Transform your sales conversations with Data Flow
In this video, industry experts discuss the intricacies of data flow mapping and its importance in cybersecurity and compliance. They explore how understanding a client's business processes and risk tolerance can lead to more effective security strategies and better alignment of IT services. Through engaging discussions, the speakers emphasize the need for MSPs to build strong client relationships and approach security with a strategic, empathetic mindset.<ul><li>Understanding a client's business processes and mapping data flows is crucial for identifying risks and improving security posture.</li><li>MSPs should focus on building relationships with clients, understanding their business needs, and aligning IT solutions to address their specific risks and compliance requirements.</li><li>Effective collaboration between MSPs and clients involves continuous learning, open communication, and leveraging a network of complementary service providers to address diverse client needs.</li></ul>
Guests
Video Transcript
Hey, welcome Everybody to session 81 on the cyber call. Good to see everybody. Uh, you got that going, huh? Gary? Um, What, what? I gotta say I like Gary in his like salmon outfit. I think he's built for Florida these days. Yeah, it's 'cause I'm in Florida. You just get off the boat. Well, welcome, welcome to the sunny state of 35 degrees. I think if it was, uh, we had some precipitation, we would've may have gotten snow. Um, but welcome everybody. Um, so just real quick announcements.
Um, one, I have a poll up. I'd love for you guys to, uh, take, you know, fill this out. It'd be awesome if you would. Um, and two, I'm just putting a quick post, uh, in chat as well as this URL lives at the bottom right. A boom is almost sold out. Um, and we are thrilled, uh, um, everybody on the cyber call today. Many of you, uh, watching today will be there.
Um, so, uh, in fact, um, it's one of the reasons I was, I was so excited to have Brian on, uh, back with us and if you haven't heard him, you're in for a treat. Um, so just to kind of set the stage real quick, um, Brian is no stranger to the MSP space. Uh, how many MSPs have you owned Brian Over your career? About, about half a dozen or so over many years. Just tells Jerry shows how old I am more than. Alright, well, um, Brian, you are someone Who's more of a glutton for punishment than me.
There's not many. Yeah. And, and Andrew really came up through the, it ranks more than anything, right? So we're, we're going back into the late eighties, early nineties. A lot of Novell network, you know, GroupWise implementations around the, around the states. But, but that grew into network infrastructure, got into the MSP, but really got bit hard in 1999 or 2000 ish.
Uh, got that entrepreneurial bug bit me and, uh, you know, to that point, uh, and what I just said a second ago, grew several MSPs organically, a mix of some rollups and and m and a and sold and exited. Um, and so, uh, I'll, what you have today, some wisdom of a lot of things that I did do the, the right way. So hopefully I can share some, some wisdom along the way along with some current observations, very specific to the MSPs that, that we come in contact with and work with today. Awesome.
So just to kind of set the stage, you know, Brian, you are gonna do a session, uh, at write a boom on data flow and da data flow diagrams. And one of the things, when we were on the pre-planning session, you started to walk through the conversation. 'cause I said, you know, Brian, I I, I hear a lot from MSPs, they ask their customers and prospects, where's your critical data? And he's like, well, that's part of the issue. It's how the questions are being asked.
And you started to kind of walk through this, you know, conversation that you have with customers. And I'm like, we've gotta get this on the cyber call. So we will do that later, uh, in the, uh, event today. And I think that's with Gary, uh, towards the back part of it. So, you know, leaving sales and, and things of that nature for Gary. So, um, with that, Brian, even the Best part for the end. That's right, of course.
Um, and, um, so before I turn it over here to, uh, Wes, Brian, can you kind of just maybe give, bring us up to date on your transition into cyberspace, the cyberspace, this cyber owning a cybersecurity, uh, organization like Cosent and what you guys are doing today? And then I'll let Wes take it over. Yeah, sure. Um, you know, as a founder over many years, uh, risk, uh, I I naturally think of risk and consider risk, right?
So we hear a lot about security and, and, and, um, some of that, and I, or being a security professional or security consultant, I think think more in, in terms of, uh, especially Cosent being more of like a risk sherpa for lack of a better way of putting it kind of help, you know, with that, that strategic guidance and leadership along a InfoSec or compliance or both journey and helping, you know, share kind of the, the best use of of funds, right?
Organizations don't have an unlimited budget, so it's important that they're saying yes to the right things and no to the right things. And understanding how to connect the value, uh, to those, uh, in, in particular security investments to hopefully mitigate or shrink, shrink some risk. Very cool. Senator Spencer dictator, um, I hear you got some big plans for write a boom. Anything you wanna leak that you, uh, are gonna be doing?
Yeah, get your man, I can talk get, get your bep 20, uh, wallets ready, baby. We're handing out some dictator coin. Uh, how about that? Uh, uh, no, but for reals, uh, although I may do that with certain fun and shenanigans. Um, yeah, I'll be the mc for the event, so it's gonna be, it's gonna be pumped. Uh, I'm, I'm gonna be pumped. Um, I was just looking through all the content and, uh, man, it's gonna be, it's gonna be great if any of you guys went to Per Chicon a couple years ago.
That was Andrew's Andrew. It was his event. Really. We just named it peran. Uh, and you'll see that same flavor of collaboration and, uh, it's gonna be, it's gonna be fun. So I, I can't wait to see you guys there. Um, Brian, I wanna turn to you, my friend. Um, so just walk us through, I want you to dive a little bit deeper. Um, I love MSPs that become security folks. I think that's a really cool journey. Uh, I think we need more people like you.
Um, and I think there's a lot of nuggets and truth that we can learn from that journey. So can you kind of pick out two or three, like pivotal, pivotal things that happened in your career that kind of got you to where you're at today from MSP journeymen to security person? Yeah, I think part of it, back when I was, uh, in the MSP, we would always conduct these like market research, right? We wanna understand what our customers are thinking.
And, and our customers would invariably always come back and say, we're starving for leadership. We want to be led along the way. Not just order taking MSPs, but we want you to help guide us. You, you know, they, they would say, you know, Hey, you answer the phone when we call, you know, and you solve our problem, but we're not getting enough strategy and leadership and coordination. So that rang in my head.
I, I sold my last MSP in 2017, and I thought, you know, the market is starving for some vendor neutral info. Second, compliance, leadership and strategy where somebody can come in and sit on the same side of the table as the, as the customer without an agenda, right? Without a, without some black box that they're selling. Or where all roads lead to a SOC that they have.
But really come back with some unbiased, vendor neutral kind of leadership and strategy and a roadmap to say, you know what, uh, I, uh, Jane customer, I, I listen to your pain. I understand your environment, I understand the pressures you're having from your customers. Uh, you know, I understand your risk to revenue. Let's lay out a path to help you sleep at night. And, and, and more than that, differentiate yourself in your, in your own competitive space, right? And do those things.
And really, it was born out of, you know, I sold that MSP in 2017, and I'm staring at a whiteboard. I'm thinking, okay, what am I gonna do next? I have like way too much energy to just buy real estate, right? Or whatever. And, um, it couldn't be a complete disconnect from what I do. All my contacts, my experience were heavy in it. I don't know. Buying real estate in 2017 was a pretty good idea, You know, but I, Yeah, you probably, you probably should have spent all your time doing that.
I don't know, it would be like asking a fish to climb a tree kind of thing. And that it just wasn't comfortable for me, right? And, and, um, really enjoy, uh, working with different businesses and, and bringing solutions to, to, to solve a problem that they're having. So, Wes, you know, for me, it, it felt really natural.
It always been kind of in leadership roles and being able to leverage that founder expertise, knowing what we know about the IT, and knowing that there's a gap in there for, uh, you know, this, this unbiased security, you know, and compliance leadership, uh, for a lot of organizations that are still starving for it today. ILI love it, Brian, what I heard loud and clear from that, I wanna just relay this back to everyone on the call leadership, right?
Like, I think we have a, we, we have a void of cybersecurity leadership. There's a lot of people that, you know, want to push the, the, the, the buttons. There's a lot of people that want to hack the hacky things. Those things are awesome. We need that for sure. But I think what we're also missing is where are the leaders? And leaders are not ones that push people and where they need to go. They bring them with them, right? They're the ones that are responsible for conveying that value.
They're the ones that are responsible for showing the way. They're the ones that are responsible for clearly articulating where the organization needs to go. That's where we have a, a void. And I love Brian that you're doing that. Um, and I've seen you do that. By the way, if you guys don't follow Brian on LinkedIn, um, just, you, you need to search him up because I love his posts. They're always getting probably more like than I get. Wow. Thanks. Uh, yeah. So you guys need to follow him.
'cause I, I love, I love how you articulate things. Um, I wanna ask this as well, Brian. Can you kind of talk to us, like, I have my little things, I mentioned this on last week's cyber call. Like when an MSP I'm trying to gauge their maturity. They like speak about their security in terms of just using vendor names, just as one example. It's like a tell, they're probably somewhat immature and that's okay. Um, how do you assess, like what are your tricks of the trade?
Uh, what are things you look for, listen for, ask for? And this is something that I totally messed up and did wrong when I started this business, right? I understood the I-T-M-S-P space very well. But when I started this, you know, it was, it was like, okay, I need to do these assessments, right? These heavy duty risk assessments.
So I'm gonna turn, you know, I'm gonna turn over every rock and look for everything, and I'm gonna give 'em this big gigantic shiny report, you know, 300 pages of everything that's wrong and all their gaps. And, you know, then we can talk about what to do. And a lot of time and money wasted, you know, and I look back, if you don't look back at the things you did a year ago and cringe, then you're probably not not progressing right? You know? So I look back at some of those early things.
And so what I do now is I don't really, you know, we don't do a, a heavy bunch of assessment. Wes, you nailed something a moment ago, and that's, you could ask some, some questions, uh, and, uh, based on the answer and the feedback you get back, you know, and so today, from an assessment perspective, we assume, especially organizations that haven't been on a, uh, compliance or InfoSec journey before, we assume greenfield, right?
I know Wes dropped off there, but, uh, you know, he mentioned that, um, Wes mentioned that, you know, when he, he talks to clients, sometimes they'll regurgitate back, you know, Hey, here's some over the products that we're using, right? And if you think of NCSF, it's, it's all about protection, right? And, and so they've spent a bunch of money on protect, protect, protect a little bit on detect and analyze, but mostly heavy on protect.
But you can tell they go to product, they go to this other. But what we've done now, and and you know, is we just assume, especially in the InfoSec space, there's low to zero maturity and there's a lot of work to do to build out and operationalize, uh, an InfoSec compliance Program. Hey Brian, you know, you mentioned report. I, I have a, I call that the big honking, the big honking report. And it's funny because what it, what it almost means is it treats security as a project.
Like, okay, Beginning and now We're gonna fix it, then we're gonna move on to the next thing. Like it's a project. Yeah, yeah, yeah. And, and you, you're exactly right, Gary. And, and Wes, what I was Sharon, is just, you hit the nail on the head, uh, as far as being able to ask questions, the right kind of questions. And based on the answers, you come back, they get, you get back, you can tell where they're at.
You don't need to to have a 500 page report with pictures or some, you know, 30 or $40,000 assessment or something. It's a series of questions. In about 30 to 45 minutes, you're basically verifying there's a load of zero maturity, uh, info, second compliance program. And the last thing they need is a whole nother big gigantic risk assessment report, uh, that they probably don't even understand. It's polarizing, right?
So the idea now is just we assume greenfield more often than not, and in fact it works better. 'cause sometimes they will say, oh, we have this, or we've done that. And, and a lot of it's not usable or it's shelfware, you know, that kind of thing. They've done a find and replace on Sam's policies and they call that their program and things like that. So, um, great question though. Hey, what's, can I answer a quick question again? Where's, what's frozen? Again, we looks frozen.
Brian, just curious, do you ever have situations where you are surprised you go in and, you know, someone maybe thinking is typically un immature and they surprise you? No, the opposite. Um, I've gone into environments that have been dealing with, uh, medical devices for two decades, uh, and they've skirted around and kicked the can on security questionnaires or, or things. So it's been more the opposite.
Andrew, I go into an environment thinking, okay, they're gonna have something, you know, fairly robust program in place. And it turns out there's nothing mm, nothing. Um, I, I, I think there's been times where you've seen some security compliance around other designations. So they show a little bit more maturity and saying, okay, this organization's been down the ISO 13 4 85 medical device path. They understand, you know, quality management systems, some of that. So there's some of that.
But really, Andrew, this is the wild, wild west in terms of actually building, you know, sustainable and manageable programs that are actually in motion and can be, you know, that, that the controls can be, um, you know, evidenced as operational and effective. That, that, that's hardly ever these days. Yeah. Okay. Is it, Especially by the time they're calling us. Right? Right. Fair. Yeah. Go ahead, Gary. I, I tease you, you own really updates.
If they're using an MSP, you can ask them two questions. How many users do they have and what do they pay per month? Right? And as soon as I figure out their seat price, I already know what can't be done because it's a math problem. Yeah. I don't need to spend three days there. We know what we're gonna find and can explain to 'em it and why. Yeah. Yeah. Yeah. I like the way you do that, Garrett. I think it's really helpful.
Maybe bring that up when, when you have the, the floor again a little later. Um, Wes, last thing and back over to you. Uh, I just couldn't make a comment. I know we can't equate ms, you know, the early days of managed services or the RMM to where we are today. Whole different environment in terms of risk, et cetera. But it is interesting, Gary and Brian, the, the feel of, remember when the RMMs first came out and people were just like, can I have a contract?
Can I, you know, I'm thinking, do you have a policy? Do you have amendment service agreement? How do you package it? You know what I mean? It was that. It's, there's so much of that similar vibe, if that makes any sense. Yeah, For sure. So Wes, For Sure, right on. But I think, oh, go ahead. Yeah, cool.
Oh no, I was just gonna say, I, I, I think if you get the gigantic, the mindset of some ginormous risk assessment, you know, as a career consultant handing over some big gigantic book, if you can get out of that mindset, then you can get right to the stuff of understanding and learning the prospect or client's business, their pain, their risks, and make it all about them and not so much the, the tools and how great your shiny reports are.
So that's been a kind of a mindset shift for, for me in in particular. Sounds like a good dating service, Brian, that you could give advice there too. I don't know about that. Totally not qualified for that. I married forever. Good one. Hey, uh, one other question for you, and I'm gonna have to go back and list them myself. I only got about 20% of that last, uh, interaction from my internet. Just took a, a huge poo poo. Um, how do you work with other MSPs, right? So you've been one before.
You know what it's like to kind of be one, uh, what are your tips? And if you, if you're sharing advice for MSPs on the call today, whether they ever work with you or not, um, how might they best work with, uh, external security folks? Yeah, most of the SP are, are interactions have been extremely positive. They, they too seem to be starving for some help in this area. Uh, they've had products or solutions and, and things they've been trying to get done in the environment, right?
But they, they come back to me, oh, well we've tried to do MFA and our, it's too much friction. Our client pushes back and we really need you. You'll, you'll help us. And, and, but it's been very positive, right? And oftentimes, especially when we're working with a, uh, a client that has an MSP, we love it, right? Because we have implementers at our fingertips. We don't do any of that for oversight and governance and independence, right? But we develop a program which just sits there, right?
The rubber can't meet the road without the Ms P. And most MSPs are, are very, uh, seems very curious to learn. They want to go along this journey with the, with the clients. I, I, I'd say the lion's share are this way. They don't see us as a threat. I mean, we, we work hard as leaders to bring everybody together on the same team. 'cause we're helping our clients to a mutual goal. And compliance sometimes gets the wallets out.
But I always joke with clients along the way, I'm like, Hey, you know, along this compliance journey, guess what? You're gonna improve your security posture by accident. You know, you're just going to, to do these things. And with an MSP or MSSP, they bring the programs that we develop to life. We can't do it otherwise. It's just v vision and a bunch of words on a page. Important words. But, but at the same time, they can't get operationalized. They can't get done.
'cause a client doesn't have the expertise or bandwidth to, to actually do it and put these things in motion. They can do the administrative controls and some of that. But there's still a ton of process, you know, onboarding, provisioning, de-provisioning, you know, just a ton of sticky processes. So oftentimes when we're working with MSPs, they're like, the, the light bulb goes on and they're like, you know what?
We're kind of connecting all this stuff from policies to procedures and these different programs. And we're starting to connect the dots between that and what the MSP does. And we're also helping the MSPs kind of show the value, right? Uh, with some of these tools. So we can work with, we can, we can have an MFA policy, right? I brought up MFA, we can pick on that. We can have an MFA policy and it's important to check a box, but that's not why the, the clients do it.
We're talking to the client. And that's what we're hoping we get into some today, is drawing a picture and saying, you know, why you need MFA, not because it's important and you could get hacked, and the average cost of a breach is blah, blah, blah. It's not any of that. It's, we drew this picture here and you, we put a circle around this revenue that's at risk. So let's talk about that. Here's the data flows that, that drive, that here's your critical business process that drives your revenue.
You know, client Jane clients, 80% of your revenue lives here. Let's protect it. And part of that is we've identified these systems, you know, that have, that have access to today. These are the people, these are the applications, these are the processes. And MFA is gonna be a tool to what shrink your risk to that revenue, right? So I love, that's the conversation. And, and as I turn it over to, to Ryan, um, I love it.
You know, I, I, I saw that, like I worked with internal audit every single week, uh, at my bank. And then engaging in external audit as well, that comes in, you know, on cadence, relationships and basis. And, you know, I, I quickly learned m make them your friend work, work alongside them, because they are the ones that give you a lot of oversight. They're like, in terms of like, this is how others are doing some of these things. This is something you may not have thought of before.
They might even cause me to enter into like a disagreement. And like you're saying this, but here's why I think we are doing this instead. Here's a compensating control. Here's an alternative way to look at it that makes us better to have those open, uh, conversations. And even using them. I talk about this somewhat, you know, offensively, right? Like, uh, you know, hey, to the decision makers, you see the audit is aligning this, we've been talking about meeting this for a while now.
Look how audit is, is, is saying the same thing. We can work together to accomplish our goals. And I've, I've had, I've had many instances like that and all of those things, I think paint that picture that you talked about is, you know, if you're an MSP and you're working with external audit, they are your friends. Um, you just have to learn how to make that friendship work, so to speak. So, uh, that's solid. Um, Ryan, I'm gonna turn it over to you, my friend. Yeah, Yeah. Thanks.
Um, so Brian, when you're, when you're in conversations with a client, where does the conversation about mapping data flows come in? Where, where in the engagement is that early? Is that late? Because we talked about the importance of doing risk assessments, but risk assessments require an understanding of the data, where it lives, where it's moving, how it's processed, how it's handled. Um, so where, where do you fit that in? Where do you slot that in? Yeah. Very, very early.
As early as possible in engagement. Okay. So the idea is 'cause, 'cause oftentimes, especially from our perspective, what we're trying to gain is the risk tolerance of the organization, right? So the best way to do that sometimes is to understand what is, what exists today? And then as you map this out, you start to say, ask the right questions, right? You say, what's your critical business processes, right? That which, what's, how do you make money? What's your risk to that revenue?
And you can start to draw that out. Who's involved? How are they involved? How are they accessing? How's it stored? Process transmitted? You don't ask, you don't use those words with the customer, but it's really Ryan as early as possible because the policy work and all that stuff has to reflect the tolerant, the risk tolerance of, of the organization, right? Every, every organization is different.
And so in order for us to tailor the right policies and put the right program, we have to understand the compliance landscape and the statutory regulatory stuff, no question. But really wanna understand how risk tolerant or risk averse is the organization. And then we know what direction to kind of start and, and take the program. Okay. So I'm a big fan of What, Go ahead.
Oh, I was just gonna say, Ryan, you know, the big why behind that is everything we do from that point forward, we wanna talk to the business and the language of the business, not in the language of IT or security with, you know, a bunch of acronyms. They don't understand. I like everything for us to do any subsequent statements of work or when we're doing a quarterly business review or whatever it is, we wanna talk in the language of the business.
So in other words, I don't want to be, if I've got this data flow diagram, I don't wanna say, okay, we, we patched all hundred of your servers, um, you know, and this is what we did for you. I'd much rather say, Hey, the 30 servers VMs that we identified as critical, that are driving the, the revenue, a hundred percent of those were patched within 30 days or within seven days or whatever the, the policy is. I think that's a much more engaging conversation.
'cause they understand what you're saying. It's not just some, you know, qualitative metric that you're, everything connects back to the language of the business and their risk to revenue as much as possible. Okay? So I'm a big fan of structured ways of thinking about problems, right? And that tends to mean frameworks, methodologies, mental models when it comes to doing that, mapping that data flow, mapping the, you know, data classification of sorts.
Do you have a methodology that you follow or some framework and like, can you, can you share that with our audience? Like if they were gonna do this, how would they, how would they approach it in a structured way? Yeah, the best way to do it is, uh, interview question response is how we do it. And these are context level diagrams. So, so Ryan, I I'm saying it for the sake of, especially working at the MSP level and the stakeholder level with the client.
These are context level zero type of diagrams, right? These are highest level getting to know the prospect or getting to know the client better. So it's not A-S-S-A-D-M or, or gain or whatever, co-ed, there's a TA ton of different official ones. You can get those and geek out, especially at the engineers, whatever, when you're really talking about data flow di real data flow diagrams are like input, value, added output and so on, all polarizing at this stage, right?
You're just trying to really understand the high level data flow so you can be that annoying three or 4-year-old in the room. Oh, well, tell me more about that. Well, who accesses that? Because you know what, in these conversations, the data goes in places. You never had a clue. It went right. You, if you talk to a business, you know, stakeholders, they'll say, well, all our data is in our ERP or in our HR system or our financial system. And we all know that's bs, right?
It, it's everywhere, right? It's exported. You're talking to people and it's like, I didn't know marketing access that database and exported to, what's that SaaS product? What I didn't know that the data went there. So you're think of DA data flows, like water goes everywhere in your organization. So this is a chance to kind of get the right people in the room, start talking about it. And the methodology is really listening.
It's being empathetic and, and something that I, I need to trademark still, I haven't yet, I've used it on some of my posts, but the KISS method, which we all know what the KISS method is, right? Is keep information security simple. And especially if you start at this context, this level zero, and ask the right questions, which I, I think we could get into here shortly. I'll definitely get into it at the right of boom, um, uh, next week. But, uh, you know, Ryan, it's, it's kind of a, a q and a.
Let the, let the let the client take you on their journey. Clients love to talk about what they do and how they make money and get 'em talking and then start being that again, annoying person. That's who, what, why, how, where, draw it out. And, uh, can I, Can I share, can I share a quick story about this? Um, when we talk about data flow diagrams, um, remember that it's not always just like, don't think about it as like network pathways only. I mean, that's, it's a valuable to start that way.
But going back to what you said, Brian, actually asking business process questions is so valuable and important. Lemme give you just one quick example. When I was at the bank, um, we had an, we had a lending platform. It's called an LLOS, like lending origination system that they used to build all the lending documentation, all the compliance stuff. This thing is huge, and I didn't know this until I started asking questions.
Lending operators would share lending files between each other over email, and then what one would do is they'd pick up the PDF, they would make their edits to it, they would save it, reattach it to the original email thread. And so now they have two PDFs floating around in email, and then the third iteration, and they would do the same thing. So it's like this chain of like attached forwarded emails all with PDFs embedded, all with all kinds of PII inside all of it.
And I'm like, how long have you guys been doing this? And they're like, well, forever we didn't know a better way to do it. And I'm like, oh, so we, and it failed to get in front of you and help you have a better way. And they're like, we'd love a better way.
I'm like, this is the worst thing I've ever seen from a compliance, a data flow, a backup, a security perspective, all because we didn't have this conversation with them and they found a better way to do it in their mind or maybe a workable way. So I just wanna share that, See it all the time. Yep.
Ryan, before you ask the next question, I would just like to, I, I put something in just now in chat for everybody, um, you, your statement before your question, Ryan, that you really love frameworks and process and things like that. You had a, uh, podcast with Matt Lee about a week ago. And if you guys want a treat of listening to Ryan and his element as a ciso, I I highly encourage you, uh, to watch that. It's, it's awesome. So anyway, go ahead, Ryan. Yeah, thanks.
Yeah, the Matt triggered me with the LinkedIn post. So next thing I know, he's got around doing 45 minute podcast, so be very careful what LinkedIn post you respond to, I guess is the answer that for that test question.
Um, so Brian, with the, again, keeping on the data flow diagram, uh, train, but thinking more about incident response, when you were in, you know, your MSPs, uh, in the past were doing data flow diagramming or understanding business processes and how data moved, how did you leverage that intelligence in the process of helping you, your business or your customer's businesses respond to security incidents?
Yeah, so the, the, the, the DFD is really just a visual, visual picture of the, the context, the lay of the land. And so what I like to do, you, you hear this thing about shifting left all the time, right? Kind of a buzz word with zero trust and a whole bunch of others, right? So shifting left, but you can understand in the, in the process, how do you start understanding what's involved along the way? And, and this is one of my favorite things to do.
So you have the data flow diagram kind of baked or baking, and you can work with your client. And this is where you get out your red pin, right? And you draw it X and you say, you know, what if this, what if this system, this process, this, this person wasn't available, an incident happens, you know, exit out, you know, and then you, you get cute, right? It get rhetorical, would, would that be a problem for you? Um, you know, and oh my gosh, yes, we can't do that.
You know, and, and so that, that starts to solicit a little bit of a emotion, which is what you want, and then you wanna make 'em feel safe, right? So it's like, okay, I understand that, that if this wasn't, wasn't available for whatever reason, I know we're just running into BC and perhaps DR too, but if it's security incident takes out this system or this personal process, do you have a way to recover? And if so, do you know everything that you have to do?
Not just statutory and regulatory, but everybody's signing contracts? You know, some people read 'em, some people don't, but they're making a ton of pros promises and breach notifications, right? So I don't know if anybody's ever mapped their contracts, uh, and promises to clients to some of the data flows.
But if you understand and go in and say, you know, what, if this data, uh, is breached, you know, along the data flows, this is where it's at, this is if it's breached, do I know my contractual obligations? Do I know how to respond? Am I early enough in the process that I have the right people engaged? If there is a breach of this specific data, and I can align the contracts to those, to those systems, and guess what, everything continues to connect back to revenue.
But really, Ryan, the data flow diagrams help most, I think when you're identifying, you know, and they identify, uh, of the, the assets, right? I, I, if I'm able to identify, if I can't identify something like we just were talking about, if, I don't know, there's, like West was sharing, if, I don't know that there's all these PDFs that are with an email and, and, and that, that I, I'm not, I'm not putting the right controls in place.
I don't have the right, the right things in place to detect and analyze and, and all that other stuff. So the MSP really comes into play helping identify those assets, but really understanding and, uh, you know, beyond the prepare phase into the detect and analyze all the way to recovery. And if there, there's a good solid diagram, and I'm, I'm getting a couple levels deep now. We're, we're well beyond level zero. We want to understand more. Now we get into data types, right?
But oftentimes what I see, what MSPs do, myself included, you want to go right to the question, right? You, you say, uh, where do you keep your PHI, you know, and the customer scratches their head so, well, what's PHI? You know, it's, instead it's, it's like, back into that, you know, you'll understand that if that they have a EMR and their data flow and some of that and ask the right question where it all, all goes.
So I, I think Ryan shifting left understanding and identifying, then you can, then you can manage and detect, analyze, and respond if something comes up, know how to respond To it. Yeah. So I'm gonna share something that I ask, ask you to share an experience where gave load diagrams how to positive outcome. Oh, Sure. Um, One of the things I do as a CISO when I step into a new environment is I tend to think of data in three buckets.
If there, if there were to be an event that affected the data, would it kill me? Would it make me very sick? Or would it have no effect? And so I think like you were talking about, like, oh, would it cause you pain if this data set was unavailable or destroyed, that that data kills you if it's not available, right? You can't run your business. Um, you're like, oh, we could probably get by for a couple weeks. Okay, well that makes you sick, right? Or they're like, ah, it doesn't matter.
It goes in the bucket. And so really what you have is you really have a, a, a two classification system, uh, kind of critical and important. Everything else is just whatever it is. I wouldn't complicate, you know, as you're thinking through data flows, you'll eventually get down to classifications and typing and mapping types to classifications and all that. But just when you're first getting into environment, think about it in those two extremes. Will it kill you? Will it make you sick?
Um, and that tends to, tends to be helpful. So, Brian, share with us an example of when a data flow diagram had a positive impact during an incident. Yeah, sure. So a lot of people don't think of data flow diagrams sometimes in the context of third party risk management or supply chain risk management. But, you know, may, hopefully that's all changing log four J and some of that understanding where, where some of that is and some of the bill of materials and, and such.
But, uh, real quick story, uh, client of ours used us for a while, uh, very fairly robust third party, uh, risk management program, right there, there were onboarding heavily compliant environment. They were onboarding a vendor to do call center stuff, right? So through the third party, risk management did the normal vetting and questionnaire. And during that process, really wanted to map out, okay, where does this specific vendor, uh, fit in in terms of data flows?
Where are they in, in the process? And then insert that, that inserted that, that call center in there. And at first blush call center doesn't sound that, um, you, you know, that dangerous, right? It's like, okay, they're taking calls, but when they're taking that calls, they're getting a lot of information, right? In some cases they're recording calls. And this is calls where in, in this environment a lot of PIs shared, okay? And so we did is said, Hey, this is a low maturity vendor, right?
There's value in using this, this, this call center vendor, but at the same time, very low or zero maturity, we need the proper controls because we understand where they fit in and our data flows, right? They fit in here, they're in this change. So putting the proper controls in place was extremely important. And a lot of that was di was visualized, just understanding where they're at.
Well, because we put the proper controls in, meaning they signed into, uh, our client's environments, client credentials, anything stored as far as call recordings, we made sure it's 30 days worth of call recordings in an environment that that was managed by our client, right? So that was important. We understood that. Had we not understood that, we may have said or had a robust third party risk management and understood the data flows, we might have just onboarded that vendor. Okay?
So that, what happened with that call center Sunday night, it's always over the weekend, right? So Sunday night you get a call, they were ransomware, okay? They were ransomware. Everything that they had on-prem, uh, shut down. And this was a, a call center had been in business a couple of decades, right? And so they were, they were going outta business, nothing they could get to, um, nothing that was on-prem or anything could impact us.
We had the right controls up front because we had documented data flows and understood where this vendor was at in, within those data flows. So we had the proper controls isolation able to bring that call center, uh, in-house, right? So our, our client service commitments weren't compromised.
Um, and just having a, a data flow diagram and understanding the data types they were involved in, uh, this vendor was, we were able to put, again, the proper controls to where the impact on their environment from a ransomware attack had zero impact other than having to scramble and bring a call center in house, which is a more operational story than anything.
But having, having that sort of of controls upfront and the visualization to go back to the business and legal, uh, when they're negotiating with that call center to put in these contingencies, we put compliance contingencies and other things on that vendor, uh, too, but critical to, and, and a lot of people don't think data flow and, and vendors, but third parties, again, your data goes everywhere.
And understanding where, who has those third, you know, from a third party application, SaaS providers call centers, I mean, important to have those, those controls. Or to West's point earlier, you know, are the compensating controls or can we get creative in how we interact with this vendor or data or system? Okay. Over to you, Gary. Okay. You know, it's funny you said risk tolerance. What I always tell MSPs is, customers aren't taking your advice.
They're not, you know, it's not because they don't have risk, they're not qualified to assess their own risk because we haven't helped them, right? And kind of what you're talking about here, you know, being able to ask questions about data in a different kind of way is a really great way to get started with prospects or customers, right? For them to understand. There may be things that they don't know about what they don't know.
'cause if they knew it, they would assign a lot wherever their risk tolerance is, they definitely would assign more risk to it, right? For sure. Yeah, for sure. Absolutely. Yeah. And, and yeah, So I, I got a, some, I got a bunch of questions here, but you see what Ross asked? Mm-Hmm. Like, you know, this is, this is when what he's writing is what every MSP is thinking. It's like, okay, I'm doing a lot now. I'm backing up. I got a tool set. I I I have all these tickets.
Now you're coming to me with, I'm trying to do some framework stuff. Now you're coming to me with data flow diagrams. Like, good god, man. Like, how do we do it? When do we do it? Who does it within my company? You know, how do I monetize it? You know, I'm not asking you to answer all these questions, but if you can just zoom out and say, how does an average MSP you know, who has, you know, 10 to 15 employees and is dealing with 20 to 80 user SMBs, where do they start?
I, I, you know, my, my advice, my recommendation and what I've had success with is, is kind of deprogram yourself as an m ms PA little bit when you're especially, uh, talking to a, a, a prospect or a client is, is get outta that mindset of critical data and PHI credit card data, PII, blah, blah, blah, blah, blah, is, again, clients don't, don't connect with it, right? They don't have an emotional response to it.
And until you say, Jane, client, you know, I really wanna learn more about you and your business. Do you mind sharing a little bit about how you make money? I, I wanna understand client, Jane, tell me, just walk me through this, your, the journey. You do the talking, help me understand how do you make money? And as they're talking about this, they're actually talking about at, at a very high level the how they operate, right? And what you can do is start to ask better questions. Okay?
It's not, and, and also, Gary, you hit the nail on the head. Customers will like to talk about sometimes tools, but more about systems and protection and buzzwords that they heard. So you gotta get beyond that and getting, getting them to be real with you. And you say, and so Jane, you told me that 80% of your revenue comes at that point in time when your widgets are delivered your, to your customer. You know, could you share a little bit more about that? Oh, yeah. Well, we get an order.
Okay, great. Let me, do you mind if I draw, you know, do you mind if I draw a quick diagram, right? I'm just gonna sketch, you know, keep a simple diagram. I just wanna make sure I'm tracking with you. I wanna make sure I understand. So you said 80% of your revenue, okay, that's, that's a big number. I'm gonna, I sometimes do like Yelp dollar signs, right? So I'll do dollar signs there, right? You know, and put that there. And then, but you start asking questions.
Do you say, well, upon delivery, well, how does the widget, how do the widgets get delivered? Oh, well, and they start reverse engineering this. They go from the revenue, and then you start going down the funnel, down and down and down as far as they're willing to go. And it's okay. You know, it's really okay when you're talking to a prospect or client that, uh, that your, you, your client may not know everything, especially if you don't have some of the, the other stakeholders in the room.
It's okay to draw a black box on your diagram with a question mark, you know, magic happens here, or something like that, that you need to go back and ask more questions. Okay? That's an area that you wanna go back and find out more. What happens in that black box? Who's involved? How do they do it? How do they access it? Those kinds of questions. But, but Gary, it's really putting the, the, the client prospect at ease.
Get them talking about their own journey and how they, how they make money, how they're profitable as an organization. Then you can draw that out and start just continuing, uh, to ask, ask better questions. Um, and yeah, you know, We're talk, we're talking about security and data flow diagrams today, but what you're describing is really any advice about technology.
You know, when I got to my second MSP, I sat down the two, you know, I'm gonna put quotes around VCIO, um, and you know, I started asking them two questions. One, tell me who you deal with in the business. Like, is it a stakeholder? 'cause if it's not, you can't even get those answers, right? And then number two, tell me everything you know about, I don't want to hear one thing about their technology. Tell me everything you know about how they do business. And it was very little.
So I think in, you know, going back to Ross's question, step one is, some of the baseline stuff about your relationship with the customer has to start with the VCIO process, you know, before it gets to security. There's a lot of reasons why we need to understand their whole business. And one of them is eventually we need to know where their risk, where their data is, where their APIs are, like all of the things you're talking about. But yet, you know, you gotta figure out a way to get there.
And so you're, I want, I'm, I want to know whether if people listening can hear your style of conversation, like that's your starting up here with their business. You're not telling 'em you wanna know about their data, you're trying to learn their business process and what's critical, right? And then eventually you're walking down to how data plays into it. Am I on a fair way? You're, you're all over it, Gary. And, and that's exactly right.
You want get them talking and, but, but the goal here is obviously you want to improve your customer's, uh, security posture if they've got compliance risk or any other things you wanna help them, uh, uh, along that journey. At the same time, you wanna do a couple things. You wanna be able to, you have a whole portfolio as you have all these accordion of different solutions and services at your fingertips that could add a ton of value.
Where the disconnect, my observation of the disconnect, especially in this role, is that the right conversations aren't, aren't happening, right? The, the MSP, you know, when we were first involved, they're just not sticky enough. You know, we go in and we'll say, okay, we want a list of all the terminated users in the last six months, right?
And then when you compare that to, you know, where, where access has been deprovisioned, that's a golden opportunity where the, the MSP is not sticky enough with the client and getting into their processes and into their flows. These, these types of data flows. If I understand them as an MSP, you know, I can say, you know what, Jane, I can help you here. It's visual, right? We're visual creatures. You say, Hey, we, this is what we talked about. I can circle here. We can help you here.
You know what that's gonna help protect about, you know, where your catastrophically, ethically ill, right? This is where 80 or 90% of your revenue is at at risk. So here's how we can help you around asset management identity and authentication. Um, you know, a variety of different things that we can help you along the way and protect this revenue that's at risk. And, and so I think that, that, you know, we, we don't, we don't give a magic wand.
And suddenly the MSP's, you know, selling more, uh, it, it, it, you gotta bring the, the client along for the ride. They have to have buy-in along the way. Then they start to resonate with this stuff. They start to say, oh yeah, I'm paying for this from this MSP because it solves this business problem that I have. You know, or it shrinks the risk over here because boy, I, I learned, I learned through this journey that I have risk exposure here that I did not know I had before.
Now I know I have it, and I would willingly pay $5 a CR I'm making up numbers, but whatever it is to, to turn on the lights for additional, additional services. And it helps us so much as security professionals. 'cause it's operationalizing our words on a page, it brings them to life. And that, to us is the, the exciting part. So the customer gets more secure.
MSPs are flexing their muscle and providing more, more services, and we're helping along a compliance journey or an InfoSec journey Along. Yeah. And listen, what you're, you're, you're what I see, right? And you know, I just came off of like six days in the past two weeks of peer meetings, right? Just sitting from, you know, nine to five in rooms like, you know, zoom rooms with, with MSPs.
And there's like, right now this point of demarcation, if you can't get to the point to have this business conversation, right? Like I'm saying VCIO first before we even get to security, it, it's just all the questions that Ross asked are really hard to answer. You know, if you're bundling enough into your price where you can afford to build these relationships with every customer, it's easier to answer the rest of the questions. They don't care whether you charge 'em 3000 or 4,300.
Like once they get it and they understand it, and the impact you can make, even conceptually, right? All those price objections that you're worried about today, you know, go away. And it's hard for MSPs to understand. They understand a tool and what a tool is, and hopefully they can convert that to something, you know, some unit of measure, uh, that they can sell. But it's harder for them to do it in roles in process, unless, unless they get there.
And so do you find the same thing that there's like, almost like a, a minimum level of kind of like business relationship that they need to get to before this gets easier? Yeah. I, I, I, I think when, when I think about it this way, I think of, I'm gonna work, I'm gonna work with a customer 'cause I wanna, I want to help them, right? And so you go in with that, that sort of attitude and, and really the data flow diagrams and practice the roles.
I think that this is early on in the, the, the client journey and something you revisit on a quarterly business review practice on yourself, like all the other tools you've done. And like we did at MSPs, I've had, oftentimes I'm looking at it, I'm like, okay, I'm gonna inflict this pain on myself first so I can understand a lot more about it and do it. But, but Gary, this type of exercise that we've been talking about isn't so much IT and information security.
And it's something that I would say go to your top five, your top 10 clients that you have. This is a farming opportunity, right? Some, most of the time your top five 10, you, you have the best, deepest, strongest relationships. I would challenge you, you probably don't know your top five or 10 clients very well. I'm gonna guess you, you, you know how much they consume and how many devices and, and how their network's set up and that, that kind of thing.
But you probably don't know them and their business very well. And I think practice on yourself. Go to your top five or 10, ask 'em these questions. Hey, you're, you're important to me. I wanna make sure that we're matching our, our solutions up in the areas that provide the most value to you, right? Shrink the most risk that you, that you wanna shrink.
Let's go through this exercise and draw a diagram out and make sure that I understand what your top one or two critical business processes are that drive the revenue that you make. Draw that out. I mean, these are amazing. I think farming opportunities as an MSP is to have this kind of discussion. I think the MRR and other products and solutions will, will follow. Um, yeah. And you'll get to know your top client better.
You know, here's the way I always think, I get so many questions about this now 'cause there's so much changing. Like we have to have a way of looking at it, right? Like, so we're always preaching. You gotta have roles and roles tied to revenue and roles tied to your, to your costs. Then when these kind of things happen, and I need to do more, okay? So I'm A-V-C-I-O, does this mean that instead of managing 40 customers, I can only manage 35? Then I know how that changes my cost.
If it falls onto some of these two, your proactive role, your alignment or, or, or compliance role, you know, is, is is something we're adding meaning that it's gonna change how many customers and seats they can manage. So Andrew, it's so important that there's a, that we take a complicated world and find a simple lens lens, right? And, you know, a lot of this is what, what Brian is saying, which is once you start to have the conversation, you, you can figure out the rest, right?
If you have those two things, the right business relationship and a lens by which you see your, your business, I think it gets way easier. Man. Gary, Go. Hey Ed. Go. Hey, I'm sorry. One, one final thought on that.
'cause Gary, uh, kind of spawned some thought here, but, and one final thought relative to this is as you are doing this, let's say with your top five or 10 clients, I, I would strongly encourage you to continue to build your network of, of kind of fellow travelers, people in complimentary businesses.
Because I can guarantee as you work with your clients and go narrow and deep and relative to their risk to revenue, there's gonna be instances, uh, when their needs don't align to aligned directly to something you do as an MSP. And you don't wanna be a, a dead end, right? So build your network with companies that you trust in, like compliance and legal insurance, accounting, hr, so you're not a dead end and you're their trusted advisor, right? So bring these resources to your client's doorstep.
You're solving, you're solving their business headaches, you know, not, not just their IT problems. Yeah. Really, really well said. So, um, I wanted to ask you in the, we have about five minutes, um, left. So in all in the MSPs that you work with, right? Can you tell us what some of the characteristics are of the ones that get down the line, not just in general, but today we're talking about data flow diagram, we're talking about one, you know, one thing. Mm-Hmm.
What are some of the char and then, or the opposite? What are the people that have characteristics that are hard to get their arms around this? Uh, help me understand the question a little Bit. Yeah. Like, of the MSPs you work with Mm-Hmm. What do they need to do to get good at this? Like, what do they need to do differently or what do they fail to do differently where it's hard? Yeah. I'm trying to get one that Are UX of the biscuit here. The, the classical MSPs have a hard time getting it.
So one that that's had the growth mindset that work with us and come in collaboratively and wanna learn, they wanna understand, right? They're not just order takers either, right? They're not just doing what we say. We have to get in a room and be creative. Again, client, most clients don't have a blank check to throw at this. So you have to be strategic and get your rifle out, not your shotgun and work with, work with them. And the best MSPs say are, are, are part of the conversation.
But a big part, 'cause as we're going through some of the controls, light bulbs go off on their, their head, Gary, and you can see 'em to say, oh, you know what? We could do this or this, or we have this solution, or whatever it is. They start bringing solutions and ideas to solve these problems creatively. Sometimes it's a crawl, walk, run or good, better, best, or here's what we can do now, or whatever it is.
But it's the ones that have an open mindset, some empathy and knowing that we're, we're involved in this together as a team and we're not adversarial. Right. We all want the same thing. And that, that's great outcomes for our, our mutual clients. Boy, and, and you know, one thing now is customers aren't doing things mainly because they don't know. And so we need to ask 'em these different questions, but if we don't, what's happening now is other people are asking those questions, right?
The insurance company, uh, a third party, um, a vendor customers are asking 'em some of these questions. And if somebody asked a question before the MSP Brian, that's usually not good for us. Right? Right. Usually not. But I, I, I mean it is, has been traditionally very focused on keeping the lights on, right. You know, kind of maintenance mode that's evolving as, and been evolving for some time where security's in, in the discussion.
Um, and, and the idea here is, is not to throw anybody, doesn't help to throw anybody under the bus or make anybody look bad, it's, Hey, we're on the same team, here's what we've found, let's deal with it together. Right? Yeah. The SP we're not looking to you, you know, and I, I, I think having a healthy relationship is important for everybody not looking to, to, I mean, we, we don't provide any services that SP does and never will, but at the same time, it's, it's, they're part of the team.
And, and I said this earlier on, the MSSP is probably one of the most important ingredients in helping the clients get from zero or low maturity into where they're having repeatable processes and the right tools to come in and prove controls are operational and effective. This isn't going away. You mentioned it. Our, our clients customers are putting pressure on them from compliance insurance companies, contractual obligations, the government.
I mean, there's just so many different directions that our, our clients are getting hit. They need us all on the team and to all be kind of rowing the boat the same direction, so to speak. Yeah. And, and MSPs make it happen. Yeah. Uh, Dustin said my comment, I think he was saying, you know, do we want to not have those questions come mainly from someone else, from a, a sales, uh, validation or what?
No, it's really on if every SMB is discovering, going on their journey of understanding their risk better, do we wanna bring 'em on that journey? Or there's risk if someone else starts to bring 'em on that journey, it starts to have those discuss. That's really what I think it comes down to. Yep. Agreed. Yeah. Alright. Uh, Andrew, we are one minute left. I'm gonna, I'm gonna to, uh, send it back to you. Great. Great job everybody today. This was awesome. Yeah.
The, the comments are coming in and, you know, when Mike Regard said it was an awesome call, um, I'm happy. So, uh, good to see you out there, Mike. Brian is always your phenomenal Ryan, uh, Brian, gosh, Ryan, Gary West, phenomenal job today and thrilled to have all of you, uh, coming up at LightUp. Boom. Uh, wishing everybody a fantastic week and make it a great day, everybody. Take care. Thanks everybody. Thanks.


