The cybersecurity industry loves to sell tools. What it rarely talks about is the hard work required to make those tools effective. In this episode, Jim Harryman joins Chris to challenge the idea that technology alone creates security. They discuss why mature organizations focus on governance, accountability, documentation, policies, review cycles, and operational discipline long before they look for the next shiny solution. If you've ever mistaken a technology purchase for progress, this conversation may be the reality check your organization needs.
[00:00:06] Welcome to MSP 1337. I'm your host Chris Johnson, a show dedicated to cybersecurity challenges solutions, a journey together, not alone. I'm joined this week by Jim Harriman of Kinetic Technology Group. Jim, welcome to the show. An hour with you man is always a pleasure. Well, let's try to keep it less.
[00:00:37] We've had these conversations over and over and over again, not on the show, about measuring progress, measuring maturity with our cybersecurity posture. And you and I have had extensive conversations with others around how do I know when I'm actually making progress? How do I know, how do I maintain accountability? What are the metrics that I should be using to determine good versus bad?
[00:01:04] Or even a better way to say it, and this is what you and I were talking about earlier, is how do I know when I'm starting to shift away from what is good long before it becomes bad? Because we're all going to eventually drift in and out by the very nature of the change in the threat landscape, the change in our technology, the change in our staff. There's so many things that impact as we navigate this path.
[00:01:29] And I was just curious, you know, to kind of maybe share it with the audience of like, what are things that they should be doing to help better understand not only where they're currently at, good, bad or otherwise, you know, what's the risk posture that they've accepted or have unknowingly accepted without looking? So versus like, how do I start working on shifting it to an alignment that I am comfortable with as an organization? Sure.
[00:02:00] Sure. I think the, yeah, I think the biggest thing that especially just in our industry, largely is that we're way too dependent upon tools and services and things of that nature. But, you know, to me, the best investment to me is not a product or a service or a tool. It's a process.
[00:02:30] Right. Okay. So the, you know, I mean, you're going to have help from these services and tools and things of that nature, but fully relying on them and whatever, you know, golden, you know, award that they are, whatever it is that they're going to the prize at the end of the rainbow pot of gold. Right. Yes. That they all offer us, you know, they're going to solve all our problems.
[00:02:57] Really, they don't and they probably never will. Sure. And we have to just constantly maintain and developing the process is really the thing and continually tweaking that process within our organization. Our, our, our program, our security program, whatever that looks like for your company, that is going to be an ever evolving maturing process.
[00:03:25] And so that's, that's where I view it, I think, for us just really getting started and I realizing that we couldn't depend on the, the tools necessarily to, to make things happen for us.
[00:03:43] That there was going to be work for us to do in this regard and that it was going to be ongoing and that we were going to have to figure out how to incorporate that into our new operational mode. Right. I mean, it w it was a, a conscious decision that was made knowing that we were going to have to do it and it was going to take resources and we were going to have to, you know, take, have some pains along the way. Yeah.
[00:04:12] But it, that, that's really for me, that's kind of what, what it's all about. Well, I think to what you said, if I think about all the pieces that go into good governance, because really at the end of the day, your process and procedures, your, you know, policy process procedures tools, all that equate to the more dialed than they are, the more you can see staff alignment with it.
[00:05:06] That's what I think. And I think that's what I think about the, which is, if the person I'm telling the ultimatum to doesn't understand the why they're immediately going to be defensive. You're, you're hurting something in their process. That was what you hired them to do that you've now impeded their performance, even though there may not be any impeding happening at all. I mean, that's, that's very true.
[00:05:27] I mean, the, the, the burden of the things that we have to do and maintain having a security program in place, it does change. It changes, it changes workloads, it changes schedules, it changes all kinds of meetings. I mean, report, I mean, documents and meeting minutes and everything else that you, you know, do and you put into place.
[00:05:57] I mean, it is, it is all a, a drain on, on your resources. And so, you know, you, we did, the thing is that for us, we've been doing this for almost a decade now. And so it's, initially it was really, really tough. Yeah. You know, we had, we had some blowback from the team members that we had at the time and some of them aren't with us anymore.
[00:06:26] Some of them still are. But I think that the people that got it and as our culture started to change internally, they realized that, you know, look, we're, we're really, you know, we're focused on maintaining our ability to be in business, you know, for the long term. We're not short sighted, we're actually looking towards the future.
[00:06:55] And, and I think the people that they got that stuck around and said, you know, I understand that, that this is part of my responsibility now. This is, this is, you know, an important part. And matter of fact, it might even outweigh some of the other things that might be more client facing that we do. It sometimes have to have, has to outweigh that. Right.
[00:07:20] So you just, it's a balancing act for sure that we have to play, but I, it's definitely achievable. Um, but you, you've gotta, you've gotta generate the right, uh, culture and excitement about what you're doing. You know, to, it's not just, uh, we're doing it because we, we have to, or cause we don't. Nobody has to do this in our, in our industry. Right.
[00:07:48] I mean, they, they, they probably should, if they want to survive another decade in this industry, but, um, you know, it's not like we have to, but it's, it's, we, we do need to, you know, and, and we should want to, I mean, it's, it's really the, become the foundation of what we do.
[00:08:11] You know, it's changed. It has completely changed as you know, over the years, been around a long time too. So, you know, it is, it is the new foundation of, of, of everything. It's no longer, you know, can you put in and support a firewall and do AV and all that other stuff we've talked about before. This is the foundation now. Well, you mentioned the drain and the strain, and I was thinking about that as you were describing sort of some of the, the maturity challenges.
[00:08:38] And what comes to mind for me is when, when the client asks you to solve a problem or challenge. In fact, I shared one with you earlier. I'm like, if you've got a laptop that's not working properly and I spend 20 minutes time trying to kind of do a precursory troubleshooting. They're like, oh, by the way, we had a power surge that happened when this suddenly occurred.
[00:09:02] You're like, oh, that would have been a really good piece of information to have shared with me. And I think that goes hand in hand with what you're talking about with that strain and drain, right? Change management. Well, what do you mean I have to schedule the patch or the take the server down? I can't just do it. Or what do you mean no one is, why do I have to document what we did to that machine yesterday to make sure all the updates were current?
[00:09:29] It's like, well, if you don't document that, then when I come in to troubleshoot whatever's not working, I have no, I have no data to inform me of what might have changed since it was in a good working state. Like, well, what did it work yesterday? It did. Okay. What time yesterday did it stop working? Well, I don't know. Right.
[00:09:49] And if I have the documentation to show me what has occurred, and I think this is one of the first big steps that MSPs start to take from a maturity standpoint, because when you have automated patching, that data is automatically logged. Right. Versus I manually patch something, and I now have to dig to see what actually happened because it's not going and telling some other system or reporting on it that it happened. It's just what I've done.
[00:10:17] And I think that when you start talking to MSPs from a maturity standpoint, you ask questions around that. Like, well, yeah, but we're a small shop. It's like, okay, well, what happens if you're saying that internally change management isn't important, but if I describe the problem that you have with a client and you're like, yeah, I hate it when that happens. Well, why are you causing yourself grief internally, but getting upset about it when it happens with your clients?
[00:10:45] Well, we can we could spend a whole you could probably have a year's worth of podcasts about, you know, why why clients are upset about whatever. Sure. But, you know, I had the the the the change management is a yeah, I mean, I think that that's an area that that we all that we all struggle with.
[00:11:10] And what's interesting to me, you know, having come out of, you know, corporate it and, you know, back in those days, I mean, we did follow like it, I L kind of guidelines and things like that, where we were, you know, we had a it process that was kind of like a framework.
[00:11:30] It wasn't a cyber security framework, it was just like, right, this is, this is how you do it, right? This is how you, you know, do all that kind of stuff. And it's like change management was a big part of that. And I think that it's also one of the things that largely we struggle with, as as MSPs, you know, is that and and tracking that and how we do it effectively.
[00:12:01] And how we communicate that stuff and people knowing where to go to make sure that all that, you know, it is, that is a that is a struggle. And it's honestly still struggle for us.
[00:12:13] I mean, we're constantly looking for ways to improve that aspect of our business, because we're finding, you know, the the more mature that we get, the more holes we find and we're looking for better ways to do it.
[00:12:31] But but sometimes the better way takes a little longer, you know, and all of a sudden you see efficiency start to to to drop and and you're like concerned, okay, we're not as efficient. Okay, well, it's temporary, because the things that take longer, usually, it's just because, okay, now I have to do this, this, this and this, right, go back and look at how long it took you to do something before it actually took you longer.
[00:13:00] Right. Right. I mean, and that's, that's, it's usually, it takes longer at first, it's, it's uncomfortable, as any changes. But, you know, we just continue to try and improve that but that is a huge area that I think we're, we, we lack in, generally.
[00:13:18] Well, you remember the first time, you know, you, you were troubleshooting a problem, you googled it, it was pretty, you actually found something that was pretty clear and concise is like, step one, do this, and kind of stepped you through a process. And, and it did, in fact, fix the problem. You're like, wow, that was really slick. When we first started doing that, most of us didn't then take that information and put it in a knowledge base to say for future use, you don't have to Google this anymore.
[00:13:49] Here is the answer to the problem. And still to this day, I don't know how many times someone says, well, I just went and Googled it, and I was able to fix problems. It's like, yeah, and you put in the ticket fixed. But you literally did a whole bunch of work that if you were to have recorded that information into the answer in the ticket of saying what you did, is saving somebody else in the future, feasibly you again, from having to, you know, start building the wheel all over again.
[00:14:16] Sure. Yeah, I mean, it's like, we've got all these, again, going back to tools, you know, whether we have a, you know, we have PSAs and ticketing systems, we've got documentation systems, we've got all these things and all the stuff that we pay for. Sure. That is highly underutilized. Right. And if you use more than 10% of it, you're in the elite category. I mean, exactly. Yeah, that is scary.
[00:14:45] I mean, I've learned a lot on the documentation side, our team has learned a lot over the last, you know, several years about, you know, we thought we were great at documenting something until we, you know, were working with a much larger organization in our space and saw how they were doing things. And we're like, oh, wow. Yeah, that's, this is mind blowing.
[00:15:14] How, you know, this, this is actually using this tool the way that it was intended to be. And we're just, we weren't even scratching the surface. And so it really changed our whole mindset about how we were relaying and documenting information about internal things, about our clients, about everything else,
[00:15:36] to where it really is becoming a key piece of what we do. Yeah, it's, it's just there, but I mean, that doesn't have anything to do with the security aspect of it, but it is, it is about just maturity in general. And I think that that is, we should always be looking for ways to improve.
[00:16:01] I mean, that, that is ultimately the, the, the key statement, I think. And as we put it into security, if you don't think you need, or if you don't think you can improve, or if you think you've got it all figured out, you're wrong. Right, right. How do I, how do I bluntly put this in a nice way?
[00:16:24] No, you know, it's, it's funny because, I mean, we've talked about maturity pretend, particularly when it comes to, excuse me, how we address doing things. Like, so it's really easy to say, okay, I address the standard or the control by doing X.
[00:16:44] But when you look at it through the lens of like, I adopted this best practice today, yes, it's feasibly a best practice, but tomorrow it might not be because there's something that's still better or can be done to, to reduce the potential compromise. But what's interesting collectively isn't about how well you've implemented it the first time.
[00:17:07] It's about the ability to show evidence of how often or a cadence that says, I reviewed it to see if there was an opportunity for us to improve upon it. And if that improvement was beneficial to our company, because in some cases, obviously, the financial burden or some other things might not make it so. But if I looked at anybody's overall, say the dashboard of what is the, you know, your, your source of truth, I would go in and go, oh, well, that's interesting.
[00:17:37] It looks like here you haven't reviewed these policies in three years. That's not optimized. That's not you, you know, you know, adhering to a best practice. That's you just saying, I did something previously and it's done. And, and I think that's the area that I think all of us can say we are either in trouble, have been in trouble, or potentially will get into trouble because we allowed that one key metric to become stagnant.
[00:18:07] It wasn't important enough. Something else took our priority away from, I didn't check the backup logs. I didn't fill in the blank. And that tends to be where the bad things end up showing their face. Sure. No, I, I agree.
[00:18:22] I mean, having gone through, you know, I mean, what really pushed me down this road and knowing about myself and I've said it a thousand times, if not 10,000 times, and at least twice on this podcast. Over time. Over time. Yeah.
[00:18:40] I know, I know that if left, left up to Jim Harriman, that if it was solely on me to do something that I, you know, it probably wouldn't get where it needed to be because I would, I would prioritize other things. Yep. And as you probably should. Exactly. I mean, it's just, it's just the way it is.
[00:19:05] I mean, you, you just, you do it, you, you put out the fires and you just keep going and you're, you're doing whatever you do. Until I, until I engaged with a third party to come in and basically hold me accountable. Right. There was, there was really, there were things that were happening, but they weren't, it wasn't a purposeful. We, we call that ad hoc. Right. And that's a nice way of saying reactive.
[00:19:33] It was, it was not a purposeful endeavor. Yeah. And so once I did that, I actually brought a third party in, we, we decided to go after SOC 2 at the time and actually just completed our like sixth SOC 2 audit. Right.
[00:19:50] So, I mean, it's, it's, it is, it is a way for us to get accountability and, and, and keep us on track, especially when we do the type two, because they are going through not just a date in time, but they're going through a span of time. Making sure that we are consistently doing these things. Right.
[00:20:14] And so that, that is to me what, what really got, kept us, it has kept us in line and it's, and it's, for me, it's been worth every penny to go that route. And I, I think that that is, you know, ultimately the way to go. Now, there are other ways to do it and there are other people way more disciplined than I am. Okay.
[00:20:39] And, and that is, that is a, a good thing because I mean, you, you know, with the trust mark, I mean, that I love the trust mark and have gone through that process and plan to continue to, to do that as well. And so I think that that is a great place and, and it's a community and it's there for you to, you know, the help is there. The support is there.
[00:21:06] Everything is, you know, you got a question, they have answers, you know, and if Chris doesn't have the answer, he knows somebody that's got the answer, you know? So it seems to be the case. I know a lot of people, so it's been very helpful. Ultimately, I do feel like the, the community aspect of it, whether you're engaging with auditors, you know, another third party coming in, whether you're engaging with it, with GTIA, whether it's a peer group community, you know, some level.
[00:21:35] I mean, our peer group started basically a cyber security accountability group when we were all chasing CIS. And it was a group of people that were just holding us accountable to that. Almost 10 years ago. Exactly. That's, so, I mean, that, but that kind of stuff is, I really feel like, and we've seen some, some great success stories come out of, of everything that I just discussed.
[00:22:04] And I, I think that ultimately that is, that, that's the, the way to go. That is the route to go. You have to get involved with other people outside of your, you know, outside of your circle of influence and, and grow that circle some and get some, get some sound advice from, from others. So, I thought it would be interesting to kind of take the, you know, how do you measure this a little bit further?
[00:22:33] You know, we talked about, is it stale or not stale? And I think that, that in and of itself is pointing to a level of maturity that's, in many cases for an MSP, very futuristic, right? To have a review state that's active or a review frequency that's active would imply that best practice has been successfully implemented by its very nature. And so, I was just curious your thoughts.
[00:22:55] So, I went to, I'm going to say great lengths to try to navigate what KPIs would be useful without getting carried away with, say, quality of work. Because if I do quality of work, it becomes very subjective. That's you and I debating whether or not SMS versus, you know, a duo is the right way to do MFA.
[00:23:19] And, and while we could probably really agree on SMS not being good, there are definitely many different ways in which to do this that aren't necessarily one better than another. So, I don't want to get into like how we measure quality of delivery outside of saying more, the more mature you are, the better to find your evidence likely is going to be to go along with your answers.
[00:23:40] So, I broke it down and I said, okay, first and foremost, I don't want to try and establish the maturity level on your ability to implement a best practice. I just want to know, did you implement? Yes, no, maybe. So, we're just keeping it super simple. This would be like your first time going through it. The second thing that I'd want to look at is when you implement, did you define a review frequency for it?
[00:24:04] So, at a minimum, just looking at most frameworks, most frameworks, most of the controls or best practices are set at 12 months. There's nothing that I have seen that goes out further than that. And while there are some that are more frequent than that, the average sits somewhere around a 12-month timeframe. And again, I'm sure someone listening is like, well, no, I think you should be reviewing, you know, your DHCP logs every day.
[00:24:30] Okay, well, that may be true, but that's very different from sort of the status quo. So, and I think it would be, I'd be very careful about having frequency across best practices, having too many that happen too often, where your resource consumption of reviewing is not sustainable or not scalable. So, that would be my first two pieces that I would measure.
[00:24:55] Is there any others that you would want to add for someone that's doing this, say, initially of what should they look at as far as looking at good momentum or good progress of a maturity cycle? I would say that the, you know, look, everybody, it's the big P word, the policy P word, right? Okay.
[00:25:21] Because that's the area that I feel like, you know, most people, and I'm not just talking about MSPs. I'm talking about small business owners in general. Paperwork. Just general, any small business. I mean, outside of an employee handbook, if they even have that, right? They don't have a lot of written policies. They're going off the, you know, seat of their pants on every decision that they make and everything that they do.
[00:25:51] And so. And rightly so. I think that that's the area that you're going to spend a lot of time in, number one. And, but it's also the area that you can get through it relatively quickly, but, you know, and it doesn't have to be as complicated as you think. I mean, you and I have talked about this, you know, keep the process part out of the policy, right?
[00:26:17] Keep, you know, make it, make it as, you know, as straightforward and, you know, concise as you can possibly make it. So you don't have to make a lot of changes to policies. You want to review them yearly, but, you know. Yeah. Let's talk about that for a minute. Because I think mature policies and immature policies have one very distinct difference. Most immature policies are pages and pages long.
[00:26:46] The mature policies are very distinct at two to four pages. And four pages is still probably a pretty long policy. And I would counter that to say that if it is four pages, I'm hoping that I'm seeing versioning controls for the policy are baked into that document, which has made it grow beyond that two to three pages.
[00:27:10] But I think the reason why I call that out is when you think about review frequency and you think about what you're trying to address with a policy, the more things you put in it, the more often you have to touch it. And the more often you have to touch it, the less likely it ever gets to a point of being comfortable with what's in it. Yeah. No, absolutely.
[00:27:32] I mean, I think that if you start to get this big, huge policy, you need to look at, okay, am I trying to cram too much into a single policy? Number one. Like, I mean, our biggest policy is like data governance, data classification and all of that. Data handling and classification. I mean, it's probably five pages long.
[00:27:59] And we've tried to shrink that down considerably. I mean, it is definitely the biggest one. Most of them are one or two pages. Right. But that one, that one's pretty big, you know? You know, acceptable use policies tend to be big too. And I think in some respects there's a good reason for that because it's not a policy. It's policies, you know, BYOD, you know, MFA might show up in there.
[00:28:28] The things that you want employees to follow directly that has a cadence, not necessarily of change, but a cadence of employee needs to re-sign off on or review annually. And so it's a great opportunity to have that, you know, front of mind when, yeah, you're going to initial this again. Here are the eight addendums that I want you to let me know that you've read because your employment may be directly tied to whether or not you did or didn't follow what's in there. Yeah. I like that. That's a good one.
[00:28:57] So that kind of goes into that documentation or evidence commitment, which I think starts to show that second level of maturity. So one of the things that I threw out there from an implementation standpoint, yes, no, maybe, is not a maturity metric in my opinion. It is just a way to start the process for measuring your frequency of review. Because if I say I've done it, then I should have a review frequency attached to it.
[00:29:22] But then I added, you know, maturity levels of like initial, developing, established, and optimized. And going back to the review frequency, your optimized would get kicked down to established if you missed your review dates. So the idea here is that you initially create a policy. You initially implement a safeguard. And I think that is, yes, it's implemented, but it might be initial.
[00:29:48] And I think when we use the term developing, it's you're improving upon what you've done the first time. And that leads into established because you're probably not able, you probably don't need to make any more changes to it. But, and I don't know what that frequency looks like to say I went from developing to established, established to optimized.
[00:30:10] But what I was trying to get away from is saying, you know, using the NIST model of zero to five or one to five of like giving you like these numerical scores that are like, oh, look, we're a four, we're a three. And, and that's great. But our goal here isn't to look at your organization through the lens of, yeah, you're doing a great job. You're perfect.
[00:30:31] It's to look at it through the lens of how do I ensure that I'm not drifting away from what good should look like, knowing that I'm constantly going to have to develop something new. I may have to start something that I haven't done before. Or, and I think that's really what this is about because we're going to have creep, right? New safeguards. AI is dominating everything that we talk about today. And quite honestly, I don't think it's all that far-fetched for it to be talked about.
[00:30:59] It's really important to the future of what we can do, especially in the IT space of the things that it can allow us to do more of without having more staff. So, you know, how do you, how do you stay on top of that? And I think if you have a good, to your point, process in place, then this shouldn't be whether or not it's a daunting task or how difficult it's going to be. It's going to be, why haven't you started? Sure.
[00:31:25] I mean, in a lot of ways, what I can say is that, I mean, you know, not to just toss another framework out there, but we've taken an EOS approach to a lot of our evidence collection and everything that we're doing from, you know, just how we're operating. Yeah.
[00:31:52] Our meeting cadences, all the, you know, the things that we do, the things that are agendas that we talk about in the meetings and everything that we're doing in that. We worked all of our cyber stuff, our security program into that. Right. And so it's become just a, it's just a part of our, what already existed. Yeah.
[00:32:17] We've woven secure, our security program into that. And so I think that's what actually made it easier for us to adopt it over, over that time period. You know, it's just that, you know, we, whatever your cadence is within your organization, if you have some kind of established cadence, meeting wise or whatever, you weave the security program into that cadence.
[00:32:46] And, and it does, you know, it does feel a little more natural than, you know, just completely changing everything. And, and, you know, I mean, we did add one meeting within our deal.
[00:33:00] We have a security meeting specifically to discuss things, you know, relevant to that, you know, that week client wise, whether it's threat intelligence, whether whatever is coming across there. But we also use that time to hold each other accountable on reviewing security awareness training for the company, security awareness training for specific clients that we're working a program with.
[00:33:31] You know, I mean, so it's, it's built in to what we're doing. And, and that is, I think that's what's made it somewhat successful for us. You know, I mean, I'm, I'm pretty hard on us when it comes to those categories, whether we're, you know, developing, established, optimized, you know, somebody, our auditors might come in and look at us as like, oh man, you guys are killing it. And I'm like, oh, what are you talking about? We're going in the wrong direction.
[00:34:01] It's like, we, we can't seem to do anything right. And yet you're telling me what a good job I'm doing. I think that gets into the, the assessment side. I think to some extent, the, the bar is relatively low. And so when they see somebody that's above what they've, and I don't mean like they set this bar.
[00:34:19] I mean that what they've seen based on industry knowledge of doing these assessments, when they see one that's doing a lot to improve their posture to them, it looks good because it is better, significantly better than what they're regularly exposed to. Right. Yeah. So just a little bit real quick, and we'll wrap this up. You, you talked about sort of the EOS way and, and not wanting to say one should adopt any of those programs necessarily.
[00:34:47] But like, I kind of looked at it through the lens of like, this goes back to the metrics, right? What are the metrics we're using to keep us accountable? Which I think that's the piece that's missing for a lot is having accountability outside of your organization. Because if you're the owner, well, you're the only one really that's holding you accountable because the staff can choose to say something.
[00:35:06] But the reality is they tend to not have the authority to, you know, outside of maybe shaming or making you feel bad that you didn't do what your staff are expecting of you, which is totally a different problem. But like your key metrics, your quarterly priorities or rocks, you know, what is the health of the things that you're trying to accomplish? What do they look like? I mean, it goes back to if it's stale, it's stale. That's not healthy. And then the last one is like being able to show, I think you kind of said this more than once is what does our meeting candidates look like?
[00:35:36] What does the staff involvement of our own maturity process truly look like? Because when someone tells me like, oh, yeah, we've designated this to so-and-so in our organization. They're responsible for our Trustmark program or CIS top 18 or fill in the blank. That is not leadership buy-in. That is not organizational buy-in. That is a I am treating this like a checklist and hoping that I improve my posture.
[00:35:59] And ironically, implementation of best practices does help improve your posture, but it's not sustainable and it will not last. I agree 100%. If I were very standoffish about it and I just expected it to happen, I don't know that. It all flows from the top, from the top down.
[00:36:28] You've got to establish some leader. It doesn't mean that you can't assign roles to people within the organization to do things, right? But it is, I mean, I spend more time on the security stuff probably in our company than maybe a lot of owners do just because it's intriguing to me and I'm fascinated by it.
[00:36:51] And that is, you know, one of the burdens I carry, but it is what it is. The, you know, the metric side of it is important. And it's not like you can treat it to me the same way that we treat operational metrics, right? No. Because it's a completely different thing. You know, it's not necessarily numbers, right? Well, there might be one parallel, though.
[00:37:21] I think operational maturity, if you really have operational maturity happening in your organization, then I would argue that your ability to implement security best practices and truly get staff buy-in is going to go back to, because of your operational maturity, your timeline for adoption on things should not be, you know, scary undertaking or feel like that it's, you know, it's going to be forever before we can do this. No, you're absolutely right.
[00:37:48] I just meant that it was different from, you know, you're not looking at, you know, leverage and, you know, you're not looking at, you know, accounts and, you know, rim and all that other kind of stuff that we look at for efficiencies in that regard. And, you know, and us not being a, you know, we're not a security operations center.
[00:38:09] So we're not looking at, you know, the number of threats or whatever that we're keeping at bay or anything on a, you know, on a dashboard, right? And we're more concerned with maintaining the process, right? Right. So we're, you know, we have on our weekly deal, we've got, you know, reviewing devices, right?
[00:38:37] So, you know, did we have any, I mean, on our network, you can't even get on our network without authorization. So it's like, you know. Which would be, makes it really easy to have that review and be like, oh, wait, whoa, what, how did this happen? How did this device show up? And it's like either confession is happening or a compromise has occurred and it means that it needs to be addressed either way. Exactly. Right. So it does make that quick and easy, right? Sure. It's not a lot of big question marks there, but that's a weekly thing. So we're doing that.
[00:39:06] We're reviewing, you know, vulnerabilities, threat intelligence and stuff like that on a, that's more daily actually. But in our meeting, we kind of go through what has come in over the previous week. Like a recap. Yeah. And do that kind of stuff. You know, we go over what we consider our risk scorecard, right? Sure. Where are we kinetic at, at this point? And then we also review connectivity for our, our SOC partner, right? Okay.
[00:39:35] Making sure that our networks are all connected because our SOC partner doesn't alert us when those connections don't work. So we have to go in and do all that. So, I mean, it's kind of a manual thing and it sucks, but that is, that is the way that it is. You can't offload everything to your point. Right. With our, with our current deal. So, I mean, and that, so those are weekly for us. Those are things that happen weekly. The monthly list is much longer.
[00:40:02] I mean, there's like 20 to 25 of those things that we're going through from, you know, reviewing security awareness trainings to, you know, going through all the, all the SOC stuff and, and incidents. I mean, we have alerts coming in if there's a, like a real incident, but then we go a little bit deeper on the things that they may, maybe didn't raise up to an incident to us.
[00:40:25] And we just kind of, you know, go through those and review and make sure, Hey, maybe we do need to check this out because, you know, even though they didn't think it was. At that level, it might've raised a flag for us for some reason. So it really makes me think that if I was really dialing in a, an accountability tool that the initial piece of the, have I filled in my answers and having some sort of posture, that's really only step one.
[00:40:52] Step two, kind of going to your point, I should be able to look at, you know, kinetic technology group. And then in your dashboard, I would see things like meeting cadence and the types of things that we're looking at across the 18 domains and what our concerns are and where we have commitment or evidence issues and where we're asking for help from other peers. Because we've done the due diligence of implementation, which is where most end up getting stuck, right?
[00:41:19] They stop at, I did these things, therefore I'm done. And in fact, have not established process. They've not established true cadence within that frequency model that we're talking about. Right. All right. Well, Hey, last question. Are you reading a book by chance that the audience would find useful? I don't know that they'd find it useful though. Oh. I mean, I'm a, I'm a fiction guy, man. I like, I like thrillers and mysteries and stuff. That's perfect.
[00:41:47] I mean, last week I had the, what is it? Something Carl, the it's the, it's kind of like a first person D and D style book on dungeon, dungeon. Something Carl, I think is the name of the book. It's part of a series. Gotcha. So I'm reading a Michael Connelly book right now. Okay. And so I don't know if you're familiar with like the Lincoln lawyer. Yeah. Yeah. So that, that's the series that I'm reading right now. So.
[00:42:17] Awesome. All right. Well, there you have it. For those of you listening, this has been an episode of MSP 1337. Thanks and have a great week.

