Brian Guenther | Crucial Conversations: CMMC, Compliance, and Your Cybersecurity Strategy
Release Date: 12/03/2024
MSP Business School
Delve into the intricacies of Technology Business Reviews with host Brian Doyle on MSP Business School. Explore how these reviews have evolved and learn innovative strategies for engaging clients amid data overload. Brian outlines a quarterly approach to QBRs, focusing on core reviews, security, health, and a year-end summary. Discover how to create joint strategic plans, assess risks, and gather valuable feedback from stakeholders. This episode is essential for MSPs looking to refine their client engagement strategies and optimize their review processes. Show Website: Host Brian...
info_outlineMSP Business School
Show Website: Guest Name: Joel Cahill LinkedIn page: Company: INFIMA Security Website: Host Brian Doyle: In this engaging episode of MSP Business School, hosted by Brian Doyle, listeners are introduced to Joel Cahill, co-founder of Infima, a cybersecurity company grounded in behavioral science. With Brian navigating through a scratchy voice due to Connecticut's pollen season, the discussion takes a dive into Joel's transition from a high-paced Wall Street career to steering a company aimed at refining security awareness training. This career leap was not just a change of industry...
info_outlineMSP Business School
Show Website: Guest Name: Jim Houghton LinkedIn page: Company: JCMR Technology Website: Host Brian Doyle: In this latest episode of MSP Business School hosted by Brian Doyle, listeners are introduced to Jim Houghton, the COO of JCMR. This engaging conversation dives into Jim's extensive 34-year journey within the IT sector. Listeners gain insights into his various roles, from engineering to consulting, and some of the critical lessons he has learned managing both startups and roles within Fortune 500 companies. Doyle and Houghton explore the evolution of technology within...
info_outlineMSP Business School
Show Website: Guest Name: Matt Yesbeck LinkedIn page: Company: Yesteck Website: Host Brian Doyle: In this insightful episode of the MSP Business School podcast, host Brian Doyle welcomes Matt Yesbeck, a seasoned IT professional and entrepreneur who has carved a unique path in the managed service provider (MSP) industry. Yesbeck shares his journey from years spent in IT, through various corporate roles, to founding Yesteck IT Services and the innovative platform MSPX. This platform aims to streamline the process of buying and selling MSP contracts, unlocking new growth...
info_outlineMSP Business School
Show Website: Guest Name: Dustin Puryear LinkedIn page: Company: Giant Rocket Ship Website: Host Brian Doyle: In this episode of MSP Business School, host Brian Doyle is joined by Dustin Puryear of Giant Rocketship to delve into effective solutions for enhancing service delivery within MSP operations. Dustin shares his journey from managing an MSP to developing a vendor product that addresses the industry’s common pain points. The conversation focuses on how Giant Rocketship innovates ticket management and service coordination through automation, reducing backlog and improving...
info_outlineMSP Business School
Insightful coaching session with Brian Doyle from VCIO Toolbox, listeners are introduced to the concept of "Governance as a Service" and how it can significantly impact and enhance the Managed Service Provider ecosphere. Brian explains the importance of governance in the security and compliance sectors, particularly in building a cybersecurity culture that increases cyber insurance viability and meets regulatory requirements. With the rising attention to governance in updates from frameworks like NIST CSF and CIS, organizations need a structured approach to ensuring cybersecurity and...
info_outlineMSP Business School
Show Website: https://mspbusinessschool.com/ Welcome to another engaging episode of MSP Business School, where your host Brian Doyle dives into the pressing issue of cyber insurance claims, which shockingly sees over 40% rejected, posing significant threats to businesses. In this fireside chat, Brian navigates through the core challenges MSPs face when dealing with cyber programs for their customers, urging them to build robust security and governance frameworks to minimize risks and ensure their claims are payable during security incidents. In this episode, the transcript illuminates how MSPs...
info_outlineMSP Business School
Show Website: Guest Name: Larry Meador LinkedIn page: Company: Cavelo Website: Host Brian Doyle: In this episode of MSP Business School, host Brian Doyle engages in a vibrant conversation with Larry Meador from Cavelo. Brian touches on his past experiences and insights into the MSP space, setting a friendly and informative tone for the discussion. Meanwhile, Larry shares his rich career journey, shedding light on the lessons learned and transformations observed in the industry over the years. The episode explores Larry's transition through different roles and companies,...
info_outlineMSP Business School
Join Brian Doyle on the MSP Business School podcast as he has a fireside chat with Frank Raimondi from Nodeware. This episode provides an engaging exploration of the critical importance of cyber hygiene for businesses heading into the new year. It highlights the evolving responsibilities of MSPs in the cybersecurity landscape. As Frank delves into the intricacies of effective cybersecurity strategies, he also shares news about his new podcast venture, "Frankly Speaking," bringing fresh perspectives to existing and potential Nodeware users. In this insightful episode, listeners will gain...
info_outlineMSP Business School
Show Website: Episode Summary: In this insightful episode of MSP Business School, Brian Doyle engages with Andrew Hartman, the founder of Time Boss, to delve into the intricacies of effective time management. The conversation highlights common pitfalls in managing time and stress, particularly in high-demand environments like MSPs, where technical founders often struggle with overwhelming tasks. Andrew shares his personal journey through oppressive stress, which even affected his health, and how he developed strategies that became foundational to his company, Time Boss. Andrew discusses...
info_outlineShow Website: https://mspbusinessschool.com/
Guest
Name: Brian Guenther
LinkedIn page: https://www.linkedin.com/in/brianwguenther/
Company: Exceed Cybersecurity & I.T. Services
Website: https://www.exceeditmd.com/
Host
Brian Doyle: https://www.linkedin.com/in/briandoylevciotoolbox/
Brian Guenther is a seasoned cybersecurity expert and the founder of Exceed Cyber. With over 26 years of experience in the IT and cybersecurity industry, Brian started his career by building PCs and gradually transitioned into IT franchise ownership. He founded Exceed Cyber in 2017, focusing on helping businesses navigate the complex landscape of cybersecurity compliance, specifically for those with federal contracts mandated by regulations such as CMMC, SoC2, and ISO 27001.
His deep understanding of governance, risk, and compliance processes makes him a valuable asset for companies needing to secure their operations against current cyber threats.
Episode Summary:
In this enlightening episode of MSB Business School, host Brian Doyle sits down with cybersecurity expert Brian Guenther to discuss the nuances of the Cybersecurity Maturity Model Certification (CMMC). As regulations around cybersecurity become more stringent, especially for defense contractors, understanding CMMC's requirements and implications is crucial. Brian Guenther, with his wealth of experience, dives into the evolution of CMMC, highlighting its origins, the essential controls necessary for compliance, and the critical role MSPs play in this landscape.
The discussion delves into how CMMC has become a focal point for organizations dealing with controlled unclassified information (CUI) and why being prepared for compliance is vital. Brian Guenther emphasizes the importance of proactive engagement in compliance processes, illustrating how MSPs can leverage their positioning by becoming CMMC-certified to differentiate themselves in the marketplace. He also sheds light on the geopolitical nuances affecting these regulations and how changes in political leadership might influence—but not diminish—the momentum towards stricter cybersecurity standards for federal contractors.
Key Takeaways:
- CMMC is paramount for defense contractors: Understanding and implementing CMMC is crucial as it enforces standards that contractors should have been following since 2017.
- Compliance does not equal security: While security frameworks like NIST 800-171 underpin CMMC, compliance serves as an initial checkpoint rather than the full spectrum of cybersecurity.
- MSPs must prepare adequately: Even though MSPs are not directly required to certify under CMMC, being prepared and knowledgeable is crucial for assisting clients.
- Cyber liability is a key driver: Insurance and regulatory requirements are pushing businesses to adopt more sophisticated cybersecurity measures.
- Proactive steps are essential: Waiting for enforcement isn't viable; MSPs and their clients should start their compliance journey immediately.