Log in

goodpods headphones icon

To access all our features

Open the Goodpods app
Close icon
Beyond the Horizon: Future-Focused MSP Insights - Ransomware as a Service: What MSPs Need to Know

Ransomware as a Service: What MSPs Need to Know

12/12/24 • 37 min

Beyond the Horizon: Future-Focused MSP Insights

In this engaging episode of the Beyond the Horizon podcast, Jim Waggoner, VP of Product Management for Security at N-able, and Lewis Pope, Security Head Nerd at Enable, dive deep into the world of Ransomware as a Service (RaaS). They explore the commoditization of cybercrime, the challenges and opportunities for Managed Service Providers (MSPs), and the cutting-edge solutions available to combat these threats.

Key Topics Covered:

  1. What is Ransomware as a Service (RaaS)?
    • Definition and explanation of RaaS.
    • How it lowers barriers for cybercriminals, enabling even non-technical actors to launch ransomware campaigns.
  2. The Economics of RaaS
    • Entry costs and the profitability of RaaS for threat actors.
    • Comparison between the startup costs for cybercriminals and legitimate MSPs.
    • Why the asymmetry of costs and skills creates significant challenges for defenders.
  3. Target Profiles and Attack Patterns:
    • How attackers cast wide nets and target vulnerabilities indiscriminately.
    • Examples of unexpected targets, including non-profits like food banks.
    • Regional patterns and why the U.S. remains a favorite target for ransomware campaigns.
  4. Challenges for MSPs:
    • Skill gaps and operational challenges for MSPs trying to combat advanced threats.
    • The high cost of building in-house SOC capabilities.
    • Growing expectations from clients for integrated security services.
  5. Opportunities for MSPs:
    • The shift toward incorporating Managed Security Service Provider (MSSP) capabilities.
    • Leveraging third-party tools like Enable's MDR for cost-effective, scalable solutions.
    • The importance of having risk management conversations with clients.
  6. Real-World Success Stories:
    • How Enable's MDR helped a city in New Jersey recover and protect itself from repeated ransomware attacks.
    • The value of rapid detection and response in minimizing downtime and financial loss.
  7. Actionable Steps for MSPs:
    • Engaging clients in honest risk management discussions.
    • Identifying and addressing gaps in their current security offerings.
    • Leveraging commoditized services like MDR to offer 24/7 protection without building in-house capabilities.
  8. Future of Cybersecurity for MSPs:
    • The evolving threat landscape and how MSPs can adapt to remain competitive and secure.
    • The importance of continuous learning and partnering with vendors who offer advanced security tools.

#Cybersecurity #CyberThreats #CyberAwareness #Ransomware #RansomwareAsAService #RAAS #MDR #ManagedDetectionAndResponse #CyberSolutions #TechPodcast #BusinessSecurity #CybersecurityTips #TechInsights

#LearnCybersecurity #ITPro #TechEducation

Disclaimer: This po

Disclaimer: This podcast provides educational information about issues that may be relevant to information technology service providers. Nothing in the podcast should be construed as any recommendation or endorsement by N-able, or as legal or any other advice. The views expressed by guests are their own and their appearance on the podcast does not imply an endorsement of them or any entity they represent. Views and opinions expressed by N-able employees are those of the employees and do not necessarily reflect the view of N-able or its officers and directors. The podcast may also contain forward-looking statements regarding future product plans, functionality, or development efforts that should not be interpreted as a commitment from N-able related to any deliverables or timeframe. All content is based on information available at the time of recording, and N-able has no obligation to update any forward-looking statements. https://www.n-able.com

plus icon
bookmark

In this engaging episode of the Beyond the Horizon podcast, Jim Waggoner, VP of Product Management for Security at N-able, and Lewis Pope, Security Head Nerd at Enable, dive deep into the world of Ransomware as a Service (RaaS). They explore the commoditization of cybercrime, the challenges and opportunities for Managed Service Providers (MSPs), and the cutting-edge solutions available to combat these threats.

Key Topics Covered:

  1. What is Ransomware as a Service (RaaS)?
    • Definition and explanation of RaaS.
    • How it lowers barriers for cybercriminals, enabling even non-technical actors to launch ransomware campaigns.
  2. The Economics of RaaS
    • Entry costs and the profitability of RaaS for threat actors.
    • Comparison between the startup costs for cybercriminals and legitimate MSPs.
    • Why the asymmetry of costs and skills creates significant challenges for defenders.
  3. Target Profiles and Attack Patterns:
    • How attackers cast wide nets and target vulnerabilities indiscriminately.
    • Examples of unexpected targets, including non-profits like food banks.
    • Regional patterns and why the U.S. remains a favorite target for ransomware campaigns.
  4. Challenges for MSPs:
    • Skill gaps and operational challenges for MSPs trying to combat advanced threats.
    • The high cost of building in-house SOC capabilities.
    • Growing expectations from clients for integrated security services.
  5. Opportunities for MSPs:
    • The shift toward incorporating Managed Security Service Provider (MSSP) capabilities.
    • Leveraging third-party tools like Enable's MDR for cost-effective, scalable solutions.
    • The importance of having risk management conversations with clients.
  6. Real-World Success Stories:
    • How Enable's MDR helped a city in New Jersey recover and protect itself from repeated ransomware attacks.
    • The value of rapid detection and response in minimizing downtime and financial loss.
  7. Actionable Steps for MSPs:
    • Engaging clients in honest risk management discussions.
    • Identifying and addressing gaps in their current security offerings.
    • Leveraging commoditized services like MDR to offer 24/7 protection without building in-house capabilities.
  8. Future of Cybersecurity for MSPs:
    • The evolving threat landscape and how MSPs can adapt to remain competitive and secure.
    • The importance of continuous learning and partnering with vendors who offer advanced security tools.

#Cybersecurity #CyberThreats #CyberAwareness #Ransomware #RansomwareAsAService #RAAS #MDR #ManagedDetectionAndResponse #CyberSolutions #TechPodcast #BusinessSecurity #CybersecurityTips #TechInsights

#LearnCybersecurity #ITPro #TechEducation

Disclaimer: This po

Disclaimer: This podcast provides educational information about issues that may be relevant to information technology service providers. Nothing in the podcast should be construed as any recommendation or endorsement by N-able, or as legal or any other advice. The views expressed by guests are their own and their appearance on the podcast does not imply an endorsement of them or any entity they represent. Views and opinions expressed by N-able employees are those of the employees and do not necessarily reflect the view of N-able or its officers and directors. The podcast may also contain forward-looking statements regarding future product plans, functionality, or development efforts that should not be interpreted as a commitment from N-able related to any deliverables or timeframe. All content is based on information available at the time of recording, and N-able has no obligation to update any forward-looking statements. https://www.n-able.com

Previous Episode

undefined - MSP Strategies for Navigating the Hybrid Landscape

MSP Strategies for Navigating the Hybrid Landscape

In this episode of the Beyond the Horizons Podcast, host Pete Roythorne is joined by N-able Head Nerd Joe Ferla, Senior Product Manager Mike Weaver, to discuss the challenges and opportunities for MSPs in managing hybrid environments. They delve into the evolution of RMM tools, the growing need for security, and practical strategies for staying competitive in the ever-changing MSP landscape.

Key Topics Covered

1. The Hybrid Landscape

Despite increasing cloud adoption, traditional on-premises RMM remains critical for certain verticals like healthcare and manufacturing.

The unique challenges of hybrid environments: balancing security, compliance, and cost considerations.

Hybrid isn't a replacement for the cloud but rather a complementary solution in specific cases.

2. Evolving RMM Tools in a Cloud-First World

The importance of RMM tools as data aggregators.

How hybrid environments increase attack surfaces and require advanced visibility.

Moving beyond devices to tenant-level and user-level management for enhanced scalability.

3. Security as a Cornerstone

The necessity of standardized security practices for MSPs.

Avoiding exceptions like skipping MFA to ensure comprehensive client protection.

Conducting tabletop exercises and live simulations with clients to prepare for security incidents.

4. Future Innovations in RMM

Shifting focus from device-centric management to user and tenant-level control.

Leveraging AI and automation to enhance operational efficiency and response times.

Integrating diverse tools into a unified experience without overcomplicating service delivery.

5. MSP Business Strategies

Differentiating services through specialization in hybrid and cloud environments.

Emphasizing long-term business planning and relationships to drive growth.

Expanding market share by addressing client-specific needs with tailored solutions.

6. Actionable Advice for MSPs

Standardize service offerings to streamline operations and enhance efficiency.

Invest in scalable tools and processes to manage hybrid environments securely.

Use security drills and robust planning to mitigate risks and build client trust.

Disclaimer: This podcast provides educational information about issues that may be relevant to information technology service providers. Nothing in the podcast should be construed as any recommendation or endorsement by N-able, or as legal or any other advice. The views expressed by guests are their own and their appearance on the podcast does not imply an endorsement of them or any entity they represent. Views and opinions expressed by N-able employees are those of the employees and do not necessarily reflect the view of N-able or its officers and dir

Disclaimer: This podcast provides educational information about issues that may be relevant to information technology service providers. Nothing in the podcast should be construed as any recommendation or endorsement by N-able, or as legal or any other advice. The views expressed by guests are their own and their appearance on the podcast does not imply an endorsement of them or any entity they represent. Views and opinions expressed by N-able employees are those of the employees and do not necessarily reflect the view of N-able or its officers and directors. The podcast may also contain forward-looking statements regarding future product plans, functionality, or development efforts that should not be interpreted as a commitment from N-able related to any deliverables or timeframe. All content is based on information available at the time of recording, and N-able has no obligation to update any forward-looking statements. https://www.n-able.com

Next Episode

undefined - Why MSPs Need to Stop Selling Security

Why MSPs Need to Stop Selling Security

Welcome to the Beyond the Horizons Podcast, in this episode we’re breaking from our usual format to bring you one of the key sessions from our Business of Security event in Texas last year (2024) where N-able Chief Security Officer Dave MacKinnon explains why selling security isn’t enough—and instead how MSPs need to focus on selling business resilience as an outcome.

Here Dave is being interviewed by Think Purple’s Alex Stanton.

Key Themes Discussed

1. Selling Resilience, Not Security

o Dave emphasizes the importance of moving away from “selling security products” and instead focusing on building business resiliency.

o Resiliency ensures that organizations can minimize disruption when, not if, a cyber event occurs.

2. The Role of Risk

o Risk is not bad; it’s healthy when acknowledged and managed.

o Businesses that ignore risk often face larger repercussions when incidents occur.

o It's essential to educate clients on identifying and understanding their business risks rather than avoiding or downplaying them.

3. Understanding Business Goals

o Start with business objectives, not security tools.

o Engage leadership with terms they understand: focus on outcomes like protecting revenue streams or minimizing operational downtime.

o Example: Discussed board-level alignment on risk tolerance and strategic investments.

4. The MSP Opportunity: Selling Outcomes, Not Products

o MSPs should present their services as enablers of business continuity and success, not just technical solutions.

o Dave encourages framing MSP offerings around risk mitigation and business continuity planning.

Key Insights

· Risk Management as a Conversation:

o MSPs should discuss tangible impacts of downtime, such as revenue loss or missed deadlines, to convey the value of investing in risk management.

o Example: A $30M office supply company loses $40,000 per half-day of downtime—a stark reminder of the cost of inaction.

· SaaS and Identity as Critical Responsibilities:

o MSPs must take responsibility for managing SaaS applications and client identity systems.

o Include identity management, provisioning, and securing integrations into service offerings.

o Highlighted the risk of lost or inaccessible data in SaaS environments without proper backups and vendor accountability.

· Tabletop Exercises and Incident Planning:

o Use tabletop exercises to identify gaps in processes, tools, or training.

o Avoid overly complex scenarios that discourage participation; start simple and build on successes.

· Tool and Vendor Selection:

o MSPs should evaluate and re-evaluate tools regularly to ensure they align with changing threats and business needs.

o Avoid tool sprawl: focus on leveraging a smaller set of tools effectively.
Disclaimer: This podcast provides educational information about issues that may be relevant to information technolog

Disclaimer: This podcast provides educational information about issues that may be relevant to information technology service providers. Nothing in the podcast should be construed as any recommendation or endorsement by N-able, or as legal or any other advice. The views expressed by guests are their own and their appearance on the podcast does not imply an endorsement of them or any entity they represent. Views and opinions expressed by N-able employees are those of the employees and do not necessarily reflect the view of N-able or its officers and directors. The podcast may also contain forward-looking statements regarding future product plans, functionality, or development efforts that should not be interpreted as a commitment from N-able related to any deliverables or timeframe. All content is based on information available at the time of recording, and N-able has no obligation to update any forward-looking statements. https://www.n-able.com

Episode Comments

Generate a badge

Get a badge for your website that links back to this episode

Select type & size
Open dropdown icon
share badge image

<a href="https://goodpods.com/podcasts/beyond-the-horizon-future-focused-msp-insights-597415/ransomware-as-a-service-what-msps-need-to-know-79977375"> <img src="https://storage.googleapis.com/goodpods-images-bucket/badges/generic-badge-1.svg" alt="listen to ransomware as a service: what msps need to know on goodpods" style="width: 225px" /> </a>

Copy