MSP 1337 | Cybersecurity Education & Security Guidance

Compliance is the floor, not the ceiling


Listen Later

In this episode of MSP 1337, Chris Johnson sits down with Jim Harryman to break down why passing audits doesn’t equal real security, and why MSPs get into trouble when frameworks turn into checklists.

Drawing from firsthand experience with SOC 2 Type 2, CIS Controls, and the GTIA Cybersecurity Trustmark, Jim shares practical lessons on evidence quality, shared responsibility, inherited security, and the dangers of assumptions. They unpack why SOC 2 excels at governance but leaves technical gaps, why CIS is the most effective starting point for MSPs and their clients, and how Trustmark helps operationalize governance for MSP-specific realities.

The discussion tackles common traps—template-driven compliance, perfection paralysis, and tool-chasing—and replaces them with a disciplined, momentum-driven approach focused on outcomes, accountability, and continuous validation. From third-party vendor management to proof over screenshots, this episode is a reality check for MSPs trying to balance assurance, security, and business growth.

If you’re relying on audits for peace of mind, or struggling to turn compliance into real-world resilience, this episode will reset how you think about frameworks, governance, and what “good” actually looks like.

Learn more about Trustmark: gtia.org/Trustmark

...more
View all episodesView all episodes
Download on the App Store

MSP 1337 | Cybersecurity Education & Security GuidanceBy Chris Johnson | Cybersecurity Education & Security Guidance

  • 5
  • 5
  • 5
  • 5
  • 5

5

4 ratings


More shows like MSP 1337 | Cybersecurity Education & Security Guidance

View all
The Daily by The New York Times

The Daily

113,121 Listeners

Up First from NPR by NPR

Up First from NPR

56,944 Listeners