[Music] good morning and good afternoon everyone and thanks for joining us today for the first ever Frankly Speaking video podcast so thanks we really appreciate you attending today uh whether you are virtual whether you are live with us today or on some platform uh we definitely appreciate you showing up and checking us out and uh doing all that so today we're going to have a lot Of fun talking all things Frank which is cool and so my name is uh here with me I have Frank Randi Frank say hi good morning good afternoon good evening
or really good morning if you happen to be uh listening from Australia but yeah yeah Australia is a whole be a different day right yeah it's already Thursday morning at 5 in the morning there so right right well before we get started guys for those that are listening live or watching us live we do Have a questions tab on your screen there uh if you have questions through out this broadcast feel free to throw those in there say hi to us pretty much anything you want to do you can do in there um we will
be reading off some of those questions uh live here on the air and we will be answering those as we go through uh today we're going to be talking about really super fun stuff cyber security services um you know know for msps and how you kind of get started In that whole world and where it's going and all kinds of fun stuff um so before we get started with that um if you can hear me okay and everything is great you have a little hand raise button on your panel there uh just raise your hand
to show me that uh your hearing us okay and everything's working as it should be and I'm seeing hand raises there so awesome really great to uh to see everybody here today um so let's get started you know getting getting going here uh In cyber security services and before we get started with that I do want to just kind of introduce ourselves tell you a little bit background on so although we share you know the similar names similar hairlines similar beards we we do have a lot of it similar experience in the channel as well
but Frank why don't you start us off with just telling us a little bit about your background and uh what you've been doing in the Channel all these years okay yeah I'll I'll Start kind of where we're at today where I'm at so I'm um for IGI infinite Group Inc and also nodewar I manage our alliances and Partnerships and distribution and uh been been with the company a little over three years three and a half years or so and um so been there and then before that to done uh way back when uh was really
more of a hardware focused guy and so um worked at Apple computer long ago and then Intel and um um actually a couple different Stints at Intel as well as some time at synx so I've kind of got a ride range of of uh vendor experience and part really focused on partners and sort of Partnerships uh really and alliances and building that so that's that's really my interest here and and um we'll we'll yeah we'll talk a little bit more and bring up some anecdotes as we go very awesome yeah and my name is Frank
gurnie and I have been in the channel gosh 20 some years now and um Started my career in Telecom so with a a company called koved Communications um so doing high-speed internet back when it was it was uh really cool um and then uh helped start a company called chartech which was uh still exists today as a training Organization for msps I was selling managed Services back then um so I've been in those shoes been out there selling that specific uh product line so really understand that that key component uh went to work for company
Called vertical action helped build them or helped build that into a large uh web marketing company in the channel as well um couple stints here and there and now I'm with IGI cyber security services and nodewar so uh really excited to be here um talking cyber stuff so with all of that um yeah let's jump into this topic Frank you know yeah actually one one of the things I was sort of thinking of is this you know beginning of the year is sort of a time when everybody's Predicting and sort of you know wrapping up
summaries of the last year and looking forward and one of the things I've seen a lot of um and I kind of I'll I'll bring it right into our topic today is is the the the predictions I mean there's the obvious ones around Ai and what's that going to do both on for the good and for the bad um but I think we one of the things that where there there's a lot of consistency is around let's just call it compliance and cyber Insurance and and sort of the what Insurance generally drives you know again
whether you go back to seat bels in the cars or um you know dozens of things right that are now just standard parts of product but they were really driven by the insurance requirements that the you know the the the uh the guaranteed profit makers in insurance companies uh have have driven because they want to reduce the risk and and and that really is what we're you Know I think we want to talk about today is how reducing risk um and sort of as part of that is without having to really drive a ton of
new resources within your company and I think in our next in our next month's session we're going to get a little bit more specific about how to add resources and you know how to build them into your into your play without having to you know add staff um but I think sort of related to that today is you know what Kind of services will help you as an MSP help your customers be compliant sort of look ahead towards compliance or you know make sure they get their cyber Insurance renewed so um yeah that's kind of
where I'm you know that that's GNA be an interesting path right right I think it's super interesting because like you know compliance it can mean a lot of things to a lot of people and it's it's really been confusing I feel like in the MSP space especially right because we've Had a lot of um kind of MSP influencers who've gone this route of cmmc and compliance and and have good had good luck over time but you know I've gone out there and said this is how you need to do your business and that sort of
thing without kind of saying like you know there's steps to all of this and and what you have to do and how you get there and that sort of thing I think manage services in itself has been pretty straightforward it's pretty Straightforward the the services that are in a managed service environment you know you have your PSA tool you have rmm you have backup and Disaster Recovery AV you know some additional tools and and things that you sell beyond that but for the most part that's like the bread and butter of a managed service organization
right y y but when you get into uh cyber security services I mean it it's just overwhelming I mean if you think about it like you got EDR you got MDR xdr sock Sim cesa ceso vciso cissp cmmc st stop stock to risk management I mean all of this stuff and where do you start with all of that I mean I think that's the biggest question is like I think msps recognized that they have to evolve into this next thing which is adding cyber security services but with all of that stuff you know red team
blue team purple what the heck like it's just too much right how Do you know where to go and where to start like what's what should these guys be thinking about you know initially yeah well you know one one of the things I think kind of comes back in in again the the the the two second commercial here right what is what nodewar and IGI cyber services are really about is sort of looking proactively in in with services and we'll get to those in a bit but I think one of the the the first parts
of of that mix that and again very Overwhelming just based on the terms that you were here about and you know if you go to a trade show right 90% of the booth say oh we provide all the security you need it's like well okay that's BS but um you know what what are there there's so much there and you know some things are overlapping some things are yeah they do two-thirds of what I need and this does another two-thirds but there's that onethird overlap so why do I need both if I'm you know it's
it's It's dizzying but I think if if if you take a step back uh and look at what you need to be you know you're an MSP you you you may again maybe you're doing some basic AB maybe you've done some vulnerability management maybe you've done um you know a little bit bit of MDR kind of thing and and you have a partner that does has a sock that you use um but realistically I think the the the play that is really relevant for adding you know starting in that mix down the path Is looking
for things that help you be more proactive right helping you reduce the risk at the Forefront right if you because if you if you can do a thing like thirdparty Risk Management or if you can do a penetration test and just see where that customer is and it could be a a base B electronic one that you just kind of do some fancy connections into the network or you can do a true you know comprehensive penetration test and and on-site physical testing and Those you know it comes back to to understand what your customer needs
but but realistically sort of starting with a proactive approach how can I reduce the risk those tools you'll add as you define what needs to be done and you'll bring in bring them in as you need but I think you know overall that's really sort of starting to take a look at um okay if I add this what does that do does that does that reduce the risk does that eliminate risk does that you know Get rid of bad systems that you know are vulnerable whatever yeah I mean I I think so you're 100% right
and I think this is something that msps understand is this proactive versus reactive approach it goes all the way back to the beginning of manage services how to sell manage services and that we were selling on the idea of proactively providing services so that their systems don't blow up and that they are efficient and that they're Continuously uh everything is working but you know when we talk into to the cyber world I think where a lot of the confusion comes in is like why do I even need this or why is this even a thing
that I need to be either providing to my current customers or to broaden my Spectrum into new customers what I think is that first and foremost this is the next Evolution for the MSP you know if you look at the MSP in general you're talking about for the Most part you know 50 or less users in an environment that you're managing on an ongoing basis and that's your opportunity for the most part because if you go beyond 50 or higher and there's you know there's some cases out there where it's you're managing bigger clients than
that but they usually have an IT department so it's hard to kind of get past those guys where I think cyber really changes that is you know because of the compliance need because there's So many larger businesses that have requirements around compliance around cyber security securing their networks there's a big opportunity for msps to be a um almost an advocate or a secondary tier or or piece of these larger organizations you know your midsize organizations who really don't have all the answers for cyber security don't have the Manpower you know so I think that in
that sense providing these types of Services gives you additional opportunity to move up a tier into that next level out of just the small business and into that Medium business and on top of that I think that for existing clients what we're finding already is government requirements are coming down very quickly so we've already seen you know what I would say is almost the lowest tier of security Frameworks your FTC Safeguard is hitting a lot More of Industries right so they're they're broadening the the description of who's who's required for that yeah your accountants you
know and all what you're GNA see is this type of thing is going to get passed down to almost everybody at some point um so if you're proactive in what you're putting in place I think that's one of the reasons you should be looking and doing this like now right because you're ahead of the game you're not behind and trying to Catch up at that point does that make sense is that you agree with that absolutely yeah no I think I think so and I think maybe maybe what we need to do is sort of
I think as part of these Services again kind of a bit of a definitional element right I mean there are there are let's call them traditional Solutions MDR xdr our Sim right that we kind of talked about but I think those are those are programs that you can use but I think if we let's Let's lean into the services right which is kind of what what what can be added and what you can do without you know again the Shameless plug here is right what who who can you go to to add these Services um
when you don't want you know you don't have the capacity you don't have the time you know you don't want to have the time or the expertise on staff but how do you how can you add those into your mix and and be the provider and your trusted provider on so so Frank Maybe go through let's define pentest and you know the and all that so as we get into that you know I I think that it's it's really good to understand that this is not much different than when manage services came into play right
because when manage services was coming in and you had bars and you know resell and you had you had it Brak fix compan a lot of people didn't know how to start a managed service organization or what to do or what tools to use or even how To do any any of it and so there were a ton of um companies that were providing different pieces of manag if not all of them the remote monitoring management you know taking the call um passing on or creating a ticket that sort of thing and now we're seeing
the same thing and IGI that's who we work for does something similar to that for folks who want to get into cyber security services so things like you know and we'll talk about each one of these but penetration Testing sock Readiness uh sock 2 Readiness cmmc Readiness um you know vulnerability management compliance all of these can be done for you to get you started down that road and I you know I always say like and you saw it in manag services like people started there and then they moved in and hired their own text or
you know got someone who was certified in this or that and then started to move and do it on their own right over time but in all of this using A third party to help you start providing cyber Services is an amazing concept and idea because you can essentially use those guys to provide these services today they have all the expertise they're doing all the good stuff you can put it on your website so you're not missing out on opportunities you can have all of these services available to you but you don't have to have
the staff and everyone else today to to provide that um so yeah let's jump Into some of those services that you know we think that they should be starting with today and I think you mentioned a couple I think penetration test is a really good place to start yeah absolutely so do you want to Define you want me to yeah why don't you why don't you throw it out there for us I I'll I'll take the first one and I and I think that one of the things to to differentiate that we we have to
do a lot of educating on still is a Vulnerability assessment or management and penetration test so you know assessments and and management is the ongoing sort of the internal look at you know kind of Readiness if you will right what systems are there right doing a good inventory looking for for vulnerabilities and remediating them right that's a continuous active program you know a management program penetration test is you know it's it's it's an attempt at an exploitation right It is an outside third party and again this is really where an MSP should not be doing
it themselves right this is really a tool a you know a service that should be done from a third party because it's otherwise it's kind of the fox watching the hen housee of yeah my system was good but anyway so penetration test think about is is testing those systems putting them you know through using the same tools that the that the bad guys and the the Hackers use uh but with with the white hat on and sort of you know with with the company's um permission and knowledge that we're going to be trying to break
the break into their system and once you get in how do you navigate through and sort of that's what a penetration test will do and it's not only it's also not just a electronic or a you know a way to get around in the systems it's also thinking about penetration from uh a physical site Right you know You' see everybody's probably seen those little fancy boxes that can read the RFID signals and credit card numbers and all the rest of that um you know it's it's coming on site and seeing if the doors that a
company has are you know protected properly or if people are letting because I've got a UPS shirt on anybody can come in and deliver a package right the it's all the little things that that involve there so that penetration test Is really again just is a quick definition is is an outside effort to come in on site electronically or physically exploit an environment and then report out on that and that report out is kind of the the action list right it's it's your as an MSP uh you're going to get that report along with your
end user and you're going to make an action plan right and here's here's what we're going to attack and here's what we're going to keep keep you know working on To improve before the next one yeah I mean and and I think that that um you know when we talk about these different services like a penetration test is really a requirement in most security framework so it's something that these folks have to check the box on these these things right and I know there's been a lot of confusion in the space around what is a
pent test because you know there's people calling things pent tests which really aren't Right and there's a lot of this kind of misrepresentation of what what is actually being done you know is this a is this kind of a pre-sales thing or is it actually for compliance and that that's really the difference right so if somebody's calling something a pentest and it's really kind of to get you in the door for a pre-sales thing that's not a true compliance yeah that's more of an assessment than a than a than a true test right right so
you're you're Doing kind of some some testing and some things to check things out um but a pentest really is a requirement in many of these security Frameworks that you need to do and and one way that IGI kind of does this really well is they have you know a basic kind of pent test which is a good starting place at a really good price and then you can move into more custom or fullon you know attacks where you know you've got award-winning you know hacker types that are literally Trying to um you know take
down a network and so you know those are those are two very different levels but there's a place you can start there which you know is a aable and and stuff like that well I say one one of the things with that right is that it's not it's not a cookie cutter thing right it's really a customized discussion so it's it's a three-way conversation most likely between you the MSP between your and your customer and then a provider like IGI or or another provider of a penetration test right you really need to be clear on
what you know what you're scoping and and be be be clear on that because you it there's too many definitionally but also just physically and electronically what what is in that realm that needs to be tested so um you know don't just don't just hire up and say hey I need pentest okay here's here's D line you need to Have that discussion with the experts yeah I remember a couple of years ago when I was first kind of introduced to the whole pen penetration testing thing and some of you as well probably have had this
where you went out to get a quote on a pentest and that quote came back at like aund and something thousand I was like wow this is insane but you know now I think it's it's gotten it's it's a lot better that you know is a very specific thing for a very high Level you know customer who probably can afford it um now but you know for your average client who needs you know uh Security check marks you know to be taken care of it's not going to be anywhere near that for for you know
their their basic pen test any longer which is nice but that is a proactive piece so as we talk about these Services that's where we kind of go to the vulnerability management which is something every MSP can be doing today Because they have the knowled the breath of knowledge to be able to manage vulnerabilities within a network but vulnerability management really is an ongoing way to manage proactively people from getting into that Network right because if I'm looking at every day the different vulnerabilities that are coming up onto people's machines and that sort of thing
and I'm patching those and taking care of them then if something happens to get to the network Hopefully I then have that next punch which is like an endpoint protection to stop it from going any further but if I'm doing that before it never even gets there right so that's why vulnerability management is so important is because if I just put EDR out there then I'm everything's getting that Network and it's hopefully stopping it 99 hopefully 100% of the time but 99% maybe isn't good enough where if I'm doing vulnerability management and Endpoint protection well
I'm taking care of that first layer no matter what and I'm managing that and making sure folks can't get there if something does get past it my percentage that it's going to get stopped is much higher at that point would you agree with all of that Frank oh yeah no absolutely I mean yeah don't move on violent agreement so yeah I mean so from a Services standpoint vulnerability Management should be a standard and that's not even a standard just for you know for regular compliance type clients but but your regular manage service clients you really
should be doing that for them because it's G to give you a lot more insight into you know what's going on in that well even just the the basics of vulnerability management is identification of assets right you can't protect and and secure what you don't even know is there so um you know that That's what a good vulnerability tool will do is make sure you know what your assets are your devices including iot right this is not just systems and and and and and desktop device or scan this is looking at everything so um yeah
you have to have to keep that that's why this really is a nice one two punch between vulnerability management and Pen testing so yeah um so so that's that's a good definition on that so what's what's the next one you would want to cover What's the next yeah I mean I think um you know risk management I think is important in VC so Services because in those a lot of msps have been hearing about VC so VC so that's like the next thing you need to be or you need to be providing those types of
services um you know at the end of the day it all comes down to risk management you know all of these things kind of fall under a riskmanagement uh engagement right because if you're talking about Compliance for somebody you need to be doing all of these things in some combination and reporting that and showing that all of these things are being done on a regular basis um because as you know it's not if a breach is going to occur it's probably when a breach is going to occur and we need to make sure that we
have everything in place that if that breach occurs one we can show Auditors here's all the things we've been been doing over time to get Ourselves in the best position we can because if you don't do that they're going to come out after you with really heavy Hammer right but if you can show an auditor like look we've been doing things proactively to get ourselves in the best position possible here's all the things we've been doing we have a VC so in place we have you know all these different thing we have a risk assessment
we do on a regular basis all of these things then at that point they Go okay well you're doing everything you're supposed to be doing this occurred that's a bummer you know here's what you should be doing next in the future um they're a lot more lenient in in that way if if you can show them that you're doing best effort right right because nobody can do everything tomorrow nobody can do it all you can't you can't all of a sudden be compliant tomorrow uh and compliance is an ongoing thing it's something that is literally
Continuous um so yeah I mean I think that's kind of your next step and what you want to be doing is you want to be adding those vcso type services to your service stack to provide to those clients that have those compliance needs yeah what are your thought and that can and and that can be both internal right I mean if if you study and become strategic enough in your own business then uh nice you know you you could add that as a as a service or um you know if You need to Outsource it
then you can Outsource it right and and you know very fractional play so um if you need somebody for you know 10 hours a month you know you you you can interview and you can you can sign a contract for that so um there's some good flexibility in that because it's it's for you know especially for a smaller company it's not a full-time requirement right it's really again kind of that objective Outsiders view on what's being done Where they're you know where they're at where they want to get to and then and then what's the
path to do that um that's really the the cisos uh you know value ad in the mix so um you know think about think about those services and and again we'll we're going to provide a form at the end if you're interested to to learn a little bit more discuss them at the end uh or discuss some after the call uh then we'd love to you know talk you through these a little bit and Describe them some more so um yeah so v v so though can really set the path for what are those prioritized
services that you need to add right you might need everything under the Sun but there's ciso is going to say you know what here's the first two you know get those done get those underway then we'll add these two and again as you say you're not going to do it all at once both your customers aren't going to be able to handle it all at once you're not going To be able to handle all once is the MSP delivering that and so um yeah know we can we can go with just again get back to
your earlier point right you you you can't you can't get there if you don't know where you're going and every every Journey starts with the first step so get get get stepped up and get going on it well I think another service that comes up a lot in the MSP World um is Cmmc right um and cmmc is this ever changing amazingly complex thing um and you know there's not a lot of people out there that truly have a good understanding or grasp on it I think we were in a meeting the other day and
they said there's something like 300 of this very specific type of person out there in the world 300 that can do or understand this piece of CM that are now required that's a requir right there's 300 people that's it in the entire world Um so you know I was I was amazed to hear that um but at the same time this is something that has been coming up a lot in the MS P world and again I go back to there's been a number of influencers in the MSP space that have talked a lot about
cmmc well things are changing rapidly and so there's a ton of requirements around what the MSP if they're working with somebody who has this government these government contracts and things what they have to Do and what what kind of certifications they have to have are have in place um so I would say you know if you're starting to think this way or you have clients that maybe fall into this it's really something good to reach out to someone like IGI to say where do I even start with this what can I do how can you
help me because it's it's overwhelming the amount of knowledge you have to have to truly see yeah and and and again it kind of Comes back to this objectivity right you you you know seeing the forest through the trees or you know add your analogy of what they're um there there's just so going on and you're kneed deep in it right and you're knee deep in this part but you forgot about this part over here so that that you know fresh perspective fresh eyes uh is really kind of a critical critical element here to deliver
and and and deliver value to your customer right I mean if it's just You doing it all the time then they you know you you're you're likely going to be missing something and that's where an outside eyeballs can help yeah I mean what I like about this model of you know hiring a third party to provide certain cyber security services for you is just the fact that you can grow your business in this way and add people you know bring it on yourself at some point as you gain more knowledge as you get that cissp
Certification as you become certified vciso as you do those things that's fantastic and you can start taking on those layers yourself but there's no reason you shouldn't have the that you have the ability to do that on your website to today because if you don't and I I I heard a story just earlier I think you were talking to somebody the other day Frank and you asked them hey I see you do cmmc on your website and they couldn't tell you anything about it the Funny part about that is I said well it's still smart
that they have it there because they're not going to lose somebody who might have gone to their website and are looking for that service they might call them up and say hey we're looking for cmmc um help right now they can come to Someone Like Us and IGI or somebody and say how can you help me with this but they don't lose it so having the services listed on your website having a third party really Keeps you from losing an opportunity that you might not have so but yeah I thought that was yeah well and
and and and there's a fine line there right between promising things or saying things that you have no clue about versus things that you at least understand the basic and know where to go when you need the expertise that's really well I would at least want to have that third party in place that can help me right if if I'm gonna go are you Turn around quick you don't want to have to you know get an inquiry and then take a week to understand who to contact so exactly actually you know what I just just
as a quick break on the on the uh the chat I'll just mention for people listening that if you want to if you want to do some followup and and ask we'll we'll put this we'll we'll say it again but if you if you want to write this down node wear.com Frankly Speaking and on there you can inquire about Nodewar vulnerability management or any of these services that we're talking about so let's get on to the next one Frank and we can uh we don't need to keep everybody on for the hour here so what
what what's the next service you want to highlight that's about um I think um I think you know sock 2 is one that comes up a lot right so getting ready for a sock two that sort of thing um it can be very very overwhelming and that's a huge process as well and has a Lot of steps and a lot of requirements um who's who's typically who's typically needing that maybe you can help Define if an msp's got yeah some some customers really need it some customers don't who who's who's who's really looking for that
Mark yeah I think that's a good question I think most most clients who need it know right so they they're going to be the ones to tell you that hey I need a sock too um can you help me with that um I don't know that it's like you Can just um mark it to folks like uh find a list of people who need a Saku right I don't know that it's that simple I think it's it's the companies that have that requirement are G to know it and they're going to let you know that
um unless you know additional Industries or something that are very I I was just started thinking of you know is there verticals like healthcare or Finance or you know Banking and you know are there particular groups that of an MSP Thinking oh I've got customers that maybe need that and they could reach out to them and say hey do you you know have you do you know what sock 2 is do you are you requiring it or is it being required of you and then that way you know the MSP can say oh yeah well
by the way I can help you with that Visa these service providers yeah I think it's a good question to ask and I think most people who know they need it know um but it does cover a lot of Industries I know Even a lot of vendors like ourselves like sock to is a requirement for a ton of vendors um so I think it I think it's one of those things that that covers just a vast amount of folks out there which which does imply good opportunity right to Ms the MSP out there to potentially
help um those clients with you know having doing creating this suu doing all of that stuff so I think that's another of those services that You know want to be able to list on your website you want to have uh somebody who can help you facilitate that at the end of the day you're providing this service that um um you know you get help with but at the end of the day you're going to make money on and it could put you in a position where you can present other solutions to those clients yeah which
is well you're gonna have to get there so okay uh what's next how about third party Risk yeah yeah yeah so yeah third party risk risk is U you know I think that that falls into this idea of how many vendors people have connecting to them right so when you think about that and that 50 plus percent this you know has come up a number of times of um breaches come through some type of third- party connection so you can be as secure as you want but because X Y or Z company is connected to
me you know I get breached Through them that and that's that's a scary thought because a lot of folks are tied into different you know software Solutions or other companies so to be able to manage all the vendors very quickly easily and and show your clients look these these folks I don't know if uh I don't know if I'd be trusting them they're not getting back to us on questioners on assessments that sort of thing I think it's important right um all around but you have any thoughts on Vendor management as well Frank no I
just I think it's you know you got to look at it both from you know supplying into the into your customer as well as their customer base right so it's it's a it's kind of in and out from the customer what they need to be understanding what their risks are um and and and there so um yeah know it's it's it's a growing I mean it's a new it's one of the latest nist requirements that's been added is is you know having A third party risk management program so um again that's something that I think
people should should start looking into and you know again it may not be something you have to add right away but when when your customer is asking you about it you need to at least know what it is and how you might be able to provide it as a service um but it is it is something that a lot of people today your customers might be doing it just on spreadsheets and you know uh you know Grunt work if you will of you know an admin or two that's you know pulling all the information about
all your suppliers or all your customers and uh how protected they are and um that can be kind of quickly automated and and you know put into a service instead so um yeah so I threw I threw a couple a couple uh fun questions out here um a little bit earlier or actually I wanted to to bring up one of those um so your take on this Franken I'm gonna I'm gonna Say this is kind of a trick question so should msps be selling cyber security services what is what what do you think well they
need to be providing them they need to be offering them um I mean ultimately it all does come down to a selling motion right and and that but that selling motion is educating without fear right and without you know the the last thing you want to be doing is selling you know thud or fear and certainty and doubt um because that just Gets you into all kinds of um you know promises made and maybe not Promises Kept so yeah yeah so when I said this a trick question you know to me it's it's yes and
no and here's why yes you should be providing like you said cyber security services should you have a sales person who's going after those types of opportunities absolutely but at the same time what I'm really talking about here is the things right so when we talk about Selling cyber security service should I be selling someone EDR MDR Sim vulnerability management no I mean I this goes back to the way we sell managed Services guys you don't sell the things I don't sell you rmm I'm not selling you a specific thing I'm bringing things together to
provide you service and so when you talk about that you know these things do there are things that exist that are requirements that have all these pieces in play that That you bring together for someone but individually never just try to sell someone vulnerability management right never try to sell somebody um you know just an EDR you know thing it's not a thing to sell it's it's more of Peace of Mind as we've always done in manag the funny thing I just I always go back to is man this today to me is like 2008
in the manage service world it's so the same like it's the the same things you've learned over time on How to sell managed Services is the way you sell cyber security services it's not on the things that you're selling them you're not trying to sell them this specific you're trying to sell them that piece of mine that security that you know compliance requirement it's it's it's business support right you you you're you're selling them AIDS and tools that build their business right and keep their business thriving yeah and that however you want to in that
Services the stack of these services are the things that we bring together to provide that to you so uh so that was a fun one um I really like that do you think compliance services are difficult for msps to provide do I think what I'm sorry say that again you think compliance services are difficult for msps to provide I don't think so right I mean in a way there may it may be an educational opportunity right some Companies may just not know what their what their compliance requirements are or you know a medical office may
just think Hippa is just keeping you know files protected right when there's a bunch of other things in that so um you know compli as you said before compliance is a big complicated you know yeah not necessarily ugly but let's call it ugly scenario right of a lot of things that you have to be cognizant of and different different types of Verticals have different types of compliances so um well this is where this was another kind of trick question because honestly compliance Services yeah I mean if you're just GNA do it on your own and
just figure it all out yourself it's going to be a long hard road now if you can bring in as we've been talking about a third party and whether that's IGI or not to help you provide these services and have the expertise there to do that it's going to Be a much easier way to provide those types of services to your clients because you're not going to have to go down that long road of Education of certification of employees of all of that stuff right and so that's where that was a little bit of a
tri question but I think you hit the nail on the head I mean really is one of those things um we talked about what the common kind of Service Act looks like for most folks what those one two punches are I think Those are really you know something to keep in mind as you're building this out everybody every vendor out there is going to be telling you you need this what you need to look at it from is that proactive and reactive so it should start with proactive move into reactive services and how do those
kind of fit together and fit as a stack for of services that you can provide so think from that perspective just like you do your manage services you're not you know You're going to you have that rmm there for your proactive stuff and then you're putting in the other things for the reactive right the same same kind of H scenario falls into play there um yeah where do you think most people are going in 2025 is this you know is this still going to be a hard year of Ed educating and getting people to understand
that this is a road they need to go down or do you think people are starting to get it and know I think I think people are Starting to get it and and probably get more scared just given you know as the AI elements right kick in both for bad and good um you know you know you know look at look at your your phone and how many text M messages you got over the last month that said your package hasn't been delivered please you know contact us and you know it just so the the
the the the in-your-face evidence is there um but I think you know again going back to being an MSP that's adding value to Their customers that you're you're you're educating without scaring right you're providing Solutions without you know uh running up your bill to them too crazily right because that's there's going to be that risk balance right of of the cost benefit or the cost risk analysis that your customers are really kind of um concerned about out and um you know you need to be an adviser right and and this kind of goes you know
roll it back into the ceso element right There are there are pieces where you're going to need to understand the situation understand the tools they have what they don't have and you know what what should be added and could be added um you know there's a lot of good risk assessment tools out there that you can start with right is you know some some automated and some some need a little bit more input but um you know you got you got to be helping somewhere and and otherwise they're going to go find Somebody that does
that can help them yeah and guys there's there's no all-in-one tool although you know that's what everybody's kind of searching for is this this tool that does all things the problem with that Concept in this world of cyber security is that if someone's doing a ton of things in a single tool they're probably doing a ton of things okay if not yeah mediocre right uh for each one of these specific things um when you see a stack Of tools that you're bringing together you really want folks that are really doing what they know best in
in cyber security and so that that means bringing on multiple tools to help you you know your GRC solution for figuring out you know where you're at in a compliance you know um state for any specific type of uh framework or requirement um you know vulnerability management doing that and doing that really well um endpoint protection having something that does That you know as you try to start to bring all these things into one platform you really start to lose um the ability for each of those um to do each piece really well so you
know just keep that in mind as you're going out there and looking and building out your stack of services and then figure out what do I really need to do like which parts do I need to be managing and what parts should I maybe be trusting to someone who has more expertise in that and and Figure that out right because that's another area that you can really um you know not get caught up in every single shiny new um vendor toy out there but um yeah with that I know we have some questions that came
in Frank so we can definitely hit some of those we had a question that came in before um before the uh the video podcast here and the the question was what is the best way to show small business owners or decision makers that they need cyber Security when they don't think that they do and uh yeah I'll let you start with that and I'll give you my take on it as well um well I I I think it's sort of a reality reality world and and um uh you know just you know kind of back
to the the texting examples right you're you're seeing attacks in every different angle and just because you're small doesn't mean uh that you're not you don't have value right I mean you have customers you have Customer data you have uh sales data you have you know all kinds of different things that you know the the way these tools work is that you know a you know they're they're corporations effectively that are trying to do ransomware trying to do break-ins and and breaches um you know they can they can reach out to a thousand they hit
you know one out one out of a thousand in a day that's a success right they've got somebody in so um the you are not too small to be to be To be uh to be you might not be a direct attack effort right they might not be going after you directly oh I'm going to look for Joe's Hardware store right but they're going to look for all you know a thousand different small businesses that um that that may have an open port or may have a an ACC level in and they don't care they
don't know if it's Joe or Jim's or Bob's or whatever right they it's it's it's it's an IP address they're attacking they're not attacking They're not attacking the business name so you know you gotta kind of start with that level of Outreach well I think from I think from a sales perspective you really need to come up with your kind of list of questions to ask that customer and I think it starts with something like have you heard heard about X breach that has occurred you know the Google breach or this breach right we're hearing
about these all the time right you you've heard about these haven't you I've heard about you know every day it seems like in the news there's some new big company that has been breached now I understand that you're not Google but do you think it would be easier to breach you or Google right yeah and you know yes they're attacking Google because there's the potential for you know a large payday but what if you were breached tomorrow and all of your client information was locked down would that Affect your business right so asking a question
like that can get someone to say Well yeah if I couldn't if I couldn't access my computers tomorrow I would be down I would not be able to do any work right and so getting them to answer those questions in a way that you want them to answer them like that and coming up with that question set I think is going to take you down the road of them understanding why they need it um and why these are these are things that You need to do at the end of the day it still comes back
to not selling cyber security things right it's more about what we do is we protect you you hear about all these cyber threats out there you see it in the news every day what's great is we're helping to protect you from that and we've put a number of things in place to help you do that yeah it's focusing on the business outcome and and the the the maintenance or the ability to maintain that business Outcome uh over time right right right again what's great is we're able to help protect you from that is it 100%
no but it sure is a high percent and we're g to do everything we can to make sure that that doesn't happen to you and if it does we're gonna have pieces in place to make sure we get you back up and get you taken care of right away right so those are the things you want to do to help them in that in that sense good good good good good Point there um the other question I think we can we can bring up is about insurance and sort of um you know the the spending
more to to get insurance as well as spending more potentially to save on your insurance um so you know H how do you sell that and um the the the quick answer is um is is understanding again what their where their insurance play is today if they have it um and one of the we've got a a partner uh on the nodor side that is looking at or that Has a program for an MSP that if they're doing this set prescription of services um their premium will be X percent less and I don't want to
quote it exactly but um uh because I don't know the exact number but uh there is a way that you could say hey if you do these things that are going to cost you let's say $1,000 a month your premium insurance which you were we paying $1,000 a month is now going to be $300 or $500 or some lower number and you can say Hey by Spending here you're reducing there and you have to have that so why not spend here so it's a bit of more of a discussion but happy to um reach out
or you know talk further on that to the to the person in the that answer the question or anybody else reach out via that link node wear.com Frankly Speaking and um we can put you in touch with those folks but yeah I mean I think cyber in itself cyber insurance is a fantastic way to potentially open the Door to providing your services to someone because most companies need it right most companies are either paying astronomically or getting denied or don't know if they'll get paid out all of those things so if you can come in
with your stack of services or you can say hey this is what we used to use back in the MSP days saying hey let me see your Telecom bills right because I bet you I can bring in a master agent who can save you $800 a month on your Telecom bills and we can just use that to add our manage services in and you've lost no money at all you could do the same thing with cyber insurance today where you can come in and say we have a stack of of of we have a stack
of services that are approved by this company who can save you x% on your premium and guarantee that you'll get paid out if something happen happens and we'll pay for those Services just there in the savings that you're going to have It's a really great sales tactic to use to go in and say here's what we can do to pay for our services for you right um so I love that idea I love the concept of that because it just goes back to how we sold managed services for so long as well we could provide
a certain savings that paid for what we were doing which is really great yeah yeah cool okay um I think that's that's good I think let's let's wrap it up unless we got any else I think we're good on the Questions um again just node where.com Frankly Speaking if you'd like to follow up um please please reach out and you can uh give us little information on what you're looking for and we'll have a discussion um Frank you want to bring up the next month's H topic yeah we'll we'll definitely be frank with you we'll
be frank with you yeah let's see I know we had um some ideas did we have one kind of yeah think it's it's how to add how to be more supportive without adding Resources and and adding staff so we're going to talk about kind of in the similar vein of adding security services without adding staff this will be more you know how do you build up your support team um and U you know we'll have some we'll have a couple we'll have we'll have a guest on that one that'll talk a little bit more about
U options and models of adding support staff so look forward to having you on come back so appreciate everybody's Attendance today um yeah for sure man it's great great to have everybody here and we really appreciate you sticking around for us or well we did almost an hour here if yeah not coming upon an hour so super fun and uh yeah just reach out to us nowh where.com Frankly Speaking otherwise we'll see you on the next one thanks guys take care have a great day everybody [Music]