The primary structural mechanism examined concerns the shift in cybersecurity operations for MSPs driven by increased automation and AI-powered platforms, specifically as evidenced by Cynomi’s virtual CISO (vCISO) solutions. This transition signals a migration of both operational workload and expertise from traditional, manual processes toward digitally augmented roles, with significant implications for how accountability and liability are managed within managed security services.
According to the facts presented by Cynomi’s CEO, the company’s recent integration-focused releases enable MSPs to accelerate assessment and compliance processes, claiming reductions from multi-day efforts to under 60 minutes in some cases. The platform aggregates data from existing MSP ecosystems (including PSA, EDR, and vulnerability management tools such as Tenable and Microsoft integrations) to assemble remediation plans and operational roadmaps, often with minimal human mediation. Cynomi states that a single vCISO operator, using these tools, can service up to 10-12 clients compared to 5 previously, with some projections reaching as high as 50. The company positions its technology as supplementing, not fully replacing, human expertise—though it acknowledges the potential for junior personnel, aided by AI, to bridge previous capability gaps.
Supporting this dynamic, the episode explored how efficiency gains introduce questions around pricing, market access, and liability. Dave Sobel questioned the sustainability of pricing models anchored on scarcity of human CISOs when automation multiplies operator capacity and competitors adopt similar tools. The conversation highlighted that as AI reduces human labor in delivering assessments and compliance, market prices could decline, but the accessible market might expand, especially among previously underserved SMBs. Liability, however, remains with the MSP; automated recommendations must still be reviewed and approved by a designated human. Concerns were raised regarding insurance exclusions when AI-generated security policies are implicated in claims, prompting focus on the importance of maintaining human oversight and evidentiary processes.
Operationally, MSPs face heightened pressure to clarify vendor and personnel accountability, reinforce internal QA on AI-driven deliverables, and rethink service economics in light of scalable automation. Vendors providing AI-enabled security assessments shift both risk and workload, but do not absolve providers of responsibility in the event of customer breaches or compliance failures. Insurers are beginning to scrutinize and sometimes exclude AI-generated outputs from coverage, underscoring the importance of documenting processes and retaining subject-matter oversight. These developments compel IT service providers to reassess vendor relationships, liability boundaries, and training needs for staff operating in an increasingly automated environment.
Supported by:
GoTo(LogMeIn)
Guardz
HaloPSA
💼 All Our Sponsors
MSP Radio is supported by our partners:
ABC Solutions · CometBackup · Firetail · Guardz · HaloPSA · LogMeIn · Mailprotector · OpenText · Pax8 · Proofpoint · Rythmz · ScalePad · TimeZest · Transit AI · USecure
Supporting the IT services community through insights, analysis, and transparency.
🚀 Join Business of Tech Plus
Get exclusive access to investigative reports, vendor analysis, leadership briefings, and more.
👉 https://businessof.tech/plus
🎧 Subscribe to the Business of Tech
Want the show on your favorite podcast app or prefer the written versions of each story?
📲 https://www.businessof.tech/subscribe
📰 Story Links & Sources
Looking for the links from today’s stories?
Every episode script — with full source links — is posted at:
🎙 Want to Be a Guest?
Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:
💬 https://www.podmatch.com/hostdetailpreview/businessoftech
🔗 Follow Business of Tech
LinkedIn: https://www.linkedin.com/company/28908079
YouTube: https://youtube.com/mspradio
Bluesky: https://bsky.app/profile/businessof.tech
Instagram: https://www.instagram.com/mspradio
TikTok: https://www.tiktok.com/@businessoftech
Facebook: https://www.facebook.com/mspradionews
Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
[00:00:00] David Primor, you are the Chief Executive Officer for Synomi. Welcome to the Business of Tech. Thanks, Dave. Pleasure to be here. So, let's start at the top. You shipped your largest release in the company's history in June. Give me the 90-second version of what actually changed for the partner that morning. Yeah, June, you know, June was a few months ago and we have so many other features coming since then.
[00:00:27] So, in June, we released sets of integrations as we believe that we must be part of the ecosystem, the MSP ecosystem. Vulnerability management, since then we added EDR. And we are going to add PSA integration very, very soon and going to have a few integrations of PSA, penetration testing.
[00:00:55] So, we focus our team in creating lots of integrations, taking the data from the ecosystem of the MSP and translating into the insights in Cynomi. So, this is a very, very important thing that we are doing. We are adding co-workers and co-workers is a very cool thing.
[00:01:16] So, we are trying to understand what are the main processes of the CISO or the virtual CISO in MSP and MSSP and trying to get it to a very few minutes. So, how can you shorten the time of assessment? This is a very big challenge. In the last version, it was several hours instead of days or weeks.
[00:01:46] But now, we are going to take it to less than 60 minutes. So, we are having the combination of a portfolio understanding, asking questions about the MSP, asking questions about the specific end customer,
[00:02:04] and giving the MSP, giving the MSP the ability to create their own assessments with their own scope, taking information from scanners, taking information from integration, and making the assessment a very, very quick process. And this is in combination with AI co-workers that take the different processes that the CISO is doing, like creating a remediation plan, a roadmap.
[00:02:34] So, taking all the information from the tasks, from the compliance, and making a suitable and very precise remediation plan. Something very exciting that we are doing is reporting agents that help you with AI to create your own report. Creating co-workers that taking the findings from integration and automatically correlated to the tasks and C conflicts.
[00:03:03] Now, let's make this tangible, particularly for like a smaller MSP. I'm thinking, say, a five or 10 person MSP right now. Now, what's the, of everything you've just talked about, what's the one thing they should focus that's available right now that they should focus on as like the key thing to know? Yeah. So, they can assess quickly any company they have. They can generate a remediation plan almost out of the box.
[00:03:31] So, asking several questions. They can take the information from external scanning from Synomi or integrate it with Microsoft or with other vulnerability management that they might use, like Tenable or Cavello or others.
[00:03:50] And getting a very fast plan to share with the customers in order to understand what is the next step, how to create a cybersecurity roadmap.
[00:04:01] And if they would like to provide assessments or they would like to provide compliance to regulations like CMMC, like HIPAA, ISO 2701, NIST CSF, whatever, they could use Synomi in order to do that and to be prepared for an audit.
[00:04:23] Now, when I was reading the release, you say that an MSP with 15 clients can spend up to 120 hours a week on manual security administration. That's three full-time people doing nothing else. Where does that number come from and what is it after Synomi?
[00:04:42] Yeah, so we understand that if you want to assess a company and understand what is the security posture in order to first understand what are the risks, trying to quantify that, understand what is the cybersecurity posture and how you improve it.
[00:05:07] And then to create a plan and to prioritize that because you know that the end customer together with MSP, they cannot do everything. So if we are trying to understand what are the time it takes for MSP to assess a company, to ask all these questions, to have those interviews, it's hours and hours and hours. And we are working with MSPs that turning this manual process into automatic process.
[00:05:35] So the assessment is the first step. Second is when you try to provide this plan or the compliance report for regulation, understanding what is the next step. Understand what are the next tools that MSP would like and need to provide to its customers. This takes a lot of time.
[00:06:00] And working with hundreds of MSPs in Synomi, trying to understand what takes them the most of the time and how they can expand. How can one CISO is doing the task of three CISOs? I think that this is what Synomi is trying to achieve. And by applying AI and adding more and more features, we are enabling the MSPs to do something that they couldn't do.
[00:06:29] We see cybersecurity, compliance, insurance requests. And those companies need help from MSPs. Currently, MSPs are very short of talent. And even if they have this demand, they don't have enough people to provide these assessments.
[00:06:51] Either it's compliance or just cybersecurity or just me to provide a standardized security posture and to understand where they stand from security perspective. And with Synomi, they now can do that. So they can add more services and they can answer this demand from end customers. The MSPs getting ahead in security aren't adding more tools. They're getting the work off their plate.
[00:07:22] Guards consolidates the stack, endpoint, email identity, and then puts an autonomous analyst on top of it. Triaging the alerts, correlating the signals, drafting the client reporting automatically. It's purpose built for MSPs protecting S&B clients month to month. Real SecOps without hiring a SecOps team. Start at guards.com. That's G-U-A-R-D-Z dot com.
[00:07:52] Well, around that demand, you told ChannelPro back in May that one person went from five virtual CISO clients to 10 with your platform. And that 30 is coming and that in a year it might be 50. Now, if I look at your pricing guide, you say to charge $2,000 to $3,500 a month, which you're anchoring against what a full-time CISO costs.
[00:08:15] But if capacity goes up 10 times, and in theory every competitor now has the tool, what happens to that price? Yeah, from a Cynomi perspective or from the MSP perspective? From an MSP perspective. Yeah, I guess that I don't think that from the MSP perspective to its customers, I think that it will be much easier for the MSP to provide those services.
[00:08:41] So they can spend the time that they have with creating a better relationship and do things that only a human can do. And I guess that the ability to answer the demand that they get from the customers will help MSPs to provide the better services.
[00:08:59] And I believe that it will enable MSP to charge more because the demand is there and customers are willing to pay more for getting the value that they need. They need to show that they are protected. They need to show that they, to the insurance that they can be insured. And they need to understand how to control the risks. Well, so, but I want to understand the pricing model to the customer because if we're anchoring against CISO salaries, right?
[00:09:28] If we're positioning this as delivering a CISO, that only works when the client believes there's a scarce human behind that. And you're telling me that the human part is what we're automating and removing. So am I selling scarce expertise or am I implementing software and automation with a markup? No, no, no. We are helping the CISOs within the MSPs to provide more.
[00:09:56] We're helping them to take all the many processes that they need to do and to think about and to analyze. We'll make it more accurate. They're still the ones that providing those services. So if you take a virtual CISO, for example, that currently or maybe before Synomi could handle five customers. Now with Synomi, they can handle between 10 to 12 customers.
[00:10:22] They're still doing a lot of optimization, lots of Excel work, lots of PowerPoint work. Then we are adding all these coworkers, like little helpers to the CISO. So it's like me using, let's say, Claude. So I'm still the one that's writing these emails. I'm still the one that's creating this relationship.
[00:10:46] But Claude helps me to write those emails 10 times quicker. So this is what Synomi is doing, enabling one CISO in the MSP to provide services to 30 customers instead of 10 customers. I believe that those services will be much better because these AI agents will enable to make less mistakes.
[00:11:14] But still, the relationship is within the MSP and the virtual CISO. So but wouldn't the honest version of this end up being that the price comes down to the end customer, but the market gets, say, five times bigger because nobody was serving these SMBs at all? Yeah, you're right. I believe that the cost will be lower because you don't need human in the loop. It's just tokens.
[00:11:40] So I believe that, like in every other software that we see that using AI, more people will be able to use, will get some virtual CISOs. And when I'm trying to imagine it, I see SMBs getting help from small virtual CISOs. And then mid-market gets from more advanced virtual CISO.
[00:12:08] And every company is paying for the quality of CISO that they're getting. And I believe that the cost for the end customers will be lower. This episode is supported by Halo. Automation is becoming a defining characteristic of modern managed services. But automation only works if the core platform supports it.
[00:12:31] Halo PSA gives service providers the flexibility to build powerful workflows, integrate automation tools, and design service processes around how their business actually runs. For MSPs building a more automation-driven operation, Halo PSA is one of the platforms increasingly showing up in those conversations. Learn more at usehalo.com. Okay, now I want to take this and I want to ask a little bit about liability.
[00:13:01] And because I think that being precise here is going to be really important. Your release says that the AI findings coworker recommends remediation for partner approval, right? That's preserving the human oversight. You also said in May that many MSPs don't have the talent either. And then in June, you could take a junior IT guy and turn him into a sophisticated cybersecurity expert with AI.
[00:13:25] So in a 15-person shop, the partner approving is that junior guy. So what's his approval actually worth? It doesn't mean that the junior will provide junior advice.
[00:13:41] It means that we can turn a junior IT guy or junior security guy into somebody that can get more knowledge from a very sophisticated AI machine. So it means that still the liability is there because we are not taking the human out of the loop. The human stays there.
[00:14:06] But we're giving them the knowledge they don't have because they don't have enough expertise or access to this type of knowledge. But how do we ensure the quality of that approval, right? We need to make sure that that person has the ability and the skill to be able to execute against that. I think this is a journey of the MSP together with vendors. I guess that it's not the only way to do that.
[00:14:33] We see it in the legal when you have legal software that helps the legal to be much better. And the QA or the assurance is very, very important. So I think that during this process, we are working with our partners, design partners,
[00:14:52] to understand what AI agents are doing well, what still need to be corrected by the expert. What we see with talking with our MSPs is that they have one expert and then set of juniors, and the experts can sometimes help those juniors to take the right decision. Can we get to the point that we will have only juniors?
[00:15:21] I think that we are not in that point yet. But certainly what we can see is that you don't need so many experts. You could hire one expert and lots of other juniors and have this expert helping with saying what you can justify, what is your reliability, and where the human must be in the loop and where you can trust the AI. Okay. Now, I want to be really clear.
[00:15:46] So when a partner or listener hands a client a risk register and a remediation roadmap that your platform generates, and then that client gets breached through something the roadmap deprioritizes, whose names end up being on the advice? Is it yours or is it theirs? How does the liability fall? The liability is always with the one that's providing the service.
[00:16:12] I guess that this is the same as any security product that you are using. So we are not claiming that we can eliminate threats or we are doing the best choices.
[00:16:30] We are saying that probably with Synomi, a CISO can create a roadmap which is very close to the optimal one. You could save resources. You could provide the level of cybersecurity expertise that you could get from a high expert.
[00:16:55] But even with a very experienced person and the best CISO in the world, sometimes when you have an attack, it's not his fault. It's a zero day. It's a misconfiguration that you couldn't detect. It's human mistakes. It's a lot of other things that... So I guess if we are generally speaking about the reliability of MSPs,
[00:17:23] there is a new program that we are doing together with a company named Spectra. And together we are doing an assessment to an MSP. And Spectra is willing to give a warranty to the MSP if they are providing the right services.
[00:17:44] And I guess that taking those risks and paying this premium will help the MSPs to understand that the services that they are providing, you can get a warranty, you can get insurance for the end customers if the level of security is a good one. And what Synomi is providing is the ability to assess the company and assess the MSP
[00:18:11] and being able to say you are following the best practices of cybersecurity in a very high level of expertise. The fact that insurance companies are willing to provide a warranty justify the efforts that Synomi is doing with that type of assessment. But can you guarantee that nobody will be attacked and you will not be sued for compliance bridge, etc.,
[00:18:41] I think that we are not there yet. You know the LogMeIn name, but when did you last look at what it does for MSPs today? Beyond the remote access it's known for, LogMeIn Resolve is a full MSP platform, and the partner side is built to the channel. A dedicated customer success manager, direct Tier 2 support, and an actual voice in where the product goes next.
[00:19:07] If LogMeIn has been sitting in the I already know them category in your head, it's worth a fresh look. Start at LogMeIn.com slash MSP Growth. So back in January, a bunch of insurers have started writing exclusions into their commercial general liability policies that say if you use generative AI to create your security policies, that doesn't count.
[00:19:35] And there are also tech E&O carriers are adding exclusions to say we're not going to cover AI output. So those both, if you're using AI to create policies and roadmaps, the insurers are starting to exclude certain pieces. I would think that affects your service. I'd like to understand, have you dug into this to understand the new liability landscape? It's a good point. We need to do that.
[00:20:03] I think that AI will be part of our life. We cannot escape from that. Everybody is using AI for policies, for roadmap. And I think that saying that, and we all know that AI has mistakes. We are working very hard at Synomi to make sure that the mistakes are minimal. We are having our own experts. We are, I think that this is the main difference between Claude and what you have in Synomi
[00:20:32] and maybe other vendors that looking carefully at the outputs of the AI. So I'm not aware of insurance that's saying, okay, if you are using any type of AI recommendations, you know, Microsoft is doing that. HubSpot is doing that. CrowdStrike is doing that. So everybody is using AI.
[00:20:58] So I need to understand what are the parts of the insurance that's saying, okay, if you're using that, maybe without any control. But I can assure that everything that you are doing within Synomi with AI, is we are having first our own human checking. So we are not giving something to the community, which didn't go a very deep way.
[00:21:26] And then we have design partners that are checking it as well. So we want to make sure that nothing will be, will not get a random answers, et cetera. Well, let me ask you then about the warranty. Because, you know, so you mentioned the Spectra partnership. We covered it on the show. It's a million dollar warranty per client with certification in days. And the idea is, is you map their criteria against assessment data already in your platform. Now that data is what your AI generated.
[00:21:55] So what is Spectra independently verifying to that? Yeah, so what we are doing is within Synomi is an assessment. The assessment is not done only by AI. It's done by collecting integration information, questions that we use AI in order to understand what are the questions, the minimal number of questions. But there is an involvement of a human in the loop, it's important to say.
[00:22:22] When you get this assessment, what Synomi can do is to do a mapping between any framework which exists, let's say, NIST CSF or ISO and also Spectra. So you don't have to do the assessment by Spectra in order to get the warranty. It's enough that you already did this assessment using Synomi. Of course, you need to provide evidence because insurers need evidence.
[00:22:52] So this is something that usually you're not always adding evidence when you're doing an assessment, mainly for audience. But for Spectra, you need to do that. But that's it. So if you already, customers for Synomi, you could do this assessment in hours or days, and then you can get this warranty. Gotcha. Has a warranty ever paid a claim? And I'm curious, when it pays, it pays the client. So what does the MSP get in that warranty?
[00:23:23] The MSP is paying to the insurer or the Spectra, and then he's covered when something is happening and the customer can sue him. What we also see is that the ability to say that you are providing warranty is a strong sales pitch to the customers. So the fact that you are not only providing those services,
[00:23:52] you could say that you are providing a warranty or you can provide a warranty. It gives some certification to your services. Has that warranty ever been paid out? We only began last month with the first customers. So not yet, but hopefully never. So last question then. Let's give some advice, some practical advice to the smaller, say, 10-person MSP shop
[00:24:21] of what they shouldn't do with a virtual CISO platform, particularly as they roll it out in the first 90 days. Starting with, okay, these are the risks that you have. This is the posture. Let's sit together and see what we need to do. In many cases, you are not really understand. And this is also a place where human in the loop is needed. What is the real need of the customer?
[00:24:51] What is the pain? Is it reputation? Is it assets that you want to protect? And if you are trying to give him and impress him by providing a plan, which is not accurate to their needs, to their threats, to their risks, sometimes too early. So understanding your customer before providing a very detailed and expensive roadmap. David Primor is the CEO of Synomi,
[00:25:18] a security platform built for MSPs, MSSPs, and V-CISO practices. He's a veteran of Israel's Unit 8200 and served as a technology director at Israel's National Cyber Authority. The company is channel-only, works with partners across North America, Europe, and Israel, and raised a $37 million Series B led by Insight Partners and Entree Capital. David, if people are interested in continuing the conversation, learning more, what's the best way for them to do so?
[00:25:45] Email me, david.sainomi.com. Well, that is the easiest answer to them all. David, thanks so much for joining me today. Thank you, Dave. It was a pleasure. The hardest part of running an MSP? Doing it alone. The Small Biz Thoughts community has been the room where independent operators compare notes for nearly 20 years. Real peers, real numbers, real answers from people running businesses just like yours.
[00:26:14] Pull up a chair at smallbizthoughts.org. Interested in advertising? Head to mspradio.com slash engage. The Business of Tech is written and produced by me, Dave Sobel, under ethics guidelines posted at businessof.tech. Thanks for listening. I'll see you on the next episode. Produced by Picture This Video.
[00:26:45] Part of the MSP Radio Network.

