Business of Tech: Daily 10-Minute IT Services Insights

MSP Regulations Shift: CMMC 2.0, FedRAMP Overhaul, UK Cyber Bill & AI Security Concerns


Listen Later

Michael Duffy, President Donald Trump's nominee for Undersecretary of Defense for Acquisition and Sustainment, has committed to reviewing the Pentagon's Cybersecurity Maturity Model Certification (CMMC) 2.0 if confirmed. This revamped program, effective since December, mandates that defense contractors handling controlled, unclassified information comply with specific cybersecurity standards to qualify for Department of Defense contracts. Concerns have been raised about the burden these regulations may impose on smaller firms, with a report indicating that over 50% of respondents felt unprepared for the program's requirements. Duffy aims to balance security needs with regulatory burdens, recognizing the vulnerability of small and medium-sized businesses in the face of cyber threats.

In addition to the CMMC developments, the General Services Administration (GSA) is set to unveil significant changes to the Federal Risk Authorization Management Program (FedRAMP). The new plan for 2025 focuses on establishing standards and policies rather than approving cloud authorization packages, which previously extended the process for up to 11 months. The GSA intends to automate at least 80% of current requirements, allowing cloud service providers to demonstrate compliance more efficiently, while reducing reliance on external support services.

Across the Atlantic, the UK government has announced a comprehensive cybersecurity and resilience bill aimed at strengthening defenses against cyber threats. This legislation will bring more firms under regulatory oversight, specifically targeting managed service providers (MSPs) that provide core IT services and have extensive access to client systems. The proposed regulations will enhance incident reporting requirements and empower the Information Commissioner's Office to proactively identify and mitigate cyber risks, setting higher expectations for cybersecurity practices among MSPs.

The episode also discusses the implications of recent developments in AI and cybersecurity. With companies like SolarWinds, CloudFlare, and Red Hat enhancing their offerings, the integration of AI into business operations raises concerns about security and compliance. The ease of generating fake documents using AI tools poses a significant risk to industries reliant on document verification. As the landscape evolves, IT service providers must adapt by advising clients on updated compliance practices and strengthening their cybersecurity measures to address these emerging threats.

 

Four things to know today

 

00:00 New Regulatory Shifts for MSPs: CMMC 2.0, FedRAMP Overhaul, and UK Cyber Security Bill

05:21 CISA Cuts and Signal on Gov Devices: What Could Go Wrong?

08:15 AI Solutions Everywhere! SolarWinds, Cloudflare, and Red Hat Go All In

11:37 OpenAI’s Image Generation Capabilities Raise Fraud Worries: How Businesses Should Respond

 

 

Supported by:  https://www.huntress.com/mspradio/

https://cometbackup.com/?utm_source=mspradio&utm_medium=podcast&utm_campaign=sponsorship

 

 

Join Dave April 22nd to learn about Marketing in the AI Era.  Signup here:  https://hubs.la/Q03dwWqg0

 

All our Sponsors:   https://businessof.tech/sponsors/

 

Do you want the show on your podcast app or the written versions of the stories? Subscribe to the Business of Tech: https://www.businessof.tech/subscribe/

Looking for a link from the stories? The entire script of the show, with links to articles, are posted in each story on https://www.businessof.tech/

 

Support the show on Patreon: https://patreon.com/mspradio/

 

Want to be a guest on Business of Tech: Daily 10-Minute IT Services Insights? Send Dave Sobel a message on PodMatch, here: https://www.podmatch.com/hostdetailpreview/businessoftech

 

Want our stuff? Cool Merch? Wear “Why Do We Care?” - Visit https://mspradio.myspreadshop.com

 

Follow us on:

LinkedIn: https://www.linkedin.com/company/28908079/

YouTube: https://youtube.com/mspradio/

Facebook: https://www.facebook.com/mspradionews/

Instagram: https://www.instagram.com/mspradio/

TikTok: https://www.tiktok.com/@businessoftech

Bluesky: https://bsky.app/profile/businessof.tech

...more
View all episodesView all episodes
Download on the App Store

Business of Tech: Daily 10-Minute IT Services InsightsBy MSP Radio

  • 4.9
  • 4.9
  • 4.9
  • 4.9
  • 4.9

4.9

129 ratings


More shows like Business of Tech: Daily 10-Minute IT Services Insights

View all
WSJ Tech News Briefing by The Wall Street Journal

WSJ Tech News Briefing

1,652 Listeners

WSJ Your Money Briefing by The Wall Street Journal

WSJ Your Money Briefing

1,741 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

634 Listeners

Bloomberg Businessweek by Bloomberg

Bloomberg Businessweek

428 Listeners

a16z Podcast by Andreessen Horowitz

a16z Podcast

1,008 Listeners

Bold Names by The Wall Street Journal

Bold Names

1,463 Listeners

Techmeme Ride Home by Ride Home Media

Techmeme Ride Home

948 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

141 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

186 Listeners

The Killing IT Podcast by Karl W. Palachuk

The Killing IT Podcast

12 Listeners

MSP Unplugged by Paco Lebron and Rick Smith

MSP Unplugged

10 Listeners

The MSP Zone by Charles Weaver

The MSP Zone

14 Listeners

MSP Business School by MSP Business School

MSP Business School

6 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

118 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

32 Listeners