Andrew shares a real example of how MSP Easy Tools was able to identify a breach within an MSPs system, who was trialling their software. Initially, the client thought it was a system error but upon closer inspection, it was revealed that cybercriminals had infiltrated the MSPs platform for over 90 days, unnoticed, posing a threat to all their clients.
Andrew elaborates on how his company swiftly helped the client to secure their system and protect all their tenants, as well as sharing some of the core principles that can help MSPs reduce cyber risk both in their own business, as well as ideas on how to protect their clients better.
A single cyber security breach can result in considerable financial and reputational damage…can you afford to take that risk?
For those who want to connect with Andrew, you can reach him via email at andrew@mspeasytools.com or visit the MSP Easy Tools website for more information about their services.
Towards the end of the episode, Andrew reveals a special offer for our listeners. You can download a free version of their security report from the MSP Easy Tools website. This free report can provide a snapshot of your system’s security status.
We encourage all our listeners to take up Andrew’s offer and assess the security of their own systems.
For more information, visit MSP Easy Tools HERE
You can also reach out to Andrew through andrew@mspeasytools.com
Download Andrew’s Free Security Report right HERE
Connect with me on LinkedIn and see what I’m up to by clicking HERE
To join our amazing Facebook Group of over 300 MSPs where we are helping you Scale Up With Confidence, then click HERE
And if you’re ready to take the next step in supercharging your MSP, take the Scale with Confidence MSP Mastery Quiz. This will provide you with insights and guidance tailored to your specific needs.
Until next time, look after yourself and I’ll catch up with you soon!
INTRO
In this episode of the IT Experts Podcast, we talked with Andrew Eardley from MSP Easy Tools and we're going to help you get on top of your security.
Welcome to the IT Experts Podcast, the only podcast to help MSP scale to 1,000,000, and if already there get to 5 and go faster at the end of the day, isn't it all about building a business that works for you rather than you for it? I hope you enjoy the show.
IAN
So, good morning, good afternoon, good evening, wherever you are. Welcome to the IT Experts podcast. Today, we're going to have a bit of a checkup with the neck up. We're going to be talking to Andrew, who's a recovering MSP owner. I am hearing that quite a bit now, Andrew. It's quite an interesting term. And I'm not sure it's that that detrimental to the work that we're doing but anyway and now own MSP easy tools. So welcome to the show.
ANDREW EARDLEY
Thank you very much.
IAN
Well, look, we got a really jam packed show planned for you guys today and this is all around cybersecurity and kind of two things really, we're going to go really go deep on today. The first thing is how do we protect you as an MSP and what are some of the things you need to be aware of with regards to all of the nasties out there in the cyber world, but also how you can protect your clients as well as people know, MSP's are a really great target for hackers and those horrible people. And we're going to help you get some tips, tricks and some strategies to help you with that. So Andrew, thanks again for your time, not only in preparation for the show, but also today. Do you want to just give us a couple of minutes and just let everyone know who you are, what you do, who you help a little bit about your journey would be interested in this recovering MSP owner. And yeah, over to you.
ANDREW EARDLEY
So, I'll say from the old set. For 25 years I ran an MSP. You know, start as a break fix, transitioned into MSP also to the point where I did what everyone dreams of doing and that's selling your IT company. You know, that's what all the hard work goes into. And I can tell you as an MSP, ex-MSP it's the best fear in the world is when you get rid of it. And I said in a really nice way. But you know, from a stress perspective. Boy, you don't realize how much stress you actually carry as an MSP owner. You know we all wait for the next phone call as an MSP owner, joking aside, you know, it's that stress that you don't appreciate until you actually get rid of it.
You know what is going to be the next phone call. You know, I started as. The Technical board one man band. Grew it up to 12 engineers about 10 years ago and I very purposely reduce the number of engineers down to five by the time I sold it. But you know, 10 years ago we would probably manage about 100 and 5000 and 60 clients by the time we sold, it was more. It was over 200 clients and we'll talk about that a bit later on, but it's that stress and the biggest, you know, my biggest fear as an MSP owner was all my tenants being breached. You know, was what was. What's the biggest thing? It wasn't, you know, it got to the point in my MSP where I wasn't really concerned about the PC's breaking or the servers dying or the, you know, if there was a data loss because of a server failure. My biggest fear was security.
IAN
Right. As it is for many, isn't it these days.
ANDREW EARDLEY
Yeah, because it's the reputational damage, if an MSP gets breached and it gets, you know that and it we've seen so many examples of that happen over the last couple of years. Well, the client, you know, the company will go bump quite quickly because people will lose complete faith in you, you know. Your staff will all go away somewhere else. Your clients will go somewhere else, but your reputation as the business owner is destroyed forever. At the end of the day, that's worried about, you know, you can never work in the IT industry again. You know, you better go off and do a be a plumber or a spa. You know something else. But because you're not going to be an MSP.
So you know, cybersecurity. Became the primary focus of my business. You know, it's not only protecting the clients, but you are protecting yourself and you know something I would say to other MSP's, why are we in business, you know. Why do we do what we do? Well, we do it because we enjoy it or we used to. At some point, but it's to provide the life that we're after. And I'm not talking about work. I'm talking about your partners, your kids, your family. You know you're there to, to grow your life, to enjoy life, buy the cars you want. Go on the holidays that you want. The business is only there for that and if it's causing you that much, you know that's stress, you got to do something about it.
IAN
Exactly. And that's some of the things that we talk about here, you know, at the growth hub is about, you know helping you become owner not needed ONN you know or Andrew not needed and you know helping you build a business that works for you rather than you for it and it's the reason it's such a great space to be and channel as you've just explained a little bit there is that it's such a leverage. It should be relatively straightforward to bringing new products, deploy them across new clients, and wake up on the 1st of the month with a nice load of money in the bank from your monthly recurring revenue. But as you say, this is real, this is a real threat right now, and it always has been, you know, so we're not talking about a subject that's, that's all of a sudden something that's brand new. But what we are going to carry on, tell a little story a little bit later on about one of Andrew's clients who was breached, but they didn't even know it. So I'm going to talk through that and find out how that happened, obviously try and prevent that from happening to you too in your MSP. So, Andrew, what's some of your key principles? What are some of the things that you did do you want to tell us a little bit about MSP Easy Tools and what they do, so we can just kind of get a bit.
ANDREW EARDLEY
Yeah, MSP tools is a is a tool kit for Office 365 and we'll talk about how I got to that in a couple of minutes, but basically, it makes sure that you fully know what's going on inside Office 365. You know, I'm going to make a statement here. You don't know what you don't know, but the only time you find out about something you don't know is when it goes wrong. What MSP tools is all about is making sure you know what needs to be done and when we do find a problem, you know about it very quickly – as in terms of alerting for example, or in our security reports, and then we give you the way to fix it really quick. And when we say we give you the ability, we give you a first line staff, the ability to fix it really quickly. So going back to what Ian was saying about being out of the business, you know. You leave your junior members and staff to fix problems really quickly without you having to get involved all the time.
IAN
This amazed me when we started talking about this cause I'm not, I'm not technical so I can get away with saying all sorts of different things in the channel to our client, but I always thought cause you got Office 365. I thought it all backed up. It's all in the cloud. It's all lovely. It's all safe and secure. No, it's not. And I thought, do you mean it's not? You need to back up what you mean in the backup you need another system to back that up as well. So for the people who may be starting out in their journey, or who maybe not as advanced as some of our other MSP business owners. What possible information could your tool bring out of Office 365 that you wouldn't know on a normal day-to-day based business that's going to be a risk to you.
ANDREW EARDLEY
Yeah, this Office 365 is one of the most complicated processes out there. It started as a very nice thought. But Microsoft keep adding to it and what they do is they keep opening up loopholes. You know, it wasn't that long ago they were leaving some key protocols such as POP and IMAP enabled by default, you know, which was which meant that cyber criminals going in with the username and password for, for your clients, they didn't know about multi factor authentication. If they got used, no. Well, they could use the old system, you know, and I could read and send emails to clients, for example.
But some vast toolkit, you know, even the experts that we talk to and I say the experts and inverted commas, they don't understand it fully. You know it's such a complicated product. But there are people out there that really do understand it because they spend 24 hours a day, seven days a week researching it, and that's the cyber criminals. They know how to get inside these products and they look for all the loopholes and you know, one of the key things about our approach is it's the cumulative knowledge of all the MSP's that we work with across the world. You know, if an MSP finds a problem that we haven't even found, we'll then build a tool to protect it, not just for that MSP, but for everybody.
IAN
Yeah. And I suppose if you think about, you know, what's happened with the Microsoft 365 stack, I think it's as we as we're kind of going to refer to it since the pandemic and all of a sudden everyone's using Teams. What's teams I? Don't know what’s Teams. Everyone's using Teams, you know, Skype for business has disappeared and it's now integrated. It's nice and easy to get all these integrations with your files and your SharePoint and your OneDrive and Word and Excel and all of this kind of good stuff.
But as you say, it's all connected to a reason and I think that probably the key thing to just remind ourselves here is that as MSP business owners, this is you know like if this I want to say something really random now don't know where this came from. It's like your granny making. A cake she never used to weigh the scales out for anything, because she knows how to make it. And you know what's in it. But the problem is, if your clients don't know how it's working or you're not protecting them for how they're using Office 365 or connecting it to all these other millions of apps that are out there now. Ohh, just connect this. It makes it easier. I'll connect it. Make that. Easier probably in your head you're saying I'll connect that and open up a loophole. I'll connect this and open up a loophole before you know it, the back doors wide open and these guys know it. And in they come and that's the way they go. Really, really, really key subjects.
ANDREW EARDLEY
So, one of the really key things about Office 365 is, especially from an MSP's perspective, you are responsible for all of your tenants. You have one access point into the Microsoft partner portal. And that will be since your engineers username and password and if you've configured it which you should have done multi factor authentication. Now multi factor authentication on the Office 365 platform is as much use as a chocolate fire guard. It's so simple to breathe. You know, you look at your engineers that are supporting your clients. Your apprentices will have full access to your office 365 tenants. They have the ability to go and fix all the problems. Yeah. There because that you're paying them for, but you're 18-19 year old apprentices and I'm picking on apprentices it can actually be your third line stuff you get come just same. Get a random e-mail asking them to do something because their office 365 be needs to be updated or whatever it is. They're not brilliant. They get conned like the rest of us do they click in, do whatever's done. And MFA is breached. Now, cyber criminals are inside your offic 365 tenants. You've set up all the configuration. You put all the warnings in place, but they've got full global admin rights on your tenants. What's the first thing they're going to do? Well, obviously they go and turn off all the damn warnings. You haven't got a clue that anything's going on. Yeah, you know how often you do you as an MSP go back and actually check all the configuration and settings. You don't because you're too busy and that's how cyber criminals game. We'll talk about that as a prime example in a couple of minutes.
IAN
Yeah, you're frightening me as it is, Andrew. On this one though, already. What was some of your principles in what some of your core principles as an MSP that you that you did to help secure yourself to and to help reduce, you know that risk in your business.
ANDREW EARDLEY
Well, I think we sat down and we actually looked at what products we were actually covering. You know, I think we were covering 6 different types of antivirus. I think we're up to about seven or eight different firewall products we got different. Were looking at serving for about four or five different server environments. You know, server 2003, 2008, 2011, you know, and we, you know, we've got all these different server environments. We were looking at a whole host of different products and it was becoming well, it wasn't becoming, it was highly complicated.
You know we got different operating systems on desktops. You know as much as you try to push your clients, they always refused. No, we're quite happy with Windows 95 and you know, we should be in on Windows, Windows 10 and it became a nightmare. Because your skills that you were having to become an expert in lots of different fields and you can't, you know, MSP's not only do we as an MSP owner have to be good at the IT we got to manage the staff, we got to deal with the clients. Wegot toa look at the accounts. We got to do all these, you know, all the marketing, all these other things. How much time do you have to concentrate on security when you've got your broad remit? So what we decided to do was we going to reduce our stack, you know? What is it we actually did so going back 10 years, we were covering all these servers. Microsoft dropped the bombshell that SBS 2014. Was it coming out? You know, there was massive uproar. You know, I was swearing at Microsoft about that, but it was the best thing that ever happened because I decided to jump into office 365 you know we were managing excess of 150 on Prem servers, SBS 2011, 2008 and what we did, we migrated into over a two year period virtually. All of those servers to the cloud. We move into Office 3.
We insisted to the clients that they've got to be on the latest operating system. We go bring the machines up back and we did get rid of a few clients who refused to work with us. You know, security is paramount. We switched as firewalls became old and they need to be replaced. We move to 1 brand. That you choose a brand. It doesn't matter, you know, predominantly, whatever you choose, it doesn't matter what antivirus products, or maybe just two.
You know, we ended up with two antivirus products, our standard day-to-day products and our ultimate product, something you can upsell one firewall brand, but you do just sell a different variety of the firewall. But you become experts in those when you're only concentrating on Office 365, one antivirus, one malware protection. You know, one of every type. You don't need to be South in this thread in terms of security, you've got the time to concentrate and that's fundamental. You can't do it overnight. This isn't something you'll do in 10 minutes, even a year, maybe two. If this might take you three or four, two or three years to achieve. For as long as you've got that longer term plan, you know that you're then on top of your security.
IAN
This should also be part of any kind of like growing and scaling plan, shouldn't it in reducing risk because you know you're in a position where you've got a risk plan. You know, most businesses should have risk. Just as and be reviewing them regularly, and if you've identified that you've got a big stack and you've got lots of open doors in the back office as it would be, then how do you reduce those and how do you, you know, keep some of those closed and then bolt them shut? So now, it's good, a good strategy and a good, good bit of information there on that.
ANDREW EARDLEY
The other thing you can. Do when you're doing that is also think about monthly recurring revenue. You know when I switch?
IAN
OK.
ANDREW EARDLEY
Everything stopped being about projects. You know, this was simultaneous thought process, you know, going to remove all the knowledge that we need to which obviously in turn makes it easier to train your engineers. But also, everything's got to be on a monthly recurring revenue. So, we switched to processes. So, we've switched to a server brand where we could charge monthly. We switched to every system, became a monthly recurring revenue. If I wouldn't put a new process in that unless it generated a monthly recurring revenue and obviously that becomes much easier than in terms of cost and trade.
IAN
Yeah, well, it becomes much easier and it makes the business much more profitable as well and also more, you know, more interested and more valuable to any potential purchasers as well.
So, okay, what does what does protecting your client, you know, from a security wise look like I know we've touched on that kind of like reducing the stack and the and the way that people are getting into there But, what does you know as a whole when someone says I'm going to go and protect you know, I need to. I need to protect my client better, particularly in Microsoft 365. What does that actually? Mean in terms of what? Do we need to do?
ANDREW EARDLEY
Yeah. Well, the first thing is knowing if cyber criminals are actually inside the platform. You know, if you talk to see particularly about Office 365, you know.
I'll ask your ask the MSP's. When do they? Typically know that a client's been breached and the answer I get 99 times out of 100 is when the client tells them. You know unusual emails are flying out to their inboxes. They've had money taken out the bank or bank, you know, invoices that should have been paid to them have been paid to cyber criminals. You know all the money they've been, they've paid to one of their suppliers or one of their customers has actually gone to the wrong bank account. And we've seen that multiple times being actually on top of what the cyber criminals are doing and that's really difficult to do on a day-to-day basis.
You know, talking about what we said earlier on. 10 years ago. I've got 12 engineers. When I realized that cyber criminals could actually get inside my Office 365 platforms for my tenants,I actually got two of those engineers working full time, constantly checking all the settings. Which is really. It's a, it's a terrible job, you know for the engineer, really terrible for use the MSP looks it's really expensive, but it's also damn boring. So, we automated that, so you know we know go look in using our toolkit, we got one of the things we've got is proactive monitoring. It proactively looks at your tenants, they're in the Microsoft partner portal and you can choose which tenants you want to protect. You don't have to protect them all. You can just choose the ones that you want to protect. It will then look for, for example for any method whereby emails can be forward out the platform, you know what cyber criminals will do is they will get in, they won't make themselves obvious. They'll set a forwarder on a mailbox for example. Now you might have already disabled that function, but the first thing to do is I'll go turn that off and turn the warning off so you don't know it's off. Emails will get forwarded out the platform until the right moment strikes and we actually saw this at our MSP. This happened to a new client that we'd won because of this problem. Basically, it's a former solicitors, so our criminals have waited and failed the transactions until the money request came in. So the e-mail got changed to the actual PDF document got changed inside the PDF document, they changed the bank details. This is in the middle of an e-mail chain. £200,000 which paid into the wrong bank account.
Now I spoke to MSP's across the world. You know we got clients globally the most I've ever heard from another MSP was in America, they just picked up a new client, they had just lost just shy of $8 million, in exactly that same scam. Now when that happened, he was the first thing the farmer Summiters looked to see. The MSP. Poor guy he, you know, he was a lovely guy. I spoke to the MSP that we took over from lovely guy. He was heartbroken. He thought he got everything covered. He thought he knew where everything was protected. You know, we ran when we got report to the problem, we ran our security report within 3 minutes we found exactly what was going on. We saw exactly the full in place and all the rest of it in seconds, we knew how to fix the problem, you know. Within a couple of minutes, we fixed the breach, but by then the damage had been done. But you know, we're checking for any method where emails can go out the business. We're looking for any new admin accounts because that's what the other thing they'll do, they'll create a new admin account. We won't go and change your password or your engineers password. What they'll do. Is they'll sit there. They will sit there for as long as possible. Now, I'm sure you've seen the or heard the statistic. For how long, on average, cyber criminals sit inside of a platform? Have you heard that one, Ian?
IAN
I've heard it, but it changes very frequently, doesn't it? I've heard 6 to 12 months but I don't know what your what your number is.
ANDREW EARDLEY
The current number we've got is 221 days and this was from a report by IBM from last year. So they sitting there for a long time. And that went up from the previous number, which was 175 days, so they sit there for a long time because they're sitting and waiting to strike, so yeah. We're looking for all the signs of cyber criminal activity. And when we see them, we don't just send you the warning once as Microsoft does because we know first line engineers miss them and you know these things happen. We keep sending the alert every hour until your first line staff fix the problem. And that's the key thing is – sent ever hour but your first line staff can fix it, cause every alert has got a corresponding tool to fix the problem. You know there are MSP we've actually got our admin staff fixing the problems because we'll have the first line guys and the other guys to fix other problems.
But you know it's all about making it really simple to do things really quickly. So the other big problem we had as an MSP was staff. You know our MSP was based in Stoke-on-Trent, which is the home of the Battery 365 gambling company that worked 24/7. So you know, I'd have staff. Take the apprentices. Get them to exactly the quite kind of guys that I wanted, guys and girls that I actually wanted knew their stuff. Normally take me about four or five years. And then they get off the job by bet 365, gor 50% more than I could pay them. Now we were paying them a decent salary, but they were going to work on continental shift 24/7. So of course I can't match that, but I've now lost four or four or five years worth of experience. I've got to start again. And it take a lot of effort. You can't get good staff, not just here in Stoke-on-Trent. You can't get good stuff anywhere in the world. You know it's the same problem for MSP's globally, so you've got to you've got to make life easier to do the complicated jobs and that's again where our toolkit comes in.
IAN
It's particularly, you know, important as well that skill set, you know, once someone goes out who you've invested all that time in over four or five years, the experience that they've got, you know, walks out the door, which kind of brings it on to a little bit of a subject around, you know, staff retention as well, which is which is really important thing that we all need to make sure we got as an MSP. Eeally interesting there just about some of the details on that, but this is also an opportunity, isn't it, that we can use this to add value to your existing clients and also to new clients. How does that kind of work out in terms of a package or what's the, what's the methodology you'd suggest to use for that?
ANDREW EARDLEY
Yeah, so you know. MSP's inherently our job was to make sure that the computers were working fine. You know, is the machines were, you know, are the machines working fast? Are there any problems you know, printer problems? I can't get excel to work, you know. But life for an MSP has changed. You know, our primary role now all the way that I saw it was our problem is not fixed computers anymore. You know, Windows 11, Windows 10, come off it, guys, you know. You can rebuild the Windows 10 or 11 machine in less than an hour now it's not complex. You know, people with very limited IT experience can fix IT problems now. Our job really is security, but our clients only see us as the IT fixing company. You know, we're the problem solvers in terms of fixing, fixing IT problems. But that's not our role anymore. Not in this day and age.
Our real role is making sure our clients are secure and what you've what we needed to do and what I did was highlight to my clients to security problems. You know, GDPR was a good instigator in terms of making people realize that security of data is key. But you know it's the reputational damage to their business if they get breached now more than anything else. So, our job as an MSP is actually about security. It's a great opportunity to upsell. So, what I did with my clients was I said fine, what I need you to do as our clients now is to add an extra line into your profit and loss account, and that's for security.
You know IT support is one thing, but security is another. You know, when I was using analogy as used the house as an analogy. You know, as an MSP, our job is to make sure you know that the house is clean, the front door opens, the fridge is working. You know those the kind of the basic things we might throw some security, a bit of antivirus. You know the front door shuts, but security now for your business needs more. You know, if we look at the house again as a security in terms of security, we can add on a big role, should the door in front of the main office, you know, if you're an American, you can be an armed guard in there or you can put a big fence around the garden with guard dogs or around CCTV alarm systems. All these things cost extra so we're keeping your machines working, but we're gonna now talk about security.
And this is, you know, if you've got the machine just down to Windows 10. Well, to be blunt, a decent antivirus system with a good RMM tool on the machine, that's automatically passion updating covers vast majority of the problems. But what about the other things? You know, the firewalls, the, the issues on Office 365. You can charge extra. The clients who have been resistant to security you need to change that process, so you know we had a lot of problems. You know, in Stoke-on-Trent they refer to each other as duck. You alright, duck? There you going, duck, you know, not mate, it’s duck. So I used to say my clients were as tight as a ducks backside. They don't like to spend money and this is world over. This isn't just Stoke-on-Trent. This is world over.
You know, point in Australia and MSP in Australia, he told me his clients got very short arms and very deep pockets. They don't want to spend money. So I use something called the disclaimer form and what I did with my MSP clients, whereas I took them to lunch because you need to get them away from the office, you need to get them into an environment where they're feeling happy and content and you ask them what life looks like in 12 months' time, not business. What does their life look like? How many hours of working? What Car are they driving? What holidays they're taking? You get them into their happy place. You get them to dream and talk about what life could look like, and then you ask the question what would happen if your company was breached? What would the impact be? And you bring them crashing down to Earth and as my old Sandler training guy used to say, you kick him in the chest and you keep kicking them until they realize that actually go do something about it and then you just talk about what you can potentially do and what I would normally do, take them for lunch, treat them, and then say I need you to look at this disc like these things I'm recommending for you now, this isn't just it's 365. It's all security things that you need to do to make sure you're right. And I would start the conversation with joy saying, Mr. Client, you do not need to have any of these things if you don't want them, but all I will ask you to do is sign the declaration. You know, to initial to say that you don't want the particular thing and then at the very end you'll sign the disclaimer. And I'll just rattle through everything that needs to be done. Explain each section. It might take a while. It's a couple of hours to get, you know, lunch and talk them through that, but it's well worth it. I promise you, at the very end I had a disclaimer and basically the not the exact wording, but something on the line, Sir. I acknowledge and insert their name there and you would repeat this by the way. You wouldn't just let them read it, you would work, you'd say it to them. I fully acknowledge that I've accepted that I don't want these technical these your recommendations, anything happens to my business. I take full responsibility. The number of clients who've gone – No, no, no, no. In terms of, we don't want that. We don't want that. We don't want that when they get to that disclaimer an you read that out to them, the number that turned round at angles is now changing.
IAN
Changes the world. Then it changes the world.
ANDREW EARDLEY
Yeah, you've taken away what could be and then you've brought them back down to Earth about if they do nothing about. We had a 95% success rate on that.
IAN
I think a lot of lot of I can't see that we call it the opt out and it's always it's always a really powerful powerful thing to do. Andrew, absolutely loving the level of detail we've got in here is really making me kind of thinking some of the conversations we have with our MSPs. But just before we wrap up, I just love to hear about this client of yours who was breached, but didn't even know about it. What was that all about?
ANDREW EARDLEY
Yeah, we'd had MsP, we've been contacting MSP's, obviously trying to get more people in to test their to try out our tools. He reluctantly said, oh, go on,we'll take the free one month trial. Within a couple of hours, him of us actually turned the system on for him, he started to run the security reports on his own MSP and we always recommend that they do that first and he came back to us and said I'm getting these alerts, but there there's something wrong with your system. You're telling me something is wrong in my system? Now our system can only tell you something that's actually there. It can't make anything up, so you know. He argued with us to begin with, until he actually sat down with the head of the development team and we showed him that actually cyber criminals had been in platform for an excess of 90 days and they've been monitoring not only his tenants but all of his tenants, all of his clients as well. He got over 120 tenants and they were literally into every single one. You know, we quickly helped him to protect himself and then over the next couple of hours, he then went through and protected all of these tenants really quickly, but he was completely oblivious to the fact that cyber criminals were actually sat inside his platform, literally chomping his way through all of his tenants. We couldn't tell him where it had happened or where it had happened because there was there's only 90 days worth of data in the audit logs. Microsoft audit logs. It had happened more than 90 days ago, but he's a very thankful and now very profitable MSP that slips way back.
IAN
It's not just about earning new money and earning new sales and marketing and all that revenue. It's all about keeping what you got as well. And if for if some of that goes out that back door, we keep talking about then then that's not a great place for anyone. Andrew been absolutely brilliant today. Thank you ever so much for your time and effort. You just want to spend a a couple of seconds and just let everybody know how they can get hold of you, and I believe you've got a little bit of a treat for everyone who listen to the podcast today.
ANDREW EARDLEY
Yeah, absolutely. So, if you want to get a hold of me, it's andrew@mspeasytools.com. Go and have a look at our website, mspeasytools.com. What you'll do if you just have a little flick through and you go and look at the security report section, we give examples and show you actually how the security report runs. You can actually download a free trial, a cut down version of the security report. It is cut down. It doesn't give you absolutely everything, but it shows you with your data - what's going on in your system. Just to give you a little flavor before you try and talk to me, you want to take a full one month trial of the demo. As I say, the demo is a the trial is free. So there's no cost, it just give you a chance to check it out.
IAN
Well, I can't see why anybody or anybody wouldn't take that, that sounds like an absolute brilliant deal. So thanks ever so much for that, Andrew. It's been great speaking to you. Thanks for your insights, knowledge and all your information today it's been really, really useful. We're going to put all the links for everything we talked about into the show notes so everyone can pop over there and click away and go and get your free assessment and see how that goes and yeah, I wish you all the very best luck and success and I look forward to catching up with you soon.
Thanks, Andrew. Take care.
ANDREW EARDLEY
Thanks, Ian.
OUTRO
So I hope you enjoyed. The show, if you did, I'd love it if. You could leave a rating in with. You on your favorite podcast platform if you want to learn more about how to take your MSP to a million or if you're already there go faster then come and join Stuart, Warwick and myself in the scale of confidence Facebook group. The link is in the show notes, you go and enjoy the rest of your day and I look forward to connecting with you soon.
OUR TRUSTED FRIENDS OF THE GROWTH HUB