
Sign up to save your podcasts
Or


Why Threat Actors might love your security stack... Surprisingly, the most dangerous thing in your organization might be the security tools you're paying for but never configured. Chris Johnson and Zach Kromkowski revealed at CornCon26 that one organization purchased a tool and left it completely unimplemented for two years, creating a false sense of security while attackers exploited the gaps.
The core insight here is uncomfortable but important: most cybersecurity breaches stem from foundational failures that have existed for decades, not from sophisticated new attacks. Organizations keep chasing shiny new tools instead of mastering what they already own, spending money without solving actual problems. (It turns out "shiny object syndrome" is a real and costly habit in security teams.)
Buying tools without clear objectives doesn't just waste money; it actively expands your attack surface. Chris and Zach point out that even integrating platforms introduces new risks, especially when teams disable security rules to keep things running smoothly.
What does good governance actually look like under real pressure?
From realistic incident response tabletop exercises to weekly documentation reviews with a team of 15, Zach and Chris lay out a practical roadmap to move from reactive breach response to genuine operational maturity.
AI adoption is moving fast, but governance is struggling to keep up. In this episode, Chris sits down with Ignacio Lopez, founder of Work-Smart.AI and Fractional Head of AI, to discuss how MSPs can help clients move from AI experimentation to secure, scalable adoption.
Drawing on his experience in auditing, risk management, and enterprise technology, Ignacio explains why governance must come before tools. They explore AI policies, connector risks, access controls, model governance, data foundations, token economics, and the growing threat of shadow AI.
Ignacio shares a practical roadmap for MSPs to evolve from tool resellers to trusted AI advisors by leading assessments, enforcing guardrails, managing deployments, controlling costs, and building governance programs that withstand security, compliance, and business scrutiny.
If you're looking to help clients adopt AI safely and effectively, this episode offers a clear blueprint for turning AI from a shiny tool into a business capability.
Special Host: Adam Anderson from Threat Captain.
What does success look like in an industry where technology changes faster than anyone can predict? In this episode of MSP1337, Chris Johnson (GTIA) and Charles Love (Showtech Solutions) join Adam Anderson from Threat Captain for a wide-ranging conversation on cybersecurity maturity, business growth, client communication, and preparing for an AI-driven future.
The discussion challenges the idea that MSPs need to be perfect before making progress. Instead, the panel explores why cybersecurity maturity is a journey, how trust is built through clear communication rather than technical jargon, and why the most successful IT professionals learn to speak both technology and business.
Along the way, they dive into behavioral economics, the psychology of decision-making, the realities of technology sales, and the traits that separate great MSP professionals from great technicians. The conversation concludes with practical career advice for students, recent graduates, and anyone navigating a rapidly changing job market shaped by AI and automation.
Whether you're an MSP owner, cybersecurity leader, technician, or someone planning the next stage of your career, this episode offers valuable insights on balancing ambition with adaptability, embracing continuous improvement, and building a future that isn't dependent on today's technology trends.
Key Takeaway: Cybersecurity, business, and careers all follow the same principle: maturity matters more than perfection.
In this episode of MSP 1337, Chris sits down with Dr. Stephen Wright of Macadamia Solutions, a rare expert whose career spans technology, law, and business. Together they explore why governance has become the defining challenge of the AI era and why many organizations remain dangerously unprepared.
The conversation examines how regulatory requirements, cybersecurity obligations, and emerging AI risks are reshaping boardroom accountability. Dr. Wright breaks down the growing threat of deepfakes, data poisoning, and data suppression, explaining how attackers increasingly target data integrity and the people who make decisions based on it, rather than traditional IT systems alone. The discussion also explores the unintended consequences of technology legislation, regulatory capture, supply chain risk, remote work security, and the persistent governance challenges that prevent organizations from achieving true cybersecurity maturity.
For MSPs, IT leaders, and business executives, this episode provides a practical look at the intersection of governance, risk, security, and compliance, and why effective governance may be the single most important capability organizations need to navigate the future of AI.
Every vendor has an AI roadmap. Every client has employees experimenting with AI. And increasingly, MSPs are building their own AI solutions. The challenge is that few organizations fully understand the risks that accompany this rapid adoption.
In this episode of MSP 1337, Chris Johnson and Jim Harryman discuss what responsible AI deployment actually looks like. They explore AI governance, vendor accountability, security testing, client readiness, and the dangers of allowing AI unrestricted access to sensitive information. Rather than treating AI as a shortcut, they argue for a disciplined approach that prioritizes transparency, validation, and human oversight.
For MSPs trying to separate opportunity from hype, this conversation offers practical insights on asking better questions, managing emerging risks, and building a foundation for sustainable AI adoption.
"The biggest AI risk isn't the technology. It's deploying it before governance catches up."
Many MSPs and businesses believe they're prepared for an outage because they have backups, redundant internet connections, or cloud-based applications. In reality, most recovery strategies fall apart when tested in real-world scenarios. In this episode of MSP 1337, Chris Johnson sits down with Charles Love of Showtech Solutions to explore the dangerous gap between perceived resilience and actual preparedness. They discuss why incident response plans must come before tabletop exercises, how internet redundancy often fails under scrutiny, and why MSPs should treat their own operational dependencies with the same rigor they apply to clients. From protecting the "core four" business applications to safeguarding documentation, passwords, and recovery keys, this conversation delivers practical guidance for building recovery plans that work when systems fail and chaos begins.
Most MSPs don't have a compliance problem. They have a starting problem.
Michael Zbarsky of Blacksmith InfoSec joins MSP1337 to challenge some of the biggest misconceptions surrounding compliance, security frameworks, and cybersecurity maturity. From the GTIA Cybersecurity Trustmark and CMMC to evidence automation and third-party assessments, the discussion focuses on what actually moves organizations forward and what keeps them stuck.
Michael shares why "good enough" today is often better than "perfect" next year, why automation cannot replace human judgment, and why MSPs are uniquely positioned to lead both their own organizations and their clients toward stronger security outcomes.
If you've ever felt overwhelmed by compliance requirements, unsure where to begin, or skeptical that another framework will help, this episode offers a practical roadmap for turning intention into action.
The MSP market is changing fast. Clients can buy technology anywhere, automate routine tasks, and access powerful AI tools with just a few clicks. The real question is no longer what technology you sell. It's whether you can help clients manage the business risks that technology creates.
This week, Chris Johnson welcomes back Auggie Staab from TD SYNNEX to discuss the next evolution of managed services. Together they explore how AI is disrupting traditional service delivery, creating new compliance and cybersecurity challenges, and forcing MSPs to rethink their value proposition.
From shadow AI and data privacy concerns to automation-driven growth opportunities, this discussion examines why governance, strategy, and risk management may become the most valuable services MSPs provide.
In this episode, Chris sits down with MJ Patent to explore the foundational principles that help Managed Service Providers grow, mature, and thrive in today's increasingly complex IT and cybersecurity landscape. Drawing from her extensive experience working with service providers of all sizes, MJ explains why many MSPs struggle to scale evenly across their business and why success starts with understanding exactly who you serve, the problems you solve, and the value you create. Together, they discuss the dangers of chasing every new technology trend, the importance of specialization, and how strategic partnerships can help MSPs deliver more without overextending their teams. The conversation also examines the growing role of fractional leadership services, including vCIOs, vCISOs, and fractional CMOs, and how MSPs can evolve from technology providers into trusted business advisors. Chris and MJ share practical insights on navigating cybersecurity complexity, managing risk, demonstrating ROI, and shifting customer conversations from service-level agreements to measurable business outcomes. Whether you're looking to refine your service strategy, strengthen customer relationships, or build a more scalable MSP, this episode offers actionable guidance for creating sustainable growth through focus, trust, and strategic leadership. Key Takeaways:
Recommended Reading: Brave Thinking by Mary Morrissey.Perfect for: MSP owners, IT service leaders, cybersecurity professionals, channel partners, and anyone looking to build a stronger, more strategic technology services business.
Human risk has become one of the most challenging and misunderstood aspects of cybersecurity. In this episode of MSP 1337, Chris Johnson sits down with Nihil Morjaria from usecure to explore why traditional security awareness training is no longer enough and what it takes to build a truly proactive human risk management strategy.
The conversation examines how MSPs and ITSPs are evolving beyond technology management into governance, risk, and compliance, and why understanding user behavior is now just as important as managing firewalls and endpoints. Chris and Nihil discuss the limitations of one-time phishing exercises, the rise of shadow IT and AI-driven data exposure, and the growing need to combine security awareness, breach intelligence, password hygiene, and user behavior into a single view of risk.
Listeners will learn how leading providers are using human risk intelligence to prioritize remediation efforts, reduce alert fatigue, empower end users, and deliver measurable security outcomes for clients. Whether you're struggling with phishing failures, unsanctioned applications, or simply trying to make security awareness more effective, this episode offers practical insights for turning your users from a potential liability into a powerful line of defense.
From the publisher's feed

111,852 Listeners

56,432 Listeners