Why Unmanaged Access Is Increasing MSP Liability: Access Governance Gaps with Kyle Bove

Why Unmanaged Access Is Increasing MSP Liability: Access Governance Gaps with Kyle Bove

The dominant structural mechanism explored in this episode centers on governance gaps in access management and the resulting liability transfer to MSPs. The discussion highlights how fragmented identity stacks, unmanaged access, and reliance on manual tracking expose MSPs to growing contractual, operational, and legal risk. Companies and technologies referenced include Microsoft 365, Google Workspace, Okta, ConnectWise, and specific access governance solutions targeting the channel. The ConnectWise 2026 Threat Report identifies credential abuse as a core attack vector, underscoring how unaddressed authorization and access drift remain a structural exposure area.

The episode cites multiple indicators and supporting data. According to the ConnectWise 2026 Threat Report, credential abuse is now the primary attack vector, with attackers commonly exploiting active and orphaned accounts left unmanaged in client environments. Fragmented identity stacks complicate the onboarding and offboarding process, with onboarding often requiring 45 minutes per client as technicians navigate numerous access portals. The prevalence of shadow IT, orphaned accounts, and missed deprovisioning windows was discussed as persistent drivers of both operational overhead and increased incident risk.

Supporting developments include community-documented scenarios where multi-factor authentication (MFA) was present but insufficient to prevent breaches, particularly when privilege escalation or temporary exclusions remain unaddressed. Examples such as the Reddit phishing event and Microsoft’s handling of MFA via VOIP demonstrate how authentication is distinct from governance, and that temporary access or exceptions frequently become permanent, heightening exposure. Regulatory environments—including healthcare, finance, and government—were cited as adding further requirements for explicit governance controls and auditable access policies, while manual spreadsheet tracking often fails to meet these demands.

The operational implications for MSPs include the need to move beyond basic practice such as MFA and endpoint protection, toward purpose-built tools and processes that provide continual visibility, auditable controls, and policy enforcement for client access. Without this, MSPs face increased administrative burden, billing discrepancies, contractual liability, and reputational risk. As regulatory audits become more demanding and clients demand clearer evidence of governance, service providers must reconcile the tradeoffs between increased process complexity and the need for automated, enforceable identity governance. This shift challenges existing pricing models, requiring MSPs to justify and potentially repackage their service offerings in the context of risk management and operational maturity.

 

💼 All Our Sponsors

MSP Radio is supported by our partners: 

Transit AI · Guardz · Pax8 · ABC Solutions · Rythmz · ScalePad · CometBackup · TimeZest

Supporting the IT services community through insights, analysis, and transparency.

 

🚀 Join Business of Tech Plus

Get exclusive access to investigative reports, vendor analysis, leadership briefings, and more.

👉 https://businessof.tech/plus

 

🎧 Subscribe to the Business of Tech

Want the show on your favorite podcast app or prefer the written versions of each story?

📲 https://www.businessof.tech/subscribe

 

📰 Story Links & Sources

Looking for the links from today’s stories?

Every episode script — with full source links — is posted at:

🌐 https://www.businessof.tech

 

🎙 Want to Be a Guest?

Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:

💬 https://www.podmatch.com/hostdetailpreview/businessoftech

 

🔗 Follow Business of Tech

 

LinkedIn: https://www.linkedin.com/company/28908079

YouTube: https://youtube.com/mspradio

Bluesky: https://bsky.app/profile/businessof.tech

Instagram: https://www.instagram.com/mspradio

TikTok: https://www.tiktok.com/@businessoftech

Facebook: https://www.facebook.com/mspradionews


Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

[00:00:10] Well, welcome to this webinar from the Business of Tech sponsored by JOSIS. I'm Dave Sobel and today we're talking about Unmanaged Access Is Your MSP Liability and What to Do About It. This is one of the most underestimated liability problems in managed services right now. It's not your firewall, it's not your EDR, it's not your SIM. It's the thing those tools don't actually see.

[00:00:35] Who has access to what, whether they should still have it, and whether anyone is watching. MSPs have done a job focusing on the threat layer. They've got MFBA deployed out, they've got endpoint protection in place, and your detection tools are running. But the authorization layer, who actually has standing access to client systems, SaaS apps, admin consoles,

[00:01:00] that's often unmanaged, undocumented, and quietly building up liability in all of the contracts you've signed. So today we're going to get specific about where that gap lives, why it defaults to you as the MSP, and what a practical path to closing it actually looks like. I'll be leading the conversation and you'll be building it. You'll be dropping your questions into chat as we go, because we've got a dedicated time for Q&A at the end.

[00:01:27] Now, joining me today is Kyle Bove, who works with Josus. It's an autonomous identity governance platform built specifically for IT teams and MSPs managing multiple client environments. Kyle works in the channel day in and day out, talking to MSPs about the access sprawl problem. That's shadow IT, orphaned accounts, offboarding features, and privileged rift, and what it actually takes to get that under control at scale.

[00:01:55] He's been on the ground at events like Channel Pro Defend and is one of the people in this space who can speak to the operational reality, not just the category pinch. Kyle, glad to have you here. Thank you, Dave. Appreciate it. I am excited. Now, a note to everyone who's listening, we're going to talk today for about 40 minutes to get back and forth. And at the end, we're going to open it up to your questions live. To submit a question during the live show, use the Q&A button at the bottom of your Zoom window.

[00:02:25] That's where I'll be pulling from, so that's the place to put your questions. Drop it in any time during the show. You don't have to wait until the end. And by the way, here's an incentive. Everyone who submits a question today through the Q&A gets entered into a drawing for an Amazon gift card. And you don't have to be picked for the live segment. Just submit a question and you're in. And by the way, we have multiple Amazon gift cards.

[00:02:53] So make sure to get in there because everybody has a good shot at getting it done. We'll answer. We'll make sure everyone is notified after the show who our winners are. Now, before we get into the content here, I want to get a quick poll of the audience to see where actually starting something. We're going to put up a poll here. And you can take out your phone, scan the QR code, and answer this question about what is your biggest challenge governing access right now. Things like offboarding or shadow IT, privileged access sprawl.

[00:03:23] We'd like to hear from you. So go ahead and submit in your question. Now, Kyle, I'm going to turn it over to you. You talk to MSPs every single day on this. What are those biggest challenges you're hearing from the field as the thing MSPs are most concerned about? Yeah, well, you know, a lot of it is sort of the same.

[00:03:41] Thin margins, labor shortage, and a growing just array of different threats from a cybersecurity standpoint that, you know, you constantly have to watch out for, monitor, remediate. And so MSPs today have their hands full. That's certainly been true. I mean, one of the things that we keep seeing is that you've got the entire security layer. And now you've been asked to talk about all of this additional piece. By the way, that's before we even are on AI agents. It's kind of the authentication that's coming in there.

[00:04:11] Now, one of the things that I've been thinking about a lot is how this is all coming together in terms of the governance layer. I think that this is one of the areas that's going to become most prevalent in our conversation. I'd like to go ahead and get a sense of what the audience is thinking. Let's go ahead and see where our polls are at in terms of the response so far. Oh, guys, we've gotten a few votes in there. We're going to leave that open for right now so that you can go ahead and put in and give us a little bit more of your feedback.

[00:04:37] Now, Kyle, I want to go ahead and get into talking a little bit about that access governance gap. When I look at some of the research data that I've been getting from the business of tech, we're showing that MSPs are really wrestling with managing that access layer across clients, particularly when they've got all of these fragmented identity stacks. Microsoft 365, Google Workspace, hybrid Active Directory, OTA, all of this coming.

[00:05:01] And onboarding is often taking, you know, 45 minutes per client in some cases because the techs have to jump between multiple access portals. By the way, on top of that, you layer on anytime Microsoft has an issue with things like misconfigurations, global admin sprawl or all of that on top of that, you know, we really have to understand that the MSPs are fighting a lot of different issues.

[00:05:24] So, Kyle, when you look at a typical MSP client environment, where's the first access problem you actually find? Not the one necessarily you expected to find, but what's that first problem point? I think the first thing really starts with discovery. I mean, a lot of MSPs, a lot of their clients just don't really know everything that exists in their environment and who has access to what, right?

[00:05:48] So it starts with sort of doing an assessment of what do you guys actually have, who has access and why? Because it's sort of like an invisible problem. Like it's quiet. It's invisible. You can't really see it. It's hard to sort of get a gauge on the scale of it until something happens and you're kind of forced to do that.

[00:06:09] And so it's kind of getting a basic foundational discovery of what's in the environment and then setting up some sort of monitoring to be able to kind of keep tabs on it. Gotcha. And I want to also get a little bit of sense. One of the community pieces that I keep looking at is there is a recurring pattern here. Employees leave. Accounts stay active. Sometimes that's for months, right?

[00:06:32] In fact, I actually was digging into the ConnectWise 2026 threat report, naming credential abuse as the primary attack vectors. So attackers aren't necessarily breaking in. They're just logging in. So how does an MSP even know how bad this problem is inside their client environments right now? Well, a lot of times it's tracked through rows upon rows of spreadsheets that maybe one guy owns and just continues to update.

[00:07:01] And maybe they don't, you know, maybe they update it constantly. Maybe they don't. Sometimes it shows up as issues with billing and reconciliation for all the tools and their stack at the end of the month. Maybe it shows up as sort of inflated service desk overhead. It's a problem that not a lot of people are actively like addressing with sort of a purpose built solution or like operationally really. But it can be more serious too. I mean, you can be looking at data corruption and exfiltration.

[00:07:27] You can be looking at expensive incidents and legal consequences and even client churn. So it can look like a lot of different things. But those are kind of just to name a few. Gotcha. Now, what was interesting is I was looking at a particular kind of law firm example. Like a client has a phishing event. Defender gets triggered. But the malware still gets evaded. And the first question the MSP asked was we need to install our RMM before we can't even touch this.

[00:07:53] The community's take on liability for environments was real concerned about ones they can't fully see. Where does the access governance gap create legal and contractual exposure for MSPs that they may not even know they've accepted? Yeah, I mean, it's a good question because any sort of, I guess, legal consequences are not good for MSPs, obviously, not conducive for business.

[00:08:24] And a lot of that, I mean, most of the time if there's, you know, some sort of incident where authorities have to get involved, courts and regulators will come after the data owner. So typically it'd be client. But where that gets messy is contractually if an MSP has, you know, endpoint protection or something that they promise in writing to deliver and the incident can be traced back to some sort of breach of that, then it starts to fall on the MSP.

[00:08:51] And then you add in anything like reputational damage, any overhead that the MSP absorbs in order to remediate and just the costs all involved in going through that process. It can create a lot of issues that, frankly, you know, with the right sort of operational and best practices implemented can be avoided.

[00:09:16] I will also highlight that neither of us are lawyers and we want to make sure that we encourage everyone that when you're looking at your master services agreement, make sure that you do talk to your lawyer to make sure you understand that. But you've got to have an understanding of the technical liability before you even have that particular portion of the conversation. Now, I want to make sure it looks like our poll question got a little bit flipped. So I want to go ahead and put the next poll question up instead. So I want to pivot to see your answers.

[00:09:42] Go ahead and let's pull those response answers up so I can get a sense of what's going on from the community. There we go. So one of the things we wanted to understand is how are you currently managing client access across your clients? So go ahead and scan that QR code and we'll get some additional response there. Kyle, when you start talking to customers around this, like what are some of the answers that you're typically hearing about the way that they're starting to address some of these issues?

[00:10:12] So it's an interesting question because a lot of current MSP stacks technically have the capabilities to do this sort of discovery and remediation, but it's not a purpose built solution and it's not operationalized typically. So we start getting into like what does mature security posture in terms of governance look like?

[00:10:33] And again, like capability wise, you might be able to go in, you might be able to go into your spreadsheets, go line by line, see who has access to what. You might be able to even, you know, go into your endpoint monitoring system and see who's been logging in and what they've been doing. But that's a lot of different portals you have to go into. That's a lot of different training, especially if you're like taking on, if you're an MSP, you're taking on new hires. You're like, yeah, this is here, this is here, this is here.

[00:11:01] So it's not operationalized and it's not, it's sort of like fledgling in terms of its maturity level right now. Gotcha. Now I want to talk a little bit now, we're going to spend some time now talking about multi-factor authentication and why it isn't governance. And I actually want to give an example that I was tracking in the MSP community. We're actually looking at a genuine, this is an example I heard directly from the community. And MSP managing around 30 or so small Microsoft 365 tenants using phone call MFA.

[00:11:30] So Microsoft blocked the VoIP numbers for MFA without any effective advance notice. And now those tenants get locked out. Recovery taking days per tenant and the community really had feedback on there. A second global admin is required for that. And a way of dealing with it by having another authenticated method would have prevented all that. Now that isn't necessarily a security architecture problem. That's an access lifecycle management failure.

[00:11:58] I want to also focus that the community has documented a real standard benchmark here. Four global admin accounts per tenant. Two for ops and two for break glass. Many MSPs can't answer that question for their own clients right now. The tenant misconfiguration discussion here shows really how conditional access exclusions and temporary privilege escalations that never get removed become permanent drifts. So Kyle, I really want to say MFA is table stakes, right?

[00:12:24] Every MSP has already talked about it, has it deployed. So walk me through scenarios that you've seen where MFA is fully deployed and something still goes wrong because of an access problem. What does that look like? Yeah, actually, there was one in the news in the last couple of years that was pretty interesting. It was with Reddit. Employees getting phished with a fake portal and the hackers sort of sitting between that fake portal and the MFA trigger.

[00:12:53] So when they entered their credentials, the hackers were able to take their MFA tokens and gain access to their org. Now, luckily, the employees acted fast when they realized what was happening. They were able to minimize damage. And because these Reddit employees were probably appropriately authorized and governed, only limited contact information and advertiser information was leaked. There was no company card information. There was no financials. There was no financials.

[00:13:21] So that might have been an example of Reddit doing a good job of governing their employees' access and making sure that nobody was overly provisioned or had access to too much sensitive information. Gotcha. Gotcha. Okay. So the other thing I realized, there was another example that was interesting to me, and it kind of highlighted the difference between authentication and authorization. Right? So if you've got an example like something like a phishing event where MFA is deployed, the one we talked about earlier, and Chrome saved passwords, like, and that was the thing that was grabbed.

[00:13:50] MFA confirmed who the user was, but it doesn't necessarily control what they access or what's already accessible. Like, talk to me the difference between authenticated and governed. Yeah. So authentication is more just an added security layer, right? You know, it's asking, who are you? You pick up your phone. You get the six-digit code. Punch it in. And it's really just trying to establish an identity, right? Tie an event back to a specific identity.

[00:14:18] And authorization asks a larger question of, is this identity allowed to even access this? At what level are they allowed to access this? So having governed and documented access to the specific resources would be where authorization sits. So it's a level above authentication, I would say. Gotcha. Okay. Now, one of the things that I also was digging into was some community conversation that shows, like, a repeated problem, right?

[00:14:46] The idea of temporary exclusions and elevated privileges that really never get removed. You know, an MSP sets an exception during, say, onboarding or they need it during an incident. They mark it as temporary, and then six months later, it's still there. How does an MSP even find that in client environments, let alone fix it? Yeah, I mean, like, it's exactly what you said.

[00:15:13] I mean, there's so many examples of, like, clients, you know, of MSPs who maybe have a project. And, you know, departmentally, like, these department heads are making decisions. They're like, oh, we need this tool, that tool, this tool. This costs money, so I'm going to put my company card information here. And then once that project is done, once those tools are no longer needed, everyone just kind of moves on, right? And the access and the applications stay in your environment.

[00:15:39] You know, that sensitive information that you might have put into those tools stays there. And then everyone just kind of forgets about it. And it's hard to think of a specific example. Excuse me. It's hard to think of a specific example just because it happens so often. Right. It's not something that is, like, specifically being actively addressed. Gotcha. Now, another one that I was looking at is, again, a discussion with some of the community about managing, you know, they've got multiple clients.

[00:16:07] And they have lots of different identity stacks, right? So one was describing 12 different clients with wildly different, you know, identity stacks. You know, they're finding that in that environment, you can have anywhere between, say, 6 to 15-minute onboarding, offboarding. But some may take as long as 45 minutes and above to remove that out. So it ends up being process and visibility.

[00:16:30] Like, what does an MSP need to be able to see across their clients to call something governed rather than just sort of managed? That's a good question. Call something governed instead of managed. There needs to be explicit policies in place, I would say, outlining, like, defining users, defining their roles, defining what they absolutely need access to, and explicitly say.

[00:16:59] And then beyond that, there also needs to be guardrails, right? Right? So it's so easy to go out of policy if something's just in writing. Well, okay, but for this project, I'm going to need access to, you know, Atlassian or something else, right? Something outside of maybe my usual, you know, day-to-day. Let me just ask for access, right? It doesn't matter. Like, they'll grant it to me. I need it for this project. But again, like, that access just sits there.

[00:17:27] And so having not just in writing, but also it being enforced, maybe some sort of JML, joint remover lever automation that says, okay, like, you know, you're out of policy right now. You have access to these apps. You also have access to this one. This one's out of policy.

[00:17:44] You know, maybe schedule a deprovisioning or something around that so that you don't, you know, end up just over-provisioned and kind of succumbing to that access creep that really starts to create a lot of risk in your access perimeter. So when you talk about managed versus governed, managed may be, you know, oh, ad hoc.

[00:18:11] Here's a, you know, here's a spreadsheet of all of these different applications and who has access, you know, will manually update this and make sure that people are, you know, correctly provisioned. Whereas governed would be like actually putting controls over it. Gotcha. Okay. By the way, for you watchers, go ahead and make sure you put some questions there into the Q&A panel. We're going to be taking questions from the audience and I want to make sure to get you entered into the raffle to win your Amazon gift cards. We've got multiple ones.

[00:18:40] So go ahead and put your questions into the Q&A panel so that we can queue them up and get them ready here. Now, Kyle, one of the things that I've been thinking a lot about is, is trying to define the problem a little bit better. If you were sort of telling an MSP to where to start and where to like think about this problem first, like where are the places that you think are the easy first moves to get started? In regard to, could you elaborate a little bit on the question?

[00:19:10] Sure. Sure. I'm intentionally broad because I'm thinking about an MSP who said, hey, I've done MFA really well. You know, I've rolled out my MFA. I have some basics, but I'm having the problems that these guys are literally describing right now, right? And saying, how do they get their hands around thinking about that identity and access control in a more systematic way? I know you've probably, you know, onboarded a number of clients. Like how do you walk them through the process? Gotcha. Yeah.

[00:19:36] I mean, again, like I think ties back to what we were mentioned talking about at the beginning where it's a little bit of an invisible problem and you have to first demonstrate why this is an issue. Right. So a lot of our clients that we've worked with, you know, SMB mid market, sorry, MSPs that work with SMBs and mid market where, you know, standard operating procedures around access governance and identity governance are sort of a mixed bag. Right. Right. You might have some standard operating procedures.

[00:20:06] You might not. And standard operating procedures around that might be, you know, again, manual spreadsheets and, you know, just people up, you know, that one person owns and people updating it as they find new things. Right. So one way that we do start kind of outlining and really exposing the problem to our clients is through a discovery assessment.

[00:20:28] So an example of that would be one of our clients, Ebo, 150 person marketing company managing, you know, they came to us, they were managing roughly, you know, 24 applications or so doing, you know, manual work to gather all this information for their quarterly audits.

[00:20:48] And, you know, and their business reviews.

[00:21:18] That are being unused and unallocated, like unallocated, underutilized. And then that was kind of like a door that was open to us being like, oh, and by the way, here's everything else that exists in your environment. Did you know that you had this? And here's all these people who are logging in. And that's when they kind of bought in and they were like, OK, like this is a challenge that we need to actively address.

[00:21:40] And so we were able to create access policies for them, create automations around them and be able to get them closer to what is sort of mature security posture in regard to access governance actually looks like. Now, you said something that was interesting in there that I think I want to want to hear a little bit more about, because we want to also make sure that we're making this relevant for clients. The way they described that was also about cost savings.

[00:22:04] Are you finding that linking it to cost savings is part of the best way to bring customers on board with governance? Like, talk me through how that process works. I think everyone has different triggers when it comes to, like, you know, what makes me care about a certain what what really gets it through my head that this is a serious challenge that we need to tackle cost savings is definitely one of them.

[00:22:26] I mean, I can think of another example where we were able to identify like forty two thousand dollars worth of of of unused SAS that was sitting on the table that we were, you know, they were able to identify with. By doing some adequate discovery and, you know, have those sort of awkward conversations at renewal with the, you know, SAS providers that they work with like, hey, we need to downsize a little bit. So cost savings is definitely one of them.

[00:22:55] And it's kind of the easiest thing to like prove, you know, like ROI on. The other thing is, like, if you're in a more regulated environment, you know, a.k.a. anyone doing business in the United States of America, it's it's it's also about risk reduction. Right. You don't want like you want to be proactive about these things.

[00:23:14] You don't want it to be something where, OK, I care about this because I had an incident where, you know, someone had unfettered access, you know, a disgruntled employee had unfettered access to, you know, core business applications. And I can think of an example right now. IT consulting company, NCS, they had a former employee who got laid off. And then three months later, 180 virtual servers of theirs disappeared overnight.

[00:23:41] Right. And then sort of the postmortem, they realized that this guy had accessed business critical applications six different times as writing scripts, identifying vulnerabilities and then just basically gave them a six hundred thousand dollar endowment problem. You know, that they had to find out after the fact. Right. Whereas if they were able to, you know, adequately monitor access and govern access beforehand, they might not have had that issue.

[00:24:07] They might not have, you know, taken that reputational hit and they might not have, you know, been six hundred thousand dollars in the hole. But, you know, hindsight 2020. Now, you said again, you said something that I want to want to hear a little bit more about. I'm with you philosophically on the idea of like everything is a regulated industry, but not all regulated industries are the same. Right. It's a little bit more of a spectrum. Like walk me through kind of the different ways that you think about that, perhaps from sort of the the the least regulated to the ones that are most intense.

[00:24:36] Like how do you think about regulated industries? I mean, so let's use like health care finance, for example, or gov, for example. Right. Those have very strict, very specific controls, you know, that they that they I guess. What's the word I'm looking for that they ask for? Sure. You know, regarding logical access, regarding, you know.

[00:25:04] Certain networks that, you know, some of their data is not allowed to touch, that sort of thing. And so when you think about those sort of very high, like those are like prime examples, highly regulated industries with specific frameworks, specific controls that, you know, probably require at least a yearly audit, if not like, you know, quarterly.

[00:25:26] And that can kind of represent a lot of labor overhead, getting ready for those audits to be able to present evidence and make sure that, you know, you're in policy. It is a spectrum, too, though. You know, not everything is super highly regulated. You know, I think the main things are SOC 2 and ISO. Right. So, you know, just being able to prove that you have business practices in place and controls over that.

[00:25:53] And at a very basic level, that's what access and identity governance are, is putting controls over your business operations or IT operations. Gotcha. And I'm assuming you've got some thinking on the way there are particular frameworks or ones to align to, particularly, you know, working with Joseph, you guys have focused on. Like, how do you approach the framework question? How do I approach the framework question?

[00:26:21] Okay. So, I would say most frameworks require some sort of evidence that these, like, obviously, you know, you got point by point, like, you guys need to do this, this, and this. There needs to be these controls. You need to prove that they're being enforced, that sort of thing.

[00:26:43] And so, I guess, like, how we address that at Joseph is we are in the area of being able to say HIPAA for logical access is a big thing, right? Is someone provisioned to, you know, were they adequately provisioned to the tools that they needed to do their job effectively? Did they have the data available to them so that they are able to, you know, do X, Y, Z, help their patients, whatever?

[00:27:11] Um, so, where we would come in there is we would say, yeah, like, you know, this tool here is tracking events, including provisioning and deprovisioning of access, right? So, on demand, you're able to pull, like, was this person provisioned in a timely manner? Yes, they were provisioned on this date. They joined the company on this, at this time. And so, we're able to prove that with on-demand reporting, right? And that's exactly where you want to be.

[00:27:36] You don't want to be scrambling for receipts when, you know, an audit comes up or when you, you know, you're in a situation that's urgent and you have to find it, right? You want it to be readily available so that you're able to produce that evidence and, you know, prove that you're in policy, you're in control. I feel like there's a story there. I feel like you've got an example of somebody who's done something in terms of pulling the right set of information or being able to document something that illustrates your point.

[00:28:06] Have you got a really good example of somebody that's done that? I don't have an example specifically of the thing I just mentioned, but I've read a lot of different just kind of horror stories of, like, we had to drop everything because, you know, we had to find all of this different paperwork and all of these different sort of receipts claiming that all of these different people, you know, had access at this specific time.

[00:28:33] Um, so that can look like 300 hours of labor for an MSP service desk if it falls on ultimately on the MSP to gather that information, right? And a lot of times, like clients work with MSPs because they don't want to take on sort of like IT is a very specialized and cyber security are very specialized. Um, and so they're relying on the MSP to be able to get them through this stuff.

[00:29:03] Um, and so maybe the MSP will get like a, you know, a message or a ticket that says, hey, like we need this information in, you know, a week. And they're looking at this and they're like, okay, this is like 300 hours worth of work that we've got on our plates right now. Like, you know, uh, I'm not going to be able to have dinner with my family. Uh, you know, I'm going to have to work late on a Friday to get this, to try and, you know, scrounge all this information up.

[00:29:24] Um, and so I'm more so speaking, uh, kind of broadly of like these kind of anecdotal stories that I've heard from various different, uh, sort of spots, um, in the space. Gotcha. Now I would think that some of the way that you've approached the, you know, the, the being able to do the logging and the reporting and stuff like that. I would think that you've got areas where you can do a really nice job of streamlining onboarding or offboarding. Can you walk me through like one of those, those, one of your favorite examples around that?

[00:29:52] Yeah. Um, I think I'm just going to go back to the Ebo example. I mean, you talked about onboarding and offboarding, you know, typically that's like a 45 minute to two hour long process. Um, you know, and, and part of access and identity governance again is setting those policies and then setting those controls and those controls, those guardrails are automations.

[00:30:14] Um, and so with Ebo, we were able to set up, uh, onboarding and offboarding automations that basically slashed their, um, you know, their onboarding and offboarding ticket overhead time from like 45 minutes to just a minute or a click of a button.

[00:30:30] Gotcha. Well, that, that's the kind of thing is, are there other areas where, where like in particular you found you've been able to do really good job with helping MSPs save time or improve their process other than the typical, we think immediately of onboarding and offboarding?

[00:30:45] I mean, the other thing is like part of, uh, operational maturity is being able to scale without adding headcount. Right. So, and part of identity governance is again, like being able to get you closer to that stack maturity, that operational maturity. Um, you know, you shouldn't have to be scrounging around for, you know, through different portals whenever there's an offboarding happening.

[00:31:11] It should ideally be all under one umbrella, all controlled, all governed, and, you know, through the central nervous system that is your, you know, access policy. Um, and so, yeah, like kind of the obvious, you know, that comes to mind is like we say, you know, saving time, uh, on onboarding and offboarding. Um, you know, and then the other thing is, uh, kind of in a more indirect way, um, QBRs, right.

[00:31:39] I mean, a lot of times, you know, for MSPs, you can kind of fall into a trap of like these just being sort of tactical laundry, like tactical touch points where you're talking about like a laundry list of, you know, uh, oh, we did, you know, X, Y, Z, you have this in your environment. Um, and being able to sort of operationalize your identity governance, uh, puts you in a spot where you're able to be a little bit more strategic in those touch points.

[00:32:05] And be able to, I guess, because one of the things that we talked about again at the beginning was like, this stuff is invisible a lot of the times, you know, um, and the truth of the matter is, um, a lot of clients don't really understand what the MSP is all doing for them month after month.

[00:32:25] They just know that the lights stay on and that things work properly. And so it's kind of hard to, uh, for an MSP at times to say like, Hey, this is the value we're providing you. And so essentially doing that and being able to like point to specific numbers and KPIs that you were able to sort of deliver or over deliver on, um, is a massive value add in those kinds of QBRs and touch points.

[00:32:52] Um, and it allows you to also save time so that you can make them more strategic, right? They're not a laundry list of items that you need to take care of anymore, right? You've had time. You can actually think about like your relationship with an MSP or your relationship with a client is more of a strategic business relationship rather than like a break fix. Um, you know, like let's make sure the lights stay on, uh, you know, transaction. Right now we're, we're, I'm going to make sure to remind our audience, you've got questions, throw them in the Q and A because we're going to be moving to that in a little bit.

[00:33:20] Now Kyle, we've done a really nice job both of talking about the problem and you've given some examples of how like addressing it. So, but I think we do need to actually talk a little bit about the widget as I always described. So just as some particular solutions here, talk me through what your tool set does and what the solution does to help MSPs address these problems. Yeah. So, um, I think of it as sort of like a, I said, I use the term central nervous system earlier cause I like that word, but yeah,

[00:33:49] that's what it really is when it comes to your identity governance. So it starts with access policies, whether, you know, you're an MSP, you have a bunch of clients. Some may have standard operating procedures around who needs to have access to what some may not. It puts structure to that and codifies it in a way where you can then enforce it with automation, with alerts, if people are outside of policy.

[00:34:12] Um, and so basically giving, uh, MSPs, uh, a very proactive way to manage a, uh, a growing invisible problem and be able to define it properly, be able to also talk to their clients about the value that they've been able to bring to them with, uh, you know, in terms of securing their access perimeter,

[00:34:35] um, and delivering and over delivering on some of those, uh, you know, high volume service desk tickets. Um, so it's the central nervous system of who has access to what, who should have access to what and why, and then enforcing it with controls. Um, well, that, that makes some sense. Now I'm starting to get some flow questions. I want to start pulling them up here a little bit, but the, but the first one that came to mind based on what you were saying, and I was, uh, and I noticed this in the conversation myself. So give me a little sense of AI here.

[00:35:05] I've managed to go a good portion of the webinar without using it. And I wanted to set a new record on that one, but I think it's worth bringing into this conversation. Are there areas where AI is going to be influencing the impact of the MSP or making it more difficult on the client? Tell me a little bit more about, about what you're thinking is there. Absolutely. I mean, AS, AI is a, is a powerful, powerful thing. And in that sense, it's kind of double-edged, right?

[00:35:30] One, it increases the amount of, of, of threats that, you know, MSPs in, you know, in cybersecurity orgs have to deal with, right? I mean, you talk about AI identities. Um, it's, I kind of compare it to like, we're, we're, we're a SAS, we, we address SAS sprawl and identities in the SAS space, right? But now you have 30, some odd AI identities crawling around in your, in your environment as well.

[00:35:59] And that's sort of like the next, you know, uh, the next evolution of identity governance, right? It's not just governing, uh, identities with regard to the actual users and the people in the environments. Also mapping out, uh, AI identities and agents that may exist in your environment and are accessing, you know, God knows what, um, and then putting controls around that.

[00:36:23] So, um, that's sort of where we're looking next. Um, and I think that that is the future of, uh, of identity governance. And I think it's going to become more and more important because it's kind of the wild west right now. I mean, that is something that's absolutely, I mean, it's being tracked probably in, in a very minimal, you know, amount of environments in the modern space. So. Gotcha. Natural fit too, because a lot of the AI is delivered out of the cloud. So it fits nicely with the, the sort of SAS bit.

[00:36:49] I want to start going ahead to take some of the questions that the first one I want to pull up and it's around specifically around people, the way that they're thinking about it. You know, if someone is already, uh, looking at the access account problem, you know, how do I even know that they've got the access account problem? Like in their clients right now, what should they be auditing first? Like where's that, where's a really good place to start with the audit? It's a good question.

[00:37:13] I mean, if you don't have a purpose built tool in place, um, I mean, kind of like what, uh, you know, orphan accounts might look like, you know, on the outside is a mysterious recurring charges to a company credit card or urgent Monday morning tickets, or maybe just like clients reaching out being like, uh, Hey, you know, so-and-so who left the company or was a contractor, like their account's still here. Like they have credentials.

[00:37:43] Um, and so I guess like in terms of what you should be auditing for, uh, take a good look at your service desk ticket volume, take a good look at, uh, you know, the charges that your, your cards are receiving. That would be the place to start if you don't have like a purpose built tool. Uh, right. I mean, you can't just, it, otherwise it's kind of just guesswork, you know, you're going into every portal, looking at all the user lists, like very, very manual, very time consuming. And we certainly don't want to be, be guiding people toward guesswork.

[00:38:12] We want to actually have an audience. So that, that's a good set of places to be. So our next question up, I want to get a little bit sense because somebody is worried about like where they've been discussing. So Joe's been asking, like, he's been saying clients to clients that MFA and defender is enough. Well, is Joe wrong? And if so, how do you, how do you broach the question of going beyond multi-factor authentication and defender as a solution because you've already been selling one position?

[00:38:39] How do you advise MSPs to move into these new offerings without kind of undermining the trust they've built so far? Let's see. I've been telling clients, am I wrong? Yeah, you're not wrong. I mean, that's, again, like, like, like Dave mentioned at the, you know, towards the beginning, like, like MFA is, is table stakes. If you're not enforcing MFA, I mean, it's, it's the bare minimum and, and the bare minimum is not a bad thing. Like that's what you should be doing. Like that's foundational level, you know, cybersecurity practice.

[00:39:09] Um, I would say, I would say identity governance, uh, you're not wrong, but I would say like, it depends on the client, right? Like it depends on their needs. It depends on what, you know, they care about. A lot of times, like if they're a smaller, maybe a startup, like shadow, a, shadow, a, I can accelerate your, your growth. You know, that's, it's innovation. That's, that's finding new tools. That's finding better ways to do things.

[00:39:33] But if it's like a larger client, you know, and you're getting a lot of tickets from them and you're like, Hey, you might want to have a conversation with them and be like, Hey, like, let's take a closer look at this. You know, let's, let's actually see what you're working with here. Like who, who is, you know, who are these, you, who are your users? Like, who, what are your tools? Like, let's, let's, let's get that kind of under control. Right. And the other thing I think this is worth highlighting is, is that this is all risk management. So you're never wrong.

[00:40:02] It's about a level of risk management that you're comfortable with. And the threat landscape changes. The hackers continues to get more, more aggressive. They're looking at new methodologies. We weren't talking about them seeking out previous credentials and breaking in five or 10 years ago. This is, these are threats that emerge and we have to respond to those. Keep those questions coming, put them in the Q and a panel. We're going to be entering for multiple of those Amazon vouchers. So just throwing in a question will give us something to work with, but I know we've got a couple more already in the queue.

[00:40:32] So I want to throw one up here again to, to, for our next question. You know, Murray's asking, like, tell me a little bit about the, you know, how, how do you price this? Like, what are the ways that you look at pricing governance as a service? Like, how does that really work? Kyle, have you got some thoughts on the way this gets integrated into an MSP's existing services or prices, new services? Yeah, there's a lot of ways you can sort of slice and dice it. One way you can look at it is sort of a margin protector, right?

[00:41:01] I mean, you, you, you talk about being able to put controls and automation into places that, you know, may or may, may be inflating your costs without you really knowing whether that's, you know, in terms of overhead or in terms of billing. So you can look at it as a margin protector.

[00:41:20] You can also, this is a really great opportunity to kind of have as an MSP differentiate yourself because, again, identity governance is a relatively like emerging sort of area of cybersecurity. And it's growing in importance. You know, everyone says access is the new perimeter or whatever. And so this is a really good opportunity from like a sales perspective, a revenue perspective to look at a new way that you can package something for extra value.

[00:41:50] I talked to some of my clients about creating SKUs around identity governance as a service and how they can kind of price that out as sort of a premium, you know, package for or an add on for their monthly, you know, managed service delivery and IT monitoring. So there's a lot of different ways you can do it.

[00:42:10] It just kind of depends on, you know, how cost sensitive your customers are, who they are and, you know, how much appetite you have for kind of changing, you know, adding, you know, trying new things. Gotcha. I think there's a follow on question that makes a ton of sense as I'm watching. Chris has got a particular question here about like with the changing of threat landscapes and the associated charges.

[00:42:36] Like how do you approach clients to increase pricing around this when they're already paying for a package that is about protecting the network? Like are there particular ways that you've looked at having that discussion about increasing prices around security? I have had discussions about that.

[00:42:58] It kind of goes back to really proving a problem that is, I keep coming back to this, but it's invisible. Like, so I guess like everything you can tie back to like a threat that you remediated and the cost associated with that, make it, put it in very blatant terms.

[00:43:24] Right. Like, you know, for instance, if you're in like in a competitive sales cycle, right, if you're if you're an MSP, you have a client, they're in a competitive sales cycle. They're trying to win a big customer. They need to be insured that, you know, you have your perimeter locked down. You're not going to, you know, you don't have any, you know, you are mitigating as many as much risk inside of your environment as possible, maybe because, you know, you're storing sensitive data or whatnot.

[00:43:56] An avenue might be saying, you know, you're able to now, you know, with this add on, prove that to your potential customer. And then that way you're tying it back to actual like real life business value and real life business outcomes that the client understands. Right. Because at the end of the day, you can talk about cybersecurity. You talk about endpoint management. You can talk about access as the new perimeter.

[00:44:23] But the client really just cares that they're able to run their business and grow it. Chris, I think I'll add to Kyle's answer there and tell you that I think from the perspective of continually evaluating, I think, first off, go back to the fundamentals of managed services. You should be raising your rates every single year. Like, I think that is a fundamental of managed services that I've been saying for over 20 years. Carl Palchuk from Swalovist, thoughts say the same thing.

[00:44:46] So you should be looking at it that way. And as part of that conversation, particularly from a security perspective, you will have a reevaluation conversation with your customers every single year. And by doing so, that gives you the opportunity to reevaluate what their tolerance for risk is and address it with solutions that way.

[00:45:05] So part of it isn't just necessarily a straight price increase on the security, but you're going to say, hey, these are the threats and the new things that we're dealing with and the requisite service that goes along with that. Kyle, does that fit with some of the conversations that you've been having with MSPs? Absolutely. You should you should be you should be, you know, again, and it kind of goes back to continuously, like being able to demonstrate the value that you're providing.

[00:45:31] Right. And then so that when those renewals roll around, you're able to have those conversations and you have a little bit of wiggle room because you're doing a lot of work for your client. Like you're keeping the lights on, you're making sure that, you know, you're not just a break fix shop shopper them. You're you're you're a business ops, you know, strategic partner. Right. So just plus one to Dave there. We're trying to we're trying to bring some real value here today.

[00:46:00] So I'm going to take one more last question here I want to address. And it's from Joanna talking about client size. Is there a particular client size where this changes? You know, some MSPs like Joanna's will have clients with 10 seats and clients with 200. Should you be thinking about that differently? Is it the same problem everywhere? How do you frame that? I think size definitely plays a part.

[00:46:28] Again, you also have to look at other things like industry. You know, if you're in a more regulated industry versus a less regulated industry, size definitely plays a part. I mean, you know, with a with a client, that's 10 seats. You know, obviously visibility is still going to be an important thing. You still want to know what's going on, you know, in your SaaS environment. But typically where it becomes most valuable is above that 50 seat mark, I would say. Gotcha. Makes sense.

[00:46:57] Now, I know we could do this all day, but I want to be respectful of everyone's time. Kyle, if people are interested in taking a look at the solution and getting and booking a demo, what's the best way for them to do that? Yeah, go to our website or scan this QR code up here. And we can schedule something, get something on the books. You know, would love to be able to connect with anybody who's interested on this. Perfect.

[00:47:26] And I know you've got you want to talk to MSPs out there if they want to talk a little bit more about some of the business challenges or or understand a little bit more of what you're up to. How can they reach out directly? Yeah. Connect with me on LinkedIn. Shoot me an email at Kyle dot B at Joseph dot com. Those are the best ways. I'm, you know, I'm always looking at my email, my LinkedIn throughout the day just because, you know, always trying to just shake new hands, meet new faces and learn more about the MSP space.

[00:47:54] So I would love to connect and talk about, you know, any business challenges that you have and, you know, how we might be able to provide some value. Well, you know, that's the best way these days to continue the conversation doing so on LinkedIn. Kyle, really appreciate you having the conversation. And thanks to the Joseph's team for making this happen. Produced by Picture This Video.

[00:48:22] Part of the MSP Radio Network. So don't you try those things because of its background. For more money that quick cannabis, you're agreeing to make money forander,