The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/Cyber For Hire
Cyber For Hire artwork

How Managed Services Providers Can Exceed Evolving SecOps Expectations - Christopher Fielder - CFH #30

Cyber For Hire · 2023-09-26 · 49 min

0:00--:--

Key moments - from our scoring

Substance score

44 / 100

Five dimensions, 20 points each

Insight Density9 / 20
Originality7 / 20
Guest Caliber11 / 20
Specificity & Evidence10 / 20
Conversational Craft7 / 20

Christopher Fielder argues that MSPs and MSSPs must move past the 'device babysitter' model - simply managing firewalls and endpoints - toward becoming strategic security partners. The conversation centers on three core pillars: breaking out of customer silos to pool threat data across multiple clients and industries for cross-organization inoculation against emerging threats; curating and deploying threat intelligence and data science alongside internal security research rather than blindly applying vendor-supplied detections; and most critically, performing sophisticated analysis that filters alert noise into high-fidelity, contextual escalations. Fielder uses concrete examples like the MGM Resorts attack (social engineering to MFA reset) and cross-industry vulnerabilities (Solar Winds, Microsoft Exchange) to illustrate why retail, healthcare, and hospitality share common technology stacks and threat vectors. The key insight: service value must survive technology stack changes - if a client cuts tools by 75%, can you still deliver security outcomes? This reframing positions the MSSP as indispensable through people, process, and intelligence, not just tool management.

Key takeaways

  • →MSPs must shift from managing individual devices to providing security outcomes that remain valuable even if clients reduce their technology stack by 75%.
  • →Cross-industry threat data pooling allows one client's incident (indicators of compromise, attack patterns) to inoculate all other clients, turning multiple siloed environments into a real-world threat intelligence lab.
  • →Threat intelligence feeds must be curated for each client's architecture, vertical, and mission to avoid alert fatigue; applying every available feed generates noise rather than high-fidelity signals.
  • →Social engineering combined with identity system compromise (like Okta federation attacks) now requires MSPs to focus on identity and access management as a core SecOps competency, not just endpoint monitoring.
  • →High-fidelity alert escalation - paring down notifications to only truly critical, verified threats - is a core service differentiator that justifies MSSP fees by reducing customer alert burden.

Guests

Christopher Fielder

Topics in this episode

XDR (Extended Detection and Response)Colonial Pipeline attackArctic WolfSIEM (Security Information and Event Management)Okta identity and access managementSecOps (Security Operations)Threat intelligence curationData science for securityCross-industry threat dataAlert fatigue reduction

Questions this episode answers

What does it mean for an MSSP to stop being a 'device babysitter'?

It means moving beyond simply pulling alerts from security tools and forwarding them to clients, instead delivering higher-level value through data analysis, threat intelligence, and contextual recommendations that remain relevant even if the client's technology changes.

How can MSPs use threat data from one client to protect others without violating privacy?

By extracting and sharing indicators of compromise, attack patterns, and threat intelligence indicators across clients and verticals while maintaining anonymity - for example, if one client is hit by a specific malware, all clients using the same vulnerable technology can be inoculated.

Why should retail and healthcare MSPs care about threats in each other's industries?

Both verticals process credit cards, maintain customer data, and often use overlapping technologies like point-of-sale systems and common platforms like Windows and Exchange; attackers exploiting a healthcare vulnerability can easily pivot to retail, and vice versa.

How do you apply threat intelligence without creating alert fatigue?

Select and curate threat feeds that match the client's specific architecture, mission, and industry vertical rather than loading every available feed; this ensures alerts are high-fidelity and relevant, reducing noise.

What telemetry data is most critical for MSPs to collect today?

Escalation and de-duplication of alerts to surface only high-fidelity, verified critical threats; clients can turn on all detections themselves, but they hire MSPs to filter noise and confirm true positives.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

9 / 20

The episode surfaces a few genuinely useful operational points - most notably the cloud monitoring gap stat and the alert-triage framing - but is diluted by a long pop-culture tangent, generic filler, and repetition of well-worn MSP advice. Idea-per-minute rate is modest.

only 18% of those that we found were using some form of CSPM or active cloud monitoring and management. That's about 81% of environments they're not really actively monitoring
let's say your client has a reduction of cost and they have to cut their technology stack down to a quarter of what it was. Can you still provide the same value?

Originality

7 / 20

The 'device babysitter' framing is a decent rhetorical device, and the cross-vertical POS/pharmacy bridge is a small creative moment, but virtually every substantive point - AI as tool not replacement, cross-industry threat sharing, alert triage - is standard industry consensus rather than contrarian or first-principles thinking.

What if that device goes away? Do they still need you? What can you provide beyond that device?
you mentioned point of sale. I guarantee in that healthcare industry there's probably point of sale equipment in there as well

Guest Caliber

11 / 20

Christopher Fielder is a legitimate practitioner at a credible MDR vendor with real operational background, but his dual role as Field CTO and Director of Product Marketing skews him toward spokesperson territory. The second-half 'guest' is a co-host presenting his own employer's survey, which is essentially self-promotion.

Christopher has been in the cybersecurity world for almost 20 years with experience ranging from military, government and corporate environments
Something that makes the company I work for unique is that we go in there and we learn the customer's environment as if it were our own

Specificity & Evidence

10 / 20

The cloud monitoring stat (99%+ cloud adoption vs. 18% CSPM usage) and the CRA endpoint survey figures (3/5 compromised, 63% with 1000+ endpoints) are concrete anchors, but key numbers are hedged ('99.3 something') and named breach examples (Colonial, SolarWinds, Exchange) are universally known rather than fresh evidence.

a little over 99%... But only 18% of those that we found were using some form of CSPM or active cloud monitoring and management
three out of five respondents admitted that they've had to deal with one or more compromised endpoints in the last year

Conversational Craft

7 / 20

The host sets up topics competently but telegraphs every follow-up and never pushes back on any claim; 'you read my mind' appears twice, signalling comfortable alignment rather than probing dialogue. The Batman segment consumes several minutes of airtime with zero operational value.

you read my mind. Because that was going to be the follow up question I was going to ask
again you read my mind because as you were starting to give the answer to my first question

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker C45%
  • Speaker A40%
  • Speaker B15%

Most-used words

security33threat30data24intelligence23batman21device18endpoint17environment16alerts15provide14devices14cloud14cyber12first12technology12information11

Episode notes

The days of an MSSP or MSP being a security device babysitter are over. Clients expect more from your SOC, SIEM and SecOps offerings, and evolving attacks will demand more of you. It's time to level up - but how does one upgrade from basic to top-tier services? According to our featured speaker, there are several key steps: more comprehensive, cross-industry threat data collection; more refined, contextual and meaningful analysis of threat telemetry data; and ample use of threat intelligence, data science and security research. This interview will examine the key challenges and opportunities associated with these critical objectives. Endpoints are everywhere and come in many forms, and especially in today's BYOD environment, it's becoming increasingly difficult to maintain visibility and control over all of them. Unfortunately, rouge endpoints represent an enticing attack vendor for adversaries who are always looking for a way inside your network.

Full transcript

49 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Level up how managed services providers can exceed evolving SecOps expectations and endpoint security entering the era of AI and XDR. That and the latest news and trends in the managed security space. Coming right up on Cyber for Hire. Building bridges between managed security providers and their clients. It's the podcast where MSSPs, VCIs and end users take a united stand against cybercrime. This is Cyber for Hire. All right, welcome, friends, to episode number 30 of Cyber for Hire. How's everybody doing today? I'm Bradley Barth with the Cyber Risk alliance in New York. And joining me today just a few hours drive away on i95, is my guest co host for the day, Bill Brenner, SVP of Audience Content Strategy at Cyber Risk Alliance. Bill, thanks for filling in this week. Uh, by the time this show is published, you and I will be in Disney World for CRA's 2023 InfoSec World Conference. Not sure if you're a theme park fan, Bill. I feel like people either really love them and they're fervent Disney fans, or they hate it with a passion. But, uh, I'll ask you the same question that I might, uh, ask some folks for fun at the show. Uh, do you have a favorite, uh, Disney, uh, ride that you'd like to come back to over and over again?

Speaker B: I do not. So I have a lot of friends who. A lot of friends in the security world, actually, who go to Disney multiple times a year and call me boring. I just don't get it. My favorite, uh, portrayal of Disney is the way it's portrayed in South Park.

Speaker A: Sort of that, uh, corporation that, uh, just basically has its hands on everything medical. Yeah, exactly. All right, fair enough. So basically what you're saying is we're there in the Coronado Springs Convention Hall. If a character walks by, there's no character that, uh, is gonna fill you with all sorts of joy and glee and nostalgia, uh, if, uh, let's say, uh, Tigger walks by and says hello. No thrill for you?

Speaker B: No.

Speaker A: No. All right, fair enough. Fair enough. I am one of those Disney files that, uh, just seems to always find my way back there, uh, over and over again. So, uh, it'll be nice to be there. Uh, of course. How to make sure that I gave myself an extra day on my own dime while I'm down there. Because there's nothing worse than being down in Disney World. And then the entire time you're there, you're just doing work and everybody else around you is having fun. So, uh, well, listen, we've got A jam packed show for you as always, but some news just can't wait. Which is why we want to begin by sharing what's top of mind today. So here's your headline. An attack by the cybercriminal threat actor Scattered Spider, an affiliate of the black cat ransomware group ALFV attacked Vegas hospitality giant MGM Resorts, exfiltrating their Data, encrypting their ESXi hypervisors and forcing them to shut down systems at multiple hotels, affecting everything from, uh, slot machines to reservations to payments, to even electronic door locks. The culprits pulled off the cyber assault apparently by impersonating an MGM employee whom they looked up via, uh, LinkedIn and then called up an IT help desk purportedly as that individual, as part of an orchestrated plan to take over key accounts and reset their Multi Factor Authentication credentials. At some point, the perpetrators gained super admin privileges to MGM's Okta identity and access systems and even configured a second fraudulent source identity provider that according to Okta, acted as an impersonation app, allowing malicious actors to access targeted systems and applications via federation and single sign on. Uh, also Caesar's Entertainment revealed, uh, shortly after that they had also been previously breached by the same actors. In their case, only data was stolen. Uh, no major shutdown because they had apparently paid the ransom. So, Bill, big story, obviously. Why should this be top of mind for MSPs and MSSPs?

Speaker B: Well, I mean, first off, the thing that really astounds me about this whole incident is just how easy it was to pull off and using LinkedIn to dupe the gate minders, um, the way it happened. Um, and I think if you're an mssp, um, the question is, how do you thwart that kind of tactic? And there isn't an easy answer for it. Um, so. But it definitely showed how one tiny social engineering trick can cascade into something so huge. Um, and I think we've seen attacks like that, but we haven't seen one like this in a long time and certainly not affecting the gaming industry as it has.

Speaker A: Yeah, absolutely.

Speaker B: I look at this with the same sense of wow that I looked at the Colonial Pipeline attack, uh, m. Two years ago where it was. Okay, we've, we've talked about this in theory as a danger, but, oh, here it is happening in real time. Yeah, we've arrived at this place and I think that for MSPs and MSSPs, the message there is this is here, this is now.

Speaker A: Mm.

Speaker B: And if you are managing IT security for big clients, this is something that you need to be Paying super sharp attention to.

Speaker A: Yeah, uh, absolutely. You know, we, we actually even have a, uh, a colleague at CRA who was there in Vegas while the attack was going down. And according to her account she said uh, it was just pretty wild to see uh, how you know, people had to wait, uh, online to make change in person. And it just created all sorts of uh, uh, chaos and inconvenience. And uh, like you said, the social engineering element of it is very simple. But it was a mix of simple and complex because what they also were able to do with creating this second source, uh, identity provider, something also uh, to watch out for, especially for those specializing in iam because uh, that's certainly a tactic, uh, worth uh, further investigation uh, as well. So interesting uh, goings on there and uh, we're still continuing to see what the full repercussions are going to be. All right, well that's our top of mind headline for the day. But now it's time to move on to our MSP and MSSP business strategy topic of the week. This one really is an equal mix of both business and security strategy. But with that said, presenting our big idea in business. Level up. How managed services providers can exceed evolving SecOps expectations the days of an MSSP or MSP being a security device babysitter are over. Clients, expect more from your SoC, SIEM and SecOps offerings and evolving attacks will demand more of you. It's time to level up. But how does one upgrade from basic to top tier services? According to our featured speaker today, there are several key steps, uh, including more comprehensive cross industry threat data collection, more refined contextual and meaningful analysis of threat telemetry data, and ample use of threat intelligence data science and security research. This interview will examine the key challenges and opportunities associated with these critical objectives. Uh, our guest for this segment is Christopher Fielder, Field CTO at Arctic Wolf. Christopher has been in the cybersecurity world for almost 20 years with experience ranging from military, government and corporate environments. He holds 18 industry certifications along with a master's degree in Information security. As I mentioned, uh, he is currently, uh, field CTO and Director of Product Marketing for Arctic Wolf, where he enjoys researching emerging security trends and highlighting the expertise of the Arctic Wolf team. Uh, so Christopher, thanks very much for being here today. Really glad you could join us. And as always we're going to jump right into things. So uh, we open with the premise of the days being a security device babysitter are over. Uh, what does that mean really to just be a security device babysitter? If we're doing sort of a before picture and an after picture, and before is really prior to leveling up and evolving along with needs and expectations, what does that look like? And then compare it to really what you need to look like today in order to both meet constantly evolving threats and constantly evolving expectations of increasingly demanding clients and customers.

Speaker C: Thank you. Yeah. So I really like that metaphor for a device, babysitter. Right. Because when we think about, like a traditional babysitter or nanny or whatever is a job function, that it's going to evolve and there's kind of a limited amount of time that you can do that job. Right. Because you're babysitting kids that are going to turn into teenagers, and then they're eventually going to grow up and they're going to be gone. In the same way that these environments are going to evolve and they're going to change and they're going to have new equipment, and if you are static and you are providing, you know, support for a certain set of equipment and that's it, well, you're really limiting what you're able to provide because these, you know, environments are going to change. They're going to have new equipment come in, they're going to have new devices come in, they're going to get rid of legacy stuff, and they're really going to outgrow you if you're stuck in that one area of we're taking the alerts out of these few devices and they were repackaging and they're sending them out to you, and that's it. That's all we're really providing. And that's kind of the traditional way that it operated. You know, uh, in my career, I've worked with amazing service providers, and I worked with some service providers that weren't as amazing, unfortunately. And, you know, the really good ones were able to do more than just, again, you know, pull the data out of those devices. And sometimes they would just pull the alerts out of the devices, throw them into an email, and then shoot them to me. And then I'm stuck going, okay, so the device can send me an email with the alert, and you're sending me an email with the alert. So I've got double the amount of emails, I've got double the amount of alerts, and I have no additional context and no additional help. And, um, I'm paying twice as much. What am I actually getting here? Right. So then the good service providers were the ones that were saying, okay, what we're going to do now is we're going to actually eliminate the amount of alerts that you get. We're only going to send you the alerts that actually matter. And we're going to add context to that as well. And we're going to move beyond the idea of okay, we're going to base our service around a set of technology. And I think that is the heart of this. Right. The traditional concept of being a device babysitter is rooted in the idea of um, its tech, technology over people. When your service needs to be about the people, not the technology. So what are you providing beyond just you know, yeah, we can manage that device. Okay, what if that device goes away? Do they still need you? What can you provide beyond that device? So start planning your service for okay, it's not about that device or series of devices, it's about what we can do with that and what we can do without it as well. So adding context to the information that's coming from the device and then you know, being able to plan for if that device goes away, we can still provide these capabilities. Um, one thing I tell you know, service providers that are out there is let's say that uh, let's say your client has a reduction of cost and they have to cut their technology stack down to a quarter of what it was. Can you still provide the same value? Can you still provide the same outcomes? What can you provide beyond just I'm um, managing all these devices that are out there for you and then that way, you know, it doesn't matter if they add more tech, if they add less tech, whatever, you are still the root of their security and you are still essential no matter what. And it doesn't matter what their tech stack looks like.

Speaker A: Yeah, absolutely. And I think that serves as a perfect introduction to now looking at the uh, three pillars of what you could consider to be uh, next level services. Uh, in this regard, uh, and I had mentioned them a little bit in my intro but uh, let's take a look at each one individually and uh, the first one that I mentioned was uh, more comprehensive cross industry threat data collection. So basically meaning, uh, you're not just uh, collecting uh, information off of the various endpoints of one individual siloed client, but rather you're collecting scores of data points from across multiple clients, uh, corporations, businesses, uh, and then taking all of that information uh, together to even get a bigger picture sense uh, as to what's going on. So just talk a little bit about some of the challenges and opportunities associated with that and then I may uh, follow up with some questions.

Speaker C: Sure. So this is something I can't preach enough to, you know, just across industry is to bust out of silos, right? Because when you're working in individual silo, you have just a small set of data that you're really working with.

Speaker A: With.

Speaker C: If you are working with, you know, multiple clients or a vast amount of clients, think of those as individual components that you can use as a larger connection point, right? So essentially, if you see something malicious occur in one environment, you can use that data, you can use those indicators of compromise, you can use whatever you've identified to further inoculate all the rest of your clients. You should absolutely be doing that. You know, you have this wealth of information, this wealth of data that you could be threat hunting through, that you could be searching through, that you can use to again, further, further support your clients and further secure them. Uh, in the same way that you shouldn't have a single point of failure, you know, you shouldn't have individuals that are only assigned to maybe one piece of technology or one device. You shouldn't look at your data in only one area as well. Right? Because that's going to be again, that single point of failure. It's about building that larger data set to work from and building that, you know, that amazing lab almost, right? It's almost like a real world lab that you're living in and you're working in that data lake that you are, uh, experimenting with and searching through. And again, I said threat hunting. But there's everything that you can do with that information. And then you also find that, you know, across verticals, you mentioned verticals. And maybe you have one individual that's like, you know, I work in a very small area of, you know, one unique set of information. Why do I care about what happens in somebody else's environment? Well, because that could then bleed over into your environment. M. You never know. Right, because. Because you're using the same technology in a lot of, in a lot of situations, a lot of cases. Something, uh, like, you know, it was mentioned the Colonial pipeline, but there's also like the Solar Winds incident and there was the Microsoft, uh, Exchange incident not terribly long ago. Remember, these are built off the same technologies. So yeah, you may be working in different verticals, you may be working with different, uh, you know, different customers or whatever, but a lot of times you're using the same base technology. So we need to understand, you know, is there an exploit against that technology? Is there a weakness in that technology? Is there somebody that's targeting that and Then using that information to again help secure you and inoculate you from those threats.

Speaker A: Uh, you read my mind. Because that was going to be the follow up question I was going to ask, which is somebody might say, hey, I work in retail, I have point, uh, of sale systems, uh, what do I care what might be going on in a healthcare environment where they're using connected medical devices. But even though there might be some disparity in some devices that are using, there's also a lot of universal technology that apply uh, across uh, a multitude of industries. And beyond that, even if the devices are a little different, sometimes an attack or a campaign or set of campaigns against one industry vertical is a precursor to those uh, same threat actors, uh, starting to uh, delve into other uh, sectors as well. Somebody that attacks healthcare, uh, might move on to hospitality next or something like that. So it's always good to know what's going on, uh, in the bigger picture as well, isn't that right?

Speaker C: Yeah. Or let's think of it like this, right? Excuse me, but let's think of it like this. What is that healthcare industry doing? They're helping patients and at least in the United States they're not doing it for free, right? So they're getting paid, they're maintaining customer data and they're processing credit cards, they're processing financial information in the same way that that retail company is. That retail company is processing credit cards and maintaining financial information and working with large amounts of money. And that attacker might be going after that. Right? They may be looking for pci, they may be looking for credit card information, whatever it is. And so they do have that common ground. And they could be, you know, that may be an area right there where we need to look out for attacks against maybe uh, particular PCI equipment or whatever it may be. Or there's probably, you know, you mentioned point of sale. I guarantee in that healthcare industry there's probably point of sale equipment in there, there as well. You know, you go into a hospital and they have cafes, they have gift, uh, shops, whatever, and the attacker may see, okay, well I know there's an exploit against this POS device and then use that as a hopping point to get somewhere else in the environment. Again, there is a lot more common ground than we think. Just because we think we're in completely separate industries. It's not the case whatsoever. Like it is built on a very strong, you know, similar foundation of technology and we do a lot of the same things and then a common ground between the two. You're like, you know, well healthcare over here is very different than retail. Well, you say that, but what about pharmacies, which is a perfect blend of the two and is a perfect bridge between the two environments and then it's very easy to go from one to the other.

Speaker A: Mhm. Yeah, that is an excellent point. Uh, all right, well now let's look at uh, another one of the pillars and this would be uh, something else that can help provide uh, more data, more uh, overall, uh, context, uh, to the threat landscape that's going on that ultimately can help you do your uh, analysis and make your recommendations later. Which is ample use of threat intelligence, data science and security research. So how do you uh, use some of those various uh, feeds and reports, uh, to also then help provide a little bit more color to the data that you're collecting from the various endpoints?

Speaker C: Threat intelligence, especially for a service provider is so important because you're trying to provide value, value beyond what just the tool is doing. I'm going to go back to that concept you mentioned before, which is busting beyond being a tool babysitter. Right? Every one of those tools has built in alerting capabilities, which is they probably have threat intelligence, they probably have detection, uh, mechanisms, indicators of compromise, artificial intelligence, whatever they're alerting off of. Right? What can you provide on top of that? And then one of the best things you can do is use the telemetry from those devices and then add your own additional threat intelligence on top of it. Because you're adding something that they don't have, you're detecting things that they're not already detecting. So utilizing additional threat feeds and also developing your own threat intelligence, providing your own threat research is an amazing value to the customer. Right? It's something they can't get just from that device itself. Uh, they can, you know, they could potentially hire somebody else to babysit that device internally for them. But whoever they're hiring to babysit that device is not bringing in years of, of threat research and threat intelligence and indicators of compromise and detection logic that you can provide to the customer in the same way. So you want to find as much threat intelligence as you can, again developing it yourself internally and looking for those external feeds as well. Uh, what I'm not recommending though however, is just going out there and grabbing every threat intelligence feed and every source of threat intelligence and loading it into the environment. Because then you're facing the potential of uh, alert fatigue. Right, which is something we want to get rid of. So it's about then analyzing. Okay, let Me match up what the devices in the end customer environment looks like, the architecture, their, you know, their mission or the vertical that they're in. With threat intelligence, it's based around that as well. Right. And try to marry the two and find the best fit. That's something that not every customer is going to be able to do as well. They're not going to first know that there's external threat intelligence and if they do, they're not going to know which one's the best fit. So it's also acting as a subject matter expert and kind of a mentor of uh, hey, we can provide threat intelligence and we could also provide recommendations on the best threat intelligence for your environment that we can use to apply to really get high fidelity alerting rather than just more alerting.

Speaker A: Yeah, well again you read my mind because as you were starting to give the answer to my first question, I was going to say, uh, are there cases where you want to narrow down the scope of all of the feeds, uh, into something that might be uh, most relevant to your client? And then you went on to actually very uh, perceptually answer that question before I actually even asked it. So I think that gives us a really good sense of uh, that second pillar of threat intelligence. Uh, now let's uh, combine the uh, telemetry data that uh, uh, basically you are collecting across multiple sources, uh, and also uh, uh, the threat intelligence, uh, that you've been uh, collecting and filtering. Uh, and now let's take the third pillar which is just the actual analysis. Uh, so getting that more refined, contextual, relevant, meaningful analysis of threat telemetry data is really um, the third element of this. Uh, so I'd love to hear more about that including uh, and this kind of almost uh, a little bit combines uh, all three uh, pillars. This thing I'm about to ask, which is uh, just what in your mind right now is uh, the most important threat, uh, related, uh, telemetry data, uh, to be sure that you're collecting for your clients these days. If there's anything that's sort of trending in that area. I'd be curious to hear your thoughts on that.

Speaker C: Sure. So when we talk about, you know, how about the escalation of alerts first? You know, that is something that, is something that you can really provide to your client that is unique and is really necessary, is going through and paring down the alerts and only escalating the alerts that are truly high and critical. Right. Uh, your customer doesn't want to be overwhelmed, your Customer doesn't want to just be inundated with the alerts. They can, again, they can turn on every detection source on those tools and be inundated with alerts themselves very easily. They're hiring you because they want to pare down the alerts and they want to know, okay, no, you have looked at this and you have verified and vetted that this is a high fidelity, true alert that I need to move on. So being able to do that, uh, and that's just going to take time and practice and expertise and understanding the customer's environment. This is something I can't explain and, you know, can't really push hard enough, is don't treat every customer environment the same. Something that makes the company I work for unique is that we go in there and we learn the customer's environment as if it were our own. Um, and then that allows us to add the context to then say, you know, is this truly a critical alert? Is this truly a high alert? Or is this something that would be high in another environment, but not particularly this one? Right. And we want to get it down to as few alerts as we actually can. Uh, then going to that second part of that question, which is, is there a source of telemetry or an area where I would recommend people really look? In the research that we've done, we don't think that there's enough individuals that are really, you know, looking at cloud and cloud in context as well. Uh, I talk a lot, you know, when I'm talking to individuals out there about when it comes, when. When it comes to cloud. The entire industry has taken the approach of, can we not, should we? Right. They've adopted cloud so quickly and just integrated cloud into their environment, but they've not taken the necessary security precautions that they really needed to. Uh, some research that came out of Arctic Wolf about a year ago was, you know, there was a statistic that said a little over 99%. And I know it's weird when I say that over 99% of organizations are using some form of public or private cloud. Right. There's like 99.3 something there. But only 18% of those that we found were using some form of CSPM or active cloud monitoring and management. That's about 81% of environments they're not really actively monitoring and prepared to respond to their cloud incidents. That's a vast amount. And you think about, okay, so that is a huge gap that attackers are probably either infiltrating, Right. So they're coming in through cloud or worse, they're exfiltrating data through cloud. You know, the top of the hour you talked about a certain group of uh, casinos, uh, that had a big data exfiltration. I would assume that's probably exfiltrated through cloud through some mechanism or another. They're not putting it out of USB and not walking it out the front door. Right. And they're probably not just throwing it out through email. They're probably slowly leaking it out through a cloud source that's not being monitored and it's not being properly secured. So it's important that we monitor our cloud very closely. But we want to monitor it in context and in balance with all the other telemetry that's out there. I look at it as a balancing act. If we want to look at the network, we want to look at the end ports, we want to look at the exact endpoints, the log sources, the cloud, we want to look at identity, right. And authentication, we want to look at all of it together in one big picture and then actually allows us to identify our. Again, goes back to my previous point, allows us to identify those high fidelity alerts. Or is this truly an alert that we need to move on?

Speaker A: And it's not just uh, managing the security alerts and knowing when to escalate to a client. It might even be a situation at times as critical as do we need to move fast and respond to a budding incident, uh, by taking some kind of uh, remediation, uh, action like a quarantine or something where you really want to make sure that you have the proper justification and grounds for doing so, uh, or if you at least have to quickly escalate, uh, to get permission or act, uh, immediately. Uh, do you think that, uh, again, as things continue to evolve, will there be uh, an increasing reliance on uh, artificial intelligence and machine learning to help with making some of this analysis and decisions for what action to take. Uh, is it going to continue to be, uh, a uh, hybrid mix of human decision making and AI based decision making?

Speaker C: I think there's going to be increased reliance on AI, but just as much reliance on a hybrid approach. Right. You're not going to be able to take humans out of the loop because personally, personally I would never trust an automated response to do those containment actions or to do any kind of, you know, uh, response capability on its own without a human as a check and a balance for that. Because the moment you do is the moment that an attacker could come in and actually utilize that against you and essentially doss your environment. Right. I mean if you have the artificial intelligence going through and isolating the systems based off of, okay, okay, this looks suspicious. Well then you can have suspicious activity in multiple devices and suddenly they're all locked down. And those could be the same devices that are doing very important things throughout your environment. So yes, an increase in artificial intelligence as a tool to assist the individuals or the humans. So we need to remember that AI needs to be a tool that is utilized to empower and increase the individuals, not to replace them them. And in any, you know, in no situation we need to see is, okay, well I just purchased this, you know, this tool so I can get rid of some of my analysts or I don't have to hire some analysts. Absolutely not the case. You're probably with that, ah, AI, uh, going to get even more noise now and you're going to have to have individuals that monitor it and work with it 247 which is fine because you're going to get more alerts and you're going to get more capabilities, but you're also going to have to use it correctly. So I think AI is something that's very beneficial. But again I can't stress enough. It is a tool. It is not a replacement for people.

Speaker A: All right, Christopher, well thanks, I appreciate all of your perspectives and analysis on this and hopefully it helps our uh, managed services audience today uh, in terms of building up from that ground floor and adding additional uh, tiers of services and expertise, uh, to their uh, offerings to help in that uh, always evolving race with the bad guys. So uh, thanks again for your time here. Before we go, I uh, do wanna do one uh, last bit with you that we always do at the end of our first half of our show. And it's a little segment that we like to call We Speak Geek. Geek. Now we speakgeek is basically a celebration of the geek and nerd culture that is so often associated with uh, the cybersecurity community. After all, we're were all a little bit geeky about something and so I'd like to ask you today, uh, Christopher, how do you speak geek?

Speaker C: Yeah, so my, I would say geekiest or nerdiest thing is I am a huge Batman fan. Uh, I have an entire tattoo sleeve dedicated to Batman. Um, it was the first, the first movie I ever went to in 1989 was 89's Batman. Uh, it was a sold out theater. I went with my stepfather. They had one seat left. My stepfather bought it, snuck me in and I actually sat on his lap at uh, about five or six years old and watched the very first Batman. And it's been my favorite, uh, favorite thing ever since.

Speaker A: All right, now, you said that you were going to actually share with us who you think the best Batman is. So this is gonna. This is gonna cause a little controversy here, I have a feeling, who was the best Batman on screen.

Speaker C: Okay, so.

Speaker A: Okay, that's.

Speaker C: That's the thing. So this, uh, separates real Batman fans from, you know, artificial Batman fans. But I believe the single best Batman of all time is Kevin Conroy. And if you don't know who that is, then you're not a real Batman. So. Kevin Conroy.

Speaker A: You know, I was actually wondering.

Speaker C: Yeah, Yep. So Kevin Conroy, go ahead. Yes, absolutely. Kevin Conroy is, to me, Batman. He embodies Batman everything. In fact, if you've heard him in behind, like, the scenes or in interviews, he almost. He has an understanding of the character that almost no other actor has as, uh, and I on screen, I believe that he is the best Batman because he's done, you know, animated movies. And if you're a fan of the CW shows, he actually played a, uh, kind of Kingdom Come version of Bruce, uh, Wayne. Batman in a couple of episodes. So, you know, rest in peace, Kevin Conroy. To me, he will always be the true Batman. He is who actually Batman is. Now, if we're going to argue about somebody that's actually put the costume on in a legitimate movie, movie that's a little bit different. You know, um, when you say who is Batman? It's very personal answer. Like, if you ask somebody who is Doctor who, they say who their doctor is. That's the first person they saw. Right. To me, uh, my Batman is Michael Keaton, like, because he was the first Batman I saw. I have a great affinity.

Speaker B: I agree with that.

Speaker C: Yeah, right. But I have a great affinity for Adam west as well. I think he was just, uh, so campy and so fun. Uh, if I had to put them in order, and this is really geeky.

Speaker B: Right.

Speaker C: I would probably say that it would go Kevin Conroy 1, Michael Keaton 2. Uh, Adam West 3. And then we get into the Christian, uh, Bale 4. Controversially, uh, probably Robert Pattinson 5. Uh, and then I would probably Val Kilmer and then put, uh, what's his name? Danny Ocean at the very bottom. I forget his name right now. Now, uh.

Speaker A: Oh, Ben Affleck. Oh, oh, no. Uh, uh, uh, George Clooney. And you forgot. And, and. And. And you. And you forgot all about Ben Affleck, which I think says a little Something about his.

Speaker C: I didn't forget him. I pretend that one doesn't exist.

Speaker A: Okay, fair enough. I, I, I, uh, think I actually pretty much, um, almost exactly in line with you on this. Maybe Adam west gets a little further down from because of the campiness, but otherwise, I think I mostly pretty much, uh, all agree with, uh, everything that you said. Uh, yeah, Michael Keaton, Kevin Conroy, and of course, uh, um, Kevin Conroy matched up perfectly with Mark Hamill. Luke Skywalker, who voiced, uh, the Joker. So, uh, last question before we go. Were you excited to finally see, see Michael, uh, Keaton, step back into the cape and cowl for the Flash movie? And did it.

Speaker C: I was so.

Speaker A: Bring back all of your nostalgic memories there.

Speaker C: I was so excited to see it. And then I was so.

Speaker B: That movie was a freaking mess, though.

Speaker C: So hurt. I was so painfully hurt by how it actually turned out. And then if. I don't want to give anything away, but if you, you know, listen to what I just said a few minutes ago and then watch the very end of the Flash movie, and it's just like a punch in the gut. It's just, just awful. Uh, I, I want so much more for Michael Keaton. So, uh, but you know what? I've heard that There is a Beetlejuice 2 coming out with Michael Keaton, so hopefully that's a redemption arc for him. And, uh, at the end of the day, I just love Michael Keaton. I just think he's an amazing actor and just a, uh, really good Batman. A really good funny actor all around. So we'll see. Fingers crossed.

Speaker A: Yep. Agreed. Maybe there's still a chance he'll, he'll do that Batman beyond project he was recommended for.

Speaker C: I hope so.

Speaker A: Uh, all right, well, you know what? We could talk about this all day, but unfortunately, we can't. We've run out of time. But that was a lot of fun. I appreciate it. Uh, but, uh, for everybody else, please stick around because there's still another half of the show, uh, left to go. We're going to be, uh, discussing our big idea in security coming up next, which will focus on some interesting research on Endpoint Security that was recently conducted by the Cyber Risk Alliance. That and more coming right up. So. So we'll see you in a moment on the other side. All right, welcome back, everyone, to Cyber for Hire, the managed security podcast. Once again. I'm Bradley Barth with Cyber Risk Alliance. In the first half of our show, we talked with Christopher Fielder at Arctic Wolf about leveling up your SecOps program. Right now I'd like to welcome back my co host for the day, Bill Brenner, because it's time for us to examine our managed services infosec topic of the week, presenting our big idea in security, endpoint security. Entering the era of AI and xdr. Endpoints are everywhere and come in many forms. And especially in today's BYOD environment, it's becoming increasingly difficult to maintain visibility and control over all of them. Unfortunately, rogue endpoints represent an enticing attack vector for adversaries who are always looking for a way inside your network. But According to an August 2023 Cybersecurity Buyer Intelligence survey of 200 security and IT leaders and executives, security professionals are actively working to address such threats with a mix of mfa, strong password policies and training. And they're hopeful that newer, more advanced tools like AI and XDR could help minimize endpoint compromise. This session will analyze this and other key findings from CRA's Endpoint Security Research and what the results mean from an MSP perspective. Uh, Bill, glad you're back with me. And as always, we're going to jump, uh, right into things. So let's start by having you paint a picture for us based on the responses from this survey, uh, about uh, how serious of an issue this is in terms of overall endpoint sprawl and why it is important to be constantly building out your solution stack to protect these endpoints.

Speaker B: Yeah, so the interesting thing about this research is you have to squint to see it, but you start to see a shift in focus for a lot of our respondents. So what I mean by that is, for years now, the central piece of an endpoint strategy has been we need to protect the end users from themselves. They cannot be trusted or relied upon to, you know, not fall for every hook that's out there. And what we see in, in this particular survey is security professionals moving on from. I mean, that's still very much the case, but this report focuses more on the what to do about it. And what's interesting here is the priorities as a lot of these respondents are going into 2024. So, for example, artificial intelligence and machine learning is the Most planned for 2024 endpoint security investment. Um, that's followed by things like XDR. And what you see here is respondents are moving beyond the basic EDR and reactionary tools. So they're trying to get ahead of threats by using technology that raises contextual awareness. So XDR is a great example of that and anticipates threats much more quickly. Which obviously that's where AI comes in. And uh, in our last segment Chris had mentioned this where AI, it's a tool, not the be all, end all. But this puts into clearer focus with something like Endpoint Security where AI is seen as the tool. Um, some other things that were interesting to me was um, certainly not surprising but it just stood out as an ongoing highlight where three out of five respondents admitted that they've had to deal with one or more compromised endpoints in the last year. So that's not a sky is falling kind of thing. It's been there. But when you consider this, that 63% of respondents reported having a thousand or more endpoints on their network, um, that translates into a lot of compromise and it's just, it shows how difficult it is to stay ahead of the threats that come via the end points.

Speaker A: Um, yeah, no, that makes a lot of sense and is a very clear indicator of that sprawl uh, to which I was referring. And yes, uh, the increasing uh, adoption rates that we'll see moving into 2024 and beyond of AI and XDR, uh, does seem to uh, indicate an interest in having more of that uh, contextual uh, intelligence uh for Endpoint Security, um, also in the interim, uh, while ah, AI and XDR seems to be uh, the future focus. Uh, I know there was also a question about uh, currently uh, which endpoint security practices are most commonly implemented. Uh, can you share with us a little bit about what are some of the most um, common uh, technologies right now that are currently being implemented and maybe a couple that might be surprising that are less of a focus. Maybe that's an area where MSPs and MSSPs can step in if those particular projects ah, aren't uh, taking place uh, on an in house basis.

Speaker B: So there's one good example to look at. Um, if you're an MSSP or an MSSP and you're doing business with security vendors in the channel, you know that Sophos is an example of a company that's been um, heavily active with that, as is Arctic Wolf. And uh, what you see in those areas is a lot of discussion around MDR managed detection response, um, as a way to deal with a lot of things. But certainly Endpoint is one of those them. Um, and I think what you see here is everybody is looking for this unified source of data that they can then see. I hate to say things like single pane of glass, everybody says that but it is true. It's where can we see everything on one screen and get the context, get where our priorities need to be in responding. Um, and so you see that at play big time here.

Speaker A: Yeah, for sure. And, uh, I know another, uh, focus of the research, uh, was, uh, asking some of the security professionals, uh, some of the top challenges in implementing Endpoint security. So what are some of the biggest barriers that you found there are currently to overcome, uh, for these implementations to become more successful?

Speaker B: So, nothing particularly new here. Um, and I mentioned it at the beginning. It's the end users, the idea that you cannot possibly get all end users, most end users, for that reason, to do all the things they need to not fall victim to, things that compromise their endpoint, that compromise their device. Not because people are stupid or they don't care. It's just when you're using multiple devices every day to do all of your work, um, you're focusing on that work and you're not thinking all day long about I shouldn't do this or I should do this because this could compromise my endpoint. You know, it's, you're working. And so it's, what can MSPs do to take that responsibility out of the hands of the users? You still need to educate, you still need to raise awareness, you still need to get as many end users as possible to do the right things and make the right decisions. But at the same time, it wouldn't be fair to put the full burden on the user who's just trying to get through life every day. And I think that is where MSPs can really make a difference. And I think the way they can make the difference is through the use of XDR MDR tools like that that bring the picture together into better focus.

Speaker A: Yeah. Uh, so before we wrap up this segment, Bill, I, uh, know that the report did have some, uh, final recommendations for readers. Can you summarize a couple of key ones for us?

Speaker B: Yeah, I mean, I think the big one, and I'm at risk of sounding like a broken record, is, um, you need, we've spent years collectively as a community, um, buying a lot of products to try and deal with every threat that comes zipping around the coin corner. But context is key, and so it's important to be looking at what you can do for your customers through use of AI and machine learning. Um, if you're not using something in the realm of XDR or mdr, um, my personal opinion is you probably ought to be. Be. Not probably you ought to be. Um, but that's pretty much a reflection of the takeaways in the report.

Speaker A: Excellent. Uh, well, great. So, yeah, for anybody that's, uh, interested. Uh, Bill, just real quick, you want to just let, uh, folks know where they can get their hands on this report?

Speaker B: Yep. So you can get your hands on the report by going to, um, SC Media, where all of these reports are kept. And also you could visit the Cyber Risk alliance website, where if you, um, go under resources, you will see that we have a press release and link to the report landing pages for all of these.

Speaker A: All right, so be sure to do that and check that out and read that report for additional insights and perspectives on endpoint security. And with that, we've reached our endpoint. We are officially out of time, but I'd like to once more thank Bill Brenner for joining me as my guest co host today. Uh, meanwhile, to everyone else watching, feel free to check out even more cybersecurity podcast content on the MSSP alert channel, E2 and SC media websites. Until next time, I'm Bradley Barth. Please reach out to us via our show page with your comments, questions and insights about the business of, uh, cybersecurity. We'll keep the conversation going on the next episode of Cyber for Hire, your inside source for cyber outsourcing.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • 🌐 Cybersecurity Unmasked 🌐 EP 35: The Blueprint for Seamless Expansion: Centralizing IT Operations Across the GTACybersecurity Unmasked · on SIEM (Security Information and Event Management)80 / 100
  • Debugging Developer Productivity in an AI-native World with Aravind Putrevu (CodeRabbit)ShipTalk · on SIEM (Security Information and Event Management)72 / 100
  • Marketing & Sales Disconnected? These Tips Will Get You On the Same PageChecked In with Splash · on Arctic Wolf71 / 100
  • XDR, EDR, SIEM, SOAR…Snooze: Cybersecurity Marketing Real Talk with Gianna WhitverHuman-Centered Security · on XDR (Extended Detection and Response)71 / 100
  • Navigating the Cybersecurity Maze, with Geoff MooreIT Matters · on XDR (Extended Detection and Response)67 / 100
  • 210: The One About the Future of Cyber WarfareThe Government Huddle with Brian Chidester · on Colonial Pipeline attack63 / 100

More from Cyber For Hire

All episodes →
  • Supply Chain Security: How Moving Accountability Upstream Helps & Hurts MSSPs - Dave Sobel - CFH #29
  • Balancing Dark Web Threat Intel: Fair Attention for MSSPs - Alex Holden - CFH #28
  • Brian Johnson - CFH #27
  • M&A Integration Challenges & Alert Fatigue: MSSP Strategies for Client Escalation - Jim Broome - CFH #26
  • Quantifying Risk & Optimizing Responses: Scaling Your MSSP for Reduced Randomness - Ira Winkler - CFH #25
Explore the best B2B Ops podcasts →
All Cyber For Hire episodes →