Youtube video

April 24, 2026

Episode 121: FOMO Pressure

Listen to the podcast

Read Transcript

 

Erick and Rich discuss why agentic AI makes business resilience versus just cyber resilience a necessity for end users and a strategic relationship builder for MSPs, as well as why and how MSPs can boost net revenue retention with their clients. Then they’re joined by Avihay Nathan of Palo Alto Networks for an insider’s take on both the challenges and opportunities of agentic AI security. And finally, one last thing: Ever wished there was a way on long drives to heed the call of nature without pulling off the road? Problem solved!

Discussed in this episode:

Business Resilience and the System of Speed

New Survey Highlights Gap Between Perceived AI Readiness and Tested Disaster Recovery Capability

Autonomous but Not Controlled: AI Agent Incidents Now Common in Enterprises

Agentic AI’s Scary Security Risks

Chinese car company patents voice-activated ‘in-vehicle toilet’

Some guests on this podcast are clients of Channel Mastered. Compensation plays no part in their appearance or the content of the discussion unless the episode they appear on is a “bonus episode” explicitly labeled as sponsored.

 

Transcript:

Rich: [00:00:00] AI adoption has already outpaced security. Your clients are using AI tools without visibility or control, exposing sensitive data across unmanaged systems and asking questions. Your current stack wasn’t designed to answer. Whether you planned it or not, you already own this risk. This isn’t just a new threat, it’s a new service category.

AI detection and response enables MSPs to deliver real time visibility into AI usage, detect risky behavior as it happens, and enforce guardrails across users, data and systems. And most importantly, it’s something you can package as a high margin recurring service. AI isn’t slowing down. The only question is, will you be the MSP who controls it, guides it, and gets paid for it?[00:01:00]

Wanna learn how early adopter MSPs are turning that risk into new recurring revenue? Fast? Then join Ms. P Chat co-host Erick Simpson for a webinar entitled The First MSPs to Own AI Detection and Response Will Win. It takes place Thursday, May 7th at 8:00 AM pacific time, and you can register at https bitly slash ai dr.

Webinar. That’s https, BI t.ly/ai Dr. Webinar, all one word. We’ll see you there and now

onto the show. And

3, 2, 1. blast off. Ladies and gentlemen, welcome with our episode of the MSP Chat podcast. Your weekly visit with two talking heads, talking with you about the services, strategies, and success tips you need to make it big and managed services.

My name is Rich Freeman. I’m Chief analyst at Channel Mastered, the organization. We’re responsible for this [00:02:00] show. I’m joined this week as every week by your other co-host, our CEO and chief strategist at Channel Mastered. His name is Erick Simpson. Erick, how are you?

Erick: I’m doing well, rich. But calm before, more travel storms for both of us.

I’m catching up and pre preparing mentally for everything that I still need to do while I’m traveling next week. To keep things running. So it’s always a bit of a juggling act and some tells me, rich, that it’s not gonna slow down for the next few months for either one of us.

Rich: I know in my case, there is a slower period very late June into July which I’m is a good thing. There’s gonna be a little bit of time to be at home and focus on things that are hard to get to when I’m traveling. But yeah, I as we’re recording this on Wednesday the 22nd, I’m about an hour away from going to the airport heading down to Las Vegas for the Google Cloud Next conference.

I’m just staying there for Kaseya Connect, where you and I will join forces again, which [00:03:00] we’re moderating a session there. We’re doing podcasts interviews. You’ll hear good stuff from that conference on the next episode of the Chaa. And then, for me, it’s just one thing after the next, after I basically with the exception of two, three nights, I am not home until I finish up a vacation.

There is a vacation in there at the end of May.

Erick: Rocking up the miles, as we like to say. And you know what, that’s a whole other topic about how, how much less we’re getting for these air airline loyalty programs. Enough of that. Let’s get into today’s story of the Week.

Rich.

Rich: Let’s get into our story of the week here. And it it concerns resilience, which was the topic of my most recent post in channel hallock, my blog, which you can find at channel Hallock News. I’m gonna set it up with some statistics that were published just within the last 48 hours here.

And this is from the Cloud Security Alliance in conjunction with a vendor called Token. They found that 53% of the organizations they polled are [00:04:00] using agents autonomously for low risk tasks, but they do have, agents doing stuff with some human review on low risk of about 13% of organizations.

So a pretty small number Have fully autonomous agents operational on site right now. On the other hand, monitoring is periodic 59% basically said they’re keeping an eye on this here and there. They don’t really have a full-blown governance model in effect for these these agents.

68% said they have high confidence in their visibility of what the agents are doing, and 82% have discovered shadow AI agents in the past year. So maybe they shouldn’t be quite so confident. Here’s some more data from a security vendor called Keep It. 94% of the people they survey said they are confident their current disaster recovery plan covers scenarios involving a agentic ai.

33%. Also said, however, that they only have partial control over the [00:05:00] use of AG agentic AI in their organizations. And only 41% have significantly changed their approach to disaster recovery due to the fact that they’ve got these AI agents operating autonomously that they only control. Partially right now.

So resilience cyber resilience has been an important topic for the MSPs in our audience for a long time. Cyber resilience traditionally is a combination of security and backup. You wanna keep data and systems safe and if when something goes wrong, you wanna know that you can get impacted data back reliably as well.

That’s cyber resilience. It’s always been important for MSPs and their clients. Right now. It is even more important right now because at a. Constantly accelerating rate. The businesses MSPs are responsible for taking care of, have agents running around, doing all sorts of stuff. The ENT technology, let’s face it, is still in its infancy.

It does weird stuff. [00:06:00] And as we’ve just seen the businesses using these things don’t have perfect visibility in, into what’s going on out there. So helping your customers with cyber resilience is even more important than before in the age of Ag Agent ai. Now, I wrote about this last week and I bring it up now because after you and I were in Las Vegas together at the Channel Partners Conference, I flew out to Florida and went to the Enable Empower Conference.

A big theme that they were emphasizing with the MSPs and their audience was don’t talk cyber resilience with your customers. Talk business resilience. Cyber resilience is about protecting systems and data. And you talk to a CEO about cyber resilience, they’re gonna move you along to whoever is responsible for systems and data.

That’s not a CEO business owner con conversation. It’s an IT conversation. Business resilience is about business continuity, meaning will I continue to have a business if something goes really [00:07:00] wrong? Natural disaster cyber attack unit. That’s something that’s, business resilience is something you can talk about with a CEO and they’re gonna wanna talk about with you.

And so that I think is sound advice. I like the sound of that. One of the things I came home from that conference appreciating though based on things enable executives said based on things enable partners at the conference said to me is we need to be thinking more than ever about resilience right now.

And thinking about resilience beyond cyber resilience and even beyond business resilience because of we find ourselves in this very new, constantly developing AI and especially agentic AI environment. And I think, and if this touches on themes we’ve touched on here on the podcast within the last few weeks in terms of there being.

A lot of uncertainty out there right now about where AI is going next and how quickly it’s gonna get there and what the implications are for everybody. This isn’t going [00:08:00] away. This is not like a temporary phenomenon. Some of it is, but this technology is going to continue evolving at a very rapid rate.

And so to deal with that effectively as an MSP and to help your end users deal with it effectively. Whatever their field it is. You need to think, I think more broadly about resilience, you need to be thinking about cyber resilience and you need to be positioning that to the customer as business resilient.

But as people at the conference we’re talking about, you also need to be thinking about financial resilience. You need to be thinking about workforce resilience, payroll. Do I have the right people in the right roles? You need to be thinking about margin and revenue and profitability, resilience.

Basically, if you’re in a world where a technology we’re still coming to understand is evolving at a very rapid pace and will continue to do so more or less indefinitely, you really need to build a, an end-to-end kind of resilience into your business. [00:09:00] An ability to adapt quickly to whatever it is that comes next.

A flexibility in every different dimension of what it takes to be a business right now. And it was just something that I hadn’t really thought of prior to the Enabled conference. But like I said, I wrote a whole post about it. ’cause I think it’s sound advice for anyone. It’s for MSPs, for their customers, and for you and me at Channel Mastered.

Erick, I think everybody needs to understand the world can change on you very quickly and you need to be in a position to take advantage of the opportunities, compensate for the challenges very rapidly as they appear.

Erick: You got my neurons firing today, rich. So good on you. I, so a few thoughts, right?

So I, the, what you just ended with here, this business resilience conversation. This, it goes beyond cyber resilience. It goes beyond AI resilience, everything underneath that business. The core, this is [00:10:00] the, it speaks to the age old challenge that MSPs have traditionally had in trying to adjust their conversation and their perspective with their clients to get them to do the things that they know the client clients need to do to achieve this business resilience.

So think of a world where instead of going into a new prospect conversation or an existing client conversation, when you’re trying to, have those boardroom conversations that we always talk about right on the podcast from the server room to the board. Instead of saying, Hey, we’re gonna do a, an AI assessment, we’re gonna do a cybersecurity assessment, we’re gonna do a network assessment.

No, we’re gonna do a business resilience assessment. Think of the shift in that conversation and how different that sounds to a business owner where you may not have a relationship. They’re talking about, wow I’ve met with three or four different IT companies. You’re the first organization that’s talking about [00:11:00] business resilience.

So if you, if we create this framework, rich, where the business resilience is the goal, maximizing, maintaining, and strengthening that business, resilience that everything else tucks up under there, financials, performance, profitability employee churn, hr, payroll, all these things that technology, ai, cybersecurity.

This, I think, is a very interesting area that I’ve not heard a lot of folks speak of in that way. So let’s type it rich and let’s start talking about, hey MSPs. Now the path forward is having conversations about business resilience, where you now, whether or not you deliver these services yourself, you can bring in other experts in other areas.

Kind of reminds me of the days when we were MSPs ourselves, rich me and my team. And we had this tool called the Client Solutions Roadmap. And [00:12:00] what we would do is identify all of our clients and every single thing that they would need to run their business. And we would deliver the things that were within our wheelhouse.

But then when we f found things that we didn’t wanna deliver directly, we would partner with other vendors to deliver those services. Think, telecom, think cabling, think even, accounting services, legal service, we, ’cause we had all these clients in different areas and we would bring them in and do that thing.

So if you think about this business resilience concept, mapping out everything that it takes for a small and or medium business to operate, which is very similar to what it takes for an m MSB to operate. We’re not starting from scratch here. Interview some of your clients and then create this business resilience assessment and change your conversation so that you’re now creating a scorecard of business resilience for your clients.

I’m bleeding into I’m over I’m overtaking my tip of the week with this one Now Rich, ’cause you got me going, right? So creating a scorecard where you’re measuring these things [00:13:00] objectively with your client’s input and then identifying and prioritizing what they need to do with your help or with the folks that you collaborate with.

And then engaging with the client’s own other strategic. Partnerships that they have, they’ve got a turn, they’ve got folks that you can sit down and interview and gather data to complete this scorecard, and then sprinkle a little AI magic on top of that rich, and then see what happens. And have those conversations move the needle together with your clients.

You become probably even more tremendously stickier with them when you’re helping them really grow that business and look out for any, gotchas or pitfalls along the way. So I like that a lot. And then my last comment would be about some of those the the data that you shared of these polls.

I, I felt like there was a lot of overconfident responses in some of that data about, 94% of, folks surveyed thought that their DR plans cover [00:14:00] scenarios with agent ai, but 41% of them, the other way. Don’t really have a plan to address it. So that was interesting. But maybe I’m colluding things that, not being the analyst on our team that that you are rich.

I’m just found some of those numbers a little bit striking. But I’m gonna stop there ’cause I just fire hosed you and probably everybody listening. Love your feedback.

Rich: First of all I could not be more on a lockstep agreement with you about overconfidence being a theme, I think, in both those studies right there based on, yeah.

And we’ll link to to press releases about both those in the show notes. You can see the high level numbers you click through the underlying report. If you wish to,

To follow up on what you were saying, earlier there, uh, Erick, you know, how many times on the show have we talked to people about how at a time when the traditional services MSPs provide, have become commoditized or getting very close to commoditize?

If you wanna have. Sticky, high [00:15:00] margin, profitable relationships with customers. You gotta move to more of a strategic relationship and have more of a strategic dialogue with the customer. And you wanna be delivering outcomes as opposed to products. And to your point, business resilient, and this is something by the way, enable said as well, business resilience is an outcome.

So it’s a strategic conversation that you can have with a a business executive, a CEO, a business owner, you can broaden their perspective on what it means to have a resilient business and what’s required for that, which is gonna be valuable in and of itself. That is a strategic conversation.

And what it can bring you to is an outcome, which is we have now helped you get to a place where you are resilient in all the different senses of this. You are ready for anything that can hit you. So it’s. It’s a solid piece of advice both because we’re at a time, the evolution of AI when businesses need to get more resilient than they are clearly.

And also [00:16:00] because this is a really good concrete way to pursue the advice we’ve been sharing with listeners on the show about being more strategic and outcome oriented.

Erick: Yes. And I’m my mind’s still churning here, so I’m thinking of it as, as a, the way that MSPs kinda work together to improve an organization’s compliance, let’s say.

It’s always, red, yellow, green. Like, how do we prioritize it and where do we focus and how do we move along? How do we chart that progress? So this business resilience concept that we’re debuting on the podcast today it, it’s, it feels similar in from a framework perspective, right? So I don’t think that MSPs, have to like.

It’s not like learning a different language. It’s okay, what do you measure in your business? What are all the different levers that you know, the best in class MSPs measure from their perspective and then just replace whatever the client’s deliverable or offering or what they’re selling or supporting [00:17:00] is, right?

You’ve still got these big business units that have to operate at a high level of not only efficiency and profitability, but resilience. And so when you can tie in the conversation to say, Hey, we’re gonna look at each one of these business units, kinda like what you know, we do with our clients at Channel Mastered and MSP Mastered.

We look at the entire business as a whole and say, here are some areas where we can, get some quick improvements, improve that translate that into resilience. Like where are the biggest threats, where are the biggest gaps? And then if you expand that conversation to platforms and workflows, now you have an easier entry into some ai.

Governance and some AI strategy and piloting. And then of course from a, efficiency and profitability perspective, you really gotta gain that trust with your clients in order for you to have access to that data. Because ultimately, if we’re gonna help these clients leverage AI to improve their business and inefficiencies, we will [00:18:00] have access to these data sets to this the data that’s the most valuable thing that these businesses have.

So I think from one perspective, rich, it’s a great approach to allow conversations to evolve beyond just a, an IT service provider into more of a business partner, but then also to elevate the value of the services that we deliver at a much, much higher way, in a much, much higher way.

Potentially superseding if we do it right. I’m, maybe I’m being optimistic here now too, myself, but me superseding some of these other trusted advisors at the table that, that the small and medium business owners rely on, to help get the most outta their businesses

Rich: well. Having a conversation with a potential new client about business resilience is, and doing a business resilience assessment is a great way to acquire a new customer begin a relationship at your tip of the week.

You gave us just a little taste of it [00:19:00] earlier. There has to do with what happens after you have successfully acquired that net new customer.

Erick: Yes. And what we’re seeing, rich is the value of the things that we measure. Is shifting a little bit in this new era of lots and lots of m and a acquisition, a lot of oversight from folks that are interested in rolling up MSPs, interested in acquiring MSPs and things like that.

And so the KPIs that, I’m used to measuring from, just 20 years ago of my MSP and the things up until just, I would say the last five or six years when all this m and a stuff started really moving forward, those KPIs and what matters to valuation have shifted a little bit.

So I wanna talk a little bit about why net revenue retention now is probably, I know I’ll probably get a bunch of comments about this but we want your comments probably more valuable than new [00:20:00] client acquisition. Think of it this way, rich. If I’m an MSP and I’ve got, let’s say 50 clients and. I am not adding very many new clients every single year.

Maybe a couple, right? Steady not hockey stick growth, maybe two or three or four nice sized clients. Every year I am growing my top line revenue, but if I’m churning out at a greater rate, then that’s a problem, right? So think of it the other way. Let’s say that I’m not growing very quickly.

Or maybe I’m growing super quick, but I’m churning even more because I’ve got these, bottlenecks in my onboarding process and customer satisfaction and love and nurture and feeding of these customer success teams and things like that. That’s not good. We would rather see more net revenue retention.

And, less up and down I, I’ve won some business, I’ve lost business, I’ve won some business. So the most [00:21:00] valuable MSPs don’t just grow, they retain at a much higher rate the best in class MSPs than other MSPs. So that’s where measuring net revenue retention is a critical metric.

So the tip of the week is the three tips here on identifying and taking action to make sure you’re not churning out. And there’s a couple of things in here that MSPs can’t control. And I hear this a lot working with MSPs Rich, where we’ve had four of our clients get acquired this year, and that’s why we lost the revenue.

So we didn’t do anything wrong. We didn’t have control over that. How do we look out for that? So I’ve got a couple of ideas on that one too. So the first thing that we need to do, rich, is make sure that we’re calculating our churn rate. So understanding how much revenue. We’re losing on a monthly and annual basis, and not just recurring revenue rich, but potential growth.

We know that if we bring on a client and they stay with us for three years, we typically will sell them so many tens of [00:22:00] thousands of dollars of projects and other things along the way. So we have to, understand what that true churn rate is in terms of revenue lost. And then we need to stay in tune with our clients’ growth plans to make sure that we’re doing that customer success motion very clearly.

They don’t see us as, just being out there trying to look for, the next quarter that they’re gonna leave on the sidewalk and things like that. We have to be really in tune and, I like me shifting toward this business resilience kind of strategy, right? To help with those conversations.

Not only do we need to understand what their growth plans are, ’cause we’re doing that typically during our qbr, maybe we’re asking, what they’re planning on doing expansion and things like that. But the one thing that, and I hinted at it a minute ago, rich, that surprises a lot of MSPs that I’ve been talking to, is they have no idea.

They may be surprised or let’s just say that the news to them comes later than the [00:23:00] MSP would’ve appreciated about them in talks to be acquired. So having those conversations with your clients has to include talks, conversations around what is the growth strategy? Are they thinking about exiting at any point?

Are they having any conversations? Is that going on? Just to give these MSPs a little bit of a heads up on what’s coming and maybe even exploring opportunities to, to jockey to hold on to that position. ’cause the o the opposite can happen too, which I’ve seen. It’s happened to us where a client gets acquired, but then we now just expand our services to the acquiring entity, right?

This happens a lot in we were focusing on legal accounting and nonprofit organizations. Those were our three verticals. And so we saw growth a lot through accounting and legal. It may be different nowadays, it’s been a minute, right? Rich. Number two tip rich is looking for [00:24:00] expansion opportunities with existing clients.

Again, you’re having more conversations. You’re looking for those opportunities to true up those clients that aren’t using your required right minimum bundle of services or they’re just not trued up the way they’re supposed to be. And looking for other opportunities for clients to adopt additional.

Services from you, like compliance or cybersecurity or maybe some advisory AI services, AI piloting and things like that. Just that expansion opportunity within that. So NRR plus growth within your existing client base is also a metric that we should be measuring. And then csat, we can’t we can’t stress how important it is to have some sort of a function to measure our customer and end users sentiment and satisfaction, because I think that’s another area that can be a gotcha rich, where MSPs think, oh, I’m [00:25:00] just, I’m, the business owner’s telling me everything’s great, but all you need is one or two users that are dissatisfied with the last couple of tickets or with, the, the conversation or the engagement or how long it took to close something or just something weird.

About, their recent experiences, who have a little bit of a platform and then can create some friction. So we wanna make sure that we are, not only measuring our direct point of contact or business owner satisfaction, but we are fielding some CSAT surveys to the end user communities within our customer organization so that we can understand sentiment.

And I would even go as far as to say Rich just picking out, a few tickets a week and reading through them like we all have time to do that, right? And just getting a sense of sentiment. And then during our standup meetings or our weekly meetings with our service teams, eliciting feedback from technicians and engineers about scenarios where, hey, [00:26:00] delighting clients, or Hey, are there any things that you guys, spidey sense identified that.

A client wasn’t completely satisfied, we’re behaving outside or an end user just behaving outside of their normal, behavior with you. Is there any friction that we should be following up on and then getting after it to make sure that we are delighting our clients as much as possible.

As rich, we all make mistakes. Clients don’t expect us to be perfect, but what they do expect is excellent immediate response and resolution to solve any of that, relationship based stuff,

Rich: good news on that last point before I share a few other quick observations about that when you’re talking about, digging through email a little bit finding the time to, to assess a customer sentiment, which I totally agree is crucial.

You, you never wanna be surprised by a customer moving away to somebody else because they’re not happy with, and you just were blindsided by this. The good news is there are AI [00:27:00] tools coming along that will make this a lot easier. And I’m thinking in particular of one that sift CCY FT is working on, it’s not in production yet.

I believe right now they’ve got a system that it listens to all of your phone and zoom interactions with customers. It turns what it tier into automated detailed documentation. At some point down the road though, it’s also going to be listening for sentiment. And I’m telling you, good news, bad news so you’ll be getting alerts essentially.

You won’t have to be as self-reliant to keep an eye on. And I’m sure there are other companies beyond sift working on that right now as well. So a year from now, I think that absolutely critical task is gonna be a little bit easier for folks in the audience. It’s a truism in sales and marketing, uh, Erick, that.

Expanding, uh, your business with an existing client is always cheaper and easier than acquiring a net new client. And that right there you just don’t want to be churning customers because it’s more expensive to get the [00:28:00] new ones. Basically a better growth strategy for the company is to expand with those existing accounts, not exclusively, obviously you’re adding customers.

But that is going to be a a scalable, more economical model for growing the business. And that gets a, that’s directly related to net revenue retention. You’re putting yourself in a position to expand your share of wallet with a business if you are retaining that account. And then the last quick thing I’ll say, and I’m I won’t go far with this, but as you were talking net revenue retention. It’s something that MSP acquirers have paid attention to before. I’m hearing exactly what you are, that it is more important in acquisition conversations than it used to be, but it has been a very important metric in the software as a service world for a long time.

And this is true in terms of, valuations and sales to private equity or IPL, like this is a very important metric. And hearing you talk about how [00:29:00] MSPs need to be focused on NRR as well. Just reminded me of a comment last week at the Channel Partner show. I moderated a session with Jason McGee, the CEO of sign, used to be the CEO of ConnectWise and Peter Melby, CEO of new charter technology.

And Jason made this comment at one point that I didn’t really. Have time on stage to follow up with him about, but would like to at some point down the road. And he said he anticipates that in the not too distant future acquirers are going to evaluate MSPs the same way they evaluate SaaS vendors and SaaS vendors get evaluated heavily on NRR.

So I, I’m not taking that anywhere, just beyond. It’s interesting, the echo there that Jason’s thinking along the lines of you need to be modeling yourself in similar ways to how SaaS vendors do, and then here you are advising people focus a little more than you used to on NRR.

Erick: Yeah, I was in the audience.

I remember him saying that. And I think it’s a direct reflection [00:30:00] of the the sophistic the sophistication of the buyers coming into the MSP market now. These more sophisticated buyers are coming. It’s not, we’re moving way past the. We’ll merge our companies together, MSPA and MSPB in the same geo and grow things and things like that.

We’re seeing a lot of, a lot more sophistication and discipline around how valuations are conducted here. And just like Jason said, coming from SAS to MSPs, now we’re seeing that, and that is definitely having an impact on how we should be looking at these things. And I think the last point that I’ll make before the break is the, this strategy should force MSPs to rethink how quickly they’re, they want to bring in net new business because we’ve also seen this rich where, we’re chasing this net new revenue.

And after a period of time, why, one of the reasons that [00:31:00] existing customers churn out is because they feel like, oh, you guys are going after these. Other opportunities and you’re not giving us the love that you used to give us. And we’re churning out those clients. And a lot of, we’ve talked in the past too, on the show about A, B and C clients, DENF customers, and saying you need to, start shedding some of those DENF customers to make room for some of those A and B clients.

But now I’m adjusting my per perception or perspective around maybe you should be shedding well, and I always thought this, but now I’m ver verbalizing it in a much more direct manner, shedding some of those customers so you can focus more energy on growing existing revenue with your existing clients, because it is much more valuable than going out and trying to, bring in that new business.

And we all, and we both know Rich it is challenging for MSPs to bring on that new revenue. But like you said, so much easier just to strengthen and build. Business resiliency [00:32:00] with your existing client base.

Rich: We began this episode of the show talking a little bit about some of the security implications of Agen ai.

Guess what that turns out to be? Not that we planned it this way, but it turns out to be a great lead in to our interview segment which is coming up right here. We are really pleased to have Ava, Ava, Nathan of Palo Alto with us. I met him about a year ago when he was a senior executive at CyberArk.

Since then, Palo Alto bought CyberArk for a very large sum of money because Palo Alto understands agentic AI security is gonna be a big issue out there right now. So today AHA is the Senior Vice President of Product Management Machine and AI agent security at Palo Alto. And he is gonna guide us through some of the dangers, some of the opportunities for our audience around agentic security that is coming your way after the break.

Stick around. We’ll be right back[00:33:00]

and welcome back to part two of this episode of the MSP Chat podcast, our spotlight interview segment. If there are two topics that are top of mind for all the MSPs in our audience right now, they’re cybersecurity and agentic ai, and we’re gonna talk about the intersection of those two things. For the next few minutes here with our guest who are extremely pleased to have with us on the show.

His name is Ava High Nathan. He is the Senior Vice President of Product Management for Machine and AI agent Security at Palo Alto Networks. Abhi, welcome to the show.

Avihay: Thank you very much. Pleasure to be here.

Rich: So before we dive into the subject matter, we’re gonna be talking about a little bit here.

For folks who are new to you, they’re gonna know Palo Alto. But tell folks a little bit about yourself and about how you wound up at Palo Alto. ’cause that in itself is interesting.

Avihay: Yeah, sure. So I’ve been I’ve been dealing with AI and machine learning for [00:34:00] quite a while now. I think almost 16 years.

I started off at PayPal. I was I did numerous jobs at PayPal at for AI machine learning. Started off as an ic, ended up as a VP of machine learning in charge of almost everything AI in the company. After that I moved to CyberArk to be head of data in AI for CyberArk for almost two years.

And then we got acquired by Palo Alto Networks. And I think it was really. A really fantastic opportunity for Cy work and for Palo Alto Networks to take the industry forward. Started off as at one job and I found myself in in a similar one. You never know what lives give you, but incredible opportunity.

I’m very happy about it.

Rich: If memory serves that acquisition, Palo Alto buying CyberArk, that was like a $27 billion deal. This was not a trivial acquisition by a company that makes acquisitions. They understand where the need is right now. And I’m sure they looked around and decided CyberArk is is the way to go.

We met first a [00:35:00] year-ish ago, and it was in response to some research that CyberArk published where you guys had found, and I’m this is from memory, so I think it’s right, but I’m not a hundred percent sure, but you guys had reported that there was something like eight. Non-human identities for every human identity that a business had to track.

And I remember looking at that and thinking, that’s a bigger number than I expected. And it’s also coming when a year ago we were still really on the cusp of ag agentic ai and heading into this era when there, there are gonna be 3, 4, 5, 8 agents per employee on top of all those non-human agents that are out there right now.

Talk a little bit about the degree to which the security risks of non-human identities were a problem before, but outside the context of agentic ai, how big an issue was that already?

Avihay: For, I think I’ll start off with the number that you just quoted. That number is gonna get bigger.

So I think [00:36:00] last year we already published that we’re seeing 82 machine identities, right? For every human. So machine identities that include the workloads and automations and AI agents. So the number by itself is already staggering and that number is gonna just keep growing and we’re gonna talk about that, I’m sure we will.

In terms of how big of a problem, look, I think it was already starting to emerge as a problem. But I think when we talked last year, it was just after we announced our solution. And I think CyberArk back then was maybe one of the first company from like identity security perspective that said, Hey, look, this is a problem, right?

You should look at this. Allies need to be on this. Where most of the industry were like we don’t know, like we’re using JGPT. So I think it was, we started to see it as a problem. I think it was more of a theoretical problem that we started seeing. And I don’t know if to say I’m happy or.

Concerned. [00:37:00] But I think a lot of the things that we talked about last year actually are coming into Fruitation this year. So it was theoretical kind of problem last year. It’s moving into a very actual problem that’s, that everyone’s facing right now.

Erick: Aha. In what ways does AG agentic AI exacerbate those existing risks?

And in what ways does it do

Avihay: so I think the most important thing to, let’s start with when you think about the AG agentic AI is, remember that at the end of the day, and I’m sure I’m gonna get quoted on this, it’s still the way we’re thinking about it. It’s a workload, it’s a machine. Until someone invents an AI agent that has, self-awareness, it’s still a machine.

And I’ll explain why I say it. It’s a very sophisticated machine. It has reasoning you can do other things. We’ll talk about it. The reason I’m saying it is because all of the fundamental security [00:38:00] topics that plug workloads or machines are still there for our agents. So you need to be able to control scale.

You need to be able to rotate certificates and secrets for those workloads. You need to establish ownership. There’s a workload in the system who owns it? There is a agent in the system who owns it. Auditing perspective. Something happened in the system. Who did it? Did I do it? Did my workload, did it, so automation, it’s the same for agents.

The problem does get bigger on the machine side by the I will say the autonomy that is given to those kind of, let’s call it machines, because on a workload you’re usually I’m gonna be very careful with this. You know exactly also, what is reading the workload. You can un understand and we’ll talk about that from like the reasoning perspective.

When you look at agents again as workloads, I see two things that are I think very interesting. [00:39:00] The first one is that people give it even more excessive permissions. That they give the usual workloads because it needs to do everything, so I’ll just give everything. So it’s a privileged identity.

Much more privileged than what you would just give a normal workload or an automation script that you wrote, right? Because it can do a lot of things. So I think that’s one thing. The second is that it’s a black box. You don’t know what the reasoning engine or the brain of the agent is going to do. So you’re putting a lot of trust in a black box.

And again, as someone who came in from the traditional machine learning, some of the stuff that I’m seeing that’s going on with agents, I’m like, wow. It used to be a dream for us to be able to deploy models. In a way that’s agents are being deployed today. Just do whatever. We didn’t have that luxury.

Or and for, I would say good reason from security perspective. Now I do wanna say one more thing, which is around what is different, right? And I think it [00:40:00] actually ties back really nicely into the last point. So we said it’s a workload, but as you guys probably heard it like a zillion times before me, it does an LLM that does reasoning.

It acts in a non-deterministic way, right? It can decide to do so in that sense. And it’s black box. So you cannot just go through all the paths of the code and see, oh, if you I do this, then I need to wave like that. It’s not a, like a solved problem. So when you look at it that way, you think about it for a second.

Oh, hold on. This is like a human. So think about it rich, if I hire you tomorrow, I do all the tests, I do all the background checks. You can do your work for two months and then you can decide to go against me. Why? I dunno. Why, because you decided and in this part, the agent is actually very similar to human.

So why do we have all the privilege control for human? Because we can’t control what the humans are doing. In their brain. We can limit what they can access. We can give them zero standard privileges. [00:41:00] We can just make sure that they get access just in time. We can do all this stuff to limit what the human can do when they decide to go rogue or when someone takes over, et cetera, et cetera, and does lateral movements.

So we have to do the same for agents. Okay? The risk comes from the combination. You have a human, which is determined, it never rests. It has access to everything. It operates in every dimension, and it can do things that no human can do. So the combination of the traditional machine risks. And the human risks all factor in this machine that never sleeps and that knows how to do things better than many of the people.

That’s what kind of creates this very unique, let’s call it risk. So hopefully that answers the question.

Rich: Yeah, absolutely. And in a very interesting way actually, because it is fascinating that agents are very much [00:42:00] like humans in some ways, and obviously very much not. They are, to your point, tireless, they’re working around the clock.

They have these sort of superhuman abilities, but just people behave unpredictably and irrationally agents can as well. And yeah, from a security standpoint, a lot of what you have to worry about is similar. It’s just a really interesting approach to the topic. So a lot has changed in the last year.

And in particular, as you were saying a lot of these machine identity threats have moved from being theoretical to being actual. So if we look at where we’re at now, and I’m sure we’ll get into what the landscape’s gonna look like later on, but if you kinda look at the landscape right now are you seeing threats exploits related to agents out there right now?

What, are there any examples you could cite of actual exploits of around agents happening right now?

Avihay: I think I can give two, two examples. So [00:43:00] let’s start with that, with the bottom line. Yes, there are stuff that are going on and I think many of the stuff that are going on are either not getting reported or you’re not severe enough.

But I always say that, we need to, with our product in really great shape because the boom is just one huge data leak or security leak away and we’re first approaching them. So that’s the bottom line. Now, I don’t wanna give two examples, I don’t wanna leave it up in there. So if you look today on the way that I would say most enterprises are utilizing their agents, there are two ways.

The first one is what we call let’s call it the helper agent on the enterprise agent. You buy an agent platform, you go to your marketers, you go to the technical writers, you go to the finance, you’re like, Hey guys, just automate right? You can do productivity savings. So they go in and they build agents that and give them permissions and do whatnot.

And those agents are getting [00:44:00] the identity, and I’m saying word identity on purpose of the human who created them. So what happens is, let’s say for example, I’m a finance person and I wrote an agent that helps me do my weekly report for the go to market. So I gave that agent, that agent tried to access the secure database for finance.

It triggered an MFA, I got an a FS say hey I triggered this thing. And from that second, the database, the target, it sees me, it doesn’t know it’s an agent. Yeah, maybe it can know it’s an automation script if it really wants to, but it doesn’t understand the inherent risk of the of the station that is going on.

Because for every, from every perspective, it’s aha. It’s the finance person who is actually pulling this off, right? So when that happens, think about just, just what happened. You have unlimited access of a black box agent, no matter, I didn’t choose a [00:45:00] specific one. It doesn’t matter rule, right?

Sometimes it’s an open source because a lot of these platforms just have open source models that are tested and everything, but it’s still open source and they have my identity and they can access every financial information in the company. When I just gave them the MFA, okay, so I basically gave my station token to the agent.

So that is one thing, by the way, I’m not even talking about people giving just their own passwords to the agent. They just hot code the passwords into the agents. That happens and we’ve seen it happen. Okay? So that’s one thing that’s happening. The second thing is all of the, let’s call it the divide coding or the local agents.

So the same CEO who is really want to push AI adoption in his organization. So is going to the developers head of RD say, Hey, I want 20, 30, 50% productivity. Again, just the os. Cloud code cursor, a lot of really lovable, a lot of really good iGen coding assistance, right? [00:46:00] So what happened there is that all of a sudden you have engineers that are working on these really fantastic platforms that are changing the world.

But those those coding assistants, in order to be effective, they have to interact with different systems in their enterprise. The JIRAs, the places where they store the PRDs, the gits to, to get the code. So what happens is that in many of these times to automate, the developers are sophisticated or not going to do an MFA.

Every time their cloud code is going to get code from Jira, what they’re gonna do, they’re gonna give it an API key or cryptographic token or something. They’re not gonna rotate the secrets. They’re not gonna do any of the security practices because. They don’t need to. So in some cases the CSO catches it in, some cases don’t.

But this is something that happens. So what happens is that you have static secrets somewhere in the code base. Again it’s local. If an attacker gained [00:47:00] access to that machine, it can just pull in all of the secrets again. And as I said, secrets sometimes just use and password and just gets that.

So these are things that are happening today. They could be happening right now, and people don’t know that it’s happening in the organization. There is a tension, there is a tension right now between the business wants to enable AI and the security that are standing almost the Dutch kid in the dam.

They’re trying to stop it with their fingers and if they don’t do it the right way, they’re getting blamed for stopping the innovation. You’re not enabling agents. If you don’t do it the right way, you are just like opening just opening Fort Knox okay, just do whatever you want. So I, it’s a very particular situation that we’re dealing with right now, but that’s what we are here for.

Erick: Ivy. I’ve never thought that deeply about the, what you just expressed is this is me giving the agent my identity, like it is [00:48:00] now me with all of my rights and privileges. And the second thing which really struck me was, yes, we’re API keying the stuff, and nobody’s changing the secrets and, so it’s falling outside of the normal purview of, best, best practices for security.

So my question to you is how well prepared is a typical SMB organization? In mitigating these risks because, hey, we talk about this kind of stuff all the time on the program, and you just blew my mind here. So what chance do ms SMBs and their end users have in addressing these security risks?

Avihay: It’s a good question to to say. I’ll explain because I think that the SMBs before everyone, they are the number one kind of, let’s call it vector at risk because the enterprises, we can talk about them and [00:49:00] the, and let’s say the smart, like the individuals are different.

But the SMBs are really in a place that what they’re hearing from the media is you don’t need to pay for marketing anymore. You have an agent that do that, does that, you don’t need to pay for design, just do this, right? Every day the stock exchange moves according to the new to the new releases.

So the SMBs are actually are the people who with the most incentive to adopt ai as soon as possible, to cut down on their cost, right? Because again, they’re not enterprise that can afford having these Zach. I don’t think they’re completely prepared, let’s call it this way, because SMBs are usually the places where the security, again, it’s just another just another cost structure.

No. Again, rotating secrets cost money. You need to have a vault in it to install it. You need to maintain it. Again, you can do it from, there’s many companies who are doing it. So I think the s and b is actually, I will say the, [00:50:00] in Hebrew we say the weak the weak stomach, right? The place where. It’s the most exposed and they do hold a lot of valuable information, financial information sensitive information of customers.

I can tell you in a second if you ask what I think the solution will be for them, but if you’re asking me if they’re prepared, then definitely not. And I would say even not recover.

Rich: Which then begs the question about the MSPs. Yeah, you were talking about the the difficult position that business leaders are in right now where they want to get all of the productivity boosting power they can out of ai.

And to do that, inevitably they create these sort of security dangers. Particularly in SMB, it’s going to be the managed service provider, those business leaders turn to, to help them navigate that, that trade off and figure out how to do it. The SMBs are not very well on their own, not very well positioned right [00:51:00] now to deal with these risks you’re talking about.

How about the MSPs? Let’s assume that they’re cyber aware. Knowing what they have known up until this point in time about security. How well armed are they to deal with this issue for their clients?

Avihay: Yeah. So I think that’s actually a big part of the solution, right? And I think we talked about SMBs.

I’ll go back to it in a way, an SMB that wants to solve, survive this will not be able to do it unless they’re taking advantage of offerings that are also gie from security perspective or they go to an s and p that does it for them. So that’s part of the solution. Now going back to the s and ps, I think from what we’re seeing and what I’m seeing personally, I think the s and ps understand this very well because at the end of the day need, they need to give a complete solution to their customers, right?

If they’re good and again, some of the MSPs we’re working with, they are top class in some cases. They understand the market just as [00:52:00] good as we are, if not more, right? Because they are standing in front of their customers. And I think they understand very clearly that, an integral part of any iGen solution, or let’s call it agent-based solution that they offer their customers have to come with inherit guardrails.

Maybe not. Again the most advanced solution they have to tailor it. But we’re having a lot of conversation with MSPs around how they’re using it, how they’re using it the right way. They’re building the architectures with us what they’re seeing with customers. I think one thing that’s interesting here is that the market is evolving as we stick.

Maybe we’ll finish this podcast and there’s a new model that came out and obliterated everything else, right? That happened I think this week. But I think that a AI is, as you guys know is the fastest adoption of technology forever. So we’re learning like the MSPs are learning with the customers.

What are [00:53:00] their needs? How does the architecture look like? What are the productivity. Games and what the customer needs to do. And in many cases, they’re sharing this with us when we’re having the the discussion. So it helps us tailor, let’s call it this way agent security much deeper to what the customer or the SMB actually would need.

So I think that’s, again, plays a really critical part here in bridging the gap between enabling at all costs and keeping it secure. And also, again, the flow of information in the industry. It’ll take time. At some point it’ll stabilize and as every industry right there is gonna be 90% commodity.

And then the company who does the 10% really good are gonna win. We’re not there in the 90%. Definitely not yet,

Erick: as if MSPs didn’t have enough on their plates just trying to keep up with. The existing infrastructure and the client’s needs and just the traditional [00:54:00] cybersecurity requirements. Now you just mentioned aha, that it, this is the fastest adoption of any technology in history.

It’s add that on top of everything else the MSPs have to worry about. So can you share a few of the most important steps for our Ms P audience that they should be thinking about to keep their SMB customers safe? What would you advise them to do?

Avihay: So the first thing I would do is really to I know it sounds trivial, but it really is to go back and understand the customer needs in agents.

I’ll explain why. Because when you actually look atj at agents, there’s a lot and lots of different ways. So everyone says agents, but you have. Enterprise agents, which are like all the builders, and you have local agents, you have SaaS agents, which are agents that you can deploy, on Salesforce or [00:55:00] ServiceNow.

We have agent browsers that maybe the customer wants to use. So these are just the type of end of agents that then you have the different ways that the customer wants to authenticate with those agents. It’s all behalf of, maybe it’s it’s with secrets and then there’s MSP and skill and eight ways.

So you really need, again, if I would be an SP, really understand what the customer intent to do with those agents and how do they get to these what are their targets so you can you can tailor a right solution because there isn’t something that fits all and no customer will use everything.

So I think again, for an SMB that usually have very specific needs. You need to understand the customer. So I think that is one. The second thing is I would think about a strategy that doesn’t force the customer into all in adoption from day zero. Okay. Customer needs, like they need to learn how to use this thing, right?

You don’t [00:56:00] take a teenager again, I don’t wanna compare the SS to teenager. It’s definitely not what I mean. But go with me for a second. You don’t take a teenager who just got a license and you give a Lamborghini and say, okay, just go to the auto band in Germany and drive kin, right? You can, some will do it most.

That’s not gonna be really safe, right? So the way I would do it is I would work and create a method to say, okay, look, hold on. Here is a system. Here is what it does. We can accelerate, we can we, we can accelerate and. Also build on top. So when something happens, then we can go to the next level.

So something modular that allows you to have checks and balances and on the other end really allows you to keep upgrading so the customer doesn’t need because the basics are the basics. Think about it like the human body. So we’re all have similar bodies and in many ways the brain is different.

So you can replace the [00:57:00] brain, make, but you still have the same kind of, okay, we walk the same way, we swing the same way, we eat the same way. So putting together infrastructure that answer the needs, that has checks and balances, but it’s also easily replaceable so you can upgrade with with new models and offerings is the stack, is the second thing I would do.

Because the, if things go right, the industry will evolve, it’s gonna be great. The customer will also evolve. They would wanna do more things like, oh, great, these agents actually doing something for me. Hey, I know that you guys helped me do vibe coding, but let’s I wanna use Salesforce for a second agents because maybe I can do better.

Great, let’s connect that. But when they do it modular in a secure way, then the customer, like the SMB, stays safe. So understanding them needs leading something modular. And it’s a journey. And I think this is something that Ms. P is not to do really well. Understand that every adoption is a [00:58:00] journey with the customer.

So not to push them. And sometimes I say one less thing, save the SMB or the customer for themselves because they all want to get, I represent AI efficiency. And they actually, again, just like a teenager they wanna drive, the Lamborghini. But maybe you wanna start them off with something until they learn how to control and then get them.

But as we know, you need to do it in a right way. So that those will be my tips.

Rich: Some of what you were just talking about, there’s a perfect segue to something I wanted to ask you about. ’cause we’re talking mostly about agentic AI as a source of risk and threats and how the end users and their MSPs can mitigate those threats, which is a very important topic.

But in addition to being a challenge, AG agentic security is potentially an opportunity as well. Just like Ag Agentic AI itself is both a source of [00:59:00] security risk and a source of immense productivity. Flipping thing, flipping the conversation around a little bit, how would you encourage the MSPs and our audience to think about AG agentic security as a business opportunity in addition to a security challenge to be overcome?

Avihay: Yeah, look, I think that when you frame it this way. I think iGen has the potential to be, again, maybe the biggest technological revolution since the internet. Okay. I, because I think going back to what what we previously said, the ability to get the best get the best marketing person in the world.

Get the best analyst in the world, right? Get, I don’t know, stick best salesperson in the world, all of them acting on your data, on your behalf, listening to your orders. That is an opportunity of a [01:00:00] lifetime, definitely for an SMB that would need to pay, beyond their reach to actually get to those kind of level of extras.

So I think as a business enablement, there is no doubt that this is not a hype. It’s something that needs to happen. I think also from a security perspective, okay, having security agents is something that can tremendously improve anyone’s security. I think what you wanna make sure when you do that is when you hire security agents, let’s say that you, we know we hire security, so I would hire the best security out there.

I wouldn’t say, oh, hold on. There is a, someone walks outside and say, Hey, I’m security. I wouldn’t hire him to guard my business or my house, right? I would go to a legitimate security company with a lot of credentials with people who are trained, ex army, ex, whatever, say, Hey, I want these guys to be my secured agents.

Just [01:01:00] like I, I wouldn’t do it for a marketing person who is oh, first out of college. So I think that by choosing the right agent on the right platforms. And it really is a matter of making good choices. And this really, again, where the MSPs come in and help make these choices. The business enablement opportunity is just, it’s just phenomenal.

And the security opportunity is just phenomenal. I just need to choose the right place. I’m actually very worried that when people just gotta start downloading security agents off the internet that someone wrote with nevermind, with not one of the platforms. And it’s no, that’s good enough.

That’s great. No, you don’t do that, right? You don’t put, you don’t put a lock on your house that you found on the streets, right? You don’t, you just don’t do that. So I think, again, that’s a big part of what the ms even though the lock is cheap and you got it for free, it’s but that lock is really expensive.

Like, why do I spend all this money, have a business to run? You would spend it because the cost of error [01:02:00] is really big. Marketing. It’s also bit, but maybe a little less, right? So this campaign went down. We’ll do another one. If the lock is if the lock is broken, then your house is gone. So I went back to the security rate, sorry.

But I tried going to enablement

Erick: earlier in our conversation. You talked about how SMBs are, using the, ineffective privilege access management techniques in ai. In January, CyberArk published some research suggesting that MSPs are also using less than ideal or outdated privileged access management techniques for the agentic AI era.

What’s the most common problem with MSPs specifically? And what’s your guidance to have them address it?

Avihay: I think that a lot of the [01:03:00] things that we talked about them, like in the beginning of the year were actually, I know to say addressed, but I think it actually got a really good reception.

We had people talking to us. We had really good we had really good traction about this. So I think that in that sense it created what we wanted, right? Which is really to bring to bring awareness. So that is really something that we liked. And, that’s part of what we do.

We we publish these things so everyone stays safe at the end of the day, so that, that’s one thing I think, what I’m seeing, I think on the MSPs and again, I wouldn’t go but I see it generally in the industry, is the push towards enabling the agents and making them autonomous is leading to a lot of ineffective use of, let’s call it the way to give these agents means of [01:04:00] access.

So we talked about the secrets, we talked about direct API calls, we talked about all sort of hacks that we’re seeing. Because we’re in a point where people are moving slight slowly from on behalf agents into, oh, this on behalf agent looks good. I’ll make it autonomous. How do I make it autonomous?

I want it fast. I don’t wanna integrate with with the Secret Store. I don’t wanna put in Hashi or nevermind. I don’t wanna just put in the effort. So what do I do? I do something

Erick: quickly.

Avihay: We’ll do it, we do a stick flow. So I don’t think there is aling of MP or recommends a Oh, we’ll just do it, right?

But what they do say is, Hey, we need to enable this thing because you bought us to get productivity gains. No one goes and say, Hey, I wanna make things, everything secure, right? You’re going because you wanna [01:05:00] save money, you wanna get 50, 60, 70% gains from ai. So I think the combination of agents technology improving to the point that people wanna make it autonomous to the means of access.

That are just other end like, okay, just let’s just do something quickly. Let’s just show results. ’cause it costs a lot of money and people wanna see results. And you go on LinkedIn and every day oh hold on, I automated all my, everything is in ai. So the FOMO creates pressure. And then Erick, what you see is the same thing that you saw for workload.

And that’s why I kept, kept saying the same flags that we already thought, they’re gone. They’re coming back to us. So that’s what we’re seeing right now. Hopefully that helps.

Rich: It absolutely does. The entire conversation has been helpful and interesting and I think we can agree, and [01:06:00] everyone in the audience can agree we’re still at an early enough point in the story, the AG agentic AI story, and therefore the ag agentic security story that and as you said, it’s changing every day anyway.

There’s a lot more thinking and conversation and work to be done. And the earlier people start raising that up as a priority the better. I’ve had for people in the audience here who would like to follow up with you a little bit, get in touch with you, learn more about what Palo Alto does in Ag Agent security.

Where would you encourage folks to go?

Avihay: So I would first encourage I think we have a lot of information on the Palo Alto sites, specifically going through the identity. We publish things both on the unit 42 Palos research unit that has a lot of knowledge about agent traits and, what can you do and how can we help as well as information about a product.

We really try our websites to be informative and not just, let’s call it [01:07:00] promotional, because I think this is really a good way to educate people about what are the risks and again, help at the end of the day, our customers. There’s also our yearly conference that is happening in May, which is a follow up.

You can watch panels conversation in in cyber week, which happened adjacent to RSA sec just in mer. Our annual conference impact is happening in May, or you’re gonna have a lot of conversation around identity security in general and specifically around identity identities. I think. If you are looking and if our customer is looking to, and listeners to learn more about identity security in general and also again, how does the intersection of identity security goes in with agents and how, our really enabling I think that’s a really fantastic unity to listen and learn.

Rich: Alright thank you again Avi for making time with us. We’ll include [01:08:00] links to some of that in the show notes for this episode. Um, folks, Erick and I are going to take a break right now. When we come back on the other side, we’re gonna share some further thoughts about this conversation with Hai Nathan of Palo Alto.

Wrap up the show. Have a little fun. Stick around. We’re gonna be right back

and welcome back to part three of this episode of the MSP Chat podcast. And thank you again to Ava. Hey Nathan of Palo Alto for joining us. I don’t believe this came up in the conversation, uh, Erick, but it’s worth noting, that AHA is based in Israel. It took us a little longer to get this the interview scheduled and completed than we originally planned on either end of the invite process because as things are complicated in that part of the world.

So I do thank him for making some time for us and finding an opportunity to speak with us. Lots of different stuff we could follow [01:09:00] up on, dive into from that. I one of the things that’s interesting is you as you talk to him, you can really. Get a feel for the trade-offs between the productivity potential of AgTech AI and the security dangers and the difficulties of weighing those and finding the right balance.

It’s a very tricky, difficult thing for a business to do or for an MSP to do advising those business businesses. And that kind of leads me one, one of the things that I really enjoyed about this conversation is how frank he was about, even he, even Palo Alto we’re all figuring a lot of this out still.

And he said something towards the end of the conversation there, he was talking about learning with the customer. Which I took to be or what was interesting about that concept to me was the idea that maybe a really smart thing to do around AI with customers right now is to be transparent about the fact that this is new.[01:10:00]

Everybody’s still learning about it, it’s changing very rapidly. A as opposed to positioning yourself as the all-knowing Oracle. And I totally get why that would be an appealing kind of stance to take with a customer. You, I know what you need to know. You can trust me. I know it.

There might be some wisdom in this idea of saying I, I know a lot about the things you don’t know about and need to know about, but we’re learning this technology and how to make it productive and safe for you together. I kinda like that that thought

Erick: that struck me as well, rich.

I like that we’re in this together, especially, when. You can remind clients that no other technology in the history of the planet has received the rapid adoption of ai. And with that comes inherent risk. And we need to just be thoughtful about it and, be deliberate about doing this together.

And in my experience, rich, when we [01:11:00] involve a client in a conversation like that, they generally will help us champion it and understand it and be our, our crossing guard, in, in the conversation with other user, things like that, that are trying to just do things right. So we’re not telling them, Hey, here’s how the, we’ve been doing this for a hundred years.

Here’s how it lays out, here’s how, here’s what you’ll expect. Here’s how we train the user, blah, blah, go for it. This is one of these things like, Hey, you guys are adopting. Tons and tons of AI that you’re probably not even aware of. Platforms that you’re leveraging in your business are AI is being injected into it.

Your users are signing up for, free versions of AI that you may not even be aware of. We need to first assess where we are and go through this journey together because your needs and what your users are doing could be completely different than somebody else. A lot of similarities.

But at the end of the day, if we let this just, run [01:12:00] rampant and be viral in your organization, we are doing the opposite of ensuring your business resilience moving forward. We’re actually negatively impacting that, right? So let’s work on this together. And I love the ability to engage with a business owner from that level and then say, Hey, let’s nominate, a leader.

And maybe if it’s a larger organization, you can say, who’s our team? How are we gonna do this stuff? How are we gonna vet it? It’s like the bringing, we’re bringing something in that, heck, it could be radioactive. Who knows, right? We don’t know. We don’t want to prescribe penicillin because we don’t know if you’re allergic to it or not.

Where are those cracks going to be? So we’ve gotta do a little bit of thoughtful assessment as we move forward in our umbrella, our new umbrella of business resilience and getting clients to buy into that.

Rich: And the more you get the client directly involved in that process, the more invested in the technology they’re going to be.

And so to, to the degree that there’s any kind of resistance coming from the sort of frontline knowledge workers around [01:13:00] this AI stuff, if they have a voice in, in, where the risks are and where it gets used and doesn’t, and I, then it becomes something that they’re doing instead of something that’s being done to them.

So that’s one more benefit of of what you’re talking about. Folks, that leaves us with time for just one last thing and, uh, you know, Erick, I, I am, I’m pretty sure most of the people in our audience can relate to the experience of being on a long distance drive. You need to go to the bathroom and it’s okay, I’ve gotta find a gas station.

Maybe I’ll stop at a restaurant somewhere I need to go find a bathroom. And it really does slow you down if you’re trying to get someplace by a certain time. That delay really can increase your travel time. And good news if this is something that you encounter a lot and that concerns you because a Chinese car company has successfully patented a voice activated in-vehicle toilet that slides out from under a passenger seat.

Now, I just noticed the passenger seat part, not the driver’s seat, so they’re gonna have to [01:14:00] work on that. But it’s voice activated. No need to to pull over to the side of the road and use nature as your your toilet. If you really need to go you just say open toilet and I assume a few minutes later, flush toilet and magically that’s done.

And no no slowdown in your momentum. Coming soon to a new car near you, I imagine, Erick.

Erick: I’ll tell you what, rich if the entire team at NASA can’t get the the facilities working correctly for the Artemis astronauts, I’m not sure how much of a chance I give this Chinese automobile company.

I’m getting it right in a car.

Rich: Time will tell, but that they have at least patented it. Now we’ll see what they come up with this concept from a safe distance. I imagine. Folks, that is all the time we’ve got for you this week on MSP Chat. We thank you very much for joining us.

We remind you as well, as we always do, this is both a video and an audio podcast. If you’re watching us on YouTube right now, but you’re into [01:15:00] audio podcasts, go to Spotify, apple, Google, wherever you get those audio podcasts, you’re gonna find us there. If you are listening to us, if you wanna check us out on video, go to YouTube, look up MSP Chat, wherever it is, however it is you find us.

Please subscribe. Rate. Review. It really will help us find and attract more listeners who enjoy the program just like you do. This show is produced by the great Riley Simpson, part of the team With us here at Channel Mastered where we work with vendors who want or wish to have a thriving MSP channel. You can learn about the full spectrum of services we offer to help with that mission at www.channel Mastered.com.

Channel Mastered has a sister organization called MSP Mastered, that’s Erick working with MSPs to help them grow and optimize their business. You can learn more about that at www.mspMastered.com. So once again, we thank you for joining us. We’ll see you in a week. Until then, folks, please remember you simply can’t spell channel.

Without

Erick: [01:16:00] MSP.