MSSP Alert

Cyber For Hire (Audio)

If you’re a managed security provider (MSP), managed security service provider (MSSP), virtual CISO, or a cybersecurity professional looking for insights and advice on ways to build bridges with your clients (or vice versa), look no further than Cyber for Hire | The Managed Security Podcast! Presented in partnership with MSSP Alert and ChannelE2E, Cyber for Hire, is a weekly 60-minute podcast (in two 30-minute segments) hosted by Ryan Morris, Principal Consultant at Morris Management Partners, and Bradley Barth, Director of Multimedia Content Strategy at CyberRisk Alliance. It’s the podcast wh...

Author

MSSP Alert

Category

Technology

Podcast website

www.scmagazine.com

Latest episode

Sep 26, 2023

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android almost 10M downloads · 4.8 rating iOS soon

Episodes

How Managed Services Providers Can Exceed Evolving SecOps Expectations - Christopher Fielder - CFH #30 26.09.2023

The days of an MSSP or MSP being a security device babysitter are over. Clients expect more from your SOC, SIEM and SecOps offerings, and evolving attacks will demand more of you. It's time to level up -- but how does one upgrade from basic to top-tier services? According to our featured speaker, there are several key steps: more comprehensive, cross-industry threat data collection; more refined,...

Supply Chain Security: How Moving Accountability Upstream Helps & Hurts MSSPs - Dave Sobel - CFH #29 31.07.2023

One of the most significant takeaways of the White House's recently unveiled National Cybersecurity Strategy is the assertion that software developers, OEMs, and technology service providers must bear the brunt of the responsibility -- rather than end-users -- for keeping cyber environments secure. With the looming prospect of further legislation and regulations looming that could impose greater l...

Balancing Dark Web Threat Intel: Fair Attention for MSSPs - Alex Holden - CFH #28 25.07.2023

Our guest for this segment spends his days where others dare not tread: the deep dark web. Here he collects information on cybercriminal activity that could be a precursor to major attack or evidence that one has already occurred. For companies that can't or won't conduct dark-web recon for themselves, outsourcing this threat intelligence service is a valuable option. Still, this kind of contracte...

Brian Johnson - CFH #27 25.07.2023

Try as they might to keep their clients in compliance with privacy and security regulations, managed services providers are still at the mercy of the organizations they serve. Unfortunately, companies don't always follow the MSSP's or vCISO's advice on items like responsible data stewardship, privacy policies and breach notification. If an attack does transpire and the company draws the ire of reg...

M&A Integration Challenges & Alert Fatigue: MSSP Strategies for Client Escalation - Jim Broome - CFH #26 04.07.2023

Last year, ChannelE2E listed more than 1,000 merger and acquisition deals involving MSPs, MSSPs and other similar service provider organizations. Typically when any M&A deal occurs, there are bound to be redundancies and overlaps in services, tools and personnel. For MSSPs that find themselves in this situation, it's important to consolidate and integrate the best of their assets across multiple e...

Quantifying Risk & Optimizing Responses: Scaling Your MSSP for Reduced Randomness - Ira Winkler - CFH #25 27.06.2023

Risk isn't a static measurement. Threats like malware campaigns, vulnerabilities, human error and unreliable third-party partners can fluctuate in their severity depending on ever-changing circumstances. That's why knowing which risk is of highest priority at any given time can allow MSSPs to dynamically adjust their prevention and mitigation efforts, for both themselves and their clients. But whi...

Going Passwordless: Preparing Your Clients for a Credentials-Free Future - Christine Owen - CFH #24 13.06.2023

It's been a big year for the passwordless movement, with tech giants Apple, Google and Microsoft supporting the FIDO Alliance's efforts to replace conventional credentials with passkey technology. Still, passwords have long been engrained into people's daily routines, so users may need some convincing to change their behaviors. And likewise, managed security services providers may need to persuade...

CFH #23 - Bill Brenner 30.05.2023

Today marks the beginning of the Identiverse conference in Las Vegas, where leaders in security gather to discuss advancements in the world of identity and access management. For MSSPs that specialize in managed IAM services, it's important to stay on top of the latest trends, including those revealed in a series of reports and articles that CyberRisk Alliance has published as part of its overall...

CFH #22 - Don Pecha 23.05.2023

Infosec leaders shouldn't just be reporting to the board room to explain themselves when things go wrong. They should be a regular part of the strategic business discussions that take place inside a company's executive halls. That's true whether they're directly employed by the company or they're a contracted vCISO provided by an external managed services provider. In this segment, we'll discuss h...

CFH #21 - Merike Kaeo 16.05.2023

Risk assessment questionnaires are a standard practice when evaluating current or prospective third-party partners. And yet some folks may justifiably ask: How valuable are these questionnaires if there are no consequences for fudging your answers, or even outright lying? This session will examine common weaknesses and oversights in the third-party assessment process, while recommending how to imp...

CFH #20 - Pete Bowers 16.05.2023

What's the best way to ensure operational resilience against cybercriminals' tactics, techniques and procedures? Well, just rearrange the letters in TTP, and you get PPT: people, process and technology. This session will examine how organizations can score, benchmark and improve their cyber resilience through a combination of security processes, proper cyber hygiene and employee behavior, and a ro...

CFH #19 - Mike Hamilton 02.05.2023

The cyber talent shortage is well documented. Rather than just trying to outbid each other in a competitive job market, wouldn't it be nice if MSSPs were also able to build out their talent pipelines through professional development programs? This session will look at strategies for creating an assembly line of ready-to-go cyber professionals to add to your managed services team, including coordin...

CFH #18 - Juan Valencia 25.04.2023

Your favorite intelligence feeds are warning of several up-and-coming new campaigns that are victimizing companies much like your clients. Maybe they're even targeting MSSPs themselves. Now it's up to you to assess and prioritize these latest threats, and determine to what extent they require you to change your approach, institute additional safeguards, or update your security awareness messaging....

CFH #17 - Michael Smith 18.04.2023

Who won the Super Bowl this year? Everyone did, in the sense that there were no major cyberattacks that disrupted the flow of the "Big Game" -- unlike, for instance the Pyeongchang Olympics, where ticket distribution was affected on the night of the Opening Ceremonies. For contracted cybersecurity services providers, protecting a prestigious one-off event like a sports championship or political co...

CFH #16 - Craig Robinson 11.04.2023

Having a clear and cogent taxonomy that classifies your managed cyber services into distinct buckets or categories is an important step for MSSPs looking to define and differentiate their market offerings to clients. Customers can refer to your taxonomy to better understand your scope of services and ensure they don't leave gaps in their security plans, while you as a service provider can leverage...

CFH #15 - Jessica C. Davis 04.04.2023

What are the market trends that are driving growth and changes in the managed security service provider market? MSSPAlert.com, an affiliate of Cyber for Hire, does an annual survey of MSSPs to find out about growth trends, technology providers, different types of incidents they see in their work with small and mid-sized businesses, and other information and insights. In this edition of Cyber for H...

CFH #14 - Matt Miller, Joe Alapat 28.03.2023

Now in its eighth iteration, the Center for Internet Security's Critical Security Controls (CIS Controls) framework provides organizations with 18 categories of high-priority best practices that they can follow in order to improve their cyber hygiene, while remaining in step with key regulations. In this segment, we'll look at what MSSPs and their client base need to know if they opt to follow CIS...

CFH #13 - Ryan Jamieson 21.03.2023

Security is a shared responsibility between MSSPs and their clients. Yes, the provider was hired to do a job -- be it SOC operations, threat intelligence or offensive security -- but part of the job is also to consult and communicate with the client to help them gain some degree of cyber self-sufficiency. This discussion will reveal how providers can teach their clients how to develop a secure cor...

CFH #12 - Ashwin Radhakrishnan 14.03.2023

In late 2022, the MITRE Engenuity foundation revealed the findings from its first-ever ATT&CK Evaluations for managed security service providers. The report measured various MSSPs' ability to recognize, analyze and report the TTPs of the OilRig Advanced Persistent Threat group. This session will dig into the findings to help MSSPs better understand where they can stand to improve when it comes to...

CFH #11 - Chris Bell 07.03.2023

For managed services providers looking to build their market strategy around XDR and MDR -- or a hybrid of the two solutions -- it's important to understand how this approach will shape future priorities for their tech stacks and toolsets, their clients and their vendor partners. What kinds of next-generation services can they build from an XDR/MDR foundation? How does this differ from a more trad...

CFH #10 - Remote Monitoring & Management Hijackings 28.02.2023

In late January, CISA, the NSA and the MS-ISAC released an advisory warning about the malicious the use of legitimate remote monitoring and management software, after uncovering illegal hacking activity on two federal civilian executive branch networks. Whether compromised via social engineering or through exploits, RMM tools can grant unauthorized users potentially unfettered access to your MSP c...

CFH #9 - A.N. Ananth 27.02.2023

The developer of a commonly used software issues an urgent out-of-band update for a coding vulnerability that is discovered to be under attack. Immediate patching is imperative. Under such circumstances, what can MSSPs do to quickly identify which of their clients are running this vulnerable software version? And then what are the best practices for managing and collaborating with these exposed or...

CFH #8 - Jason Lewkowicz 07.02.2023

In late January, law enforcement officials disrupted the operations of the Hive cybercriminal group, which has profited off of a ransomware-as-a-service (RaaS) business model. And though the takedown was an inspiring victory, there's plenty more ransomware where that came from. Indeed, Microsoft just reported that at the conclusion of 2022 it was tracking more than 100 threat actors using over 50...

CFH #7 - Michael Miora 31.01.2023

Some MSSPs have a hard time leaving their comfort zone when it comes to their toolsets. They prefer to stick to their own tried-and-true suite of tools and are reluctant to add new ones, even though it might be beneficial to do so. After all, not every client has the exact same needs and challenges. This session will look at how MSSPs can potentially boost their revenues, increase their subscripti...

CFH #6 - Candy Alexander 24.01.2023

No matter how well constructed an MSSP's security architecture is, or how tight its security controls are -- all that good work can be wasted or sabotaged far too easily when the client organization fails to follow standard cyber security hygiene practices. Just because a company uses a managed security provider to bolster its cyber preparedness doesn't mean they still don't have a responsibility...

Listen to the Cyber For Hire (Audio) podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.