https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

MSSP Insider


Shutterstock

News, headlines on mobile device

MSPs: Improve Internal Security Practices, Avoid Headlines

  • April 13, 2020
From 2FA to system isolation, beefed-up internal security practices keep MSPs, clients safe.
Kalleo Technologies' Doug Truitt

Doug Truitt

By Doug Truitt, Kalleo Technologies

Make no mistake: The high-profile $2.5 million ransomware attack striking multiple local governments in Texas last summer that was traced to a single compromised managed service provider has raised the stakes for all MSPs. Not too long ago, MSPs’ greatest danger was perhaps that a single client might be infected by malware. Now, MSPs must worry about being hacked themselves (and attackers then exposing all of their customers). MSPs must improve internal security practices.

Conversations among MSPs on Reddit make it clear that attacks compromising MSPs’ entire clientele have become nearly a weekly occurrence. This new reality has MSPs fearing breaches of their own systems like never before. It has given even the smaller MSPs new incentive to implement every security precaution.

Best Practices

While emerging MSPs lack the resources to enlist expensive tools, they can still employ many effective best practices against these threats and improve internal security practices. Here are five internal security practices these MSPs ought to implement as soon as possible, if they haven’t already:

1) Remove risks stemming from employee mistakes (with two-factor authentication, access controls, etc.). At its heart, IT security is the art of managing human nature. I’ll give you an example on the client side of things: In the past 12 months we’ve had employees at four different clients fall for the “Please buy me iTunes gift cards because I’m stuck in a meeting” phishing scam. It’s important to understand that none of these individuals are stupid — they simply got hit at the perfect distracted moment. This may be a client example, but its lesson applies to internal MSP teams. Don’t think that your people are “too savvy to fall for that kind of thing.” No, they’re not.

To secure against social engineering threats, smaller MSPs should design systems where an employee can fall for a scam and it doesn’t matter. In our case, we now use two-factor authentication (2FA) across all our solutions. We do that so that if an employee has a bad day and exposes his or her login credentials, attackers still cannot access our systems. MSPs must also be strict in adhering to these types of security strategies for them to be effective. For example, standardizing all solutions across a multifactor authentication (MFA) tool of choice, like Duo or AuthAnvil. If our techs want to adopt a new solution, it has to support our 2FA tool.

We also use Beachhead Solutions’ SimplySecure to erase the impact of mistakes when it comes to safeguarding employee devices and the data they hold. With this platform, if a device with access to our data is lost or stolen, the tool can block access or delete that data remotely. Because phones are the key to our two-factor authentication, this capability to protect phone devices is even more essential to us. It not only prevents isolated data breach incidents but ensures that such events can’t cascade and expose additional systems.

We have an easy time selling a tool like this to clients as well. We sell it like insurance against data breaches — a proposition they understand and are eager to engage with. This is clear example of how implementing secure solutions for your business can serve as a launchpad for secure client-facing solutions.

2) Introduce isolation. Practice isolation so that one compromised system cannot impact others. For example, our servers are isolated from each other and located in a SOC-compliant data center. Emerging MSPs can introduce isolation without introducing big expenses. Take strategic inventory of each system’s access capabilities and the associated risks. Analyze your systems as an attacker would — if you wanted to break in and escalate access to impact all systems and clients, how could you do it? Then, limit those systems, shutting off every avenue that might give an attacker hope.

3) Enlist capable external tools. As a small MSP in 2004, we created our tools. However, that was another time and another world. If I was starting over today, I’d use zero in-house tools. Today’s cloud-based solutions are simply far more capable from a security perspective. For example, we use a third-party business management software provider built for MSPs.

We also use a heavy-duty endpoint security that locks down how much trouble a user can get into.This has helped to reduce the endpoint infections…

  • Page 1
  • Page 2
Tags: MSPs Business of Security MSSP Insider Security Training and Policies

Most Recent


  • AI spells the end of end-user security
    AI Spells the End of End User Security
    We need to do a hard reset on our expectations for end user security.
  • Cloud Roundup
    Google Cloud Lashes Out at Microsoft, New Hurdle for Broadcom-VMware
    This cloud computing wrap-up showcases some big news and happenings at more under-the-radar cloud firms.
  • Joseph Chong Enterprise Connect
    ‘Collaborate Happy’: Zoom, Google Cloud, AWS Showcase New AI, Machine Learning Tools
    “Things that are not possible are possible,” said Google Cloud at Enterprise Connect.
  • Growth
    Okta Launching Updated Partner Program to Accelerate Growth
    Okta wants to engage with its partners more strategically.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • DevSecOps
    ServiceNow, Microsoft Set to Deliver Broad SecOps Integration
  • Dunce Cap Businessman
    Tired of MSSPs ‘Failing,’ Nuspire Debuts Platform to Combat Cyberattacks
  • Malicious hacker at computer with code
    FragAttacks Wi-Fi Vulnerabilities Pose Widespread Threat to Individuals, Businesses
  • Colonial Pipeline Just the Latest Victim in Darkside Ransomware Crime Spree

Upcoming Events

View all

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Channel Partners Europe

June 13, 2023 - June 14, 2023

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Galleries

View all

Google Cloud Lashes Out at Microsoft, New Hurdle for Broadcom-VMware

March 30, 2023

National Women’s History Month: Channel Women on Getting Good Advice

March 30, 2023

Amplify 2023: HP Tackling Tough Market with ‘Realistic Optimism’

March 29, 2023

Industry Perspectives

View all

AI Spells the End of End User Security

March 30, 2023

Why You Should Include Audiovisual Solutions in Your UC Services

March 28, 2023

Selling Your MSP: Strategic vs. Financial Buyers

March 22, 2023

Webinars

View all

Give Customers the Power: How MSPs Can Leverage Cloud Choice

April 4, 2023

DE&I Dialogue: How the Right DE&I Initiatives Can Propel Your Business

April 5, 2023

Meet the 2023 Channel Futures Channel Influencers

April 13, 2023

White Papers

View all

6 UCaaS Reseller Challenges and How Real World Businesses Solved Them

February 1, 2023

Frost Radar: North American UCaaS Market, 2022

February 1, 2023

The Complete Guide to White-Label UCaaS for Reseller Success

February 1, 2023

Channel Futures TV

View all

Kaseya, Post-Acquisition, Expanding ‘Well-Regarded’ Datto Partner Program

Aryaka ‘Driving Value to the Channel Community’ with Throttle

March 24, 2023

Coffee with Craig and James Episode 121: Hewlett Packard Enterprise

March 23, 2023

Real-Life M&A: Advice for a Successful Channel Deal

March 13, 2023

Twitter

ChannelFutures

.@HP thanks partners, promises to reduce wait times and complexity across organization. #HPAmplify… twitter.com/i/web/status/1…

March 30, 2023
ChannelFutures

.@Kyndryl #layoffs impacting a percentage of workforce. dlvr.it/SllFbF https://t.co/Bo77KdJMpx

March 30, 2023
ChannelFutures

[email protected] makes #DE&I a priority year-round, not just for @womenshistmonth. “A constant cadence of activism… twitter.com/i/web/status/1…

March 30, 2023
ChannelFutures

📺 Tune into the latest CFTV episode, brought to you by @HitachiVantara, all about how you can identify your competi… twitter.com/i/web/status/1…

March 30, 2023
ChannelFutures

“Things that are not possible are possible,” said @Google's @behshad_behzadi at #EnterpriseConnect about generative… twitter.com/i/web/status/1…

March 30, 2023
ChannelFutures

📺 We asked 2023 #ChannelInfluencer @peter_kujawa from Service Leadership what his secret sauce is- his work philoso… twitter.com/i/web/status/1…

March 30, 2023
ChannelFutures

.@okta rolling out redesigned partner program. #cybersecurity dlvr.it/SlkYJl https://t.co/52Wx5prcNS

March 30, 2023
ChannelFutures

Need some advice? Women in the communications and IT channel share some of the best they’ve ever received about wor… twitter.com/i/web/status/1…

March 30, 2023

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X