Why Compliance Is a Value-Add For MSPs And Customers

Information security lead at centrexIT explains how compliance goes hand in hand with cybersecurity.

Written By
Katie Bavoso
Katie Bavoso
Nov 6, 2024
1 minute read

Transcription

it's never not needed there's not a single business out there that can tell me hey I don't need this hey Channel insiders welcome back to channel Insider partner POV I'm your host Katie boso and today I'm interviewing Josh hobin information security lead at manage services provider Centrix it Josh and I explore his company's approach to compliance and why it's so important for customers to understand and invest in it especially if cyber security measures are compromised as you'll hear a proper compliance model can be the difference between a few hours of downtime for a business or a few weeks welcome Josh hey glad to be here thanks for having me on so glad to have you here really excited for everything we're going to dig into today first of all though talk to me about your role at Centrix it and also tell me a little bit about it itself yeah absolutely so Centrix it we are a manage service provider based out of San Diego uh area um we have clients kind of all along the west coast we actually have a couple that are East Coast middle so wide variety of geographic locations as well as various different verticals most of our clients are between 50 and 250 employees we do have a couple lower we do have a couple that are much larger than that um we're focusing mainly on your non profits um biotech life sciences and Professional Services are main verticals we've been around I think for 22 23 years now I've been with Centric for about two two of those years so the best two years of its existence I'm sure yeah absolutely that's I like to say as far as my role goes so my title is information security lead and U I say it's fairly accurate for for what I do for the most part so really anything and everything information which includes compliance which includes cyber security um so doing some like if you think about vciso services so working with our clients on road mapping uh budgeting reducing risk you compliance and then also uh doing instant response overseeing sock owning our security products and things like that and then um you the the non-title things they do a lot of stuff internally as well just due to my experience with the MSP around kind of efficiency and Automation and processes well that's exciting to hear about especially with the biosciences that you handle those customers that you handle I can imagine that today's topic is going to be extremely relevant for those so why don't we crack into that right now because we're talking about compliance uh first of all since you're the expert here would you mind for our audience defining compliance for me when we talk about it in terms of it what exactly is it so what really comes down to what I think of compliance is basically complying with regulatory requirements or some sort of security framework so again depending on the client they may or may not have to follow such things like FTC safeguards or even cmmc uh we internally have developed a cyber security maturity model that's based off of the CIS guidelines and we take all of our clients as well as ourselves through it as well uh so when we're talking about compliance it's basically different security measures policies and procedures that are all in place so you're complying with regulatory requirements with Frameworks so I have a question that's probably going to make your head spin but it's important to ask is compliance a cash grab for msps it's necessary I mean um I would say yes it can generate money it does generate Revenue but at the same time uh the role of an MSP we're no longer the break fix you know the computer you hey fix my computer fix my network um we are trusted service providers and trusted security providers so we're going to be the first people that our clients ask when it comes to these things you maybe that question is hey isn't this something you guys take care of me uh take care of for me um but the the role of the MSP has definitely evolved I mean I've been in the MSP industry for almost 20 years I mean it's 17 18 now and I mean it's vastly different now in the things that we're expected to know and to have um so I don't think it's a cash grab I mean it's not going away uh yes it generates Revenue but it's not a uh get get rich overnight thing you know talk to me about your cyber security model at uh Centric it how does compliance fall into that maturity model yeah so again with our cyber security maturity model we took the CIS controls as well as uh industry standard cyber security insurance requirements so when you go through and you're filling out those forms of cyber Insurance do you have this do you have this do you have this in place what we did is instead of going in through and saying hey uh we're going to align you to the uh CIS standards there's like 150 different controls right and no one cares about it no one cares about the controls they just want to make sure that their stuff works and it's up and going so we made a simplified version and it's a very easy to follow five-stage process where it says Hey at level one here are the controls you need here's level two here's level three four Etc and our goal is is to get all of our clients to at least level three we're requiring that for all clients regardless of vertical and then once we get there we can look at what regulatory requirements um does it make sense to invest more to lower the risk um because like I always say you wouldn't put a $1,000 fence around a $100 horse you know you want to make sure your investment is actually worthwhile and as part of that there are compliance things there are policies and procedures that need to be put into place such as designated security officer having an incident response plan a disaster recovery plan business continuity plan wire transfer protocols things like that in place and again we at the MSP are saying hey you need these things but we're getting that information because cyber insurance is requ requiring it in order to be covered in order to have better coverage to have better claims or again your CIS framework Center for Internet Security says this is a best practice and so and they're made up of a whole bunch of different people in the industry working together to make those right so although it is kind of our own system it is it is borrowed and then we're just trying to make it simpler uh so that way the people who you know you you give the presentation to and they they don't really care about uh the controls again they just sayy just make this work like cool okay this is what we need very simple to digest and then you always know what the next step are so hey uh how do we mature what was our budget look like well let's look at the model and hey next uh next quarter we're going to focus on these controls so we can slowly make you more maturity over time can a client say no I don't want to pay for no I don't want to deal with the compliance part uh is that an option they have or will you literally not take them on if they don't want to do it the answer is is it depends right every client should have cyber insurance and yeah you can get Cyber insurance without certain compliance and policies in place but if you have a disaster recovery plan business continuity plan Etc incident response plan documented you have one in place you're testing it uh we've seen and and obviously we're not in an insurance company but we do work closely with with various ones um we've seen that they can get better coverage or lower premiums or you know maybe it's the same premium but they're able to to get um higher levels of coverage for that and let's just take insurance out of there there's also industry um comparisons and and numbers that show well when these things happen because it's not a matter of if it is a matter of when when you have these incidents has happen you're going to experience downtime and that downtime can be well I can't access the systems or this person can't work or this person I look at their email all the way to reputational harm or you know various other soft CA costs and it showed that if you have a disaster recovery policy or an incident response plan if you have those things documented you can reduce your downtime because every hour every day that you're down I mean you can look at well what's your gross your uh your gross revenue for a year you divide that by however many hours you're working in a year well that's your downtime for an hour so if you're down for two weeks that's 80 hours you're down that's a lot of money right and if we can reduce that by x amount just by having a policy a document that we turn to because again when these incidents happen we need to know exactly what to do and there's two times to do it is you can do it beforehand where you make the policy and you train on it or you can do it while everything's on fire and try to figure out where this is going and wasting time because you don't have it it's never not needed there's not a single business out there that can tell me hey I don't need this you can say you don't want it but you you should have it you need it you talked about in there how there there is inevitably going to be some sort of downtime or some sort of situation in which there will need to be addressed the cyber security of a company might need to be addressed and that was one of my questions that I wanted to ask if a client is still breached does that mean the compliance model failed and as you said right there it doesn't because there's a difference in getting you back up in a day or getting you back up in two weeks and it's all about how you make that plan yeah you say um we say again it's not a matter of uh if it's going to happen it's a matter of when so we can put these things in place to try to prevent it yes that should be done uh we want to focus on making sure it's prevented but when it does happen we want to be able to recover as quickly as possible and limit the blast radius and all of the things that we do all the preventive action is to do that because it's going to happen but we need to be able to alert to it very quickly respond to it and recover from it as quickly as possible to reduce that downtime you've mentioned cyber Insurance a few times and that you don't necessarily provide it uh because you're not a cyber insurance company but you do have ones that you would suggest so just based on the recommendations of ones that you go back to time and time again or tell your clients to to take a look into what are some of the top things that they should be looking for when they do uh partner with a cyber insurance company so we partner mostly with fifth wall Insurance who is a absolutely fantastic MSP Insurance partnership they're focused and specialized only in cyber Insurance uh and and Eno policies and they're very proactive uh they will get on the call with you for the clients uh there are tools that you can use um and they'll work I mean hand in hand and right side by side with you for these and help educate the clients one of the things that they do for us is if we have a client who doesn't have insurance through them they will even just review the policy and just have a conversation with the client and they'll say hey um we're Insurance experts and we think this is a good policy you're good uh if you have any questions let us know but if it's not or if they could potentially save them money get them bed coverage you know then that's something that they can obviously assist with and and get them a policy but at the very least it's leading by education it's hey uh it's a third-party attestment to well Centric is telling you to do things I'm not I don't work at Centrix I work at fifth wall and I'm the insurance provider and I'm the one who's going to tell you your policy your dollars and cents and what Centrix is telling you to do it and not just other other msps as well that are out there doing these proactive things you know they can say hey what they're telling you to do is what you should be doing so not only are they educating the client making sure that they're covered U but they're also a partner for the MSP as well saying hey if they're telling you to do this security project or this product or solution you should do it you know it might cost you up front to to Centric or the MSP but then you're going to save money in the back end so going on from there and and kind of returning to some of the the chief complaints that uneducated customers coming in might be asking well why why do I need this why do I have to have it what do you hear when they come to you and you have that initial conversation what's what's usually the hold back for them usually it's a timing thing I mean it can be a budget because it does take a while right so to make these policies I mean we have a um we have a policy solution that that we work with our clients to to give them that does have an upfront cost but if a client were to make these I mean it it takes a lot of time I mean you're you're even if you go through you get a template or you use AI to generate it like a are you sure that it has everything that you need on there you still have to gather all that information you still have to take time out of your day to make it a focus uh to do those things so even if the business itself is trying to to do that there might not be a a a cost for them to do it but there is an internal you're spending labor hours where you could be spending money you know that you're working on the business uh and they might lack the the expertise and the to know that what everything that they need is in this policy and then again if they try you know hiring us or other compliance as a service and providers that come into there there obviously is a cost so then you know you have to figure out you know budget for it or you outway because again it's one of those things where it doesn't get you an instant uh result like hey we installed this security software it's blocking these things right it's hey we we have a plan it's it's a piece of paper it's like well I spent thousands of dollars for this piece of paper not realizing the impact of actually having that and and when these things happen they're reducing the downtime so um I mean I've definitely heard you know both like it's time it's it's money are very common um objections to the compliance side what do you do to kind of help that along you mentioned a solution that you use at at Centrix it to help with that whether it be through a vendor or through something internally that you've created is there anything you've done to just make it an easier or smoother process for your customers yeah so we we've partnered with compliance scorecard so it's same golden solution which is a absolute fantastic solution and in our package we provide 10 documents and every document in our cyber security maturity model is covered in this policy package you get 10 and then uh I'm able to utilize his platform to quickly efficiently at scale deploy these um but when I say deploy I get rough draft because it does take quite a bit of work with the client to finish these right I can I can get a really good rough draft about 90 you know I say 90 95% but it does take the client it is their data it is their business they need to take ownership on it so it's me working with them and passing that ownership of the document off to them to get that rest of the the 10 to 5% done um but in order to even get there I mean I wouldn't be able to do it without the compliance scorecard solution that we're using just to to be frank what we were doing before is if we would recommend these and then we would have to just bring in another compliance as a service uh provider to make these documents and things and uh the thirdparty vendor usually charged I mean it was close to $10,000 per document for them and it's it's money on the table that we're able to to have now and and to kind of continue to build that relationship with our clients by providing these and having the conversations because when we're building these incident response plans and the disaster recovery and things we also get a better and deeper insight into the client's environments and how we can help them better has AI become something that oh no no you laugh has AI become something that's impacted your job or the conversations that you're having with clients well I mean there's really fun ones where you can like have them make pictures and you can like make songs with so you know it's a plenty of time but we wasted on those but uh as far as when it comes to the business I mean you can have have them assist with some of these things the the more conversation we have clients who are curious about well how how can I have this help me or how can this be more efficient um their employees may be using chat GPT or gemini or or what other ones out there um and they're kind of struggling to to keep up with it well how do I know like what information I'm putting and because there's horror stories of like even on the tech side somebody puts in hey uh I have a uh fortigate firewall and I need to convert the config to sonic wall so they'll put the config file with all of the proprietary information into it and these the AI is it's a large language model so it's learning on what you put into it so now you've just put all of this proprietary information into a large language model that now has that information other people can can ask and and somehow get out of there so it's really been around um I mean not to throw compliance back in it but how to use it in a secure and compliant manner so what you can and cannot put in there um and then various different ways to to make it better you know with co-pilot how to actually effectively use it um because it it's not I mean it's it's not going away it's only going to get better more efficient and allow us to do jobs better so the conversations have really been you know hey make sure that your stuff is actually you locked down um because when you throw a co-pilot in there it could depending on the settings potentially see everything that's within the tenant so you have access to SharePoint files and stuff that you aren't supposed to and you didn't know about it and you ask it to query these things well now it can grab this data so making sure that you're you're ready for those things and you have uh DLP policies in place and making sure that your data is segmented knowing where it lives who has access to it and then you know then you can open it up and um know that people aren't going to see what they they shouldn't see so just wrapping up here Josh since you're so engaged in the world of cyber security I would just like to know when it comes to the tools the solutions the vendors out there who you feel most supported by or just have great products are there any of them that you would shout out right now yeah so I mean compliance scorecard for sure Shield cyber is a great uh vulnerability management solution out there um they're kind of up and coming on on that side of things they started on the pen testing side but they do have a really cool product um that not only shows you the cves so how bad guys can get or thread actors can get in um what they can exploit to try to get into your environment but then once they're in there what do they do next it's usually privilege escalation lateral movement their tool shows hey this is how they can get in and then once they're get in this is how they can uh ex move around and make things worse if we want to learn more about Centrix it or if we want to reach out to you where can we go yeah uh we can go to our website Centrix it.com or we're also on LinkedIn uh I'm on LinkedIn as well and if you guys are in any of the the Discord communities um there's MSP geek um there is the tech generates MSP media Network I'm on those uh as well as uh the Reddit rmsp pretty active in there so try to be a little bit of a little bit of everywhere so easy to find me thank you so much thanks so much to Josh for joining me today and thank you for watching or listening check out all episodes of Channel Insider partner POV on Channel insider.com or check us out on YouTube at YouTube / Chanel inssider newws and Trends you can also listen to us as a podcast on your favorite podcast listening platform don't forget to like subscribe and follow wherever possible so you never miss an episode once again I'm Katie boso and I'll see you next time

This transcript was generated automatically from the video's captions and may contain errors.

Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More
Katie Bavoso

Katie Bavoso is a 2017 Regional New England Emmy-nominated broadcaster with over a decade of professional content creation, production, hosting, and interviewing experience. Starting her career off in TV news, she pivoted to the IT channel to help connect vendors, solutions and services providers, and IT buyers through exciting video content and storytelling. Katie is now the host of Channel Insider: Partner POV, a video and podcast series shining a light on the most innovative solution providers of the IT channel.

Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.