Video: How MSPs Can Turn Compliance Into Profit According to Choice Cyber Solutions COO

Transcription

Hey channel insiders, welcome back to channel insider partner POV. I'm your host Katie Bavoso and with National Cyber Security Awareness Month upon us, I wanted to explore what MSPs need to know in the often confusing world of compliance. By this month, the Department of Defense's cyber security maturity model certification or CMMC was set to be a mandatory requirement for DoD contractors and subcontractors. So, what does this mean for MSPs and providers?

I spoke with Alex Spiegel, COO of Choice Cyber Solutions, to find out what opportunities lie in the upheaval. Welcome, Alex. It's great to have you. >> Thanks so much for having me. It's great to be here. Thank you so much for being a part of it today. I know you are coming up on the most I'm referring to October so I would say that it's probably one of the busiest times a year for you but I assume that Q4 is just going to be busy no matter what for you.

CMC is now finalized. So and HIPPA is changing so my world has been very busy. Yes, but all good things very good things and we'll definitely dive into all of that today. Uh, I first want to take a moment to get to know Choice Cyber Solutions for you when you talk about Choice Cyber Solutions to whether it be a customer or even a family member. How do you describe it? Because the way that I look at you, you're still a service provider, but you're catering to other managed service providers in a way that I think is really bespoke and unique to them.

How do you describe Choice? >> Absolutely. You're definitely correct. We're a compliance, well, a cyber and privacy compliance services company. So we typically partner with uh managed service providers or MSPs to help them grow their revenue in their business. Compliance puts a structure around cyber security, right? It gives you the things that are necessary and those layers of security in order to meet compliance and those cyber security best practices.

So our business is able to take their client requirements or the things that they're really trying to meet for business development and help add to the MSP monthly recurring revenue. and a typically a lot of project revenue as well. >> So you said the magic word with compliance there. I obviously know that's a huge focus for your company, but why is it such a hurdle or a pain point for the channel providers that you partner with? >> It's really complex and complicated and in my world things change a lot.

So like a couple of years ago, we knew ISO27001 very very well and then in 2022 it completely changed. Well, there was a lot of additions. You know, CMMC the rules have constantly changed and evolved. I think that also there's a lot of room for interpretation in a lot of these things and that causes a lot of confusion where we've been through a lot of audits, you know, we have a lot of resources so we've seen a lot of these things. So, it's less of a question mark in our world and more of a okay, this is how we get it done and here's what we're going to do. >> Very good points for you.

Where was the need as as a company kind of focusing on where you were going to take those solutions and who you're going to partner with to do that? Why focus on going straight to MSPs and solution providers rather than going directly to their customers for example? Where did you say this is really where the opportunity is for us as a business? We started this business to educate MSPs in compliance and help them and empower them to offer compliance services to their clients themselves. we quickly realized that that was not going to work.

Um, and that was eight plus years ago now. My business partner owned and operated an MSP for 21 years. So, he very much saw the gap in the market and what was necessary um, at the time. You know, compliance used to be a nice to have back then. Now, it's not a nice to have anymore. their clients need it and if they bring in someone else from the outside and it's not their partner um a lot of times they lose the business um because they can't stay proactive enough or all of the remediations and things are shown as a negative where in my world I try to show them as a the MSP isn't doing a great job to this point but we just need to add another layer now to meet compliance right and make still shine a great light on them and I'm able to just find a way to bridge that gap to make everyone happy and look good in most situations.

And the partnership opportunities, you know, when we have more than one client uh with that partner, we're able to reuse a lot of resources. The processes that they have are always the same. So like the first time it's a lot, right? They're adding new tools. We have to document things for them. You know, it's a overhaul. But then from there, you know, they can just soar and make a lot of money. We love that. We love to hear that for sure. So, let's talk about something you've already brought up, which is CMMC, which stands for cyber security maturity model certification.

And just to give the audience, in case you're new to that term, which hopefully you're not very new to it by now, it's a federal program that helps ensure the Department of Defense contractors and subcontractors comply with DoD requirements to safeguard federal contract information and controlled unclassified information. So this rule went into effect officially in December of last year. But what does CMMC mean for MSPs and service providers right now in 2025?

What does it require of them? Because it has shifted a bit. >> I truly feel that CMMC is one of the biggest opportunities to happen to this industry and the MSP business since HIPPA um in 2006. So uh there's a ton of opportunity. The majority of our clients and our MSP partners clients um are smaller organizations in that SMB space that do work for prime contractors. So Lockhe Martin, Boeing, some directly for the government and the Department of Defense, but a lot of them through those primes as subs.

So they still have to meet very similar requirements and they're still held to a very high standard, but they don't have the budget. they don't have the same resources because they're a small company. So, we've gotten very good at the SMB space of CMMC and helping them meet compliance. In theory, CMMC is a great thing, right? Um, it's protecting our government, it's protecting our nation, it's a great resource, but for a small business, it can feel really daunting. um and like a huge lift and we try to take that off of our partners and our clients as much as we can. >> And Alex, can you review for me why now is such a pivotal point for CMMC?

It it's taken full effect this year. So talk to me about the details behind it and why it's probably such a stressful point for MSPs and solution providers right now in 2025. So recently the final rule was passed in August 25th of 2025 to go into effect. So they changed a couple of things like who's required to have an audit in the first year, but the final rule really holds accountability and for public inspection and documentation and mandates um really around anyone that touches the Department of Defense or controlled and classified information or FCI, which is federal classified information.

The woman that is in charge of security for the Pentagon and Department of Defense, Katie Arrington, means business. She's very eager to put this in place and make things happen. And we're also seeing a lot of false claims acts. Um, so like clients are claiming that they were compliant at a certain time and the Department of Justice is really cracking down on that too. So whether or not they need an audit in place, whatever they're saying, they have to be able to prove or they will come after them in other ways.

So I think that that in my world has also changed things. The only clients I've helped through DOJ situations came to me with the DOJ situation. I haven't, thank goodness, have the opposite problem, but uh it's still a very lengthy process and very difficult. So there's three tiers to CMMC. In my world, we only focus primarily on level two. Level one doesn't really protect an organization and it's very minimal the overhaul. Level two is what really protects that control and classified information and any type of CUI.

A lot of times my clients also come to us with ITAR compliance which is the international traffic and arms regulation. Um, so that's all around uh like weapons and resources of that nature and the rules are basically of CMMC and then above and beyond. So resources that touch that data can only be US citizens. Um, it just takes it to the next level. Um, so there's just like a lot of nuances and complications that actually aren't new but are new to a lot now that the final rule is in place.

And that third tier is really for the Boeings, the locked, the the big guns of the world and just adds that level too. But all vendors in any capacity if they touch controlled and classified information have to meet CMMC and they have to prove that their men vendors are compliant and meeting CMMC if they're sharing that CI. So the rules are very clear and now that the final rule changes out, they mean business as early as November. >> Oh wow. So, as far as helping the MSPs that you you serve and partner with get up to snuff, so to speak, by November, because that's coming very, very quickly, is there anything that you're able to help streamline?

I guess walk me through your process and how you work with them to be able to become compliant because as I understand it, it it can be quite a bit of a process if an MSP is trying to do it on their own. >> Yeah. And on average for um a business of like a 100 employees that doesn't have much in place, it takes about a year um to actually implement. They have to change a lot of their workflows and different things. So how they go about things is really entirely dependent on the organization, you know, what they have in place, the documentation, their technical tools, where that CUI is living, how they're transmitting it, how they're using it.

Level two of CMMC really cares all about that transmission of controlled and classified information. Um, so stored, transmitted, and used. That's really what it cares about. But it's a comprehensive evaluation, right? It's not just like the technology. It's, you know, the system security from a technical perspective, from governance, from risk. And it really requires like a solid approach um that encompasses the right documentation and resources, right evidence or artifacts including policies, procedures, you know, identifying and documenting where that CUI exists, you know, a network diagram, a CUI flow diagram, and then there everything is kind of put together for an auditor and what they call an SSP, a system security plan.

So that's a complete current updated resource detailing the system environment, the boundaries, the architecture, the controls, um, including how all the assessment objectives may be measured, uh, with links to the policies and procedures. It's usually well over a 100 pages. Honestly, the ones I've seen lately that are 100 pages don't meet the requirements. >> Um, but it's also very dependent on the supplementary resources, right? So, it can be shorter if you have linked resources that document and outline everything, but it's very detailed and the things that they want.

The audits that we went through last year are nothing compared to the ones that we've been going through this year. Um, now that CMMC is in place, the auditors all have are rowing the boat in a little bit of a different direction. We've been waiting for new auditor training to come out since April. So hopefully that'll be out soon and there'll be more streamlined resources between auditors because depending on the auditor you get is the rules that or how they like to do things.

So Alex, by the time these MSPs come to you, come to Choice for help and they've tried this already, how far have they gotten? I'm assuming that it's not very far in the CMMC process. >> It really depends on the partner, the work that they put in, and the resources that they have. Um, you know, I've had partners all across the board from I have two clients and I just don't want to build the business and I hire their employee that's doing it all the way to a partner that really tried for years and then gave us all of his clients.

Um, it really just depends. And then I have partners that, you know, do audits great in other aspects but want nothing to do with CMMC and are like just find another MSP. Um, that's not the way I would go. the rules as is today is that it's all around a shared responsibility matrix. So just defining who's in charge of what and making that really clear. So back to what I was saying earlier, the overhaul of the first one is a lot, but the changes are minimal um for all future clients after that, but the MSP is part of that audit.

So it's a lot of a fox watching the hen house situation. I think is why MSPs originally come to us and then they see how much they can still do and charge and the revenue that they're able to make while we do all the heavy lifting. They shine at the technology, right? The implementation of the tools, the R&D of the tools. We help them select the tools, make sure that they meet compliance, help them set it up to meet compliance, and then do all of the documentation things that they don't want to do.

So the policies and the procedures, the governance side of things. When it comes to compliance, there's usually three lanes. The administrative or that governance side, um the technical and then like the physical side. So only that middle lane, that technical is really where an MSP shines typically. And we shine in the other two and the project management side to get everything done. In my experience, um, my partners don't always have project management resources and just helping them know like this is how we're going to do things.

This is the steps, you know, these are the support tickets you need, this is what needs to happen. It helps a lot and we're able to, you know, advance their client significantly further. A lot of times they come to us with policies andor procedures already started or documented, you know, those formal approved and implemented documents um for each domain or an SPS score um already achieved in some capacity for a client. That's how things are monitored and tracked today.

A lot of times what I find is that the policy or the procedures are way over complicated um and just lengthy um because they're they don't know what they don't know. So like if a policy is longer than two pages in my world that's a problem, right? It should just be simple, easy for the end user to understand and come with a cheat sheet in most cases or some type of quick video or training. And a policy is just the rules. what does compliance say you have to do and the rules to go with it.

The procedures then outline all of the things that you're doing to meet the rules. And I like to keep those pretty high level also and then have processes that go into it. I want to create documentation that needs to be edited or changed as little as possible. And I don't know that that mindset exists in the same way for a lot of partners that come to us um having tried to offer these services. You know, I also that's all I do. So I'm able to streamline.

I'm able to, you know, create processes. I'm able to to do things in a different way. It's impossible to streamline compliance entirely, right? Every organization is different. Everyone's needs are totally different. Every partner functions a little bit differently, but there's a lot of things that can be streamlined. And a lot of the things that the MSP shines in, um, like that technical side and implementing the tools and managing all of these things, if they're doing their job correctly in their lane, they're mostly invisible in a lot of ways, right?

So, I feel like most of the time when we get clients from an MSP that was trying to do it themselves, it's because they were on the brink of losing the client or the client's so frustrated or they're so frustrated. If there's one thing I can, you know, leave your viewers with, it's don't get to that point. You don't have to. There's ways to make money without it and still able to look good to your clients and, you know, make a difference in the compliance world, without the frustration and those things, right?

And staying in your technical lane and not having to deal with the administrative nonsense and the physical side of things, you know, just where it's not technology centered. Um, and making sure that they stay where they shine, right? and showing where they shine. Even if what they're doing is mostly invisible, by documenting all that they're doing, the client's really seeing all that they're doing. And there's just a lot of detail that goes into these things.

And I think that it's so natural for my partners to be doing these things like patch management or whatever, um, help desk tickets, etc., that it's hard for them to map out the exact process that's like like that level that's necessary for compliance. So we come in and we're able to help them in a lot of ways. I like to use compliance for efficiency wherever possible. So a lot of my partners, you know, have improved their businesses through our compliance services for their end clients.

Some of them come to us for services for themselves because they want to, you know, use it for their own marketing or they want to be CMMC compliant themselves or meet a cyber security best practice. And they're able to streamline a lot, right? like whatever we document for one client on help desk ticketing like if they didn't have a process that was fully documented they're able to use it throughout their entire business for all clients. Same on the client side you know we make onboardings for new users so much easier thanks to compliance offboarding so much easier thanks to compliance and workflows in the middle.

So it's all about making the partner and the client see how compliance can help them also. If not it's just frustrating along the way. >> Definitely frustrating. I can understand that. And you've mentioned that there's plenty of money to be made with compliance and plenty of money to be made, I'm sure, with CMMC specifically if you are to be compliant with that set of rulings. So I I want to talk about the opportunities more that you see with with generally becoming compliant generally becoming compliant to the extent that you need to be, but not only that, but with CMMC as well.

What are some of the opportunities that can entice MSPs to want to get started sooner of course rather than later down their CMMC compliance journey? >> There is no reason for an MSP to meet CMMC compliance as is today, but I do recommend that they all eat their own dog food and make sure that they're following some type of cyber security best practices framework. I like ISO27001 2022 or I helped Compti at the time now GTIA create the cyber security trust mark that's designed for MSPs to protect their business.

They don't have CUI or that controlled and classified information. So unless they really need it like they have five or more CMMC clients costbenefit analysis does not prove that they should meet CMMC but they should have documentation in place. They should be protecting their house. they should be protecting their clients um in the right ways and became ready if and when they get more than five clients and it makes sense for their business on the end user side when it comes to the managed service provider and providing those resources to their clients compliance is no longer a nice to have right it's a need and a revenue center at that you know our partner program was developed with more than 30 years of MSP experience and with that in mind it allows us to offer compliance services for their clients and give them the opportunity to stay where they shine and to deliver the same compliance services without the hassle or the overhead.

So typically it involves um moving u Microsoft tenants um so we provide like guidance in different arenas. So they're the Microsoft gurus typically but sometimes the GCC high world and how to get licenses can be confusing or things of that nature. So, we'll help guide through the process where to start. Um, but then once they get in there, they see that it's very similar and they really know what they're doing. There's just a lot of limitations that they're not used to.

But almost always there's an increase in Microsoft licenses. So whether it's to like the government cloud like uh G3 or G5 or into that GCC high um environment for ITAR, there's really almost always a need in that capacity. or if it's, you know, an ISO27001 or a sock 2 or something else. A lot of times they come to us on like business licenses or business premium despite what the MSP's been trying to sell for years. Um, and it's just more economical and better for everyone if they move to like enterprise like E35.

Um, so there's usually always, you know, that as a first step and then from there there's usually additional layers of cyber security to add. Um, so, uh, security incident event monitoring, um, vulnerability scanning, there's just a lot of things that are more of a security 2.0 layer that aren't the essentials to do business or um, but they're required for compliance and really add that extra layer. My favorite partners and my favorite clients are proactive, right? they just want to put cyber security best practices in place.

Want to put a a structure around cyber security and protect their business. Um but the truth is most of it comes from you know what their clients need or what they need for business development or what they need to keep their contracts and that's their motivators and we just have to work within those lines. >> For those who are just maybe starting that CMMC journey with you and who are coming in saying well what else do I need? Does CMMFC in particular dovetail into other frameworks like NIST or any any related ones?

Do they still need to get these other certifications and how do you help them streamline that process as well? Because I'm sure when you do one, it's not exactly like the other and you have to kind of keep going down the dominoes until you can be fully certified. >> So, first I'll just give an overview. So, a lot of them do crosswalk between each other. Um so that means that um one helps meet the other in some capacity. CMMC is based on NIST 800171.

So it is that NIST framework and it goes into a NIST 853 which is a more complex version for government contractors but it's not focused on the controlled and classified information that's UI. So how you protect the cui if you're going to protect sensitive data in the same way a lot overlaps to ISO27001 or even HIPPA if you're going to protect your electronic personal health information your EPI in the same way but a lot of times clients handle those things differently because the rules are different right you have to protect CI to the highest most stringent level and you have to protect sensitive data but not to the same level and standards so sometimes it's the same sometimes It's different.

A lot of our clients have multiple compliance frameworks. They start with one uh business development leads them down another lane uh and they go for the second one. My most complex client has seven active compliance frameworks, all like complicated compliance frameworks. You would think that like a NIST cyber security framework would kind of dubtail directly into a NIS 800 171 and they would, you know, it's about 100 controls that would go right into that 110.

Um, but it doesn't really work like that. A lot of them, you know, if you're meeting an estate 171 or CMMC control will at least partially answer a lot of things. Good GRC tools will crosswalk for you and show you where things match, where they don't, um, and what you need to do. Um, but then nuances like how you're protecting each type of sensitive data, all of that comes down to documentation and knowledge um on how to meet the controls. But I think, you know, with a HIPPA side of things, you know, these new proposed regulations to give HIPPA more teeth, you know, I won't take a HIPPA client now without a cyber security best practices framework.

It's a huge liability to both my business and theirs, and it's just not one I'm willing to take. So, a lot of our partners have uh HIPPA clients, right? A lot of them have built their businesses on medical practices. I know that, you know, that's how my business partner got into the space. You know, that's where he specialized. Um, so if there's one thing I can uh leave you with, it's to go educate yourself um on these HIPPA proposed changes now to get your clients ready for the transition cuz a lot of them are not.

You know, put in the new HIPPA proposed resources that are, you know, cyber focused that can help them increase their revenue. We can absolutely help them do that or put a cyber security best practices framework in place. like >> either one will help towards that goal. But getting back to your question, I think however you start as an MSP, I'm happy in my world, right? As long as you're protecting your house and your clients, however they choose to do that, I'm super grateful and try to help them in any possible way.

On the client side, we always try to make it, you know, what's best for the business, right? What makes sense for them. If they want a cyber security best practices framework, it's okay. Do they have a a big network infrastructure to protect, right? If that's the case, an cyber security framework might be a great resource. Do they do department of defense work? Right? Then they need that CMMC. Uh do they do international work? You know, that's where the ISO27001 or the cyber security international cyber security best practices framework comes in play. or do they really need you know documentation for business development or marketing etc.

In that case you know let's talk to type two might be the best resource so a lot of them come to us with what their clients are asking but I would say at least you know 20% of the time they ask for our guidance and you know through a couple of questions and a needs analysis we're able to direct both our partners and their clients who become our clients in the right direction. I want to talk more about HIPPA that you brought up there because as you said it has more teeth now with the regulations there.

Can you explain that to me a little further? What are some of those proposed regulations and is this probably the most seismic shift we've seen with HIPPA since it was introduced earlier in in this millennium? >> In this millennium, yes. Um but it changed um I think a lot between 1998 and 2006. I'm not 100% sure on the years, but there were different additions and different things. But the fact that it hasn't been updated since 2006 um is pretty terrifying in my world.

The additions are primarily around cyber security best practices and taking care of that data that now lives in the cloud that didn't really exist as much in 2006 and protecting that data from a more stringent level the way that it should be protected in 2025. But the reason you hear about a lot of HIPPA breaches and a lot of different things, it's not because they're not HIPPA compliant. It's because HIPPA doesn't meet 2025 cyber security standards um to actually enforce and protect that data.

I don't know about you, but my technology has changed a lot since 2006. Pretty sure I had like a flip phone uh on at least my fifth iPhone. So, you know, think about how much business technology has changed like a electronic health record or ER system. These things change. uh and protecting them has also changed and their needs have changed. It's been a long time coming for sure, but it's still not a definite right. We would really like to see it happen.

And either way, the way I see things is that the my partner or the MSP is liable at the end of the day, no matter what. If there's an incident, whether or not they're meeting HIPPA, they're the ones liable for the incident. That's who they're going to call and blame when they have a ransomware situation and they can't get into their devices, and that's who they're going to yell at, right? um whether or not it's their fault. They could have tried to sell them you know the right resources 30 times and at every quarterly business review for the last five years and you know been denied or and you know that's what happens.

So using these proposed rules or the things that are changing is a great business development tool for the MSP to go to these clients be like this is coming when it comes things are just going to change like you're going to be expected to have this in play right the audit side is all about you only have to go through a hip audit if you have an incident or a breach you never want to go through a HIPPA audit unless it's there's now proactive versions like you can combine a sock two with HIPPA and you can go through a proactive HIPPA audit or evaluation or assessment just to make sure, but you never want to go through a HIPPA audit with the Office of Civil Rights.

Um, I've been through a few. Uh, it is not fun. Um, you also don't want to go through an audit with the Department of Justice or the DOJ. That also is really not fun. So, helping them enforce and protect their house, um, is great. The most recent HIPPA incident that I I helped uh remediate was with a client that refused a cyber security best practice framework. It was a while ago now. Um but since then it's no longer optional. It's a necessity to do business with us.

But that should be the case for all of our partners too, right? Like they have to protect themselves and their business and their reputation. They're still a client of ours, right? And the partner is still a partner because we did nothing wrong. All we did was try to get them a cyber security best practices framework over and over and when they went through their audit they passed because they were meeting all the HIPPO requirements, you know, but things still happen because they're not fully protected.

So, this just gives you an opportunity to go to your clients to tell them it's coming to implement the tools that you've been trying to sell and those cyber security layers that they're saying no to and really try to protect their business and yours. I'm wondering if there's anything thinking about MSPs in particular who are trying to make sure that they're also encouraging their clients that compliance is important and it needs to be thought of as its own thing.

Is there anything that you would encourage the MSPs of the channel to do to really be able to hone in and have their clients understand the importance of this or do they literally need to set a boundary and protect themselves and say, "If you're not going to take it seriously, we can't serve you anymore." How strict do they need to be? >> I have a lot of friends in the industry that do that and it really works. Um, even if they lose the client, they come running back with their tail between their legs.

I don't know that every resource or every organization has that luxury. So, if you have that luxury, by all means, it's a great great way to go about things. If that's not where your comfort level is, you know, if you don't have that luxury, at least protecting yourself and your house and educating your clients. I don't do it anymore, but my stop gap in the middle was that I made sure that all of our clients signed a a legal addendum saying that we weren't liable in the event that something happened because they refused, you know, our recommendations.

And we still do that from time to time when our recommendations are ignored. So something like that might be a better resource and somewhere where is more comfortable um especially when a lot of the leadership in a managed service provider business and mine is in sales. So you know there's it's really hard to get new business. I always try to go with education over that FUD, that fear, uncertainty and doubt. But I'm not scared to use it here anymore because it's an if not a when.

Um, so if they don't take care of themselves, they will be targeted. They're just easy targets, so why not? A lot of them are getting in through the MSP. So if the MSP doesn't protect their house, you know, they're going to have problems, too. So I think that staying in your comfort zone is really important here. But protecting your business through, you know, legal resources. I'm not a lawyer. This is not uh legal advice, but talk to your lawyer, get legal advice, and have your own resources in place. uh to protect your business, to protect your clients.

I think it's very important. >> Very much so. I totally agree. We have some other interviews with lawyers on Channel Insider Partner POV. If anybody needs to find those resources, too, we've got them. No problem. I want to switch gears for a moment there, Alex, because as we start to wrap up, something I really wanted to talk to you about is actually your position not only at your company, but in the channel and in technology that is such a maledominated industry still.

I I find it to be a responsibility of mine as a female content creator within this industry to really dig into these questions because I'm always so excited to meet and highlight and celebrate women who are at the sea level positions like you. So, I'd love to know who or what, if anything, has played a major role in helping you achieve success in your career, and how do you pass that support along down the line to encourage more women to step into similar roles, whether it be leadership or roles within security like you're in? >> My journey has not always been easy.

Uh, in the 15 years that I've been in the channel and the 10 years that I've been in this business, running this business, who champions you and stands behind you is huge, right? Uh my dad is my business partner and he's my biggest champion and resource but he really pushed me to work for everything that I have and in some ways I had to earn my own name and work even harder because I was just Steve Rekovitz's daughter. I didn't have my own identity.

So the nepotism um in his MSP business when I worked there was huge. But once I started this with him and was a partner and an equal and had the opportunity to hire from the get- go, the respect was there, but my leadership skills weren't. I think understanding where you shine and your superpowers as a leader in any industry, no matter what you do, is critical. you know, knowing where you your strengths are and really knowing your weaknesses and then hiring and surrounding yourself with those gaps or weaknesses as soon as you can afford them.

And opportunity cost plays into everything that I do. So, I love creating slide decks and pretty things, but it takes me 10 hours and I don't have that kind of time with my running a business and a toddler. So, you know, that's where the graphic designer comes in. you know, 2 hours of her time, you know, saves me 10 hours. So, using that also helps a lot from a leadership perspective. Just leading with empathy and leading as a woman, I think goes a long way.

I do not try to be something that I'm not. I am empathetic. I lead with that empathy. I know where I can improve and I'm always willing to do that. I started as a sponge. I just went into every room and just absorbed as much as I possibly could. I got really involved in the what was then the CompTIA community that became the GTIA community and I've always just tried to give way more than I receive. So when I've needed something, you know, it's always just been a phone call away.

So whether it's, you know, knowledge or whatever it is, the camaraderie or like the friendships and the resources that I made there were invaluable to me. it is super lonely at the top and having friends that are also at the top that are also struggling with the same things and meeting them through that community um has helped a lot. Also, leadership coaching has helped and just always trying to learn and grow and do better. That's why we're all in this industry, right?

Like anyone that doesn't have that mindset, you're in the wrong industry. So I think we all have that passion for learning and I tried to focus on learning in the best ways for me. So I hate taking certification tests. Um I sat for my CCNA for the first time at 18 and failed miserably and I've had like a huge fear of taking since then. I've passed a few but it's just not something that I strive to do. But I'm always reading a business book. I'm always you know trying to learn and to grow in other ways. and I surround myself with people that have those certifications and when it's important I make sure that I get them.

But I really have a strong strong passion for helping organizations develop a structured approach to cyber security. I really believe in using compliance um to help each organization um meet and achieve their goals and help my partners along the way. I really try to empower my clients, my team, my MSP partners to achieve, you know, stronger, more secure business that can evolve to this ever changing uh threat landscape. But I really find it very rewarding to see organizations become more secure and proactive and efficient and successful thanks to compliance.

And I take a lot of pride in protecting their v business from threats and helping them win new business and grow their business and you know achieving and understanding and guiding them towards that governance and risk management. So I'm always super grateful to pay it forward and you know share any opportunity to share my expertise or the things I've learned along the way. It's always a privilege to be in this position um to be in a seat where I can help others, but I think being humble is also important um to a certain degree.

I was asked to be a part of a mentorship program about a year ago and I was like, "Yeah, I'd love a mentor." And he's like, "No, to be a mentor." >> And I was like, "Oh, yeah, sure." So, uh I've and you know, I've mentored my team over the years, but not in that GTIA world in the same way. So, you know, I definitely have learned uh that there's always things to learn. You know, there's always a way to be that mentee, but you can be the mentor and the mentee at the same time.

But I really firmly believe that sharing our collective knowledge and sharing our experience, we grow stronger together to make our MSP community a better, safer place. You can learn more about the services from ChoiceCyers at choicecyersolutions.com. Thanks so much to Alex for joining me today and thank you for watching or listening. You can check out every episode of Channel Insider Partner POV on channelinsider.com or watch us on YouTube at youtube.com/ channelinsider_news and trends.

You can also listen to us as a podcast wherever you get your podcasts from. Don't forget to like, subscribe, and follow wherever possible to never miss an episode. Once again, I'm your host, Katie Pavoso, and I'll see you next time.

This transcript was generated automatically from the video's captions and may contain errors.

Choice Cyber Solutions COO Alex Spigel on how MSPs can navigate CMMC 2.0 and HIPAA updates in 2025 to turn cybersecurity compliance into a business growth opportunity.

Written By
Katie Bavoso
Katie Bavoso
Oct 22, 2025
2 minute read
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

With Cybersecurity Awareness Month (October) in full swing, Channel Insider’s Katie Bavoso sits down with Alex Spigel, COO of Choice Cyber Solutions, to demystify CMMC 2.0, explore the latest HIPAA regulation changes, and uncover how MSPs can turn compliance challenges into business opportunities in 2025 and beyond.

Whether you’re a managed service provider (MSP), IT consultant, or channel partner supporting federal contractors, this conversation is packed with insights on how to prepare for new compliance mandates, streamline certification, and grow your services revenue—without getting buried in red tape. 
 

Watch to learn: 

What CMMC 2.0 really means for MSPs in 2025 

How Choice Cyber Solutions helps MSPs become compliant faster 

How compliance frameworks like NIST and CMMC overlap 

What the new HIPAA updates mean for the healthcare sector 

The hidden opportunities MSPs can unlock through compliance services 

Plus, Alex’s advice for women leaders in cybersecurity and technology

🕒 Time Codes:

00:00 – Intro: Why compliance matters during Cybersecurity Awareness Month and the rest of the year, too 

01:12 – What is Choice Cyber Solutions? 

02:16 – Why compliance is such a pain point for MSPs 

05:06 – What CMMC 2.0 requires of MSPs in 2025 

06:47 – Why this year is pivotal for CMMC adoption 

09:49 – How Choice Cyber helps MSPs streamline the compliance process 

12:26 – Common mistakes MSPs make with CMMC 

18:35 – How compliance creates new revenue opportunities 

22:30 – How CMMC dovetails with NIST and other frameworks 

27:08 – HIPAA’s biggest regulatory shift in years 

31:03 – Helping clients understand the value of compliance 

33:28 – Supporting women in cybersecurity and leadership 

39:19 – Learn more at ChoiceCyberSolutions.com

Katie Bavoso

Katie Bavoso is a 2017 Regional New England Emmy-nominated broadcaster with over a decade of professional content creation, production, hosting, and interviewing experience. Starting her career off in TV news, she pivoted to the IT channel to help connect vendors, solutions and services providers, and IT buyers through exciting video content and storytelling. Katie is now the host of Channel Insider: Partner POV, a video and podcast series shining a light on the most innovative solution providers of the IT channel.

Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.