https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
    • Diversity, Equity & Inclusion
  • MSP 501
    • Back
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
    • MSP 501 Information Center
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2022 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Channel Partners 101 (CP 101)
  • Events
    • Back
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
    • Diversity, Equity & Inclusion
  • MSP 501
    • Back
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
    • MSP 501 Information Center
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2022 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Channel Partners 101 (CP 101)
  • Events
    • Back
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

Best Practices


Shutterstock

Framework spelled out in blocks

MSPs Welcome Proposals for New Cybersecurity Framework

  • Written by Christine Horton
  • June 1, 2021
They want regulation? The MSPs we talked to say bring it on if it helps prevent disaster.

The UK government is mulling a new cybersecurity framework for MSPs to prevent third-party attacks.

MSPs have become an increasingly common target for cybercriminals. That’s because hackers increasingly use MSPs as a single point of access to their clients’ sensitive data.

In 2020, the U.S,. Secret Service warned of an increase in such attacks. It noted that criminals are leveraging compromised MSPs to conduct a variety of attacks. These include point-of-sale intrusions, business email compromise (BEC) and ransomware attacks.

Elsewhere, Perch Security from ConnectWise recently predicted “the first moves by government and insurance providers to regulate the MSP industry.” The company warned that MSPs pointed to an increase in “Buffalo Jumps.” This is a new tactic that cybercriminals use to ransom a service provider and many of their customers at once.

Now the UK government is testing the suitability of a proposed cybersecurity framework for MSPs.

The proposals could require MSPs to adhere to a set of 14 cyber security principles called the Cyber Assessment Framework. The framework sets out measures organisations should take, such as having policies to protect devices and prevent unauthorised access. It would also require them to ensure data is protected at rest and in transit. Furthermore, it advocates for keeping secure and accessible backups of data and training staff, and pursuing a positive cybersecurity culture.

MSPs Welcome the Move

The proposal for the cybersecurity framework has been welcomed by UK MSPs.

Rick Gray is sales director at MSSP Cyberfit. The company acts as an adviser for MSPs that don’t have security expertise. This involves putting a security wrap around any offering the MSP is hosting for its end-customers.

Gray strongly believes that the government should implement the new framework, as “too many of these MSPs are doing the bare minimum. They think offering antivirus is enough — it’s just a tick box exercise. They say it’s secure when it’s not.

Cyberfit's Rick Gray

Cyberfit’s Rick Gray

“We had a client that hosted an exchange service for one of their customers and didn’t do the correct level of patching. So the customer got hit by the recent Exchange attacks. It’s a great thing that the government is bringing out these parameters for MSPs. There are too many out there getting away with it,” he said.

Ballard, Joanne_Maintel

Ballard, Joanne_Maintel

Joanne Ballard, customer experience director at Maintel, believes a central regulation will benefit both suppliers and customers. She said it would provide “peace of mind to the end user that they are working with a trusted provider.”

Re-inventing the Wheel?

Mark Herridge, CISO at Calligo, says the Cyber Assessment Framework “is clearly a step in the right direction.”

However, he notes that “there is little if anything new … that is not already covered by established certifications.

“These are well recognised not only by industry, but also by end-user organisations. We are seeing an increasing number of potential customers openly favour MSPs that have these accreditations.”

Calligo's Mark Herridge

Calligo’s Mark Herridge

He also said some customers even require their MSP to adhere to their own data security agreements. This is typically built off the principles of ISO, SOC and others.

Rather than re-inventing the wheel, Herridge said the government may be better off taking another route. It could do this by “simply stipulating that MSPs must attain and maintain these globally recognised certifications. If I were a potential customer, I wouldn’t contract with [an MSP] that did not have ISO 27001 as a minimum.”

Claudio Stahnke is senior research analyst, European Security at IDC. He said the UK “is certainly moving in the right direction.” He pointed out that the recent Colonial Pipeline hack has shown how vulnerable supply chains can be to cybersecurity breaches.

IDC's Claudio Stahnke

IDC’s Claudio Stahnke

Stahnke said the rapid growth of IT security means MSPs often provide cybersecurity even though they are not specialists. Regardless, he said “creating a framework that IT suppliers will have to follow will certainly help improve and level the field.”

He said this is required “in a world where the race between hackers and defenders keeps ramping up.”

Tags: MSPs Best Practices EMEA Security Strategy

Most Recent


  • European continent at night
    Infinigate Buying Nuvias for ‘Pan-European Cybersecurity Powerhouse’
    The deal will establish a footprint across 21 countries and 1.4 billion Euro in revenue.
  • DartPoints' Jackie Steinberg
    Channel People on the Move: AT&T, HPE, Google Cloud, Comcast, More
    Plus, moves at TBI, Trend Micro, Microsoft, Sandler Partners, Nitel and more.
  • Cloud computing news
    Missed June’s Cloud News? AWS, VMware, HPE, Google Cloud Made Headlines
    In case you’ve been busy (or on much-needed summer break), we’ve collected the biggest news for cloud partners.
  • Cloud computing
    Public Cloud Momentum Pacing Past Forecasts, With AWS, Azure in Lead
    We assess the soaring numbers with the help of Gartner, IDC and Synergy Research.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • CF Top Gun 51 with new logo
    2021 Top Gun 51 Nominations Are Open — Apply Now!
  • USB drive
    A Coup and a Theft: Why MSPs Can’t Let Clients Get Lax About USB Security
  • Ransomware skull and crossbones
    JBS Did What it 'Needed to Do' with $11 Million Ransom Payment
  • Cloud Certification
    CompTIA Updates Cloud+ Certification, Drops New AI Guide for Businesses

Upcoming Events

View all

MSP Summit

September 13, 2022 - September 16, 2022

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Galleries

View all

Channel People on the Move: AT&T, HPE, Google Cloud, Comcast, More

July 5, 2022

Missed June’s Cloud News? AWS, VMware, HPE, Google Cloud Made Headlines

July 5, 2022

Public Cloud Momentum Pacing Past Forecasts, With AWS, Azure in Lead

July 4, 2022

Industry Perspectives

View all

How to Make Embracing Change Part of Your Company Culture

July 1, 2022

How to Differentiate to Leverage 5G’s Revenue Opportunity

June 28, 2022

Why MSPs are Attractive Cyberattack Targets

June 24, 2022

Webinars

View all

VEP Platform for Delivery of uCPE, SD-WAN and SASE

June 29, 2022

The Digital Worker: How to Empower Customers with a Flexible, Scalable VDI Solution to Enable Remote Work

June 30, 2022

Growing Partner Revenue and Customer Satisfaction with Power Management Services

June 23, 2022

White Papers

View all

Work Goes Remote – (and Other Top ITOps Trends)

May 25, 2022

The New Bottom Line: How MSPs Can Meet the Healthcare Crisis While Evolving Their Businesses

April 19, 2022

How to build a Security Operations Center (on a budget)

April 4, 2022

Channel Futures TV

View all

Vonage a ‘Single Communications Stack Provider’ for Partners, Customers

IBM, Partners and the $1 Trillion Hybrid Cloud Opportunity

June 26, 2022

Agents Share ‘Secrets,’ Industry Opportunity

May 11, 2022

AT&T, Microsoft, Cisco, ThreatLocker on Unlocking Partner Potential

May 6, 2022

Twitter

ChannelFutures

Distributor @Infinigate to acquire @nuviasgroup to create "pan-European #cybersecurity powerhouse."… twitter.com/i/web/status/1…

July 5, 2022
ChannelFutures

[email protected], @AWSCloud, @VMware, @Azure, @HPE, more, all made big waves in June with respective #cloud news.… twitter.com/i/web/status/1…

July 5, 2022
ChannelFutures

Happy Independence Day 🎇 to our U.S. colleagues, from the #ChannelFutures and #ChannelPartners team to yours! We ho… twitter.com/i/web/status/1…

July 4, 2022
ChannelFutures

#Publiccloud demand is going nowhere. We dive into stats. @AWSCloud @Azure @IDC @Gartner_inc @SRG_Research #cloud… twitter.com/i/web/status/1…

July 4, 2022
ChannelFutures

Partners can bring more value to #customerrelationships with the #customerexperience, says @SAPPartners4U.… twitter.com/i/web/status/1…

July 4, 2022
ChannelFutures

Channel people making waves this week include: @jpdepa3rd, @RiyaShanmugam, @sandyhogan dlvr.it/STCM6S https://t.co/oVB86ztTtP

July 1, 2022
ChannelFutures

#Cybersecurity experts say July 4th weekend ripe for #ransomware, other attacks. @blumirasec @Netenrich @Vectra_AI… twitter.com/i/web/status/1…

July 1, 2022
ChannelFutures

New @PureStorage #ITchannel leader details jump from Veritas. dlvr.it/STBsLB https://t.co/BFSmZ5ubff

July 1, 2022

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2022 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X