Top 8 MSP Cybersecurity Blog Posts to Read Before 2021

If cybersecurity isn’t a big part of your managed services offering in 2021, you may need to reevaluate what’s important to your clients.

As you know, cybersecurity attacks are on the rise. In fact, there have been 4,000 cyberattacks a day since the COVID-19 pandemic, according to MonsterCloud. Ensuring your clients and their systems and networks are protected from cybercriminals should be one of your top priorities in 2021.

We’ve covered many cybersecurity topics this year on the TruMethods blog. Take some time this month to review them before heading into the new year.

What is the Cybersecurity Maturity Model Certification (CMMC)?

If you have not heard of the CMMC yet, it’s not the end of the world. The latest certification requirements were finalized by the Department of Defense (DoD) on January 31st and at the moment they are in the process of approving auditors for the new certification. What does this mean for you as an MSP? Not a whole not unless you and your customers meet specific criteria.

Creating an MSP Incident Response Plan? Here’s Some Advice

The best way to ensure things go from bad to worse for your MSP clients is to not have an incident response (IR) plan in place when you’re hit with a cyberattack. And many MSPs don’t have an IR plan to follow for one simple reason: They don’t know how to develop one. To make things easier for them, Chris Loehr, EVP of Solis Security, and Wes Spencer, CISO of Perch Security, recently joined me on a webinar to discuss what MSPs should know about IR plans.

Wanted: Trustworthy Guidance from a Security Professional

In the wake of the COVID-19 pandemic, companies are facing the dual challenges of supporting employees working from home while absorbing the fallout from the associated economic downturn. Although economies are slowly re-opening around the world, it’s unclear just how long it will take to get back to where it was before the shutdown.

It’s Official: Hackers Have Left Their Basements

MSPs have struggled with keeping up with the increasingly complex IT threat landscape, mainly due to fundamental business structure issues preventing them from achieving optimal results. Many MSPs simply don’t have the knowledge, tools, process or profits to secure their customers in the way they would like — but why not?

MSP Templates for a Best Practices Cybersecurity Assessment

If you haven’t heard about cybersecurity online, in print, or on the news in the last 10 years, exactly how safe are your customers? Cybersecurity has become a serious topic for businesses and consumers. And unfortunately, cyber threats are set aside in favor of other initiatives and become a bigger problem in the long run.

End User Cyber Security Risks and Training Options

In today’s IT environments productivity is necessary, uptime is essential, and security is critical. The latest hardware and software provide layers of protection in hopes of preventing cyberattacks. The newest technology causes most IT providers to forget the weakest link: the end user.

Closing the MSP Cybersecurity Skills Gap

Companies often struggle to create and enforce robust cybersecurity strategies, partly because compliance varies among employees. This inconsistency could be caused by the specifics of job roles within the company that might make policies more or less inconvenient to employees based on their position. In addition, different levels of security awareness and technical skills across an organization can create further security challenges.

Security-Centric RMM: Making Managed Security Better

As the number of cyberattacks targeting SMBs increases, there is more pressure to protect against those attacks. That’s why MSPs handling the IT needs of these businesses must place security at the top of their priority list. One way to build a strong security offering is from the ground up, starting with one of the most fundamental tools used by and MSP — their remote monitoring and management (RMM) solution.

Now is the time to reassess your cybersecurity strategies. Read and reread the blog posts above if you want to step into the new year with a managed services offering centered around cybersecurity in 2021.

cybersecurity ebook

ConnectWise Acquires Perch Security: What You Should Know

Many of you heard that ConnectWise acquired Perch Security. Now, if you’re not aware, ConnectWise is owned by private equity firm Thoma Bravo, as is SolarWinds. This is another in a list of channel acquisitions. 

The Big Four — Datto, ConnectWise, Kaseya and SolarWinds— continue to acquire additional pieces to build each oftheir technology stacks. The strategies are clear:Each is building an ecosystem to make it attractive to consume their entire stack. Each vendor is especially focused on building their security offering

But here’s the question: Is security better in the hands of PE-driven companies? Or does innovation grow in startups run by entrepreneurs? It seems as if startups create the innovation and then the private equity companies acquire it and provide the distribution model

Will Perch be a better company with ConnectWise?I’m not sure. Will their services become more costeffective and impact more SMBs and MSPsProbably. So, ConnectWise acquiring Perch isn’t necessarily good or bad. It’s just a function of how the channel operates.

If you look at the valuations in the security space, it tells you that the industry understands that it needs to help MSPs solve this growing imbalance between MSPs and imposters. Today,MSPsas a whole are losing the war. In theory, the process makes sense. It’s hard for big software companies to innovate because they have to put most dollars into sales and marketing in order to growGrowing is why they exist. On the other hand, it’s hard for startups to scale. Building a great innovative solution requires a different skillset than building a scalable, go-to-market function.

If you look at all the successes and the failures in the channel over the past 10 years, this theory plays out almost without exception. If you look at the enterprise, you see a much different level of innovation than in the MSP space. It’s five years (maybe even in some areas 10 years ahead) with AIdriven products, security solutions and a host of other solutions.The rapid change in the security landscape is pushing the channel to innovate at a pace that it’s not accustomed to.

We need to make sure that we’re seeing all these implications, and that we’re keeping a perspective on what I would call the macro implications of what’s happening quickly in our channelso that we’re prepared to make the best decisions in the future.

cybersecurity ebook

TruMethods MSP Success Summit: Are You Joining Us?

I’ve got some big news for TruMethods members and the MSP community at large: TruMethods is hosting its first MSP Success Summit in December — and you’re invited!

The MSP Success Summit is a week-long event designed to help MSPs climb the mountain of MSP Success. But reaching the top of MSP Success is no easy task.

So, for this industry-wide event, we decided to invite some of our closest friends — including Perch, IT Glue and ID Agent — to help us with educating MSPs on proven success principles focused on security, sales, documentation and more.

Beginning on Dec.7, we’ll start our adventure together. Each day, you’ll receive a free resource from one of your mountain guides. These tools will help you improve a specific area of your business.

On the last day of the event, we’ll get together on a live webinar to discuss all the assets you received during the event, how you can deploy those assets, answer your questions and make sure that you’re set up to take advantage of all the opportunities 2021 will present you with.

Also, just for signing up, you’ll have a chance to win our grand prize — a brand new Samsung 75-in. TV and Sonos Set surround sound system! If you want an extra entry for the grand prize, make sure to enter our Twitter giveaway. This will give you an extra entry for the Summit grand prize AND give you a shot to win a $50 Amazon gift card. You can find the information for the Twitter giveaway here.

Here’s what you get after registering for the event:

  • An email each day with your free giveaway.
  • You’ll automatically be entered into the grand prize sweepstakes (only if you’re in North America).
  • You’ll be registered for the live MSP Success Summit on Dec. 11th from 12PM-1:30PM EST.

To learn more about the summit and register, go to https://www.trumethods.com/summit.

It’s a long way to the top of the mountain of MSP Success, but you don’t have to do it alone!

New call-to-action

MSP Business Planning and Technology Success

For TruMethods, it’s the most wonderful time of year – Business and Sales Planning time! We have found through the years that so many MSPs do not have a business plan, and at the same time those that have a business plan seem to reach their goals much more consistently than those that don’t.  Why does this dichotomy exist? Oftentimes the link between business planning and day to day life can seem disconnected.  But how can a humble TAM (Technology Alignment Manager) or vCIO (virtual CIO) contribute to a business plan that is written by management?

The success of any MSP’s business plan largely depends on the contributions of the technology success team, as they deliver the value that clients can clearly understand.  Tighten up your processes, keep to your scheduling disciplines, and always strive for continuous improvement.  Conduct your TAM reviews, conduct your vCIO reviews, schedule Standards Committee meetings, wash, rinse, repeat. To quote one of TruMethods core values, you need to be awesome!

It isn’t enough to do just business as usual though, especially when planning for the future and looking for ways to make our process better.  What do your metrics look like now? What do they actually indicate? Are we doing the things to move the needle or things that just feel important but actually aren’t? Once we know the answers to these questions, we can write our own technology success plan. A good basic structure to use would be to come up with a Quarterly Action Plan, because that’s where it is broken down to what we need to do each day, each week, each month, to achieve our goals for 10 years from now. While it might seem almost silly to ignore a screaming ticket to write down our goals for the future, TruMethods has seen planning be a key factor in MSP success. It doesn’t matter if we have the plan in our heads or we think we’re too small to write one or we have this emergency, we have to have scheduling discipline to put things in writing. We cannot let working IN the business shove aside working ON the business.

Many TruMethods members already know this, but putting the Quarterly Action plan into motion is what our software (myITprocess) and our TruMethods Framework do best.  As a TruMethods member, you have a Member Success Advisor that you can reach out to for guidance, we will help you and your team apply these concepts to your Tech Success process.  TAMs and vCIOs even have peer groups that can help them with questions regarding their specific goals (TAM and vCIO all-stars). We have also often seen teams come up with Quarterly Rocks as things to focus on as a group, and they can be structured to ensure they are contributing to the company’s goals overall.

It has always been impossible to keep customers secure to the best of our ability without having proactive roles, and today’s environment only exacerbates and proves that point further.  Ensuring we can provide technology success also ensures we are doing our best to achieve all of the company’s goals across the board.  The entirety of your company’s offering should revolve around what your team is doing, so we need to do everything to the best of our ability.

There has never been a better time to be an MSP.  The security and technology landscape is changing constantly and it is up to us as technology professionals to stay on the forefront and protect our clients.  Being World Class is the best thing a TAM or vCIO can do to ensure their company achieves or exceeds their goals.

Request My Demo

Preparing for Your 2021 MSP Business Plan: Vision, Purpose, Values

Reevaluating your company’s vision, purpose and values before developing your MSP business plan for 2021 is key.Now is also the best time to assess how you can become a better version of yourself and what that foray into personal development could potentially do to help you with putting your business in a better position for 2021.

For the remainder of 2020, assess who you are as a person. Have you created a vision for the life you want? What’s your purpose? What are your values? Take some time to do some soul searching. After determiningyour starting pointyou can then build a positive company culture.

And another thing: Your personal plan must align with your business plan.If it doesn’t, you’re setting yourself up for failure. 

Is your vision still the same?

Now is the time to revisit your vision for your business and life.

Your vision for life should give you some direction (a starting point) when developing your organization’s vision. Think about what you want your organization to represent and achieve in the future.Ask yourself, “What do I want my organization to look like five years from now?Your vision should inspire.

If it does, your employees will get on board, and that’s the kind of buy-in you’ll need to succeed. 

Is your company’s purpose clear?

Don’t know why your company exists? Then you don’t know your company’s purpose!

Your company should provide your employees with a greater sense of purpose. Consider the mark you want your company to make on the world.

Think about it this way: Besides paychecks, what are your employees working for? Why are they doing what they’re doing every dayA company’s purposeunites team members under a single cause.

Once you identify your company’s purpose, share it with your team membersThen, ensure everyone in your organization knows your company’s purpose by keeping it top of mind in whatever they do.

Creating a purpose-driven organization is challenging, but it’s not impossible. 

What are your company’s values?

Defining your company’s core values is no easy feat for any business owner.

I often get asked, “What are core values?” Simply put, they’re the cultural foundation of your company. They are not just a list of feel-good slogans you throw up on a wall somewhere. It takes time to fully establish the right values for your organization, but after you’ve identified them, decision making should be a lot easier.

For example, we have two core values at TruMethods: Members First and Be Awesome.

When faced with tough decision, oftentimes turn to TruMethodscore values for guidance. Fall back on yourcompany’s core values when having a difficult time with making a decisionYou’ll find that your core values will keep you on the right path.

There is still time to assess your company’s vision, purpose and values before the new year. They are what define your company’s culture, so take chunk time out of your schedule to revisit them.

Becoming A Top-Performing MSP

What is the Cybersecurity Maturity Model Certification (CMMC)?

If you have not heard of the Cybersecurity Maturity Model Certification (CMMC) yet, it is not the end of the world. The latest certification requirements were finalized by the Department of Defense (DoD) on January 31st and at the moment they are in the process of approving auditors for the new certification. What does this mean for you as an MSP? Not a whole not unless you and your customers meet specific criteria.

The DoD website answers some of the basic questions needed to understand the CMMC, why it is important, and who qualifies for the certification.

What is the CMMC?

CMMC stands for “Cybersecurity Maturity Model Certification”. The CMMC will encompass multiple maturity levels that ranges from “Basic Cybersecurity Hygiene” to “Advanced/Progressive”. The intent is to incorporate CMMC into Defense Federal Acquisition Regulation Supplement (DFARS) and use it as a requirement for contract award.

Why is the CMMC being created?

DOD is planning to migrate to the new CMMC framework in order to assess and enhance the cybersecurity posture of the Defense Industrial Base (DIB). The CMMC is intended to serve as a verification mechanism to ensure appropriate levels of cybersecurity practices and processes are in place to ensure basic cyber hygiene as well as protect controlled unclassified information (CUI) that resides on the Department’s industry partners’ networks.

How will my organization become certified?

The CMMC Accreditation Body (AB), a non-profit, independent organization, will accredit CMMC Third Party Assessment Organizations (C3PAOs) and individual assessors. The CMMC AB will provide the requisite information and updates on its website (www.cmmcab.org).

The CMMC AB plans to establish a CMMC Marketplace that will include a list of approved C3PAOs as well as other information. After the CMMC Marketplace is established, DIB companies will be able to select one of the approved C3PAOs and schedule a CMMC assessment for a specific level.

My organization does not handle Controlled Unclassified Information (CUI). Do I have to be certified anyway?

If a DIB company does not possess CUI but possesses Federal Contract Information (FCI), it is required to meet FAR Clause 52.204-21 and must be certified at a minimum of CMMC Level 1.

Companies that solely produce Commercial-Off-The-Shelf (COTS) products do not require a CMMC certification.

I am a subcontractor on a DoD contract. Does my organization need to be certified?

Yes, so long as your company does not solely produce Commercial-Off-The-Shelf COTS products, it will need to obtain a CMMC certificate. The level of the CMMC certificate is dependent upon the type and nature of information flowed down from your prime contractor.

How does my company become a CMMC third-party assessor organization (C3PAO)?

The CMMC AB will provide information and set requirements for prospective C3PAOs and individual assessors. Prospective C3PAOs and assessors should reference the CMMC AB website (www.cmmcab.org).

In a nutshell, if you do not handle CUI or personally perform government contracts, there is no need to worry about the certification. If your customers are involved in DoD contracts or anything mentioned above or on the website, it is better to be safe than sorry and look into the next steps.

TruMethods does not offer advice on this type of content. It is wise to consult proper legal counsel on these matters. This blog post references information cited by the Department of Defense. Visit the official website for answers to additional questions on the Cybersecurity Maturity Model Certification.

cybersecurity ebook

MSP Advice: Making the Most Out of the Future

Undoubtedly, bias impacts our view of the future. To prove my point, let’s take just one example we all can relate to —the workfromhome (WFH) movement.

Many businesspeople say things like,“We aren’t a remote company, so we‘re going to get back to the office as soon as we can.In fact, I’ve felt this way at points during the pandemicBut as time has gone on,I’ve stepped away from my feelings and beliefs, and worked harder to gain perspective about what’s likely possibleThis means dealing with the facts as they are.

A recent survey found that 75 percent of people working from home say they don’t want to go back to the office full time. My point of bringing up this study is that the marketplace has changed forever. We all have to live with what it hands us. You don’t get to choose how things will be. The universe is doing that for you. 

However, if we can see the reality more clearly, then we can make better decisions and find more opportunities. Each of your customers needs help gaining perspective on what the new world will look like work from home is just one example but many aspects of how companies will operate are changing, or have already changed. 

We need to spend more time gaining perspective and educating ourselves on the most likely outcomes and less time holding on to what we wantor what we think things should look like. (Here’s a hint: You won’t find the perspective you’re looking for on a cable news channel.)

We don’t get to choose the future. But we do get to make the most of it. That means seeing it for what it is. Today, this is more difficult because so many things are changing so quickly. 

So whave to work harder to recognize our bias and how we view the future. There’s never been more opportunities available. We just have to see it clearly. 

New call-to-action

How Are You Spending Your Time in Your MSP Role?

If you want to do more of something in your business (sell more, gain better results, improve processes), the first question you should ask yourself is: How do I spend my time?

Let’s focus on the sales goal for a moment. Let’s say a main goal for your business is to increase sales and add new MRR.

How many hours are you spending specifically on this goal? To truly see a change from one quarter to the next, you need to dedicate more time to this single initiative.

One thing you should do — at least once a year — is journal your time for about two weeks. Then total that time and break it down by what you spend your time on. Next, list your priorities and see if the time you spend on each matches up. You may be surprised at what you find!

The truth is that you’re most likely spending a lot of time on things that don’t move the needle for your job, role and business. This exercise is a great way to see if this is in fact the case for you.

I learned this lesson when I sold my first MSP. My role at the time revolved around several business areas, including sales, finance and leadership. I was also managing our vCIOs.

Now, I considered my main priority to be sales, which showed because we sold new business every quarter. But once I sold the business, I had an earnout clause that was tied to money. The buyer wanted my main focus to be continuing to add new MRR, so I pulled myself out of things like the vCIO process and anything else that was not related to sales. And I assumed what would happen was that we would begin to have issues in the areas I pulled away from.

Well, here’s what actually happened: We sold way more, and everything else was fine. The time I was spending on those other things wasn’t actually moving the needle much.

My teams in other areas stepped up. We added better instrumentation, so that I could guide the results, and we became a better company because of that!

So, whatever your role is, take a deeper look at how you’re spending your time. This is a great time of the year to look at your results for 2020 and your goals for 2021. If there is a results gap, looking at how you spend your time is one of the best ways to close it.

Lastly, think about what you enjoy most about your work or role. How much time do you spend doing what you love or are good at, and how does that intersect with what makes you successful in that role? That intersection is the sweet spot. Find that and expand it to not only improve results, but to also find passion and enthusiasm.

So, again, ask yourself, “How do you spend your time?”

Becoming A Top-Performing MSP

5 Things MSPs Should be Doing Now to Drive Revenue and Protect Customers

As we approach the end of 2020 and make plans for the first quarter of 2021, there appears to be no end in sight for the ongoing economic and political uncertainty that has plagued businesses since March. The cold weather on the way may further exacerbate the COVID-19 pandemic, with cases rising in some regions where the worst seemed to be over. Your MSP clients may continue to struggle both with falling revenues and the challenges of remote work.

It brings to mind that dire warning from Game of Thrones: Winter is coming. How can you keep your own business in the black while continuing to protect your customers? Here are five things MSPs should do now to keep their businesses healthy heading into the new year.

  1. Shore up remote work capabilities for your own business and your clients. In March, many companies learned a hard lesson about just how unprepared they were for long-term disruptions and remote work scenarios. Even after eight months, there are still challenges to remote connectivity and security, and some of your clients might still be treating this like a temporary situation. Revisit computing best practices with your clients, encourage the use of secure technology infrastructure, and invest in tools you can use to help your clients better manage the transition between office-based and remote work. Internally, make sure you have deployed these same solutions to keep your data and applications secure and your team productive.
  2. Implement processes and incentives to encourage increasing wallet share with your existing client base. With so much uncertainty, winning new business in many sectors is more challenging than ever. Ensure your team focuses on maintaining customer relationships and finding ways to provide more services to clients. The clients who have stuck with you are still going to need a lot of help; make sure you are offering the right mix of services to secure their infrastructure and reduce costs. Consider adding different services to the mix (e.g., managed print, hosted VOIP, compliance-as-a-service) to expand  potential touchpoints with customers.
  3. Encourage employees to update their certifications and improve their skills. Many people have a bit more time on their hands, with so many activities closed down or extremely limited. To stay competitive, your team should be sharpening their skills via online training and obtaining industry certifications (e.g., ISO27001, SOC 2), which can help show clients that you possess the domain-level expertise they need.
  4. Focus on cybersecurity. The global market for cybersecurity services and solutions continues to expand rapidly, and new, sophisticated threats are emerging weekly. The turmoil caused by remote work has only made the need for robust security more acute. There is still a high demand for data security expertise, cybersecurity training, and innovative technologies such as artificial intelligence to help automate security processes. Security offerings can help strengthen client relationships while providing an ongoing revenue source with a high value-add for the client.
  5. Maintain strong communication with your team and with your customers. If you are still primarily working remotely, the way you interact with clients and co-workers has likely changed significantly over the past eight months. Your customers may be stressed out by business challenges, working in close quarters with their spouses or children, and dealing with online school issues. Your team is likely under strain as well. Make sure you are reaching out to clients over the phone to see how things are going for them and reinforce the human connection that has been lost with on-site visits being limited. Try to get an idea of how they are planning for the coming new year, and look for ways to help them achieve their goals. Internally, find ways to keep your staff engaged and connected through similar daily or weekly check-ins. 

While the outlook heading into 2021 is still challenging, MSPs can create new business opportunities while also helping clients weather the storm.

Michael Mowder is the Senior Director of Global Partner Success for Barracuda MSP, a provider of security and data protection solutions for managed services providers, where he is responsible for the partner journey from on-boarding, to implementation, through professional services and finally, renewal.

cybersecurity ebook