Human risk has become one of the most challenging and misunderstood aspects of cybersecurity. In this episode of MSP 1337, Chris Johnson sits down with Nihil Morjaria from usecure to explore why traditional security awareness training is no longer enough and what it takes to build a truly proactive human risk management strategy.
The conversation examines how MSPs and ITSPs are evolving beyond technology management into governance, risk, and compliance, and why understanding user behavior is now just as important as managing firewalls and endpoints. Chris and Nihil discuss the limitations of one-time phishing exercises, the rise of shadow IT and AI-driven data exposure, and the growing need to combine security awareness, breach intelligence, password hygiene, and user behavior into a single view of risk.
Listeners will learn how leading providers are using human risk intelligence to prioritize remediation efforts, reduce alert fatigue, empower end users, and deliver measurable security outcomes for clients. Whether you're struggling with phishing failures, unsanctioned applications, or simply trying to make security awareness more effective, this episode offers practical insights for turning your users from a potential liability into a powerful line of defense.
[00:00:06] Welcome to MSP 1337. I'm your host, Chris Johnson, a show dedicated to cybersecurity challenges solutions, a journey together, not alone. Welcome everybody to another episode of MSP 1337. If you've been paying attention to the show, you noticed that there was a gap.
[00:00:32] We took a week off and didn't tell anybody. I had some technical difficulties, as I'm sure many of you have had. This week, I am privileged to have Nihil Majaria on the show. Did I get it close? You did. You corrected yourself just in time. You nailed it on the second one. Just in time. Well, with you, Sekir, and we're going to talk today about something that has come up on this show before.
[00:01:02] As we were prepping to start recording, one of the things that we were kind of joking about and the data that goes along with it is what are the different things that MSPs, ITSPs, and then we started going down the rabbit hole of MIAs and MIPs and all the different things that what is traditionally the IT services industry, which has been flipped on its head over the last few years of incorporating
[00:01:31] services that are not part of what would have been traditionally called an IT service package or services stack as we deal with a threat landscape that involves governance, risk, and compliance on a whole new level.
[00:01:46] I think unprecedented in our industry, especially as we introduce things like AI into the equation and the expanse of where we go today, which is most bad things that happen are still tied to the in the middle attack. And when I say in the middle, it's in between the chair and the keyboard is where the elements of problematic elements come into play of I clicked on the link.
[00:02:13] I chose to take the call. I responded to the SMS. I still believe the Nigerian Prince will give me my money.
[00:02:22] It keeps promising. So tell us a little bit about the shift that you secure and some of the things that you're envisioning that will be, I think, really important to our industry and maybe perhaps a little bit unprecedented when I think about, if I think about it in the ITSP space first, this gets a little bit complicated just because of the way a lot of service providers operate.
[00:02:46] If I think about this in like a traditional, and correct me if I'm wrong here, like mid-market enterprise, the first thing that came to mind for me was I'm thinking about the role of a CISO in an organization that is having to look at the entire organization, all the staff and going, where am I going to click? No matter what training I do with them, they're going to click. They take the phone call, they're under pressure, they're going to say, yes, I will transfer that money.
[00:03:13] And how does that, because what we're really talking about, I think, is the human error and how human error impacts the bottom line for any organization. And hopefully I got that close. Absolutely. Yeah, that human element is everything that we focus on. And I think you touched on a few really important points there, Chris.
[00:03:34] I mean, the fact that there's that massive uptick in GRC expectations around how we are monitoring, but also now empowering end users. You know, it's not just about tripping them up. It's not about, you know, just the stick approach. It's about making sure that we have processes that can build culture, that we can incorporate the end users into our ecosystem to mean that they aren't this ticking time bomb that can undo all your work around infrastructure.
[00:04:03] They are there to supplement and to build that extra layer. You know, the things and from a GRC perspective, there are more things that are formalizing that and are essentially validating that this isn't just security best practice. It is actual mandated process. And obviously that's exacerbated by the things you speak about with, you know, AI, the evolution of these threats, the way in which they are targeting users, both in terms of identifying who they should be targeting and then finding ways to actually get that user to engage.
[00:04:32] They're evolving incredibly quickly. And that's been a challenge for us. You know, it's been a consistent challenge. And I know when people think about human risk and security awareness programs, quite often there's a historical trauma of incredibly boring training, not fit for purpose. It's just a tick box. And so we've been very conscious over the last, you know, four or five years in particular to make sure that we're evolving our messaging and importantly, our offering to reflect how training and phishing should be done in an effective way.
[00:05:01] But also mirroring the type of risk vectors that are actually present in modern business, you know, the dark web process and policy to make sure we're building culture. And now we're moving into a new phase where we need to be more proactive, we need to be more intelligence led, and we need to be able to piece together multiple data points to basically have a more comprehensive view of that user.
[00:05:21] And again, the idea is to make sure that that end user then can supplement and become an extra layer of security to the ecosystem, complement the ecosystem, rather than being that forgotten element of it. So what comes to mind for me is as I think about all the things that you've kind of listed that are sort of the, you know, shifting from what I would say is that reactive to proactive and thinking about like fishing simulations as an example.
[00:05:48] Fishing simulations are great as people go through them and it helps them say, you know, reduce the exposure because they've made, they understand what fishing is. Like if you don't do any fishing training, I read an interesting report, I think it was from Boeseran or Boeseran Security, they're out of Canada.
[00:06:07] They did a research study on how well fishing simulations do or don't work based on a study that came out of one of the universities out of California that basically was saying that security awareness training is a waste of time. Like that you're going to be a waste of time. And the research actually came out and said that that was true if you only do it once a year.
[00:06:33] And they were able to point that you do the training and at 30 days, how the shift back to bad habits comes at 90 days at six months. And then at like 300 and, you know, 70, you know, 65 to 70 days, depending on when you get that close to that end of year or past the end of year. It was back to like 92% of being programmed to now go back to bad habits.
[00:06:57] So I think this kind of is a good transition to talking more about that proactive because one of the things I think that comes to mind for me is, you know, what's the difference between human risk versus the technical threats? Like they're interwoven or should be, but like what's the difference? Because I think that's what you're talking about with getting into the proactive.
[00:07:17] Exactly. Exactly. And that point about habits is really important because in any walk of life, in any process, if you're not reinforcing it, you're going to revert back to what is easy and convenient in security that often is what is the least secure.
[00:07:35] So, yeah, your point about, you know, how the ecosystem and the end users can interact is really important because there's so much data that we can identify using those systems that inform us about the end users. And at the moment, one of the challenges that people have is being able to, that data can sit in disparate places and being able to understand and collate that information in a way that makes it easy to digest, but also helps you to identify how those things combine.
[00:08:03] You know, an example is we can train somebody up on secure passwords, best practices, and we can send them a policy where they'll sign a document that says they're going to change their password every 90 days. But how do we actually monitor that? How do we actually verify if they're doing that? That can sit in the systems. You know, 365 can tell us when they last reset their password, can tell us when they have MFA set up. But how often are we using human? Is it a good password? Well, exactly. Exactly. Have they just changed it to just add an exclamation mark at the end?
[00:08:32] You know, these type of things where it's trying to get those real-life risk signals that do sit often in our ecosystem but just are underutilized. And then it comes back to your point, Chris, about being proactive. If we can, what a more compelling story to be able to say we're combining these different data points and now we are having a stack that is complementing each other. And that is allowing us to build more of a story. And then we can be proactive and we can action the things we need to off the data that we found.
[00:09:00] And if you're an end customer, realistically, they're going to want to know about the outcome, not necessarily the thought that went into that process because that's what they pay their MSP for. Well, there's an underlying message that I think we're touching on without actually saying. And the reality is that we want to support the end user. This isn't about causing friction or taking away from the end user.
[00:09:25] So going back to, like, the education process I think is fundamentally flawed in the space that we're in. We talked about it before we started the show, like, you know, legacy or antiquated training videos. Training videos that are vague, full of ambiguity, and designed to allow you to pass without really understanding the message. Or the message is so easy to understand, you don't really need to watch the video to get the outcome. And I get some of it.
[00:09:53] Like, at some point, you have to start somewhere. But the thing that keeps going through my head is, from a strategic standpoint, if we're really about supporting the user, then it's not about, like, kind of to your point, like, thinking about why would someone add exclamation point to their password when they change it? Well, because no one's probably done a lot of effort into helping them understand that that doesn't really mean that you've changed your password. It's like having a combination lock, and you're able to figure out the first two numbers.
[00:10:20] Well, it's not going to take very long to actually get it right with the third one, because there's only so many variables that can be, you know, used. And computers are very quick. The example that comes to mind for me that happens a lot, too, is everybody's using a password manager. Awesome. That's great. And you change the password that you use to get into your password vault all the time. But all the passwords in the vault are the same. And you've essentially created the same problem, right? They're not attacking your password vault.
[00:10:47] They're attacking where you use the passwords in the vault to go and log in. But that doesn't mean that the person that you're trying to support understands that or even has a clue as to how those systems work. You know, if I hand you a laptop, I assume you know how to use it. How many times? I don't know about you. I don't know how many times I've seen where, like, I remember with Apple computers, they removed the power symbol from the button that was the power button. And then because then it became the fingerprint idea as well.
[00:11:14] I don't know how many staff I had where they were like, yeah, I turned it off. Okay. And I'm like, how did you turn it off? They're like, I closed the lid. So, like, we did eventually program a lot of the devices for those that were repeat offenders so that when they did close the lid and actually shut the computer down, you know, problem solved. We're supporting the user, right? Instead of saying, like, look, I'm going to reinvent how you use this so that you recognize to use the power button. I'm just going to do it for you. Yeah. Yeah. Exactly.
[00:11:42] And that's almost a very good example to show that, like, agility to adapt to your users. But also, a lot of that, I think, comes down to, particularly in security with end users, is to a certain degree, I don't necessarily blame them for not taking the initiative with these kind of processes. Because unless they've been informed about their responsibilities, a lot of them will just defer to their IT department and have a semi-air of complacency because they haven't been told.
[00:12:10] They haven't been informed about that they are a proactive part and that they have these responsibilities to play. And so naturally, then they gravitate towards what they're familiar with or what is most convenient. And again, that comes down to that point about habit. There's something you touched on earlier about, you know, somebody receiving a phishing attack, for example. And one of the things that we're trying to get better understanding, and I think more people are asking for, is why? Like, why was that user targeted?
[00:12:38] What were the steps that led to that social engineering attack that we could have maybe presented at the source? And that comes down to things like the dark web. You know, is that person involved in multiple breaches where their repeat password is being leaked or their security questions and the answers they're giving to them are being leaked? You know, these sort of things that build a profile on that individual user. Those are the type of things that now lead to more smarter attacks rather than the spray and pray sort of Nigerian prince type of incident that you refer to.
[00:13:07] Well, to clarifying there, what we're getting at is not all humans present the same risk. Exactly. So with that, and this is something that I've really struggled with. In fact, I've gone down this rabbit hole of like, how do I protect a specific individual in an organization? And I would categorize it in sort of three categories, physical security, technology security, and social engineering protections. Right? Those three things.
[00:13:37] Like, and when we say physical security, like, yeah, I'm serious. Like, we see where they probably would benefit from having, you know, a security, you know, person traveling with them, you know, traveling in a car that has, you know, the armored, you know, bulletproof glasses, those kind of things. And I know to some extent it sounds almost comical when we think about the space that we're in, the SMB world that we largely live in.
[00:14:01] But we've also seen examples of, you know, CEOs getting, you know, assassinated in the street because of some policy. And I think with the accessibility that we have of technology, it's not hard for someone to figure out where their target is at any given moment, if they're targeting you. So when I think about that, you know, I go back to what we've been talking about is we're not just looking at how the person behaves. We're also looking at what the risk of that individual is as a target.
[00:14:31] And I think that's where our industry gets lost. They stop thinking about it like, oh, well, if you get a text message and it says from whoever your CEO is, are you available to talk? And you know that that's not a normal behavior. Just imagine that on a broader scale when they start to be very specific and targeted where they're actually talking to the CEO of your company and they have done a good job of voice impersonations. Or, you know, what do you have in place that protects either, you know, anyone in that organization?
[00:15:01] Exactly. And that's exactly where we're trying to move towards. You know, you could argue even going back just two or three years, the type of awareness programs people had in place wasn't really making a dent into the stats around social engineering. It was, as you sort of touched on, a tick in the box and then a move on kind of situation. What we have now is the need to be much more intelligence led because fundamentally attackers have evolved so much in the last couple of years.
[00:15:29] And compliance, as we talked about as well with things like GRC, it's changed so much to become much more rigid and again, drive much more need for productivity. And so you're absolutely right about what what is it about the end user beyond just their awareness levels? What is it about their role? You know, do they work in the finance team and therefore process a lot of invoices or even are they an internal recruiter? A recruiter who it's their job to download attachments and look at CVs and sift through them.
[00:15:58] You know, those type of things where people sometimes feel like, oh, it has to be senior management. Who are those with the high value? It's not necessarily. It's a case of those with their job role, who they report into. Like you mentioned with, you know, talking to the CEO, if they have a direct line to them and, you know, business email compromise would mean that an attacker could have that line of communication, could get insight into how the CEO communicates, type of things they speak about. Again, these are all the type of social cues and the type of intelligence that an attacker is leveraging.
[00:16:27] And the frustrating thing is that a lot of these clues and these insights, we have access to them. We could combine the data. But it's a lot of the insights live in separate systems and collating them and understanding if you're an MSP with dozens of clients and hundreds of users across them, understanding what the most critical risk is and where you need to focus your time, what you need to remediate. It's incredibly tough. And I think that's the real challenge that a lot of people are having when it comes to that proactive intelligence led security.
[00:16:55] And it's not like they're trying, right? The threat actors don't have to try to have the information to do the social engineering. I mean, Copilot, I don't remember exactly when it was in the last 90 days or so. They added the discovery when you have an upcoming meeting. But you can also go into Copilot, put somebody's email address in and the name, and it'll do a full profile write-up, scraping LinkedIn and any other public-facing social media information. I mean, it's great for when you have a meeting.
[00:17:24] I had one the other day. They actually called out. They're on the other side of the globe, and we had a meeting scheduled. And on the call, they asked me how weather was in Iowa. My email address does not say lives in Iowa, right? Like, I don't even think my LinkedIn profile, actually my LinkedIn profile might have on the public side that I'm in Iowa. It doesn't say exactly where, but like it's Iowa.
[00:17:49] So the reality is narrowing down where I live because I'm in a state that has such a small population, it wouldn't take a lot. I think that there's some layering that I want to get your thoughts on. If I think about the traditional areas that we've already kind of covered, phishing email attacks, right? We spot those, we do phishing simulations. We're always talking about how do we prevent credential theft and misuse.
[00:18:15] But there's two areas that I think we often don't spend enough time on that are actually sitting underneath the surface. You know, the tip of the iceberg, this is the underneath the water. And it would be the unsafe data practices. And in most cases, they're unintentional. So like, obviously putting sensitive data into an LLM isn't a good idea. But thinking about unsafe data practice, you have to go back and say,
[00:18:39] how well did the organization or individual define data types to clearly understand from an asset standpoint, what needs to be, how you implement, you know, safe data practices? It doesn't really help you if you don't know what data types you're trying to be safe with. And then the other one that goes right along with it is the unsanctioned apps. And obviously we've seen a plethora of that happen in the era that we now live in of, I can build something in the blink of an eye with AI.
[00:19:09] And so we have those level of unsanctioned apps. But I think it goes far beyond that. And we see it going back to the credential theft and misuse when users are like, oh yeah, I'm going to set up an account with XYZ vendor to use their tool. And they're like, would you like to use your Microsoft credentials to log in? And you're like, well, yes, I would. It sure is easy. So like, talk to me a little bit about what you're seeing. Because I think those data points, they sit underneath the surface.
[00:19:36] They're the areas that we're not talking about and we're not really governing well today. I think those are two areas that if we did those two things well, I think we would reduce, and I'm going to make up a statistic here, but I think we would reduce probably 80% or more of what is happening in real time from the threat landscape. Yeah, that data sprawl point is a really important one.
[00:20:01] I think I read that the, it was off the top of my head, I think the average number of applications that somebody has signed up for using their business email over the last 12 years has gone from around 85 to around 97. You know, people are moving towards consolidation. But the amount of apps that are coming out, the amount of new products, the amount of things that are being launched incredibly quickly, people want to test them. And I know a lot of our partners are struggling with getting that balance right,
[00:20:29] where they don't want to clip the wings of their engineers or their clients. But they also are concerned that it's snowballing away from them because who knows, you know, the data residency, the data process of these applications they're signing up for, it increases that data sprawl and it increases that person's exposure. I think that and the point that you made at start around, you know, data practices and defining these kind of things.
[00:20:53] Again, it comes back to that point of standardizing process in a way that is digestible and that is understandable. There's no point in having incredibly detailed, super granular security processes if your staff members can't actually understand what's being asked of them and also understand why. And it's a combination, again, of that cultural shift to take more ownership,
[00:21:18] to put things in place that allow you to communicate more effectively to your staff members and not bombard them, not overload them, but give them the insight they need through things like company policies, through things like awareness training. But then also to make sure that you as the IT team or the MSP are taking the ownership to monitor whether that is actually being followed. And that includes, if you use single sign as an example, you know, monitoring where they are signing up,
[00:21:45] monitoring where their information is being exposed on public dark web forums. And then that way you've got the two sort of two pronged approach of, again, empowering the end users, but then also having some sort of route to actually verify if they are following. And that's something that those two elements are often missing when it comes to security programs in general. Makes me think of the, I had to look it up so that I didn't say it wrong,
[00:22:08] but the five E's of risk reduction, engagement, education, empowerment, environment, and evaluation. And maybe we got, I don't need all five in this particular instance, but I think one of the pieces that we don't do a good job is the empowerment, like helping users be empowered to help other users be more proactive in their security posture.
[00:22:32] And then, of course, that last one is how often are we evaluating whether or not what we are doing is actually effective? Exactly. And that's a really important missing link is, and again, I kind of touched on it earlier. If you can train somebody up on how to use, sorry, how to set a secure password and resetting their password, but verifying whether they're doing it or not is incredibly tricky. And the thing with human risk is that it's universal.
[00:23:01] It has more external validation through frameworks. And it's also visible. Like clients have often looked into this. They're often aware their staff members maybe aren't as empowered as they should be. And it's a medium priority until it becomes a high priority off the back of an instant. And we spoke about this at the start, about how, you know, more MSPs are, if not wanting to become full MIPs or MIAs. Right.
[00:23:26] At least wanting a playbook to be able to leverage the efficiencies they can get with the greater insight they can get with the tooling that's out there to fundamentally become more proactive and outcome-driven with their clients rather than reactive. Not just service resellers, but service enablers. People that can weave together the offering that's there, weave together the products in an ecosystem, and proactively drive security. So, you know, people talk about QBRs being really tricky to get right and often becoming a bit of a procession.
[00:23:55] But as an MSP, if you're able to go into that QBR and say, we've done all this work to combine these data points. We've already taken these steps to make sure we're mediating that risk. And here's a list of what we've done and the impact that's going to have on you guys. That's such a more outcome-driven proactive QBR rather than going to that QBR and saying, these are the points that we've pulled. This is what we think we should do. What do you think? They're going to zone out.
[00:24:21] They're not going to really, you know, unless they're very technical, they're not really going to take it on board in the way in which you hope they would. And the fundamental question they're asking is, is my MSP proactively identifying things that I don't have the ability to identify? And then importantly, taking the steps to then actively reduce my risk. And that's what we find a lot of MSPs are wanting a structure to be able to do, but are finding it quite tricky to know where to start. I think that's the challenge that we have across the board is, you know, where do we start?
[00:24:50] And I think what you're unpacking and what YouSecure is doing is changing it. And I realize that there are other companies doing some of this, but there's probably today not enough vendors or solution providers focused on the human risk element. We look at things like if I put technical tools in place, if I put XDRs in place, if I put mail spam filtering and malware filtering in place, then I'm reducing the threat service.
[00:25:19] And that is totally true. But we're never going to remove the human element from this. So why are we spending so much time not even addressing it in any way, shape or form, but instead saying, because I've done these technical things, I have a direct correlation to how I impact the human risk. And it's not. That doesn't change the human risk. That has only created, you know, barriers that may reduce the probability of it happening.
[00:25:47] But humans are resilient. So if they want something that's in a link in an email, they will find a way to mess that up. If we don't educate them on what actually is going to happen. There is no brand new Beats headphones on the other end of that trail.
[00:26:04] Yeah, I also think psychologically a lot of clients have like an underlying concern about whether AI is going to make jobs redundant and replace people and change their roles forever. And we found talking about human risk is a real validator that human beings actually aren't going anywhere.
[00:26:29] And it's about making sure that we can enable them better as opposed to completely disregarding them and sort of just looking at systems. And it's almost like something plugs into their psyche of like, oh, actually, no, we can make people more at the forefront. We just need to have processes and systems in place that enable that. And also, I think sometimes there is a little bit of fatigue, particularly in the SME space, about hearing all about AI software, hearing all about infrastructure and tooling and that kind of sense.
[00:26:56] And bringing it back to something physical and tangible like their employees. It's a nice antidote. Well, and I think, you know, we've been kind of touching on it, I think, throughout this entire episode. But at the end of the day, the end user and in a lot of cases, the people that do the enforcement, your IT department, your security officers, it's all looked at things that, yes, it's supposed to help protect me. But it's impeding my work. It's getting in the way of it's going to cause me to slow down.
[00:27:26] It's going all the we know all the excuses, the reality. And the most important piece, I think, to take away is that we are putting these things in place to support our end users, to ensure they are successful. And if you don't understand what it is that we're putting in place, then you should be asking why, because sometimes it shouldn't be getting put in place or the version or the way in which it's being put in place. Put it into play is changing the risk in the wrong direction for your organization.
[00:27:57] And, you know, some things are maybe valuable and maybe it will be a better security posture. But is the cost? Does the cost to implement outweigh the benefit? Exactly. And there's also, I think, two broad strands around that as well. Like from the end user's perspective, you know, we've designed the awareness programs to be really non-intrusive. We know people don't want to sit down and do two hours of cybersecurity awareness training. Nobody does.
[00:28:25] But we know that bite-sized continual reinforcement is really important. It will also help with that engagement. Go back to that point about habits, you know, it will help form those habits. But also it will reduce those barriers to entry. And that really, really helps with engagement. But also the other strand is from a partner's perspective. And this is where the, you know, moving more into human risk intelligence is that we know a lot of partners have some time like a Monday morning problem. I log in in the morning. I look at my clients. What do I need to prioritize this week?
[00:28:53] You know, what are the key things I need to remediate? I need to action to make sure that I am securing my clients. And doing that can be incredibly time consuming. And so what we're doing now with Usecure, and it comes back to the point about combining different data sources and different data points. We can now look at the awareness program and say Chris has two outstanding courses and has failed 12% of his phishing simulations. And we've also found a new data breach on him three weeks ago.
[00:29:19] But also what we've also found through our 365 sync is that he hasn't resets password in a year. He doesn't have MFA set up either. And therefore these things combining mean that he's much more of a compelling target for an attacker. And that type of thing where we can then show an MSP and say, look, we've identified Chris. This is a critical task for you to remediate. And these are the reasons why. And so rather than having to trawl through different systems and build that story themselves,
[00:29:47] it sits within Usecure in a dashboard, lists them their top priority tasks. And then again, it moves back to that point about MSPs becoming more process driven, more outcome driven, and moving towards that intelligence provider. Because then it enables them to actually remediate efficiently, saves them time in the long run. And then their client knows or can see a report that says, okay, all these things have been remediated. And I didn't even have to give any level of thought towards it. My partner is taking care of it for me.
[00:30:15] That gets into that whole frequency of task, if you will, is more valuable than doing a large volume of tasks at one time, you know, less often, right? Like if I think about some of the training that I've had to do, it's like, okay, it's that time of the year again. And here's a 30 minute, an hour, however many things that they want me to do versus having it on a weekly basis.
[00:30:41] And it's five minutes or 10 minutes or a series of tasks that I can do throughout the week that might add up to 30 minutes, 45 minutes. But I don't notice it because it's part of a daily routine. It's five to 10 minutes at a time. And it's unique specific to me, which means that I have an understanding that I could go talk about what I'm doing to somebody else in our organization, but that doesn't mean that they're doing the same things. Yeah. I like it. Yeah.
[00:31:10] And also, yeah, it comes back to that point about, you know, this is human risk. Right. Human risk. Exactly. We're all individuals. We are at the end of time. A couple of questions. Where can people find you if they want to ask more questions about your opinions on human risk or how YouSecure is taking on human risk management? Where can they find you? So our website is YouSecure.io. We're on LinkedIn. I'm on LinkedIn.
[00:31:39] We are also at a lot of MSP events. You know, we're really trying to be as visible as possible to get as much of a feel for what our partners are struggling with. But yeah, the easiest way to hear from us is through our LinkedIn page. All right. Last question. Is there currently on your shelf or on your desk a book that you're reading that you think the audience would benefit from? That's a very good question. Or enjoy.
[00:32:07] It does not have to be, you know, work related. It enjoys a weird question, given what I'm about to answer. So I just it's not it's not work related, but it's one of those books that really stays with you. It's like a hundred page novella called A Short Stay in Hell. If you've come across it. I have not. I don't know that I want to stay that long at all.
[00:32:32] It's yeah, it's basically a book about a man who goes to hell slash purgatory. And as I'm explaining this now, it sounds awful. It's really depressing, but also really uplifting at the same time. And basically he gets sent to his own his own hell and has to work out how to get out of it. And it's a hell where he's full of a library of books about any possible story in the world. And he has to find the story that reflects his own life. It's 100 pages long. You can read it in a good afternoon.
[00:33:00] And it's one of those where you will think about it for weeks, months afterwards. It's great. That's great. And the best part is because it is a short story. That means that most of you listening to this show can find a few minutes to read 100 pages. All right. Well, there you have it. For those of you listening, this has been an episode of MSP 1337. Thanks and have a great week. Thank you.

