9 Policy Management Features That Matter in 2026

Regulated organizations generate more policies than ever, and most of those policies live in shared folders, inboxes, or outdated wikis where no one can track what’s current, who approved it, or whether anyone read it. For MSPs delivering compliance management software services to clients in healthcare, finance, and government, helping those clients get policy management […]
8 GRC Capabilities MSPs Need in 2026

Regulatory pressure on your clients keeps climbing. So does the demand for you to prove their security posture to auditors, insurers, and upstream vendors. Blacksmith InfoSec helps MSPs turn that pressure into a structured, scalable compliance-as-a-service offering. But whether you use Blacksmith or another platform, certain GRC capabilities separate tools that help you scale from tools that become bottlenecks. […]
Get NIST-y Roundup: The Compliance Trap, the CMMC Monster, and the AI Wild West

Three episodes, one throughline: MSPs catch flak for the compliance decisions their clients refuse to make. This roundup pulls the practical takeaways from our latest run of Get NIST-y — the podcast where we skip the framework LARP and talk about what actually works in a client environment on a Tuesday afternoon. If you missed […]
Why Teams Vishing Just Became the Attack Surface Your Email Gateway Can’t See

Microsoft’s Q2 2026 Email Threat Landscape report, published July 23, delivered a striking pair of numbers: phishing tied to the Tycoon2FA platform collapsed 92% after a takedown operation, while weekly malicious Microsoft Teams call attempts are now running at nearly ten times their mid-2025 baseline. Weekly Teams vishing rose 31% from April to May, another […]
Why AI Agents Are the Fastest-Growing Attack Surface Your MSP Isn’t Governing

Your clients are hiring a shadow workforce — Copilot Studio flows, Salesforce Einstein actions, n8n automations, coding assistants with tokens into production repos, MCP servers wired into internal data. They’re not paying it, not onboarding it, and mostly not telling you about it. BeyondTrust’s Phantom Labs clocked a 466.7% year-over-year jump in enterprise AI agents. […]
A Single Prompt, a Full Breach: What This Experiment Means for MSP Security

A single prompt is now enough to run a full cyber attack chain. For MSPs, that’s not science fiction — it’s a design constraint you have to build around. Cato Networks’ recent “agentic attacker” demo with GPT‑5.5 showed how a frontier model, given one offensive objective plus tools, can compress reconnaissance, exploitation, lateral movement, and […]
7 Features MSPs Need in Compliance Software

For MSPs, the right compliance management software is the difference between chaotic, spreadsheet-driven audits and a scalable, profitable compliance-as-a-service offering. This list breaks down seven core features that help providers reduce manual work, deliver consistent outcomes across clients, and stay audit-ready year round. Multi-Framework Coverage Your Clients Actually Need MSPs rarely support just one framework, […]
Blacksmith Launches GTIA Cybersecurity Trustmark Framework Support for MSPs and Solution Providers

Managed service providers and solution providers need practical ways to turn cybersecurity standards into repeatable operational workflows. Blacksmith’s new support for the GTIA Cybersecurity Trustmark framework is built to do exactly that, giving partners a more streamlined path to manage, operationalize, and demonstrate progress toward the Trustmark inside the Blacksmith platform. This launch reflects a collaboration between Blacksmith and the Global […]
The Gate Moved, the Bar Didn’t: What CMMC’s Phase 2 Suspension Really Means for MSPs

At 3:30 PM Eastern on July 13, 2026, the Department of War (DoW) dropped two memos and kicked off a lot of speculation. The subject lines: “Implementing Department of War Chief Information Officer’s Suspension of the Advancement to Cybersecurity Maturity Model Certification Phase 2 Requirements” and “Removing Barriers to Defense Industrial Base Expansion: Immediate Suspension […]
Cyber Risk Review: Phantom Squatting, Slopsquatting, and HalluSquatting

AI hallucinations are creating a new supply-chain problem for MSPs and the organizations they protect, and the threat has a few names worth remembering: phantom squatting for domains, slopsquatting for packages, and hallusquatting (HalluSquatting) as the broader pattern of weaponizing invented names and links. In the domain version, attackers register the fake web addresses that LLMs […]