Andrew Morgan
The CyberCall Podcast
The Voice of Cybersecurity for MSPs & MSSPs! The CyberCall is the weekly podcast where cybersecurity meets business reality. Hosted by Andrew Morgan, Founder of Right of Boom, this is the go-to show for Managed Service Providers (MSPs), virtual CISOs (vCISOs), and IT leaders navigating the complex world of cyber risk, compliance, and AI. Each episode features raw, practical conversations with the sharpest minds in cybersecurity—from operators in the trenches to CISOs, researchers, policymakers, and toolmakers shaping the future. If you care about protecting your clients, growing your practice,...
Author
Andrew Morgan
Category
Podcast website
Latest episode
Jul 6, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Faster, Smarter, Scalable: The Future of M365 Management 25.11.2025 59:10
Today’s conversation is all about what comes next for Microsoft 365 — because after Ignite, it’s clear that we’re entering a brand-new era. AI agents, identity-first security, native Sysmon, tenant baselines — Microsoft is rebuilding the entire stack around speed, intelligence, and scale. And when you talk about managing M365 at scale, there’s one person MSPs look to: Kelvin Tegelaar , founder of...
The Ulimate Partner – Building an MSP Growth Engine with Microsoft 18.11.2025 1:02:14
Today we’re talking about what it really takes to partner with a giant . Every MSP wants to grow alongside hyperscalers like Microsoft — but few truly know how to align, scale, and turn partnership into profit. Our guest today has lived that journey from the inside out. Vince Menzione , Founder of The Ultimate Partner and former Microsoft channel leader, has helped thousands of partners build thri...
From Bouncer to MSP Baller – How to Make Microsoft Notice Your MSP 11.11.2025 1:02:19
Today’s guest has one of the most unconventional origin stories in the MSP world. Nabil Aitoumeziane started his career not behind a keyboard—but at the door of a nightclub. While working nights as a bouncer, he began doing something few would dare: asking customers for business introductions and meetings. Fast-forward a few years, and he’s now the president of FSI , an 85-person managed service p...
The State of Pen Testing in 2025 & the Role of AI & Autonomous Solutions (with John Strand) 03.11.2025 1:01:28
Today we’re talking about one of the biggest shifts in offensive security that MSPs, CISOs, and defenders cannot ignore. For years, pen testing was about human creativity — sneaking in where we “shouldn’t” be, showing you how you’d really get burned in an incident. But in 2025, that world is colliding with AI and automated attack platforms that claim they can do it faster, cheaper, and nonstop. So...
ZTNA & SASE, the Next Era for MSPs 27.10.2025 1:03:33
Today we’re tackling one of the biggest shifts in modern network security. VPNs are breaking under the weight of hybrid work, SaaS sprawl, and constant attack — and MSPs are being forced to rethink how they secure access itself. Enter Zero Trust Network Access (ZTNA) and Secure Access Service Edge (SASE) — not just buzzwords, but the blueprint for the next decade of MSP security architecture. Join...
The Human Lag: Why AI Outpaces Operational Readiness 14.10.2025 1:01:11
Artificial intelligence is evolving faster than most organizations can operationally absorb. We’ve automated analysis, accelerated response, and even delegated decisions to machines — but our people, processes, and governance are still running at human speed. This week on The CyberCall , I’m joined by Sounil Yu , creator of the Cyber Defense Matrix and one of the most forward-thinking minds in cyb...
Disinformation Security – Deepfakes & Social Deception 06.10.2025 57:50
This week on The CyberCall , we’re turning up the heat on deepfakes & disinformation —why they’re no longer sci-fi, and how they’re already targeting MSPs and the Defense Industrial Base . I’m joined by Sandy Kronenberg (Netarx) and Scott Edwards (Summit 7) to unpack: • Real attack chains: voice clones, lip-sync, synthetic exec approvals • The “liar’s dividend” & reputational warfare • Wha...
NIST Small Business Primer and Quick Start Guides 30.09.2025 1:01:07
Today we’re talking about something that may sound government-heavy but is actually critical for MSPs and the SMBs they serve: the new NIST Small Business Primer for SP 800-171 Rev. 3 . At its core, this guide is about protecting Controlled Unclassified Information , or CUI. And while that might sound like it only applies to defense contractors, the reality is that CUI requirements increasingly to...
Microsegmentation Demystified: What Every MSP & Client Should Know 23.09.2025 1:03:02
Today we’re tackling microsegmentation—a solution that could change the game against ransomware. Ransomware thrives on lateral movement: one compromised device turns into an entire network takedown. Microsegmentation stops that by creating secure ‘neighborhoods’ inside the network, containing the damage before it spreads. The big questions: can MSPs realistically deploy this at scale, without addi...
AI’s Evolving Role in Attacks & Incident Reponse 16.09.2025 1:01:04
Over the past couple of days, I was digging into the latest Anthropic Threat Report and one section really hit me. They wrote: ‘ We’ve developed sophisticated safety and security measures to prevent misuse of our AI models. While generally effective, cybercriminals keep finding ways around them .’ And then they shared some eye-opening case studies—threat actors aren’t just asking AI for advice, th...
Encryption to Extortion, the Evolution of Cloud Based Attacks 08.09.2025 1:02:02
In this session we talk about Salesloft Drift and the implications of OAuth based attacks. Companies use Drift with Salesloft to automate lead capture + sales workflows into Salesforce.com. Enter Nation State threat actor UNC6395, who was able to steal the tokens and gain a backdoor into Salesforce via these OAuth tokens. We then dive into the Evolution of Cloud Based Attacks, where threat actors...
When Cyber Hits the Fan: How Your Contracts Protect or Expose You 25.08.2025 59:42
Last week, we dug into the surge of SonicWall VPN compromises. At first, there was speculation about a possible new zero day — but as the dust settled, we learned it was far more familiar: unpatched systems, misconfigurations, stale service accounts. One of the biggest takeaways came from breach attorney Spencer Pollack, who cautioned MSPs: don’t speculate . When cyber hits the fan, the truth come...
Akira Ransomware’s Relentless Attack on SonicWall SSLVPNs 18.08.2025 1:02:45
In this session of The CyberCall, we’re cutting straight into one of the most relentless threats MSPs and their clients are facing right now—targeted ransomware attacks exploiting SonicWall SSLVPNs, with signs the attackers are already shifting to Fortinet VPNs. This isn’t theory. It’s happening in the wild, and the fallout is real. Huntress has been on the frontlines analyzing the tactics, SonicW...
Selling IT & Cybersecurity Services to the CFO (the one who writes the checks) 11.08.2025 1:00:43
When MSPs are selling IT and security services, the real decision often comes from the person who owns the budget and measures the risk — the CFO. In this session of The CyberCall, we’re getting inside that mindset. Jason Duncan , CFO of InfoSystems, has over two decades of experience working as a Corporate Controller & CFO, making financial, IT & security decisions. This week he's he...
From Tokens to Trust: Microsoft’s Biggest Security Shift Yet 04.08.2025 1:01:52
This week, we’re diving into three huge shifts happening in the Microsoft ecosystem that every MSP should have on their radar: · Token Protection is now available for Entra ID P1 licenses — and it’s a game changer for securing identity tokens and stopping session hijacking. · GDAP — the move from legacy DAP to Granular Delegated Admin Privileges — is creating both confusion and opportuni...
From Milestone to Mandate: What the Latest CMMC Update Means for Your MSP & Your Clients 28.07.2025 1:00:28
Big news for the defense and MSP community: The 48 CFR CMMC final rule has officially reached OMB review. This is the second-to-last milestone before publication in the Federal Register — and we’re expecting to see the final rule land by October with no 60-day delay . Translation? The phased rollout begins Q4 2025 . If you work with defense contractors, or your clients do, the countdown just got...
What Makes a Good vCISO & Delivering at Scale 21.07.2025 1:01:17
Last week, we tackled a big one: 'Risk, Revenue, Responsibility: The Real Job of the vCISO — and it sparked an incredible conversation around how vCISOs are no longer just about frameworks and firewalls, but about protecting business outcomes , navigating executive risk , and helping clients make strategic decisions . This week, we’re taking it a step further. Because if you're serious a...
Risk, Revenue, and Responsibility: The vCISO’s Real Job 14.07.2025 1:01:30
In this episode of The CyberCall, we're cutting through the noise and rethinking the true purpose of the vCISO role. It’s not just about frameworks, policies, and tech stacks, it’s about tying risk to business outcomes (risk to revenue). The vCISO’s true value goes way beyond compliance checklists and technical jargon; it’s about being a business partner/enabler, protecting critical revenue s...
The Ingram Micro Cyber Incident & Building Security Maturity - F12’s ISO 27001Journey 08.07.2025 1:03:30
Supply chain attacks doubled according to the 2025 Verizon DBIR. This week the channel awakens to Ingram Micro being attacked by the SafePay Ransomware group. Incident Response (IR) expert, Chris Loehr , EVP of Solis joins The CyberCall, to share perspective on the GlobalProtect VPN compromise. That’s why today on today's CyberCall, we’re talking about what MSPs can do right now to get seriou...
The Intersection of AI, RPA & Cyber - What Your MSP Needs to Know 03.07.2025 59:50
In this must-listen episode of The CyberCall, hosts Andrew Morgan, Phyllis Lee & Gary Pica are joined by Aharon Chernin, Founder & CEO of Rewst — to explore how Artificial Intelligence (AI), Robotic Process Automation (RPA), and Cybersecurity are colliding in today’s MSP landscape. Tune in to learn what your MSP needs to know now to stay ahead! Connect with Right of Boom: Website & Co...
CIS Controls - Version 8.1 Update Overview 09.08.2024 52:09
With the release of NIST Cybersecurity Framework 2.0, CIS felt strongly that an update to The Controls was necessary to crossmap to CSF 2.0. Specifically the strongest driver, was the release of the Govern function. Co-hosts : Phyllis Lee : https://www.linkedin.com/in/phyllis-lee-21b58a1a4/ Brian Blakely : https://www.linkedin.com/in/bblakley/ Eric Woodard : https://www.linkedin.com/in/eric-woodar...
CIS Control 18 - Penetration Testing - Sponsored by Hacket Cyber 26.07.2023 1:06:26
Penetration testing is something that more companies and organizations should be considering a necessary expense. Pen Testing is an important aspect of discovery and identifying potential critical vulnerabilities within your organizations external network, internal network, applications, or systems. They provide a valuable insight on how your digital and human assets perform. In this episode we r...
CIS Control 17 - Incident Response Management - Sponsored by Exigence 02.06.2023 53:38
The biggest takeaway from CIS Control 17 is that planning and communication are critical when responding to an incident . The longer an intruder has access to your network, the more time they’ve had to embed themselves into your systems. Communicating with everyone involved can help limit the duration between attack and clean-up. Establish a program to develop and maintain an incident response cap...
CIS Control 16 - Application Software Security - Sponsored by Manicode 14.03.2023 1:06:54
CIS Control 16 - Application Software Security The way in which we interact with applications has changed dramatically over years. Organizations use applications in day-to-day operations to manage their most sensitive data and control access to system resources. Instead of traversing a labyrinth of networks and systems, attackers today see an opening to turn an organizations applications against i...
CIS Control 15 - Service Provider Management 22.01.2023 1:02:48
LastPass and the recent Rackspace Exchange incident are two prime examples of "why" this Control is Critical!! Develop a process to evaluate service providers who hold sensitive data, or are responsible for critical IT platforms or processes, to ensure these providers are protecting those platforms and data appropriately. Identify your business needs and create a set of standards that ca...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.