9 Policy Management Features That Matter in 2026

Regulated organizations generate more policies than ever, and most of those policies live in shared folders, inboxes, or outdated wikis where no one can track what’s current, who approved it, or whether anyone read it. For MSPs delivering compliance management software services to clients in healthcare, finance, and government, helping those clients get policy management […]
Get NIST-y Roundup: The Compliance Trap, the CMMC Monster, and the AI Wild West

Three episodes, one throughline: MSPs catch flak for the compliance decisions their clients refuse to make. This roundup pulls the practical takeaways from our latest run of Get NIST-y — the podcast where we skip the framework LARP and talk about what actually works in a client environment on a Tuesday afternoon. If you missed […]
Why Teams Vishing Just Became the Attack Surface Your Email Gateway Can’t See

Microsoft’s Q2 2026 Email Threat Landscape report, published July 23, delivered a striking pair of numbers: phishing tied to the Tycoon2FA platform collapsed 92% after a takedown operation, while weekly malicious Microsoft Teams call attempts are now running at nearly ten times their mid-2025 baseline. Weekly Teams vishing rose 31% from April to May, another […]
Why AI Agents Are the Fastest-Growing Attack Surface Your MSP Isn’t Governing

Your clients are hiring a shadow workforce — Copilot Studio flows, Salesforce Einstein actions, n8n automations, coding assistants with tokens into production repos, MCP servers wired into internal data. They’re not paying it, not onboarding it, and mostly not telling you about it. BeyondTrust’s Phantom Labs clocked a 466.7% year-over-year jump in enterprise AI agents. […]
A Single Prompt, a Full Breach: What This Experiment Means for MSP Security

A single prompt is now enough to run a full cyber attack chain. For MSPs, that’s not science fiction — it’s a design constraint you have to build around. Cato Networks’ recent “agentic attacker” demo with GPT‑5.5 showed how a frontier model, given one offensive objective plus tools, can compress reconnaissance, exploitation, lateral movement, and […]
ClickFix Is Winning Right Now. MSPs Need to Treat It Like a Tier-1 Delivery Threat

ClickFix has become one of the most noteworthy malware delivery methods in 2026 because it bypasses the normal technical choke points MSPs rely on and instead turns end users into the execution mechanism. Recent reporting indicates the technique dominated malware delivery in the March-May 2026 period and should no longer be treated as an emerging tactic […]
Don’t Blame the Drill: Why Your Security Stack Isn’t Your Security Strategy

Imagine you hire a handyman to mount your new TV. A few days later, it crashes off the wall. Your first instinct isn’t to question the brand of drill he used. You blame the man who held it. Something he did wasn’t up to par — the anchor placement, the stud check, the torque on […]
Shadow AI Is Now Your Problem: Why Doubling Sensitive Data Uploads Should Keep MSPs Up at Night

There has been a 93% year-over-year increase in employees transferring enterprise data to AI tools. — Zscaler 2026 AI Threat Report Managed service providers are quietly inheriting a new kind of data‑loss problem: clients’ employees are shoveling sensitive data into AI tools at a rate that has doubled in the last year, with the average […]
MSPs Are Under Direct Attack: Hardening RMM, IAM, and Your Own House First

For attackers, compromising a managed service provider is one of the highest-leverage plays in cybersecurity. NSA and CISA warn that malicious actors are known to target MSPs because MSPs often hold privileged access into customer environments, giving an attacker a trusted path to pivot into multiple downstream tenants and making those actions harder to detect […]
Vendor Risk, Fake Automation, and the Green Check Trap

A vendor questionnaire is not vendor risk management. It’s a starting point. Sometimes a useful one. But if your process ends with a filled-out form and a SOC report in a folder, you’re not managing risk — you’re documenting optimism. In this Get NIST-y, Jared and Mike use the Mythos supply chain mess to highlight […]