Tying What Matters to Your Clients and Zero Trust that Translates to Sales
In this video, Andrew and Gary discuss the intricacies of zero trust architecture with experts Jason Garvis and Keith from DBK. They delve into how MSPs can implement zero trust principles to improve security and business agility for their clients, emphasizing the importance of understanding client business cases. The conversation highlights the challenges and opportunities in adopting zero trust and how it can be effectively communicated to clients to drive better security investments.<ul><li>Zero Trust is a comprehensive security philosophy and approach that emphasizes the principle of least privilege, securing access for all identities, and operating under a default deny mechanism.</li><li>The shift towards Zero Trust is being driven by the need for improved business resilience, cost savings, and better user experience, with a focus on aligning security initiatives with business objectives.</li><li>There is a growing emphasis on understanding clients' business use cases to effectively implement security measures and communicate value, making it essential for MSPs to engage in business-centric conversations.</li></ul>
Guests
Video Transcript
Alright, welcome back everybody. Happy Monday. Hope you all had a great Mother's Day weekend. Uh, happy to, happy Mother's Day. Belated to all the moms on the call. Gary, I think you, um, you got, you were visiting Gary Junior in Tennessee, right? How did that go? Awesome. We had a great time in Nashville. Uh, a lot of fun. Great Mother's Day with my wife. Awesome. Fantastic. It's not what Sue told me, but I'll, you know, I'll, I'll, uh, I'll just go with that. Alright.
No, I said I had a good time. I didn't say anybody else did. That's awesome. All right. So a few quick announcements. I did put up a, um, uh, call to action in there. Spencer P*****k, who a lot of you've known, a lot of you have seen phenomenal breach, uh, attorney. Um, gonna walk through a case, I'll, I'll get to walk through a case study with him on Data xl. The interesting thing about this one is, it's actually, it's a true case study.
It's actually a law firm that, um, defends high profile organizations. In this case it was a petroleum organization, uh, that, uh, and when the breach occurred. Um, so we'll go through Tech Stack, we'll ask some questions to the audience. I think this would be really interesting versus the, the typical scenario that we do. Um, one other, two other things. Um, just a quick announcement. I don't have registration up yet.
However, we probably anticipate in the next four to six weeks, we will, um, write a boom, MGM, uh, March 6th through eighth of 2024. Uh, keynote speaker is going to be, uh, Brent Gleason, uh, Navy Seal, um, who, uh, is gonna do a workshop. He is best known for, um, his coaching on adverse conditions and building teams during adverse events. And I thought that it was pretty apropos to what we do.
And it's a leadership workshop, so we're broadening out kinda a little bit on the scope of the pre-Day events as well. Um, lastly, uh, we have Jason Garbus here with us today. Um, we'll let Jason, um, introduce himself shortly, but Jason is the author, if you haven't read it, it's phenomenal. Uh, zero trust, security. Um, I highly, it's actually readable. Not a lot of security books are. This one is, and it's very, very, very good. Uh, the fact that I can read it says a lot.
Um, and then, uh, so in setting the stage here, Gary, we are at year three, by the way. Year three for the cyber call episode one 40. Um, can't believe it is three years in the making. Um, we Have a special cohost today too. We do, yes. Thank you for that. Um, maybe let me let you introduce our special co-host because, um, you told him to quit his job about eight, nine years ago. It's a great story. Yeah, I did. So, uh, uh, Keith is here today. He is the CEO and owner of DBK in Dallas.
And, uh, when I met him, DKB, he's close, he's real close. D Kb D kb, sorry. And when I met him, he was, uh, working for Dell, young guy working for Dell. And he came to a, one of my early schiz fest and he said, Hey, you know, I don't know, I'm thinking about maybe quitting a good job and maybe starting MSP. And I'm like, oh yeah, you should definitely do that. Yeah, you be really easy. Yeah, no problem. Yeah. And, uh, he's in our, uh, peer groups and is just one of my favorite people. Yeah.
And just has built an amazing, um, business. But, but he's a good example. Keith's a good example of that security, right? It is good business. Yeah. And the whole changes with this landscape, really, I'd say Keith, are really central to the success in terms of growth and profitability. You've embraced it and it really is what you go to market with today, right? Yeah, absolutely. It's, it's in the, the very center of what we do.
It's that security first and it's the vast majority of of prospects and clients that we sign our, uh, looking at, at doing security better, raising the bar. And so that's where we position ourselves. Yeah, I love, And, uh, and Wes said he's also the CEO of BARF Airlines. Yeah. I have a first class seat reserve for you, Wes, Maria. Look, keep talking. Anybody that makes me strap on a parachute to ride with him, I'm just not sure about this. Some minor detail. Yeah. Yeah.
Jason, just so you know, he is an aerobatic. Uh, he, he flies aerobatic, uh, air, you know, the, the correct Show. He's not, but that's the whole thing. He's not, he's not that He's been flying for 10 minutes. He's not an actor. Yeah. Come on. It's the parachute requirement. He's the parachute, right? Wes, maybe He's Just a beginner, right? This is a whole learning experience. You gotta start somewhere Upside down, but Hey. Yeah, Yeah. Little roll. No big deal, right Keith? Yeah.
It's risk management. It's the same business we're all in. Come on. Yeah. I Think this is one of those things when you renew your life insurance, when you get to my age, that uh, they make you sign that you're not gonna do that. Yeah, very. Yeah. Really? Probably. Yeah. That and the trampoline in your backyard, right, Jason? Um, alright, so let me kind of set the stage here.
Um, so, um, I I, I got a call from Jason or reached out and I was really grateful because Jason, as he'll tell you, uh, held a former pretty big role in, uh, in a security company. And he's like, Hey, I went out on my own. And, uh, we started talking about his role at, um, cloud Security Alliance, which is, uh, a pretty, uh, important role that he, he chairs and, and, and around zero trust, et cetera.
And we started getting into the conversation that, you know, as they roll out more architectures, if you will, in white papers, what is it that, you know, we need to think about from an MSP's perspective? And I said, you know, the biggest thing that I see is we've gotta change conversations. We've gotta start talking about risk to revenue.
As Brian Blakely likes to say, we've gotta start talking about the business objectives because if we don't get into those types of conversations, we're just not gonna get action. And so all this great stuff we're doing is gonna be meaningless if we can't move the needle. Um, and Jason, uh, really aligned with that and it's something they're working on, uh, as we speak at in, in some of the work that he's doing at Cloud Secured Alliance.
But, uh, I was really excited for him that he's gone out on his own. And, and so I wanted to give him an opportunity also to tell a little everybody a little about what he does, his background. So Jason, thank you so much for joining us and, uh, tell us a little about yourself now that you're, you're out on your own, your own shingle, but certainly a background would be would be wonderful as well. Yeah. Thanks Andrew. And I, I appreciate the, uh, the opportunity to be here.
I'm looking forward to a, a lively conversation. Um, so yeah, I've been working in the security business for, um, geez, over a decade ago. Come close to 15 years now. And, um, in a, uh, typically for software companies working in product management roles and leadership roles.
But over the last seven, eight years as I've gotten into this, this area that now today we call Zero Trust, um, I've really spent a lot of time and effort doing thought leadership, uh, working with the Cloud Security Alliance in a volunteer role where I'm now co-chair of the Zero Trust Working Group. Um, and I found that that part of my, my job and what, and my work really resonated, and that got me excited. And I got, um, I felt like it was the right time for me to step outta my own.
So I started my business called Number Line Security. And what I do is I'm really focused on helping enterprises to prepare for, define and execute on effective zero trust strategies. 'cause I really believe that this is a better way to do security, and that we really all have an obligation and an opportunity to pull our enterprises, or if you're an MSP, your customers into this better world, that's a lot more effective. It's a lot more resilient.
And is, uh, has non-security benefits because you were alluding this, Andrew, it's, you know, it breaks our heart, but our customers MSP customers don't really care that much about security. They care about their business, and of course, they care about resiliency, but they don't wake up in the morning like we do and say, Hey, how do I make the world, how do I make this place? How do I make my business more secure? They wake up in the morning, how do I grow my revenue?
How do I accomplish my business's mission? Yeah. And we've gotta learn to communicate that language in the right way. Yeah. And I think it's inherent in human nature. Um, and the study certainly suggests that if things are going well, that things will continue to go well. You know, Gary, you always say everything's fine until it's not. But human nature and, and, and study after study after study show humans are really poor judges of risks.
Uh, and humans typically make poor decisions on the margin when presented information about risk, because again, we don't present it in a good way in which they can actually do something with it. Um, so with that, um, Keith, I really appreciate you joining us today. Phyllis is out sick. Um, we're hoping she gets better very quickly. And in the meantime, um, you didn't take me up on any wigs or alternative lifestyles, but we'll take you like you're, and, uh, let you let you kick things off.
Great. Um, yeah, so, so fascinating stuff. We're gonna dive right in. So, uh, Jason, just to sort of frame up the topic, we're talking about Zero Trust. Uh, you literally wrote the book on it. Uh, so let, let's, let's, um, let's talk about what that looks like. And an important question there is, is zero trust a philosophy? Is it an architecture, a way of life? Like something else? Just tell us what that is. Yeah, Sure thing. And, um, you know, for for the record, I didn't invent zero trust.
There's a lot of really smart, really experience. I said you Wrote the book on it. I mean, put some credit. So it's, I really, uh, yeah. So the, the concepts of Zero Trust have been, had been kind of on a simmer in the industry for quite a while. And if you look at the history of it, a lot of this started with even original principles created by this group called the Jericho Forum.
In 2003, 2004, Google really started promoting it with what they call Beyond Corp, which was their internal zero trust implementation that they started in 2009. They started publishing on, in 2016, John Kinder Bug coined the term Zero Trust with this influential Forester report in 2010 called No More Chewy Centers, where he introduced some of these concepts.
And at, at the same time, I got involved in the, the cloud Security Alliance working group on what was called the Software Defined perimeter, which is an architecture. And all of these things have kind of come together into this, you know, we'll give ourselves some credit, this tapestry that the industry has woven. And Zero Trust is a philosophy and an approach to security.
And it's built on some core principles of enforcing the principle of least privilege, securing access to all resources for all identities, both human and non-human, no matter where those identities are, no matter where the resources are. And, um, operating under a default deny policy or default deny mechanism, both at the application level and most importantly at the network layer.
So that these identities, whether they're malicious or not, can't get access to anything on the network until, and unless there's a policy that gets evaluated and positively assigned to them based on their identity context, their device context, the workload context, or the data that they're trying to access and the overall system, and then that policy gets evaluated, then they get through the principle of least privilege, very pinpoint access control.
So I've said a lot, and there's a lot to it because as a philosophy, it really needs to inform everything about how you approach security. And the good news is that you don't have to do it all at once. In fact, you can't do it all at once.
But it should have let us pivot from traditional, very flat open networks that we know are very high risk, they're not resilient, they put ourselves, uh, and our organizations, you know, at risk of service interruption or data breach, and shift it to a mindset. Uh, I want to enforce the principle of least privilege, and by default, not allow a system or a packet to traverse the network until it's positively authenticated. Gotcha. Yeah. Okay. Awesome. Keith, I just had a question.
Post covid did, did do you guys, and, and the fact that, you know, you guys practice, you know, security, you, you, I think term for us, the, the term, you know, client zero, did this become a bigger thing for you, and is it becoming bigger for you as an Ms P? I'm just curious. Yeah. For us, absolutely. It, it, it is.
And I think it's an area where probably MSPs, MSPs tend to develop some technical debt, because just going back to what you said, uh, if things are running well, you don't have a lot of motivation to dig into risk. But knowing that, that your architecture philosophy has to change, we have to adapt or die, uh, zero trust is absolutely an area that we're exploring and incrementally adding, uh, pieces of that framework in into place. So yeah, it's, it's, it's a big topic for us.
It is, and it's, it's, you know, it's definitely not as big as, as it is and as much of a trend in the industry to understand it's not a radical change, right? It's building on very well proven principles of multifactor authentication role-based access control principle of least privilege, and really tying them together in a way that is, it's more sophisticated and it's more dynamic than it has been possible to do with traditional architectures. Sure.
So, so number line security, Jason, uh, your new startup. Congrats. Um, so you, you plan on working with MSPs and MSPs or maybe describe what your, your target market looks like. Yeah, absolutely. I mean, I'm initially targeting enterprises.
I think Andrew and I have had some great conversations, and I think MSPs and MSPs are gonna be really interesting because it's, it's, you have a, you in this market have a very concentrated view of, first of all, you have a very deep view of your customer's environments and operational responsibility, and you also have a very concentrated view across your whole customer base.
So it's, it's an excellent way for you to, number one, improve your resilience, make yourselves less likely to be attacked, or when you are attacked, uh, to reduce the blast radius, but also gives you the opportunity to really amplify and, and deliver value added revenue generating services to your clients by saying, Hey, for, you know, an extra X dollars, we can provide this service, we can give you, you know, additional monitoring, additional access control, whatever the right kind of vector is for that.
So I think it's beneficial in, uh, in both ways, but it also, I think there is a, a precondition, which I know an Andrew wants us to talk about, which is, okay, how do I sell this right to my clients? Not just, I'm doing a better job for you. Great. It's how do you as a, as a client get more business value out of what we're doing here? And here's why you should invest more with me. Good, good.
So in a recent video, you'd shared Jason, uh, some stats from Google on, uh, some search data, like since on Zero Trust specifically, and growth since 2017, right? Mm-Hmm. Um, so, so talk to us about what the findings are, uh, what's driving the interest. Sure. Yeah. So this was a, um, I did a couple of follow up videos for the Cloud Security Alliance. So I gave a presentation at the 2017, uh, RSA conference, um, where CSA does a a one day event.
And I talked about the software defined perimeter. I talked about some of these principles, and it's been six years since then. So they gave me the opportunity to do a short video where I reflected on that, and what I talked about was a little bit of the history of how the software defined perimeter has become over these years, woven into what today we all think about and talk about as Zero Trust.
And I use the Google Analytics to show, you know, this dramatic growth over that time period of the search term zero trust. And it's now really, it's become very much, certainly mainstream if you're part of the US Federal government because it's mandated that you and your organization follow this. But it's also become adopted by governments and commercial enterprises in US and worldwide. It's really, I would say, an exciting time and satisfying to see that.
And I think, you know, we at the CSA can take a little bit of credit for this, um, and also kind of be, um, excited about the work that sits in front of us, because there's a lot of work to do when you talk to these enterprises and they say, Hey, I wanna talk about Zero Trust. Okay, great. Tell me how you're doing identity. Tell me about your networking. And, you know, especially for the larger organizations, there's a lot of technical debt and a lot of complexity that they have to overcome.
And that's really, you know, that's really the challenge. I don't know that, that, um, saying it's mandated for government that the, that that's necessarily The best commercial for anything secure. I, I think that might be a landmine, maybe we should avoid Too funny. Well, well, you mentioned software defined perimeter, SDP in that Jason. So, um, what's the evolution there? How's that become a reality? It, I mean, it, it sounds like the vision that you cast there is becoming a reality.
Maybe just unpack what that SDP is a little more Sure thing. So the software defined perimeter, or SDP is an architecture and defined by the Cloud Security Alliance. And it, it takes some of the concepts of, you know, what today we calls Zero Trust and, um, captures them in an architecture. Or you have this notion of a separate control plane. In the data plane, you have a controller, which is the policy decision point.
In the zero trust world, you have these enforcement points, they're called gateways, and then you have mechanisms for enforcing policies across those. So, SDP had a couple of elements to it that, uh, have made their way into zero trust. Some of those core principles of dynamic policy, distributed co policy enforcement points, and separate control plane and SEP and data plane. SDP is one of the architectures.
If you look at things like the nist, uh, zero trust architecture document, that's one of the possible architectures they recommend for approaching Zero Trust. And in the latest revision of SDP, we really embrace this and said, look, we're not here to mandate that you have to follow this exact architecture because there's lots of different ways to do things. We love the creative market and different vendors, both open source and closed source, who are approaching things different ways.
Um, and I think what the Cloud Security Alliance did was promoted this architecture, really did a great job of getting the word about it, evangelizing it across the market, and now the principles have enrolled into Zero Trust. It's mentioned, you know, deliberately and explicitly as a call out, as part of the NIST document. And, um, some of the other, uh, federal documents that are becoming kind of wide, excuse me, widespread and widely accepted in the industry. Gotcha. Thanks. Very cool.
Um, I think that was your last one, right? Keith? If I take a look down. So we're gonna hand it on over to, yeah. Mr. Spencer. Um, cool. Wes, congratulations on your new role. I think you're in your new co co-op there. Uh, and, uh, yeah, it's good. You and Princess Leia, Uh, yeah, right. It's pretty awesome. I'm, I'm in Adam Slatkin's office, and if we get to, how about this, we get to 6,000 on cyber call, I'll steal one of Adam's helmets and I'll put it on for a cyber call. How about that?
That's, that's my deal. But we gotta hit, we gotta hit 7,000 or 6,000 babies. So start hitting those, uh, invites to your friends and get, I Think we can accomplish that this afternoon. That that'd be great. Let's make it happen. Let's make it happen. So Jason, I wanna ask you a question on Reddit, we have this thing, thing we call explain, like I'm five, right? Where we take a com complex topic and we try to simplify it down to like, talk to me like a five year-old.
I'm gonna, I'm gonna mimic that, but I'm gonna say explain like I'm MSP. All right. So give me an explain like I'm MSP, what is the Cloud Security Alliance? You mentioned it before, but, um, break it down because I think gimme a yes or no in chat while, while Jason Q's up, um, if you've heard of CSA or not, and if you're using it or aware of it another way other than just the name, give us some feedback, yes or no, if you know it. Um, so Jason, explain to us what this whole thing is. Okay.
So the Clouds Code Alliance is a nonprofit organization based outside of Seattle, and it was formed with the mission of researching, publishing and promoting best practices around cloud security. And I honestly don't know when it was created. I joined in 2015, and it was fairly established by then, and it's a typically a volunteer led organization.
Like all my, all the work that I've done for the CSA has been on a volunteer basis, and there's hundreds and hundreds, if not thousands of people who participate in that across about 20 active working groups. The Zero Trust Working Group is one of the more prominent ones, and we created, uh, actually nine parallel work streams within that. So what the CSA does is it generates revenue through memberships, uh, from corporations and sponsorships through a variety of events that they hold.
The bulk of their work has to do with these working groups where, uh, individuals will create, uh, research and published white papers on a huge variety of security topics. Everything the CSA does, by the way, it's, you know, it's open and public and is freely available. So it's nonprofit. Yeah. And, and I think had a pretty big role in CIS version eight. Right. Jason, in terms of, um, the, this most recent cl uh, controls release, Right? Right.
The, uh, the, the CSA also has some, uh, some certification mechanisms. They have a cloud controls matrix and what they call the star, which is, I don't remember what the acronym is, it's for, um, SaaS providers to either self-assess or have third parties, uh, assess their security capabilities against the standard. Got it. Got it. Wes, this is like old perch days. I mean, hopefully he's got some, uh, yeah, yeah.
I think, I think Adam heard that, uh, he was gonna pill for something and called the security guard. Yeah, it got kicked out. Andrew, what's funny, when you see him walk through the office, you see, you see the, uh, uh, the walls and stuff. They never painted those walls. They the same colors Yeah. In that ConnectWise office. Yep. You know, back in 2004. I know, True, true startup world. It's like, we'll get to painting when we can get to painting. Yeah, it's so true. Kind of scary Flashback.
I spent a lot of time little PT early on in That, in that office. Yeah. I remember a lot of, a lot of, uh, a lot of, uh, meetings there. All right. So Jason, my next question, I'm gonna post a link here. You put this in, uh, you did a LinkedIn post recently on this on AWS's approach to Zero Trust and, um, what they call verified access. Can you walk us through what that is?
I know not a ton of MSPs like heavy into the AWS world as much as they are in like the Asia world, but can you kind of walk us through why this is significant or, or what your thoughts are on it? Sure. So AWS um, recently, uh, released this as a preview at the end of last year. And they just last week announced the general availability, which is what prompted me to to write about it.
And so what AWS verified access is essentially a first step for them in terms of, uh, talking about zero trust and zero trust to access.
And you can think of it as essentially a identity aware proxy that let's, uh, the identity authenticate gives you the ability to tie into external identity providers, whether it's, you know, an Okta or Microsoft, anything that uses SAML or Open ID Connect and then let's you set up policies for controlling which users are allowed to access which resources, which web applications that, uh, under which circumstances.
And I thought this was interesting because obviously AWS is the biggest cloud security provider, but they're also the last one to do this. Google has been talking about Zero Trust through their Beyond Corp now, beyond Corp Enterprise offering for quite a while.
And of course, Microsoft being, you know, probably the biggest identity provider on the planet, has done a lot around Zero Trust through conditional access, um, and some of the other capabilities they have, like Azure Information Protection. Um, so we certainly welcome AWS to this. This is a fairly narrow type of offering.
AWS is obviously not a big identity provider in, uh, in the same way that Google and Microsoft are, but it's important to have them talking about it as well and beginning to bring these principles, uh, these, these principles to bear. And do you, maybe a follow up question.
Is there discussion about like, I dunno how to even say it, like a unified framework or an open source, unified zero trust protocol of sorts that would sort of like unify the vision and approach almost like TCP IP for networking something similar to the Zero Trust type of world. Is is such a thing even possible? It's certainly possible. It's, we're quite a ways off from that for sure. I mean, if you think about the way that the major vendors are doing this, it's all proprietary.
And I don't mean to denigrate that. I've already spent my whole career working for software vendors building a lot of proprietary things. It delivers value to, to customers, but they're not doing it the way that, that enables open interoperability. So you look at the major players like, you know, the net scopes and the Z scalers of the world. They have integrations, of course, with the CrowdStrike and Microsoft Defenders and things like that.
But these are really point to point type of connections. Um, there are some emerging standards around this really early days. So there isn't anything that's, I would say, open. And there really isn't an open reference architecture yet around this. I think that's pretty, a pretty exciting area.
There's, you know, a few standards that I'm kind of monitoring, and I think that we have a ways to go, but I would love to see a, a place where there's an open way to define and communicate security attributes and context and events that happen, and to have those be shared among components. Yeah, I completely agree. And that, that's kinda what I was getting at is like, what, what would be that next step of like area of focus around standardization between all of the large cloud providers.
So that, that makes a lot of sense. Anything else you'd point to as far as like the near term roadmap on what's happening in the enterprise space between Azure, Google, Microsoft, in this world of zero trust that you see? Um, that'd be pertinent to us. I, there's a lot of momentum and a lot of discussion around applying the newest revision of the zero trust maturity model that came out of cisa.
So cisa, the US Cybersecurity and Infrastructure Security Agency, they released version two of the maturity model about two, three weeks ago. And there's been a lot of discussion around, okay, how do I take that? Which is you narrowly defined as, Hey, this is a political to the non DOD federal agencies. How do I apply that to my commercial will? And I think that there's, I'm having a lot of good discussions around that.
And um, that's an area where I think there's ripe for us to morph that a little bit, provide some clarity and some slight changes or some things that I think need to be enhanced around taking that and giving enterprises some guidance. And then for the MSP worlds, I think there's probably a variant of it where we can look at it and say, okay, maybe there's two or three profiles for MSPs and the types of customers they talk to.
Here's a really good framework to take them along the zero trust maturity model, and this is what it means to them. And I think kind of tying back to Andrew's kickoff point, which is these MSP, your MSP clients may not care about that directly. They care about it indirectly, but it'll be a really good framework for our MSP to say, look, this is how and why we're delivering these kinds of business value to you.
And by the way, we're using this well understood, federally created framework to take you along this pathway. So you know, you're in good hands. Okay. Yeah, that makes sense. So this, oh, go ahead, Andrew. I was just gonna ask, I I is, and Wes, I'd love your thoughts, maybe Keith even is, do you have to almost approach this from a tabletop perspective to get people to understand the, you know, the risk and implications of this? Because again, it's, you know, it's, it's a, it's a concept, right?
And, and it has very important, uh, implementations along the way, architectures along the way. But I dunno, Keith, you, you know, any thoughts on this, like team mindshare versus just, Hey, it's somebody going for 800, 1 71 and they need a better, I don't know, wifi FIPs validated, blah, blah, blah, where you're ticking, you know, a a a control. I, I, I mean, I think it's mapping out the use cases, really.
And I think what certainly makes it more complicated from an MSP standpoint is that you've got different use cases for all of your clients. Uh, and you may be serving different industries, and so that they can be vastly different. Our own use cases are very, very different from our own clients. But I think it, for, for us, it starts with really mapping out what are those and what are those security needs, compliance needs around it? And then, you know, what, what makes sense?
Where, where's the low line fruit? Because there's some obvious, uh, zero trust principles that that can be easily turned on and put into place and maybe done across yourself as an MS P and all of your clients. And it, it, it's really like that CS start with IG one, you know, lock the doors before you build the fence, uh, starts. But yeah, you bring up a good point.
And, and Wes, feel free to chime in here for you for an MSP Keith, I mean, I gotta believe number one use case is protecting your biggest risk to revenue, which is gonna be P-S-A-R-M-M document management. Because again, if you can't operate those or if they're hijacked, you got big issues on your hand. So yeah. Yeah. Where are the crown jewels at and, and how can I, um, how can I put zero trust in place at the, the least level of effort right.
Quickly and, and inexpensively and then work from there. Yeah. Yeah. The, Andrew, you're getting my brain going on this because I think you are right. Um, one of the, the challenges that I think the misperception that still exists both down market with your clients and for MSPs in general is, and we talked about this a lot before, but oh, it's in the cloud. I've shoved responsibility to them. We're good. Right?
Um, and, and you know, we've talked about the shared responsibility matrix that, that all of the large cloud providers have, have given, just to further illustrate, Hey, look, there's a whole lot of things that we're not responsible for, but the clients knee-jerk into that same thing.
Your clients have thought this forever, and I know this is gonna trigger Gary here, um, in the sense of like, they think that security is your job because it's always been your job because they're paying you $120 a seat, and so therefore you're taking care of all their security, so they're not gonna get hacked. And the me and the reason you're moving all your stuff out into the cloud is for that same reason.
Oh, because my MSP's put it all in the cloud to keep it safe and to keep it secure and to keep it there forever, and I don't have to worry about the stuff anymore. Right. And if you're not having those conversations about shared responsibility and the client's responsibility in yours and your provider, you're steering yourself for some trouble. Gary, I'm, I'm hoping you meant $120 per seat per week. Right? I'm speaking in, um, I mean, per month speaking in per week.
That's the problem though, isn't it? And, And, well, I'm thinking like, so any a a a lot of the, the concepts, and Jason with zero trust, this is a perfect one to make this point. Um, you know, if you are managing an environment, you have your, like, I'll use case words, your, your use case, and you start to implement these things and you know, whether you have, you know, 200 employees or whether you have 500, it doesn't make that much of a difference.
But for you, Keith, how many customers do you manage today? Right? A lot. And every one of them has a different use case. So this is another example of why all of, and anything that starts with philosophy and concept is much, much harder. It's almost like we're waiting around till someone just delivers a, a zero trust app, that all we gotta do is install the app and it's done for us right now. Yeah. This is not something that lends itself today, right.
Uh, maybe someday with ai it'll be different, but it requires that, you know, that that intervention and, and discipline. But that's where I feel like the, again, these are the kind of things that MSPs, I believe so much more involved, and then they have to commercialize it, which I'm gonna talk to Jason about in a few. Yeah. And, and your clients don't understand the use cases. That's, that's what's clear, right?
I, I just had this conversation last week with a financial services firm that didn't think that FTC safeguard's rule coming, coming up here, June 9th, applied to them because their, uh, ERP was in the cloud, and their client data and their financial data was in the cloud, right? And they thought th their, their approach to FTC safeguards was, well, it doesn't really matter because it's in the cloud.
And, uh, forget the, the fact that I have BYOD devices out there, people working from home, which I don't know if they've got any sort of malware protection, there's no monitoring, certainly no MFA, any of that, but, uh, BYOD and the cloud, that's good enough, right? And, and you have to educate and you have to show them like, okay, what if there's a key logger on one of those machines? What if there's a backdoor? Doesn't that give you access to everything that the employee has?
And they're accessing all that financial information And it was like a, an aha moment. So I think, I think what's hard is we have to educate our clients and really dig in and find those use cases. They're not going to surface for you. Yeah. Well, and, and you bring, you bring up, and we'll get back to Wes and Jason, but Keith, you bring up a really good point where they were fine, right? Air quoting, they were fine. Mm-Hmm. But it's the same thing when similar objection.
We don't have anything, you know, someone would wanna steal. Well, it's like, well, okay, well the Business like money. Yeah. Like, You literally took words outta my mouth, Jerry, like business email compromise and wire fraud. You're, you're exempt from people taking money from you. And it's like, again, we've got to sh and that's why this is just, I'm on this mission, Gary, that we have got to this year, help everybody in the MSP community that wants to be, helped change the conversation.
It's gotta become business centric. It's gotta become risk to revenue. It's gotta be around critical processes and people, and it's systems that, that speaks to them. 'cause if we don't, we're not moving the needle. Yeah. I, I think, Gary, there's definitely things that, um, straightforward things that are well understood that definitely should be done, that are aligned with the zero trust philosophy. So we shouldn't be this big scary, you know, I'll get to it in five years.
You know, think, you think about your RMM, right? You wanna make sure that you've got MFA in place, you got strong administrative passwords that aren't shared, et cetera. You wanna make sure that you have, uh, it seg segmented on the network so that even if people can't log in, if there's malware on your network and it tries to just bring an open port or exploit some sort of vulnerability, it could take that down or it could hold you up for ransom.
Those types of things are very well aligned with zero trust. They're really good security hygiene, right? This is not anything radical. And, you know, in terms of risk of revenue for the, the MSP itself, I mean, that's the most critical system. That's good stuff. It's good stuff. Alright, so here's a question. Um, in the split around cyber insurance and regulation, let's kind of tie both of those in for a minute.
Um, we, if you look at the carriers, they're, they're really starting to baseline around a minimum set of security controls just for general eligibility, especially in the small, like, you know, 10 to 25 million in revenue. Like those, those smaller companies right around like MFA everywhere, full backups that are immutable, EDR in place, vulnerability management, security awareness training, all the normal stuff, right? So that's good.
Um, I guess my question for you is, when we go further up market into the enterprise level, Jason, do you see cyber insurance also driving initiatives? Do you see regulation? Do you see carriers pushing for zero trust or asking questions around it? Any kind of insight that you're seeing further up the food chain? I think it's great that these carriers are starting to enforce and require some of those basics.
Everything you mentioned is really good security hygiene and, and organizations have to do that. And I think it's, I don't know what the threshold is in terms of complexity of the environment, because, you know, at some point some of these things, they're, they become something you have to do as opposed to say, right?
Because you, everything you rattle off, you could go to an enterprise and they could check the box and, but they're, if they're not really doing it, you know, it doesn't matter, right? So we gotta make sure that these organizations don't just check the box for these things so they can get a better insurance rate, but they're actually doing them properly. And of course, that gets harder and harder, the bigger the enterprise and the more legacy stuff. And the more complexity there is.
Um, I was on the phone with a defense contractor a few weeks ago, and the premise of the call was, Hey, what comes after zero trust? I'm like, okay. So I thought about it a little bit and they got on the call and they're at step one of 10, right? They're, they're talking about, oh yeah, we're still in the middle of this gigantic migration from this network infrastructure to that network or infrastructure for Europe. And we have this other incompatible one in the us.
And I'm thinking, okay, let's just do some of the basics here. So it's, you know, these enterprises are really hard. We haven't made it easy for ourselves. And as soon as you get things right, you know, there's an m and a or divestiture, and now you have this completely gigantic set of things. And you know, you know, even in the smaller types of businesses that you deal with as MSPs, you still have complexity in things.
I don't know what, we lost an H there, We lost an H poor one out for the h uh, Jason, that's good feedback. And so it doesn't sound like it's all that dissimilar then to, um, where the rest of us are at. I, I think you're right. I think that it's good to see this coming from the insurance companies, right? This is showing the level of maturity and structure.
And I think hopefully there will be a more widely accepted, unified, or somewhat universally set of standards, or at least menu of standards and controls and measurements that are shared across these organizations. Yeah. Well said. Yeah. All right, Gary, my friend. And not a lot of regulation. Yeah, yeah, for sure. So you talked a little about your, some of your initiatives at, uh, at CSA and you know, why the sales conversation, uh, is important to deliver.
And I guess the way Andrew put it was like a reference guide, like to the market, right? Um, but what I want to ask you is, when you're talking to c-suite, right? You're talking to decision makers, and part of this is getting them to understand it commercially, you know, open their wallets when it comes to zero trust, uh, implementations. What are the most important business drivers that you focus on when you, when you're having those conversations? So the, the, and this is hard, right?
For us as security nerds, people who love security like me, it's, we can talk about this stuff all day, but that's not meaningful. And if you do it the wrong way, then you end up talking about this and it's being perceived as, okay, security wants more money and it's a better VPN, great. Yeah. Whatever. And that's the wrong way to do it. And you're gonna fail, right? The right way to do it is to tie it to some sort of business value and business initiative.
And the types of things that I've found that really work well are improving end user productivity and user experience. Because there's always gonna be things that people hate, whether it's your VPN or you know, some other types of, of system, whether it's a, an employee onboarding process and the zero trust approach can accelerate that, give you the organization a secure way to reinvent that process, um, and smooth that user experience. Cost savings are another thing.
In many cases, uh, a zero trust approach can help reduce, uh, either networking to cost, like reducing as, um, uh, wide area networking or MPLS costs. It can also simplify the infrastructure and help organizations get rid of maybe legacy network infrastructure or consolidate pieces of security infrastructure, uh, to have cost savings that way.
The way to really get to win friends and influence people across the businesses to understand what business initiatives or business strategic business activities are going on. Are we doing a cloud migration? Are we shifting to from traditional application development to DevOps? Are we, You're saying now I gotta ask my customers questions about their business? I hate to break it to you, but Yes, yes.
If you understand their business, that that's gonna give you the opportunity to, to raise your prices. Yeah, absolutely. So what are some of the biggest objections, like, do, like, you know, when you're having these conversations and you know, uh, what, what's some of the pushback? What's some of the objections that you think people get? There's, you know, definitely, uh, objections around, Hey, this is marketing bs. Um, this is just vendor hype. Uh, it's complicated. It's too much.
Uh, it's gonna be expensive, and I got other things to worry about, you know, let someone else take care of this. Yeah. So it's, it's, and none of the, so the key is to understand what matters to your customer. And you can talk about business resiliency. You can talk about, you know, reducing the blast radius of attack. You can talk about the impact on revenue.
And you can also talk about enabling securely, enabling a new line of business or a new, uh, initiative adopting new technology and business agility. It's really helpful when you're ha when you are having these business conversations with your, your clients to ask them and be able to ask the what would it mean to you type of, of question.
So when you understand their business and you say something like, I'm making this up, you know, I've heard that, you know, it's really hard for your engineering team to share specifications with your clients for manufacturing, blah, blah, blah. What would it mean to you if, you know, you could onboard these people, give them secure access and revoke it immediately when you know it doesn't work out or whatever.
Those types of questions start to get, hopefully have the, your client's ears perk up and then get them engaged. And then it's not a security conversation, it's a business agility. It's a innovation conversation. Yeah. I mean, I, I'm always so amazed how little so many MSPs I meet know about their customer's business. Like they know about their technology, but they don't know about their business.
And kind of, I guess the question I'm asking you almost relates to what Keith said, which is they don't know their business cases. Mm-Hmm. Like, they know their business, but they don't know their business cases.
And so I feel like it's really impossible in all areas of security, but specifically what we're talking about with you today, I think it's impossible to commercialize this with customers and get them to not only make more of an investment, but feel good about making more an of an investment if we don't get to another level of, of, of business understanding. And I think this is the hugest hurdle that MSPs have to deal with in, in, you know, in general.
Um, one thing, um, that, uh, I I was thinking about, like, we do these special projects with our peer groups is one that I did when I bought a second MSP, which is I sat down with our V CIOs and I just went through and asked them like, okay, who, who are you dealing with at every customer? Were they a decision maker or not? And then tell me what you know about their business. And from that, like developed a starting point. 'cause I feel like all of this is built on understanding, right?
Understanding their Right. It is. And I, you know, I, I feel for, for the model, because you have to operate at scale, right? And Keith mentioned he's got a lot of customers and he can't talk to every single one and deeply understand the business. But I think there's a way to, to boil these things down or distill them down to a certain set of repeatable, either use cases or patterns or things like that.
And depending on who your customer is, you know, you, you'll, you know, best what that commonality is. But Yeah. But maybe it's, go ahead. Bring up. No, but I think you bring up a good point following Gary. Gary, you always talk about roles, responsibilities, and scale.
And, and this, you're kind of typifying that, and I'm, you know, let's just say it's A-V-C-I-O or VCs O whatever role is in, you've defined in your company that that person needs to understand if use case A is, as Jason say, is around engineering and use case B is law firms. Well, you need to understand that law firms wanna bill their, their lawyers a hundred twenty, a hundred forty, a hundred sixty hours a month and understanding, you know, their remote nature and on and on and on.
But somebody has to own that. And I, I think you can do it at scale, but you have to know where it sits in the business. No, Yeah. I, I, I agree with you. And, and here's the funny thing that I've seen, Andrew, I've trained many, many V CIOs, right? Build a software product to help enable it. It's a big, you know, big part of my, uh, of my life and what I've seen over and over again is, it's like anything else. Getting started in doing it this way is the hardest part.
Once you do, um, you do get pattern recognition, both what's different between industries, but also those things that are the same. And you become like way more interesting. And by the way, it's the, that on the VCIO and sales side, 'cause I've done both. Uh, and getting to understand people's businesses was the funnest thing about my entire, you know, career. A a as an MSP. And by the way, it's how I learn most of what I know about business.
And it's what your pe by the way, what your clients and prospects really wanna talk about. It is. It is. And and what's funny is that in terms of commercializing, right, uh, security, once you get to that point with them and then you talk about a security concept, like zero trust, they connect their dots. You don't even have to do it. They don't care whether you charge 'em 5,000 or 4,000 a month. They don't care. Yeah, yeah, yeah. Absolutely. Yeah.
I, I had one more, uh, question I wanted to ask. If there were like, um, are there, are there two or three or four industries that you think are leading the way, um, in terms of where you see people adopting? Um, uh, zero trust. We definitely see, uh, rapid and advanced adoption among, uh, technology companies and, uh, financial services companies, which is not really a surprise, obviously. 'cause they, they do tend to be on the cutting edge.
We're seeing a lot of activity in government as well, because it's been mandated, uh, for sure. But it's really, it's a very horizontal thing. I mean, I think that there's, even in some of the tradi, traditionally lagging industries, there is, there's outliers and there's folks who are doing this. And I would say it's on everyone's radar. And that's good and bad, right? It's good because you got lots of people talking about it.
It's a little bit bad because now you've got budgets and things allocated to this, and you have every vendor saying, Hey, we can do this by us, and we're the magic silver bullet, et cetera. So Keith, I have a question for you. Um, you know, we've been talking here for a couple years about, you know, assumed breach and, and, um, and I think that a lot of MSPs now use that in terms of their customers understanding. It's part of our, our, our lingo.
When you're with customers, your team's with customers, are you using the terms zero trust yet? Not, I, I would say rarely. I think we're using maybe zero trust concepts. I I think the industry still sees zero trust as maybe an architecture more than than what you were saying, Jason, the philosophy. So we're distilling it down to those use cases to go, okay, for this piece of your business and how these users access this data, we need to put lease privilege in.
We need, uh, secure concepts, really zero trust. But I would say that that term hasn't really taken on a life of its own yet. Yeah. Still Spring term It's important, right? Like for, I I find it like from, because we really sell our customers concept. We don't sell 'em detailed philosophy, we sell 'em concepts.
So it's why frameworks have worked so well in, in terms of, forget about securing things, uh, being able to frame a conversation, you know, using, you know, terms like I mentioned, you know, like assumed breach really stirs up, you know, your ability to explain something complex. So I'm always looking to say, how do we build up our library of terms that we can use in a conceptual way to attach, help people attach risk or risk reduction to their business cases.
Uh, I think that's the center of what we need to do. I, I think that's, that's, that's quite sound. It's, it's, you know, don't use the term zero trust if it's not gonna be meaningful to them. And it's probably not, right? I mean, these are, these people are, are focused on running their own businesses. They're not in the security world. And you can go to them and say, Hey, we're the best MSP because we use zero trust.
And that's not gonna be any more meaningful than, Hey, we're the best MSP, because, you know, all of our employees wear blue T-shirts every day. It's like, who cares? Right? But if you cast it as business resiliency or revenue resiliency, or assume breach or whatever the, you know, however you wanna communicate it, then that's interesting to them, right? Hey, we're the best MSB because we make sure that you, uh, your revenue stream is not interrupted. Oh, okay. That's interesting.
Tell me why, tell me how I think, I think also what you guys are articulating is, you know, I'll bring Brian Blakely into it, you know, when he's sitting there interviewing a customer, a potential customer, he's drawing, and he talks about following the bouncing ball of data and, you know, the people involved with it, the systems, what drives revenue.
And I think it's a lot easier and people can, when people can see it and understand what you're doing, and like, oh, wow, I didn't realize this, this, and this occur. I didn't realize this, this, and this, or at risk. And so I think it's impactful. I think we need to again, be creative and how we're communicating. What, what are your thoughts on that, Gary? Yeah, a a, absolutely. I think finding new ways. I, I mean, listen, what I try to tell MSPs, if it was me, right?
And I was running an MSP, you know, on a day-to-day basis, just like I always did in sales, every week I would be doing from a ciso, VCSO or, or, or v uh, VCIO standpoint, be doing role playing on these things. Mm-Hmm. Hey, how did you present this? What came back? Can we talk about a different way? And really getting your talk track down. Because when you taking cons, when you have things that are complex and they, and, and that your customer doesn't understand, you need to find simple ways.
And the only way to know what works is you have those conversations and you see the light bulb go, go on, Right? It's also what you Continue to hold them. So like, I, this is the most important thing you have to do. You think it's delivery, you think it's all that. You'll figure that out. The most important thing you have to do is be the best at having these conversations with customers so that they want to be able to make investments in these things because they see it as an investment.
And if you do that, you'll have the time and money to figure out everything else. And so ask yourself, how much time every week do you spend on being better at that compared to 50 other things that maybe your customers or, or aren't gonna change your business at all. Put your time on the right things, man. Yeah, no, that's really well said, Gary.
And, and you know, we, we've talked, and I'm a huge believer in challenger sale, and that's another area, Gary, for people that have outbound dialers still. Um, you know, to your point of, of use case, like figure out what it is that's going to evoke somebody to go, wow, I didn't think about that. I'll take a meeting. Right? Mm-Hmm. Um, that, that's another way that, you know, you can figure out are you on the mark or not, right? Yeah. Once you get it, it, it, it informs your marketing, right?
It informs your, your, your messaging, your, you know, your sales messaging. The same thing that works with customers, works with prospects, right. And the job is the same, which is simplifying it and finding those talk tracks where people can really understand and feel like they can make better decisions than they could before you came through the door. Yeah. Or trying to help people make better decisions.
And, you know, every week, I always say the thing that drives me crazy right now about MSPs is they still continue to blame their customers, right? My customers don't want to make the investments. My customers don't care about security. That's the most preposterous thing I ever heard. Like are like, you see now I'm all fired up, but you're with me on this, right, Andrew? It's just like, you can't, it's not your customers. Yeah. It's our fault, it's you and it's okay, but you gotta say it's you.
And then we just gotta get better and better at it. Yep. Absolutely. A hundred percent. Gary, you, you, you, yeah. Because if you're waiting for them to get better at it, you're gonna be waiting a long time. Yeah. Really good point. Jason. Um, I did put up, uh, earlier your, you know, your, your LinkedIn, your website, but, um, if people want help in implementing Zero Trust architecture, how can they get ahold of you? Feel free to put it in chat.
Um, are you, are you doing some consulting in, in this area for, you know, is this an area that you, you'll work with and, you know? Yeah, absolutely. So folks can reach out to me on, uh, on LinkedIn is probably the easiest way to do it. Okay. Or they can, they can shoot me an email to at Jason dot garvis@numberlinesecurity.com. Um, and happy to chat.
Um, yeah, I'm definitely, like I said, I, it's pretty new this business is, uh, but I'm, I'm working with enterprises and, you know, I think it'll be really great for us to, Andrew, for us to collaborate, work with some of the folks, uh, on the line here and put together a structure that, uh, is tuned for, uh, for the MSPs. I think that there's, there's gonna be a lot of good that we can deliver there. Yeah, I agree. I I figured it out over the last hour, so I'll Okay. All Right.
We'll, we'll I'll probably just come out with a blog that I'll post. That'll pretty much be the guide To me. Awesome. You Can't have any HS in there. Sorry. Yeah, that's right. Yeah, no, like do it without an H Jason, did I put that incorrectly? Uh, Jason do gar number lines. Yep. Thank you. Alright, perfect. Alright, well until next week, we've, uh, I'm trying to think of who I have next week. I already have it scheduled, but uh, I know it's a good show.
And Remember you said we're gonna have some weeks without guests. Yeah, yeah, yeah. We never did it. I know, I know. Um, who the heck, oh, Brian Blakely's back next week, but, uh, we could do it the following week. Yeah. Okay. Okay, cool. Alright, everybody take care and have a great day, everyone. Thank.


