
Sign up to save your podcasts
Or


Today we're talking about MSPs and AI: what's working and what's not.
When it comes to AI, our clients are moving fast. They're turning on Copilot, using ChatGPT and starting to run AI agents that can get into their email, files and financial systems. A lot of the time, they're doing it without telling us.
Most companies running agents don't have written policies for them, and almost half don't have a reliable list of what's running. Those are large companies. Our SMB clients are likely further behind.
The stakes are going up too. Last week the FTC opened an investigation into the major AI labs, and the FTC chairman has said the people who instruct these agents are responsible for what they do.
That's a lot of risk, but it's also a real opportunity for MSPs to step in and help.
Joining us today is Ryan Davis, CISO at New Charter. Ryan has led security at NS1 (an IBM Company) and Veracode, and now at one of the larger MSPs in the country, so he's seen AI from a lot of different angles. We'll get his take on what's working, where MSPs and their clients are running into trouble, and how we can turn this into a service.
Two big stories from Microsoft landed within days of each other.
First, EvilTokens. Last week, Nathan Taylor told us some of his co-managed clients were getting compromised through device code flow. Then Microsoft published a report showing just how big this got. EvilTokens is phishing sold as a subscription, and it uses AI at every step. It hit more than 12,000 inboxes across over 10,000 organizations, and the victims land on the real Microsoft sign-in page.
Second, Microsoft announced what Satya calls the biggest Copilot update yet: Home, Code and Autopilot. Autopilot is an agent with its own identity that works in your tenant around the clock. Code lets anyone build apps, and a lot of it runs on usage-based billing.
Put those two stories side by side. Attackers are stealing tokens at scale, and Microsoft is about to put autonomous agents with their own identities into every tenant we manage. That's a big opportunity and a big responsibility for MSPs.
To help us make sense of it, we've got the perfect guest. Dux Raymond Sy, Chief Transformation Officer at Avepoint.
Here's the story from Microsoft: https://www.microsoft.com/en-us/security/blog/2026/09/22/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing/?_sp=f01b38e4-937e-48d4-b3ed-b1afe836185d.1790118273927
Everywhere you look right now, we're hearing about AI-powered cyberattacks and what attackers might be capable of next. But while we're preparing for the attack of tomorrow, what are MSPs actually fighting today?
Nathan Taylor at Sourcepass told me it's been non-stop business email compromise and Microsoft 365 hardening. And one attack in particular is exploding: device-code phishing.
What's concerning is that attackers aren't necessarily exploiting some new vulnerability. In many cases, they're abusing legitimate Microsoft authentication workflows, stealing sessions and tokens, and turning trusted identities against us.
So today I want to separate the hype from what's actually happening in the field.
How are attackers getting into M365 environments? Why isn't MFA always stopping them? What are MSPs getting wrong when hardening Microsoft 365? And what should we be doing differently right now?
Two weeks ago, OpenAI published an open letter, as we discussed, during the previous CyberCall. Over a hundred companies signed it, warning that AI enabled cyberattacks are about to get a lot worse. A week later, they announced Daybreak, their cybersecurity solution, along with a billion dollars in subsidized access to their own platform for water utilities, hospitals, and community banks. Around the same time, Bill Gates published his own essay saying the cybersecurity experts he talks to are genuinely scared about what's coming.
Then this week, Jensen Huang, CEO of Nvidia stood on stage at a Goldman Sachs conference and said what we’ve been discussing, out loud. He said the reason everyone's talking about cybersecurity right now is that the industry is getting ready to launch some products. His words were, why not create demand by creating a problem.
So is the threat real, or is FUD the pitch deck? And either way, neither OpenAI's letter nor Daybreak mentions an MSP once. So where does that leave the people actually running security for these organizations?
Today we have Corey Nachreiner with us. He's CISO of WatchGuard, a company that sells entirely through the MSP channel. We will discuss these topics and the rise of Open Weight models and more.
Last week, OpenAI published an open letter and over a hundred companies signed on. CrowdStrike, Microsoft, Google, Cisco, AWS, Anthropic, basically every major name in cybersecurity and enterprise tech. The letter warns that AI-enabled cyberattacks are about to get faster and more sophisticated, and it specifically calls out hospitals, water treatment plants, and critical infrastructure as the places most at risk.
It lays out a plan: every organization needs to raise its security standards, cybersecurity companies need to build AI-powered defenses, governments need to fund the utilities that can't fund themselves, and frontier AI labs — the OpenAIs, the Anthropics — need to hand tools and support directly to the defenders who need it most.
I went through every name on that signatory list. Not one of them is an MSP. Not one of them is the company that actually shows up when a small-town water authority's systems go down at 2am.
So today on CyberCall, I've got Alan McDonald with me, as he runs an MSP that services a number of municipal water districts. And I want to find out: when the biggest names in cybersecurity write a letter about protecting critical infrastructure, where does someone like Alan actually fit in?
For years, security awareness training has focused almost entirely on email phishing: spot the bad link, question the urgent request, verify the sender. But Unit 42 just published research showing attackers have found a different door, and most teams aren't watching it. Collaboration platforms like Slack and Teams have become part of the identity attack surface. Unit 42 tracked a fourfold increase in malicious activity tied to these platforms over the past year, and 99% of it started as chat-based phishing.
Here's what makes this especially relevant for MSPs: most organizations use Teams to collaborate with outside companies, including their IT provider. Attackers know that. They pose as the MSP itself, or as IT support, because that relationship already carries a zone of trust. When "your IT provider" messages you on Teams asking you to approve an MFA prompt, most people don't question it, they just comply.
That's why we wanted Wil Klusovsky on the show. Wil's known for translating technical risk into something executives can actually understand and act on, and this topic needs exactly that.
Palo Alto's Unit42 Research:
https://unit42.paloaltonetworks.com/communication-channel-identity-risks/
https://unit42.paloaltonetworks.com/microsoft-teams-phishing/
This week's conversation is one we believe every MSP needs to hear.
AI-generated vulnerability patches have become the obvious next move for software developers drowning in a tsunami of CVEs. It sounds like a great answer, until you look at the actual data.
That's exactly why we wanted Keith Hoodlet on the show. Keith just published the inaugural research from 1Password's new security research team, Off-by-1 Labs, and the findings are fascinating: when frontier AI models were tasked with patching six real, recently-disclosed vulnerabilities, they got it fully right without breaking anything else, just 26% of the time. More than half the time, the patch either didn't fix the vulnerability, introduced a new one, or both.
Keith's research can be found here.
AI is reshaping our industry faster than anything we have witnessed, and yes, threat actors are using it too. But we don't want to spend today talking about AI simply as a threat. We want to talk about it as the biggest opportunity our industry has had in a long time and how we consider adopting AI for ourselves and our clients.
That's exactly why we wanted Lior Bela on the show. Lior recently stepped into a new role leading AI Strategy for Security at Microsoft, and he posted something that we believe resonates with every MSP. Organizations are eager to adopt AI, they just need to do it securely and helping customers navigate that is what excites him most.
So that's where we're headed today. No product pitches. Just a real conversation about where the opportunity is, how governance and go-to-market are shifting, and what the next six to twelve months look like at the speed AI is moving.
Most MSPs are asking the same question in a different way: "Do I need to care about MCP, or is this just another acronym I can ignore for six months?"
MCP Servers are becoming the connective tissue between AI agents and the tools you already run; your PSA, your RMM, your security stack. MSPs are using them to kick off assessments, run queries to determine continuous EDR deployment and many other critical tasks within the business.
So today we're getting digging into this topic to help you make good decisions. Where are MSPs are actually finding value with MCP right now, and where the hype is running ahead of what it can really do. What a smart first move looks like if you're starting from zero. And the part nobody wants to skip past governance and security. What access an AI agent should never have. How you audit what it actually did. Who inside your business should own that call in the first place.
To help us work through it, we’ve got Aharon Chernin, CEO of Rewst, who has a firshand view of “what good looks like” when it comes to MSP and MCP.
Right now, every MSP is hearing the same sentence from clients: "We need AI." But when you start to ask questions like “what are you trying to accomplish,” there is no plan, no process, just a mandate.
Our guest has heard it three times before. Ian Barkin built his career watching this exact cycle repeat, first in Business Process Outsourcing, then in Robotic Process Automation, and now in agentic AI. Same hammer, different decade. Companies are convinced the tool is the answer before they've asked what problem they're actually solving, or done the unglamorous work of documenting the process underneath it.
Ian is the author of All Hands on Tech and founder of magentIQ, and he's going to walk us through the frameworks and methodolgies he's built, for leading clients through the proper steps that produce tangible outcomes.
If you've ever sat across from a client who wants AI yesterday and a roadmap never, this one's for you.
From the publisher's feed
The Voice of Cybersecurity for MSPs & MSSPs!
The CyberCall is the weekly podcast where cybersecurity meets business reality. Hosted by Andrew Morgan, Founder of Right of Boom, this is the…
Each episode features raw, practical conversations with the sharpest minds in cybersecurity—from operators in the trenches to CISOs, researchers, policymakers, and toolmakers shaping the future. If you care about protecting your clients, growing your practice, and becoming the security partner businesses trust—this podcast is your playbook.
Co hosts: Phyllis Lee, VP of Content at CIS & Gary Pica, President of TruMethods