EP199 - Why Becoming a Cyber Advisor Will Help Your MSP Grow With Neil Smith and Ian Luckett

IT Experts Podcast - The MSP Growth Hub - IAN LUCKETT - THE MSP GROWTH HUB - NEIL SMITH FROM REFORM IT - Podcast Episode 199 - UK - WordPress

Click below to listen to the episode

In this episode of the IT Experts Podcast, we explore an increasingly hot topic for MSPs: the role of the cyber advisor and how embracing this role can significantly boost your business and profitability. I had the pleasure of speaking with Neil Smith, Managing Director of Reform IT and a valued client of The MSP Growth Hub, who shared his experience of becoming a cyber advisor. 

 

Neil Smith explains how his journey into the cyber advisor space has not only strengthened his business by enhancing his credibility but also provided new revenue opportunities. He explains that the cyber advisor role is not just about securing clients but about positioning yourself as a trusted authority in the field of cybersecurity. With cybersecurity becoming more complex, Neil highlights the importance of MSPs adopting the Cyber Essentials and Cyber Essentials Plus certifications as a minimum standard. According to Neil, these certifications, which are significant milestones, are achievable and can set an MSP apart from the competition. 

 

A key takeaway from our conversation is the opportunity that the cyber advisor role presents in a rapidly evolving regulatory landscape. Neil points out that the UK government has been moving towards regulating MSPs, particularly in terms of cybersecurity. While the regulatory changes may still be a few years away, Neil wisely suggests that proactive MSPs should get ahead of the curve by becoming cyber advisors now. By doing so, MSPs can not only comply with future regulations but also monetise the process through gap analysis services and further consulting. 

 

Neil Smith shares that Reform IT chose to go down the IASME route for their Cyber Essentials Plus and Cyber Assurance certifications. This route was more cost-effective and provided the same level of credibility as the more expensive ISO 27001 certification. Neil explains that becoming a cyber advisor involves not just the certification of the business but also the training and accreditation of an individual within the organisation. This dual approach ensures that the business is fully prepared to deliver the cyber advisor service to clients. 

 

One of the key benefits of becoming a cyber advisor, as Neil explains, is the ability to add substantial credibility to your MSP. With the official NCSC Cyber Advisor logo on your website and marketing materials, you can demonstrate to potential clients that you take cybersecurity seriously. Neil notes that this level of recognition can be a game-changer, particularly as more clients start to look for MSPs who can prove their commitment to cybersecurity. 

 

Throughout the episode, Neil and I discuss the tangible benefits of being a cyber advisor, including the opportunity to stand out in a crowded market. Neil shares that, as of August 2024, there are only 82 organisations listed as cyber advisors in the UK. With approximately 15,000 MSPs across the country, this presents a significant opportunity for early adopters to differentiate themselves and capture market share. 

 

In closing, Neil Smith offers practical advice for MSPs considering the cyber advisor route. He suggests leveraging the certification to educate existing and potential clients about the importance of cybersecurity. This, he believes, can lead to further business opportunities, as clients often require additional services once their cybersecurity gaps have been identified. 

 

You can reach out to Neil Smith by sending him an email at neil@reformit.co.uk 

 

Want to be part of the IT Experts Podcast AND win a £200 Amazon voucher? Drop your question HERE 

 

Connect with Ian HERE on LinkedIn and also Stuart by clicking this LINK 

 

If you’re ready to take the next step in supercharging your MSP, take the Scale with Confidence MSP Mastery Quiz. This tool is designed to help you understand where your MSP stands and what steps you can take to scale profitably and effectively. This will provide you with insights and guidance tailored to your specific needs.

 

OR to join our amazing Facebook Group of over 400 MSPs where we are helping you Scale Up with Confidence, then click HERE 

 

Until next time, look after yourself and I’ll catch up with you soon!  

Check Out the Full Transcript Below:

INTRO: In this episode of the IT Experts podcast, we help you understand why becoming a cyber advisor can help grow your business and your profits.

Welcome to the IT Experts podcast, the only podcast to help MSPs scale to 1 million, and if already there, get to five and go faster At the end of the day, isn't it all about building a business that works for you rather than you for it? I hope you enjoy the show.

IAN: So good morning, good afternoon, good evening. Welcome to the IT Experts podcast. Today we're going to be talking about the cyber advisor role and what it is and how it can help you, how it can help your MSP, how it can help your profits and how it can help you generate more business. And we welcome to the show today an amazing client of ours at the MSP Growth Hub, Neil Smith from Reform IT. Good morning, Neil. How are you doing today? Good

NEIL: Morning, Ian. All well here. Thank you.

IAN: Great stuff. Just back from holiday. Nice and refreshed. Raring to go straight into the podcast lounge. What a better place. What a better place to be. So today we are talking about cyber security, but more importantly, around the role of the cyber advisor in relation to cyber essentials and how this can become such a benefit for you as an MSP. As, you know, we talk and work with lots of MSPs and having the right security stack is obviously important for yourselves and it's important for your clients. But there's so many opportunities and today's opportunity around this cyber advisor role has really helped you and your business, Neil. And we're going to learn all the little things that tips and the tricks and the strategies that Neil's done to help them do that. But before we do that, Neil, just can you explain to the wonderful listeners here, who are you, what you do and who'd you help?

NEIL: So my name is Neil Smith, managing director of Reform IT. We are a Cheltenham based managed service provider team of about 23. We help small or medium sized businesses with all of their IT issues, as most MSPs do. But we've recently added the CyberEssentials and CyberEssentials Plus certification body with IASME to our stack of services too, which I think this neatly fits into.

IAN: Lovely, lovely, great stuff. So we've, we had quite a few conversations as the, as the community did at the growth hub over the last couple of months about protecting yourselves against the bad guys. And what was, throughout all the conversations we had, which went from insurance to product, to shiny ball, to product, to shiny ball, to product, to another shiny ball, to another security tool. And it boiled down to the fact of, absolutely 101 every MSP should have Cyber Essentials Plus. And if you've got CyberEssentials Plus as your first stage to securing yourself, then you're taken by the world as being a bit serious. And then what happened was that we then had some panel discussions and we got yourself and some other clients. Michael Freeman's one of very experienced and in depth and take this super, super seriously, which is why we said, Neil, we need to bottle that, put it in the podcast and away we go. So let's start off at the top. We've got to show structure, which obviously we completely ignore. And then I just go off on a tangent. We talk about something else. What in your opinion, Neil, why is cyber essentials or cyber essentials plus, why is it so important that every single MSP who's listening to this podcast, no matter what size they are? Has it? What's it all about?

NEIL: It's credibility and it's achievable credibility. So it's, I think as MSPs and certainly we at ReformIT, we try and hold all of our clients to the cyber essential standard. Whether they decide to go down the certification route or not, that has to be the minimum standard that, that you look to hold your clients to. Because it, provides and covers, as its name suggests, cyber essentials. It covers all the essentials of cyber security. And the fact is the statistics speak for themselves that if you are covering all of those essentials, all of those basics of cybersecurity, you are probably in the top 10 or 15 percent best protected organizations in the UK. And it's the ones that aren't doing those basics that are getting attacked. And I think what's I know that the, what happened is that in 2022, the government started to do a consultation. And this is where our sort of journey started all of this. In that, they started to look at where the managed service providers, we managed MSPs should be and in, it's crazy that we're not. We all look after usually regulated clients, so we have the keys to the castles of solicitors of financial advisors, probably of some look after health companies, all sort of companies that hold very sensitive data that are regulated as a result. But we as the IT support company who have the keys to that castle are not regulated. And that's bonkers, really. So the government did this , consultation about how they look, would look to expand what they call, , the NIS Network Information Systems regulation of 2018. It's a very dry document when you read it, but currently wouldn't even recommend it as bedtime reading, but it is, it currently only covers the largest MSPs in the country. 10 million turnover plus you've got to be supporting major national infrastructure. I think there's a number of employees, 50 plus employees. It's the big guys that are currently only encompassed by this regulation. And in 2022, the government did this kind of consultation where they said actually, should we include all MSPs? In this regulation and have them meet whatever standards we expect. And of course, the answer is yes, it's absolutely sensible. Now, that's where it ended various political chaos, because, , in order for this to progress I think the ICO is going to be the regulator when it eventually it does come through. Aand of course the ICO need money to do this. That has to go through parliament, , at the end of 2022 good old Liz and quasi came in and, and made a bit of a chaos for 10 minutes. And since then, politically, it's all been a mess anyway. So it's got stale, although , the government have released a further document in February of this year where they've done a bit of market analysis on cause one of the problems was defining legally defining what an MSP is so that they can say you are an MSP. Therefore you need to be regulated or you're not. And I think we all know, what an MSP is, clearly it's got to be legally defined. And I think they've done another document where they have done another document, which I posted in the team's channel which, which has done some market research on sizes of MSPs, the actual size of the market. It's really quite an interesting for once and a government document. It actually makes some very interesting reading. So this is, I think clearly progress towards what is the inevitable thing. So regulation costs money. And it costs us MSPs. If we're going to be regulated, that means we're going to have to tick boxes. I suspect that it would seem to make sense that MSPs having cyber essentials. I would say at least cyber essentials basic, but I would suspect it will be cyber essentials plus will be the minimum kind of level. And of course, this all takes time. It all costs money. And, At the minute, potentially apart from the fact that you get to shout about it and put it in your marketing, and of course it does give you credibility. And I would argue that most MSPs have probably come across at least one client that has said to them. How do we know that your systems are secure? And how do we know that you looking after us is a good thing, that you are doing and looking after your own house, as well as you say that you're looking after us, you demonstrate that. And of course. Cyber essentials or ISOs to 27, 001, 9, 001, whatever they might be. They're all good ways off helping demonstrate your credibility. But I suppose what if there's a way of really Getting some really good credibility and also potentially making some money out of it as well.

IAN: Wow it’s quite exciting.

NEIL: And this is where the cyber advisor scheme comes in to play. If we're all going to get regulated and I think it's inevitable, it still might take months or years, but...

IAN: Yeah.

NEIL: Good honest MSPs that are part of a great community here, let's get ahead of it. Let's be the best. Cause that's what the MSP growth hub is all about. Let's get ahead of the game. Let's get that accreditation. Let's get cyber essentials plus. Now, if you've got cyber essentials plus, then you're already halfway to becoming a cyber advisor that, you then need to get and there are two or three different ways of doing it. An ISO route is one of them. ISO 27, 001 can be quite an expensive thing to do. And for the cyber advisor scheme, you have to go down the There are a couple of different versions of ISO, if I remember rightly. There's a kind of a bit of a cheap and cheerful one, and then there's the proper one. And I forget the exact terminology of which is the proper one, but you have to have the proper one, which I don't think you get a lot of change out of 10 grand for. No, I think that's around the number, isn't it? So we've gone down the IASME route. And it's about getting something called IASME Cyber Assurance, which is roughly equivalent to ISO 27001. And in fact, on the IASME website, there is a grid, a comparison , that, links the two together and shows you if there are, or what differences there are, and there aren't that many. And that's IASME Cyber Assurance lot less expensive to obtain than ISO 27001, but it ticks the next box that you need for Cyber Assurance for the Cyber Advisor Scheme. So once you've got your Cyber Assurance , scheme or cyber assurance qualification which effectively covers the business.

You then need an individual to go and pass the cyber advisor SCA cyber advisor exam. Now, if you have ever done a cyber essentials questionnaire, taking one of your clients through cyber essentials, that effectively is what the exam is all about. They are looking for two things. They're looking three things. They're looking for knowledge of Cyber Essentials. So you've got to know the Cyber Essentials scheme inside and out all of the kind of the pillars of it and the questions that are asked. You've got to be able to explain to a pretend client, how they might meet the requirements of the cyber essential scheme in words that a non technical person can understand. And finally, they're looking for somebody to be able to do all that in a professional manner. Now, my view is that's what we MSPs do all day long.

IAN: Yeah.

NEIL: This is something that you've got to be able to do that to be an MSP. Being able to go out to clients, create that credibility in a conversation, in a sales conversation, whatever it might be, and be able to explain what it is you do to protect them in words that they understand. That's what we do all day every day. We wouldn't be able to sell our services if we couldn't do that. Yeah.

IAN: Exactly.

NEIL: So IASME and the NCSC, so this is an NCSC driven scheme, they're partnering with IASME to deliver the training and the credibility. And obviously it's all to do with cyber essentials, which is the IASME scheme anyway. I could be wrong, but I think they've been fishing in slightly the wrong pond in terms of finding cyber advisors. I think they've been going down the route of talking to their cyber security experts who are not MSPs and who, God bless them, I think they probably go down the, they're not the best at explaining things, technical things in a non technical way. And that has been, as we understand, the chief reason for people failing the cyber advisor exam, they've gone down the route about talking about VLANs and port forwarding and firewalls and things that are just going to blow the average client's mind and not make any sense to them rather than being able to take those quite technical concepts and explain them in ways that something non technical can understand, which as I say, is what we are brilliant at doing or should be brilliant at doing. So if you pass the exam and you therefore, once you've done that, you have to sign some paperwork to say you'll meet a code of ethics. Being a cyber advisor you do have to take your sales hat off initially. So although you work for an MSP and you can declare that you work for an MSP when you go in to do the cyber advice bit, and it's all about, so just to be clear about what the cyber advisor role is, this is what I asked me in the NCSC have found this gap. They found a whole bunch off customers or potential customers that need cyber essentials, but they don't know where to start. They don't know what they need. They don't know what they've got to do to achieve the cyber essential standard, and it's either because they haven't got formal it support or their existing it support. Equally doesn't know help. Or they're just all at sea. They don't know what they're doing. So the idea of the cyber advisor role is you go in and you do that gap analysis and you charge for your time as well. And obviously inevitably in theory, you're going to find some gaps, but you have to come at it with a non sales hat on and say, look, okay, your systems are out of date, but you could just patch them yourself and that will tick the box.

IAN: Yeah.

NEIL: Once that report's been done and the client's accepted it, there is nothing to stop you going in and saying, actually, obviously we work for an MSPI work, we can help you with some of this. Yeah. If you wish, if you want to automate your patching Yeah. Monitor your security, all the rest, and then obviously we can help you through cyber essentials as well. And that's the kind of the, the lead in to further work and sales. So you've been in charge for your time doing the cyber advisor report and then potentially. There is further work beyond that. So this is where you make your money. Now, on top of that, once you've become a cyber advisor, you also get a lovely NCSC logo that says you're a cyber advisor for cyber essentials that you can put across your website, your emails and all the rest of it.

IAN: Fantastic.

NEIL: Whilst I would completely forgive people perhaps for not knowing necessarily what Cyber Essentials was, certainly not necessarily knowing what IASME Cyber Assurance was, I think most people know who the NCSC are because of the high the high profile they have whenever they're in a cyber attack in the UK. It's always the NCSC that get involved and they're all over the news and all the rest of it. So I would say certainly most people. will know who the NCSC are. And if you could put a logo on your website that says you are NCSC certified approved as a cyber advisor, I think that brings a huge amount of credibility too.

IAN: This is just such great opportunity because isn't it amazing that someone in a technical era, technical space in the cyber security world have identified that there's this disconnect between techies. And I'm going to say real people, but I kind of people who listen to this podcast and know what I'm talking about, because that's the ethics of educating, your prospects and people into why they need technology, why they need what you do, why they need to keep safe and how to keep safe. And if this is if this role here that they've created gives the opportunity to stand out from the crowd, because, just while you were talking there, you've got two opportunities here. Either you sit here and you wait for regulation to come along and you go, Oh my God, what a nightmare. Why have I got to do all this? Or you're proactive about it. And someone said to me once, he said, watch, look at what's going on to you, or you could look at what's going on around you and understand what's going on around you and going how many is that in that space? Now, Neil. How many MSPs do we think there are in the UK roughly?

NEIL: Do you know? I read that document that I mentioned earlier.

IAN: You didn't answer it because I only read the one. It's around 11,000, something like that.

NEIL: 11,000. That's it. Yeah.

IAN: And I'm going to say that there is probably, I'm gonna put some put a good old bet on the fact it's probably about another 4,000 IT support companies who don't even know what an MSP is and don't even know what a managed services, right? So I reckon we're looking at 15, 000, 15, 000 businesses here. Currently, Neil, at the time of recording, which is August, 2024, how many cyber advisors are there under this scheme?

NEIL: 82.

IAN: 82.

NEIL: 82 organizations, including reform it that are currently now listed on the NCSC website as a cyber advisor for cyber central.

IAN: Wow. So what an opportunity, the opportunity here to go and get yourselves accredited and get yourselves, so do you, so is it the business then that gets the accreditation or is it one person within it? How does that kind of work?

NEIL: Both. So the business gets the accreditation, cyber essentials. And then as we went, as I said that there are three different routes you can go down. One route I've never heard of before and I can't think of it, the NCSC website, but I've never ever come across it before. So it's, potentially, it's a bit of a weird one. You can go down the ISO route. So ISO 27,001, but as I say, it's got to be the proper expensive one, not the cheaper one. Or you can go down the As IASME Cyber assurance route, which is the route that we took. We went down the IASME route and IASME Cyber Assurance also covers the organization. So the organization, so this is where I'm coming back to the NIS, regulation. I am as certain as I probably can be that having Cyber Essentials and IASME Cyber Assurance that covers the organization, we're going to be more than ticking the boxes of any potential regulation. So that's done. And in terms of costs for all of this I'll come back to that in a second. So we've got Cyber Essentials, we've got IASME Cyber Assurance, and then you have to have an individual within the organization who is the cyber advisor.

IAN: Okay.

NEIL: Now, Anybody in the company, once you've got that, anybody in the company can go and do the cyber advisor stuff. It's just that individual has to rubber stamp it and check it to make sure that it meets the requirements of the cyber advisor scheme. But so you've got to have those two things. The company's got to be certified and you have got to have an individual who's passed the cyber advisor scan cyber advisor exam. Which they run the exams in Cheltenham, Manchester. think Birmingham and London. So there's the way you can go and do it. The exam takes about three hours. As I remember you've got two hours is the written bit. And there's a kind of an hour, which is a is an interview, to check out the cross professionally or so it is. It's a thorough exam, and it's... time is the hardest part of it. If I'm honest with you, you run out of time quite quickly, particularly in the written part, if you waffle like I do anyway. But it's, as I say, if you've done Cyber Essentials assessments and you know the Cyber Essentials scheme well and you're an MSP because this is what we do, it's not difficult. It really isn't. There are some example again on the, I think it's the Cyber Scheme website who do the exam. They've got some example like an example question, an example scenario that you might be presented with in the exam so you can practice.

IAN: Brilliant. So obviously this instantly rates your credibility, but you're still maybe a little bit of a secret to everyone in, your area, in Cheltenham that you've got this accreditation, which we know everybody's listening to this is going great. That's a really great thing to do. How do you then, what's the best kind of practice that, that you've come across that you then open up your office doors and then you're out educating people. What's the best way to then turn this into an opportunity? Cause this sounds like a classic land and expand. We're going to come and talk to you today about your cyber security. We're going to give you an audit. We're not talking about managed services. We're not going to sell you office 365. We're not going to do any of that stuff. This is just a value add service that you can charge for. I guess you could probably decide not to charge for it if you didn't want to. Could you?

NEIL: You could. Yeah it's up to the, neither the ISME or NCSC set any rules around what you charge for doing the cyber advisor gap analysis. So you could treat it as a loss leader if you wanted to. I think you've got to value your time. Because it is, it's probably at least half a day's work, right?

IAN: Okay, that was going to be my next question. What's the size of the time on this? Half a day.

NEIL: I think, effectively to do the gap analysis as a cyber advisor, you are effectively taking that client through cyber essentials basic.

IAN: Right.

NEIL: You're going to be using the cyber central standard to gap analysis on each of the pillars on answering each of the questions. So Actually it's going to take you as long and you do then have to write a report as we are asking is to feedback the reports and the customers that we've done this likelihood as time progresses, they will probably come and check our homework to make sure that we're doing it correctly and they're looking for feedback from the clients that have that have had the cyber advisor experience to make sure it's working. The NCSC will be requiring that as well. So yeah, I think it's quite a lot of time to give away in time. It's there are no rules around it. You can do what you like.

IAN: No, that's a fair point. You could always discount it or reduce it if they start with you. What's the best way. Do you think then to go out and to start educating businesses that you may never have know about how you've contacted people, how do we then start to generate leads?

NEIL: This is the journey we're now on. And yeah, it is about shouting about it on social media through all of your normal marketing channels, whether you've got email newsletters, putting it on the website. And I think, I know the other aspect of it is that both IASB and the NCSC are also going to be starting to shout about it too. So they're going to be taking a bit of the marketing load office and helping us promote and obviously all of the other cyber advisors what the services, what it offers and what you can gain from it as a normal client, help us promote it. Why wouldn't you want to be on that bandwagon?

IAN: Yeah particularly in the early days where you've got the numbers and then as the years and years come on, it's then going to be a, yeah, we've been doing this for years and that's just going to bolt that credibility straight in. , is there any particular size of business that this suits best in terms of an end client? Is it, does it work for, if you've got someone under 10 users, is this going to be a bit of a heavy hand for them or is it for larger corporate sort of 50, 60, 100, 200 user customers? What's does the, where do you see this fitting in your business?

NEIL: As with cyber essentials, it agnostic. And I think what's, what the great thing about the cyber advisor role is in terms of MSP size it's agnostic as well. You if you've, I think the biggest cost of it is time. So in terms of the cost of getting IASME cyber assurance and cyber essentials plus, and doing the exam, it's roughly five grand. So five grand invested into your MSP. And then it's the time you've obviously got to have the time to particularly cyber assurance, ISB cyber assurance, just as with ISO. There's a lot of writing box ticking policies to create all of that sort of thing. But there's help out there to do that as well. We were lucky in that Nathan, who's our Cyber internal cyber security chap did all of that with management involvement. But I was able to effectively delegate that. But if you've got the time, then, you could be a one man band do become a cyber advisor. This is the other great part about it. Five grand is it's a chunk of money. Don't get me wrong, but it's not an unachievable chunk of money. I don't think for MSPs.

IAN: And, I think we've covered what we were going to discuss that. I think this is a great opportunity. If you want to stand out from the crowd, if you want to be seen to be taking security in your MSP and in your clients, secure, your clients, businesses as well, seriously it's a no brainer in it.

NEIL: Yeah, and getting ahead of that regulation. We're just ticking boxes and making money from it.

IAN: It's going to happen. It just depends prepare for that. And I think you're absolutely from what I'm hearing from people in the area and how it works I think this is exactly like how you can see the little jigsaw pieces of the cyber world lining up to try and help protect people as much as they can. It makes perfect sense. Neil, thank you for sharing. Thank you. All the information, everything that you've done today you're an amazing share in our community and with the channel and we are terribly grateful for you for that. If people want to have a chat with you about this, how do they get in contact with you? If you want them to get in contact with you, that is...

NEIL: Neil@reformit.co.uk.

IAN: We'll pop his email address on the show notes and it will, we'll share with you all the details there. Unless we have anything else. That was an amazing show. Thank you very much, Neil. Thanks for your time. And look forward to all the cyber advisors popping up over the world as a result of this podcast. Lovely stuff. Thanks again. Catch up with you on the next one. Take care now.

OUTRO: Hang on a minute just before you go. And if you're curious about how this episode links with the ability to scale your MSP to a million or if you're already there, accelerate to five, then we want to invite you to come and take the MSP mastery quiz. And in just three minutes, you're going to get a 360 degree scan of your business where you can identify the one or two tactics that can help you find more time engaging along your people and help generate more leads in your MSP. It's really simple. Just click on the link in the show notes. And if you have enjoyed this episode, we'd love to get some feedback from you by means of a rating review on Spotify or iTunes or your podcast platform of choice. We really appreciate every single one of them. Now you can go and enjoy the rest of your day and we look forward to catching up and connecting with you soon. All the best.