Skip to main content
Right of Boom
May 12, 2025
757078

Voice the MSP (Hot Topics)

As we move into the second half of 2025, the cybersecurity landscape is growing more complex, but the fundamentals remain as critical as ever. This week’s Cyber Call brought together leading MSP experts to share actionable insights on how managed service providers can better protect clients and drive growth. The key takeaway? Double down on the basics. The Verizon DBIR reinforced that essential cyber hygiene—like regular patching, strong password policies, multi-factor authentication, and consistent employee training—is still the foundation of an effective defense.

The panel also explored the shift toward Zero Trust Network Access (ZTNA), which is increasingly replacing outdated VPNs. ZTNA reduces attack surfaces, enhances user experiences, and supports stronger security controls by verifying every access request. MSPs should begin evaluating ZTNA solutions and clearly communicate their benefits to clients as part of a larger security strategy.

Another hot topic was the decision to outsource your Security Operations Center (SOC). Once MSPs hit a certain client count—typically around 25 to 30—it becomes more efficient to outsource SOC functions to ensure 24/7 monitoring and compliance across diverse environments. The discussion emphasized understanding when the cost, complexity, and staffing needs justify outsourcing.

The call also addressed cloud security, particularly Microsoft 365. MSPs were reminded of the shared responsibility model, where Microsoft secures the infrastructure, but it’s up to the client—and the MSP—to configure settings and enforce best practices. Regular 365 assessments and focused recommendations can make a big impact without overwhelming the client.

Finally, the conversation turned toward differentiation. In a crowded MSP market, those who speak the language of business—tying cybersecurity to operational risk, downtime, and compliance—will stand out. Offering proactive assessments, peer benchmarking, and industry-specific expertise can help MSPs not just retain clients, but grow their value and service offerings.

The path forward is clear: reinforce the fundamentals, adopt strategic technologies like ZTNA, understand your clients’ businesses, and lead with expertise. By doing so, MSPs can offer stronger protection and tap into new opportunities to monetize their services in an evolving threat environment.

Guests

Andrew Morgan

Video Transcript

All right. Welcome everybody. Happy Monday. And, uh, we are in, gosh, second week of May, almost halfway through 2025. Bob, that's, uh, that's pretty wild, isn't it, when you think about it. Yeah. My life is centers around when kids get outta school and conference time, but you're right, we're halfway there already. That's just crazy. Yeah, yeah. Yeah.

I know we talk about this pretty much week in, week out, but every time I look at the calendar, I'm kind of like, I, I, it really floors me how quick, um, this year is moving. I Know. Yeah. Right, Phyllis, I mean, it's crazy. It's crazy that it's already mid May. Oh, today's my daughter's birthday. She turned 16 today, so Birthday Bob Bob's got the guitars. We can Only, I don't have one on me, but I, yeah, usually I do. Come on, Bob. I'll work on something for you though. Yeah.

She has to take her ap, uh, an AP exam today, so she's like, oh, my birthday. I am like, it's okay. It's okay. There'll be more birthdays. Mm-hmm. All right. Let's all, let's go. All right, fantastic. So, um, we will get on into it here. Um, we got folks coming in, um, last week. Um, I don't know if you all caught last week, but, and, uh, once we get rolling, I will put the URL in for everybody to see. Yeah, Charlie, it's, it's, it's crazy that, that QQ two. Yeah. Q two's halfway over.

Um, you know, um, for those of you that are really focused, like I know, um, ed choa out there is, you know, in peer groups that are really, um, you know, centric around selling, you know, your ma your metrics and everything. You know, we, you know, deep into Q2 already, it's, it's pretty wild.

Um, but, uh, what I was gonna say is last week, uh, for the fourth year in a row, Philip, or as he goes by Phil Lwa of, um, Verizon joined us, uh, and reviewed the 2025 DBIR, um, that was like, we're gonna have him, we're gonna have him back. He agreed to come back. And because we only got like, scratch the surface, I felt Phyllis of that report. It's massive. Um, what, what did, what was your favorite part of it, Phyllis?

Anything for you that you really, you know, took away from that conversation? Um, I think, you know, it's just kind of like the trends while the are different, you know, ransomwares up and things like that. I think, you know, it really is, I say it all the time, back to the basics, how you mitigate really, you know, is the same. And so time and time again, it's really that, uh, essential cyber hygiene that is going to help organizations, um, defend against these top threats.

So, I mean, I think that's encouraging for everyone listening in to the cyber call, right? Because we've been, you know, Andrew, I mean, next week is gonna be the five year anniversary, and you have been beating the same drum. Kudos to you. Um, you know, what is it that MSPs should be, you know, doing, implementing on their own enterprises and then, you know, implementing on their customer's enterprises?

And, you know, this, this, um, webinar in particular is like, this is how, um, we can do it and this is how we can monetize. Right? And how you should be having those regular quarterly check-ins Yeah. Um, with your own business and with your clients. So, Yeah. Yeah. Yeah. It's, um, it's, it's, it's, it is a kind of, um, interesting when you take a, a kind of a retrospective back. Um, we talked about, you know, things that you guys have done, like the community defense model mm-hmm.

For those of you that weren't on the call, um, CIS does a great job of looking at the threat reports, Verizon being a big one. Mm-hmm. And then looks at the attacks, Maxim ba maps 'em back to Mitre and says, Hey, if you had these controls in place, you know, what would the efficacy have been? And, um, and it's a phenomenal report. Um, but it basically, uh, typifies what you're saying, Phyllis, which is, you know, if you had a basic security program, call it IG one mm-hmm.

CIS in place, majority of attacks, you would stop. Um, right. You know, um, so yeah. I, I, I thought it was true. I, the thing that really, um, I, I loved hearing Philip say, and, and kind of in a weird way when I say love that, not, not in a positive way, but, you know, just the, the, the interesting part of vulnerabilities like that overtaking phishing as an in, as, as, you know, the initial access, you know, for initial access. Mm-hmm.

Um, that to me was like, that, that was like pretty profound. Um, that being, um, and then, then the rise in third parties doubling year over year. Yeah. Um, because those two, two, you know, I was having a conversation earlier today. Those two things go hand in hand, right, Bob? I mean, so often, you know, uh, the conversation I was having earlier in the day was, you know, my customers, and I'd love Steven and Jason's to, we'll get to the today, I promise.

But I think this is really interesting because, you know, some of us so often it's like, I can't, you know, customers don't wanna buy vulnerability management. And it's like, well, no kidding. It's, it's that that doesn't speak the language of the business, as Brian Blakely likes to say, right?

Bob, I mean, now talk about what, what runs the business and drives revenue, and, you know, what are the implications to those systems if they're down right, to your, to your customers, to your contractual obligations? That's a very different conversation. Fair. A hundred percent. Yeah. I mean, we're so integrated now too, right? A lot of, uh, you know, a lot of our tool sets are starting to do a better job of integrating one another.

So if you experience a third party attack on one system, it's not just isolated to that one system anymore. Now, it can actually affect your whole workflow. So it's, it's getting more complex. Um, when you look at the number of systems involved in a workflow to get something delivered, sold, delivered, supported, it doesn't take a lot sometimes to disrupt that. So, yeah.

Well, well, the example I'll give here, you know, Steven, and your take on this, there was a release today, um, you know, that as it was Asen, one of the big healthcare providers, I think it was Ascension, um, they were, um, you know, there, there were, they were breached something like 360,000 health records. The point is, is when you trace it back to what Bob just said, it was the Clio vulnerability. Oh, yeah.

Like, like, and, and again, you know, like I said, you know, an executive in, in a big medical organization doesn't care about vulnerability management, but an executive in a big healthcare organization does care whether their EMR isn't working and whether they're gonna have to tell, you know, STEM state regulator that, you know, they're now responsible for 360,000 records, right? Absolutely.

You compromise, and They're gonna worry about the HIPAA violation and release they're gonna have to deal with, right? Um, there, there's, there's a way to speak to a business that isn't your software's out of date. That's very challenging to explain to a business leader, but it's a lot easier to say, Hey, how much does it cost you every month to have an employee say, I don't average of, you know, $10,000, whatever the case is.

Well, what if you have five employees that are 50% down for two weeks? Then the math becomes very trivial to say, there's a reason we're doing this. It's an ROI, we're just doing a cost benefit analysis of keeping stuff up to date. And beyond the security implications, there's always like, Hey, our software's up to date. Always has some significant benefits to it too. As long as you can speak to the risk and the cost, it's a lot easier to talk to an owner. Yeah. Yeah. Yeah.

Ja, any thoughts on that? As you, as you hear, There's definitely like an underestimation of risk. People always think, oh, that'll never happen to me. I'll never click on that email. I'll never download that malware. But, you know, it happens to people all the time, every day, and it's those people.

So it's kind of like, um, you, you don't rise to, uh, either your best intent and what you think you can do when you're paying a lot of attention, you fall to like, the level of your systems and what's fault and what's allowed. So, you know, thinking about what's permissible within an organization, what you should be doing is great. And some of the security, like, there are things you can do that don't even cost a lot of money that you should be doing that are inherent in there as well.

Like, you know, things like local admin that just make sense to do, um, yeah. Just a, people don't think about, um, if you, if you try to sell 'em cyber, they're gonna say, why do I need this other thing? But if you talk about the business risks, like Steven was saying, and Bob was saying, like, it's really, really, it helps them connect to what they're actually trying to buy and what they actually care about. Yeah. Absolutely. Absolutely. So, good, good points.

All right, so let's get into today. I, I just wanted to frame out why, you know, last week, you know, we were very high, you know, it was so high level. We, we went into the gold standard of threat reports. You know, I think it's something in tune of, uh, their, their metadata set starts at about 40,000 incidences, and then they start to dwin, you know, whittle it down a little, but it's global.

It's, it's, you know, oh, by the way, SMB was 88%, um, in terms of, uh, um, I, I forget the exact what, what it was pointing to, but I mean, it was significantly more 80, 80% relative to enterprises to, of, of being compromised. It was like off the charts. Um, we did talk about that as well, but today we wanted to kind of, um, get a, you know, what MSPs, um, are personally dealing with, and, and I call it the hot topics, right?

Steve, and you and I were talking, um, about a week ago about some things that are really on your mind. And so I thought, let, let's get three awesome MSPs on today. Talk about those subjects that, you know, folks like you are dealing with, and I, I'd imagine everybody in our audience are dealing with. So, um, as we get into that, let me kind of do some intros. We're gonna talk today, Steven, about, you know, some ideas you had, which was around ZTNA.

Um, uh, because everybody loves VPNs, um, outsourcing, you know, soc insource versus outsource. When, when do you do one versus the other? Um, securing M 365. Um, so, uh, we could maybe summon Bo Bullock in here for those, uh, bo, um, but some, some things that we're all, uh, dealing with. But with that, Steven, let me start off with you quick intros. We'll kick it off to Phyllis for the question. So Steven, welcome for the first time. Hey, thanks, Andrew. Good to, good to have you guys.

Hi everybody. My name's Steve. Um, I am the security practice manager over at nSight. We're, uh, about a 400 client firm in yeah, California and Hawaii. We focus as probably most MSS MSPs do on small to medium business between about two 20 and about 150 people. Um, I also lead the MSSP practice, so we do both client outsourcing and other outsourcing for just pure security. So security is what I do. It's all I do, so that's why I'm here. Did did you know, I just have a question.

Is this, you know, the Mike Chait question, did he add the Hawaii, uh, location? You know, listen, if the Honolulu office gets compromised, I need to physically go visit it because of security reasons that are real, sir. Uh, yeah. That's what he want. Yeah. Okay. I have to go there. Jason, welcome. Good to see you, and thanks for coming to the cyber call. A little bit about yourself, my friend. Yeah, absolutely. Um, I, I am Jason has, I've been in and around the what?

Oh, I've been in and around, uh, yeah, you're the MSP industry since about 2007. Um, known Andrew since the start of the cyber call before that. Um, and just, uh, I'm working in a company drawbridge now. We do a lot of governance oversight, uh, advisory for alternate investment companies. So very hyper specialized in the space, but a lot of just general MSP business background and scaling companies and working in, um, regulated spaces, uh, mostly So a pleasure to be on today. Yeah.

And you're, you're pretty humble. Jason, I'll toot your horn for you that, you know, you were at Castle, which is a massive MSP for a number of years. You were instrumental in leading their, um, uh, ServiceNow implementation, so you got some chops behind you, and, uh, you're very humble, so thanks for joining us. I'm excited to hear about your perspective on ops and things like that. You look at things in a pretty unique way. So thanks for joining, Bob. It was always great to have you back.

Yeah, man, I'm glad to be here. I'm, I've gotten aware, I really enjoy being able to get online, and especially Phyllis is here. That's always kind a special thing for me personally. Yeah. But yeah, I'm, you know, I'm managing M-S-P-M-S-S-P and, uh, southern Louisiana, nowhere near Hawaii. Um, but, um, but yes, so I've been doing that for about seven years. So that's, that's my chops as it relates to this. Good, good. All right, Ms. Phyllis, I'll kick it to you for some questions. Yeah, sure.

Um, also, I looked up the 88% figure, and it's, um, SMBs, um, are experienced ran, are experiencing ransomware related breaches, um, to the tune of 88%. So that's pretty high. And it's higher than enterprises. Yes. Large enterprises, which Is, it was significant. Phyllis, it was something like 88 to 30 something, 39% is for the large organization. So, um, we all have to pay attention to that for sure on this call. Yeah, absolutely. Yeah.

So, um, Steven, how has your, um, MSP approached implementing ZTN a's zero trust network access, and, um, did you receive any pushback from any of your clients, um, while you were rolling it out? Well, uh, I pretty much always received pushback when I'm trying to sell stuff. So I think we're all there on that one, but, so we, we started noticing probably early last year, um, a decent amount of compromise in SSLV, VP N remote access VPNs.

And, uh, it, it originally was zero day flaws or, you know, air or old old firmware and firewalls, stuff like that. But, um, it got to the point where it was unpatched zero day flaws, and it, it appeared to us that the technology of A VPN where you have a whole open listening on the internet for a connection to come in, uh, I can imagine that's just not a particularly safe methodology anymore. Right.

The, the design is flawed because you're, you're listening for something and eventually someone's going to find a flaw, whether you're not patching the firewall or you're not patching the firewall quickly enough, or it's a zero day and nobody knows about the error. Like, this is a, a common thing we were finding, in fact, um, we've had this calendar year 25 alone, we've had five breaches of our clients, um, of a flaw that was a month old or less, right?

So we just, we had to go to our clients and say, listen, this is just not a secure design anymore. It, it just, it just isn't, listening for something coming into your network is, is an issue. Um, the biggest problem we got is that, you know, typically when you sell a firewall, um, you sell it with a license, uh, uh, and, and that license can come with, you know, VPN access or something. Right?

And clients understand, even if the license is in addition, this is what the firewall annual renewal costs, and it's part of the firewall budget, and it's part of the thing you sell every year. The biggest pushback we got was wanting to go to an independent third party where in zero trust, most of the authentication is done up in the cloud, right? So you're, you're connecting it to SSO via 365 or, or whatever the case. Um, and that's where, and then it rides the initial connection back down.

So you're not listening for anything, but there's a vendor involved in that. Mm-hmm. There's a different price involved in that. There's more to say, Hey, we were connecting remotely, but you want us to connect remotely still, but pay for it. Now. That's, I mean, obviously it's not completely true. They were paying for it previously, but the biggest problem was saying, this is new. You need to pay to do the same thing in a way you didn't before.

And getting clients to understand the first five minutes of what I just said about connections coming in and how it's not safe, that's, that was a huge pushback for us, and it's, it still is. Yeah. Jason, I was just curious, Jason, do you, you know, you guys being regulated and, you know, dealing with a lot of, sorry, dealing with a lot of regulated clients, So Just challenging or, you know, give, give us a sense of what's, what the scenario.

It's two sides of the same coin for some of it, because, you know, you're working with highly regulated clients. There's a forcing function, there's a forcing function from investors. There's a forcing function from competition, but there's also just the general need to be secure and run your business, the general comprehension. Um, some of the pieces about zero trust are that it can work easier and better than VPN two.

So there's some things that you can approach for how you set it up and how you look at it, that it's a user experience improvement in addition to the security.

So there, there are ways to kind of frame it and bundle it in for how you're packaging it that I've looked at in past companies for how you can, um, how you can think about rolling these out to customers and having them be happy to, you know, pay the additional to make it easier so that people can be more efficient and not deal the same issues.

Like, um, a good example for that might be looking at, you know, how much time are you actually spending troubleshooting things for VPN, and how much time are people having issues connecting? How much can you alleviate by having it just on the device and just work? Uh, so there, there's some great examples around that too, that you can enable through the data.

As you talk through that change Is, is there some elasticity, if you will, with, you know, the funds, you know, 'cause these, these companies you deal with, you know, when they can't work, you're talking millions and billions of dollars potentially trading is, is, is, does it give you more leeway with them in terms of, of, you know, a business kind of positioning of why they need to do this versus others? It's the same as Steven was talking.

It just, you know, different scale and value for what the people are doing and what the event is. But it, it's the, the, the cost of time, the cost of your people's time, and their ability to work. So if you're framing it in that context of, you know, if you avoid this much downtime, you're able to save this much money, it's a really good return on investment. It makes it an easier selling point, um, whether you have it as, you know, a a frontline worker or an investment banker or whoever.

So there are a lot of, uh, a lot of similarities in that sales cycle in that conversation. Got it. And with that, Jason, there's also something to be said for, um, ease of use, like you were saying, right? If you take the firewall out of it, you put it up in the cloud, right? You're having, it's a lot harder, less, a lot less troubleshooting. It's a lot harder for things to go wrong in that scenario. It's absolutely a good way to put present it.

Even so, some people are still getting rid of their office with the new realities of remote work. You know, there's no office, you're not trying to connect to the office. People wanna work from more and more locations. They want pops around the world, and the technology just enables that better in a lot of different ways. Yes, That's very true.

So, speaking of, um, you know, excuse me, everyone working hybrid and remote, um, today, what practical lessons did you learn, um, when replacing VPNs with, um, ZTNA solutions with today's environment? Steve? Yeah. I, I gotta tell you, um, a lot of VPNs worked through the great firewall in China and a lot of zt NA does not. Hmm. Um, which I thought was very interesting. Now, we don't have a ton of clients in China, but we have several that regularly travel.

That was a pretty significant thing of finding a very specific, uh, zero trust solution that actually worked consistently through the great firewall. That was, that was a hard one, uh, for us. Um, the, the other things that we found is, so VPN, of course, if you're, uh, connecting to your own firewall in your own office is both, is dependent on the internet connection in one physical location.

So, if I travel from, uh, California to Europe and want to have a VoIP call, but I have to do it over VPN, the latency of going from where I am to my office and then back out to the VoIP provider is very challenging, right? That could be a very significant issue, but there's lots of zero trust entry points across the entire globe. So you can get a little bit more, a little bit better latency.

And I know this is gonna sound weird, but better performance in, in lots of cases where you have maybe an underpowered firewall and 14 or 15 people trying to connect to A VPN at once. Um, I'm not, I'm not gonna tell you, you can run, you know, Revit or AutoCAD over it, but, uh, we, we have seen that it is faster. It is a lot more easily managed.

It's a lot easier to SSO and, um, as Jason was saying, having it just work, you can, a lot of these VPN, or sorry, the zero trust clients, you can put on an endpoint and have it auto connect. It's just on. Right. And if you're connecting to a local node, you may not necessarily have a lot of user visibility at all. Right. So you're safe then from like public wifi and stuff. Sorry, Andrew, go Ahead. No, no, no.

I was gonna ask you, do you find like a, you know, with single packet authorization, like it is like a, an additional layer for phishing as well, Steven, like mm-hmm. You know that Yeah, but that it, it, It does a really good job of like checking the traffic to see where you're going. Um, I don't know if you guys know, but Kelvin and his wonderful SIP product have a protection of 365.

So you can see, like if somebody logs in to a 365 page from a mirrored page, you can actually look at that traffic and zero trust as well and say, Hey, this is connecting to a known site, and map it back to threat intelligence. And Phyllis loves that kind of stuff. So it's all, it's all it, there's a lot of really significant benefit to filtering your traffic through a secondary connection. It's just really hard if it's half a planet away, because you're gonna get crazy latency.

Hmm, good point. Good Point. Yeah. Interesting. And it drives home the point of, you know, uh, the usability going up, um, with the speed. Yeah. So, um, what were the biggest misunderstandings about zero zero trust that you saw when rolling it out to your SMB client clients? And, um, how did you reframe it? We already talked about it a little bit. Was there anything additional that you wanted to add? I really want to echo Jason's simpler point.

Um, we, for zero trust clients, um, since we've chosen a, a large global organization for our zero trust, right? It's not the, happens to be whatever firewall vendors there. Um, I can put it in my RMM, and so I can deploy it very quickly with, uh, configuration profiles and I can set, it's always on, so it can be functionally seamless for a user. Right Now, everybody knows remote access and anything messing with a connection is not always going to be completely seamless.

Um, but everybody's on this call, somebody's done some level of VPN troubleshooting or it didn't work and it was working, and then all of a sudden you couldn't access because VDNS was somehow broken. And the v it all goes on and on and on. Those problems seem to be much less significant because as everybody knows, uh, developers are putting a lot of money into the cloud and subscription based models.

So there's a decent amount of support and development behind cloud options because it's an annual or a monthly cost, right? So the biggest misunderstanding is it's gonna be very, very expensive, and it's really not for when you, uh, frame it in the, the view of a employee productivity and it's gonna be very technically challenging, which is actually less technically challenging. So, I dunno, Jason, if you have any more on that, but that's what I was thinking.

I'm just kind of curious as you frame it out, like there's a, there's the new client perspective, or if you're bringing on a new client, you can put them on anything. They usually, as long as it works, they, they don't always have preferences about which way you do it, as long as they can get to that end goal of the remote connectivity.

But you have a, a bigger challenge with those existing clients and changing over, and I don't know how it's been changing over some of them where you might get more pushback because they're already a client, they're already on something existing, you know, you're telling them the new clients are going on this other thing. But like, how have you bridged that gap between, from the existing clients to the new? You're absolutely right. Right? That goes back to the first thing.

If we have VPN, it doesn't cost us anything. Now, of course, we all know that's not true, right? It comes in the firewall license. Yeah. Um, why do you want us to pay $7 a month per person for this thing? Um, and, and you're, you're right. And basically what we have to say is, listen, we've had a bunch of attacks recently and as security, my job and everybody should know this, is to predict the future, right? And for in complete honesty, I'm not very good at that, right?

The bad guys innovate and the good guys catch up and the bad guys innovate. So I'm trying to prevent you from ever getting attacked or breached in this way. We've seen a lot of these, this is why we're recommending this standard is a challenging conversation, but it's one that's important to have, right?

Being able to say, listen, I know you haven't ever been, but several of our clients in this exact same configuration have been, so it's our job and it's our duty to tell you this is something that is a vulnerability of yours. And it is kind of a generic amorphous vulnerability that may happen in the future, but we're seeing it realized. Yeah. Are you seeing any differences with the upkeep side of it too?

Because there's like the patching on the agent, the patching on the VPN, there's keeping up to date with firewall where the zt NA where, you know, it works a little different for mm-hmm. You know, for how you're applying updates and there's like a total cost of ownership, uh, conversation to be had as well about like, how much does it take to actually upkeep this thing versus the, versus something new That goes back to vulnerabilities from the, the Verizon report, right?

Um, this is road access technology a vulnerability, and that's really bad. It's really, really bad. Um, with, with zero trust, right? The cloud provider never makes you patch their cloud architecture. That's their job. So all you have to do is make sure your single application on endpoints and not your firewall, and not your IDS and not all these other things have to get patched, right?

Um, and a lot of them auto update, uh, that's, that's some, that's a very common thing for SaaS applications, right? So, um, yeah, it's actually, uh, a lot less upkeep for us and a lot less for the clients, Steven, with those clients that were, um, and we, we all, we all have stories about that, right?

You know, the, where you did have an SSLV VP N compromised, what kind of downtime, you know, what kind of impact to their critical systems and servicing their customers contractual obligations, were there impacts on those things Tremendously? So I'll give you a couple. Um, so MSP's out there, um, I know we've all had some kind of a, like a single sign-on connected to active directory for your, for your VPN. Um, sometimes those have too much power.

We had a client whose VPN had been configured by their previous provider to be a domain admin, and it was the Fortinet flaw. And they got in, they compromised the domain admin account, and we said, you are now resetting every password across your cloud and your enterprise. This was about 150 person client. The downtime was multiple days before they were back up at a hundred percent. That's, that's a lot. Right? Plus we had to say they had domain admin access, right?

And what kind of company was it? This was biotech. Yeah. And, and did they have, for example, with biotech, did they have ip, you know, certain types of I IP in their, in their biotech, did they have, you know, fulfillment, did they have things of that nature and relate racial? Yes. All of it. Yeah. Yes. And, and prov and personally identifiable information.

It wasn't hipaa, but it was, they had to, there were some very uncomfortable conversations and everybody reputational damage is really hard to show on a balance sheet, but that does not make it any less valuable. Financially. It is a big deal. But it, this is the point is the no one cares about patching. No one care people get very focused on it's $7 more. I love the fact that if we can start to think about the, what is the business impact and the stories, here's the story.

This is a real thing that happened. You know, would you pay me, you know, hypothetically, Stephen, 150 people, or let's go ahead. So it's gonna be, you know, whatever, 10,000 bucks, what a more a month, right? It's seven bucks. Sure. They were down for two days. Right. You know, what's that cost? Right? It's fun having that conversation with attorneys. They know exactly how much they cost to be down. And a lot of, some, some of the SMBs don't.

I mean, we all know that financial planning and analysis is crazy strong in, uh, some of the, some of the smaller businesses, but, but all the hourly billing employees, uh, you know, where, where you're charging any kind type of consultancy, they know exactly how much it costs to be down. And we, you can say, listen, this, they, they, and they weren't even a hundred percent up in two days. They were a hundred percent up in five days. They were 50% up in two days. Right.

There's, there's a lot of really trivial arithmetic to do to say, this is worth removing this risk. Yeah, yeah. Yeah. But again, the, the, the, the end result, what I want everybody to get outta here is, is, is really focus on not like fud and you're gonna be down and this, that, but the business impact, like, we talk about business impact analysis, right? That's, that's where the, you know, I, I'm seeing companies that are selling the most. It, it's those conversations, right?

It's not about the the controls, right? It's not the details and the minutia. Yeah. I mean, I think, I think you just covered my last question, which was what is your strategy, um, you know, when dealing with organizations who have never suffered a breach when you're trying to sell them security or a new security project or product? Yeah. I mean, it's easy. People find religion once they're breached. Of Course. Now that all the animals are gone, let's close that door. Yeah.

Honestly, Jason probably has a really good point on this. It, it, it's fairly, it's challenging to sell. I something may happen. We're trying to prevent it from happening. This is the best practice. But Jason, I would assume it's less challenging when somebody's heavily regulated and you get to say, Hey, um, FINRA says you gotta do this. That's it. You know, There's some of those where you can lean on it and you can say, an investor said you had to do this.

There's some, you could lean on it and say, a regulator had to do it, but increasingly we're looking at the data and saying, here's what all your peers are doing. Here's what all the people that look like you were doing, you're doing less than this area or another area. And as a result, you should do more to keep up with the crowd, with your average peer, um, so that you can compete in the market.

Everybody, Microsoft 365 secure score has a fantastic comparison of clin, ease of, of companies of similar type and scale in there. And you can say you're at 44% averages, 52% what's going on? That's a, and it's an amazing sales tool. Yeah. Jason, you've always been really good at that. I, I, I'm glad you brought that up. Um, you know, what are your peers doing? What's best in class look like for your category, right? You're in the legal field.

Let me share with you what the leading law firms are doing. You know, they're doing this, this, and this. Your, your score is in here, there, in here. Um, it's a challenge because you, you know, you're competing with each other, with the other companies in some sense. So you could differentiate a little bit to say, you know, do we more secure than the other law firms? So you should trust us with your data, with your case.

It may not be the reason that they ultimately buy it, but if they're down to, you know, it's one or the other and they're looking at you in a final stages, like it, it could be a differentiator that could push you over the edge into why you get a customer, why you don't get a customer. But it's helpful to get down to that level and really understand like what people are doing. And I, you know, I always equate it back to, you don't have to be faster than the bear.

You have to be faster than the person next to you. Exactly. And especially as you talk about like ransomware and phishing and some of these other tools, there's a lot of spray and prey. Like there are all these spear phishing DeepFakes that like, make the news. But from like the Verizon report for everything else, it's a lot of things that just get sent out in bulk, hoping to hit some sort of target. And from there they try and get a foothold and then take it to the next step.

But, um, like it's just, uh, it's surprising how that, I guess, not surprising how that's still prevalent. That's, that's actually, you know, a very interesting, um, strategy. And it kind of rings true, um, to me as well. We have our, um, free control self-assessment tool. And like, one of the most highly popular features is the, this is how you rate against your peers, um, you know, implementing this control or whatever.

So, Um, it, it really helps, Phyllis, I gotta tell you how much I love being able to say, Hey, CIS this nonprofit that has nothing to sell you. That is not some guy, one opinion is saying, this is an industry standard thing, and your peers rank like this is very powerful because it comes up as non-partisan affects effectively. There are two kinds of comparison that are really important. There's comparison against your peers that is changing over time. There are always new things.

But as someone working at one of your clients, the comparison over time is helpful for them. They wanna show their boss that they've improved security over time, month over month, year over year, because they wanna go and show that scorecard to them and say, I deserve a bonus. 'cause I did this great thing. I made us more secure. I saved us this much money. I did something else. So it's helpful to them too, even though they might not realize it. Yeah, that's, that's excellent.

I know we're going to, Bob, and I think one of, you know, to maybe just hammer this home one last time, Jason, it's, I think also, and you know, Brent Adamson said this, right? A boom, the keynote speaker. It's about giving companies confidence in making decisions. So it's like, Hey, in working with companies like yours, there's five questions. They, they look at, one of them is how they compare to their peers when it comes to X, right?

And, and, you know, you're not sitting there telling them, now all of a sudden they go, well, what do you mean how I compare to X? And then you can say, well, leading law firms such as, you know, such and such, when looking at Microsoft, using a Steven's example, looking at Microsoft Secure, secure score, uh, secure score, we're at 80, 82%, right? What are we at? Uh, well, let's take a look. Right? You know, So, and why does it matter? What, what at risk does it tie out to? Exactly.

All right, Bob, over to you. All right. So yeah, Jason, my, my experience with this has always been when you start talking to people who really don't understand all of those peripheral issues that really cost more than just money, like reputational thing, it still comes down to a one plus $1 is too damn much in their minds, right? Because they just don't have any emotional attachment to the situation.

So have you, have you found a specific story or a tool or an analog in some way to, you know, showing clients that, that you know, that the risk is not acceptable and they should be invested in the cybersecurity strategy?

Have you, have you, I it's probably gonna be, I know you're gonna have two or three, but have you got Some Well, you know what, I, I actually have some challenges with how this, like, this is constructed because there's some of it where it's hard to convince someone that doesn't want pay the money, they don't see the value. It's really hard to just give them a generic example.

So you can talk about NGM, you can talk about, you know, Olly having ransomware and having to file for bankruptcy partly as a result of it. Um, those still might not hit home. I, I find that if you're talking to someone about security in general, throughout the course of my career, it's about bringing that example home of knowing their workflows and knowing what they're doing.

It's about saying, you know, assume this teacher has personal information on their laptop and they bring it to their kid's soccer game, to, you know, to grade papers and they lose it. The drive wasn't encrypted. All that information is out there potentially exposed. And the more that you can show that you understand them and their workflows, the better it's received.

So it's less about like a specific analogy or an example and more about just putting it in, um, in their vernacular in ways that they talk about their business and how they run. Um, I, I dunno if you found the same Steven or Bob, You gotta learn about their business, man. A hundred percent. You gotta do that heat mapping. You gotta understand what their business is.

It gets a lot, it's a lot more straightforward when you understand how their systems work and how they derive value outta their own systems to do the job, right? And so anytime you can con put it in context to that, it's a much better conversation. I would say. I don't know about you, Steven, but that's at least our, how it's worked for us. So Yep. Everybody out here listening, you ever had a CEO accidentally leave their cell phone in a bar?

I got a couple of attorneys that like to do that every month, and I got a couple of financial advisors that would never do that in the history ever. It would just not happen to them. And knowing those nuance really important in explaining risk to them. Yeah, I can believe that. So Jason, same sort of, and along those same lines, I mean, when you've got a bunch of people who are often similar solutions that we're talking about, right?

Because there are, there, there are a lot of us that, that kind of offer similar solutions. What's a, what's a way to get above things like the vendor noise and, and actually try to differentiate yourself, um, in some way that makes the fact that we're all working with the same tool sets in a lot of case that, that that's not the thing that you're compared against, you're compared against whatever characteristics that bring value.

I, I'm a little biased in this just for my career and also my current role. So I just raising that as a flag verse, but I, you know, I, I think that the specialization and really understanding the customers is important. Um, one of the things that I've done throughout my career is worked at a highly specialized firms.

And I think that there's a value attributable to knowing what a thousand of their peers are doing at the same time for, um, a client that know that calls you up and says, I have an issue with my Bloomberg machine, and the response isn't what's Bloomberg. It's, oh, I saw that issue at another client. We're actively working on it. It's a, it's night and day. And the same thing for here's how these other law firms are dealing with risk.

Or we've looked at risk across thousands and thousands of companies in the same way. Here's how they work, here's how they operate. Um, even outside of cyber, when I go to a vendor, I want them to tell me, here's how a thousand of your peers are doing it. Here's how everyone else is making this problem work. 'cause as much as we all all like to think that we're unique, even from the risk side, we're we're not.

We're not, we, we have a lot of the same problems in every single company, every single industry across the map Users. Yeah. Yeah. I believe that You Say users, Jason, do, do you especially users. I was gonna say, have I ever had playbook? A, a, a phone at a bar? I mean, I live right next to New Orleans, so Yeah, it happens all the time. Steven, they leave, they leave their phones at bars all the time. Hundred percent. You're right. You gotta be able to handle that, obviously. So, um, mm-hmm.

So Jason, do you guys actually standardize on some framework, you know, on a framework, you know, when you're talking you use that as a, as a vocabulary method? Like say I asked or NIST to kind of benchmark their assessment. Is that something you guys do? Phyllis? Don't kill me on this one. Uh, we love all the frameworks, uh, and they're very helpful.

But just like everything else, our, our clients are trying to prioritize and figure out where to focus, which is, you know, some of the, some of the implementation groups and some of the other ways. So we've actually taken some best practices from a few different frameworks and built our own that's, uh, a little more specialized and a little more operational around our industry.

Um, so it's just, uh, very, very focused that we found has a pretty good result in highlighting risks that they should fix that are very impactful for them as far as the relative score and from, you know, unique risks to their firm. Like they, there's a lot that the frameworks go into that work for so many companies across so many industries, and we try to make it a little more specialized.

Um, so, uh, not to say there isn't value in looking at them, but we've done something a little more, uh, unique and boutique for the specific industry. Well, I mean, you're using that as an element of differentiation, right? So that is a way that you're differentiating yourself, right? You're looking at best practices across multiple frameworks and making that, making that have value because you understand your customer and what their, you know, what their business is, right?

So it makes complete sense to me. We branded on our website as the drawbridge benchmark, so we have a, our own unique score. There's some proprietary value in doing that. So again, biased in that sense, but, you know, ultimately we're trying to get people hyperfocused on the things that matter. And no matter what framework, you have to put it in business context.

And you have to talk about like the three to five things that they can fix and how they can fix them and how to make it easy for them. The, the more work you make people do as you identify these risks, the the worse they are at adopting it. I've seen that just over and over again throughout my career. Sorry, Andrew, go ahead. No, No, no. I, I didn't mean to interrupt you, Jason. I, I, I think you just said something that's really important.

I've been the, I was at K Connect and I did a, a, a presentation, a lot of it grounded in this book called The Jolt Effect. And, and you mentioned something that's really important, not offering too many things, right? I think I'm, if I heard you say it, am I, am I paraphrasing you correctly, first off? Yeah. I mean they, it, it's very helpful to get people to focus on a handful of things. And I've actually even heard someone say, we give people options, give them two, not three.

So minimizing it, so it's not much to, to think about and decide between, Well, no, I'm glad you said this 'cause so what they're, they're finding is, and I'm not gonna get into the research and all this right now, but they found that top sellers do a few things differently. Number one, they limit options, right? Number two, they, um, the buyers these days are more fearful of making a wrong decision than doing something that could lead to a better outcome.

So think about that, two and a half times more fearful of being wrong than they are doing something that could be potentially good. And what these top sellers are doing, Jason, is they help the buyer de-risk and give recommendations and start to narrow down, like, Hey, look, based on your profile, you know, being in all, you know, in this type of alternative investments, yada, yada, yada, we found that focusing on this or this is are the most important things, right?

For an alternative hedge fund as an example, right? Well, there's only so many dollars, like some of our clients, maybe we'll spend more than some maybe not be able to, depending on the firm that you're working with and the size. But it's, there's only so many dollars to go around for any kind of budget related to technology, related to cyber related, everything else, like where do you get the best bang for your buck? Where do you get the best protection? You're not gonna do everything.

And it, it's, it's a perpetual challenge of prioritization. Um, and the, there's no perfect answer. Yeah, no, and this, like I said, there were multiple studies, this book sites that the more, as you increase options, actually decisions go down significantly. Yeah. They did that jam or the jelly study at the supermarket. Yes.

So they had like the 50 jars and nobody bought when there were so many choices, but when they reduced it to like two or three, they were able to decide and they made a lot more sales. Yeah. That was one of the, that was one of the, they cited many studies. That was one of them. It's obviously people would go, well, how is GM related to technology? It's not about that. It's about how people's psychology works when presented too many options.

So yeah, I, I spent a lot of time looking at those kind of things. Uh, I leave the, the highly technical things to people like Bob and Steven who are a lot smarter. So, ah, so Jason, I mean, I know you guys do assessments, right? So have you managed to use assessments as a way to kind of create some recurring revenue or to at least help with the roadmap conversations that go on with your prospects? You, we we're actually in a unique place. We do, uh, governance, risk advisory.

We don't do any actual, like, hands to keyboard of fixing things. So we are in a unique place to do a tremendous number of assessments and we've built enough data around it that we're creating our own score through those assessments that kind of help steer the conversation. But we partner with a lot of MSPs and what we wanna see is we wanna see risk get highlighted and roadmaps being created for MSPs of things that they can fix that are impactful, that can really drive the industry forward.

'cause you know, we're working with altered investment people that, you know, sometimes get a better reputation, but a lot of the money comes from endowments, from institutions, from universities, from like, you know, hardworking people there, like the FDNY or whoever else. And do you wanna see that money protected? You wanna see people do well?

Um, so it's, uh, it's really important to see what we can do to just partner with every technology provider and everyone to get the, the level increase, just like Andrew's doing with the cyber call across just the whole ecosystem. Yeah. Alright. Phyllis, over to you. Yeah, sure. Just changing gears a little bit. So Steven, um, when did you realize it was time to outsource your SOC and what made you pull the trigger? So, EDR has a lot of logs.

It, it, it, and that makes me happy and I want our clients to also be happy, but having a bunch of data that you don't do anything with doesn't generate that level of joy and confidence. So I think there's a sweet spot when it comes to clients and, and, uh, client count and engineer count where, listen, if you've got 25 clients and you have an EDR and you're sending all the alerts to your help desk, you're probably not flooding that help desk.

They can probably actually respond and, and see things, but at some point you get to so much noise that needs to be filtered properly and maybe you don't have a KQL expert on site running your sim that is doing absolutely everything that it's, it's worth it to outsource to have, say, listen, we're watching 24 7, we can lock accounts 24 7, we can isolate computers 24 7, and I think it's about 25 to 30 clients, right? Any more than that.

And you have all this really great data from the AI on top of an antivirus that is an EDR, uh, but you're not doing anything with it, right? And, and, and, you know, you may miss an impossible travel or you, you may miss, uh, behaviors and, and stuff like that that might, might not be something you wanna miss. Mm-hmm.

And Steven, you, you, you know, just curious, obviously you're mentioning you're focusing on EDR right now, but what about, you know, for companies that are regulated and you have to take ingest logs or you know, companies that are, you know, more, more mindful even just because of maybe a cyber insurance questionnaire and wanna log just from a forensics perspective, I mean, now now you're starting to talk about a significant amount more data.

Do you, do you guys look at that as well, you know, in the Yes, absolutely. So the, the point of this whole thing is to say the financial and and demand will drive whether you're outsourcing your SOC or not, right? If you have one client that's giving you a hundred million dollars a year to watch their soc, you can probably make your own.

But if you have a bunch of clients that need 24 7 monitoring, or they need to come ingest different data sources, or they need to have a SIM that's monitored and you can't staff for that, you either are locking yourself out of that client market, you're not doing them the best service, or you need to outsource your soc. And there are plenty, plenty of very nice outsourced soc out there on the market right now. Um, Andrew's got several right? A boom by the way.

Uh, and so it, it's, it's something, it's something to be said for listen, at some point. The cost to protect and the cost to monitor are both absolutely required. You can't just say, I installed this thing and it's fine and it's good. The human element matters. And I think there's an upper limit as well. When you need to ingest all this data, you need to take all these sources, you need to look at all these logs, and it's literally less expensive for you to build your own team.

But I think that's going to be far afield of the average MSP size, uh, that's listening to the call. I, I feel like one time, um, Andrew, someone asked Gary Peak of that on this call, and I feel like Gary Pika said, um, you have to be around a $200 million MSP to offer your own soc. Yeah, I'm with Gary Pika, which is a sentence is pretty safe to say. Yeah. Um, so that, you know, kind of speaks to your, your finances. Um, so you, you went and you shopped for a soc.

Um, can you tell us what non-negotiables did you look for, um, when you were looking for, um, a SOC to partner with and what red flags should we watch for? Right. So I think this is gonna sound interesting coming on the cyber call, but I think the most important part is, uh, business maturity of the soc, right?

I need someone that integrates into my PSA, I need someone that can actually call me and give me information that is relevant when it's necessary, and I need someone that can actually stop the flow. Everybody knows the first, the first thing you do in an incident is you stop the bleeding, right? That's, that's by far the first thing.

So we, we need someone who can do all these things, who can bill me accurately, we can bill my clients accurately, who is not crushing the performance of my systems and, and who is, who is able to actually provide the services that they are contractually obligated to provide.

And you'd be surprised how many we found that that simply couldn't make a call when it was necessary or couldn't, uh, isolate a machine within a a certain period of time or didn't see, uh, you know, the human portion of, uh, like an attacker doing a lateral movement, which may not be very, uh, tool detection based, but it could be human behavior based. So the, the thing that mattered to us was, can you soc let's start there.

Um, and the biggest red flags we looked for were someone that literally couldn't integrate into our, our, our PSA. Like if, if you have someone that cannot automatically bill your clients, they are missing other business maturation portions. There's something else that's not quite there. Um, engineers build great companies, but at some point you need to be a business partner in the channel. Um, without that it becomes extremely challenging to do business with you.

I, I think that's the number one thing I would, I would watch out for. Make sure they integrate with your systems in a way that is useful. Awesome. Over to you, Bob. All right. So Jason, I'm gonna swing this a little bit different direction now.

So what, and this is gonna go to more of the cloud-based, you know, environments that, that, that are so prevalent nowadays, but in, in your opinion, what's the number one mistake that you see clients making when it comes to like doing Microsoft 365 security? I assume you guys are involved in that to some extent, huh?

Yeah, I mean, it, we do 365 assessments and other cloud assessments, and they, the biggest mistake is it just that, uh, the fallacy of thinking that, you know, they spend millions and millions of dollars on security. So I'm secure. I don't have to worry about it. I don't have to audit, I don't have to look at it. I don't have to continually check it.

Uh, you know, people just getting in that mindset and not thinking like there's actual operational risk to how I set this up, or, you know, someone connected a brand new third party system to my data. Like it is my data exposed now because they had a random connection that they can now do more easily because we're in 365 versus somewhere else. Uh, people don't think about those connections.

They think about, they see the top dollar numbers and these articles about how much they spend on security and how, you know, you know, someone just acquired a new security company or that new security company, but they don't think about just the basics of like, how do I check, how do I audit, how do I make sure I'm actually secure and practice? Um, and some of those things don't cost a lot of money to do. Yeah. I think it's surprising you can, yeah, I think it right.

I think it's kind surprising that the, some of the features that you can get now, right? And configure, you have to know to configure 'em. That's the main thing. You have to know how to turn things on. But to your point, it is not a fire and forget sort of a thing that you do, right? Once you're up and running in a cloud environment, it's still a live environment and changes happen all the time.

We, we could talk, we could probably talk a whole hour about just turning copilot on in your tenant, right? And all the things that can go down along. I saw Steven even where I'm at on that, right? This is now I'm cold. Thanks, Bob. Well, but I mean, that's the truth though, right? I mean, that's the environment. Everybody's, everybody's so focused on wanting to get the productivity gains that you can get when you use these models.

But we're still in the, we're still kind of in the beginning stages, right? How to secure these cloud tenants, um, to the point that you can actually turn people loose in the organization to, to use them without exposing, you know, without exposing everything that's in there because it hasn't been tagged correctly, or you don't have a strategy as it relates to it. Um, I heard, I heard Scott The other day. Do you wanna hear it? Say that again? Probably not. I heard a scary stat the other day.

Do you wanna hear it? Yeah, Please. Percent of iPhone users don't touch the settings at all. 80% of iPhone users don't touch the settings at all. Use the default off the shelf. Don't change anything. It's frightening. I, I'm not sure why that's a surprise. They don't. It's just scary. It's not surprising. It's just scary. Yeah. Yeah. Scary. And, and, and this, these are your BYODs on top of it, right? Jace, right? Yeah, yeah, yeah.

Um, so these are The people that are not as technically savvy, that are leaving their settings and they're clicking on Phish phones and bars and, you know, someone sent a random phishing link to all these iPhones that have generic settings, so the person sending the link knows what their default settings are and has geared these phishing links to people with default settings to be easier to exploit them.

And it's, it's scary, But what, what you just, I think it, it's interesting what you just came full circle. I think you started off by saying, but not saying it, people think their cloud cloud infrastructure cloud app provider, they don't understand what's in the shared responsibility matrix. If I'm paraphrasing what I It's true. Yeah. No, that's it. Yeah. And then, and then on top of it, right? When you think about coming all the way full circle back to, you know, devices, right?

BYOD, um, you know, the, that that's, you know, Eric Woodard's big thing, right? Phyllis, we've heard him a million times talk about, you know, how he looks at, you know, a shared responsibility model with his customers and that, you know, if a customer has a mobile, mobile devices that are accessing M 365 or any type of customer infrastructure, and he and the company won't allow him to put some type of, you know, MDM on those, it's like, I'm that's, that's yours.

Anything, they Don't even think there's a responsibility matrix. They just think it's all handled, it's done. It's magic. It works behind the scenes, Right? I mean, and I think, you know, the strength of what Eric does, he details it very clearly. I mean, he has, this is what I'm responsible for and this is what you're responsible for. You're re, you know, and he, he really does detail like the shared part, right? Yeah.

Like, okay, asset management, here's what I'm willing to do, but here's what you have to do. And he goes over that in detail. Yeah, yeah. Yeah. He's, he is very good at it, so, mm-hmm. Alright, I got one more question and then I'll hand it back over to Andrew, but, so Jason, I think I'll open this should be Steven and Jason 'cause and, and I have a little bit of experience so we can talk about it, but how do you guys approach hiring offshore talent for your security teams?

And, you know, especially in some cases when clients require be us only, um, you know, where's the line legally or ethically when we start talking about, you know, hiring offshore security personnel for supplementing our, our workforces? What do you guys, what's your experience there? Like, we need Eric till on the call for that one. This is my, yeah, it's a, it's a challenge with data all the time because like we, where do you actually draw the line?

So, you know, I, I could use a full US team, but my tools might be developed in any other country. It might be developing Canada and the Canadian company that develops them might use developers from South Korea. So it's like, where do you actually draw that line? I've seen a lot of people kind of, uh, contain certain data access to a limited group and number of people within the firm from the MSP that are servicing it.

But in reality, there's potential for so many people to touch that data along the value chain of how it comes in, how it comes in through your PSA, how it's processed in your data and analytics systems. Um, you know, how it goes out over email, how the email's protected. There's so many areas that non-US people might be able to see it or non, uh, of a certain domestic or certain requirement might be able to see it.

So, you know, you have your best for your controls, but it, you're only, uh, I I guess you're only as good as your weakest link there. I, I dunno what you've experienced, Bob or Steven, what you've seen Steven. So I think, yeah, I think it's, it's, it's relatively trivial to like isolated a password system, right? And that that'll take a lot out, right? You don't have the passwords to these clients. It doesn't, it doesn't kill the PSA, it doesn't kill the RMM, right?

Because you can still run scripts. I think one of the biggest lessons we learned on this is when clients say US only, we have to be very, very specific on what that means and what data pertains to, does that mean only US citizens currently in the United States can access absolutely anything to do with your company at all, or you only want people who are a US citizen or in the United States logging in your systems. Those are not, there's not the same thing, right?

And, and being able to very clearly say what can and cannot be accessed. There are some clients we have that have very, very, very high levels of security, right? They're in the, the 365 glove go, uh, GC high, and they're very, very, very specific on what data can be there. And we just have instructed our employees, you absolutely do not access these systems. We take away as much as we can and we in writing tell the client, this is our protection. One or two.

It's not been good enough for you just say, Hey, um, we do have offshoring, and it is possible that at some point something could happen, but we are doing our best. It's usually okay, but not always. Yeah. We have some state law enforcement agencies that we have to be very careful about, right?

So we have a subset of our organization approved to work with that group, and all of our workflow systems have to be able to support that isolation, you know, as we're, as we're doing things like support or engineering. So it, it takes a different mindset, you know, to be able to kind of run the ball there. So, back over to you, Andrew. Yeah, Well, we can let, you can just let Tracy loose on them. Oh, listen, wants Tracy. Yeah.

He, he is our, he is our secret weapon as far as our abilities are concerned. Yeah. All right. Well first off, I, I put a a, a quick link in there as we close out. Next week is the fifth year anniversary. We'll have Kyle, Hans Lovin, uh, CEO of Huntress. Uh, we'll have Wes Spencer and Gary Pika. Um, Phyllis, you're welcome to sit in, but it's gonna be the originals, um, uh, here on the cyber call. Uh, it's hard to believe it's five years in the making.

Um, so we'll look forward to, to seeing you all next week. Please share it out, um, that URL is to put it on your calendar and has, uh, the URL to the actual event. Um, Jason, thanks a million for coming on. It was awesome to have you with us for our first time. I was this a first I think for you or not? First time. First time, yeah. Same for Steven, I believe. Yes, sir. Many more to come. And Bob, thanks as always for sitting in and, uh, doing a phenomenal job, co-hosting.

Phyllis, great seeing you as, as always. So, uh, a great, great, uh, great time, uh, and great subjects. Have a great week, everybody. We'll see you soon. Take care. Thank you. Take care. Thanks everyone. Alright, we're good.

Related Videos