The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Startups & Founders/MSP Business School
MSP Business School artwork

Frank Raimondi | Continuous Vulnerability Management in the Age of AI

MSP Business School · 2026-06-23 · 23 min

0:00--:--

Key moments - from our scoring

Substance score

32 / 100

Five dimensions, 20 points each

Insight Density7 / 20
Originality6 / 20
Guest Caliber9 / 20
Specificity & Evidence5 / 20
Conversational Craft5 / 20

The conversation centers on how AI is fundamentally changing the vulnerability landscape for managed service providers. While initial concern about AI replacing vulnerability management tools has faded, the reality is more nuanced: AI tools are discovering vulnerabilities faster than ever, compressing the timeline from discovery to exploitation from days to hours. Frank Raimondi emphasizes that continuous vulnerability monitoring through tools like Nodeware - pulling daily CVE and KEV (known exploited vulnerability) feeds - is now more essential than ever. Beyond vulnerability scanning, the discussion pivots to shadow AI: employees unknowingly using free AI tools like ChatGPT, Claude, and Gemini to process sensitive customer data, financial information, and IP, inadvertently training large language models with proprietary information. This poses compliance risks (particularly under CMMC and privacy laws like Massachusetts regulations) and requires MSPs to position themselves as managed information providers (MIPs) who can educate customers on AI policy, data governance, and readiness assessments. The speakers argue MSPs have an opportunity to step up as trusted advisors on AI strategy rather than ceding this relationship to external consultants, but only if they proactively educate customers and define relationship boundaries around AI.

Key takeaways

  • →AI is discovering vulnerabilities faster than zero-day timelines previously allowed, making daily vulnerability scans and known exploited vulnerability (KEV) tracking essential rather than optional for MSP customers.
  • →Shadow AI - employees using free generative AI tools to process sensitive data - poses greater compliance and data exposure risks than traditional phishing threats because it happens innocently at scale across all departments.
  • →MSPs should position themselves as managed information providers (MIPs) by educating customer leadership on AI policy, data governance, and readiness assessments rather than treating AI as a technology problem to solve.
  • →Enterprises haven't yet mandated paid AI tool versions for employees, leaving organizations exposed to data leakage through training of large language models, making AI governance and user education the immediate priority.
  • →The MSP that doesn't proactively address AI strategy with customers risks losing that relationship to outside consultants or non-traditional IT vendors positioned as AI experts.

Guests

Frank Raimondi

Topics in this episode

shadow AIPenetration testingCMMC complianceNodewareContinuous vulnerability managementKnown exploited vulnerabilities (KEVs)AI policy and governanceManaged information provider (MIP)Vulnerability scanningIGI cybersecurity

Questions this episode answers

How is AI changing the timeline for vulnerability exploitation?

AI tools are discovering vulnerabilities and enabling exploitation much faster than the traditional zero-day model; the window between discovery and attack has compressed from days to hours or less, making continuous monitoring rather than monthly or annual scans necessary.

What is shadow AI and why should MSPs be concerned about it?

Shadow AI refers to employees using free generative AI tools (ChatGPT, Claude, Gemini) to process confidential company data, customer information, and IP without authorization, which trains the AI models with proprietary information and creates compliance violations under laws like CMMC and Massachusetts privacy regulations.

Can AI tools and large language models replace traditional vulnerability management?

No - while AI can discover vulnerabilities faster, human interpretation, prioritization, and remediation expertise are still required; the real value of tools like Nodeware is the daily threat analysis and integration with compliance frameworks.

How should MSPs position themselves to capture AI-related opportunities with customers?

MSPs should position as managed information providers offering AI readiness assessments, policy development, data governance education, and employee training rather than treating AI as a technology implementation problem; this positions them as trusted advisors rather than vendors.

What compliance risks do companies face from employee use of free AI tools?

Uploading customer lists, financial data, or other contextual information to free AI services violates privacy regulations and creates liability; for example, even a simple name and email list could violate Massachusetts privacy laws if processed through unauthorized AI tools.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

7 / 20

A handful of useful observations surface - AI compressing exploit timelines below zero-day, shadow AI as the next shadow IT, the MSP-to-MIP framing - but they are buried under filler, mutual affirmation, and vague hand-waving. The episode rarely moves past acknowledging a problem to explaining how to act on it.

there used to be a sort of zero day or infiltration plus 10 before something might happen. Well, now things are kind of happening before they even get on site. So there's less than a zero day impact.
the shadow AI is, I think you'd probably, God, if I was a business owner today, that would, I mean, you know, I would be that much more concerned

Originality

6 / 20

The shadow-AI-as-shadow-IT parallel and the MIP reframe have some freshness, but neither is developed with first-principles rigour; both are borrowed from community conversations (GTIA). The rest is standard AI-changes-everything commentary with no contrarian or counterintuitive arguments.

the managed service providers becoming really almost a managed information provider
tokens become the new oil, if you will

Guest Caliber

9 / 20

Frank has genuine channel and vendor experience spanning Intel, Apple, and TD Synnex, plus current operational responsibility at a real vulnerability management company - so he is a relevant practitioner. However, his role is alliances and BD rather than hands-on technical security, which caps the depth of insight he can deliver.

I manage our alliances and partnerships and sort of large accounts for NodeWare
long history around big companies like Intel and Apple Computer and Cynics. Before it was TD Cynics. So I've been around partnerships and alliances

Specificity & Evidence

5 / 20

The only concrete example is a brief anecdote about a CISO planning to feed CMMC requirements into Claude - useful but undeveloped and data-free. No metrics, no named breaches, no remediation timelines, no customer outcomes, no pricing or ROI figures are offered anywhere in the episode.

we had a customer discussion last week that we were approaching regarding the CMMC sort of surface, right? It's a big company, you know, and one of their CISOs actually just said it... Basically, we'll throw the compliance, the regulations into Claude and have that compare it to what we have internally
uploading, you know, customer lists, which may only consist of, you know, individual name and email address, but it's still contextual information in Massachusetts. That would be enough to be in violation

Conversational Craft

5 / 20

The host frames the conversation as deliberately low-stakes from the outset and never challenges a claim, asks for evidence, or probes a mechanism. Questions are broad and leading, and the guest's product plugs go completely unchallenged. The dynamic is two friendly acquaintances agreeing with each other for 23 minutes.

I don't think we're going to go so hardcore on, you know, things that we typically talk about, right?
I always learn a little something too, when you join me

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

tools15today12vulnerability11customer11frank10everybody10better10nodeware7help7world7seeing7security7somebody7quickly7tool7back7

Episode notes

Join Brian Doyle in an engaging episode of MSP Business School as he welcomes Frank Raimondi from Nodeware, a frequent guest and expert in cybersecurity and MSP strategies. This discussion veers from the typical focus on specific technologies, diving into the transformative impact of AI on security and technology advancements. Frank shares insights from his extensive background in vulnerability management, discussing how AI affects the landscape of cybersecurity and the role of MSPs in navigating these changes. In this episode, Doyle and Raimondi explore how AI is reshaping industries and the increasing need for security vigilance. With the rapid emergence of AI tools, businesses face new vulnerabilities that MSPs must manage effectively. Raimondi emphasizes the importance of continuous vulnerability management, highlighting how tools like Nodeware play a crucial role in protecting company assets. They also discuss how AI is enabling faster detection of vulnerabilities and the necessity for MSPs to guide organizations in crafting AI policies to safeguard their data and operations.

Full transcript

23 min

Transcribed and scored by The B2B Podcast Index.

Hey, everyone, welcome to the latest installment of MSP Business School. As always, I'm Brian Doyle. And with me today is another friend of the show. Frank has joined us a couple times now, and he came in today as a late game pinch hitter for me, which I really, really appreciate.

That's one of the beautiful things about Frankie. He, as a friend of the show, he'll jump in anytime that we've got a moment. Anytime you need me to talk, I'll talk. So I want to welcome Frank Ramondi from Nodeware to the show.

Thanks, Frank. My pleasure, Brian. Great to be on. And, yeah, I don't know if that's a good thing or a bad thing that I'm available when you need me, but I'm here for you, man.

No, what makes it a good thing? One, you know, love to have you on. We always have a fun time chatting. But it also gives you more times at bat, right?

You know, those of us that are willing to help others out tend to get a little bit more FaceTime and visibility, right? So it's never a bad thing. So with that being said, today's going to be a little bit different. I don't think we're going to go so hardcore on, you know, things that we typically talk about, right?

You and I have had many conversations about vulnerability on its own, but more about really the changing pace of technology. and then where things like vulnerability and advisory and those kind of things are, you know, really coming into play. So, you know, why don't we kick off first, Frank, for anybody that doesn't know who you are, maybe a little bit about your background, and then we'll jump in and kind of talk about the accelerating technology world that we live in. Perfect.

So, yeah, so I manage our alliances and partnerships and sort of large accounts for NodeWare, And we actually have two parts of the company, IGI cybersecurity, which does penetration testing, compliance readiness, VC, so types of things. And then NodeWare is our software arm of the company, vulnerability management, threat exposure types of things. But I've been around in channels for a long time, a little less time on the software and MSP world, sort of the last five to 10 years.

but long history around big companies like Intel and Apple Computer and Cynics. Before it was TD Cynics. So I've been around partnerships and alliances and really value the community element. And it's another thing we have in common around GTIA, and we can talk about some of that.

But, you know, again, as you said, less about some of the products today, I have a more, I think, the understanding of the speed of things happening and what that implies for an MSP. I can forgive my perspective, and you're seeing it as well. Yeah, I mean, look, the word that everybody's probably getting tired of hearing all the time is AI, right? But the reality is AI, forget about what it's doing from a productivity efficiency, all those kind of standpoints.

It's really becoming a very big security concern too, right? And, you know, we're hot on the heels of the announcement of, you know, of Fable 5 going live and then Fable 5 coming offline. And, you know, and I think some of that is trying to put some guardrails around what's going on. But, you know, Frank, as somebody that's been in the vulnerability sector for a long time, it's certainly changing how we need to look at vulnerability, vulnerability scanning, those kind of things.

Yeah, no, absolutely. You know, it was sort of when we sort of first became sort of the real evident piece and was going to change things. Oh, shoot, we're done for, right? You don't need the vulnerability management.

AI is going to do everything. And then it was like, you know what? Not really. I mean, AI is going to make changes everywhere, everything, every day, right, that we deal with.

But I think if you look at the devices and the access into environments, right, and what AI can detect and how quickly it can detect. I mean, we've already seen some of the, you know, the vulnerabilities that are just discovered by random AI bots doing things within a system. Well, that's producing, in a traditional sense, a CVE, right, or a new vulnerability that's found. but it's finding them that much quicker.

And I heard somebody today, I was on an earlier call, about there used to be a sort of zero day or infiltration plus 10 before something might happen. Well, now things are kind of happening before they even get on site. So there's less than a zero day impact. And if you're not looking at the devices and the software that's on them and the open ports and the access to things, on a daily basis, hourly basis, then you're really missing the boat and increasing the risk for your customer.

So the AI kind of, again, will expedite things, you know, or find things out more quickly, which is why, which kind of reinforces why you need a tool like, again, not to be too commercial here, but a tool like Nodeware or any of the other vulnerability tools that is looking for those and, you know, gets a daily download, right? We get a daily download of all the new CVEs, and particularly KEVs, known exploited vulnerabilities, that get published. And those are gonna come quicker now because they're being found and being discovered by some of the AI tools.

But if you're not looking out for that and getting alerted of when a new one's been found in your environment or your customer environment then you just waiting for disaster right So these tools I think are you know even more critical potentially than they have been before And I think you've hit upon a few things that have really come out of, you know, as AI emerges that are becoming realities, too. You know, you spoke at the top of, you know, that conversation thread that, you know, people were thinking, oh, maybe we'll go build our own, right?

And I think very quickly they're looking at it saying, yeah, we can build and go maybe do a scan, but then we got to know what to do with it. And that's where companies like yours have the security professional expertise to better understand what's coming in, what really needs to be worried about today, what might be something that you can kind of let slide a little bit further. And you're seeing more of that around everything AI, right? Like, you know, you can build almost anything in AI and you can build it quickly.

Can you maintain it? Can you interpret it? Can you act upon it? Can you stay up and stay current with it?

And I think, you know, what was feeling like a little bit of a threat to a lot of software companies, you know, ours included, right, yours included, is becoming a little bit less because we're starting to see, well, A, things don't come free. B, you still got to have the expertise sitting behind it. And then, you know, C, as tokens become the new oil, if you will, can we actually operate it and sustain it long term? And, you know, and similar to that, it's these exploits are coming much faster because that access is available to us.

Can we actually remediate them quick enough? And, you know, certainly that's the key part, right? I mean, I think, you know, the AI tools and we have some AI tools within us, as do you. And there's things that can be discovered more quickly, right, or more efficiently by the same number of techs and, you know, analysts.

But you still, as you said, you still got to do it. But one of the sort of we had a customer discussion last week that we were approaching regarding the CMMC sort of surface, right? It's a big company, you know, and one of their CISOs actually just said it. Kind of we were like, really?

Basically, we'll throw the compliance, the regulations into Claude and have that compare it to what we have internally, and it'll tell us what we need to know and what we need to fix. and was like, okay, good luck with that for one. You know, you might get some of that, but again, the interpretation, as you say, the analysis and the prioritization, right, of that real-world situation is going to be critical. And then, again, it's ultimately getting it prepared for the final audit, the final people that are actually going to put that stamp of approval on that or not.

So it's going to help, right? But as you said, I think it enables sort of exemplifies or strengthens the need for the tools that are doing the grunt work, right? The real analysis and the up-to-date current analysis. Yeah, but, you know, again, AI is an amazing concept that's going to be here to really drive change moving forward.

And I think all of us are excited about the fact that it helps us get to some problem points we all had as vendors, potentially in our innovation pipeline and getting there faster. And that's one of the things I'm seeing. And of course, that means everybody benefits. But as we see with Fable 5 being pulled back, there's also some real-life concerns that come with innovating too quickly and making sure that we can approach things the right way and making sure that these tools are used right by the good guys and not getting exploited by the bad guys, if you will.

Yeah, yeah. No, and I'll reference, you know, your article you just posted today when this was being recorded on the MIP, right, from the MSP to the MIP and that information, you know, whether it's, again, sharing, you know, using it internally, sharing with your customers because, you know, any MSP, I'm sure they get 10 inquiries a day. Oh, I saw this tool. Is that, am I going to be impacted by that?

Am I going to need this tool? And if you're using the information wisely, you still got to do your core deliverables, right? There's no getting around that. And those might get some better efficiency on them.

But maybe I could stand for interpreter, right? I mean, you're interpreting things for your customers differently now, and you have better tools to do that. But, yep. And I'll say for the listener, if you don't know what Frank was alluding to, I put up a post about, you know, the managed service providers becoming really almost a managed information provider.

And that's where the I can also be very easy interpreter, right, as well. But that's not something, you know, I coined, I think both of us can, you know, agree. We started hearing a little bit more about that, probably starting with GTIA's, you know, communities and councils event and then going forward, you know, but it really comes down to, you know, when we think about what our customers need now. We've got digital natives in the seat of making decisions.

It's not like when you and I started where there was a lot of trying to help people understand what the solution was going to be and why they need to make the investment. Now it's, hey, how do I get more out of what I got? How do I get to my results faster? How can I better build better outcomes for my organization?

And there's never been a better time for the MSP to really level up their game, if you've been wondering how to get more strategic or how to position yourself better with the customer, AI is probably your easiest avenue, if nothing else, just, you know, sharing with a customer, hey, this is what it is. And this is why you got to care. And you and I is, you know, at our core security guys you know inside of ourselves And we looking at it as and you got to know what going on amongst your people because bad things can be happening without you even knowing it you know right there in your own environment Ultimately I think you know kind of like shadow IT has always been that right People bringing in their own device and having access.

But, you know, the shadow AI is, I think you'd probably, God, if I was a business owner today, that would, I mean, you know, I would be that much more concerned. And I don't think they're there yet, right? I think they're kind of just still sort of seeing it as, oh, this is kind of cool. You know, everybody, go ahead.

But how you protect the data they're accessing, you know, what they're providing now, what they're using it for. And I don't know that - have you seen many good tools yet for an MSP to help with that? Well, no, that's the challenge. I mean, you know, obviously folks like John Harden over Lemhi are trying to find some better ways to do that.

And, you know, they came to life a couple weeks ago, as many of the listeners know. And, you know, there's certainly some other tools out there, but I don't think anybody's got a panacea for it. And the reality is it comes back to that user education, right? Just like we have phishing testing.

It's almost like the security and awareness tools really need to start bringing in AI concepts into those tools as well, because I think the threat's even more than me clicking on the wrong thing. Like, you know, it used to be, oh, you got that text from your boss saying to go get the gift cards. And, you know, there might have been a $50,000 problem, but now you're talking about potentially exposing your entire financial information or putting your customer list in and really or your IP into AI totally innocently, totally being done by somebody that doesn't know any better because they saw a video that said, hey, you can get better controller reports as, you know, in finance if you do this.

And those people are trying to make a name for themselves. They don't understand, you know, the other side of this. Hey, you're using a free tool. That's training the LLM.

that information now becomes part of it you know and and all the things that go with and i it's to me that's the scary part right now like you know somebody can do something totally inadvertently and truly innocently that can create much bigger havoc than i think even the phishing threats were it yeah yeah it's funny just just you know i've been using gemini a bit i used some clod you know i haven't really used open ai or chat gpt very much but the other ones but you know you you ask at you know compare these two things or you know tell me about these two companies and and you it's just it's easy it's easy to forget what is public and what is what you're doing as you said training them yeah what are the things that people want to look at and and it's just yeah as old farts like us right it's like it's like this is this is this is a little scary well you know this shadow it part was always scary because you know i used to always make fun of the marketing groups, right?

And which I feel like I can do because being part of that world, you can do it. But, you know, marketing is constantly trying new tools, right? To try to get engagement, those kinds of things and uploading, you know, customer lists, which may only consist of, you know, individual name and email address, but it's still contextual information in Massachusetts. That would be enough to be in violation as an example of some of the privacy rules there.

And, you know, it happens every day. And nobody meant to do anything wrong. They just wanted to find a way to get a competitive edge. And I'm just seeing AI being the same way, but I think it's a little bit more widespread.

It's across all departments. Everybody can have a use case for it. And I think businesses haven't gotten yet to that point where they're at least saying, hey, let's buy, you know, buy pro versions for everybody. So we're in control of what goes out.

Or, you know, certainly we need to get AI policies drafted and have AI policy, you know, education events internally because it is happening so fast and everybody's certainly seeing the benefit. You just sort of springed a thought and, you know, sort of the cost benefit, right, or the cost analysis, right? If you say that the pro versions, right, what is that going to cost per employee? Okay, does that, you know, I got to put another thing in my IT bill, right?

I mean, you know, the same was with vulnerability management, you know, a few years ago, people, you know, I can just do it once a month or once a year checkbox and I'm good. It's like, no, right, you need this. And so all these things, you look at a security stack of an MSP and the amount of items on there, it's just really just humongous, right? Humongous.

And so, you know, adding another AI tool and maybe, you know, I guess people probably are a little bit more open to grab that in. But, you know, but again, it's another aspect of cost that you need to do. So that may be some value of the positioning. Maybe you have some other people you can bring on to talk about that is how do you really position, you know, the value of doing some of these tools and the cost benefit and the, you know, just the security value of doing that.

Well, I think it goes back to the whole MIP conversation, right? Because really, this is where the service provider has an opportunity to step up and a little bit more neutral, too, because I don't think, you know, obviously, there's now ways that we can sell AI as a community. But I think a lot of folks are still looking at it going, all right, the customer's using X and how can we get control around it? But really, it's educating the leadership at a company and saying, hey, here's what we're seeing.

here's what's the reality. There's a lot of noise around those two letters, but here's the reality. Your teams are using it whether you know it or not Is your information protected Do you have a policy to govern them So if you see somebody using it the wrong way forget about everything else You can terminate them if it for cause and you have data to back it up It's really an education that if you're looking to become, there's always been this argument from my world of VCIO of, hey, we really can't embed ourselves in as leaders.

And ultimately, we don't want to have decision-making control, but we do want to have influential control. And this is a topic that I think we can be very influential with and really start working with the customer. And it's ultimately going to lead to the projects that we want to do. It's going to elevate us, but it's also a defense mechanism.

I'm hearing more and more from the MSP community that these guys that think they're AI gurus now who have nothing to do with traditional IT are coming in and taking that AI seat right out from under the MSP. Interesting. And a lot of that's going to come back to the expectation that the customer has of their MSP. I thought I was already paying for that kind of stuff.

I mean, that's the agile dilemma. Yep. Have you defined the edges, especially in the world of AI? Have you defined the edges of your relationship?

Are you viewed as a commodity? If you are, this is an opportunity to maybe step up because it's a really hot topic. And even the smallest of businesses are kind of like, what can I do with AI to a degree? But I I think, you know, when in talking to the MSPs I speak to, many of them haven't even done their first project yet because everybody's still very confused on what can be done, what should be done.

And, you know, we've added readiness assessments within our tool. And again, not to be a, you know, a commercial, but it's to kind of help everybody kind of level set and go, hey, we even thought about what our strategy is. Do we know who the people are going to be involved in this, you know, as we get into it? And that's where an MSP can really go in and shine today saying, hey, here's your procedural concerns, your people concerns, your security concerns, your data concerns.

I mean, you know, is your data even clean, right, before you even go into those things? So there's a lot to be gained today through just a simple conversation of what don't you know, Mr. Customer? What have you been thinking about, AI, and can I help you formulate those thoughts?

That's a great positioning, right? it goes back to the influencer, back to the trusted advisor, you know, any of the various terms. Cause, cause if, if you're not answering and talking to that, they're having that discussion, somebody else is going to be. Yeah.

Or they're going to find somebody else not thinking you're the one. And that's the biggest shame. You've already got the relationship. Right.

And you know, that's what we're trying to share with folks is if you haven't just asked people, where do you need help? You know, that that's question number one. And if you hear the same thing enough times, than if you're wondering what your next webinar should be. So we're getting near the end of our time, Frank.

I don't know if you have anything else you wanted to cover off on before we wrap up for today. No, if you don't mind, I just wanted to just remind people a little bit of the points that we offer. Just, you know, continuous vulnerability management, right, and thread exposure is really our core deliverable with NodeWare. And it's easy to use, quick to deploy.

It's the full enterprise coverage, both for devices and for the applications on the Windows devices in particular. We're able to monitor and manage those vulnerabilities and patch. And we support tools. You know, the data goes into the vSail toolbox, as an example.

So if you are doing compliance, we're easy to fit for that kind of thing. the other piece of our business again just is services around penetration testing of all types physical, on-site, keyboard OWASP sort of application testing some VC stuff so if you're interested in any of that we'd love to hear more from you you can find me on LinkedIn or reach out at nodeware.com and we'd love to have some more discussion thanks so much Brian great conversation I should thank you for stepping in very quickly and jumping in here.

And, but as you always are willing to, but, you know, I always learn a little something too, when you join me. So it's, I appreciate that more so. And, you know, I'm excited that, you know, we're not too far away for those of you that are going out there. GTIA is in about a month, give or take from when this is going live.

And, and it'll be really fun to see the channel come together at one of those shows where pretty much almost everybody is there. Yeah, and I agree. Everybody's there, and it's a really different variety of a show if you haven't been before. It really is the community.

You can meet up, go up to the CEO or TTO of Pax8 to England to TD Cynics to the largest partners and MSPs in the world to the biggest vendors. So it really is a good, Good Avenue. If you haven't signed up yet, I know they're still taking registrations and hotel rooms are available. So it's in San Diego, which in August is never a bad place.

Nope. Weather's always great in San Diego. So you can't go wrong. But awesome, Frank.

Well, thank you again for joining me today. And listeners, as always, you can get this out on YouTube. Just subscribe so you can stay up to date on all the latest episodes or download it anywhere that you want to listen to your podcast. Within the show notes, we'll have Frank's LinkedIn address as well as links to both Nodeware and IGI.

And Frank, I'll see you in about a month in real time. All right. Take care.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Why CMMC became necessary in the first place.Trust Issues · on CMMC compliance88 / 100
  • Shadow AI: 7 Out of 10 Workers Use AI Their Company Can’t See | Ravi Soin, CISO SmartsheetCXO Spotlight · on shadow AI87 / 100
  • AI in Healthcare: Shadow AI, Trust & the Human’s Role - with Dr Keith Grimes (#70)The Healthusiasm Podcast · on shadow AI81 / 100
  • July 2026 CMMC ConnectCyberspin · on Penetration testing80 / 100
  • 32 - When AI Attacks - Part 2Cyber Compliance & Beyond · on shadow AI78 / 100
  • SailPoint presents: How healthcare can secure AI tools and non-human identitiesHIMSSCast · on shadow AI77 / 100

More from MSP Business School

All episodes →
  • Johnathan Skofi | The Art of Purpose-Driven Leadership
  • John Harden | Turning MSPs into Managed Intelligence Providers with AI
  • Fireside Chat | The MSP's Guide to Becoming an AI Strategic Partner
  • Chris Cooke | The Secret to Building a Sustainable Business
  • The Trusted Advisor Blueprint: Evolving VCIO, VCISO & AI Leadership in MSPs
Explore the best B2B Startups & Founders podcasts →
All MSP Business School episodes →