Skip to main content
Right of Boom
July 22, 2025
717073

What Makes a Good vCISO and How to Scale this Service

The role of a vCISO (Virtual Chief Information Security Officer) is evolving from simple compliance checks to strategic business leadership, and MSPs (Managed Service Providers) that embrace this shift can unlock new levels of success. A modern vCISO goes beyond risk identification, focusing on protecting revenue, enabling growth, and reducing friction in cybersecurity processes. By understanding business drivers, speaking the language of executives, and leveraging real-world experience, MSPs can deliver high-value, low-volume engagements that provide actionable roadmaps and measurable results. Building a vCISO practice requires aligning internal teams, developing deep expertise in frameworks like CISSP and CISM, and focusing on the clients who benefit most from strategic security leadership. With the right foundation, MSPs can transform into trusted advisors, delivering not just technology but true business outcomes.

Guests

Andrew Morgan

Video Transcript

All right. Welcome. Welcome, everybody. Uh, lemme just do a little text here in chat. Welcome, happy Monday. Make sure you guys can hear and see us. Okay. Let me know if, uh, we're coming through loud and clear to you all, and, um, yeah, we'll, we'll kick things right on off as we let people on in here. So, last week, um, Brian, thanks for doing a repeat session. Hopefully I can cajole you to, you know, fill in and come on every week, um, as much as possible.

Um, we, uh, we, we, uh, we really enjoy you, you being part of it. Um, so we talked about risk, revenue, and responsibility last week, that quote unquote real job of the bc So this week we're gonna get a little bit more nuanced and, and, and take a look at, you know, what does that role actually take? What are the qualities, training, education, and all those components?

And then about scale before I, before we start to go into that, just as, uh, I, I've mentioned on the last few cyber calls, we're now doing this right afterwards, we're doing a post-production and, um, getting this over to, um, a podcast. We've had hundreds and hundreds of listens. So like, we've literally doubled, uh, quote unquote, you know, viewer and lead, you know, uh, viewership, I was gonna say. But, um, let me, uh, let me also put that in, uh, the URLs.

And so I want to just quickly share, um, who's here. And, uh, then we'll get right into it. So just in chat, this was last week's. Um, and we'll have it, you know, again, you can see all of these, um, on, um, our site there, podcast writer boom.com, they're on all the major players, apple, Spotify, whatever your flavor of listening is, it'll be out there. So, as I said, we have Brian Blakely here back, uh, this week. Um, chief Risk Officer at Compliance Scorecard.

Brian's owned a number of MSPs over the years, as he likes to say, InfoSec nerd. And I think that's one of the differences, Brian, is you entered this industry, uh, versus an IT practitioner, um, which also led you to scale and build a vcso practice that which you also, uh, sold, uh, to DMIA few years back. So, uh, good for you for all the success. Uh, we also have Eric Sun with us. Um, heads up the Vcso team at Core, inte, who's been with us a few times and coming back again as well.

Steven Hicks, who does the same over at nSight. So the nice paddle route today is, you know, we've got people that are actually in the trenches doing this, doing it at scale, have teams, um, and somebody that has built, successfully exited, uh, and, and then, you know, really does it on a day in and day out basis as well, I think on a consulting side. So, Steve, just so you know, you might wanna mute, we can hear you tapping away there. Um, and then you can bang away on those keyboards.

So, um, a little bit of banter for today. Um, I'm sure you've heard, but if you haven't heard, um, Microsoft, um, online, I'm sorry, I keep saying that on-prem, SharePoint has, um, uh, been the target of a fairly large, um, attack, um, in the wild going on right now.

Um, you, you know, Ryan, uh, starting off with you on this, um, is it, you know, just tech debt that, you know, Microsoft is completely focused on M 365, um, where you could, you know, you see these things, you know, we, from time to time, we Right, we see these on-prem server, you know, exchange, large scale compromises. I mean, obviously people are still running, um, you know, large scale enterprises. What are, what are your thoughts on this? I guess take two sides.

One, is it, like I said, just old tech debt that Microsoft isn't really keeping, you know, up to speed as, as much as M 365, it's not a priority. And then two, why are companies still keeping this on-prem? Yeah, I think those are the two fundamental questions, Andrew, when, when you look at this, I, I, and, and, right? We can't blame, I, I just can't see blaming Microsoft for this. There's, uh, they're a business, right? And they need to put resources where it matters.

I think Microsoft zero day alert on the on-prem SharePoint, I think it was 2016, and 2019 isn't really just a, a patch at moment. I think it's proof to kind of what you were just sharing, Andrew, it's proof that legacy infrastructure is a liability, okay? If you think about it in terms of risk, it's a liability. And, and I get it, we all still have legacy stuff to deal with, but if you're still running old critical systems on premise, I would say you're not just behind, you're exposed.

And it's time to really accelerate toward, uh, cloud, and I would even say zero trust principles as the perimeter is our, our user's fingertips, right? So look at that and, and, and do those things to modernize or accept the, the, the breach risk. Yeah. Okay. Eric, you guys work with some larger customers. Are you still dealing with this at all?

Um, you know, and then, not to be dismissive of you, Steve, you've just characterized a lot of your customers as typically the, you know, 25 to two 50, your sweet spot. I'm, I'll ask you if there's any, but Eric, any, you know, you guys have some bigger co companies. Um, are, are, are you dealing with any of this legacy stuff? I don't think there's any on-prem SharePoint that I'm aware of. I'm not aware of everything. Um, but yeah, I mean, there's been a lot of transition there, right?

And of course, on-prem SharePoint was kind of garbage for a long time too. Terms usability. And I'm guessing that's probably still true. So, you know, the move to hosted SharePoint makes it a marginally better. Got it.

So the, the one thing I will note though, I think, and Brian, I don't know if you saw this also, when I was looking at the report on this vulnerability, one of the people was noting when they patched a couple vulnerabilities in the past, they didn't account for the way those could be chained, uh, which led the part of this seemingly.

And so I would lay at least that part on some of the Microsoft's feed of when they're doing their vulnerability mediation, they need to account for vulnerability chaining as well. But, And, and Eric, that could be a whole other podcast, I think, right? Is, is people ignoring medium and low vulnerabilities. 'cause they, they treat 'em in isolation instead of just knowing, hey, you can link these damn things together where a medium and a low turns into, you know, a, a significant business impact.

People forget about the chaining aspect and just focus on critical highs. It's dangerous. Yeah, absolutely. Steve, any, any, any companies just fighting, you still, you know, the small ones, the, Hey, we're not gonna upgrade. We, we've been doing it this way forever. Sure, yeah. Happens all the time. And, and I don't think we actually have any SharePoint 2016 out there, but I know from 2019 out there, and uh, for all of you watching, I know some exchange on-prem out there gasp.

Um, and it is, it is what it is, right? Um, for many reasons, Andrew, you're right. You know, exchange 2019 is still supported, right? So SharePoint 29, these, these are, they're supported by Microsoft. Um, we've obviously advised our clients, listen, you're fighting the current, right? If all the development money, all the security money, all the research money's going into a SaaS model and you want, uh, uh, an on-premises like single, single purchase type model, that's fine.

And they'll, they'll still support it right now, but it's not their primary focus. So you're gonna see stuff like this, and Microsoft even says they're developing a patch for 2016 SharePoint right now, not, here's the patch. And that's indicative of this type of thing. Screen connected, the same thing a couple of weeks ago, right? Yeah. All the, all the cloud stuff was fine with the on-prem wasn't, Yeah, fair. Alright.

The other thing, um, I'll just talk real briefly about this, was this is one that, um, I just put in chat. Alright, Brian, starting off with you. Um, let's take this from, you know, the CMMC perspective.

So, so basically m the, somebody a whistleblower came out and said, Hey, you know, Microsoft has these, um, contracts, for lack of a better word, if you will, Brian, with people in China that are, you know, these digital escorts and that are, you know, basically looking at literally us, you know, the contractual stuff that Microsoft has with the US government.

And, you know, you sit there and look at, you know, the, the rigor that folks in CMMC are going through right now at level two and higher and, you know, to, to be in, uh, GCC high, what they're spending. And then lo and behold, this comes out, um, what are your, what are your, what's your take here on this? And it's been addressed since, like, Microsoft was, I, I'm being a little sarcastic. Well, we weren't really aware of this and now we're getting rid of all this.

Well, It's very intentional, right? And all money based, right? And I always say, you know, disclosure's better than discovery. And in this case, I think Microsoft's been discovered here a little bit. And then they came up with this digital escort concept of saying, yeah, we hired people that aren't US citizens to do the engineering and support, but we had our US based digital escorts to kind of watch what they were doing.

And at the end of the day, this should really p**s a lot of people off that have to be FedRAMP and CMMC level two or above because they're paying three to four times the operational costs.

Some have done quarter million, half a million dollar, million dollar migrations to GCC because they deal with things like ITAR and other export control data where they're paying for a service where it's all US based, not just the servers and infrastructure on US soil, but all the support and engineering is on the us right? And this should really, I, I mean, it's impacting people that use this environment, potentially their compliance.

And they've already made the investment and have put their trust in Microsoft to do this. And Microsoft has breached this trust, in my opinion. And again, this could be a whole other podcast that, that we, we talk through that. But that's my initial gut reaction is people should be p****d off that are reading this, who have spent three to four times as much operational cost and a chi a ton of money to get from where the commercial into, into GCC. Yeah. Yeah. Eric, you guys, any thoughts here?

Are you dealing with any folks, um, with CMMC? Uh, not the, not the CMMC specific side of it. I mean, I have no love for Microsoft being cheapskates, right? You want to pay for logs you also have, are gonna outsource for CMMC services. Yeah. It doesn't make any sense. Um, and especially in a country that, as the article talks about is a declared adversary, whatever anyone wants to argue about that back and forth, it's still true. Govern that they're declared as a concern. Yeah. Yeah. Yeah.

Steve, closing thoughts on this? We'll get into it. So for my technical brethren, um, you ever watch somebody work and audited their work in some kind of a meaningful way? Like I, I'm not, I'm sure not, I'm not clear on how that concept works. Like, oh, we we're overseeing them, are you now? So you're a sim um, and Andrew, this is actually relevant to our current topic, right? The qualifications of people to do their job.

This is like a, a pretty significant thing we've been talking about here, especially in security. Um, turns out that you, you need qualified people to do that kind of a thing, including watching people work remotely. Not clear how that works, but I'm sure it does. Fair enough. All right, let's get on into it. So, as I mentioned, um, I would highly encourage you guys to watch last week's session.

Brian did a, a masterful job laying out what I call the risk to revenue conversation really talked about. And we, we will talk a little bit about that today. But, um, we really looked, we really looked at the job of the bcso kind of at a more of what I would say the macro level brand. And then, you know, you and I were talking and we're like, well, what about the micro of this? Like, what, what does it take to be a, a good bcso? What, how do you know if you have one in, in house?

How do you train one? You know, what does good look like? And once we know that, how do you scale that? How do you, you know, start to build a business around that? You've done that. And so I thought you'd be a great person, uh, to come on. Um, so we'll dig into that today. And, and with that, let's do quick intros, um, just in case you all, um, uh, don't know. So Brian, just, uh, just give us a real quick one. We'll go to Eric, Steve, and then get right on into it. Sure, yeah. Hey everyone.

Brian Blakely here, spent the last three decades or so really in the trenches as an engineer founding bill and growing, selling, exiting several MSPs over the years, then evolving into a full-time mid-market CISO for about four years for a FinTech company and many, many Vcso roles helping MSPs and SMBs and, and larger mid-market companies turn security and compliance into, into real business value.

I'm currently as, as Andrew stated, chief risk Officer and lead the professional services, uh, team at Compliance Scorecard. And again, Andrew, excited to be here. Always fun to, to catch up. You're such a Go-Giver in the community and anything I can do to help support you and the community at large, I, I'm all about. So thanks again for having me on the cyber call today. Thanks for coming, Brian. Okay, Eric, over to you, bud.

Yeah, um, serving as a vcso and team lead for the Vcso practice at cortent. Um, so we got a lot of customers in financial, biotech, et cetera, et cetera, um, and helping serve 'em and their business needs. Perfect. Thanks Steve. Welcome back. Uh, Thanks there. Uh, Steve Hicks, everybody, a security practice manager over at nSight. We're a, a small to mid-market MSP up out in California. Um, uh, like Brian, 30 years of engineering experience moving into this.

I've done Ben field engineer and security engineer up into practice leadership now. So that's who we are and what we do. Very cool. Alright, Steve, lemme turn it over to you asking Brian a few questions. I know you gotta leave about five uh, minutes early. Yeah, so I'll wave to everybody. I'll say goodbye y'all. But Brian, let, let's talk, uh, what is, what is a visa CISO today and how has that changed in the last five years as the industry's evolved?

Yeah, I, I, I think five years ago, most people, even if they even heard of the term v ciso a lot, hadn't thought of it as a part-time like compliance nerd, compliance consultant or technical resource who help check boxes for different frameworks like HIPAA or SOC two or whatever, very tactical, reactive and framed around deliverables. Not, not outcome, but I think that that definition has really completely started to evolve, right?

Today, a VCSO is a, a strategic business leader, or should be, and we're gonna get into some of this. They're not a glorified technician, they're not a technical account manager and not a policy pusher, but they're someone who aligns cybersecurity data privacy and, and compliance decisions with, with the business priorities.

Andrew kind of set the stage earlier around this business focus risk management and, and I think the, the CISO does it in a way that protects revenue, enables growth and shrinks risk with the least amount of friction possible. And so the modern, the modern v CISO doesn't start with a a risk register, right? They start with a business plan, they ask, how does this company, uh, make money? What are the profitable revenue streams? That kind of stuff.

What contracts and customer expectations are driving, um, compliance needs? What's our sales strategy and how do we reduce friction with customers, partners, and insurers? And, and I've kind of seen firsthand in this evolution that the vcso roles is really when done right? It's a competitive advantage, right? Whether you're an MSP supporting SMBs or mid-market company, fielding security questionnaires every week, right? The vcso is no longer optional. It's become more strategic.

So the role has evolved from this security, I'd say, you know, task master to more of an executive level translator. And I think the ones that that get that who understand that shift are gonna be the ones that that survive.

So what I'm hearing is it's, it's gone a little bit from a technical role and account managerials role to a business professional, someone who's going to actually be able to discuss the role of the business, where the money comes from, where the risks are, and do that in a way that that sustains an advantage for the organization above competitors. Something like that. Yeah, a hundred percent. Yeah.

It's all about relating these technical risks and vulnerabilities into the impact to the business in a way that the business can understand and react to that. Okay. So in that same vein, since we're trying to shift the, the, the mentality from a technical to a business professional, what separates a good vcso from a great one? And is there any traits or mindsets that you can imagine, like, are beneficial to this? Or can anyone be trained to be a great vcso? Yeah, great question.

And you might not like some folks out there in the MSP space might not like some of this that I'm gonna share. The answers Are part of it. A mediocre vcso delivers reports, right? And dashboards, that kind of thing. A great vcso makes decisions, okay? They don't just identify risks, they help the business understand them, prioritize them resour, get resources around them and, and act, right? They know their job just isn't to consult and advise, it's to lead. Okay?

And that means showing up with cl things like clarity and strategy and confidence when it matters most. The other part that you just asked, this is unpopular. Can anyone be trained to become a strong, uh, you know, a really great vcso? Honestly, not everyone. Okay? You can teach frameworks, you can teach certifications and controls, but what separates the, the great ones is, is a mindset. They think like an operator, not a technician, right?

They focus on protecting revenue, not just patch and vulnerabilities. They seek to understand this is important. They listen, they actively listen and seek to understand how the business makes money, how contracts create obligations for their clients and how to align security with, with forward momentum and not, not lead with fear, uncertainty and doubt. Fud, right? So great Vcso also, Steve, they, they communicate like, like executives, right?

They can speak to the CFO, they can speak to the board, the leadership teams as well as kind of that frontline IT team with that same calm, strategic presence. Okay? And they know that every dollar spent on security and compliance should solve a business problem, not just fulfill a requirement or check a box. So yes, some of this can be trained, but the real leap in my opinion is when security pros stop talking about tools and tasks and start really owning the mission, right?

Protect the business, reduce friction and, and build trust at the speed and velocity of of business. So I'm hearing that there are some level, there are some educational training certification type things that, that are helpful for, for like the optics of coming in with, with some kind of power behind your back. But also there is some natural ability in there to be able to speak, uh, to executives and be able to say, Hey, listen, here, here are the risks you're taking.

Are you aligning your risk appetite and your risk profile? Um, which may not be something that everyone can have. Andrew? Yeah, I was gonna say, Brian, the, you started off answering that question with something I I really piqued my interest, said vcso make decisions and I'm paraphrasing, right? Something to that degree. And it's, um, you know, we've, I've, I've beaten this to death about what's holding up sales, right? And it's, it's indecision.

Um, one of the reasons is because we're not doing a good job. Number one, simplifying, right? What, what the issue is and, and providing quantifiable really good actionable steps to a problem and, and that are simple to understand. Is that part of it? Do you, you know why they're, like you say it's not, not everybody can do that. Not everybody can see the vision of the business, make a recommendation.

This is what we need to do, how we need to do it, why we need to do it, how it aligns to the CFO and leadership and contracts. It's, it's a multifaceted thing. But coming in with that recommendation on the why is why you get movement. I would've rec I would argue that why people spend money with you more so than not. Yeah. I, I, 'cause I I think you're, you know, what it requires is, is not just experience but exposure, right?

You have to be in those situations because what they're paying for is leadership and decisions that use your judgment and wisdom. Okay? And judgment and wisdom doesn't chug out of an AI thing and it doesn't come out of a, a, a, a shiny new platform or tool, right? That just comes from, from exposure to a lot of different things. And, and I'll say exposure to how leadership communicates.

And when you talk about clarity, Andrew, it's putting it in a way that they can understand and react to technical people. Us as engineers, we'd love to come in with the how and we vomit all over them with, with too many options and too many crazy stuff that they can't make decisions on. You literally come in and you make it as clear as this is the blue pill, this is what you get, and this is the red pill and this is what we get two options.

And make it very clear when you articulate that in a way that that demonstrates that, hey, there's, here's how long it's gonna, here's, here's the problem, the business impact, here's how long it's gonna take to fix it and how much it's gonna cost. And by the way, here's the cost if we don't do anything right? And so that's really just kind of communicating in a way that they can react and resonate to instead of talking about a bazillion CVEs and vulnerabilities like we tend to do. I like that.

I think when we speak to clients and do like risk assessments and analysis, it's there, it's easy to say, oh, you need to turn on your D Kim and you need to configure conditional access. And that's not a, that's not a thing that resonates with executives, right? You need to say, Hey, here's option one and the cost to fulfill and the cost of non fulfill and option two and the cost of fulfilling cost of non fulfill.

Those are, well, Yeah, if we don't do this, then it's gonna impact invoicing and you're not gonna get your in invoices out, which is, I'm gonna direct impact cash flow. Right? Right. I didn't say anything about the technical vulnerabilities or, or any of that, right? So that's, that's what kind of gets their attention and, and makes them lean in. So yeah, why does v chem matter D Im, doesn't matter.

Just 'cause d m's off DM matters for the sake of email delivery, effective communications, reputation, et cetera. That's good that, that's, it's important to point out. So Brian, you've made a couple of comments and I think I agree with you about there, there is a certain level of technicality that is required to back up your recommendations and a certain level of, um, soft skills that are required given that we can't speak to soft skills on this call as well.

Every, everybody be charismatic and do good. Like, that's, that's kind of a hard, hard directive. Um, is there, are there any core training frameworks, et cetera, certifications you think are critical things that people can actually go tactically do now to boost their credibility, um, for a vcso role and to give them some level of, um, exposure and experience while they're working on the other harder stuff? Yeah. You know, and that, that's a, that's a great question.

'cause we all, you know, there's people that certificate bash all the time, right? Where they come out and, hey, you're paper tiger and, you know, no real world experience and that kind of stuff. But I think there are certifications and, and frameworks that are, are, I think foundational, but they're not too many people treat these certs as the, the finish line, right? Again, they're just a, a baseline, they're not the finish line.

So C-I-S-S-P-C-I-S-M, the certified ciso, there's a lot of different ones out there. I, I do think it's a good idea. I do feel it's a great idea actually to have some of those, for some of the foundational e experience, right? They force you to understand these broader domains of security and governance. And I think that's important. But I, I can tell every aspiring, if you're a vcso out there, your search won't matter if you can't speak the language of the business.

Some of those soft skills that you're talking about, the best, best vcso I've trained or or mentored, combine this formal learning with, with practical experience. So yes, get familiar with, with frameworks and this, this, and ISO that and that kind of thing, but then go deeper, learn how to read a financial statement, sit in on a sales strategy meeting, right Andrew?

When you sit in on a sales strategy meetings, that's, that's a whole other different vernacular and language that you pick up on, but you really figure out what's important to the business. How can I enable and grease the wheels of, of the sales process, right? So study the contracts your client signed. We talked a lot, a lot about that last week. It's hu it's often missed, right?

Because that's where the real risk lives and that's how you learn to tie security investments to revenue protection. And I always say, and I said this a second ago, experience versus exposure. You don't need two or three decades of experience to become a great vc. So, but you do need exposure.

And that's why I push, like shadowing so hard, sit with someone who's done the job, watch how they navigate leadership teams boardrooms, how they prioritize risk, how they talk, how they guide leadership through, through trade trade-offs. And, and that's how you build judgment. I think judgment is the real skillset of a vcso.

So yes, get the certs, master the frameworks, but combine that with mentorship, shadowing, and what I would characterize as kind of a relentless focus on understanding business drivers, right? That's what makes the difference between someone who kind of knows the controls and someone who knows how to lead.

Brian, I'll never forget this, a story you were telling once, um, about, you know, you were kind of looking at the different facets of the business and you did get into the conversation around the CRM and you know, how they work with their customers and how the lady and marketing stood up and is like, you wanna tell about what she, where she was putting all the contracts and your, your, Yeah, this is something we talk about a lot when you're talking about to a company and how they make money.

You can plot this out on kind of like, I'll get nerdy here for a second context, zero kind of, uh, uh, let context level zero kind of diagram. But that's how you can really get to know the company. So you get all the right people in the room and you talk about their data flow and here's their top revenue streams and they get 80% of their revenue comes from let's say transaction processing fees. So you start asking the client question, oh, great, how do you do that?

And, and you start documenting kind of the little circles, people, process, technology that, that drives those revenue streams. And it's, we'll pick on marketing for a second, but invariably the marketing person will say, oh, I also export that list into HubSpot. Or I I take that and export it over here, and we do a mailing.

And you look at the, and it's a bunch of personally identifiable information or regulated data and that kind of thing that floats, they've even said, I've even heard, uh, this is a couple weeks ago, this is fresh. Uh, uh, someone in marketing say, oh, I copy all that to my, my personal Google drive.

And then I have, uh, Jane Doe who's, uh, that's uh, uh, she helps me out in the past at another company and she gets in and she scrubs the data and the spreadsheet, and then we take it and we import and those data flows. You should see it's face, you know, it's Got cold. Oh Yeah. And it's like, whoa, whoa, whoa. That's not any of the known data flows. And so you get into that.

And so, but that's what I mean by really active listening and trying to understand the business drivers, because a vulnerability scan and that kind of thing, don't never pick up those kinds of, of things. That's what I said, a vcso, you're gonna spend most of your time, if you know the OSI model, you probably think it starts stops at seven. There's eight layer eight is where you spend most of your time. And that's politics and people For sure. It's also the biggest risk And opportunity.

Yeah, sure. So, okay, Brian, you, you've, you've made a lot of points about being able to speak the language and those, those are, those are awesome. We love those. Let's dig a little deeper. What kind of simulations, what kind of pre training practice can you actually give people that they can go do to prep, to speak to executives, to work in the boardroom? That's a, that's a pretty important thing. So, um, we've mentioned the soft skills matter. How do we train those? Yeah.

And, um, in my experience, there's no better, um, substitute than being battle tested. Okay? So what I mean by that is kind of the best preparation for the boardroom isn't just theory and certifications. It's living through real world incidents, right? Hard decisions, those high pressure moments, those very emotional type of, of situations and scenarios too. And if you've led, led, uh, that's important here.

If you've led a company through a data breach, if you've ever had to brief a, a, a board or a leadership teams, while lawyers and PR teams are kind of spinning up, that changes how, how you communicate, right? Prioritize and, and lead. And I think that's where confidence and, and, and wisdom is, is made. So yes, I think there, there's a component where hands-on, like this battle tested incident response is critical.

But again, I I say led the led the response and not just the technical parts and pieces. You need to be in the room where the execs are there when executives are trying to decide what to disclose, uh, when and, and to whom. I just lived through this, uh, about a month ago. I can't say who they are, you'd recognize their name, but just, uh, got, got hit with the play ransomware.

And boy, you talk about emotions and, and people on edge and, and, and, and you just need to be in those rooms and you need to see what the trade-offs are, experience the fear and the, the business risk, all of it. And that's how I think CISOs earn, um, that executive presence. And if you haven't lived that yet, find, find people who have, right, find mentors who have shadow CISOs, v CISOs or even A CIO, right, who have been through it.

Ask them kind of what they wish they knew going into the first breach and ask to sit in on if there's any other, other meetings in the future or debriefs. Just really pick their brain. There's no faster way to grow. And I'll, I'll share this too. I shared this with, with, uh, uh, Andrew a couple weeks ago on some feedback I got early on when I was doing some, some risk assessments. But this is something a lot of people overlook.

And it's great for vcso to grow, ask for feedback from other executives after a board presentation, after a leadership team or strategy session, pull the CFO or CEO or COO aside, or VP of ops, whoever that is, has asked, did just say, Hey, I was in that meeting, you know, did, did that land, did I add value? Was that useful to you? That feedback is, is gold.

It's hard, it's difficult sometimes to ask for that feedback, but the feedback's gold and it's gonna really sharpen your, your message, your messaging, right? Your presence and your ability to earn and keep a seat at the table. Because I, I think in the end, I, I'll end with this thought being battle tested. It, it's, it's not always about having the right answers or the perfect answers. It's about having that, that judgment piece, the right judgment under pressure.

And that's what your client's leadership teams and and boards are, are really looking for in true vcso leadership. Appreciate that. That's a a lot, a lot of that's really great information, especially the feedback portion. It is very challenging sometimes to speak the different language. And it can be a, you're right, it's a definer between good and great, whether you can communicate with your actual, You want the feedback loop, you know? And so, but it takes courage, man.

'cause you know, you know, some of the, the them and the way they communicate, you know, especially board members and audit committees and others, you know, you've gotta be ready to, to be a sponge and, and take it all constructively as possible. Don't take it personally, right? You, you, you either win or you learn and, uh, you, you know, learning how to sharpen your message and, and, and add clarity only allows you to grow and, and, and get better.

I mentioned a scenario a few weeks ago, or I mean a few, several years ago actually, that, um, I got feedback, uh, from the CEO who said, Brian, you know, that was a lot of information. Anytime you hear that from an executive, you've given us a lot to think about. That's, that's not a good sign, right? 'cause you've overwhelmed them. But that, you know, get that feedback and then incorporate it in what do you do, you do and, and how you do it. That's awesome.

I'm gonna pass the mic over to Eric. He's got some more questions, so thank you Brian. Yeah, I was also thinking a couple of things here, Brian, I was curious. I'll just note these comments and see if you have thoughts on 'em. But like the C-I-S-S-P test, for example, one of the big things you'll find all over the place on YouTube related to that test is how to think like a manager for the cyst.

Um, which I think is really noteworthy to your point a minute ago about, it's a different sort of mindset to speak to business leaders with IT context than it's technical. Um, so there's that as like a potential training thing. Like if you don't get that side of your CISP training yet, if you're doing it double down on that hard potentially, uh, the other thought I had here is, especially business size makes a big difference for some of this too.

Like some of the smaller businesses in the small business scope, all these things that, that Brian, that you're talking about are sometimes leading the business to a place of maturity they're not at yet in some of the Considerations. Great Point. Um, and so that could be something.

And so, and then the other thing which then leads into a question, so I'm not gonna ask the question yet, but there are nuances in reporting between different customers, which I'm guessing you've probably seen too, where like, one business sees red, yellow, green, they're like, okay, cool, whatever the next business sees the red and goes, whoa, what is that? And like immediately wants action taken out to figure it out or wants to change the way the reporting is presented.

But any thoughts on those comments? Yeah, I think what you're talking about a little bit is into, um, kind of, you can't, you can't cookie cutter or over template your VCSO program, right? And, and you know, my approach, I I to VCSO delivery is, is really what you're talking about. Because clients are at different, and in different industries, they have different requirements, they're at different maturities levels, they're different sizes.

So my approach to vcso delivery is I, I think has always been intentionally flexible. That's the type of programs you want to be where you want to be, right? Because every client is in a, in a different place. And trying to force that one size fits all model, I think is the, gonna be the fastest way to, to kill trust. Um, I think net brought it up last week. It was a great point. And the job is to meet them where they are at, right? Not drag them into where you think they should be.

And I think that the vcso role is kind of part strategist, part translator, and part chameleon, which Eric, I think speaks to some of what you're, you're talking about and kind of that chameleon attitude. For example, like, like some of what you characterize a a startup in growth mode, VCSO might be in the weeds, right? Building the entire security program from scratch, negotiating, um, maybe with vendors, uh, setting up policies, helping 'em survive due diligence with their clients, right?

And for a more mature, like mid-market organization, the program, the VCSO program might focus on like a aligning different silos or multiple silos under, under a certain risk strategy or supporting more like board or executive leadership level type of governance. Same title, right? Um, but, uh, uh, very different roles. So, so Eric, really, I, I start by asking myself a couple questions, right?

And, and I, I know I beat this one to death, but talk to them about, about their revenue streams, their profitable revenue streams, how they make money, and what could stop them from making it right. That that tells us where to focus if we're gonna be a chameleon or have this accordion of, of opportunities or abilities, how do we want to flex? Where do we want to focus, whether it's compliance or resilience or prioritize different risk, and then build an engagement around those, those drivers.

So if the business needs like lightweight, high impact support, you stay lean. If they're preparing for some big compliance, uh, push or a sale or m and a, you go, you go deeper. So really wanna deliver, and I think you brought this up too, uh, Eric tailor the, the, my delivery language, right? Some clients are, are very technical, right? And they can understand what red means, that kind of thing. Others are allergic to it, right? So a good, I think a good VC so knows how to, how to flex.

And we're not, you know, we're not there to impress with our vocabulary. We're there to earn trust and get buy-in. And I think at the end of the day, customizing the delivery isn't just about, uh, like service tiers. It, it, it's, it's leadership awareness. And the more you listen, adapt and align, the more influence you'll, you'll earn.

And I think that's what helps kind of make the model valuable and what can potentially help the model scale Hair, just, just thought, not that this is revolutionary, but Brian, you know, somebody that has the trust level that you, you know, you're referring to, those are also the ones that are gonna allow MSPs to scale their automation and AI practices. Are they not?

Because I mean, the, you're gonna see, like you're talking about how they make money, how they view the com, the competition, their contractual obligations. You're gonna, you're gonna be able to, how they view, you know, you're gonna, like, you talk about data flow, right? If we're gonna talk about large language models, understanding that data, you know, again, aren't you gonna have that leg up if you're doing this? Well, Yeah. As, as a vcso, you're gonna be thought of as valuable, right?

You're in there, you're getting s**t done in the areas that matter most to the, to the business. And when you do that, you're, again, you're, you're greasing the wheels of sales. You're seeing it a different light than you are as some technical nerd or compliance geek, you know, at the end of the day.

And I, I think that, that asking those questions and aligning, and then when you communicate, you're, you know, you can't put risk in relevant terms to business impact unless you really have deep, you know, a deep dive with the client and understand those data, data flows, revenue streams and some of that. And then translate that into, you know, words that they, that, that resonate with them. I've said it before, if they call a gadget a widget, call it a widget every time.

If they call clients customers, call 'em customers every time. Those little things go a long way when you're talking to them about, about, um, the, the, the, you know, your judgment calls your leadership and the risk to pay attention to and the risk that can be ignored. That's important. Mm-hmm. Cool. So there's a lot of, uh, downward price pressure in the MSP space lots of times.

So kind of slightly combining a couple of these questions, but when we're thinking through scaling vcso services, what have you used as worked in the past and how do we standardize without losing customized strategic partner feel? What does that look like to be, here's a way that can be repeatable and yet is customizable so that it's an enabler rather than a hindrance to strategic partnership. Yeah. And a more unpopular opinion here real quick.

Um, 'cause it's kind of contradictory to what you see a lot in the, the v CSO platforms and some of the other, other areas, but one of the biggest mistakes I think if we, we focus there, um, when, when, when, when MSPs think of scaling and growing, okay, and again, this, I'm gonna catch heat for this, but I'll just say it. One of the biggest mistakes I see MSPs make when trying to scale VCSO services is thinking in terms of volume instead of margin.

MSPs are wired to think, how do I sell this vcso to every single client? Okay? That mindset doesn't work with vcso. I think early, there's been early evidence, right? It didn't work real well with VCIO and it's definitely not gonna work with vcso, and this is because it's not a help desk add-on, right? It's a leadership role. It's high touch, it's high trust, it's high stakes, and you can't scale it like, like antivirus.

So the truth is, not all your clients are ready for want or need vcso, and you gotta be okay with that. Don't try to sell vcso to your entire book of business, right? Start with your top five or 10 clients. I've said this for a few years now, if you focus there, that's probably 80% for most of our MSPs out there. My guess is most of you, your top five or 10 clients is driving probably 80% or more of your revenue.

That's the, that's the, that's the ones I would focus on with real revenue, at stake, regulatory exposure, uh, contractual obligations, strategic growth plans, that kind of thing. And that's where the real value is. And that's where leadership is gonna ma matter most. So my, my own opinion, vcso services scale best when they are high margin, low volume offering that means fewer clients, but deeper engagements, bigger impact, and a lot less churn.

The moment you try to water it down for mass adoption, you're gonna lose strategic value and your delivery quality tanks. Okay? So let's stop thinking in terms of how do I get more clients on vcso and start thinking, how do I deliver massive strategic value to a handful of the right clients who will pay for IT leadership, not, not just labor. And that's where the margin is and that's where the trust is. And that's how in, in my opinion, you actually scale the service, um, the right way. Yeah.

Brian, Annette said that was gold. I agree. It's really about understanding your ICP for this role. Correct? This is not, uh, ubiquitous across the board, like you say EDR for everybody, A hundred percent right? Is is your, your, the, the fact of the matter is you're gonna waste a lot of time in brain cells trying to get after your entire client base. We've talked about this before. There's kind of three buckets, right? You have this highly regulated, bigger type of client that is prime, right?

They've got some compliance contractual obligations, they're prime, they're gonna get what you're talking about and see the value in it. Then you have these other smaller clients that are never, ever see the value, right? It's this meaty middle that, that we really need to kind of focus how do we sell vcso services to that group and penetrate that big meaty middle that, um, that'll probably be more of where the gold is in the future for vcso, uh, programs.

A lot of everybody's fighting over that, that top part. But how do you get after that? That middle part I think will be the biggest bigger strategy. Just one quick question on that, Brian. And we talked about this is the meaty middle.

Are you looking for, again, that's why you under, you wanna know who their largest clients are, are there is upstream, are there any customers that they might have that have regulation that do, you know, big business with, you know, maybe the federal government, any, you know, thing that might flow downhill, right? That's, that's the next layer in that medium middle, right? Yeah. Compliance, like s**t rolls downhill.

And these flow down things you're talking about are, are even our s and B clients sell into larger enterprise and we're even seeing CMMC flow down that's causing, you know, these larger manufacturers that's, they're definitely in the meaty middle. They're like, oh yeah, I did sign DFARS several years ago and I am subject to False Claims Act and I will lose my DOD business and that kind of, or, or prime contract related business or did business if I don't do these things.

So that Andrew comes in contractual flow down obligations where they might not be in a, a regulated industry, but they've signed on the dotted line that they have a whole bunch of stuff in place, uh, that they don't. And that's where we can, a vcso can really be of value and is low high value stuff you can do for your client. Review those client contracts and remind them of the promises they've made to their customers and how what you do protects the revenue associated those contracts.

And briefly mentioned earlier, Brian, trying to avoid fud, uh, to the point of Jack's question in the chat just a second ago, CMMC space, how you, the requirements helping the customer get the risks and the reward. How much is enough and what's too much? Like how do we explain risks without it being fud? I think also ties into this question of how do we standardize and customize at the same time? Yeah, you wanna make it a objective, right?

And I, I think when you communicating, we will pick CMMC as the example is, you don't say, if you don't do this, you're gonna miss out on millions of dollars of contract and blah, blah, blah. Business owners need to make business decisions, right? Especially CMMC, you're talking about manufacturers, sometimes second, third generation owned manufacturers, they're very set in their ways.

So what you do is you start off with something a little bit, a little bit more bite-sized instead of going into saying, oh yeah, this could be millions of dollars and all this kind of stuff. Fear, uncertainty and doubt is you go in and say, Hey, I wanna help you make a business decision. I wanna help you not have to spend a dollar more than you have to on security and compliance. And with CMMC, the biggest thing I can help you with is a is is an input to a business decision you have to make.

What I can tell you is with like a scope assessment, gap assessment and roadmap engagement, smaller bite-sized engagement, I can tell you exactly how long it's gonna take, right? Can we do an enclave strategy? Can we shrink your environment? No, let's do a scope assessment. Gap assessment and roadmap. So strategically, you have a way to solve a problem. You're gonna know the different role takes a village to get across the, the finish line here of CMMC, right?

You have a, the auditor, you have the stuff, their time, they always want to know how much time they're going to have in it. You might have a readiness expert and then the C3 PAL costs, right? And you control all that. But that gives them an input to make a business decision. It's objective, it's relatable. Now they can say, okay, I get it. I have 25 million in government contracts, Brian, and you're saying it's gonna cost me 500,000 this year, 250,000 next year and 200,000 next year.

Now I can make a business decision, right? It's objective, it takes all the FUD out of it and it's a way that they can really grasp and understand ROI, if I put a dollar into this, do I get $5 out or $10 out? That's kind of the, the, the language of, of the business. And then also helps them kind of relate this scary compliance stuff back to I need to make a business decision. Awesome. Thanks. I'm gonna kick back over to Steve for a Matt. Alright, cool.

Uh, so Brian, since I'm gonna say most of the people on this call are MSPs, I got a couple of questions on how to interface like security vcso practices, like with the MSP, I think the first one I, I, I get is how, what do we need to do internal to our MSPs to maintain alignment with the MSSP or the VCSO practice?

What kinds of cadence calls or cross-functional meetings do you find useful to make sure the technical team and the security team are aligned both from a individual client perspective and an entire service delivery perspective? This right here is why I think MSPs have a advantage doing vcso services, uh, over maybe a peer consulting and advisory firm. Okay, the one big advantage. Um, but it's often I think, uh, overlooked.

It's that internal alignment that you, that you mentioned, Steve, A vcso does not succeed in a silo or as an island, right? They need support and insight, uh, uh, communication from across the entire MSP to be effective. And this is where a lot of MSPs are not getting this, right? So if your internal teams aren't talking, here's big problem. Your vcso are end up flying blind or spending time, and this is what's the big complaint around MSPs and running a vcso service.

The VCSO ends up being a technical account manager with a little bit of a security slant, right? They're flying blind and spending time fixing like internal misfires instead of advising the, the client. So that cross-functional communication, you know, alignment with the service desk or the knock or the sock, the vcso needs that visibility into the recurring issues. Uh, the noisier alerts, uh, patch failures because those things affect security, posture and credibility.

So I recommend like an every two week kind of biweekly sync with service leadership for the vcso to kind of stay grounded and what are the operational realities impacting my client. Second real quick is alignment, um, alignment with, uh, like account management or the client success teams or whatever you call 'em. These folks hear what the client isn't saying, maybe directly to the VCSO or VCIO if you're, if you have those.

So, so they catch the tone and the, the frustrations and, and those unspoken risk concerns. So monthly crosstalk between the, the VCSO and account management team, whatever you call that is key for the emotional and strategic type of intelligence. And third, uh, you know, alignment with the technical team or the VCIO function, right? The vcso might define the why and what, but it's often the VCIO or the solutions team that owns the how, right?

If those two roles aren't in sync, and I see this a lot when the two roles aren't in sync, you know, clients get mixed messages or see big delays in like the execution and that erodes trust quickly, right? So, so yes, meeting cadence matters, but not just to fill calendars. I see this a lot with, with people too. They'll just fill up the calendar with a bunch of things that, that make it appear productive and busy.

But it's about creating, I think, intentional kinda rhythms that let your vcso stays informed, right? Collaborates without as much friction and you lead with confidence. Um, and really you want those cross-functional insight really flowing to the vcso. So they're, they're not just the security voice, but you can use the vcso to really amplify the things that your MSP is already doing, doing well and doing right, reinforce the value of the MSP and MSSP services. That's fantastic. Thanks.

Um, Eric, I'm gonna turn it back to you 'cause I have to take off for a little bit of a plane ride, but everybody thank you all very much. Hey Steve, thanks for joining. See y'all later. Awesome. So Brian, in those meetings, um, and conversation flows, how have you approached any kind of resistance from key contacts at the customer side? How have you presented things like risk registers or data flow diagrams or things in a business context, maybe as a couple examples?

Yeah, a couple things on the, on the resistance. Um, when you, when you're a vcso or even a ciso go for that matter, my experience, you're rarely, you don't really have this ton of authority over the whole organization. People always think the almighty CISO comes down and people just bow to the bow the knee. And that's just not the case. You're still expected to lead. So the key is, is really learning, you know, trying to learn to lead with influence, not authority, right?

And influence comes from one thing. This is contrary to what popular, popular belief, right? But comes from one thing be valuable. So when I face resistance from internal IT foam folks, um, and, and even other consultants, I don't, I don't try to p posture or pull rank. I show up, I listen, I help, I get stuff done. And you build trust really by solving problems, not by swinging frameworks around.

I also remind my, my, myself and, and the team that managing risk is, and this is something people forget too. It's a negotiation. It's not my way or the highway, right? If it pushes back, don't, don't escalate, collaborate. You know, what would make this, you know, things like what would make this workable for you or what trade-offs are we dealing with here?

And a good vc, so I think knows how that every control recommendation needs to survive Certain things like, like reality, budgets, bandwidth, legacy, politics, which we've talked a little bit about. And sometimes the best thing you can do, Eric, is, is what I do sometimes is reframe the ask, right? Instead of saying we need MFA, you say we need to protect access to, um, to your billing system so you can keep cash flowing. Here's two options.

What's doable right, that language turns kind of resistance into more alignment and vc. So trust, I think, not by being the smartest person, uh, in the room, but by being the most useful, you know, show up as a partner, not a critic, and, and lead with empathy and back it with the, the clarity that we've talked about. And, and hopefully you can turn friction into forward motion.

The other thing I'm just gonna say real quick, I know we're short on time, is, um, uh, you mentioned risk register and data flow diagram. This is a big mistake. I see more technical vcso do they come in armed with this arm full of, uh, maybe it's virtually armed or whatever, but they've got all this stuff at their fingertips with, you know, risk assessments and vulnerability scans and cool dashboards and all that.

So my role is I never bring a risk register, a data flow diagram into a CEO's office without first translating it into business risk. They actually care about the CEO does not want see and doesn't have time for, and won't even understand 10 rows of CVEs. Or even like we talked about, color-coded data maps, right? Most they just don't have capacity for that. So what they want to know is what's at risk? How bad could it be? What's the plan and how much will it cost to fix it versus doing nothing.

You know, small companies, oftentimes your, your budget is competing with them. I ran into this a few years back. Sometimes your budget or your ask for resources competing with them, like buying a boat, you know, literally it's, they're looking at, I could spend money over here on what Brian's telling me about, or, gosh, I'm gonna buy that boat this year. Literally for smaller companies, sometimes that's what you're competing against.

So I try to frame the roadmap around, again, those critical business functions and revenue streams. I say, Hey, hey Joe, this system supports your receivables process. If it goes down, invoices stop. Right? Here's the risk, here's the impact, here's the cost to fix it. Here's the cost. If we don't right, that usually will land every time. And it, and I'm not, it's not security speak, it's, it's business language. And boil the roadmap into simple three buckets.

You know, take your big gigantic 800 page roadmap and boil it down to these three buckets. Must do now, should do soon and plan for later. You know, tie each one to risk that the CEO understands things like revenue interruption and regulatory exposure, reputational damage or, or contractual loss to name a a, a few then provide options. I don't just say patch it all, say, you know, here's two ways to solve this. One's faster and one's cheaper.

I mean, literally boil it down that, that, that easy. Here's one that's faster, here's one that's cheaper, both reduced risk. Let's choose one based on, on, on the business goals and objectives. So getting alignment, and that's how you can kind of present risk as a business decision with ROI, not just a, a technical problem. And from my experience, the CEO won't just listen. I, I think at that point they'll lean in and start to to resource. Excellent. Thanks.

Um, okay, so I'm gonna ask the final question as we're closing out and Andrew take over with whatever. But Brian, if MSPs are looking in the mirror and asking, am I ready to do vc? So services, what, what are the the worst they should be looking out for that say no, what are the positives they'd be looking out for that say yes? Yeah, I think, I think this one's, this one's tricky.

Um, because, because, uh, you know, again, there's, there's some of these top mistakes and, um, um, is there, you know, a formula to that? Is it risk-based decisions? Is it, um, you know, Eric, I guess how would you answer that question? Uh, well, I think I'd probably start with one thing that is just the fact that you signed up for pick, insert GRC tool here doesn't mean you are now a vc.

So, um, and looking at your internal resourcing and expertise, do I actually have someone who's ready to lead in this sort of way that we're talking about? Um, or do I just have a bunch of technical nerds who are great at tech and that's very valuable, but aren't ready to talk business level with leaders? Yeah, I just want to expand. I'm glad you brought that up because buying a tool does not make you a strategist, okay?

And if you sell this service without the capabilities to back it up, I think the downside is, is serious. You don't just lose the client, you lose trust and damage your brand. So I think as the market matures, remember the client, the, the, the buyer is going to mature too and they're gonna ask better questions. And I think you've got to have the, the right preparation and the right mentorship and, um, really lean into those leadership skills and you'll start to differentiate. Really well said.

Really great, great job, Brian, as always. And, and Eric, it's, I think, I hope you all out there found this and, uh, very helpful. Um, as I said, this was a kind of a part two to leaning in and looking at, you know, specific qualifications that we need in this role. Um, and I think, you know, I'm, like I said Brian and Eric, I'm bullish on this.

I think MSPs that are leaning in, learning this role, getting good at it, um, have a leg up in many different areas that, you know, we've talked about. As I said, I, Gary Pika has mentioned automation, ai, these areas you have a strategic advantage over. So, um, yeah, Brian as always, appreciate you coming back on and like I said, the door's always open. Same for you Eric. Really appreciate it and everybody out there appreciate your time. As always, I'll get this out on podcast.

Um, hope you share it with your friends and peers and be safe and we will look forward to seeing you next Monday. Take care. Cool. Yeah, thanks all. Thanks.

Related Videos