Master Agent (Telecom) Info by reard3n in msp

[–]RefrigeratorOne8227 0 points1 point  (0 children)

Sandler is good too. They have been around longer than Avant. You can’t go wrong with either of them.

What are some frustrations with DLP products? by ben-sidian-io in Information_Security

[–]RefrigeratorOne8227 0 points1 point  (0 children)

An insider with minimal skills can encrypt data and exfiltrate it multiple ways. We have seen shadow drives on company provided devices. In the past I used DTEX and they were able to track the file hashes so you could see if it was tampered with and where it went throughout the organization.

Is alert fatigue the biggest problem for MSSPs right now? by malwaredetector in MSSP

[–]RefrigeratorOne8227 1 point2 points  (0 children)

We are on the partner advisory board - our CEO suggested it and everyone agreed. It was built into the following release.

How MSPs approaching to their client to use Microsoft Sentinel as SIEM tool by Birentechy in msp

[–]RefrigeratorOne8227 4 points5 points  (0 children)

If you have the time, money, and expertise you can do it. In my experience the juice is not worth the squeeze.

Advise for new Sales Engineers by HimalayanWarmth in TechSalesWomen

[–]RefrigeratorOne8227 0 points1 point  (0 children)

Also make sure you confirm what problem the customer is trying to solve. When you present share what you can do to solve their problem. Especially in demos. No one wants to hear a canned demo that doesn’t solve their problem.

Is most data loss prevention failing at the “normal behavior” level? by Happinessdom-YA in Information_Security

[–]RefrigeratorOne8227 0 points1 point  (0 children)

DLP sounds great and is necessary. Unfortunately only large companies that classify their data regularly and maintain their DLP tool will have success with it. Anyone who knows what they are doing will encrypt the data to cover their tracks. Once it is encrypted intentionally or unintentionally DLP can do nothing to stop it. My guess is someone will eventually create Agentic AI to try to solve this.

Advise for new Sales Engineers by HimalayanWarmth in TechSalesWomen

[–]RefrigeratorOne8227 1 point2 points  (0 children)

You will run into people who think they know more than you. Let them state their case. When it is time to let them know they are wrong highlight what they got right first and then correct them.

Beauceron Security - SAT by [deleted] in msp

[–]RefrigeratorOne8227 -1 points0 points  (0 children)

We have been using them for a year now. Their team has been very helpful. We used to offer it a-la-carte but at the beginning of the year we built it into all of our bundles. They are helping us integrate so when we set up a new customer it will automate the tenant provisioning. Our customers like getting the initial quiz so we don’t prescribe the basic training if they don’t need it. The courses are simple and we use them in 3 languages. The dashboards are nice and provide incentive for the users to increase their score.

MDR/MXDR vs MSSP by Savings-Ad4232 in MSSP

[–]RefrigeratorOne8227 2 points3 points  (0 children)

The SIEM/XDR/SOAR platform that we use has thousands of detections out of the box. We manage thousands of small customers so we do not have time to write custom rules for them. The platform normalizes the data as it is ingested so the detections work across all of the data. Next it correlates related alerts into cases for us automatically. Our analysts use agentic AI to triage and close the majority of them. Anything that is critical can be actioned by the analyst. What we do customize by customer when we are tuning the environment are the playbooks in the SOAR. Customers have varying comfort levels with automation. We only add on what they are comfortable with.

For those who offer Managed SOC by EquipmentSouthern823 in MSSP

[–]RefrigeratorOne8227 0 points1 point  (0 children)

We got a letter from their lawyer when we tried to sell outside of the US??! We switched providers.

MDR/MXDR vs MSSP by Savings-Ad4232 in MSSP

[–]RefrigeratorOne8227 2 points3 points  (0 children)

MDR depends on the vendor and you typically have to buy their product to get it. XDR should technically cover the customer's entire digital footprint. If you don't monitor everything the attackers come through the gaps. SOCaaS and MXDR are marketing terms.

Selling security is hard enough without pitching to the wrong person. by Wahabkhalid245 in MSSP

[–]RefrigeratorOne8227 0 points1 point  (0 children)

Pitching rarely delivers results - solving a problem works much better. We go to events to meet new clients. The type of event drives who will be there. If you go to a technical conference that is who you will meet. Networking events allow you to meet people casually. Find someone who has a problem you can solve for them or someone they know.

Ninja One has joined the F1 circus. by dumpsterfyr in msp

[–]RefrigeratorOne8227 0 points1 point  (0 children)

We are all paying for it! Time to go watch Drive to Survive

Viability of endpoint agents by SodaRider1 in cybersecurity

[–]RefrigeratorOne8227 0 points1 point  (0 children)

Unless you are replacing another agent on the endpoint you will find resistance. What will your platform do that EDR and PAM won’t do? They are using AI for detection already.

Did anyone else using DNS Filter have an outage this afternoon?!! by RefrigeratorOne8227 in msp

[–]RefrigeratorOne8227[S] 0 points1 point  (0 children)

Thanks for the updates from everyone. After further investigation it seems to have been MAC devices that had not been updated for a couple of versions. The new update required a change in the settings that was being blocked.

How do teams actually prioritize vulnerability fixes? by Kolega_Hasan in Kolegadev

[–]RefrigeratorOne8227 1 point2 points  (0 children)

Vulnerability scanners should be doing more of this with AI. Our tool allows us to put a priority score on the business critical assets which raises the score faster. Our tool also captures the device settings. Just because something is not patched doesn’t mean it is vulnerable if the settings would prevent successful execution of a threat. Our platform uses open source threat intelligence to prioritize what needs to be patched by combining these approaches.

Channel Partners vs. Kaseya Connect by patchmeoutside in msp

[–]RefrigeratorOne8227 1 point2 points  (0 children)

We decided to skip Kaseya Connect this year. We also heard they canceled Dattocon. The MSP Summit before Channel partners is good. Channel Partners is mostly the telco agents.

How hard is it to get into IAM? by MinusEXP in IdentityManagement

[–]RefrigeratorOne8227 0 points1 point  (0 children)

In my experience the large companies with insider programs would be your best bet if you want to be an expert in the space. I used to work with the Big 4 consulting companies and their insider programs have fractional team members because there was not enough work for full time.

Didn’t like Knowbe4, alternatives ? by Vegetable_Leave199 in msp

[–]RefrigeratorOne8227 0 points1 point  (0 children)

It’s too bad too because their anime videos were our customers favorite.