The CyberCall Podcast

40 Episodes
Subscribe

By: Andrew Morgan

The Voice of Cybersecurity for MSPs & MSSPs!The CyberCall is the weekly podcast where cybersecurity meets business reality. Hosted by Andrew Morgan, Founder of Right of Boom, this is the go-to show for Managed Service Providers (MSPs), virtual CISOs (vCISOs), and IT leaders navigating the complex world of cyber risk, compliance, and AI.Each episode features raw, practical conversations with the sharpest minds in cybersecurity—from operators in the trenches to CISOs, researchers, policymakers, and toolmakers shaping the future. If you care about protecting your clients, growing your practice, and becoming the security partner businesses trust—this podcast is your play...

✂️ Turn this podcast into clips
MCP for MSPs: Cutting Through the Noise
Today at 9:00 PM

Most MSPs are asking the same question in a different way: "Do I need to care about MCP, or is this just another acronym I can ignore for six months?"

MCP Servers are becoming the connective tissue between AI agents and the tools you already run; your PSA, your RMM, your security stack. MSPs are using them to kick off assessments, run queries to determine continuous EDR deployment and many other critical tasks within the business.

So today we're getting digging into this topic to help you make good decisions. Where are MSPs are actually...


When AI is the Hammer, is Everything a Nail?
07/27/2026

Right now, every MSP is hearing the same sentence from clients: "We need AI." But when you start to ask questions like “what are you trying to accomplish,” there is no plan, no process, just a mandate. 

Our guest has heard it three times before. Ian Barkin built his career watching this exact cycle repeat, first in Business Process Outsourcing, then in Robotic Process Automation, and now in agentic AI. Same hammer, different decade. Companies are convinced the tool is the answer before they've asked what problem they're actually solving, or done the unglamorous work of documenting the p...


How MSPs Can Win Clients on LinkedIn: Turning Cyber Expertise into Pipeline
07/20/2026

Today we're doing something different. No tradecraft, compliance or threat intel. Today is about the other thing that keeps MSP owners up at night: where the next client comes from.

Here's the uncomfortable truth. Your buyers are on LinkedIn every single day and most MSPs are invisible there. Or worse than invisible: a profile that reads like a resume from 2014, three posts a year about patch Tuesday, and a network full of other MSPs and vendors. Everyone selling, nobody buying.

Our guest today built his entire company on fixing exactly that. Dean Seddon is the...


CMMC Phase II Paused: What Every MSP Needs to Know
07/20/2026

It's Thursday, July 16th, and three days ago the Department of War suspended CMMC Phase II, effective immediately. The third-party certification requirement that was set to hit on November 10th is gone for now, a reform task force has 60 days to review the entire program, and officials would not rule out scrapping it altogether.

Here's the thing: if you were paying attention, you saw this coming. Back in March, CIO Kirsten Davies sat in front of the House Armed Services cyber subcommittee and told lawmakers she was looking at CMMC through the lens of Secretary Hegseth's push...


Who’s Breach Is It – The Legal Grey Area of MSP Client Transitions
07/14/2026

Here's a scenario that's playing out right now, for several MSPs across the country, and based on our research, most do not have it covered in writing.

A client decides to switch providers. The new MSP starts rolling out EDR and standing up monitoring. The old MSP begins winding down. Somewhere in that overlap, credentials are still active, agents are only half deployed, and it isn't clear who's actually watching. Then the breach hits.

Now two MSPs are pointing at each other, the client's data is exposed, and everyone reaches for the contract, only to...


Inside the Credential Spray Hitting Microsoft 365
07/06/2026

This week we're digging into a Huntress report that came out on June 30th, updated just a couple days ago on July 2nd a large-scale password spray campaign that hit Microsoft 365 environments through Azure CLI. Between June 12th and June 26th, Huntress tracked more than 81 million login attempts, leading to at least 78 compromised accounts across 64 organizations.

What makes this one worth a full conversation isn't just the volume it's that a lot of the businesses hit already had Conditional Access policies and MFA in place. The attackers got in anyway, by using a deprecated OAuth flow called...


The Vulnpocalypse is here and your MSP can survive it
06/30/2026

Today we have one of the most important voices in cybersecurity joining us.

Chris Hughes started his career defending the nation in the United States Air Force. He's spent over two decades in the trenches from the Department of Defense to the federal government to the commercial world as a CISO, security architect, and engineer. 

Today he's VP of Security Strategy at Zenity, where his focus is on what he believes is the defining security challenge of our era: agentic AI.

He's the author of multiple books published by Wiley, including Modern Vulnerability M...


The Vulnerability Crisis No One is Funding
06/22/2026

Last week, I asked Philippe Langlois, principal author of the 2026 Verizon DBIR, a simple question: if an MSP could only focus on one thing this year, what should it be? His answer, without hesitation: "Vulnerability management."

That tracks, as this is the first year in DBIR history that vulnerability exploitation has overtaken stolen credentials as the top breach entry point, jumping from 20% to 31%. Meanwhile, median time-to-patch climbed from 32 to 43 days, and only 26% of known exploited vulnerabilities got fully remediated.

As most know, NIST just overhauled how the National Vulnerability Database operates, moving to a risk-based...


The 2026 Verizon DBIR Unpacked with Author Philippe Langlois
06/15/2026

Today's session is one you genuinely don't want to miss. Every year, Verizon publishes what is arguably the most respected, data-backed snapshot of the global threat landscape, the Data Breach Investigations Report. 

The 2026 edition is the 19th annual installment, and it just set a new record: over 22,000 confirmed breaches analyzed across 145 countries. The numbers don't just confirm what we suspected, they shift how we must implement our defense in depth strategies. 

Joining us is Philippe Langlois, principal author of the 2026 DBIR and one of the minds behind how Verizon collects, interprets, and translates breach data in...


Identity, the Browser and the New Perimeter
06/01/2026

We spent a decade building security around the network. Then five years around the endpoint. The whole time, sitting right in front of every user, every day the browser. Unmanaged. Unexamined. Trusted by default.

The 2026 Verizon DBIR makes it hard to look away anymore. Infostealers, session token theft, OAuth attacks almost every major attack pattern this year runs through the browser at some point.

Today's guest thinks about this problem at a scale very few people get to. He's going to help us understand what the MSP community is missing and what it actually means...


CMMC FAQ May Pubulication Unpacked with Jacob Horne
05/19/2026

This week we're doing something a little different. Instead of talking about CMMC in the abstract, we're putting an actual document on the table the CMMC Program FAQ, freshly updated to Revision 2.3. 

It's the kind of document most contractors skim and most MSPs never read closely. 

To help us read between the lines, we have one of the sharpest interpreters of CMMC in the industry. Jacob Horne has spent years doing exactly this — taking dense regulatory language and turning it into something a contractor can actually act on. Today we're going to put him to work...


From C3PAO to Cyber AB: Scott Singer on What's Coming Next
05/11/2026

CMMC is no longer theoretical the rule is final, the clock is running, and every MSP in the DIB is about to find out whether the work they've done actually holds up under an assessment.

To cut through the noise, we have someone who sees this from angles almost nobody else does. Scott Singer is chair of the Cyber AB’s C3PAO Advisory Council, former CEO of CyberNINES and current President of ControlCase’s Federal Division and he runs two authorized C3PAOs, CyberNINES and ControlCase and a FedRAMP 3PAO. He's helping shape the rules, sitting acro...


From Server Room to Board Room – Selling AI to the C-Suite
05/05/2026

For the past two weeks, we've been building what a Mythos-ready security program actually looks like. None of that matters if we can't walk into a business or boardroom and get the C-suite to buy in. Today is leadership call. How do MSPs earn the right to be in the boardroom on AI and stop being the vendor who fixes things and start being the partner who helps the business win. That's why I'm so excited about today's guest.

Joining us is Bob Zukis, the founder of the Digital Directors Network, lead author of The Great Reboot...


Mythos Ready Security Program Debrief
04/27/2026

Two weeks ago, Anthropic announced Claude Mythos. A model that autonomously found thousands of zero-days, generated working exploits, and broke out of its own containment sandbox.

The moment the industry has been warning about for years just arrived.

Within 48 hours, the Cloud Security Alliance pulled together more than 80 CISOs and security leaders Heather Adkins, Rob Joyce, Bruce Schneier, Jen Easterly and produced "The AI Vulnerability Storm: Building a Mythos-Ready Security Program." It's one of the most important security documents published this year.

My guest today is one of its authors. Sounil Yu CTO...


The Calm Before the Premium
04/20/2026

The cyber insurance market right now is the softest it's been since 2021. Premiums are flat. Capacity is abundant. Carriers are competing aggressively for MSP business, and your SMB clients are getting pricing their predecessors would have dreamed about three years ago.

Here's the problem. Loss frequency is up. Ransomware attack frequency rose 45% year-over-year. A single Cloudflare outage in November cost the economy somewhere between 5 and 15 billion dollars. AI-powered attacks are collapsing the window between a vulnerability existing and being weaponized from weeks to hours. And Anthropic just announced a model that found thousands of zero-days autonomously and...


The Impact of Mythos – The Model to Dangerous to Release
04/14/2026

This week we need to talk about something every MSP, every security pro, and every business owner needs to understand because it changes the threat equation for everyone, not just the enterprise players it was built for. It was only fitting to bring in John Strand, Founder of Black Hills Information Security to discuss.

Anthropic just announced a model called Mythos Preview that can autonomously find and exploit zero-day vulnerabilities across every major OS and browser on the planet flaws that survived decades of human review. They're not releasing it publicly. They've locked it inside a restricted...


Unpacking Axios – 400 million downloads. One Compromised Password
04/07/2026

On March 31st, Axios was compromised. Four hundred million monthly downloads. The HTTP library sitting inside almost every web application your clients use, depend on, or have had custom-built for them. 

 The attacker did not touch a single line of code. They hijacked the maintainer's credentials, slipped in one hidden dependency, and let your clients' own systems install the malware automatically during a routine update. It stole every credential it could find, cleaned up after itself, and left no trace. Three hours. Gone before most people woke up.

 That attack did not come out of now...


Is AI “Poisoning” Your MSPs Marketing?
03/31/2026

Last week, a supply chain attack hit LiteLLM the open-source AI gateway that sits inside 36% of cloud environment and for about six hours, anyone who ran a routine install command handed over their SSH keys, cloud credentials, and API tokens to a threat group that had been quietly chaining compromises across the open-source ecosystem for months. The attack didn't announce itself. It passed every integrity check. 

 That is the world our guest operates in and it is exactly why her work matters right now. Ashleigh Vogstad is the CEO of Transcends, a go-to-market firm that wo...


AI Installed the Backdoor. Now What?
03/23/2026

Imagine this. A developer opens their laptop. Gets a routine VS Code update notification. Clicks install. Goes back to work.

What they don't know is that an AI triage bot the kind built to make their team more efficient just read a manipulated GitHub Issue title, followed hidden instructions, stole three publishing tokens, and silently installed a rogue AI agent on their machine. One that survives reboots. One that takes remote commands. One that they never heard of, never evaluated, and never consented to.

This wasn't a nation-state. This wasn't a zero-day. This was one...


Code Wars: How Nation-States Really Launch Cyberattacks
03/17/2026

For years, many of us have thought about cyberattacks as criminals chasing money. But when you zoom out, you realize something much bigger is happening.

Cyber has become one of the most powerful geopolitical weapons of the 21st century. Nations use it to spy, influence elections, sabotage infrastructure, and increasingly—disrupt supply chains that businesses rely on every day.

Purchase Allie's book here on Amazon.

For MSPs, this isn’t theoretical. We’ve seen it with SolarWinds and with the growing number of attacks aimed at the very p...


Iran Knocked Out AWS. Your Clients' Business Continuity Plan Wasn't Built for This
03/09/2026

On February 28th, the United States and Israel launched coordinated strikes on Iran. Most people know that part.

What most people don't know is that Iran responded by sending drones directly into Amazon Web Services data centers in the UAE. Two facilities struck. A third in Bahrain damaged. For the first time in history, commercial cloud infrastructure became a military target — and most of your clients have no idea it happened.

What's worse — Iranian cyber operators had already pre-positioned backdoors inside American banks and airports before the first bomb dropped. And with Iran's conventional military now...


From Tech Talk to Table Talk
03/03/2026

There’s a conversation happening in boardrooms right now that most security professionals aren’t equipped to lead. Not because they don’t understand the technology. They do.

But translating risk into business decisions… defending budgets… guiding executives through uncertainty… that’s a different discipline entirely.

And that gap? That’s where security programs stall. That’s where funding gets delayed. That’s where the vCISO role becomes reactive instead of strategic.

For MSPs, this matters more than ever.

The future of growth isn’t just in deploying tools — it’s in leading clients through...


Incident Response Simplified
02/24/2026

There's a concept in military and emergency response called the fog of war — that moment when everything is happening at once, information is incomplete, and the people who trained for this have to decide right now, with what they have.

Cybersecurity incident response is that moment. Every time.

And the dirty secret is that most organizations don't have a plan that actually holds up when the fog rolls in. They have a playbook nobody has read and a response team about to find out whether their preparation was real or theoretical.

Today's guest ha...


The Hard Truths About M365 Security
02/17/2026

Last week at Right of Boom, something interesting happened.

In a conference full of great sessions, one stood out — not because of hype, but because of urgency. Kelvin Tegelaar’s CIPP certification session on securing Microsoft 365 was standing room only. MSPs weren’t there for theory. They were there because M365 has quietly become the single largest attack surface in most of their client environments.

 And yet, despite years of focus on security… many organizations are still dangerously exposed. So today isn’t a recap. It’s a debrief.

 We’re going to unpack what Kelv...


Beyond Zero-Days: What Real Threat Hunting Is Actually Finding
01/27/2026

Every week there’s a new zero-day, a new CVE, a new headline. But what rarely gets talked about is what real threat hunting is uncovering when you actually go looking.

Today’s conversation is about what’s happening beyond zero-days — the automated scanning, the long-tail exploitation, the shared infrastructure, and the attack behavior that lives in the background noise of the internet.

We’re joined by Vijay Akasapu, CEO of Cylerian, whose team recently went hunting for early React2Shell exploitation and instead uncovered something much bigger: a multi-layered exploitation ecosystem probing across Jav...


AI & Third Party Risk
01/21/2026

Welcome back to The CyberCall. Today we’re tackling one of the fastest-growing risks MSPs face: third-party exposure in the age of AI.

Our guest is Greg Rasner — author of Cybersecurity and Third-Party Risk and a leading voice on how AI is reshaping vendor security. Greg has spent years helping organizations understand how a single weak vendor can create massive operational, financial, and reputational damage.

With his new book on AI and third-party risk coming soon, Greg joins us to share what’s changing, what MSPs are missing, and what leaders must do now to protec...


John Strand & the BHIS Team at RoB26
01/14/2026

Today’s conversation is all about how MSPs actually win in the modern threat landscape — before, during, and after an attack.

We’re joined by three practitioners who will each be leading hands-on workshops at Right of Boom 2026. John Strand will take us inside Cloud Forever Days and intro to pen testing, showing how attackers really move through cloud environments. Joff Thyer will break down how MSPs can use AI automation to scale security operations without scaling chaos. And Patterson Cake will walk us through what incident response should look like when things stop being theoretical and start...


The Year of Identity Based Attacks
01/08/2026

In 2025, attackers aren’t breaking in through zero-days — they’re logging in. Identity has become the primary attack surface, and once access is gained, everything else happens fast.

Today, we’re joined by Chip Buck, CTO of SaaS Alerts — someone who lives at the front lines of identity-based attacks across SaaS platforms every single day. Chip sees how session theft, OAuth abuse, and legitimate-looking logins turn into real business damage for MSPs and their clients.

This isn’t a theoretical discussion. We’re here to talk about what identity attacks actually look like in the wild, what MSP...


ISO & CMMC – Lessons Learned During Audits
12/29/2025

Welcome back to The CyberCall. Our guest, Joy Beland from Summit7, helps lead security and compliance at the largest MSP serving the Defense Industrial Base.

Joy joins us to share what it actually took to prepare as a service provider, what broke, what changed, and what lessons MSPs can learn if they expect CMMC — or ISO 27001 — to become part of their future.

If you’re an MSP trying to understand what real compliance maturity looks like at scale, this conversation will give you clarity — not marketing, not hype, just experience


Your 2026 Business Plan – Impacts of AI, Cyber & Automation on MSPs.
12/09/2025

Most MSPs don’t fail because of ransomware. They fail because they drift. They chase revenue without direction. They stack tools without a strategy.
 And they wake up one year later asking the same dangerous question: 

“Why didn’t last year change anything?”

Today isn’t about theory. It’s about execution.

Our guest Gary Pica, doesn’t just teach business planning—he’s been stress-testing it with real MSP owners for over 20 years. Through recessions. Through acquisitions. Through “ RMM, Cloud, Security, Automation and now AI revolutions” in our industry. 


Faster, Smarter, Scalable: The Future of M365 Management
11/25/2025

Today’s conversation is all about what comes next for Microsoft 365 — because after Ignite, it’s clear that we’re entering a brand-new era. AI agents, identity-first security, native Sysmon, tenant baselines — Microsoft is rebuilding the entire stack around speed, intelligence, and scale.

And when you talk about managing M365 at scale, there’s one person MSPs look to: Kelvin Tegelaar, founder of CIPP. Kelvin just sold out his first CIPP certification class at Right of Boom, he’s about to ship version 8.7.0, and his platform is now used by over 10,000 MSP partners trying to tame...


The Ulimate Partner – Building an MSP Growth Engine with Microsoft
11/18/2025

Today we’re talking about what it really takes to partner with a giant.

Every MSP wants to grow alongside hyperscalers like Microsoft — but few truly know how to align, scale, and turn partnership into profit.

Our guest today has lived that journey from the inside out. Vince Menzione, Founder of The Ultimate Partner and former Microsoft channel leader, has helped thousands of partners build thriving businesses within the Microsoft ecosystem.

We discuss #cloud, #security, #AI - all the buzzwords!!

 


From Bouncer to MSP Baller – How to Make Microsoft Notice Your MSP
11/11/2025

Today’s guest has one of the most unconventional origin stories in the MSP world. Nabil Aitoumeziane started his career not behind a keyboard—but at the door of a nightclub. While working nights as a bouncer, he began doing something few would dare: asking customers for business introductions and meetings. Fast-forward a few years, and he’s now the president of FSI, an 85-person managed service provider and one of Microsoft’s go-to partners for SMBs.

From reading crowds to reading client needs, Nabil turned street smarts into boardroom strategy—and built one of the...


The State of Pen Testing in 2025 & the Role of AI & Autonomous Solutions (with John Strand)
11/03/2025

Today we’re talking about one of the biggest shifts in offensive security that MSPs, CISOs, and defenders cannot ignore.

For years, pen testing was about human creativity — sneaking in where we “shouldn’t” be, showing you how you’d really get burned in an incident. But in 2025, that world is colliding with AI and automated attack platforms that claim they can do it faster, cheaper, and nonstop.

So the question is: are we entering a golden age of continuous validation — or are we fooling ourselves with marketing and dashboards?

To dig into that, we’ve go...


ZTNA & SASE, the Next Era for MSPs
10/27/2025

Today we’re tackling one of the biggest shifts in modern network security. VPNs are breaking under the weight of hybrid work, SaaS sprawl, and constant attack — and MSPs are being forced to rethink how they secure access itself.

Enter Zero Trust Network Access (ZTNA) and Secure Access Service Edge (SASE) — not just buzzwords, but the blueprint for the next decade of MSP security architecture.

Joining us are two leaders shaping this transformation:

Jason Garbis, Founder of Numberline Security and author of “Zero Trust”
Ahmet Polat, Founder & CTO of Timus.

Together...


The Human Lag: Why AI Outpaces Operational Readiness
10/14/2025

Artificial intelligence is evolving faster than most organizations can operationally absorb. We’ve automated analysis, accelerated response, and even delegated decisions to machines — but our people, processes, and governance are still running at human speed.

This week on The CyberCall, I’m joined by Sounil Yu, creator of the Cyber Defense Matrix and one of the most forward-thinking minds in cybersecurity, to unpack “The Human Lag: Why AI Outpaces Operational Readiness.”

We’ll explore what happens when innovation outruns process, where humans still matter most, and how security leaders can close th...


Disinformation Security – Deepfakes & Social Deception
10/06/2025

This week on The CyberCall, we’re turning up the heat on deepfakes & disinformation—why they’re no longer sci-fi, and how they’re already targeting MSPs and the Defense Industrial Base.

I’m joined by Sandy Kronenberg (Netarx) and Scott Edwards (Summit 7) to unpack:
• Real attack chains: voice clones, lip-sync, synthetic exec approvals
• The “liar’s dividend” & reputational warfare
• What actually works: identity verification, playbooks, and awareness training
• Fast wins MSPs can roll out this quarter


NIST Small Business Primer and Quick Start Guides
09/30/2025

Today we’re talking about something that may sound government-heavy but is actually critical for MSPs and the SMBs they serve: the new NIST Small Business Primer for SP 800-171 Rev. 3.

At its core, this guide is about protecting Controlled Unclassified Information, or CUI. And while that might sound like it only applies to defense contractors, the reality is that CUI requirements increasingly touch SMBs through contracts, regulations, and supply chains.

What’s powerful here is that NIST designed this Primer specifically for smaller organizations. It takes complex requirements and translates them into prac...


Microsegmentation Demystified: What Every MSP & Client Should Know
09/23/2025

Today we’re tackling microsegmentation—a solution that could change the game against ransomware.

Ransomware thrives on lateral movement: one compromised device turns into an entire network takedown. Microsegmentation stops that by creating secure ‘neighborhoods’ inside the network, containing the damage before it spreads.

The big questions: can MSPs realistically deploy this at scale, without adding complexity? And how do we frame it in business terms—protecting revenue, uptime, and client trust?

Special guest: Brian Haugli, CEO of SideChannel


AI’s Evolving Role in Attacks & Incident Reponse
09/16/2025

Over the past couple of days, I was digging into the latest Anthropic Threat Report and one section really hit me.

They wrote: ‘We’ve developed sophisticated safety and security measures to prevent misuse of our AI models. While generally effective, cybercriminals keep finding ways around them.’

And then they shared some eye-opening case studies—threat actors aren’t just asking AI for advice, they’re embedding it across their entire attack lifecycle. We’re talking reconnaissance, credential harvesting, extortion campaigns, even creating fake identities at scale. This is a whole new level of AI misuse—w...