Secure Connections

Secure Connections

By IoTSSA (Internet of Things Security Services Association)BusinessTechnology
Download on the App Store

Secure Connections episodes

  • Protecting Data in the Cloud
    Brian talks with CEO of Vault America, Zak Karsan on protecting data in the cloud. Data sprawl is a growing concern for all businesses from the SMB to enterprise…enter IoT devices and the challenge now becomes even more complex to manage. Zak provides a step by step model for MSPs to use with their customers […]
    0 min
  • Protecting Data in the Cloud
    Brian talks with CEO of Vault America, Zak Karsan on protecting data in the cloud.

    Data sprawl is a growing concern for all businesses from the SMB to enterprise…enter IoT devices and the challenge now becomes even more complex to manage.

    Zak provides a step by step model for MSPs to use with their customers in order to develop a solution that best suits them. He explains that it starts with really understanding your customers business operations and he also provides a few questions you should be asking in order to lead the conversation and ultimately get the information you need to properly secure their data.

     
    0 min
  • Risk & Vulnerabilities
    Be prepared to listen to this one more that once as John Ford CISO at ConnectWise has a very frank discussion with Brian on Risk Assessments and where the majority of SMBs fall short in today’s threat landscape. There are no short cuts in cyber security. A risk assessment is a holistic approach and drives […]
    0 min
  • Risk & Vulnerabilities
    Be prepared to listen to this one more that once as John Ford CISO at ConnectWise has a very frank discussion with Brian on Risk Assessments and where the majority of SMBs fall short in today's threat landscape.

    There are no short cuts in cyber security. A risk assessment is a holistic approach and drives next steps. Contrary to what some believe, vulnerability assessments support the risk assessment, they don’t replace them.

    Based on real time anonymous aggregate data from the ConnectWise Identify assessment tool for MSPs the top 3 vulnerabilities are:

    1. Neither MSP or their customers are doing adequate security awareness training
    2. There is a lack in sufficient risk management practices
    3. Inadequate monitoring or protection of client environments

    When looking at enterprise security deployment vs. MSPs securing SMBs, John refers to it as bolting it on rather than baking it in and that service to SMB is somewhat transactional in nature rather than being process driven.

    Transparency is your best approach with clients and prospects. Move the conversation to risk and determine how much your clients are willing to endure. Start by really understanding your client’s business before you can suggest the best and most adequate cyber security protections.

    Links discussed in this Podcast:
    1. https://www.connectwise.com/software/identify
    2. https://www.sans.org/
    3. https://misti.com/
    4. https://www.nist.gov/cyberframework
    5. https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final

    #connectwiseidentify #Securityrisk #cybersecurity #securityassessments #SecureConnections #IoTSSA
    0 min
  • The Evolving Spear Phishing Threat
    We hear daily of new attacks and the rapidly evolving threat landscape facing IT Service Providers and the SMB. Our feedback from the IT Channel is ‘Yes we are aware of the threats, but now what? What do we do and how do we effectively lock down ourselves and our clients?’

    Don’t miss this 30min Podcast Brian has with Neal Bradbury, Sr. Director of Business Development with Barracuda MSP. Neal talks about the importance of staying educated and keeping ahead of the threat landscape or you will quickly fall behind. The threats are evolving so fast that as IT Service Providers we need to rely on all resources available to us starting with leveraging our Vendors and the support and tools they offer.

    Barracuda MSP recently released their Spear Phishing Top Threat and Trends Report where it states 93% of breaches start with an email attack.

    These attacks can be broken into 3 categories:
    1. Brand Impersonation
    2. Blackmail
    3. Business Email Compromise

    Neal gives a step by step checklist to effectively build out a layered and advanced security defense against these threats.

    Kenny Bania from Seinfeld came to mind in a few spots during this podcast…’Gold Jerry…Gold!’.

    Links discussed in this Podcast:
    1. https://www.cyberseek.org/
    2. https://smartermsp.com/
    3. https://haveibeenpwned.com/

     
    0 min
  • Cobblers Kids have no Shoes
    We have been hearing for the past little while that IT Service Providers are a prime hackers target….for obvious reasons. Much of the feedback we have been receiving from the IoTSSA community is that yes we are aware, however how can we effectively protect ourselves and our clients?

    Doug Hazelman, VP Technical Marketing for CloudBerry states ‘Assume you are going to be attacked’.

    Brian sits down with Doug to discuss the importance of staying on top of an escalating and increasing threat of attack. The bad guys are working together and evolving tirelessly in their efforts which has become a big big business for them and in many cases also State sponsored which equates to deep funding and support.

    As an IT Service Provider it is critical that you keep up to date and pay close attention to this evolution and expansion of the attack surface. What was released as a warning from government 6 months ago certainly hasn’t gone away, only continued to expand and become more sophisticated.

    Doug and Brian discuss managing BYOD, decryptor tools, patching and security warnings. Leverage your security vendors and keep an open dialogue with them so that you can benefit from their expertise and keep ahead of new tools available to you.

    The Cobblers kids have no shoes, can’t be more prevalent than in today's threat landscape because the alternative can be catastrophic. Have you invested in a Pen Test on your own environment? This is a final step not the beginning. Once you are comfortable with your own security posture and stack….A Pen Test should follow. Note: A Pen Test is a huge selling feature for your prospects and clients when discussing cybersecurity. You have invested in and passed a Pen Test on your own environment in order to ensure their protection!

     
    0 min
  • Cybersecurity Maturity with Chris Johnson, PinPoint Solutions
    Brian sits down with Chris Johnson from Pinpoint Solutions a cybersecurity consulting firm. Chris talks about cybersecurity maturity and getting away from what he describes as ‘Chasing the shiny objects’. Satisfying regulatory requirements is much more than just checking boxes. The largest vulnerabilities for MSPs is the unknown.
    0 min
  • Cybersecurity Maturity with Chris Johnson, PinPoint Solutions
    Brian sits down with Chris Johnson from Pinpoint Solutions a cybersecurity consulting firm. Chris talks about cybersecurity maturity and getting away from what he describes as ‘Chasing the shiny objects’. Satisfying regulatory requirements is much more than just checking boxes. The largest vulnerabilities for MSPs is the unknown.

     
    0 min

About Secure Connections

From the publisher's feed

Ryan Morris, IT Channel Veteran, catches up with todays cybersecurity experts to discuss all things cybersecurity. The current threat landscape, the newest bleeding edge tools and communicating their…