エピソード

  • Frontier Models Call for Collective Action on Cyber Defenses
    2026/08/31

    Last week, OpenAI published an open letter and over a hundred companies signed on. CrowdStrike, Microsoft, Google, Cisco, AWS, Anthropic, basically every major name in cybersecurity and enterprise tech. The letter warns that AI-enabled cyberattacks are about to get faster and more sophisticated, and it specifically calls out hospitals, water treatment plants, and critical infrastructure as the places most at risk.

    It lays out a plan: every organization needs to raise its security standards, cybersecurity companies need to build AI-powered defenses, governments need to fund the utilities that can't fund themselves, and frontier AI labs — the OpenAIs, the Anthropics — need to hand tools and support directly to the defenders who need it most.

    I went through every name on that signatory list. Not one of them is an MSP. Not one of them is the company that actually shows up when a small-town water authority's systems go down at 2am.

    So today on CyberCall, I've got Alan McDonald with me, as he runs an MSP that services a number of municipal water districts. And I want to find out: when the biggest names in cybersecurity write a letter about protecting critical infrastructure, where does someone like Alan actually fit in?

    続きを読む 一部表示
    1 時間 2 分
  • Collaboration Platforms are the New Phishing Frontier
    2026/08/24

    For years, security awareness training has focused almost entirely on email phishing: spot the bad link, question the urgent request, verify the sender. But Unit 42 just published research showing attackers have found a different door, and most teams aren't watching it. Collaboration platforms like Slack and Teams have become part of the identity attack surface. Unit 42 tracked a fourfold increase in malicious activity tied to these platforms over the past year, and 99% of it started as chat-based phishing.

    Here's what makes this especially relevant for MSPs: most organizations use Teams to collaborate with outside companies, including their IT provider. Attackers know that. They pose as the MSP itself, or as IT support, because that relationship already carries a zone of trust. When "your IT provider" messages you on Teams asking you to approve an MFA prompt, most people don't question it, they just comply.

    That's why we wanted Wil Klusovsky on the show. Wil's known for translating technical risk into something executives can actually understand and act on, and this topic needs exactly that.

    Palo Alto's Unit42 Research:

    https://unit42.paloaltonetworks.com/communication-channel-identity-risks/

    https://unit42.paloaltonetworks.com/microsoft-teams-phishing/

    続きを読む 一部表示
    1 時間 3 分
  • When AI Generated Patches Become the New Vulnerability
    2026/08/18

    This week's conversation is one we believe every MSP needs to hear.

    AI-generated vulnerability patches have become the obvious next move for software developers drowning in a tsunami of CVEs. It sounds like a great answer, until you look at the actual data.

    That's exactly why we wanted Keith Hoodlet on the show. Keith just published the inaugural research from 1Password's new security research team, Off-by-1 Labs, and the findings are fascinating: when frontier AI models were tasked with patching six real, recently-disclosed vulnerabilities, they got it fully right without breaking anything else, just 26% of the time. More than half the time, the patch either didn't fix the vulnerability, introduced a new one, or both.

    Keith's research can be found here.

    続きを読む 一部表示
    59 分
  • Future of AI Advisory for MSPs
    2026/08/10

    AI is reshaping our industry faster than anything we have witnessed, and yes, threat actors are using it too. But we don't want to spend today talking about AI simply as a threat. We want to talk about it as the biggest opportunity our industry has had in a long time and how we consider adopting AI for ourselves and our clients.

    That's exactly why we wanted Lior Bela on the show. Lior recently stepped into a new role leading AI Strategy for Security at Microsoft, and he posted something that we believe resonates with every MSP. Organizations are eager to adopt AI, they just need to do it securely and helping customers navigate that is what excites him most.

    So that's where we're headed today. No product pitches. Just a real conversation about where the opportunity is, how governance and go-to-market are shifting, and what the next six to twelve months look like at the speed AI is moving.

    続きを読む 一部表示
    1 時間 5 分
  • MCP for MSPs: Cutting Through the Noise
    2026/08/03

    Most MSPs are asking the same question in a different way: "Do I need to care about MCP, or is this just another acronym I can ignore for six months?"

    MCP Servers are becoming the connective tissue between AI agents and the tools you already run; your PSA, your RMM, your security stack. MSPs are using them to kick off assessments, run queries to determine continuous EDR deployment and many other critical tasks within the business.

    So today we're getting digging into this topic to help you make good decisions. Where are MSPs are actually finding value with MCP right now, and where the hype is running ahead of what it can really do. What a smart first move looks like if you're starting from zero. And the part nobody wants to skip past governance and security. What access an AI agent should never have. How you audit what it actually did. Who inside your business should own that call in the first place.

    To help us work through it, we’ve got Aharon Chernin, CEO of Rewst, who has a firshand view of “what good looks like” when it comes to MSP and MCP.

    続きを読む 一部表示
    1 時間 1 分
  • When AI is the Hammer, is Everything a Nail?
    2026/07/27

    Right now, every MSP is hearing the same sentence from clients: "We need AI." But when you start to ask questions like “what are you trying to accomplish,” there is no plan, no process, just a mandate.

    Our guest has heard it three times before. Ian Barkin built his career watching this exact cycle repeat, first in Business Process Outsourcing, then in Robotic Process Automation, and now in agentic AI. Same hammer, different decade. Companies are convinced the tool is the answer before they've asked what problem they're actually solving, or done the unglamorous work of documenting the process underneath it.

    Ian is the author of All Hands on Tech and founder of magentIQ, and he's going to walk us through the frameworks and methodolgies he's built, for leading clients through the proper steps that produce tangible outcomes.

    If you've ever sat across from a client who wants AI yesterday and a roadmap never, this one's for you.

    続きを読む 一部表示
    1 時間 5 分
  • How MSPs Can Win Clients on LinkedIn: Turning Cyber Expertise into Pipeline
    2026/07/20

    Today we're doing something different. No tradecraft, compliance or threat intel. Today is about the other thing that keeps MSP owners up at night: where the next client comes from.

    Here's the uncomfortable truth. Your buyers are on LinkedIn every single day and most MSPs are invisible there. Or worse than invisible: a profile that reads like a resume from 2014, three posts a year about patch Tuesday, and a network full of other MSPs and vendors. Everyone selling, nobody buying.

    Our guest today built his entire company on fixing exactly that. Dean Seddon is the founder and CEO of Maverrik, the number one social selling training company. He's trained over 150,000 professionals across 11 countries, speaks at more than a hundred events a year, and his mission is to equip one million businesses to get clients through social selling. They don't call him the Dean of LinkedIn for nothing.

    続きを読む 一部表示
    1 時間 4 分
  • CMMC Phase II Paused: What Every MSP Needs to Know
    2026/07/20

    It's Thursday, July 16th, and three days ago the Department of War suspended CMMC Phase II, effective immediately. The third-party certification requirement that was set to hit on November 10th is gone for now, a reform task force has 60 days to review the entire program, and officials would not rule out scrapping it altogether.

    Here's the thing: if you were paying attention, you saw this coming. Back in March, CIO Kirsten Davies sat in front of the House Armed Services cyber subcommittee and told lawmakers she was looking at CMMC through the lens of Secretary Hegseth's push to reduce regulatory burden. Congressmen were quoting GAO findings that compliance costs could bankrupt small contractors, and Davies confirmed a dedicated review of the CMMC ecosystem was already underway. Monday was that review going public.

    But here's what did NOT change, and it's the reason this call exists. The Department's own release says this action "does not eliminate the requirement for companies to protect federal data." Self-assessments are still in force. DFARS 7012 didn't move. NIST 800-171 is still the standard. What got suspended is the referee, not the rules. And with self-attestation now the primary enforcement mechanism, the False Claims Act exposure for your clients arguably went up on Monday, not down.

    Your DIB clients are calling this week asking to pause projects and redirect budgets. Today we're giving you the answers for those calls.

    Joining me is the Mount Rushmore of CMMC: Jacob Horne, Scott Singer, Ryan Bonner, Andy Sauer and co-host Scott Edwards.

    Important: Legal considerations for MSPs working with the DIB is laid out in this blog by Eric Tilds.

    続きを読む 一部表示
    1 時間 29 分