TruMethods Security Content & Portal Access
In this video, industry experts discuss the importance of cybersecurity and asset management in building a robust security program. They emphasize the critical need for MSPs to understand their own security landscapes and implement effective incident response plans. Through insightful conversations, they explore the challenges MSPs face in aligning their security practices with business needs and the role of proactive measures in reducing cybersecurity risks.<ul><li>The importance of asset management in cybersecurity cannot be overstated, as it lays the foundation for understanding what needs protection and helps prevent a false sense of security.</li><li>A strong internal security culture and program are crucial for building a successful, repeatable, and scalable cybersecurity practice.</li><li>Cybersecurity requires a shift from a tool-centric mindset to focusing on people, processes, and proactive roles to effectively manage risks and improve security outcomes.</li></ul>
Guests
Video Transcript
There we go. Hey guys. Welcome. We are in year two. Year two already. Can you believe that, Gary? We just flipped. No, I can, I cannot believe it. It feels like we've been doing this for 10 minutes. We flipped the calendar. Welcome everybody. Big, uh, gender reveal today, Gary. Um, as I like to say, tons of announcements. First, um, just wanted to tell everybody if you scroll way up, I put 'em all in there for you.
I figured I'd be prepared ahead of time this time, but lemme just run through them real quick 'cause we've got a lot going on. A lot of great stuff. We just finished, um, the second episode of the Cyber Cast. Thank you. Wes Ryan Fell, Lee and Brian Blakely. Um, it, the feedback has been fantastic and, uh, I, I know that inventory control is in one of the most, um, exciting security controls or sexy security controls.
But, um, after doing this, I gotta tell you, I'm, I, I, it's gotta be one of the most important. Ryan, would you echo that, Wes? A Hundred? A hundred percent. Yeah. You can't really do anything in cybersecurity if you don't have an understanding of what it is you're trying to protect. Yeah. The foundation of everything we do. I'm gonna ask you some questions about that today, Ryan. All right. Bring it. Yeah. Um, so that's, that's there for your listening pleasure.
Um, and then the threat modeling workshop, which is coming up quickly. We're gonna have Mitre, we're gonna have Red Canary. Ryan pulled some strings, and I mean, this is gonna be fantastic. So, um, please, uh, tell friends, family, neighbors and everybody about that. The next, um, our very own Kelvin Gellar, uh, and he's got something called the cyber drain and Kelvin does a phenomenal job with his CTFs. Um, so I want everybody to know about that last time he blew that out.
Um, this in terms of registrations, um, and, uh, I was hoping he was here to tell everybody a little about it at the end. If he is, we can, if we have time. Last few things. Um, CMMC, webinar part two. Uh, part one was awesome last week with Ryan Bonner. For those of you that don't know Ryan and or if you do anything, uh, in the defense industrial place, I highly encourage you to come listen to him. Wes, what are your thoughts on Mr. Bonner there? Yeah, I love me some, Ryan.
Um, he's one of the few in the industry that truly knows what's going on with CMMC, and, uh, obviously every conversation I get into, I was in Amelia Island last week and that was a huge topic. It's, um, so yeah, Ryan is awesome. Uh, great person to talk to and know for sure. Yeah. And then Ryan heor, oh, sorry, heor, who is the one of the partners at Steel Root who is on the cyber call, who wrote the 21 Things You Should Ask.
Your MSP who only focuses on the Defense Industrial base is going to be with Ryan talking about what it's like and how to successively work with a consultant firm, uh, et cetera. So, um, lastly, and this is what today is about, uh, access to the True Methods member portal. Um, Gary, I've known you a long time. You guys have built a tremendous, uh, bit of content in there, um, and very, you know, prescriptive in how you do it. Uh, want to give a huge set up for the folks at Cisco.
Um, they sponsored, um, a lot of the work behind the scenes, uh, economically for this to happen. And, um, and you're a beneficiary of that, by the way. Um, so we're gonna be talking about that today. Uh, Gary, um, yeah, it's 10, it's 10 years. It's 12 years of my life. Yeah. So, um, uh, if you get in and you don't think it's awesome, just don't tell me 'cause my feelings will get hurt. Nah, you can tell me my feelings never get hurt. Fair enough. Throw up a poll.
Um, this would be helpful if you, if you guys could just let us know, guys and gals, um, about, um, your own security posture. Um, and that's up there for you to let us know. Um, again, it'd be real helpful if you could, guys could participate. It only takes a click, uh, in the poll and it's anonymous, uh, but it kind of gives us some context on where your practice is. Alright, so Gary, with that, um, talk to us a little bit about big day to day.
They're gonna see the True Methods member portal. You're gonna show us Yeah, a little bit about your last 12 years of work. Um, this is something that people pay at minimum three 50 a month at minimum. And you have people that pay a lot more, but give us some insights on what it's about. What are you gonna be showing? And, uh, yeah. Yeah. So, um, uh, yeah, we're gonna get everybody in for 60 days. We want it to be long enough where they can actually learn the things they wanna learn. Mm-Hmm.
And, um, so when, uh, when you sign up and I'm gonna show you the landing page, um, you'll get back credentials to get in full access, uh, to the entire portal. Also, uh, one of our member success folks will reach out and they'll kind of guide you through. So they'll come on with you, they'll take you right to show you the security track, but they'll also show you the rest of the portal that you're welcome to have access. So this is not a skinny down, you know, version, Andrew.
We want everybody to learn as much and just resources, download whatever you want, like just have at it, you know? Um, 'cause part of this is about, you know, cybersecurity and as we're gonna talk about, part of it is just about your business. So the first thing I want to do is, um, Gary, Why don't you're bringing that up. It's roles based, right? I mean, there's, if you have a team, I mean, you know, it's not just, Yeah, you can have as many people look at it as you want. It's fine, right?
Yeah, yeah. So here's what it is. And again, Cisco worked with us on this. All you have to do is fill out the information on here and say, start my trial. And it's really, it's really that easy and we'll get you going. No, um, you know, no credit card, um, just no strings attached. Um, so, uh, when you come in, you'll see the True Methods, uh, dashboard here, and you see some alerts and notices, um, upcoming webinars. So we do members only webinars.
I think there's, uh, I do three of them a month. And then our team, uh, does another two or three. So you'll be able to sign up and register for any of those. I do a weekly short podcast, usually under five minutes you'll be able to have access to that. And then, uh, the heart of it is, um, our training. Uh, we did some stuff specifically for COVID-19, uh, and I'll go back through some of it, but I wanna get right to here, which is the reason why we're here, which is the cybersecurity track.
And we broke it into three pieces. The first piece is foundations. Oops. Um, we take you through a security overview, myself and our CTO, Bob Penland, just overall the track and where we are as MSPs. Then we have two sessions on Get Your House in Order. One's a short one conceptually, and then there's something called Cybersecurity Jumpstart. Uh, this is a way of evaluating where you are based heavily on implementation Group one.
Uh, we originally did it for our peer groups as a special project, and they loved it so much. We did a webinar for all of our members and we included it in here. Uh, then there's a 20 minute session on Go to market, as well as a panel that we did, uh, on, on Go to market and an eight minute sales role play.
In addition to that, all these technical resources and the folks that are on this call and others, uh, were involved with many of these, um, uh, everything from, uh, resilience, um, you guys, um, uh, Ryan and Wes, you did an awesome job. Um, you know, on that one to incident response, um, tabletops, RM Breach, tabletops, vulnerability scanning, and exploitation, uh, this was done by Huntress, um, shows how people avoid antivirus, uh, and exploitation of, uh, uh, of the web.
In addition to that, down the bottom is the Cisco enablement. So if you're a Cisco partner, we relate this contest specifically to the Cisco security stack. If you're not using Cisco, you can take a look at it. We did this, Andrew and I did this jointly with Cisco, um, to kind of see where they fit in. So, Andrew, one more thing I wanna show here is, um, outside the security track, uh, we have, uh, what we call a starter kit.
If you want to go through and really check out everything around what we have built around being a world class, uh, MSP, all the fundamentals of that, what we call technology success. Um, each one of them has a video that you can watch. This is one on, this is one on smart numbers. Uh, and here's just sales, right? Building a sales engine, short videos are mainly seven to 10 minutes.
Once you get past that, if there's an area that you want to, um, uh, dive more into, such as sales, you can go into that module and you can see how much content we have. Like this is just on controlling the sale, presenting Lead generation. So we have the same thing on service delivery, every service delivery role, a whole area on command, a whole section for resources.
So really there isn't a question that I've been asked in the past 10 years that at some point we haven't done a video to answer that question. So we have something here called Ask True Methods, where you'll learn, you can send me and my team questions, I answer most of them, uh, personally, and almost every time I answer it, a short question. And then I say, go watch this video in this sec. Uh, if you want to get in a full hour answer to it. So does that give a pretty good overview?
That was fantastic. What do you guys think? Um, how about a y if you think, uh, like, or a thumbs up. I don't even know if you can do emojis in there. Yeah, you can. Thumbs up emoji. That's awesome, Gary. Um, so no, I'm very, very excited about that. Wes. Ryan, what are your thoughts? Good stuff. See What people, there we go. Yeah, I, I think, you know, the, the future of, um, so like, okay, maybe this is what I'm trying, took me second my thoughts together.
You know, us on the call, you may be like, man, this is really good. You know, is it critical? Probably. But think about the rest of your teams in your organization that crave this. I see this at ConnectWise all the time, is just conversations I'm having with tons of people that are just trying to learn security. They're trying to get their hands around what the heck this means and why it's important.
Or, you know, I'm, I'm on these conversations with partners all the time and, you know, even their clients are trying to get their hands around it, right? And so education is the future for sure. And Gary, your stuff is top-notch, right? There's nothing better. So, um, yes, it's Really, really, really good stuff. Yeah. It's like we always talk about Andrew, if you are, you know, working in an IT department, you can go and get more resources, do what you have to do.
But if you're an MSP, you can't make this turn just by learning about cybersecurity. You can't do it if you can't express it to, to customers and, and to prospects. If you can't get them to invest the right, you know, amount of money with you so that you can build out these proactive roles and the tool sets that you need in order to deliver it, only your intentions will change. We're not in the same boat as someone who has a thousand users in an IT department.
We're just not, we don't have one person to go to. If we have a thousand, uh, endpoints, we probably gotta go to 40, uh, or 50, uh, different, uh, people in order to be able to change our financial model. That's why we're stuck, Andrew. Well look, you know, the kind of leading into my next question in the poll, um, I'm glad it's actually, I wish more people would vote, but I'm glad it's dead on right now. Gary. 50%. Think about that.
Half of the group that's answered has not implemented IG one C-I-S-I-G one. So think about this for a minute, Gary. You know, for years, and I've mentioned this ad nauseum on this show, so people are gonna be like, there he goes again. But command and the relationship, I've never, I don't think seen a closer relationship to being able to sell and building a cybersecurity program closely aligned. And, and what I mean by that is you have to have command in order to be able to sell.
You can't hire somebody and say, Hey, go build my sales. It just never happens. Gary. We've seen people go through business after business, go through hundreds and hundreds of thousands of dollars trying to hire a salesperson and do, you know, just doesn't happen. The same thing with cyber. You can't go and have a conversation with a business owner, a leader if you're not doing it yourself. 'cause you just mentioned you need to understand the roles, the process.
And as we know, as we get override a boom, that means once an incident happens, guess what, Ryan? Is it more technology or more people in process? More people in process. There you go. I had to wake you up there. So Gary, what? You know, Can I tell a quick story? Yeah. So, uh, I love all the shows like, um, the profit restaurant, impossible. My favorite is Bar Rescue. I love John Taffer. Anybody at John Taffer fan, uh, he goes in to fix these businesses.
And I relate to him because he is never really fixing businesses. He's fixing people. But the one reason why these bars fail is they don't have command. They don't know what their liquor costs are. They aren't tracking their inventory. Uh, they don't know, they don't know the four or five things like how much each stool should generate in revenue. How those things could get it up by 15% by doing this or that they don't have command.
The difference is the bar owner's just gonna lose money and go out of business. His customers aren't gonna get a cyber attack and pay millions of dollars in ransom. Right? Right, right. The concept is the same that they fail in most businesses. 'cause they don't really understand their cost drivers and their key metrics. And the same thing is happening.
So what I'm seeing, Andrew, is like my peer group members who came into these last couple years already understanding their drivers, their packaging and pricing, their value proposition. This has just been fuel. It's been much not easy, but it's been an easier transition. And they're selling more in commanding more. So we wanna, that's the reason why we're doing this. We wanna give everybody access to the basic information to be the kind of business person you need to be right now.
Not just the kind of technical person, uh, with security, more security knowledge. Although there's a bunch of, although there's a bunch of, Yeah. Well, you and I were talking this weekend, Gary, I turn it over to you to start asking Ryan some questions.
But you and I were talking this weekend, again, when we look at the cybersecurity framework, and you look again left of boom, which is, you know, again, you know, really where MSPs play in cyber, which are all around the preventative or protective controls and some detective. But if you look at that, uh, you know, I said, Gary, this is where everybody's adding tools, right? Well, what do tools do? They typically generate something a lot of noise, which is more tickets, which increases cost.
And you were saying like every time you add a tool, a lot of times MSPs just look at it of, okay, my hard cogs are this. If I mark it up here, that's awesome. I'm, and that's Like, and their margins, they think they're making 50% margins on a tool. Um, but they're not accounting for everything else. And now there's a general tax that all tools have, which is, there's so many of 'em to manage, and it's becoming so complex. You need a higher level person spending more time.
So I call it the tools tax, uh, on it. By the way, if anybody wants to know what Andrew and I do on the weekends, pretty much this is it. It's Pretty, it's pretty much the cyber call, uh, except, uh, we're the only two that are, we're the only two that are on it, right? So that's a really great point, Andrew. People are not considering all of these other costs.
And so we see the bottom half of the market when they don't understand why they're, why they're, um, uh, margins are, are getting squeezed. And I can't wait to get back out on the road now. Like I had my scheduled for my first event, uh, since the pandemic and start talking to people and really, you know, finding out where they are, finding out, Hey, how much has your price changed in the past year? That one question alone is gonna let me know where they are in their security journey. Mm-Hmm.
Very cool. Well, lemme like, turn it over to you. You got some questions for, uh, for Ryan? And, um, oh, and by the way, I didn't say this, but I, I just wanna say again, there's a lot of conversation about CMMC out there. I just wanna give a huge shout out to, uh, Ken Tripp and, uh, Jim Smith of, of networks. They are the ones sponsoring, by the way, all that stuff for CMMC and you can win a consulting gig with Ryan. So, sorry about that. Go ahead, Gary.
First I have to give my, one of my favorite John Taffer lines. He looks at guy in his failing bar, the owner, and he says to him, I'm gonna give it to you straight. That's why your first wife left you. It's not the drinking. Yeah. That's giving, that's giving Steve, Steve drinks. Oh, by the way, if anyone out there is thinking about buying a bar, only buy a bar. If you want someplace to drink, do not do it to make money. Yeah.
So Ryan, um, you know, we talk a lot about successful, repeatable, scalable, profitable security practice, but you know, I want you to talk a minute about how much that's dependent on a strong security culture and internal program. Yeah, I mean, this is an interesting question for me. Um, when I joined Datto, for example, uh, four and a half years ago now, um, that's crazy. Uh, you know, there are a lot of people that are like, we gotta get you out there. You're an expert.
We gotta get you talking to MSPs. And I'm like, no, I gotta get my house in order. I don't have any credibility until I get my house in order. Like, if I don't, if I don't build this thing out and start moving this thing in the right direction, no one's gonna listen to me. No one's, no one's gonna take what I have to say. Seriously. No one's gonna understand that I'm, that I'm not just another talking head. Um, and so I think you have to have complete command of your subject matter, right?
So if you're trying to go out and you're trying to grow your business by selling security, and to you that's selling a couple tools, but you don't really understand the larger landscape, you don't really understand, um, like some of these fundamental concepts we're talking about lift and right of boom, um, you know, really being prepared for for when it happens, um, you're gonna struggle and you know, you, you might get away with that with some SMBs, but the customers that, that are really looking for a true secure MSP partner are gonna be able to see through that.
And so to me, command is absolutely critical. And it has to start with yourself. If you can't look yourself in the mirror every day and say, I'm doing the right things, I'm moving my ship in the right direction, um, then it's gonna be really hard to to have a, an honest conversation with SMBs unless you're gonna say, Hey, you know what? We're moving in this direction and we're gonna be doing it with you and we're gonna be learning on this journey with you.
And maybe, maybe your customers will like that, maybe they won't. But just the most important thing is being honest. And for me it starts with really getting your own house in order. Yeah. Um, well, I'll tell a quick story. So it was pretty early on. It was like DA Ocon, it must have been maybe the first DA Ocon after you got there. And, um, Rob Ray said to me, you know, I was running a content track.
He's like, oh, we'll we'll get our vvc uh, our vvc ciso or get our ciso, um, uh, to do a panel. And, um, he said, yeah, he, he doesn't really think he wants to do presentations. He doesn't, you know, he doesn't really know how how good he's gonna be at this. And then you came on the panel, and then after that I went to watch one of your presentations. I'm like, Hmm. I think Ryan knew he'd be good at it. I I did, but I, I just, I'm not gonna, I'm not gonna represent something.
Um, I, it, to me it's disingenuous, right? And, and to me, like when it comes to security, there's a moral and ethical responsibility when you're, when you're putting yourself out there, you have to know that your business is doing the right things. Right? West can sit here because he knows perch 1000% puts their customer's security and their security first. Yeah. Right? And it's the same for me right now. I needed time to build that out. And I, you know, Rob was right.
Like, I could have stood up on stage that first a con and I could have done just fine. But, um, it doesn't mean anything if, you know, 'cause 'cause a lot of MSPs at that point would've been like, Datto security, what those things don't go together. Right? And it took a couple years to change that, that that culture Yeah. Of, of Datto within, within the MSP ecosystem really. And, and you know, that's not to say that we don't have room for improvement every MSP vendor does.
Um, and that's why I'm still employed and, you know, that's why I'm having fun doing what I'm doing every day. But, um, you know, you, you gotta, to me, you, you can't, you can't stand up and, and not know what you're talking about and not have your own house in order. That's just, I don't know, malpractice. Malpractice.
The next question I had, so you've touched on this over the past year a couple times, but I thought today, uh, would be a great day to have you talk about it because I, I love your perspective. I know part of your job is once you understand the landscape and the risks, you have to go to stakeholders. Mm-Hmm. And you have to be able to communicate that. And you have to sometimes be able to get budget in the form of either tools, services, or people.
And that's what, in a more complicated way, that's what we have to do as MSPs. So can you talk to that a little bit and, and maybe give MSPs some advice, uh, because I think it really parallels and, and you've drawn it a couple times. It's really awesome. Y yeah, I mean, it's a bit of a broad question, but, um, you know, the, the business didn't hire me to just say, okay, go do what you need. Right? They hired me to say, help us understand what we need to do and why we need to do it.
And so there's a really important partnership with your leadership team, your executive team or your board if, if you have one as an MSP, where you need to start having these kind of, these really honest conversations about where you are and where you need to improve. Um, and one of the things that I like to do, um, right, I, I do a lot of benchmarking exercises. Like we kind of know where we sit against frameworks and a capability maturity models all the time.
And we communicate that up to our executive leadership team. Uh, I meet with them on a biweekly basis. Um, and we have an information security steering committee as well, which has roughly half the executive team. And then we meet with the audit committee, um, at least bi-annually. So we're presenting all of these internal artifacts. And then the other thing I do is I say, but don't take my word for it.
I hired this external company and I had them come in and I had them look at what we're doing and I had them benchmark where we are and they actually think we're a little better than I think we are, you know, which is good, right? You don't want them to think you're worse than you think you are.
But once you kind of really have that foundation of trust that you, um, that you've assessed the right things that you know where you need to kind of invest next and you have a solid plan for it, the conversations really change. They become less about you justifying what you wanna do and more about how can we help you accomplish what you need to do. And that's really what you need the conversation to shift to is one of how does the business become a supporter and an enabler of what you do.
And again, I go back to this thing with MSPs, you're in a very unique position for most companies. Cybersecurity is a cost center, right? Unless you're in like financial services, like, you know, your security can matter and like, there's a few places where security is not a cost center, but for MSPs, if you get good at security, you can turn that into profit.
And so getting your own house in order, going back to the last question and getting executive buy-in getting leadership buy-in getting board buy-in actually creates a new revenue stream for you. Um, and so I don't understand why more MSPs aren't like chomping at the bit to go after this. So I don't know if that really answered your question. Yeah, no.
You said something in there I wanna make sure I highlight, uh, around this is that, you know, you start to turn this from a cost center into, they get to the point where they want to help you. 'cause they know you're on the same page of helping them achieve their goals of data, right? Yeah. This is part of it. That's, that's where we have to get to as MSPs with every one of our customers.
You know, Ryan, you're not asking, sometimes part of it is you need a tool or a resource or something and it costs money and you're asking for budget. You don't make any more money. You're doing that because it's just the right thing to do. Correct. And so, as MSPs, our customers, although we do need to make money 'cause we're a business, they need to see that these recommendations that we're making, they need to see 'em exactly the way.
Go back and listen to this again, what Ryan just said for the next few minutes because it's exactly the relationship that we need to have with a hundred percent of our customers, man. Right? I mean my, i the, the sentiment that comes to mind for me is you're gonna pay for it at some point. You can pay for it now or you can pay for it later. And paying for it later is gonna be a lot more painful and a lot more expensive. Right?
So getting your house in order, you know, and, and business risk tolerances are gonna be different. And you have to calibrate to those. Like, I, I, I think, you know, I think Wes and I are interesting 'cause I can kind of tell Wes is also a person that doesn't come from a place of, no. And that's the same with me, right? Like, you wanna go build candy bar and you wanna, you wanna make candy bars and sell them? Cool. Let me figure out how to help you do that as safely as possible, right?
And I'll tell you what I need to do that, and then we'll run the numbers and, and, and we're actually so serious about it that we're actually shifting our risk management program at Datto to quantitative risk, which is extremely rare. Like the number of people that are doing quantitative risk is like mostly in like healthcare and financial services. Um, and so, you know, we're, we're like, we're very my executive team and my board is extremely serious about understanding the risk.
And we got them to that point of wanting quantitative risk because we walked them the whole way through and they're like, alright, we understand that there's, there's this risk, but we still don't really, And there's a cost to it. That's why they wanna do it. Cost. Yeah, We don't, but we still need, we need more data to make this decision. We're like, okay, we can help you with that, but we need to change our framework.
We need to change how we have these conversations and we need to root these conversations more in, in financial terms, in terms of what it costs to fix them, what the, you know, probable loss scenarios are, what the costs of the business would be in those loss scenarios. And again, most MSPs aren't gonna get there, but you can sit down and have a reasonable conversation without going through like Monte Carlo simulations, right? To, to figure that stuff out.
Like you, you know, 90% of what you need to know and when you're getting started, like, I didn't have this when I started at data four years ago was me, my gut and a spreadsheet, right? And then going out and having conversations. Um, yeah. So it's, I mean, you got, you have to start the conversation. That's like number one, you have to start the conversation, be open to being wrong, be open to having more information, uh, come at you. But you, you have to involve your internal stakeholders.
You have to create a culture around, uh, wanting to, to make that improvement. There's another nugget in there. He's always leaving little nuggets. Another nugget in there. I say it in a different kind of way. Uh, datto's costs have already changed. That has nothing to do with Ryan Weeks. Your job is to help them figure it out, uh, understand what those risks are, have them attach a value to it, go over the solution and have them make better decisions. That's exactly what MSPs do.
That's our VCIO role, right? Like to a t if we could, if I would've said that, you wouldn't be able to know what role I was saying. And so that's what we have to tell all of our customers. We're not raising your costs. Your costs have already changed the marketplace. Okay? The environment has changed your cost. And you, you can't not, you have to live with that. That's the reality of, of being in business today. We're just gonna make sure you see it clearly and make the best decisions.
Yeah, I mean, I love that if you, you know, your costs have changed and if you're not paying down that debt now you're accumulating interest on it and it's gonna cost you more in the long run. Awesome. I have one last question for you. Um, you mentioned about asset, uh, management, um, you know, and we saw how many MSPs aren't all, all, all the way there. Um, and that's just one security control.
Can you just talk to that and try to really make sure that you're communicating, uh, this based on those poll results? Yeah, so I think I was sharing a story with, um, Andrew and Wes after our last, um, cyber cast about, God, it must have been like six months or so ago. Um, someone reached out to me, I think it was through LinkedIn and said, Hey, I run a peer group. We're working through CIS foundational controls. Um, would you be willing to come and talk to my peer group?
And I'm like, sure, how long does your peer group meet? And they're like, well, it's three hours, but we don't only need an hour from you. And I'm like, okay, sure, yeah, we'll come and talk. I'm like, what do you need help with? And he's like, well, all of our members are working on basic right now. Um, but none of them, like they, they're all working on the stuff that's not asset management. No one wants to do asset management.
Can you come to the peer group and talk about why asset management is important? Um, and I'm like, I would love to. Um, so I got in there, it was, I don't know, maybe a dozen MSPs. Um, we talked for three, we talked for the full three hours about asset management.
And I just kept giving them example, like example after example about how, if you're doing this thing today, or you're building this control in the CIS control framework, and you haven't built your asset management inventory, really, ultimately what it means is you're doing things and they're making you feel better, but you don't actually know that they're making you safer.
And if there's one thing in this world that I am like allergic to, um, it's a false sense of safety when it comes to cybersecurity. And so for me, like every single person that I've hired into Datto, the first job I give them is an inventorying job. Go understand your world and build me a highly accurate inventory so that we can start making better decisions about how to start protecting some of this stuff. And that's where it all starts, right?
I mean, I'm, I'm hiring some world class talent and I'm telling them to go build inventories, right? Think about that. I mean, just, you know, for example, just brought on a guy who's, um, a business continuity and disaster recovery professional, right? And I said, Hey, I need you to go review our inventory of bis and I need you to look at them and tell me where we need improvement and um, where we're missing information and let's do 'em all again. Right? And he was like, okay, right.
But like, that's effectively an inventorying exercise. And so you, asset management is a subclass of inventory, but having inventories, whether it's business processes, employees, uh, data asset inventories, um, software assets, third party vendors, hardware assets, like there are so many things that you need to have control over from an inventory perspective if you're gonna build a cybersecurity program that really works.
Which is why every single framework that has anything to do with information security has asset management as the first thing to do. So even you, You know what? I can't, yeah. I can't tell you how many times I talked to an M Ms P that had a breach and I'm expecting to feel like this this big, you know, big bad guy came in and I say, well, what happened? He's like, yeah.
He's like, well, we have all the tools, but someone, you know, provisioned a pc and one of my people put it on and we didn't have it on our tool set. And they found that one, I'm gonna guess here, one of the things we did every quarter at both my MSPs, um, we did a centralized client by client when we did the rest of our best practices, one of them, them was an asset and tools check that we knew every asset for that company because it's spread across.
We had 160 clients in the first, and we did a tools check. And do you know how often every quarter we found something that didn't have something deployed because things move fast and clients and, and sometimes our didn't close gap or, or was part of it that we didn't control around the, the customer, one of our employees. And so just so, so critical man. Yeah, absolutely. Yeah.
We, I mean, at this point, you know, for where we are at Datto, again, when I came in, we were missing some inventories and we, I literally went to the data center and walked the data center floor with the operation staff and the internal audit staff and said, where's this box? Show me where this box is in inventory. Tell me what it does. Tell me who owns it. Tell me when it was deployed. Like, um, you know, and where we couldn't find information.
We started to build that competency and it started with just walking around and pointing at things. Now it's all automated. We have a, we have a bucket of things that if something shows up and it's not known, it pops into an audit group and there's an SLA around reviewing everything that shows up in the audit group. That's awesome. And it took years to get to that point.
But again, it started with let's drive to the data center and let's walk the floor, and I'm gonna pick random boxes out of racks and say, where is this? Right? Awesome. It, it, again, you don't, there's not a perfect place to get started. You just have to get started. Gary, I want you to talk to Wes. Yeah. And Wes, by the way, Wes did a fantastic job in the cyber cast about looking at incident response and the implications of poor asset management to incident response, which was fantastic.
The other thing that Brian Blakely, Brian was phenomenal in this, but Brian Blakely brought up, which is something he's like, I don't know how many MSPs know about this data flow diagrams or DFDS as they're called.
And I thought it was interesting and kind of an exercise for us all maybe to start to think about, because if, if we start to, if we start to understand the relationship of assets and how the critical how data flows and the critical data, you can have quite a business conversation with prospect and customers that they probably never had before.
And even before you get to data flow diagrams, just basic questions about how people run their business and asking basic questions like, let's go through all your apps and data and let's talk about, uh, how you would prioritize them and what would happen if you didn't have access to 'em. And these do a workaround we can use in case that happened. It can start that simple. But Wes, That that, uh, I'm sorry. So you said it easier, but that's really around resilience that Ryan talks about.
It's like, these are most critical assets. What are we doing to build resiliency in the event if and when? 'cause we are going to have a breach. By the way, same questions I ask if I'm prospecting. Has your vendor asked you this? Eh, wes you're presenting at Secure coming up, right? I think so. Yeah. Um, tell me what you're gonna be talking about, man. So, because That tells me what you're thinking, what topics you pick tells me what's on Wes' mind right now, how he sees the world.
Well, uh, we've got some cool things that we're gonna be talking about, um, Bryson, so if you guys don't know Bryson Met Lock. He's our director of threat research, and he's like, he's awesome. Super awesome. Yes, he is. Uh, and maybe I'm just gonna shout him out for a second because I'm working with him on some things and I'm gonna help him promote a couple things that they're working on behind the scenes. Yeah.
So one of them, uh, I can't talk about too much other than to say, uh, it's going to be a usable tool that you will have access to. It is completely free. What would Happen if you talk, what would happen if you talked about it? Like, will you die or be arrested? Uh, yeah. Bryson has, Bryson has a, uh, a, a a, uh, group of ninjas that he's been known to send after people. All right. Uh, which are better than helicopters, by the way. I, I happen to have a large helicopter fleet.
But, uh, so anyway, this tool is going to be free. Uh, it is going to be highly usable and it's going to be community driven. So it's gonna be, it's super exciting. Uh, and this is a lot of Bryson and his team's creation. So we'll be talking about that. Um, you know, I, I will be doing like a, like a main stage kind of presentation thing on just kind of where we see the industry going. I'm gonna kind of dive in a little bit into the results from the Perch threat report.
Um, just talking about, you know, where MSPs have gone. We'll be talking about what the future is looking like in terms of how I see it, in my view of like where regulation is coming into play, how it will play out. We've talked about this a lot on the cyber call. Yeah. So many of you may be familiar with this, but most of the people there won't be. Uh, and then the other thing, Gary, I would just say, I'm gonna pop this in. What's kind of cool about this year is it's a hybrid event.
And if anyone's, I'm gonna be there in person, which I'm super duper, duper pumped about. Um, there is the content. Most of the content, I'd say 90% of the content is not ConnectWise. Uh, this is led by other vendors, people, um, some awesome people. I saw Matt Lee on there. Um, there's a ton of like people, you guys partners that are generating in leading content. Jason Slagel, of course, is working last minute on his slides.
So this is gonna be a great event because it's really, really partner sourced and partner driven. So just take a peek through that. And again, if you haven't made plans to go, but it's possible for you to go, I would love to see you there. It's gonna be a great event, Carrie. Yeah. Awesome.
And, um, I'm just thinking about how like getting together, and you and I presented many times at, at IT Nation Insecure, um, just what a different world you're presenting to than the last time you were in person with people, right? Yeah, it's, it's different in every way for sure. Um, and, and you know, I welcome that I, I, I am glad that we're in a situation in which the world is constantly changing around us. I'm glad to be back in person again, at least hybrid.
Uh, and, um, yeah, it's gonna be great, Gary. And, and I wanna ask this about like this, 'cause this comes up a lot. I know like in our portal, we have to cater to both. And even if you look at the track that we did, some of it, I'm really talking to the business leaders, you know, uh, in an EMSP and other ones, we're talking more directly to the, the doers, the technical people. And you know, how do you look at that?
Obviously your technical people have to know more, but as business leaders, we also have to have a level of education around these things. And so maybe to the point where of an MSP might not sit through a technical track, they, they might consider that more. Now, don't you think? Yes. Part of what you said cut out. I dunno if it's on my end or yours, but I I caught enough of that to get the gist. Um, so the boardroom is truly where the agenda is set.
The strategy is driven and the budget is aligned. That's the truth for Fortune five hundreds. That's the truth for MSPs today, and that's especially true of their clients. And you know, Gary, just as an example of this, I was, um, at a conference on Amelia Island last week with, uh, Mike, Mike Estep from Becca, it, one of our awesome partners. And I was speaking on behalf of Mike and Becca really is just a conduit to a whole bunch of engineers.
So these are like CFOs and CEOs of Georgia engineering firms. So really large down to small, you know, you name it, chemical engineering, mechanical, whatever it may be. And I, I, you know, I, one of the things I told them, Gary was like, you know, oftentimes the IT guys are begging for help and the best that they know to do is scare people into action. You know, these big scary thready threats are coming your way and you gotta do something and then it doesn't happen.
And then you're the boy that cried wolf and I just asked them, is for you guys as executives in that are not practicing it, raise your hand if you feel like that's been the case, and like 90% of their hands go up, right? And so I come, okay, so here I am as your conduit, right?
Is what I said is maybe the, the ambassador for security people that want to share what they, they want action, but they don't know how to get it, and they wanna scare you into it because it's the only way they know to do it. And so, um, we talked about that and I got some great feedback from them. They're like, yes, that's how I truly feel. And so Gary, you know, we talk about this a lot, but really the truth is in security, it's a lot of, like what Ryan said earlier, like aligning risk.
What does the risk look like to the organization? What's the impact of it? Uh, what are the results from it? One of the things we also did at this event last week is we brought a, and there was a really awesome company, a very large, about a thousand employee organization that, uh, it was an engineering firm that went through a breach last year. And he shared how it happened. He shared some things like, man, they were in our network for 30 days. We didn't know he shared how it happened.
He shared the aftermath. He shared, you know, how difficult it was. You know, their view now of security going through it. And, you know, just, that's a great example to think like, okay, look at how that organization is now post breach. How can we generate that same attitude pre breach? And again, I think a lot of it comes down to distilling or dispelling the misinformation that I think a lot of people have, which we've talked about. Like, I'm too small to be attacked.
It won't really cost me much. I, you know, I don't have data that anybody cares about. They don't understand how ransomware works. It's not just stuff that you have to pay money to get back, but it's a complete business outage. And it's our job to illustrate to them, look, when ransomware hits, you're, everything's out of commission. Things aren't running business prop, uh, business processes are failing.
And so this was like the eye-opening moment for everybody that was at the conference to hear right from a peer what this did to their organization. And so, again, I think it's our job to communicate through risk and clear communication, Gary, why this matters for our partners. And just to go back, it starts in the boardroom, it starts with the decision Makers. And I'm gonna take it one more step. Everything you said, and now I wanna talk to a customer or a prospect.
And what I always tell our members, don't tie the results back to tools. Yeah. Because you're tying it back to something that is generic, no matter what tool you use. Every perch is awesome. Everyone can buy perch if they want it, right? You have to use that as almost an assumption. And if someone doesn't have everything in the stack, it's a negative. Then you wanna go to your roles and process. And as you uncover Paine, you wanna tie it back, Hey, can I show you an example?
You mentioned this around passwords. Can I show you the nine questions we ask on a quarterly basis about passwords? Do you understand why my customers don't deal with the same things that you think everyone deals with? Yeah. Do you understand why they're willing to invest a little bit more so that we can take the time and have the role to do that? You wanna make clearly in big, broad strokes, you take that one last step, and that's how it communicates, uh, to customers and prospects.
And that's how you make raving fans, right? Is that you're able to show them an end state. They want that end state, and then you simply show available and they're really gonna get it. And that's when everything starts to change. Wes, think about if you're an MSP, you are still running the old businessman, like every, there's nothing that we aren't doing that we were doing before. Now we have everything else that we talk about every week around security here.
And so the complexity of it is, is, is so high now. That's why we keep harping on the fact that they gotta, they gotta start to, to, to put boxes around this, you know, in terms of the roles and their process and their standards, and equate that to what they, what they charge customers. Not an easy thing to do, but that's what we're trying to do.
Bring it back to the portal, Andrew, is not only give them access to, we talk about that stuff related, but go into and dive deeper into our sales, into our packaging and pricing, into our command session. Go in there and see how exactly the framework of how a high performing MSP is designed. Gary, you just said something that I, I wanna bring up to you. And, and again, it's, you always say, I'm not here to clunk people, but really bothersome to me right now.
72% of the people that answered this question said, no, we have an incident response plan. We've assigned roles and tested it. You just said you're gonna have to have conversations around people and process if you are an SP. And you get, if you answered no, just, and by the way, let's talk content. Don't Tell your customers that. Yeah, yeah. Please don't tell your customers that.
But so in the portal, we have phenomenal content about building your incident response plan, running a tabletop, so you can't use that excuse anymore. But Gary West, tie this back to business conversations. I mean, my gosh, Let West take the first shot at that one. Tying it, tying what part? Back to business conversations. Just how we communicate to a decision maker. That's not technical. We know this. No, we know this.
We know that 70% of the people said they, they don't have a well documented, tested IR plan. We know that about that same percentage have not had a cybersecurity conversation with every single one of their customers. There's two examples. You mean a cyber insurance Conversation? Well, I know I've had that conversation. I, I want to Hear both of you guys then. Go Ahead. Yeah. Ryan, you start.
Yeah, so there's, um, there's, there's a company that actually does data analytics of companies that have been breached. And they found that companies that are, um, un under prepared, they don't have proper IR and proper, proper crisis management. The cost of the breach is on average three times more than as if they didn't have it. So if you, if you can estimate, you know, for the size of your environment, your ransom's probably gonna be around a hundred thousand dollars for your business.
The downtime for us to recover for you, you're probably gonna be out for five days. So, you know, the cost of your downtime is this, and your ransom amount is this, but oh, you don't have a proper IR plan. So let's multiply that number by three. Wow. Yep. So here's some thoughts I have and I want to ask in the, to the audience, those of you on the poll question two that Andrew is referencing, um, you know, we have an IR plan, but we haven't tested. If you're No. Give me a reason why.
No, Gary, here's what I think the reasons no are gonna come down to is one possible reason. We just haven't had time for it. We want to, but we haven't had time for it. By the way, My defense, dude, I'm very busy doing tickets and alerts. Yep. There, there you go. And one thing I always say, this is a mental thing for Wes, whenever I say I don't have time for something, what I'm truly saying is it's not a priority. Yeah. That's the reality. And that's okay. Just know where your priorities are.
Anytime someone says, well, I don't have time for this, or I say that, I'm just saying it's not a priority for me. 'cause I'll make time for what's, what's priority. It's only 24 hours in a day. So let's start there. Second reason I think that it may come out is they don't know how, and this is where true methods helps, right? Like I'm looking at the technical resources right now, and you have the recording of the tabletop session that Chris Leer and I did.
So you have at least one guidepost to start on that. So if you're in the category two of like, I just don't know how, there you are. There's your answers three is, you know, I, I'm afraid to go down that road because I don't know what it will uncover. I don't know what my clients are gonna start saying. I don't know that I have the solutions in place to like, repair and work on it.
I would say if, if you're kind of scared into inaction, you have analysis paralysis, the best way to start is to start. Um, and then have honest conversations yourselves to say, look, this is a, this is a a path. We're gonna get there. We're gonna pick the top three priorities and go from there, right? Um, in instead of being scared and in action. So I think those are, and you're seeing some come in, you know, Joe's saying, yeah, resources and knowhow is, is definitely there.
Um, Ryan, I see you popped in a link if you wanna chat about that. Yeah, someone had just asked about, um, where I got that three times number from and, uh, I put in this analytical report of, uh, companies that have been breached and where that number comes from. Got it. Yep. And, and I would say too, oh, go ahead Andrew.
I was just Gonna say what I just, again, I I, I think Gary has it in the portal, but just again guys, if you haven't built your incident response plan, it's sitting in Cyber Nation, Mike Beard, literally sanitized. I mean, you're talking about a 1200 person MSP, who's gone through a SOC two type two. He sanitized and we did an entire, we collectively did an entire, um, oh, there it is, Gary. So go into the two methods, go into site, just but get, go. So sorry, go west, please.
Yeah, no, that's, that's it right there. And so the thing you've gotta remember when you're beginning all this is something is better than nothing and something leads to the next thing. You know, in the world of SaaS companies, of which, you know, I've been embedded for a long time now. We talk about this agile method.
And agile is all about, you know, as you're building something, it needs to be functional along the way rather than like, I'm trying to build a card, it can't come off the assembly line. So the whole thing's done. I gotta start with, you know, the engine, the chassis, blah, blah, blah. No, no, we're talking about start with something, even if it's a shell and a little copy paste of Mike guard's sample incident response plan, and you just work from there, now you've got one.
Then you can begin to, to enhance it and test against it and see how you can map it in. You can begin to add some ancillaries with it, like a business impact analysis and even the BIA itself. You can start very simply with just known internal critical MSP processes. But you can begin to go down this road, but it doesn't happen until you begin the journey at some point. And so, um, I would just encourage you just start on it.
Uh, and, and again, if you have this challenge, Gary, you talk about this more than anybody of everyone's assigned to tickets and they're ticket generating and you know, uh, you may have a, a business process problem in the Ms. P or you need someone to be assigned and focused on cybersecurity. And I think, Gary, don't you agree that all MSPs eventually come to that size and complexity by which they say somebody in the MSB has got to focus full-time on security and not juggling tickets?
Yeah, I'll say proactive security is part of it, right? And it's a big part of it. But, but it's proactive. Having people that have a dedicated, proactive role or, or function. That's basically what we teach. That's the secret sauce of true methods and is getting people to do that, to see the results. See, when I started True Methods, I thought there we, I have a video in our start, in our foundations called the Four Steps Success. I thought in the beginning there will be two steps.
I'll tell people what to do and they'll do it. Then it turned out that way, okay? Because they were busy doing tickets and alerts. Turns out they had to have desire, right? Then we gave them the knowledge. Then as they implemented, they saw some results that changed their beliefs and their expectations that built their desire. And we got the thing spun up. Otherwise in this business, and I know people who've been in it for 20 years and they're in the same place.
They just come in and they just deal with the tickets, alerts, and projects that, that are always there for 20 years. It never, it never changes. The first thing that has to change, if you want, you, yourself and your customers be more secure, the first thing that has to change is you. Yep. And you said something that really got me thinking, Gary, is like the whole reason we went into managed it from break fix is for the pro be the, the proactivity out of it, right?
Let's be proactive and we can actually reduce costs in the longer term and, and then give you the all you can eat. But in security, we're still working towards that. Most of us are, we're not actually proactive in security yet, even though we've mastered that in it. We have a long way to go in security and we're still so often break fix and we have the menu and the olive cart stuff. I don't Think we've mastered it in it and maybe not.
I think that a lot of people call proactivity the same thing they're trying to do with security. They call it tools and it's not. Yeah. Proactivity is roles and process and discipline and security now is just shining a spotlight on it. 'cause before it was great what those results were between great vendors and average vendors. Now they're real easy. The same way you can have different jobs, but if you're in sales, it's really easy to judge you, you sold or oh no you didn't. Right?
You're a business owner every month you push the p and l, you get a report card. You grew and made money and, and, and are profitable or you're not, no matter how great you are or how much your customers love you. Yes, indeed. See Andrew, I knew what happened. Three minutes left. I got all fired up. Well, Look, I want to, I want to just share what you've been talking about and again, why I was horrified about the IR plan.
Um, again, Ryan and Wes do a great job at different times in their cyber resilience webinar talk. Oh, it's A great session. You go to that one right away when you go into our portal, it's awesome. Can you guys see my screen by the way, Gary? Yes. Okay, so look, here's where the, here's where Boom happens, right, right here, right of boom is over here. This is by Sunil Yu like the guy's world known in terms of, you know, who he is, et cetera.
But look at the change from technology to people and process. Gary, you hammer this home week after week after week. Tools are not gonna save you. Hey, uh, Andrew, I have a great analogy to this or example that may be an example of this is, so two weeks ago I did a session with, I'll just say the name 'cause they're awesome. Is J Mark one of my favorite partners and they brought a whole bunch of banks. They're awesome. They are awesome.
I brought a bunch of bank, they, they brought a bunch of banks on. I just talked about the journey of detection and, and I shared part of that with them. And, and I shared, look, as you go down into detection, response and recovery, first you can't even have response and recovery until you detect something one way or another was detected poor you or you detect it. Um, but then the next thing that came out of it was look, just like you said Andrew, look how people begins into this whole process.
And one of the banks made a comment, they wrote into the chat. They said, so I'm looking at a new solution that's gonna be $2,000 more, but it actually has people reviewing the logs. Is that worth it? And you could tell that question would never have come up in his mind until he saw that graphic and understood that this is a people-centric piece, not just technology that you throw at it.
And I answered back, I said, uh, something along the lines of like 2000 a month, you gonna find any person out there that's gonna do that for 20, for for 2000 a month, let alone 24 7, let alone 365. And they're like, I get it. It makes sense, right? And so I love that graphic because it really does paint some of the challenges and also some of the requirements and the client expectations. And all of a sudden they went from thinking, 2000 a month is so expensive to I like, that's cheap.
Like that's, that's minimum wage almost is what that is. Yeah. And it's funny you're hearing that from three guys that all have software and services tools for MSPs. Like, you know, we sell my IT process. So the people that are selling, we make our living selling you tools and we're telling you the tools can't save you. So Gary, we're Necessary but insufficient. So Gary, we're at the top of the hour. Can I just ask that you pop the landing page one last, uh, for everybody in the chat? Yep.
Simple. I'll type it in. It's just true methods.com/cisco. Okay. And look, if you have a peer that you want to share this with, share it. Um, this isn't about us holding back. Yeah, this isn't about holding back. Uh, we wanna help. We do this. We're not here getting paid. You guys know where our passion is. So please get people, let's start working on your IR plans. If you need help tabletops, we're gonna be doing more of it again. So anyway, And we have labor into this.
So someone is gonna reach out from my team to everyone. They're gonna ask them some questions about their business. They're gonna guide 'em through this and they're gonna make sure, see what their goals are that you make the absolute best use of the time. You have to get the most out of it. They're, um, if this was a library, they know the Dewey Decimal system. I think it's called Google these days, Gary. Um, all right.
So with that, everybody, um, thanks for, uh, making episode 53 or session 53. Great. Ryan West, always, thanks for your great input, Gary. Great to have you. Thanks for what you're doing. Everybody. Wishing everybody a fantastic week. We'll see you this time next week. Take care everybody. Thanks Guys. Bye.


