Home About Speaking Framework Press Podcasts Field Notes Say Hello
Profit Grow Exit · Season 1, Episode 16 · Guest appearance

Cybercrime Is a Human Problem: What MSPs Need to Know

with Sean Walsh, CEO of Encore

Cyrus Walker joins Encore CEO Sean Walsh on Profit Grow Exit to explain why cybercrime is a human problem, what MSPs get wrong in the first hours after an attack, and why the MSP model has to move from alerts to operations.

← Back to Podcasts Next →

On this episode of Profit Grow Exit, a podcast for managed service provider (MSP) owners, Cyrus Walker and Encore CEO Sean Walsh — a former police detective and computer forensics investigator — trace their paths into cybercrime investigation and make the case that cybercrime is a human problem, not a technology one. They walk through the mistakes MSPs make in the first hours after an attack, from wiping the drives that hold the evidence to restoring backups that bring the vulnerabilities back, and discuss how AI is lowering the bar for attackers while helping defenders cut through the noise. Cyrus closes on why MSPs need to move from a monitor-and-alert model to a co-managed, operations-driven one.

Key takeaways

  • Attackers target people because it is cheaper than beating the technology. A former municipal client of Data Defenders had zero breaches in six years; four months after switching vendors, one phone call that talked a controller out of their credentials cost it $1.2 million.
  • The biggest mistake after an attack is going straight into restoration instead of triage. Wiping and re-imaging destroys evidence, and a sophisticated ransomware variant keeps changing while you chase it — one Chicago police agency spent three weeks before calling in professionals.
  • If you feel you have to act, pull the plug rather than shutting down, remove the hard drive, and label, date and lock it away to keep the chain of custody. Restore onto a new drive.
  • Restoring from a backup or image can put the original vulnerability straight back, and advanced attacks hunt down and corrupt backups. Keep backups air-gapped and check images before they go back into production.
  • MSPs should build each client’s incident response plan at onboarding — including who the insurer would send — and run regular breach “fire drills,” the same way they test backups.

← Back to Podcasts