News, Trends, and Insights for IT & Managed Services Providers
News, Trends, and Insights for IT & Managed Services Providers
Business of Tech | The fed weighs in

Federal agencies must “immediately” adopt guidance on software supply chain security as required under the May 2021 cybersecurity executive order, the Office of Management and Budget stated on Wednesday.   Federal agencies must begin to adopt NIST’s Software Supply Chain Security Framework and related guidance effective immediately, tailoring it to the agency’s risk profile and mission, the agency said in a statement.

CISA has warned about the Ragnar Locker gang, which the FBI says has breached at least 52 organizations from multiple US critical infrastructure sectors.    Specifically, Ragnar Locker operators terminate remote management software (e.g., ConnectWise, Kaseya) used by managed service providers (MSPs) to manage clients’ systems remotely on compromised enterprise endpoints.

N-able findings show that managed service providers (MSPs) are quickly overtaking their customers as a primary target for cybercriminals. The research also revealed that while 90% of the surveyed MSPs suffered a cyberattack in the last 18 months, the number of attacks these MSPs are preventing has almost doubled, from six to 11 

  • 82% of MSPs have also seen attacks on their customers rise, though not quite at the same rate, with an average of 14 attacks prevented per month. 
  • DDoS and ransomware are among the primary attacks MSPs detect, but the top attack remains phishing.

I also want to highlight a change in perception of open-source software.    89% of IT chiefs believe open-source software is as secure as proprietary software, according to a survey by IBM-owned Red Hat, the maintainer of Red Hat Enterprise Linux (RHEL).    This is from Red Hat’s The State of Enterprise Open Source.

Why do we care? 

Changing perceptions… that’s my thought today.    Open source isn’t the risk it was.   MSPs themselves are more the target than their customers.    
If I were still working for a vendor, I’d have taken the N-Able data to imply how much security matters for MSPs.   Now, my analysis adds the other side – MSPs are at greater risk even than their customers.    

It’s about challenging assumptions – so-called Best Practices.   Those change over time, and it’s important not to forget that.   I’m pondering a lot of those right now.

Choose your upgrade:

Get the full benefits of Business of Tech Plus

Insider Access

$12/month

Perfect for MSPs and ITSPs that want full interviews, early access, and ad-free listening

  • Programmatic Ad-free private podcast feedSame show, little interruptions
  • Channel Chatter previews1–2 topics with light insights
  • Early access to interview episodesHear it days before public release
  • Monthly Insider BriefTighter analysis you can share internally
  • Extra audio segmentsCut interviews, behind-the-scenes commentary, quick competitive notes
  • Become an Insider for $12/month

    Leadership Access

    $149/month

    Perfect for MSPs and Vendors that run a team and need the extended tactics, executive summaries, and weekly alignment brief

  • All Insider Access benefits plus . . .
  • Invite your teamIncludes access for 5 team members with option to add more
  • Vendor Strategy BriefsThe entire library, plus new analysis every month
  • Channel ChatterAll topics, full insights, complete vendor discussion + sentiment list
  • Quarterly State of the Channel Briefing
  • Monthly AMA submission priorityAsk Dave direct questions, and skip the line
  • Get the Leadership Edge for $149/month

    Vendor Partner

    $500/month

    Perfect for channel companies or vendors looking to deepen their engagement with the show.

  • All Leadership Access benefits plus . . .
  • Get highlighted as a show sponsor You'll get placement in the show notes, throughout the website, and on our dedicated sponsors page.
  • Enjoy regular shout outs You'll be featured in a rotating format during the show
  • Become a show sponsor for $500/month

    Search all stories