States Are Offering Carrots As Well As Sticks
For the past several years states have been passing privacy laws that impose stiff penalties on organizations that mishandle the personal information of their residents. However, a growing number of states have passed legislation that can provide legal “safe harbor” to those organizations that implement and maintain security measures based on a recognized cybersecurity framework.
Compliance-as-a-Service…Great Idea! But Start With Your Own Practice
This week, Kaseya released it 2023 Global Benchmark Survey Report. The survey, completed by more than 1000 respondents worldwide (predominantly the Americas), highlights the top trends in the MSP industry for the current year and compares them against the previous year.
Unsurprisingly, CyberSecurity ranks as the highest concern of MSPs showing a 15% increase over the 2022 results. In fact the top five new services MSPs plan to offer in the coming year fall into the Cybersecurity services category. Topping the list at 39% is Regulatory Compliance Management and Reporting. This is followed by Managed Detection and Response, Dark Web Monitoring, Identity and Access Management, and Security Awareness Training.
The interest in offering Regulatory Compliance Management services, often referred to as Compliance-as-a-Service makes sense with the increase in regulatory requirements.
However, many MSPs need to start by getting their own house in order. True compliance requires that policies and procedures are documented, processes are audited, and all employees are trained and follow the documented procedures. Although many MSPs have implemented strong security measures and practice good general cyber hygiene, many lack the documentation and consistent auditing to pass an external audit.