Blacksmith InfoSec

Get NIST-y

Get NIST-y is a podcast that breaks compliance out of the checkbox trap and turns it into a real security advantage. No fluff, no FUD—just practical strategies to make compliance work for your MSP. Each week, we'll dive into compliance topics based on real questions from our MSP partners and subscribers.

Author

Blacksmith InfoSec

Category

Technology

Podcast website

blacksmithinfosec.com

Latest episode

Jul 7, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

If Nothing’s Broken, Why Fix Security? Making Cyber Risk Visible 13.01.2026

If your systems are running and nothing bad has happened, how should leaders think about cyber risk? In this episode, we tackle two listener questions. Kevin, a COO in Phoenix, asks how business leaders should evaluate security risk when there has been no breach, outage, or audit failure to force the issue. Allison, an IT Director in Portland, wants to know how to show real progress in cybersecuri...

Compliance Predictions for 2026 06.01.2026

We're kicking off the 2026 season of Get NIST-y with some predictions about what's to come in the world of compliance and cybersecurity. At the end of year, we'll make sure to grade ourselves on how well we predicted things, too. Want to get your compliance or cybersecurity questions answered? Head over to https://blacksmithinfosec.com/ask

A little rapping paper for the holidays 30.12.2025

We're taking this week off, so instead of hearing us talk about compliance this week, you get to hear us rap!

A NIST-y Review of 2025 23.12.2025

In this special episode, Mike and Jared talk about the compliance trends and cybersecurity disasters in an entertaining recap of 2025. Stay tuned for the 2026 preview! Want to get your own questions about cybersecurity or compliance answered? Head on over to https://blacksmithinfosec.com/ask

Compliance, Clients, and the QBR Problem: Part 1 16.12.2025

This is part one of a two-part crossover with Adam Walter from Humanize IT⁠ . In this episode, we dig into two real listener questions that every MSP will recognize. First, we help Marisol from a dental practice understand why compliance is a program and not a one-off project, using an orthodontics metaphor that goes way further than anyone planned. Then we answer a question from Ryan, a COO who i...

Compliance as an Advantage and Increasing Margins 09.12.2025

In this episode of Get NIST-y , hosts Jared Casner and Michael Zbarsky talk about how MSPs can stop seeing compliance as a burden and start using it to grow their business. Question 1: “When I'm talking to prospects, compliance always comes up as a pain. How can MSPs flip compliance into a trust signal or competitive advantage instead of a burden?” — Daniel, MSP Sales Leader in Chicago Jared a...

Get NIST-y LIVE: Incident Response with Bob Miller 02.12.2025

Most MSPs think they have incident response under control, at least until chaos hits. In this live episode of Get NIST-y , hosts Jared Casner and Michael Zbarsky sit down with Bob Miller , CEO of IR Game and Chief Evangelist for Right of Boom , to explore why even the most “mature” IR plans crumble under pressure and what real-world readiness actually looks like. From the limitations of tabletop e...

Most MSPs Aren't Built to Scale (But They Could Be!) 25.11.2025

In this episode of Get NIST-y, we're joined by our friend Dustin Puryear, founder of https://giantrocketship.com/ . We talk about how to use automation, documentation, and compliance to set your MSP up for success and long-term, sustainable growth. Want to get your own questions answered about cybersecurity or compliance? Head on over to https://blacksmithinfosec.com/ask

Relationship Intelligence: Can AI Build Real Trust in Sales and Security? 18.11.2025

In this episode of Get NIST-y, hosts Jared Casner and Michael Zbarsky engage with Jean Templin, founder of nayak.ai , to explore the evolving landscape of sales, particularly in the context of AI. They discuss the importance of building trust and rapport with clients, understanding buyer perceptions, and leveraging AI to enhance emotional intelligence in sales interactions. The conversation delves...

Security Culture and Human Risk 11.11.2025

Our questions this week revolve around training and culture. The first is, “I’ve rolled out security awareness training, but it doesn’t seem to stick. How do you actually build a culture where employees care about cybersecurity?” The second is, “We’ve been doing phishing tests, but people get upset and feel tricked. How do you balance training and testing without making employees resent IT?” Want...

AI and Security: Partners or Opponents? 04.11.2025

Jared and Mike talk with guests Everykey and TurboDocx ! Is AI a powerful tool for cybersecurity — or is it too early to tell? What tasks can we trust AI to perform like pro, and which still need human oversight and expertise? Want to get your own compliance or security questions answered? Ask them at ⁠https://blacksmithinfosec.com/ask

From Inbox to Demo: Securing and Scaling Every Customer Touchpoint 28.10.2025

Jared and Mike talk with guests (and fellow PitchIT participants) HitWit and Palisade ! We'll discuss the best way to engage and convert clients using a variety of marketing and sales channels (and cutting-edge tech!) Want to get your own compliance or security questions answered? Ask them at ⁠https://blacksmithinfosec.com/ask

Leveraging Compliance to Sell More Security Services 21.10.2025

In this conversation with Matthew Koenig, VP of Channel Sales at Nodeware , we discussed the critical relationship between compliance and security, emphasizing that compliance frameworks serve as a foundation for effective security measures. We explored the challenges MSPs face in selling compliance and security services, the importance of understanding client needs, and the necessity of building...

AI in Compliance 14.10.2025

We’re recording this episode just shy of ChatGPTs 3rdanniversary, so it seemed fitting  to do an AI episode. I’m sure these answers will age well… “There are so many AI-powered compliance tools being advertised. Are they really capable of managing compliance, or do they leave hidden risks?” “If AI can’t replace humans, where does automation actually help in compliance? What tasks can safely be aut...

Insurance, Feds, or SMBs: Who is REALLY Driving Compliance for MSPs? 07.10.2025

Replay of a live episode we recorded with Michael Cannady from https://liongard.com where we broke down the driving forces behind the demand for compliance services. Are regulations rolling back? Are end-users themselves picking up the slack and demanding cybersecurity that fits a known framework? Discussion topics: Compliance and governance software for MSPs, policy reviews, and the best framewor...

Expert vCISO Says MSPs are Doing Compliance All Wrong 30.09.2025

Replay of a live recording we did with veteran vCISO Mike Ellerhorst from NTM Advisory . In this episode, we broke down some of the common mistakes MSPs make when running compliance programs for their clients and, more importantly, how they can fix or prevent those mistakes from happening. Discussion topics: Change fatigue, client relations and QBRs, and why building your MSP's security progra...

Is Your Compliance Prescriptive or Performative? 23.09.2025

Is your compliance offering just for show? Let's fix that. Join us for a straight-shooting look at turning compliance requirements into real security wins for your MSP. We'll cut through the noise of checkbox-ticking solutions that promise the world but leave your clients vulnerable, show you how to build compliance that actually means something, and reveal why MSPs who get this right are laughing...

What is an RMF and how can I scale it for my SMB clients? 16.09.2025

This week, we're tackling two related questions about Risk Management Frameworks (RMFs). “I keep hearing people refer to different security frameworks as ‘RMFs’. What is an RMF and how is it different from a security framework?” “Can you give some real-world examples of how RMF principles (such as user audits and access control) can scale down for a small business without feeling overwhelming?...

CIA Triad and the Value of Compliance 09.09.2025

This week, Mike and Jared tackle 2 listener questions. First, a question from an anonymous user: I’ve heard a lot about a “CIA triad”. What is that, and how does it apply to compliance? Is this some sort of spy thing? Second, a question from a California-based MSP: A lot of my clients are doctors, dentists, and restaurants. Many of them operate on razor thin margins and tell me they can’t afford t...

Welcome to Get NIST-y! 02.09.2025

Welcome to Get NIST-y , the series that breaks compliance out of the checkbox trap and turns it into a real security advantage. No fluff, no FUD—just practical strategies to make compliance work for your MSP. We originally launched Get NIST-y as a live webinar series. So, why are we relaunching it as a podcast? As we had guestsjoin us for our live discussions, we realized that a lot of the content...

Listen to the Get NIST-y podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.