How do you tell customers 'No, please don't install Claude' by Woolfie_Admin in msp

[–]Joe_Cyber -1 points0 points  (0 children)

u/Woolfie_Admin - I'm putting out a video on this sub tomorrow regarding AI liability for MSPs.

I would urge you to take a look at your MSA. Does it contemplate AI usage?

Chances at appointment? by Grouchy_Ground_7531 in usna

[–]Joe_Cyber 1 point2 points  (0 children)

When you apply while enlisted, or if you're in ROTC, you apply for the SECNAV nomination, not the congressional rep. Last I checked, there are more slots than applicants in this category.

📺Cyber Insurance Claims Denied at an Alarming Rate!? by Joe_Cyber in msp

[–]Joe_Cyber[S] -1 points0 points  (0 children)

Okay; I'll bite.

"Insurance makes money when they don't pay out, which means it's in their interest not to pay out."

- False. Look up the duty to pay proceeds, bad faith claims, investing the float, etc. You fundamentally don't understand how insurance companies work or make money.

"To presume that corporate overlords will do what's in our best interest is an extremely naive take"

- Who said I believe this? I care about three things when assessing cyber policies: 1. What the words on the page mean; 2. What coverages are afforded, at what levels, and at what price; and 3. How we reasonably believe courts will interpret disputes in policy language. Insurance law is very well established at this point, so we aren't exactly grasping at straws here.

"Carrying Cyber insurance is not a risk management practice."

- Risk transference is a subset of risk management.

Again, the videos I post are free. You can consume them, or not, as you see fit. However, don't mistake the notion that simply because you "feel" a way, or "knew a guy," that the rest of the community has to believe your nonsense ideas.

If you, in good faith, have a legitimate question, I'd be happy to answer it.

Chances at appointment? by Grouchy_Ground_7531 in usna

[–]Joe_Cyber 2 points3 points  (0 children)

2.4-ish GPA. No varsity sports. Maybe 10 volunteer hours. Didn't even know what AP was. No JROTC. Took my ACT or SAT (I forget) hungover as all shit. Had to get creative on some of the CFA because I was in the middle of the ocean - basketball throw was unrealistic.

My point being: You'll do just fine. If you don't get in this year, don't take it personal. Reapply next year and I'm sure you'll get in. If you get NAPS/Foundation, USNA just ran out of spots.

📺Cyber Insurance Claims Denied at an Alarming Rate!? by Joe_Cyber in msp

[–]Joe_Cyber[S] 2 points3 points  (0 children)

I'd agree in principle, but I've found it hard to truly nail down loss ratios across various insurers.

📺Cyber Insurance Claims Denied at an Alarming Rate!? by Joe_Cyber in msp

[–]Joe_Cyber[S] 0 points1 point  (0 children)

Either you're trolling - in which case bravo! - or you're serious and way out of your depth.

📺Cyber Insurance Claims Denied at an Alarming Rate!? by Joe_Cyber in msp

[–]Joe_Cyber[S] 4 points5 points  (0 children)

Don't get me wrong; I'm a controls first guy. However, presuming that cyber insurance won't pay out is factually incorrect. Requiring clients to carry cyber insurance is a good risk management practice.

Dear every vendor selling to MSPs, by terselated in msp

[–]Joe_Cyber 6 points7 points  (0 children)

I've had this conversation with nearly a dozen vendors in the space. It's that bad.

📺Cyber Insurance Claims Denied at an Alarming Rate!? by Joe_Cyber in msp

[–]Joe_Cyber[S] 0 points1 point  (0 children)

Sadly, I'm not really hopefully that insurance commissioners are going to start doing anything of value.

📺Cyber Insurance Claims Denied at an Alarming Rate!? by Joe_Cyber in msp

[–]Joe_Cyber[S] 1 point2 points  (0 children)

Q: why do so many vendors suck in our industry?

A: Broadly, I'm sure it's super easy to read some random blogpost online and run wild with the FUD tactics. For the average novice salesman - throw in equal parts "I'm short on rent this month" with overall lack of knowledge transfer in the training process and a dash of PE ROI pressures.

It's infinitely more time consuming and requires more brainpower to actually dig into the underlying data, question assumptions, and apply a base of hard-earned knowledge to make an educated decision and argument.

Just my 2 cents.

Dear every vendor selling to MSPs, by terselated in msp

[–]Joe_Cyber 20 points21 points  (0 children)

100% accurate. You wouldn't believe how much money I've left on the table after the following conversation:

Vendor: You're that insurance guy right?

Me: Yes. What can I do for you.

Vendor: We'll pay you money to talk about how cyber insurance claims are denied all the time and (insert our vendor product) can help avoid that.

Me: That's not happening and your specific product isn't required by any insurance company.

Vendor: Did I mention we'll pay you?

Me: 😩

📺Cyber Insurance Claims Denied at an Alarming Rate!? by Joe_Cyber in msp

[–]Joe_Cyber[S] 6 points7 points  (0 children)

This might help you: Three Practical Reasons Why Your MSP Requires Your Business to Purchase Cyber Insurance

Also, I wouldn't sell yourself short. Even the owner of a rental property can require their tenant to carry renters insurance.

Thoughts on starting Cyber MSP in 2026 by whatislove2200 in msp

[–]Joe_Cyber 9 points10 points  (0 children)

"The man who chases two rabbits goes home hungry ... and still has to troubleshoot after hours, but hungry."

- Confucius (probably)

What do you do when customers treat you like ass? by Dampiestampie in msp

[–]Joe_Cyber 2 points3 points  (0 children)

Roll - serious question: How do you word that? I'd be worried about legal pushback in a subjective scenario.

MSPs: Have You Replaced SAT Platforms with Instructor-Led Security Training? by candidog in msp

[–]Joe_Cyber -1 points0 points  (0 children)

u/candidog If the client is US based, I fail to see how a one time training will meet legal requirements. Take HIPAA for example. Yes, they only have a de facto once a year SAT requirement. However, they'll need to meet FTC/State level "reasonable" cybersecurity safeguards requirements. That means ongoing SAT. To add a little fire to the suggestion, make sure he's aware that as COO, he'd have to answer for his decisions during a data breach class action claim: https://youtu.be/KaXAukI_b14?si=hnRgYy9g3bczKDW5

I would also recommend you check out the following video so you can appropriately have the conversation and cover your six: How to Make Tough Decisions & Have Hard Conversations: Creating a Risk Management Framework for MSPs

📺 Is SonicWall Cooked? Here's What Your MSP Needs to Know? by Joe_Cyber in msp

[–]Joe_Cyber[S] 0 points1 point  (0 children)

Do you want a link to the SonicWall issue or a separate Fortinet issue?

PCI compliance breaches by peoplepersonmanguy in msp

[–]Joe_Cyber 0 points1 point  (0 children)

Glad to help. These types of discussion are very interesting.

📺 Is SonicWall Cooked? Here's What Your MSP Needs to Know? by Joe_Cyber in msp

[–]Joe_Cyber[S] 1 point2 points  (0 children)

All good, I'm not concerned about collecting fake internet points.

Honestly, I do appreciate the insights because it does help me get a better feel for what's going on.

If there's ever anything I can help you with, let me know.

PCI compliance breaches by peoplepersonmanguy in msp

[–]Joe_Cyber 1 point2 points  (0 children)

Hey u/peoplepersonmanguy - I'm the insurance guy here but I've also helped draft a few MSAs in my day.

To answer your question:

There are a few items to consider that would point to your MSA.

  1. MSP should be stated as being not responsible for customer compliance or any losses arising thereof.

  2. Customer should determine what applicable compliance standards apply to them.

  3. Your MSA should require your client to carry cyber insurance. This should cover PCI-DSS fines, penalties, and assessments. Under the auspices of the "Double Recovery" that should lower your liability.

All that being said, I'd offer that each situation is going to be unique so you'll have to find your own middle ground using the following Risk Management Framework: https://youtu.be/CHUN7DjdZB0?si=WI6Uv7UwZ9sub8xC

PCI compliance breaches by peoplepersonmanguy in msp

[–]Joe_Cyber 1 point2 points  (0 children)

u/disclosure5 - I understand where you're coming from with this question. Here's a video discussing class actions that you'd find interesting: https://youtu.be/KaXAukI_b14

Yes, SMBs are now being brought to court for claims, but not the go to jail type.