EP283 - MSP Channel Insights Panel- Cybersecurity, Compliance, and Resilience – with Neil Smith, Gene Kim, David Clarke, and Ian Luckett

IT Experts Podcast - The MSP Growth Hub - Ian Luckett - Neil Smith - Gene Kim - David Clarke - The MSP Growth Hub - Podcast Episode 283 - UK - WordPress

Click below to listen to the episode

In this episode of The IT Experts Podcast, we explore what it really takes for MSPs to build a strong foundation in cybersecurity, compliance, and resilience in a world where risk is constantly evolving. In this special roundtable session, I am joined by Neil Smith, Gene Kim, and David Clarke, who each bring deep, practical experience from the front line of cybersecurity and compliance within the MSP space.

 

You will hear how the role of the MSP has shifted from simply managing IT systems to becoming a central part of how businesses manage risk. As Neil Smith shares from his own journey, the demand from clients has changed significantly. Businesses are no longer asking for technical support alone. They want reassurance that they are protected, aligned with standards, and prepared for whatever may come next. This is where cybersecurity, compliance, and resilience come together as a core offering rather than an add on. 

  

Gene Kim expands on this by highlighting how trust is now directly linked to revenue. Clients expect MSPs to provide clear visibility, consistent reporting, and confidence that systems are secure and recoverable. This is not about tools alone. It is about outcomes. MSPs are now expected to help clients prove they are operating securely, not only for their own peace of mind, though also for insurers, auditors, and stakeholders. 

  

A strong theme throughout the conversation is education. As Neil Smith explains, many businesses still believe they are not a target or that basic protection is enough. The role of the MSP is to guide clients through understanding their risks in a calm and structured way. This is not about creating fear. It is about building awareness and helping clients make informed decisions that support long term stability. 

  

David Clarke brings a valuable perspective on compliance and governance. He highlights how frameworks such as GDPR and Cyber Essentials provide a strong foundation, though they are not a one-off exercise. Cybersecurity, compliance, and resilience require continuous attention. It is similar to securing your home. You do not lock the door once and forget about it. You maintain awareness and take responsibility over time. 

  

The conversation also explores the importance of clearly defined responsibility. MSPs play a critical role in implementing and managing systems, though the ownership of risk always sits with the client. David Clarke reinforces that understanding who owns the risk leads to stronger, more productive conversations. When this is clear, businesses can make better decisions and avoid confusion during critical moments. 

  

Supply chain security is another key focus. With MSPs relying on a growing number of vendors and tools, every decision introduces potential exposure. Gene Kim and Neil Smith both emphasise the need for transparency, trust, and careful evaluation when selecting partners. It is not only about functionality. It is about reliability, communication, and how those vendors respond when something goes wrong. 

  

When the discussion moves to incident response, the tone becomes even more practical. Every MSP needs a clear and well understood plan. David Clarke explains the importance of rapid escalation, strong leadership, and access to the right expertise at the right time. Decisions need to be made quickly, often with incomplete information, and preparation makes all the difference. 

  

Neil Smith adds that these conversations should happen before an incident occurs. Working through scenarios with clients, even in a simple tabletop format, can highlight gaps and build confidence. Gene Kim reinforces this by stressing the importance of having systems that can recover quickly and maintain control during an incident. 

  

Resilience is the thread that connects everything discussed in this episode. It is not enough to reduce risk. Businesses need to be able to continue operating when challenges arise. Cybersecurity, compliance, and resilience work together to create that outcome. When done well, they provide stability, confidence, and a platform for growth. 

  

This episode makes one thing very clear. MSPs who fully embrace cybersecurity, compliance, and resilience will stand out. As Neil Smith demonstrates through his own positioning, this creates a powerful advantage in the market. It builds trust, strengthens relationships, and supports long term success. 

  

If you want to position your MSP as a trusted advisor and create a more secure, scalable business, this episode offers clear and practical direction. Focus on the fundamentals, build strong frameworks, educate your clients, and keep refining your approach. Over time, this creates a business that not only protects clients, though also grows with confidence. 

 

Connect with Neil Smith through LinkedIn HERE. 

Connect with Gene Kim through LinkedIn HERE. 

Connect with David Clarke through LinkedIn HERE. 

 

Make sure to check out our Ultimate MSP Growth Guide, a free guide that walks you through a proven process to take your MSP from stuck to scalable, without working even more hours. It’s 44 pages rammed with advice, insights and inspiration to help you decide what support is available to you now if you want to grow and scale your business. Click HERE to get your copy. 

 

Connect on LinkedIn HERE with Ian and also with Stuart by clicking this LINK 

 

And when you’re ready to take the next step in growing your MSP, come and take the Scale with Confidence MSP Mastery Quiz. In just three minutes, you’ll get a 360-degree scan of your MSP and identify the one or two tactics that could help you find more time, engage & align your people and generate more leads. 

 

If you’re serious about growth and want to explore what this could look like for your MSP, you can book a Right Fit Clarity Call with us HERE. 

OR  

To join our amazing Facebook Group of over 400 MSPs where we are helping you Scale Up with Confidence, then click HERE 

Until next time, look after yourself and I’ll catch up with you soon!    

Check Out the Full Transcript Below:

IAN: In this week's episode of The IT Experts Podcast, I have got a super treat for you. I'm going to be sharing with you a whole round table discussion around cybersecurity, compliance and resilience, a brand new playbook for MSPs from the MSP channel round tables.

INTRO: Welcome to The IT Experts Podcast, the only podcast to help MSPs scale to 1 million, and if already there, get to five and go faster. At the end of the day, isn't it all about building a business that works for you rather than you for it? I hope you enjoy the show.

IAN: So good morning, good afternoon, good evening. Welcome to The IT Experts Podcast. Got a bit of a treat for you today. It's a bit of a longer show, and there's a reason for that because I'm going to be sharing with you the full audio and video from one of the recent MSP roundtables I hosted in March this year, which was all around cybersecurity, compliance and resilience, a brand new playbook for MSPs. Now, the reason that I'm sharing with it on the IT experts podcast is because these episodes, these panelists are absolutely brilliant. The golden nuggets, the information, and you may or may not be aware about the channel insights, roundtables, they take place three or four times a year. I host them and I, every time I get off them, I go, oh my God, that was brilliant. Everybody needs to hear about this and depending on where you get your media from, you either will or you won't get to hear about it. So I said to Suki at, the MSP channel. So I says, look, can I put this audio out on the podcast? And he said, absolutely no problem whatsoever. So let me just share with you a little bit. And then we're going to cut straight into, so they're entering in their third year. But the MSP channel round tables, are increasingly valuable resources for the MSP community, they're great discussions from key industry issues exchanging peer ideas and the people we've got involved in these, are absolutely brilliant, and as I say, I enjoy every single one of them. But each session brings together senior leaders, industry experts, and technology partners to tackle the most important issues. And this one's going to be, this one is all around cyber compliance and resilience. And it's helping you in your MSP think about things a different way to not only keep you safe and secure, but everybody else too. On the panel, we've got Neil Smith, who's a serious security focused MSP. We've got David Clark, who's the Chief Technology Officer from Trust Bridge, and we've got Gene King, who's the vice president of Managed Services at Absolute Security. I'm going to hand over to the main show now. It's you. You're going to love it. I know you're going to love it. There's so going to be so many golden nuggets in it. I'm just going to leave the rest. Well, to me and the panelists.

Good morning everybody. Welcome to this month's MSP Channel Insights Session, Round Table session. We've got a great set of experts for you today. And today we're going to be talking about cybersecurity compliance and resilience. And as I mentioned, we've got some really great experts. So, you know, this is still the number one priority for many MSPs. You know, the threat in the landscape is still expanding, and today we are going to explore how MSPs can build a more. Robust cyber practice that goes beyond the defense and we're going to incorporate governance, compliance, cyber insurance, and all of those kind of great things as well. But, you know, key things coming up is as regulation tightens and the customers demand greater accountability for MSPs need to adopt and. Be a proactive threat detection incident response, and also to manage those frameworks as well. So we've got some great questions. We've got some great panelists coming up, which introduce you to those in one moment, but these sessions would not be, possible if it wasn't for our amazing sponsors. So Platinum sponsors, we have ourselves, the MSP Growth Hub helping MSPs get to a million profitably. If they're already there, we help them get to five, and exit faster. We've got absolute security where we've got gene on the line today. He'll be able to explain a little bit what more, what they do. And then also David from Trust Bridge. Finally, our gold sponsors today are Ninja One and Barracuda. So thank you very much for our, sponsors for that. Before we get going, let's introduce our panel of experts and find out who they are, what they do, and who they help. So first on the blocks, Neil Smith.

NEIL: Good morning. Yes, my name's Neil Smith, CEO, founder of Reform IT. Yes, we're a Cheltenham based managed IT service provider as well as being a certification body for cyber essentials. We look after everything from circuses to cheese manufacturers and everything in between.

IAN: Lovely stuff. Thank you very much, Neil. Love that little, love the difference in your demographics there. Literally catch everybody. Gene, good morning.

GENE: Good morning everyone. I'm Gene Kim, vice President of the Managed Service Provider Program at Absolute Security. I work with MSPs globally on building scalable security compliance and resilient services that reduce the risk of protecting businesses continuity. Excited to dig into the new playbook and see what that looks like and what's going on in the field.

IAN: Absolutely. Thank you very much for that and for being here today. Last but not least, David.

DAVID: Hi. Thanks a lot, Ian. Yet CTO and co-founder at the Trust Bridge. And we work with MSPs and quite a few different organisations on ensuring that they have the right level of compliance. They can survive due diligence from, government, large companies. And, we've been kind of starting doing a lot of work now with MSPs on the cybersecurity resilience bill, which really is putting MSPs in the firing line.

IAN: Yeah. Yeah. And we're going to, we're going to cover off that today as well. How to protect yourself, not only from the bad guys, but also from making yourself stand out. It is great opportunity.

DAVID: Well, it's not just the bad guys. You got to protect yourself from the good guys, inverted commas now as well.

IAN: It's good guys, it's good guys as well. It's any guys. We'll cover that. I am absolutely certain. So let's, first of all, let's kick off with talking about the changing role of the MSP in cybersecurity. And, Neil, I'm going to come to you first, but, you know, you've really embraced the whole cybersecurity element as an offering and a service and a key part of your business. But so how has the role of the MSP evolved as, cybersecurity, you know, is even coming even more top of the priority for clients?

NEIL: Yeah. It's certainly been a journey. If I look how we've evolved over the last 10 years, I think it was probably four or five years ago that I made the decision that actually we were getting asked an awful lot more about cybersecurity issues. Obviously there was a lot more in the press, in the news about breaches, well-known household names, and that hasn't stopped. It continues right up to the current day and that kind of, in some cases put the fear of God into some of our clients and they wanted to know what it was that we were doing to keep them safe. And it sort of occurred to me that actually, although we were pro. Providing great managed IT services. We hadn't really got a sort of a good framework around which to sort of demonstrate what we did and how it was keeping our clients safe. So took the decision to become a certification body for cyber essentials right. I've kind of been involved with IASME and cyber essentials for sort of on and offer for a good 10 years. We, already been kind of taking some of our clients through it, but not being the actual certification body for that. So yeah, but kind of bringing that in-house and building, rebuilding our managed IT services around cyber essentials such that what we were doing were, was keeping our clients aligned to that standard as much as possible, as well as going way beyond it. I think the way it's changed for us as well is it's also the education piece. So we are having to sort of, and continue to do that education piece, doing events and marketing that sort of shows why that's a difference, why we stand out from the rest and why it's important.

IAN: What do you find is the hardest thing when educating a prospect? Because, cyber. We'll talk, you know, we'll say, you know, cybersecurity as a whole, it's a bit like an insurance policy, isn't it?

NEIL: Completely.

IAN: If you are, you want the cheapest until you get your car hit, and then they repair it with a plastic band rather than the paint that should have been done. But how do you, how are you overcoming that conversation and helping them, helping prospects and businesses, I guess just educate in why they need this, why it's so important.

NEIL: The car insurance analogy is a good one. I mean, really everything that NMSP does is a little bit like an insurance policy, you are there in case things go wrong.

IAN: Yeah.

NEIL: But the cybersecurity aspect is more important. But yeah, the biggest objection is I've never been hacked. Why do I need all this? You know? Well, antivirus, it's all a big con, right? Yeah. So it's that's probably the biggest objection. But I think actually as time has gone on, that pushback has become less, I think people realise the importance of it and it doesn't have to be enormously expensive to get the basics right. Cyber Essentials is designed to be you don't, in theory, you don't actually necessarily need to buy anything to be cyber essentials compliant. You can do everything manually to meet the requirements of the standard. It's very hard. It's very time consuming. And obviously automation and tools and MSPs like us are there to kind of take that hassle away from the client. But, yeah, just getting those basics right is not enormously complicated or necessarily expensive.

IAN: Do you use tools like surveys or assessments or things like that to kind of demonstrate, you know, don't just take our word for it let's grade your business and see how safe you actually are, do they work? What's the best ones that you?

NEIL: Absolutely. I mean, the Cyber Centrals assessment itself is almost a great way of going through that kind of the gap analysis. And in fact, that's what the cyber advisor role is about. I'm a qualified cyber advisor as well. The NCSC have kind of pushed this out with the help of IASME to enable people to log a, you know, log something on the NCSC website, which enables them to get 30 minutes of free advice if they want to perhaps look at the cyber essentials journey, what it's needed, what, the costs are, those kind of things. You can get a free 30 minute call and talk to an advisor like me to kind of answer your questions around what that's what's involved, and what the standard's all about and why it's important.

IAN: Great and load loads of support out there to help businesses, because it's just like, let's just keep many people safe as we possibly can. So That's brilliant. Thank you Neil. David, I imagine in your world you come across a rather large amount of data that's coming, flying at you from different angles every single day. How's this showed up differently in what you see in the MSP landscape with regards to like priorities for the next 12 months.

DAVID: Yeah. Yeah. And I think trouble is data is always more complex. Actually kind of knowing what data you've got, where it is, oh, I'm sorry. One, one of the things the Trust Bridge have done is that we've got one of the four certified schemes by the ICO for GDPR.

IAN: Oh, nice.

DAVID: And you know, we kind of appreciate GDPR's, you know, been around a while, but unfortunately it's the foundation of many of the new bits of legislation coming in, because if you have a problem, it's probably going to affect personal data. Therefore, you're going to have to deal with maybe one or two regulators. And if you're in Europe, you'll be dealing. Maybe three or four regulators at the same time. So one of the kind of things is identifying you know, what data you've got and where it is. And I appreciate some of even the big global cloud companies and not a hundred percent certain where data is as well, which doesn't necessarily make things easier. And to kind of carry on from, you know, where Neil kind of left off. Part of the problem is getting the message that, this is an ongoing process. It's a bit like your front door.

IAN: Yeah.

DAVID: I've locked my front door this morning. I don't need to look at it for another year. Is that right or wrong?

IAN: Yeah.

DAVID: Well, you know, I've got, my cleaning lady's got a key, my kids lose keys. Yeah. You know, I've got to make sure that door is locked when I go out, which is, critically important and with me especially, I probably not locked the back door. So there's actually surrounding processes you have to keep an eye on and keep an eye on them all the time. So kind of saying I am on this day okay. Is kind of great, but it's kind of not enough. You need to make sure you are great all the time.

IAN: Yeah.

DAVID: And we often get asked questions like, we're not a big company. You know, we don't really kind of need to do all the stuff that's best practice. And I guess the best analogy I've got is, well, I don't drive very fast. I only go to Sainsbury's, don't commute much. Therefore I don't really need a full MOT, you know, you can forget about my breaks and the lights and all that kind of stuff. That's not going to hold water. My car will not get an MOT no matter what car it is, and what my use case is. And so we kind of have to get that message across. And I think one of the things that we try and get across, and it's a bit of a subtle concept, is who actually is the risk owner? You know, so I might be IT, I might arrange for everybody to get their finance package, but I am not the risk owner for that finance package. If that finance package has only got an availability of, you know, an RTO of, three days, have I explained that to the finance director that what he's paid for is something that could go down and it could last up to three days because he hasn't paid for the next level up, which is maybe four hours or one hour or whatever, yeah. You know, I am the operator, I am the implementer, but I'm not the risk owner. And we have to kind of get that message across. And, you know, we were talking to a company literally last week or the week before, and the lady goes, runs their compliance goes, well, I think we need to delete the clear desks policy. Why do you need to need do that? Well, our company's quite messy and we've only got 300 staff and do we really need to do it? And then I realised she felt she was responsible for everybody's messy desk because she's writing the policy rather than saying, actually this is a risk that needs to be accessed by your board. In some areas you will have Meta Dash, but you know, you've got locked doors and CCT cameras, you've got a mitigation. So it is really getting those concepts of understood and it's worse for an MSP having run some very big security operation centers for global companies. Quite often the customer goes. You manage our security, therefore it's your problem.

IAN: Yeah.

DAVID: And we have to kind of explain to them, no, we kind of run the management of your systems. We don't run the security, we don't decide, you know, who comes in the building, but we will configure it to what you want. And if you have an incident, we will work with you to decide, what containment needs to be done, upgrades, et cetera, et cetera. But we are not the final authority on that. We can advise that it's your business and you will have to make those decisions.

IAN: Absolutely, and I think the risk word is something we talk about a lot at the MSP growth Hub with our clients, and it's all around making sure that you've got, you're not scaring people with the risk, but the businesses are being responsible and mature enough to have that conversation around this is a risk to your business and who owns this risk. I did actually, I was actually talking to one of our MSPs and they said, yeah, when you start assigning risks at your QBR or your TBRs with your clients. They start listening very quickly.

DAVID: Oh, you're a hundred percent right. And this is kind of everywhere. About two years ago I was having coffee with a chairman of a very well big known company, got places in every high street in the UK. I mention their name and he was saying to me, you know, what questions should I ask My CIO and my IT managed to sure that we're okay. And then we started talking about risk and he kind of smiled and I go, or what are you thinking? And he goes, he says, I love risk. He says, what I do is I get a list of risks I give them to my chief risk officer and then it's his problem.

IAN: Yeah.

DAVID: And I thought, yeah, that's great, but really. What he's kind of not quite got, or maybe was deliberate probably knowing him.

IAN: Yeah.

DAVID: He's the risk owner whether somebody else operates it or not.

IAN: Yeah.

DAVID: And you know, so it's a sort of subtle kind of differentiator that kind of needs to be understood, because it's very easy to blame all the staff are, you didn't do this properly and whatever. And actually risk has to go to the top.

IAN: And that's where this education piece that, that Neil was talking about comes in as well. Oh, absolutely. Early on in that stage. Gene what you are currently doing your initiative at the moment new into the MSP space. What is it that you've seen that's kind of been a bit of a change as the MSP's role has evolved around cyber and security?

GENE: Yeah. You know, what I see is that MSPs have shifted being from an outsourced IT company that keeps it running to being more about helping businesses manage that risk. Right. And that's a big change, you know. Clients are asking MSPs to more of, you know, to own more of the security outcome if it were not just about deploying tools and managing IT, you know, and customers want better visibility and better response and clear reporting that they can take to their leadership and auditors, and arguably most importantly, their insurers, right? Because cybersecurity is, and the risks associated with that, the insurance are looking at it way more intently than they ever have. I think the other evolution is how now, trust is really tied to revenue. It affects customer retention. It affects your ability to win new business, and in some cases it affects whether the client can even get that insurance or not right at a reasonable rate. So the MSP's role, I think, has expanded from things like just providing baseline security standards to things like what David had mentioned, like it's that continuous monitoring incident readiness you know, being able to help clients prove that they're doing the thing their things right. And again, it's not just a once a year thing, but it's on a continuous basis. I love the analogy about the house, you know, that kind of onetime security assessment and how things change constantly with contractors and people going in and out of the house. And you know, one of the examples that I like to give is about cybersecurity being a house. And all the doors and the windows being locked tight. But when an incident does occur, and it's not a question of if right, with AI and all the tools that hackers have nowadays, you know, this whole notion of completely outsourcing, cyber crime is a real one. And so, and when that does occur, right? Businesses really need to look at how their partners are going to help them recover, right? It's that resilience. Now, in terms of business continuity cybersecurity is going to reduce risk. But resilience will ensure that the lights are going to stay on and that company that they're providing services for. It doesn't go out of business.

IAN: Yeah. Absolutely. And I love it. Love it when we all get together and then one person mentions an analogy of a house and then it rides for the hold of the next hour. And it's great. And we dip into the house and Neil will probably build an extension on it in a minute. Let's talk about so we've got the frameworks, we've got GDPR, we've got cyber essentials. I'm sure David, you'll touch on some of the other regulations that we've got coming up. And it's easy to say, yes, we provide, you know, as an MSP, we provide cybersecurity. We do this, we help you keep safe and secure and all of that kind of jazz. But. What can we do to help our clients meet these frameworks? You know, there's you'll go and do a survey and we'll do an assessment and we'll say, yes, we've got these things that we need to do, but what's some of the tricks? I'm going to come to you first on this one, Neil, with, you know, what are some of the ways that we can support our business, you know, our end business clients to meet these frameworks. It might be around, you know, tactical things that we need to do, but also understanding, as David was saying about, you know, this whole clear desk policy and all of those that the education of the wider users, what can we do to kind of like, help out there?

NEIL: It comes back to that risk analysis actually and the asset register and the education piece. So it's helping a client understand what they've got and where it is. Potentially how it's protected or not as the case may be. And that then enables you to explain the potential risk and from there, you can start, it's not necessarily about putting the fear of God into the client. Although that can help sometimes. It is about perhaps managing that because I think if you put the fear of God up into people they kind of put walls up and they're not interested. So it is about kind of perhaps more gently encouraging rather than panicking people. But yeah, it is saying, look, you know, your business has grown, your business has developed over the last X years, just as ours has. And actually these are the changes that have happened. You've moved to the cloud. You know the server in the corner, you are still using that server for a particular line of business application. And they're kind of helping them understand. Why that's a risk and where their data is. And once you've done that, you can then start to help them look at the various frameworks. Obviously I'm going to bang on about cyber essentials because I think that's brilliant. But it's a great foundational sort of assessment that again, just helps them get the basics right. It's quite easy to get into that as well. So it's not enormously expensive. It doesn't take huge amounts of time, and it really does cover the basics. And then from there. It depends then what the client's own requirements are. So obviously what we're seeing a great deal more of these days is supply chain requirements. So if you know, if you are going to be working with us, whether you are a supplier or customer, actually you need to have at least cyber essentials. Or it might be ISO 27,001. There might be all sorts of requirements that either a client or a supplier might, might need that our client to have in order to continue trading with them. So that tends to be the starter these days. That tends to be what kind of picks, picks the attention up. You know, we might have been speaking to a client about the risks and the potential problems and obviously what we do to keep them protected. But all of a sudden, a supplier or a client has come to them and said, right, in order to now renew this contract or win this contract, you've now got to have compliance.

IAN: Yeah. Yeah. Excellent stuff. Thank you. Thank you for that. Neil. Gene, what's your view on this? What are some of the things that MSPs can do to help these frameworks?

GENE: I think the best MSPs translate these frameworks into operational reality. Most frameworks, as Neil said, you know, they boil down to some simple things, you know, done consistently, right? Knowing what assets you have, controlling access, patching on time, logging and monitoring, backing up properly and having an incident response plan. So the MSP's job is really to take those requirements and turn them into a standard service offering, understanding baseline configurations, patching SLAs, identity and access hygiene, you know, documenting all the processes and recurring reporting, right? And the key I think is evidence, helping the client continuously be able to prove proof. Produce that on a regular basis. And I'm not just talking about screenshots the night before an audit happens, right? It's having the appropriate instrumentation like dashboards, audit ready reports, and having those routine reviews to make sure all the compliance standards are operating and sustain sustainable, right. As a business. And I think, you know, from a practicality perspective, responsibilities need to be clarified early, right? The MSPs are going to operate the controls, but the client owns the policy decisions and risk acceptance. That needs to be explicit so everyone knows who does what.

IAN: Mm-hmm. Absolutely. No, that's brilliant. Thank you. Thank you for your input on that. David, anything to add on this one?

DAVID: Yeah, I think great stuff, great advice. You know, from Neil and Gene, absolutely spot on. In the one things I kind of would add to that is in reality this is about MSPs making money, getting proper big deals rather than small deals because at the end of the day, most of this compliance is going to be driven by their customers who are either big or either dealing with big customers, because the supply chain is now in scope big time. And you know, if you can get them those deals. Your prices don't necessarily have to be the lowest in the marketplace because you can comply. The other kind of thing is, is actually somebody needs to be responsible. I think we've been talking a bit too generic and MSP is responsible. No want name people in those MSPs who are responsible. So, you know, things can get done. And I think the other thing, you know, where we kind of have an a advantage, and I'm going to borrow stuff from Neil here yet. We kind of know what best practice is. Best practice has been evolving for quite a while. We know what works to stop compromise.

IAN: Mm-hmm.

DAVID: You know, most of the time. So it's not really a negotiable thing. It's like, we know this works. The US government know it works, the UK government know it works, yeah. Which is kind of why we're asking people, you know, to do the cyber essentials or any other standard. Because they are based on best practice that works. It's not quite the same as, you know, driving a speedboat. There's too many variables in a speedboat and we you know, we'll never kind of understand what's going on, but we will with cyber because we see them. Looking at the NCSC report last year, which is kind of scary in itself, about nation state threats phishing alone in 2025, when at 10, 20, 5%, and I know about you guys, I thought it was bad enough in 2024, let alone going up huge. And we don't know what it's going to be like this year. They're kind of reckoning. This year's going to be even worse because part of the reason why MSPs are now in scope is because it's getting too wild in the rest of the world now. And we've got to help, you know, UK companies do the best they can and the best advice they're going to get is from MSPs. You know, they see this all day long and also MSPs need to be, making sure that they're aligned with it all as well.

NEIL: I couldn't agree with that more, David actually, it's, we hold the keys to so many castles and to regulated castles as well. So financial advisors, NHS, you know, all of these people who ha who are themselves regulated. So for us as MSPs to not be regulated has always been completely bizarre to me.

DAVID: I think it was about three years ago, I was talking to a financial advisor and he goes, Dave, what's all this kind of cyber stuff? He says, you know, in my business we don't use any cloud systems at all. And I said, oh, well, how do you do your work? He goes, well, we only use Dropbox and Google Mail.

LAUGH: Um,

IAN: Case in point. Absolute case in point.

STUART INTERRUPT: Hey, just a quick one from me, for everybody that's listening, Stuart here. If you're serious about growing your MSP, but you're not sure what helps right for you, then just grab our ultimate MSP Growth Guide. It's a really simple way to check out what's out there for support that could really help you work. There's no fluff. There's no filler, just facts. Or alternatively, if you want to meet us face to face and see how we do things up close, come along to one of our events. They're regularly put on, they're all in the links below. Go check them out, and now it's back to the show.

IAN: Thanks, Stuart.

David, I want to stick with you for, as we kind of move tac, but we're not going to move tac the MSP is you know, ultimately, responsible for not only their own security, but also that of their customers as well. But one thing that, that gets mentioned and overlooked quite a bit is supply chain. And you know, you are letting in, you've got all these vendors with your RMM, your PSA, uncle Tom Cobian, all with AI at the moment, because there's probably about 48 million different AI tools that MSPs are just plugging in. And look at this, solving the world. Well, maybe not, but anyway, most of it's automation, but we'll let that one live. That's a whole another round table. Let's just talk about what should, what is best practice for MSPs when they get shiny ball syndrome and they're going to go and buy a new product or a new system or a new tool around their supply chain. What should they be looking for? What's the, we know there's a danger there, but what should they be looking for when bringing in a new partner?

DAVID: Yeah, this is actually kind of a really tough question because having kind of been, you know, both sides of the fence. Yeah. This was quite a while ago, yeah. And I was looking at some latest cyber technology and everybody in the company I kind of worked for was saying, you know, over my dead body, will we be using that within three months. I was told by my boss, this is standard now. Why aren't we? Why haven't we got it everywhere? Because there was nothing else that gave you any level of protection. Didn't work brilliantly, what? 50, 60%. But that 50, 60% enabled trading to happen. I mean, financial trading. So you know, 50% of something is better than the other side. Nothing of nothing. So that bit you've got to bear in mind. The next bit is, has the company got the capability to give you the support that you need? Because if it can't give you that support, you might as well not have it. You know, and that's an important one, that company has got to make the MSP look good, because if it doesn't, you're just going to have a headache going on. And we've seen this. Seen this quite a few times where, cyber providers you know, unfortunately send the wrong email to the right person routine, not necessarily the end of the world in each case, but it doesn't inspire confidence when that happens reports go to the wrong people, that type of thing. And you know, when I've kind of investigated some of this for MSPs, what you kind of find is oh, we made a change in the code here. Okay. You made a change in the code, so who approved it, who tested it, what happened? And you kind of get no answers generally, because some of it is a little bit run like we are still in the nineties. Mid twenties maybe. So we've got got to be really kind of careful. And it's the same with the supply chain, you know, are they, when they make a change to their product, are they testing it thoroughly? Sometimes? I totally agree. You've got to make a change and whatever the fallout is, the fallout is you know, I remember a big pharmaceutical company and they must have had about three, 400 firewalls, when I was kind of managing the operation center. And they said, oh, the vendor says there's a vulnerability and we must have them all patched by the weekend. So you go through the vulnerability and then you realise that vulnerability is only applicable if you're running certain services on the firewall. So that narrowed it down from hundreds to about half a dozen. So, and I confirmed with the vendor, and the vendor goes, yeah, but our standard message is you must always upgrade. But totally agree that actually this would work because doing that many firewalls in one weekend, you know you're going to bring that company to its knees by Monday morning because some stuff will work. And then we had our own stats that when we did this vulnerability patching probably one in forward Bloats Springs out, and you'd need to put new hardware in. So that means, you know, when you've got a global company, you've got to have guys on site with new hardware in case that goes wrong, so you can keep them going. And then eventually we kind of narrowed it down and said, look, these, it came out to like three firewalls and we said, okay, we'll do the upgrades for you and we'll have prepared new hardware in case it goes wrong. It took me nine months to get that change window eventually, and then I had to point out, you do realise in nine months that this firewall will be out, support, see, might as well put a new one in. Which is not conversations customers really want to be hearing, but that's kind of reality of, you know, what MSPs have to deal with. So I totally appreciate it is difficult and it's not easy. And the one thing, sorry, I've want to go back to one of Neil's point is cyber essentials on paper, I got to say looks really straightforward. But what I've kind of seen, and you know, we help companies go through their cyber essentials once they get to a certain size. They've kind of lost control. And it will be, yes, all our machines are up to date and then they produce a report. Actually, these 40 are still running, you know, windows nine or whatever. Yeah. And then it's, well what about your servers? Yeah. But we, they're, you know, they're in the two thousands. What's wrong with that? Okay. So, then you've got, the thing is they need budget, they need money, they need resource to, to do this work because changing a server that your whole businesses depend on is really scary. And just running the upgrade is just not good enough. Sorry, Gene.

GENE: No, I was going to say, you're exactly right around, when you're looking at security vulnerabilities and patching, especially, context is incredibly important, right? Is it 900 devices or is it really my effective in your case three that is exposed? And so I think a lot of organisations don't keep that in mind. You know, generally I think when assessing, you know, vendors and supply chain, you know, the very tools that MSPs are using. I look for transparency, you know, and operational maturity on the part of your partners. Proof means things like security assurance, you know, the standard things, the SOC two and the ISO style controls, but real world behaviours, how quickly they patch vulnerabilities, how they handle those disclosures and what sort of logging and audit capabilities that they're providing is really really important. And transparency matters because no vendor is going to be perfect. So if when something does go wrong, are they communicating with you very quickly? You know, do they have a very clear incident notification, timeline and policy? Do they support your investigations? Right? And this operational maturity, I think means strong access to controls, but more importantly, good segregation of customer data. Right? Everything needs to be multi-tenant. You know, security features that match how MSPs operate need to be taken into account. And, lastly, like when something does happen, what's that blast radius look like, right? If this vendor gets compromised, what's the worst case impact to your customers? And that question I think is going to drive the practical decisions about limiting privileges and, you know, monitoring integrations and, you know, having those sorts of contingency plans on a per platform basis.

IAN: Absolutely. Thanks for that. Neil, from an MSP's point of view, you know, you've obviously know, you've embraced the security element very much, but how does this show up in your SOPs when you're looking to onboard new vendors or new partners that want to plug into your system?

NEIL: Yeah, it's really kind of reiterate what Gene just said there really, it is about it's almost building a case. You, you look at all of the evidence that the vendor supplies in terms of its own credentials the standard, it's hearing to, you're looking at reviews, you're looking at yeah, experience that other MSPs may have had, and you, you're kind of looking to build that trust. Because, yeah, engaging with any new vendor, particularly around something around cybersecurity, and you are trusting them to, with your, well, with your reputation, you know, that, that, that's the that's the importance of it because obviously if it doesn't work or if they have a breach, it's our reputation that, that will suffer. Because very often the client doesn't know and really doesn't want to know what tools that we are using. They just want that peace of mind. They just want to know that we know what we are doing and that we've selected the tools and the stack that we use because we know how to do that. We know what looks good and we trust the vendors that we work with. So yeah, it used to be, it's certainly a lot more complicated these days. A lot more time consuming these days to work and select you know, work with a vendor and select their product. So yeah, proof of concept, all of that kind of stuff that we go through when we make any change like that.

GENE: Neil, I think you really made a great point in that, end customers of the MSPs, they're not waking up in the morning thinking, oh my gosh, I wish, I think I'm going to buy a new EDR today. Right, or...

NEIL: Yeah, they really don't.

GENE: I really want a new SOC today. Right. They're thinking about the outcome of ensuring that they're going to continue to be in business. And so, you know, when you're and when MSPs look at tools they need to make sure that they're always up and running and operational. And that's one of the benefits that absolute provides to MSPs. We're the control layer to support all of the capabilities and tools that they're using on a day in, day out basis, the security stack their RMMs to ensure that those tools are up and available and always operating to protect those very customers. And so I think we, because we're tied and embedded in the hardware of 600 million plus devices and uniquely have this capability to ensure that the very tools that MSPs are running are always available and doing the job they're supposed to be doing and protecting their customers is an absolutely essential consideration when looking at vendors specifically to ensure, hey, are they going to be around? Are the very controls that I'm relying on going to be available when something goes wrong?

IAN: Absolutely.

DAVID: And I think, sorry, there's one kind of other bit which kind of probably layers across what Neil and Gene are saying, yeah, is really kind of, if possible, design security in depth. Number of times we've come across a customer and go, you know, have you thought about this? And they go, yeah, we've got two firewalls. Obviously of the same vendor back to back. And that's really like if you've got a vulnerability in one, you've got a vulnerability in both of them and you know, in sort of financial areas, yeah. You may often have 13, 14 layers of defense in depth. Okay. Maybe not everybody needs that, but you certainly need multiple layers and we've kind of tended to go, I want one vendor. One source, one problem. Really? You need multiple vendors, because the one thing, you know, for certain, that vendor will get a problem sooner or later.

IAN: Yeah, absolutely. Absolutely. Brilliant conversation. Thank you very much. Thank you very much everyone for that. So we've gone through the journey on what do we need to do to educate our clients? What do we need to do to keep ourselves safe now? For the last section of this, we want to talk about something that we hope never, ever happens, but we need to prepare for it, right? It's like as we sort of say the emergency service is falling over, you're going to cut your knee incident response. Let's talk about, you know, should the worst happen and your, client phones up in the morning and says, crickey, there's a big bad guy on my screen, I can't get in. What is it? David, I'm going to come to you first on this one. You know, what should every MSP have in place in terms for an incident response? Because we're, you know, we're saying it's not a case of if it's a case of when but what does a break glass look like? What should that process look like for MSPs?

DAVID: I think the number one kind of process that not just MSPs have is have a really, really fast, robust escalation method. You can't waste time coming. I need this guy because he's the cleverest guy. He needs to be able to say, we need these guys, we need him on a call. We need to triage it ASAP. And it's always better to bring the best in. And downgrade the incident rather than go, you know what? I haven't seen too much, so let it ride. That's really dangerous because quite often, you know, people talk about ransomware, yeah. Ransomware is probably the fifth layer of an attack. It's not the attack in itself. You've been compromised somewhere down the line. You've failed phishing you've had a compromise or a malicious insider. You could have had multiple things go wrong before you get ransomware. And when I've had calls, oh, we've got ransomware. Yeah, you kind of know something's gone wrong in the last past three months, almost without fail, maybe even longer. All your data has been exfiltrated. So the main thing is a) getting the right people. And you may not know who the right people are. So you're going to have to sort of say, let's get our best people on the call. Same with the, customer. Decisions have got to be made really quickly. So this is where, you know, unfortunately, you know, CEOs really have to earn their money. They can't ask their lawyer, they can't ask the accountant. They've got to make a decision. And there are no good decisions. There's just less bad decisions to make and they've got to make quickly. And then the other thing that I found, you know, I have had, you know, luckily or whatever I've had the experience dealing with hundreds of incidents, yeah. You will run out of resource and you'll run out of resource really quickly because you need stuff done in the next three days. So you've got to work out how do you get the resource, do you get it from your MSP? Does your MSP have a kind of scalable. Process where they can borrow other, sometimes MSPs staff and resources.

IAN: Yeah.

DAVID: Because you'll need all the help you can get.

IAN: Absolutely key. Thanks for that. Gene, what does this look like from your experience, what is it the MSPs need to make sure they've got in place?

GENE: You know, at minimum every MSP needs a plan that's operational, right? Not just a document that's going to sit in a folder. This means clear roles, escalation paths, and decision rights. Like who declares the incident, right? Who talks to the client, who talks to legal and insurance, and who's doing the technical containment and the recovery, right? So who has that role in your MSP? So very clearly defined, you know, what's going to happen and who's going to do it, you know? The basic things like communication templates and evidence, preservation steps and run books for isolating systems and restoring safety. They all need to be pre-thought out and pre-built. And I think what might get overlooked is practice, tabletop exercises are huge. You don't want the first time you run in, you're going to run the plan to be when it's a real ransomware event, right? And so I think the plan should really reflect the way that attackers. Are trying to disable security tools today. So, you know the first part of an instant response is to make sure that you can restore controls quickly, right? Regain that visibility and reestablish that security posture so that you can bring those systems back with confidence, right? Making sure you're not reinfected already as soon as you bring those things back. So, that's what I would advise.

IAN: Excellent stuff. Thank you. Thank you for that. Neil, I'm going to put a slightly different twist to this one. So you've just gone through this amazing sales pitch and the clients bought into you, you're, they're confident that you are going to keep them safe and secure. How do you then prepare? Any of your clients or your customers or you know, the businesses for an incident? I mean, there must be some sort of conversations to say, we are going to try our real best to make sure this never happens. But if it does happen, this is what it looks like. Do you do any education around that? And how do you frame that? So it sounds like, yeah, we're going to give you all this stuff, but if it goes wrong, we're going to do this as well. What does that look like in your world?

NEIL: Well, I think it's actually the conversation is not, if it's when. Because there is no MSP in the world that can guarantee a hundred percent cybersecurity, that you will never, ever be hacked. And if they say that, they're lying. Because this has always been a game of catch up and trying to stay as few steps behind the criminals as possible and occasionally one step ahead. That's not often. So, we have conversations with our clients around, and Gene touched on this, around insurance. So cyber insurance is quite important I think in almost any business these days. It's important for us as an MSP, but the insurance provider can, if they're a good insurance provider, if the worst happens. When the worst happens, they will work with us and they will help us bring that client back into an operational capacity as quickly as possible. They will also help run things like PR, the communications, external comms to the press or to clients. That's really important too, I think trying to hide it, trying to bury your head in the sand, trying to sort of, you know that never ends well. So ensuring that the client has got and has thought about because not a lot of clients did until we started having the conversation with them. We are not insurance salesman. And you know, we have to be quite careful about that because, we get told off. But actually just ensuring the client has got something that is appropriate, right size, fit for purpose. Cyber essentials, for example, if you just pass cyber essentials, basically you get 25,000 pounds worth of free cyber insurance. It doesn't go very far that. So actually that's great. It's better than nothing, but actually is that really appropriate for the size of business, for the damage that can be caused. I love what Gene was saying there about the tabletop exercises as well. Even if it's just a sort of an annual conversation of actually what if, you know, let's pretend today that that something has gone wrong. because I mean there are so many different potential, variables and connotations and things like that, but actually just role-playing it. Who does what actually, you know, where are the potential gaps in the event we get a ransomware attack and actually none of our IT systems work today. What is the impact? Who calls the insurance company? Who is point of contact for the press, if that is a requirement and who is our point of liaison as the MSP in the event of a crisis? So actually that little tabletop exercise, just stress tests, those sorts of fairly fundamental things, I think.

IAN: Yeah, I remember someone saying once that a tabletop exercise, you should walk into your client's office and then just get everybody into the boardroom and say, right, okay, we've just been compromised. What are we going to do?

NEIL: Yeah.

IAN: And they'll go, oh, let's just go, Nope, you can't go into there, that computer doesn't work. Nope. Your phones don't work. You know, what are we going to do? And it's kind of like that moment when you just sort of think, oh my word, this is what the reality could look like, sort of thing. And it's as simple as that, because that's, you know, what can happen if, you know, if we're not careful. So...

NEIL: And we're all off to the pub is not the right answer.

IAN: No.

GENE: And that's why I think today it's incredibly important that, to your point, Neil, the very tools that MSPs are using need to be available and most, most importantly, self-healing and can survive an incident. And that's why absolute leads the world. Because of our unique capability being tied to hardware within the firmware, we tether into the operating system to ensure that those controls, the EDR, the RMM, you know, the encryption tools that MSPs are using will automatically self-heal themselves if they are disabled by a bad actor, right? And so getting control back from the bad actors. First and foremost, the job of the MSP and then to do all the remediative work in order to get that business back up and running. But if you don't have those very tools that you're reliant on, one, they're not protecting your customers. And then you cannot manage that environment back into business operational.

NEIL: I think that's great. Gene, you prevention is always better than cure, right? And actually going back to the house analogy, most criminals are lazy. And , in a sort of a, looking at the sort of the, if you like, the stereotypical burglar, if you make your house look secure, you make it difficult to get into, you put CCTV on it. The door locks are good, the windows are shut. All of that house just as driving by, I can tell that house is pretty secure, but next door isn't as a burglar, I'm going to break into next door because it's just less hassle. So putting those things in place to make you a less attractive target, whether MSP or your client has an effect to.

IAN: Amazing. A brilliant conversation gentlemen. Thank you very much. I'm going to come to ask you for your final thoughts and last pieces of advice for the MSP community in a moment. But just before, I just wanted to remind you, that coming up on the 27th of May, the next MSP Channel Insights round tables around intelligent MSP operations. So here we can talk about AI automation. We're probably going to have to stem the flow of panelists on this one and how it can help you scale your MSP as well. But today's session was brought to you with platinum sponsors the MSP Growth Hub ourselves. Absolute security. So again, thank you Gene and the Trust Bridge from David and Gold sponsors Ninja One and Barracuda. So thank you very much for making this event possible. Gene, final thoughts, we're just about to fly away into the sunset. You turn around to your MSPs and you say to them...

GENE: You know, to close I'd leave them with a simple challenge, if they ask their customers tomorrow or if the customers ask them, right, prove that we're secure, prove we're compliant, prove we can recover. Could you answer that question with evidence? Right. Within a short period of time, you know, 24 hours, you know, that's where the market is heading. With regulations tightening, cyber insurance requirements getting more and more stringent.

IAN: Yeah.

GENE: Customers are realising. Cybersecurity just minimises that risk. But resilience delivers business continuity. So the MSPs that own this next stage of growth in the next couple of years are going to really operate with a lot of discipline. They're going to standardise their baselines. They're going to, automate. The evidence that's being collected. And they're going to rehearse responses. And when you can do that, you know, security stops being a cost conversation and becomes a growth story, right? It helps customers, you know, helps the partners, the MSPs win deals, pass audits and stay insurable. So at absolute, we're investing in this same idea of resilience as control, helping MSPs ensure that their critical security postures on endpoints stay present healthy and recoverable because in the next few years, the differentiator, it won't be the tools. MSPs all have very similar tools. It's going to be who can make sure that those controls are up and running, that's going to matter most.

IAN: Absolutely. Lovely. Thank you very much and thank you for your contribution today, Gene. David, what's your final thoughts on today's conversation?

DAVID: Great, thanks for, you know, Neil and Gene, I think some great stuff there. I think the one thing that companies and MSPs need to realise, they I forgot the exact name of it. I think it's Kobayashi Maru, the game in Star Trek, that you can never win, you can never win it, but you don't have to be the worst at it. And that comes down to kind of even going back to Sun Tzu. It is great to have tactics, which are all the tools, but you do need the strategy to enable you to at least come out looking good, because I think we said this earlier, probably as a bit of a joke, you are not just against the bad guys. You're up against the good guys as well who will want to blame you. You are up against the regulators as well, who will also want to find fault with what you're doing. So you need to have defense, you know, at three levels. Bad guys goodish guys and higher level of good guys without naming names.

IAN: That's lovely. Thank you very much for that, David. And hopefully we haven't deterred too many MSPs from running their businesses. Maybe we should run a session on the m and a next, and then we can see how many are now scared. They don't want to do it but it is possible to really make a big impact, isn't it? Neil, you know with your final thoughts on what you guys are doing, you know, the cyber advisor, the really embracing the whole you know, the next level of security, this is something that if you embrace, you'll be standing out from the crowd in an extremely successful business, rather than running away from it. Right.

NEIL: Quite right. And, we remain the only MSP in Gloucestershire that has all of the qualifications that we have, right, in one space, which does make us stand out. It's a great marketing advantage and I hope it provides both clients existing and potential that sort of greater level of confidence that we know what we're doing. It is, I'm going to use another Star Trek a quote, taking inspiration from Dave. The more complicated you make the plumbing, the easier it is to stop at the drains. And I think what there's a word of caution there in that cybersecurity has been a hot topic for quite some time now, but as we move forward and obviously the latest hot topic is AI. And I think it's a cautionary tale for MSPs. Just don't take your eye off the ball because it's very easy to go after the next flashing light. The next exciting thing, the next brilliant moneymaking idea of and implementing AI. Unquestionably, AI is going to have a huge impact on what MSPs do and how they interact with their clients and how they make the money. But. Without cybersecurity as a solid foundation underneath that, you're going to find yourselves in trouble. So don't take your eye off the ball. It's very easy to do.

IAN: I think that's amazing. Amazing final words there from everyone. So, just remain say thank you very much for that great conversation. I absolutely love doing these sessions because it's amazing what you can learn every day is a school day. Thanks for your contribution and your insights and sponsorship into this and we look forward to seeing you and all the other members. Very soon. Take care. Have a great day. See you soon now.

DAVID: Thanks, Ian.

NEIL: Cheers.

IAN: Thanks guys.

GENE: Bye-Bye.

IAN: So there you go. I hope you enjoyed that. I just know that it's going to offer so much value to you, and there's so many little things in there that you're going to take away without kind of leaving the comfortable place of where you are for your podcast. So I hope you enjoyed it. I'm going to bring more of these to you as well. If there's anything in, you know, obviously if there's anything that you want to hear or see on the IT Experts podcast, then please let us know. Keep an eye out. We're going to put the link in the show notes for the MSP Insights Roundtable so you don't miss them when they go out live. You can catch up with all of them and the replays there as well. But I just thought I'd share this with you. As I said, loads of information, great insights is what it's all about. Anyway, look forward to catching up with you on next week's show. Take care. All the best now.

NEXT WEEK TEASER:   And in next week's show, it's an absolute corker. You are going to love it. If you feel in your MSP that you are a superhero and you are running around putting all the fires out, jumping off the building, saving everybody who's in trouble, then that's okay. But it's not scalable and it's not sustainable, and it's not going to help you build a business that works for you. And in next week's show, I help you how to go from being a superhero to help you get that structure and that control back in your business, you're going to love it. Tune in next week.

OUTRO: Oh, but one last thing just before you shoot off. And if you're curious about how this episode links with the ability to scale your MSP to a million or, or if you are already there, accelerate to five, then we want to invite you to come and take the MSP Mastery quiz. And in just three minutes, you're going to get a 360 degrees scan of your business where you can identify the one or two tactics that can help you find more time, engage in, align your people and help generate more leads in your MSP. It's really simple. Just click on the link in the show notes and if you have enjoyed this episode, we'd love to get some feedback from you by means of a rating review on Spotify or iTunes, or your podcast platform of choice. We really appreciate every single one of them. Now, you can go and enjoy the rest of your day and we look forward to catching up and connecting with you soon. All the best day.