https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

Best Practices


Shutterstock

Don't Make Assumptions

3 Assumptions That Will Land MSPs’ Clients in Compliance Trouble

  • Written by Cam Roberson
  • October 30, 2019
Trust but verify should be standard for MSPs implementing security and compliance programs.
Beachhead Solutions' Cam Roberson

Cam Roberson

For MSPs delivering device and data security as part of their offering, unearthing their clients’ incumbent and faulty security practices – often guided by misplaced assumptions – remains commonplace. No matter what a client says or believes about the details of their own IT environment as it relates to regulatory compliance requirements, the right move for MSPs is to trust but verify. Or, put simpler: never just take your client’s word for it. Doing so may leave the door open to damaging data breaches, and leave the client (and in some cases even you, the MSP) exposed to crippling regulatory fines.

Considering the mishaps clients can and will get into when it comes to handling data and safeguarding their IT systems, MSPs would be wise to introduce their own compliance-as-a-service offerings in addition to existing services, to fully protect the interests of their clients and themselves.

Here are three recent tales we’ve heard from MSPs about occasions where their clients made dangerous assumptions that would have left their systems out of compliance and at substantial risk:

1. The client assumes legacy policies remain compliant forever.

Dereck Jacques, team lead and project manager at Charles IT, told us the story of a client that needed to bring its systems into SOC compliance and came to the MSP for help. According to Jacques, “They were a rapidly growing company, whose technology and policies had started to lag behind because they had been so focused on scaling the business.”

The client assumed that the MSP’s compliance efforts would focus solely on replacing equipment (such as out-of-date legacy servers) and then updating the network to introduce intrusion prevention and detection that could bolster overall security. A primary client focus was the introduction of a Security Information and Event Management (SIEM) platform, fulfilling a key component of SOC compliance by providing a full record of important actions taken within the network.

However, the client also intended to leave its existing legacy policies in place, assuming them to be aligned with the company’s compliance goals. Luckily for the client, Charles IT went beyond simply fulfilling its technology requests and instead examined the client’s compliance profile in its entirety. When it did, those legacy policies stuck out as a major risk factor. “Rewriting and filling gaps in policies played a big part in our client’s move toward compliance,” Jacques explained. “We updated aging policies, and created new policies to keep the client in-step with its industry’s quickly changing technological landscape. Thanks to that more holistic focus, the client successfully passed their SOC audit and was awarded compliance.”

2. The client assumes its devices were devoid of sensitive PHI data.

Brad Storz, president of Cirrus IT Solutions, recently told us this story about a new client in the health care industry that insisted its computers held no electronic personal health information (ePHI) whatsoever. Health Insurance Portability and Accountability Act (HIPAA) regulations governing the industry require careful handling and storage of ePHI, enforced with substantial fines and even the dreaded public shaming. At the same time, any entity handling ePHI on behalf of a HIPAA-covered entity must …

  • Page 1
  • Page 2
Tags: MSPs Best Practices Security Strategy

Most Recent


  • Seattle
    Microsoft Job Cuts Hit Hundreds More Workers in Seattle Area
    In January, Microsoft initiated a plan to shed about 10,000 workers.
  • boxing gloves
    Channel Conflict, Controversy: Avaya Bankruptcy, Mass Layoffs, High-Profile Execs Depart
    There's always something to buzz about in the channel.
  • Celebrating millionaire geezer
    AT&T Alliance Channel Awards: Telarus Wins, Avant Rises, Intelisys Slides
    TD Synnex was among the partners joining this awards list for the first time. See who else earned accolades from the carrier.
  • Mergers and acquisitions
    Intelligent Technical Solutions Buys 5 MSPs
    The acquired companies are based in four western states.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • Stressed young people
    More Partner Pain Points: MSPs On Lack of End-to-End Security, 'New Normal'
  • CIO
    ScanSource Hires New CIO to Lead Global IT Strategy
  • zero trust security
    Leveraging Partner Expertise to Build a Zero-Trust Strategy
  • Drive revenue
    Proofpoint Protect: Rising Vendor, Partner Revenues Amid COVID-19

Upcoming Events

View all

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Channel Partners Europe

June 13, 2023 - June 14, 2023

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Galleries

View all

Channel Conflict, Controversy: Avaya Bankruptcy, Mass Layoffs, High-Profile Execs Depart

March 28, 2023

Cisco African American Partner Community Eyes Hiring, HBCU Opportunities

March 28, 2023

National Women’s History Month: Channel Women Recall ‘the Best Thing’

March 28, 2023

Industry Perspectives

View all

Why You Should Include Audiovisual Solutions in Your UC Services

March 28, 2023

Selling Your MSP: Strategic vs. Financial Buyers

March 22, 2023

10 Strategic Smart Enterprise Drivers for 2023

March 16, 2023

Webinars

View all

Give Customers the Power: How MSPs Can Leverage Cloud Choice

April 4, 2023

DE&I Dialogue: How the Right DE&I Initiatives Can Propel Your Business

April 5, 2023

Meet the 2023 Channel Futures Channel Influencers

April 13, 2023

White Papers

View all

6 UCaaS Reseller Challenges and How Real World Businesses Solved Them

February 1, 2023

Frost Radar: North American UCaaS Market, 2022

February 1, 2023

The Complete Guide to White-Label UCaaS for Reseller Success

February 1, 2023

Channel Futures TV

View all

Coffee with Craig and James Episode 121: Hewlett Packard Enterprise

Aryaka ‘Driving Value to the Channel Community’ with Throttle

March 24, 2023

Real-Life M&A: Advice for a Successful Channel Deal

March 13, 2023

Coffee with Craig and James Episode 120: Ronnell Richards

March 3, 2023

Twitter

ChannelFutures

.@Microsoft #layoffs target more workers in Seattle area. dlvr.it/SldRzg https://t.co/DGtDBBU4m0

March 28, 2023
ChannelFutures

[email protected] buys 5 MSPs to expand geographic footprint dlvr.it/SldPyq https://t.co/GnewmOXRch

March 28, 2023
ChannelFutures

.@Lacework announces partner program updates, new #MSP program. #security dlvr.it/SldP9H https://t.co/hUKTOYgoY3

March 28, 2023
ChannelFutures

Learn how MSPs can generate new revenue streams with audiovisual solutions. @shure #ucservices #channelpartners… twitter.com/i/web/status/1…

March 28, 2023
ChannelFutures

⭐ 2023 #ChannelInfluencer spotlight: @andrewsage from @Cisco! Congratulations on this incredible honor from your pe… twitter.com/i/web/status/1…

March 28, 2023
ChannelFutures

The latest @ATTPartners awards give a nice glimpse of how M&A is shaping partner hierarchies.… twitter.com/i/web/status/1…

March 28, 2023
ChannelFutures

.@Netsurion announces partner program enhancements. #XDR dlvr.it/Sld2wM https://t.co/KuanLOeTMB

March 28, 2023
ChannelFutures

.@ATTBusiness retains top spot in latest carrier-managed #SDWAN leaderboard. dlvr.it/SlcvcN https://t.co/QehfYFbOrN

March 28, 2023

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X