Listen "My Thoughts on the CISA MSP Advisory"
Episode Synopsis
CISA published their advisory bulletin addressing risk considerations for organizations thinking about using managed service providers. This is a great advisory, but it has some areas of potential misinterpretation in it, chiefly because CISA has departed from a security group and expanded into territory in which it has little experience.
Highlights:
What if organizations stopped using MSPs?
Yes, all customers ought to be responsible and consider risks of outsourcing. But, risks of not managing IT are far greater than the risks of outsourcing
Targeting of managed services supply chain vendors is NOT a symptom of poor MSP security, it's a symptom of the unchecked business of cybercrime
MSP Zone Reading Material: Risk Considerations for MSP Customers | CISA
Highlights:
What if organizations stopped using MSPs?
Yes, all customers ought to be responsible and consider risks of outsourcing. But, risks of not managing IT are far greater than the risks of outsourcing
Targeting of managed services supply chain vendors is NOT a symptom of poor MSP security, it's a symptom of the unchecked business of cybercrime
MSP Zone Reading Material: Risk Considerations for MSP Customers | CISA
More episodes of the podcast The MSP Zone
Is the MSP M&A Market Cooling in 2026?
14/12/2025
Is the MSP Business Model Obsolete?
17/11/2025
Cybersecurity Awareness: Beyond the Basics
05/11/2025
Is It Too Late to Start an MSP?
28/10/2025
Competing against Low Priced MSPs
15/09/2025
ZARZA We are Zarza, the prestigious firm behind major projects in information technology.