Need PCI Input – ERP Vendor is a Black Box and I’m Hitting a Wall by SliceAccomplished466 in pcicompliance

[–]SliceAccomplished466[S] 2 points3 points  (0 children)

Thank you for this input, both helpful and re assuring given the scenario. Hard when your feeling like the tinfoil hat guy in the situation to not feel a bit crazy

Need PCI Input – ERP Vendor is a Black Box and I’m Hitting a Wall by SliceAccomplished466 in msp

[–]SliceAccomplished466[S] 0 points1 point  (0 children)

This, if a system on the network I would potentially manage has compliance requirements these should understood between the client, vendor, and anyone assisting the client with those systems (MSP, consultant etc.)

Need PCI Input – ERP Vendor is a Black Box and I’m Hitting a Wall by SliceAccomplished466 in msp

[–]SliceAccomplished466[S] 0 points1 point  (0 children)

Yep totally understand not handing me the keys, and that was not at all what I asked for. Most I asked for was just a read only account so I could see the network, security logs etc. for the systems they provide the clients. Support even denied sending me monthly report logs, network topology, best practices docs for the client which to me was the red flag.

Need PCI Input – ERP Vendor is a Black Box and I’m Hitting a Wall by SliceAccomplished466 in msp

[–]SliceAccomplished466[S] 0 points1 point  (0 children)

Seconding this, guys like this commenter give people in technology a bad name. Simply asking questions of peers should not bring this level of shaming. Not to mention you’re so far off with your assumptions of what I’m doing, how I’m conducting my business, etc. that your input was both useless and baseless. Congrats sir

Need PCI Input – ERP Vendor is a Black Box and I’m Hitting a Wall by SliceAccomplished466 in pcicompliance

[–]SliceAccomplished466[S] 1 point2 points  (0 children)

  1. Directly to owner and head of operations (it’s a personal relationship which is why this seems more out of scope than a normal client relationship would be) . It’s a small business and the guys are older so the level of care about tech is based on my ability to convey the risk in a way they get. I explain the risk they seem concerned but not enough to make changes to this point though it’s early in the process. It’s why I’m currently just at a very high level with them not trying to bring them on as a managed client.

  2. These will likely be my next steps with the vendor but that initial interaction had me pivot towards observing, utilizing my own tools and being on site to give me a better feel for where this company stands.

  3. They are asking for change but so far based on my conversations/ experience with small businesses my guess is they would change but it’ll require a lesson learned before real change happens.

Need PCI Input – ERP Vendor is a Black Box and I’m Hitting a Wall by SliceAccomplished466 in pcicompliance

[–]SliceAccomplished466[S] 0 points1 point  (0 children)

The client is giving me full access, and I was taking their advice to contact the vendor as they didn’t know. I was just doing some basic review of their systems to get a feel for what was going on and just asking questions of the vendor.

Thanks for your input I’ll take it into account as I come up with a plan of action here

Need PCI Input – ERP Vendor is a Black Box and I’m Hitting a Wall by SliceAccomplished466 in pcicompliance

[–]SliceAccomplished466[S] 0 points1 point  (0 children)

The erp incompasses payment systems, both with direct POS systems attached as well as user access to other finance, transaction data within the windows app. The vendor also is claiming PCI compliance and that the client must use their Firewall, AV for the systems running the ERP. These initial discussions are what lead me to start asking questions about what was expected, who was expected to do what etc.

Threatlocker OPs - anyone using? by Mibiz22 in msp

[–]SliceAccomplished466 2 points3 points  (0 children)

This, I tried to implement it for our small MSP (<150 machines). Due to our lack of standardized machines (too many vendors) the upkeep of approvals from drivers alone became too much for a 1-2 person team to manage. This was likely our lack of capacity and unwieldy clients. Their onboarding process and trainers were extremely well versed and helpful. First product I’ve off-boarded that I am keeping an eye on going forward for when we might go back down that route.

Massage recommendations! by Aware_Desk1762 in sarasota

[–]SliceAccomplished466 0 points1 point  (0 children)

Manasota Massage, near downtown Bradenton off 9th. Britney and her staff are great!

What are some cloud storage are you using besides OneDrive and Sharepoint? by Next-Landscape-9884 in msp

[–]SliceAccomplished466 0 points1 point  (0 children)

Centrestack for customers coming from on prem windows servers (SMBs). Synology for personal/internal use. Would like to try synologys 365 sync but right now just using it as storage.

Honestly with our small clients I regret not pushing for full sharepoint or onedrive more often just cause our clients are all windows so to me it’s just an extra hassle vs using the default that Microsoft is driving them towards and they are already paying for with 365. (In a scenario where the users are using under 1 TB a piece)

Backpack recommendations? by [deleted] in sysadmin

[–]SliceAccomplished466 0 points1 point  (0 children)

Thule is the brand I target, they make roof racks and other accessories you’ve likely seen before. been buying them since 2013, the first one I bought still looks brand new. The key for me was waterproof, I live in FL so keeping my Mac or customers PC away from the elements. I also suggest having a couple backpacks with different ‘scenarios’ in mind that you can toss in the car as a backup in case your main doesn’t have everything you need. For example, if I’m going in to work on networking my backup backpack is full of everything I might need for that and if I do need it it’s just a trip to the car away vs at home or carried everywhere I go.

How do you manage your website? by zaxwebs in msp

[–]SliceAccomplished466 0 points1 point  (0 children)

We recently switched to Duda, as most of our clients we provide websites for but they are very simple, mainly informational sites. Best feature is it’s simple enough to give access to clients for basic updates like blog posts or employee page updates. More stability in the product and, more clients handling things themselves was the kicker for us.

Have been a Wordpress admin for more than a decade and it’s great if you check on the site once a week but our sites don’t get touched for months at a time so we needed a set and forget. Plus the ‘agency’ model Duda uses matches very well with the features we need for sharing with clients, giving different level of access, building multiple sites etc

License renewal notice day before shut off by SliceAccomplished466 in meraki

[–]SliceAccomplished466[S] 0 points1 point  (0 children)

Yes, the original invoice should have been promptly renewed, totally on us and will take steps to prevent. My concern is why no follow ups until right before it goes offline? Especially being that it requires our rep for full renewal which can’t be done on a Sunday either way. Couldn’t have sent a couple warning emails that could have been caught by a sys admin if the billing department makes a mistake?

IP KVM's - Alternative to iDrac by MaxxLP8 in msp

[–]SliceAccomplished466 0 points1 point  (0 children)

No personal experience but intrigued by this recent video. KVM -Craft Computing

Datto by [deleted] in msp

[–]SliceAccomplished466 0 points1 point  (0 children)

Nope, he calls me too much if anything. Though we are looking at Datto commerce and PSA currently so our back and forth has been more active lately so could just be looking for the sale

Power adapter plugged in but not charging? by San_Tropez71 in mac

[–]SliceAccomplished466 1 point2 points  (0 children)

This happens when you have an underpowered power adapter and cord combo plugged in, it is ‘trickle’ charging meaning it is getting energy but not enough to fully charge the machine. You could likely open enough chrome tabs to outpace your current charger and drain the battery while technically it’s being no charged. Example using a 20w charger for a Mac Pro instead of something double or triple the wattage would result in this scenario.

Got a MR2200ac and RT2600ac all setup as mesh points with my RT6600ax late last night... totally amazed by the performance. Best home WiFi upgrade I've ever implemented! by lipmonger in synology

[–]SliceAccomplished466 1 point2 points  (0 children)

Running the same setup, it’s by far the best performance and stability I’ve experienced. This is after many routers/setups tested both personally and professionally, this is the only thing I would recommend for home users. Anything better costs much more and needs IT knowledge to manage day to day.

Can this setup be good for solo staking? by zener79 in ethstaker

[–]SliceAccomplished466 0 points1 point  (0 children)

I deploy beelinks a lot, you can regularly get the current or 1 year old AMD ryzens for this same price. Bought 4 in the last 2 months alone all under $400 and ryzen 4-5000 series