Chris Johnson | Cybersecurity Education & Security Guidance

MSP 1337 | Cybersecurity Education & Security Guidance

News EN ↓ 298 episodes

Educational sound bytes to help MSPs and their clients navigate Cybersecurity. Cybersecurity maturity is a journey; don't go it alone. Interviews and guidance from fellow MSPs and other Industry experts. Our goal is Secure Outcomes, and together we can make a difference.

Author

Chris Johnson | Cybersecurity Education & Security Guidance

Category

News

Podcast website

podcasters.spotify.com

Latest episode

Jul 6, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Your Phone is the Weakest Link 06.07.2026

Everyone talks about email phishing, ransomware, and endpoint security, but one of the most dangerous attack vectors is sitting in your pocket. In this episode of MSP1337, Chris Johnson sits down with Mark Kreitzman of Efani to expose the growing threat of SIM swapping, mobile account takeovers, and the hidden security gaps traditional carriers have failed to solve. They explore why mobile numbers...

Measuring What Matters in Cybersecurity Maturity 30.06.2026

The cybersecurity industry loves to sell tools. What it rarely talks about is the hard work required to make those tools effective. In this episode, Jim Harryman joins Chris to challenge the idea that technology alone creates security. They discuss why mature organizations focus on governance, accountability, documentation, policies, review cycles, and operational discipline long before they look...

Your Passport Isn’t the Problem, Your Security Habits Are 23.06.2026

Planes, hotels, and conference stages aren’t what put you at risk, it’s what you bring with you. In this episode, Dawn Sizer of 3rd Element dives into the real reasons traveling professionals become easy targets: weak policies, poor communication, unsecured devices, and total blind spots around personal data exposure. From conditional access headaches to rideshare risks and AI policy chaos, this i...

From Reactive Security to Continuous Intelligence 16.06.2026

This episode explores how cybersecurity is evolving from point-in-time assessments to continuous, intelligence-driven operations. Galina Kho of Cyberbay shares how predictive analytics, crowdsourced ethical hackers, and AI are reshaping how organizations understand and manage risk. We discuss how to scale security without adding headcount, why human expertise remains essential, and how governance...

Taking Advantage of GTIA Resources for Lasting Business Impact 09.06.2026

In this special episode of MSP 1337, CJ is joined by Brooke Lee (Rev.io) and Stacey Whitley (GTIA) to unpack how ITSPs can translate industry engagement into measurable outcomes. Attending events is easy, but most organizations struggle to turn what they learn into real operational outcomes. Brooke and Stacey share how their collaborative event recap initiative is helping bridge that gap by distil...

Simplifying Risk Assessments for Real Cybersecurity Impact 02.06.2026

In this episode, Josh Hohbein of CentrexIT breaks down a practical, MSP-centric approach to risk assessments that moves beyond complex, consultant-driven reports and toward clear, actionable business outcomes. He shares how combining vulnerability scans, client interviews, and system configuration reviews, anchored in a cyber maturity model, helps MSPs translate technical findings into meaningful...

Vulnpocalypse Isn’t Coming, It’s Already Breaking Your Patch Cycle 26.05.2026

In this MSP1337 fireside chat, you and Matt Lee unpack the idea of a “vulnpocalypse”, a rapidly emerging reality in which AI-driven tools are accelerating vulnerability discovery at a pace organizations can't keep up with. While much of the industry is focused on the fear and hype, the conversation shifts to what actually matters: operational response. You highlight that the shrinking gap betw...

Governance, Risk, Compliance (GRC), and the MSP Wake-up Call 19.05.2026

In this episode, Chris Johnson sits down with Eric Shoemaker of Genius GRC to unpack one of the most misunderstood shifts in the MSP space: the move from tool-driven cybersecurity to standards-aligned governance, risk, and compliance programs. Eric explains why Genius GRC isn’t a software platform and why that distinction matters. Together, they explore how early automation wins (like continuous a...

The New Reality for MSP Security Operations Center Services 12.05.2026

In this episode of MSP1337 , Chris Johnson is joined by Jeff Majka, founder of Security Bulldog, to unpack why MSP‑delivered SOC services are at a breaking point, and how AI and automation are forcing a reset. They explore why traditional tiered SOC models and white‑label thinking no longer scale, how ungoverned AI adoption collides with zero trust, and why speed and decision quality now matter mo...

Guardrails, Drift, and Evidence: Cybersecurity Maturity is Continuous Improvements 05.05.2026

Chris Johnson sits down with Ido Green of Espresso Labs to explore how AI and local agents can reduce cybersecurity noise, offload Level 1 work, and continuously enforce compliance, without losing human control. They discuss guardrails for safe automation, multi-vendor telemetry, drift detection, evidence collection at scale, and why “reporting gaps” isn’t enough if you can’t execute remediation a...

Selling Cybersecurity to Skeptical Clients and Prospects 28.04.2026

A sit-down with Hamid Ganadan, author of “Not Buying It: The Art of Selling to Scientists, Doctors, and Other Professional Skeptics,” on how MSPs can sell to skeptical, highly educated buyers. This is an exploration of the psychology of decision-making, shifting prospects from skepticism to curiosity, leading with feelings over facts, crafting insights that differentiate offerings, and timing data...

Compliance is the floor, not the ceiling 21.04.2026

In this episode of MSP 1337 , Chris Johnson sits down with Jim Harryman to break down why passing audits doesn’t equal real security, and why MSPs get into trouble when frameworks turn into checklists. Drawing from firsthand experience with SOC 2 Type 2, CIS Controls, and the GTIA Cybersecurity Trustmark, Jim shares practical lessons on evidence quality, shared responsibility, inherited security,...

Cybersecurity Maturity Beyond Tools 14.04.2026

Most MSPs don’t fail at cybersecurity because of missing tools; they stall because they miss the maturity inflection point where governance must replace tactics. In this episode, we break down what actually defines cybersecurity maturity, contrasting technical frameworks with governance-driven models that reflect real organizational behavior. Using the GTIA Cybersecurity Trustmark’s four-level mat...

E&O, Cyber Insurance, and the Illusion of Risk Transfer for MSPs 07.04.2026

In this episode, we unpack one of the most misunderstood topics in the MSP industry: insurance. From Errors & Omissions to cyber insurance, we break down what these policies actually cover, and more importantly, what they don’t. The conversation challenges the assumption that buying insurance equals risk transfer and explores how liability really plays out across MSPs, clients, and third‑party...

Why Communication, Not Cybersecurity, Is the Real ITSP Problem 31.03.2026

Clear communication is one of the most overlooked and most costly challenges in IT service providers. In this episode, Chris sits down with Amy Reczek , communication and presence expert, to unpack why misalignment happens between leadership, teams, and clients, and how understanding the “why” behind communication changes everything. From ineffective meetings and virtual body language to intent ve...

Installing or Configuring Is Just Not Enough 24.03.2026

The critical importance of going beyond just getting technology to work, addressing the underlying security, scalability, and proper implementation, rather than just fixing symptoms. Eric Hansen, of Inland Productivity Solutions, emphasized the importance of starting troubleshooting at the very beginning, even when engineers claim they've already done everything. He discussed their hiring process,...

GTIA On Location Interview: A Phishing Expedition and Cybersecurity Maturity 18.03.2026

A real-world phishing incident. Real financial impact. Real lessons for MSPs. In this episode, we unpack a phishing attack that led to unauthorized access to an Azure subscription and significant financial loss for an MSP client. The conversation goes beyond the incident itself to examine where policy gaps, weak controls, and unclear ownership increased liability, and what changed when the MSP com...

Suspended, Hacked, or Outbid - Cybersecurity and Marketing, Can They Co-exist? 10.03.2026

Google Ads can disappear overnight, and for millions of businesses, it has. In this episode, John Horn of Stub Group breaks down the growing cybersecurity risks behind Google Ads account suspensions and why 39 million accounts were shut down in 2024 . We explore Google’s automated, all‑or‑nothing enforcement model, how website vulnerabilities, phishing attacks, and account takeovers trigger suspen...

Operational Maturity Meets Cybersecurity 03.03.2026

Cybersecurity maturity isn’t earned in audits, it’s earned in the operational moments where governance either shows up… or it doesn’t. Today’s conversation with Mike Stewart of Anchor Networks goes deep on MSP maturity. How leadership tone, culture, and repeatable decision systems turn policies into actual behavior. We cover why security awareness must be frequent (not annual), why “the why” behin...

AI Governance and the MSP Maturity Model 24.02.2026

Managed Service Providers are being pushed to “get compliant fast.” In my discussion with Bruno Leqoc, we reframe the challenge. Compliance isn’t security, and lasting compliance depends on security maturity first. Highlighting how AI policy can extend existing governance frameworks, why Microsoft Secure Score is a practical readiness indicator, and why foundational controls (MFA, patching, device...

Governing AI in a High Risk World 17.02.2026

Exploring the fast-moving intersection of AI governance, ethics, and cybersecurity , examining how organizations are struggling to adopt AI responsibly while keeping pace with innovation. The conversation highlights a growing disconnect between enthusiasm for AI tools and the absence of clearly defined use cases, governance models, and security guardrails. As AI capabilities rapidly expand, Dr. Ad...

Do Phishing Simulations Really Work? 10.02.2026

Phishing simulations are one of the most debated tools in cybersecurity awareness, but do they actually work? In today’s episode, we’re joined by David Shipley , former soldier turned cybersecurity researcher and founder of Beauceron Security , to unpack what the data really says about phishing simulations, human behavior, and why zero clicks has never been, and will never be, the goal.

Physical Safeguards and Process and Procedures 03.02.2026

Have you ever been stuck in an elevator? What happens when you push the call button? Physical safeguards managed by a 3rd party are often ignored or marked as N/A. What happens when processes and procedures don't get updated after a change? Listen in as Charles Love of ShowTech Solutions shares his experience of being trapped in an elevator and what we should all take away in lessons learned.

Data Privacy and Security Trends in 2026 27.01.2026

A much-needed discussion on the fast‑shifting world of data privacy in 2026 and what it means for MSPs on the front lines. From the tangled web of U.S. state privacy laws to the rising risks hidden in modern data flows (yes, even your car!), guest Andy Sambandam, Clarip CEO & Founder, lays out why every security breach is now a privacy breach, and why security and privacy are officially a fore...

Exploring AI Usage, Misconceptions, and of course Security Concerns 20.01.2026

In this episode, we cut through the AI hype with Alane Boyd to unpack what MSPs really need to know about today’s AI landscape. We cut right to the chase on data‑privacy pitfalls and free-tool misconceptions, and on the rise of AI agents that go far beyond simple automation. We explore practical, business-ready use cases, how to build safe and effective AI policies, and why better prompting (and b...

Listen to the MSP 1337 | Cybersecurity Education & Security Guidance podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.