Youtube video

July 10, 2026

Episode 130: VCAIISO

Listen to the podcast

Read Transcript

 
Erick and Rich discuss why service desk automation startup Squash believes there’s a close connection between AI automation for MSPs and governance and why they’re probably correct, as well as three steps MSPs can take to ready tomorrow’s generation of leaders today. Then they’re joined by Arve Kjoelen for a timely conversation about the security implications for MSPs and their customers posed by leading-edge LLMs like Mythos and GPT-5.6. And finally, one last thing: how two joy-riding teens discovered the hard way that the long arm of the law extends into Waymos.
 
Discussed in this episode:
 
Some guests on this podcast are clients of Channel Mastered. Compensation plays no part in their appearance or the content of the discussion unless the episode they appear on is a “bonus episode” explicitly labeled as sponsored.
 

Transcript:

Rich: [00:00:00] MSPs, summer is here, and so are vacation schedules, staffing gaps, and the challenge of keeping service levels high with fewer hands on deck. Join MSP industry thought leader Erick Simpson and Kaseya’s Dan Tomashevski for a live discussion on how successful MSPs are leveraging AI and automation to streamline operations, reduce manual work, and support more clients without continuously adding headcount.

You’ll discover practical use cases for AI powered service desks, ticket triage, security operations, and faster issue resolution that can help your team work smarter while maintaining an exceptional client experience. Save your seat today at [00:01:00] https://bit.ly/aimspwebinar. That’s https://bit.ly/aimspwebinar, and learn how to run lean, stay profitable, and scale support this summer.

And now, on to the show. And three, two, one. Blast off. Ladies and gentlemen, welcome to another episode of the MSP Chat Podcast, your weekly visit with two talking heads talking with you about the services, strategies, and success tips you need to make it big in managed services. My name is Rich Freeman. I am Chief Analyst at Channel Mastered, the organization responsible for the show.

I am joined, as I am every week, by your other co-host, our CEO and Chief Strategist at Channel Mastered. He is Erick Simpson. Erick, how you doing?

Erick: Doing well, Rich. How about you? Surviving the heat wave?

Rich: Excuse me?

Erick: Surviving the heat wave.

Rich: It is not that hot, actually yeah, I, where I am. I’m in Seattle right now, and I, w- the forecast for [00:02:00] today is a high of 71 degrees, which is warm by Seattle standards.

It is not a heat wave.

Erick: Picturesque. Perfect. Perfect. Yeah, it’s warmer here in Southern California. It’s the, or the lower 80s it’ll be today. I think yesterday was 86, so yeah, we’ve been on the upper 80s trend the last couple of days

Rich: But it’s a dry heat as they say here, so there’s

Erick: that. Oh, yeah. It’s drier than other places I’ve lived, that’s for sure.

Rich: Okay. Let’s plunge right into our story of the week here. This comes straight from my blog, Channel Hawk, which you can find at channelhawk.news. This is a story I wrote about a service desk automation startup, and I’m not… my purpose here is not to endorse this software or to say that they’re doing something that’s significantly better than anyone else, but what they’re doing and why they’re doing it is very interesting to me for reasons that I think connect a few themes that come up on this show fairly regularly Erick.

So the company in [00:03:00] question is called Squash like the vegetable basically. You can find them easily enough online. Service desk automation tool. They would tell you that a big part of what differentiates their product from other products in what is clearly a pretty crowded market right now is that it goes a little further out in capitalizing on what AI can do to automate the work that your engineers are doing right now.

And if this is hard for me to validate or confirm, and I can’t really compare what they’re doing to other tools like that, but let’s just take them at their word and assume they’re… And these are not words they use. These, this is my characterization. But let’s assume they, their AI gets closer to op- OpenClaw territory, like closer to the leading edge of what AI can do than some of the other tools out there.

The other thing that is distinctive about this tool though is that it has pretty deep governance functionality. And in fact, when I [00:04:00] interviewed the CEO of Squash, he basically described Squash as a governance first company. So governance first, AI second. And there’s a strategy behind that which kind of makes intuitive sense when you think about it a little bit.

If you are going to unleash AI that’s closer to the leading edge in an MSP’s environment, you need to know that you can do that as safely as possible. You need good, robust governance functionality, and you really need that logically, you need that built into the same platform as the AI.

And so before they wrote, before they coded anything AI related at Squash, the first thing they built was the tool’s governance component. And and they have a whole sort of onboarding process where they make sure the guardrails are in place and are working before they start letting you ramp up the AI functionality of the tool.

I think there’s an interesting one-two relationship there and a smart relationship that I think applies to MSPs [00:05:00] as well in their work with clients. To the degree that you want to be the person who can go into a client environment and enable your SMB clients to get as much from the power of AI as is possible, to get them as close to the leading edge as you can and as makes sense for them as benefits them, delivers ROI for them, but safely.

The– and if you don’t do that obviously there’s someone else who will. So you do kinda wanna be the go-to MSP for cutting edge AI functionality, but you need to know that you’re doing that safely, and your clients need to know that you’re doing it safely. And that’s the other thing about Squash and the governance first approach that I didn’t mention before, Erick, is yes, they wanna know that the tool they’re rolling out will help you take advantage of AI safely.

But they also know MSPs won’t use the tool unless they have confidence that it will do [00:06:00] what it does safely. And so the guar- you know the guardrails, the governance first approach, that’s a confidence building tool as well for the MSPs. And that mindset I think is gonna be important for MSPs as well when they’re talking to their customers that your customers need to have confidence in these interesting AI workflow automation, digital transformation tools.

They need to know that what you’re proposing can happen safely. So I– we’ve been talking about governance and getting MSPs to take that a little bit more seriously than they have been. We’ve been talking about being the virtual chief AI officer to your clients. I think the lesson from Squash to MSPs is basically you need to take both of those disciplines equally serious because they are very closely related to one another.

Erick: Yeah. A- absolutely, and I think that this is a very mindful way of developing anything that’s related to AI. We’ve got to build out the governance first, Rich. Containerize it, make sure that, we are bulletproofing [00:07:00] anything that happens within the container of activities that the agents or the AI is working within.

So I think that’s really interesting that is the, the leading message is like we began with governance first. Which, I’m, I don’t think I’m seeing a lot of other folks out there leading with that, right? It’s all about, the AI, the efficiency, and the productivity enhancements, and all these other things.

So that’s really interesting. As you were talking, Rich, I had two thoughts. A first, squash is a vegetable and a sport. And second I remember, in the early days of managed services in our MSP, we brought on a, an offshore NOC backup team for our service desk.

So these were folks in India that, that powered our NOC services. They never e- engaged directly with our end customers. They worked with our technicians and engineers for the, behind the scenes. And there was [00:08:00] always this debate, Rich, about as this grows, because you could see, the potential, the future, just like with AI Were we going to let our customers know that we were using outsourced offshore folks in the service delivery component of our business?

Now, and the parallel is should MSPs today let their customers know they’re using AI powered tools and things like that to deliver better service? Back in the day, Rich, we decided we’re gonna be completely transparent with our customers, and it served us well. We didn’t have any pushback. We the way that we explained it was we had our guardrails, right?

They worked with our team, and then and we were… we didn’t hide it. And so I think the question for our audience, post in the comments below whether, number one, you’re using AI and your tools that are, that you’re [00:09:00] using are powered by AI, which many of them are, and are you being open with your clients, or are you still piloting it internally and not yet sure how you’re going to position it with your customers?

That’s the question I would like to pose to our audience. Rich, what are your thoughts?

Rich: It’s it’s an interesting and c- it calls to mind a conversation with that I had with the CEO of a fairly large multi-city MSP. And I’ve had, I’ve heard similar things from one or two other MSPs since then, come to think of it.

But these are companies that have told their clients they, they want to position themselves to their clients as being eh, technologically advanced, and therefore AI forward. And without, demoing anything to the customer they’ll let the customers know we- we’re doing exciting things with AI internally within the business here, and it’s making us more product- productive.

And we can bring the lessons we’ve learned and the expertise we’re homing to, to you as well. Eh, and so that, you can… That’s [00:10:00] the pro case basically for being transparent, especially right now when the end users the customers, I think, want to talk with you specifically about AI. And we can come back to that a little bit.

Here’s the con case, though, to being transparent about your internal use of AI, is that these MSPs I’m thinking of who said I’m very open with my clients about our AI use internally,” they all said that, “Some of our clients are coming back to us and saying if you’re way more productive with this AI stuff, why am I paying you the same rate?'”

Exactly. Yeah. So there is that to consider. Another conversation … that conversation that you might have. And then the last quick thing that that I’ll say is is just I do think customers want to have a con- conversation with you about AI now. I do foresee us getting to a point where that is no longer the case and we go, i- in essence, go back to the world w- we’ve been in and MSPs all [00:11:00] should have been in, where what they’re talking with talking to the customer about is outcomes.

And how you deliver that outcomes is part of the conversation, but it’s not an AI conversation. It’s what do you need to do? Where are your pain points? What are your aspirations? Here’s how I can use tech to help you accomplish that. And the degree to which AI is a part of that story kinda fades into the background, I think, more than it does right now.

Erick: Yeah. The more that I think about it, Rich, I think that, transparency is good, and it does set the opportunity up for those MSPs that want to monetize AI d- by delivering, AI forward services to their clients, right? And you’re right. There’s that, that awkward kind of hesitation that says if, I don’t wanna deal with an objection about my pricing when I introduce this.

A couple of thoughts come to mind for me, Rich, is one we’re probably all in the same kind of ballpark here is- We come to the c- to our client and let them know what we’re [00:12:00] doing, and let them know what we would like to do for them. And then also let them know that because of this enhanced efficiency and productivity, we are now able to do these one, two, three additional things for the client.

Becoming more strategic, spending more time with them, spending time in the boardroom but rather than the server room or under a desk. So I think, positioning it that way where the client understands, oh, I see you’re becoming more productive, you’re analyzing and assessing data a little bit differently.

You’re coming to me now and helping me in other strategic ways that you did not have the opportunity to do because you were constrained by the tools and the and the processes that, that you were… And human labor, right? So I think there’s a balance there. There’s probably a really effective approach to having that conversation with clients that, that hopefully tamps down their kind of thinking we should get a break then on our pricing.”

And if you’ve got cl- c- clients that are always looking after the bottom [00:13:00] line and not really growing and not adopting more of your services and expanding and listening to you, they’re probably not a good fit for you in the long term anyway Rich? So

Rich: Yeah, we talk about AI automation not being an excuse to fire techs for MSPs.

You hire more slowly than you had to before, but you’re not getting rid of anybody. You’re just reassigning them to higher value tasks. And assuming those tasks you’ve reassigned them to really are higher in value, then I think you’re totally right. You want to be, you wanna talk to the customer about that.

Thanks to our AI productivity and the kind of expertise we can bring to you, we’re able to do these higher value things for you and that’s why so you’re getting more value basically for what you were paying before essentially. I think that’s a really smart kinda appro- and it’s a set of talking points that MSPs are gonna have to hone over time, assuming they are transparent with customers about using AI.

So that’s forward-looking. That’s something that people are gonna have to to get [00:14:00] better at. I’ve been working on a a blog post that gets to something kind of forward-looking as well. I’ve been diving into the latest service leadership data and looking at how it talks about how young, smaller MSPs grow at a pretty rapid rate.

Older, mature ones assuming they’re run well, they grow at a rapid rate. There’s this in between stage where the growth tails off a little bit, and service leadership says it’s because they, the companies have to get past some, some of the constraints, organizational constraints of their younger days, including long-winded way of getting to your tip of the week, Erick, including you can’t be the only decision maker anymore.

Erick: Yeah. Great way to set it up. And, what you’re talking about, Rich, is really that inflection point that says we have to evolve to the next level of maturity. We’re being forced to if for nothing else, because we h- we’re hiring more people. I’ve read a couple of different articles over the years that indicate [00:15:00] that, somewhere between every three people that you hire, you have to evolve, right?

And sometimes if you’re… It’s a fast-moving organization, you have to evolve more quickly if you’re hiring two or more. But certainly, if you’re doubling your staff, holy cow you’re f- you’re struggling to catch up. And so the idea that we have to empower our teams and then begin delegating and then building other leaders is the point of today’s tip of the week.

And, I wrote an article, and this has been years ago, Rich. It’s a blog post that’s on MSP Mastered, and it is, it’s probably, it’s gotta be 15 years old, and it’s titled The 14- The traits of top leaders or something like that. And even today, it is the top article that is re-read on my blog.

And, I’ve got hundreds and hundreds of articles on that blog. So leadership, people [00:16:00] are very interested in what the core components of leadership are. And I’m not gonna go through 14 leadership traits of effective leaders today, but what I will say is, as MSPs become more savvy and mature and are thinking about exit, right?

So what do I do when I get to a certain point in my career where I feel like I’m ready for the next thing, right? And the entrepreneurs are entrepreneurs and want to get to the next thing. We speak to a lot of them all the time, and what happens when they exit? They start something new, and they do it quicker and faster and better because they’ve learned, right?

But one of the things that a buyer does not want is to buy a job for themselves, right? They don’t want to be in the position where, like you said, they have to make all the decisions. They’re involved in every conversation. That is not a thriving, growing, scalable organization. So our job as leaders in our organizations is to build other leaders, obviously.

And we talk on the show before about succession strategies and things like [00:17:00] that. When you look at your org chart I go through an exercise with MSPs, Rich, where I say, “Okay, show me everybody that’s in your org chart now. Now show me all of the positions that you will need to fill, even if there’s no- nobody’s names in them now, over the next three years, and what does that look like?”

Or s- or if someone is wearing that hat, here’s the telling point, where you’ve got one person that is in four or five different roles, right? That is spinning way too many plates, and means that we’ve got to begin thinking about building our team and delegating. And this is one of the most painful things, Rich, for a te- a technically-minded business owner.

Ask me how I know. To feel like I’m going to spend time, more time than I have available, training, coaching, mentoring, and this is the key, everybody should be mentoring somebody in the organization, someone else, and then giving them kind of the keys to the [00:18:00] sports car and saying, “Okay, I trust you. Don’t crash the car,” right?

So that’s the most, one of the most challenging things for somebody like me. It’s like letting go and not wanting to make sure that I’m micro ma- or not trying to micromanage, right? We have to trust our team, we have to trust… And we have to expect that they will make mistakes, but that’s not what we evaluate them on.

We evaluate them on how they respond to it, how they react to it. Do they bring it to us? Do we work together to solve it? And then we guide them along the way. And not everybody’s gonna get it right the first time, in a new role or taking on a new responsibility, but you’ve got to be patient.

And the more that you’re able to delegate, yes, it might take two or three times longer for that person to do something. And that’s the other mistake that leaders do when trying to build other leaders. Instead of doing the right thing and saying, “You own this,” and then something comes up and says I’ll just take care of it because I can do it way quicker.”

Stop doing that, right? And don’t delegate the things that have to be done quickly, [00:19:00] right? Ramp somebody up over time, and then start giving more and more of that. So when you’re doing this properly, you’re looking at your org chart and you’re saying, “Okay, what is the succession strategy for every member of the team?”

And share that with the team. Say, “Hey, we’re gonna be working with you to get you to the next level of growth for the organization.” Don’t force it on them. I’ve made that mistake before too, Rich. Some folks just want to close tickets. They wanna come in at 8:00, leave at 5:00, and that’s great. We will support them as well.

But for the folks that want to grow with the organization and earn the benefits of that, then we will work with those folks. Coach instead of solve, right? So I’m not gonna tell somebody how I want them to do it. I’m gonna give them the objective. So if it’s a new project, if it’s something like that, then say, “Look, here’s the project.

Here’s… Come back to me. Here’s a, an old project plan-” Don’t follow it. I want you to review it. I want you to improve it, right? [00:20:00] Given the objective, here’s what we need to do, and then come back to me, and then let’s whiteboard it. Show me what you’re doing. And then instead of saying, “I would do this differently, I’d do this,” I ask questions on the whiteboarding session.

“Have you thought about this? What if this happens?” And get that person to start building that, those muscles, right? Those cognitive muscles, the problem-solving muscles, where you do that once with a great technician or engineer and they immediately go to it next time. And then when they have an issue or a problem, “Don’t come to me with the problem.

Tell me what’s going on and give me the three options, and the one you think we should execute.” So then I can say, “Great.” Or I’m not gonna tell them, “No, that’s the wrong approach.” I’m gonna say what happens– What if this happens? Have you thought about this?” Get them to think around it and lead them there.

And then that way they feel empowered, they feel like they’re owning that resolution, and they’re energized to keep doing it. And then identify over time who, and work with your leadership team if [00:21:00] you have one, to identify who do they think are the next future leaders that are gonna move up eventually to take their role.

Now, this is a very difficult conversation to have, Rich, because people aren’t thinking like that, right? They’re thinking like “You’re gonna come after my job?” But you’ve gotta have another position for those folks as well. So thinking way ahead, looking at the crystal ball, what does the organization look like to where we need to get it to, so that when we do decide to entertain the myriad offers of, getting s- getting bought by all these PE groups or roll-up groups that all MSPs are experiencing now, we are best prepared to command the highest offer

Rich: It you’ve got me hearkening back to my time working at Microsoft 20-plus years ago now.

And I remember when I transitioned from individual contributor to manager, and the most important lesson that I had to learn was along the lines of coach instead of solve. Basically [00:22:00] you’ve gotta set ex- expectations, you’ve gotta define the outcome, the r- the result that you’re trying to reach, and then you’ve gotta trust the person on your team to do that work.

And it might not, they might not do it the way you would do it. That’s okay, as long as they get to to the result. That’s hard to do if you’ve been an effective individual contributor for most of the past several years or your entire professional life. But it’s a critical lesson to learn, and particularly for MSPs, really any entrepreneur because if p- if you can’t do that, it really does become a growth bottleneck.

So you, you gotta get past that. And then the other thing you said that reminded me a little bit of Microsoft, you were kinda talking about some of the techs on your team just wanna close tickets, and that’s fine, right? Unders- you know, identify who those people are and put them in a position to, to do what they’re great at and enjoy doing.

And this was a particular problem at Microsoft when I was there, because the company really only knew one thing to do with effective individual contributors, which was to turn [00:23:00] them into managers, and a lot of them really just did not wanna do that, and therefore were not good at it. And I remember when I was there, at least, when they did exit interviews at Microsoft, the number one reason that, that people, like good employees, left the company was a bad manager.

Arve : Oh, yeah.

Rich: Likelihood being this was a manager who should not have been a manager in the first place. So yeah you wanna help people grow in their job, but just make sure that they’re, you’re helping them grow in the right direction.

Erick: Yeah, I’m- have you heard the term people don’t quit companies, they quit their supervisor or their manager?

That’s what happens, right? And, the other thing that I think of is just because you’re, like, in a sports, organization, just because you’re a great quarterback doesn’t mean you’re gonna be a great coach, right? Just because you’re a great running back, just because you’re a great, three-point shooter doesn’t mean you’ll be a great coach for the team.

So that’s another part of, learning to be a good leader, is to identify everyone’s strengths and challenges, coaching and mentoring them through some of their challenges, and [00:24:00] understanding what they want out of their career. I again, you’re having interviews with these folks and saying, “Hey, we’re gonna be instituting this accelerated program to, for advancement of some folks.

Would you be interested? Because I think you’ve got some potential, and here’s what I see for you.” And then just get their feedback. If they’re, like, immediately “Oh no. I’ve got this or that,” or… And sometimes it’s just family stuff, like they’ve got responsibilities with kids and things like that, where they just feel they, they may want it, but they’re just not ready at that time.

So don’t just write them off either. Come back to them, every, couple of quarters, once a year in doing their, annual review or whatever, and just talk to them and see if anything’s changed. Maybe they see their peers advancing and, making more money and having, doing more interesting and fun things and go, “You know what?

Yeah I’ve changed my mind. I might want to try something.”

Rich: All right. With that, folks we are ready to take a quick break here. When Erick and I come back from the other side of that, we are going to be joined by Arvi Kajolan. He’s the chief information security officer at [00:25:00] Barracuda, and we’re very pleased to have him on the show because he has agreed to speak with us about Mythos and Fable and GPT 5.6, these very effective, scary effective AI models out there right now, and their security implications, both for you as an MSP and for your customers.

So that’s all coming your way in just a moment. Stick around, we’ll be right back.

And welcome back to part two of this episode of the MSP Chat Podcast, our spotlight interview segment where we are very pleased to be joined by Arve Kajolan. He is the chief information security officer at Barracuda. Arve, welcome to the show.

Arve : Thank you. It’s great to be here.

Rich: It is great for us as well, ’cause we’re gonna be digging into the security implications for MSPs and their customers of Mythos and Fable and ChatGPT 5.6, all of these high-powered models present now and coming certainly in the future.

But before we do [00:26:00] that tell folks a little bit about yourself and your role at Barracuda.

Arve : Great. I am relatively new at Barracuda, about six months. I spent quite a bit of time in the technology industry, so I’ve been at both smaller startups as well as some larger companies. I am e-excited to be back in the enterprise and in the space where our customers are companies who have high demands and who ask for, better and better quality from us.

One of the things we’re doing internally is working to have a more centralized way of running all of our own products internally so that we also can contribute to to the feedback for the products and be a real customer for them. So excited to do that as well.

Rich: And this is perfect for us ’cause you basically are responsible for dealing with the issue at Barracuda that the folks in our audience are responsible for dealing with as well which is figuring out what needs to change in response to the appearance of of these models.

I’m sure most of the people in the audience are aware Mythos, [00:27:00] Fable, GPT 5.6, they’re all much more powerful than their predecessors and much more dangerous in various ways. But just to set the stage a little bit and make sure we’re all starting from the same point, how would you describe, summarize what’s different about the dangers that these particular models pose?

Arve : I think it’s a gradual change, and I think this change has been coming for a while. For years both attackers and defenders have improved things by creating better scripts, kinda stringing together full attack paths, automatically finding vulnerabilities. And so we’re now getting to a point where where the machine is much better at doing that than humans in, in most cases, with some exceptions.

And so what that means is if we look at the horizon over the next few years we’re going to see more vulnerabilities. We’re going to see more of these CVEs published and the increase will be significant. And that’ll just put stress on all of our [00:28:00] organizations in terms of now there are more vulnerabilities to patch do I have the resources to do this, and so on.

Erick: Arvind, in your role at Barracuda, what are you doing as CISO to protect Barracuda itself from these dangers?

Arve : So the most important thing is to continue to focus on the basics because the f-first-order result of these models is that you just get more vulnerabilities published more quickly. And that means we have to do the same things that we’re doing today, but just do more of it and ensure that we have better coverage.

Let’s take multi-factor authentication as an example. That’s probably one of the stronger controls that we can put in place. But let’s make sure that we go back and not just that everyone is covered, but is everyone covered by the strongest versions, right? So MFA, if you have enabled this text SMS callback, that is not the [00:29:00] strongest way to do MFA, right?

And so just making sure that everyone is covered and that we’re using the strongest ways to do that. So that would be one example, but focus on the basics first before we even get to any of the more advanced things.

Rich: We’ve been talking about these models with respect to the the dangers, the threats that they pose o-out there.

But MSPs can take advantage of those same powers for defensive purposes. And in fact access to these models has been restricted for extended periods of time so that white hats essentially can find the vulnerabilities these models expose themselves and do something about it. Talk a little bit about how MSPs can potentially take advantage of these models from a defensive standpoint, and also what you’re doing at Barracuda to take advantage of the defensive capabilities.

Arve : Yeah. So for MSPs, I think you still want to start with the basics that I talked about. So that includes [00:30:00] MFA, having solid email security, making sure that you’re patching your vulnerabilities. Beyond that, when you start looking at the models it depends a little bit on where you are and what you’re doing.

If you think about the customer side of things, if you’re an MSP and you have software vendors who are customers now there’s a conversation about, okay, to what extent do those software vendors want to use want to use these models to improve their own software? Many MSPs do not have that many software companies as customers, and so for them it becomes a little bit different.

It becomes focused on looking at their own software providers. So if you’re an MSP, who are you buying software for– f- software from? Are they using modern tooling and are they doing some of the things that we at Barracuda and other, and a lot of other companies as well have started to do?

And what some of those things are is the most important thing that a software vendor like us can do is [00:31:00] to focus on our own software and using these advanced models to scan that software. And that’s how this explosion of vulnerabilities comes about, right? Because companies like us and other companies are finding more vulnerabilities in their own software.

A lot of times, if it’s new software, we will just patch that before it is before it is released to the public. But if it is older software, then you have to go through the process of you’re creating a new CVE, new vulnerability. That one gets issued, and now there’s just more work for the downstream adopters of that.

Erick: Arve, these days we talk a lot about how MSPs can leverage AI to automate and increase their efficiencies in, specifically in service delivery, in service desk operations, the level one ticket triaging and management and things like that. Can models like Fable potentially [00:32:00] help MSPs increase productivity and efficiency by automating some of their security processes?

What are the pros and cons of that? What’s the risk and reward? What how do you view that?

Arve : Absolutely. Outside of scanning your own software and so on, which I think is difficult you need a certain size to be able to do that. There are so many security processes that have the potential to be automated.

I would maybe start up by saying that there is a cost to doing all of this. So if you are going to build your own mini software product that automates a pro- function, maybe it is you want to automatically fill out incoming security questionnaires. You have to create that. You may have to update that when a new model comes out, and you need to dedicate some level of resources just to keep that up to date.

And so as long as you keep that in mind that there is an overhead cost to doing many of these things yourself I think the sky’s the limit when it comes to what you can automate. [00:33:00] Some of the areas that we have looked at ourselves internally around governance, risk and compliance, risk management, automating dashboards, automating communication metrics.

It’s if you’re a larger company and you’re running your own SOC type of environment, then there are even things that you can do to automate that SOC function. There are of course vendors that play in that space as well and sale, sell AI automation for SOCs, but there are many things that you can do yourself as well.

As long as you keep that in mind that it’s gonna cost you a little bit from an overhead perspective.

Erick: Yeah, the burn.

Rich: So we’re we’re coming up on Black Hat which means I’m getting a lot of contact from security companies that are hoping to meet there. I got something from ISC Squared just yesterday or the day before.

They have somebody attending who wants to talk about what he’s calling the forthcoming patch tsunami. So these models, as you’ve said, they’re really good at finding [00:34:00] vulnerabilities. Attackers are gonna take advantage of that. Software companies are taking advantage of that. And that means there’s just gonna be a l- a lot of vulnerabilities to patch out there.

And I, I know I worry a little bit about how manageable that is. So what are your thoughts basically about the patching burden that MSPs may have coming their way, how manageable that is and what, if anything, they can do about it?

Arve : Yeah, it’s a great question. The first thing I would say is that yes I have spent some time doing modeling around what will this look like?

‘Cause obviously when these new CVEs are created, these new vulnerabilities you have to go and patch it to some extent. And it varies a little bit depending on what you have. You will have users who use a lot of SaaS, and if you use a lot of SaaS, then it’s really on that SaaS company to do the patching.

So you may be less affected by this patch tsunami. If you are on [00:35:00] Microsoft I think there are two thoughts on what will happen if you have a lot of Microsoft. Because Microsoft does the Patch Tuesday once a month, and I don’t know that it’s going to be that big of a difference to you whether there are 100 vulnerabilities in the patch that you’re applying or whether there are 200 vulnerabilities in the patch that you’re applying.

So that would be one viewpoint, but I think the other viewpoint, and perhaps more s- more scary one is, will Microsoft and other vendors get to a point where they don’t want to wait and issue these updates once a month? And so if you start getting emergency pack- patches, that’s going to be really disruptive.

So-

The two things to be able to patch effectively you, you have to have the asset inventories. You have to know what it is that you own. That’s one piece of it. And then I think also keep an eye on things that perhaps are not commonly included in vulnerability management tools. Let’s say you are running a firewall.

[00:36:00] It’s not likely that your vulnerability tool can be installed on that firewall, so you need to make sure that you also keep an eye on vulnerabilities for any hardware, any appliance-type hardware that you may not that may not be covered by your vulnerability management tool.

Erick: Arve, as a former MSP, I remember the aftermath of the Patch Tuesday and everything that stopped working or broke back in the old days.

I think it’s better now, but… And I know that the more mature MSPs are managing when they release some of these patches. Obviously, zero days have to go out when they go out. It’s not negotiable. But, having, giving a little time to breathe and seeing if there are any let’s just say, negative impacts with some software or something that that customers typically own was always we were always crossing our fingers to see, okay, what’s the aftermath of this?

But let’s talk a little bit about the opportunity for MSPs to leverage the [00:37:00] opportunity offered by Mythos and GPT 5.6, not in their own environment. So let’s turn the lens outward because, as MSPs really want to monetize AI, and they’re trying to figure out ways to do it. If you were to sit down with a small group of MSPs and are having a conversation and they’re asking things about, “Okay.

We see the value internally, but we want to create a revenue opportunity with these products with our customers,” what kinds of things would you share with them?

Arve : Ooh, I think that’s a, that’s an excellent question. I think I’ll start out by assuming that there are kinda two paths that they can go down, right?

Like they can build their own, in which case they have a lot of freedom but, comes with cost, comes with time commitment and so on. Or they can look at vendors that provide kinda new and exciting capabilities that they can provide to their customers.

Is that how you would categorize [00:38:00] it as well?

Erick: Yeah. I would think of a way to leverage not just the benefits of the solution, but, what kind of services attached could we think about. If I’m delivering some new feature and benefit that’s baked into a vendor solution and deliver it, how– what else could I do from my managed recurring revenue thought process- Yep

to increase that, that MRR, ARR and add more strategic value based upon like the business outcomes that those customers are really trying to achieve.

Arve : Yeah. I think I would, without talking about specific ideas, maybe I would talk about a framework for how to think about it. I think there are two, three things going on in the industry.

We should probably just start with AI in general, right? So if there are ways, I see a move towards more certification emphasis in the AI world. There is an ISO certification called 42001 [00:39:00] that we are pursuing. It’s maybe more of a revenue protection play, but that, looking at that or are there ways that you could help your customers customers help obtain that.

Outside of AI and the products that are coming in that space, right? So there’s can you find shadow AI? That’s one. Can you just help your customers be confident about what their employees are doing with AI and which models they are connect to and what they are what they are putting into that model.

I think that’s one opportunity. I think another one is around thinking about what’s going on with the ways that attackers are getting in. So right now, attackers are getting in via vulnerabilities. It’s really the largest one if you look at, say, Google’s M-Trends reports, Verizon’s data breach report they all point towards vulnerabilities as being number one.

A-and it will continue to be high until [00:40:00] these vulnerabilities are identified and eliminated, which will take a few years. So during the CVE bubble, vulnerabilities will continue to be high. But attackers are gonna need to shift once these vulnerabilities are eliminated from new software, and where they’re shifting to is often in the identity space.

So what can you do around offering things that protect from an identity perspective? Maybe that is that is vishing, so voice phishing. That’s an area that’s been growing rapidly the last few years. Maybe it is privileged access management and making sure that you control your privileged users better.

So I think those would be two other areas just due to where the attackers are moving next.

Erick: Are you seeing more MSPs thinking along the lines of a VC-AIO? ‘Cause we talk about that a lot on the program. We use that term and say this is a new differentiated role that could add more value if we’re actually delivering secure AI [00:41:00] usage and capabilities to our customers.”

And understanding kind of moving the conversation from the call it from under the desk or the server room into the boardroom, is how we think about it.

Arve : Yeah. Yeah. I think that’s accurate. I think, A- And there are other areas in the AI s- space as well, so we talked about shadow AI and so on.

But if you are, if you’re offering services that somehow you’re putting behind AI or you’re using an LLM, you have an open API, you have anything that you- your people can query internally or external people can query, making sure that’s protected properly as well.

Rich: Avi I was at a a conference hosted by Veen not too long ago. I was interviewing one of their executives. I brought up Mythos, which was pretty new still at the time, and he just grinned and said, “Everybody’s asking me about Mythos. Every meeting it comes up.” Which is actually a good sign.

He was mostly [00:42:00] talking about conversations he was having with enterprise k- so like your peers in the CISO world were obviously very interested in it and were all paying attention and asking questions. Do you have a sense at all for the degree to which that’s true among MSPs as well? Are you guys getting questions about this from them?

Are they trying to figure out what it means, if anything? Or is there maybe some more awareness that you’d like to see building out there?

Arve : We are getting questions, but I don’t know that I have data to tell you whether it’s, it’s the appropriate level of of concern. I should probably say and be transparent about the fact that I…

Although Mythos and Fable and so on continue to increase the level of the level that these LLMs can find vulnerabilities at, I, I’m a little skeptical just as a security professional of [00:43:00] some of the restrictions that have been put in place. And the reason I say that is I go back to what was going on when vulnerability management first became an industry, right?

And we had these two individuals. One was Dan Farmer who was working for Silicon Graphics. One was a Dutch researcher named Wietse Venema. They created the first host-based firewall. They decided to create this new security scanner and make it freely available. And the same discussions that we have today were had then.

There was concern about national security. There was pressure brought to bear not to release it at all. They released it anyway. Stan Farmer parted ways with Silicon Graphics, then later went to work for Sun. But where are we today, right? We are, it’s a multi-billion dollar industry, vulnerability management.

And those scanning products enable that administrator to sit and click a button and get an overview of all the vulnerabilities that existed in their environment. So I worry that we are [00:44:00] restricting defender access to these models. And it’s impacted me at Barracuda, and it’s impacting others as well who would like to do more to pr-protect themselves and protect their customers.

Erick: So Arve, we’ve talked about a lot of different topics. If I were to ask you, speaking with that same group of MSPs in kind of that boardroom session to come up with a roadmap, maybe top three or five things in the appropriate order that you would recommend to MSPs today, understanding the tremendous pressure that they’re under, the risk that their customers are under, what would that guidance look like?

Arve : If the purpose of the roadmap is to protect yourself, then then it’s the things that we talked about earlier. It’s make sure that you have the basics in place. It is make sure that the vendors that you are buying from take it seriously and are working actively to scan their own [00:45:00] software. It’s not so important to do a, a deep dive audit on your vendors, but make sure that they’re flexible, that they’re m- nimble, that they can move with speed, that they’re concerned about this about this issue.

And then on the revenue side, I would say that AI security and identity are probably the two areas to think about how you can monetize that.

Rich: Arve Kodjolan, thank you so much for joining us here on the show. Very interesting conversation about an important topic. For folks in the audience right now who would to get in touch with you get in touch with Barracuda where would you point them?

Arve : What is the easiest way to do this? Have Jeff then come through you. If they they email, say, security@barracuda, that will make it to me. Via email. I’m accessible on LinkedIn. Yeah, I welcome outreach. This is… These are important topics, and none of us have the full answers.

We can, We all have opinions, and we all have part of the answer, and the more we interact, I think the better [00:46:00] solutions we’re gonna come up with.

Rich: All right. Fantastic. Once again, thank you very much for joining us on the show. Folks, Erick and I are gonna take a quick break here. When we come back on the other side, we’re gonna share some parting thoughts about this very interesting conversation, have a little fun, wrap up the show.

Stick around. We’ll be right back.

Welcome back to part three of this episode of the MSP Chat Podcast. One last thank you to Arvy Kajolan of Barracuda for that, as I said, timely conversation. I– there are tons of things I could follow up on in that conversation. Yeah, Erick, I’ll just pick out a few. So first of all we were asking him what what do you do about the dangers posed by these models?

And it’s interesting how the answer the primary answer to that question is the answer that we always get to that question because it is the right answer and a good one, which is cyber hygiene, the basics [00:47:00] as he put it. MFA needs to be in place. And if I drew anything different from the answer there is that you wanna be a little extra rigorous in terms of the basics, right?

Like SMS-based MFA might not be good enough. You’re looking for the best way to handle the basics, but the basics come first. If there’s ever been a good reason to make sure 100% of the users at 100% of your clients are doing all that stuff, this is it right now I did find the whole topic of whether or not access to these models should be restricted temporarily or beyond is a very controversial one.

There’s just a lot to dive in there. But I did find it a little reassuring that his take on the matter essentially was, we’ve been through this kind of thing before when he was talking about the birth of vulnerability scanning. And it’s understandable, that people get really worried about the cybersecurity implications, national security implications, but it…

This is not totally and completely unprecedented. And we can figure our way out of this based on historical precedent without [00:48:00] just denying everybody the ability to use these tools forever. I think, Erick, we need to announce the birth of a new acronym here on the show, and I wrote it down.

I want to get this exactly right. It is VCAIISO, Virtual Chief AI Information Security Officer. When you were talking about the revenue generating opportunities around these models the idea to if you’re doing vCISO services now the opportunity to really add more of an AI flavor to that is an interesting thought for folks with the with that kind of vCISO relationship with their customers right now.

And then last but not least it was interesting seeing you get triggered by memories of Patch Tuesday from 20, 25 years ago. It did… This was an if, not a when, but he was saying if MSPs start getting hit by more patch days, it doesn’t… It’s not just Patch Tuesday. That, he– I think he’s absolutely right.

That will have a disruptive impact on MSPs, and so that will be [00:49:00] something to watch for coming up in the next couple months or so.

Erick: Yeah. I appreciate you re- re-resurfacing that pain for me, Rich. Nice. Yeah, and I also like the, the first thing you mentioned was the through line that I stuck with me is no matter who we interview about security and AI, it all comes down to do the basics, right?

Do the basics. That hygiene is the through line. So if, folks if you’ve been hearing it on the show over and over, like we’ve been hearing it, and you’re not taking action, it’s time to probably get that done first. And I think you can monetize that, Rich, as well. You can say, “Hey, we’re gonna do a complete security assessment, and here are the things that we need to implement, and this is something that you’ve been resisting.

It’s gonna take this much time to do it.” I would try to monetize it because clients take things more seriously when they have to pay for them, I believe. They don’t, they… isn’t that included?” You know what? It’s now gotten to a point [00:50:00] where we have to do an in-depth assessment. And we’re all…

While we’re at it, we’re gonna do an a shadow AI assessment and shadow IT assessment. Now, you roll all that in and present it as a next evolution of security assessment and optimization program, I think you can make money on it. That’s me saying that. So you, you heard it here first.

The other thing that I thought was interesting was w- when Arve predicted where the puck is going, and he said vishing is the next opportunity. The phone call, the virtual call. And we’ve talked a little bit about, the deep fakes and stuff that we’re seeing, but, I’m really starting to be a little bit more concerned about just how good all of this AI

is going to be in the next three to five years. And, you will probably, and especially I think for, older folks, right? Who are the most susceptible and are targeted by a lot of these criminals for these [00:51:00] types of things, and the old scams, Rich, you’ll recall, it’s oh, they impersonate, the granddaughter, calling the grandmother and saying, “Oh, hey, Grandma” and then trying to social engineer, “I need a, I need a bus pass or something.

Please send me money,” and that kind of stuff. That’s… It’s gonna be so evolved and so hard to determine what’s real and not. The security professionals are definitely gonna have their hands full trying to address, how to overcome that kind of stuff. So that was interesting, like beyond now, what’s next kind of a thing that he’s thinking about.

Rich: And that, that too in a way is a- an example of a cyber basic that it just, you know, and at least not necessarily with your grandparents, although maybe, but certainly in the corporate environment, you know, security awareness training and so on. Th- this kind of plays into that. I wanna underscrie…

I really like the point you made about turning this into a revenue opportunity with customers because there really is an o- e- especially if you’ve had trouble [00:52:00] with customers in the past, getting them to really take the basics seriously, this is an opportunity to come to them, make a little money by positioning this as a sort of AI hardening service that you’re bringing them.

And folks like me in the media, we’re setting the table for you, right? ‘Cause we keep talking about how scary these models are, and the government is reinforcing that. So th- they’re aware of this. This is a moment for you to come in and make a few bucks doing stuff that in a lot of cases they should’ve been doing a long time ago.

And if you’re charging money for that, like you said, I think you’re totally right, they will take it more seriously. Between my headlines and the fact that they’re paying money for that AI hardening service, they’ll take it more seriously than they have.

Erick: Yeah. And the old tactic of the the sign this form that says you declining all this stuff, and so when the bad thing does happen, we’re gonna charge you our highest rate to come in and help you recover from it.

And that won’t be [00:53:00] the most you ever pay to get out of some situations, because it is so dire. You know the statistics of businesses that end up closing, a year after a huge cyber attack and things like that. It’s serious stuff. So I think MSPs are really understanding the risk more than they did, a couple years ago and are- way better positioned to, to get clients to say yes to enhance cybersecurity, especially if it serves their business vision of leveraging AI and all that.

It’s a perfect conversation to have and charge them for that. And for the folks that just are not gonna move, I don’t recommend you just letting them off the hook with a, a waiver of responsibility form or something. You’re still at a tremendous amount of risk no matter what. Over time, you’ll prob- it’ll probably force you to adjust, your profile of your ideal client profile and maybe exit those guys over time and work with the folks that get it and are growing and, take your advice and do what you [00:54:00] want them to do to keep themselves and you safe

Rich: Okay.

Folks, that leaves us with time for just one last thing. And if I’m not mistaken, Erick, on last week’s show, we talked about a DoorDash delivery bot helping out in the middle of a SWAT operation by arriving with pizza. We have another law and order story for you this week from the realm of robots and autonomous vehicles and all that good stuff.

This comes to us from your hometown of, actually, the report’s from West End. This happened in San Mateo, Northern California, where police detained two 15-year-olds who they said were drinking and shooting water beads Orbeez, I had never heard of this before which are soft water-absorbent polymer beads.

But they were in a Waymo driving around town drinking and firing these Orbeez at people, and the folks at Waymo became aware of this behavior. They steered the car over to the side of the road. They dispatched police. I- interestingly enough, Waymo did [00:55:00] emphasize that the two teens were not locked in the car, so they had the opportunity to get out and flee.

Apparently, they did not take advantage of this, but police responded. And thank you for the law enforcement assist, Waymo.

Erick: Yeah, really, right? They were probably, teens drinking. They probably were like, “Why has the car stopped?” They had no idea that, the autonomous, overlords are dispatching law enforcement to give them some guidance on what they should and should not be doing, whether it’s an autonomous vehicle or not.

Crazy kids.

Rich: You’re probably exactly right. When the police showed up, the teens were in the back of the car on their phone trying to figure out how to get this thing driving again. Yeah. All’s well that ends well. And that goes for this episode of the show as well, folks. Thank you very much for joining us.

Erick and I are gonna be back in a week’s time. Until then, I will just remind you as I always do, this is both a video and an audio podcast, which means that if you are listening to us right now but would like to check us out on [00:56:00] video, go to YouTube, look up MSP Chat. If you are watching us on YouTube but you’re into audio podcasts, go to Spotify, Google, Apple.

Wherever it is you get your audio podcasts, you’re probably gonna find us there, too. And wherever it is you find us, please subscribe, rate, review. It’s gonna help other people find and enjoy the show just like you. This show is produced by the great Riley Simpson, part of the team with us here at Channel Mastered, where we help vendors build thriving MSP channels in a wide variety of ways.

You can learn all about them at our website located at www.channelmastered.com. Channel Mastered has a sister organization called MSP Mastered. That’s Erick and his team working directly with MSPs to help them grow and optimize their business. You can learn more about that at www.mspmastered.com. So once again, we thank you for joining us here on the show.

We’ll see you in a week. Until then, please remember, as I always urge you to, you can’t spell channel without [00:57:00] MSP