8 MSP Compliance Bottlenecks to Fix Before You Scale

Countless MSPs have hit the same wall. Their first few compliance clients felt like careful, custom work. Their next ten felt like they were drowning. By client thirty, the MSP was pulling technicians off billable work every audit cycle, drafting the same policy from scratch for the fourth time, watching their margin evaporate into the […]
“City-Forum” Campaign Quietly Harvests Salesforce and ServiceNow Data Through Guest-User Misconfigs — And MSPs Are on the Hook

A long-running threat campaign dubbed “City-Forum” has been systematically extracting data from Salesforce and ServiceNow tenants worldwide since at least March 2025 — without exploiting a single vulnerability. Every record was pulled through legitimate, unauthenticated endpoints that customers left overly permissive. If you manage a client’s Salesforce Experience Cloud site, Lightning Web Runtime portal, or […]
Blacksmith’s “Get NIST-y” Podcast Wins 2026 MSP Media Impact Award!

From MSP Influencer: Meet the creators helping inform, educate, and connect the MSP industry. The 2026 ForzaDash MSPInfluencer Media Impact Award winners are recognized for producing relevant content, sharing valuable insights, amplifying industry voices, and creating meaningful conversations across the MSP community. This recognition honors the creators and platforms influencing the MSP industry through valuable […]
Local Government Cyberattacks Are Disrupting Public Services. MSPs Need to Prepare Now.

A recent string of cyber incidents has forced local governments in multiple states to shut down networks, interrupt public-facing services, and shift emergency operations to backup processes. For MSPs supporting municipalities, this is a reminder that ransomware recovery is not just an IT exercise — it can become a public-safety obligation. The incidents are not […]
7 Policy Automation Facts MSPs Should Know in 2026

Managing compliance for one client is a process. Managing it for twenty, fifty, or one hundred clients is an operational challenge. Policies need to be assigned, reviewed, updated, acknowledged, and connected to the risks and controls they are meant to support. Evidence needs to be organized before an audit request arrives — not assembled from […]
9 Policy Management Features That Matter in 2026

Regulated organizations generate more policies than ever, and most of those policies live in shared folders, inboxes, or outdated wikis where no one can track what’s current, who approved it, or whether anyone read it. For MSPs delivering compliance management software services to clients in healthcare, finance, and government, helping those clients get policy management […]
8 GRC Capabilities MSPs Need in 2026

Regulatory pressure on your clients keeps climbing. So does the demand for you to prove their security posture to auditors, insurers, and upstream vendors. Blacksmith InfoSec helps MSPs turn that pressure into a structured, scalable compliance-as-a-service offering. But whether you use Blacksmith or another platform, certain GRC capabilities separate tools that help you scale from tools that become bottlenecks. […]
Get NIST-y Roundup: The Compliance Trap, the CMMC Monster, and the AI Wild West

Three episodes, one throughline: MSPs catch flak for the compliance decisions their clients refuse to make. This roundup pulls the practical takeaways from our latest run of Get NIST-y — the podcast where we skip the framework LARP and talk about what actually works in a client environment on a Tuesday afternoon. If you missed […]
Why Teams Vishing Just Became the Attack Surface Your Email Gateway Can’t See

Microsoft’s Q2 2026 Email Threat Landscape report, published July 23, delivered a striking pair of numbers: phishing tied to the Tycoon2FA platform collapsed 92% after a takedown operation, while weekly malicious Microsoft Teams call attempts are now running at nearly ten times their mid-2025 baseline. Weekly Teams vishing rose 31% from April to May, another […]
Why AI Agents Are the Fastest-Growing Attack Surface Your MSP Isn’t Governing

Your clients are hiring a shadow workforce — Copilot Studio flows, Salesforce Einstein actions, n8n automations, coding assistants with tokens into production repos, MCP servers wired into internal data. They’re not paying it, not onboarding it, and mostly not telling you about it. BeyondTrust’s Phantom Labs clocked a 466.7% year-over-year jump in enterprise AI agents. […]