Andrew Morgan

The CyberCall Podcast

The Voice of Cybersecurity for MSPs & MSSPs! The CyberCall is the weekly podcast where cybersecurity meets business reality. Hosted by Andrew Morgan, Founder of Right of Boom, this is the go-to show for Managed Service Providers (MSPs), virtual CISOs (vCISOs), and IT leaders navigating the complex world of cyber risk, compliance, and AI. Each episode features raw, practical conversations with the sharpest minds in cybersecurity—from operators in the trenches to CISOs, researchers, policymakers, and toolmakers shaping the future. If you care about protecting your clients, growing your practice,...

Author

Andrew Morgan

Category

Technology

Podcast website

podcast.rightofboom.com

Latest episode

Jul 6, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Inside the Credential Spray Hitting Microsoft 365 06.07.2026

This week we're digging into a Huntress report that came out on June 30th, updated just a couple days ago on July 2nd a large-scale password spray campaign that hit Microsoft 365 environments through Azure CLI. Between June 12th and June 26th, Huntress tracked more than 81 million login attempts, leading to at least 78 compromised accounts across 64 organizations. What makes this one worth a...

The Vulnpocalypse is here and your MSP can survive it 30.06.2026

Today we have one of the most important voices in cybersecurity joining us. Chris Hughes started his career defending the nation in the United States Air Force. He's spent over two decades in the trenches from the Department of Defense to the federal government to the commercial world as a CISO, security architect, and engineer.  Today he's VP of Security Strategy at Zenity, where his fo...

The Vulnerability Crisis No One is Funding 22.06.2026

Last week, I asked Philippe Langlois, principal author of the 2026 Verizon DBIR, a simple question: if an MSP could only focus on one thing this year, what should it be? His answer, without hesitation: "Vulnerability management." That tracks, as this is the first year in DBIR history that vulnerability exploitation has overtaken stolen credentials as the top breach entry point, jumping f...

The 2026 Verizon DBIR Unpacked with Author Philippe Langlois 15.06.2026

Today's session is one you genuinely don't want to miss. Every year, Verizon publishes what is arguably the most respected, data-backed snapshot of the global threat landscape, the Data Breach Investigations Report.  The 2026 edition is the 19th annual installment, and it just set a new record: over 22,000 confirmed breaches analyzed across 145 countries. The numbers don't just conf...

Identity, the Browser and the New Perimeter 01.06.2026

We spent a decade building security around the network. Then five years around the endpoint. The whole time, sitting right in front of every user, every day the browser. Unmanaged. Unexamined. Trusted by default. The 2026 Verizon DBIR makes it hard to look away anymore. Infostealers, session token theft, OAuth attacks almost every major attack pattern this year runs through the browser at some poi...

CMMC FAQ May Pubulication Unpacked with Jacob Horne 19.05.2026

This week we're doing something a little different. Instead of talking about CMMC in the abstract, we're putting an actual document on the table the CMMC Program FAQ, freshly updated to Revision 2.3.  It's the kind of document most contractors skim and most MSPs never read closely.  To help us read between the lines, we have one of the sharpest interpreters of CMMC in the industry....

From C3PAO to Cyber AB: Scott Singer on What's Coming Next 11.05.2026

CMMC is no longer theoretical the rule is final, the clock is running, and every MSP in the DIB is about to find out whether the work they've done actually holds up under an assessment. To cut through the noise, we have someone who sees this from angles almost nobody else does. Scott Singer is chair of the Cyber AB’s C3PAO Advisory Council, former CEO of CyberNINES and current President of Co...

From Server Room to Board Room – Selling AI to the C-Suite 05.05.2026

For the past two weeks, we've been building what a Mythos-ready security program actually looks like. None of that matters if we can't walk into a business or boardroom and get the C-suite to buy in. Today is leadership call. How do MSPs earn the right to be in the boardroom on AI and stop being the vendor who fixes things and start being the partner who helps the business win. That&apos...

Mythos Ready Security Program Debrief 27.04.2026

Two weeks ago, Anthropic announced Claude Mythos. A model that autonomously found thousands of zero-days, generated working exploits, and broke out of its own containment sandbox. The moment the industry has been warning about for years just arrived. Within 48 hours, the Cloud Security Alliance pulled together more than 80 CISOs and security leaders Heather Adkins, Rob Joyce, Bruce Schneier, Jen E...

The Calm Before the Premium 20.04.2026

The cyber insurance market right now is the softest it's been since 2021. Premiums are flat. Capacity is abundant. Carriers are competing aggressively for MSP business, and your SMB clients are getting pricing their predecessors would have dreamed about three years ago. Here's the problem. Loss frequency is up. Ransomware attack frequency rose 45% year-over-year. A single Cloudflare outa...

The Impact of Mythos – The Model to Dangerous to Release 14.04.2026

This week we need to talk about something every MSP, every security pro, and every business owner needs to understand because it changes the threat equation for everyone, not just the enterprise players it was built for. It was only fitting to bring in John Strand , Founder of Black Hills Information Security to discuss. Anthropic just announced a model called Mythos Preview that can autonomously...

Unpacking Axios – 400 million downloads. One Compromised Password 07.04.2026

On March 31st, Axios was compromised. Four hundred million monthly downloads. The HTTP library sitting inside almost every web application your clients use, depend on, or have had custom-built for them.   The attacker did not touch a single line of code. They hijacked the maintainer's credentials, slipped in one hidden dependency, and let your clients' own systems install the malware aut...

Is AI “Poisoning” Your MSPs Marketing? 31.03.2026

Last week, a supply chain attack hit LiteLLM the open-source AI gateway that sits inside 36% of cloud environment and for about six hours, anyone who ran a routine install command handed over their SSH keys, cloud credentials, and API tokens to a threat group that had been quietly chaining compromises across the open-source ecosystem for months. The attack didn't announce itself. It passed ev...

AI Installed the Backdoor. Now What? 23.03.2026

Imagine this. A developer opens their laptop. Gets a routine VS Code update notification. Clicks install. Goes back to work. What they don't know is that an AI triage bot the kind built to make their team more efficient just read a manipulated GitHub Issue title, followed hidden instructions, stole three publishing tokens, and silently installed a rogue AI agent on their machine. One that sur...

Code Wars: How Nation-States Really Launch Cyberattacks 17.03.2026

For years, many of us have thought about cyberattacks as criminals chasing money. But when you zoom out, you realize something much bigger is happening. Cyber has become one of the most powerful geopolitical weapons of the 21st century. Nations use it to spy, influence elections, sabotage infrastructure, and increasingly—disrupt supply chains that businesses rely on every day. Purchase Allie'...

Iran Knocked Out AWS. Your Clients' Business Continuity Plan Wasn't Built for This 09.03.2026

On February 28th, the United States and Israel launched coordinated strikes on Iran. Most people know that part. What most people don't know is that Iran responded by sending drones directly into Amazon Web Services data centers in the UAE. Two facilities struck. A third in Bahrain damaged. For the first time in history, commercial cloud infrastructure became a military target — and most of y...

From Tech Talk to Table Talk 03.03.2026

There’s a conversation happening in boardrooms right now that most security professionals aren’t equipped to lead. Not because they don’t understand the technology. They do. But translating risk into business decisions… defending budgets… guiding executives through uncertainty… that’s a different discipline entirely. And that gap? That’s where security programs stall. That’s where funding gets del...

Incident Response Simplified 24.02.2026

There's a concept in military and emergency response called the fog of war — that moment when everything is happening at once, information is incomplete, and the people who trained for this have to decide right now, with what they have. Cybersecurity incident response is that moment. Every time. And the dirty secret is that most organizations don't have a plan that actually holds up when...

The Hard Truths About M365 Security 17.02.2026

Last week at Right of Boom, something interesting happened. In a conference full of great sessions, one stood out — not because of hype, but because of urgency. Kelvin Tegelaar’s CIPP certification session on securing Microsoft 365 was standing room only. MSPs weren’t there for theory. They were there because M365 has quietly become the single largest attack surface in most of their client environ...

Beyond Zero-Days: What Real Threat Hunting Is Actually Finding 27.01.2026

Every week there’s a new zero-day, a new CVE, a new headline. But what rarely gets talked about is what real threat hunting is uncovering when you actually go looking. Today’s conversation is about what’s happening beyond zero-days — the automated scanning, the long-tail exploitation, the shared infrastructure, and the attack behavior that lives in the background noise of the internet. We’re joine...

AI & Third Party Risk 21.01.2026

Welcome back to The CyberCall. Today we’re tackling one of the fastest-growing risks MSPs face: third-party exposure in the age of AI. Our guest is Greg Rasner — author of Cybersecurity and Third-Party Risk and a leading voice on how AI is reshaping vendor security. Greg has spent years helping organizations understand how a single weak vendor can create massive operational, financial, and reputat...

John Strand & the BHIS Team at RoB26 14.01.2026

Today’s conversation is all about how MSPs actually win in the modern threat landscape — before, during, and after an attack. We’re joined by three practitioners who will each be leading hands-on workshops at Right of Boom 2026. John Strand will take us inside Cloud Forever Days and intro to pen testing, showing how attackers really move through cloud environments. Joff Thyer will break down how M...

The Year of Identity Based Attacks 08.01.2026

In 2025, attackers aren’t breaking in through zero-days — they’re logging in. Identity has become the primary attack surface, and once access is gained, everything else happens fast. Today, we’re joined by Chip Buck , CTO of SaaS Alerts — someone who lives at the front lines of identity-based attacks across SaaS platforms every single day. Chip sees how session theft, OAuth abuse, and legitimate-l...

ISO & CMMC – Lessons Learned During Audits 29.12.2025

Welcome back to The CyberCall. Our guest, Joy Beland from Summit7, helps lead security and compliance at the largest MSP serving the Defense Industrial Base. Joy joins us to share what it actually took to prepare as a service provider, what broke, what changed, and what lessons MSPs can learn if they expect CMMC — or ISO 27001 — to become part of their future. If you’re an MSP trying to understand...

Your 2026 Business Plan – Impacts of AI, Cyber & Automation on MSPs. 09.12.2025

Most MSPs don’t fail because of ransomware. They fail because they drift. They chase revenue without direction. They stack tools without a strategy.  And they wake up one year later asking the same dangerous question:  “Why didn’t last year change anything?” Today isn’t about theory. It’s about execution. Our guest Gary Pica , doesn’t just teach business planning— he’s been stress-testing it with...

Listen to the The CyberCall Podcast podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.