You already know that MSPs remain under attack. The question: What are you personally doing to lock down your business from potential hackers, ransomware and malware attacks?The issue remains particularly timely for managed IT services providers. Consider the latest anecdotes:Research – MSP Cyberattacks: Over the past year, 74 percent of MSPs have suffered a cyberattack, with 83 percent reporting that their SMB customers have suffered one as well, according to research commissioned by Continuum and conducted by Vanson Bourne. Research – Ransomware Part One: Eighty-five percent of MSPs reported attacks against SMBs over the last two years, compared to 79 percent of MSPs who reported the same in 2018, according to Datto's latest Global State of the Channel Ransomware Report. Research – Ransomware Part Two: Ransomware attacks continued to become more focused and sophisticated in Q2 and Q3 2019, an Emsisoft report says. In contrast to the spray-and-pray campaigns of the past, threat actors are increasingly targeting larger and more profitable targets such as businesses, schools and government organizations, the company says. If MSPs and their technology suppliers don't move more aggressively to address cybersecurity, the MSP industry as a whole could face a crisis of credibility, ChannelE2E has warned.Sign up immediately for U.S. Department of Homeland Security Alerts, which are issued by the Cybersecurity and Infrastructure Security Agency. Some of the alerts specifically mention MSPs, CSPs, telcos and other types of service providers. Study the NIST Cybersecurity Framework to understand how to mitigate risk within your own business before moving on to mitigate risk across your customer base. Explore cybersecurity awareness training for your business and your end-customers to drive down cyberattack hit rates. Connect the dots between your cybersecurity and data protection vendors. Understand how their offerings can be integrated and aligned to (A) prevent attacks, (B) mitigate attacks and (C) recover data if an attack circumvents your cyber defenses. Continue to attend channel-related conferences, but extend to attend major cybersecurity events — particularly RSA Conference, Black Hat and Amazon AWS re:Inforce. (PS: Also, keep your eyes open for PerchyCon 2020 -- more details soon.) Clearly documented information about basic and advanced security settings in their products. Fully documented information about known cyber vulnerabilities, and timely, easy-to-find information about closing those vulnerabilities. Easy-to-find contact information for reporting or requesting information about cybersecurity issues. This should be far more than a generic "contact us" inbox. Zero finger pointing between vendors while investigating and mitigating a cyber incident. Clear product roadmaps that explain cyber features and expected delivery dates. ConnectWise is working to build an Information Sharing and Analysis Organization (ISAO) for technology solutions providers. Datto has been partnering up with vendors on information sharing efforts; and NIST is seeking comments from MSPs on a project titled “Improving Cybersecurity of Managed Service Providers.” In the meantime, this guide from NinjaRMM is vendor-neutral and all about MSP ransomware mitigation. No doubt, selling security services is a major MSP opportunity. But if you don't practice proper security inside your business, please avoid the temptation to pitch cybersecurity services outside of your business.
Related Events
You can skip this ad in 5 seconds