EP242 – Stopping 365 Breaches Starts with YOU with Scott Riley & Ian Luckett
IT Experts Podcast with Ian Luckett
Release Date: 07/20/2025
IT Experts Podcast with Ian Luckett
In this episode of the IT Experts Podcast, I sit down with the brilliant Marcus Sheridan to unpack one of the biggest questions on every MSP owners mind how to attract endless customers into your MSP in a world that has completely changed the way it buys. This conversation is all about practical action. Marcus and I explore what is really going on in the heads of your buyers, why they now arrive eighty percent of the way through their buying journey before they ever speak to you, and how you can position your MSP as the firm that AI tools and humans are both recommending. If you are...
info_outlineIT Experts Podcast with Ian Luckett
In this episode of the IT Experts Podcast, we explore why so many MSPs hit a ceiling when it comes to growth and how shifting your marketing mindset from activity to strategy can unlock the next level of success. I’m joined by THE Nicola Moss, a seasoned marketing leader and founder of The Fractional Marketeer, who works with MSPs to bring structure, credibility and clear direction to their marketing efforts. Nicola has spent years leading marketing functions inside MSPs, so she knows first-hand the challenges that owners face when they try to move from...
info_outlineIT Experts Podcast with Ian Luckett
In this episode of the IT Experts Podcast, I sat down with the brilliant Fiona Challis to separate reality from the noise and give MSP owners a practical route to value. We opened with a simple viewpoint. AI is not a magic fix and it is not a toy to chase. It becomes powerful when it sits on top of clear processes, clean data, and a focused plan. That theme runs through the whole conversation with Fiona Challis, who has spent recent years enabling partners around enterprise AI and then translating that experience for the MSP world. The result is a set of grounded lessons...
info_outlineIT Experts Podcast with Ian Luckett
Ian begins by reflecting on how mindset shapes outcomes. He shares how his own transformation began during long commutes to Heathrow Airport years ago, when he discovered the power of self-belief through learning from leaders like Tony Robbins. That journey sparked a shift in perspective, from being an employee to building a business owner mindset. The lesson is simple but profound: your body listens to what your mind tells it. If you believe you can achieve something, you probably will. If you believe you cannot, that becomes your reality too. Many MSP owners, as Ian points out, didn’t...
info_outlineIT Experts Podcast with Ian Luckett
1. Control through clarity When your business starts growing faster, the natural reaction is to hold on tighter. You try to stay in every detail because it feels safer. The problem is that this habit quickly turns you into the bottleneck. The solution is targeted delegation supported by simple and clear processes. I encourage MSP leaders to split their work into three levels. The first level is low-value work that an assistant or automation can handle. The second level is management work that belongs to team leaders who take responsibility for outcomes. The third level is...
info_outlineIT Experts Podcast with Ian Luckett
The reality is that many MSPs grow through referrals and good account management. That, in itself, is not a bad thing, but when the business matures, you can find yourself in a position where a single client represents 30, 40, even 50 percent of your revenue. They may also be one of your most profitable accounts, so the dependency is even greater. If that client gets bought, merges, or decides to build an internal IT team, you are left exposed. Worse still, if they go bust, you’re not only losing revenue but also carrying the burden of licences, subscriptions, and staff wages with no way to...
info_outlineIT Experts Podcast with Ian Luckett
Stuart and I opened the room with a simple truth. Progress comes from consistency. The Intensive works because it anchors everyone to a living plan that links a three-to-five-year vision to an annual focus and down to a current sixteen-week sprint. When owners follow the process, complete their dashboards, and show up to the weekly rhythm, results compound. The Intensive is where that discipline gets renewed. People sit with peers, compare notes, and see with fresh eyes that the next leap is in reach when the right activity happens in the right order. A major theme this time was...
info_outlineIT Experts Podcast with Ian Luckett
Running an MSP can feel like a whirlwind of tickets, meetings, and decisions. This episode sets out a calm, workable route to operations that hum. Start with a clear plan that covers financials, growth, structure, and how each role fits. Communicate it well. Give every person a role profile, a scorecard, and clear expectations. When people know what they own and when to seek support, accountability rises, and your MSP becomes consistent and easier to lead. One of the key themes in this conversation is how important it is to have a clear plan. Without a plan, everything in the business...
info_outlineIT Experts Podcast with Ian Luckett
Over the last few days, I have had some powerful conversations with MSP owners about what really moves the needle when it comes to building a scalable and profitable business, and the truth is clear. A slick Marketing campaign will not compensate for weak processes, bottlenecks in delivery, or an MSP that still relies too heavily on the owner being needed in the day-to-day. I share in this episode how the three key pillars of your MSP – direction and planning, building an effective and scalable team, and then sales and Marketing – need to be kept in balance. Too often the third...
info_outlineIT Experts Podcast with Ian Luckett
In this special episode Stuart and I take time to reflect on the milestones that have shaped our partnership, our clients, and the Growth Hub as a whole. We start right at the beginning when we first met. It was late in the Covid period and what started as a one-to-one conversation quickly turned into something much bigger. We realised that our values aligned, that our different personalities and skills would complement each other, and that together we could help more people, change more lives, and have a greater impact. That first milestone of recognising the power of working together has...
info_outlineScott Riley has worked with MSPs for over six years, helping them tighten up their security practices and take real control of their 365 tenancies. In this episode, be prepared for the shift in mindset that Scott encourages. The idea that you are too small or not interesting enough to be a target is no longer valid. The reality is that attackers are not selective. They cast a wide net. If your MSP gets breached, the damage can extend far beyond email. Your PSA, RMM, partner centre, licence platforms, password vaults, and all client environments are at risk.
Scott Riley explains that token theft is one of the most common attack methods in play right now. A stolen login token can allow someone to log in as you without being challenged. If your global admin account is tied to your day-to-day login, the attacker has immediate access to your critical systems. Many MSPs still store MFA tokens inside password managers alongside usernames and passwords. It might seem convenient, but it undermines the whole point of multi-factor authentication.
We explore the emotional and financial consequences of a breach. Scott shares a real-life case where criminals sat silently inside a business email system, watching communication styles and eventually mimicking the MD’s tone to authorise fraudulent payments. The losses started small but escalated quickly. These attacks are personal and targeted. For a small business, losing six thousand pounds can be the difference between making payroll and laying people off.
Scott stresses the importance of making this real for clients. He talks about positioning cybersecurity not as a technical need but as a business-critical risk conversation. Instead of relying on fear or jargon, help clients picture the consequences. What would happen if they were locked out of systems, lost money, or lost their reputation? Clients need to be educated through impact-based questions and examples they can relate to.
We also cover the responsibility that MSPs carry themselves. Cybersecurity starts with you. It must be owned by the business and led from the top. While the technical work can be delegated, the responsibility cannot be passed on. Regular reviews, clear security standards, and the discipline to follow them are essential. Inside Agent, Scott’s platform, helps MSPs quickly assess their Microsoft 365 environments and bring them up to best practice. It gives a live compliance score, offers guided fixes, and creates ongoing visibility. It is designed to simplify the process, not complicate it.
We discuss why compliance frameworks such as Cyber Essentials Plus should be a minimum standard, and how the upcoming UK Cybersecurity and Resilience Bill is going to push MSPs to meet new legal requirements. With MSPs being seen as part of critical national infrastructure, business owners need to ensure that their internal environments are secure and compliant, not just their clients’ systems.
Scott Riley shares clear recommendations for securing 365 tenants. These include using hardware MFA tokens, enforcing location and device-based access policies, reviewing and removing unused app integrations, ensuring third parties such as accountants or offshore VAs have the right restrictions in place, and stopping the use of global admin accounts for daily operations. He encourages every MSP to sit with their team regularly and walk through breach scenarios to build internal clarity and confidence.
The message is simple. Know where you are exposed. Fix what needs to be fixed. Get independent validation to confirm it. This episode is full of practical, plain-speaking advice that any MSP can follow. Scott Riley brings clarity, urgency, and support to an area that often gets ignored or pushed to the bottom of the list. If you want to protect your business, your team, and your clients, this episode is the reminder you need to act today. Thank you, Scott, for bringing such clear value to this conversation.
Connect with Scott Riley on his LinkedIn profile by clicking HERE.
Or you can also find out more about Inside Agent by clicking HERE.
Make sure to check out our Ultimate MSP Growth Guide HERE, and remember that the help is out there. You just have to go get it.
And when you’re ready to take the next step in growing your MSP, come and take the Scale with Confidence MSP Mastery Quiz. In just three minutes, you’ll get a 360-degree scan of your MSP and identify the one or two tactics that could help you find more time, engage & align your people, and generate more leads.
OR
To join our amazing Facebook Group of over 400 MSPs where we are helping you Scale Up with Confidence, then click HERE
Until next time, look after yourself, and I’ll catch up with you soon!