The MSP Zone: Recent Episodes

mspalliance

Weekly discussion of news, events, and topics of interest to the global managed services professional community. Series will have the latest and most relevant discussions in managed services and cloud computing, featuring special guests and notable figures in the profession.

View Details

Chris Massey's journey in the IT field is a testament to the dynamic nature of the managed services industry. Starting as an internal IT professional, Chris has traversed various roles, gaining invaluable experience along the way. His tenure at Bocada, DRS, and Involta equipped him with a deep understanding of the industry's intricacies. At N-able, Chris has taken on the mantle of a mentor, guiding MSPs globally. His insights are shared on the N-able podcast, 'Now That's IT,' where he delves into the evolution of managed services. The conversation with Chris Massey reveals the profound transformation within the managed services sector. From its early days of simply providing tools, the industry has matured into a comprehensive support system for partners, encompassing a multitude of their MSP practice facets. This evolution reflects the increasing complexity and sophistication of IT environments and the growing recognition of the strategic value MSPs bring to businesses. As the industry continues to evolve, figures like Chris Massey will be at the forefront, shaping the future of managed services and ensuring that MSPs remain integral to the IT ecosystem. The trajectory of managed services is poised to expand further, driven by innovation and the relentless pursuit of excellence, much like the career of Chris Massey himself.

View Details

John Street's contributions to the managed services professional community have been significant and long-lasting. His entrepreneurial journey began with the founding of MX Logic in 2002, a company that quickly became a household name among Managed Service Providers (MSPs) for its robust email security solutions. The acquisition of MX Logic by McAfee in 2009 stands as a testament to the company's success and the value it provided in the realm of cybersecurity. Continuing his visionary approach, Mr. Street established Pax8 in 2012, aiming to revolutionize the way cloud-based products are sold and managed. Pax8's innovative platform has since been instrumental in streamlining the procurement and management of cloud services, further cementing Mr. Street's reputation as a pioneer in the industry. His foresight and dedication to improving the MSP ecosystem have undoubtedly left an indelible mark on the field.

View Details

If you are an MSP, chances are you protect, monitor, and manage client data all the time. But the rules around data have changed significantly. Previously used tools, tactics, and rules are no longer applicable as data theft crimes and risk increase. Guy Bavly, CEO of Actifile (actifile.com), enters the MSP Zone to discuss these issues.

View Details

Transitioning from a traditional IT model to a managed service provider (MSP) model is a significant change that involves a strategic overhaul of business operations. The process typically includes adopting a proactive approach to IT services, which contrasts with the reactive nature of many legacy IT models. The journey from a reactive IT company to a successful MSP practice, as exemplified by David Besse and the 415 Group, involves several key steps. Initially, it requires a clear understanding of the managed services model, which focuses on proactive monitoring and maintenance, cost efficiency, enhanced security, and scalability and flexibility. A comprehensive transition plan is crucial, which should outline the objectives, assess migration targets, establish success criteria, and prioritize objectives. Overcoming potential challenges such as resistance to change and migration obstacles is also part of the process.David Besse has led the 415 Group through this transition. Under his guidance, the company has focused on offering clients the necessary services and tools for success, emphasizing the importance of a strategic partnership with an MSP that aligns with the business's goals and needs.In summary, transitioning to an MSP requires a well-thought-out plan, a willingness to embrace change, and a proactive approach to IT management. By following these steps and learning from the experiences of those like David Besse and the 415 Group, companies can navigate the complexities of this transition and emerge as successful MSP practices.

View Details

State and local governments are under attack like never before. Drive by cyber-attacks are crippling already overwhelmed governments and creating unnecessary financial and political pressure on these organizations.

The source of these attacks and the methods being used is not in dispute. What is not being discussed, is the solution. So, I am going to present a very simple, immediately available solution to any governmental employee out there listening to this podcast: managed service providers!

Now, I know what you're going to say. I thought MSPs added risk to our cybersecurity. That is simply not true. It has never been true. In fact, it is a falsehood propagated by inept cybersecurity insurance companies who can't figure out how to quantify their own cyber risk, so they blame the only visible party in the equation, the MSP.

Now, you may be also saying, well why would I use an MSP when they are being sued by their clients for failing to prevent cyberattacks? Well, again, that's a falsehood beingpropagated by uneducated people in the media and elsewhere, who just don't know what they are talking about.

MSPs do not practice reactive or break/fix services. The oxymoronic phrase "reactive IT management" does not make sense because you cannot manage IT in a reactivemode. Only proactive services (i.e., managed services can truly "manage IT." Recent headlines claiming MSPs being sued by their clients are really reactive or break/fix IT companies…not MSPs!

Finally, MSPs are the only organization capable of addressing the systemic issue here; the lack of consistently applied policies, procedures, and controls, designed toradically reduce (not eliminate) the chance of a cyberattack being successful.

View Details

I commonly get questions related to MSP documentation. When is a good time to start? I only need documentation for when I get certified, right? I'm going to get to that, only later on when I'm established.

The truth is, MSP documentation should start early in your practice; ideally, during the planning stages before you've started to deliver services. Here are some helpful tips so you can better understand why MSP documentation is so important, what is involved, and when you should start.

Why is MSP documentation so important?

MSP Documentation

  • Policies - HR, legal,
  • Procedures/process
  • Controls

When should you start documenting?

View Details

FUD: what does it mean? Should you use it in your MSP practice? And, is there a risk to using FUD style tactics? Fear uncertainty and doubt, otherwise known as FUD, may have been created by IBM sales professionals in the 1970s, but it certainly is still being used today by many sales and marketing professionals beyond IBM.

View Details

Niraj Tolia, CEO of Alcion, enters the MSP Zone.

The deployment of AI in MSP backup tools addresses several critical challenges in the managed services industry. By integrating AI, MSPs can automate routine and repetitive tasks, such as system monitoring, patch management, and backups, which significantly reduces human error, enhances efficiency, and optimizes resource allocation. This automation leads to cost savings and improved service delivery, which is essential in a competitive market where talent is scarce and operational efficiency is paramount.

The adoption of AI was driven both by MSPs' desire to stay ahead of technological advancements and by internal motivations to improve service quality and reliability. AI has made a substantial positive impact on MSPs and their service delivery by enabling proactive issue resolution.

Niraj discusses his thoughts around AI in data backup, what MSPs need in a modern-day backup solution, why he decided to enter the legacy MSP backup marketplace, and how AI will empower MSPs to succeed.

View Details

In the evolving landscape of IT services, the distinction between Managed Service Providers (MSPs) and other IT service models, like break/fix or security consultancy, has become increasingly important.

MSPs offer a comprehensive suite of services that manage and assume the responsibility of a defined set of day-to-day management services for their clients, proactively and under a subscription model. This is in contrast to break/fix services that operate reactively, or security consultants who may focus solely on specific aspects like penetration testing.

The confusion arises when companies misrepresent their services as managed services, which can lead to a misunderstanding of the value and scope of what an MSP truly offers. It's crucial for businesses to recognize the signs of a genuine MSP, such as a proactive approach to IT management, a broad range of services beyond just security, and a partnership mentality rather than an adversarial one.

Understanding these differences can help businesses make informed decisions when choosing an IT service provider that aligns with their needs.

View Details

I had the opportunity to play golf with an executive who shared some very insightful perspectives about risk, cyber insurance, and MSPs. The interaction was completely by accident but the information I got was invaluable.

View Details

There is a lot of wiggle room when it comes to knowledge and implementation of compliance in a managed services environment. More precisely, MSPs must understand and operate with accurate knowledge of the difference between preparing for an audit or certification and the testing or auditing of an environment. Both components are important, but the MSP is more suited to one and not the other.

Here's what MSPs need to know.

  • Audit and certifications in a compliance setting
  • Preparation for and audit or certification
  • Consulting vs testing
  • Role of the MSP in audits and certifications
  • Preparation and consulting are the domain of the MSP
  • MSPs actively manage infrastructure, networks, and objects being tested, therefore, the MSP should not be the one testing

View Details

For a lot of MSPs, trying to convert reactive (i.e., break/fix) clients into proactive (managed services) clients can be a struggle. No matter how hard you try, those reactive clients just won't budge.

Fortunately, there is a pretty effective technique you can use to begin to impress upon your reactive clientele all the benefits and reasons they would be better off as a managed services client.

Step 1: Communication. You have to have a conversation with your reactive clients about everything. Times are changing. Everyone is taking cybersecurity more seriously these days. Explain how reactive IT management isn't IT management at all; it's IT disaster cleanup. And, it can get pretty ugly. The point is, talk to your clients and let them know what's about to happen.

Step 2: Put your reactive clientele through some sort of security baseline. Don't get fancy. You can use something like the CIS framework. CIS does not have a certification so you just will be assessing the client's existing controls, policies, and procedures against the CIS controls. By the way, this technique can also be used quite effectively for all new managed services prospects.
Step 3: Deliver the results of the assessment and make your adjustments. What does this mean? If the client is doing everything they should be, there is no reason for them not to become a managed services client. Their billings should stabilize, their level of trust in their IT investments should be solid, and both client and MSP can sleep better at night.

For clients below the CIS level, you can let them know where the gaps are, that you can fix those gaps, but that a managed services relationship is what is needed.

Finally, if the reactive client still won't budge, you can raise your rates due to the provable increase in risk they represent to your MSP practice.

This technique is a combination of compliance baseline plus risk-based pricing, and it can be a very powerful and persuasive tool in getting reactive clients to understand the modern cyber world in which we live.

View Details

Ep 276 - The term EBITDA is not something a lot of MSPs fullly understand or use regularly. As a financial tool, it is worth knowing how it is used and why. But, should you use EBITDA as a metric for managing your MSP practice? Maybe, maybe not.

To answer this question, we must define EBITDA, look at how it is used within general accounting, and more specifically how it is used within MSP M&A and investing. Only then can you know whether EBITDA is something you should use regularly as a guidepost for running your MSP practice.

View Details

Recently, at the MSPAlliance Inspire meeting, I witnessed something I've never seen before, something I'm now calling the "great MSP reset." This reset is an accumulation of several different things happening at roughly the same time and I think it bodes well for the future of the managed services profession.
Here's what I witnessed.

  1. MSPs are going through significant equity changes
  2. MSPs are making tool changes
  3. MSP process overhauls

These activities, taken in their totality, represent a very clear sign that there is a lot of positive change taking place in the managed services profession.

View Details

A lot of MSPs spend the majority of their time focused on revenue growth, and for good reason. If you're not growing, you're shrinking.But, not all revenue is the same. In fact, some revenue types may actually be harming your managed services growth. Confused? Don't be. There are some really simple metrics you can use to begin aligning your MSP practice towards a pro-growth future. Revenue Mixture: What is it?

  • Proactive IT offerings (i.e., your managed services deliverables)
  • Professional services (non-recurring services such as consulting)
  • Hardware & Software

Revenue Mixture and Why It's Important

  • Revenue mixture can tell you a lot about who you really areOne of the most important MSP KPIs you can track
  • Revenue mixture can help your MSP practice Promote proactive IT products
  • Properly prioritize your reactive revenue streams
  • Add discipline to your practice regarding new clientsImprove valuation

View Details

Recently, one of our members reached out with some questions about how to achieve growth while simultaneously addressing a sizeable break/fix client base. It's a really good question and one that I know a lot of MSPs face.

First, acknowledge that break/fix customers inhibit managed services growth

Second, have a plan to migrate those break/fix customers to managed services plans

Third, execute your plan and have a timeline. Don't make it an "open-ended" strategy.

View Details

It's that time of year again. Time to review the past year and look to the future and predict what is likely to happen. The MSP world is changing more rapidly than ever before. Let's take a look at what 2024 has in store for the MSP profession. Ransomware Responses Changing: MSPs (and customers) have to look at ransomware in a very different way in 2024. As numerous governments worldwide continue to march towards inevitable prohibition of ransomware payments, MSPs need to adapt to this evolving threat response and develop new service delivery models to help their clients prepare for breaches and attacks. Break/Fix is still dead. If you are clinging to reactive IT service delivery models, be aware that the break/fix business model is still dead. If you have reactive clients, either a) convert them to managed services, or b) terminate your relationship with them. It may sound harsh, but times change and we all have to keep up with change! AI or no AI, that is the question: No matter what your opinion of AI happens to be, you have to have one (an opinion, that is). Some MSPs are pursuing AI technology to be a force multiplier of their existing team, while other MSPs are having to confirm to customers that AI will not be part of their managed services experience. Create your MSP Baseline: All MSPs should be entering 2024 with the objective of creating an MSP baseline. What is an MSP baseline? The minimum requirements you have for any managed services customer. This baseline will be different for each MSP. But you should have one because we are now at a point in our profession where all organizations ought to be practicing some minimal level of security standards. Review/Adjust MSP Pricing: Once you have created your MSP baseline, then the fun begins. It's now time to establish or adjust your risk based pricing models. It does not matter what type of pricing model you use, you can always apply a risk based pricing element to that model. Implementing a risk based pricing model with the aid of managed services baseline becomes incredibly easy; or at least much easier than trying to apply some regional minimum wage labor rate model. What's your compliance situation? Compliance is one of those topics (like AI) where you have to have a position. As so many customers are turning to their MSPs for help with compliance related matters, MSPs cannot claim ignorance on the subject of compliance. Whether you have a formally developed CaaS/vCISO/vCIO program, or you are just casually helping clients fill out cyber insurance forms, MSPs have an undeniable role to play in modern compliance and should act as such. XDR Upgrade: For those of you still using (or selling) legacy anti-virus and firewall technologies, it's time to upgrade your tool belt. For MSPs, it is considered a current best practice to have some form of XDR technology deployed internally in your MSP practice. For customers, XDR would also be considered a modern day best practice for any sized organization. If your NOC/helpdesk team is stretched thin, consider a managed XDR/EDR solution (they'll thank you for it). Get Cyber Verified: It's 2024. If you haven't started the process of getting your Cyber Verify certification, you should start your planning. Not only will it open up new opportunities for your MSP practice, it's also a great way to simultaneously achieve compliance with many globally recognized certifications and audits!

View Details

MSPs vs Vendor Controlled Remote AccessThe FBI advisory to private sector industries was released and raises some interesting questions regarding MSPs. While not specifically mentioning MSPs by name, the advisory covers general threats from ransomware and how they are being executed.

Doesn't mention MSPs, but they are clearly being addressed in this notice

3rd parties and legitimate system toolsAll the guidance the FBI provides is already well established in the MSP Verify program Unmanaged vs Managed ITUnmanaged Devices - still think break/fix is an effective IT management model?

“80 to 90 % of all compromises originate from unmanaged devices...Most human-operated ransomware attacks attempt to compromise or gain access to unmanaged or bring-your own devices (personal devices used to access work-related systems and information). These typically have fewer security controls and defenses" - Microsoft If you read this Microsoft quote and still think reactive IT is a viable business model or IT management model, think again.

  • Break/fix or reactive IT is not managed IT, it's IT crime scene clean up
  • If you are like many MSPs have a mixture of managed services and reactive IT clients, have a plan to deal with this situation
  • If rising cyber premiums, guidance from the FBI and countless other government agencies, and overall awareness about cyber threats are not enough to convince your break/fix clients, guess what, they're using you to offload their risk. My M&A Challenge to MSPs in 2024I would like to encourage those MSPs out there attempting M&A strategies to consider this challenge for 2024. You may be surprised by what I have to say, but if you think about it I hope you will see the logic and value behind it.
  • What is your M&A strategy and how does it fit into your overall strategy?
  • M&A isn't a corporate growth strategy
  • M&A challenge for 2024
  • Geography Service expansionMarket/customer expansionRevenue doubling

View Details

The end of Ransomware?You may have seen some news lately about the US government working with other governments to ban ransomware payments. Well, I'm not so sure it will stop ransomware but it is an interesting topic and something we should discuss.

Banning ransomware; what impact would it have? Government bans on ransomware payments will change how MSPs "manage" those clientsPrivate sector should pay attention Can MSPs be more proactive?I read an article who's headline talked about MSPs being more "proactive" with their customers. It occurred to me that this type of guidance is not aimed at MSPs, but instead at break/fix companies. Which begs the question, why include MSP in the title at all? And there lies the problem. These articles cannot distinguish between MSP and non-MSP.

Reactive IT providers…there are expectations you must meet when joining the ranks of the professional MSP

Being more proactive means being an MSP; that's the point! You can't be a little proactive; it's either all in or nothing at all You can't "resell" compliance vCIO or CaaS offerings depend on your familiarity in speaking the MSP compliance language. We are talking to a lot of MSPs today who look at compliance in a way that is very short sighted and not what will make a competitive difference in the MSP organization over the long run. What does it mean to "speak MSP compliance?"Understand compliance frameworks which matter to your customersUnderstand the role your MSP organization plays in customer compliance

Reselling a GRC tool does not make you a compliance expert

View Details

There is no recession in managed servicesYou may be watching the economic news out there and thinking to yourself, how will this impact my managed services business. It’s a good question to ask. Economic indicators seem to be pointing to some form of recession or slowdown (some call it a soft landing) in the near future. For all we know we might already be in a recession. But, does a recession mean MSPs are going to be hit as well? Not if the past is any indicator.Historical recessions impact on MSPsGartner IT spending projections looking really goodHow to prepare for economic downturnsManaged services (including security) should be a significant shelter from any stormvCISO, vCIO, CaaS offerings will strengthen any managed services practice Should MSPs be concerned about job loss to AI?Ever since ChatGPT launched many articles have been written about AI causing massive job loss in the future. While I would agree there are industries in dire need of innovation which typically cause large scale job shifts, managed services is not one of them.Job openings in managed services profession still unfilledAI is not going to solve anything close to all the labor shortages facing MSPsAI still needs to be managed (managed AI?)AI should be evaluated as an extension of your MSP workforce, not a replacement of it Advice for 1 person MSPsThere is nothing more exciting (or scary) than being a one person business owner. Managed services, like many other professions, has its share of one person MSP shops. I recently talked to one such MSP who wanted advice on how to grow beyond just himself.PartnersEmployeesCapital Organic (can be tough and take a while to see results)

View Details

In this riveting podcast episode, join us as we delve deep into the intricate landscape of recent high-profile cyber-attacks that have sent shockwaves through the digital realm. Our seasoned guests, Shannon Wilkinson, the CEO of Tego Cyber, and Brent Watkins, the Director of Business Development at Tego Cyber, step into the MSP Zone to unravel the layers of these incidents, providing invaluable analysis and guidance that every Managed Service Provider (MSP) should heed. Our exploration begins with a meticulous examination of three notable targets—MGM, Caesars, and Okta—each falling victim to distinct cyber onslaughts. We not only examine the sophisticated methods employed by the attackers but also dissect the responses undertaken by the affected organizations. As organizations increasingly rely on dynamic and interconnected systems, change management processes become a potential vulnerability ripe for exploitation. Our guests shed light on how attackers leverage change management loopholes, emphasizing the critical need for MSPs to redefine their strategies and bolster defenses in this evolving threat landscape. Tune in for a captivating journey through the intricacies of cyber warfare. Whether you are an MSP looking to sharpen your defense strategies or a cybersecurity enthusiast keen on staying ahead of the curve, this episode promises to be a compelling source of insights and actionable takeaways.

View Details

How are MSPs dealing with CMMC? John Burgess, from Mainstream Technologies drops into the MSP Zone to discuss how MSPs should deal with the changes coming from CMMC, but how they can stay ahead of them as well.

Regardless of where you stand on the issue, having something to say about compliance is a wise thing these days. MSPs with exposure to CMMC have a lot of revenue and trust potential, if they act. If MSPs stay silent on the issue when asked, that could lead to an erosion of trust and lost opportunities.

MSP Zone Highlights:

  • What is happening right now in the CMMC/DIB community
  • What opportunities are there for MSPs and CMMC?
  • What can MSPs do during cybersecurity awareness month?

View Details

Poor MSP Growth May Not be Due to Lack of SalesMany times, I hear MSPs complain about their stagnant or lack of growth. Now, regardless of whether you have a sales team and process or if you predominantly rely on referrals, lack of growth can frequently be caused by two general issues: inefficient process, and lack of customer focus.Limited service catalogDefined customersWith these two elements, you can develop an effective sales and/or referral programFrankenstein ComplianceIf your MSP practice is running around, chasing the latest framework, you may be setting yourself up for a difficult road ahead. We hear a lot of MSPs contact us because they want to be complaint with some new framework they've heard about.While being compliant is not a bad thing, there is a right way and a wrong way to go about achieving MSP compliance.Start with UCS; which will get you your own controlsThen, you map your controls to other frameworksIf you start with non-MSP frameworks, you will end up with a lot of confusion and potential for chaos. It'll also cost you time, resources, and moneyMSP M&A Integration: What are your baselines? If you are an MSP considering merging with or acquiring another MSP, pay attention. Aside from all the other risks associated with M&A, there are some very easy steps you can take to radically lower your risk once you've completed your deal.Develop your baselineWhat is a baseline?Baseline during due diligence

View Details

About a year ago I started to hear MSPs talk about a new company, Halo PSA. It turns out, this company is not new, but they are doing some rather innovative things in the MSP ticketing space and being somewhat disruptive.

So, we decided to reach out and invite Tim Bowers, CEO of Halo PSA to join the MSP Zone and talk about his company and what they are doing.

Highlights:

  • What is Halo PSA?
  • Origins of the company
  • Being disruptive in the PSA market
  • Why are MSPs talking about Halo PSA so much?

View Details

In this MSP Zone spotlight Travis Spring, vice president of Sagiss, joins us to share his thoughts on the MSP market. We discuss a wide range of topics, from economics, labor, technical, AI, and other business issues which impact all MSPs. Economy and its impact on managed servicesThe impact of AI on MSPs Are MSPs using AI? Labor challenges facing MSPs

View Details

Modern lead generation is a racketI receive a lot of "lead generation" cold calls and emails. When I say these solicitations are horribly bad, I am being generous. MSPs get hit up all the time to create or expand their cold calling efforts and if these same groups are soliciting them, this is crazy.Does cold calling really work for MSPs? Cold calling vs Inbound lead generationMSP content must be a factor of your marketing and lead cultivation Control Frameworks: Which is right for you?A lot of MSPs today are struggling with where to start on their compliance journey. Usually, this confusion manifests itself in deciding on a control framework. But, what if there are multiple frameworks? What if your customers pull you into different control framework directions? All reasonable questions and we'll give you some easy tips on how to start making sense of everything.What is relevant to your customer? Do it once, then translateMSP controls are different from client controls The MSP Business PlanMost people don't like to hear this but the very first step you should take when deciding to become an MSP is develop and write a business plan. Highlights: Provides structure for your MSP goalsPrevents missteps and waisted resourcesEliminates a lot of effort downstreamFaster time to marketIdentify relevant control frameworks sooner

View Details

MSP Growth Exaggerated?

  • Canalys is doing some great work in analyzing managed services. Long overdue.
  • Disproportionate # of MSPs actually producing revenue.
  • Hardware/software influence (more on this in the next segment)

Do MSPs Impact Hardware Sales?

I recently saw someone promoting a webinar on the topic of MSPs increasing hardware sales, and it caught my eye. It's not a typical subject we see discussed these days, but it is still a relevant one.

  • Legacy role of MSPs and hardware
  • Modern day MSP and hardware
    • Defensive (prevent encroachment by other MSPs)
    • HaaS
  • MSPs as hardware/software influencers

Co-Managed IT: Is it Possible?

I see a lot of websites promote co-managed services offerings. Given the sheer number of these offerings I assume that co-managed services is enjoying some measure of success these days. However, questions must be presented (and answered) before any MSP ought to proceed with a co-managed services offering.

  • Maturity of the client
  • Customer IT capabilities
    • Technical
    • Controls
  • Participation of client management
  • What does the agreement say?

View Details

Out of the Box MSSPs

This story came to us from one of our friends, Brent Watkins. At first, I thought it was a joke, but upon a second look, it wasn't. Completely serious promo from a security vendor…become an MSSP in 1 day! Unbelievable? I assure you it is not (the claim, not actually becoming an MSSP in a single day).

Talk to any legitimate MSP out there and they'll tell you being an MSP takes practice, focus, and execution of strategy. Claims like this one ultimately harm the MSP profession.

  • Why do vendors make these claims?
  • Am I anti-MDR?
  • How do customers view this type of messaging?

Still unsure about whether to call yourself an MSP?

In a recent episode I addressed a member email where they asked the question whether MSPs should still be using the term MSP and managed services. Just as we published that episode I saw this article about 4 reasons businesses should consider using an MSP. Need I say more?

  • Customers still use MSP and managed services
  • The name MSP isn't your problem
  • Companies afraid of the obligations associated with MSPs might want to avoid the term

MSPs Cautiously Optimistic about AI

In a recent webinar we discussed the pros and cons of artificial intelligence in a managed services practice. The real interesting stuff happened (as usual) in the Q&A where a lot of the MSPs said they were evaluating (or actually using) AI. But, there were a lot of restrictions about how they were planning on using it.

  • AI has legitimate use for internal MSP operations
  • Most MSPs hesitant about using AI in any customer interfacing way

View Details

SEC Adopts Cyber Disclosure Rule

The securities and exchange commission recently made news with an announcement of their cybersecurity disclosure rule. While this isn't the first governmental agency to announce such a rule, it should confirm to every MSP on the planet the direction in which we are headed and offer plenty of guidance for handling privacy and security incidents.

  • SEC rule explained
  • Purpose behind the rule
  • Impact of the rule on MSPs and clients
  • Failure to comply (i.e., lack of compliance)

MSPs Confused About Who They Are

I received a great email from one of our members asking me for an opinion. Now, I've discussed this topic a lot in recent years but its good to see MSPs still caring about this enough to email into the program.

My advice for MSPs wondering if managed services still has value left in it.

Master MSPs Play Crucial Role in Certification

The role of the master MSP has definitely evolved over the past decade. The needs of partners evaluating a relationship with a master MSP has certainly changed. But, in one crticial aspect, the relationship between master MSP and partner MSP has not changed; that is regarding compliance.

As MSPs develop relationships with external service providers (i.e., master MSPs), these relationships must be examined from a risk/reward basis. Here are some questions you may want to consider asking with regards to your ESP relationships.

  • Managed service supply chain - how does the ESP impact this risk? Do they increase or decrease my risk?
  • Does any part of the ESP help me with my own MSP practice controls?
  • Does the ESP have its own compliance and certification house in order?

View Details

Is it better to be cyber secure or cyber resilient?

If you think this is a trick question, it isn't. There are many who believe that security is solely a matter of defense. While defensive measure are crucial to any MSP (or their customers), preparing for eventual attacks which are successful, is also crucial.

So, what is an MSP to do? Here are some simple measures every MSP ought to be doing right now to be both prepared for cyber-attacks, but also resilient to them if they are successful.

  • Planning
    • Documenting your plans
    • Identifying where your risks are
    • Anticipating those attacks, and eventual breaches
  • Testing
    • Test means test
    • Test, and often
    • Document your test results. Learn from them
  • Monitoring
    • Keeping a watchful eye on your internal MSP network and IT assets
    • RMM isn't enough

More Fake MSPs

I no longer trust websites. When you hear this story you may not either. While this story is completely true, it is also, regrettably, a reality we must face as a profession and fix!

Urgent News for Break/Fix Providers

Three decades since the first MSPs were created, we still have IT organizations who are in doubt as to the business model around managed services. If these non-MSPs can't be persuaded based on the logic of the business model alone, perhaps we can present a very real economic motive for getting rid of your break/fix and reactive customers.

Remember, no matter how much your client's try and make you think that reactive IT services are the best for them, they are wrong!

View Details

I often hear MSPs talk about getting rid of problem clients, particularly those clients who do not embrace managed services. But, it's always good to dive deeper into the motivations behind such claims. I was able to do just that when Jimmy Puckett, CEO of SPINEN, entered the MSP Zone.

Jimmy and I spoke about innovation in the managed services profession. We also discussed how MSPs rely on their vendor partners to continuously evolve and develop new technologies to help MSPs maintain success.

Highlights:

  • Who is SPINEN?
  • Why they fired 70% of their clients
  • Vendor relationships and how to keep them productive
  • Innovation involving artificial intelligence

View Details

The MSP Generation Divide

Time changes everything. That certainly seems like an appropriate saying when examining the managed services profession. MSPs seem to be getting younger and younger every year. Or maybe we are just getting older.

The point is, the generational divide amongst MSP professionals is increasing. We have older and younger members of our profession, and a lot of knowledge must be transferred between these generations.

  • New MSP generation doesn't have preconceived notions of managed services
  • Younger MSP generations have a lot to learn
  • Younger MSP generations need access to the veteran MSPs

Vulnerability Scans Don't Do This

Many people believe vulnerability scans are a magic bullet, capable of solving lots of different problems. While vulnerability scanning technology is a necessary tool in the MSP tool belt, it is not a cure-all and should be utilized cautiously and appropriately.

  • Vulnerability scan use cases
  • Vulnerability scans: what they don't do
  • Vulnerability scanning isn't a business model

Why the MSP Name is Valuable

We have two examples of the "MSP" word being misused or misapplied. One example involves an end-user, the other example involves MSPAlliance.

  • End-user organization fooled by cyber consultant claiming to be MSP
  • MSPAlliance mistakenly believes organization is MSP despite clear language on their website

View Details

What do PE Firms Want from MSPs?

For the last several years MSPs have been courted by private equity firms desperate to enter the managed services space. At the risk of being obvious, what do private equity (PE) firms want from their MSP investments?

It's an important question and knowing the answer can help you successfully navigate the process of working with a PE.

  • PE vs other MSP buyers
  • Types of investment
  • Hold times

Managed Service Sales is Easier Than you Think

Stop overthinking sales. After reading a sales book (non-MSP) I'm convinced that the majority of MSPs have over complicated their approach to sales. Instead of focusing on native skills which all MSPs should have, they believe that it is necessary to acquire sales capabilities which are not native to most sales organizations and may be harmful to selling managed services.

  • Are closing and handling objections the real barriers to successful MSP sales?
  • The MSP sales magic bullet?
  • Lead generation and account handling

Help me fix my MSP pricing

MSPs struggle with pricing. Pricing questions come up many different sizes of MSP organizations (so it's not just an SMB issue). There are many reasons why MSPs might believe their pricing is either too high or too low. Following these simple methods should help you get a lot more comfort around how and where you price your managed services.

  • Pricing methods revisited
  • Prices are too high
  • Prices are too low
  • Pricing KPIs

View Details

Are Accounting Firms Squeezing MSPs?

  • Misunderstanding MSPs in the larger IT channel discussion
  • Why are accounting firms getting into managed services?
  • How does the CPA community impact MSPs moving forward?

Could the Master Cyber Provider Model Backfire?

Those who ignore history are doomed to repeat it. Truer words were never spoken, particularly in the IT channel. Way back when managed services was just getting started, the master MSP model emerged. There are important lessons to be learned from this era, particularly when we start to see history repeating itself today. It's like déjà vu.

  • Role of the "master MSP" then
  • Today's "Master MSSP"
  • Resellers vs MSPs, it really does matter!

Manages Services Pricing Reality Check

There are a lot of methodologies for approaching managed services pricing. Regardless of what method you choose (and you should have a method), understanding the role of risk as a prime pricing determination factor is important. So, important, if you forget to include it you could be risking a lot more than just low margins.

  • Risk based pricing revisited
  • Understanding the role of margin in your pricing
  • Avoiding commodity price traps

View Details

Internal IT vs MSP

Can an MSP do everything an internal IT department can? That is the quintessential question the world has been asking for 30 years. Just because an organization has an internal IT department does not guarantee that it will be efficient. In fact, all IT departments face the same choices as IT service providers: you can be proactive or reactive.

  • Struggles of internal IT
  • Natural barriers of scalability with internal IT
  • Reactive vs proactive internal IT

MSP Market Still Growing

According to Allied Market Research , the MSP market is growing at a solid rate and will reach growth of more than 11%, with an estimated revenue of $594 billion globally by 2031. Now, this study focused entirely on enterprise class MSPs, but it still has some value for the rest of the MSP community.

  • If managed services is growing at the enterprise level, there is no reason to believe it is doing anything different at the mid-market and SMB levels
  • The drivers behind the growth are also applicable to all levels of the MSP market; factors such as adoption of cloud computing, keeping IT management costs in line, and increasing data security threats.
  • At these levels, managed services will represent half of all IT services spending around the world.

Does Size Matter in Managed Services?

I hear a lot of MSPs talk about what they would do if they only had more resources. While more resources can make a difference, it isn't the only thing that indicates success in managed services. In fact, there are many examples of large organizations who have very poorly run managed services operations.

  • Efficiency, not size is what matters
  • Resources only gets you as far as your process
  • It's all about execution

View Details

N-able CEO Advises MSPs on Upcoming Challenges

N-able held its partner conference in Prague last week and their CEO had some very interesting comments regarding the economy, compliance, security, and other "challenges" facing MSPs.

  • Headwinds for the rest of the economy are tailwinds for MSPs, if they position themselves correctly
  • Major "business" shift for MSPs
  • This is a very simple adjustment for MSPs, if you don't look at it as a technical change

MDR vs MSP

Do you think managed detection and response is the same as managed services? Think again. Many people conflate these two practices but they are not necessarily the same; although they can be. Confused? Don't be.

  • Definition MDR
  • Defining MSP
  • Venn Diagram solution

Tightening Credit Markets Present Interesting Choice for MSP channel

As the US (and others) government attempts a soft landing from a red hot economy full of inflation and cheap currency, there are two solid choices for the IT/MSP channel. The choice your company takes will greatly depend on whether you are closer to an MSP or closer to a break/fix company.

  • IT lending
  • Product (project) refreshes
  • Using managed services to push through difficult economic periods

View Details

Can MSPs "Guarantee" Compliance?

It's no secret that many MSPs are helping clients deal with compliance issues. Whether this is gathering evidence for a client audit, or simply offering traditional managed services to demonstrate compliance for a given framework.

However, when it comes to guarantees, compliance may not be the area where you make any guarantees. Here's why.

  • Compliance within the MSPs' control
  • Customer interference
  • Making guarantees in the first place

Benefits of Managed IT Services for Proactive Monitoring, Maintenance, and Support - Tech Guide

Converting Reactive Clients to Proactive

As some economists are predicting a 2023 Q4 recession, making sure your MSP ship is in excellent condition for potentially rough seas is a good thing. What could you be doing to better prepare your MSP practice for difficult times? Converting as many reactive customers to managed services would likely be a great starting point. Here's some advice on how to do just that!

  • First, why conversion to proactive is necessary
  • Migration strategies
    • Compliance
    • Security/privacy
    • It's the only choice!
  • Get creative
    • Offer incentives
    • Sunset your reactive practice

Should MSPs get Involved with Customer Policies

This topic was discussed at the last MSPAlliance Inspire meeting and the debate was interesting. What was unanimously agreed upon was there is a role for the MSP to play in compliance with their customers. What was in dispute was whether working on client policies was something an MSP ought to do.

  • MSP influence customer compliance all the time
  • MSPs compliance roles
  • Compliance can involve controls and policies, or both

View Details

Weaver Outrage Meter: Low

Don't Rely (too much) on Cyber Insurance

Barracuda surveyed 400 enterprise IT and security professionals globally, ranging from IT managers to CISOs, to discover the biggest cybersecurity challenges businesses face in 2023.

  • Are organizations placing too much emphasis on cyber insurance?
  • What should MSPs do about this?
  • Are cyber insurance policies being used to target ransomware victims?

MSP Economics Update for Q2

We just had the latest MSPAlliance Inspire meeting last week in Boston and it was a blast. A little chilly but the group went to a Red Sox game, had a great time, and also got a lot accomplished. One of the outcomes was an update of unanimous agreement regarding the economy and its impact on managed services operations.

  • Is the Q1 slow down still in effect?
  • What does Q2 have in store for MSPs?
  • What are MSPs doing to plan for the future?

Should MSPs Represent Themselves During M&A Deals?

We are in the middle of a curious period of MSP M&A. M&A deals seem to have slowed, and yet MSPs still report pestering from brokers and buyers trying to sign them up as clients. What can we make of this?

  • M&A demand is still strong amongst the MSP profession
  • Every MSP (buyer or seller) should have representation
  • Don't fall for traps that entice you to represent yourself

View Details

Weaver Outrage Meter: Low

AI Ethics in Managed Services

You heard correctly. Ethics in artificial intelligence. This is going to be a big issue moving forward and MSPs had better familiarize themselves with what is happening because before too long, MSPs will be dealing directly with AI devices and scenarios.

Compliance reporting

All the discussion around compliance lately is missing one crucial element: reporting. Without reporting, no compliance exercise you undertake will be of use to anyone outside your organization.

  • Compliance reporting
  • Balancing transparency with security
  • Lessons learned from FFIEC

Making Peace with Cyber Consultants

The old adage is "if you can't beat 'em, join 'em." Well, that's not exactly the issue here but it's close. Maybe a better way to put it is "if they can't beat you, they should join you." Cyber consultants are likely here to stay, which is not to say that we can't (or shouldn't) attempt to forge a pathway that is, if not together, at least on parallel tracks.

  • Cyber workers are like anyone else…they all start from the beginning
  • Cyber workers need to understand their own career path
  • Cyber workers need to understand MSPs and be respectful of the role they have

View Details

Weaver Outrage Meter: Low

Cyber Consultants at it Again

We have been coming across a unique brand of marketing and website design company lately; yes, you guessed it, they also do cybersecurity. It seems difficult not to come across cyber security "experts" these days, even if that claim may be dubious.

  • Marketing gets into cybersecurity
  • Cyber consultants need understanding of MSPs
  • First do no harm!

Managing MSP remote workers (ticket reviews)

Since the pandemic remote work has exploded. The same is true within the managed services sector. MSPs, however, have some unique methods they can use to ensure their remote technical staff are actually being productive.

  • Unproductive remote workers
  • Lack of data
  • Ticket review benefits

Compliance isn't Security

With so much noise around compliance, I thought it might be nice to explore some fundamentals around compliance, what it is, and what it is not.

  • Security isn't compliance either
  • Being secure is its own goal and reward
  • Compliance is about communication and transparency

View Details

Weaver Outrage Meter: Low

We have officially wrapped up Q1 2023 and its time to evaluate how the managed services profession did  and what the outlook is like.

  • Q1 analysis
  • MSP outlook
  • Tech stock performance

S&P 500 doing well because of IT stocks

https://stocks.apple.com/A4qzi73EUTAqsG5chNLDjkw

Cyber Consultants Continued

We have been discussing (for years) the ongoing evolution and emergence of consultants in the cybersecurity field and the impact they are having on managed service providers (and their clients). We have an update on this topic from actual MSPs who are encountering these consultants in the field and the feedback may surprise you.

  • MSP interaction with cyber consultants (mature vs reactive MSPs)
  • Agenda of the cyber consultant movement
  • What can MSPs do?

AI vs Automation

MSPs need to evolve. Evolutionary change has been a constant in the managed services profession since its beginning in the early 1990s. As MSPs search for ways to become more efficient and scalable, an emerging debate is presenting itself as we understand more about artificial intelligence and automation tools.

  • AI vs automation
  • AI risks in managed services
  • MSP guidance for automation and AI technologies

View Details

Weaver Outrage Meter: Low

North Dakota Announces Mandatory Cybersecurity EducationNorth Dakota just announced a new educational mandate for grade school students to learn more about cybersecurity. Such a move is not only a smart one, but it is going to have a positive impact on future generations of cybersecurity professionals.

  • Cyber skills gap acknowledged
  • Good example of government leadership and action
  • Good news for MSPs (and other employers) in the near future

https://www-kxnet-com.cdn.ampproject.org/c/s/www.kxnet.com/news/state-news/north-dakota-is-first-state-to-approve-required-cybersecurity-education/amp/

MSP Recession PlanningMore talk about a recession here in the United States; it seems inevitable that we are headed into, or may already be in a recession. What, if anything, can you do to prepare? Credit tightening will impact service providers, but more so on the reactive side. VARs, system integrators, break/fix companies, these are the types of IT business models most vulnerable to tight credit markets and will feel the financial pain more acutely compared to an MSP with steady, predictable recurring revenue and cash flow.

  • Historical impact of recessions on MSPs
  • Credit markets tightening, who will suffer most?
  • Can MSPs thrive during recessionary periods?

CaaS dangers MSPs should avoidCompliance as a Service is getting more attention in the IT channel. With such attention, MSPs (and non-MSPs) are both jumping onto the CaaS bandwagon. But, just as with most things in life, there are right ways and wrong ways to go about developing a CaaS strategy and offering. Here are some helpful tips to get you pointed in the right direction.

  • Beware of reactive CaaS providers
  • Scanning is not compliance
  • If you've never been through an external organizational certification or audit, CaaS is probably going to be more challenging for you

View Details

Weaver Outrage Meter: Low

What is continuous compliance? Sound like a headache? It isn’t. Continuous compliance is where the managed services profession is headed and MSPs had better start preparing now.

  • Continuous compliance defined
  • Why continuous compliance is the future
  • Guidance for transitioning from standard to continuous

Recent news stories would have you believe that the recent bank failures are really caused by underlying fractures within the tech sector. Let’s examine an alternative theory for what is really happening.

  • Big tech layoffs
  • Bank failure root causes
  • Health of MSP market

We are seeing more “providers” intentionally (or not) being vague about the types of services they are offering. Here’s why this is a bad idea.

  • Problems with mislabeling your services
  • MSPs who aren’t, and cyber providers who claim MSP status
  • You can’t run from what you do

View Details

Weaver Outrage Meter: Low

First, let's discuss Silicon Valley Bank (SVB). You may be wondering what does SVB have to do with managed services. Good question. Nothing directly ties SVB to managed services, other than there are a number of MSPAlliance members who bank there and may be impacted by recent events.

  • Will SVB have any long or short term effects on the managed services profession?
  • Is the SVB collapse an indicator of technology health?

Second, some advice for MSP startups. Much of the discussion around compliance and achieving certifications for MSP organizations has been focused on more mature MSPs. This needs to change.

Since the launch of Cyber Verify, we will be spending a lot more time dealing with the issue of MSP compliance, especially for MSP startups and less mature organizations.

  • Make compliance an "everyday" part of your business
  • Start with your policies and procedures documentation
  • Use platforms like Cyber Verify to begin mapping your control gap areas so you have a remediation plan

Third, let's talk about managed services pricing. We mostly discuss pricing when we talk about raising them. But, let's just examine why an MSP might want to consider lowering their pricing.

  • Price economics
  • Security standardization
  • Automation and other methods of lowering service delivery costs

View Details

Weaver Outrage Meter: Medium

MSP Zone examines the idea of a cyber tax, what that would look like, and whether a cyber tax would be a good thing for MSPs

Highlights:

  • Cyber tax credits
  • Codes of conduct
  • Government oversight?

Cyber Verify has been launched. What is Cyber Verify? How can it help MSPs at both ends of the MSP maturity spectrum?

The Art of Managed Services 2nd Edition is now available for purchase. What went into the 2nd edition? What has changed since the first edition was published in 2007?

Supplemental reading:

Cloud Computing Needs a Universal Standard - WSJ

View Details

Weaver Outrage Meter: Low)

In the US, we just had our national state of the union address, so we thought it would be fun (and interesting) to do our own state of the union address on how the managed services profession is doing in 2023.

Drawing from global IT spending data and MSPAlliance member input, we have put together some of the more noteworthy areas of interest to MSPs in 2023, both areas of opportunity and issues of concern.

Enjoy

Highlights:

  • IT Spending for 2023
  • Compliance challenges and opportunities
  • MSP market differentiation

View Details

Weaver Outrage Meter (Low)

There are many reasons why you would want to work with a provider of managed services. During a recession (or the threat of a recession), IT and business needs tend to become a bit more clear and in focus as you come to reality about what it is you really need versus what you don't.

The benefits of managed services really only apply to true MSP organizations. We are not talking about break/fix and reactive IT companies as they do not create the same types of economic and IT benefits as a managed services provider.

Highlights:

  • Predictability
    • IT performance
    • IT spend
  • Flexibility
    • Adjust up
    • Adjust down
  • Security
    • Stabilization
    • Constant monitoring
    • Not reactive

View Details

Weaver Outrage Meter (Low)

Many MSPs think of compliance as a "once a year" activity. Much like doing your taxes, compliance is a doing it once and then forget it event that gets revisited next year. This is dangerous thinking and should be part of every MSP's new year's resolution for 2023.

Compliance doesn't have to be a dirty word. In fact, compliance should have nothing to do with tax preparation or any other dreaded activity you have to do on an ongoing basis. Instead, compliance ought to be like breathing; second nature to all MSPs.

Sound too easy? It isn't. There are a few simple tricks you can take to get your MSP practice headed down the path of continuous compliance.

Highlights:

  • Continuous vs cyclical compliance
  • Compliance is a team sport
  • Compliance documentation and evidence

View Details

Weaver Outrage Meter (Medium)

I recently read a blog written by a government about how to properly use MSPs in a cloud environment. Now. I am not sure what background this author has but I’m assuming a good number of people read and approved of the article since it was published (for the public to read) on a government website.

I do not like attacking people directly when they have no ability to respond to the allegation but in this case, I believe the idea raised is so contentious that it must be addressed. So, that is what I intend to do.

I won’t name the person or the organization, but I do intend to discuss the nature of the article and what it purports to encourage: namely, that MSPs ought to behave more like cloud providers.

Highlights:

  • What attributes of the cloud provider ought to be mimicked by the MSPs?
  • How do MSPs and cloud providers interact?
  • If MSPs did not exist, would the cloud provider be able to service the customer?
  • Do we really want MSPs to be more like cloud providers?

View Details

Weaver Outrage Meter (Medium)

I thought you'd never see the day when you hear me say the words, maybe roll ups work in the MSP profession. Before you get too excited, there are still some "right" ways and "wrong" ways to go about doing M&A and that is part of what we will discuss today. But, part of my analysis on MSP acquisitions over the last few years does involve what some of you out there would classify as roll up acquisition strategies.

Do they work? Are they really roll ups? Let's dig in further and find out.

Highlights:

  • Definition of roll ups
  • Historical roll up strategies examined
  • Modern "roll ups" defined
  • What this means for investors and MSPs in 2023

View Details

If cyber is uninsurable, then MSPs just got a lot more valuable. Here's the conundrum. If MSPs represent aggregate risk to insurers yet are invaluable in the fight against cyber threats, and if cyber is becoming more uninsurable, then MSPs become even more critical in the cyber risk equation. Sound complicated? I'll explain.

Most of the discussion around cyber risk insurance today can be boiled down to lack of visibility and understanding about the MSP market and IT threats in general. I don't want to make too large of a generalized statement but there is a lot of ignorance out there. Trust me.

MSPs do present a threat surface for cyber criminals, just like every other entity. I can make a convincing argument as to why MSPs have less of an attack surface but that's for another time. The point is, MSPs cannot be ignored when it comes to solving the cyber threat question. If the insurance industry is unable (at the moment) to answer this question, then maybe it's up to the MSPs to do so.

Highlights:

  • Cyber underwriting flaws
  • Lack of visibility into cyber and MSP markets
  • Alternative cyber risk mitigation models

View Details

Weaver Outrage Meter (Low)

2022 began very differently than it ended. The pandemic, global supply chain, cyber-attacks, cyber risk, the economy, MSP talent, and many other areas saw change (good and bad) during the year.

This summary of the year 2022 in managed services looks at a variety of areas all related to the global managed services profession and attempts to extract some lessons learned so we can apply them to 2023.

MSP Zone Guest: Rob Scott

Highlights:

  • Cyber Risk - legal, technical, business, and other
  • MSP business model changes in 2022
  • Legal updates

View Details

It has been a while since we discussed the topic of MSP talent shortages, specific to security (i.e., cybersecurity). A lot has happened since earlier in the year and I wanted to provide you all with an update on where we stand, how the industry is doing, and where we are seeing the most results.

Now, the first warning is do not get upset by what you hear. I am going to talk in generalities about what we are seeing across a very large profession. If something I say is troubling to you, just know that it doesn't necessarily mean it is going to happen to your practice.

Highlights:

  • Summary of cyber talent in the MSP sector
  • Mass tech layoffs
  • MSP talent sources

View Details

Here is some friendly advice for policy makers and legislators moving on the issue of MSP regulation (of any kind) next year, 2023. Since 2020, we have seen a large amount of activity in the cyber regulation area, including specific regulations calling out managed service providers (MSP).

Highlights:

  • Direction of MSP Regulation in 2023
  • Flaws in MSP regulation requiring a fix
  • What MSPs Need from MSP Regulation

View Details

With all the pressure and hype around growth-oriented MSP platforms these days, I thought it might be helpful to talk about one characteristic of the small MSP which is actually very important. Now, this does not mean larger MSP organizations do not possess this characteristic. It does mean, however, that smaller MSPs are more likely to find this type of process much easier to perform.

What am I talking about? Analyzing, identifying, digesting, and remediating MSP risk. While risk assessing is the duty of every MSP organization, smaller MSPs will find certain elements of the risk assessment far easier than their larger colleagues.

Highlights:

  • Review of the MSP risk assessment
  • Reporting and documentation requirements
  • Tips for remaining in compliance

View Details

For many MSP owners and operators sales is a foreign concept. Sales is acknowledged as a necessary business component for all MSPs, but very few MSPs have mastered the art form of sales.

Today we attempt to breakdown the stereotypes of sales in the managed services profession. We examine everything from process, metrics, business goals, and the important integration of sales into the managed services engine.

If you have ever struggled with sales in a managed services environment, this episode is for you.

Highlights:

  • MSP sales objectives
  • How to build an MSP sales engine
    • Methodology
    • Metrics
    • Training
    • People
  • MSP sales: Myth vs reality

View Details

Last week was the MSPAlliance Inspire "peer" group meeting in Las Vegas. I say "peer group" in quotes because this group sees themselves as the anti-peer group. Born out of the frustration of many peer group veterans, they created the MSPAlliance Inspire to bring networking and leadership in managed services to a new level.

Here are some of the things they discussed and what I learned from observing these MSPs.

Highlights:

  • MSPs need a place to vent
  • Staffing remains an issue, but MSPs do have solutions
  • Cyber insurance is both a good and bad thing for MSPs

View Details

I recently spoke with an insurance executive and we had a very interesting conversation about risk and perceptions of risk related to cyber security and managed services. This conversation was eye-opening for a number of reasons, but mostly because it exposed me to a viewpoint I had not fully considered before.

This conversation is important because it represents what I believe is the larger debate happening right now between MSPs on one hand and public policy makers on the other. Is risk truly a black and white issue or is there reasonable ground to disagree? Let's dig in and find out.

Highlights:

  • Insurance view of MSPs
  • MSP view of Insurance
  • Where does risk really occur? The bad MSP and the bad client
  • How can we move forward?

View Details

Ransomware impacts many industries throughout the world, but today we focus on the manufacturing sector. Is the manufacturing industry facing an increase in cyber-attacks? If so, how are they responding to these attacks and what changes are they making to become more resilient to such attacks?

John Shier, senior security advisor with Sophos, enters the MSP Zone to discuss his analysis of a recent Sophos ransomware study.

Highlights

  • 52% of manufacturing organizations were hit with ransomware in 2021 - a sharp uptick from 36% in 2020
  • 66% of surveyed manufacturing and production organizations reported an increase in the complexity of cyber attacks

  • 61% reported an increase in the volume of cyber attacks when compared to the previous year

  • Only 75% of those surveyed reported having cyber insurance - the lowest percentage across all sectors

  • What lessons can we learn from cyber attacks on manufacturing organizations?

  • What can MSPs do to protect these types of clients?
  • What should manufacturing organizations be doing differently?

View Details

Weaver Outrage Meter (Low)

Sponsored by: Dell Expert Network

Any organization can experience growth. Some may have to buy it, such as through M&A transactions. Others, may be lucky enough to experience growth organically. Maybe they have a really good product, perhaps they just have an awesome sales and marketing team, or perhaps they are just fortunate to be in the right place at the right time.

The same is true for MSPs. MSPs, however, have to consider something when going through a growth period: how will such change impact their service delivery and security? Growth at the expense of scalability or security is just not worth it. So, what is to be done?

There are some steps any MSP can take to prepare themselves for any unusual growth period in their company. We will examine some of those steps today.

Highlights:

  • Planning for growth
  • Bulking Up
  • Compliance Responsibility
  • Knowing when to hit the brakes

View Details

There are many organizations looking to get a better handle on their IT management, including their security. For the majority of these organizations, it is impossible to do this entirely on their own. As such, these entities often seek out MSPs to resolve a variety of business, technical, and security objectives.

Before engaging an MSP, however, there are some things you ought to know about your MSP. Here is our list of questions you ought to ask your MSP prior to engaging their services.

Highlights:

  • Alignment between MSP and customer
  • Read the contract
  • Risk analysis
  • Risk Inheritance

View Details

Weaver Outrage Meter (Low)

Sponsored by: Dell Expert Network

As the economy continues to behave erratically, there are disturbing reports emerging about how the MSP sector may respond to this economic turbulence.

MSPs will respond one way to economic  tough times, reactive or break/fix providers tend to react in a very different manner. How these different providers respond may have far reaching consequences, both to their own organizations, but also for their customers.

Highlights:

  • MSP vs Break/fix Models Explained
  • How Proactive and Reactive providers respond to difficult economic times
  • Proactive vs Reactive Impact on clients

View Details

Weaver Outrage Meter (Low)

Sponsored by: Dell Expert Network & VARC

Risk assessments. Sounds like a good thing to have. Everyone can universally agree that they are good to have. And yet, when you dig deeper, risk assessments can mean very different things to different people.

This episode we delve into the world of risk assessments. What are they? How can you perform them? What should your expectations be from doing a risk assessment?

Put your feet up and take a listen as we explore the world of risk assessments.

Highlights:

  • What is a risk assessment?
  • Risk assessments for MSPs
  • Compliance value of risk assessments
  • Risk assessment best practices

View Details

Our friend Corey Munson from PC Matic brought this study to our attention and it's a great piece that every MSP ought to read. The study, published by Deloitte and NASCIO, compares attitudes by state CIOs on a variety of topics from 2020 and 2022.

The report identifies a pretty significant increase in the number of state CIOs wanting to work with an MSP in 2022. But, it's important to unpack some of the historical data around governments working with MSPs and it's especially important to understand the reasons why these CIOs want to work with MSPs.

Highlights:

  • 2020-2022 changes
  • Shifts in MSP business models
  • Maturity of state governments as to the role of the MSP
  • Louisiana as the template

View Details

Managed Service Providers (MSP) have been at the center of a global discussion around security.  There is nothing wrong with this discussion. In fact, it is a good thing that we have a conversation around data privacy, security, and the ways people and organizations can protect themselves against such threats (hint: working with an MSP should make you safer!).

However, the role of the MSP (historically and even through to today) has not solely been about security. MSPs help their clients in a great variety of ways, from security, IT management, productivity, and even disaster prevention and recovery.

As we near the end of North American hurricane season, we are reminded of the many way in which MSPs have been helping clients prepare their businesses from many forms of disaster (both natural and unnatural). Ken Stringer, CTO of CMA, enters the MSP Zone to discuss his views on disaster preparation and recovery.

Highlights:

  • How do MSPs interact with clients regarding disaster preparation & recovery?
  • Do cyber attacks have any similarities to DR?
  • What lessons can we learn from modern (and historical) disasters to better prepare for future business disruption events?

MSP Zone Guest: Ken Stringer, CTO, CMA

View Details

Weaver Outrage Meter (Low)

If you offer any form of managed security offering (or plan to in the near term), then listen up: you may want to stop up-selling customers on managed security. Sound provocative? It isn't.

Managed security ought to be (for the vast majority of MSPs and their clients) part of the standard managed services offering. Meaning, it should be the exception to the rule that an MSP agrees to have a managed services client who does not receive security from the MSP. We will discuss what some of those exceptions might be, but we will focus on how you can more accurately align your MSP practice with the needs of your customers and still make money.

Highlights:

  • Incorporate security into your managed services offerings
  • Exceptions to this rule
  • Up-sell opportunities

View Details

Weaver Outrage Meter (Low)

Sponsored by: Dell Expert Network

The terms managed services and MSP have a particular meaning, both professionally through organizations like MSPAlliance, but also through the common usage. When those accepted terms begin to change to the point where they no longer have the same meaning, you can expect problems to occur.

Regardless of your definition of managed services (here is ours), take a listen to this episode and come to your own conclusions about what MSP and managed services means.

Highlights:

The role of the MSP has always been mission critical

Managed services has never historically been applied much outside of IT

Today's definition of managed services certainly does not mean much beyond IT

MSP Zone Reading Material: What Is A Managed Service Provider (MSP)? – Forbes Advisor

View Details

Co-managed services is not new. In fact, it has been around since the beginning of the managed services profession. If you want to be completely honest, managed services began as a "co-managed" model with the MSP playing the critical outsourcing role but being directed by internal IT. Those days have changed.

Highlights:

  • Origins of co-managed services
  • Co-managed services defined
  • When co-managed services does not work

View Details

Co-managed services is not new. In fact, it has been around since the beginning of the managed services profession. If you want to be completely honest, managed services began as a "co-managed" model with the MSP playing the critical outsourcing role but being directed by internal IT. Those days have changed.

Highlights:

  • Origins of co-managed services
  • Co-managed services defined
  • When co-managed services does not work

View Details

For the past several years, we have heard nothing but the perils of cybersecurity attacks, and the mounting difficulty in preparing for and defending against such attacks. That type of sustained pressure can lead to desensitization, apathy, and burnout.  

But, in all seriousness, cybersecurity has never been more critical, and the stakes have never been higher. So, what is an MSP (Managed Service Provider) to do?  

The following recommendations may help you strike a balanced approach to your managed services practice by incorporating cybersecurity into your business model, without letting it dominate and turn you into something you are not. Let us get started.  

View Details

For the past several years, we have heard nothing but the perils of cybersecurity attacks, and the mounting difficulty in preparing for and defending against such attacks. That type of sustained pressure can lead to desensitization, apathy, and burnout.  

But, in all seriousness, cybersecurity has never been more critical, and the stakes have never been higher. So, what is an MSP (Managed Service Provider) to do?  

The following recommendations may help you strike a balanced approach to your managed services practice by incorporating cybersecurity into your business model, without letting it dominate and turn you into something you are not. Let us get started.  

View Details

If you have ever considered or called yourself a "trusted advisor" then you may want to pay attention to this. The trusted advisor designation is under attack and is being threatened with the worst possible outcome, irrelevance.

The thing you have to understand is as trusted advisors, this naming designation is like a knife's edge, it must always be sharpened or else it will become dull and cease to have value. MSPs are facing this same threat but from a new direction, the cybersecurity vendor. Not the software or hardware companies, but the cyber consulting firms sprouting up like weeds all over the world. These firms are proliferating at an alarming rate and they have their sights firmly set on the managed service provider.

View Details

If you have ever considered or called yourself a "trusted advisor" then you may want to pay attention to this. The trusted advisor designation is under attack and is being threatened with the worst possible outcome, irrelevance.

The thing you have to understand is as trusted advisors, this naming designation is like a knife's edge, it must always be sharpened or else it will become dull and cease to have value. MSPs are facing this same threat but from a new direction, the cybersecurity vendor. Not the software or hardware companies, but the cyber consulting firms sprouting up like weeds all over the world. These firms are proliferating at an alarming rate and they have their sights firmly set on the managed service provider.

View Details

Documentation is not a new topic amongst the MSP community, but it is something that most MSPs could be doing better. Today's discussion focuses on why documentation is important in an MSP practice, the benefits is brings to the MSP, the problems lack of documentation can produce, and last, we will offer some helpful tips on ways you can improve your MSP documentation using common tools you already have.

Highlights:

  • Current state of MSP documentation
  • Benefits of documentation in an MSP practice
    • Security
    • Scalability
  • Ways to immediately improve your service delivery documentation
    • Documentation platforms
    • Areas of immediate focus
    • Documentation as an ongoing practice

View Details

Documentation is not a new topic amongst the MSP community, but it is something that most MSPs could be doing better. Today's discussion focuses on why documentation is important in an MSP practice, the benefits is brings to the MSP, the problems lack of documentation can produce, and last, we will offer some helpful tips on ways you can improve your MSP documentation using common tools you already have.

Highlights:

  • Current state of MSP documentation
  • Benefits of documentation in an MSP practice
    • Security
    • Scalability
  • Ways to immediately improve your service delivery documentation
    • Documentation platforms
    • Areas of immediate focus
    • Documentation as an ongoing practice

View Details

Weaver Outrage Meter (WOM): Low

Are you looking for MSP acquisitions? Do you think you are ready? I come across a lot of MSPs who think they are ready do to acquisitions. In reality, few have given much thought to what is involved in the process and what it will really do to their MSP practice.

This episode will examine both sides of the M&A process (buyer and seller) and discuss some facts about the M&A world which may be new to many of you. These tips will be very helpful for you, regardless of whether you are a buyer or a seller.

Highlights:

  • Buyside best practices
    • Funding
    • Integration
    • Motive
  • Sellside best practices
    • Financials
    • Process documentation
    • metrics
  • M&A best practices
    • What are your company goals?
    • Do you have people to run the process?
    • Cost
    • Outcome measurement

View Details

Weaver Outrage Meter (WOM): Low

Are you looking for MSP acquisitions? Do you think you are ready? I come across a lot of MSPs who think they are ready do to acquisitions. In reality, few have given much thought to what is involved in the process and what it will really do to their MSP practice.

This episode will examine both sides of the M&A process (buyer and seller) and discuss some facts about the M&A world which may be new to many of you. These tips will be very helpful for you, regardless of whether you are a buyer or a seller.

Highlights:

  • Buyside best practices
    • Funding
    • Integration
    • Motive
  • Sellside best practices
    • Financials
    • Process documentation
    • metrics
  • M&A best practices
    • What are your company goals?
    • Do you have people to run the process?
    • Cost
    • Outcome measurement

View Details

Weaver Outrage Meter (WOM): Low

Most people think of the IT channel as just some vast thoroughfare of companies all moving in the same general direction, all doing pretty much the same thing. Nothing could be further from the truth.

If you want to sell to MSPs, you should listen to this podcast. You will learn about the various types of channel companies, what makes them each unique, and most importantly how the MSP business model stands apart from all other IT channel companies.

Highlights:

  • Overview of the IT channel
  • What makes MSPs different?
  • Why you would want an MSP compared to a reseller
  • MSP channel best practices

View Details

Weaver Outrage Meter (WOM): Low

Most people think of the IT channel as just some vast thoroughfare of companies all moving in the same general direction, all doing pretty much the same thing. Nothing could be further from the truth.

If you want to sell to MSPs, you should listen to this podcast. You will learn about the various types of channel companies, what makes them each unique, and most importantly how the MSP business model stands apart from all other IT channel companies.

Highlights:

  • Overview of the IT channel
  • What makes MSPs different?
  • Why you would want an MSP compared to a reseller
  • MSP channel best practices

View Details

What is a managed service provider? It's a question I have been getting asked for decades. In fairness, it is an important question, as well as a difficult one to answer.

In this episode we will address the question from a variety of perspectives, attempting to create a workable definition everyone can use.

Highlights:

  • Who is asking the question?
  • Why do they want to know?
  • What is an MSP?

View Details

Now that you have your business plan and the right tools, it is time to create your service catalog. Some of you may be wondering what the purpose of a service catalog is, but do not worry. We will explain everything.

The service catalog is an important, some say vital, component of your managed services practice and will help you improve efficiency, reduce risk, and close more deals, as much as it will decrease manual steps, avoid costly sales missteps, and align customer and MSP goals.

Highlights:

  • Service catalog explained
  • How to create your service catalog
  • Benefits of service catalog:
    • legal
    • sales/marketing
    • service delivery

View Details

When cybersecurity consultants attack. Just kidding. Well, sort of. Today, we address the issue of cybersecurity consultants and the impact (not always good) on managed services customers. These consultants, who are not in any way knowledgeable about managed services, or have  limited exposure about security issues and best practices, are actively inserting themselves into managed service client relationships with a goal towards helping the client improve their interaction with the MSP, including their cybersecurity posture.

This would be a fantastic thing if it were true. Unfortunately, this scenario is far from the truth.

Cybersecurity consultants, when evaluated on the basis of their actual interactions with end-users, often create conflicting and harmful results, typically cleaned up by the MSP.

Highlights:

  • Primary care MSPs
  • Identifying scope of cyber consultants
  • Coordinating with MSPs

View Details

MSP channel veteran Stephan Tallent, Stellar Cyber, drops into the MSP Zone to discuss a wide range of topics. We cover trends in hiring security analysts, bridging the MSP talent gap, adoption rates of XDR amongst MSPs and customers, and more.

Highlights:

  • Good time to be an MSP?
  • XDR or SASE
  • Talent Gap

MSP Zone Guest: Stephan Tallent, Stellar Cyber

View Details

Is saving money a legitimate objective when engaging an MSP? Justin Current of Sirvis enters the MSP Zone to discuss the age old question, can MSPs save their clients money through managed services.

This question has actually been around since the early days of managed services. You may be surprised but there are ways that MSPs can save their clients money, particularly when it comes to infrastructure costs related to data centers. No, this isn't your typical move everything to the cloud discussion. We will discuss server and data center consolidation tactics that can have real cost saving benefits to customers.

Highlights:

  • Cost cutting for data centers
  • Sustainability
  • Threat footprint reduction (by having fewer servers)
  • The role of the MSP in helping clients reduce their power footprint

MSP Zone Guest: Justin Current, Sirvis

View Details

While we may accept that remote work is here to stay (at least in some capacity), we must have a discussion around how remote workers should be working. Most of the discussion to date has been around securing the remote worker but little has been spent talking about productivity and communications.

Corey Jones from NUSO joins the MSP Zone for an important discussion around changes which must occur in order for remote workers to become fully equipped and enabled to remain productivity within their organizations.

Highlights:

  • Expanding your workforce
  • Business/operational continuity
  • Maintaining and growing productivity in remote work environments
  • SMS and similar tools for communication

MSP Zone Guest: Corey Jones, NUSO

View Details

According to the US gross domestic product (GDP) numbers we are in a recession. But, that doesn’t mean you have to panic. In fact, if you are an MSP, you might actually have a pretty good economic future, if you take the right steps.

The right steps will depend on your particular situation but there are some fundamentals every MSP ought to consider and prepare for when going into difficult financial and economic times.

Highlights:

  • How leveraged is your MSP practice on break/fix and VAR revenue?
  • What is your revenue sequence?
  • Your recession may be very different from your customers

View Details

Weaver Outrage Meter (WOM): Low

I used to do a lot of M&A work in a previous life…specifically for MSPs. I have some amount of perspective about MSP deals and what markers make for good ones and the characteristics attached to the bad deals.

Recently, M&A activity within the MSP profession has been significant, including record high valuations. As more MSPs are closing deals, the next challenge comes with the integration. Curiously, MSPAlliance has become involved again in M&A, but this time through the lens of MSP Verify and the role of process and controls.

Highlights:

  • Integration planning
  • Controls and process strategy…do you have one?
  • Best advice for MSPs contemplating one or multiple MSP acquisitions

View Details

Kaseya now owns Datto. A purchase which cost them $6.2 billion. The big four are technically the big three, although every indication is that Datto will remain intact in many ways. And Kaseya arguably becomes the largest MSP software platform company in existence. That's a lot of responsibility. 

Fred Voccola, the CEO of Kaseya and the man in charge of leading this MSP platform juggernaut enters the MSP Zone. We talk about a variety of topics related to the Datto acquisition, the future of Kaseya and the MSP market, as well as last year's July 4th cyber incident which has caused a lot of industry chatter. 

Don't miss this episode!

MSP Zone Guest: Fred Voccola, CEO of Kaseya

View Details

While managed services has enjoyed nearly two consecutive decades of strong growth, there have been peaks and valleys along the way. In this episode we examine the current economic climate facing the managed services profession.

Highlights:

  • Demand for managed services
  • MSP health
  • Layoffs
  • Startup investments
  • Private Equity interest in managed services
  • M&A activity

MSP Zone Reading Material:

  • Tech Layoffs: US Startups And Tech Companies With Job Cuts In 2022 (crunchbase.com)
  • Managed Services Market to Reach $393.72 Billion by 2028 | (globenewswire.com)
  • 10 Reasons to Work with a Managed Service Provider for the New School Year - TechBullion
  • https://justthenews.com/nation/economy/startup-funding-plunges-economic-turmoil-continues

View Details

Despite even the best security measures, none of us are immune from the menace of ransomware attacks. 2021 saw not only an increase in attacks, but more evolved ransomware variants that threaten data exfiltration and target MSPs.  

If you want to be prepared, then you need to have a good protection and response plan in place. This session will cover important topics to help you prepare and respond quickly to a ransomware attack to minimize down-time and exposure.

Highlights:

  • Create a cyber incident response plan
  • Security training
  • Backup in your in protection strategy
  • Recovery procedures

David Gugick VP of Product Management

View Details

If you have a dominant amount of your IT management practice coming from break/fix or reactive IT, then you should listen to this episode.

Break/fix vs managed services used to be a business choice amongst IT entrepreneurs. Today, it is less of a choice and more of an imperative. What is the role of the modern day break/fix company? Do these tech firms have a legitimate role to play in combating cyber crime, for example?

We will examine the break/fix provider, in detail, and provide some guidance on what you ought to do if you are still involved in reactive IT management.

Highlights:

  • Impact on profession overall
  • Impact on provider organization
  • Impact on customer
  • Impact on vendors

View Details

MSP software visionary Gavin Garbutt of Augmentt drops into the MSPZone to discuss the opportunity for MSPs to manage hybrid IT environments. Not sure what hybrid IT is? Not to worry. We’ll explain it for you and discuss new revenue opportunities for MSPs.

Highlights:

  • Managing Hybrid IT
  • Shadow IT update
  • Maximizing all of your IT staff
  • Changes to the MSP service desk

MSPZone Special Guest: Gavin Garbutt

View Details

This episode presents a tale of two MSPs. Not actual MSPs, but two types of MSPs as viewed through the lens of two news stories presenting MSPs and how customers view them.

We also examine this tale of two MSPs through the lens of cyber insurance and how insurance companies may be getting it completely wrong when it comes to underwriting and assessing risk in the managed services profession.

Highlights:

  • MSP cyber insurance mistakes
  • How can insurance companies improve their risk portfolio underwriting MSPs
  • Why are there so many contradictory stories written about MSPs?

View Details

WOM: Low

MSPs play a unique role in the acquisition of technology and delivery of managed services to customers. Unlike VARs, MSPs do not always resell a technology to customers. For many MSPs, they acquire licenses from a vendor and use that technology to service customers utilizing a managed services agreement. Between vendors who want maximum predictability of revenue and MSPs who want maximum freedom to use those licenses, there is bound to be friction.

MSP and Microsoft partner Jean Prejean of Guardian Computer is in the MSP Zone this week to discuss her views of software licensing and how it impacts the MSP profession.

Highlights:

  • What is NCE?
  • Does it represent the larger ISV community?
  • What are the term options for MSPs that appeal most to clients?
  • License flexibility for MSPs
  • What changes would you like to see from Microsoft licensing?

MSP Zone Guest: Jean Prejean - president of Guardian Computer

View Details

Episode brought to you by Dell Expert Network

Is backup dead? Short answer is no. But, if you haven't' changed your approach to backup in the last 10 years, you are likely missing a lot of opportunities to help your clients reach their full potential for disaster recovery, cyber attach prevention, and many other business benefits all relating to backing up data.

Join my discussion with Charlie Tomeo as we discuss the history of managed backup, how it has changed, and what MSPs need to be doing to maintain relevancy today as it pertains to their managed backup offerings.

Highlights:

  • Is backup dead?
  • How has backup for MSPs changed over the last 10 years?
  • The impact of business continuity on managed back up
  • What is the future of managed backup?

MSPZone Special Guest: Charlie Tomeo, Chief Revenue Officer at Axcient

View Details

Data is everything. MSPs protect it, customers value it, and cyber criminals want to steal it. But, not all data is the same. Certain data is worthy of more protection and management, and other data has less of a value. In short, data must be managed.

But, to manage data effectively, you need to understand it first. Which brings us to data assessments. Amanda Regnerus of Aparavi enters the MSPZone to share her opinions on the value of data assessments, data managed services, and the role MSPs can play in this area.

Highlights:

  • Why is data growing so fast?
  • What is unstructured data?
  • Should unstructured data be protected?
  • What is the risk of unstructured data being kept?
  • What is a data assessment program?
  • Managed services case studies in performing data assessments

Amanda Regnerus, VP of marketing for the Americas for Aparavi

View Details

Break/fix companies (or companies that provide reactive IT services) must address the security question: both internal security and the security services they provide to customers. Whether it is the struggle to become a proactive managed service provider or just the pace at which security threats and solutions have been evolving, the issue of security is a real element to becoming an MSP and certainly something every break/fix company needs to address.

Michael Crean from Solutions Granted enters the MSP Zone to discuss his perspective on what break/fix providers need to address when it comes to security, both internal and as a service.

Highlights:

  • Why are partners coming to you guys?
  • Do break/fix providers understand their security obligations?
  • Do break/fix providers treat themselves differently than their customers?
  • Don’t give customers an option for cybersecurity

MSPZone Guest: Michael Crean, CEO & Founder - Solutions Granted

View Details

The skills and people gap is impacting everyone, everywhere! Customer organizations already facing staffing shortages have even more difficulties filling IT and cyber related positions. So, how do we solve this problem?

Join Chris Hass and me as we discuss a new, modernized, and distributed workforce and its impact on staffing, security, and productivity. These trends also have had a significant impact on the way cyber criminals view their target landscape and it influences the way they devise their attacks.

Highlights:

  • People & Skills must be addressed
  • Scarcity of people and skills is a benefit to MSPs
  • How to solve this problem

MSPZone Special Guest: Chris Hass - Head of Information Security & IT for Automox

View Details

What is the customer experience within the managed services profession? Our profession talks a lot about service delivery with a predominant focus on the technical. And, for good reason.

However, it is important we not forget the customer experience. We address that issue in this episode. We examine the role of the traditional PSA/ticketing platforms and whether they are sufficient to deliver excellent customer service.

Highlights:

  • What is the role of the PSA?
  • Does the existing PSA solution address the customer experience?
  • What is managed services engagement maturity?
  • What can MSPs do to improve the customer experience within the managed services relationship?

MSPZone Special Guest: Jeff Farris - President & CEO of CloudRadial

View Details

Fighting cybercrime may require policies, procedures, technology, and the know-how to put it all together in a cohesive manner, but the individual also has an important role to play which cannot be discounted. Individual people must be aware of the threats facing them, their organization, and cannot be lulled into a false sense of security just because they have an MSP or an internal IT department. Even the best MSPs need the active participation of the individual to combat cybercrime.

Inky CEO Dave Baggett enters the MSPZone to discuss his thoughts on cybercrime and how MSPs can equip individuals to become more active in this ongoing fight.

Highlights:

  • The role of the individual in cyber defense
  • Educating staff on email threats
  • All organization personnel must be activated and equipped to defend against email attacks
  • Social engineering tactics exploited through email

MSPZone Special Guest: Dave Baggett, CEO & Founder of INKY

View Details

WOM Level: Low

Lots of economic data coming out in recent weeks about signals of an impending recession. Let's really take a look at how a recession might impact MSPs globally and what you may want to do to prepare you practice (and clients) for such an event.

We will also examine the recent CISA guidance for MSPs and offer some analysis on what practicing MSPs need to know about staying safe.

MSPZone Reading Material:

  • https://www.forbes.com/sites/greatspeculations/2022/05/18/cybersecurity-players-should-do-well-despite-economic-headwinds/?sh=6525fa147f9c
  • https://www.darkreading.com/application-security/venture-capital-fund-emerging-cybersecurity-tech
  • https://www.cisa.gov/uscert/ncas/current-activity/2022/05/11/cisa-joins-partners-release-advisory-protecting-msps-and-their

View Details

Cloud computing is one of those terms that gets used a lot, often by people who have no real idea as to what it means. This is understandable given how ubiquitous cloud computing has become over the last decade. While cloud computing has brought technology into the mainstream, it also is a term which needs clarification and definition.

Cloud computing, hybrid, public, private, are all variations on a theme with very different business, technical, and privacy outcomes depending on which one you choose. For MSPs, understanding cloud computing in all its various forms and being able to describe it to customers (many who have no technical experience) is a critical business skill.

Laurelle Roseman, director of channel partnerships at Vultr, drops by the MSPZone to provide her perspective on how cloud computing is helping MSPs meet a growing and increasingly complex set of customer needs.

Highlights:

  • Shift in the partner industry
    • What cloud actually means
    • Partners have to convince people to move over the cloud
    • Trust in cloud computing
  • What is relevant to your MSP practice?
  • Geographical expansion
    • Latency
    • Privacy
    • Peace of mind
    • Why you need more than just AWS – business rational
  • Why it's important to have a multi-cloud strategy
    • It's not an either or situation
    • Customers want options

MSPZone Guest: Laurelle Roseman, Director of Channel Partnerships with Vultr

View Details

There’s a stark contrast to how the threat of Ransomware is perceived by MSPs vs SMBs. MSPs have long understood cyber, business, and IT risks that face their customers. Customers, on the other hand, can have a slightly wider range of experience and understanding when it comes to cyber risks. Why is that?

Join us in this podcast as we uncover the reasons why this discrepancy exists, disclose the precursors of ransomware and discuss solutions.

Highlights:

  • Why do we see so much ransomware?
  • Do MSPs perceive ransomware differently from end-user customers?
  • How do we solve the ransomware issue?

MSPZone Guest: Ricardo VillaDiego, Founder & CEO of Lumu Technologies

View Details

Access management has been a managed service offering for customers for many years. Today, the issue of internal access management has now become mainstream for MSPs of all sizes. How users gain access to internal MSP systems and networks is just as important as it is for managed services customers. But, being secure about your user onboarding and offboarding does not mean you can't also be efficient in your movements.

That's what we discuss on today's episode.

Highlights:

  • Who is Devolutions?
  • What is the current state of MSP internal security?
  • How can MSPs elevate their internal security?
  • Can you be secure and efficient as an MSP?

MSPZone Guest: Maurice Cote - VP Business Solutions with Devolutions

View Details

In today’s connected and security conscious world, customers are looking to MSPs to provide them with backup and recovery services that will help safeguard their organization against ransomware, user errors, and other evolving threats to their business operations and reputation. These same benefits also hold true for the MSPs themselves.

Steve Rodin, CEO of Storagepipe enters the MSPZone and offers his perspectives on a variety of topics.

Highlights:

  • New high-margin monthly recurring revenue streams
  • Data sovereignty/residency
  • The importance of cloud backup
  • Cloud application backup
  • Backup as Business Continuity

Sponsored by Storagepipe: Storagepipe | Cloud, Backup and Disaster Recovery Services Partner Program ( https://storagepipe.com/storagepipe-partner-program/)

View Details

Brian Stoner from Stellar Cyber joins MSPZone to discuss the future of cybersecurity talent within the managed services profession. We discuss the relationship with Boise State, how that connection came to be, and how this could be a template for future cybersecurity talent cultivation all over the world.  

Highlights:  

  • Are we still in a cybersecurity talent drought?
  • Boise State connection
  • The problem with existing cybersecurity talent

MSPZone Guest: Brian Stoner, Stellar Cyber 

View Details

WOM: Low

It does not happen a lot where an approach to selling and marketing managed services can actually apply to a large selection of MSP verticals. But, I think we have one for you today.  

Based on actual conversations with MSPs who are using this approach successfully, and an equal number of MSPs who are not doing it but could benefit from it, I believe this approach will work for the vast number of MSPs throughout the world.  

I am talking about cyber insurance. Specifically, I’m talking about the use of cyber insurance as a conduit for many other managed services offerings.  

Highlights:  

  • Role of MSP cyber insurance
  • 1st Party insurance defined
  • Customer insurance pain points
  • MSPs to the rescue!

View Details

Raffy Marty, the ConnectWise general manager, cybersecurity, drops by the MSPZone to brief us on their latest MSP Threat Report. As the role of RMM vendors becomes more critical to the ongoing security of the global MSP community, companies such as ConnectWise are increasing their efforts to educate and equip their MSP partners with information and technologies.  

Highlights:  

  • 10-15% increase in ransomware incidents by quarter in 2021
  • Evolution of the "super-MSP"
  • Ransomware operator tactics
  • 2022 predictions

MSPZone Reading Material: https://www.connectwise.com/resources/ebook-2022-msp-threat-report 

View Details

In part 2 of our MSP best practices series, we look at the selection of tools during the initial stages of creating an MSP practice. The right tools are critical to your success in delivering managed services.  

Armed with a thorough business plan, selecting the appropriate hardware and software technologies can become easier, although it should still be a process you undertake with a high degree of seriousness.  

Highlights:  

  • MSP tool selection philosophies
  • Questions to ask your MSP tool vendor
  • Integration Considerations

View Details

So you want to become an MSP. Maybe you are already an MSP and just want to get better. The managed services profession is an exciting, vibrant, and important community serving tens of thousands of customer organizations all over the world.  

Being a great MSP takes practice, patience, and a good amount of planning. That’s why we decided to create this series of short, instructional videos to help guide newer MSP organizations navigate the often complicated world of managed services.  

This series will take you through the very early stages of a pre-revenue MSP business model, all the way through some of the more advanced stages of delivering a managed service offering. We hope you find these videos insightful and helpful. 

Enjoy. 

The Business Plan 

Most people don't like to hear this but the very first step you should take when deciding to become an MSP is develop and write a business plan.  

Highlights:  

  • Provides structure for your MSP goals
  • Prevents missteps and waisted resources
  • Eliminates a lot of effort downstream
  • Faster time to market

View Details

Now that we have had some time to digest the news about Kaseya buying Datto, it is time to get the MSP on the street perspective. Travis Springer of Sagiss, joins MSPZone and shares his thoughts on the deal, the likely reaction from MSPs and vendors alike, and ultimately whether the deal will be good, bad, or neutral for the managed services profession.  

Highlights:  

  • Analysis of the deal
  • Why did the deal take place?
  • Will vendor consolidation drive or stifle innovation?
  • How do other MSPs feel about it?
  • What reaction, if any, will this cause from the remaining "big 4" companies?

With guest Travis Springer, Vice President of Sagiss 

View Details

Are we winning or losing the ongoing war against cybercrime? Today's guests have an answer. You may not like the answer, but it does reflect two professional opinions from people who know a lot about the cybersecurity war.  

More importantly, our guests understand what it takes to win that war and the role MSPs will play in achieving that victory.  

Join Scott Augenbaum - Supervisory Special Agent FBI retired, and Corey Munson from PC Matic, as they discuss this important topic.  

Highlights:  

  • We need good technology but it needs to be applied properly.
  • Do MSPs know how to sell security?
  • Are end-users doing enough to participate in their own survival?

View Details

The big 4 become the big 3. Yesterday, Datto announced that it is going to be purchased by Kaseya. The deal has huge potential for the global MSP marketplace and we will analyze what those outcomes might be in this podcast.

What is impressive is to see a company like Kaseya who less than a year ago suffered a significant cyber attack rebound and pull off a deal like this one. There are bound to be questions and speculations about how this acquisition will impact the global MSP market. This is to be expected. The responses, furthermore, won't be limited just to the MSPs, but will include the MSP tool vendors such as ConnectWise and N-able.

Highlights:

  • Reverse IPO?
  • Objective of deal
  • SMB managed services impact
  • ConnectWise & N-able response
  • MSP channel reaction
  • Secondary market reaction

MSPZone Reading Materials:

  • https://investors.datto.com/news/news-details/2022/Datto-to-be-Acquired-by-Kaseya-for-6.2-Billion-with-Funding-Led-by-Insight-Partners/default.aspx
  • https://mspalliance.com/my-thoughts-on-the-kaseya-breach/
  • https://mspalliance.com/private-equity-is-moving-on-the-managed-services-profession/
  • https://mspalliance.com/msp-rmm-vendor-datto-files-for-ipo/
  • https://mspalliance.com/msp-tool-decentralization/

View Details

Mature (i.e., larger sized) managed service organizations often will have a chief compliance officer (or team) dedicate to maintaining proper internal compliance for the company. These compliance individuals play an important role in the company. For smaller MSP organizations, however, having a compliance officer may not be feasible.  

Yet, compliance impacts large and small MSPs alike. So, what should a smaller MSP organization do?  

Highlights:  

  • The role of the modern MSP compliance officer
  • Advice for smaller MSP organizations
  • Team based compliance

Sponsored by: Webroot: https://www.webroot.com/MSPsolutions

View Details

WOM: Low

MSPs have been seeing increases in their cyber insurance premiums for several years now. As cyber threats and attacks continue to increase, paying more to get and maintain cyber insurance has been a reality for MSPs across the globe. But, there is hope.  

One MSP business owner joins MSPZone and talks about his past several years of experience with his insurance broker, his increasing rates, and how he got his MSP cyber insurance premium to actually lower in 2022.  

Join MSP owner Karl Springer of Sagiss as he walks us through the process he used that led to a lowering of his insurance premium and could be a path for many other MSPs to follow.  

Highlights:  

  • MSPCV as a certification is different than SOC 2
  • MSPCV helped Sagiss lower its cyber insurance premium
  • Cyber Insurance for MSPs ought to standardize on MSPCV

Sponsored by Acronis Backup Protection - Cyber Protection Solutions - Acronis

View Details

WOM: Low

I had the opportunity to speak to a lot of MSPs at MSPWorld last week and, as usual, learned a lot. While there were a lot of topics on the agenda, there are always standout issues which seem to take on a life and momentum of their own. That’s exactly what happened this time.  

Here are some of my highlights and takeaways from MSPWorld. 

Highlights: 

  • MSPAlliance Peer Groups
  • Cyber Insurance Update
  • M&A and Growth Update

This episode is sponsored by: Aparavi Data Intelligence Software & Storage Automation Platform (aparavi.com)

View Details

MSPs are not alone in the ongoing fight against cybersecurity. On this episode of MSPZone, we speak with Raffael Marty, general manager, cybersecurity, with ConnectWise.  

Raffael discusses some of the latest announcements from the company concerning Intel, how ConnectWise is helping MSPs face the persistent issue of cyber attacks, and what MSPs need to do in order to remain one step ahead of the cyber underworld.  

MSPZone Reading Material: https://www.connectwise.com/company/press/releases/connectwise-expands-collaboration-with-intel-to-further-strengthen-cybersecurity-for-smbs 

View Details

WOM: Medium

It has been a longstanding issue at the MSPAlliance that we have standards for the MSP profession. While this may have been a philosophical issue early on, it is no longer merely an academic matter. Today, standards matter.  

The UK government is now taking matters into their own hands regarding MSP standards and practices. Why does this matter? Because the UK (and many other governments) are now acting without the benefit of any working knowledge about MSPs, and doing so believing the MSPs have no formalized standard of their own.  

Highlights:  

  • MSPs do have standards
  • Governmental action is legitimate, but be warned not to overreach
  • Do not mistake lack of enforcement for lack of a standard

MSPZone Reading Material: https://www.lexology.com/library/detail.aspx?g=3022e31f-a8d1-4dd1-87d4-e6c10f284b9b 

Sponsored by Nerdio: Nerdio | Microsoft Azure & Virtual Desktop Management (getnerdio.com)

View Details

WOM: Medium

The increase of cyber consultants has produced a lot of confusion and not always positive outcomes. But, there is one positive outcome we can point to: general awareness of cybersecurity issues has become more central to our daily discussion as a society.  

A recent story about misconfiguration of ServiceNow instances is a great example of how cybersecurity and managed services are very close, and yet sometimes quite far apart.  

MSPZone Reading Material: https://threatpost.com/most-servicenow-instances-misconfigured-exposed/178827/?web_view=true 

View Details

Weaver Outrage Meter (WOM): Medium

MSPs have been dealing with scarcity of technical and security talent for many years. The global pandemic and the more recent inflationary pressures have contributed to MSPs paying much higher wages than in previous years. This trend may be coming to an end.  

I don't want to suggest that we are entering a phase of wage deflation, but, it seems to me that we have peaked when it comes to the excesses in hiring MSP and technical talent. Let me explain.  

Highlights: 

  • This has happened before during the dotcom years
  • Offshoring talent - MSPs are looking to new places to source less expensive talent
  • Automation and AI

MSPZone Reading Material: https://www.cio.com/article/306053/us-it-jobs-growth-slowed-in-february.html 

View Details

In the early days of the managed services profession we saw an incredible amount of misinformation about the role of the MSP. In fact, this was one of the chief reasons the MSPAlliance was created, to address and correct that misinformation.  

Today, history seems to be repeating itself. Just like when outsourcing and offshoring were confused with managed services, we are seeing similar confusion and damaging beliefs being shared by a growing number of people around MSPs. Never fear, though. We will break all this down and provide expert analysis.  

Highlights:  

  • MSP Security - separating the real MSPs from the break/fix providers
  • CMMC Security "Experts"
  • Cyber Insurance "Experts"
  • What can we do to fix this? We won't be changing our name

View Details

Weaver Outrage Meter (WOM): Low

The importance of cyber insurance should be obvious to most people today. The fact that cyber insurance coverage is being denied to an increasing number of organizations should be 1) a wake up call and 2) an opportunity for MSPs to have important conversations with their clients.  

There are some simple yet effective techniques you can employ right now to generate new sales and marketing opportunities, all related to cyber insurance.  

Highlights: 

  • Lack of information is a vital aspect driving insurance concerns
  • Misinformation of MSP and break/fix is causing confusion
  • Cyber education is desperately needed

MSPZone Reading Material: https://securityboulevard.com/2022/02/5-reasons-companies-are-denied-cybersecurity-insurance-aria/ 

View Details

WOM (Weaver Outrage Meter): Medium

Aside from the obvious additional "S", the inclusion of security in MSP is both incorrect and misleading. Looking at the historical evolution of the MSP profession, managed security has been baked into managed IT services from the very early days.  

What has changed? MSSPs are now the rage and there is an active campaign taking place to disrupt existing managed services philosophy. We will examine the leading causes behind this MSP vs. MSSP battle, and offer opinions on what normal MSPs ought to be doing today.  

Highlights:  

  • Do normal MSPs avoid security?
  • What is behind the MSSP push?
  • Can general practitioner MSPs become MSSPs? If so, how?
  • Outsourcing your NOC vs Outsourcing your SOC

View Details

If you were paying attention during the early and mid 2000s you heard the phrase, “trusted advisor” used quite extensively. Today, some might have you believe that MSPs have lost that trusted advisor status with their clients. I don’t know if this is true, but it does deserve further investigation.  

Highlights:  

  • Trusted Advisor History
  • Impact of Non-MSP “trusted advisors”
  • How do we solve the trusted advisor dilemma?

View Details

Outrage Level - Low

A really interesting article about a recent study from CrowdStrike. The premise of the article is that while cyber-attacks surged last year, 62% of those attacks did not involve malware. What does this mean? It means that old-fashioned intrusion methods are still very much alive and well today.  

It also means that we should not rely exclusively on malware intrusion defense technologies. Layered approaches to cybersecurity for MSP and customers alike are what is required. MSPs need to adopt and promote technologies to identify and prevent these non-malware intrusions.  

Highlights:

  • “non-malware, hands-on-keyboard activity" still a dangerous reality for MSPs and customers. This means we should not place all our eggs into one basket, namely email defense and scoring.
  • industrial and engineering sectors most targeted
  • “Threat actors continue to exploit vulnerabilities across endpoints and cloud environments, and ramp up innovation on how they use identities and stolen credentials to bypass legacy defenses – all to reach their goal, which is your data,” according to George Kurtz, CrowdStrike's CEO.
  • Recent claims by CISA that moving to the cloud will make us safer, may not be accurate.

MSP Zone Reading Material: https://www.infosecurity-magazine.com/news/threefifths-of-cyberattacks-2021/

This episode is sponsored by VULTR: www.vultr.com

View Details

It's that time of year again…MSPWorld! This episode will focus on all the things that I am excited to see at the upcoming MSPWorld conference. Speakers, sessions, sponsors, and topics I anticipate will be on everyone's mind.  

Highlights:  

  • Overview of sessions
  • Review of this year's sponsors
  • Analysis of MSP topics

This episode is sponsored by PCMatic: PCMatic.com/MSP 

View Details

MSPs and customers alike are instrumental in the global fight against cyber attacks. Nobody can win by themselves; both groups are crucial to winning this fight.  

This episode will explore what lessons we have learned in the past 12 months regarding the global cybersecurity war and what methodologies are being successfully employed to reduce the  attack surface for cyber threats.  

Highlights:  

  • Stopping threats before they cause damage
  • Understanding the source of the attack; similar to even correlation
  • Attack vectors and how they have changed

MSP Zone Guest: Brian Stoner, Stellar Cyber 

This episode is sponsored by ThreatLocker: www.threatlocker.com  

View Details

Cloud computing is not a new topic for MSPs. In 2009-10 our profession had an extensive debate around public cloud computing and its impact on MSPs and their clients. Today, it is time we have another discussion about cloud: the post pandemic cloud options for MSPs and their clients.  

Highlights:  

  • Current cloud situation
  • Supply chain impact on private and hybrid cloud
  • Flexibility for the MSP, customization

With Guest: Shane Zide VP of Global Sales & Channel at Vultr

This episode is sponsored by Nuso: https://nuso.cloud/ 

View Details

The stock continues to be volatile, inflation is impacting large sections of our economy, oil prices are rising, and geo-political events are creating uncertainty. And yet, the managed services market remains strong.  

There are many reasons why investors and customers are continuing to invest in the managed services sector. In today’s episode, we examine the 2022 economic outlook and provide some analysis for MSP owners and managers to help plan for the upcoming year.  

Highlights: 

  • Economic volatility and impact on MSPs
  • Labor market analysis
  • IT and security spending forecast

Episode is sponsored by Redstor: www.redstor.com 

View Details

Cyber insurance has become critically important to our modern business operations. For MSPs, the role of cyber insurance is especially important, both because of the protection it affords the MSP, but also for the protection it offers customers of the MSP.

While cyber insurance carriers struggle to understand the complex world of managed IT services, cloud computing, and IT security, some brokers are taking bold and potentially dangerous steps into the cyber insurance world.

Highlights: 

  • Should you give your customer information over to an insurance carrier or underwriter?
  • What are the legal and business risks associated with giving insurance underwriters access to your clients?
  • Do cyber insurance brokers have a better understanding of IT managed services best practices than the MSPs themselves?

MSP Zone Guest: Rob Scott

View Details

Pennsylvania Senate Bill 726 from the 2021 session has passed. Now what? While this bill is not yet law, it is important to understand what is in this law and how it may impact MSPs, particularly those practicing within the Commonwealth of Pennsylvania.  

Highlights:  

  • Bill overview
  • MSP impact
  • Analysis and comparison to other MSP legislation
  • Impact on future legislation

This episode is sponsored by Solutions Granted: solutionsgranted.com

Email sales@solutionsgranted.com or call 800-619-8481

View Details

The role of automation in managed services is not new, however, it has a rough history. MSPs have always recognized the need to scale their operations but have struggled with how to implement automation in a consistent fashion. 

Besides the obvious benefits automation can bring to the internal operations of the MSP, there are revenue generating opportunities as well. The same automation practices can easily be applied to service offerings to be provided to the customer, managed by the MSP.

Highlights:

  • What is RPA?
  • There are benefits to the MSP, but that's not what we are talking about today
  • Service product ideas for MSPs based on RPA

MSP Zone Guest: Keith Abramson, ElectroNeek

View Details

The United Kingdom and the Commonwealth of Pennsylvania both took steps recently to pass legislation around managed IT service providers (MSP) and cybersecurity. While these actions by themselves are not concerning, underlying assumptions surrounding the role of the MSP in our modern world should be triggering the alarm bells in every MSP operating throughout the world.  

Highlights:  

  • MSPs need to test their internal cyber incident response plans
  • Initiate client cyber response plans
  • Stop taking the blame for poor customer cyber hygiene

MSP Zone Reading Materials:  

  • https://www.computerweekly.com/microscope/news/252512236/MSPs-alerted-to-costs-of-potential-security-regulation-changes
  • https://www.legis.state.pa.us/cfdocs/billInfo/billInfo.cfm?sYear=2021&sInd=0&body=S&type=B&bn=0726
  • https://mspalliance.com/analysis-of-new-msp-registration-law/

This episode is sponsored by Stellar Cyber: Open XDR cybersecurity tools, cloud & network security solutions (stellarcyber.ai).

View Details

Ten years ago, I wrote an article in the Wall Street Journal arguing for a “universal standard” for cloud computing. While a lot has changed in the last decade, the need for standards has not. There are many standards related to Information Technology (IT), but each has its own focus and area of expertise. The same is true for cyber security standards.

View Details

The rise of armchair cybersecurity “experts” has accelerated in recent years. Perhaps the industry most impacted by these armchair cybersecurity experts is managed services.  

As cyberattacks and threats continue to increase, so do the voices from these “amateur” compliance and security individuals who sometimes place unwarranted and dangerous risk on the MSP they use. Risks such as these must be identified and addressed immediately by the MSP if they hope to avoid assuming that risk internally.  

Highlights:  

  • What are the characteristics of an armchair cyber expert?
  • What are the risk impacts to the MSP?
  • Role of contracts in addressing that risk
  • Profile of “risky” clients who pose risk
  • Without the MSP, where would this risk reside?

MSP Zone Guest: Rob Scott 

View Details

The time has come for MSP protection legislation. MSPs safeguard many thousands of industries throughout the world and they need our support. More importantly, MSPs need the support of our legislative community.  

We, at the MSPAlliance, believe that MSP protection legislation will go a long way in fighting the cyber war.  

Highlights:  

  • Distinctions between MSPs and break/fix companies
  • Steps MSPs take today to safeguard their customers
  • Civil and criminal penalties should be applied to attacks on MSPs and their supply chain vendors

View Details

Part of the responsibility of being an MSP is to understand what is being said about your profession. The task of observing how "non-industry" people and organizations talk about MSPs is of particular concern, because it can create negative or even false ideas about how we operate.  

Sometimes, the content comes in a mixed fashion, where it is not all right, but it is also not entirely wrong. This is the case today where we examine an article on the "pros and cons" of using a managed service provider.  

Highlights:  

  • How do tech writers view MSPs?
  • What do they get right?
  • What do they not understand?
  • How can we fix this misunderstanding moving forward?

MSP Zone Show Notes: 

The Pros And Cons Of Investing In Managed IT Services - TFOT (thefutureofthings.com) 

View Details

There are many mistakes you should avoid when selecting your MSP. To be honest, the most critical mistakes will differ depending on who you are, your organizational needs, the type of MSP you are talking to, and a few other factors.  

Nevertheless, there are some fundamentals we can generally apply whenever you are discussing the engagement of an MSP. I came across an article the other day (author unknown) and the title was "5 Mistakes to Avoid When Using Managed IT Services". It's a short article, but it got me thinking about how I would approach an MSP if I was a potential customer.  

Now, there are some very valid points in this article, and there are some which are more debatable. You can come to your own conclusions. In this episode, cover each of the 5 points made by the author and offer my own analysis.  

MSP Zone Reading Material: 5 Mistakes to Avoid When Using Managed IT services - The Open News (openthenews.com) 

View Details

When you are exposed to anything long enough, you will become familiar with that thing. In this case, I'm talking about selling managed services. To say that managed services sales and marketing has been a sticking point for many MSPs globally, would be an understatement.  

Highlights:  

  • Know your customers
  • Sell Through Education
  • Have Defined Products/Services (i.e., Service Catalog)
  • Document the Sales Process
  • Scale
  • Rinse/Repeat

View Details

Is inflation having an impact on the MSP market? As undeniable evidence of inflation is being felt, at least in the United States, it was only a matter of time before someone asked the question: is inflation having an impact on MSPs?  

Highlights:  

  • Inflation evidence in the general market
  • Inflationary impact on MSPs; how would it manifest itself?
  • Should MSPs raise prices? Do MSPs need to raise prices?

Please fill out this survey for MSPAlliance: https://forms.office.com/r/CtgVXCMk5W 

View Details

Data processing is an important element of any managed services agreement. The handling of data belonging to clients has never been more critical to the relationship between customer and MSP. Data processing is no longer just a service delivery issue, it is now a contractual one as well.  

Join the discussion as MSP Zone explores the various ways in which data processing occurs within a managed services relationship, how you can protect your MSP practice from risk associated with data processing compliance requests, and what you shouldn't do when presented with certain data processing agreements.  

Highlights: 

  • What does the client believe you are doing?
  • What are the relevant laws impacting that relationship?
  • What do you need to do in order to be compliant with data processing requirements?
  • Signing a document is not the end of the issue
  • Data processing compliance through MSP Verify

MSP Zone Guest: Rob Scott 

View Details

Not a month goes by without some analyst firm or consulting agency producing a managed services spending report. You would think, with all these reports forecasting future managed services spending and growth, that there would be an abundance of data for MSPs and consumers. You would be wrong.  

The existence of these "managed services analyst reports" provide little to no value whatsoever to the average MSP, much less to consumers of managed services.  

Highlights:  

  • Historical review of analyst coverage of the managed services profession
  • Current coverage of MSPs
  • What are the gaps?

MSP Zone Reading Material 

Managed Services Providers (MSP) Market Is Likely to Experience a Tremendous Growth in Near Future - Energy Siren 

View Details

MSPs spend a lot of time "in the channel", that is to say, learning from and interacting with both other providers and technology vendors. Yes, MSPs also spend a great deal of time with their clients. But, what I'm talking about today is how non-managed services entities and individuals view the MSP profession.  

As with many things "managed services related", there are a lot of misconceptions about MSPs and what they do. It seems we can add cybersecurity "experts" to that list.  

Highlights:  

  • Common misconceptions about MSPs
  • Cybersecurity perspectives on the managed services landscape
  • How to correct these negative view

Alleged Russian Hacks of Microsoft Service Providers Highlight Cybersecurity Deficiencies (voanews.com) 

View Details

In a follow up to our episode titled "Who are Hackers Really Targeting?", we have further evidence that it is not MSPs who are vulnerable to attack, but instead, the non-MSP organization has a higher likelihood of being successfully breached in a cyberattack compared to an MSP.  

This is not to say MSPs do not get targeted or breached. This does mean, however, that successful cyberattacks are more likely to occur in a non-MSP organization than a fully matured managed services entity.  

Highlights:  

Remote access systems  

MSP vs non-MSP risk 

Differentiating between MSPs and non-MSPs…why it matters 

View Details

MSPs have agreements with everyone; customers, vendors, partners. The managed services agreement with customers, perhaps, is the most important. Regardless of the type of MSP you are, the types of services, or your customers, the contracts you use will likely be negotiated.  

Warranties and indemnification clauses are common boilerplate in modern managed services agreements. But, not all such clauses ought to be accepted without review and consideration.  

Highlights:  

  • What are limitation of liabilities?
  • Indemnification clauses
    • By Provider
    • By Client
  • Limitation of Liability Carveouts

Email MSPZone@mspalliance.com to acquire your copy of the 3rd party disclosure addendum.  

MSP Zone Guest: Rob Scott 

View Details

Fact: Ransomware "gangs" are actively trying to attack organizations of all sizes. The attacks have had some success and will likely continue for the foreseeable future. But, are the attack vectors really targeting MSPs, or is there another target that exists?  

Highlights:  

  • Who are the real targets of these ransomware attacks?
  • Why are these tactics being used?
  • Can anything be done to stop them?
  • Is the MSP the real attack vector?

MSP Zone Reading Material 

Solarwinds hackers targeting global IT supply chain,  Microsoft says (cnbc.com) 

View Details

Pandemic related supply chain disruptions are happening on a global basis. Since the beginning of the pandemic, everyday items have become subject to distribution disruption. These supply chain disruptions are also having an impact on value added resellers. Could supply chain problems signal a business shift for VARs towards managed services?  

Highlights:  

  • VAR supply chain disruption
  • Impact on VAR business model
  • Impact on managed services

MSP Zone Reading Material: The Value Of VARs Is Diminishing In Cybersecu rity: Here’s How To Get It Back (forbes.com) 

View Details

It seems there is never a shortage of M&A related chatter within the IT channel and we appear to be in the middle of one such rumor mill once again. In fairness, this may be part rumor and part misconception (probably more the latter).  

Is there an M&A consolidation frenzy taking place in the MSP profession? We will examine that question.  

Highlights:  

MSP Zone Show Notes: Private equity is ready to take MSP consolidation to the next level | TechCrunch 

View Details

MSPs have agreements with everyone; customers, vendors, partners. The managed services agreement with customers, perhaps, is the most important. Regardless of the type of MSP you are, the types of services, or your customers, the contracts you use will likely be negotiated.  

The terms you negotiate with customers matter, and sometimes there are ways you can arrive at terms which are mutual beneficial to both MSP and customer.  

Highlights:  

  • Term & Renewal
  • Termination
  • Termination for Convenience
  • Termination for Cause

MSP Zone Guest: Rob Scott 

View Details

Too often we think only of technology as that which will save us from cyber security threats. Yet, there is an even more powerful resource in the fight against cybercrime…people.  

The human element is where the majority of email borne attacks are being focused. Are we doing enough to help those users fight what is aimed at them?  

Highlights:  

  • Cybersecurity attacks have become more prevalent and more sophisticated, and organizations of all sizes and industries are being targeted.
  • Phishing emails look so real these days – end users are clicking despite organizations best efforts to educate and train.
  • The costs to organizations – those clicks open the door to ransomware among other attacks.  Costs to businesses go far beyond paying the ransom.  Downtime, damaged reputations, and lost customers add up.
  • Traditional email security measures are no longer enough.
  • What MSPs should consider for next generation email security protection.

MSP Zone Guest: Dave Baggett, CEO of Inky 

View Details

A few episodes ago we discussed the challenges cyber insurance carriers are having identifying and categorizing risk. This has been evidenced in difficulties MSPs (and their customers) have been experiencing in obtaining and renewing cyber coverage.  

A recent article in Crain's lends further evidence of this  issue. But, is it a lack of cybersecurity standard we face, or is it lack of enforcement and adoption of a standard?  

Highlights:  

  • Current Cyber Standards
  • MSP vs End-User Standards
  • Enforcement of Cyber Standards

MSP Zone Reading Material: Insurance carriers scrutinize cybersecurity controls | Crain's Cleveland Business (crainscleveland.com) 

View Details

Insurance is one of those topics often misunderstood by many, and yet has an undeniable impact on many industries. The common belief is that MSPs have been the more risky bets for cyber insurance carriers but that may not be true. In fact, the problem of cyber insurance coverage, best practices, and underwriting, may be far more serious that we realize.  

Highlights:  

  • What is the cyber insurance problem we face?
  • Which industries are impacted?
  • Are MSPs the cause or the solution?

MSP Zone Reading Material: Ransomware Has Been a ‘Game Changer’ for Cyber Insurance (insurancejournal.com) 

View Details

MSPs looking to acquire other MSPs are everywhere. MSP buyers have always existed and will always exist. Having seen what works and what doesn't, I thought it would be helpful to discuss a few commonly employed buyer tactics I believe a) don't work, and b) actually may work contrary to your organization's best interests.  

Highlights: 

  • What are MSP buyers looking for?
  • Buyer outreach tactics currently used
    • Randomized outreach
    • No personalization
    • Commodity approach to M&A
  • Advice for how to reach
    • Make it personal
    • Develop relationships
    • Communicate, don't solicit
    • Sell your yourself, not the other MSP

View Details

The Information Technology industry has long suffered from nearly constant changing of names and the introduction of new names to replace old ones. Whether this is a successful rebranding technique developed by analyst and marketing firms, I'll leave that for another time.  

What is clear to me, however, is that repeatedly changing terms and definitions can have a detrimental effect on a profession. Is Cybersecurity as a Service a new gimmick, or merely an old service being wrapped in new packaging?  

Highlights: 

  • What is Cybersecurity as a Service?
  • Does it differ from managed services?
  • Who is driving this naming convention?

MSP Zone Reading Material: Cyber Security As A Service Market Present Scenario, Key Vendors, Industry Share and Growth Forecast up to 2027 | Virtual-Strategy Magazine 

View Details

It has been several years since GDPR went into effect and it has had an impact on MSPs and clients alike. Today, many more laws are being and have been enacted that aim to copy what GDPR has accomplished, in large part, to combat the rise in ransomware attacks.  

Highlights:  

  • Impact of GDPR on MSPs
  • Differences between GDPR and MSP supply chain vendor policies
  • Which approach protects the MSP and the client most?

MSP Zone Guest: Rob Scott 

View Details

It was going to happen eventually after the UK left the European Union. The UK is deliberating on whether GDPR will remain as a central theme in data privacy and security for UK citizens. This decision asks the larger question of what could replace GDPR as a privacy and security framework for the country.  

Highlights: 

  • What does it mean if the UK does abandon the principles of GDPR?
  • What would the UK use instead?
  • Suggestions for the UK policy makers

UK To Consult On Weakening Data Protection Laws (forbes.com) 

Big Tech cloud services could face resilience test, says Bank of England | Reuters 

View Details

For 25 years MSPs have been attempting to communicate why they are necessary to their clients. For existing managed services customers, this value makes sense since they already know what they are receiving.  

However, in the age of cybersecurity threats and ransomware, the value of the MSP (or MSSP) should be even more simple and powerful to identify. If this is the case, why do articles like this exist?  

Highlights:  

  • Outsourcing vs Managed Services, Again
  • MSP vs MSSP
  • Failing to Address Internal Client Risks is the Problem!

MSP Zone Materials: 6 risk factors customers assess when hiring an MSSP - Channel Asia 

View Details

Ransomware is a problem for everyone. MSPs fight every day to keep their clients safe from ransomware, and yet, we must plan for the worst case scenario.  

MSPs need to address ransomware with their clients, and one of the best places to do this is through the managed services agreement. This episode will help MSPs understand the best practices for including ransomware clauses within their agreements, as well as how to do this fairly so it protects both the client and the MSP.  

Highlights:  

  • What mention of ransomware should be in your agreements?
  • What changed before and after recent cyber attacks?
  • Third party ransomware scenarios
  • Exclusions from vendors

MSP Zone Guest: Rob Scott 

View Details

CISA published their advisory bulletin addressing risk considerations for organizations thinking about using managed service providers. This is a great advisory, but it has some areas of potential misinterpretation in it, chiefly because CISA has departed from a security group and expanded into territory in which it has little experience.  

Highlights:  

  • What if organizations stopped using MSPs?
  • Yes, all customers ought to be responsible and consider risks of outsourcing. But, risks of not managing IT are far greater than the risks of outsourcing
  • Targeting of managed services supply chain vendors is NOT a symptom of poor MSP security, it's a symptom of the unchecked business of cybercrime

MSP Zone Reading Material: Risk Considerations for MSP Customers | CISA 

View Details

It is a question we used to get often during the early days of managed services. Particularly, when organizations did not fully understand the requirements of owning IT infrastructure. To be sure, cyber threats, the complexities of managing IT, and the overall reliance on IT for business operations was must different back then compared to today.  

Today, however, it may seem odd to ask the question "do we need managed services?" Perhaps a different question would be more appropriate "can you survive without managed services?" 

Highlights:  

  • Vendor management
  • Cyber Threats
  • Scarcity of people, technology, and process

MSP Zone Reading Materials: 

https://www.ilounge.com/articles/why-do-modern-businesses-need-managed-it-services-today 

View Details

There has been a lot of discussion concerning the MSP regulation our profession should have. Standards for MSPs, cyber practices to reduce the number of cyberattacks, etc.  

Instead, I’d like to turn the conversation into the type of legislation MSPs actually need. There are laws that would make the job of the MSP (and the benefits they provide to clients), more accessible. Those are the laws that should be enacted, not laws that make being an MSP more difficult.  

Highlights  

  • Pass laws that make being an MSP easier, not more difficult
  • Alignment of MSP and customer goals
  • Shrink the chasm between MSP practices and client behavior
  • Education of the role managed services has in the global market

View Details

How should your managed services catalog change, if at all, when delivering your offerings in the cloud? How can you use your updated services catalog to improve your sales and service delivery process, along with reduce your overall MSP risk?  

Highlights 

What is a service catalog? 

Does the catalog change with cloud service offerings? 

How does the service catalog interact with the service agreement? 

MSP Zone Special Guest: Rob Scott 

View Details

Every MSP needs to have an important conversation with their clients about cyberattacks and ransomware. These conversations don't have to be difficult, but they have to happen. Here are my thoughts about how you should approach this discussion and how you can use it to change the relationship you have with your customers. Who knows, they may even thank you for it. 

Highlights:  

  • There is no right time to have it, just make it happen
  • Don't avoid the news
  • Talk about your expectations for their cybersecurity
  • Tell them how you are protecting your MSP practice
  • Practice business disruption scenarios with them

View Details

In the aftermath of recent ransomware attacks on software companies used by MSPs, the question of how do we respond as a community is, and should, be asked. Some believe that more legislation is the answer. Maybe they are right. But, it would be a grave mistake for any legislation directly involving MSPs to be undertaken without first understanding what measures already exist to protect MSP and clients alike.  

MSPs are responding to the ransomware epidemic. Here's how.  

Highlights: 

  • MSP Verify
  • Leadership council
  • Insurance
  • Vendor certification

View Details

"Secretive" cloud providers have a problem. So do the MSPs who use these cloud providers. Fixing the issue of secrecy and lack of transparency is important to the non-IT world and we must address it now.  

Highlights:  

  • Cloud vs MSP Transparency
  • SaaS & Vendor Transparency
  • Applying Existing Standards

Bank of England to crack down on 'secretive' cloud computing services | Reuters 

View Details

What's the difference between internal IT departments and managed service providers? There are some important distinctions which define the relationships between internal IT and the external MSP. Understanding those differences can improve how both interact with one another. 

Highlights: 

  • MSPs have to face a more diverse set of users, ecosystems, and threats. This diversity makes the MSP a far more knowledgeable organization than the vast majority of companies (even those with an internal it department)
  • Access to Tools – MSPs, by necessity, use a variety of tools not typically seen in the internal IT department. These tools typically associate themselves with scalable, one-to-many styles of service
  • Experimentation. MSPs see things on a more expansive scale than internal IT departments.

View Details

It was almost an inevitability that MSPs would begin to rethink their procurement of managed services enabling tools in the wake of the Kaseya ransomware attack. Sure enough, we are starting to hear from MSPs telling us that they are reversing their previous strategy of consolidating tools around big four MSP tool platforms.  

Highlights:  

  • Should MSPs decentralize?
  • How will this impact the MSP market?
  • What advice do we have for MSP platform vendors?

View Details

What's an MSP? What is an MSSP? What is a SOC? These terms are common throughout the managed services community but often have overlap and can cause confusion. We will explore these terms and examine how they often present themselves in everyday business scenarios.  

Highlights:  

  • Defining MSP, MSSP, and SOC (including SOCaaS)
  • Business characteristics of each
  • Common overlaps

View Details

To all of you bloggers out there with aspirations of becoming an "expert" in managed services and providing MSPs with advice on how to respond to the Kaseya ransomware attack, this podcast is for you!  

View Details

An interview with Rob Scott about the legal, political, and business impact of the Kaseya ransomware attack. 

Highlights: 

  • Breach requirements for MSPs
  • Role of insurance
  • The sequence of steps taken by MSPs post-breach
  • Dealing with vendor contract limitations
  • Is this a gross negligence situation?

MSP Zone guest: Rob Scott  

View Details

My random thoughts on the Kaseya breach and how the managed services profession will ultimately respond. 

Highlights: 

  • Don't Panic!
  • How will this impact the managed services profession?

    • MSPs
    • Customers
    • Vendors
    • Legislators
  • There will be an industry response

  • This event will change the nature of how we look at the roles and responsibilities within the managed services profession. It will also influence change in how we contract and insure the several parties within the managed services ecosystem

View Details

MSPs face many realities when it comes to the management of customer IT environments. Shadow IT is a reality amongst many corporate organizations and very little is known about it or how pervasive it really is. But, there are steps MSPs can take to bring shadow IT under control and manage it more effectively, on behalf of their managed services customers.

Highlights:

  • The biggest problems caused by Shadow IT
  • Securing your client’s environment when the perimeter no longer exists
  • SaaS management opportunities for MSPs?
  • Where does SaaS Management fit on the MSP maturity curve?

MSP Zone Guest: Derik Belair, Augmentt 

View Details

Louisiana may have been the first State to pass an MSP law, but it certainly won't be the last. Four other states, including North Carolina, Pennsylvania, New York, and Texas, all have bills that deal with ransomware payments, and even some specifically mentioning MSPs.  

Highlights: 

NY Law - NY State Senate Bill S6806A (nysenate.gov) 

NC Law - House Bill 813 (2021-2022 Session) - North Carolina General Assembly (ncleg.gov) 

TX Law - TX HB3892 | 2021-2022 | 87th Legislature | LegiScan 

PA Law - Bill Information - Senate Bill 726; Regular Session 2021-2022 - PA General Assembly (state.pa.us) 

MSP Analysis 

View Details

Whether they are called SLAs or service guarantees, the concept of outcome-based terms within a contract is not new for MSPs. Whether MSPs should still continue to use guarantees within their service agreements today, that is a different question.  

View Details

Will cybersecurity resellers have an impact on managed service providers? Like the value-added resellers of yesterday, these upgraded VARs are making a splash by capitalizing on cybersecurity. But, what is it they are really offering? Are they delivering any services themselves?  

Highlights:  

Traditional VARs vs. Cybersecurity Resellers 

Are these cybersecurity resellers offering any managed services?  

What can MSPs do to differentiate themselves?  

View Details

Besides the obvious answers to this question, such as profit margin, ability to scale, efficiency, and higher customer satisfaction, one of the biggest differentiators between MSPs (proactive) and reactive or break/fix providers, is their view of data privacy and security. 

Summary 

  • Data breach requirements
  • Monitoring & Management
  • Cybersecurity controls

View Details

Pricing your managed services offerings has been a longstanding debate within the MSP community. When certain types of customers present more lucrative targeting from cybercriminals, perhaps it is time to revisit pricing techniques for MSPs and their more high-profile clients.

Summary:

  • Risk-Based Pricing Review
  • MSP internal risk assessments; should they involve clients?
  • Insurance, best practices, and legal agreements all impact your pricing and risk

View Details

There are many reasons why you should have a managed services portfolio. Some call it a service catalog, others a service offering. Whatever you call it, the importance of having it within our managed services practice is crucial and can have many long-term impacts throughout your business.

Summary: 

Why is a service catalog important?

Managed Services are not consulting services 

Precise service offerings are easier to communicate in a service agreement 

View Details

Documentation has many benefits within a managed services practice. But, it also can be incredibly important for compliance. Here are some best practices MSPs of all sizes can adopt and implement.

View Details

The decision to change from a break/fix or reactive IT company into a proactive or managed services company is not an easy one, nor should it be undertaken lightly. Being an MSP is a commitment to your clients, and doing things in a very different way. Here are some considerations to help you in your decision-making process.

Summary: Why do you want to be an MSP? Do clients have anything to do with this change? Do you understand what is required of you? It's more than just buying the right software Be in it to win!

View Details

Insurance for your MSP practice has never been more important. What types of insurance should you get? What insurance will protect you versus your client?

View Details

Is there a race to the bottom within the managed services profession? Commodity pressures, competition, these elements have always been with us but they do not mean that we are throwing away our services at rock bottom prices because the race to the bottom is inevitable. 

Show notes: https://rcpmag.com/blogs/the-evolving-msp/2020/12/for-msps-where-to-from-here.aspx

View Details

Many MSPs are so tightly fused with their clients' business and technology needs that it can difficult to separate the two. This is understandable given the high level of trust clients place in their MSPs. But, there is a difference between relying on your MSP to assist you with your compliance needs and transferring your compliance obligations to your MSP.

Summary:

  • MSP vs Client Compliance
  • Some things you can't transfer
  • Consulting vs involvement

View Details

Much has been made of the "single pane of glass" functionality of the major MSP platform companies. A single place from which the MSP can perform much of their work. And yet, as MSPs continue to have more options when it comes to MSP tools, is the single pane of glass concept ending?

Highlights:

  • Big Vendors Have More Risk of "non-performance" from their security tools
  • MSPs are Starting to Hold MSP Platforms Accountable for their Security Performance
  • MSPs are taking a more "best of breed" approach to their toolsets

View Details

MSPs often outsource SOC, SIEM, and other security-related services to their vendors, including some of the larger MSP platform companies. But, what happens when those vendors miss something? Does the MSP have any liability to the client? What can the MSP do to protect themselves?

Highlights: Do MSPs need security SLAs from their vendors? What do MSP platform company contracts say? Public Policy issues with limitation of liability clauses

MSP Zone Guest: Rob Scott, Scott & Scott LLP

View Details

Are you considering the MSP Verify certification? If so, here are some practice insights into how you should approach the process and how to maximize the value.

Highlights:

  • Why did you choose to go through the MSP Verify?
  • How are managed services clients responding to your certification?
  • What advice would you give to MSPs considering MSP Verify?

MSP Zone Guest: Karl Springer, Sagiss

View Details

Most of our attention has been on the big 4 MSP platforms. But, are we ignoring the growing army of MSP RMM, ticketing, and point solution tools being developed on a regular basis? The big 4 might want to pay attention to this.

View Details

MSPs don't get a lot of attention, don't have many articles written about that, and yet perform a critical role in our global economy that cannot be overlooked. It's time we pay attention to the small MSP! 

View Details

For 21 years, I've been anticipating a day when MSPs are recognized as the indispensable guardians of data privacy and security that they are. With that recognition comes responsibility, and responsibility will continue to arrive in the form of government regulation of MSPs in a particular way.

View Details

Can a managed services customer impact your ability to be compliant? An interesting question, and one that is on the minds of many MSPs. The question can be expanded also to include whether clients can add risk to the MSP. 

View Details

Cyber insurance claims are becoming a part of everyday life, both for MSPs and customers. There are, however, some best practices you can adopt to make your managed services practice a little easier when it comes to understanding cybersecurity insurance policies, how they work, and what do to when you may have a claim.

View Details

Virtual desktops are not a new concept for MSPs, but it may be time to revisit this technology as a model for managing current challenges. 

View Details

The DOJ is stepping up its fight against ransomware. How will this impact your MSP practice?

View Details

MSPs are at risk of losing their cyber liability insurance coverage. Insurance companies want greater assurance from MSPs

Key Points:

  • MSPs need to prove what they are doing, not just claim they do it
  • What are cyber insurance carriers really looking for from MSPs?
  • How to lower your cyber rates for your MSP practice

View Details

MSPs are going through interesting times, particularly when it comes to their relationship with vendors. If you are an MSP (new or old) and need some advice on how to negotiate with your vendors, you've come to the right place. 

View Details

Do we put too much trust in MSPs? Where else will you put your trust? These are important questions to ask, but the answers must be arrived at deliberately and with accurate information.

View Details

In the wake of recent US Federal government data breaches, there is a rumor of an executive order that could have a huge impact on the MSP sector. We will examine what these new proposed rules could mean for your MSP practice in today's MSP Zone.

View Details

Private labeling (or white labeling) solutions as an MSP is not a new concept. It has been in practice for many years. And yet, with all the changes in privacy and security disclosures in recent years, it begs the question of whether white labeling is still something MSPs ought to do. 

Program Highlights: 

  • Is white labeling still relevant today?
  • Ability to disclaim white labeled products/services
  • How to fully disclose the use of third-party solutions?

MSP Zone Guest: Rob Scott

View Details

What are the key areas of security focus for remote workers? We will discuss 4 key attack vectors MSPs should be considering when developing a managed security offering. 

View Details

More companies are entering the Cybersecurity insurance business and realizing how important MSPs are to that model. What does this mean for MSPs? We’ll discuss on today’s MSPZone.

View Details

Is the professional managed services market contracting? We will address this question on today’s MSP Zone.

View Details

There are 3 steps MSPs can take to help clients reduce their risk of ransomware. Put slightly differently, here are 3 things you can do to avoid bailing your customer out of a ransomware situation that was not your fault!

Episode Highlights:

  • Cyber liability insurance (for both your MSP practice AND your client)
  • Revised Managed Services Agreements
  • Updated managed services offerings and internal practices

View Details

SolarWinds MSP changes name to N-able. What does this mean for the MSP community? We’ll discuss on today’s MSP Zone. 

Show Notes: www.n-able.com

View Details

If you are an MSP in the European Union you are probably familiar with the term DPO, or data protection officer. DPOs are required under GDPR and are responsible for the protection of consumer data while in the custody of the company. 

  • Episode Highlights:
  • Should MSPs start creating DPO roles?
  • When is the right time to hire a DPO?
  • What are the responsibilities of a DPO?

https://edps.europa.eu/data-protection/data-protection/reference-library/data-protection-officer-dpo_en

View Details

Cybersecurity has become a big business. And, it's getting bigger every day. Much has been made about the transition from MSP to MSSP, and cybersecurity consulting firms are cashing in on this business shift.

Here are some random thoughts about cybersecurity consulting firms, what value they really are providing, and how MSPs ought to be viewing them in order to deliver the best possible managed services offerings to their customers.

View Details

Recent cyberattacks involving vendor technologies could be creating more risk for managed services customers. Are these attacks setting clients on a collision course with technology vendors (not MSPs)? We will discuss on today's MSP Zone. 

  • MSPs need to disclaim liability (in their customer contracts) for downstream vendors
  • All systems are vulnerable. MSPs can’t indemnify them against all risks
  • Make customers deal directly with vendors, allowing MSP to avoid taking on risk from the vendor
  • SPLA vs EULA
  • Is Microsoft the model to follow?

MSP Zone Guest: Rob Scott, Scott & Scott, LLP

View Details

Datto releases 2020 financial results, and could this be the end of manual help desk practices? We will review these news stories and provide our commentary on today's episode. 

View Details

Chip manufacturer Intel has been serving the IT channel for decades. Today, Intel is heading in a new direction and it could have significant implications for the MSP and their customers.

Episode Highlights

  • Post-Pandemic Work Environment
  • What are the best tools for communication & collaboration?
  • Role of the MSP in managing these tools

MSP Zone Guest: Brian Cockrell, Intel

View Details

MSPs are facing increased pressure by some vendors who are requiring minimum recurring revenue levels in order to add new services, such as security. What will this mean for your MSP practice? We will discuss on today’s episode. 

View Details

MSPs serving the healthcare sector have played a unique and important role in the last year. Frontline medical staff have helped lead the charge against a global pandemic. What challenges have MSPs serving this sector experienced? How have they overcome those challenges? We talk with an MSP who shares their stories around managing IT for healthcare clients and what it takes to be successful in that vertical market. 

MSP Zone Guest: Bryan Fuller, Contigo Technology

View Details

MSPs have maturity journeys they take, often starting as highly manual, reactive companies, but moving towards greater efficiency, automation, and profitability. The same is true with compliance. MSPs need to have a charted path towards compliance, regardless of where they are on the path. If you don't know where you are, you're at the beginning. Let's get you started down your compliance journey.

View Details

MSP platform company Kaseya, just announced that it has acquired RocketCyber, an MSP that provides Security Operations Center (SOC) services to MSPs. 

View Details

People used to ask (they still do) what is an MSP. Typically, they'd follow up with another question, how do you define managed services? These questions are still relevant today but for slightly different reasons. 

This Episode sponsored by Avast

View Details

What obligations do MSPs have when they learn of a data breach within one of their supply chain vendors? Does such a breach automatically mean the MSP needs to issue a notification? Perhaps not. This episode will discuss this topic and provide MSPs with some valuable analysis and helpful insights.

MSP Zone Guest: Rob Scott, Scott & Scott, LLP

View Details

What was the sunburst attack and how can MSPs protect themselves against in the future? That’s what we’ll be discussing in today’s episode. 

MSP Zone Guest: Brian Stoner, Stellar Cyber

View Details

It's easy to think of MSPs only as providers of an IT service, but what about IT controls? Should MSPs help their clients in creating and implementing IT controls as part of a managed services relationship? The short answer is yes, probably.

View Details

2021 looks like it will be a lot better than 2020, especially when it comes to IT spending. But, if you are an MSP and want to safeguard your practice against future risks, there are some things you should consider as you begin implementing your 2021 business plan.

View Details

Can you save money by moving to the public cloud? Of course, you can. Well, maybe. The answer really depends. What started as a response to the 2009 global financial crisis should not be generally applied to all scenarios where on-premise infrastructure is placed into the public cloud. There are always exceptions and best practices. 

MSP Zone Guest: Christopher Church, Mainstream Technologies

View Details

Does the MSP business model you are operating under still make sense? Is it still relevant to your clients?

MSP Zone Guest: Rob Scott, Scott & Scott LLP

View Details

2020 is in the past. But, work from home may be a permanent change left from the global pandemic. How will work from home continue to evolve into 2021 and how should MSPs approach this change? 

MSP Zone Guest: Nick Emanuel - Webroot, an OpenText Company

View Details

Bad people know the generally applied practices for IT management. As such, managed services delivery procedures should be consistently reviewed. These best practices can help your MSP practice become more secure and transfer that security to your clients.

View Details

DNS over HTTPS is here. What is it? This episode of MSP Zone will discuss DoH, the threats it is attempting to solve, and how MSPs can use it in their managed services offerings. 

Program Highlights:

  • What is DoH?
  • When will this change happen?
  • What are the advantages?
  • What is there to worry about?
  • What do my clients need to know?
  • How does DNS Protection work with DoH?

MSP Zone Guest: Jonathan Barnett, Product Manager, Webroot, an OpenText Company

View Details

Patching isn’t just a process every MSP should be doing. Patching is an essential component to keeping client systems safe and secure, and operational.

MSP Zone Guest: Shane Cooper, Webroot, an OpenText company

View Details

What is ZTNA? As MSPs face increasing challenges in protecting their clients against global cyber threats, new ways of defense are needed. Could ZTNA be an effective new tool for MSPs? We will discuss. 

Program Highlights

  • Applicability to public and private clouds
  • How is it to manage?
  • Best Practices for MSPs

MSP Zone Guest: Robert Krug, AVAST

View Details

The supply chain in managed services involves numerous technology relationships with external parties. This is a normal practice. There are, however, some easy and necessary steps every MSP ought to take when reviewing their supply chain partners and making decisions that ultimately affect risk and profitability. 

MSP Zone Guest: Rob Scott, Scott & Scott LLP

View Details

Managing any object (as a managed service) requires skill. But, beyond mere expertise, there are several critical characteristics that can really make your private cloud managed services offering take off in 2021. 

Here are 4 fundamental process changes your MSP practice can implement in 2021 to improve your private cloud offering. 

  • Automating the back-office workflow
  • Offering a self-service portal that can be accessed by both end-customers and the internal help desk
  • Automating service fulfillment to allow for efficiency in provisioning
  • Offering flexible pricing and resource consumption just like the public cloud hyperscalers

MSP Zone Guest: Alan Zurakowski, HyAlto

View Details

2020 will be a historic year, not just because we had a global pandemic. The managed services profession achieved some significant milestones this year. We will examine a few of the highlights in this year-end review of 2020. 

  • MSPs Rose to the Challenge in 2020
  • The pandemic caused a major separation between professional MSPs and other IT providers
  • Regulation of IT is now upon us
  • Managed services contracts went through some changes this year. Terms, risk strategies, even negotiating tactics
  • Cyber Attacks - both against MSPs and clients
  • Changes in ransomware payment policy
  • IT labor uncertainties created new opportunities for MSPs

MSP Zone Guest: Rob Scott, Scott & Scott, LLP

View Details

MSP regulation is upon us. But, could there be unintended consequences not foreseen by the regulators and legislators passing such laws? Today, we talk to a Louisiana based MSP to get his thoughts on what impact MSP regulation may have on managed service providers. 

Landon Futch - Essential Solutions, LLC

  • Will the laws & regulations actually make MSPs and their clients safer?
  • Is MSP regulation an excuse for poor client cyber hygiene?
  • Will new security laws force better IT security behavior amongst clients?
  • Will the law impact both governmental and private customers?