『Get NIST-y』のカバーアート

Get NIST-y

Get NIST-y

著者: Blacksmith InfoSec
無料で聴く

【Amazonプライム会員限定】今ならプレミアムプランが4か月 月額99円。

10月19日まで。※適用条件あり
Get NIST-y is a podcast that breaks compliance out of the checkbox trap and turns it into a real security advantage. No fluff, no FUD—just practical strategies to make compliance work for your MSP. Each week, we'll dive into compliance topics based on real questions from our MSP partners and subscribers.Blacksmith InfoSec
エピソード
  • Minimum Viable Security: Build It and Keep It Running
    2026/09/22

    Antivirus, backups, and MFA are a start. They won't tell you how payroll runs when the check printer is inaccessible or keep your risk register current six months later. This week, Jared and Mike talk about what a small business actually needs and how to keep that work going.


    - Identify the client's critical data and the processes that keep the business running.

    - Check the less obvious dependencies, from break-glass accounts to the payroll check printer.

    - Use CIS Implementation Group 1 as a starting point, then keep improving.

    - Schedule user audits, policy reviews, and risk assessments as recurring work.


    We answer:

    - What should a 50-person company with antivirus, backups, and MFA be doing repeatedly to have a minimum viable security program?

    - How do you keep that program alive when policies go stale, evidence goes missing, and nobody updates the risk register?


    Make sure to follow the podcast or ask your own questions at: https://blacksmithinfosec.com/nisty/

    続きを読む 一部表示
    24 分
  • Your MSP Is Not the Client's Unpaid Compliance Department
    2026/09/15

    It started with one questionnaire. Now you're the compliance department, and apparently that's included in the flat rate. On Get NIST-y, Blacksmith InfoSec's cybersecurity and compliance podcast for MSPs, we're talking about who owns the program and who pays for the work.


    - Name one executive owner at the client before work starts. Your day-to-day contact doesn't have to be that person.

    - Check the contract before charging for new work. Catching up on patching you already owed is different from adding a managed compliance service.


    We answer:

    - Our client wants to "get compliant," but every task comes back to us. When do we insist on an internal owner?

    - How do we keep questionnaire help from turning into unlimited compliance work under a flat-rate MSP agreement?


    Make sure to follow the podcast or ask your own questions at:

    https://blacksmithinfosec.com/nisty/

    続きを読む 一部表示
    21 分
  • AI Policy After the Horse Has Already Left the Barn
    2026/09/08

    AI adoption happened before most clients wrote the rules. That does not make an AI policy useless. It changes the job from trying to stop AI to governing the tools already in use, training people to make better decisions, and protecting sensitive data.


    Takeaways:

    - Why governance, education, and security are the only realistic levers left

    - How the data, platform, subscription tier, and vendor agreement determine whether a prompt is acceptable

    - Why AI output still needs human validation, especially when the topic is unfamiliar


    We answer:

    - AI is already everywhere at our clients. Is it too late for a policy to help?

    - How specific does AI training need to be before employees stop calling IT about every email and spreadsheet?


    Make sure to follow the podcast or ask your own questions at:

    https://blacksmithinfosec.com/nisty/

    続きを読む 一部表示
    19 分
adbl_web_anon_alc_button_suppression_t1
まだレビューはありません