Most MSPs don't have a compliance problem. They have a starting problem.
Michael Zbarsky of Blacksmith InfoSec joins MSP1337 to challenge some of the biggest misconceptions surrounding compliance, security frameworks, and cybersecurity maturity. From the GTIA Cybersecurity Trustmark and CMMC to evidence automation and third-party assessments, the discussion focuses on what actually moves organizations forward and what keeps them stuck.
Michael shares why "good enough" today is often better than "perfect" next year, why automation cannot replace human judgment, and why MSPs are uniquely positioned to lead both their own organizations and their clients toward stronger security outcomes.
If you've ever felt overwhelmed by compliance requirements, unsure where to begin, or skeptical that another framework will help, this episode offers a practical roadmap for turning intention into action.
[00:00:06] Welcome to MSP 1337. I'm your host Chris Johnson, a show dedicated to cybersecurity challenges solutions a journey together, not alone. I'm joined this week by Michael Zbarski of Blacksmith InfoSec. Did I say your name right? I do that sometimes I don't even ask. I'll take a yeah. Super straightforward, you get one vowel, but you just say everything.
[00:00:36] You just like vomit it out. That's I think we do that in English language. Anyway, we make up words and we sometimes choose to put vowels or not put vowels in it anyway. And then make up random rules about how to pronounce stuff because. Oh, or use the same word with different spelling to mean different things or the same same same spelling. Two different words. Yeah. Yeah. It's a wonderful language.
[00:01:03] That's why no one that's that's why I think at the end of the day, if we look at the the the the languages in the US and people are like, I just wish they learn the English language. I'm like, I only speak quote the English language and I struggle with it. So I think it's kind of unfair to say that anybody else is going to figure it out very quickly. Yeah. Okay, well, we have fully derailed from what we're going to talk about. For those of you listening, I am in the southern hemisphere.
[00:01:28] I am in Australia for this recording to talk to Michael, who obviously is in, I think, North America right now. A backdrop doesn't tell me a lot. But and one of the things that I wanted to touch on and this is just to touch on because I think while it's important, I want to get to the bigger conversation that Michael and I have been talking about for a while now. And I think a lot of our vendors that are involved at GTIA with what we do from a how do we help the ITS piece community mature their practice.
[00:01:56] And you guys just came on board as one of the GRC vendors into the program. Thank you so much for coming on. And it's very helpful. I know a lot of people are excited about it. But you guys posted a blog article and I just wanted to give you a chance to share before we get into like the meat of why we do these things. Like, why did you guys feel the importance of getting behind the trust mark? Yeah. And so there's a lot of good things about the trust mark.
[00:02:23] I'm going to talk at a little bit higher level and then we can come down to the trust mark a little bit. In general, people are not doing compliance period and they really need to. And they also need to understand that security is not compliance and compliance is not security. They go hand in hand, but they're two kind of separate beasts that complete each other. As Jerry Maguire would say, you can plead me.
[00:02:53] So, you know, our background was in the SMB space. I used to be so Jared's and start a plan in San Francisco. We both built out too many security programs with SMBs just to kind of put some structure around doing security. Otherwise, you're just plugging holes and using the shotgun approach of, hey, let's go plan a bunch of tooling.
[00:03:19] But there's no thought process necessarily behind it of like, hey, hey, is this tool even worth doing? Sure. There's no risk discussion. There's none of that. And so one of the things that we've kind of seen over and over again is people are just not doing anything and they need to start doing something. And that goes for any framework, whether you know your HIP entity or anything else, FTC safeguards.
[00:03:47] If you have no regulating body, NIST CSF, CIS controls, whatever. Like people just need to pick something and start on that track to get the motion in place. Trustmark specifically. Sorry, go ahead. Yeah. No, go ahead. Go ahead. Trustmark specifically.
[00:04:05] We really like what you guys have put together for an MSP at the station body so that ideally as it spreads, MSPs can right now, MSPs, the way they kind of market, the way they attempt to kind of solidify stuff is usually going through SOC 2. And most of that is suspect. Yeah.
[00:04:31] And so I really like the program that you guys put together. I like really the tiered approach. You know, one of the other frameworks that does this really well, CS controls obviously does it well. But as far as regulated bodies, New York DFS does it really well. I really like how they have the tiered approach for, you know, small organization, medium and large. They use great language to it, what they're getting at.
[00:04:57] That was one of the things I really liked about NY DFS is they really, they really explain well what the expectation is as opposed to, hey, just go do this thing because that's a good idea to do it. They really kind of talk to like the importance of and really giving a path to say, you might not be able to do this by yourself. Here's how you can go about doing that. Yep. No, absolutely. Absolutely. I also like the fact that they have that like highest person in the company attesting to it annually.
[00:05:24] Yeah, it actually, and you and I were talking about this a little bit before the call, the number of people that should be accountable for anything should be one. If you have less than one, no one's accountable. Right. If you have more than one, no one's accountable because they're going to be pointing fingers. And so sure. Having someone be accountable to say, yes, we are doing this. And yes, I will attest that we're doing this is huge. I wish when they redo HIPAA in 2027, they do something like that. They won't, but it would be, I can dream.
[00:05:54] Yeah. You know, I think. Well, I think not to spend too much time on this, but I think one of the challenges you have is the same challenge we're seeing playing out with CMMC. You know, it's not necessarily crazy for large organizations to do what's being asked on their own. And even for those companies, even some of the stuff that's in there can be quite challenging in and of itself. I think HIPAA is the same way. You have hospital systems that have IT departments.
[00:06:20] They have qualified, skilled individuals working for the organization that can do these things. But then they take it and say this has to be applicable all the way down to the one doctor practice. And I think therein lies why I think the trust market exists, why things like SME 1001 from DSI exist.
[00:06:39] You're getting into what is, how do we, how do we put at least a starting point in place that gives a path to be successful, regardless of what framework gets put on them. I think that's, and protect themselves along the way because compliance to just do compliance is really just checking boxes or ticking boxes, depending on where you are, to say, yeah, we're going to do this in order to get this client. We're going to do this in order to get insurance. We're going to do this to not get penalized.
[00:07:09] But the reality is you're not in business to do things for people because they just demand of you that costs you money. It's not why you got into business. You're like, hey, you know what? We're going to use QuickBooks instead of zero because QuickBooks costs more. That's the only reason we picked that one. Like that's, that's ludicrous right now. We gotta charge our clients more. We're going to get our costs back or like, or even saying things like, well, we're not really in this to make money. We just want to help people. It's like, okay, well then why do you charge them money? Like the reality is that that's not the case.
[00:07:35] And so if you're doing anything to protect your business that costs more than it is actually worth to be in business. And I think that's where some of these compliance frameworks get in the way of progress is they, they take the, the most restrictive scenario with a specific vertical and say, okay, let's use that most restrictive one. And we're going to use that as what we're going to use for the, how we measure this for, for everybody.
[00:07:57] And so, and we saw that with what Phyllis came out with, with CIS, when they added the levels in, you know, it made it very clear, like, hey, if you just did level one, that's like 90% of what you're trying to protect against. So when we looked at the trust mark to roll that out, the one thing that was really different when we, when we rebooted it in 22 was there's one conceptual thing that was missing from the ITSP space. And that was governance.
[00:08:22] So we were really excited when we saw 8.1, when this, when this CSF released their whole, like, and we've added governance and we're like, okay, let's see what we're going to be updating in the trust mark. CIS 8.1, eight, it's going to add in governance or govern. And what we uncovered was sort of kind of not really. I mean, yes, documentation is part of governance, but governance isn't in itself defined by just documentation. And I like to say it's the, the ability for the business to operate under pressure.
[00:08:52] Like all the things work because everybody's working together to ensure success. And when we just talk about like, oh, well, we have a policy for that. It's like, oh, okay. But does your level one helped us guy understand it? And when they asked why did you give them clear answer or did you just tell them to sign the policy? Yeah, no. And I've seen that a bunch. I've also seen people approving policies without reading them and they have no clue what they're even approving. And it goes out.
[00:09:18] I've seen, I think one of the reasons that we originally, or one of the things that I personally, that kind of pushed me more towards the path of building blacksmith and development more was I actually ran to one of my old V-Sysso clients. And random events. Yeah. And we were standing there talking, catching up. And I was like, hey, how's the security program going to put in place?
[00:09:46] He's like, well, we haven't talked to you in about three years. And the policies have been in my desk for three years. And I was just like. Wait, at least not in a filing cabinet. And so is the operas, operization. How do you operationalize? Yeah. English. How do you operationalize security and compliance and make it actually repeatable and build that muscle memory? And don't make it complicated.
[00:10:16] Yes. And that's the nice thing, again, about how Trustmark is. It gives them, I've seen more and more frameworks do the tiered approach, which I really like. Spectra's framework does the same thing. They've got three tiers in there. If HIPAA actually did tiers, it would be phenomenal. Because to your point. Sure. Single doctor's practice and the hospital. Well, okay. So let's just talk about it from an ITSP perspective.
[00:10:43] It drives me, I should probably do this more at a bar as opposed to on a recording. But it really bothers me that in the MSP, ITSP space, it's like, you know, if there was only something easier to do. If only we just didn't have to do all of it. If only, you know, I'm really busy. It's like, well, why did you decide to start your MSP? Did you do it just so that you could, you know, get compromised by threat actors? Probably not.
[00:11:09] And so if you think about the industry, like all of the industries that are out there, the ITSP community is solely equipped to really be the only real player in the space that can help the other businesses who their specialty is not in IT to get these things done. And so when an MSP tells me, oh, it's too hard, nine out of 10 times, they actually haven't even looked at it.
[00:11:36] In fact, one of my favorite conversations I've had with an MSP that has Trustmark Assured status is that he was, he had gone through SOC 2, ISO 27001, and he decided to see MMC and the Trustmark at the same time. He said to me after, I think it took him, I think it took him just shy of 16, 18 months. I can't remember the exact time. He goes, I wished I wouldn't have done any of those other frameworks before the Trustmark. And I said, why? I said, why do you say that?
[00:12:02] He goes, because the Trustmark was about protecting my business first. And he's like, most frameworks are either about protecting somebody else's data, a specific data type. And they don't really care about you. Like, CMMC is a great example of a truly selfish framework. And for right reasons, I'm not trying to make light of the reason for CMMC, but like, they don't care about your other clients' data. They don't care about your employee data records. They don't care about your IP.
[00:12:31] They only care about CUI or the other one. I just drew a blank. FCI, if you're being level one. Yes, level one, right. So the interesting thing about all of this is we no longer have a position that we can take that's tied to the selfishness of, well, it's too hard for me. It's like, yeah, but you're the only ones that can do this.
[00:12:54] And the only reason we're putting levels in or giving you like, hey, do this first maybe, is because we're trying to get you to acknowledge that maybe doing something isn't all that hard. And once you do the first something and then you do the second something, you're like, wow, maybe this isn't so difficult after all. Because most of the people we talk to, the only one that's getting away in them doing the trust mark or really any framework is paralysis of getting started. Yep. And I've seen that even outside of compliance.
[00:13:22] I remember early in my career, I got a little ahead of myself and stood up Qualys, ran a vulnerability scan, got a nice like 400 page report that I put on my director of IT's desk. And I was like, hey, I just ran this vulnerability scan. And he's like, cool, took it and put it in the trash. I'm like, cool. So that's not the right approach. And it's the paralysis, right? When you have too much to do. And Jared says this all the time.
[00:13:52] It's the how do you eat an elephant? One bite at a time, right? Just start doing something. Start making those little baby steps. You know, I'll throw out random other euphemisms, crawl, walk, run, right? It's all been said a thousand times. But do something. Or the stupid one is, what are you doing? Take stock of what you are doing today. Let's not and will not be judgy. Just tell me what you're doing. And let's review what that actually does cover.
[00:14:20] And so it's funny. So the trust mark is 177 safeguards. I think 175 of them are required to be answered. Two of them are more. They were kind of an all encompassing. Like if you have WISP or SSPs, rather than having you break it apart, use those policy placeholders. As a place to store that. At any rate, what I run into is we used to say like, don't spend more than 90 minutes on this.
[00:14:47] And we would have MSPs that have spent like two weeks and 90 days. And they're like, yeah, we're almost done. We got a couple things we need to check. I'm like, no, no, no, no, no. This is a gap assessment. This is like, what does your gut tell you about your organization? And if your gut tells you you need to go check something, I would argue you should probably put down not doing. Or I'll even give you a maybe. And they're like, yeah, but I'm like, no, no, no. Don't over-engineer this. This is no different than telling me your policy is not done because you don't have your logo on it. No one cares if your logo is on it.
[00:15:16] All we care about is does it say what you're doing? And can you prove with evidence that you're supporting that document? That's it. And then they're like, well, you know, I'm on page nine of my policy. Nope, probably not a policy anymore. My guess is after page two or page three, you started writing out all the products and how you install them and who's responsible for them. Not policy anymore. And so if you can get the MSPs past this idea that, you know, perfection is really the enemy of good.
[00:15:45] We are looking for okay. And everybody's like, well, why would you want, you know, clients don't hire MSPs because they're okay. Okay. Although now we're starting to see okay MSP who's cheap versus really, really good MSP who's expensive. That's starting to make a difference. But I think the reality is that an MSP that's really good at what they do, they don't like to settle for okay. They don't settle for okay with how they deliver services to their clients. So when you propose to them, just do an okay job of implementing fill in the blank.
[00:16:14] I don't care what framework it is, except for maybe those that are regulated. Okay. You still get punished if you just did okay. But like, it's a starting point. Maybe. Right. But again, I'd rather you do okay on HIPAA than do nothing. Right. Again, start, do something and make it okay. And then improve. This whole concept of continuous improvement within any of the frameworks is there. Right. So, yeah, doing okay even in a regulated framework is perfectly fine.
[00:16:45] I guess my point is you can't cheat, right? You can't cheat this system, right? So you can't just say, hey, I got three clients that they need me to be CMMC. So we're going to do that. We'll have it done probably in the next 90 days. It's like that won't be okay. It's not even going to be at a level of okay. And so I think that's where I think a lot of these guys are getting themselves in trouble is they've chased the opportunity, the financial, the elephant. Yes, you can't eat one bite at a time, but will it catch up to you before you can get to the last bite?
[00:17:13] And so I go back to why the trust mark, why frameworks like CIS, SME 1001. Those are not regulated frameworks, which means you get to do them at your own pace with your own level of investment and you can cherry pick what you believe it applies to you and that which doesn't. Now the trust mark, we don't want you to cherry pick, but I think you'll see that if you actually get into it.
[00:17:33] One of the things that we're talking about with DSI and the SME 1001 today, and we talked about this yesterday, is what does it look like to establish something in the SME space? And I'm like, well, I think first we have to establish what is SMB? I said, and so that was really kind of a funny statement because they're like, well, you know, in the US, you know, an SMB is all the way up to like 200 employees. And I'm like, yeah, maybe, but I said, we really measure it based on revenue.
[00:18:03] So like, you know, a five or seven person MSP that's doing 6 million in revenue, we're probably not saying they are a small micro MSP. They're probably a very adept MSP. But to their point, they were talking about how like the real challenge that we have is the MSP who's already in the SMB space providing services to what would be they would classify as their SMB would be our micro SMB.
[00:18:28] So like the one person flower shop that's got a point of sale system and maybe some QuickBooks or some other intellectual property that they don't want to lose. And it's like, how do we do like these 10 things that at least slow the bad guys down or at least are a deterrent? Like we talk about, okay, a camera that doesn't work that points at the doors of a convenience store is at least making the person that wants to do bad things pause. And sometimes all you need is for them to pause.
[00:18:58] Well, and we have this conversation with people all the time, right? It's the, we get the, well, I'm too small for the threat actors to care about me. You're absolutely right. You are too small. Threat actors don't care about you. All you are to them is a number. And if your door is wide open, they'll come in. And if you don't pay the ransom, that's fine. They don't care. You're just a number to them. They did not care about you. Right. One of the things I always, I used to ask clients is why do you lock your door at night?
[00:19:27] Well, what do you mean? Why do you lock your home door at night? Or do you lock it? I don't know. Like, well, yeah, I lock it. I'm like, why? Like, well, because somebody, I want somebody to come to my house at night. I'm like, cool. But if somebody wants to come into your house, I mean, they'll have a lock fix. So they'll pick the lock. They'll walk in anyways. He's like, well, yeah. But like whoever's walking by isn't going to be able to just walk in. Like same concept, right? There's people constantly scanning. And if you're wide open, your network's wide open, guess what? They're going to hit it.
[00:19:55] If you've got some precautions in place, you know, if someone wants to hack you, they're going to hack you. There's nothing you can do about it. Yeah. My son made a comment a while back about no one would ever break into his window because he likes to just leave it open. And I'm like, it's on the second story. And it's like a, it's probably a good 20 feet from his window to the ground. And there's no, and there's nothing there. There's like no like overhang. There's no trellis. There's not like something you're going to climb.
[00:20:21] But ironically, there's a 24 foot extension ladder that is literally laying 35 feet away or it's hanging on the side of a building. But I'm like, if someone wants to get into your house, the reality is it doesn't matter that your window's open or closed. Do you have something that's worth stealing? And if so, and it's the door, the door is open. They don't need to know in advance. They're going to come look anyway. Yeah. Well, it's funny to bring that up because like six months ago, we had a string of robberies
[00:20:50] in our area where people were literally pulling up the houses with a ladder, crawling into second-story windows, robbing the house and leaving. Well, and no one questions somebody walking out the front door. Yep, exactly. So, I mean, I think this is, you know, and we go on the other side of this, like you mentioned SpectroCyber and there's others.
[00:21:17] You know, one of the things that's kind of funny is how we validate things, right? How do we verify that things are being done? And what's interesting is, and I hate when someone says this, they're like, well, we have cybersecurity insurance. I'm like, okay, let's have this really simple conversation. I said, first question I'm going to ask you is one that I know you can get right. The car you have sitting outside right now, pick the car that you drive, tell me what your insurance coverage is on. Like, oh yeah, I have comprehensive, I have full because we're still paying for it, fill in the blank, right?
[00:21:46] Like, all right, I want that level of detail. I want you to tell me what your cybersecurity insurance is. Go. They're like, well, you know, we just signed a new policy. I'm like, well, it should be really fresh in your mind. This should be like, you know, like blatantly what is in there. And he's like, yeah, I don't. I'm like, look, I get it. It's a far more complex policy than insurance. And it hasn't been around nearly as long as car insurance has. But if you aren't already on the same page of what your insurance does cover and something
[00:22:15] that is complicated, then why do you have that policy if you don't know what it does? Well, I'll take it one step further. Within our platform, you can actually put in for under the incident response stuff, your cyber insurance contact info, et cetera. The amount of times that you've seen people put in their broker contact info instead of breach is just baffling to me. I'm like, what are you doing? Why are you calling your broker? Like, figure out what the breach line is. That's the number you need.
[00:22:46] I had one where they called to do a tabletop exercise, called the insurance company, called the, I think it was like the main line for the insurance company. They routed them appropriately. They left a message, which is great because they left a message. I think it was more than 72 hours before they actually talked to a live person. And ironically, they were so quick to say, we're firing this insurance company. And I was like, well, why are you firing them? They're like, well, they didn't do this. They didn't do this. I go, what was the reason that they didn't answer the phone or didn't get back to you in a reasonable amount of time?
[00:23:15] He goes, well, they were, they were putting in a new phone system and one of the auto attendants didn't get set up. I go, just throwing this out there. Call your insurance company, ask them how many claims they've had in the last year. I bet it's very, very low. I said, so if you think about it, there's a good chance that you were the first person to call for any reason that needed to talk to that side of the house. So to just say that they can't make mistakes, that's probably not a real fair shake.
[00:23:43] Be thankful that it was a tabletop exercise, right? And that you're part of, you know, part of third-party vendor management isn't so you can slap them every time something changes. Be part of the solution, right? The vendor and partner ecosystem works when you work together. It doesn't work very well when it's transaction-based, particularly in the managed services space. Yeah, no, absolutely. And it's funny because, you know, we're always looking to get feedback from our partners and that's how we get better.
[00:24:13] Like, we love it when people come to us and say, hey, we found this bug. So that means they're using the product. They're actually kicking it, moving it, using it, and then telling us when something is wrong. And sometimes it's wrong by design, sometimes it's wrong because we didn't think of something. But either way, it gets better. Same thing goes for everything else, right? You brought up the bane of my existence, which is third-party risk management. But I won't get on that soapbox. Actually, I love it.
[00:24:43] That's actually an area that we have within the GTIA resources is third-party vendor management guidebook. There's templates for how to evaluate a vendor. I've watched MSPs get really creative in this space. Microsoft lists. So going back a year or two, Microsoft lists had just come out of beta. And I think we were maybe three months into looking at how it was valuable and they released the form enablement. So whatever your columns are, you can turn it into a form and then that form can live somewhere.
[00:25:12] So anytime you add a vendor or you need to update a vendor, you just update the form and voila. Yeah, no, that part is fine. It's the asking S9 questions in an Excel sheet without having with drop downs where they don't have to capture the new ones with no place to put comments with a person I know that isn't going to even bother reading it. There's doing it as a checkmark exercise. Like that's the part. Was this additional feature? Was it vibe coded or did it actually get this?
[00:25:43] We could go down a rabbit hole. You know, that makes me want to ask a question. I had this come up with an MSP. I gave them my two cents. I was very adamant about my two cents. I'll tell you what it is so you don't disagree with me on this show. But I think you may have some additional insight that I think is important. One, because you are a GRC platform. I am well aware that you guys have quite a few integrations into your platform to help with things like automation of data collection or evidence collection. And I think that's really important. I really do.
[00:26:12] My conversation was with this particular MSP. They wanted to know that any of the GRC vendors in the program, if they picked one, that they could avoid the busy work because of integrations to automate that evidence collection. And I said, look, I'm not going to try and tell you which ones I think do integrations great or not great. And I said, and I honestly don't really care. I said, my concern is, is that when you're looking at evaluating a GRC vendor for the
[00:26:38] first time you go through something like the Trustmark, is that you're focused on how you can automate your evidence gathering. And I said, because inevitably, the first time you do this, if you don't do it manually, you won't know the difference between what should look good and what looks bad or where you've mapped evidence that is incorrect for the best practice you're trying to attach it to. And I said, look, the easiest and most selfish example that I will give you, and this is
[00:27:05] what I told them, as I said, when an assessor is assessing your organization, we don't want to start giving them reasons to how they can't afford to continue to assess companies at the low, low price of $2,500 because they keep dealing with the evidence is a picture of your cat or it's the wrong system for asset inventory because you switched it out and you're still allowing that to populate your evidence. And he's like, that makes a lot of sense. I said, now, when you're doing this in your round two, and I said, and I'll share this
[00:27:34] for everybody listening to not fall down on this, you should be doing automation to capture things like current reports, current, and you shouldn't have to go and manually find that to get it fed in. It should be like when you don't see it show up in your GRC that you're like red flagging long before you go get assessed to find out like the last time you had a valid report for your 90 day of reporting period was 12 months ago. Yeah. So I don't know.
[00:28:00] I know those are long roundabout way, but like, I know you guys have integrations. How did you go about doing this? Because I see that like some of them are actually quite intricate for dialing in with your platform. So I was just curious, kind of your take on that. Yeah. So we've got a couple integrations. We don't have a lot. And it's mainly for that reason is we want eyes on the evidence, right? So in our lives, we've used a bunch of different GRC tools. Sure.
[00:28:27] And what we've seen is some through the fault of the tool and some through the fault of human psychology, they can create this false sense of security. Yeah. I'll give you a couple examples. So first of all, if something goes, we'll use the technical term of wonky, would they be high policy, right? All of a sudden you're getting data that is potentially bad. Whether, you know, Microsoft. Arnold calls that foobar. Yeah.
[00:28:58] And if you're not checking the data that's pulling in, and a lot of times people don't because all they see is a green check mark. And they're like, cool, I'm done. And then they've got garbage evidence. Which is everything else we see in our industry, right? Every tool we use, SIM tools, firewall logs, you name it, how many of those are actually being monitored, period? The other part of this and the bigger part really, because the technical aspect of the
[00:29:27] API returns the wrong thing you can fix. The bigger issue is if I build an integration to Microsoft and it goes into Microsoft and checks, hey, do you have MFA? You do? You do? Great. Cool. I pull evidence of that in. And I say you have MFA. Green check mark. But I haven't checked your accounting system, your HR system, all your other systems that aren't integrated.
[00:29:56] And so this is the human psychology piece of how do you build integrations to ingest evidence? Because we do want to do that, and we're doing a bigger push to do that over the next couple months, actually. But at the same time, keep the person in the loop and engaged to not just say, cool, I have a bunch of green check marks. I'm done. And I'll give you a great story. We actually have a friend that went through SOC 2 for their company. They were using an enterprise GRC tool.
[00:30:27] And they got their SOC 2, and they actually came to us and said, hey, would you guys just mind taking a look and letting me know I'm done? I've got my SOC 2. What else should I do? And we're like, cool. Let's take a look. We logged in. Talked to him a little bit. We're like, where are you guys doing all your AI workloads? Oh, we're doing it in Azure. You never connected Azure to this GRC tool.
[00:30:53] Like, all your AI workloads are out of scope for the SOC 2. The SOC 2 is worthless, basically. Right? But all he saw was green check marks. All the auditor came in, saw his green check marks, and he doesn't know there's Azure stuff. Right? What do you mean I can't use my RMM tool for my inventory? Yeah. And that's a big thing. Like, you cannot just automate compliance.
[00:31:17] You can leverage automation to expedite, but you still need someone to actually do that thinking and say, hey, is everything connected? For the stuff that can't connect, have I pulled evidence manually? How do I prove that I'm doing A, B, and C in this random tool? Right? Would you say that that's where you get into it? Like, I feel like drift is probably one of the things that automation can do a really good job at. It can identify when something that has been properly configured and implemented changes. Yeah.
[00:31:47] But it can't tell you whether or not. It's never going to be any better than what you implemented. Yeah. So it doesn't know necessarily what the right way to have done it was. It just knows that you said you did it, and it's capturing whatever evidence and populating your evidence folder. Yeah. Well, the other kind of thing that creates the false sense of security that I've seen a bunch of is everyone's telling people to say, hey, if you have... I'm going to pick on Huntress. Huntress is a great tool.
[00:32:15] I'm not picking on them, but I will use their name. Sure. You have Huntress. Huntress suffices these 30 controls or whatever it is. But you don't know that. You don't know how the person configured Huntress. Maybe he's using one thing and there are nothing else. Right. Like... On one endpoint. Right. And so, again, it's the... Just because you have a tool doesn't mean it's configured correctly. And I've seen this time and time again. I've seen MDM that's deployed but not actually enforcing anything. Right?
[00:32:45] I've seen all kinds of stuff in my career. And so that goes back to keeping that human in the loop and making sure that you're actually looking at stuff and making a judgment call. Hey, is this correct? Am I actually looking at it? And especially the first couple times even, do it manually. And then start automating. It's... You know, it's always funny because... Do you think this gets into... Going back to what you said about the SOC audit or thinking about an assessor in general.
[00:33:15] Obviously, we want assessors to be very objective. But I think... I went down this path not so long ago and said, you know, I'm going to go through the steps to be a practitioner for CMMC. And I did... I got the... I finished all of the stuff for the first round back when it was still version one. And one of the things that kept going through my head is like, I still didn't feel qualified from a... Like, if I were to go down the assessor path, I was like... Because you see this with a lot of the regulated space.
[00:33:43] You get assessed and they give you the... And now you can do the assessing. And I'm like, I don't think there's a... Because you have gotten a sticker that says, good job. That suddenly you have a new qualification or skill set that you didn't have before you were assessed. Like, I feel like assessor is like a rare breed that we are hoping that there were more of and we want more of. But... This goes back to what you were saying. Like, the human in the loop.
[00:34:10] I would love to say that we need more people that have gone through some sort of level of... Some sort of like... I don't want to call it rudimentary. But that they've gone through some sort of like objective understanding of what it is that you're trying to accomplish. So they can recognize what good looks like or what it should look like. Versus trying to be at the level of assessing a company and the stakes and the liability and risk that goes along with doing those things. I think we're missing that piece.
[00:34:39] I want to automate it. Why do you want to automate it? Oh, because all the work that's involved. It's like, yes. But would you know if it was being done right any different manually versus automated? Well, and so I haven't... That's a good question actually for you is for the auditing for Trustmark. Who's conducting the auditing? Because I know like for SOC 2, it's utterly broken because they have accountants who do not understand technology doing the audits. So you want to talk a little bit about...
[00:35:09] So they're not audits. We don't say audit. We say assess. Assessments. Assessments. Legal words, right? Legal words. So there are two companies that are part of the assessing. There could someday be more. But today of the six that have this... What do you call it? Accredited from Crest International, Verispray, and Prescient Security, the only two of I think it's six that have what is largely the CIS.
[00:35:37] So they have CIS accredited through Crest. And then Crest also does their initial organizational... So it's a combination of Crest as an organizational level audit identifies things like making sure the assessors have certain training. So if someone wanted to... You know, like just for their own, like how do I know what I'm looking at? I think it's... I want to say it's ISC Squared has a... It's the GCC certification.
[00:36:06] That's one I've thought about doing it just for like my own sort of like improve my own understanding. But those are some of the examples. Those are the two companies in the program now that have... So when they assess your company, they are accredited through a global third party to say these guys are qualified to assess business. And they have a lot of them, not just those two, but they have... Those aren't the only things they're accredited for. So like pen testing and other services. It's just a reminder if you choose to have, say, Prescient do your pen testing, you're probably...
[00:36:35] You need to disclose that when you're ready for an assessment so that they're not also the ones doing your assessing. If they did your pen test. Yeah. And that's like... And that's really good, right? Because again, like I have dealt with so many accountants that do not understand technology assessing SOC 2 that I'm just like, no, like this is correct. Let me explain to you why this is correct. But I'm looking for this thing that I was told to look for. I'm like, no, I get that. But this is exactly why this is the same thing.
[00:37:03] And I'm like, go talk to your lead accountant or lead auditor and like let's talk then. Right. And that also goes back to your, you know, as you were going through the CMMC assessment piece of like, hey, am I really qualified? Am I really ready for this? It's a little bit of a pyramid scheme, right? Yeah. Yeah. Yeah. It's a sticker. And then you can get two stickers to one for three friends and then they can give stickers to their friends.
[00:37:32] And well, and you know, what's interesting is if we look closely at the players, we're seeing like essential eight is being redone. I think now it's going to be the essential layers. They're doing a different surprise tiered approach. You've got cyber essentials out of the UK and I, and they are shifting their approach. They've got all these different pieces now in there. And yet clarity is not a hundred percent. We're seeing this with CMMC in the States where they paused phase two.
[00:38:01] And it's like, no one's saying that we don't need these things, but I think they're having to recognize that you can't just tell a seven person company that you need to go do these hundred, 300, 500 things. And that are, you'll penalize them. They're like, I've been making your bolts for your planes for 50 years and you decided not to buy them at Lowe's or Home Depot. So here you go. Like it's still a bolt.
[00:38:24] And I think that while all of those things are true, the pause didn't help the SMB space, right? We're still seeing your Boeing, your Northrop Grumman still saying, Hey, we're not requiring you to have a CMMC3 PAL certified assessment of your business, but we are requiring you that you no longer are just self-attesting. We want to see that there was a third party that is known for being, and I say this calloused and sarcastically, like even if all I know is accounting.
[00:38:52] Because at least it had eyes on that weren't self-attestation. Well, I will get my CMMC cell box for a couple minutes. Okay. So CMMC doesn't partially fixes the problem of what it was trying to fix, right? The problem it was trying to fix originally was people were self-attesting 800-171.
[00:39:19] CMMC really should have been not a non-thing, right? They should have said, Hey, you have to do this. And people should have just said, Cool, we've already been doing this for a decade. Cool, go ahead and assess this. Yep. But the reason that it wasn't working properly is the government contracting entity was supposed to be validating the SPRS scores, and they weren't doing that because the government's lazy. Sure. And so now they've outsourced that piece to CMMC, but they haven't fixed all the other things. Sure.
[00:39:50] There's a bunch of things that are flagged as CUI that just shouldn't be. Right. I'll give you an example. We were talking to MSP a couple months back. This was, what, like, February of this year? And they had a client who's a moving company. They literally move furniture. But because service members' names and addresses are CUI, they had to get CMMC. They got a letter that had to be CMMC certified.
[00:40:19] Right? Did the Postal Service or FedEx or UPS have to get certified then? Well, so they are not contracted with the government. They are a separate government entity. Right? Yeah. And so there's nuance there. And so, like, a dentist, for example, would not have to be unless it's a dentist through the VA, in which case they had a contract with the government, and now they do. Right? Right. It's the envelope getting pushed. You see this in education, too.
[00:40:48] So if you have an actual medical clinic inside of a school, that's protected under student records before it's protected under HIPAA. So it's a very, you know, one can trump the other. But I think to your point, I mean, we've even seen it with, like, note-taking, right? Someone takes paper notes about a meeting. If the meeting had to do with the company that is the contract, now all those notes are CUI, even if nothing that was tied to the contract was in those notes.
[00:41:15] Or I wrote on a rock outside on Smoke Break, and now the rock is part of CUI. Like, I actually heard that one. That one made me laugh. They actually wrote something on the rock as a sarcastic joke, only to find that it wasn't so funny because now it is in scope. Again, I go back to you. I think you and I are 100% lockstep on this. Our job isn't to solve for regulation. Our job isn't to solve for having perfect compliance against standards.
[00:41:44] But I think at the end of the day, if we're teaching, particularly in the ITSP space, the ability to do best practices and to do it continuously and to continuously improve, adhering to a framework, being compliant with a framework, that's going to be the least of their challenges. That's going to be the easy work. I mean, not always easy, but I mean, the reality is we're just talking about doing things through different lenses or maybe making it a little bit more strict than what we had. That's very different from the approach that's currently being taken.
[00:42:14] I have to do all these things. I got to get it done tomorrow. It's like, well, that's not realistically going to happen. And I would argue that anybody that tries to accelerate their process to being compliant, whether it's best practices or not, they're just asking for another gap in their business or going out of business because they spend too much money to be compliant. Well, and the funny thing is, this is something that I've seen over my career that's, that a lot of people don't realize when it comes to compliance is,
[00:42:40] as you build out these repeatable processes and you start like getting this under your belt, everything just starts going a lot smoother and faster and your hair is not on fire. And all of a sudden it's not taking that much longer, if at all. Sometimes it's faster because you bring on a new client and you're like, cool. I already have all these processes built out. Guess what? I know how to do all this stuff for you. Let me get you to compliance with whatever you need to do. For sure. And I can't stress this enough. I know you can't stress this enough.
[00:43:10] The worst thing they can do is sit in their hands and just do nothing. Just go do something. Start the journey. That's our mission, right? Keep them from sitting on their hands. Yep. Michael, I appreciate you coming on. It's been far too long, especially considering the timing of your press release on being involved with the Trustmark and the GRC platform. I appreciate you. Appreciate you being involved with GTA. For those of you listening, this has been an episode of MSP 1337. Thanks and have a great week. Thank you. Thank you.

