After 20 years, we've closed the chapter on Tubblog - The Hub for MSPs

TubbTalk 179: Risk and the ROC Solution: What to Know for Growth

TubbTalk 179: Risk and the ROC Solution: What to Know for Growth image

Matt Middleton-Leal is the Managing Director, EMEA North, of Qualys, a pioneering and disruptive cloud-based IT, security and compliance solutions provider.

An Interview With Matt Middleton-Leal

What MSPs are Missing About Risk

When we hear the words ‘vulnerability’ or ‘risk’, says Matt, there’s a tendency for MSPs to just jump straight in with a solution. However, he suggests a different, more effective approach:

“Step back and say, ‘What are you trying to secure and why? What’s the inherent risk if you don’t secure it?’ Because they might not need a vulnerability management tool. Maybe they need a patching tool, or something completely different.

“When that happens, the MSP has missed the point and therefore an opportunity to sell their services and solve a pain point. So I always encourage people to step back and say ‘why’ and explore the benefit the client is looking for before you do anything else.”

Why Qualys Provide a ROC Solution

A few years ago, Qualys decided to introduce patching for CISOs so they could remediate risks. Matt explains: “And a lot of people laughed. They didn’t want to take responsibility for mediation of threats and vulnerabilities – they just wanted to report them.

“But we found that what we were doing up to that point wasn’t working. SOCs (security operations centres) were finding, triaging and solving incidents, but really by that point it’s too late. 

“So a ROC (risk operations centre) is proactive. It measures the risk, communicates with the right stakeholders in the business about it and then solves the problem. It also give the CISO more data to report back to the CFO on where there are risks and how these are increasing business costs.”

The Opportunity for MSPs and MSSPs in Offering a ROC

Having a ROC is about bringing together multiple capabilities, integrating them and normalising the risk data. It’s not about the things that are traditionally done in the SOC, Matt says. He shares the four key service areas that Qualys have identified.

“We believe that the MSPs can build their business around cyber risk quantification advisory services. There’s high level consultancy to quantify the financial impact of risk. Then, there’s onboarding technologies to help clients manage it.

Thirdly, there’s ongoing risk monitoring services, and finally remediation services. These combined, with or without the use of Qualys technology, will help MSPs to help their clients to change the way they do business and get ahead of threats.”

What do #MSPs need to understand about risk and managing it? And what the heck is a #ROC? Matt Middleton-Leal of @qualys explains all. Click to Share

How the ROC Approach can Reduce CISO Burnout

Matt acknowledges that CISOs are asked to do a lot, and it’s a challenge to afford enough staff, meaning those that are in a company work even harder. “So I think leveraging technology will make a massive difference.

“And to me, that’s through automation of repetitive tasks. It won’t solve all the problems, but it will reduce stress and remove pointless tasks for people. For instance, a lot of time is spent on patching, but the risk perspective is very low. 

“Start looking for areas of low risk, high volume issues where you can start to remove the workload and allow people to focus on high risk items. If you measure through risk, this is straightforward. And it reduces overwhelm and makes people feel more valued and appreciated.”

How to Stay Ahead of the Cybersecurity Curve

For UK-based MSPs, it’s important to stay up to date with what the National Cyber Security Centre (NCSC) is doing and the guidelines they produce, says Matt. Look into Cyber Essentials and the Plus version.

“However, what’s more important is that the NCSC then challenged MSPs by asking them to aim to patch high risk vulnerabilities on internal systems within seven days of detection and external ones within five days of detection.

“Now, these are just guidelines for the moment. But forward-looking MSPs and MSSPs should be thinking of how they can build their services and support offering to help their clients remediate or eliminate risks faster. We know that cybercriminals quickly exploit vulnerabilities, so adhering to the guidelines is key.”

How to Show Your Clients You’re Mitigating Risk for Them

The easiest way to show how you’re protecting your clients comes down to KPIs (key performance indicators), says Matt. You should have an agreed set of deliverables and articulate how you’re progressing with them. He adds:

“Look for quick wins. Find partners who want to improve their business, agree those deliverables and give them the outcome they want. That’s not ‘I detected some malware’; it’s ‘I protected your system from getting hit by malware.

“Be clear about how you measure your KPI and communicate clearly and regularly with your clients so they know you’re being proactive. Always share when you’ve removed a risk and continually demonstrate your value.”

How to Connect With Matt Middleton-Leal

How to Connect With Me

Mentioned in This Episode

You Might Also be Interested in

RICHARD TUBB

Richard Tubb is one of the best-known experts within the global IT Managed Service Provider (MSP) community. He launched and sold his own MSP business before creating a leading MSP media and consultancy practice. Richard helps IT business owner’s take back control by freeing up their time and building a business that can run without them. He’s the author of the book “The IT Business Owner’s Survival Guide” and writer of the award-winning blog www.tubblog.co.uk

All Posts

You might like:

Wired for Connection 11: Equality, Diversity and Strong Leadership for Successful Modern MSPs image

Wired for Connection 11: Equality, Diversity and Strong Leadership for Successful Modern MSPs

Podcasts | By Lenka Koppova
Wired for Connection 10: How Positive Thinking Makes you a Better Leader image

Wired for Connection 10: How Positive Thinking Makes you a Better Leader

Podcasts | By Lenka Koppova
Wired for Connection 9: Be Grateful, Make Human Connections & Avoid Burnout image

Wired for Connection 9: Be Grateful, Make Human Connections & Avoid Burnout

Podcasts | By Lenka Koppova
TubbTalk 189: The Final TubbTalk: Saying Goodbye to Tubblog image

TubbTalk 189: The Final TubbTalk: Saying Goodbye to Tubblog

Podcasts | By Richard Tubb
Wired for Connection 8: Diversity, Leadership & Being a Strong Woman in Tech image

Wired for Connection 8: Diversity, Leadership & Being a Strong Woman in Tech

Podcasts | By Lenka Koppova
TubbTalk 188: MSP Exits Uncovered: Everything You Wanted to Know (But Didn’t Ask) image

TubbTalk 188: MSP Exits Uncovered: Everything You Wanted to Know (But Didn’t Ask)

Podcasts | By Richard Tubb
TubbTalk 187: Smarter MSPs, Microsoft 365 & The Future of Managed Services image

TubbTalk 187: Smarter MSPs, Microsoft 365 & The Future of Managed Services

Podcasts | By Richard Tubb
TubbTalk 186: Better MSP Sales: No Hard Sell, Just More Confidence image

TubbTalk 186: Better MSP Sales: No Hard Sell, Just More Confidence

Podcasts | By Richard Tubb
TubbTalk 185: How NetSec Became Emerging MSP of the Year image

TubbTalk 185: How NetSec Became Emerging MSP of the Year

Podcasts | By Richard Tubb
Wired for Connection 7: Empathy and Sounding Boards: How to Deliver Partner Care image

Wired for Connection 7: Empathy and Sounding Boards: How to Deliver Partner Care

Podcasts | By Lenka Koppova
Wired for Connection 6: Empowering MSP Teams to Deliver Better Customer Services image

Wired for Connection 6: Empowering MSP Teams to Deliver Better Customer Services

Podcasts | By Lenka Koppova
TubbTalk 184: The MSP’s Guide to LinkedIn Growth: Expert Tips from John Espirian image

TubbTalk 184: The MSP’s Guide to LinkedIn Growth: Expert Tips from John Espirian

Podcasts | By Richard Tubb

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore.

Share via
Send this to a friend