EP170 – The Reality of Securing Your MSP in 2024 with Keith Hayes and Ian Luckett

IT Experts Podcast - The MSP Growth Hub - MSP - Keith Hayes - Podcast Episode 170 - UK - WordPress

Click below to listen to the episode

In this episode of the IT Experts Podcast, we are joined by expert Keith Hayes as he brings a wealth of knowledge and experience to the table, offering valuable insights into how MSPs can bolster their security measures and ensure their clients’ systems are robustly protected. 
 

One key takeaway from our conversation with Keith is the importance of taking a proactive approach to security rather than simply relying on reactive measures. Keith emphasises the need for regular checking and monitoring, stressing that security should be someone’s whole responsibility within the MSP team. By implementing thorough ticket triage and actively protecting against potential threats, MSPs can instil confidence in their clients and demonstrate their commitment to safeguarding their systems. 

 

Change control emerges as a fundamental aspect of maintaining security within an MSP environment, according to Keith. Understanding what changes are being made and ensuring they align with regulatory compliance is crucial for mitigating risks and avoiding potential litigation. By establishing robust change control procedures, MSPs can minimise the likelihood of security breaches and protect both their own business and their clients’. 

 

Moreover, Keith highlights the importance of access control in securing MSP environments. With MSPs being lucrative targets for cyberattacks due to the potential access they hold to multiple clients’ systems, it’s essential to tighten access controls and implement multi-factor authentication measures. By prioritising access control, MSPs can significantly reduce the risk of unauthorised access and mitigate the impact of potential security breaches. 

 

During our discussion, Keith also stresses the significance of regular audits and assessments to ensure that internal processes are functioning effectively. By conducting random audits and scrutinising key metrics such as admin account activity and patching success rates, MSPs can identify potential vulnerabilities and address them proactively. This proactive approach not only enhances security but also instils confidence in clients by demonstrating a commitment to ongoing improvement and vigilance. 

 

Furthermore, Keith advocates for a risk-based approach to client communication and service delivery. By engaging in conversations about clients’ business objectives and critical processes, MSPs can tailor their services to meet specific needs and priorities. By aligning service offerings with clients’ recovery time objectives (RTO) and recovery point objectives (RPO), MSPs can provide targeted solutions that address clients’ most pressing concerns and minimise downtime in the event of a security incident. 

 

In summary, this episode underscores the importance of proactive security measures and risk-based approaches in the MSP space. By prioritising regular monitoring, robust change control, access management, and client communication, MSPs can enhance their security posture, mitigate risks, and deliver value-added services that meet clients’ evolving needs and expectations. 

 

Connect with Keith Hayes on LinkedIn by clicking HERE 

 

Connect with me on LinkedIn and see what I’m up to by clicking HERE 

 

To join our amazing Facebook Group of over 300 MSPs where we are helping you Scale Up with Confidence, then click HERE 

 

Again, if you’re ready to take the next step in supercharging your MSP, take the Scale with Confidence MSP Mastery Quiz. This will provide you with insights and guidance tailored to your specific needs.   

 

Until next time, look after yourself and I’ll catch up with you soon!   

Check Out the Full Transcript Below:

INTRO

In this episode of the IT Experts Podcast, we're going to help you understand the reality of your MSP services in 2024 with Keith Hayes

Welcome to the IT Experts Podcast, the only podcast to help MSP's scale to 1,000,000 in if already there get to 5 and go fast at the end of the day. Isn't it all about building a business that works for you rather than you for it? I hope you enjoy the show.

IAN

So, good morning, good afternoon, good evening. Welcome to the IT Experts podcast. Today we've got a really special show, they’re all special shows actually, in fairness, today, we're going to be talking to Keith Hayes, who is an MSP security expert about expelling some of the myths and actually getting to the nitty gritty, the nuts and the bolts around. What MSP should be doing and shouldn't be, this year, in 2024, around their security stack for their MSP. So welcome to the show, Keith.

KEITH

Thanks, Ian. It's a pleasure to be here.

IAN

Excellent stuff. Well, we met through one of our clients. You're doing some work with one of my clients, which I'm sure we will talk about in a little while, but through our conversations, which was really interesting, you know, there's been some big breaches. Recently, a lot of discussion, controversy, opinion on did they do the right thing? Did they not do the right thing? How did it happen? You know, did they leave the cat flap open, which is one of my favorite analogies around security? Or was the back door widely open and with a big sign saying, hey, bad guys come in here. I think it's very interesting when things happen in the MSP space because as we know, you know there are targets to cyber crime and all of these and the horrible bad. And luckily, we got people like you in the channel and in the area that can help us to expel some of these myths. So before we get too far into the nuts and the bolts of the show, Keith, do you want to explain to us kind of who you are, what you do, who you help and kind of where you come from, what's your experience in this in this room?

KEITH

Certainly, as you can see, I'm about 4,000,000 years old in cyber security since it wasn't cyber, I can't remember what year they decided to call it cyber. But anyway and actually started off on a help desk years and years ago. So I've right been there on the front lines in the trenches and then I've managed help desks and then I've helped MSPs right up to being global seasons for big corporate companies like Boots and Dixons, but I still don't know a lot of voluntary work about talking to groups about awareness and about the reality of where threats come from, because there's a lot of scaremongering that goes.

IAN

Yes, there is. Yep, yeah.

KEITH

In live and a lot of snake oil salesman. So he's trying to sort out the wheat from the chaff quickly. So what, hopefully what I’m going to do is bring all of that experience to bear today when we talk about the reality of it. And actually, what are the challenges as an MSP like haven't got unlimited resources. So how can you focus those in the right way to protect yourself? But then, hopefully you're impressing your customers so much. They come and talk to you about something else that they might want to buy from you.

IAN

Exactly. And, you know, running an MSP is really hard work as it is and you know one of the things that we see a lot of the time well, most of the time, almost every time actually is the amount of new security vendors that have come up. The amount of new systems you need to protect this and to protect that and to do this and to do that and when you start looking at the functionality of it and you go to some of these events, you look around the room and 70% of them are security vendors saying ohh you need this and you need that. And one thing another and it's all about, pen testing and we need to do this and you know, when we talk about tools and we talk about the selection of what you need to keep safe. How would an MSP assess whether he's got the right or the wrong security stack and tool set in place? Because normally you know they get but they go and buy a product and then they go and buy another product cause they've market it in a different way, in actual fact the first product they're probably fixes the second product. Obviously this is something that you come across all the time. But how do we help? How do we help the MSPs to sort as you say, sort the wheat from the chaff.

KEITH

I've got into a bit of trouble down the years and being called dangerous for simplifying this right? It isn't. And I'm going to say it again. It's not that complicated. So if you can have a conversation around what risk means to you and how that means what that means to your customers, because obviously yes, get your own house in order, but obviously you're the custodian of someone else at the same time. So the basics right, you can still point back to the basics. I mean, like people kind of laugh at cyber essentials, but it's like a day, you know, for running properly and is somebody monitoring it to make sure it's working? Have you got your patches installed, might cause that is still a mass infector for attackers, that's the biggest textbook for attackers now is the phishing e-mail in and you haven't got a patch on them. Yeah, it's almost like an arms race, you know, to make you think about it. Have you got the right missiles to shoot the missiles down? Well, missiles from like 10 years ago. Still work if, you haven't got the right patches on you, yes.

So that's okay, access control. It is a big one for MSPs, right? So just lean on that for a second. So we're assuming that, you know, antivirus is a bit leapfrogging. So just to go back to that, so if you getting a decent leading antivirus, right, and remember that bit defender on Windows is pretty damn good now, it never used to be with this now. And you get your patches done and somebody's monitoring that those patches are done. So you're looking at your vulnerabilities. Somebody's job is to look for those vulnerabilities. Now when we talk about access control and access controls about passwords and accounts and things. Like that but this is where it starts to become very interesting for an MSP. Right. Do you recognize that guy that works for you? That's got all the passwords that knows, asks to fix all systems, and if he gets really, really stuck, it ends up with him. Right. I'll call him Ian, right? So, but he's also likely to be the one that's got. In the best way, a back door password because he's always the one that needs to fix it and he might go on when he's on holiday or it might go on when he's at home and everything ends with him, that is a threat effector for you as an MSP. If you recognize that guy, that guy is one of your big risks, not a piece of tech, not a piece of technology, that guy is also probably the guy that likes to have some little tools and toys to help him fix things that aren't necessarily on to the next is your inventory, right? Do you know what machines you've got? And do you know what's installed on those machines, the key, so if I've got Adobe Acrobat, I know that the bad guys are going to come out with an exploit for that every month. But Acrobat are going to come out with a patch, right? If I'm diving the ball back end techie that's installed lots of open source little tools that help me do my job because it's easier and hacks come out for them. You don't even know as an MSP you've got that on your estate. Never mind whether it's being patched or not. So you've got to install a discipline across the staff, which is, we need to understand and have an inventory of exactly what tools we use in, because you could be patched up to the gills, but if you've got something that that ain't even published, patches for, you've got a problem, potentially.

So let me just lean into that. Why that becomes a companion issue then for your guru guys, right? So typically what they'll do is they will stay logged on to an admin account all day. Because it's easy. Consequently, then, if that account gets compromised, they've got admin access across the board. If it's an admin account and they're doing remote management and the target machines got viruses on it. Yep. Now somebody else has got the admin password as well, so you've got to install a discipline within staff that says right, an admin and user ID is used for admin tasks and the rest of the time you're using your basic user ID that has doesn't have privileged or escalated because when you get hacked. It gets, that gets inherited. You're in problem, right? So. Again, I mean, this is just experience, right? So I had a I had a recent a recent instance. Where I discovered a support somebody who's supporting a number of websites but using the same admin password. Because it's easier to support, isn't it? Makes life easier. All the pressure the bosses telling me I got to fix it really quick. I don't want to be worrying about lots and lots and lots of different passwords. Right.

Well, you do right. Find a reputable password manager, change them on a regular basis and the last bit of the access control piece is obvious multifactor authentication, right? Make sure you get in the code. I don't care who knows my password because I can't get in because it's going to give me a multi factor right. In a nutshell that's it for me from that's the big thing that I've seen and I see everywhere I go. And when I talk to people, they get, they kind of nod sagely try and stop tools.

Sprawling basic tools will work. You don't need to buy the snake oil like good antivirus good vulnerability scanner. Penetration tests are great, but expensive, and penetration tests will tell you that you were secure last Wednesday. You know well or six months ago. It's a point in time. So the if you can install change control this is the other big MSP bug there, right? We've got a problem. Fix it and then I'll try that. I'm not sure if that works. We'll try that, not sure if that works. And then ultimately it gets fixed, but you're not quite sure what you did to fix it. Like I get that we stretched. And resource we can't have lots and lots of gurus. But you've got to have some kind of peer review in there from a change control perspective. Otherwise somebody just jumps on, fills around at the back end. You don't know what's happened, so that that's how you protect your investment in penetration tests. So you might have a penetration test done and say, right, I'm okay and if you've got some good change control along the way, you know what changes have been made so you make a good case to go. I don't need an expensive penetration test. I'll just do a vulnerability scan, which is relatively cheap until such maybe next year when I'll do another one. But if people are tinkering around in the back end. You can't with a degree of certainty, say that you're secure anymore, so change control peer review.

IAN

Because you leave because you kind of leaving that door open all day. If you're sitting in your admin account when in actual fact you can just nip in and nip out and secure it back up again by it not being open and access as it were, as it would be. Let's talk for a minute about is there such a thing as a typical MSP? Well, I'm going to pick a number out the sky now, so we've got an MSP. We're turning over about 750K we're going to say they're a lean, meat operating machine. They've got five or six people with them. Couple of help desk maybe three, help desk one on projects bit of a manager, maybe bit of an admin, something like that. When we've been talking about previous breaches and situations that we've heard about I've you know understanding your, you know monitoring and I did a podcast recently with the with Mark from Chorus who just set up their own CSOC. Which was, which is really interesting for me because the from not being from a technical background, I kind of like all this techie stuff cause it's like, oh, hang on, that's interesting. How does that work? And they've set up this whole monitoring system to help you, you know, keep safe and secure cause there's someone there all the time, all day, all night looking at your system now its opportunity, I think, and for some it's great and needed and depending on you know client base size and all this sort of thing you know there isn't one-size-fits-all MSP. But going back to our super successful MSP where they've only got 5 or 6 people. What level of you know, very good, technically, everything's kind of all working in terms of getting things up and running break. You know, fixing, fixing problems. But what sort of level of support, attention time, training, monitoring would you suggest that typical MSP should be operating on their own SOPs during an average week for example.

KEITH

I'm just thinking about, you know, how much time did you spend training and stand up pricing pretty easily, but logging and monitoring is usually a weak point. It always is, so people work their way through trying to get cyber essentials to go to logging, monitoring, right? Do we need a SOC or do we need what's called a seam to come to collate all of the different logs and put them through some logic questions and work out what we need to look at those can end up very, very expensive, very, very quickly. What if, depending on unless you've got a 750K year MSP, probably hasn't got massively complicated systems, probably supporting the usual stuff that it's a Google, it's a Microsoft. It's not like firewall it they might have a bit of web filtering for that customer. It's not going to be complicated as long as you've got the staff time and you make sure that they do it. Each of those products produces a small log any. So if it's somebody's job to check them and then to send an e-mail to say that they've been checked. You're kind of performing the task of a mini-SOC right.

Training is absolutely key, right? The guys on the project team and the guys on the Help desk team are usually the first wave, right? So you get a call that comes in. And so I think my password's being hack or if it's one customer, one customer within the client might be many, right? Maybe they're under attack and you have to remember that you are usually the source of all knowledge in that wise. So get well. We haven't even got any IT people left. So you're we have to ask you everything about it. That puts you in a super position to give them some great advice, but you need to make sure the staff on the desk themselves are trained to spot a potential security event as opposed to a ticket.

Ohh and everything in the world is a ticket, by the way. None need me to tell you tha. No, doesn't matter what it is. It's a ticket, right? So I've had some alerts that I've missed right as being the cyber expert within an MSP that the desk have picked up and actually they respond really well to that training as well I've fan, yeah, because you kind of brought, you know kind of you set them up as like almost investigators. So they're looking at tickets in a different way, so. The training is absolutely key, but you can, I mean, depending on your staff, right, and how much time they've got. But each secure each of the security products that secure. So for instance Active Directory or Office 365 or any firewall will produce a log of its own. Right. So as long as you know what normal looks like, you're then looking for abnormal to give you a very quick instance, right? PlayStation had a massive hack once which was involved in investigating. And what then? Of course, if they check the logs and then we haven't got time to go through checking all the logs. And he looked at the size of the logs. And on Monday is this big Tuesday, this big Monday, It's this big Thursday. It was this big, right? You didn't need to be checking the detail of it. You're going to go. Hold on, mate. So it's got a number.

IAN

And that's the events of the things that have happened and all of a sudden something's out the normal for the purpose you're listening to this podcast on Audio Keith has done Tuesday, Wednesday, very small Thursday, large hand movement.

KEITH

There you go as an insular approach, yeah.

But we, you know, we, that regular checking, be something that some of the trainings were we had them doing that because it's a really important job and you get a positive. I have done this check and it's like that and it gets people invested in it because they're actually proactively protecting the you know.

IAN

And you know. The first question that we've we, we've kind of answered there was how do we you know when it comes to security, how do we get our home own house in order and it sounds like the answer to that question was don't just plug in a product and go away and play golf and expect it to do what you wanted to do, make sure it's someone's whole responsibility ticket triage, whatever it might be, to go and make sure everything okay, with product one, everything okay, with product two, everything okay, with product three and then you know making sure you're keeping all the doors shut and you know looking at the logs and knowing what looking good and looking bad looks like, but more importantly that training, which I'm guessing that the vendors will give you on the on the products, aren't they? So that you can get where you need to be in terms of a minimum level.

KEITH

They will, but it's fairly simple. The real value in training is getting an awareness session with the desk, like that's where the real goal is, because they understand that if this log says something and a ticket that comes. And says I can't get onto my account anymore, but they can put it together to going ohh.

IAN

Yeah, OK. Yeah, yeah.

KEITH

Ohh right. And then we've actually done rewards for desks before. I've done financial little incentives for help desk operators that spot security events. Right and then almost becomes a puzzle during the day, because your biggest asset is the people. Absolutely every time technology is great, right? But the biggest asset as usually is people, and if you've got them as your, your little army checking stuff and correlating some of the information because humans correlate these rules better than these big teams do.

IAN

And it's around understanding, connecting it together and working out what good looks like and what a little bit odd should you know, should look like and things like. So apart from getting you know checking your logs, making sure you've got some you know the good training and your understanding a little bit more everyone's kind of been training a little bit more. In that place was some other good best practices that you'd recommend for an MSP to make sure that their house is in order as a as a kind of like a baseline minimum.

KEITH

The big ones that jump out for me, we've talked about a little bit anyway. Right. And we don't have to over engineer it. It doesn't need to slow the business down, but it's about change control, right? Beyond understand what changes are being made because with the amount of litigation around now and with regulatory compliance big thing you could find out that that a technical operative for the best reasons, are taking risk decisions on behalf of your business and your clients business as well, and it needs to be you, that may takes that risk. So change control is absolutely fundamental. So when you know when the environment changes the inventory is absolutely key again absolutely key, and because MSPs are such a juicy target, because if they get had been accessed, they've got all your customers too, right? That access control has to be tight, tight, tight, tight, right. It's got the multi factor. You don't log on all day with your ID and you don't share passwords because it's, you know, because it makes your life easier.

IAN

So how does the MSP business owner then test his own internal processes so that he knows everything's been done, organised, monitored and everything's in a good place? How does he get to sleep at night. Well, you know you...

KEITH

Do the random audit thing I used to work for a fantastic manager who was he managed by random Interference. His comment was and I really, really like him because you never know which bit he's going toa look at, you need to make sure it was all bikes. You know, just never knew, right? So, just take an odd sample of things so have just to have a look at how many admin accounts have you got when was the last time an ordinary account was logged into. So if you if your guru has got an ordinary account, it's supposed to be using it and the last time it was logged into two weeks ago you got fairly good idea when you. You're saying it's happening? Right. Yeah, yeah, yeah. Just you can well, depending on the level of technical expertise got like say all of these small and these are not expensive tools all produce a lot. So just go have a look here again. Yeah. What's the success of your passion? Then done. So, so and another issue and this is difficult to report to a customer. It's a thorny one for customers, but also for you, it's, you send the report to your customers to say we're doing your patching for you and 95% of machines are all patched every week. Does it ever occur to somebody that the 5% might be always be the same 5%? So it's about just having a little down and get your feet wet.

Just go and have a little look. So maybe go and have a look at your antivirus. Right. What's that look like? Cause this is fantastic, this is gold for your customers too, potentially. So if how many you know? How many alerts did we have last week 3 how many alerts we got this week, 20. Well, isn't that conversation with somebody, right? How's me patching? Getting on am I successfully getting my patches done? If I'm not, why not? That's another one. How often are passwords being changed right? You can pick that up from Active Directory. If you're using Active Directory, you can force password changes as well. On people sit there festering away for it. So you can you can dip in and again these are not expensive products, right? So you probably got antivirus anyway, so the free you know. The defender will give you alerting you can look at that that's free as well. Vulnerability scanners are relatively cheap, and if you're clever enough, free. So again that will give you an idea, I would, that's my approach is.

IAN

Yeah, you know it's, you know, it's wonderfully simple in terms of, you know, you've got the tools there. Just look at them, go and do an audit, make sure that you, you, you checking in on things and make sure that your tools are there are serving a purpose and you're exploiting all the features of each of the tools because as you alluded to there, you know this is yes we’ve got you know you've got all your customers there, your high target which kind of comes into the last bit. I just wanted to talk about which was around. How do we now? Now we know what's going on with our client systems and the and the logs and the information and the opportunities and all of that kind of good stuff. How do we then approach to sell this without selling it and more importantly, selling it without fear. Because I think there's a lot of people try and scare people, you need this. Otherwise your business is going to go out of touch and all of that sort of thing whenever we're talking to our clients around this, we're always saying, you know, we'll have a conversation with them about what's the impact of not doing. This what's the impact if you couldn't log on to your system today, what's the impact if your clients can't log on to their system today? You know, are the contract. And I know that this opens up a big old can of information. But you know, where's the contracts lying. But you know what are some of the basics around and how an MSP could approach us either in an account management conversation or in a pitch to a new client. What were some of your techniques for that? Because I know this is one of your expertises, isn't it?

KEITH

Yeah. Well, depending on how far out your service is reaching to the clients, whether you're providing them with a managed Security Service as well as a support service potentially. There's an awful lot of activity happening all the time as we know in that threat space. Knock it up into a PowerPoint and get it out to the customer. I was used to describe it as like I'm old enough to remember Tom and Jerry, but Tom sitting outside Jerry’s household waiting for him to come out right, that is the whole of the Internet waiting for a vulnerability all the time. So they'll just the customer will know there's something coming away in the background. Yeah, but you can prove. Well, actually we've blocked this many threats. We've blocked on the firewall for instance. We've done this many patches. You might have seen, you know, the latest, the very latest hack is the big LinkedIn, the mother of all breaches, which has been published this week, right. Billions of records been lost, so leaders of companies have those conversations go. Does this affect me? So if you do pick up, because remember you are the font of all knowledge probably right that outsource it to you. They haven't got anybody else. They might have an enthusiastic camera, so that probably. Gets in your way, right? But they won't have anybody else to ask. So if there is a big news article for instance, like that. Why don't you just drop them a note just to tell them why that affects them or why it doesn't affect them? Yeah, because it's a business conversation. The other thing I would say is, have a risk conversation with them if you can about their business right. If you understand what makes their business tick, critical processes or critical applications right, you can have a conversation that you can look at the services that you provide and look at any risk there and highlight a risk with them just about in a friendly not a not a sales conversation. Which is to go well. Actually, we've had a look at that. We've compared it there and let me give you just one quick for instance. I've got taught lots of MSPs to talk into two different phrases, right? RTO and RPO. Of the two big phrases that go and talk to your customer about recovery time objective and recovery point objective. So with this service that you deliver to somebody, recover a time objective is if it goes bang, how long does it take to get it back working? Again, Lillian, I can't,that cannot be done for more than four hours because it cost me a fortune. What's actually recovery time? Objective. So how often you take the backups can't be 6 hours, can't be daily right? So that structures the service that you provide to them for instance right hot standby devices. Maybe you know depending on whether you're delivering server services or not. Can you get that back within 4 hours? Does your contract support that? To that customer, so always have that. Watch your RTO for that system. Watch your RTO for that you know RPO is report covery point objective so if it goes bang how much data can you afford to lose before it really hurts those two conversations with the customer can usually flush out potential where you can assist their business. Make sure that the service that you're providing fits in with what they expect because you're the source of your knowledge, you will get a conversation with. If you'd have told me about that you not have done something about it. Afterwards, you're asking me to ask about IT, right? It's up to you to tell me.

IAN

But also from that point of view that that they're actually telling you what they want in terms of the service that's going to affect their operations. And then you just match your services to their requirements. So no one selling anything, you're not telling them that they need to be doing, you know, having it recovered in such a way or we're going to do it in such a way. And it's going to cost you to mount it, it's, you know, it's all coming from their point of view, which is, you know, they're buying it from you rather than you having to sell it to them, aren't they?

KEITH

Absolutely. I mean, would you believe? We might say which city? It was, but there was a full Internet facility running in a library in a metropolitan city, which I did a check on, and this is about, you know, that's a massive flagship service and you and you go and do digging and poking around. You actually found the little 6 Volt, 10 ports switch hanging out the back of the cabinet. That if it went by, I would have taken the whole thing down, right? I'm not even sure they made those things anymore, so it's just understanding. I mean from a process and a people and a system and a service point of view, you can be a business advisor, not just an MSP to go actually, yeah, we probably couldn't get with what we currently do. We probably couldn't get that back then, within 16 hours is that okay? And if they go, yeah, then you get them to sign. Because then when it's not back within 16 hours, you're going to go well. You accepted that risk and that risk conversation is fundamental. Absolutely fundamental.

IAN

And that's the part of then the lining up with their terms and conditions and contract and everything like that, just to make sure that everything's all in good order.

Keith, whole load of information here. Just before we wrap up, I just want to remind everybody that we've other security podcast that we've done recently as I say, we did the podcast with Mark from Chorus about their CSOC, but also in episode 133, we were talking about securing your stack with Andrew Eardley from MSP Easy Tools which was very interesting all around how that sits with the Microsoft platform and then our good friend Trevor Cornbill, who we know through CompTIA did a he unraveled a bit of cyber insurance which you know, more, we talk about this now shouldn't be used as a plaster. It should be used as a last defense sort of thing to protect for your business and that was in episode 142.

So a Couple of other episodes there. We'll drop those links into the showing at which are very interested in, you know and line up with this subject. I think really well that's been great. Thank you. I mean I love it because I learned an awful lot here, Keith. Anyway, from my from my point of view, which is really great, but what, what final thoughts have you got today for the MSPs listening to this, the plan has not been to scare or to scare mung. It's to make it, as you say. Very simple and straightforward so. What's at the top of the hour for you in terms of the final thoughts that Keith?

KEITH

Well, very much. So my approach has always been one of very much pragmatic, right? We all but ultimately sources, all of us and I'm not disparaging any of the security vendors at all in any way but in my experience, which is obviously very, very long, if you do the basic things well. You're probably going to protect yourself as much as or better than most people, most big breaches are some really basic thing that's being missed. If a really talented or determined hacker wants to get you, they will, regardless of how big you are like. But most of the time you're not a big target, but you are a target. Do the basics really, really well. You can do that really, really cost effectively. And then you're protected. Better than most. You'd be surprised how big companies, not even doing the basics properly.

IAN

That's brilliant. And when you hear about some of these, these incidents that are happening or how did that happen, it's ohh cause such and such wasn't patched and it was like what that's so simple when you hear and we're talking to each other and then you got to look in the mirror and go, could that have been me. So keep it simple. Keep it really simple which I think is the is the summary of today's show.

Keith, thank you very much for your time in preparing for the show and also your expertise in Lawrence today has been absolutely brilliant. Do you just want to share with everybody if you've piqued their interest and they will have a chat with you about anything we've talked about today or anything to do with? Security at all in their MSPs, then how do they get in contact with you?

KEITH

The best way is through LinkedIn. You can find the key tags on LinkedIn. Drop me a message in LinkedIn. I'm happy to have a chat and offer some advice.

IAN

Fantastic. And we'll pop the link in the show, pop our LinkedIn link in the show notes, so where people can do that nice and easily, so look great thanks ever. Much for that, I'm wishing you a very super safe 2024 and yeah, look forward to catching up you soon. I'm sure. Thanks again, Keith. Cheers now.

OUTRO

So I hope you enjoyed the show if you did, I'd love it if you could leave a rating and review on your favorite podcast platform. If you want to know more about how to take your MSP to a million or if you're already there go faster. Then come and join Stuart Warwick and myself in the scale with confidence Facebook group the link is in the show notes. You go enjoy the rest of your day and I look forward to connecting with you soon.