

Listen to the podcast
Read Transcript
Erick and Rich discuss Treeline, a new kind of venture capital-backed MSP with interesting implications for the competitive landscape, as well as tips for driving more business with clients by clarifying your value proposition. Then they’re joined by Michael Crean of SonicWall for a look at the interesting and sobering results of the company’s 2026 Cyber Protect Report. And finally, one last thing: The most European robbery ever, and its amusing aftermath.
Discussed in this episode:
Treeline Raises $25 Million to Reinvent IT Services
Thieves steal 12 tons of KitKat bars in Europe chocolate heist
How a Massive KitKat Heist Turned Into Crisis PR Gold
Some guests on this podcast are clients of Channel Mastered. Compensation plays no part in their appearance or the content of the discussion unless the episode they appear on is a “bonus episode” explicitly labeled as sponsored.
Transcript:
Rich: [00:00:00] And 3, 2, 1. Blast off. Ladies and gentlemen, welcome another episode of the MSP Chat podcast, your weekly visit with two talking heads, talking with you about the services, strategies and success tips you need to make it big and managed services. My name is Rich Freeman. I’m chief analyst at Channel Mastered at the organization responsible for this show.
I’m joined side by side virtually this week, unlike last week by your other co-host, our CEO and chief strategist at Channel mastered. His name is Erick Simpson. How you doing Erick?
Erick: Doing well, rich. Doing well, but the calm between the storm of more conference travel is where we’re sitting right now.
Coming off of RSA last week. A little bit of back at the [00:01:00] home office before we take off for attending more events and having more travels in the community that we call MSP.
Rich: Yeah, this week and next week I am home and then I am pretty much not home at all until very late in May. So lots of conferences coming up.
Lots of really good ones. Some that I’ll be speaking at lots of ones where I’ll be interviewing people, so lots of travel to look forward to, but it is nice to have a little rest, couple of weeks at home doing the show with you from the home office.
Erick: Absolutely a little hiatus before we rev the engines again and relaunch.
Rich: Alright, let’s dive into our story of the week. It’s an interesting one. Erick, and this is one that I will be writing about in the coming the next post on my blog channel Holic. And it is about the official launch. Of a new MSP basically called treeline. You go back, you and I we’re old timers.
We go back to the earliest days of managed services. You helped [00:02:00] invent managed services. There were basically just a few models out there. You were either running your own practice, maybe you merged with some other practices to, to create a bigger one. More recently, we’ve seen private equity companies come into the marketplace here and start acquiring and combining MSPs into platforms and roll-ups.
Last year it’s this trend is about 12 months old at this time, but we started to see venture capital come into the space and two companies in particular got a ton of attention. Rightly so last year. One’s called Titan. Funded by a venture capital firm called general Catalyst. Another one is called Shield Technology Partners.
They’ve got money from principally from thrive Holdings, which is part of. Thrive, but a very large venture capital firm. And they changed the model. They introduced a new model into the world of managed services for the first time in a long while, and we now have a third company that fits into that venture [00:03:00] backed bucket.
So what is treeline? Erick I’m gonna approach that by basically telling you what they’re not, and hopefully when I’m done, what’s left over is some kind of picture of what they are. As I just said, they’re not the first AI native MSP, all of these venture backed firms. Titan Shield now treeline, they are AI native MSPs, meaning that they, their whole sort of investment thesis is that we are going to use cutting edge AI to accomplish things that conventional MSPs can’t do otherwise.
So treeline is the first they’re the third that we know about right now, loosely speaking. They’re not actually a new company officially they’re launching this week. They’ve actually been in business for about two years. They’ve got 200 customers. They’ve acquired three MSPs to this point.
They’ve got seven Silicon Valley grade AI engineers on staff. So they’ve been around, not exactly in stealth mode. They’ve been [00:04:00] learning the market, perfecting the motions, and now they’re officially coming out like tightening shield. They’re an MSP, I keep referring to them that way, but they’re not necessarily a services company and they’re not necessarily a software company.
They’re both. And the question is just, are they a services company that owns their own software or a software company that delivers their own services? I tend to think of the of all three of these companies as software companies that own service delivery. That’s what defines them.
And part of why I think that is again what is treeline not, they’re not private equity. They’re not part of a private equity platform. That’s not their strategy. They are funded to the tune, I should say, of $25 million in a Series A by Andreessen Horowitz, the granddaddy of venture capital firms.
And venture Andreesen Horowitz, their slogan is still, software is Eating the [00:05:00] World. They’re investing in an MSP, but as far as they’re concerned, this is a software play that because that’s a services component, gives us an opportunity to make a lot of money. Interestingly, these guys treeline, they are not just about the help desk or the service desk.
Now I fully expect Titan and Shield over time to start getting into other areas of applying AI to build and grow a managed services business. But right now, the cutting edge tools they’re developing in-house are being applied principally to the service desk and service desk optimization and efficiency.
And by all means, treeline is doing that as well. But right outta the gate right now, they’re also, they’ve got their own AI soc, they’re doing AI powered MDR services, and they’re doing AI powered compliance services. Nothing something their peers are not doing. And they are very swiftly moving towards talking to their customers about helping their customers build [00:06:00] AI solutions, use the kind of technology treeline is using in-house tighten and shield or using house to make their end user businesses more efficient and profitable as well.
And so essentially playing that virtual chief AI officer role I’ve written about, we’ve spoken about on the show, they’re already on their way to having that kind of conversation. With customers too. They don’t, treeline does not compete on price. You can tell how they, so it’s basically a two-pronged value proposition they bring to end users, including your clients by the way.
And one is we’re running this super efficient service desk kind of operation. We’re gonna keep your endpoints and your your network and your cloud operational, and it’s all gonna be the best experience of that kind you’ve ever had. But we’re also going to have these strategic consultative conversations about applying AI to the business with you.
And oh, by the way, this is part of the message [00:07:00] because we’re utilizing cutting edge ai. We’re a lot cheaper than anyone else you’ve talked to. So they’re not leading with the price message, but they can and will compete with you on price. And last but not least, unlike Titan and Shield. They are not a rollup Erick.
So their strategy isn’t to acquire as many great MSPs as they can and build this big MSP platform. They’ve acquired three, they will acquire more anytime they acquire a company. It’s because they want some geographic reach or they want some to bring some expertise in house. But this is not a role at play.
This is a managed services play. They are a company you are much likelier to compete with than sell to. And so this is just, it’s a new beast on the marketplace. Erick, a new model and a new issue for the folks in our audience to consider as they think about the competitive landscape and their place in it going [00:08:00] forward.
Erick: Rich things are starting to get real. For the MSP channel in regards to how these different organizations Titan Shield treeline are focusing on leveraging AI in order to lower costs and compete directly with MSPs in a way that we haven’t seen before. This is not possible without leading with AI first and building from a platform of AI and leaning heavily into AI to leverage the improved efficiencies, the clear the clearing of the noise.
Maybe some level one, level two, triage the things that we’ve been talking about, rich for probably the last 12 months, if not longer on the program. And boy, we are watching it unfold right before our very eyes. It just seems like this is happening so quickly. We have [00:09:00] had very interesting conversations on the program and some very, smart guests and panelists that tell us, Hey, there’s an opportunity for smaller MSPs to compete with these folks, but really focus on the fundamentals first.
Get your house in order. Make sure that you have your processes documented. Make sure that your stack is solid, and then think about, AI and how you can introduce it. And so this is a very, it could be, it could create a lot of fear, uncertainty, and doubt in the channel. Rich for some of these smaller MSPs that are thinking, oh my goodness, the Walmart just moved in across the street and I’m the retailer.
Or McDonald’s moved in across the street and I’m the local sandwich shop. But what MSPs have in spades is that customer trust with their existing clients. Great attitudes around helping their clients grow. I think it’s one of these situations where MSPs [00:10:00] have to not freak out about this, but then think very logically about how do I become the modern, the modernized, we’re hearing now version five, MSP 5.0.
I think I missed two, three and four, somewhere in there. Rich, maybe missed three and four, but now I’m hearing five. But I’d love to get your thoughts rich on let’s read the tea leaves together and see what this means to MSPs that aren’t quite ready to sell yet, but thinking about it and how they can leverage what we’re seeing these, big players do in order to build some of that company value and make them attractive for an exit.
Or alternatively, hey, I want to growth through acquisition too. I see an opportunity. We can certainly compete. I think there’s plenty of room for growth here, but I think that all of this, activity that we’re seeing from VCs and PE firms and these acquisitions and roll-ups are distracting MSPs to the point where [00:11:00] we need to get them reoriented back to what makes them valuable to their clients and how to grow their businesses.
What are your thoughts?
Rich: I think that’s exactly right. I would just the only nuance I would add there yeah, so you don’t wanna be distracted and panicky and rethinking the fundamentals of who you are and and solely because there are these different kinds of players on the landscape out there.
On the other hand, you don’t want to be complacent about the way you’re doing business now. You know what, one of the big advantages. That a lot of folks in the audience have right now is if they’re doing their job well, they have these entrenched, healthy relationships with their clients right now, and I I see relationships basically as one of the things that defends software companies, vendors as, as well as MSPs from the, the threat of ai.
And then, it’s a whole different conversation about the SAS apocalypse, but relationships matter in, in that story as [00:12:00] well. And they matter a lot for MSPs. But if you just count on the business the way you’ve been doing it before, getting you through what’s coming now, you could find yourself in a situation where that, that relationship moat erodes on you basically.
So don’t panic. Don’t overreact, don’t throw out the things that have made you successful, but do think about what your customer base is going to want from a service provider like you going forward, and set a deliberate strategy and intelligent, roadmap strategy for getting there so that you can compete with these companies.
In, in treeline case specifically they’ve acquired three MSPs. Their geographic reach right now is relatively limited. And this is still true for the most part. I don’t know the latest numbers on how many companies Titan Shield have acquired, the geographic reach relatively limited right now.
They’re not necessarily an imminent threat to you and your market [00:13:00] right now, but they are. Companies like that or companies like that will be coming along to your market at some point down the road. And remember that, have folks at Shield. A big part of their model is relationship strength.
They’re looking for company when they make an acquisition. They’re looking for companies that are really good at customer service and relationships and operationally messy because their AI can clean up the operational mess and create all sorts of profitability and upside potential.
But they understand the importance of relationships and service just like you do. So you need to be thinking about having that kind of hybrid strategy as well built around what you’ve traditionally done really well, but incorporating AI in the way AI changes expectations and opportunities.
Erick: Yeah, I agree, rich it’s, we’ve all heard the adage, evolve or die.
I don’t know if it’s that d evolve or erode or lose relevance, and lose market share. So evolving, thoughtfully applying, just best practices. Getting the core [00:14:00] business where it needs to be from a. From a net revenue retention perspective, from a, a strategic growth perspective, and then, maybe pivoting to electing a role within the organization that’s more of a customer success role where this is something that we’re seeing more and more rich of MSPs that have been in the channel for a while and are evolving and are seeing this role being.
It’s not a sales role, it’s not really a QBR role, but it’s one of those roles where you are intentionally reaching out and having conversations with clients just to make sure that they’re getting the most out of that solutions that, that you’re delivering to them, as well as understanding what their pains and challenges are and feeding that back to the folks internally that manage those those sales motions and those QBR so they can dig deeper and make sure that we’re delighting our clients and retaining those clients over time.
That’s a big KPI that. Starting to track more thoughtfully now in the age of [00:15:00] m MSPM and A is, net revenue retention, but also, client churn and employee churn and things like that. So some of these basic fundamentals should be squared away then introducing AI to lower your cost of operation.
And, I’m not a, a big proponent rich of competing on price at all. But at the end of the day, if you can be a little bit more efficient and still make your target profit margins, you will be more competitive in your pricing model against other folks. It’s not a race to the bottom, but at the end of the day, if it’s a difference between, a couple of bucks per user per month that’s stopping you from winning business, analyze that and say how much efficiency can we gain through, applying AI in a thoughtful manner.
To see how that reduces our internal costs so that we can be a little bit more competitive when we need to sharpen up.
Rich: And I would say that’s a reason to be serious about AI service desk automation software [00:16:00] right now. Absolutely. In terms of remaining competitive from a price standpoint.
Another good reason though is the excellent point you made a moment ago about investing in customer success. ’cause one of the things that we are seeing in the industry now, mostly from larger MSPs, is they are incorporating AI service desk automation, and then they are reassigning the technicians and the service dispatchers and so on who were doing that kind of work before that the AI software is doing now to customer success.
And what that does is enable you to strengthen and maintain those customer relationships we were just talking about that are a big part of what are going to insulate you from the threat of these venture and p backs newcomers. Plenty of good reasons to be thinking about in a thoughtful way about a hybrid kind of model where we’re gonna capitalize on AI to the maximum extent possible while continuing to to do business in the way that’s made us successful to this point.
Erick: Yeah. And that customer success role is [00:17:00] definitely a big driver of growing existing client revenues because we’re having more thoughtful conversations with these clients and understanding them and their goals and their vision in a way that just traditional, annual or biannual or maybe even quarterly QS that doesn’t impact every single client.
So customer success, prioritizes who we engage with, but again, we’re trying to touch every single client on a regular basis, where sometimes with QS and strategic business reviews, we just don’t do it with every client Rich.
Rich: So to the extent that there are going to be some very well-funded companies talking to your current or potential clients, the importance of having a good, solid, clear message and value proposition when you are talking to current potential clients could not be more important.
And Erick, that’s my best shot at a segue to your tip of the week.
Erick: Good job, rich. Good job. Rich we, [00:18:00] we know that today’s MSP market is much more competitive than it was, when I was operating my MSP, 20 years ago. So aging myself now pretty deeply here. And so what’s the, what is the most important thing that an MSP can do?
To make sure that we win business against our competitors. Setting aside kind of operational efficiency and lowering our internal costs so we can compete, more directly head to head when we need to on price. Again, not recommended, because if we really understand our value proposition and we can communicate that value proposition to our prospects and reinforce that value proposition to our existing clients, that’s what creates the flywheel of folks that want to engage with you against someone else who may be competing but just doesn’t have that unique value proposition nailed down.
Maybe they’re not maybe they’re working [00:19:00] outside their ideal client, target profile a thing. So what really helps close more sales and grow more revenue rich are making sure that. We can communicate clearly what our value proposition is in an MSP, what we do and how we do it, and why it matters to that prospect or client.
We talk a lot Rich on the program about positioning ourselves to deliver business outcomes rather than technology outcomes or reselling hardware and things like that. This is really, I think, the crux of what delays or what extends sales cycles and what, allows prospects to consider other competitors when they’re having a conversation with you.
I’ve been in many sales situations in my career, rich, where it was clearly evident that I’ve done a great job in doing just that. Simplifying my core message and delivering that [00:20:00] clearly. And from a business outcome perspective, I immediately saw. Improvement when we started switching from, Hey, here’s everything that we do for you and here’s what it costs to tell me a little bit about what your biggest challenges are.
What are your biggest pain points? What keeps you up at night, right? And here’s how we’re going to help you, and what are your goals? What are you looking out three years, five years from now? Start thinking that way more strategically. And of course when we talk about service desk and patching and updating solutions software, asset management, helping users, maintain business continuity so they can do the only thing they can do for your business.
Of course, we do all that stuff, but the reason Rich, why our clients work with us is because this is how we help them achieve their business growth goals from a strategic perspective. Switching that up, delivering that value proposition. Tip number one, simplify [00:21:00] the core message. So it directly impacts how the business owner or the leader, or the business unit leader, whoever it is that you’re engaging with, understand what their core needs and pains are.
And sometimes you have to shift that message and you have to qualify a little bit better and do your research before you get on these sales appointments. The worst thing you can do, rich, is show up to a new sales appointment and say, oh it’s great. Thanks for taking time to talk with me.
So why don’t you guys tell me what you do here. That is the deal killer right there. If you don’t come prepared and understand where that company’s origins came from. Get into the history of the company. Express you know how you know what your knowledge is of that. And then ask questions based upon that journey and what’s next.
That’s gonna set you apart immediately from any competitor because you’ve done your homework. You’ve taken the time to sit down and really analyze and prepare your questions based upon that research and based [00:22:00] upon what’s coming next for that client and the other things that are affecting business, today’s security and AI and things like that.
These are great conversation starters. Another thing that I recommend, so that’s the first tip, simplify your core message number two, review your proposal template and start eliminating things that are too technical. No more cling on, right? You’ve got to make it simple and address the address overcoming the business challenges and the growth challenges of the organization.
So instead of saying, Hey, we’re going to patch every Wednesday and we’re going to, close tickets from the services. Talk about how your services are going to help that organization achieve its business growth goals and its business outcomes. So what are the business outcomes? And tie that back, right?
Instead of just having a one page quote. So create a real [00:23:00] proposal. Work with your AI tools to help feed them your existing proposal. Say, I want to transition this into a more outcome based proposal for these types of buyers. And just work with it until you feel that it’s eliminated all of the gobbly gook and delivers the value proposition that matches with your simplified core message and aligns with what those business owners feel are the most important things to them.
And then the third tip, rich, is to speak with a prospect that you may have closed recently or that you didn’t close. Or an existing client and get feedback on exactly what we’re talking about, how you are, what what guidance would they give you on simplifying that core message? What value do they see and what is it that, that we are missing when we are expressing that value and that unique value proposition?
[00:24:00] And give us some guidance on even the proposal. Hey, here’s our standard proposal format. What here we’re thinking about modifying it in this way. Work with a couple of your a clients, they will help you. I know many of my a clients help me along the way in learning to become just a better business owner back in my MSP fledgling MSP days, rich.
Rich: A lot of really good stuff in there. Two things in particular that sort of come to mind. And one is in terms of when you’re simplifying your core message, which I think just purely from a marketing standpoint as well as a sales standpoint, really smart advice. But simplify it and simplify it down to something differentiated.
’cause as we both know it, telling people that we’re really great at customer service and we really know technology. Everybody’s saying that. So really zero in, on, on something. You were getting at this what is the, your business name here way? What is your. Way of doing business that is special and [00:25:00] differentiating that your clients love.
And that’s the core message that you wanna build around as opposed to the stuff everyone else is saying. And then at the end there, there was something you talked about that I think is a really important and useful thing that a lot of people don’t do. By all means, talk to the clients who love you about what they love about you so that you are clear on that.
And you can do more of that and you can highlight that with new potential clients and so on. But there’s nothing wrong with going to the business that decided to hire somebody else of their MSP or that. Fired you essentially, and ask them in a very polite, peer-to-peer kind of way, what could we have done better?
Because if nothing else you’re probably gonna learn some things that were obvious to them, that weren’t obvious to you. But I’ve been in situations before where I’ve seen that turn a loss into a win. Basically where you ask the question, disappointing news, totally understand, [00:26:00] help me understand what we could have done better.
And then, oh, I can do that. And then all of a sudden it’s there, there were five decision criteria, you satisfied four of them, not the fifth. You put the fifth in place and I want you. I, that’s a great best practice to cultivate basically is to ask the people who don’t hire you or who fire you, what went wrong?
How can I do a better job next time?
Erick: I agree, rich, and taking all of this all this data and new awareness maybe for some folks, and then putting it in your sales slide presentation deck. I always recommend that we have a slide deck that we present a value proposition and the highlights of how we work together.
Even the sales proposal. Cut it down to three or four slides. The essence of what you extracted from the conversation. What’s the most important, what are the pain points, and here’s how we address them and help that client grow their business. A great, elevator pitch, that’s your UVP right here.
Your simplified message is what you say in [00:27:00] an elevator up to your floor next to somebody says, Hey, what do you guys do? We help our clients, accelerate the, unleash the potential of their businesses, right? And revenue growth by man, managing the core that drives the business.
Something like that is very, not technical. It’s aspirational and it’s outcome based, right? But yeah drop that into your slide presentation and any, every objection that you’ve heard before from clients because you know they’re talking to their MSPs. Two, you’re gonna try to overcome those in your three or four slides when you present to a client.
So they go, oh, okay. Wow, that’s great. Outcome based. Okay. I don’t need to ask that question. He’s already answered it from an objection perspective. And it just makes the conversation flow a little bit more naturally and a avoids it getting stuck on, little things that really don’t mean a lot in this, in the big picture of things, right?
Some clients get caught up on, a small thing. And those are just, [00:28:00] objections that are easily overcome once you present, the bulk of your value proposition concisely and simply to them.
Rich: Them over the head with it. ‘Cause that’s what what sets you apart and what gets you business.
Folks, with that, Erick and I are gonna take a quick break. When we come back, we will be joined by Michael Kre. He’s the Senior Vice President and General Manager of Managed Security Services at SonicWall. I get lots of security research papers sent my way. SonicWall sent me one recently, their 2026 Cyber Protect Report.
As folks know, I’m interested into interesting statistics. There were some interesting and slightly depressing statistics in this report, and I wanted to get into it with Michael. He was kind enough to join us. We’re gonna be back in a moment, folks. Stick around for that conversation with Michael Cream.
And welcome back to part two of this episode of the MSP Chat podcast, our [00:29:00] spotlight interview segment where Erick and I are very pleased to be joined by Michael Kre. He is the SVP and General Manager of Managed Security Services at SonicWall, and he is joining us as we record this on the very day that SonicWall just published its 2026 Cyber Protect Report.
I got an advanced look at it. There are some really interesting statistics in there, some really interesting advice, and I appreciate Michael making some time to get into it with us. Michael, welcome to the show.
Michael: Thanks for having me guys. Good to see you again.
Rich: I have known you since you were at solutions granted a company acquired by SonicWall that a lot of folks in our audience will be familiar with.
But for anyone out there in that audience who doesn’t know you, I’m gonna assume they know all about SonicWall, but tell folks a little bit about yourself and about the group you lead within SonicWall.
Michael: So nine year United States Army Combat Veteran, got out, started my own business, ran it for 22 years, morphed into being [00:30:00] the MSSP for MSPs was acquired by SonicWall two and a half years ago, and now we’re still doing the same thing that we did as solutions.
Granted, just on a much bigger scale. So providing the MDR services, the SOC and Security Operations center, and being the protector to the protectors and keeping MSP safe and allowing them and their customers to sleep peaceful at night.
Rich: Okay. Like I said the, you folks sent me an advanced look at the report I started diving into there.
The, a lot of the report is dedicated to what you guys refer to as the seven deadly sins of security. And I, that’s gonna be an interesting conversation because if any of those seven daily rules surprises anyone in the audience that’s bad news. And yet, see, there’s a ton of evidence in the report that people are neglecting these seven supposedly basic things.
But there were some statistics in there that immediately grabbed my attention. And I’m gonna start with one. It was the first [00:31:00] one that I looked at and thought, holy cow, could this be right? And it’s, you guys have found that automated bots generate over 36,000 vulnerability scans per second, making up more than half of all internet traffic as they probe every public website for simple thought, over 50%.
Internet traffic is attackers basically probing for weaknesses in public websites. That is incredible. From a sonic wall point of view, from your point of view what is significant or interesting about that finding?
Michael: I think the interesting part to that finding is that, I think we believe that the threat adversaries are becoming more mature.
They’re becoming better, they’re getting really high sophistication and they’re doing all of these really great things. But when you think about that many attacks per second, or that many scans per second, this is a spray and prey. They’re looking for a moment of opportunity. They’re looking for [00:32:00] something that presents itself with weakness.
And when you can automate this and you can go that fast using ai, using the scripting, using this as a service type opportunity, it really does change how quickly they’re able to start taking advantage of people all over the world.
Erick: Michael, you guys have thousands of detection rules, but the report says that less than 1% of them generate something like 80% of all of your alert volume.
What are some of the most important rules and what does the fact that they account for so many alerts indicate to us?
Michael: I don’t know that we can just say what are the most important rules? ‘Cause the tactics and techniques are changing every day, and so this is a constant evolution of things that we’re tracking.
But it’s [00:33:00] some of the most simple things like, why we would lead management interfaces exposed for people to probe and check in on why we wouldn’t try to hide them? Because it’s easy to do. It’s not hard. Why we wouldn’t try to. Just limit the blast radius and cut down the exposure by doing proper segmentation, doing these really simple, easy things.
Look, I think if I had to pick one thing that is the most fundamental that causes probably the biggest problems today, it’s the lack of MFA. That’s probably the one thing that bothers me the most. It’s only a 20-year-old problem we’ve been talking about.
Rich: Yeah. That we’re already ki tiptoeing our way towards the seven deadly sins.
And yeah. I still with you basically about MFA, but before we get there I do wanna talk about something. One, one thing I really appreciate about research like this from SonicWall. And this goes back like five, six years. You guys, to a much greater degree than a [00:34:00] lot of the companies that send me research call out and focus on IOT threats and issues, which I mean five, six years ago was an emerging category of threat.
I’m curious to get your take on what its status is on the threat landscape today, but there was some data in this report specific to iot. It said that IOT related hits rose to 600, 9.9 million. That’s up 11% year over year. For 2025. Is this just basically another year’s continuation of a long-term trend going back five, six years or more?
Or are you seeing something new in terms of the target, the the success that attackers? Is there anything new going on in, in IOT security? That folks should be aware of? Or is this one of those issues that has been an issue for a long time and is just continuing to to grow at double digit rates?
Michael: I think it’s a little bit of everything. Obviously it [00:35:00] is just the natural progression of what we’ve seen for the last couple years and it is going to continue to get bigger. But people are using a lot more of it. When you think about I’ll even use myself as an example. Like I have a dishwasher that’s connected.
I have a refrigerator that’s connected. I have a stove that’s connected. I have so many connected devices in my house, and if I’m not picking a vendor that maybe takes their security a little bit more serious. And if I take all of those things that I have in my home and then I transition that into a corporate environment where we’ve got a refrigerator and a corporate environment and we’ve got a smart TV and you don’t do proper isolation and segmentation.
That’s part of the reason we’re seeing some of this exploitation and these numbers ramping up because it’s becoming easier targets, these jump points that you can then leverage some of these iot devices for the vulnerabilities that exist, that maybe they’re not getting updated or patched quicker enough, or the vendors [00:36:00] aren’t taking care of in the way that they should.
That then just allows for the exploit to a corporate environment.
Erick: So Michael, the report also indicated that 85% of actionable security alerts last year came from credential and identity compromise. Back to your, let’s get some MFA in here. Yeah. And that it takes 102 days on average to patch identity vulnerabilities in the financial services industry.
So what’s the lesson for verticals specific to the ones that MSP support? Across all verticals, what are you seeing?
Michael: The lesson here is the fundamentals matter. It is truly what we’re talking about here. Like some of this business email compromise, identity compromise, the vast majority of it is defensible.
It’s the idea if the bear is chasing a group of people, just don’t be the slowest kid. Don’t let that [00:37:00] be you. And that’s what we’re seeing right now. The people that are doing it well, the ones that are using good MFA, putting conditional access in place, thinking about the policies, using least privilege, trying to use a Sassy or ZTNA to really put their defenses first.
They’re the ones that are surviving right now. Everybody else is, I don’t know why, but we seem to have forgotten the priorities of what we should be doing and how we should be doing it. When we used to defend what was in our physical infrastructure, now that we’re in the cloud, we bumped our head a little bit and lost our way.
Rich: Hundred and two days on average to patch identity vulnerabilities in financial services. You should be using MFA and your client should be using MFFA everywhere they can, obviously folks, but at an absolute minimum, go right now to every banking and investment account that you have and enable MFA ’cause my goodness, [00:38:00] four months
Michael: more than that.
Rich. Think about like your personal email accounts. Like how many people, like we saw it recently, like what just happened recently with a government official and their personal email being attacked. This is common behavior. If somebody really wants to get at me, maybe they don’t take the attack of me and they take the attack of my mom.
My mom isn’t as security savvy. Maybe she’s not running her updates. That’s shame on me. I should teach my mom better. Maybe she’s not using MFA in all of those places, but her compromise could lead to me. So isn’t necessarily just the direct attack that we think it might be. Not to pick on my mom, ’cause I love her to death and I think she’s doing a pretty good job.
But if she’s not, that’s my fault.
Erick: You took the hit on so you were Yeah you’re good, Michael.
Rich: Yeah. If your mom was security savvy, she would be amazing. And
Michael: she is, she’s an amazing woman.
Rich: So we’ve been hinting at the seven Deadly Sins. We should get into that [00:39:00] right now.
But to set that up, there’s a quote in the report that I wanna quote. In part, I think because it calls attention to something very legitimate. That I am at least as guilty of anyone of. And so the quote is, the vast majority of attacks we’re investigating are basic fundamentals still being missed.
We’ve gotten so focused on AI that we’re allowing it to overcompensate for the thing that still probably matter most. And I just spent several days with Erick at the RSA conference in San Francisco. 90% of the 14 vendor interviews I did over there were AI focused. And yet there are these seven kind of basic things going on out there that are still issues.
Talk a little bit, just introduce people to the the seven Deadly sins concept and and just explain why you think more newfangled issues like AI are maybe getting a little more attention relative to those seven issues than they [00:40:00] should.
Michael: I think this is something that.
It’s probably not new. We’ve been experiencing this for a while. It’s the technology hype or the new whatever it is that is being produced. It’s, whether it’s EDR, technology, a next Gen, av, XDR, technology, ai, we get wrapped around the shiny penny. I know we don’t make pennies anymore ’cause it’s too expensive to make them and they’re not worth what they’re being made for.
But it’s that idea that we see it and we stop and we lose the focus on everything that’s going on around us. So the first one you brought up, ignoring fundamentals. We could have all of the, I call it the high speed, low drag, amazing technology that’s backed with all of this awesomeness of AI out there.
But if you’re not patching your systems, what did it do? If you have excessive admin privileges and you really don’t need it, your users don’t need the admin privileges. They just need to be a basic user. What are we doing that allows the [00:41:00] really great piece of the fundamentals of what we’re doing that are being ignored, and how is AI helping us?
Because it can’t really save us from the thing that we’re just allowing to happen to ourselves.
Erick: Rich, did you just use the term newfangled on the podcast? All right. Don’t think I’ve heard that one on the pod yet, but points for you just calling it out. So Michael, deadly sin number two in the report is false confidence.
Michael: Yep.
Erick: What I mean by that is that 88% of SMB breaches involve ransomware versus only 39% at large enterprises. So what does that tell you about false confidence at the MSMB level, specifically with respect to ransomware? What are SMBs and their MSPs failing to do? That they should be?
Michael: I think first it almost starts with the, we’re too [00:42:00] small, we don’t have any information that’s worth anything to anyone.
Why would somebody want to target us? Or overestimating the controls that you have in place because somebody sold you, I’m gonna use the word again, let’s just go with it. That newfangled thing, and you didn’t deploy it properly. You didn’t really understand all of its capabilities and how you could extract every last ounce of your investment.
And we’re killing ourselves. Like we bought all of the tools, we bought all of the stuff, but it actually get deployed properly because we’re so confident that we’re doing it all right, that we’re not checking it. And this idea that, the numbers prove it. If all of these businesses where this 80 plus percentage of.
Small businesses that are having compromises that are showing with ransomware. You’ve gotta understand that you are a target. If you are a nation state, do you wanna go after a bunch of [00:43:00] small businesses that probably never get the attention of the federal government, or you gonna go after one behemoth company?
I’m going low and slow is what I’m going, ’cause I’m gonna get it. And is it really gonna make the news that the two, two cheered dental practice in Memphis, Tennessee got hit with ransomware? Probably not, unfortunately. And they’re probably not gonna report it either. ’cause they don’t want that reputation damage.
They don’t want their customers thinking that they did something wrong and they may not have.
Erick: So what you’re describing, Michael, is the SMBs feeling like they don’t need to invest big bucks to protect themselves because of that old myth that, nobody wants our data. We’re too small when in fact.
You business owner watch your data, don’t you? And then is the challenge that the MSP is not being effective enough in delivering that message, or simply that, there’s a little bit of movement on both sides, right? That need to happen?
Rich: Let’s let’s move [00:44:00] on to deadly sin number four here. And this the sin is reactive posture. We’re moving right into your wheelhouse in terms of managed security. I think Michael, the report says that 44% of all security alerts go uninvestigated. Not because teams don’t care, but because the volume of noise, those 36,000 probes per second, et cetera, the volume of noise has exceeded what humans can process.
So for the MSPs in our audience, what does that imply? In terms of keeping up with threats that are worthy of investigation in relation to services like NDR et cetera.
Michael: I think what it means to me is there’s a couple opportunities to be successful. You can buy it, you can build it or you can partner with it.
You have to be on one of those journeys if you’re going to build it. Then you have to have people 24 hours a day, seven days a week, three or 65 days a year, [00:45:00] that have their eyes on the class that are looking for it and can investigate the events that are happening and have the systems that can help them get rid of the trash.
’cause there are a lot of trash events that take place. Partnering with it is almost the immediate success for any SMB out there partnering with a company like SonicWall, and there’s lots of great vendors out there, but we happen to be one of them where you can have instantaneous 24 7. They’re at your disposal, doing the work for you, keeping you and your customers safe by keeping that ever watchful eye.
It’s like having an alarm system on your home. And if you’re home, obviously when the alarm goes off, you know that you’re gonna get up, you’re gonna go look at it, you’re gonna try to understand why is it telling you that the front door is open? But if you’re not home and that alarm system isn’t hooked up to a call center and somebody actually opens that front door, what do you know?
I think we all know what you know, you don’t know anything ’cause you don’t know that it happened. [00:46:00] For organizations that say, I’m gonna wake up when I get that text message that says there’s a critical alert that only works for so long. We are machines. We need rest. We need to be able to operate properly.
And before too long at 36,000 events a second, you’re probably not getting any sleep.
Erick: So dentally send number six is legacy access models. And you report that 48% of breaches involve VPN as the initial vector. You dropped ZTNA, in a comment a minute ago. What’s the takeaway for MSPs from that, these legacy models?
What’s your guidance?
Michael: My guidance is this is not a sonic well problem, this is an industry problem. S-S-L-V-P-N technologies have been attacked for the last two years. They’re being attacked faster, they’re being attacked more efficiently. They’re finding more and more vulnerabilities. It’s time [00:47:00] for us to put it to bed.
Like how many people go out and buy a new car today and say, I don’t want anti-lock brakes. Let’s go back to the old way of doing breaks. I don’t care about the anti-lock brakes, I don’t care about the collision avoidance systems. Why are we doing it this way in our own personal lives? When it just comes to us, when we start thinking about the survivability of our businesses and how we’re using this connectivity feature that we’re still using a 10-year-old technology.
It just doesn’t make sense to me.
Rich: So we, we highlighted three of the seven deadly sins here, and I don’t wanna put you on the spot. And I’ll also just mention to folks that we will link to the report in the show notes. And so I encourage you to go out and get the whole report, read the whole thing, and it will spell out the seven Dead we sins.
But it, if you happen to have those memorized, can you just touch briefly on what those seven dead we sins are.
Michael: So it’s [00:48:00] ignoring the fundamentals, false confidence that overexposed access. Reactive security postures, cost driven security decisions. That one I’m really bothered by. Rich reliance on legacy access models and chasing hype over execution.
Rich: Go ahead and tell us what is especially bothersome about that one. Sense
Michael: the cost driven security decisions. I was speaking at a conference last week and I ask everybody in the conference like, how many people bought a car in the last 18 months? Lots of people raise their hands. How many of you bought the cheapest car on the lot in that particular model that you were looking for?
Everybody dropped their hands. So why or why are we so concerned about getting the cheapest thing that we can to secure our data, the thing that drives our businesses, that fuels our economy, that keeps our nation safe? Everything is coming down to, I’m not asking [00:49:00] you to buy the most expensive, but why does everything have to be the cheapest when we certainly don’t buy the cheapest cars when we’re out buying?
Anyone? Blows my mind.
Erick: That’s a great analogy. If you want safety and security, you’re gonna buy the car that you feel will protect you and your family. Why that doesn’t transition into, some of these SMB conversations and mid and enterprise conference. I think it’s more prevalent in the enterprise based on your reporting.
But yeah, the SMBs, we’ve, we MSPs have got a lot of heavy lifting to do, to to keep.
Michael: And it’s our responsibility to educate our customers, to tell them but it’s my job to educate my mom. I have a particular set of skills borrowing a line from Liam Neeson. With those set of skills, I should educate people and I should share that information so that ripple effect is they can go out and tell people we can all be better together.
Rich: And so to be clear, and this is really a question for both of you. The issue here in terms of [00:50:00] where the excessive focus on cost is, that’s more on the end user side versus the msp, the MSPs, they understand the importance of getting something good as opposed to getting something cheap. The trick is convincing, talking about it with a customer and convincing the customer to think the same way.
Michael: I personally think it’s both. I’ve heard, and especially for me being a CEO and a founder, I’ve heard so many CEOs and founders of these small MSPs that say, my customer won’t pay for that. And my immediate question is, how do you know? I know my customers. Did you try? No, I didn’t try yet because I know my customers.
So you gave them the answer of no before they could give it to you. That’s. It’s like me looking at my son and saying, my man, why didn’t you just ask me if you could go do that? I thought you would say no. I actually would’ve said yes. Now you’re grounded.
Erick: Yeah, I think you’re spot on, Michael.
I think it’s, and Rich, we’ve spoken on the program before about, setting a date and [00:51:00] time for your customers to subscribe to at least your minimum required, cybersecurity enhanced bundle in order to remain your client because the risk is too great for not only the, that, that client and their business, but also to the MSPs that serve them.
It’s one of these things where you have to move forward in this direction. And for every new client that an MSP brings on board, they’re automatically required to include those set of minimum security standard that you feel. Are necessary to make sure, like you said earlier, Michael, that the clients and you as the MSSP sleep good at night, right?
Michael: Yeah. And Erick, I think it’s not even about what you feel, it’s what you know and it’s that confidence that you portray in those conversations and how you can educate people and lead them. Like I go to my surgeon like, I need my knee fixed. If he says, I need you to do these [00:52:00] five things so that I can do my five things, and if I don’t participate in the journey, I’ll bet you the surgeon tells me that the surgery is not going to be successful and you’re just going to come back to me again and will probably tell me if he’s a really good surgeon, he’s not gonna do it.
Erick: Yeah. The power of the word no, we will not remain my client if you do not pick one of these bundles of services and at and by and if you don’t pick one by this date, we will automatically enroll you in our lowest, required bundle of services. That is it. And then they wanna fight you after that, then you’ve just gotta let ’em go because
Michael: but most of them will say yes, Erick, like Matt Lee tells this amazing story when he was at Iconic and how they went through this process and they were telling their customers, we turned this thing on.
Here’s what your bill is going to be. And they did that multiple times in the year and their acceptance rate was insane.
Erick: Yeah.
Michael: And the ones that told them no, they got the conversation that they wanted to have, they just didn’t wanna have to have it with everybody. Most of the time our customers will say yes if we can just [00:53:00] tell them within reason and logic why we’re doing it and what the outcome is we’re gonna deliver.
Erick: Yeah. Ask forgiveness later. That’s the way to go in these conversations, in my opinion. So I agree with Matt.
Michael: Agree.
Rich: We usually do, yes, in security related matters here. The report we’ve been discussing is the SonicWall 2026 Cyber Protect report. We will have a link to it in the show notes.
I encourage everybody to go check it out. Michael, for folks who wanna get in touch with you talk with you about the, that research or anything else security related, where should they go?
Michael: I would suggest not using courier, pigeons, or smoke signals because I’m not good with those anymore, and the, those courier pigeons don’t seem to be doing a great job.
Drop me an email. I do my very best to reply to every email that comes to me every day. You can reach me at M-C-R-E-A-N, at sonic well.com, or you can just visit us on our website and ask for more information.
Rich: All right, Michael Cream SonicWall. Thank you [00:54:00] so much for joining us on the show, folks.
Erick and I are gonna take a quick break now. When we come back on the other side, we’re gonna share some final thoughts about this very interesting conversation with Michael. Have a little fun wrap up the show. Stick around. We’re gonna be right back.
And welcome back to Breathe this episode of the MSP Chat podcast. One final thank you to Michael Cream for joining us on what behind the scenes glimpse, folks, it was a relatively short notice kind of thing to get him involved in the show. He’s a busy guy, but he agreed to get on and talk with us because as you can see, there are a lot of things to be discussed in that report and discussed in the hominin sense of D-I-G-U-S-T might actually be appropriate here too, just given the degree to which for all the talk about AI and advanced threats and all of the progress we’re making in the technology world.
The fact [00:55:00] that these. Issues and vulnerabilities and threats and the techniques that attacker have been using continue to be effective. Basically that some of these best practices that MFA is not, universal out there right now. A little bit depressing but very useful for us to get that quantified from the folks at at SonicWall.
S spray and pray still works, and there are reasons for that are relatively easily rectified. And boy, I hope anyone out there who recognized an issue in their own business or with their clients is doubly motivated now to get out there and clean things up.
Erick: Yeah. Rich, I think MFA is just a simple first step, and I think that, MSPs that haven’t yet enforced, that might be.
Dreading the awkward conversation that might, you know, that, that may or may not happen with a client. I think that one is a real [00:56:00] simple notification to clients because you’re not asking them for more money. You’re not asking them yet to invest in your next bundle of services for cybersecurity or enforcing that, but immediately just some communications in advance, maybe 30 days because of, what we’re dealing with in terms of risk here is saying, letting them know that, we’re moving forward to implementing multifactor authentication and here’s what that means for you.
I would even, shoot a short. Two minute video about it and just say, Hey, here’s what we’re doing. Here’s how it’s gonna work for you guys. Here’s the reason, and here’s what your experience will be like. And then give them some examples of logging into some of their applications and just show them, Hey, you’ve got an authenticator, however you’re gonna do it right.
Just explain to it. And then just drip that message weekly until the date [00:57:00] that MFA is activated and rolled out. And I would say strengthen up your tier one service desk force for that first week after the announcement goes out and you enable MFA because you’re gonna get a lot of calls and tickets about that.
Clients and users are gonna need help. And some of them may be on vacation on PTO, they show up and they’re like, what is happening? But this is what we do, rich, and we have to enforce these protocols. With our clients and they, and we as MSPs will be better off for it.
Rich: Yeah. It’s basic behavioral economics.
Basically. It’s nudging people in the right direction. It’s making them opt out of the right thing instead of opt into the right thing. I it’s stunning to me every time I cross a vendor that has not made MFA on their software mandatory. And it should just be the default.
It should just be, man. Yeah. Specifically on, on MFA. It should just be the [00:58:00] default, basically. And if to, to your point, if you haven’t had that conversation, if you don’t have MFA in place with your clients, it’s not a question of talking them into it. It’s making them tell you that I’m absolutely not going to do it.
And then you have to consider the client relationship.
Erick: You’re training them in advance rich, you’re acclimating them for the next time you do this with them. Because MFA is not gonna be it. The next thing we’re gonna do is, Hey, we’re enforcing this and here’s your third. So you’re training the clients and the end users to expect these things.
Just like our streaming services have trained us Rich to expect the $3 increase every month moving forward. So it’s one of these things where it’s like, ah, you know what? I gotta have my streaming service, so what am I gonna do? This is for the good of the organization, for the security of the users.
The users are the target of bad actors from a phishing and sing and ransomware approach. Job one, activate and [00:59:00] enable and enforce MFA.
Rich: Folks, that leaves us with time for just one last thing. And this is a story that I’m guessing some people might have heard about a little bit, and when I first came across it, I thought to myself is there anything more European than a chocolate heist?
Because that’s not what gets stolen in the, like we, we’ve talked about, raccoons stealing alcohol on this show before that. That’s what our, what Americans go after. Apparently not so much in Europe where we learned that a a shipment of 413,793 Kit Kat bars were stolen on their way from a factory in Central Italy to Poland.
413,793 Kit Kat Bars. I looked this up before here in Seattle, at least, I’m sure Prices vary. A Kit Kat bar goes for $2. So that’s actually, you know what, $827,000. Worth a Kit Kat bars, not a minor heist. Still interesting that chocolate is what they went a after. The [01:00:00] other thing that’s interesting, or at least fun, if there’s any fun about somebody getting robbed of that kind of money is the fun that people have been having with this story from a marketing standpoint.
So the folks at Domino’s for example posted in social media we’d like to share our thoughts and condolences with Kit Kat. And then it said, on a completely unrelated note, we’re pleased to announce. We’ll now be selling a new Kit Kat Pizza. Charlotte fc, a major league soccer club. Same kind of thing.
Thoughts and sympathies. On an unrelated note, we’re happy to share. We’ll be offering roughly 413,000 Kit Kats at Saturday’s game. That Ryan, a bunch of people have had a little bit of fun with this unfortunate news that has befallen nisley. The folks who are responsible for the Kit Kat Bar, which just by the buy Erick, is a delicious candy bar.
Erick: Oh, I know. And I know Nestle’s gimme a break with all these memes and all these jokes. You’re profiting off of our pain. My question is, how do you [01:01:00] fence all these Kit Kat bars, rich? Like, where do you go? You can’t like it’s, that would be, I guess maybe we’ll have a follow up and figure out if they identify these Kit Kat thiefs, or is it gonna be like, a heist at the Louvre where who knows, they, they dropped a few Kit Kat bars along the way, but we don’t really know where they are these days.
Rich: They got hired by a billionaire who loves KitKat bars so much. He said, go steal only 400,000 of them. And yeah the world will never know who that sponsor will. It’s impo. I had the same thought about fencing. I don’t know how you fence 413,000 KitKat bars. Exactly a pallet at a time or something.
But we’ll see. Time will tell if this turns out to be the perfect crime.
Erick: The chocolate
Rich: all the time. Got for you. This week on MSP Chat, we’re gonna be back in a week’s time with another episode for you. Until then, I’ll remind you this is both a video and an audio podcast, which means if you’re listening to us right now, but you’d like to check us out on video, go to YouTube, book up SP chat.
If you’re [01:02:00] watching us on YouTube, but you’re into audio podcasts, go to Google, apple, Spotify, wherever you get your audio podcast, you’re gonna find us there too. And wherever you find us, please subscribe, rate, review. It’s gonna help other people discover and enjoy the show. Just. Like you do. This show is produced by the great Riley Simpson, part of the team with us here at Channel Mastered channel mastered where we work with vendors to help them launch, grow, optimize perfect MSP channels.
You can learn more about all of the services we provide at www.channel Mastered.com channel. Mastered has a sister organization called MSP Mastered, that’s Erick working one-on-one with MSPs to help them grow and optimize their business. You can learn more about that at www.mspMastered.com. So once again, we thank you for joining us.
We’ll see you in a week. Until then, please allow us to remind you, as we always do that you can’t spell channel. Without [01:03:00] MSP.
No products in the cart.
Subscribe and listen to future MSP Chat episodes with your favorite podcatcher
MSP Chat Podcast
A look at the strategies, services, and success tips IT providers need to make it big in managed services from two of the industry’s most experienced MSP authorities, Erick Simpson and Rich Freeman of Channel Mastered.