Neil starts by giving us a solid understanding of IASME’s pivotal role as the sole delivery partner of the Cyber Essentials scheme on behalf of the National Cyber Security Centre (NCSC). Working in close partnership with the NCSC and the Department for Science, Innovation, and Technology (DSIT), IASME ensures the consistency and credibility of Cyber Essentials across the UK. Neil explains how this collaborative effort aims to improve awareness, adoption, and implementation of essential cybersecurity measures, particularly for MSPs and their clients.
One of the key points of our discussion is Neil’s emphasis on the necessity of Cyber Essentials. He explains that the scheme is designed to protect businesses against the most common cyber threats, offering a prescriptive approach to cybersecurity. Unlike other standards, Cyber Essentials doesn’t simply recommend best practices—it mandates them. Neil stresses that MSPs, as custodians of their clients’ IT systems, must lead the charge in implementing these essential controls. From patch management to MFA (multi-factor authentication), Cyber Essentials lays out straightforward measures that every organisation, regardless of size, can adopt.
Neil provides context about why some MSPs are still hesitant to embrace Cyber Essentials. He attributes it to a lack of education and regulation within the industry. Despite being targeted by cybercriminals due to the vast number of endpoints they manage, many MSPs either underestimate the risks or delay action until after an incident. Neil calls on MSPs to take proactive steps by embedding Cyber Essentials into their service offerings, not only to secure their clients but also to stand out in an increasingly competitive marketplace.
We also explore the three tiers of accreditation offered by IASME: Cyber Essentials, Cyber Essentials Plus, and the IASME Cyber Advisor certification. Neil elaborates on the differences, highlighting how Cyber Essentials focuses on a self-assessment validated by a trained assessor, while Cyber Essentials Plus involves an external audit of a business’s IT systems. For those looking to further establish credibility, the IASME Cyber Advisor certification is an excellent option. Advisors are trained to provide implementation guidance and help businesses achieve compliance. This certification represents a golden opportunity for MSPs to differentiate themselves and gain the trust of potential clients.
Neil’s passion for education is evident throughout our conversation. He believes Cyber Essentials is not just a sales tool but a vital framework for educating businesses about cybersecurity. Whether it’s a sole trader or a multinational corporation, adopting Cyber Essentials means laying a solid foundation for cybersecurity and safeguarding against the ever-present threat of cyberattacks. He challenges MSPs to embrace their role as educators and advisors, helping clients understand the importance of these controls and encouraging adoption.
In terms of what’s next, Neil shares exciting updates about upcoming changes to Cyber Essentials. Starting in April, IASME will introduce a new set of requirements, codenamed “Willow”. These updates will reflect the industry’s shift towards passwordless authentication and more robust vulnerability management. Neil highlights the growing role of passkeys, which offer a safer alternative to traditional passwords. This evolution aims to stay ahead of cyber threats while making compliance more accessible and effective for businesses of all sizes.
As the episode concludes, Neil reinforces the importance of collaboration across the industry to secure the UK against cyber threats. IASME is committed to being approachable and responsive, ensuring MSPs have the support they need to succeed. Whether it’s through their technical guidance team or Neil himself, IASME offers resources to help MSPs navigate the certification process and enhance their cybersecurity offerings.
With Cyber Essentials growing in adoption year after year, the time has never been better to get involved. Whether you’re considering Cyber Essentials certification, Cyber Essentials Plus, or becoming an IASME Cyber Advisor, this conversation with Neil Furminger will inspire you to take the next step.
Feel free to contact Neil Furminger through his email at neilfurminger@iasme.co.uk
Connect with Ian HERE on LinkedIn and also Stuart by clicking this LINK
If you’re ready to take the next step in supercharging your MSP, take the Scale with Confidence MSP Mastery Quiz. This tool is designed to help you understand where your MSP stands and what steps you can take to scale profitably and effectively. This will provide you with insights and guidance tailored to your specific needs.
OR to join our amazing Facebook Group of over 400 MSPs where we are helping you Scale Up with Confidence, then click HERE
Until next time, look after yourself and I’ll catch up with you soon!
IAN: In this episode of the IT experts podcast, we are joined by the head of cyber essentials from IASME to give you an IASME security update.
INTRO: Welcome to the IT Experts podcast, the only podcast to help MSPs scale to 1 million and if already there, get to 5 and go fast. At the end of the day, isn't it all about building a business that works for you rather than you for it? I hope you enjoy the show.
IAN: So good morning, good afternoon, good evening. Welcome to the IT experts podcast today. We've got a really exciting and special guest, we've got Neil Furminger from IASME. He's the head of cyber essentials. Good morning, Neil. Welcome to the show.
NEIL: Yeah, good morning Ian. Yep.
IAN: Great to have you here. We've had a couple of false starts on this due to Christmas illnesses and all sorts of bits and pieces, but we're here now and the purpose of today's show is to help MSPs understand properly, without any BS, with complete straight talking, why They need to take security seriously, why they need to understand all about cyber essentials, plus what IASME do, where do they fit in this grand scheme of things? How do they work with, any of the governmental bodies, anything like that? And Neil's going to explain all of this great stuff to us. And we've also agreed that Neil's going to come back every six months. And we're going to do a bit of an update on what's going on with the program, what's going on in the world with threats and anything that he can share with us, I'm trying to prize out some of the juicy stuff, but he's been very careful on what he's going to say and absolutely for the right reasons as well. So welcome to the show, Neil. Do you want to just explain to everybody first, who are you, what you do and who'd you help?
NEIL: Yeah thank you, Ian. Yeah, I'm Neil Furminger. So I'm the head of Cyber Essentials at IASME. I've been working on Cyber Essentials as an Assessor and then moved to IASME for the last nine years. Cyber Essentials is my working life for the vast majority of that time, but I did work at a certifying body before I moved to IASME. So I've done assessments and see plus assessment, but my background is in IT support and I've had a 25 plus year career in IT support working in various MSPs, large PLCs. I was an IT manager of a law firm for nearly six years. So I've got a very wide ranging background to this that I use on a daily basis in my work around cyber essentials, it has my role of head of cyber essentials. I look after the technical aspects of cyber essentials, not the day to day administration of it, but the technical side. So I work very closely with the NCSC and I chair the technical working group that oversees the changes that happen on a regular basis, nearly on a 12 monthly basis for cyber essentials about the updated requirements, I also head up the question set. So I know all about the changes to the question set, et cetera. So I'm very deep rooted in this. Yes, and I work around the country speaking about cyber essentials, demystifying it, trying to talk about the misconceptions, et cetera. But I really do understand why we asked for these certain controls in cyber essentials, because I'm part of that decision process.
IAN: Lovely. And I it’s think fair to say we have the authority in the room today. So what I'm actually going to do Neil, next time we record our show. Before the show, I'm going to pop out some polls onto LinkedIn and emails and everything to ask people, what do they want to know from you? Because there is only one of you and you are flying around the country. And I'm sure that as this episode pops up, this is more of an introductory episode into, why do you need it? What is it all about? Why do we need it? And why does it keep changing and why is it clunky and why all these sorts of things we're going to, try and cover off today. So just let's get back right the way back to basics. For people who may or may not know who are IASME and what do they do? Where do they fit into the grand scheme of things?
NEIL: So IASME is the delivery partner for the cyber central scheme. On behalf of the N. C. S. C. So we work very closely with the N. C. S. C. on cyber essentials. Full stop. So five years ago, so it'd be five years in April, we became the sole delivery partner for cyber essentials. We managed the nearly well through between 350 and 400 certifying bodies for the scheme and the nearly 1000 assessors mark and advise on cyber essentials throughout the UK. And one of my jobs in that part of my role is to manage the consistency of how the scheme is applied at a technical level. So we do an awful lot of work about guidance, et cetera. So your authority to get the correct information about cyber essentials is via the NCSC or IASME. What I mean, we work with them very closely we meet on a, almost daily basis to talk about it and the technical working group, which I chair, which I mentioned earlier that meets once a week to discuss the changes and whether there's anything we need to consider for future updates so we're very much it's a partnership with the NCSE to deliver cyber essentials, which is crucial and but that also gives us a link in because there is a policy holder within government and that is the Department of Science Innovation and Technology and that they're abbreviated to DCIT and we work with people there closely as well to deliver. So it's a partnership between the three bodies and you'll see more on the advertising front. There is some new videos been released just before Christmas about Cyber Essentials, which will be used in collaboration between all three parties to promote Cyber Essentials across the UK.
IAN: Absolutely. Fantastic. So, Neil, the NCSC, that's the National Cyber Security Centre, yeah? What is it that they do and where do they fit into the grand scheme of things?
NEIL: They are the UK authority on cyber security. And they advise government, the crown, etc., and they are yeah, they're effectively the key holders to securing the UK and their advice is, recognized worldwide. They're part of what's called the five eyes. So the five eyes nations all work together to make the world secure in cyber security. So we work with the Americans, et cetera. But it's a lot, it's the public facing arm really of the GCHQ.
IAN: Brilliant. Okay. You must have some really interesting conversations that we're not going to talk about on this podcast on what the bad guys are doing, but I think what I just wanted to just share there was, where you're the enabler to help, MSPs with the tools around, cyber essentials, and you're getting some really great, you're working with the authorities on what's going on and how to keep, the UK safe. I think that is like the top of the bill for this one, we talk about, MSPs being a number one target themselves because of obviously the amount of customers and endpoints that they get involved in and how they're connected to it and yet it's still, and I'm not technical. It's still absolutely blows my brain out how many MSPs have not got cyber essentials. As a basic let alone cyber essentials, plus let alone the IASME cyber advisor, which we've done a podcast on before, and I'm sure we'll talk about today. Why, Neil? Why? Let's start with a different why question, why are people just not taking this seriously? Seriously why is this sometimes something that is it like an insurance policy? You only really get to get scared about it when you crash your car or you need to claim, because this is. For you and I, it's no brainer, right? But why is this something that doesn't get the attention and the focus in these businesses that it should do?
NEIL: I suppose if we go back in time a little bit, everything that we promote in cyber essentials has been around for a long time in IT systems, 20, 25, 30 years. Cyber essentials is based on some core principles, good asset management, blocking your incoming ports on a firewall, applying security updates in a timely manner using the principle of least privilege when are you talking about your user accounts? None of this is new, it's been around a long time, it's been around, certainly, it's since the mid 90s when we had NT4 and stuff like that with Active Directory floating around the controls in Cyber Essentials are based around preventing a, what a commodity or a common cyber attack. Okay, but the actual preventative measures to stop that are measures that any MSP should be putting in place because they are the key holders to all those IT systems they are managing on behalf of their clients, now they're managing them. They don't own those systems. They're owned by the companies and it's up to them to apply the controls correctly. But we know with MSPs and IT services companies, there is no regulator, there is no real trade body. It's a very vendor-led industry. And you're working on the best practices promoted by those vendors, and there are very good articles by the vendors, but it's trying to amalgamate it all rather, so not every house, and this is one of the things that or business, since the pandemic, there's a huge mixture and variety of vendors in use by different companies. What's the best practice for applying it across those different vendors, different solutions from Apple and Microsoft, etc. CyberEssentials tries to bring that all together, and I suppose for the first time really it's, we're telling you to do something, because that's what makes this accreditation, or certificate different to say, using ISO 27001. CyberEssentials is prescriptive in manner, you have to do this, you must do this, you must apply MFA on a cloud service, you must have a 12 character password if you've got no other protections in place. If you've got an eight character password, you must have a multi factor authentication in place or a password deny list, etc. And I think it's the first time, really, people being told you must do this on your IT systems. But everything is common sense. It's one of the questions that's often, we get lots and lots of pushback about cyber essentials. And because it's getting more common, that's getting less in the early days when we took over five years ago, we got a lot of feedback, negative feedback about cyber essentials. But one of the things that seems to always be agreed, though, is when you actually, I asked the question back. So I get lots of questions put to me and I go back to him and said, but do any of you would disagree with the controls in cyber essentials? And nearly everybody comes back and says, No, it's the right thing to do. It's just doing it at scale. So you have different issues to the sole trader compared to a big multinational or a medium sized company. So for a sole trader, it's, they don't have the technical knowledge. The small companies don't have the technical resources, a medium company and large it's because they've got to do it at scale. So one of the things we tried to do with cyber essentials, whenever we recreate the requirements we say, can this be applied to a single laptop? That is the foundations of the actual technical controls and moving it on. But coming back to your actual question, why aren't people doing it? Because they're not being told to do it, right? Maybe the insurance company is telling them to do it. We may need it for a supply chain requirement. You may need it for a government contract or a local authority, that's the main reason.
IAN: Okay.
NEIL: We are increasingly seeing people wanting to improve and I think it's one down to the fact that there are more and more conversations going on about Cyber attacks and the stigma around being attacked, there's a stigma about it. It's unfortunately, we still live in the world that people believe they're too small. Some companies, small companies are too small to be attacked. That's wrong, anybody can be attacked. It's when you're going to get attacked, not if you get attacked. And that's, we're still breaking down all those misconceptions, Yeah, everybody's connects to the Internet on a daily basis, and that means the whole world can connect to. So there's good guys you want to connect to, but equally, there are bad guys when you get back and try and run ransomwares or steal information, etc. And there's some basic things that can do to protect and they're outlined in cyber essentials. But sometimes that means, it's being told you've got to have a 12 character password and that doesn't go down well in certain companies. There's a lot of users of systems and MSPs are led by their vendors. We know that with the RMM tools, et cetera, et cetera. But it's trying to get those ingrained in there as best practices, and we'd love to see the cyber essentials is the best practices. Anybody should put in to start their cyber security journey.
IAN: Exactly. And I think it's, for us, we're working with lots of MSPs. We've worked with hundreds over the years. And We was doing the same thing to stand out and to really put yourself in a business, to build a lovely, profitable, automated hands off business means you need to have one that's going to do its best. I think is probably the most sensible phrase to be prevented from being compromised and your clients as well. I've heard briefly, I don't know too many details about the this Scottish charter there's talk about regulation and there's all these other things around, how does a business decide whether or not you're a good MSP and when they go through Google and they go through the websites and trust pilot and all these other bits and pieces, they don't really, we do see a lot of attraction on the ISO accreditation. So if you are ISO accredited, 000, whatever it might be, you will attract like minded businesses who go, oh, if you've got that means you're serious. And that means that you're serious about process and quality and time and controls and all of these types of good things. And we're now starting to see while the education in the space and, some of it comes through the vendors, there's still too many shiny balls out there for my liking, but that's a whole another podcast is that, if you have got CE plus, when people are hunting around for an MSP or they're looking for IT support, they're going to go, Oh, what's this? What does that mean about you? What does that tell me about you? And although it's not an ISO it's a good accreditation. So we've got, three key things that we're talking about at the moment, isn't it? The cyber essentials is cyber essentials plus, and then there's the IASME cyber advisors. Can you just explain the difference between the three? Cause they go in a bit of a level, don't they? In terms of ascension on expertise in particular.
NEIL: So the cyber essentials and cyber essentials plus work together. So the cyber essential certificate is where you do a self assessment questionnaire, which is then validated and checked over by a Cyber Essentials Assessor who is trained in understanding Cyber Essentials, has some experience in the real world, and they look at your answers and say, make a judgment on whether you're applying the controls of Cyber Essentials through your answers. Okay. The Cyber Essentials Plus then is the next level, which is where you get an audit, so there are a number of tests carried out by an assessor against a sample of devices in your IT estate and depending on how many devices you have, they will select, the assessor will select a sample of devices to be tested to check whether you're separating your user account from your administrator account, whether you are applying MFA to your cloud services, whether you are patching within 14 days, so they do vulnerability scan on your internal systems, and they do an external scan on your external IP addresses through your firewalls to make sure holes are blocked and you haven't got any vulnerabilities exposed, and then they do a series of malware protection tests against your web browser, your email system, etc. et cetera, and check that's all working correct. So that's it. There's that higher level of assurance because you've got somebody independent coming in to carry out an audit and actually saying the C plus we have actually put these controls in place where the cyber advisor comes in. So the cyber advisor is a different role within cyber essentials to a cyber essentials assessor. So assessor work is either a cyber essentials, verified self assessment assessor or they're a cyber essentials plus assessor. So they go in and do the vulnerability scans an advisor is somebody you can go and advise a company who's had no dealings with cyber essentials Certainly in the small sector and the micro sectors sized businesses and go and advise and give implementation advice on how to set up their systems to be cyber essentials compliant and that's actually we're finding through the process of having assessors and advisors, the advisors is a higher level because they're the people who should know how to do it because to do it across multiple systems and one of the things that is coming out through the exam and everything and what we tried to achieve, which is different from other advisory schemes and IT qualifications, etc. We're trying to assess their soft skills, how they communicate these technical controls across. And that's the difficult thing, that's a real, I think that's been discovered. That's a real skill. And so you become that higher level if you're an advisor. To be honest, and that's where I would encourage MSPs to go. I'd love to see a huge uptake in advisors with MSPs because they're actually doing the job. Go out, get yourself accredited, get yourself that NCSE badge, get yourself accredited that you are an advisor company and you will have You'll be on the database that we put on the NCSE website and then people that will get built up. We're trying to get things like crown commercial services, etc. To recognize the advisor and say you need to go and get your advice to cyber essentials from the trained advisors. Currently, we have about 100 advisors throughout the UK, but this is a real area. If you the MSP market, we'd love to see you there because they're already doing the work, get yourself accredited and show that you really can and you'll win yourself work, get involved in Cyber essentials. There's a huge ecosystem around cyber essentials There's always new developments going on with it and it's got a good steady growth every year 20 growth a year. So we've just celebrated issuing the 200 000 certificate in the scheme. So it took seven and a half years to get the first hundred thousand, two and a half years to get the next hundred thousand. So this is something that's growing and growing all the time and they're Some entry points for MSPs advises a great route into being part of the scheme.
IAN: And that's how we're actually talking today. One of our clients, Neil who is actually on episode one 199 of the IT Experts podcast telling you shameless plug how, and why it's exactly going into the detail that Neil's just talked about there about the benefits of becoming a cyber advisor and also the lead generating opportunities, the education opportunities and also the credibility opportunities that are Neil has got now with having that accreditation. So you've actually gone there. So from, I think when we recorded that episode, which was probably around this goes to show you how slow this is growing and therefore the opportunity that episode was around the beginning of end of August, maybe last year, we're now in January. And at that time it was 80 advisors. So that's only 20 in four months. And these people are seen as the pinnacle, the advisors the authorities. And we've got, I think we've got three or four of our clients who are advisors and, they are just right at the front edge of everything that's going on, which is brilliant. Neil, we've got some really great information here now. We're going to catch up again in six months time and we're going to get some questions put to you from our amazing MSPs. However, what's coming up? What's the new thing that's coming up in the world of CE plus and IASME?
NEIL: So from April, we have a new set of requirements out and a new question set and the code name for that is Willow. The IT world is vastly changing on the authentication. We're fast moving away from username and passwords, and we are looking at multifactorial authentication. So a third step, but we are actually moving away from passwords entirely. So we have passwordless systems, which we've not recognized in our in cyber centrals before and it's now written into the requirements that we recognize that but we're actually moving towards the use of pass keys. We are seeing it from some of the major vendors I noticed the other day that E-bay are now asking you to set up your pass keys to log in So that's using a device you have rather than something you know, your password, if you've got something in your hand, that's your passkey, which is your phone or a RFI key or whatever you want to call it. It's not something could be guessed a password can still be guessed and it's still the most common way to be attacked is password guessing. And that's something we're trying to protect against. So cyber centrals needs to move on and it's going to happen in a phase to stage. So this year we're recognizing a passwordless systems, passwordless systems exist and that they are recognized and can be compliant for cyber centrals. Another area, because we haven't done any changes for two years because we wanted to let multi-factor authentication take a hold within the scheme. Another area that is changing is about patching vulnerabilities, updating vulnerabilities. It's not a case of just being a patch or an update anymore. It could be a config change. It could be running a script. It could be installing a feature. Now that happened with exchange earlier in 2024. Where a critical vulnerability of 9.8 on the CVSS scoring version 3 for Microsoft Exchange, in order to fix that critical vulnerability, it said you need to install this feature if you haven't got it installed. So we're trying to protect from the critical and high vulnerabilities in cyber essentials, and we got to recognize that it's gone beyond just running a patch or an update. Nowadays, many do registry fix. So we've changed the wording and we now talk about vulnerability fixes need to be remediated. Within 14 days of being released by the vendor, we can't get away from the fact that somebody's got a critical vulnerability on it. It needs to be fixed. Yeah, we can't unfortunately, we have people, so it's not a patch or an update, so we're not going to apply it, but that's not fixing the critical vulnerability for the applicants, is it? And that's the most important thing. So they're the major changes. In C plus there's some changes it affects the assessors more but it's about they need to prove that the scope that is determined in the self assessment is correct and what they're auditing against when they come to do the C plus test, they need to test the segregation, the correct form of segregation in place between in scope networks and outer scope networks they're checking that the sample's correct. So that's the changes really you. If by doing it every 12 months, their steps changes. Three years ago we put in some big changes that was caused by the pandemic and it took a long time and it was seen as a very major change to the scheme. They were worthwhile changes because it was all about multi factor authentication but we do it in a more stepped way now so there'll be smaller changes but they're still significant in their own way. So that's what's coming but the roadmap for Cyber Essentials is to get that you're using pass keys. Over two, three years, I'm not sure what the timeline is, but that's the discussions going on and it's discussion. You will see articles come from the NCSC on a regular basis because it's very much UK policy to move to using past keys as the author. The default method of authentication.
IAN: So those pass keys then is that something that you'll generate yourself? Or will that be something that will be generated by a system or what? How's that different to a password?
NEIL: If there's many ways of it happening at the moment, but you'll see a lot of vendors and I see a lot of cloud services now starting to say you log in on with a passkey. I see Google use it an awful lot now. So basically you're not using a password directly to log in. You're using a phone or a code generated on it, or you're just saying, yes, it's me on there. So that's passkey, so there's normally something, there's some certificate. In the background or public key private key infrastructure that they've set up to log in So it's something that can't be guessed by an attacker that's why the move to the passkey is it makes you a hell of a lot more secure. We can all leave behind the stat from Microsoft that they published years ago by employing MFA on a Microsoft system, you're 99.9 percent more secure than if you don't. There are lots of stats to prove the new authentication methods are far more effective.
IAN: Lovely. Lovely. That's great. Neil, it's been a very insightful show. Interesting into what's going on. Interesting into continue the conversation. I think as we move forwards with these regular shows, it'd be great to get into maybe some of the things that people can do to make life easier to people can do to help them get through the accreditations if they're struggling to do that, or even maybe to get buy in from their clients or even from other members in the team, because a lot of the time we do talk about. It been a bit of a marketing exercise and you need to educate and we need to educate people on why they need this rather than sit there and talking to them about lessons learned after they've been compromised. And you've spent hold of your Christmas break, trying to get all your clients data back, which nobody wants to be doing. Any final remarks, final comments for you on this one before we wrap the show up?
NEIL: I think that's the really, you just mentioned the really important word. It's not about a sales thing. Cyber essentials is education and getting people to put the controls in place. That's the main, I don't, I'm not a sales person by any, I feel I'm an educator on this and I'm an educator to everybody who's involved in cyber essentials about why the technical controls. And I'd love to talk about that on the part more, the part that MSPs could play in actually securing their clients by adopting it within their support services. It's really important to me. I've seen it working in the MSP industry and having created a certifying body, how it can be of benefit as a service to the MSPs, but also to the clients. And that's ultimately what this is all about, protecting applicants and clients who adopt the controls from a common cyber attack. And that's the most important element here. And that's what we've all got a part to play in it. Everybody who's involved in cyber essentials, everybody who's involved in the IT services support industry have all got a part to play in securing their clients and applicants to the scheme.
IAN: Lovely stuff. You might regret, be careful how you answer this next question, Neil. If anybody wants to continue a conversation and ask you a question, maybe how do they do that? I'm not, why don't you just give them, give everybody, give the world your email address and then you get bombarded with it. But, if people want to have a chat, they've got a query, they need some help and they need some support. What do they do?
NEIL: Actually I do give out my email address and we that's one of the things we are at IASME. We want to be approachable. We want to hear people's feedback. We want that. So we give out our email addresses. That's not a problem. And it's NeilFurmingeratIASME.co.uk. I may not answer all of them. What I may do is pass it on to our skilled team of technical support we've got. So we have a technical support team for Cyber Essentials and we can answer any of your questions. So we, like everybody, the scheme's grown, IASME has grown significantly over the last five years. So we have these support mechanisms in the background, but I'm approachable email, drop me an email. You know if you're wanting if I'm not around it's info at IASME.co uk, and somebody will pick up your query. It's we're here to be approachable if we don't if we didn't make ourselves approachable, we're not going to solve this big problem and that's making the UK more secure
IAN: Exactly.
NEIL: And it's really important to us at IASME that's what we want to do.
IAN: So we've gone full circle on that. It's just about keeping everybody in the UK secure.
NEIL: Exactly.
IAN: Thank you very much for your time, Neil. I know you're doing a fair chunk of podcasts. I appreciate your time. And we did get this one done. If anybody's got any questions, either email, Neil, drop us a message. We'll include the question in the next podcast, in the next update we'll do. In the meantime, you look after yourself, you take care, keep safe. And we'll keep on the warpath, as it would be look forward to seeing you soon. Cheers, Neil.
NEIL: Thank you, Ian. Cheers.
OUTRO: Just before you go, and if you're curious about how this episode links with the ability to scale your MSP to a million or, or if you're already there, accelerate to five, then we want to invite you to come and take the MSP mastery quiz. And in just three minutes, you're going to get a 360 degree scan of your business where you can identify the one or two tactics that can help you find more time engaging along your people and help generate more leads in your MSP. It's really simple, just click on the link in the show notes. And if you have enjoyed this episode, we'd love to get some feedback from you by means of a rating, review on Spotify your podcast platform of choice. We really appreciate every single one of them. Now you can go and enjoy the rest of your day and we look forward to catching up and connecting with you soon. All the best now.
OUR TRUSTED FRIENDS OF THE GROWTH HUB