# Blacksmith Infosec | Compliance-as-a-Service for MSPs > Compliance simplified with a MSP focused solution ## Posts - [OAuth Abuse Is the New Phishing: Why “Log In With X” Keeps Burning You](https://blacksmithinfosec.com/oauth-abuse-is-the-new-phishing-why-log-in-with-x-keeps-burning-you/): OAuth abuse has quietly become the phishing technique that slips past your MFA, your “security‑aware” users, and your cloud email filters. Recent campaigns abusing OAuth redirects and malicious apps in Microsoft Entra ID and Google Workspace show that “Log in with X” is now one of the easiest ways into your SaaS estate. Phishing Without Passwords In early March, Microsoft detailed phishing campaigns that used legitimate OAuth redirect URLs from Entra ID and Google Workspace to send victims to attacker‑controlled sites. Instead of stealing credentials, attackers crafted OAuth URLs with parameters like intentionally invalid scopes that forced an error and […] - [The New Breach Supply Chain: When Your Data Broker Gets Pwned](https://blacksmithinfosec.com/the-new-breach-supply-chain-when-your-data-broker-gets-pwned/): When your supply chain gets breached, you inherit its chaos, whether you like it or not. The LexisNexis incident and a wave of third‑party breaches in 2026 are a warning shot for every legal, risk, and engineering leader who leans on data brokers to keep their business compliant and fraud‑resistant. When Your Data Provider Makes the Front Page At 6:17 a.m., the CISO of a mid‑size regional bank gets a text from a colleague: “Have you seen this?” The link points to a headline about a major cloud breach at their core risk‑data provider, a LexisNexis‑style legal and analytics giant […] - [MFA Bypass Kits, AI Phishing, and the End of ‘Good Enough’ Authentication](https://blacksmithinfosec.com/mfa-bypass-kits-ai-phishing-and-the-end-of-good-enough-authentication/): MFA used to be the control that let MSPs and security pros sleep at night. In 2026, industrial‑grade phishing kits and AI email engines have turned “we turned on MFA” into the new “we installed antivirus” — expected, but nowhere near enough. When MFA stops saving you Picture the pattern you’ve seen in too many incident reviews this year. A finance manager gets what looks like a routine single sign‑on prompt: same branding, same URL pattern, same Okta‑style flow. They enter their username and password, get an MFA challenge on their phone, approve it, and go back to their day. […] - [Inside the Conduent Mega-Breach: What a “Largest in U.S. History” Incident Teaches About Third‑Party Risk](https://blacksmithinfosec.com/inside-the-conduent-mega-breach-what-a-largest-in-u-s-history-incident-teaches-about-third%e2%80%91party-risk/): When a contractor you barely name in board meetings leaks Social Security and health data for at least 25 million people, it stops being “their” incident and becomes a referendum on your third‑party risk program. The Conduent breach is exactly that kind of stress test. When your outsourcer becomes the soft underbelly Conduent, a New Jersey‑based outsourcer that handles back‑office, payment, and document services for major health insurers and state agencies, disclosed a cyberattack in early 2025 that has since grown to affect at least 25 million Americans. Investigators say attackers, linked to the Safepay ransomware group, accessed Conduent systems […] - [CMMC by Stealth: How GSA Is Sneaking NIST 800‑171 Into Civilian Contracts](https://blacksmithinfosec.com/cmmc-by-stealth-how-gsa-is-sneaking-nist-800%e2%80%91171-into-civilian-contracts/): GSA is turning NIST 800‑171 into a de facto requirement for civilian contractors, even without a formal CMMC program — especially anywhere Controlled Unclassified Information (CUI) touches your systems. For small and mid-size firms, that means “good enough IT” is no longer compatible with keeping GSA work. The stealth rollout: CMMC without the brand GSA isn’t creating its own CMMC clone; it’s quietly embedding CMMC-like expectations into clauses, guides, and approval processes. Recent GSA moves extend cybersecurity obligations across contracting vehicles via solicitation provisions, contract clauses, and FISMA-linked guidance, all aligned to NIST SP 800‑171.​ GSA’s internal CUI security guides […] - [Compliance Debt Is the New Tech Debt: Surviving 2026’s Layered Cyber Regulations](https://blacksmithinfosec.com/compliance-debt-is-the-new-tech-debt-surviving-2026s-layered-cyber-regulations/): Compliance debt is the pile‑up of half-implemented controls, untested policies, and missing evidence that builds as new regulations land faster than teams can operationalize them. In 2026, SEC exam priorities, NIS2, and AI-governance rules are turning that debt into a real balance sheet risk for security leaders. What “compliance debt” really is Like tech debt, compliance debt comes from shortcuts: quick policy updates, one-off projects, and “paper compliance” that never get fully integrated into operations.​ Each new rule — Reg S-P changes, NIS2 security measures, AI Act obligations — adds new requirements on top of that shaky foundation. The interest on that […] - [AI Meets Compliance: Using the DOJ’s ECCP as a Security Guardrail](https://blacksmithinfosec.com/ai-meets-compliance-using-the-dojs-eccp-as-a-security-guardrail/): The mandate is everywhere now: “We need to use AI.” Boards want efficiency. Executives want innovation. Vendors are quietly flipping on AI “copilots” in tools you already own. And somewhere in the middle sits security and compliance, being told to adopt AI with little clarity on why, where, or how. Simply saying “no” is no longer a serious option. The US Department of Justice has already folded artificial intelligence into how it evaluates corporate compliance programs, via updates to its Evaluation of Corporate Compliance Programs (ECCP). That means prosecutors will treat AI like any other powerful technology: if you use […] - [Security Reporting Rules Are Coming for Everyone: How MSPs and vCISOs Prepare Clients for CISA‑Grade Incident Disclosures](https://blacksmithinfosec.com/security-reporting-rules-are-coming-for-everyone-how-msps-and-vcisos-prepare-clients-for-cisa%e2%80%91grade-incident-disclosures/): The era of “optional” cyber incident reporting is ending, and the operational burden is going to land squarely on managed security providers and vCISOs. CISA is actively refining cyber incident and ransom‑payment reporting rules under CIRCIA, reopening comments, and launching town halls with critical infrastructure sectors to stress‑test what’s realistic. Even if many of your clients won’t be in the very first wave of “covered entities,” the style of reporting CISA is normalizing — fast, structured, and data‑rich — will bleed into contracts, insurers, and upstream customers. If a regulator or major customer started a 72‑hour clock on one of […] - [From Alerts to Action: Teaching Execs to Read Cyber Risk Like a Weather Report](https://blacksmithinfosec.com/from-alerts-to-action-teaching-execs-to-read-cyber-risk-like-a-weather-report/): Executives are drowning in cyber alerts and starving for decisions. If you want their support, your job isn’t to forward every CVE — it’s to turn threat noise into something they can read like a weather report: clear, comparable, and decision‑ready. What Executives Actually Need (And Don’t) The SOC lives in logs, CVEs, and vendor advisories. Executives live in budgets, risk, and headlines. That gap is the root of most “they don’t get security” complaints. At a minimum, every update to a senior leader should answer three questions in plain language: What’s happening? Does it affect us? What do you […] - [When Ransomware Becomes a Civic Emergency: What Cities Must Learn from St. Paul](https://blacksmithinfosec.com/when-ransomware-becomes-a-civic-emergency-what-cities-must-learn-from-st-paul/): When ransomware hits a city, it stops being an IT story and becomes a public safety problem. In 2025, St. Paul, Minnesota gave us a template for what that escalation looks like. When “IT Outage” Turns into a State of Emergency On July 25, 2025, St. Paul began detecting suspicious activity on its internal networks, the first sign of what would become a full‑blown cyber crisis. Over the next few days, the incident metastasized from “weird logs” into a deliberate shutdown of city systems to contain a coordinated digital attack. By July 28, officials had pulled the plug on core […] - [Turning a Free Risk Assessment Into Your Client Security Language (Not Just a Compliance Check)](https://blacksmithinfosec.com/turning-a-free-risk-assessment-into-your-client-security-language-not-just-a-compliance-check/): Most MSPs don’t have a language problem with security; they have a translation problem. The Blacksmith Free Risk Assessment gives you a single, reusable grammar you can use to talk about both compliance and security with non‑technical clients in a way that sticks. The problem: no shared language with clients When you walk into a QBR and start talking about EDR, CIS 18, or “identity perimeter,” your client’s eyes glaze over. They care about outages, invoices, and insurance renewals—not frameworks. Meanwhile, compliance conversations live in a separate universe: SOC 2, HIPAA, cyber insurance questionnaires. The result is fragmented stories: security is “tools,” compliance is […] - [NIST’s AI Risk Management Framework: What It Is, Why It Exists, and What MSPs Should Know](https://blacksmithinfosec.com/nists-ai-risk-management-framework-what-it-is-why-it-exists-and-what-msps-should-know/): Artificial intelligence is exploding into every corner of business, but most organizations are still treating AI risk like a side quest instead of part of core governance. The NIST AI Risk Management Framework (AI RMF) is an attempt to fix that by giving a structured, technology‑agnostic way to think about AI risks across the entire lifecycle. Why NIST Created an AI Risk Framework NIST developed the AI RMF to help organizations “better manage risks to individuals, organizations, and society associated with artificial intelligence.” The framework is explicitly voluntary but is designed to become a shared language for regulators, vendors, and […] - [Zero-Click Visibility: Securing a Brand When No One Ever Hits Your Site](https://blacksmithinfosec.com/zero-click-visibility-securing-a-brand-when-no-one-ever-hits-your-site/): We’re fast approaching a time when most of your prospects will never land on a site you manage — and that’s a security problem you can’t patch with an agent install. When a CFO types “Is [Client]’s backup provider secure?” or “Best cybersecurity for a 50‑person firm” into Google or an AI assistant, they get an instant, confident answer, make a judgment about you, and move on. No portal login, no landing page, no chance for you to show off your stack or your processes. All they see is mediated text that may or may not be accurate, current, or […] - [Blacksmith Wins Channel Program Q4 Category Leader Badge](https://blacksmithinfosec.com/blacksmith-wins-channel-program-q4-category-leader-badge/): Blacksmith was again awarded the Channel Program’s Category Leader badge, a distinction reserved for the top-rated vendors in the IT channel across more than 80 technology categories! Which Categories Did We Lead? Blacksmith was awarded this badge in the following: Category Leader: Automation Category Leader: Data Privacy, Governance, & Risk Category Leader: Risk & Compromise Assessment Category Leader: Supply Chain Security   What is the Channel Program Category Leader badge? Channel Program’s Category Leader badge recognizes vendors who land in the top-right quadrant of StackCharts for their category — meaning they’re among the highest‑rated, most trusted solutions as ranked by […] - [Operational Ransomware: When Uptime Becomes the Real Crown Jewel](https://blacksmithinfosec.com/operational-ransomware-when-uptime-becomes-the-real-crown-jewel/): Ransomware is increasingly about stopping a business from functioning, not just stealing or encrypting files. The sectors feeling this most acutely are healthcare, manufacturing, managed service providers, and critical services where every minute of downtime carries a real human or economic cost.​ When “just” data loss isn’t the point In today’s big-game ransomware operations, the goal is often to paralyze hospitals, factories, and essential services long enough that paying a ransom looks (or is) cheaper than staying offline. Research on healthcare incidents shows that even short-lived disruptions to electronic health records, labs, imaging, and communications can force hospitals to divert […] - [KEV-Driven Patching and “Emergency Directive Fatigue”](https://blacksmithinfosec.com/kev-driven-patching-and-emergency-directive-fatigue/): Stop chasing every CVE headline; build a KEV-first, risk-based patch playbook If it feels like you’ve been living in a permanent “drop everything and patch” sprint for the last five years, you’re not imagining it. Every week ships a new “critical” CVE, a vendor blast, and at least one headline implying that if you don’t patch by close of business, your network becomes part of a ransomware buffet.​ Meanwhile, the same organizations that sprint from headline to headline are still getting burned by vulnerabilities that have been exploited in the wild for months, sometimes years. The problem isn’t that there’s too […] - [Building a Digital Trust Architecture: Moving Beyond Isolated Controls](https://blacksmithinfosec.com/building-a-digital-trust-architecture-moving-beyond-isolated-controls/): We’ve said it (and you’ve heard it) many times now: digital trust has become table stakes for doing business. At its core, digital trust is the confidence that systems, data, and interactions are secure, reliable, and respectful of users and their rights. As organizations lean into AI, automation, and always-on digital services, they need more than scattered controls; they need a coherent architecture that makes trustworthy behavior the default across the board. In many sectors, this kind of deliberate digital trust strategy is emerging as a competitive differentiator — clients and regulators now expect it, and brands that lack it […] - [Turn Compliance Into a Core MSP Offering, Not an Add-On](https://blacksmithinfosec.com/turn-compliance-into-a-core-msp-offering-not-an-add-on/): Compliance Is the New Growth Engine For years, most MSPs treated compliance like an annoying side quest: something you help with begrudgingly when a client’s cyber insurer or auditor sends over a questionnaire. That model is breaking down. Buyers are no longer satisfied with “we keep things patched” as an answer when their board, regulator, or carrier is demanding proof of controls and documented processes. Across the MSP space, security and compliance have shifted from back-office headaches to front-of-house differentiators that drive new logos, higher ARPU, and longer retention. Reports on MSP trends for 2025–2026 consistently highlight security, compliance, and […] - [Blue Team vs. GenAI Attackers: What Actually Changes at the Keyboard](https://blacksmithinfosec.com/blue-team-vs-genai-attackers-what-actually-changes-at-the-keyboard/): What’s the full story when it comes to AI-powered cyberattacks? Blue teams are not suddenly fighting alien TTPs; they are fighting familiar kill chains with the volume turned up and the dwell time compressed. The real change is how both sides use the keyboard: attackers to iterate faster, defenders to triage and decide faster.​ From hype to hands‑on reality Security reports reveal a pattern: generative AI is an operational accelerator, not a sci‑fi breakthrough in offense. Well‑aligned crews use models to script, debug, and plan at machine speed, while less skilled actors finally clear the baseline required for credible phishing, […] - [Why Security Culture Beats Security Tools (And Makes Them Worth What You Paid)](https://blacksmithinfosec.com/why-security-culture-beats-security-tools-and-makes-them-worth-what-you-paid/): Security culture beats security tools because tools only amplify the behavior you already have. A great stack in the hands of a rushed, over‑pressured organization just turns bad habits into faster, louder failures. A modest stack inside a culture that takes security seriously will almost always outperform it. Breached with everything “turned on” Picture the company with all the badges of being “serious” about security: SIEM, EDR, SSO, DLP, zero trust banners in the lobby. The breach still starts the old‑fashioned way: someone reuses a password, pastes an API key into chat “just for a second,” or clicks through a […] - [Building A “Green IT” Offering Your SMB Clients Will Actually Pay For](https://blacksmithinfosec.com/building-a-green-it-offering-your-smb-clients-will-actually-pay-for/): Green IT has shifted from “nice to have” to a buying criterion, especially for younger, growth‑minded SMBs. Sustainability is now showing up in MSP trend reports as both a differentiator and a way to justify premium service tiers when it is tied directly to cost savings and risk reduction.​ Why SMBs Will Pay For Green IT Many SMBs are under soft pressure from customers, investors, or larger partners to demonstrate basic ESG or sustainability practices, but they lack in‑house IT expertise to quantify or act on it. At the same time, energy costs and hardware waste are tangible pain points, […] - [Surviving Supply-Chain Ransomware As An MSP](https://blacksmithinfosec.com/surviving-supply-chain-ransomware-as-an-msp/): Supply‑chain ransomware has turned MSPs into high‑value dominoes: hit one provider, get dozens of downstream victims as a bonus. In this article, we’ll discuss how to defend your own house, constrain vendor blast radius, and explain the risk in plain English to SMBs.​ Why MSPs Are Now Prime Targets MSPs sit in the middle of the IT supply chain with privileged access, remote tools, and update rights across many tenants, which makes them an ideal pivot for ransomware operators. Attackers increasingly compromise a weaker vendor — RMM, PSA, backup, SaaS, or an upstream integrator — and then walk into client […] - [The 2026 MSP: AI Threats, Business Risk, and the New Model for Growth](https://blacksmithinfosec.com/the-2026-msp-ai-threats-business-risk-and-the-new-model-for-growth/): Managed services are heading into one of the most important transitions in their history. AI‑driven attacks are accelerating, cyber insurance is tightening, regulators are raising expectations, and clients are less interested in tickets closed than in risk reduced and revenue protected. For MSPs, 2026 is not just another planning cycle; it is a structural reset that will separate reactive providers from true strategic partners.​ Modern research on SMB security and MSP trends points in the same direction: the future favors providers that combine intelligent automation, real risk management, and outcome‑based services that tie directly to business impact. In this article, […] - [Always-On, Always At Risk: MSP Mental Health in the Age of 24/7 Incidents](https://blacksmithinfosec.com/always-on-always-at-risk-msp-mental-health-in-the-age-of-24-7-incidents/): MSPs are carrying more risk than ever, and it is not just technical. Chronic stress, 24/7 expectations, and nonstop incidents are turning mental health into a frontline security issue. When an MSP’s people are exhausted, clients are less safe. The always-on reality of MSP work MSPs live in a world of middle-of-the-night alerts, demanding SLAs, and the constant fear that one missed notification could become tomorrow’s breach headline. Many MSP-focused burnout pieces describe “always on call” cultures where downtime never feels truly off, and staff anticipate the next outage even while trying to rest. Studies on technostress and information overload […] - [Adding AI to Everything is Making Compliance a Nightmare for MSPs](https://blacksmithinfosec.com/adding-ai-to-everything-is-making-compliance-a-nightmare-for-msps/): Have you noticed how AI is being worked into everything…often without adding any value beyond the marketing headlines? (That was rhetorical, because of course you’ve noticed.) If you’ve been around IT for more than a few years, it might bring back not-so-fond memories of the IoT wave. Back when everything from cameras to light bulbs suddenly needed connectivity and compute, opening a back door into your network became as easy as flipping a switch. Now, “AI washing” and the hype cycle are doing the same thing — encouraging rushed adoption that outpaces governance and security readiness. Now, as many as […] - [Blacksmith Wins Multiple 2025 MSP Influencer Awards](https://blacksmithinfosec.com/blacksmith-wins-multiple-2025-msp-influencer-awards/): Blacksmith proudly received two awards from the great people at MSP Influencer! We were awarded the 2025 Vendor Excellence Award in Governance & Compliance for MSPs. This award goes to vendors going above and beyond for MSP partners, a distinction our compliance tool earned through “disciplined, engineering-driven approach to helping MSPs build stronger, more secure, and more compliant environments.” From MSP Influencer: “Clients consistently highlight Blacksmith’s communication, structured methodologies, and commitment to transparency. The team’s emphasis on education and clear documentation empowers MSPs to adopt better practices, improve their internal processes, and deliver stronger security outcomes to their own customers. […] - [Choose Your Own Adventure: You Are the CMMC Project Manager](https://blacksmithinfosec.com/choose-your-own-adventure-you-are-the-cmmc-project-manager/): You wake up in a cold sweat. The calendar says “CMMC Readiness QBR,” the invite says “mandatory,” and your inbox says “57 unread: URGENT.” Congratulations: you are now the CMMC Project Manager. You didn’t apply for this job. That’s how you know it’s real. Your mission: get your defense shop to CMMC Level 2 without losing your contracts, your sanity, or your MSP. Rule #1: When prompted, choose an option.Rule #2: There are no good options, just less‑terrible ones.Rule #3: The POA&M always wins in the end. Scene 1: The Gap Assessment Your CISO bursts into your office: “We got […] - [From Cost Center to Capture Strategy: How Compliance Wins Defense Contracts](https://blacksmithinfosec.com/from-cost-center-to-capture-strategy-how-compliance-wins-defense-contracts/): For years, “compliance” has been treated like an unavoidable tax on doing business with the Pentagon. Today, with CMMC 2.0 tied directly to award eligibility, it has quietly become one of the strongest competitive levers defense contractors and their MSP partners can pull. According to recent research, only about 1% of defense contractors report being fully prepared for CMMC audits, even as enforcement begins to bite; that gap is creating winners and losers in real time.​ The compliance gap no one can ignore Recent state-of-the-DIB reporting shows that despite years of lead time, the vast majority of contractors are still […] - [New York: Mass SMS Scam via Hijacked Alert Service](https://blacksmithinfosec.com/new-york-mass-sms-scam-via-hijacked-alert-service/): On November 10th, hackers exploited a legitimate mass texting service to send hundreds of thousands of scam messages — including to New York State’s official alert subscribers. This incident, which leveraged public trust in emergency messaging channels, marks an evolution in SMS phishing (“smishing”) scams and raises pressing concerns for individuals and organizations alike.​ What Happened? Hackers gained unauthorized access to Mobile Commons, a high-volume SMS provider used by government and civic organizations. Using this access, the attackers sent scam texts from real, trusted short-code numbers typically reserved for official alerts. The fraudulent messages claimed there was a suspicious or […] - [MSPs: Are You Prepared to Be AI Compliance Officers?](https://blacksmithinfosec.com/msps-are-you-prepared-to-be-ai-compliance-officers/): The integration of artificial intelligence into business operations has brought sweeping changes, creating opportunities and compliance challenges. As organizations scramble to harness AI’s potential, a corresponding demand has emerged for specialized oversight that bridges legal, technical, and ethical gaps. This demand is fueling the rise of a new professional: the AI Compliance Officer. Their task is clear — build defensible and business-aligned frameworks for managing AI that match the pace of regulatory and technological change. As AI technology grows more embedded in critical business processes, organizations are recognizing that compliance cannot be an afterthought, but must instead be a proactive, […] - [MSP as Compliance Coach: Educating Clients to Prevent Regulatory Mistakes Before They Happen](https://blacksmithinfosec.com/msp-as-compliance-coach-educating-clients-to-prevent-regulatory-mistakes-before-they-happen/): Managed service providers are more than just technical troubleshooters — they’re essential compliance coaches, guiding clients through complex requirements and helping them avoid costly mistakes before they happen. Here’s how smart MSPs can position themselves as compliance coaches, using technology and education to drive measurable client success (and how tools like Blacksmith make that journey easier).​ The Coach’s Mindset: Proactive Education, Not Passive Enforcement Great MSPs understand that compliance isn’t just a one-time checklist or a “necessary evil” — it’s a continuous process and a business differentiator. When MSPs approach compliance as an ongoing conversation and education strategy, clients are […] - [Free, Open Source Risk Assessment Tool for MSPs and vCISOs](https://blacksmithinfosec.com/free-open-source-risk-assessment-tool-for-msps-and-vcisos/): We Just Released a Free Risk Assessment Tool! We’ve been talking with a lot of our partners lately, and a couple of things keep coming up: risk assessments and sales enablement. MSPs want a simple tool to evaluate client risk and show value early in the conversation without getting buried in complexity or licensing costs. So, we decided to build one. We’re excited to introduce Blacksmith’s free, open source risk assessment tool — a quick, 20-question checklist designed to help MSPs run high-quality cybersecurity assessments that look professional and deliver results.   What It Does Our tool runs through twenty […] - [It Takes More Than Policies — Building a Resilient Compliance Culture](https://blacksmithinfosec.com/it-takes-more-than-policies-building-a-resilient-compliance-culture/): Most organizations have compliance policies. Yet with compliance and risk constantly changing these days, policies alone don’t create a culture that can withstand regulatory scrutiny, reputation shocks, or evolving threats. To deliver true business resilience, compliance must be lived by every team, championed daily by leadership, and woven into the operational fabric of every department.​ Leadership and Accountability: Tone from the Top Compliance culture begins at the top. Effective leaders do more than issue mandates — they actively model compliance, communicate its business value, and back up words with visible action and resource allocation. Leadership accountability means integrating compliance into […] - [The Rise of DragonForce — How Ransomware Cartels Reshape Cybercrime](https://blacksmithinfosec.com/the-rise-of-dragonforce-how-ransomware-cartels-reshape-cybercrime/): DragonForce has quickly transformed from the shadows of obscurity into one of the most watched ransomware cartels of 2025, marking a significant evolution in both the scale and style of cyber extortion. First identified by security researchers in 2023, DragonForce initially operated as a Ransomware-as-a-Service (RaaS) enterprise, rapidly gaining notoriety in 2024 with high-profile attacks and an aggressive affiliate program. Despite ongoing debate about its true origins —possibly tied to the Malaysian-based hacktivist group “DragonForce Malaysia” — the cartel’s operational maturity and escalating frequency of attacks make it a central focus for defenders and analysts alike. As of early 2025, […] - [Nine States Team Up for Data Privacy — A New Era of Cross-State Enforcement](https://blacksmithinfosec.com/nine-states-team-up-for-data-privacy-a-new-era-of-cross-state-enforcement/): With the absence of a comprehensive federal data privacy law in the U.S., states have been stepping up individually to protect their residents’ information. Now, nine states have formed a collaborative regulatory force, sharing resources and enforcement strategies to address the challenges posed by digital data crossing jurisdictional lines. This historic partnership aims to harmonize privacy protections, making meaningful consumer safeguards the new standard and signaling a major shift in how privacy will be enforced nationwide.​ Who’s Involved? The Consortium of Privacy Regulators includes California, Colorado, Connecticut, Delaware, Indiana, New Jersey, Oregon, Minnesota, and New Hampshire, along with their respective […] - [How to Make Security Awareness Stick With Your Clients (Without Scare Tactics)](https://blacksmithinfosec.com/how-to-make-security-awareness-stick-with-your-clients-without-scare-tactics/): Every October, inboxes fill with ghostly warnings, skeleton memes, and stats about lurking cyber threats — because Halloween is peak season for “scary” security marketing. Vendors and MSPs have leaned on puns and percentages for years, hoping to rattle clients into paying attention. Yet research shows that fear-based tactics, while momentarily grabbing attention, rarely create lasting change and can even backfire by wearing out trust or causing people to tune out.​ Why Fear Falls Flat — And What Works Instead Constant fear messaging may work with less experienced buyers, but most users and business leaders have seen it all before […] - [What is Couch to Compliance?](https://blacksmithinfosec.com/what-is-couch-to-compliance/): This is a bit of a teaser introduction to our brand-new Couch to Compliance program. (If you’re a partner or you’ve been on a Blacksmith demo, you might have already seen some emails about it. 😎) Couch to Compliance is all about making the leap from the sidelines into the action, turning the complex world of compliance into something every MSP can tackle, one manageable step at a time. Inspired by the popular “Couch to 5k” fitness movement — which helps anyone go from zero to running a full 5k with friendly, achievable steps — our program does the same […] - [What Is Decision Debt — and Why It Matters for Compliance and MSPs](https://blacksmithinfosec.com/what-is-decision-debt-and-why-it-matters-for-compliance-and-msps/): In the fast-moving tech economy, every organization faces pressure to evolve quickly. But when leaders hesitate, delay, or defer critical choices, they accumulate something rarely tracked on any report: decision debt. Like technical debt in code, decision debt silently compounds interest until progress, compliance, and culture are all burdened by its weight.   What Is Decision Debt? According to Strategic Depth’s September 2025 analysis, decision debt is the cumulative cost of unresolved or poorly made decisions — in other words, the backlog of “let’s circle back” and “we’ll decide next quarter” moments that we’ve all experienced. Compliance Week further describes it as “the silent […] - [5 Compliance Myths That Deserve to Be Busted](https://blacksmithinfosec.com/5-compliance-myths-that-deserve-to-be-busted/): Managed Service Providers have evolved far beyond their origins as break/fixers and IT caretakers. In 2025, MSPs operate inside a tightening mesh of cybersecurity obligations, data privacy regulation, and AI governance frameworks. Yet even as MSPs step up to protect client networks, many still stumble over long-standing myths about compliance — myths that can prove to be costly both in dollars and in trust. In this article, we debunk five persistent misconceptions that are quietly holding MSPs back from becoming true guardians of compliant, resilient operations. Myth 1: “Compliance Isn’t Our Responsibility — It’s the Client’s” Reality: Compliance is a shared […] - [The Hidden Compliance Crisis: Shadow AI in the Workplace](https://blacksmithinfosec.com/the-hidden-compliance-crisis-shadow-ai-in-the-workplace/): As artificial intelligence reshapes business operations, one of the most pressing yet underappreciated compliance risks is the rise of Shadow AI — employees using unsanctioned AI tools without organizational oversight. From ChatGPT-style assistants and automated copilots to image generators and workflow agents, these tools have infiltrated workplaces at astonishing rates. According to Microsoft’s 2025 Work Trend Index, 58% of employees use AI tools on the job without explicit employer authorization. This trend, while often well-intentioned, introduces significant compliance, data security, and reputational threats for organizations.​ What Shadow AI Is — and Why It’s Spreading Shadow AI mirrors the older concept of […] - [MSPs Face Compliance Crossroads: Managing Supply Chain, Third-Party, and Data Privacy Risks in 2026](https://blacksmithinfosec.com/msps-face-2026-compliance-crossroads-managing-supply-chain-third-party-and-data-privacy-risks-in-a-high-stakes-regulatory-era/): MSPs (Managed Service Providers) are facing an urgent need to elevate their risk and compliance programs due to evolving supply chain, third-party, privacy, and disclosure requirements in 2025 and into 2026. For compliance leaders, keeping pace with these changes is no longer optional — it’s both a survival strategy and a proactive way to leverage early adoption into market success.​ Supply Chain & Third-Party Risk Disruptions from geopolitical instability, extreme weather events, and escalating trade restrictions are exposing supply chains to unprecedented risk.​ Geopolitical challenges and unpredictable tariffs are forcing MSPs to diversify supplier bases and invest in scenario planning. […] - [State Breach Laws, SEC Regulation S-P, and CIRCIA Drive Urgent Changes for 2025](https://blacksmithinfosec.com/state-breach-laws-sec-regulation-s-p-and-circia-drive-urgent-changes-for-2025/): Major regulatory and compliance changes in 2025 will transform how Managed Service Providers (MSPs) operate, manage risk, and support clients. Getting serious about compliance now is critical for MSPs who want to hedge against steep penalties and regulatory disruption in the years ahead.​ State Breach Notification Law Updates U.S. states such as California, New York, Oklahoma, Texas, and Florida are tightening data breach notification rules, with stricter notification timelines, broader definitions of personal data, and new requirements to notify Attorneys General if a breach impacts a threshold number of residents.​ California and New York now require breach notifications within 30 […] - [CISA Flags Rapid7 Velociraptor Vulnerability as Active Ransomware Target](https://blacksmithinfosec.com/cisa-flags-rapid7-velociraptor-vulnerability-as-active-ransomware-target/): A critical vulnerability in Rapid7’s Velociraptor — tracked as CVE-2025-6264 — has recently been highlighted by the Cybersecurity and Infrastructure Security Agency (CISA), underscoring new risks faced by organizations relying on security tools for endpoint monitoring and threat hunting. The flaw, now included in CISA’s Known Exploited Vulnerabilities catalogue, has become a key target for ransomware operators, igniting urgent discussions across InfoSec circles.​ Understanding the Velociraptor Vulnerability Rapid7 Velociraptor is a popular digital forensics and incident response tool used to monitor and investigate endpoints in enterprise environments. The newly discovered vulnerability (CVE-2025-6264) arises from incorrect default permissions (classified under CWE-276), […] - [Blacksmith Wins Channel Program Category Leader Badge](https://blacksmithinfosec.com/blacksmith-wins-channel-program-category-leader-badge/): Blacksmith has just been awarded the Channel Program’s prestigious Category Leader badge, a distinction reserved for the top-rated vendors in the IT channel across more than 80 technology categories. This achievement is a powerful endorsement from the Managed Service Provider (MSP) community, as Category Leader badges are earned through verified, real-world peer reviews and evaluations — not participation trophies. What Is the Channel Program Category Leader Badge? The Category Leader badge from Channel Program recognizes companies that hold a position in the upper-right quadrant of StackCharts within their respective categories. Winners are chosen based on direct feedback from the MSP […] - [Ransomware as a Service: The Shift in Cybercrime Targeting MSPs and Their Clients](https://blacksmithinfosec.com/ransomware-as-a-service-the-shift-in-cybercrime-targeting-msps-and-their-clients/): Understanding Ransomware as a Service (RaaS) Ransomware-as-a-Service (RaaS) is transforming the way MSPs face cybercrime, allowing anyone — not just technical experts — to launch devastating attacks through rented ransomware platforms. These service models reduce the barriers to entry for ransomware actors by providing them with ready-made toolkits, infrastructure, and support, while developers take a share of the ransom profits. This has led to a sharp increase in organized attacks specifically targeting high-value entities such as Managed Service Providers (MSPs). Why MSPs Are Prime Targets MSPs hold the keys to countless client networks and mission-critical data, making them lucrative targets […] - [MSPs and Incident Response Plans — An Overview](https://blacksmithinfosec.com/msps-and-incident-response-plans-an-overview/): For Managed Service Providers (MSPs), incident response planning is a critical part of cybersecurity preparedness. With cyber threats targeting not only their own infrastructure but also their clients’ systems, MSPs face unique risks and high stakes when it comes to incident response. Having a clear, actionable incident response plan can mean the difference between business continuity and costly downtime, reputational damage, and client loss. Incident Response Fundamentals for Managed Service Providers Incident response refers to the organized approach an MSP takes to manage and mitigate the effects of cybersecurity incidents such as ransomware attacks, data breaches, or unauthorized access. Key […] - [Exploring the October 2025 Discord Data Leak](https://blacksmithinfosec.com/exploring-the-october-2025-discord-data-leak/): In early October 2025, Discord disclosed a significant data breach that exposed confidential user data through a compromise at a third-party customer support provider. This incident has triggered renewed concerns about supply chain security and the risks associated with trusted external vendors in today’s interconnected IT ecosystem. The breach not only affected Discord’s own systems but revealed how attackers increasingly target the weakest link—third-party platforms that handle sensitive information on behalf of major tech companies. Timeline of the Incident The Discord data leak traces back to September 20, 2025, when attackers infiltrated a third-party provider responsible for managing customer support […] - [Rising Regulatory Pressure on SMBs: Why Compliance is Now a Critical Priority](https://blacksmithinfosec.com/rising-regulatory-pressure-on-smbs-why-compliance-is-now-a-critical-priority/): It’s become a standard refrain in industry forums and vendor webinars: demand for compliance services is skyrocketing for managed service providers (MSPs) and their clients. But have you ever wondered exactly why this is happening? The answer isn’t just about headline-grabbing breaches or new technology — it’s about an unprecedented surge in regulatory pressure that’s now reaching deep into the SMB sector. Where once regulatory scrutiny was mostly reserved for large enterprises, today even small and mid-sized businesses are finding themselves in the crosshairs of state privacy laws, federal rules, and industry frameworks. This dramatic shift is driving fundamental changes in […] - [Cyber Insurance and Compliance: The New Gatekeepers](https://blacksmithinfosec.com/cyber-insurance-and-compliance-the-new-gatekeepers/): Cyber insurance was once viewed as a safety net — merely a way for businesses to transfer risk in the event of a breach or ransomware attack. But that safety net is tightening. Rising premiums, stricter exclusions, and growing demands for evidence of security maturity mean that insurance is no longer a backstop you can buy after the fact. Instead, compliance with specific security standards has become the ticket in the door. For managed service providers (MSPs), this shift is pivotal. Clients are no longer asking “Should we get cyber insurance?” — they’re asking “How do we meet the demands […] - [Compliance: Make 2025 the Last Year of Spreadsheets](https://blacksmithinfosec.com/compliance-make-2025-the-last-year-of-spreadsheets/): It’s no secret that spreadsheet-driven compliance management is becoming obsolete. They might be familiar and easy to use, but spreadsheets introduce significant (and often hidden) risks that threaten operational efficiency, audit success, and security posture. The Risks of Spreadsheet-Based Compliance Spreadsheets rely heavily on manual data entry, which is inherently error-prone — any oversight can instantly render compliance tracking inaccurate or incomplete. The dangers here are exponential. With every additional spreadsheet, organizations multiply their risk profile: version control issues, miscommunication, and conflicting data updates are persistent headaches for teams trying to maintain real-time compliance visibility. Sensitive information stored in spreadsheets […] - [Semi-Autonomous Security Operations: How AI and Humans Team Up](https://blacksmithinfosec.com/semi-autonomous-security-operations-how-ai-and-humans-team-up/): Semi-autonomous security operations are reshaping how organizations defend against evolving threats, marrying the strengths of AI-driven platforms with the irreplaceable judgement of human analysts. Advanced Security Operations Center (SOC) tools now automate initial triage, evidence gathering, and even aspects of incident response, enabling faster, around-the-clock threat detection and significantly reducing repetitive manual toil for security teams. The Rise of AI-Driven SOC Tools Modern SOC platforms increasingly harness artificial intelligence to process vast security data streams, correlate anomalies, and prioritize alerts for human investigation. AI analysts can aggregate signals from diverse tools across cloud, endpoint, identity, and network layers, helping analysts […] - [How Cybersecurity Ratings and Compliance Help Build Strong Business Relationships](https://blacksmithinfosec.com/how-cybersecurity-ratings-and-compliance-help-build-strong-business-relationships/): Cybersecurity ratings and compliance are more than technical checkboxes — they are key drivers in building strong business relationships and earning trust among clients, vendors, and partners. Building Trust Through Transparency Security ratings offer measurable insights into an organization’s cyber posture, making it clear whether robust controls and best practices are in place. High ratings signal that an organization treats risk seriously and maintains ongoing diligence, which reassures partners and customers that their sensitive data will be protected. For SMBs, a favorable cyber rating functions as a verifiable endorsement, helping win new contracts and strengthening credibility in the marketplace. Enabling […] - [Stay Ahead or Fall Behind: Continuous Monitoring as a New Security Standard](https://blacksmithinfosec.com/stay-ahead-or-fall-behind-continuous-monitoring-as-a-new-security-standard/): Compliance has long relied on point-in-time audits — structured reviews conducted annually or semi-annually to check if organizations meet regulatory requirements. But as cyber threats grow more dynamic and regulators demand real-time assurance, that model is increasingly inadequate. Continuous monitoring is becoming the new standard, offering organizations a more proactive and resilient approach to compliance. The Limitations of Point-in-Time Audits Traditional audits resemble a snapshot: they capture the organization’s security and compliance posture at one specific moment. While valuable for identifying obvious gaps, this model suffers from serious limitations: Lagging indicators: Audit results reflect security practices months before, not the […] - [What the Salesloft Drift Breach Reveals About Trust and Risk](https://blacksmithinfosec.com/what-the-salesloft-drift-breach-reveals-about-trust-and-risk/): When trust in SaaS becomes a liability, every MSP should take notice. The recent compromise of Salesloft through its Drift integration proves how quickly a trusted business tool can turn into a threat vector for hundreds of organizations. The following sections break down key insights from this attack and offer headlines for follow-up coverage. Salesloft Drift Attack: Supply Chain Breach Hits Hundreds In August 2025, threat actors targeted Salesloft’s Drift integration, exploiting OAuth tokens to access Salesforce environments at scale. The attack lasted 10 days — from August 8 to 18 — before emergency measures disabled all Drift integrations, but […] - [Risk Appetite for Managed Service Providers (MSPs)](https://blacksmithinfosec.com/risk-appetite-for-managed-service-providers-msps/): For Managed Service Providers (MSPs), understanding risk appetite is no longer optional — it’s essential for shaping your business strategy and long-term client success. Risk appetite is the level and type of risk an organization is willing to accept in pursuit of its objectives, acting as a guide for decision-making and balancing opportunities with threats. For MSPs, defining risk appetite goes beyond internal planning; it influences how compliance services are delivered, how innovative solutions are introduced, and how trusted relationships with clients are built and maintained. By embracing risk appetite as a strategic tool, MSPs position themselves to offer better […] - [Innovation at the Edge: Securing Progress Without Compromise](https://blacksmithinfosec.com/innovation-at-the-edge-securing-progress-without-compromise/): In cybersecurity and information security, innovation is both an opportunity and a liability. Organizations must adapt faster than adversaries, deploying new technologies, processes, and defenses to maintain advantage. Yet history shows that unchecked innovation — whether in AI-driven analytics, cloud migration, or zero-trust adoption — can introduce just as many vulnerabilities as it solves. The most resilient leaders recognize that security is not a brake on innovation but a stabilizer. By embedding risk management into the design and execution of innovative initiatives, they ensure that creativity and caution coexist. Lessons from Cybersecurity Trailblazers Security-conscious organizations across industries demonstrate how it is […] - [Global Geopolitics and Espionage Campaigns (2025 Update)](https://blacksmithinfosec.com/global-geopolitics-and-espionage-campaigns-2025-update/): Recent cyberespionage campaigns reveal an alarming global surge in state-sponsored hacking — especially targeting telecom, government, and media. In this article, we’ll explore notable government-aligned cyber activity in 2025. Chinese State-Aligned Attacks on Telecom Networks This year, “Salt Typhoon,” a hacking group almost certainly linked to the People’s Republic of China (PRC), was confirmed to be targeting Canadian telecommunications providers. In February 2025, three network devices at a major provider were compromised using the CVE-2023-20198 vulnerability. The attackers extracted configuration files and set up GRE tunnels to siphon network traffic, enabling both data theft and clandestine surveillance. According to Canadian […] - [Insider Threats in a Hybrid Workforce: What to Watch for in 2025](https://blacksmithinfosec.com/insider-threats-in-a-hybrid-workforce/): Insider threats — malicious, negligent, or even accidental breaches performed by trusted individuals — have evolved rapidly with the rise of distributed teams and the proliferation of hybrid work models. Organizations face a growing challenge: how to safeguard sensitive information when employees, contractors, and partners operate remotely, often with less oversight and on diverse networks. The Changing Landscape of Insider Threats Hybrid work widens the attack surface. Employees work from offices, homes, and public spaces, accessing resources from personal and corporate devices. Traditional security models built for physical boundaries and centralized control are being tested as trust shifts from location-centric […] - [Gamification in Security Awareness Training](https://blacksmithinfosec.com/gamification-in-security-awareness/): Gamification in security awareness transforms cybersecurity training from a routine task into a dynamic, engaging experience. By weaving game mechanics — such as quizzes, challenges, and recognition programs — into training content, organizations can motivate participation, reinforce key concepts, and cultivate a culture of continuous vigilance.   Why Gamify Security Awareness? Gamification leverages the brain’s reward system, turning security education into active participation. Points, badges, leaderboards, and team-based competitions create a sense of achievement and friendly rivalry, increasing motivation to adopt secure behaviors. Research shows that gamified security training improves retention by providing immediate feedback and enabling employees to learn […] - [Rise of Voice Phishing: AI-Powered Vishing Targeting Enterprise CRMs](https://blacksmithinfosec.com/rise-of-voice-phishing-ai-powered-vishing-targeting-enterprise-crms/): AI-powered voice phishing, or “vishing,” has emerged as a top threat by bypassing email filters and traditional controls to directly target employees through convincing, real-time social engineering. In 2025, several high-profile breaches demonstrate that vishing’s evolution — combining AI voice synthesis, CRM targeting, and publicly scraped data — is redefining the cyber risk facing corporations of all sizes, How AI-Powered Vishing Works Modern vishing attacks deploy artificial intelligence to generate hyper-realistic voice clones of executives, IT staff, or customer support agents. Attackers use leaked or public employee information, often harvested from social networks or previous breaches, to personalize their approach. […] - [Turning Compliance Into Opportunity: How Blacksmith Fuels MSP Growth](https://blacksmithinfosec.com/turning-compliance-into-opportunity-how-blacksmith-fuels-msp-growth/): If you’ve scrolled any cybersecurity headlines in 2025, you’ve noticed a trend: “Lack of compliance” isn’t just a technicality — it’s become a key cause of major breaches across industries. The growing scrutiny is clear: when organizations are hit, the first big question reporters, regulators, and clients ask is, “Were they compliant?” Breaches, Compliance, and Why MSPs Are in the Spotlight Recent attacks in healthcare, finance, retail, and more are putting managed service providers (MSPs) under the microscope. Clients count on MSPs not only to deliver technology, but also to ensure their processes and policies meet industry standards—from HIPAA and […] - [Press Release: Blacksmith Announces Strategic Integration with HaloPSA](https://blacksmithinfosec.com/press-release-blacksmith-announces-strategic-integration-with-halopsa/): Blacksmith, the channel’s leading platform for policy creation, audit tracking, and security program management, has announced a transformative integration with HaloPSA, the unified professional services automation solution for modern MSPs. This integration allows managed service providers (MSPs) to operationalize compliance by turning Compliance Roadmaps in Blacksmith into actionable HaloPSA projects — streamlining security, compliance, and project execution across both platforms.  Setting a New Standard for Meeting Compliance Demands  As regulatory requirements like NIST CSF, HIPAA, PCI-DSS, and CMMC become industry benchmarks, compliance is now table stakes for the IT channel. Blacksmith’s purpose-built solution brings compliance management full-cycle — from framework […] - [Allianz Life Hack Impacts 1.1 Million Customers — What Happened and Why It Matters](https://blacksmithinfosec.com/allianz-life-hack-impacts-1-1-million-customers-what-happened-and-why-it-matters/): In July 2025, Allianz Life Insurance Company of North America disclosed a major cyberattack impacting approximately 1.1 million customers. The breach exposed sensitive personal information and is part of a broader wave of high-profile cyberattacks targeting global companies. As the digital footprint of financial institutions continues to expand, this incident highlights the evolving risks associated with cloud-based platforms and sophisticated social engineering tactics targeting companies and their clients.   Timeline and Nature of the Attack The Allianz Life breach was first identified in late July 2025 when unusual activity was detected within the company’s cloud-based customer relationship management (CRM) system. Threat actors reportedly used advanced […] - [Securing the Expanding Attack Surface: From IoT to 5G](https://blacksmithinfosec.com/securing-the-expanding-attack-surface-from-iot-to-5g/): The explosion of connected devices and faster networks is fundamentally redefining cybersecurity in 2025. With millions of new IoT devices deployed in fields ranging from manufacturing to healthcare, and 5G networks rapidly scaling up worldwide, organizations now face a vastly widened attack surface. Hackers are quick to target these new entry points—and without proactive defense, businesses risk falling behind. Securing the expanding digital perimeter is no longer optional; it’s mission-critical for risk management and regulatory compliance. The Expanding Attack Surface Several factors are converging to stretch the boundaries of corporate networks: IoT everywhere: From smart cameras and sensors in factories to […] - [Understanding the CIA Triad in Cybersecurity and MSP Compliance](https://blacksmithinfosec.com/understanding-the-cia-triad-in-cybersecurity-and-msp-compliance/): The CIA Triad — Confidentiality, Integrity, and Availability — is the heart of every effective cybersecurity strategy. These three interlocking principles define what it means to keep data safe in any organization, from global enterprises to small businesses. What Are the Parts of the CIA Triad? Confidentiality: Ensures information is accessible only to those authorized to view it. Think of confidentiality as the digital version of a locked safe — your data is protected from prying eyes. This involves encryption, access controls, and privacy policies. Integrity: Means data remains accurate and unaltered, except by those with proper authority. Integrity protects information from […] - [Building Smarter Security Programs: How MSPs Can Win with Regulatory Frameworks](https://blacksmithinfosec.com/building-smarter-security-programs-how-msps-can-win-with-regulatory-frameworks/): Cybersecurity isn’t just a technical problem but a business imperative, and the smartest Managed Service Providers (MSPs) are embracing this fact and rethinking the foundations of their security programs. The days of quick fixes and compliance as a checkbox are over. Today, the winning MSP strategy centers around building security on tried-and-tested regulatory frameworks — like the widely respected NIST Cybersecurity Framework (CSF) — not out of fear, but for the real business advantages this approach delivers.   The Framework Advantage Adopting regulatory frameworks isn’t about bogging down operations in red tape — it’s about creating a scalable, repeatable, and […] - [What the U.S. Can Learn from Europe’s NIS2 Rollout: Lessons for Future Compliance](https://blacksmithinfosec.com/what-the-u-s-can-learn-from-europes-nis2-rollout-lessons-for-future-compliance/): The European Union’s NIS2 Directive is sending ripples across the Atlantic — not only for U.S. companies already doing business in Europe but as a case study for what’s likely on the horizon in American compliance. As states and federal agencies introduce tougher cybersecurity mandates and incident reporting rules, NIS2’s implementation offers a unique preview of the hurdles, pitfalls, and solutions that U.S. enterprises may soon face. Key Lessons from NIS2’s Implementation 1. Relying on Proven Frameworks Makes All the Difference Perhaps the most striking parallel emerging from companies navigating NIS2 is that those with mature, globally recognized cybersecurity and […] - [Commoditizing Cybercrime: How Ransomware-as-a-Service Changes the Risk Equation](https://blacksmithinfosec.com/commoditizing-cybercrime-how-ransomware-as-a-service-changes-the-risk-equation/): Ransomware is no longer the domain of lone-wolf hackers or exotic APT syndicates. In 2025, the growth of Ransomware-as-a-Service (RaaS) has industrialized cyber extortion on an unprecedented scale — bringing ruthless cybercriminal capabilities to anyone with cryptocurrency and a grudge. This “platformization” of ransomware not only amplifies the threat landscape but fundamentally challenges how organizations approach business continuity, governance, risk, and compliance (GRC) in the face of ever-evolving digital dangers. The RaaS Revolution: Cybercrime on Demand RaaS platforms operate much like legitimate SaaS businesses. Ransomware developers supply powerful, easy-to-deploy attack kits — complete with user-friendly dashboards, documentation, and even “customer […] - [Is AI Letting Your Compliance Slip? How ‘Silent’ Gaps Are Becoming the Biggest GRC Risk of 2025](https://blacksmithinfosec.com/is-ai-letting-your-compliance-slip-how-silent-gaps-are-becoming-the-biggest-grc-risk-of-2025/): 2025 is seeing an explosion of AI-powered processes embedded throughout business operations — yet few companies update their Governance, Risk, and Compliance (GRC) monitoring to match. In the rush to harness artificial intelligence for speed, efficiency, and insight, organizations across the globe have quietly introduced a new type of risk — a phenomenon security and compliance professionals are starting to call “AI-driven compliance drift.” As machine learning bots automate everything from policy checks to audit logging, many GRC teams assume these systems will catch every gap and alert them to every slip. But in 2025, a string of costly enforcement […] - [The Ingram Micro Ransomware Hack: What Happened and Why It Matters](https://blacksmithinfosec.com/the-ingram-micro-ransomware-hack-what-happened-and-why-it-matters/): Overview In early July 2025, Ingram Micro — one of the world’s largest distributors of IT products, cloud services, and technology solutions — was struck by a significant ransomware attack that disrupted its global operations, rippled through the tech supply chain, and serves as a warning for organizations everywhere. The incident was quickly linked to the SafePay ransomware group, a relatively new but increasingly active threat actor known for targeting large enterprise and supply chain targets with “double-extortion” campaigns. Timeline of the Attack July 3, 2025: Employees began to report ransomware notes on their computers. Customers worldwide lost access to Ingram Micro’s website […] - [Zero-Trust Architecture: Compliance Mandate or Best Practice?](https://blacksmithinfosec.com/zero-trust-architecture-compliance-mandate-or-best-practice/): Why Zero Trust Has Become Essential The zero-trust security model flips the traditional notion of network security: instead of trusting devices and users inside a defined network perimeter, it requires continuous verification of every user and device—never trust, always verify. As threats have become more sophisticated and workforces more distributed, this approach is now a mainstream expectation, not merely a cybersecurity ideal. Several catalysts are driving zero trust into the compliance mainstream: High-profile data breaches often trace back to compromised internal accounts or lateral movement inside trusted networks. Remote and hybrid work have dissolved rigid network boundaries. Cloud adoption and SaaS proliferation mean sensitive data […] - [$16K in Prizes. 10 Days. It’s Almost Channel Daze Time!](https://blacksmithinfosec.com/16k-in-prizes-10-days-its-almost-channel-daze-time/): It’s almost that time of year again — sun’s out, energy’s up, and Channel Daze is about to kick off! Starting August 4th, we’re bringing you 10 straight weekdays of giveaways. That’s two prizes a day, from 34 awesome sponsors who just want to say thanks. It’s easy, it’s free – and it’s all for you. There’ll be daily drawings for prizes like a PS5, getaway packages, gift cards, and tech gear. Just sign up once, and you’re in the running for every giveaway from your signup date through August 15th. Ready to jump in? Register now and you’ll be […] - [Why Off-Channel Messaging Is a Compliance Risk for MSPs and Their Clients](https://blacksmithinfosec.com/why-off-channel-messaging-is-a-compliance-risk-for-msps-and-their-clients/): Today’s businesses thrive on speed and connectivity, but the rising use of unauthorized messaging and collaboration tools — known as off-channel communications or Shadow IT — poses a growing compliance and security risk. As enforcement actions accelerate, managed service providers (MSPs) must recognize these dangers not just for their clients, but also for their own operations and reputations. What Counts as Off-Channel Communication? Personal messaging apps (e.g., WhatsApp, Signal, Telegram) used for business conversations. Unauthorized cloud collaboration platforms (e.g., Google Drive, Dropbox, Slack, Discord). SMS, personal email, or other tools outside official recordkeeping and monitoring systems. These channels often lack the controls […] - [Threat Alert: Sophisticated Deepfake Scams Surge, Targeting U.S. Financial Sector and Enterprises](https://blacksmithinfosec.com/threat-alert-sophisticated-deepfake-scams-surge-targeting-u-s-financial-sector-and-enterprises/): July 2025 has marked a sharp escalation in deepfake-driven cybercrime targeting U.S. financial institutions and enterprises. Attackers are increasingly using AI-generated voice and video impersonations to trick employees into transferring funds or divulging sensitive information, often bypassing even well-established security protocols. These deepfake scams have evolved beyond traditional phishing and business email compromise. In several high-profile incidents, synthetic audio or video calls have enabled criminals to convincingly pose as corporate leaders or trusted colleagues, coercing staff into executing high-value wire transfers or releasing confidential data. The financial sector, including banks and real estate firms, has become a prime target, with […] - [Say Goodbye to CSVs: Why Legacy Audit Reporting Holds MSPs Back](https://blacksmithinfosec.com/say-goodbye-to-csvs-why-legacy-audit-reporting-holds-msps-back/): For years, Managed Service Providers (MSPs) have leaned heavily on CSV exports to meet audit and compliance demands. Run a PowerShell script, wrangle the output, download a log, manually parse permissions — repeat for every client, every month. It’s how things have always been done. (No wonder so many MSPs still believe that compliance is a cost center, not a revenue stream!) As you can imagine, sticking with this legacy approach is becoming a liability, not just for efficiency, but for security and quality of service. Traditional CSV-based audit reporting is slow, error-prone, and disconnected from the realities of modern, […] - [Bridging Visibility and Governance: What Next-Gen Compliance Should Look Like for MSPs](https://blacksmithinfosec.com/bridging-visibility-and-governance-what-next-gen-compliance-should-look-like-for-msps/): Modern Managed Service Providers (MSPs) face a new reality: compliance isn’t just about going through the motions for an auditor’s checklist — it’s about equipping organizations to detect, defend, and adapt to ever-evolving threats. Achieving true compliance maturity requires orchestrating both visibility into technical environments and governance through actionable, business-ready controls. Why Traditional Approaches Fall Short Many MSPs still rely on static reports, isolated tools, and manual review cycles. This approach often results in: Blind spots across cloud and on-prem systems Outdated or incomplete user access data Compliance evidence that satisfies auditors, but lacks operational value Painful, spreadsheet-driven audit prep that distracts from […] - [Blacksmith InfoSec and Liongard Announce Strategic Integration](https://blacksmithinfosec.com/blacksmith-infosec-and-liongard-announce-strategic-integration/): At Blacksmith InfoSec, we’ve always believed that real security outcomes should drive compliance. That’s why we’re thrilled to announce our latest integration with Liongard, a move that transforms how Managed Service Providers (MSPs) approach compliance audits. This integration empowers MSPs to automate user-centric security audits across Microsoft 365, Google Workspace, and any system connected via Liongard — eliminating spreadsheet wrangling, manual exports, and confusing technical reports. What This Integration Means for MSPs In an era of increasingly complex tech stacks and regulatory pressure, delivering clear, audit-ready documentation has become both essential and exhausting. With this integration, MSPs can now: Run fully […] - [Demystifying CMMC for MSPs](https://blacksmithinfosec.com/demystifying-cmmc-for-msps/): The Cybersecurity Maturity Model Certification (CMMC) has become a central compliance requirement for organizations in the U.S. defense supply chain. For Managed Service Providers (MSPs), understanding CMMC is essential — not only to support clients but also to ensure their own operations align with evolving Department of Defense (DoD) expectations. This article breaks down what CMMC means for MSPs, clarifies common misconceptions, and outlines practical steps for compliance. What Is CMMC? CMMC is a unified cybersecurity standard developed by the DoD to protect Controlled Unclassified Information (CUI) and Federal Contract Information (FCI) within the Defense Industrial Base (DIB). It builds […] - [Understanding Security Policies for MSPs and IT Professionals](https://blacksmithinfosec.com/understanding-security-policies-for-msps-and-it-professionals/): Security policies are the backbone of an organization’s information security program. These policies are shaped not only by internal business needs but also by a complex landscape of federal and state regulations. Security policies define how information assets are protected, who is responsible for safeguarding them, and the standards by which compliance is measured. For organizations of all sizes, robust security policies are essential. They help prevent data breaches, reduce risk, and ensure compliance with laws such as HIPAA, GLBA, and SOX. Whether a business is a small startup or a large enterprise, clear and effective security policies establish expectations […] - [The Great Password Purge: Why 2025 is the Year to Finally Kill Legacy Authentication](https://blacksmithinfosec.com/the-great-password-purge-why-2025-is-the-year-to-finally-kill-legacy-authentication/): The era of passwords could be ending — and if that’s true, 2025 marks the tipping point. With password attacks surging to 7,000 per second and legacy authentication becoming the weakest link in organizational security, the shift to passwordless methods is no longer optional but a critical business imperative. As Microsoft phases out password support in Authenticator by August 2025 and industry-wide FIDO2 adoption accelerates, organizations face a now-or-never moment to modernize authentication. The Business Case: Cost, Security, and Productivity Passwordless systems deliver immediate financial and operational benefits: Help desk costs plummet by 75-90%, eliminating $400,000–$600,000 annually in password reset tickets for […] - [AI Model Poisoning: The Silent Threat to Your Organization's Machine Learning Infrastructure](https://blacksmithinfosec.com/ai-model-poisoning-the-silent-threat-to-your-organizations-machine-learning-infrastructure/): As organizations rapidly integrate artificial intelligence into their operations, a insidious new attack vector has emerged that threatens the very foundation of machine learning systems. AI model poisoning represents a sophisticated form of cyberattack that manipulates training data to corrupt AI models, potentially causing catastrophic failures in critical business systems. Understanding the Attack Vector AI model poisoning is a deliberate attempt to introduce malicious or corrupted data into an AI model’s training datasets. Unlike traditional cyberattacks that target systems directly, these attacks exploit the fundamental dependency of machine learning models on data quality and integrity. The attack works by injecting incorrect or biased data points […] - [A Practical Guide to Choosing the Right Frameworks for Your Organization](https://blacksmithinfosec.com/a-practical-guide-to-choosing-the-right-frameworks-for-your-organization/): Navigating compliance in 2025 feels like standing in front of a wall of acronyms — SOC 2, HIPAA, PCI DSS, NIST CSF, CIS Controls, CMMC — each promising to solve your security and regulatory challenges. For managed service providers and IT organizations, this abundance of frameworks creates a paradox of choice that can paralyze decision-making and drain resources. The question isn’t whether you need compliance frameworks; it’s which ones will actually serve your business objectives while meeting your clients’ regulatory requirements. The reality is that most organizations don’t need every framework, but choosing the wrong ones can be costly. While […] - [Mid-Year Cyber Threat Landscape Review: What's Changed in 2025](https://blacksmithinfosec.com/mid-year-cyber-threat-landscape-review-whats-changed-in-2025/): As we reach the halfway point of 2025, the cybersecurity realm has undergone dramatic shifts that demand immediate attention from security professionals worldwide. The first six months of this year have revealed unprecedented changes in attack methodologies, threat actor sophistication, and the integration of artificial intelligence into cybercriminal operations. This comprehensive review examines the most significant developments and provides strategic guidance for adapting security postures in the second half of 2025. The AI Revolution in Cybercrime Multi-Agent Attack Systems The most transformative development in 2025 has been the emergence of coordinated AI agents capable of conducting reconnaissance, identifying vulnerabilities, and […] - [Summer Security Slump: Protecting Your Organization During Vacation Season](https://blacksmithinfosec.com/summer-security-slump-protecting-your-organization-during-vacation-season/): Summer vacation season presents a perfect storm of cybersecurity challenges for organizations worldwide. While employees enjoy well-deserved time off, cybercriminals are ramping up their efforts, taking advantage of reduced staffing, delayed incident response capabilities, and relaxed end-user vigilance. With 85% of organizations scaling down their security operations center staffing during holidays and weekends, the summer months have become a prime hunting season for threat actors. The Summer Vulnerability Window Reduced Security Oversight During summer months, IT and security teams often operate with significantly reduced headcount as vacation schedules roll out1. This creates extended windows of opportunity for adversaries to move laterally, escalate […] - [FAQs: Answering the Most Common Compliance Questions for Businesses](https://blacksmithinfosec.com/faqs-answering-the-most-common-compliance-questions-for-businesses/): Navigating compliance is not optional for many organizations operating in the United States — and the number of businesses affected by regulations is growing. As it stands, U.S. businesses must adhere to a wide range of federal, state, and local regulations that govern everything from data privacy and workplace safety to tax reporting and employment practices. But maintaining compliance is not just a legal obligation — it is vital for safeguarding your company’s reputation, protecting against costly fines and penalties, and ensuring data privacy and cybersecurity. Failure to comply with applicable U.S. regulations can result in severe consequences, including financial […] - [MSP Compliance in 2025: The Ultimate Guide for Managed Services Providers](https://blacksmithinfosec.com/msp-compliance-2025-the-ultimate-guide-for-managed-services-providers/): In an era defined by relentless cyber threats and increasingly stringent regulations, Managed Services Providers (MSPs) find themselves at the heart of a digital battleground. The frequency and sophistication of cyberattacks continue to surge, while governments and industries worldwide impose tighter compliance requirements to safeguard sensitive data and critical infrastructure. This dual pressure — cyber risk on one side, regulatory scrutiny on the other — has thrust MSP compliance into the spotlight as a cornerstone of modern IT operations. For MSPs, compliance is no longer just a box to check or a means to mitigate risk. It has emerged as a […] - [Quantum Computing and Cryptography: Preparing for the Future](https://blacksmithinfosec.com/quantum-computing-and-cryptography-preparing-for-the-future/): Quantum computing promises breakthroughs in fields like drug discovery and AI, but it also poses an existential threat to modern encryption. As organizations store and transmit sensitive data, compliance teams must understand how quantum advancements could render current cryptographic methods obsolete — and what steps to take now to future-proof their security frameworks. The Quantum Threat to Modern Encryption Today’s encryption relies on mathematical problems that classical computers struggle to solve, such as factoring large prime numbers (RSA) or solving elliptic curve equations (ECC). Quantum computers, however, can exploit algorithms like Shor’s algorithm to break these systems in hours or minutes, […] - [Understanding Identity and Access Management (IAM)](https://blacksmithinfosec.com/understanding-identity-and-access-management-iam/): Identity and Access Management, or IAM, is a foundational framework of business processes, policies, and technologies that organizations use to manage digital identities and control who — or what — can access specific resources within their systems. At its core, IAM ensures that only the right people, machines, or software components get access to the right resources at the right time, and for the right reasons. What Is Identity and Access Management (IAM)? IAM begins with the concept of a digital identity — a unique set of attributes or identifiers that represent a person, device, or application within a system. These identities […] - [Cybersecurity Acronyms: Let's Talk SOC, SOAR, XDR and More](https://blacksmithinfosec.com/cybersecurity-acronyms-lets-talk-soc-soar-xdr-and-more/): Some might say cybersecurity has an acronym problem. For the average person, it can seem like everyone in the industry got together and decided to make things as confusing as possible. You can’t go to a single meeting without someone throwing around SOC, SOAR, XDR, and a dozen other letter combinations that make your head spin. If you’re having a hard time sorting out these acronyms and initializations, this article will help. I’m going to break down a few of the major ones you actually need to know, in plain English, without the corporate buzzword bingo. SOC: Your Security Command […] - [What Is an Advanced Persistent Threat (APT) in Cybersecurity?](https://blacksmithinfosec.com/what-is-an-advanced-persistent-threat-apt-in-cybersecurity/): An advanced persistent threat (APT) is a sophisticated, long-term cyberattack in which an intruder establishes an undetected presence within a network to steal sensitive data or disrupt operations over an extended period. Unlike typical cyberattacks — which are often opportunistic and short-lived — APTs are carefully planned, highly targeted, and executed by skilled (and often well-funded) adversaries, such as nation-states or organized crime groups. How APTs Differ from Typical Cyberattacks Targeted Approach: APTs are aimed at specific organizations, industries, or even countries, often after extensive reconnaissance to identify vulnerabilities. Long-Term Engagement: Attackers maintain access for weeks, months, or even years, […] - [How MSPs Can Prepare for Evolving US Privacy Laws in 2025](https://blacksmithinfosec.com/how-msps-can-prepare-for-evolving-us-privacy-laws-in-2025/): Privacy in the United States is evolving at a breakneck pace, and 2025 is shaping up to be a landmark year. With at least eight new state privacy laws coming into effect, managed service providers (MSPs) are facing a surge of new compliance obligations — not just for their own operations, but for every client whose data they touch. Unlike traditional IT security requirements, these privacy laws introduce complex, overlapping mandates that vary from state to state, affecting everything from data collection and sharing to breach notification and consumer rights. For MSPs, the challenge is twofold: you must ensure your […] - [Ransomware in 2025 and the Rise of Multiple Extortion](https://blacksmithinfosec.com/ransomware-2025-multiple-extortion/): Ransomware has undergone a dramatic transformation over the past decade. In its early days, ransomware attacks followed a relatively simple playbook: threat actors would infiltrate a network, encrypt critical files, and demand a ransom payment in exchange for the decryption key. This “single extortion” model relied on the victim’s inability to access their own data, leveraging operational paralysis as the primary pressure point. However, as organizations improved their defenses — largely by implementing robust backup systems and investing in cybersecurity awareness — attackers found their traditional tactics less effective. Many victims could restore their data from BDR, reducing the incentive […] - [Operationalizing Compliance: 2025 Guide for MSPs and Enterprises](https://blacksmithinfosec.com/operationalizing-compliance-2025-guide-for-msps-and-enterprises/): By this point, we’re all aware that compliance isn’t something you can shove into a filing cabinet and forget about until audits roll around. If you’re still treating it like a box-checking exercise or scrambling to get your act together before regulatory deadlines, you’re doing it wrong — and it’s going to cost you. If not in damages, in stress and eventual burnout. The game has changed. In a world where data breaches make headlines and regulators have real teeth, compliance has become a business-critical function that touches everything your organization does. The question isn’t whether you need to care […] - [The Human Side of Compliance: Mental Health and Ethics](https://blacksmithinfosec.com/the-human-side-of-compliance-mental-health-and-ethics/): Let’s talk about something nobody wants to admit: compliance work is slowly burning people out, and it’s creating bigger problems than anyone wants to acknowledge. We spend so much time talking about policies, procedures, and regulatory frameworks that we’ve forgotten there are actual humans trying to implement all this stuff. And those humans? They’re cracking under the pressure. The Reality Check Compliance professionals are operating in what feels like a pressure cooker. They’re juggling constantly changing regulations, impossible deadlines, and the fun responsibility of being everyone’s moral compass. Oh, and if they mess up? The whole organization could face massive […] - [Insider Threats: Building a Culture of Trust and Vigilance](https://blacksmithinfosec.com/insider-threats-building-a-culture-of-trust-and-vigilance/): Insider threats — risks posed by individuals within an organization — remain one of the most challenging aspects of modern compliance and cybersecurity. These threats can be malicious, negligent, or even inadvertent, but the consequences are often severe. Building a culture of trust and vigilance is essential for mitigating insider threats. Identifying Insider Threats Detection requires both human and technological vigilance: Behavioral Indicators: Sudden negative changes in attitude, bypassing access controls, working odd hours, or displaying disgruntled behavior can all signal risk. Employees discussing resignation or new opportunities may also warrant attention. Technical Indicators: Unusual data movement (such as large downloads […] - [MSP Peer Groups and Communities: Finding Your Happy Place in 2025](https://blacksmithinfosec.com/msp-peer-groups-and-communities-finding-your-happy-place-in-2025/): The 2025 MSP market is more competitive than ever. With accelerating technology, rising client demands, and constant business challenges, no provider can succeed alone. Peer communities have become strategic assets that you don’t want to miss out on. These groups — be they forums, associations, or masterminds — connect managed service providers facing similar challenges. Members share insights, support each other, and celebrate wins. This collective knowledge helps providers solve problems faster and discover new growth strategies. This post covers how to find valuable MSP peer communities in 2025, what to look for when evaluating options, and how to maximize […] - [Understanding the Stages of Compliance Maturity](https://blacksmithinfosec.com/understanding-the-stages-of-compliance-maturity/): What is the Compliance Maturity Model? A compliance maturity model provides organizations with a structured pathway to evaluate and strengthen their compliance practices systematically. Rather than viewing compliance as a fixed state with some kind of ‘on-off switch’, this framework recognizes it as an evolutionary journey through distinct developmental stages — from reactive scrambling to strategic integration. By assessing capabilities across critical dimensions, businesses gain clear visibility into their current position, allowing targeted improvements that align compliance initiatives with broader organizational objectives and regulatory requirements. Such frameworks deliver multiple strategic benefits to MSPs and their clients: taking them from reactive […] - [Operationalizing Compliance: What It Means, Benefits, and Maturity Signals](https://blacksmithinfosec.com/operationalizing-compliance-what-it-means-benefits-and-maturity-signals/): What distinguishes leading managed service providers when it comes to compliance-as-a-service? One just needs to check if they approach compliance as an operational fundamental rather than a check-the-box exercise. When embedded into daily workflows, compliance transforms from burden to advantage. In the face of this trend, operationalizing is a path to reducing risk, improving efficiency, and building accountability. For MSPs seeking competitive differentiation and organizations pursuing sustainable growth, operationalized compliance has become essential. This article examines the practical implementation of operationalized compliance, its strategic value proposition, and why it signals organizational maturity. What Does Operationalizing Compliance Mean? Operationalizing compliance means embedding […] - [Survey Insights: What GRC Leaders Are Prioritizing in 2025](https://blacksmithinfosec.com/survey-insights-what-grc-leaders-are-prioritizing-in-2025/): Governance, Risk, and Compliance (GRC) leaders are recalibrating their priorities for 2025, with recent global surveys of GRC professionals revealing a sharp focus on regulatory complexity, operational resilience, cybersecurity, and artificial intelligence (AI) in risk management. Here’s what MSPs need to know to align their services with client priorities. Regulatory Complexity Remains the Top Challenge Across multiple surveys, regulatory complexity is consistently cited as the foremost concern. Over half of GRC professionals (51%) identified navigating a rapidly evolving regulatory ecosystem as their biggest challenge this year, with new laws and sector-specific regulations like GDPR, CCPA, DORA, and NIS2 adding layers […] - [Introducing the Shared Responsibility Model (SRM): What MSPs and Clients Need to Know](https://blacksmithinfosec.com/shared-responsibility-model-msp/): Cybersecurity and compliance have evolved dramatically over the last decade, and so too has the relationship between Managed Service Providers (MSPs) and their clients. The days of MSPs promising to “handle everything” are over; in today’s regulatory environment, both parties must clearly understand and document their respective roles. This is where the Shared Responsibility Model (SRM) comes into play — a framework that defines how security and compliance duties are distributed between IT providers and their clients. What Is the Shared Responsibility Model? The Shared Responsibility Model is a formalized approach that delineates which security and compliance responsibilities are managed […] ## Pages - [Enterprise and End Users | Request a Compliance Risk Assessment](https://blacksmithinfosec.com/free-assessment/): Looking to Better Understand Your Business’ Compliance Needs and Risks? Get a Free, No-Obligation Risk Assessment from a Blacksmith Partner! After submitting this form, you will be contacted by a Blacksmith Partner in your area. They will walk you through a quick, non-invasive risk assessment which will involve answering questions about your security requirements, IT landscape, and other factors which can impact risk and regulatory compliance.  Once the assessment is complete, our partner will guide you through understanding your resulting score and risk factors. We share this information with a Blacksmith partner in your area. We will not sell your […] - [Blacksmith Demo Booking Confirmed!](https://blacksmithinfosec.com/booked/): Your Meeting is Scheduled! In the meantime, check out these great resources! Download the “Forging Trust” eBook! You will be directed to a PDF download. Check Out Our Award-Winning Podcast for MSPs! See Episodes Subscribe to Our MSP Compliance Newsletter! - [Demo Booking Confirmation](https://blacksmithinfosec.com/booked-2/) - [Feast of Onboarding 2025!](https://blacksmithinfosec.com/feast-2025/) - [New to MSP Compliance? | Resources and Links](https://blacksmithinfosec.com/new/): Is Your Compliance Quest Just Beginning? Still trying to decide how to bring compliance into your MSP’s stack? Or maybe you’re still wondering the basics — like why is everyone talking about compliance in the first place? We’ve put together a list of great resources just for you! Download the “Forging Trust” eBook! Blacksmith’s creators wrote this book to help MSPs understand the basics of compliance — including how to turn it into a profitable part of your business! You will be directed to a PDF download. We do not rent, sell, or share this information. Schedule a Call with […] - [Blacksmith vs. Galactic Advisors](https://blacksmithinfosec.com/blacksmith-vs-galactic-advisors/): Blacksmith vs. Galactic Advisors Both Blacksmith and Galactic Advisors help navigate regulatory compliance.  Blacksmith InfoSec targets MSPs who want to deliver ongoing, multi-tenant compliance and security services — especially those seeking scalable, standardized processes for regulated verticals like healthcare, finance, and government contracting.  Galactic Advisors appeals most to MSPs seeking objective security auditing, sales enablement through external validation, and practical risk assessments that don’t tie into specific security product stacks.   Shared Strengths Both are purpose-built for MSPs and IT providers serving SMB clients, focusing on enhancing cybersecurity practices and compliance outcomes. Each offers reporting or advisory outputs that MSPs can […] - [Blacksmith Blog | IT Channel Compliance News](https://blacksmithinfosec.com/blacksmith-blog/): Blog Business Compliance Cybersecurity MSP Blacksmith Team October 15, 2025 MSPs Face Compliance Crossroads: Managing Supply Chain, Third-Party, and Data Privacy Risks in 2026 MSPs (Managed Service Providers) are facing an urgent need to elevate their risk and compliance programs due to evolving supply chain, third-party, privacy, and disclosure… Read More Business Compliance Culture MSP Blacksmith Team October 15, 2025 State Breach Laws, SEC Regulation S-P, and CIRCIA Drive Urgent Changes for 2025 Major regulatory and compliance changes in 2025 will transform how Managed Service Providers (MSPs) operate, manage risk, and support clients. Getting serious about compliance now… Read More […] - [Blacksmith vs. ControlMap](https://blacksmithinfosec.com/blacksmith-vs-control-map/): Blacksmith vs. ControlMap: Practical Comparison Both Blacksmith and ControlMap are advanced compliance platforms empowering MSPs to deliver scalable, profitable compliance and cybersecurity services.  Shared Strengths Both platforms are purpose-built for MSPs, with robust compliance management and automation features for multi-client oversight. Each supports multi-tenant functionality, central policy management, audit-ready documentation, risk register operations, and security framework mapping (though you’ll need to pay attention to ControlMap’s tiers). Policy templates and automated roadmaps streamline compliance workflows, reducing manual effort for MSPs. Where Blacksmith Adds Value Created by compliance experts with direct input from MSPs — professional insight is built into every tool […] - [Blacksmith vs. Cynomi](https://blacksmithinfosec.com/blacksmith-vs-cynomi/): Blacksmith vs. Cynomi: Practical Comparison Both Blacksmith and Cynomi are leading compliance management platforms designed to empower MSPs to deliver efficient, scalable, and profitable compliance-as-a-service. Shared Strengths Both platforms are purpose-built to enable efficient compliance management and extensive policy automation. Each provides multi-tenant capability, central policy management, audit tracking, asset governance, and risk register functionality. Compliance documentation is streamlined, with customizable templates and easy content deployment for diverse client needs. Where Blacksmith Adds Value Built by Compliance Experts: Blacksmith’s foundation is deep compliance and vCISO expertise, not MSP legacy. This means the platform’s design is guided by professionals who live and […] - [Ultimate Guide to Compliance Tools (2025)](https://blacksmithinfosec.com/ultimate-guide-to-compliance-tools-2025/): The Ultimate Guide to MSP Compliance Tools Table of Contents Navigating the world of compliance isn’t just about passing audits — it’s about gaining a strategic advantage and building an MSP practice around resilient growth. Blacksmith empowers MSPs to master compliance as both a business driver and a security pillar, combining regulatory expertise, automation, and customization in a single platform.  Why Compliance is Now Core for Modern MSPs  The scope of regulatory demands for MSPs has expanded dramatically. Beyond safeguarding IT infrastructure, providers now must ensure clients meet complex requirements like HIPAA, the FTC Safeguards Rule, NIST, and ISO 27001 […] - [Blacksmith vs. Compliance Scorecard](https://blacksmithinfosec.com/blacksmith-vs-compliance-scorecard/): Blacksmith vs. Compliance Scorecard: Practical Comparison Both Blacksmith and Compliance Scorecard support MSPs in navigating regulatory compliance, minimizing risk, and operationalizing their compliance services.  Shared Strengths Both platforms are purpose-built for MSPs, enabling efficient compliance management and policy automation. Each provides multi-tenant capability, central policy management, audit tracking, asset governance, and risk register functionality. Compliance documentation is streamlined, with customizable templates and easy content deployment.   Fast-track cyber insurance eligibility across dozens of carriers via platform-built integrations. Feature Comparison Where Blacksmith Adds Value Built by Compliance Experts: While both platforms are built for MSPs, Blacksmith was created by experts in […] - [Okta: Blacksmith Integrations](https://blacksmithinfosec.com/okta-blacksmith-integrations/): Blacksmith InfoSec + Okta: Integration Overview With the Blacksmith InfoSec + Okta integration, MSPs can transform identity and compliance management from a manual burden into an always-on safeguard — ensuring security, efficiency, and peace of mind across their client base. The Blacksmith InfoSec integration with Okta brings modern, automated identity governance to MSPs seeking rigorous, yet effortless, compliance across all client environments. By synchronizing Okta’s cloud-based identity and access management engine with Blacksmith’s compliance automation platform, MSPs can centralize user lifecycle management, run continuous access reviews, and generate audit-ready documentation — removing the manual effort and risks of disconnected tools […] - [Microsoft 365: Blacksmith Integrations](https://blacksmithinfosec.com/m365-blacksmith-integrations/): Blacksmith InfoSec + Microsoft 365: Integration Overview The Blacksmith InfoSec integration with Microsoft 365 gives MSPs fully automated, secure, and continuous identity compliance directly sourced from Azure Active Directory using SCIM provisioning. By connecting Microsoft’s enterprise cloud directory to Blacksmith’s compliance automation platform, MSPs can synchronize users and groups in real time, conduct streamlined access reviews, and generate audit-ready compliance evidence—all without resorting to manual exports or error-prone spreadsheet work. How the Integration Works Automatic User and Group Sync:Utilizing secure SCIM (System for Cross-domain Identity Management) integration, Blacksmith ingests live user and group data from Microsoft 365 (Azure AD). This […] - [ConnectWise: Blacksmith Integrations](https://blacksmithinfosec.com/connectwise-blacksmith-integration/): Blacksmith + ConnectWise: Integration Overview With Blacksmith InfoSec and ConnectWise, compliance goes from a disruptive chore to a seamless, value-adding capability — increasing security, margin, and client satisfaction for modern service providers Blacksmith InfoSec’s integration with ConnectWise Manage streamlines compliance for MSPs by bringing automated compliance tasks and audit workflows directly into the PSA platform technicians use daily. This certified integration optimizes efficiency, eliminates redundant manual work, and ensures audit readiness by automatically mirroring compliance projects and tasks from Blacksmith into ConnectWise, where they can be tracked, worked, and resolved natively. The result is a unified, transparent, and scalable compliance […] - [Liongard: Blacksmith Integrations](https://blacksmithinfosec.com/integrations-liongard/): Unlock Automated Compliance: Blacksmith InfoSec’s Integration with Liongard In 2025, cybersecurity threats are the top challenge for nearly 60% of MSPs, while evolving privacy regulations and client demands are pushing compliance requirements higher every quarter. Manual audits, fragmented documentation, and lack of real-time visibility increase risk, push up costs, and slow down incident response. The Blacksmith-Liongard integration addresses these challenges head-on. Effortless Compliance Audits for MSPs The Blacksmith InfoSec and Liongard integration transforms the way Managed Service Providers (MSPs) deliver compliance — replacing tedious manual tasks with fully automated, actionable user access reviews across Microsoft 365, Google Workspace, and every […] - [Blacksmith Integrations with MSP Software](https://blacksmithinfosec.com/blacksmith-integrations/): MSP-Focused Integrations When you’re looking to operationalize compliance, you want to rest easy knowing that your compliance platform plays nice with your solution stack. Blacksmith gives you powerful integrations designed to make your life easier — while you make your clients compliant and secure. By connecting Liongard’s automated, cross-platform visibility with Blacksmith’s purpose-built compliance workflows, you can streamline the entire audit process — eliminating manual data pulls, reducing spreadsheet sprawl, and delivering clear, actionable reports.  No More Manual Exports or Spreadsheets Instant, Business-Ready Reporting Centralized Access & Clarity Learn More By linking Blacksmith with ConnectWise Manage, you can seamlessly convert […] - [Get NIST-Y | Ask a Question](https://blacksmithinfosec.com/ask/) - [Blacksmith Link Tree | Downloads and Meetings](https://blacksmithinfosec.com/links/): Follow-Up Links Download the “Forging Trust” eBook! You will be directed to a PDF download. We do not rent, sell, or share this information. Schedule a Call with Blacksmith! Evaluate your compliance maturity and decide if Blacksmith is the best partner for your MSP. (Product demo optional.) Schedule Check Out Our Podcast for MSPs! See Episodes Subscribe to Our MSP Compliance Newsletter! - [Download Your Sample of Forging Trust](https://blacksmithinfosec.com/forging-trust/): Download Your Free Sample of Forging Trust Includes sample chapters from each section of the complete book! How to Bundle and Sell Compliance-as-a-Service Understanding and Building a Security Program Overviews of the Most Common Frameworks - [Happy Hour!](https://blacksmithinfosec.com/happy-hour/): Sponsored by: MSP Mixer: BREACH THE BAR Join us for a hearty mug of ale or a flagon of mead to kick off IT Nation Secure the right way! Monday, June 2nd @ 9:00PM Wreckers Sports Bar Reserve Your Spot! Sponsored by: - [Elementor #3299](https://blacksmithinfosec.com/elementor-3299/): Use Comparison Category Information Security Management System Governance, Risk, and Compliance Automation Training and Email Security Security Policies Consulting Features Blacksmith Vanta / Drata KnowBe4 / Mimecast Download Policy Templates vCISO General  ▶ 100% 50% 50% 75% 100%1 No Per User Costs ✔ ✘ ✘ ✔ ✔ No Per Framework Costs ✔ ✘ ✘ ✘ ✔1 Support For 7+ Frameworks ✔ ✔ ✔ ✔ ✔ Reduced Costs For Cyber Insurance ✔ ✔ ✔ ✔ ✔ Security Policies  ▶ 100% 17% 17% 33% 100%1 Security Policy Templates ✔ ✔ ✘ ✔ ✔ Approval Workflow ✔ ✘ ✘ ✘ ✔ Policy Agreement […] - [Get NIST-y | Blacksmith Infosec Compliance Webinar Series](https://blacksmithinfosec.com/nisty/): Get NIST-y! Home / Get NIST-y Get NIST-y is the award-winning podcast that breaks compliance out of the checkbox trap and turns it into a real security advantage. No fluff. No FUD. Just practical advice to help your MSP. Award-Winning Podcast! Ask a Question for an Upcoming Podcast Follow wherever you listen Amazon Music Apple Podcasts Pocketcasts RSS Feed - [Master Subscription Agreement](https://blacksmithinfosec.com/master-subscription-agreement/): Master Subscription Agreement Current as of: February 24, 2025 Subscription Agreement This Subscription Agreement (this “Agreement”), contains terms and conditions that govern your purchase and use of the Services (as defined below), and is a contract between Blacksmith InfoSec, LLC., a Delaware (USA) corporation (“Blacksmith InfoSec”), and you or the entity or organization that you represent. This Agreement takes effect when you enter into an Order (as defined below) with Blacksmith InfoSec (the “Effective Date”). Capitalized terms not otherwise defined in this Agreement will have the respective meanings assigned to them in Section 22. Blacksmith InfoSec may modify this Agreement […] - [Legal](https://blacksmithinfosec.com/legal/): Legal Privacy Policy Master Subscription Agreement Acceptable Use Policy - [Acceptable Use Policy](https://blacksmithinfosec.com/acceptable-use-policy/): Acceptable Use Policy​ Current as of December 1, 2023 This Acceptable Use Policy (this “Policy”) describes prohibited uses of the hosted application and Information Security Management Service (ISMS) (the “Service”) offered by Blacksmith InfoSec LLC. (“Blacksmith InfoSec”) and the related website located at https://blacksmithinfosec.com (the “Site”). This policy supplements, and is incorporated into, Blacksmith Infosec’s Master Subscription Agreement (currently published at https://blacksmithinfosec.com/master-subscription-agreement) (the “MSA”). If any provision in this Policy conflicts with a term in the MSA, then the applicable provisions of MSA will prevail unless the term in this Policy specifically states that it will prevail. If you violate this Policy, Blacksmith […] - [User Guides | Configure Client](https://blacksmithinfosec.com/user-guides-configure-client/): Configure Client NFR and Client Setup Configure the license (client or NFR) under Company Settings.  Choose how policies will be acknowledged by end users. Choose applicable industry and compliance frameworks. Select who in the company will be managing the security program. Select the applicable answers for all remaining questions. That’s it! You’ve complete the basics of configuring a client! If you have any further questions, don’t hesitate to contact your account manager, or return to the Resources section for more helpful articles. - [User Guides | Add First Client](https://blacksmithinfosec.com/add-first-client/): Add Your First Client Open the Blacksmith portal and click the ADD CUSTOMER button on the right. Fill out the information and click save. That completes the basic steps of adding your first client! If you have any further questions, don’t hesitate to contact your account manager, or return to the Resources for more helpful articles. - [User Guides | Draft and Assign Policies](https://blacksmithinfosec.com/user-guides-policies/): Draft and Assign Policies Navigate to the POLICY ADMIN panel. Manage and view policies from this dashboard. View a policy, see important notes, and make changes to the drafts. Assign policy owner and select variables as needed. That completes the basic steps of creating policies in the portal! If you have any further questions, don’t hesitate to contact your account manager, or return to the Resources for more helpful articles. - [User Guides | Adding Users](https://blacksmithinfosec.com/user-guides-adding-users/): Adding Users Navigate to the USER ADMIN panel. Invite or Edit users to enter their information. Use the dropdown to configure roles. The Admin role grants access to the entire platform. The Client Admin role lacks administrative functionality, but the user can still manage clients and add clients. The Client Technician (Client Tech) role can manage clients, but isn’t permitted to add new clients. That completes the basic steps of adding users to the portal! If you have any further questions, don’t hesitate to contact your account manager, or return to the Resources for more helpful articles. - [User Guides | Custom Branding](https://blacksmithinfosec.com/user-guide-custom-branding/): Custom Branding Configure MSP branding, including custom URL, application name, and logos inside the MSP SETTINGS panel. That completes the basic steps of adding your MSP to the portal! If you have any further questions, don’t hesitate to contact your account manager, or return to the Resources for more helpful articles. - [User Guides | Setting Up Your MSP](https://blacksmithinfosec.com/user-guides-setting-up/): Setting Up Your MSP Login to the Blacksmith portal. <Login Link> From the Blacksmith dashboard, navigate to SETTINGS. Configure MSP branding, including custom URL, application name, and logos. Choose to enable (default) or disable the end-user training module. Configure company security settings, including Single Sign-On and SCIM. Configure integration settings (i.e. ConnectWise integration to turn the Compliance Roadmap into a project in CWM). Add users and assign roles.  The Admin role grants access to the entire platform. The Client Admin role lacks administrative functionality, but the user can still manage clients and add clients. The Client Technician (Client Tech) role […] - [Case Study | Blacksmith | CTS](https://blacksmithinfosec.com/case-study-blacksmith-cts/): Home / Case Study: CTS Client Charter Technology Solutions Date February 3, 2025 Location New England, USA Partner with Us to Become a Trusted Compliance Partner Schedule a Demo Required Login Please Login for Submit Form. Close Success “Blacksmith has been a critical part of our Compliance-as-a-Service bundle and absolutely improves the profitability of an MSP.” David A. Cyber Practice Lead Streamlining Compliance and Policy Documentation Processes Like many MSPs, Charter Technology Solutions was seeing an increased demand for compliance management services. This demand led to a realization — that manual processes and client-by-client policy creation was not sustainable. CTS […] - [Case Study | Blacksmith | NTM Advisory](https://blacksmithinfosec.com/case-study-blacksmith-ntm/): Home / Case Study: NTM Advisory Client NTM Advisory Date January 9, 2025 Location Colorado, USA Partner with Us to Become a Trusted Compliance Partner Schedule a Demo Required Login Please Login for Submit Form. Close Success Close “Onboarding was intuitive and straightforward. From the perspective of someone who has been doing programs for years, I knew right away that this platform covered everything an SMB needs to build out a security platform.” Mike E. Owner/vCISO Optimizing Compliance Offering and Driving Security Programs Mike started NTM Advisory after spending most of his career supporting large enterprises. During that time, he […] - [Pricing | Blacksmith Infosec | Compliance Solution for IT Providers](https://blacksmithinfosec.com/pricing/): Pricing Home / Pricing Competitive Pricing We believe in complete transparency, which is why our pricing is public and free of hidden fees and upcharges. Free Trial $0 Setup your NFR and see how Blacksmith will improve your compliance workflows. No Payment Info Required Add client FREE for 30 days All Policy Templates All Frameworks Unlimited Users Unlimited Documents All Integrations Get Started Managed Services Partner MSP Only! Contact Us for MSP Pricing Flat rate pricing for easy scaling and bundling. No sign-up fees or additional charges. Blacksmith Unified Portal All Policy Templates All Frameworks Unlimited Users Unlimited Documents All […] - [Case Study | Blacksmith | Systech](https://blacksmithinfosec.com/case-study-blacksmith-systech/): Home / Case Study: Systech Client Systech Date January 15, 2025 Location New York, USA Partner with Us to Become a Trusted Compliance Partner Schedule a Demo Required Login Please Login for Submit Form. Close Success Close “Even though we were doing compliance, we didn’t have a way to see our work in an all-in-one dashboard until Blacksmith.” Joel D. Operations Manager Optimizing Compliance Offering and Driving Security Programs Like many MSPs, Systech was managing compliance ‘by the seat of their pants’. With no system in place for either selling or managing compliance, clients were managed with tedious spreadsheets — […] - [Blacksmith Blog | Compliance and Security Articles for MSPs](https://blacksmithinfosec.com/blog/): Blacksmith Blog Home / Blog Your Compliance Knowledge Hub Search Business Compliance Product Blacksmith Team July 16, 2025 Say Goodbye to CSVs: Why Legacy Audit Reporting Holds MSPs Back For years, Managed Service Providers (MSPs) have leaned heavily on CSV exports to meet audit and compliance demands. Run a PowerShell script, wrangle the output,… Read More Business Compliance Cybersecurity MSP Blacksmith Team July 16, 2025 Bridging Visibility and Governance: What Next-Gen Compliance Should Look Like for MSPs Modern Managed Service Providers (MSPs) face a new reality: compliance isn’t just about going through the motions for an auditor’s checklist — it’s […] - [User Guides | Walkthrough](https://blacksmithinfosec.com/walkthrough/): New MSP Walkthrough Initial Portal Setup (MSP) Login to the Blacksmith portal. <Login Link> From the Blacksmith dashboard, navigate to SETTINGS. Configure MSP branding, including custom URL, application name, and logos. Choose to enable (default) or disable the end-user training module. Configure company security settings, including Single Sign-On and SCIM. Configure integration settings (i.e. ConnectWise integration to turn the Compliance Roadmap into a project in CWM). Add users and assign roles. The Admin role grants access to the entire platform. The Client Admin role lacks administrative functionality, but the user can still manage clients and add clients. The Client Technician […] - [Resources](https://blacksmithinfosec.com/resources/): Resources Home / Resources Documentation Access Control 1 Invalid Login Lockout Attempts Explore More ConnectWise 1 ConnectWise Integration Explore More Microsoft 365 2 Invalid Login Lockout Attempts Microsoft 365 SCIM Integration Explore More SCIM 2 OKTA SCIM Integration Microsoft 365 SCIM Integration Explore More User Guides New MSP Quick-Start Guide Blacksmith Walkthrough MSP Onboarding Steps Setting up your MSP account Custom branding Add your first client Configure clients (and NFR) Add users Draft policies & policy assignment - [Overview | Blacksmith Infosec | Compliance as a Service](https://blacksmithinfosec.com/overview/): Blacksmith Overview Home / Overview Grow your business with our CaaS platform. Start your clients on their cybersecurity compliance journey with Blacksmith InfoSec. Our SaaS application provides each of your customers with bespoke policies, risk management, compliance roadmap, business system user audits, and security awareness training, all with a simple, centralized management platform so you can manage their tenant with white glove service. Set yourself apart from other MSPs today! Why Blacksmith? Custom Forged Policies Deploy custom security policies Use templates designed by experts Add milestones to track progress and foster long-term client relationships Holistic Security Programs Easily start compliance/security […] - [Media | Blacksmith Infosec Compliance for MSPs](https://blacksmithinfosec.com/media/): Media Home / Media Blacksmith’s Jared Casner and Host Joey Pinz Mike and Jared Rap at IT Nation Connect AWS Showcase Announcement All Things MSP Office Hours Making Compliance Simple for MSPs (IT Business Podcast) Get Informed: Get NIST-y! Register and ask your questions live during our next show in this compliance-focused series!  Register - [Blacksmith Infosec | Compliance as a Service for MSPs](https://blacksmithinfosec.com/): Operationalize Your Compliance-as-a-Service Offering Blacksmith takes the guesswork and hassle out of managed service compliance offerings, so you can make your clients more secure while generating additional revenue. Learn More or Get a Demo or are you an enterprise or business looking to minimize risk and address compliance? Click here! "Blacksmith helped us tremendously to be able to track the actual cyber health of a company. Until now, even though we did it, we didn't really have a way to see an all-in-one dashboard with what we're doing. And we can also show this to the client and say: 'Hey, […] - [Privacy Policy](https://blacksmithinfosec.com/privacy-policy/): Privacy Policy Current as of December 01, 2023 Your trust is important to us, and we want to ensure that your personal information is protected. This Privacy Policy explains how we collect and use your personal information in relation to Blacksmith InfoSec products, services, events, and websites or applications that link to this Policy (together, the “Blacksmith InfoSec Products”). It also describes how you can control or exercise your rights related to your personal information.   Personal Information We Collect We process information about you while providing the Blacksmith InfoSec Products. Below, we outline the kinds of information we collect. […] [comment]: # (Generated by Hostinger Tools Plugin)