The MSP's Guide to SOC 2: How to Get Started and What to Expect
Release Date: 05/14/2024
MSP Business School
In this episode, Sean Sweeney shares his unique journey from law to technology, his experience supporting enterprise and SMB clients, and insights on AI adoption and risk management in MSPs. Guest Name: Sean Sweeney LinkedIn page: Company: Valley Technology Partners Website: Show Website: Host Brian Doyle: Sponsor vCIOToolbox:
info_outlineMSP Business School
In this enlightening coaching session, Brian Doyle offers his seasoned insights into the gap between client perceptions and the actual deliverables provided by Managed Service Providers (MSPs). Doyle, drawing on his extensive background as an MSP, provides a nuanced understanding of how to bridge these gaps through clear communication and precise contract terms. The episode dives into topics like client assumptions about MSP deliverables, how to manage these expectations, and offers strategic approaches to avoid conflicts arising from misunderstandings in service agreements. Throughout the...
info_outlineMSP Business School
In this episode of MSP Business School, host Brian Doyle welcomes the dynamic and insightful Josh Hohbein from centrexIT. Josh, highlighted as a rising star in cybersecurity, shares his expansive journey from tech support to a leadership role in cybersecurity and automation. The conversation unveils how Josh's background in service industries has shaped his understanding and approach to managing IT services. Josh discusses the challenges of aligning cybersecurity frameworks with client understanding and interest. By distilling complex standards into manageable and actionable plans, he ensures...
info_outlineMSP Business School
In this engaging episode of MSP Business School, host Brian Doyle welcomes Brendan Giesick, the industrious CRO of Adams Brown Technology. They delve into Brendan’s unique journey into the MSP industry, illustrating his transition from a business major with ambitions in retail marketing to a key figure in managed services. Brendan shares insightful anecdotes from his experiences, highlighting the valuable lessons learned from his mentors and career pivots that led him to his current role at Adams Brown. The conversation unravels the distinctions between established MSP organizations like...
info_outlineMSP Business School
In this episode of MSP Business School, host Brian Doyle delves into the evolving role of the VCIO within the managed service provider space, coinciding with a special St. Patrick's Day greeting to viewers. Brian contrasts the often superficial duties of traditional account managers with the strategic, forward-thinking responsibilities critical to the position of a VCIO. The episode emphasizes how MSPs can develop VCIOs not just as technical overseers but as integral business leaders capable of steering organizations through the rapid changes imposed by new technological advancements....
info_outlineMSP Business School
In this engaging episode of MSP Business School, host Brian Doyle sits down with Shane Naugher, a pioneering figure in the world of AI and automation for MSPs. The discussion takes a deep dive into the real-world application of AI, focusing on how it can be utilized to streamline operations and deliver tangible ROI for businesses. Whether you're curious about how AI fits into your MSP strategy or eager to learn about automation opportunities, this episode delivers practical insights into what Shane calls the "mature business model" of MSPs. As the conversation unfolds, Shane shares his dual...
info_outlineMSP Business School
Join Brian Doyle on this episode of MSP Business School as he sits down with Doug Kreitzberg from SeedPod Cyber to discuss the intricate world of cybersecurity insurance. Kreitzberg, with a rich background in the insurance industry, explores the dynamic relationship between MSPs and cyber insurance providers. He highlights the importance of having well-designed insurance programs that align with the specific technology and risk environments of SMBs (Small and Medium-sized Businesses). Doug's insights shed light on how MSPs can leverage cyber insurance to build trust and offer more value to...
info_outlineMSP Business School
In this episode of MSP Business School, host Brian Doyle welcomes back industry analyst and media personality Dave Sobel. Known for his critical and transparent approach, Sobel dives into the transformative journey of his recent acquisition, discussing the strategic merger with Carl Polachuk's Small Business Thoughts Community. This episode provides an in-depth look into the dynamics of the merger and acquisition process, touching upon essential topics such as collaboration, community building, and strategic growth within the MSP industry. During the conversation, Dave Sobel elaborates on the...
info_outlineMSP Business School
In this engaging episode of MSP Business School, host Brian Doyle introduces Keegan Sullivan, a creative marketing force leading the charge at Threat Captain. The discussion highlights Keegan's unique approach to marketing, emphasizing the importance of storytelling, authenticity, and creative expression in an industry saturated with sameness. Keegan shares his professional journey, from his early days of capturing stories with a camera to his current role, where he uses his talents to demystify complex concepts and build captivating narratives that resonate with audiences. Throughout the...
info_outlineMSP Business School
In this engaging episode of MSP Business School, host Brian Doyle takes listeners through a comprehensive exploration of Technology Business Reviews (TBRs) and their evolving role in the MSP industry. TBRs have shifted from data-heavy presentations to become more strategic and client-focused, addressing clients' growing needs around cybersecurity, compliance, and risk management. Brian Doyle delves into a structured approach to Quarterly Business Reviews (QBRs), breaking down the process into four distinct phases. Each phase targets specific aspects of technology management—from setting a...
info_outlineIn the latest installment of MSP Business School, Brian Doyle hosts an insightful conversation with compliance experts Bo Bito and Angelika Mayen from Render Compliance. The episode zeroes in on the increasingly critical subject of SOC 2 compliance for Managed Service Providers (MSPs), delving into the nuts and bolts of the process and offering pearls of wisdom for businesses considering the SOC 2 journey.
The discussion kicks off with a detailed expedition into the SOC 2 process, demystifying the steps from an MSP's standpoint. Bo and Angelica highlight the importance of involving experienced personnel or consultants early on and underscore the value of engaging with auditors in the initial stages. Offering a rare peak behind the SOC 2 curtain, they detail the differences between SOC 2 Type 1 and Type 2 reports, explaining the significance of each type in establishing and demonstrating a company's commitment to security and compliance.
Key Takeaways:
-
MSPs looking to obtain SOC 2 compliance should start by evaluating in-house expertise, consider working with consultants, and connect with auditors early in the process.
-
SOC 2 Type 1 vs. Type 2: Type 1 evaluates the design of controls at a point in time, while Type 2 assesses how those controls operate over a period.
-
Engaging with technology and tools such as compliance platforms can streamline the SOC 2 process by organizing tasks and centralizing evidence collection.
-
Timeline and cost: A typical SOC 2 engagement may span nine weeks, with costs starting from $16,000 up to $40,000, depending on various factors like business size and control complexity.