It’s Time to Adjust Your 2020 MSP Business Plan

A lot in the world has changed since youdrafted your 2020 business plan late last year.

The COVID-19 pandemic has without a doubt transformed the way we live our lives and operate our businessesYour customers have new expectations and are demanding more from you and your employees, so my question to you right now is this: Have you adjusted this year’s business plan yet?

Here’s the thing: Too manyMSPsare sitting back in a defensive posture — and it’s worrying meIt’s almost like they’re waiting for theCOVID-19 pandemic to passbefore seizingthe opportunities being presented to them at this very moment. 

Now, I can’t predict what will happen with the current health crisis (of course, it’ll eventually pass, but we don’t know exactly when), but from an economic perspective, here’s what we do know:Unemployment is forecasted to spike in June to twenty percent

Before I go any further, let that number sink in. 

Twenty percent is a staggering figure to comprehendso make no mistake about it: We’re in a new economic cycle, and it’s time for us to prepare for what lies ahead — a bumpy ride

So, fasten your seatbelt, and protect yourself and your company from what’s coming down the pike by reevaluating your 2020 business plan.You can do this by reviewing your process, go-to-market strategies, and packaging and pricing to better prepare yourself and your customers for the new economy. 

I normally recommend tobusiness owners that theydraft a ten-year vision, three-year targets, a one-year plan and quarterly action plans, but the future is a lot fuzzier now than ever before.

Adapt to today’s uncertainty by focusing on what I’m calling arolling 90dayaction plan. 

In other words, determine what must happen in thenext 90 days and then thefollowing 30 days. Stay in this cycle until we can get a better view of the future to recalibrate.

I’m encouraging MSP business leaders to get their teams involved during this process. It’ll pay tremendous dividends in the end.

New call-to-action

It’s Official: Hackers Have Left Their Basements

The security landscape for SMBs and MSPs has changed dramatically over the past several years.

Hackers have left their basements and moved into high-rise buildings. They’re nowwell-funded by governments and private organizations. Many cybercriminals are larger and more mature in how they operate their businesses than you or your customers.

MSPs have struggled with keeping up with the increasingly complexIT threat landscapemainlydue to fundamental business structure issuespreventing them from achieving optimal results. Many MSPs simply don’t have the knowledge, tools, process or profits to secure their customers in the way they would like — but why not?

The reality is this: Many MSPs haven’t been charging enough for their services — it’s a simple math problem.

Now, fast forward to today — an opportunity awaits.

Many SMBs around the worldover the past eight weeks were forced to change their topologies.

You helped thewith enabling their employees to work from home, but that came with a cost to their IT infrastructuresUser data and risk became decentralized almost overnight, and the bad guys responded quickly with new threat vectors.

I’m the business analyst on a weekly cybersecurity podcast with top security resources in the industry. They’ve been painting a pretty bleak picture of ramped up threats and breaches in the SMB spaceIs their outlook arisk or an opportunity for you?

The answer is it depends.

If you’re not quickly adapting to change your process, approach standards, perspective and culture from a security standpoint,you and your clients have more risk today than two months ago.

But if you’ve changed or plan to change, then this is a huge opportunity for youNow you can work even closer with your customers.

Leverage this changein the security landscape by increasing yourpricesUse security as a wedge in the sales process.

As I’ve said before, we must take this time to become better business peopleby focusingon sales, our customers, profitability and security. 

If we do, we’ll thrive on the other side.

cybersecurity ebook

MSP Templates for a Best Practices Cybersecurity Assessment

If you have not heard about cybersecurity online, in print, or on the news in the last 10 years, exactly how safe are your customers? Cybersecurity has become a serious topic for businesses and consumers. And unfortunately, cyber threats are set aside in favor of other initiatives and become a bigger problem in the long run.

Creating an initial and ongoing cybersecurity plan requires effort. Best practices are chosen, an assessment is performed, recommendations and gap analysis determine resolution, a project becomes implemented, rinse, and repeat. It is like a Technology Alignment Manager (TAM) onsite assessment with an emphasis on securing Personal Identifiable Information (PII) from malicious threats.

To maintain the security of a customer—and their customers—there are three areas to understand: Threats, Exploits, and Vulnerabilities.

  • A Threat is a person or thing likely to cause damage or danger intentionally or unintentionally. Understanding who, what, and where threats originate assists in reducing the risk of a breach.
  • An Exploit is a method of circumventing or taking advantage of a bug to cause unintended behavior to occur. These are often discovered and used by threats to gain access to software and systems.
  • A Vulnerability is a bug or defect that presents a weakness and exposes it to a threat. These allow unauthorized actions to execute within a system to access confidential information.

The three areas are summed up in a simple sentence: Threats use Exploits to attack Vulnerabilities. Cybersecurity requires detailed attention to all three areas to protect clients. Focusing on one area temporarily relieves risk and is not a permanent solution. Every customer needs a cybersecurity assessment regardless of their industry. Protecting company data is critical and executing the minimum requirements is the least a Technology Success Practice (TSP) can do for its customers.

As of this writing, there are a few templates in our myITprocess software that are available to assist with a company-wide cybersecurity assessment.

  • NIST Cybersecurity Framework (CSF) 1.1
  • NIST 800-171
  • CIS Controls 7.1
  • UK Cyber Essentials

There are many templates available within myITprocess, but this set has particular advantages over others for a general cybersecurity assessment.

  • They are easy to interpret. Many regulations and statutory requirements come directly from the law. It takes a bit of translation to make them understandable for a TAM, vCIO, and the customer.
  • They are industry- and technology-neutral best practices. No specific hardware, software, or service comes recommended by name. This is due to the varying risks different businesses face in their industry.
  • In comparison, they are easy to deploy and maintain. Each of the templates has minimum requirements with maximum effectiveness. Allowing a TAM to maximize their assessment with fewer questions makes a recurring audit workable.

Because these templates are not tied to one industry, they are usable for almost any customer. But take that statement lightly; Industry-specific regulations must follow their own set of rules. For instance, a government contractor must follow NIST 800-171, and performing a CIS Controls 7.1 assessment in its place is not advisable.

There is a lot of flexibility for Technology Service Providers to mix and match questions and categories to fulfill a clear-cut need. Vendor- and technology-neutral guidelines contribute to customized assessments by focusing on risk mitigation and not which brand to use.

cybersecurity ebook

Is Your MSP Compliant?

In a COVID-19 world there is a lot to think about and focus on.  The most important thing to always keep in mind is the safety of our family and friends, but for better or worse we still have to think about being business owners.  Clients need to be able to work from home and MSPs need to make sure we can pay the bills and stay on track with processes.  Economic, emotional, and social instability like this is something that nefarious groups can easily exploit.  We have already seen an upshift in hacking, ransomware, and malware attacks on everyone those people can reach, and it is likely to get worse.  What do we do to make sure we are protected?

MSPs are always thinking about their clients, as they should be.  The client needs to be compliant with security best practices to make sure they are not open for a possible attack. We at TruMethods are providing multiple 100 percent remote templates in our myITprocess software to facilitate this endeavor.

It may feel selfish or irrelevant to take care of ourselves as an MSP right now, but if we are not well as an organization, we are unable to help others. Think of the saying ‘The shoemaker’s children always go barefoot’. It’s the idea that the people closest to us sometimes don’t benefit from our expertise.  Eventually, if those kids don’t wear shoes they’re going to step on something that hurts them; if we do not protect ourselves, we are going to have things hurt us too. The shoemaker must make time to take care of their children and we as MSPs must take care of our own.

A great way for our members to start taking care of things internally is to complete a review using the template ‘Improving Cyber Security of Managed Service Providers’ that is found in myITprocess.   All MSPs though should have some way to keep track of the software and equipment in their environment, and a way to keep it organized.  A consistent review process should be set up internally as well, to make sure our own cables, firewalls, and antivirus software are all the versions they should be and no vendor relationships have expired.

Your company should also have its own Strategic Roadmap set up, stipulating when new things will be implemented or installed.  Maybe you decided to implement a new backup system or a marketing campaign.  If that implementation isn’t running as smoothly in the timeframe you wanted it to, having it on the strategic roadmap can help keep everything more accountable.  For some ideas on what to include on your roadmap right now, our members can reach out to their dedicated Member Success Advisor, who can show them the COVID-19 response team roadmap that was created as a helpful guide.

We all know how hard it is to focus on working ON the business as opposed to working IN the business.  Things can get out of hand quickly and it’s easy to focus on things that feel like they matter right now, as opposed to the things that actually matter for the long term.  While it can seem counter intuitive, if a hacker can get into your business, not only can they ruin everything you’ve built, they can ruin everything all of your clients have built too. This is not said to scare anyone, but we all must be realistic about what is going on, especially right now.  A healthy MSP is better equipped to make their clients healthy too!

Request My Demo

End User Cyber Security Risks and Training Options

In today’s IT environments productivity is necessary, uptime is essential, and security is critical. The latest hardware and software provide layers of protection in hopes of preventing cyber attacks. The newest technology causes most IT providers to forget the weakest link: the end user.

A typical user focuses on their job responsibilities without prioritizing security risks. A surprising amount of security breaches stem from users unknowingly granting administrative access or installing crypto-malware—all due to a lack of user security awareness and training.

Common Malicious Security Risks for End Users

Employees in all divisions within an organization are subject to malicious threats. Believe it or not, computer users are not the only asset regarded as a cybersecurity threat. Warehouse workers, receptionists, and delivery drivers are potential vulnerabilities. Security awareness and training are not intended for a specific group of users, but for the entire workforce.

Security breaches come in many forms: technical, physical, and administrative. Training employees in these areas reduces risks associated with data breaches, lowers active noise, builds a proactive service provider, and prevents lost productivity.

Baiting

A baiting attack exploits a person’s curiosity. An attacker may leave a USB memory stick in the open—labeled ‘Confidential’ or ‘Payroll files’—to bait a user into plugging it into their computer. Attaching it to a PC would then activate malicious code or files with the intent of accessing company information.

Phishing

Phishing attacks are the most common social engineering technique. Attackers use email, social media, or SMS to trick victims into divulging sensitive information or to direct the user to a malicious website to infect the user’s PC. Like baiting, phishing usually involves a method of attracting the user’s attention by leveraging their curiosity.

A spear-phishing attack is like a regular phishing attempt but targets a particular end user. This is usually accomplished by the attacker impersonating another employee—like a member of Human Resources—and requesting specific information.

Whaling

A whaling attack uses sophisticated social engineering techniques to steal confidential or personal data. The information typically has a relevant value from an economic or commercial perspective. What distinguishes whaling from phishing is the target: an executive or heads of government agencies. The term “whaling” implies there is a bigger fish to capture.

Quid Pro Quo

A common tactic of a quid pro quo attack is calling a user while impersonating technical support. They attempt to befriend the user by fixing their issue in exchange for access to the user’s PC or other information. A user may unwillingly grant access to the individual because they assume they are calling from their service provider.

Tailgating

This type of attack is a simple and very common attempt at physically accessing a restricted area. An attacker may ‘piggyback’ an authorized employee, delivery person, or warehouse worker by waiting for someone to open the door and stepping through, avoiding security measures. These attacks are common in areas with many employees due to the constant exchange of employees in the restricted area.

Human Social Engineering

Gaining access to sensitive information and security questions is as simple as talking to another person. An attacker will befriend an employee, asking questions to drill down and divulge the data they need. A common example is gaining a user’s trust and having a conversation on topics like their choice of password. The attacker will steer the conversation towards their process of selecting a password and get the user to reciprocate.

Benefits of User Training

User training provides benefits to the service provider when implemented regularly. Cybersecurity awareness is important and working with clients that trust their vCIO strengthens the strategic relationship.

Implementing a recurring training program creates a steady flow of Non-Recurring Revenue (NRR). Training sessions have the potential to generate multiple revenue projects per year. A Technology Service Provider not prioritizing user training is a surprise, to be sure, but an unwelcome one. Training strengthens and reinforces the strategic relationship. When a customer trusts their IT service provider, they are more willing to accept recommendations. Strong connections do not see expenditures as a sales pitch or revenue-generating scheme, but as a partner concerned for their best interests.

Users who identify threats and resolve minor issues on their own reduce tickets which in turn reduces Reactive Hours per Endpoint per Month (RHEM). A self-sufficient customer—even if eliminating a handful of tickets per month—is a great boost to efficiency. The reduction of RHEM leads to a reduction in tickets and leads to an increase in margins.

At the end of the process, security awareness and user training benefit the service provider and client. There is no reason to deny a customer the knowledge of preventing their own issues. Users who can sustain themselves are much more productive, efficient, and better customers in the long run.

cybersecurity ebook

Why Compliance Supports the vCIO Process

I worked as a vCIO for an established MSP in my area. I had the traditional vCIO responsibilities: onboarding new clients, detailing service plans, generating proposals, planning meetings, discussing budgets, consulting, and so on. It was about 6 months into the role when I shifted exclusively to a Health Care vCIO and relied on HIPAA as my compliance backbone.

To solidify my position as the Health Care vCIO, I attended a training course and became certified by a third party in Sterling, VA. I worked with medical practices, dentists, and businesses that managed clinical trials for patients. Having dealt with an array of companies in the industry, becoming familiar with HIPAA compliance was a no-brainer. In fact, even as a novice in the field, I still understood more than the businesses that required compliance. Even better: most of them did not know they needed to be compliant. Interesting, right?

Clients I managed were in the medical industry for years, had many locations, and annual revenues in the millions of dollars. But the sad part is their compliance was lacking. It was lacking to a point where the business owners had no concern. This was a level of willful neglect I had never seen as a vCIO. Why would they not be familiar with Federal regulation requirements?

As Anakin Skywalker said, “This is where the fun begins.”

Regulatory, statutory, and contractual cybersecurity requirements bring vCIO to a whole new level. The benefits of compliance add value to the process and can tip the scales in the vCIO’s favor. A recommendation to upgrade an aging server may get tossed aside, but replacing it to follow Federal law? That can move up the priority a few notches.

A majority of customers needed persistent convincing to spend money on valuable upgrades. Most did not see the value in the MSP besides the unlimited support. There was no incentive to spend money on projects when the Support Desk could patch problems and keep the business running. Our equivalent of a Design Desk and I would spend extra time researching, adding as much relevant information in the proposal as possible; we figured it would create more leverage to justify the expenditure. Sometimes that alone was enough. Other times it would not make the highest revenue customers budge.

When I began to work HIPAA into the mix, there were some noticeable changes in the attitudes of these clients.

The clients with the strongest relationship gave me more attention and opened their availability to meet more often. They started asking questions related to proposed projects or how to increase security by reducing their risks.

Clients with an average relationship sat up in their chairs and began to give their undivided attention. Recommendations still required a push, but their tone often changed when HIPAA was in the mix.

Customers with little to no relationship never truly changed. For the most part, they wanted to hear what I had to say about recommendations and regulations. Some were even interested in moving towards better compliance. But when a proposal had a price tag, they usually put it on the back burner.

A dedicated Health Care vCIO helped during the sales process as well. I had the opportunity to introduce myself before a sale was complete, solidifying my dedication to the industry with new clients from the start. Onboarding new customers was easier when compliance is on the table. Some were already working towards reducing risk and being compliant; they only needed a nudge in the right direction. Others lacking the personnel or knowledge of HIPAA compliance were a bit easier to guide in the long run. As I always say, “We provide the canvas, you provide the paint.”

At the end of the day, we need to remind customers that recommendations are not only about the sale. For a Technology Success Provider and their clients to succeed, everyone needs to be on board with the process. Recommendations benefit both parties when failure to comply is looming over them. This is especially true with HIPAA where a Covered Entity (customer) and their Business Associates (TSP) are liable during a data breach.

Health care is only an example of compliance. Specific industries have their own compliance standards, but in general, businesses must follow some form of regulatory, statutory, or contractual compliance from a Federal, state, or private entity. Compliance help will guide customers towards Technology Success.

Request My Demo

MSP Sales Advice: Who Are Your Centers of Influence?

Many MSPs aren’t cultivating enough COIs (centers of influence) to generate new business. While there are many ways to generate leads, COIs are a keystone of your warm lead generation process.

Unlike other lead generation strategies, including cold calls and inbound marketing, COIs generate warm leads for your business, which is why every MSP should consider building out a COI network.

Without a doubt, the COI process is an important component to building an effective sales engine. If you currently aren’t working with COIs, there are a few things to consider before you begin.

What are characteristics of a good COI?

Be selective. Not everyone is the right fit for what you’re looking to accomplish. Potential COIs must be good networkers. They should also be business owners with known ties their communities. Even if potential COIs have access to networks, they should also be on the same page as you as far as their motivations for working with COIs and approaching business and client results. Your COIs should also target the same markets as you, deal with the same decision makers, want to grow their businesses and have processes in place to generate new leads.

Where to find potential COIs

Potential COIs are everywhere. For example, consider professional services firms (e.g., lawyers, advertising professionals, accountants, financial advisers and engineers). They typically have some great relationships in place — just think about the number of SMBs they have access to in their books of business. The best way to approach these potential COIs is by finding out how you can help them.

Clients can also make great COIs if you’re close enough with them. You may want to talk with them first to find out who they like and trust. Do they have any qualified leads for you? Even though they may, don’t stop at your clients. Consider what your prospects can offer you. They can also make great COIs. Whenever meeting with prospects, learn more about their businesses by being curious.

What to discuss when meeting with a potential COI

Of course, after identifying potential COIs in your industries and communities, your next step is to meet with them. Finding them isn’t enough. Doing your due diligence is essential. You must sit down with a potential COI to determine if there’s an opportunity to develop a mutually beneficial relationship between the two of you — sometimes there isn’t one. It’s always best to discuss your businesses with one another by comparing company profiles. Are marketing and sales processes similar? What about average deal sizes? Be open to having conversations about what your motivations are. Find out theirs. Discuss how the relationship would work if you entered into one. What would the expectations be? Always do your best to get everything out on the table. If you don’t, you may regret it later on.

Finding the right COIs to work with takes time, but once you begin refining your network, you’ll notice a significant difference in the quality of warm leads you receive from your COIs.

MSP Sales Mistakes

Closing the MSP Cybersecurity Skills Gap

Companies often struggle to create and enforce robust cybersecurity strategies, partly because compliance varies among employees. This inconsistency could be caused by the specifics of job roles within the company that might make policies more or less inconvenient to employees based on their position. In addition, different levels of security awareness and technical skills across an organization can create further security challenges.

With the majority of employees now being forced to work from home, those security skills gaps are now even more apparent. If employees struggled to follow cybersecurity protocols in the office, they might have even more difficulty when they’re at home. These days, it is not uncommon for professionals to be working alongside their children, who are likely either loudly taking part in Zoom calls and Duolingo sessions, or boisterously playing, nearby. Even without children in the picture, folks adjusting to a remote work environment may be more distracted and disciplined than they are in the office.

MSPs that want to ensure their employees are adhering to cybersecurity programs, or improve their clients’ ability to do the same must make the following security practices part of their hiring and training processes.

Invest in training: Provide regular cybersecurity training for all employees — veterans and new hires — from the C-level down. This improves cyber awareness, and periodic refresher training (which can be conducted in person or online) will help keep everyone up-to-date on the latest threats.

Refresh and modernize your security technology: New security tools that leverage artificial intelligence and machine learning can help reduce risks by eliminating human error in identifying potential threats. These solutions also help determine which employees are more likely to become victims of a phishing scam or other type of attack, and then recommend additional relevant training for those employees.

Regularly test for security gaps: Even with technology and training in place, employees will still make mistakes. Conduct regular tests of your network to check for potential vulnerabilities and threats. It’s just as important to test your work products — whether that involves testing code or running attack simulations on the systems you’re providing to your customers. MSPs are increasingly becoming a target of cyberattacks because they provide a gateway to other companies’ networks. Regular testing can help prevent your company from becoming a platform for phishing or ransomware attacks.

Expand your recruiting channels: While cybersecurity experts are few and far between, there are non-traditional channels that could provide you with employees who can quickly be trained in cybersecurity. Veterans or those with law enforcement training, for example, often have transferrable skills.

Do your due diligence during the hiring phase: Background checks and reference checks are just the beginning. When evaluating new hires, you should also try to get a picture of their cybersecurity IQ and explain expectations and policies. Emphasizing the importance of security training and following protocols right from the start will provide an excellent foundation from which to build. Make it clear that security is vital to your company and will need to be taken seriously by anyone joining the team.

Create a robust professional development or upskilling program: Ongoing security training can also provide a way for employees to continue their professional development, build new skills, and generate opportunities for advancement. Online training tools can be used to create upskilling or certification programs that allow employees to opt-in and work at their own pace. These solutions can also provide data that will help identify employee strengths and weaknesses. With that information, managers can help guide employees to the best opportunities, while also ensuring they have been provided with updated security information and tools.

In a remote work environment, these strategies are even more critical. Hiring and managing remote employees requires a high level of trust and confidence in their ability to work safely and adhere to cybersecurity processes. Right now, almost every MSP is managing a remote workforce, whether they ever planned to or not. You can significantly enhance that trust by creating a security-centric environment through improved training and technology.

Nathan Bradbury is Manager of Systems Engineering for Barracuda MSP, a provider of security and data protection solutions for managed services providers.

Request My Demo

What’s On Your MSP’s ‘Never Again’ List?

I think we’ve all learned a lot over the past month. Think about it. You’ve probably learned a lot about your customers, vendors, team members, process, business fundamentals, and, most of all, yourself.

So, with all the knowledge you’ve acquired, what have you learned about yourself or your business that you would say never again to?

Never again will I have a customer that’s more than 10 percent of my revenue. Never again will I give customers credit on hardware. Never again will I have an inaccurate seat cost calculation.

For me, over the past month, I’ve delegated a lot more to my team. It has made me wonder why I held on to so much for so long. So, for me, never again will I not delegate things I don’t need to do.

Look around your business and start compiling a “never again” list. Ask your team to do the same.

Good things are coming out of the COVID crisis already. (Obviously, I’m not talking about the health crisis or the economy, both of which are very serious.) I’m talking about in our world of business.

Some of the positives have revealed themselves over the past few weeks.

For example, the MSP owners I’ve recently spoken with revealed to me various changes they’ve made to their business processes over the past few weeks, many of which have heightened focus and improved accountability among their team members.

These leaders agreed on the following: Maintaining what they’ve been able to accomplish during this pandemic is absolutely necessary.

In fact, we at TruMethods have talked about building additional accountability measures into our peer process to ensure that our members maintain the improvements they’ve made during these challenging times.

So, start your never again list, add to it, and watch your success continue and flourish on the other side.

Request My Demo

5 Ways to Protect Your MSP Business During the COVID-19 Crisis

Without a doubt, getting your MSP business through the COVID-19 pandemic is challenging for MSPs. If you can successfully protect your business, you’re going to pull through and come out a stronger business on the other side.

There are several ways you can protect your MSP business during the COVID-19 crisis.

Evaluate your current situation before making any decisions

Even though we’re all experiencing the same crisis, our businesses are facing different challenges. That’s why it’s so important for you as a business owner to evaluate your current situation and address whatever obstacles are in your way — not somebody else’s.

For instance, you can’t compare your cash situation to another company’s. Even though you should be doing this regularly, assess how much cash you have on hand. What do you have available in the bank? Do you have open lines of credit? Don’t forget to calculate out what’s owed to you. Is it possible for you to collect on accounts receivable sooner than usual?

Find out what matters most in your situation, then act accordingly.

Be transparent with your stakeholders

You also want to communicate with your employees, clients and vendors regularly. All these stakeholders want to hear from you, especially during a time of uncertainty. Communicate with them through the appropriate channels.

For example, these stakeholders are currently receiving plenty of emails about COVID-19 from other companies, so you may want to pick up the phone instead to stand out. The good news is many decision makers are now available to take your call.

Now, more than ever, is the time to be transparent with your stakeholders.

What are your contingency plans and triggers?

Nobody enjoys running through what-if scenarios (especially when many of us are trying to stay optimistic), but it’s absolutely necessary. Preparing for what lies ahead when there’s uncertainty coming at you from every angle can protect you from surprises when you least expect them.

This exercise is designed to better prepare you for making tough decisions when they arise, so be particular with your what-if scenarios. “What if I lose revenue?” isn’t a good enough question to ask yourself. Be more specific. “What if my revenue drops by 30 percent?” is a better question.

Then, determine the best way to address each scenario on your list. For example, how will you handle a customer asking for a rate reduction? Is a rate reduction out of the question? If it isn’t, how much of a reduction are you willing to provide?

It’s much easier to make business decisions on the spot if you’ve already considered what-if scenarios ahead of time.

Don’t lose sight of who you are as a company by reinforcing your values

It’s easier for your employees to make the right decisions when they’re aware of what the company they work for represents. Now, more than ever, it’s important for you to reinforce your company’s values with your employees on a daily basis. Your company’s values are tested during a crisis.

Even though your employees are more than likely working remotely right now, it’s still possible to protect your company’s culture (typically made up from your values, attitudes and beliefs) from afar. For instance, if employee safety is of the utmost importance to you, continue holding meetings with your employees to check in on more than just work-related matters. Show them you truly care by asking how they and their family members have been holding up and what you can do as a leader to help them through these challenging times.

Losing track of what your company stands for during a crisis can set you up for failure.

Pay down your technical debt

Now’s the perfect time to go back to the things you let slide when previously servicing your customers.

Remember that time when you were supposed to update documentation but didn’t because you were “busy”? What about the security gaps you left open while quickly setting up your clients to work remotely?

Pay down your technical debt before you end up having to pay more later.

If you don’t protect what you have today, you may not have anything to grow tomorrow.

New call-to-action