How MSPs Can Automate Policy Management and Risk Registers

If every client review starts with finding the current policy, chasing approvals, and reconstructing last quarter’s risk decisions, the problem is bigger than document storage. Your compliance service needs a repeatable operating process. Policy and risk automation should make that process easier to run: fewer duplicate entries, clearer ownership, and better visibility into unfinished work. […]
A Quiet Dashboard Isn’t a Security Strategy

Your client’s monthly security report shows fewer alerts. That sounds like good news, and it might be. But before you put a green arrow next to the number, there’s a question worth asking: What actually changed? Did the environment become harder to compromise? Did your team eliminate repetitive noise? Or did a logging integration stop […]
5 GRC Platforms for MSPs: A ConnectWise and Halo Buyer’s Guide

Choosing a GRC platform for MSPs starts with a practical question: how will your team turn a compliance finding into completed work? If your technicians manage service delivery in ConnectWise or Halo, ask vendors to demonstrate that entire workflow, not just point to a PSA logo on an integrations page. Blacksmith InfoSec offers a ConnectWise […]
The Complete Guide to MSP CaaS Platforms in 2026

Regulatory requirements are multiplying for your clients, and point-in-time audits are losing relevance. Insurers want ongoing evidence of controls. Enterprise procurement teams want live compliance posture, not last year’s certification. For MSPs, this shift creates a recurring revenue opportunity that did not exist five years ago: Compliance as a Service. CaaS platforms give you the […]
Your AI Is Only As Good As Your Worst-Documented Client

Danelle Au made an argument in SecurityWeek recently that deserves more attention in the MSP channel than it will probably get: the future of AI-driven security depends less on model sophistication than on data completeness, because every filtered log and excluded system creates a blind spot the model can’t reason around. She’s writing for enterprise […]
Press Release: Blacksmith and SPECTRA Partner to Bring Cyber Resilience Certification and Insurance-Readiness Into the MSP Workflow
New partnership helps managed service providers align security operations with a recognized resilience framework, strengthen client protection, and support eligibility for preferred cyber-insurance programs. September 16, 2026 — Blacksmith, the cybersecurity compliance platform built for managed service providers (MSPs), today announced a strategic partnership with SPECTRA, a cyber-resilience certification and risk-management platform serving the MSP […]
SPECTRA Framework Support Is Coming to Blacksmith: Cyber Resilience Certification and Insurance Readiness in One Workflow

Your clients want proof. Their insurers want proof. And increasingly, the two are asking for the same thing in different vocabularies. Having security tools deployed is no longer the bar. MSPs are being asked to demonstrate that their services are resilient, repeatable, and aligned with what customers and carriers expect — with documentation to back […]
Treat the SonicWall SMA 1000 Like an IdP: An MSP Playbook for the September Zero-Days

On September 1, 2026, SonicWall’s PSIRT disclosed two vulnerabilities in the SMA 1000 Series secure-remote-access appliances and confirmed they were already being exploited in the wild. The advisory says the quiet part out loud: “These vulnerabilities have been confirmed as being actively exploited in the wild.” CISA added both CVEs to the Known Exploited Vulnerabilities […]
What MSPs Need to Know About Compliance Roadmaps

Regulatory pressure keeps growing, and your clients increasingly expect you to help them meet compliance requirements across HIPAA, NIST, SOC 2, and CMMC. Turning compliance roadmaps and risk registers into MSP compliance management services is one of the most effective ways to build recurring revenue while making clients more secure. Blacksmith InfoSec gives MSPs the […]
Your Underwriter Wants Exports, Not Answers

A cyber insurance application looks like a survey. It behaves like a representation. That distinction is easy to miss when a client forwards you a forty-question renewal form three days before it is due and asks you to “fill in the technical parts.” You know the environment. You know the answers. You type yes where […]