エピソード

  • Minimum Viable Security: Build It and Keep It Running
    2026/09/22

    Antivirus, backups, and MFA are a start. They won't tell you how payroll runs when the check printer is inaccessible or keep your risk register current six months later. This week, Jared and Mike talk about what a small business actually needs and how to keep that work going.


    - Identify the client's critical data and the processes that keep the business running.

    - Check the less obvious dependencies, from break-glass accounts to the payroll check printer.

    - Use CIS Implementation Group 1 as a starting point, then keep improving.

    - Schedule user audits, policy reviews, and risk assessments as recurring work.


    We answer:

    - What should a 50-person company with antivirus, backups, and MFA be doing repeatedly to have a minimum viable security program?

    - How do you keep that program alive when policies go stale, evidence goes missing, and nobody updates the risk register?


    Make sure to follow the podcast or ask your own questions at: https://blacksmithinfosec.com/nisty/

    続きを読む 一部表示
    24 分
  • Your MSP Is Not the Client's Unpaid Compliance Department
    2026/09/15

    It started with one questionnaire. Now you're the compliance department, and apparently that's included in the flat rate. On Get NIST-y, Blacksmith InfoSec's cybersecurity and compliance podcast for MSPs, we're talking about who owns the program and who pays for the work.


    - Name one executive owner at the client before work starts. Your day-to-day contact doesn't have to be that person.

    - Check the contract before charging for new work. Catching up on patching you already owed is different from adding a managed compliance service.


    We answer:

    - Our client wants to "get compliant," but every task comes back to us. When do we insist on an internal owner?

    - How do we keep questionnaire help from turning into unlimited compliance work under a flat-rate MSP agreement?


    Make sure to follow the podcast or ask your own questions at:

    https://blacksmithinfosec.com/nisty/

    続きを読む 一部表示
    21 分
  • AI Policy After the Horse Has Already Left the Barn
    2026/09/08

    AI adoption happened before most clients wrote the rules. That does not make an AI policy useless. It changes the job from trying to stop AI to governing the tools already in use, training people to make better decisions, and protecting sensitive data.


    Takeaways:

    - Why governance, education, and security are the only realistic levers left

    - How the data, platform, subscription tier, and vendor agreement determine whether a prompt is acceptable

    - Why AI output still needs human validation, especially when the topic is unfamiliar


    We answer:

    - AI is already everywhere at our clients. Is it too late for a policy to help?

    - How specific does AI training need to be before employees stop calling IT about every email and spreadsheet?


    Make sure to follow the podcast or ask your own questions at:

    https://blacksmithinfosec.com/nisty/

    続きを読む 一部表示
    19 分
  • New York Compliance: What the MSP Owns and What It Doesn't
    2026/09/01

    Following NIST does not automatically cover New York-specific rules, and that does not mean your MSP needs to become a law firm. We sort out where legal counsel belongs, what the client must own, and which responsibilities an MSP can safely take on. We also thank our listeners for helping Get NIST-y win an MSP Influencer award.Takeaways:• Keep lawyers focused on legal and privacy questions, not every security policy detail.• Put one client executive in charge of the security program and risk.• Treat SSO as a security control, not a substitute for application-level user audits.We answer:• How can an MSP track New York Education Law 2-d and 23 NYCRR Part 500 without becoming a lawyer?• How much of the client’s compliance work should the MSP actually own?Make sure to follow the podcast or ask your own questions at:https://blacksmithinfosec.com/nisty/

    続きを読む 一部表示
    22 分
  • Open Source Risk: How MSPs Decide What They Can Trust
    2026/08/25

    Open source is already in your stack, whether you deliberately installed it or not. In this ChannelCon 2026 talk, Jared lays out a practical way for MSPs to decide what deserves trust, what needs guardrails, and what needs to go.


    Takeaways:

    • Scope the risk by asking what the software touches and what happens if it breaks

    • Check whether the project is actually alive, maintained, and prepared to handle security reports

    • Look beyond the package itself to dependencies, SBOMs, and supply-chain risk

    • Assign one clear owner to monitor approved software after the initial review


    And one important reality check: commercial software is not automatically safer. Your vendors are using open source too.


    Make sure to follow the podcast or ask your own questions at:

    https://blacksmithinfosec.com/nisty/


    Want to see the slides or get the extra content? That's all available at https://blacksmithinfosec.com/channelcon

    続きを読む 一部表示
    47 分
  • Why Cyber Insurance Questionnaires Keep Failing MSPs
    2026/08/18

    Cyber insurance questionnaires ask businesses to make definitive claims about security controls they may not even understand. Spectra Cyber founder and CEO Edouard von Herberstein joins Michael at ChannelCon to talk about why insurers need better evidence, not longer forms.


    Takeaways:

    • Why easier insurance requirements today may tighten again as the market cycle changes

    • Why MSPs should not complete cyber insurance applications for their clients

    • Why verified evidence of MFA, backups, patching, encryption, and other controls beats self-reported answers

    • Why contracts and vendor risk management still matter, even for cloud-first MSPs


    Make sure to follow the podcast or ask your own questions at:

    https://blacksmithinfosec.com/nisty/

    続きを読む 一部表示
    23 分
  • Who Owns Compliance? And Why Evidence Fire Drills Fail
    2026/08/11

    Your client wants you to “make us compliant,” but nobody on their side will approve policies, review risks, or chase employees. Then a questionnaire shows up and suddenly everyone needs twelve months of evidence by Friday.In this episode, we talk about where MSP responsibility ends, why executive ownership matters, and how routine evidence collection keeps compliance from turning into a fire drill.Takeaways:• Compliance needs an internal executive owner who can make decisions and unblock people.• If leadership refuses to participate, the MSP may need to walk away instead of absorbing the risk.• Evidence collection should match the risk and the system, not run on one arbitrary cadence.• Useful evidence can include screenshots, reports, tickets, meeting records, backup tests, and access reviews. Screenshots should show enough context to identify the system and time.We answer:• Our client keeps delegating compliance to us. What can the MSP own, what must the client own, and what happens if they refuse?• Every questionnaire becomes a fire drill. What evidence should a small business and its MSP collect routinely before anyone asks for it?Make sure to follow the podcast or ask your own questions at:https://blacksmithinfosec.com/nisty/

    続きを読む 一部表示
    28 分
  • Cyber Safe Harbor, Bad Tech Laws, and the MSP Voice
    2026/08/04

    Starting an MSP takes less red tape than cutting hair. That gets awkward when lawmakers write cybersecurity rules without enough input from people who actually run IT services. NSITSP legislative chair Ted Giesler explains how MSPs can help shape smarter state policy before a well-intended bill becomes a technical mess.


    • Why cyber safe harbor provides a legal defense, not immunity

    • How company size, available resources, data sensitivity, and framework choice affect that defense

    • Why Ohio’s model spread to five other states, while Oklahoma limited its version to hospitals

    • How one Michigan proposal aimed at online pornography also tried to ban VPNs, proxy servers, and encryption


    Make sure to follow the podcast or ask your own questions at:

    https://blacksmithinfosec.com/nisty/


    Curious about getting involved with NSITSP in general or the legislative committee specifically? You can reach out to Ted at leg@nsitsp.org.

    続きを読む 一部表示
    42 分