A lot of MSPs say they “do security.”
That does not mean they do enough of it.
In this episode of Get NIST-y, Jared and Mike sit down with Josh Hohbein of Centrex IT to talk about where MSP security is getting better, where it still falls apart in the real world, and why community reputation matters more than most vendors want to admit.
Takeaways:
- A lot of MSPs offer security, but the depth of capability is all over the place
- Backups are not enough if they are not isolated, tested, and actually recoverable
- Identity is still one of the biggest weak spots, especially in Microsoft 365
- Mature MSPs do not just buy tools, they align security to a framework and improve over time
We answer:
- What are MSPs getting right about security right now, and where are they still falling short?
- Where does real-world MSP execution clash with “perfect” security guidance?
- Why does a framework like GTIA Trustmark matter for MSPs?
- How do MSP communities shape buying decisions, tooling, and security standards?
- How should MSPs think more strategically about tool selection instead of chasing shiny objects?
Submit your own questions at https://blacksmithinfosec.com/nisty/