The Almost MSSP Playbook Easy Ways to Beef up your Security Offerings NOTES: MSSP. It’s an attractive title, isn’t it? Hey, you - don’t be fooled! Necessary for some? Sure. But as an MSP, efficiency is the hallmark of your operation and much of what is housed under the umbrella of a traditional MSSP’s service offerings is actually overkill for small to medium sized clients like yours, better suited instead for larger enterprise businesses. Lucky for you, there are much simpler ways to enhance your current security offerings to better serve your SMB clients. This Almost MSSP Playbook will detail various areas of focus so you can beef up your current security offerings across networking, OS, Software, Education and Backup. This will allow you to enhance your security offerings without wasted efforts while charging a premium for additional security items. 1 THE ALMOST MSSP PLAYBOOK NOTES: Networking Networking - it’s your clients’ exposure to the internet and a hackers first point of entry. It’s typically a focal point of targeted attacks. Network vulnerabilities are commonly-detected by bots and other automated attackers. Translation? You need to protect your neck. Next Generation Firewall – Upgrade to traditional network firewall. Device should perform the following functions: Antivirus, intrusion detection, anti-spyware, URL filtering, Data Loss Protection and zero-day analysis. Vulnerability Scanning – Identifies rogue systems, poor patching and non-compliance with security controls. This technology allows you to see holes in network. 2 THE ALMOST MSSP PLAYBOOK NOTES: Operating Systems Unsupported, outdated and poorly patched operating systems are an easy target for automated tools and malware. Your clients’ OS is under a constant threat from broad stroke security attacks like viruses, trojan horses, worms and other programmatic threats. By enhancing OS controls, you can protect your users while they’re remote or on public networks such as the local coffee house. Iced latte, please. Hold the virus. EDR (Endpoint Detection and Response)/Next Gen Antivirus – Both of these will give you greater visibility into what’s going on in the OS and allow you to protect against advanced malware. They will also give you contextual data of what happened and how. Whole Disc Encryption – Ensures data is protected in the event of loss or theft. This keeps you from having to tell people you lost their data. Phew! Local Firewall – Local firewalls are often overlooked and generally free of software cost. They provide significant protection for remote users and those on public wireless networks. 3 THE ALMOST MSSP PLAYBOOK NOTES: Software With the cultural change from desktop applications to cloud services, perimeter controls no longer protect your clients’ data or users. Implementing security controls that extend past your network is now an essential piece of any good security program. Credential Management – This could possibly be the most important thing on this list - so listen up! Credential Management allows you to protect secrets and passwords for online applications and critical systems. 4 Application Management and Inventory – This is most commonly addressed with a whitelisting product. AMI gives you the ability to immediately stop ransomware and other malicious programs. THE ALMOST MSSP PLAYBOOK NOTES: Education Pretend you have a building. You secure it with all of the most secure bells and whistles. The best that money can buy. Cameras, alarms, you name it. No one is getting in if you don’t want them to. But what good is all of that when an employee leaves a door open? All the other stuff is useless if people aren’t properly trained on best practices. Security Awareness Training – The human is commonly compromised. Implement a comprehensive training program that addresses all risks appropriate to your client. Security Awareness Testing – This should be a combination of penetration testing and phishing attempts. This allows you to proactively test your users and see how subjectable they are to exploitation. 5 THE ALMOST MSSP PLAYBOOK NOTES: Backup & Disaster Recovery There’s one certainty when it comes to security - your security functions will always fail at some point. That’s why you need backup. Nothing is impenetrable. If you can’t get your clients’ data back you’re going to lose that client and your reputation as a security advisor. Backup of the following is essential to protecting client infrastructure… Devices/Endpoints –Data loss is often fatal. One study showed that 60 percent of small and medium size businesses (SMBs) that lose their data will shut down within six months. Axcient Business Continuity software enable SMBs to focus on their business instead of worrying about their data or business availability. Infrastructure – In addition to ensuring complete resilience for their clients’ infrastructure, applications, and data, today’s IT leaders are asked to find new ways to deliver higher levels of service at lower cost and using fewer resources. Axcient Fusion allows MSPs to consolidate and converge infrastructure and workloads in a single, secure cloud platform. 6 THE ALMOST MSSP PLAYBOOK NOTES: Backup & Disaster Recovery continued... Critical Apps (0365) – The move to Office 365 makes sense for many companies. Automatic software updates and security fixes, access to documents anytime from anywhere on any device. And it’s automatically backed up, right? Wrong. CloudFinder from Axcient puts you back in control of your Office 365 data by providing cloud backup and restore so you can continue to access your documents and Exchange Online anytime from anywhere on any device. Critical Docs – Many small and medium size businesses, lacking the resources to build out their own enterprise-class file sync environment, turn to consumer-grade alternatives such as Box, Dropbox, and Google Drive. But sometimes “free” costs too much. Anchor from Axcient enables MSPs to offer their clients secure file access anywhere, anytime, on any device, across all corporate content. 7 THE ALMOST MSSP PLAYBOOK Thank You. For more information on how Axcient can help you strengthen your security offerings, please contact us at info@axcient.com or visit us at www.axcient.com