EP242 – Stopping 365 Breaches Starts with YOU with Scott Riley & Ian Luckett

IT Experts Podcast - The MSP Growth Hub - Ian Luckett - The MSP Growth Hub - Scott Riley - 365 - Podcast Episode 242 - UK

Click below to listen to the episode

In this episode of the IT Experts Podcast, I sit down with the brilliant Scott Riley from Inside Agent. It’s taken a long time to get him on the show, and it was well worth the wait. Scott brings years of practical experience, straightforward advice, and a refreshing perspective on what MSPs must do now to properly secure their Microsoft 365 environments. 

 

Scott Riley has worked with MSPs for over six years, helping them tighten up their security practices and take real control of their 365 tenancies. In this episode, be prepared for the shift in mindset that Scott encourages. The idea that you are too small or not interesting enough to be a target is no longer valid. The reality is that attackers are not selective. They cast a wide net. If your MSP gets breached, the damage can extend far beyond email. Your PSA, RMM, partner centre, licence platforms, password vaults and all client environments are at risk. 

 

Scott Riley explains that token theft is one of the most common attack methods in play right now. A stolen login token can allow someone to log in as you without being challenged. If your global admin account is tied to your day-to-day login, the attacker has immediate access to your critical systems. Many MSPs still store MFA tokens inside password managers alongside usernames and passwords. It might seem convenient, but it undermines the whole point of multi-factor authentication. 

 

We explore the emotional and financial consequences of a breach. Scott shares a real-life case where criminals sat silently inside a business email system, watching communication styles and eventually mimicking the MD’s tone to authorise fraudulent payments. The losses started small but escalated quickly. These attacks are personal and targeted. For a small business, losing six thousand pounds can be the difference between making payroll and laying people off. 

 

Scott stresses the importance of making this real for clients. He talks about positioning cybersecurity not as a technical need but as a business-critical risk conversation. Instead of relying on fear or jargon, help clients picture the consequences. What would happen if they were locked out of systems, lost money, or lost their reputation? Clients need to be educated through impact-based questions and examples they can relate to. 

 

We also cover the responsibility that MSPs carry themselves. Cybersecurity starts with you. It must be owned by the business and led from the top. While the technical work can be delegated, the responsibility cannot be passed on. Regular reviews, clear security standards, and the discipline to follow them are essential. Inside Agent, Scott’s platform, helps MSPs quickly assess their Microsoft 365 environments and bring them up to best practice. It gives a live compliance score, offers guided fixes, and creates ongoing visibility. It is designed to simplify the process, not complicate it. 

 

We discuss why compliance frameworks such as Cyber Essentials Plus should be a minimum standard, and how the upcoming UK Cybersecurity and Resilience Bill is going to push MSPs to meet new legal requirements. With MSPs being seen as part of critical national infrastructure, business owners need to ensure that their internal environments are secure and compliant, not just their clients’ systems. 

 

Scott Riley shares clear recommendations for securing 365 tenants. These include using hardware MFA tokens, enforcing location and device-based access policies, reviewing and removing unused app integrations, ensuring third parties such as accountants or offshore VAs have the right restrictions in place, and stopping the use of global admin accounts for daily operations. He encourages every MSP to sit with their team regularly and walk through breach scenarios to build internal clarity and confidence. 

 

The message is simple. Know where you are exposed. Fix what needs to be fixed. Get independent validation to confirm it. This episode is full of practical, plain-speaking advice that any MSP can follow. Scott Riley brings clarity, urgency and support to an area that often gets ignored or pushed to the bottom of the list. If you want to protect your business, your team, and your clients, this episode is the reminder you need to act today. Thank you, Scott, for bringing such clear value to this conversation. 

 

Connect with Scott Riley on his LinkedIn profile by clicking HERE. 
Or you can also find out more about Inside Agent by clicking HERE. 

 

Make sure to check out our Ultimate MSP Growth Guide HERE, and remember that the help is out there. You just have to go get it. 

 

Connect with Ian HERE on LinkedIn and also Stuart by clicking this LINK 

 

If you’re ready to take the next step in supercharging your MSP, take the Scale with Confidence MSP Mastery Quiz. This tool is designed to help you understand where your MSP stands and what steps you can take to scale profitably and effectively. This will provide you with insights and guidance tailored to your specific needs.

 

OR to join our amazing Facebook Group of over 400 MSPs where we are helping you Scale Up with Confidence, then click HERE 

 

Until next time, look after yourself and I’ll catch up with you soon!  

Check Out the Full Transcript Below:

IAN: In this episode of the IT Experts Podcast, we're going to help you work out why stopping 365 breaches starts with you.

INTRO: Welcome to the IT Experts podcast, the only podcast to help MSPs scale to 1 million, and if already there, get to five and go faster at the end of the day. Isn't it all about building a business that works for you rather than you for it? I hope you enjoy the show.

IAN: So good morning, good afternoon, good evening. Welcome to the IT Experts podcast. I've got a real special guest. I've been after this guy for two years now. Drum it up. Drum roll. Welcome to the podcast lounge, Scott Riley, how you doing?

SCOTT: I am good, man. Oh, thank you so much for having me on this podcast. I tell you what, I've been going through the back catalog and I am in some bloody good company here, so thank you so much for having me on. I know we've been fighting to get together, so this is awesome. I'm so glad to be here.

IAN: We have, and it's all because he's probably got his personal email address on his LinkedIn page, but anyway, that doesn't matter. That's a whole nother story, right. Why are we talking today? So recently caught up with Scott at at the show and we've been talking about 365 environment and securing your tenancy because we all know, it's obvious is that noses on our face, that if an MSP gets breached it's a bad day, high risk, and we know about that. And what we're going to talk about today is how we're going to help you understand steps to take to protect your 365 environment in 2025, because it's probably different than it was last year. Because we've got more bad guys, clever bad guys. And as we were saying, probably younger, bad guys as well, which makes us feel even worse and even more determined to solve this problem. So this is going to be around security. This is going to be around helping you get that environment nice and secure and and safe for you and for your clients. But in the meanwhile Scott, just give us a little bit, who are you, what do you do, and who'd you help and what's been going on in your world in the last couple of years?

SCOTT: Yeah, man. Oh, it's been hectic. For the last six years or so, we've read this lovely consultancy of Cloud Nexus, so you've probably seen this everywhere with our little clouds and rockets and cloud. Yeah, our mascot, we've been trying to get him everywhere and it's really lovely because people are always like, oh, can I get a cloud? Can I get yeah, yeah. I've got a wall full of them. They're back there. Get one sent over for you. But yeah, it's been so nice. We've been consulting with the MSPs and helping them with their 365 security. That's what we've been doing for the last six years. But mostly like consultancy work. Yeah. And any of our partners we work with, they might have 20 tenants. They might have a hundred, they might have 400. And pretty much we might help them with one or two. It's always been in our hearts to go well. How the heck do we help you with all the others? There's not enough hours in the day for us to do all that kind of consultancy, but we figured can we streamline it, automate it, and that's where we came up with this crazy idea to make a SaaS platform. And so that's, the last two years have just flown by that's been absolutely crazy. I tell you what, running a SaaS business is very different to running a consultancy business. Oh, consultancy. It's so nice. It's so slow. It's lazy almost. You're like we'll choose who we work with and when we work with them and, oh, it's so nice. SaaS, oh my God. You don't stop, you don't, you just... it's just

ah,

IAN: This constant just driving forward. Yeah, because we saw you at the MSP show and it was hilarious story, where our clients have created their own, and this is genius, they've created their own discount scheme. So for all the vendors out there, be very careful of the MSP growth hub clients. Because I was standing at our stand and Scott sent over all these gifts and it came from his team and it's oh, we, Scott is the most, send us all over to Thank you. I'm thinking what I thought, I haven't seen Scott for 18 months. I thought, what's going on? It's no to thanks. So I came over and we had a chat and yeah. Tell us what the cheeky little sods have been doing, Scott.

SCOTT: Yeah. So all of your members, as cheeky as they are they've all been talking to each other. So one of them obviously got in on our early adopter program and there was like a good price point for that. Really low price, but really good. And they've obviously gone back into the Growth Hub and gone tell you what guys, you could ignore that retail price in. Just tell them to get the MSP growth hub special price. And so now every one of them turns up and I'm like, yes. Alright, of course you can. So they've all been getting this special discount just for being members of the MSP Growth Hub. So I'll tell you what it works.

IAN: That's, and it's, and that's right. And I'm sure there'll be a podcast discount as well.

If you mention the, and there'll be a cheese pay discount then.

SCOTT: That's right. Yeah. It feels I tell you what, I'm glad Ben isn't in the room with me right now because he always tells me off there's a discount or a bargain. Oh, honestly, he's a good old fashioned New York showman.

IAN: Yes. We have a few we have a few from that neck of the woods, and I know what you mean. So the reason that we're talking today is to to find out what's the latest things in 365, environment security. What's your view on where it's changed in the last, couple of years maybe Scott, and why do we need now to really start to take this seriously rather than just some MSPs take security a bit like your car insurance, don't you? It's all right until I get, and then I'll find out whether it works or not, by then it's going to be too late. Because you're not just going to have a dented wing, the whole car's going to gone, isn't it? Yeah. So it's a serious environment. Talk to us about the environment because some people think hopefully not so many now that it's in the cloud, it's safe, everything's okay, backed up, everything's in, if it goes wrong, I've got it. It's all in the internet. It'll be far. They're a bit wrong there, aren't they?

SCOTT: There are a little bit, yeah, yeah. I always like to think as well, like sometimes you can find MSPs are a bit like plumbers. Where they've saw it out everyone else's problems, but they saw that leaky tap at home. And I think that can be a bit of a risk, but I'll tell you why. It's bothering me more. And it's one of the reasons why we're, we do what we do in that consultancy world for the last six years as well, is if you look at what's happening now, we've got, we've always had script kiddies, finding a little bit of stuff on the internet, something in GitHub, running it, sit, just trying what they can do. And do you know, when you talk to like small businesses as an MSP trying to convince them to do cybersecurity's hard? Because they're always like, I'm too small. I'm not interested enough. I haven't got enough stuff worth stealing. No one's interested in me. And we have to try and convince them, look, no one's actually targeting you as an SME. They're just doing like these big spray attacks and they'll find some email addresses on the internet and they'll have a go and they'll see if they get in. And so we have to as MSPs, we have to convince the customers of that. We're having to convince the MSPs of that, because again, some of the MSPs are going, oh, we're not interested. No one's really bothered in us. It's our customers that we need to worry about. And I'm like, no, let's just have a think about what happens if you get breached. Yeah, because if someone and like token theft is one of the most prevalent attacks that's happening right now. Because it just walks through everything like your MFA tokens, doesn't matter. It just walks straight through everything. If someone can steal your little login token, they could just log in as you, it doesn't matter where they are, they'll just log straight in, won't get challenged for anything. Microsoft goes, oh yeah, you've logged in before. Cool. If you get breached as an MSP, you've got access to your emails fine. Yeah, your files. Okay, fair enough. Is your Microsoft partner center connected to that global admin account? because I bet it is. And so now we can go and see all of your customers and we can probably even go and administer some of those customers straight away. What about your PSA or your RMM platform? Are you using single sign on with Microsoft as part of that, because if they're breached, your Microsoft account. Now they're straight into your PSA and your RMM. So not only can we see your customers and or the invoices potentially and or the account details there, but we could also remote manage them as well. And I'm like, holy crap. Yeah. Like we've breached one account and we've got access to, like I said, the average of 22 tenants, 22 customers could be a hundred, could be 400. What about your billing? Do you get, do you do your billing through somebody like PAX eight? Do you buy your licenses through those guys? Has that got your single sign-on integration? Because the great thing is we've done this beautiful thing of going, oh, I tell you what, if we're going to bring a product into our stack I'm going to make sure that it uses single sign-on with Microsoft 365. Because that way it's easy for my texts and we can all log into the same platform. Our password manager's in Keeper and Keeper uses single sign on, so that gets into 365. So now Oh, great. Okay. So if I can get into 365, I can get into your password vaults, I can get into your RMM platforms. I get to your PSAI can get to your licenses. Bloody hell I've literally got the keys to the kingdom and it's terrifying. When I think about that is and that's why it makes me look at if we do and thank God we're not, but if the script could wake up to this and start attacking MSPs, are we really set up properly for this? Are we ready to be, defended and I'm having worked over the last six years with MSPs and seen their 365 - 10 seen their customers. No, we're not. We're not ready. There's a bit of work to do

IAN: And it's frightening, isn't it? We've been chatting with Neil from Neil Furminger from IASME and every single MSP who's listening to this podcast, absolute minimum should be Cyber Essentials plus, without attack.

SCOTT: Bare minimum

IAN: If not start climbing up the IASME cyber advisor route and all of this sort of thing. And I don't know I say, I don't know why it's something that they're not really getting focused on. But one thing I just want to just dig into is you're saying about convincing the customers let's just spend a couple of minutes, talking about how do we convince the customers to see if we can help the MSPs convince themselves that why this is so bloody important. We know that many MSPs don't like sales conversations and they don't like having that difficult conversation. And within our new client runway framework we use for sales and marketing, we do not let any MSP like even think about doing an event or a lead magnet going into anybody else's content unless they've worked out their compelling position as we call it, which is who are they, what do they do and who, how do they help them, so important that you understand this, but not from a technical point of view, from a business point of view. So how would if I was a customer and I just said the things that you just said to me, which was, look Scott. I know what you're saying, but I'm all right and everything's okay. I'm not big enough, all of that sort of stuff. How would you start to convince me or start to, go down a script that would lead me into saying, God, I really need this.

SCOTT: Yeah. So I think that the way that I always look at stuff like this is a bit like Apple products being advertised on TV. Yeah. It's never about the texts and specs and speeds and feeds. It's about the lifestyle. And so when I'm looking at this stuff and it's around cybersecurity with a client, an end client, my conversation would be around what would be the impact if this was to happen? How's it going to affect your business? How's it going to impact your people? What happens when there's no money in the bank and you can't make payroll? How is that going to impact the business? Yeah. And what about your customers when they now recognize you've been briefed? Is that going to lead to churning customers? Is that going to lead to a loss of confidence in you as a supplier for them? Yeah. And so what does the future of your business look like? And especially when you're dealing with small businesses, I've seen like , the guy who spent 26 years building up their business and they've got a small team of 10 people and they're really enjoying it and everything's great and they, they make a bit of money each month and then suddenly six grand has gone out, the bank account mysteriously, and they're like what's this? And someone's been in and they've compromised the email.

IAN: Yeah.

SCOTT: And they've convinced the girl in accounts because they've watched, they sit and they watch, and I've literally, this is a real case that I've seen. They sit, they sat and they watched like how the MD would talk to the finance team. And unfortunately in that case the cadence was very much this account, this sort code, account number, money go. And that's how he would communicate with them. So that they were in there and they just went, it can't be this easy. So they just sent her an email from him, sort code, account number, money go, and they got paid and they were just like, bloody hell. So they just went larger and larger amounts each time. And so they would just keep trying out. And so when you talk to those business owners and you tell them where the real stories, I know we've all seen M and S is the latest one, but British Airways, we all see the big brands, right? But when you look into the eyes of someone who's a small business owner, who's their business has been absolutely destroyed. Like six grand going, missing is no joke to some of these small business owners. We always look at the millions, right? But six grand could be the difference between not making payroll this week. Yeah. And so for me it's about the impact. Help them really stop and think because the general approach is just I can't hear you, that they don't want to pay attention. So help them put it in real terms. What's the actual impact? There's some great like tabletop exercises that you can go through for this stuff as well, but it's probably a bit heavy. I think you can just have a genuine one-to-one conversation. Just because no. Let's just stop and think for a second. Because this is really what's happening in small business everywhere. And again, you're right. You're not big, you're not special, you're not fancy, you're not clever, you don't really have anything worth stealing, but that's not what they're doing. They're just literally going to hit anybody and try their look. And if they get a couple of grand out of you and a couple of grand out of the next one, they're still making tons of money.

IAN: They're doing all right. They're doing all right.

SCOTT: Yeah, but this stuff is weaponized now as well. And you don't really need to get into the massive fear, and doubt side of things. But you can literally rent like farms of machines to go and attack organizations and break in. You don't have to do it yourself. It's so super simple now.

IAN: Crime is a service.

SCOTT: No, it is. And so genuinely on the dark web, you can literally get these things as a service. You can rent farms of computers to go do it for you and just let you know when it's got in.

IAN: Unbelievable. Unbelievable. We'll stop talking about that, because that sounds like a really good idea.

SCOTT: Sorry. So for me, good idea. It's about the lifestyle. Think about Apple, think about how they showcase their products. Think about what would it really be like if you got breached,

IAN: And I'm going to, recognize something that Greg Jones said. A few years ago now, I was at a COMPTIA to talk and I remember doing a video about it. He said, get your clients or get your MSP, get them all in a meeting room ad hoc meeting. No one knows that. They're coming. Put them all in the meeting room maybe at this conversation you've had right now. And you say, okay. Everyone, we've just been breached. You can't get access to the internet. You can't get access to any files. What are we going to do? And the first thing is he says, people will pick up their phones and go, no, put your phone down because you can't get access to it. And I go have you got a paper? Who do we ring? What's the phone number? You haven't got access to it. How do we get into the, or what? And that moment, and I can see you now go, bloody hell. I'm thinking about this myself. It's what do you do? So the MSP every year MSP should be sitting together, all the techs and everyone saying, guys, what do we do? How do we protect ourselves? What does that kind like look like? because it is that impact of the of the end result, isn't it? That's the major problem. At the recent show, the MSSP show, we saw many shiny balls, didn't we, Scott? By means of all these wonderful new technologies and some of the times, I've said many times before, I'm not technical, but we work with technical people and we hear every week in the growth hub, oh, I've tried this,, oh, I've got that, oh, I've got this, oh, I've got this. And if you were to deconstruct it, you could probably get rid of half of them because we know most of them probably do the rest. And if you have good account management with your vendors, then you should be able to cover off a lot of the duplication. But what, this year, in 2025, what is the things that MSPs need to be doing to secure their MSP environment? And I think. We'll move on in a minute but secure and know that their environment is secure. Because I think that's the thing, isn't it? You can always plug a widget in and go, oh, the lights are green, everything's okay. But does that really mean that it's okay? And are there different levels of depth on this? So what's your take on what first level 101 security should look like in a 365?

SCOTT: Yeah. No, and I think there's simple stuff there as well. For me. It comes down to a couple of really simple things. I'll obviously talk about the 365 side of things. Because that is obviously my main focus and has been for the last few years. But that is in a lot of cases, the heart of the identity part of all those MSPs, right? So that is where they're using their main emails and passwords are in there. Have you got it locked down? Have you properly got it locked down by country, by device? Are you using like hardware tokens for your global admins rather than just, simple authenticator methods? Have you and I know the answer, have you built in a password manager and in that password manager, do you store the username, the password, and also the software MFA tokens? Because I know that you do. And so again, our two factor authentication has just become a one factor authentication, because it's all sat in the same bloody password vault. I know that we do this and I don't know why some people are a bit more savvy.

IAN: Have you heard complain about 2FA, Oh, what are pain this is, oh, I've got to get my bloody token. I've got to get this out. I've got to get that. Yes. And the thing is, it's that we hear MSPs talking to each other about it, moaning about it, and they're the ones supposed to be advocating it.

SCOTT: And then they go, don't worry, I've made it easy. I've just put it all in keeper. So when I go into keeper, it fills in the username password and the MFA code for me. I don't have to press anything in. You're just like, okay, I understand why that's easy. That is not a good choice. So yeah. So look, it's, that's the basics, but again. It's the simple stuff. You can then have location policies. You can then have device policies. You can make sure that only these devices from these IP addresses can be locked in, like serious stuff for breaching MFA and token theft and stuff like that In 365, if you were to use something like a VPN service, I know there's many of them, right? Yeah. But there's many enterprise grade VPN services, if you were to use one of them and lock your 365 instance down to that VPN provider. So now the only people can log into your 365 is if you come in through that VPN and that's the only way that you can get access. That's one way of doing things. And it could be a bit Draconian for some people, but it stops you, getting all those random IP address attacks, someone trying to log in from Russia or China, wherever it is, all of that stuff goes away because you can't literally can't log in hardware tokens, like your little UBI keys are your global admins using those, because they are physical hardware tokens, like they're not going to get a session breach from somewhere else in the world. It's a physical hardware token. And we always talk about using stricter hardware for global admins and stricter MFA methods, but people don't, they still use the same ones that are at risk of phishing. And again, I don't want to be too techy and boring, but it's these simple steps that we all know. The MSPs? No, we're just not doing it because as you said, it's easy. Yeah. And my genuine concern is, and I think we've known this for a while, it's been a bit like the Wild West in MSP, a lot of the people listening to this podcast are probably the more forward thinking MSPs, right? Because they've taken the time to invest and listen to something that will help them grow their knowledge. Probably, we might even be talking and preaching to the choir, Ian. We might be talking to the wrong people, but it is a bit of the wild west. They've got all the other cowboys. It's a bit like cowboy builders. I'll show my age and going back on BBC but, it's a bit like that and rogue traders, there's so many of the other guys out there that are not doing this. Yeah, definitely. I think the good guys have been crying out for some kind of legislation or compliance or something, some kind of standards that needs to happen in this industry so that we can get rid of some of these rogue traders. And I think that is finally happening now with this UK Cybersecurity and Resilience bill. So that's the thing that was announced in the King's speech this year that they're looking to bring in as of next year. And that is going to say that MSPs are essentially a critical infrastructure provider. And I grabbed the words, the word says because of their unprecedented access to clients' IT systems, network infrastructure and data. And because of that, they are going to be putting in a lot of checks and balances. And again, it's exactly as used earlier. Cybersecurity plus is, or cyber sensor plus is one of those bare minimum requirements. But there's also things in there now that are like mandatory. If you have a breach, if your client has a breach, you have to report it. We all know you're supposed to report to the ICO, but again, a lot of MSPs aren't registered with the ICO. So if you're registered with the ICO, you're supposed to report to them. But again, under this bill, there's some wide ranging impacts. I'd encourage MSP owners, especially again, listeners of this podcast, because I know you're more forward thinking. Go and have a read or do yourself a favor. Ask your best friend, Chad or Claude to summarize the Cybersecurity and Resilience Bill, and give you the bullet points because it's a long gold document. But get the highlights, get the cliff notes, and understand how it's going to impact your business. And I think this will drive you back to going, where's my holy crap moment? We need to make sure that we're doing things properly, because if we're not safe, none of our customers are safe. No. And it doesn't matter how well we've set them up and how many items we've put in our stack, and how many bits and bobs and shiny goobers we've added, if we're not safe, they're not safe. And exactly as you said earlier, they could even do that once a year, sit around the table and go, we've just been breached. What do we do?

IAN: What's the SOP?

SCOTT: What happens next

IAN: And keep quiet. Very impactful points there. Scott, is there anything else that's, you've just mentioned some of the things about the, turning some of the tokens and approvals into the physical hardware sort of thing. What are some of the other things that MSPs need to be absolutely doing either on a daily, weekly, or a monthly basis to ensure that they've, or know that they've got themselves in a green light, a sea of green light position as it would be.

SCOTT: Yeah, definitely. I think, again, this comes down to some of the other stuff that we talk to our customers about, but we probably don't practice ourselves potentially. So supply chain management, and you're like, that sounds really boring. You are like, yeah, okay. But, most MSPs especially the smaller ones, will have someone who does their outsourced accounting. And it could be a local bookkeeper, who's really lovely and I know our local bookkeeper is really lovely.

IAN: Everybody, the most, everybody, local bookkeeper are really lovely.

SCOTT: They are.

IAN: You ask them to do something special on or something oh, hang on a minute. I'm not technically

SCOTT: yeah, but they're not generally very tech savvy either. No. And you've probably give them access to your zero or, whatever other finance systems you've got. Ours has access to things like our Amazon account and some other things as well, so they can go and log in and make sure they can get access to different things. And they've got a 365 account so they can handle the mailbox and all this kind of stuff. And you're like, worries me that they have access to quite a lot of sensitive data. Yeah. And they're not the most tech savvy people. Yeah. So again, we've had to put guardrails in place to make sure, okay, can we limit the access? Can we force MFA on those people? Can we lock it down to their office so they can only log in from there? And just try and put those guardrails around people that, we know have to have access to our sensitive data, but try and do it in the most sensible way possible. I think, again, we've probably just gone, oh, it's the accountant, we know they need access. We'll let them into this system and that system. But what happens if your accountant gets breached? Because again, they're great targets for this stuff. These guys want money. Yeah. They want money. Bay, yeah, go and sell your accountant some MSP managed services and make sure you got them set up properly. That's a great idea. Yeah. But I think, looking at your supply chain, looking at your partners and who's got access to your platforms is really important. I think the other thing as well is you out there with your shiny tool collection. You know who you are. You go to a trade show and oh, shiny and go and plug something in, and then three weeks say, oh, shiny, you can plug something else in. How many things have you got connected to your. Infrastructure now that you don't use. How many of these management tools, automation tools, security tools, assessment tools, how many of them have you left lying around that you're not using, you don't need? But actually what it means is your customer data, your end user client data probably is sat around in a million different systems that you're not even using anymore. You might even still be paying for them, so I might be saving you some money here. So go and turn them off. But remove them, disconnect them from your system. Remove them from your, if you want to be technical, your enterprise apps in 365, go and kick them out of there because you're not using them. But I tell you what, you've still got that instance of whatever setup and it's still pulling your customer data and sticking it in their database. What happens if they get breached? You're not even using it. So again, think about just reducing the risks, not just from your own team, but also the apps that you've plugged into it. The people that you've got connected to your system the lovely accountant that you trust. Because they're lovely. Again, some people have hired offshore executive assistants. Okay, great. Have they been locked down? Have you done the proper licensing? Are they using good conditional access or location policies? Yeah, whatever it is. Again, can we be sure? Because again, these shared EA and shared resources, they have access to lots and lots of different people's platforms. Yeah. So again, they might pick up some nasty phishing or virus or whatever from someone else's platform who isn't locked down and now they're logging into your system as well from their machine. Did you give them a machine to work on just for your work, or are they just using a general purpose? Just get this, there's loads of these little things that you could just pick up and go. Let's just look at our risk exposure. As an MSP look at all of our entry points and be really clear about it and say, can we make some sensible decisions? Are there anything else that we need to look at? And then, you can start to feel a bit more confident, but your second point of your question earlier, about 20 minutes ago before I started rambling on Ian, was, once you've done that, how can you be sure? Yeah. You said, I'll tell you what, Scott, you're looking handsome today. No. You made the point of, how can they be sure. So have they checked all those lights green and how can they be sure. And the how can they be sure is to get audited. So get someone in to do an assessment. Are you doing your cyber essentials plus assessment? Are you doing any other kind of assessment to make sure that actually the doors bolted and all that kind of good stuff? Are you bringing anyone in to do those checks? Yeah, because I think it's always great to have something that looks at the platform and goes, tell you what that is, set up properly. Here's a load of green lights and we've checked it. We checked it today. We'll check it again tomorrow.

IAN: Because self-governance is great, isn't it? But having someone else qualify that this is best practice for what we see and some of the things you've mentioned there. I have absolutely no doubt that there'll be MSPs, whether they're driving or walking or just listening to this in the office, scribbling down notes going, shit, we're not doing that, or We need to be doing this, we need to be doing that. While we were just talking then Scott, and I think that was a great technical ramble, wasn't a ramble. It was a great little line of things to consider. I'm hearing the MSPs going, but I'm busy enough as it is. Why have I got now faff about with all or not, why have I got a faff around with this? Let's just talk for a minute about, obviously the buck stops with the business owner. Okay. But let's talk about the hierarchy of ownership of this and what you would recommend. And if we set a typical MSP of, I'm going to say, 8-10 people, something like that you've got some emerging senior people and coming up within the help desk, does the business owner have to take this whole burden on themselves? Or is this something that you could. Quite easily like layer down through the layers of the organization into targets and into processes and SOPs that are owned by other people. What would, in your view, what would be the optimal way to cascade this important task or subject.

SCOTT: So I think I would look at this the same way in that I would have a conversation with a client, right? So when you talk to a client about their cybersecurity and you're selling them a stack or a product or a service or whatever it is, I would hope that we make it really clear that although they're outsourcing their cybersecurity to you as the MSP, they are not abdicating responsibility for cybersecurity. So they have made a choice to use you as the MSP to sort out their cybersecurity, right? But they are still ultimately responsible and they have to be convinced themselves that you're doing the right things and you're checking the right things. I think the business owner for me is still ultimately responsible because when it goes wrong, they're the one that, again, if money goes missing, you can't make payroll. They're going to want, they're going to have to make massive decisions very quickly. And the impact is huge. And I've seen when this happens in MSPs, and I've seen I actually saw a team of guys retelling the story of what happened when their MSP was breached. And even telling the story again, three years after the event, the guy was almost in tears as he remembered the stress and the pressure of everything that happened. And some people just wouldn't come back. They'd been working all weekend, they went away and some guys just wouldn't come back in. They're like, guys, I just can't, I can't deal with it anymore. It's just, it's too much pressure. So don't underestimate the impact that somebody like this can have when it's your MSP that gets breached. But I think as the owner, yeah, you're busy. You can't do it all yourself. You've got to have the trust in your teams to get these things done. And so we've got to delegate those tasks out. But it's got to be very specific objectives and achievements and you've got to be convinced and not flannel by the team underneath. Because the, again, the team are going to be busy. Everyone's busy. But make sure that you set out what are our objectives. And again, this is where, external auditing can come in. Because it makes it real simple, right? Either we passed that audit or we didn't, and there's no internal politics to say, ah, yes, but no, it's a fail mate. We need to make that red light go green. So I think don't take it all on yourself. Do make sure it's a team effort, because again, when the crap hits the fan, if something like that was to happen. It'll be an all-nighter for everyone. Everyone's coming in, everyone's working nonstop, so it's in everyone's best interest to make sure that we get this right. And so I think as the owner, bring your senior team into this, make sure it's an objective for the year and for every year that you know your infrastructure is as tight as it possibly can be. And then obviously you can cascade that security levels out to your customers. But make sure it's reviewed regularly. It's got to be on your quarterly objectives. It's got to be checked at least quarterly that you are happy with this stuff. Ideally, I'd be looking at things that are like monthly checks. Say, have we still checked? We're still in the right place. Any systems that we can do daily, fine. But that's too much for your business owners. Your business owners need to be able to stop at any point and say, I want to know right now where in the best security place that we could be. And that's only going to be through, the right systems and the right processes. Not just shiny tools, but making sure that those checks and balances are in place.

IAN: Scott, brilliant. Bucket load of information there that I'm sure the MSPs are going to go back and listen to again and tidy up and build into a bit of a plan of their own. Just before we close out the show, what are some of the top things that that everybody needs to take away from a high level point of view? It's a bit like doing an AI summary, isn't it, on the whole podcast of all this. What would that look like, Scott,

SCOTT: I should have asked Claude to do it whilst we were chatting. You could. Look, so I think the simple thing is for me, go back today. Go and check that for me. Your 365 environment is set up properly. Make sure that it's locked down properly. You've got good conditional access, you've got location-based policies, you've got device-based policies, real simple stuff that you are using the phishing resistant MFA for your global admins, that is really important. Again, we're all using much simpler methods, and I'll tell you the two things that people keep getting away with but shouldn't. One is using their global admin account as their day-today account. You know who you are. You know you're doing it. You've got your email attached to your 365 global admin.

IAN: I'm you.

SCOTT: Yeah, I tell you what, you click that phishing link ho. All right. Good night. And the other thing is you tech team who are logged into their machine right now as a local administrator. Because again, that is problem number two. They're sat there as a local admin. Again, something happens to their account or they get some kind of breach. Yeah, they've got admin account on that machine straight away, and guess what? Yeah. They've got access to all your customers and all your RMM and all your PSA. They've got access to everything, don't have anyone running as local administrator and don't have anyone running as global admin. You use those things when you need them. Yeah, not on a daily basis, and I know what the techs are going to say. Oh, but I need it. I'm special. I know what I'm doing. It's not good enough. It's not you. Yeah, the others, it's not about you, it's about all of us. And so we're going to do things in the safest way possible.

IAN: Absolutely. Brilliant. Scott, thank you very much for that. Scott, just spend a couple of minutes now shameless plug time. What is Inside Agent? What have you been up to? How's it going to help MSPs to overcome some of the things we've chatted about in the in the podcast?

SCOTT: Oh, wonderful. Yeah, of course. So look, we've spent the last oh, a year and a half to two years now building out inside agent. So inside agent is our 365 multi-tenant management tool. So it is designed for MSPs to go ahead and load in your 365 tenants, including your own, and we will give you a very quick look. Like within five minutes you put a tenant in, within five minutes, we're going to say if this is what good looks like. This is where your tenant is right now, and here are all the red traffic lights that you need to sort amazing. And by the way, here's a load of buttons that you can press to go and fix those things right now. So again, we're seeing people log in and bring in their MSP tenant and our score, we have our little compliance score in there. It'll say, hey, you're at 38%. And within 10 minutes, they're getting that up to 80% compliance because oh, crap, right? I can turn this off. I can turn that off. I can turn these things on. We can enforce these. So we're making it super simple, but one of the big challenges for me that I've seen over the last six years is MSPs have got, like we said earlier, 20, a hundred, 400 clients to manage. It's a lot of bloody Microsoft tenants. Yeah. And so firstly, do you know what good looks like? And if you know what good looks like, have you applied that to every single one of your customers? And when was the last time you did that, and when was the last time that you checked that it was still in line with your best practice for a deployment. Our platform lets you do that. So you'll bring them in, you'll have an assessment straight away. You can, push out the remediations and then every day we're going to check that it's still matches up to that standard that you wanted. And the minute that it doesn't, or one of those things goes out of compliance, we're going to pop a ticket in your ticket system and let you know. If that sounds interesting, I'd love people to, gimme a shout. Catch me on LinkedIn if you want to take the pain and hassle out of managing hundreds of 365 tenants. Yeah. Easy. We make life easy.

IAN: And if you can give us a link, Scott we can pop it in the show notes and then the guys can just click straight in and either get to the website or get to book a call or whatever it might be, have a conversation about how it can possibly help them go a sea of green. We want a sea of security green is what we sea of green. Yeah, absolutely.

SCOTT: And do you know what? It's completely free for the MSP to use anyway. So if you want to use it on your own tenant and you just want to do an assessment, it's free. It's always free. There you go. So yeah, all good.

IAN: Fantastic. And don't forget to mention the MSP. No. The IT....

SCOTT: Oh yeah. Yeah. And if you mentioned the MSP Growth Hub, we'll do you a deal

IAN: But that's for people who join the Growth Hub.

SCOTT: Yeah. Yeah. You have to be, so join the MSP Growth Hub and then come back at me and then you're going to get a crazy.

IAN: But it's a discount, right? So that's the most important thing. Scott, it's been great catching up with you. Love the show bucket loads of information there. Bucket loads of value. And I think that the security thing we will never tire talking about, because as one of our clients says, if we're all in this amazing community, whether it be within the Growth hub or the podcast or any of the other great communities out there, and one of us disappears because metaphorically speaking, because of a breach. That's a sad day because we've got so much of, knowledge and everything that everyone can share and just share it and do it right. So there we go. All the best with Inside Agent and what's going on with you guys in your world. Bigger screen at the next show, please. Even though it's huge as it was right now. And yes, all the best and look forward to catching up with you soon, mate. Thanks again for

SCOTT: No, thank you so much and thanks to everyone for listening into this episode. Again, if you want to catch me, ask me anything, jump on LinkedIn, I'm right there, but it's been amazing. Thank you so much.

IAN: Top man. Cheers, Scott. Take care now. All the best.

SCOTT: Cheers.

IAN: Bye.

OUTRO: Oh, but one last thing just before you shoot off. And if you're curious about how this episode links with the ability to scale your MSP to a million or, or if you are already there, accelerate to five, then we want to invite you to come and take the MSP Mastery quiz. And in just three minutes, you're going to get a 360 degrees scan of your business where you can identify the one or two tactics that can help you find more time engage in, align your people and help generate more leads in your MSP. It's really simple. Just click on the link in the show notes. And if you have enjoyed this episode, we'd love to get some feedback from you by means of a rating review on Spotify or iTunes, or your podcast platform of choice. We really appreciate every single one of them. Now, you can go and enjoy the rest of your day, and we look forward to catching up and connecting with you soon. All the best.