Youtube video

August 4, 2025

Episode 84: If You Build It, Will They Come?

Listen to the podcast

Read Transcript

Live and side by side at GTIA’s ChannelCon event in Nashville, Erick and Rich discuss Pax8’s bold plan to re-invent marketplaces for the agentic AI era, and a roadmap MSPs can use to get started in AI services before it’s too late. Then they’re joined by back-to-back interview guests—Will Brooks from UKON and Eric Altamura from SPECTRA—to explore two of several emerging models for turning cyber insurance from a stressful headache into value-adding risk management conversation. And finally, one last thing: Chuck E. Cheese has been busted for credit card fraud.

Discussed in this episode:

UKON Announces Strategic Partnerships with Cork, CreditPulse, Blackpoint Cyber, and SeedPod

Spectra Releases Certification of Resilience for MSPs; Launches Advisory Board

‘Come with me, Chuck E’: Florida police arrest mascot for credit card fraud as children look on

 

Transcript:

8-3-25 MSP Chat Episode 84 audio export

Rich: [00:00:00] And 3, 2, 1. Blast off. Ladies and gentlemen. Welcome to another episode of the MSP Chat podcast. Your weekly visit with two talking heads, talking with you about these services, strategies, and success tips you need to make it big and manage services. My name is Rich Freeman. I’m chief analyst at Channel Mastered, the organization responsible for the show.

I’m joined side by side, physically this week to my pleasure by your other co-host, our chief strategist at Channel Mastered at he is Eric Simpson. Eric, how you doing? Doing well, rich. Good to be on the road with you again, my friend. It is. It absolutely is. We are in Nashville, Tennessee at the GTIA Channel con conference last day of that event.

It’s been a great [00:01:00] one here in Nashville. Lots and lots of interesting content and information and interesting vendors in the expo hall and as always, at a channel count event. Lots and lots of great hallway conversations. It’s it’s been a good week. It has been a good week. And a big week for GTIA.

The, that organization is 200 days old as of this show right now. And so a big part of what they were doing here was just introducing people to the mission and some of the new resources that they have going. But what I kinda wanna dive into for our story of the week here, Eric, I, this is like a bit of catch up for me.

As a lot of folks out there will know, I disappeared for a little while there for personal reasons we won’t be getting into. But I was just outta the picture for a little while and that. Period of time happened to coincide with PAX Eights Beyond Conference in Denver, which was back at the beginning of June.

And they used that conference to introduce their sort of next generation vision for where their marketplace is going from here, and I finally got an opportunity here at Channel Con to meet with some of their [00:02:00] senior executives and better understand what it is they’re building and why. And I gotta tell you, Eric.

It’s a big ambitious vision. And the, for reasons I’ll explain, there are pieces of it that I think are gonna be very challenging. But on the other hand I think not pursuing this vision is going to be dangerous both for marketplaces and distributors and for the MSP. What am I talking about here?

In the earliest days of distribution, it was all about pick, pack, and ship. You had a warehouse full of boxes and the distributors were specialists in getting boxes of hardware and boxes of software out to the customers. Along comes the cloud software as a service. You don’t need as many boxes anymore, and a lot of people figured distribution is irrelevant.

It’s dead. It cost billions of dollars collectively, but distribution adapted found a new way to play in the era of cloud computing and software as a service. And this is very much where PAX eight kind of came into the picture. You could go to PAX eight. You could identify a customer need [00:03:00] fine, multiple applications that would address that need weave that together with your own services and bring a solution to the customer.

What happens in the age of AI though? Where a lot of the work that users, end users are doing today is actually being done by agents and by ai. It’s an entirely different customer need. And therefore, people are gonna be looking for and need an entirely different kind of marketplace. A marketplace that’s just gonna give me applications isn’t going to get me to the solution that I need to be delivering for my customer, who at that point is real, really, truly just looking for an outcome.

They don’t even want to talk to you about the applications that go into that solution because they’re never gonna interact with it. All the work is being done by AI agents and other forms of AI invisible behind the scenes. Here’s my need. Give me an outcome. And in order to meet that demand, which is where the market’s going, if you wanna be relevant as an MSP, you’ve got to be equipped to meet [00:04:00] that demand.

To do that, you need a marketplace that can give you not just the applications, but the agents as well, all of the tools that you need to create that agentic solution and the integrations that weave the agents together with one another and weave the agents together with the applications and allow the applications to talk.

This is a next generation marketplace. It’s not something that. Any of the marketplace operators or any of the distributors can do today. You think about the Azure marketplace, AWS you think about the the platforms and marketplaces that, Ingram and tds, all those kinds of companies.

Nobody’s doing anything even remotely like that right now. And PAX eight believes passionately that just as in order to have remained relevant as the entire industry shifted into the cloud, you had to build around that cloud business need and and partner need. You’re gonna have to do that as a marketplace and as an MSP around ai.

And that’s what they’re. Looking to build now they’re gonna, they’re in the process of creating what they’re [00:05:00] calling an agent marketplace. So in addition to the solutions that they’re already offering to their partners, they’re all also going to have a selection of agents that their own partners are gonna create that vendors are gonna create that companies that do nothing but build and sell agents are going to create.

And you’re gonna be able to pull together the agents and the applications and the integrations. You need to assemble and run orchestrate one of these ag agentic AI solutions for your customer. The thing about a marketplace though is I guess the question around this vision, Eric, is if you build it, will they come?

Because PAX eight, they’ve got the smarts and the people and the skills and the money to build what I’m describing to you, but it really only works for them and for the industry. If the MSPs buy into that and if the vendors buy into that. It’s gonna be a heavy lift to get the MSPs to wrap their brains around this idea that I need to adapt to a new, a totally and completely new era of [00:06:00] it in which I am delivering these heavily, if not completely automated solutions, and working with companies that can give me the tools I need to do that.

So you gotta bring the MSPs along, and that requires a lot of education and evangelism and rethinking reward structures and pricing structures. And then you gotta bring the vendors along too. They’ve gotta be bought into being part of these solutions. So they’ve got a lot of work ahead of them at PAX eight.

But I gotta say they also, hats off to them. They are way out in front in terms of really thinking at a big level about what AI and the AI explosion that is happening, but it really is just beginning to happen in the IT world. Means for companies like PAX eight and they are not waiting to see how that plays out.

They are placing some big bets right now.

Erick: Yes, and I attended that conference and, interviewed several other leadership. I saw the vision and I was very impressed. But you raise a [00:07:00] really good question, rich, is will the MSPs show up and respond? Now we’re talking about. A segment of service providers that historically have been challenged at, pricing and bundling their services in a profitable manner.

You hear different statistics in the industry about what percentage of MSPs are unprofitable, and it’s pretty surprising if you believe these statistics. You’ve got these providers that are trying to true up their existing clients to what they’re currently charging their next new customer tomorrow to be.

They’re trying to get their existing customers to sign up for enhanced cybersecurity so everybody can sleep good at night, right? And trying to get them to say yes to this. And then all of a sudden, here comes this ai, tsunami, which everybody is touting to be the next level of value that [00:08:00] MSPs can deliver to their clients.

The mature MSPs the first movers will have the advantage, will leverage everything that, PAX eight is putting together and start dedicating resources internally, if not teams, to build out an AI practice to deliver these services for their clients. But the most successful ones will really be focused on those business outcomes.

And I think Rich, we were having some hallway conversation earlier today about, how mature an MSP needs to be to do this, and how they sh they can adjust their pricing model to be focused on the outcomes that they deliver through AI workflows, agents orchestrating and managing these agents.

That’s different potentially than how they bill for today because they’re a completely different model, right? You can bill like per chat bot, per agent, per workflow. The most interesting and the highest profit [00:09:00] potential that I see are tying your solutions around the business improvement that can be measured, increased sales, increased customer sat increased lead generation, things like that.

More efficient shorting the time for accounts receivable and accounts payable to be those kinds of things that are just, fundamental building blocks of any business. We saw Stat that Jay McBain shared at at Beyond, and I believe it was 86 or 87% of business owners Polled, said they want to incorporate AI into their organizations.

So it’s a huge opportunity, but it’s gotta be a thoughtful architecture and portfolio build out and a deployment and measurement process. To be successful for MSPs and they need the help of partners like PAX eight to do this. MSPs can’t figure it out on their own. They’re just too busy [00:10:00] doing all these other things.

So I like what PAX eight strategy is helping to train and enable their partners to go do these things and provide them some of these rating aid agents that they can deploy and tweak and deploy and bring to their clients. But again, if they’re gonna do it right, they have to be thoughtful about it and sell and deliver their value proposition in a much different manner than maybe the commoditized portfolio of managed services that the majority of MSPs are delivering to everybody else.

Rich: Yeah. Yeah. And you raised a particularly important point that the PAX eight folks emphasize as well, which is that you, you are not as an MSP going to have to convince your end user clients to invest in ai. They are eager, if not desperate to do that. There, there was some data presented here at the show based on GTIA research where they were asking people about their their sort of bearing in relation to ai.

And I think it was [00:11:00] 31% of the SMBs they surveyed described themselves as ambitious, like hungry to move as fast as they can move. And it was 40 some odd percent who call themselves planning. They are absolutely gonna do it, but they’re at a slightly earlier stage in terms of adoption and enthusiasm.

But add those two together. And it’s massive and it gets you into the zone of the canals numbers that Jane McBain presented. So the, your customers are already chopping at the bit to do this. And this goes to, the first mover advantage you were talking about the people who move in first to satisfy that demand are gonna have massive lock-in and the last people to the party are gonna be in a really bad place.

And one of the things Pax eight kind of talks about is and this goes to your point as well you can’t necessarily dive headfirst all the way into the pool, but there are things you can do right away and probably should do right away. That there are no regret decisions. And education is a good [00:12:00] example of that understanding what a agentic AI is going to mean for IT services for your end user.

And and this is why Pax Eight’s rolling out all sorts of educational materials to help MSPs figure that out. But yeah you don’t have to get out over your skis too much, but you’d also don’t want to to wait too long to start figuring this out so that you can begin working with your clients on what they wanna work on with you before it’s too late.

Absolutely. Yeah. So I’ve got some thoughts

Erick: about that in my tip of the week. Perfect segue, sir. Dive in. Alright we were just talking Rich about, my, my position that says, look, MSPs got a lot of work to do to get their house on order before bringing on a whole new solution.

But their customers are asking for it. They’re, they want it now. So how do we maybe get the best of both worlds? So one big need [00:13:00] that MSP’s customers have is strengthening their cybersecurity posture. Looking at compliance and things like that. AI requires a lot of governance. It requires security.

We know that there are folks that are out there just signing up for these, LLMs and chatbots and with no thought to what they’re putting into the platform and where that’s going, and who else can search. Find that data. We know that if Chad GPT is not configured correctly, that you can expose, business information, personal information that can show up in someone else’s chat.

GPT query. I’ve seen examples where people are actually, MSPs are actually training chat GPT to find their company when business owners are searching for an MSP. So think [00:14:00] about that, right? So clients are really looking to, and business owners are really looking to leverage the promise of ai.

So let’s have a business conversation with our customer that sounds like this. Hey, what’s your appetite for ai? We know that it can do all these great and wonderful things, and we have some solutions that we’d like to introduce to you. So that you can achieve these business benefits, these outcomes that can be measurable like the ones I mentioned, increased, closing better sales or qualifying better and lead generation all kinds of different internal operational things.

Client increase in client satisfaction. We can build out these agents based upon, prioritizing where your biggest need is and the biggest improvement we can deliver to you. Wow. What business auto wouldn’t want to hear about that. Here’s what we’re gonna do first though. We’re gonna do an assessment of your infrastructure from a cybersecurity perspective to make sure that we can [00:15:00] prepare you for the delivery of AI and agentic AI and things like that.

So that’s kinda what I’m thinking, rich, is this is how the MSPs can get two bites of the apple for the, for their customers that haven’t yet. Signed up for everything the MSP requires to keep them safe and secure, reduce their risk. The MSP can sleep better at night as well as like the customer, but then also using AI and the promise of AI to improve certain aspects of their business in a prioritized manner that can be rolled out in phases.

But first, we have to build this foundational assessment of their readiness for ai, which includes a thorough cybersecurity assessment, penetration testing, and things like that to get them to their minimum baseline of a cybersecurity bundle that they require every one of their clients to sign up for.

Just to be their client anyway. But now I think AI could be a little bit of a carrot to help along that path.

Rich: Yeah, as a responsible MSP, you [00:16:00] really have to begin the AI journey for any client you’re working with two things. And that’s securing compliance on the one hand and making sure you’re prepared to preserve both of those as they get deeper into ai.

And then also on data on the other. You’ve gotta clean, consolidate, ready the day, the data for AI and that, and that requires assessments. This is something that you can charge for. This is valuable work for the customer. It’s also conveniently, in a lot of cases, a little bit closer to the kinds of things that you’re doing.

It’s not quite as unfamiliar as building agent first solutions and so on. And so it’s a way to to get in sooner versus later while you’re preparing yourself to to get in more sophisticated ways later on. And and the other important thing that you said is that you can one, once.

If they’re ready, your client is ready to begin doing things with ai, you can create a roadmap for them and ease them into it. It’s from [00:17:00] what I’m hearing from the MSPs who are having success already in AI strategy for their clients, it’s a great idea to find one, one need, one opportunity, one broken workflow, one pain point within the business, fix it with ai and create an appetite for more.

And, build up a comfort level both on the end user side and your side that this is gonna work.

Erick: Yeah, and I think the, the easy toe in the pool, if you will, for a lot of these customers is copilot Microsoft copilot, right? But with that, you have to have the same amount of governance.

You have to have identity and access management, so you know which folks in the company have elevated privileges to do things and to access different data, like you said, find out where all the data is and prepare it properly. But also you have to determine do we need to create our own private LLM and bring that in house so it isn’t public, or, what security control.

So you’ve gotta really measure the the risk profile. Now nobody wants any of their data out in the open, but you do have to give [00:18:00] folks access to certain, abilities to manage, the agents and things like that. Maybe if you’re not orchestrating them and managing them yourself. But again, there’s gotta be this assessment that you can have a very business discussion, a businesslike discussion with a client to say, okay, here are all the risks.

Here are all the benefits, so let’s prioritize how we move forward together. And again, just deploying Microsoft copilot as a starting point for a few folks helping and then educating and training them and then deploying it further into the organization is a great way to, give a client what they’re asking for in a way that’s easier for those MSPs to manage because they’re already managing their Microsoft on id instances and email and all these other things.

Rich: Complex topic. I’ve got another complex topic for you though, Eric, and that would be cyber insurance. It just so happens that here at the GTIA Channel Con conference we crossed paths with not one, but two different [00:19:00] companies that are deeply immersed in the world of cyber insurance.

One is a company called Yukon. You might know them better under their former brand fifth Wall. They have not just rebranded, but really rethought what they’re delivering to the marketplace. Another is a younger, newer entrant into the MSP scene called Spectra. So we have got a spotlight interview.

Twofer for you this week. On this channel con special episode, we’re gonna do two interview interviews for you back to back, both about cyber insurance from two different companies coming at this issue and the concerns that MSPs have and the challenges they run into, and the opportunities cyber insurance presents for them from two very different angles.

So we’re gonna take a quick break. When we come back, we’ll be joined by will Brooks from Yukon. That’ll be the first of our two interviews. And then we’ll be joined by Eric Altara from Spectra. A lot of good thoughts from thought leaders and people who really understand cyber insurance coming your way after the break.[00:20:00]

All right, welcome back to part two of this episode of the MSP Chat podcast, our first of our two spotlight interview segment. It is a very interesting time in the cyber insurance market right now. There are all sorts of new players and opportunities for MSPs around cyber insurance. And so we are pleased to be joined by somebody who can speak to us a little bit about what’s going on in the market and how it’s changing.

Right now. He’s Will Brooks, he’s the channel chief at Yukon. If you have not heard of Yukon yet, there’s a good reason for that. We’ll get into that over the course of this interview, but first will welcome to the show.

Will: Yeah, thanks for having me on here. Pretty

Rich: excited. I do wanna talk more about Yukon as we move along.

But first for folks in the audience who are new to you. Tell ’em a little

Will: bit about yourself, about myself. So I fell into the cyber insurance and cybersecurity world by accident and I’ve always been a self-proclaimed tech junkie, cybersecurity junkie. But it was also a personal level.

[00:21:00] And I was just looking for work. And there was a company that did cyber insurance specifically. Through traditional insurance agency networks and whatnot. And I came I just was looking for work and they hired me on. And in that year they started building they saw the writing on the wall on how MSPs were gonna start getting inundated with a lot of stuff.

And they started going to MSP conferences. And I was looking at that and it’s this looks super fun. Mainly because it’s my kind of people. So I am, my, my histories is in, in things like ministry and teaching, and I was an algebra teacher, everything all over the place. It fell into this world and have loved every second of it.

Mainly because it, I am a very personable person. I love community and I feel like the community in the MSP space is amazing. So it’s been a lot of fun engaging people and finding my way into all these new relationships and whatnot. But yeah, when it comes to my professional walk this is not a world I thought I’d see myself in.

But it’s one, I’m. Happy to have fallen into, because it really is something [00:22:00] that I don’t think is going away. And it’s one that excites me every time I come to a conference like this to see the future of where this industry’s headed, because people recognize that it’s gonna blow up.

Rich: Now you’ve actually been in the world of cyber insurance longer than you’ve been in the world of managed services in a sense. So you have a longer term perspective on that industry than a lot of people. For years when the topic of cyber insurance has come up, that certain other topics have come along with it, that the price of cyber insurance the difficulty of getting it, the difficulties around getting claims paid. Where are we today in terms of those kinds of issues versus where we were maybe two years ago? Is any of that getting better, worse, different?

Will: Yes and no. So we’re in, it’s it’s almost like we’re in a similar place, but.

In a different aisle now, if that makes sense. Quick history lesson. Back in, in 20 17, 20 18, cyber insurance was super cheap. It was like a thousand dollars. No security controls were necessary. They were just giving it out like hotcakes, [00:23:00] and it was a really dumb idea, but they didn’t know at the time.

Then when the pandemic happened and all the companies went remote, and all of ’em started seeing this ransomware uprise or uptick they started getting hit really hard and carriers just lost tons of money. And so the drama around cyber insurance actually really started around 2020 when carriers started to look into these things called security controls and started building their underwriting guidelines around those.

And what actually ended up happening was carriers got a lot stricter on what they required, and they started jacking rates, right? So that was the world we lived in. So you fast forward to 20 23, 20 24. A lot of MSPs are asking the question. Hey, what security controls can I use to bring down my client’s rates on their cyber insurance?

’cause we’re thinking of insurance like we do the auto industry, right? Or the homeowner industry where it’s if I have an alarm system or if I have daytime running lights on my car, I can save money on my policy. And carriers are like, we’re not, we’re still building our tables out. We don’t know if any of this stuff’s actually any good [00:24:00] from a long-term.

We know from a cybersecurity industry, but from a long-term actuarial data, building your tables around historic losses and like in carriers like to do, they don’t actually know if this stuff’s like good or not in narrow eyes yet. So each one is acting independently. There are no like unified discounts now, a little bit.

Some carriers are starting to get into things like. MDR for example, if they see MDR, they’re like, okay, we’ll discount your policy, but it has to be a very specific MDR product and you have to use us as your carrier. And so you create these little pockets of discounts, but there’s no unanimous ones across the board.

So what, why I say we’re in a different aisle now is you have people who have started to deviate from the norm. So you have these carriers and then you have these, I’ll call ’em mini carriers who say I can do this better, right? So I’m gonna create a product that can discount based on security posture and discount on controls.

But all that really does is create one potential option for a small subset of [00:25:00] businesses that might use that mini carrier that not many people know about. So it, it doesn’t change what what you’re asking. It doesn’t change the industry, it just provides an avenue for some people to get the rates they’re looking for.

Some of ’em work out, some of them don’t. So it’s a weird, it’s a weird world. In the current stage that we’re living in. And I know we’re gonna get to Yukon. I’m gonna talk a little bit about that in a little bit. But yeah, I would say the current state of things is a little shifted. The industry hasn’t transformed yet.

It’s still dealing with a lot of the same problems. It has been.

Erick: Yeah. We’ve seen the cyber insurance come into the Ms. P channel. We see MSPs trying to figure out how to monetize that opportunity. Some MSPs will. Create, we’ll take a look at a customer’s cyber insurance policy, and then they may build a project around, okay, you’re not doing this, and this to align with the minimum requirement for your policy in case something happens.

We wanna make sure that, claims don’t get kicked back or approved. So look, maybe create a project [00:26:00] around it to bring those services in. They may create an MRR opportunity by ensuring that there’s compliance or maintaining that, that demonstr the ability to demonstrate compliance against those.

How do you folks at UConn advise MSPs to integrate the cyber insurance conversation into the mix with their clients and how to approach that from a provider perspective?

Will: Yeah, so that actually aligns with what you were asking before is you do have a lot of pain points around cyber insurance still, and a lot of clients really get frustrated about it because what you run into are these, every MSP you talk to today, they know it.

You run into these 1415 page cyber insurance questionnaires that just are laundry list of controls. And at the same time, the carriers are asking them in a way that’s black and white, where any MSP you talk to, they’re like I have to qualify all of these ’cause they’re not black and white answers.

And [00:27:00] so what you run into is a lot of confusion for clients. So MSPs who can establish themselves as someone who is aware of what cyber insurance requires on a, even on a base level. ’cause like I said before, there are some difference differences across carriers, but you do have a standard set of security that the law of large numbers have shown Hey.

At least these things are a baseline when it comes to good security services. So MSP so can establish themselves that way and say, Hey, baseline stack, every single one of my clients needs to have these things, and here’s why. Because it’s gonna help you with your cyber insurance. It does create a sales opportunity.

It does create potential to keep that monthly recurring revenue up. It also down the road, one, one of the things we really help with is advising on the security controls that are coming. It’s not just what is now, but it’s also giving the MSPs an opportunity to have conversations about what’s coming the next year, the next two years, the next three years.

Because it’s also, good practice as an Ms. P, right? Is. Prepare your clients and prompt them on the realities that [00:28:00] cybersecurity is a journey. It’s not just this one thing that one day you’re suddenly secure and you’re good to go. It’s like you’re gonna need to keep improving because threats are gonna keep improving.

They’re gonna get better and better at attacking you, so you gotta get better at defending yourself, and here’s how. And so as carrier requirements continue to evolve, it allows them to have that continual conversation of, Hey, we need to keep upgrading your security. And that’s where things sit and have sat for the MSPs who have really taken it upon themselves to, to use that cyber insurance to their advantage.

And that’s kinda where we start the conversation. Okay, you do have the opportunity to increase your security. You do have the ability to make sure your clients are insurance ready. But then it comes, it inevitably goes back to what we brought up before where it’s what are these controls are gonna actually save them on premium?

What are these controls are gonna are affecting eligibility versus giving them discounts versus whatever it is. That’s where when you have those conversations on advising MSPs, use the cyber insurance as a leverage tool, but don’t solicit it yourself. ‘Cause you’re [00:29:00] not most of them aren’t licensed.

I’ve met two who are licensed in insurance and that’s always a fun conversation ’cause it does change the way they can have. But most of them, it’s hey, know the base requirements. Get yourself to a place where you’re able to advise your clients on the security they need to be a good risk. But then, pass it back to the agent to do the insurance component.

Create that networking opportunity between you and your local agent so that you guys can make each other’s job more efficient. And basically lower your sales cycle. Make it faster. Make your close rates faster. ’cause you’re not sitting there just giving what could look like ambiguous security control requirements.

You’re tying it to something tangible that the clients can understand.

Erick: And I love what you said that resonates with me. Is that could, you’re both now working on the client’s behalf. On the customer’s behalf together. Yeah. Yeah.

Rich: So another thing that I’ve noticed I mean I personally have noticed it over the course of the last year or so, but I think it, it goes back a little bit further than that is some of the [00:30:00] carriers are starting to do what MSPs traditionally they’re starting to work directly with the insured parties out there.

How much of that are you seeing? What are the longer term

Will: implications for usps? I think it’s reactive. It’s reactive because, again, they’re building their actuary tables where they say, Hey, something like an MDR tool has been really efficient in stopping attacks in their tracks. And it carriers wanna hold onto as much money as possible.

They don’t, they, they don’t want to deny claims as much as people might think they do. They don’t wanna deny claims, but they also don’t wanna have to pay out as much for a claim. So if they can see tools like MDR being equipped where they say, Hey, this is gonna shut down the attackers. Attack vector entry point into the system, right?

It’s gonna shut ’em down. It’s gonna kick ’em out so that they can’t do as much damage as they would’ve been able to do otherwise, then we won’t have to pay as much on the claim. That’s their kind of thought process. So they say, okay, we could just start offering our own version of that tool.

’cause to us, [00:31:00] that tool helps keep our claim payouts down. So I think it’s a reactive thing. I do not think it’s, personally, I don’t think it’s the best decision for a client to go with a carrier provided security tool. And the reason is at UConn we do really believe in client autonomy and the ability to make decisions and choose what is best for you.

When you lock yourself into a carrier specific tool, you’re kinda locking yourself into that carrier. What happens when that carrier in two years changes their appetite and drops you as a client? ’cause they say we’re not taking on a risk that, let’s say it’s a school. Say we’re not taking on schools anymore.

We’ve decided not to do schools anymore. Now you’ve lost your insurance policy and your E-D-R-M-D-R tools tied to the carrier who dropped you. So now you have to go find a new MDR tool too. So it creates a lot of chaos. Whereas if you have an MSP who says, I am consistently working on your behalf, I’m working to make sure that your security is aligned with insurance standards, and then you now have the freedom to go out there and remarket your policy every year so [00:32:00] you’re not bound to a single carrier.

What happens often, and we get enticed by discounts, right? We get enticed by the idea like, oh, save 10% on your policy. So if Carrier A says, Hey, you’re gonna save 10% because you’re using our MDR tool, and carrier B says we don’t offer discounts, but their policy is just generally cheaper than carrier A, even with the 10% discount.

The marketing the enticing part of us is oh, I’m gonna go with carrier A ’cause I’m getting a 10% discount. They never go to carrier B and see that carrier B’S pricing is actually better even without the discount. So when you have autonomy, when you say, I have all the controls that are gonna affect pricing and all that good stuff, but I now also have the freedom to go to whatever carrier I want, that’s where you see, I think, the most success for our clients.

And that’s something we really work to do at UConn. ’cause we have access to over 50 carriers. So our whole approach is to say, we wanna remarket you every year. We wanna make sure you are getting the best option. And the only way to do that is if you have an MSP handling in the driver’s seat for your cybersecurity controls.

Not a carrier, a singular carrier.

Erick: So let’s talk about Yukon [00:33:00] for a bit. It’s a new name, a new strategy. Tell us a little bit about the origins as Fifth Wall and what’s behind the change in brand.

Will: Yeah, that’s a great question. So Fifth Wall Solutions. Was the brainchild of some of the founders back in, in 20 15, 20 16, because one of the founders actually underwent a cyber attack at his own company and he had cyber insurance at the time, but it paid garbage.

And he’s this is messed up. This was so complicated. And this is back before cyber insurance was difficult. And he said, there’s something wrong here. Why is this so challenging and so annoying to new navigate and maneuver? There’s gotta be an easier way. So he went and built a company around it.

He said, I’m gonna, I’m gonna fix this problem myself. So over the course of, ’cause the rebrand happened this year, 2025, so over the course of nine or 10 years, we functioned as a, what’s called a cyber insurance wholesaler, kinda like a distributor. And we’re still very much that. But the way that the, that works is, [00:34:00] like I said, we have access to over 50 carriers and we would contract with agents.

To help them sell cyber insurance to their clients. And what happened I brought up our whole MSP channel. We did a whole lot. We deviated and put our hands in a lot of different PO pots and started doing things. And what we started to see is that we were working with different different channels, different avenues that were the pieces of a much greater whole.

So you have agents who are capable of selling cyber insurance. You have MSPs who are capable of putting security controls in place to make sure clients are cyber ready. Guess who isn’t talking to each other? The MSPs and the agents. And so the agent became the middleman for the insurance carrier and the MSP in a way that you’re playing a game of telephone.

Every time an insurance application had to be filled out, the carrier would say, Hey, we wanna see these security controls. And the agent who doesn’t know what any of those mean, have to pass those requirements to a client who definitely doesn’t know what any of those mean. And then the clients throw their MSP and say [00:35:00] I think I need this thing.

And then two days before renewal, they’re told, oh, you need MDR and all your endpoints. And now it’s emergency projects. For the MSP, they have to charge more because of the timeline that they have to get this whole thing in installed and put in place, and just created a lot of chaos. So what we did is we just, we designed a product that we’re calling Yukon, and the rebrand came with that in the sense of saying, rather than being Fifth Wall solutions and saying we have our own insurance product and we have this technology that people can utilize called Yukon, but an insurance product that they can use, and all this kind of stuff.

We’re like, let’s just keep it all under one banner. Let’s name, let’s make sure our company is aligned with the tech that we’re gonna be providing to msp. So we created a free tool. It doesn’t cost anything for the MSP to use. And what it does is, and it what’s coming, is that you’re gonna have. MSPs and you’re gonna have agents who have the ability to access this tool too, and it’s creating the ecosystem that didn’t exist.

All the players in the game of cyber risk now have an inward look on that risk in the, in seeing what they need to see. [00:36:00] So MSPs are gonna be able to see what their clients are capable of losing in the event of an incident based on their current security posture. And when I say capable of losing, we’re not talking about things like arbitrary risk scores where it’s like, ah, you’re an 86% in your security score.

What the heck does that mean? What we’re saying is, Hey, based on your revenue, based on your industry historically due to claims losses, your a business of your security would lose like two and a half million dollars. You know what improve your security? That’s gonna come down to 1 million. And now you can go out and buy a cheaper policy because you don’t need as much coverage.

So it changes the game. Everyone wants discounts. You’re not gonna get discounts across the board, but what you can do is reduce the risk so the client doesn’t need to buy as much insurance. Then the agent gets connected who’s also in the platform and says, all right, great. The NSP has brought that risk down.

Now I can get the insurance in place for my client. And we become that ecosystem in that place. So you have MSPs and agents who are part of networking groups together. They get together for breakfast at a diner once a month, and they pass referrals [00:37:00] back and forth. Now we actually created an avenue for them, not just to pass referrals, but get business done quickly and make that referral mean something more than just a potential business opportunity.

And that’s what our vision of Yukon has been. And then the third piece of that is the carrier can now look in and see the security posture of the client that’s applying for coverage. So now it’s not just a I think this answer means this, and I’m gonna check yes on this box in the application. It’s real time underwriting.

It’s something the carrier can look at, offer quotes through the platform so the clients aren’t spending hours filling out apps for 20 different carriers. The carriers just look at the one submission. They say, great, we’re gonna offer coverage based on what we see. So it’s really creating an opportunity for all the players to see the risk and close business faster across the board.

Rich: I should say quickly for folks in the audience here, we keep saying Yukon. That is UKON. Yes. We will link to to information about Yukon in the show notes for this episode here in the launch announcement, which is [00:38:00] quite recent. I. Think beginning of June. Yeah. So this is a very young venture for you folks.

In the launch announcement, you were talking about this role that you envisioned for the MSP who interacts with their client the way you just described being the cyber risk advisor. And the idea as I understand it is you are looking for a way for the AM SP to incorporate cyber insurance and cyber insurance guidance into their security offering safely, because the issue for years has always been, there are all these regulations in place.

Do not talk insurance with your clients a liability scare. Yeah. Yeah. Talk a little bit about what you know, what cyber risk advisor means for you folks and the degree to which you are trying to find a way for MSPs to have a productive insurance conversation with their clients safely.

Will: It’s a great question. Answer this as simply as possible to us, right? Cybersecurity and being an MSP in today’s world is a lot more than [00:39:00] just equipping a client with security controls, right? There, there is a, when you look at things like us, the cm the nist framework and how there’s all the protective stuff, but there’s also the response and recovery components of those things.

MSPs have their hands in that now too. It’s not just, oh I set you up with your security, you’re good to go. And if an incident happens hire an ir, a company like MSPs are involved in all of it. And to be a true cyber risk advisor is to say from start to finish, from getting you equipped properly to both be protected from a cyber attack, but also withstand the blast of one.

That’s the key kind of component for me of a cyber risk advisor, is that someone who’s saying, let’s analyze the full scope of your risk from start to finish. So let’s look at you as a company. Let’s determine what security you need in order to protect you from a cyber attack happening. But Mr. And Mrs.

Klein, I cannot guarantee that no cyber attack will ever happen. So the other part of what I’m gonna do here is set you up to withstand the blast of one ’cause that’s just as important for an MSP. If their client can’t withstand the blast of a client or of a of an attack, two [00:40:00] things are gonna happen.

They either go outta business or they’re suing the MSP or both, right? And the MSSP doesn’t want either of those things. ’cause either you lose a client. Oh, in both cases you lose a client. In one case, you lose a client and a ton of money, even if you can defend against the claim, right? The whole component of a cyber risk advisor is say, start to finish.

We’re analyzing your risk. We’re making sure you’re protected. We’re making sure you can recover. Now, I, let’s say I’m an MSP, I can’t advise you on insurance specifically ’cause I’m not licensed in that. But I want to get you moving in such a way that you’re gonna be able to visualize your risk from start to finish, right?

So if you had an attack today, you’d lose you. On average a company like yours would lose $1.3 million. I’ve got an agent in the wings here who can hook you up with a policy that’s gonna cover you for that so that you don’t have to go out and buy a $3 million policy. ’cause I’ve helped to bring your security controls down.

I can’t tell you how much insurance you should carry, but this agent can help guide you on what kind of policy you should have. So the MSP, while they can’t necessarily sell the insurance. They’re able to [00:41:00] pull the strings to make sure their clients are protected. And this is so important because going back to what I was saying is if a client has a cyber attack and they can’t withstand the blast while they’re suing the MSS P, it’s under it.

It basically, every MSSP we talk to today we’re advising you should be requiring cyber insurance in your MSAs. It is too necessary in today’s cyber environment to not require your clients to carry it. So then say, okay, I require my clients to carry it. Okay, to be the cyber risk advisor to take it, the advisor is to take it to the next stage and say, I’m actually going to make sure my clients actually have it, rather than just telling me they do.

And if they don’t, I need to provide an avenue for them to get it. And so that’s where Yukon kind of is the brainchild. We want the MSP to be in the driver’s seat of all cyber risk for their client. And then when it gets to that final insurance component. There’s basically an easy button for them to pass it over to the referral agent they’re connected to, to make sure that piece gets taken care of [00:42:00] too.

And so they’re doing everything they can to manage the full scope of the risk.

Erick: Shortly after you announced the Yukon name you also announced a bunch of strategic partnerships with Cork, credit, pulse, black Point Cyber and Seed Pod. So what do these companies do and how does teaming up with them help Yukon’s partners?

Will: Sure. So it’s funny for two of, for four of those, because Cork, when they first came on the scene. Their whole thing is the cyber warranty. And they actually were seen as a, not only a competitor, but a pretty contentious competitor for us at the time because there was a lot of confusion for MSPs around warranties and insurance.

And if my client has a warranty, do they need insurance? And our MSPs selling warranties, is it too close to insur? Like it got really confusing and it became an issue. The thing with Cork, their technology is awesome. They have this whole internal scan that’s based on [00:43:00] APIs, so there’s no agent installed, there’s none of that stuff.

And we said that’s really good technology. So we reached out to Cork and can we incorporate your tech into our platform? And that worked out really well because what I said before about carriers being able to be certain on the security posture of a client’s. Security posture being certain on that.

They need something to tell them that’s the case. So Cork’s tool made that very easy for us to let our carriers know where a client stands in terms of their security. So that became a really good entryway to fuse a partnership that was seen as contentious for a while.

Erick: So it scans the clients’ network and devices, and then comes back and says it’s within compliance of the policy.

Explain that

Will: sort of. So cork’s tool, I, and I don’t, I’m not the developer, so I don’t know everything, but what I can tell you is Cork has the ability to connect all of your security partners who offer APIs so that it’s capable of reading out, doing a readout of where their current security posture stands.

So do you have MDR [00:44:00] enabled? Do you have MFA on these things? And if it’s on, it’s a yes. And if it’s a, if it’s off, it’s a no. That’s all carriers really need to see. And that’s where it’s not an internal scan, like it’s running this massive scan. It’s literally saying, Hey, here are the tools carriers are interested in.

And Cork’s tool is allowing us to tell the carriers, look, they’re actually turned on and they’re staying turned on. So there’s it’s much different from you filling out a checkbox and then six months later you turn off that tool. But you said you had it six months ago and nobody knows.

No one’s the wiser, like I envision a day where you have this continuous underwriting. So if a carrier sees you turned off EDR, but you said you have it, they send you a cancellation notice and they say We’re canceling your policy in a week if you don’t turn it back on or something. Like it’s that type of thing where if you are using cyber insurance, you’re entering into a contract with that carrier and if you don’t uphold your end of the contract, why should they?

So it’s that kind of thing. But it’s funny ’cause Seed Pod is another good example, right? Seed Pod was for all intents and purposes a com, a micro competitor of ours, ’cause they’re not a wholesaler, we were. So it was a very different type of [00:45:00] competition, but they were still selling cyber insurance and they were working with MSPs to do it.

But they have their own product, right? So we said, why don’t you just integrate into our platform and then you can literally sell your product through our platform ’cause it’s an insurance product. And that’s the whole idea is with Yukon, we’re trying to disrupt the industry. We’re trying to transform it into something.

When you just make little adjustments, you say carriers aren’t doing it right, so I’m gonna do it a different way. Again, like I said at the beginning, all that really does is create a small contingency of people who are using your product. But if you can create an ecosystem where everybody is playing together, all of a sudden every carrier needs to adapt and change.

And that’s what changes the industry. So that’s what we’re trying to do with Yukon. So anyone who used to be a perceived competitor, it’s no, just be part of what we’re doing.

Erick: So Seed Pod then becomes another carrier for you to offer to your partners?

Will: Yeah.

Erick: And how about black Point and Credit Pulse?

Will: So Black Point is a good example of something that. We Black Point offering an MDR product, [00:46:00] right? Is our first way of saying, look, this whole thing where carriers can see your your current security posture, if you’re a Black Point user, you’re gonna be able to integrate into that platform. So it’s that on that side, it’s just that initial push to say, look, carrier or vendors who offer these security services, they’re gonna be in here.

The ones the ones you use, you’re gonna be able to integrate with your, bring your APIs in, you’re gonna be able to do things in order to make sure and ensure with an e that your client’s security posture is where it needs to be a good risk to the insurance carriers. And then with Credit Pulse, that’s our whole that, that piece I said at the beginning where we’re pulling this risk data and we’re saying, Hey, in the event of an incident, we want to be able to tell your client how much they’re at risk of ruing.

And we do that in, we do that by pulling historic loss data, but you can’t really pull historic loss data unless you have things like carry a client’s. Industry and a client’s revenue information and things like that. And that’s where the credit pulse partnership is really helpful for us because even though it’s [00:47:00] guesstimated in terms of their revenue, it at least gives that launching point for an MSP to sit down with what we call the cyber risk report and show that data to their clients.

Now the clients have the opportunity to go in and say, oh, actually my revenue’s a little different. So they can type it in and it’ll adjust, but at least gives that launching point for the MSP to start that sales conversation to improve security. So were you were utilizing all these partnerships to really drive the efficiency of the Yukon ecosystem

Rich: as it happens?

I interviewed the CEO of Co last week. I just wrote something from my blog channel Holic about this and they’re integrating now with 93 different security systems. I mean that this is from their perspective, a differentiators. They really can see whatever combination of systems you’ve got out there on the endpoints.

And the interesting thing for me about the. Cork story that Dan Candy, their CEO told me when I covered Cork at launch, when the company just first opened it, its doors, it was a warranty company that had this kind of interesting tool for monitoring [00:48:00] compliance. And then they discovered that actually that tool was the core, that was where the value was.

And today that, that’s the star of the show, is that tool. And then they’ve also got warranties in case everything goes wrong for you. In my mind that’s a good example of something that you guys have in the launch announcement for Yukon. You described Yukon as a technology first company.

You’ve spoken a little bit, al already about that, but talk a little bit more about the scope of the technology that you’re building and how being technology first positions you for the

Will: BMSP space. Yeah, so start with the fact that the insurance industry historically is anything but technology first.

And that’s part of the issue is you had. Cyber insurance, which I brought up before, is an extremely necessary thing in today’s cybersecurity landscape. Still being done on like pen and paper applications I guess check boxes on a computer, but pen and paper applications for all intents and purposes.

And that is the blocker. That’s the blocker that was preventing this industry [00:49:00] from shooting forward is if you’re still treating everything like you did insurance two centuries, three centuries ago, the way they’re still doing it with auto and home and all that kind of stuff. It’s what are we doing and why is cyber insurance less technological than auto insurance?

Like auto insurance. You can go online and bind coverage like that, but cyber insurance, which is literally rooted in technology, at least conceptually. Is less technological than all the other lines of insurance. That’s a problem. So when we say technology first, that was the drive is say, we need to take this industry that is is archaic, and turn it into something that’s in the, or in the 21st century now, 21st century, 22nd century insurance.

We gotta transform this into something that can be utilized by the people who are offering the technology. So you have cybersecurity professionals who have the capability to offer security solutions to their clients. You have vendors in the cybersecurity space who are saying, Hey, I want to [00:50:00] integrate my security solutions into that platform to make that real time underwriting more efficient and the data that’s gonna allow us to connect.

And this is, this really excites me about the platform. I have a lot of vendors reach out to me and say, Hey, how do I get put on carrier panels so that they’ll approve my product and actually offer, better rates or whatever based on my product. And I. If you want to go the old school route, it’s probably gonna take you a while, but what we’re gonna be able to do is show over that you brought up Black Point, right?

So let’s say we have hundreds of MSPs utilizing Black Point, thousands of MSPs utilizing Black Point and a carrier who didn’t have Black Point on their radar. Looks and sees that no clients from that MS from those MSPs using Black Points, have had any sort of losses that have surpassed X amount of dollars.

All of a sudden. Now, to them, black Point is a big deal, all Black Point’s awesome. So the idea of the technology first concept is we are able to collect data. We are able to pass that data on to who [00:51:00] needs to see it. We’re able to integrate all those technology partners, even carriers themselves are integrating their quoting services into the platform.

So everything is operating efficiently because technology is meant to make our lives more efficient. It could be bad, there’s bad tech out there or addictive tech out there that’s not good for our brains. But when technology is used as a tool like it should be, it should make everything more efficient and easier.

So that’s our whole goal with insurance or with Yukon in the cyber insurance and the cybersecurity world. If you can integrate all of those different pieces together, now everybody’s operating at efficiency. As opposed to taking days or weeks to even get a quote turned around for a client. And that’s our whole vision with this platform.

Erick: Will, I think we just witnessed your your passion and excitement crank up to 11 just now? Yes. So from where you sit, take a look six, 12 months down the road and share with us what you think. Any [00:52:00] changes, if any, you predict to be happening in the cyber insurance market.

Will: Yeah. So six months down the road, I’ll start there.

The component of Yukon we’re building right now is the ability for agents to get in there and assess the risk as well. And when that gets unlocked, that’s gonna transform this whole industry because as I mentioned before, now MSPs can secure the risk and agents will be able to take that certainty of security, which they did not have before.

And simply. Fill out the contact information for the client and turn around and get the quotes that they need in order to push that coverage forward. And when you can start turning, there are some crazy statistics out there on cyber insurance on the number of companies that are either not insured or underinsured.

It’s some massive percentage. And I’m not gonna pretend I know what that number is. But it’s a lot. And what our hope is and what Yukon’s kind of mission statement is that we believe every business has the [00:53:00] right to survive a cyber attack. The only way you’re gonna do that is if you have cyber insurance that’s gonna accurately cover your potential loss.

And the only way the companies are going to even give cyber insurance the time of day is if all the players are acting efficiently. So if the MSP can secure the risk, the agent can get in there and put the coverage in place within. An hour or shorter, they just click the buttons and here’s your, alright, go ahead.

Pay your invoice. You’re good to go. Now all of a sudden you’ve transformed the industry and you’ve disrupted everything. ’cause you’re not spending days going back and forth playing telephone. And that’s my hope for the next six to 12 months is to see that start to become a reality where it doesn’t, it’s not a painful process.

It doesn’t feel like pulling teeth just to get a cyber policy in place. It just becomes an additional component of onboarding a client onto an MSPs platform is, Hey, you gotta get that science, cyber insurance in place. Here’s the way to do that. Here’s your pathway. Here’s the agent who can walk you through it.

Bam. Go do it. And that just becomes a natural progression for every client [00:54:00] who’s getting cybersecurity put in place. That insurance just is wrapped up in that.

Rich: It, it’s interesting listening to you talk there. ’cause you’ve used the term marketplace a few times in this conversation. Yukon u talked about creating a cyber insurance marketplace and its launch materials and really what you are doing in the cyber insurance realm is, reminds me just a ton of what PAX eight is doing for software MSP.

It’s like they’re in the middle, they’re connecting the end users and the MSPs and the vendors and enabling all those people to get stuff done more easily. That’s what you’re trying to set up is a central point like a hub that’s going to serve the needs of the end users and the MSPs and the agents and the carriers and just facilitate a lot of business.

So it’s, I guess it’s another win for the marketplace concept at this moment in in channel history. Super interesting conversation. Will we thank you for taking time out here at the Channel Co con show to, to speak with us. For folks in our audience who wanna get in touch with you, [00:55:00] learn about more learn more about you, get in touch or learn more about Yukon, where should they

Will: go?

I go to yukon.com. Again, it’s uk o n.com. You can follow me on LinkedIn. I’ll just send you it, you put in the show notes. It’s too complicated to try and share. And then yeah, go to uconn.com and then [email protected]. If they just wanna shoot me an email, we can connect that way too. But yeah, we want them to, we want, we wanna help people engage ’cause nobody’s, nobody was talking and that was the biggest problem, is all the people who are necessary in cyber insurance weren’t communicating with each other.

And that’s what we’re trying to fix.

Erick: Thanks for joining us. Yeah, thank you.

Rich: Thanks. Folks, we’re gonna take a quick break. When we come back, we’re gonna be joined by Eric Altura of Spectra another company with a different kind of approach to the whole cyber insurance story. Stick around.

We’re gonna be right back

and welcome back to the second of our two spotlight interviews for this episode of the MSP Chat podcast, where we are [00:56:00] pleased to be joined by the Chief Operating Officer of Spectra. His name is Eric Timore. Eric, welcome to the show. Thanks, rich Eric. Appreciate you having me. Eric two, as you’ll see in a moment, is deeply embedded in the world of cyber insurance.

Spectra has a very interesting take on pain points that MSPs are encountering right now and how best to address those. Before we get into any of that, before we get into the spectra or the cyber insurance, just tell folks a little bit about yourself and your role at

Erick: Spectra. Sure.

Yeah. I guess I’ll start with before joining Spectra. I actually don’t come from the insurance industry. I used to be at an MSP. So I led the mayor security practice at a mid-sized MSP. And prior to that spent most of my career working in government about half that time in the military, and and then the other half in a couple different civilian roles.

So I really come from the cybersecurity side of the house rather than that kind of pure insurance background. But what really, what got me excited about Spectra was the idea that [00:57:00] there was actually a segment of the insurance market that was really interested in working together with MSPs to solve problems for their mutual customers instead of just, being the enemy.

Right? Which is, I think what, a lot of people perceive the dynamic.

Rich: And that’s a great segue to where I wanted to kick things off is, we wanna take advantage of the fact that we have access to somebody who is immersed in the world of cyber insurance right now. From the perspective probably of a lot of MSPs out there that a state of play in the industry is relatively similar to what it has been in terms of pricing and access to coverage and getting claims paid and so on.

But as somebody who is very familiar with the world of managed services, but also in touch with the insurers and what they are doing right now how do you see the state of play in cyber insurance right now? Where does it stand? How has it maybe evolved over the course of the last couple years?

Erick: Yeah, so I think there’s [00:58:00] two kind of really interesting trends for, for MSPs in particular that we’re saying. The first one is. This convergence of insurance and security where, customers and who are ultimately insurance buyers are looking at cyber risk management as a whole, right?

And so that risk management strategy includes protecting the business, right? Using those defensive controls. It includes mitigating, risks or damage from events when they hurt. But then finally there’s an insurance layer to that, right? And I think insurance companies are starting to wake up to the fact that, rather than just sitting here at the end of the chain, they actually have an opportunity to participate more forward in that left of bang, if you will, right?

With their customs. And you’re seeing a trend across the industry where insurance companies are either teaming up with an MSP purchasing their own MSP or building it in house to then deliver managed services themselves to the policy holders [00:59:00] are the premise that. Protecting those customers then makes them much better risk to take on from the insurance principles.

So that’s been a really interesting trend to see. The other one and I think is related to that is then the insurance buyer, right? That kind of smaller mid-market customer, especially if they operate in a regulated environment, seem to ha be much more demanding of both their insurance provider and their technology provider in terms of, Hey, I need you to help me come solve a business problem, right?

I need you to deliver a comprehensive solution. I don’t just want to buy my single point kind of commoditized solution from each of you, right? I want you to solve the whole problem for me. And I know that’s something that you guys talked a lot about, about, this kind of evolution of the role of the MSP and to becoming that strategic partner.

And I think that. Aligns very closely with what we’re seeing from the insurance side, which is that those customers they want to see that [01:00:00] their IT investment, the security investment is also having results translating into results on the insurance buy-in, on the financial services side of the has, right?

So that’s really what I mean by the convergence of those two worlds. Eric, as a former Ms. P, you know that MSPs are always looking for ways to generate more revenue, whether it’s from a project based perspective, recurring revenue is king typically. So what we’re seeing today are MSPs leveraging a cyber insurance policy to generate project work to meet the requirements of the cyber insurance policy.

We see other MSPs building recurring revenue deliverables around achieving and maintaining compliance for their. Clients. Yep. How would you advise MSPs to leverage cyber insurance as a way to create more strategic value stickiness and grow their revenues? Yeah, that’s a great question. I’d say it’s not necessarily an easy answer, and [01:01:00] that’s the, sometimes I’d say the insurance market does not have a ton of logic behind it in terms of Right.

Do X and generate y outcome. But in general, I think the requirements that insurance companies and underwriters expect of the of the insurance applicant they’re constantly changing. There’s additional there’s more and more scrutiny year over year. Several years ago people talk about MFA it’s R right?

And then it was EDR, and then the insurance market realized, hey, if that solution isn’t being managed, then it’s not really worth as much as we thought it was. So now it’s managed EDR, and that translates into M-D-R-X-D-R. And now, reports from I think it was Chubb just published their annual claims report.

And they have a whole section talking about how zero trust is the future I really wanna push. And so I’d say for MSPs it’s the opportunity to go to their customers and say Hey look, it’s unrealistic to expect you to be the expert each of these technologies, and also keep your finger on the [01:02:00] pulse of what your insurance company’s demanding, right?

In the ideal world, no one wants to think about insurance. No one wants to talk to their insurance broker, right? They just want to know that there’s a product available to them. So that’s an opportunity for that M Ms. P to say, Hey, look, leave it to me to make sure that. As the market evolves, as the requirements evolve, we’ll make sure that your environment keeps pace with those requirements and solve that business problem for for the customer.

Rich: It feels a little bit to me, like we’re at a more mature phase of the cyber insurance story right now. There, there was the phase in cyber insurance history where the carriers all jumped in and figured this is gonna be a breeze and discovered that it wasn’t. And and, MSPs were really just figuring out cyber insurance for the first time.

At this point. The carriers better understand the threat landscape. They are as you said better understanding the role of the MSP in risk control. MSPs are a little bit more familiar with the. The [01:03:00] issues and pain points around cyber insurance. And so I’m encountering I’m coming across a number of different companies that are connected to the carriers on the one hand and the MSPs on the other, and they’re all in different ways.

Embracing this sort of cyber risk management, cyber risk insight kind of role that you were talking about before, based on different conceptions of the, of what the core pain points for an MSP are around cyber insurance right now. What is the spectra take on the real issues that MSPs are dealing with around cyber insurance now?

Erick: Yeah, so I’d say, first and foremost they’re it’s a minefield when it comes to liability challenges, right? I know, I’d say I’m guilty of it myself, back when I was at, when I was an MSP, which was that. Your client forwards you the questionnaire, they say, I don’t understand this.

Help me fill it out. And just that act alone can introduce a ton of challenges. Especially if and when something goes wrong. There’s also the [01:04:00] participating in the sale of insurance or even the end of that relationship can be challenging, especially if you’re not a licensed entity.

And the way we’ve set up Spectra and the platform is to create almost a buffer zone for MSPs where they can engage with their customers in these cyber risk management discussion. They can have trusted relationships with the insurance market, but there’s still a very clear separation between the entities that are participating in regulated activities.

And then the MSP and what the, so we try and take that kinda liability off of the, off the table. For them, I’d say. An another pain point that, they’re encountering, which, is, I kinda alluded to it earlier, which is that, as more insurance companies go to market with their own managed services offering, there is that risk of displacing the managed service provider or at least certain [01:05:00] elements, if not the entire relationship, right?

A broker may go to the CFO of the business and say, Hey, look, if you buy the MDR service from pick your insurance provider, I can get you a 20% discount on, your premium. And then that CFO signs off without ever even talking to whoever owns the relationship with the MSP. And now they just found out, hey, you gotta figure out a way to play nice with, this new provider who’s coming in, who’s gonna own that aspect.

Tremendously challenging and. Very difficult to implement, even from a practicality lever, right? In terms of who’s gonna be responsible, who’s actually, are you loyal to the customer? Are your allegiances to the insurance provider? Do you really trust your soc if they were, they’re part of the insurance company, right?

So it’s Messer, right? I don’t think that the market has really come up with a very clean way to address that issue. I would say our take on it is we try and keep everyone in their swim lanes, right? The the insurance carriers that we work with, we’re very clear with them at the outset before they onboard to our program, is [01:06:00] we are not gonna be reselling your managed services into the client base, right?

The MSP zones that own that relationship. They deliver the services, they protect the environment, and then you deliver the insurance products, right? And if we keep everyone in their lane, ultimately it’s a win-win for everyone. The insurance company, the only reason they’re delivering the services in the first place is because.

They aren’t confident in the risk. And so they want a better understanding. They want a deeper involvement, but they get that through a partnership with the MSP. And then the MSP still gets to protect that relationship with the customer in terms of being the trusted kind of frontline defense against these risks.

So Eric, what sets you apart in the industry? What is Spectra’s special sauce strategic take to address some of these issues and also help the MSPs be successful? How do you fit into that equation? So I’d say, I and foremost we are we’re channel exclusive, right? He, we can only succeed [01:07:00] if our partners are successful.

So we’re never gonna be going around the MSP to work with that end customer. We have to enable our partners to be successful with the program, and then that’s how we drive our success. I would say that first and foremost. Our position as that bridge between the insurance market and the channel is we’re vendor agnostic, right?

We’re technology agnostic. We’re not gonna tell MSPs how to run their business. We’re not gonna say you have to use these these technologies. They have to be designed this way. What we’re gonna do is say, Hey, look, we are interested in you delivering this outcome for your clients. Help me understand how you do that.

And every MSP’s gonna have their own secret sauce and how those come together. Everyone’s gonna have a slightly different tech stack. They’re gonna have, a couple of engineers who have been there for, a decade or two who like, they’ve pieced together that solution and we don’t want to go in and tell them how to run their business, right?

We wanna understand how they’re delivering that outcome. So we can translate that into usable data for the insurance underwriter to feel more confident about that risk and then deliver [01:08:00] that better product for the end customer. So allowing the MSPs to select their stack potentially could be different for different customers.

Then Spectra comes in. And then how do you help that MSP protect and secure and ensure that end customer through the carrier? Give us that, unpack how that relationship works and how you potentially can, in some cases even help the customer realize lower insurance premiums because they’re working with an MSP that you are supporter.

So essentially, what we do is we’ll work with the partner to effectively pre-qualify their solution for insurer. So then when they go to market with their customers, they can say, Hey, here’s our comprehensive service that includes our, full stack IT and security services, right?

And if you subscribe to that, [01:09:00] every time we deploy the solution into a new customer environment, it’s certified by a third party being spectra, right? So they, the customer gets that extra level of assurance that what they’re buying is actually valuable and being deployed in a way that, if that customer doesn’t have in-house IT expertise, they might not know whether their MSPs a jobber, right?

So we add that extra level layer of assurance, and we back that with a cyber warranty. So we say, Hey, look, if if you’re purchasing, if your MSP’s handling your identity and access management, they’re handling your entrance security, they’re managing your backups and your disaster recovery, right?

And you still get hit by ransomware you’re entitled to your money back because the solution did not perform as we certified it to. We deliver that cash back to the customer. And then finally the insurance program is designed to really reward those investments insecurity. So now the MSP can say, Hey, look, there’s a clear ROI to that end customer’s additional investment in security.

So maybe they haven’t purchased the full stack and it costs them [01:10:00] a couple hundred bucks extra a month to get the full stack offering in place, but they’re saving thousands, or in some instances, tens of thousands of dollars on the insurance renewal. So now you’re saving money in the long run and you have a better security posture, right?

So again, that’s, it’s that win-win for all parties.

Rich: To be clear, the savings come from you have relationships on the carrier side so that your certification that’s not only assurance to the end user that this is a a legitimate and complete that stack of security solutions.

But the carriers agree if Spectra certifies this MSP in their stack, we can feel assured confident about offering favorable rates.

Erick: Correct?

Rich: Correct.

Erick: So we have spectra was born out of that kind of insurance and reinsurance, DNA from, so our founder Eduard, right? He comes from the reinsurance world, 25 plus years of experience, that industry with all the relationships that come with that, right?

So we started at the end of the supply [01:11:00] chain and built that trust with these different insurance markets. Say, Hey, here’s what we’re doing. Here’s the level of quality that you can be confident in when we bring MSPs into the program. So now those carriers give us that recognition. And the same thing on the brokerage side of the house as well. And one thing I didn’t mention is we have broker partners today who have clients who want cyber insurance but can’t get it because maybe they had a claim in the past three years, maybe they operate in a high risk vertical, that the insurance market is a little bit, worried about.

Or maybe they’re just, they don’t have kind of fundamental security in place, right? Or they’re not working with an MSP, right? There’s tons of small businesses out there who, aren’t working with MSPs today. And so effectively what we’ve done is we’ve gone to those brokers and said, Hey, look, bring, feed those customers.

Here’s a list of certified MSPs that are, regionally aligned with those customers or who may have specializations in the verticals that those customers [01:12:00] falling. Bring that business to the MSP, let the MSP remediate that environment and then feed them back in the insurance chain. And the brokers they, A, they love it.

B, they don’t even ask for, they don’t ask for anything. They don’t ask for referral fees or anything like that because they know that once we make that client quote unquote insurable, they’re gonna benefit from their brokerage on the insurance premium that otherwise wouldn’t have existed. So we’ve built that ecosystem model where, it’s not just MSPs feeding their customers into the insurance market.

It’s actually the insurance market. Identifying challenging customers and feeding them to MSPs to help them make become better risks.

Rich: Yeah, as I mentioned before, there are a number of different companies with answers to this cyber risk management concept, a number of them are about peering into end points, end user environments, feeding real-time telemetry.

Compliance data to the insurance company, you guys have made a conscious decision not to do that, to, to come at [01:13:00] this from a different direction. Explain the thinking bind. Correct? Yeah.

Erick: Trying to operate off of analogies here, right? If you’re ensuring a kinda a large commercial real estate and, call it South Florida, right?

The insurance company, they may send inspectors to the building, right? They’re gonna check that the building materials are up to code. They’re gonna check that, the contractor doing the build that has all the right experience and qualifications, the quality of the windows, how high above sea level is that building, right?

All the data that they need to essentially feed that into their models. What they’re not gonna do is install security cameras inside the building and look over your shoulder 24 7, right? And there’s actually, there, there’s been a number of studies on the in the insurance market that they’ve demonstrated that there isn’t actually a meaningful difference on the performance side between clients who have that continuous monitoring set up and those who don’t.

The idea here is not to play big [01:14:00] brother against the MSPs and make them, feel like we’re trying to catch them doing something wrong. I think, I can make a, a compliance report, say whatever I want it to at the end of the day. You can configure those tools to generate the outcome you’re looking for.

That doesn’t necessarily mean you’re any more secure. So yeah we’ve deliberately tried to shy away from that. And also we, we don’t wanna be a, potential vector of an attack into one of our, or expose one of our clients to unnecessary risk because of something that could happen on our end.

So we’ve. Again, the number of reasons why we’ve gone away from that model and tried to just apply lessons learned that have been successful historically for decades and centuries, in some instances in the insurance market in the tangible worlds, and just apply that to the intangible world being cyber.

Eric, looking at cyber insurance as an MSP, can feel a little bit overwhelming, can feel complex, complicated. You’ve taken steps to ease this for the MSPs that you work with. But there [01:15:00] are some bigger pain points from an MSP’s perspective in helping clients qualify for insurance, filling out questionnaires.

It’s a lot of work that MSPs typically can’t bill for or don’t, or feel awkward billing for. So how do you help them through that process? Yeah, so we, the idea is, if we can front load a lot of that effort, then once the MSP is onboard to our program, we can kinda be the easy button for them and their clients.

I would say on your first point in terms of, as speaking with one of our partners who he actually has all of his clients’ insurance renewals, mapped up maps out on his calendar and just blocks time to help them with their questionnaires. And that’s non-billable. We’re just like, just spending time working with clients trying to help them through that process.

And so what we’ve done is we’ve said, Hey, look, if and we’ve gotten, all the underwriters on our program to agree to this, which is if the MSP Spectra certified, [01:16:00] there’s no insurance questionnaire, there’s no applications, there’s no 200 question long, yes. No. Do you have EDR check the box?

Yes. Do you have a firewall? Check the box. Yes. We’ve done away with all that. We already have all the data we need from the certification process to evidence that this is a quality service provider. So the questionnaire becomes redundant, so we just do away with it. So I think that’s pain point number one.

Pain point number two is okay, how do I monetize this? And so I think that’s where the a the warranty program comes into play, right? Is being able to then provide that premier tier service offering to their end customers and uplift their pricing as a result so they can generate revenue leveraging the time and investment they’ve made in the SPEC program.

And like I said, that the opportunity to then have access to warn leads through that broker channel, which is a completely kind of new go to market for those MSPs, right? I think all that comes together to help with the monetization strategy behind this.

Rich: You touched on something before that I wanna get into a little bit more, which is this idea that the [01:17:00] insurance companies, the insurance carriers are acquiring MSPs, they’re partnering with MSPs they’re selecting their favored NDR vendor and they’re talking to the insured part, the end users, basically about this.

I’m familiar as somebody who, you know, outside the insurance world, I’m familiar with some scattershot instances of this. So I guess question one is just, how pervasive, how prevalent is that? How much of that’s going on right now? And then what advice do you give MS. P and what are the implications for MSPs and what should they be doing about that?

Erick: Yeah, I’ll say, it’s a bit anecdotal, but I had three calls last week with partners who were dealing with this exact issue where one of the where their customers said, Hey, look we’re buying insurance from this provider and we’re gonna start leveraging in. In every instance it was br There are some other services, but that’s the main one these days. So I would say it’s, at least from where I’m sitting it’s pretty common. Comes up quite frequently in our discussion with [01:18:00] partners. I think, the way to defend against it, my advice, it’s tough to, go to war with a, trillion dollar industry that the insurance market is, right.

So I think it’s more of just it’s building those trusted relationships. It’s, I think there, I truly believe there is an opportunity for cooperation that actually nets in a PO and a better result for all parties involved. And that’s what we’re doing at Spectra. So I think leveraging the program to build that trust, but then also talking to clients and saying, Hey, look like we’ve been working together for, 20, 25, 30 years, go way back.

How can I help you? How can I be your trusted advisor on this, on solving this it problem before you start outsourcing that to other parties? The reality for that, that small business and I mentioned earlier is do you really want your 24 by seven, soc as a service provider to report to your insurance company, right?

Like when an incident goes down, what happens if. They missed the detection and that’s what resulted in the incident right? Then all of a sudden you introduce a host of liability challenge, right? So what might [01:19:00] seem very easy upfront actually introduces all of these problems downstream for when, if and when something goes wrong.

So I think, if MSPs can go to their partners and say, Hey, look, we’ve actually been forward thinking, we’ve been proactive about thinking what happens on a bad day? What are all the things you need to have in place? I think that’s just that’s such a more powerful net message for them to deliver to the client than, whatever is coming from the insurance broker who, you know, that individual may or may not have any kind of domain knowledge in cyber, they’re just passing on a pamphlet for some MDR service. So that’d be my advice. Looking into the future a little bit, six, 12 months down the road. What changes, if any, do you anticipate happening in the cyber insurance market? It’s. It’s tough to say, the insurance market does operate in cycles, right?

At least historically that’s been true. We’re in, what is referred to as a soft market where insurance is a bit easier to obtain today than it was say, three, [01:20:00] four years ago. And certainly more affordable than it was. I think it’s because the insurance market really they learn by looking backwards, right?

So they have to experience pain that then causes a change in behavior, right? And so what ended up happening is there were a couple of very profitable years that then led a lot of new entrants to take a shot on cyber who weren’t currently writing cyber in the insurance market. So there’s a lot of kind of resources have been pushing into this space.

Which has brought the price down, made products more accessible as different carriers are fighting for access to premium, essentially. But, that can only go on for so long. And I think what, we’re already starting to hear whispers of, and I think we’ll see this even there’ll be evidence, certainly 12 months from now.

I think if I was to bet it’s a, the pendulum start to swing back the other way where, there’s gonna be some losses. Insurers are gonna realize that, the pricing is just at a level that it can’t sustain the losses that they’re incurring. The [01:21:00] threats aren’t getting any less sophisticated.

Half the sessions, here today have just been talking about ai, about the opportunity, but also the threat and the challenge that, that MSPs need to be thinking about. So that landscape isn’t getting any less complex. So really that’s what. I think a lot of people in the market are talking about right now is when’s the pendulum gonna shift back?

And then insurance is gonna be more difficult to obtain. Prices may be less consistent. And so that’s really where there’s an opportunity for MSPs to position themselves as Hey, I’ve, I can solve that problem for my customers.

Rich: Interesting stuff. Eric. We’re we appreciate you filling us in on Spectra and what Spectra’s about also giving us here, so the expert view on the cyber insurance and the just insurance industry world.

For folks in the audience here who wanna get in touch with you wanna learn more about Spectra, where should they go?

Erick: Yeah you check on our website, spectra cyber.com. Honestly, just reach out to me directly. It’s [email protected]. I’d love to chat with you learn about your MSP, learn about the customers you service, your [01:22:00] plans.

So yeah, just reach out directly.

Rich: Fantastic. Eric Altura from Spectra. Thank you for joining us on MSP Chat. Cool. Thanks Rich Eric. Appreciate the fun. Thanks folks. We’re gonna take a quick break here. When Eric and I come back on the other side, we’re gonna talk a little bit about both the conversations that you just listened to and watched here on the show.

Have a little fun wrap up the show. Stick around. We’re gonna be right.

And welcome back to part three of this episode of the MSP Chat podcast by a lot of insight and knowledge by people who understand the world of insurance at a level. We, and most MSPs don’t. It was useful in clarifying for me what we got into over the course of these conversations that is on my mind a lot.

And was before these conversations, but will be even more so now after that, is this evolution of cyber insurance from a checklist item. It’s the thing that the [01:23:00] client has to have in order to be completely safe and secure and resilient in the face of threats out there into something that really has, more value, more benefit, this idea of risk management, that what you’re really providing with the cyber insurance policy, with the cyber warranty as a backup what you’re really doing is helping that end user understand and manage risk. And that’s a value added service to the customer.

That’s you being a better partner to the customer. It is also positioning you to help them get coverage more easily. Remove, the Spectra guys are just taking the questionnaire out of the equation. So it’s easier to get coverage as well as user are qualified, you’re gonna pay less.

So you’re addressing a lot of those pain points that have plagued MSPs for years around cyber insurance, but you’re doing it in a way where you’re also adding some value, providing a needed service to your client by helping them understand and manage risk.

Erick: Yeah. And [01:24:00] cyber insurance is on everybody’s mind, like you said, rich.

It’s something that, you know, even with the MSPs that we speak with, it’s the pain point is there’s so much complexity around it. How do I get my, my clients always send me the questionnaire and then I’m having to do all these questionnaires, every time they need to renew.

And how do I, that’s, how do I charge for that? It’s very awkward and I think, folks like these new Yukon and Spectra organizations are trying to simplify that for Babylon, the MSP, for the customer themselves. And so now it becomes a more natural way of having another added value when you’re sitting with your clients and you’re.

You’re monitoring okay, when is the time for renewal for your plan? Can we maybe shop for better rates now? So over time, I think it just becomes another way to show strategic value to your clients as you’re talking to ’em about not only, the, their cybersecurity risk profile and all [01:25:00] that, but there’s cyber insurance and then the backup of a warranty.

It just makes perfect sense because of course, business owners don’t wanna deal with any of that stuff either. They just want to know that if something does happen, I’m covered.

Rich: And the emergence of companies like Yukon and likes spectra they are helping MSPs talk to their customers about cyber insurance in a safe way.

Because there are a lot of potential. Regulatory pitfalls. It, for some MSPs it’s a scary conversation to have. And because these companies sit in between the MSP and the MSP’s customer and the insurance carriers, they can negotiate some of that in a way that allows you to have a conversation with your customer without exposing yourself to risk of any kind.

Erick: ‘Cause we know there’s enough risk to go around for MSPs these days. Absolutely true.

Rich: Folks, that leaves us with time for just one last thing and, when crime is committed in the world, Eric we want the people of law [01:26:00] enforcement to go out there and bring, take those criminals down.

We want justice to be served when crime happens, but timing sometimes does play into the picture a little bit. I take you now for an example to Tallahassee, Florida, where on July 3rd, a woman contacted the police to say that somebody at a Chuck E Cheese out let, had put about a hundred dollars worth of fraudulent charges on her credit card.

And the police stepped in. They investigated, they figured out who was responsible for the credit card fraud. It turned out to be an employee of the Chuck E. Cheese. And actually Eric, it turned out to be Chuck himself. And the police showed up at the outlet while Chuck was at work entertaining children.

They cuffed him. They dragged him off. These poor kids were absolutely horrified. Justice was served. It’ll, it’s a memory. Those poor kids will never forget, but the wheels of justice can’t be stopped sometimes.

Erick: That’s gotta be so traumatic for these kids. You hear stories like this at other amusement parks where, [01:27:00] the the, Mickey Mouse or Mini Mouse or whatever these things happen and they unmask them in front of the kids and the kids are like, oh, no, it’s what happened.

Rich: W we will link to a newspaper story about this incident in the show notes. And I encourage you to click through, find that link and click it just to see this picture of Chuck E. Cheese with his hands cuffed behind him. It is quite priceless. It’s

Erick: the perp walk they’ve got.

They’ve got Chucky, they’ve perp, perp walking ’em out. Handcuffed behind his back. Oh man.

Rich: Folks, that is all the time we’ve got for you this week on MSP Chat. We thank you for joining us. We’re gonna be back in a week with another episode for you. Until then, I will just remind you, this is both a video and an audio podcast, which means if you’re listening to us, but you’d like to check us out on video, go to YouTube, book up MSP chat.

If you are watching us on YouTube, but you’re into audio podcasts, go to wherever it is you get those Spotify, apple, Google, you name it, you’re probably gonna find us there. And wherever it is you do find us, please subscribe, [01:28:00] rate, review. It’s gonna help other people find and enjoy the show as much as you do.

Channel Mastered is produced by the great Rust Johns. It is edited by the great Riley Simpson. They’re part of the team with us here at Channel Mastered. They are already willing and able to create a podcast for you, if that’s something you’d like to do. And. Podcasts I need and tell you is just a tiny little sliver of what we do for our clients at Channel Mastered.

To get the big picture, I encourage you to go to www.channel Mastered.com. Channel Mastered has a sister organization called MSP Mastered, that’s Eric working one-on-one with MSPs to help them grow and optimize their business. You can learn more about that at www.mspMastered.com. So once again, thank you for joining us.

We’ll see you in a week. Until then, everybody, please remember, as we always encourage you to, you can’t spell channel. Without [01:29:00] MSP.