, the tails have turned a little bit, but, um, sometimes it's price, you know, sometimes it's just, Hey, do we really need this? And you know, the insurance questionnaire thing, the reason we got why we all got together today has definitely helped see the need for that. And I think, you know, I'm not, I don't love the media.

I don't like, a lot of times the selling through fear thing, but the fear, you know, and saying, okay, you know, I turn on evening news and three times a week you can see local companies got hacked, is helping to raise that awareness. And, you know, when we go into places, if we're doing forensics, I'm like, Hey, have you guys ever had a pen test on? A lot of times the answer is no. Right? We've never had anyone try to hack us.

That's why RDP was through the firewall and the password was password one, you know? Um, so that's a, you know, that those are the really the biggest objections there. Like, well, why do I, you know, why do I need this? Well, you know, if if we don't find it and someone else finds it, it's not gonna be a good day. So I, I mean, know we're top of the hour, I'll, I'll close on this.

If you're out there talking to your customers and you're getting a lot of pushback, if you wanna try to implement a program like we're talking about today, and you get a lot of pushback, I think it's a big wake up call for where you are and what your relationship is with your customers, uh, and, and, and the way that you're positioning things and it tells you that you have work to do, man. So this was really good. We really appreciate, uh, having you here today. Yeah, No, thank you. Fantastic.

Loved it. Hey, Gary. And, and, and Wes we'll get together on, 'cause again, I think we're, we're onto something for a special project here. This is all coming together really nicely. Um, I'll shoot you guys an email shortly, James, wonderful having you with us. It was so good to have you on. Thank you. Really appreciate it. Um, Eric, appreciate you, uh, being on the other side here, filling in for Phyllis, who's filling in for Ryan. Um, until, uh, next week, everybody have a fantastic one.

We'll see you next Monday. Take care. Cool, Thanks everyone.

Related Videos