A cyber insurance application looks like a survey. It behaves like a representation. That distinction is easy to miss when a client forwards you a forty-question renewal form three days before it is due and asks you to “fill in the technical parts.” You know the environment. You know the answers. You type yes where […]
Choosing a GRC platform for MSPs is one of the highest-stakes decisions your practice will make this year. The wrong pick means duplicated effort across client environments, reporting gaps during audits, and a compliance offering that does not scale. Blacksmith InfoSec helps MSPs turn that decision into a repeatable, profitable compliance-as-a-service practice by removing the […]
Every framework your clients need to meet has one thing in common: it requires evidence, documentation, and ongoing attention that most MSPs simply cannot deliver with scattered tools and ad hoc processes. Compliance as a service (CaaS) changes that equation by turning regulatory obligations into a structured, recurring service line. Blacksmith InfoSec gives MSPs an […]
Something strange showed up in the defense industrial base this month. Contractors are reporting the best cybersecurity scores in the history of the program — and simultaneously trusting those scores less than they ever have. CyberSheath’s 2026 State of the DIB report, published August 20, found the average self-reported Supplier Performance Risk System score climbed […]
MSP compliance management sits at the intersection of expanding regulations and limited operational capacity. Every new framework your clients fall under adds documentation, controls, and audit cycles to your plate. This article breaks down the root causes behind these operational bottlenecks and shows how a Compliance-as-a-Service model can reduce your team’s workload. Blacksmith InfoSec helps […]
Countless MSPs have hit the same wall. Their first few compliance clients felt like careful, custom work. Their next ten felt like they were drowning. By client thirty, the MSP was pulling technicians off billable work every audit cycle, drafting the same policy from scratch for the fourth time, watching their margin evaporate into the […]
A long-running threat campaign dubbed “City-Forum” has been systematically extracting data from Salesforce and ServiceNow tenants worldwide since at least March 2025 — without exploiting a single vulnerability. Every record was pulled through legitimate, unauthenticated endpoints that customers left overly permissive. If you manage a client’s Salesforce Experience Cloud site, Lightning Web Runtime portal, or […]
From MSP Influencer: Meet the creators helping inform, educate, and connect the MSP industry. The 2026 ForzaDash MSPInfluencer Media Impact Award winners are recognized for producing relevant content, sharing valuable insights, amplifying industry voices, and creating meaningful conversations across the MSP community. This recognition honors the creators and platforms influencing the MSP industry through valuable […]
A recent string of cyber incidents has forced local governments in multiple states to shut down networks, interrupt public-facing services, and shift emergency operations to backup processes. For MSPs supporting municipalities, this is a reminder that ransomware recovery is not just an IT exercise — it can become a public-safety obligation. The incidents are not […]
Managing compliance for one client is a process. Managing it for twenty, fifty, or one hundred clients is an operational challenge. Policies need to be assigned, reviewed, updated, acknowledged, and connected to the risks and controls they are meant to support. Evidence needs to be organized before an audit request arrives — not assembled from […]