Podcast charts
Published by Chris Johnson | Cybersecurity Education & Security Guidance
Educational sound bytes to help MSPs and their clients navigate Cybersecurity. Cybersecurity maturity is a journey; don't go it alone. Interviews and guidance from fellow MSPs and other Industry experts. Our goal is Secure Outcomes, and together we can make a difference.
On the charts
Every published chart this podcast appears in, in the snapshot behind this page. Each one links to the chart it came off.
The Mato Topic Intelligence Platform does not report this podcast as charting in a published category in this snapshot.
From the feed
The latest episodes published to this podcast’s own RSS feed. Titles and descriptions are the publisher’s.
In this episode of MSP 1337 , Chris sits down with Dr. Stephen Wright of Macadamia Solutions , a rare expert whose career spans technology, law, and business. Together they explore why governance has become the defining challenge of the AI era and why many organizations remain dangerously unprepared. The conversation examines how regulatory requirements, cybersecurity obligations, and emerging AI risks are reshaping boardroom accountability. Dr. Wright breaks down the growing threat of deepfakes, data poisoning, and data suppression, explaining how attackers increasingly target data integrity and the people who make decisions based on it, rather than traditional IT systems alone. The discussion also explores the unintended consequences of technology legislation, regulatory capture, supply chain risk, remote work security, and the persistent governance challenges that prevent organizations from achieving true cybersecurity maturity. For MSPs, IT leaders, and business executives, this episode provides a practical look at the intersection of governance, risk, security, and compliance, and why effective governance may be the single most important capability organizations need to navigate the future of AI.
Every vendor has an AI roadmap. Every client has employees experimenting with AI. And increasingly, MSPs are building their own AI solutions. The challenge is that few organizations fully understand the risks that accompany this rapid adoption. In this episode of MSP 1337, Chris Johnson and Jim Harryman discuss what responsible AI deployment actually looks like. They explore AI governance, vendor accountability, security testing, client readiness, and the dangers of allowing AI unrestricted access to sensitive information. Rather than treating AI as a shortcut, they argue for a disciplined approach that prioritizes transparency, validation, and human oversight. For MSPs trying to separate opportunity from hype, this conversation offers practical insights on asking better questions, managing emerging risks, and building a foundation for sustainable AI adoption. "The biggest AI risk isn't the technology. It's deploying it before governance catches up."
Many MSPs and businesses believe they're prepared for an outage because they have backups, redundant internet connections, or cloud-based applications. In reality, most recovery strategies fall apart when tested in real-world scenarios. In this episode of MSP 1337, Chris Johnson sits down with Charles Love of Showtech Solutions to explore the dangerous gap between perceived resilience and actual preparedness. They discuss why incident response plans must come before tabletop exercises, how internet redundancy often fails under scrutiny, and why MSPs should treat their own operational dependencies with the same rigor they apply to clients. From protecting the "core four" business applications to safeguarding documentation, passwords, and recovery keys, this conversation delivers practical guidance for building recovery plans that work when systems fail and chaos begins.
Most MSPs don't have a compliance problem. They have a starting problem. Michael Zbarsky of Blacksmith InfoSec joins MSP1337 to challenge some of the biggest misconceptions surrounding compliance, security frameworks, and cybersecurity maturity. From the GTIA Cybersecurity Trustmark and CMMC to evidence automation and third-party assessments, the discussion focuses on what actually moves organizations forward and what keeps them stuck. Michael shares why "good enough" today is often better than "perfect" next year, why automation cannot replace human judgment, and why MSPs are uniquely positioned to lead both their own organizations and their clients toward stronger security outcomes. If you've ever felt overwhelmed by compliance requirements, unsure where to begin, or skeptical that another framework will help, this episode offers a practical roadmap for turning intention into action.
The MSP market is changing fast. Clients can buy technology anywhere, automate routine tasks, and access powerful AI tools with just a few clicks. The real question is no longer what technology you sell. It's whether you can help clients manage the business risks that technology creates. This week, Chris Johnson welcomes back Auggie Staab from TD SYNNEX to discuss the next evolution of managed services. Together they explore how AI is disrupting traditional service delivery, creating new compliance and cybersecurity challenges, and forcing MSPs to rethink their value proposition. From shadow AI and data privacy concerns to automation-driven growth opportunities, this discussion examines why governance, strategy, and risk management may become the most valuable services MSPs provide.
In this episode, Chris sits down with MJ Patent to explore the foundational principles that help Managed Service Providers grow, mature, and thrive in today's increasingly complex IT and cybersecurity landscape. Drawing from her extensive experience working with service providers of all sizes, MJ explains why many MSPs struggle to scale evenly across their business and why success starts with understanding exactly who you serve, the problems you solve, and the value you create. Together, they discuss the dangers of chasing every new technology trend, the importance of specialization, and how strategic partnerships can help MSPs deliver more without overextending their teams. The conversation also examines the growing role of fractional leadership services, including vCIOs, vCISOs, and fractional CMOs, and how MSPs can evolve from technology providers into trusted business advisors. Chris and MJ share practical insights on navigating cybersecurity complexity, managing risk, demonstrating ROI, and shifting customer conversations from service-level agreements to measurable business outcomes. Whether you're looking to refine your service strategy, strengthen customer relationships, or build a more scalable MSP, this episode offers actionable guidance for creating sustainable growth through focus, trust, and strategic leadership. Key Takeaways: Why MSP growth depends on balancing operational maturity across the business How specialization creates stronger customer relationships and better outcomes The evolving role of vCIO, vCISO, and fractional leadership services Why trust, risk management, and business outcomes matter more than SLAs How strategic marketing leadership can accelerate MSP growth Practical advice for demonstrating value and earning long-term client loyalty Recommended Reading: Brave Thinking by Mary Morrissey. Perfect for: MSP owners, IT service leaders, cybersecurity professionals, channel partners, and anyone looking to build a stronger, more strategic technology services business.
Human risk has become one of the most challenging and misunderstood aspects of cybersecurity. In this episode of MSP 1337, Chris Johnson sits down with Nihil Morjaria from usecure to explore why traditional security awareness training is no longer enough and what it takes to build a truly proactive human risk management strategy. The conversation examines how MSPs and ITSPs are evolving beyond technology management into governance, risk, and compliance, and why understanding user behavior is now just as important as managing firewalls and endpoints. Chris and Nihil discuss the limitations of one-time phishing exercises, the rise of shadow IT and AI-driven data exposure, and the growing need to combine security awareness, breach intelligence, password hygiene, and user behavior into a single view of risk. Listeners will learn how leading providers are using human risk intelligence to prioritize remediation efforts, reduce alert fatigue, empower end users, and deliver measurable security outcomes for clients. Whether you're struggling with phishing failures, unsanctioned applications, or simply trying to make security awareness more effective, this episode offers practical insights for turning your users from a potential liability into a powerful line of defense.
In this episode of MSP 1337, episode 300, Chris Johnson sits down with Matt Lee for a candid fireside chat on one of the most misunderstood topics in business and cybersecurity: governance. Using relatable examples, from concrete truck deliveries to vacuuming a floor, Matt breaks down why governance isn't about policies, paperwork, or compliance checklists. It's about setting clear goals, assigning accountability, managing risk, and ensuring everyone works toward the same outcome. The conversation explores why governance has historically been treated as an afterthought in IT and security, why separating security from IT often creates more problems than it solves, and how organizations can build stronger operational resilience through shared leadership, stakeholder alignment, and intentional decision-making. More importantly, Matt challenges listeners to stop viewing governance as a bureaucratic exercise and start seeing it as the foundation that enables security, operations, and business success. Because when governance is missing, even the best tools, frameworks, and people struggle to deliver consistent outcomes. If you've ever wondered why organizations with great technology still experience recurring failures, it's tied to the absence of governance. Key Takeaway: Security doesn't create accountability. Compliance doesn't create resilience. Governance creates the conditions that make both possible.
Most organizations don't have a security tool problem, they have a signal-to-noise problem. Chris and Tatum Treadwell dive into the realities of securing decades-old technologies against modern attackers, the rise of AI-enhanced social engineering, and the growing challenge of alert fatigue. The conversation explores why education, human judgment, and meaningful action matter more than flashy marketing claims, offering MSPs a practical perspective on building resilience in an increasingly complex threat environment.
Everyone talks about email phishing, ransomware, and endpoint security, but one of the most dangerous attack vectors is sitting in your pocket. In this episode of MSP1337, Chris Johnson sits down with Mark Kreitzman of Efani to expose the growing threat of SIM swapping, mobile account takeovers, and the hidden security gaps traditional carriers have failed to solve. They explore why mobile numbers remain a critical trust anchor for banking, MFA, and identity verification, how carrier business models contribute to risk, and what individuals and organizations can do to better protect themselves. The conversation also examines secure phones, privacy realities, and why true mobile security requires protecting the account behind the device, not just the device itself. There are some perks to going to the following efani landing page: https://efani.com/msp1337
The cybersecurity industry loves to sell tools. What it rarely talks about is the hard work required to make those tools effective. In this episode, Jim Harryman joins Chris to challenge the idea that technology alone creates security. They discuss why mature organizations focus on governance, accountability, documentation, policies, review cycles, and operational discipline long before they look for the next shiny solution. If you've ever mistaken a technology purchase for progress, this conversation may be the reality check your organization needs.
Planes, hotels, and conference stages aren’t what put you at risk, it’s what you bring with you. In this episode, Dawn Sizer of 3rd Element dives into the real reasons traveling professionals become easy targets: weak policies, poor communication, unsecured devices, and total blind spots around personal data exposure. From conditional access headaches to rideshare risks and AI policy chaos, this is a practical, no-excuses look at how security breaks down in the real world, and what you need to fix before your next trip.
This episode explores how cybersecurity is evolving from point-in-time assessments to continuous, intelligence-driven operations. Galina Kho of Cyberbay shares how predictive analytics, crowdsourced ethical hackers, and AI are reshaping how organizations understand and manage risk. We discuss how to scale security without adding headcount, why human expertise remains essential, and how governance and trust underpin effective security ecosystems. The result is a clearer model for modern cybersecurity, proactive, collaborative, and built for constant change.
In this special episode of MSP 1337, CJ is joined by Brooke Lee (Rev.io) and Stacey Whitley (GTIA) to unpack how ITSPs can translate industry engagement into measurable outcomes. Attending events is easy, but most organizations struggle to turn what they learn into real operational outcomes. Brooke and Stacey share how their collaborative event recap initiative is helping bridge that gap by distilling key takeaways from major channel events into practical, accessible insights. More importantly, they highlight how GTIA serves as the connective tissue that sustains momentum beyond the event, enabling peer accountability, ongoing education, and real community engagement. The discussion reinforces the business value of GTIA membership beyond networking. From structured onboarding and mentorship to role-based education and vendor-neutral collaboration, GTIA provides a scalable approach to developing teams, reducing isolation, and accelerating organizational maturity. Brooke’s perspective on embedding GTIA into Rev.io’s onboarding model illustrates how intentional engagement can drive adoption and long-term ROI. Cybersecurity is a central theme, with a focus on GTIA’s Cybersecurity Resource Hub, ISAO, and the GTIA Cybersecurity Trustmark Best Practices. Stacey emphasizes the importance of community-driven intelligence and real-time peer support, particularly during incidents, capabilities that many ITSPs struggle to access independently. The episode closes with a candid look at how authentic, experience-driven content, rather than polished production, builds trust, strengthens relationships, and lowers barriers to participation across the channel. Bottom line: GTIA is more than membership, it is more than a community, and as an association, it is greater than the sum of its parts. GTIA is a force multiplier for learning, accountability, and cybersecurity maturity when actively leveraged.
In this episode, Josh Hohbein of CentrexIT breaks down a practical, MSP-centric approach to risk assessments that moves beyond complex, consultant-driven reports and toward clear, actionable business outcomes. He shares how combining vulnerability scans, client interviews, and system configuration reviews, anchored in a cyber maturity model, helps MSPs translate technical findings into meaningful risk conversations, especially during onboarding. The discussion highlights the importance of ownership, communication, and collaboration in managing inherited client risk, while previewing a live demonstration session at Pack State Beyond, designed to equip MSPs with repeatable frameworks they can own. Ultimately, the episode reinforces that effective risk assessments aren’t about identifying more issues; they’re about enabling better decisions, strengthening governance, and driving measurable security maturity.
In this MSP1337 fireside chat, you and Matt Lee unpack the idea of a “vulnpocalypse”, a rapidly emerging reality in which AI-driven tools are accelerating vulnerability discovery at a pace organizations can't keep up with. While much of the industry is focused on the fear and hype, the conversation shifts to what actually matters: operational response. You highlight that the shrinking gap between proof of concept and active exploitation is forcing a fundamental change in how MSPs and organizations manage risk, especially in patching velocity, exposure management, and accountability for internet-facing systems. The takeaway is clear: this isn’t just a future threat, it’s a present inflection point requiring faster, more automated, and governance-aligned security practices.
In this episode, Chris Johnson sits down with Eric Shoemaker of Genius GRC to unpack one of the most misunderstood shifts in the MSP space: the move from tool-driven cybersecurity to standards-aligned governance, risk, and compliance programs. Eric explains why Genius GRC isn’t a software platform and why that distinction matters. Together, they explore how early automation wins (like continuous access reconciliations) impressed auditors but didn’t replace the need for real governance, documented reviews, and independent judgment. As the market matures, the conversation turns to a growing risk: MSPs and SMBs stacking new security tools while core systems remain misconfigured and under-governed. Chris and Eric tackle the myth of “do-it-yourself” GRC, the dangers of vibe-based compliance, and why tools only amplify expertise; they don’t replace it. They also dig into the critical separation between IT operations and security leadership, making the case for advisory or independent CISO models that reduce conflicts of interest and improve risk outcomes. The discussion closes with practical, budget-conscious fundamentals, such as DNS filtering, CIS IG1, and free or low-cost controls that actually move the needle, plus hard truths about negligence versus resourcing failures and why resilience must be budgeted from day one. If you’re an MSP, consultant, or business leader navigating cybersecurity maturity, this episode is a grounded, no-hype look at what actually reduces risk.
In this episode of MSP1337 , Chris Johnson is joined by Jeff Majka, founder of Security Bulldog, to unpack why MSP‑delivered SOC services are at a breaking point, and how AI and automation are forcing a reset. They explore why traditional tiered SOC models and white‑label thinking no longer scale, how ungoverned AI adoption collides with zero trust, and why speed and decision quality now matter more than raw data or CVE counts. From ticket overload and false positives to exploitability, continuous monitoring, and breach resilience, the conversation underscores a hard truth: MSPs must redesign security operations around automation-first workflows that reduce noise, protect high‑value assets, and preserve human judgment for what truly matters in an AI‑accelerated threat landscape.
Chris Johnson sits down with Ido Green of Espresso Labs to explore how AI and local agents can reduce cybersecurity noise, offload Level 1 work, and continuously enforce compliance, without losing human control. They discuss guardrails for safe automation, multi-vendor telemetry, drift detection, evidence collection at scale, and why “reporting gaps” isn’t enough if you can’t execute remediation and preserve proof. The episode closes with a roadmap for frameworks, partnerships, and insurance-ready visibility.
A sit-down with Hamid Ganadan, author of “Not Buying It: The Art of Selling to Scientists, Doctors, and Other Professional Skeptics,” on how MSPs can sell to skeptical, highly educated buyers. This is an exploration of the psychology of decision-making, shifting prospects from skepticism to curiosity, leading with feelings over facts, crafting insights that differentiate offerings, and timing data to validate rather than trigger doubt. Hamid shares practical scripts, a lead follow-up case study that massively improved response rates. Selling cybersecurity doesn't have to be painful.
Ranking source
Apple Podcasts rankings via the Mato Topic Intelligence Platform.
Observed September 17, 2026. Cached outside the daily freshness window; the positions keep the date they were taken on.
Apple and Apple Podcasts are trademarks of Apple Inc., registered in the U.S. and other countries.
Pairs with
Bring this source into Mato to read its transferable patterns, then turn them into an original show for your own audience.