Folgen

  • How MSPs Can Win Clients on LinkedIn: Turning Cyber Expertise into Pipeline
    Jul 20 2026

    Today we're doing something different. No tradecraft, compliance or threat intel. Today is about the other thing that keeps MSP owners up at night: where the next client comes from.

    Here's the uncomfortable truth. Your buyers are on LinkedIn every single day and most MSPs are invisible there. Or worse than invisible: a profile that reads like a resume from 2014, three posts a year about patch Tuesday, and a network full of other MSPs and vendors. Everyone selling, nobody buying.

    Our guest today built his entire company on fixing exactly that. Dean Seddon is the founder and CEO of Maverrik, the number one social selling training company. He's trained over 150,000 professionals across 11 countries, speaks at more than a hundred events a year, and his mission is to equip one million businesses to get clients through social selling. They don't call him the Dean of LinkedIn for nothing.

    Mehr anzeigen Weniger anzeigen
    1 Std. und 4 Min.
  • CMMC Phase II Paused: What Every MSP Needs to Know
    Jul 20 2026

    It's Thursday, July 16th, and three days ago the Department of War suspended CMMC Phase II, effective immediately. The third-party certification requirement that was set to hit on November 10th is gone for now, a reform task force has 60 days to review the entire program, and officials would not rule out scrapping it altogether.

    Here's the thing: if you were paying attention, you saw this coming. Back in March, CIO Kirsten Davies sat in front of the House Armed Services cyber subcommittee and told lawmakers she was looking at CMMC through the lens of Secretary Hegseth's push to reduce regulatory burden. Congressmen were quoting GAO findings that compliance costs could bankrupt small contractors, and Davies confirmed a dedicated review of the CMMC ecosystem was already underway. Monday was that review going public.

    But here's what did NOT change, and it's the reason this call exists. The Department's own release says this action "does not eliminate the requirement for companies to protect federal data." Self-assessments are still in force. DFARS 7012 didn't move. NIST 800-171 is still the standard. What got suspended is the referee, not the rules. And with self-attestation now the primary enforcement mechanism, the False Claims Act exposure for your clients arguably went up on Monday, not down.

    Your DIB clients are calling this week asking to pause projects and redirect budgets. Today we're giving you the answers for those calls.

    Joining me is the Mount Rushmore of CMMC: Jacob Horne, Scott Singer, Ryan Bonner, Andy Sauer and co-host Scott Edwards.

    Important: Legal considerations for MSPs working with the DIB is laid out in this blog by Eric Tilds.

    Mehr anzeigen Weniger anzeigen
    1 Std. und 29 Min.
  • Who’s Breach Is It – The Legal Grey Area of MSP Client Transitions
    Jul 14 2026

    Here's a scenario that's playing out right now, for several MSPs across the country, and based on our research, most do not have it covered in writing.

    A client decides to switch providers. The new MSP starts rolling out EDR and standing up monitoring. The old MSP begins winding down. Somewhere in that overlap, credentials are still active, agents are only half deployed, and it isn't clear who's actually watching. Then the breach hits.

    Now two MSPs are pointing at each other, the client's data is exposed, and everyone reaches for the contract, only to find the transition period was not CLEARLY defined. Who was responsible? When did one watch end and the other begin? The MSA doesn't say. The SOW doesn't say.

    This is one of the biggest gray areas in managed services, and it's the one that ends up in court.

    To help us walk through it, we are joined by Melissa Ventrone, attorney at Clark Hill, who has lived this from the incident response side, where she sees what happens after the handoff goes wrong. We're going to dig into the controls and monitoring gap, who owns the risk during a transition, and what every MSP should put in writing before they ever take on, or hand off, a client.

    Mehr anzeigen Weniger anzeigen
    1 Std.
  • Inside the Credential Spray Hitting Microsoft 365
    Jul 6 2026

    This week we're digging into a Huntress report that came out on June 30th, updated just a couple days ago on July 2nd a large-scale password spray campaign that hit Microsoft 365 environments through Azure CLI. Between June 12th and June 26th, Huntress tracked more than 81 million login attempts, leading to at least 78 compromised accounts across 64 organizations.

    What makes this one worth a full conversation isn't just the volume it's that a lot of the businesses hit already had Conditional Access policies and MFA in place. The attackers got in anyway, by using a deprecated OAuth flow called ROPC that quietly sidesteps MFA if your policy isn't scoped correctly. So this is really a story about the gap between "MFA is turned on" and "MFA is actually enforced everywhere it needs to be."

    Andrew “Spike” Brandt, Principal Threat Intelligence, Incident Commander at Huntress, sat down with us to unpack what happened, why it worked, and what to actually go check in your own client environments this week.

    Mehr anzeigen Weniger anzeigen
    1 Std.
  • The Vulnpocalypse is here and your MSP can survive it
    Jun 30 2026

    Today we have one of the most important voices in cybersecurity joining us.

    Chris Hughes started his career defending the nation in the United States Air Force. He's spent over two decades in the trenches from the Department of Defense to the federal government to the commercial world as a CISO, security architect, and engineer.

    Today he's VP of Security Strategy at Zenity, where his focus is on what he believes is the defining security challenge of our era: agentic AI.

    He's the author of multiple books published by Wiley, including Modern Vulnerability Management, and he runs Resilient Cyber, a newsletter and podcast that reaches over 31,000 security professionals every single week.

    But here's what you really need to know walking into today’s session, CVE counts are on pace to exceed 50,000 this year. NIST has conceded it can no longer keep up with enriching vulnerability data. And exploit timelines have collapsed from weeks to hours. Our guest has a word for what's coming and he coined it himself: the Vulnpocalypse. But, there’s hope, as Chris will share

    Mehr anzeigen Weniger anzeigen
    1 Std. und 2 Min.
  • The Vulnerability Crisis No One is Funding
    Jun 22 2026

    Last week, I asked Philippe Langlois, principal author of the 2026 Verizon DBIR, a simple question: if an MSP could only focus on one thing this year, what should it be? His answer, without hesitation: "Vulnerability management."

    That tracks, as this is the first year in DBIR history that vulnerability exploitation has overtaken stolen credentials as the top breach entry point, jumping from 20% to 31%. Meanwhile, median time-to-patch climbed from 32 to 43 days, and only 26% of known exploited vulnerabilities got fully remediated.

    As most know, NIST just overhauled how the National Vulnerability Database operates, moving to a risk-based triage model after CVE submissions jumped 263% since 2020. Joining us to unpack it is Steve Carter, CEO and co-founder of Nucleus Security, who's spent over two decades in vulnerability management

    Mehr anzeigen Weniger anzeigen
    1 Std. und 1 Min.
  • The 2026 Verizon DBIR Unpacked with Author Philippe Langlois
    Jun 15 2026

    Today's session is one you genuinely don't want to miss. Every year, Verizon publishes what is arguably the most respected, data-backed snapshot of the global threat landscape, the Data Breach Investigations Report.

    The 2026 edition is the 19th annual installment, and it just set a new record: over 22,000 confirmed breaches analyzed across 145 countries. The numbers don't just confirm what we suspected, they shift how we must implement our defense in depth strategies.

    Joining us is Philippe Langlois, principal author of the 2026 DBIR and one of the minds behind how Verizon collects, interprets, and translates breach data into actionable intelligence.

    Mehr anzeigen Weniger anzeigen
    1 Std.
  • Identity, the Browser and the New Perimeter
    Jun 1 2026

    We spent a decade building security around the network. Then five years around the endpoint. The whole time, sitting right in front of every user, every day the browser. Unmanaged. Unexamined. Trusted by default.

    The 2026 Verizon DBIR makes it hard to look away anymore. Infostealers, session token theft, OAuth attacks almost every major attack pattern this year runs through the browser at some point.

    Today's guest thinks about this problem at a scale very few people get to. He's going to help us understand what the MSP community is missing and what it actually means to secure the place where work happens.

    Arunesh Chandra, Head of Product, Microsoft Edge for Business joins The CyberCall to discuss these topics and more.


    Mehr anzeigen Weniger anzeigen
    1 Std. und 3 Min.