POPULARITY
The episode details a structural shift within the managed services market toward increased operational automation and integration, framed by vendor-led consolidation of core service platforms with embedded AI-driven workflows. ConnectWise has combined previously separate systems—PSA, RMM, ScreenConnect, and others—into a unified platform powered by agent-based automation ("agentic AI") under the "Predictive IT" model. The associated risk for service providers is growing reliance on consolidated vendor ecosystems for both service delivery operations and automation capabilities, blurring the distinction between core service expertise and contextual tooling. A consequential data point highlighted is from Service Leadership benchmarking, which shows sustained 19% EBITDA over six years for MSPs, with the most profitable—in what ConnectWise identifies as "best-in-class"—gaining advantage through higher investment in automation and agent-driven workflows. According to ConnectWise, production test data show that deploying agentic automations has produced a 30–60% reduction in tickets requiring direct human involvement, along with 45% reductions in handling times and claimed margin improvements of 5–12 percentage points. Importantly, labor cost pressures and technician burnout persist, positioning automation as a response to both expense management and workforce availability challenges. Supporting developments clarify that best-in-class or larger MSPs often experiment with building their own automation tools, but many report variable outcomes, including cases where internally built solutions fail to deliver anticipated efficiency or escalate costs—a result ConnectWise attributes to confusion over what constitutes "core" versus "contextual" investment. ConnectWise now positions its integrated approach as a way for smaller and mid-size MSPs to access operational automation without standing up custom software projects or incurring the risks and overhead of internal development. The episode also surfaces channel-wide conversation about the tension between per-user, per-workflow, and consumption-based pricing, highlighting the risk of variable costs being introduced into previously fixed-fee MSP engagement models. For service providers, the practical implications are increased dependency on platform vendors for operational tooling, with a shift away from internally built processes toward outsourced automation and dashboard-driven performance tracking. This creates new pricing models—metered by user, workflow, or consumption—which can introduce variability and contract risk when compared against flat-fee client agreements. Providers need to monitor the alignment between vendor billing structures and their own client contracts, assess the operational impact of vendor stack consolidation, and maintain transparency around efficiency gains versus workload transfers. Oversight mechanisms must be updated to account for reliance on agent-run workflows and to mitigate associated accountability and governance risks. Supported by: WebPros (CometBackUp)Pax8
The episode highlights the shift toward AI-driven knowledge management within the MSP sector, revealing increased operational dependency on structured data and sophisticated integrations. Lexful, an AI-native documentation platform designed specifically for MSPs, represents this trend by positioning itself not as a simple add-on but as a replacement for legacy documentation tools—controlling critical record-keeping functions and interfacing with principal PSA and RMM systems. This development signals greater infrastructure dependence on AI-based documentation and the implications of technical integration across diverse operational tools. According to Lexful's CEO and statements made during the episode, the platform has completed integrations with major PSA and RMM tools and now handles data by employing a “context-engineered” large language model tailored specifically to the MSP context. Lexful claims its engine minimizes LLM hallucinations, supports record-level access control, and functions as a system of record rather than a direct action platform. Socializing its compliance trajectory, Lexful has achieved SOC 2 Type 2 and shipped its MCP server, but its listing in marketplaces like Pax8 and SureWeb has been delayed, with current status characterized as “coming soon” and full integration targeted before the end of 2026. Supporting developments underscore the complexity and risk of deploying AI-native platforms into MSP environments. The absence of public customer or partner counts persists, with the company attributing constrained accessibility to pending integrations rather than lack of market uptake. Pricing structures diverge from incumbents, moving from per-user to per-client models and establishing minimum contract terms—raising questions about justification of cost versus legacy alternatives. A key operational risk centers on access control and human-in-the-loop governance, with sensitive systems such as password vaults only accessible through layered permissions, and Lexful emphasizing the necessity of robust accountability frameworks to minimize harm from potential automation failures. Practical implications for MSPs include heightened need for rigorous governance of AI systems, especially around data access, role management, and auditability. Vendor dependency deepens as platforms like Lexful supplant multiple existing tools and drive uptake via deeper integration with distribution marketplaces and SaaS ecosystems. Pricing and contract structures require MSPs to reconsider value calculations, as cost is no longer purely user-driven but tied to client volume and operational breadth. The tradeoff is between purported efficiency gains from automation and the risk profile associated with delegating documentation and knowledge management to AI-based infrastructure, particularly as human oversight remains essential to mitigate errors and ensure regulatory compliance. Supported by: ScalePad
Wil Santiago, Wil Santiago, chief security and trust officer at Blackpoint Cyber Wil Santiago, chief security and trust officer at Blackpoint Cyber, joins In The Channel to discuss the findings of the company’s 2026 Annual Threat Report – research grounded in thousands of real incidents investigated by Blackpoint’s security operations centre, not surveys. The headline finding: attackers are no longer trying to break in. They’re logging in. Using stolen credentials and commodity remote management tools, threat actors are walking through the front door, hiding in plain sight, and operating with system-level privileges – sometimes for days before anyone notices. Santiago walks through the key trends the SOC identified across 2025: ClickFix and fake CAPTCHA campaigns accounted for more than half of all identifiable incidents, with attackers abusing trusted infrastructure including Azure Blob storage and Cloudflare to deliver payloads. RMM abuse showed up in roughly 30 per cent of triaged incidents – threat actors installing their own version of the same tools MSPs use legitimately, then living off the land with god-mode access. And Adversary-in-the-Middle attacks are now routinely hijacking authenticated sessions even when MFA is in place, by abusing OAuth token handling. The conversation also covers Blackpoint’s detection philosophy: behavioral context over malware signatures. Understanding what normal looks like in an environment – who uses what tool, at what time, from where – is what allows the SOC to catch attackers before they act. It’s a philosophy that is producing results: Blackpoint disrupted 56 per cent of incidents before a payload was ever deployed. Santiago’s closing recommendation for MSPs is straightforward: start with an RMM audit. Know every remote management tool deployed across every endpoint and server you manage. You cannot protect what you don’t know exists. The 2026 Annual Threat Report is available for download on the Blackpoint Cyber website. Read Full Transcript Robert Dutt: Hello and welcome to In The Channel from ChannelBuzz.ca, bringing news and information to the Canadian IT channel community for the last 16 years. I’m Robert Dutt, editor of ChannelBuzz.ca and your host for the show. Wil Santiago is Chief Security and Trust Officer at Blackpoint Cyber, an MDR provider whose SOC monitors and responds to threats in real time across a large base of MSPs and their clients. And unlike a lot of threat research that’s survey-based or derived from external reporting, what Blackpoint publishes comes from live incident data, thousands of actual threat responses they’ve worked through in the SOC. Their 2026 annual threat report has a thesis that cuts right through it. Attackers are no longer trying to break in, they’re logging in, using stolen credentials and legitimate IT tools, the same RMMs, the same cloud platforms that MSPs rely on every day, to walk through the front door, hide in plain sight, and work their way towards payday. It’s a theme we’ve been tracking at ChannelBuzz.ca. If you caught our conversation with Tony Anscombe from ESET, that one dug into the mechanics of how MSP tools are being weaponized against the very clients they’re supposed to protect. This conversation is the data layer behind that story, and the detection philosophy that Wil and the Blackpoint team have built to counter it. Their SOC is disrupting 56% of incidents before a payload even deploys. We talk about how. Let’s get right into it. My chat with Wil Santiago. Wil, thanks for taking the time, I appreciate it. Wil Santiago: Thank you, Robert. Robert Dutt: For people who know Blackpoint primarily as an MDR provider, but maybe haven’t dug into the research side, can you give us a quick sense of what your SOC is actually seeing day to day? When you say this report is based on thousands of real incidents, what does that mean in practical terms, in terms of how you gathered this data? Wil Santiago: That’s a great question, Robert. It really starts at the core of what we focus on at Blackpoint Cyber. In 2025, we focused a lot of our detection efforts in the cloud endpoints, but what we realized is that at the core, at that identity layer, that’s the most important thing. But what we’re protecting at Blackpoint is the identity. What we observed in 2025 is this interesting shift where, yes, there’s vulnerabilities, there will continue to be vulnerabilities. However, threat actors don’t necessarily need to weaponize those vulnerabilities to gain access into an environment. They’re not really targeting customers or companies with any specific new zero-day technology or exploits that are novel. They’re just logging in using stolen passwords. We’re still at that pivotal point, but we’re still talking about the same things we’ve been talking about, password reuse, making sure you’re protecting yourself from phishing emails, so on and so forth. But the reality is that threat actors are getting in. They’re stealing credentials and they’re using legitimate tools to just log in, walking through the front door. Robert Dutt: Yeah, the headline from the report was very catchy with the attackers are no longer trying to break in. They’re just logging in, as you say. And that framing echoes what we’ve seen in other reports elsewhere. People are calling 2025 the year of the abuse of trust in terms of security trends, but your numbers are operational and not survey-based. I’m curious what trusted compromise looks like from where you sit. Is there really a shift away from what you were seeing a couple of years ago or three years ago, or has this always been the playbook and we’re only now measuring it properly? Wil Santiago: Yeah, so if I compare back to, let’s say, 2022, I think we at Blackpoint would still see a trend, the threat actors gaining access into an environment, usually using some type of exploit at that time. You can point to a number of Microsoft Exchange exploits that happened during that time. The Hafnium group was doing a lot of Exchange exploits. The reality is there came a certain time where we were detecting Cobalt Strike, a malware commodity tool, every single day in Blackpoint Cyber’s SOC. And then eventually it became once a week, and then it became once a month. So then we started to think, well, what’s happening with the shift of tactics with the threat actors? And what we found is instead of installing Cobalt Strike, they started to install legitimate IT tools. And that’s the trust component. When they’re installing tools that you use internally, they now can abuse those tools the same way that you use those legitimately. And so we have these threat actors that not only are abusing legitimate tools, but like I said, they’re abusing legitimate identities. So when you have what I call the keys to the kingdom, the passwords, I am you. I am now Robert, for all intents and purposes for this sort of webinar. I think the interesting part that we’ve seen at Blackpoint is that threat actors have really, really focused on leave-behinds. And those leave-behinds are commodity remote management tools. Why do they do that? Because EDRs don’t know how to detect them as malicious, right? These are legitimate IT tools that are being used to service MSPs and their customers. And a threat actor just installs their version of the same exact tool that you’re using legitimately. Right? And so the trust component is you go to review your assets and you see ScreenConnect installed in your environments because you use ScreenConnect, right? But then when you start taking a closer look, you start to realize, wait a second, there’s four different ScreenConnect IDs on this one machine. Now we have a more of a problem, right? And so the attack is a little bit of an invisible signature detection because it’s an authorized tool, right? And so we really have to get to this layer of identifying threat actor activity with behavior context. If you’re an AnyDesk shop, then why do you have TeamViewer installed on your file server that’s publicly facing, right? Let’s start to ask those questions and dig into that a little bit. Robert Dutt: Your SOC found that fake CAPTCHA and ClickFix campaigns accounted for, I think it was 50-odd percent of identifiable incidents. That’s a majority of attacks being driven by a technique that essentially requires the victim to step on the link to execute it themselves. Why is that scaling so fast right now? And especially for an MSP who tends to think, you know, my technicians are too smart to do that. What’s kind of the honest answer for what they need to be looking for and protecting against? Wil Santiago: Yeah. And, you know, ClickFix is such an easy attack when you really get into the root of what it does. But it starts with social engineering. You’re enticing someone, again, just like with phishing, to visit something that you’re going to tell them to do an action. And most of the time, they’re going to do that action. Now, why this is so effective is we’re seeing techniques that really enable the threat actor to deliver the payload. And how do they do that? Search engine optimization, right? These SEO links at the top, when you go look for an OBS installer, because you need your camera to look well, or you get a Google sponsor result. Threat actors are just buying those sponsored results and delivering their payloads on there. You click on it thinking you’re going to download OBS, and then it tells you, hey, wait a second, you have to make sure that you are human. Verify that we’re used to verifying we’re humans to download something. So we go and we click it. But then it says, hey, open up your Windows Run command and maybe run this command on us, on your computer for us. And what happens? Threat actors go and they put the commands on a website. They have this watering hole spread out all throughout infrastructure that’s globally distributed. Google, Microsoft, all these sort of cloud infrastructure hosting providers that exist. Threat actors use those. So when you’re looking at your firewall logs and you’re seeing your internal team going to Microsoft.com, hey, it’s Microsoft, right? But the reality is, it’s likely an Azure Blob site that’s just being hosted on Microsoft, that is a threat actor that’s actually hosting it. And so they’re abusing that trust function to say, hey, you need this OBS installer. You Googled it. I didn’t tell you to go Google that. You were the one that did that. And then they found my link, which I posted a malicious payload there. And so again, that abuse factor is all the things we’ve taught our employees, our customers, our MSPs to do, right? Go to Google, make sure you identify the link. Make sure you look for Microsoft. Make sure you see the end of a URL or domain. Validate that. Well, the adversary goes, okay, they want to play that game. I’m just going to host this on Cloudflare. And now we’re back to this gate where now someone clicks on something. Well, what’s this Cloudflare? That’s a legitimate service. I know that to be true, right? It’s very true. The reality is the infrastructure is very, very easy to set up. And it doesn’t require a lot of action. It just requires someone to take a command and put it on their machine. And all the background work happens in the background, right? And so beyond that, we used to see a lot of threat actors use this sort of technique to download malware onto machines. But again, going back to what I mentioned about RMMs, now they’re just downloading an RMM. And that just looks like a legitimate process to an EDR. Robert Dutt: Right. So for an MSP, especially when training or making sure their technicians are aware, is it just as simple as making sure they’re aware of this threat landscape and this wrinkle in it? Or is there something more that’s sort of the advice there on how to protect yourself as best you can? Wil Santiago: That’s a great question. And really, you know, I would say any MSP watching this show, starting today or tomorrow, the first thing that I always tell people, audit your RMM inventory. Asset inventory is the number one thing that customers should be doing, right? You cannot protect what you don’t know exists. And so every single remote management tool that’s deployed across every endpoint you manage, every server you manage, you need to audit those, right? Like you’re giving direct access to a system. And most of the time, those RMMs run in the system context, which means they have the permissions and privileges of any admin, right? And now you have this adversary that has a foothold. They can deploy tools using admin privileges and permissions. So you have to audit your RMM inventory, right? Making sure that you understand what’s happening across those production servers. And forcing MFA, that’s a big one. We see a lot of incidents that source from RMM abuse because they log into the MSP’s RMM console, the cloud-based consoles. Some of those don’t have MFA involved. Again, keys to the kingdom, MFA everywhere, that needs to be a reality. Then we need to start moving into what I call more resilient engineering, right? Conditional access policies, preventing individuals from logging in from untrusted sources, locations, right? There’s ways that you can lock down access to an RMM and assume a threat actor is able to steal credentials because they maybe installed an info stealer on a user’s machine, stole their browser credentials. They reuse the same credentials for Gmail that they do for their corporate environment. Well, now a threat actor just perusing finds their credentials and says, “Oh, I’ve got IT Glue permissions now. I’m going to go log into this and restore all these configs in IT Glue or whatever tools out there.” Well, now the threat actor has access to that. And so that’s how they’re pivoting across these environments. They’re going from cloud to on-prem, on-prem to cloud. One of the things that we caught at Blackpoint recently, and this was a really cool response, but the threat actor compromised the cloud environment first. They then took that cloud access, deployed an RMM using Intune to the devices, and then they used that on-prem access to go to those machines and do their own work directly from that console. I called it overkill. They didn’t have to do that because they had the cloud environment. But because they did that, that sort of prompted this investigation for this MSP to approach us and say, “Hey, we believe something is happening. We investigated and quickly saw the Intune process was the responsible process for deploying some of this malware. So we told them, “Hey, deploy our cloud response suite. We want to understand what’s happening in your cloud.” And sure enough, seven global admins were compromised. So again, limiting scope is important here, right? Least privilege. Why do we have so many people with admin privileges and permissions? I think there’s 192 admin roles or something like that in Microsoft, but we default to just, you get global admin, you get all the permissions. And so now an adversary compromises a Microsoft 365 tenant. Well, now they have the permissions of a global admin. And unfortunately for us, when we shifted from the on-prem strategy to the cloud strategy, we just started pushing everything in the cloud and we say, “Oh, it’s fine. It’s in SharePoint.” We didn’t realize though that that’s only being protected by a password and an MFA token, both of which can be stolen, right? So the protection is not really there. That’s why we have to move to that resilient engineering. And so it’s moving from that reactive alerting to that posture alerting, right? Why is someone trying to log in from France? We have nobody in France. Robert Dutt: So your report showed almost a third of triaged incidents involved RMM abuse. And that’s something, that kind of trend line is something that we’ve seen in other reports. You know, one of your peers is talking about a 200 plus percent spike in abuse of RMM in attacks. I’m curious, especially since you’re sitting in the SOC there, what does RMM based intrusion actually look like in the SOC here? You know, I’m guessing curious, is there a moment where it’s genuinely hard to tell, you know, is this actually a tech doing a routine task or is this an attacker? And if so, what kind of breaks the tie and causes you to go, “No, no, that’s not right.” Wil Santiago: Yeah. Well, there’s kind of two ways to look at it, right? We have threat actors that are compromising MSP RMM tools. These are tools that are owned, managed by the MSP. They’re usually protected with some cloud login, whether they self-host it or they have the vendor host it for them. Threat actors can log into those systems with a password and a username, right? So we see a lot of brute forcing of those systems, especially if they’re self-hosted systems, they usually don’t have the protections of the vendors. They don’t put a WAF in front of them. And so they’ll try to brute force them and just log in, right? Those are few and far between, to be quite honest. We don’t see those as often, but what we do see often is, again, they gain access into an environment, usually by compromising a VPN. Now they’re on the network. Now they can move throughout that network as they’re on the VPN, and they’ll usually find a foothold. And if they have a credential like a local admin, they’ll take that one foothold and then they’ll distribute their RMM across that entire fleet of the network with one command from that foothold. So for us, when we’re looking at RMM deployments, MSPs deploy RMMs in a certain manner and format. They’re not deploying an RMM at two o’clock in the morning on a Saturday when they’re a US-based company. And oh, by the way, they just logged in from a Chinese-based IP, right? So again, there’s indicators that are very clear cut of like, okay, this deployment of RMM tools absolutely malicious. Most of those cases come to the case of, you know, we have application control within Blackpoint that allows us to alert when someone is installing a new application that’s unauthorized. And so what we tell our MSPs to do is, hey, set up your policies that if you’re a Ninja RMM shop, you cannot have any other installations of any other RMM. ScreenConnect is not going to be involved. And so that allows us and affords us the ability to do is, when we get that alert that says someone’s attempting to install a ScreenConnect, we can go back and sort of recreate the path of how do they get here. And what that allows us to really get into is, again, that response, right? And that response is preventing the installation of the RMM, eradicating the threat actor by isolating the machine, making sure you remove their footholds, getting those SSL VPNs off of the public facing internet, and having that exposure management reduced, right? And so when we look at RMM abuse in practice, once they get that RMM installed, again, they’re living off the land with system privileges. System privileges is something that most people tend to understand, but it’s just keys to the kingdom. You are God mode at that point. You can do whatever you feel to deploy and ultimately spread your access with that level of access, right? And so they’ll use it for backdoors. And oftentimes, they may compromise the environment and say, “You know what? I’m busy.” We’ve actually seen this over the holidays where they go take their breaks. Just like everyone else does. It’s Christmas. I’ve done a lot of hacking. So they leave their leave-behind tools and they come back. That’s their access factor. Again, it’s one of those things where they’re hiding in plain sight. Robert Dutt: You touched on MFA a little while ago and the report flagged the use of adversary-in-the-middle attacks. AiTM attacks that let threat actors hijack authenticated sessions, even when the MFA is there. So I guess what’s the message to MSPs who are thinking, “All right, if we just get MFA everywhere, we’re good, we’re covered.” Wil Santiago: Token protection, right? MFA is great. You have to have it. But understand that there’s flaws in the way that MFA communicates to servers. And so the whole way that an adversary-in-the-middle attack works is by abusing OAuth. And OAuth is a standard protocol of just making sure that we understand how systems should communicate for authentication. And what’s really nice about that is we can take that offensive research and then make defensive practices towards that. And so token protection is really huge there. There are a lot of built-in protections in Microsoft that allow you to invalidate session tokens after a certain period of time. Every hour you could refresh these tokens. You now, again, when you get to this resilient engineering, you start to push the adversary to be a little bit more aggressive. And that’s your detection mechanism. When you allow an adversary to move unfettered throughout a network, they’re going to move unfettered throughout a network. But the moment that you give them that sort of, “Eh, stop here. Let me see your ID.” Then they start to get a little uneasy. They’re like, “Wait a second. I don’t know how to move anymore.” And so specifically in MFA, when we talk about session hijacking and session tokens, the token protection aspect is really important because that’s a conditional access policy that you can implement. And most people do not implement those conditional access policies. Now, there’s a slew of them that work in conjunction with each other. But the idea here is your tokens will likely be compromised at some point. If you are duped into clicking one of these phishing links, it’s very easy to steal a session token. So we have to move past that. Now that we know that’s going to happen, how do we prevent the adversary from actually using those session tokens successfully? And that’s where invalidating the sessions comes in, having the session protection, conditional access policies, protected devices, things of that sort. That prevents them from being able to use those session tokens. Robert Dutt: A stat that I keep looking at in the report was that you guys managed to disrupt in the SOC 55, 56 percent of incidents before a payload was deployed. It’s a real number. That’s pretty significant. I guess what is disrupted before the payload hits mean operationally? And what does it tell us about where the detection opportunity actually lives? Because it sounds like the window isn’t did malware execute? It’s something a lot earlier. Wil Santiago: That’s exactly right. When we look at the cyber kill chain, we want to start pushing our adversaries as far left of boom as possible. Right. And so when you hear about this whole right of boom concept, basically, you’ve met your match. And now boom, you’ve now been impacted. Right. And so there’s a lot of indicators of compromise that we can start to hone in on. That will give us an understanding of whether this is legitimate or illegitimate. Right before an adversary even types the command. And again, that’s the context. And the context is what the SOC is really understanding of a customer. Where do they operate? What are their hours of operation? Where are they globally distributed? What’s the infrastructure they use? What are the tools they use? How did they use those tools? Did they deploy tools every Thursday at 2 p.m.? So there’s this constant checklist that they’re doing every single day to understand this. And so when we talk about living off the land, threat actors are trying to execute commands. Right. They’re just trying to sit there. We’re typing on a keyboard command line. Hey, I’m not going to introduce any new factors to my intrusion. I’m just going to live off the land. Ultimately, they want to deploy a payload at the end of all of that. But if they deploy a payload too early in their kill chain, they risk getting caught. Right. And so what they’ll do is they’ll stage everything. They’ll compromise an endpoint. They’ll add a persistent backdoor user. They’ll deploy some small scripts to enumerate the network. Just to get an understanding of what’s happening. But they’ll usually stage those in like a C:UsersMusic folder. And that’s their staging environment. So you can catch them. And we’ve caught at Blackpoint a number of threat actors where their toolkits are still on the machine because we caught them so early left of boom that legitimately all they did was log into a machine, try to mount a share, but it failed. And then that failed share mount is like, wait a second. They have never tried to mount a share on this file server ever. And then you call the MSP and they’re like, yeah, Monday through Friday, our hours are from eight to three and it’s seven p.m. at Thursday. Right. Well, now the context of the intrusion starts to become a little bit more apparent. And so we have to do this very quickly. The reality is for us, behavioral context, it matters more than ever. That is the true bread and butter for stopping threat adversaries is understanding the behaviors in the context of which they employ to compromise the network or compromise an endpoint. And so we focus a lot of our threat intelligence and our adversarial intrusion analysis based off of what hack or tradecraft is. We always say this internally, you cannot protect what you don’t know how to hack. So we spend a lot of our time recreating these attacks, understanding where do we catch them? And one of the things that we found is in those early development cycles of understanding the behaviors of an adversary, we found key indicators of like, wait, that is a very high fidelity indicator that before an adversary even gets on a keyboard, we’ve already caught them. They don’t know that yet. Right. And so that’s a little bit of our secret sauce there. But the reality is that secret sauce was created because we thought like threat actors and we sort of recreated what they did in controlled environments and testing environments to then to make sure the detection and the efficacy of what they’re doing is caught within our product. Robert Dutt: So this is a bit of a sidebar, but it was a new term, at least to me. You flagged Etherhiding in the report, attackers embedding malicious logic and blockchain smart contracts to manage compromised sites. Can you walk me through that real quick? And how real is this in terms of how widely it’s being deployed today? And why does it matter for detection purposes? Wil Santiago: It’s a newer term. You know, I would like to say that we have way too many terms in security and security, you know, sort of like we’re trying to be cool. The reality is this is a technique that leverages transactions on a public blockchain to basically retrieve malicious payloads. Right. And so this is another sort of trend that an adversary is using where they’re just retrieving a payload from something that is trusted. In this case, cryptocurrency. A lot of people trust cryptocurrency. A lot of people trust public blockchains. And so the idea here is that, you know, threat actors are usually going to utilize some type of social engineering and then that social engineering is going to get you to come to like a WordPress site through that WordPress site. They’re going to basically have scripts that you’re going to download and ultimately run. Innocuously. Now, when that happens, you download something that you think is OBS, like the example I gave earlier, it’s actually a JavaScript payload. Well, that JavaScript payload goes and reaches out and it pulls a malicious payload from the ether blockchain. Right. And so that’s that aspect of there’s function calls that we’ve identified within Blackpoint that are related to that remote management of pulling payloads from that blockchain. My personal opinion of this sort of technique is, you know, it gives a lot of advantage to the threat actors in terms of stealth and flexibility. But it is one of those techniques that is complicated for majority of what we see at Blackpoint. Most threat actors are not getting to that complicated level of compromising. They’re just hosting malware on a compromised WordPress site of a legitimate company that they’ve co-opted the passwords for. Right. And again, we see threat actors from different angles. 90 percent of what we see sort of today is cybercrime related. Right. So you have a lot of the fake CAPTCHA, the ClickFix lures, the Etherhiding stuff. The reality is at the end of that payload, we see everything from Etherhiding to Cobalt Strike to ransomware and compromise. The way that they get to that sort of compromise is kind of the same, though. Robert Dutt: Last one for me, if an MSP is listening to this and they’ve just absorbed that, you know, more than half of the attacks they’re going to see start with legitimate credentials, their own tools are showing up in about a third of incidents. MFA isn’t necessarily a guarantee. Where do you start? You know, what’s the one thing they probably aren’t doing today that would meaningfully move the needle for them in terms of making sure things are as locked down, as protected as is possible? Wil Santiago: That’s a great question. I like to say we should probably be spending most of our time right now really focusing on posture and posture management, reducing the attack surface. Right. How do you how do you start? Where do you start reducing the attack surface? This is where frameworks really come into play. And there’s some really great frameworks that are really prescriptive out there. One of them is the Center for Internet Security Controls, CIS version 8.1. It’s very prescriptive and it starts from the very top, right? External facing assets and applications. How do you lock those down? Cloud assets and applications, internal assets, user accounts, passwords, right? And it gives you a prescriptive way to deal with incidents. Beyond that, there’s kind of this like practical implementation groups that they have, right? And so you can start by implementing the CIS Controls with implementing one Implementation Group, right? You don’t have to implement them all. And so I think there’s a subset of Implementation Groups that can be used, but it’s about identifying, you know, what of these sort of subset groups will really resonate with your organization and your maturity level, right? And so I tell most people, look at IG1, start with the essentials. If you’ve already fit the bill on that, then move to IG2, right? But the reality is IG1 is going to give you that foundational security for organizations. And then IG2 and IG3 are going to be a little bit more advanced for more complex things. Most people are probably in that IG1, but they probably could benefit from some of the things in the IG2, the Implementation Groups there. That’s really going to help you really target your defenses against ransomware. That’s going to help you sort of approach a risk-based approach. That’s another thing that, you know, all risk is not the same, right? Risk is treated differently. And it’s important for anyone running a security team to help understand how should I prioritize my risk, right? Where is my risk going to really give me issues if a threat actor gets into it? And therefore, I always say, start there. We all know what keeps us up at night. So that’s the areas that we need to focus on. Robert Dutt: All right. Some sage advice and some sobering numbers as well. I appreciate your taking the time and walking us through some good stuff. Wil Santiago: Thank you, Robert. I really appreciate it. Robert Dutt: There you have it. Wil Santiago from Blackpoint Cyber. I’d like to thank Wil for his time today and for bringing some real energy to what can sometimes be pretty dense subject matter. And of course, I’d like to thank you for listening. The data in this conversation is worth thinking about. More than half of the attacks Blackpoint’s SOC starts with someone simply logging in, using credentials that were stolen sometimes long ago, and that users are still reusing across platforms. A third of triaged incidents involve RMM tools, the same tools your techs are using right now to manage endpoints. And MFA, as much as we’ve come to rely on it, is no longer the finish line it once appeared to be. The antidote Wil describes is behavioral context, understanding what normal looks like in an environment so you can spot when something legitimate is being done illegitimately. Not “Is this malware?” But “Is this person, using this tool at this hour from this location, doing something they’ve never done before?” That’s a fundamentally different way about thinking of detection, and it’s why the human element in the SOC still matters. And I’ll add one thing that Wil mentioned after we wrapped the recording. It’s a dimension of this fight that doesn’t get talked about often enough. Blackpoint’s work doesn’t stop at detection and response. They’re actively working to identify and disrupt adversary infrastructure, notifying law enforcement, including, he noted, Canadian authorities, with the specific goal of making cybercrime economically painful. The logic is straightforward. If your infrastructure gets taken down every time you try to run a campaign, the math of operating a criminal enterprise starts to change. That’s offense, and it sounds like they’re playing it. If you’re finding the show valuable, I’d encourage you to follow or subscribe to the podcast. You can find us on Apple Podcasts, Spotify, YouTube, all the major directories. A rating review always helps. Until next time, I’m Robert Dutt for ChannelBuzz.ca, and I’ll see you in the channel.
On this week's show Patrick Gray and James Wilson are joined by guest co-host Brad Arkin to talk through the week's news, including: The AI-agent-hacks-stuff saga continues. This week we have one booting gymgoers from full classes to nab its owner a spot Somehow OpenAI's legal team allowed the company to spill all the Hugging Face tea at BlackHat and it's hot and delicious More details emerge about Iran's hacking campaign against US water utilities, but Brad is unimpressed It turns out TeamPCP has been around longer than we thought and predates the AI era Some absolute plonker kept the DEFCON party going on a Delta flight home. No word yet on if they made the plane fly sideways Much, much more This week's show is brought to you by cloud security platform Prowler. Founder and CEO Toni de la Fuente chats about what the company is doing with AI and some of the cool ways customers are using it with Prowler. This episode is also available on YouTube Show notes How a simple request for AI to book a gym class exposed a major threat | Social Signals OK, Well, There Are Even More AI Agent Hacking Incidents | wired.com OpenAI BlackHat talk re Hugging Face incident | OpenAI says Daybreak will expand to offer specialized cyber services | CyberScoop Cyberattacks targeting water systems expand to 12 states as South Dakota, Georgia announce incidents | therecord.media Cyberattack on North Carolina Ports ‘contained' as Coast Guard, state officials investigate | therecord.media Local governments in four states dealing with cyberattacks that have shut down services | The Record Follow-Up Report of the December 2025 Energy Sector Incident | CERT Polska Chinese telcos maintain deep US presence despite Salt Typhoon links, House committee says | The Record State Department says Trump raised cyber scam compound issue with Xi | therecord.media Open-source software's archenemy TeamPCP goes back further than anyone thought | CyberScoop A Security Pro Hacked North Korean Hackers. He Found They'd Breached Hundreds of Networks Worldwide | wired.com Srsly Risky Biz: Being a North Korean Hacker Is About to Be Less Fun - Risky Business Media | Chrome adopts what may be the best protection yet against account takeovers | Ars Technica CSS:the bomb inside your inbox | PortSwigger Research Security update available for Metabase - Please upgrade now | Social Signals Canadian man pleads guilty to Snowflake hacks that led to 165 breaches | therecord.media British ‘Com' member who abused more than 100 girls worldwide jailed for two years | therecord.media FBI says cybercriminals are hacking into victims' online accounts to steal their intimate pictures | TechCrunch Security AI is getting better at election facts, but voters shouldn't rely on it | CyberScoop The FTC wants to regulate AI for ideological bias | cyberscoop.com US and South Korea warn of Gunra ransomware targeting govt agencies | BleepingComputer CISA: Microsoft SharePoint flaw now exploited in ransomware attacks | BleepingComputer CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs | BleepingComputer N-able N-central exploitation results in RMM tool deployment | Sophos Delta investigating after someone set up fake Wi-Fi network mid-flight | TechCrunch Security mcp-dashboard-demo/prompt/prowler_dashboard_prompt.md at main · prowler-cloud/mcp-dashboard-demo | GitHub
Two pen testers have spent thousands of hours inside client networks, and the most common failure they see isn't a missing security product — it's an EDR nobody ever tuned.In this episode, Spencer and Tyler open up the CrowdStrike Falcon console and walk through the specific settings that decide whether your team catches an attack or never sees it. They start with the story that kicked the whole thing off: Tyler running a pen test where every AMSI bypass gets blocked and detections fire left and right, while Spencer runs nearly identical tooling against the same product at another client and the SOC sees nothing all week. Same CrowdStrike. Same version. Different checkboxes.From there it's a tactical walkthrough of Endpoint Security → Prevention Policies and the settings worth your attention: Enhanced Exploitation Visibility, which unlocks command-line and PowerShell telemetry that Microsoft disables by default; Enhanced DLL Load Visibility for side-loading attacks; WSL2 Visibility, which closes a sandbox threat actors have been using to run Kali tooling under the radar; memory scanning for in-memory C# tradecraft; Office malicious macro removal; file system containment for ransomware over SMB; vulnerable driver protection, the direct mitigation for BYOVD attacks and EDR killers; and cloud-based anomalous process execution for living-off-the-land binaries.They also cover custom IOA rule groups for blocking unauthorized RMM tools, centralized firewall policy management, device policies for USB control, and a warning on exclusions — especially wildcard paths, which Tyler calls a threat actor's best dream.The takeaway is simple: you're paying real money for EDR, and default configurations aren't giving you what you paid for. Open your console, work through the settings, test them against an IT pilot group, and enable what fits your environment.TOPICS COVERED- Why EDR vendors ship deficient defaults on purpose- Enhanced Exploitation Visibility and the telemetry gap in PowerShell attacks- DLL side-loading, WSL2 abuse, and vulnerable driver attacks- Memory scanning and in-memory tooling detection- Blocking RMM tools with custom IOA rule groups- Exclusion hygiene and the wildcard path problem- Device policies, USB blocking, and insider threatSentinel One and Defender for Endpoint are next — let us know what else you want covered.Blog: https://offsec.blogWork with us on an internal pen test: https://securit360.comBlog: https://offsec.blog/Youtube: https://www.youtube.com/@cyberthreatpovTwitter: https://x.com/cyberthreatpovFollow Spencer on social ⬇Spencer's Links: https://spenceralessi.comWork with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.
Today’s headline news for Canadian IT solution providers: TD SYNNEX appoints Chris Fabes as President of Canada: TD SYNNEX announced today that Chris Fabes has been appointed President of Canada, with responsibility for driving the company’s distribution strategy and accelerating customer growth across the Canadian market. Fabes brings more than two decades of IT channel leadership, most recently from SHI where he led a multi-year strategic growth initiative across Canada, and previously from Lenovo where he served as Canadian channel chief and helped triple channel revenue to more than $1.2 billion. He succeeds Mitchell Martin, who retired earlier this year after more than 36 years with the company. Huntress warns of massive Azure CLI password spray attacks: A new Huntress report published Monday warns that threat actors have been running massive password spray attacks against Microsoft Azure Command Line Interface accounts, making more than 81 million attempts between June 12 and June 26, 2026. According to Huntress, attackers are exploiting a loophole in Azure CLI that does not support multifactor authentication, allowing them to target service accounts and non-human identities that are often poorly monitored. Huntress has reported the issue to Microsoft. MSSPs face employee retention problem driven by invisible work, says Guardz: MSSPs are facing a significant employee retention challenge driven by what the report calls “invisible work” – security analysts spending hours on manual data correlation and reporting that customers never see. Guardz, in announcing a new agentic reporting capability, said the problem is burning out analysts who feel their work lacks visible impact. The new tool uses an AI agent to automatically turn blocked threats and client risk data into formatted reports that MSPs can present to SMB customers. ManageEngine launches developer marketplace: ManageEngine has launched a developer marketplace for integrations, extensions, and AI agents across its IT management platforms. The marketplace is designed to allow partner-developers, independent software vendors, and customers to build and distribute add-ons. GAM Tech ranks No. 97 on 2026 MSP 501, No. 1 in Western Canada: GAM Tech has climbed to No. 97 globally on the 2026 MSP 501 and ranks No. 1 in Western Canada, according to the company. The MSP 501 list recognizes managed service providers based on metrics including recurring revenue, profit margin, and operational efficiency. Read Full Transcript Welcome to The Buzz from ChannelBuzz.ca, I’m Robert Dutt, today is Tuesday, July 21, 2026, and here’s what’s happening in the channel today. TD SYNNEX has appointed Chris Fabes as President of Canada, filling the role left by Mitchell Martin who retired earlier this year after more than thirty-six years with the company. In a statement, TD SYNNEX said Fabes brings more than two decades of IT channel leadership across vendor, distributor, and customer perspectives. He most recently led a multi-year strategic growth initiative at SHI across Canada, and before that served as Canadian channel chief at Lenovo, where he helped triple channel revenue to more than one point two billion dollars in three years. TD SYNNEX North America president Reyna Thompson said Fabes’ end-to-end understanding of the Canadian technology market makes him well positioned to lead the Canada business into its next chapter. The appointment comes at a time when TD SYNNEX has been expanding its vendor relationships in Canada, including recent global distribution deals with Fortinet and HPE. Canadian partners will be watching how Fabes shapes the distributor’s local strategy, particularly around AI, cybersecurity, and cloud marketplace growth. A new Huntress report published Monday warns that threat actors have been running massive password spray attacks against Microsoft Azure Command Line Interface accounts, making more than eighty-one million attempts between June 12 and June 26, 2026. According to Huntress, attackers are exploiting a loophole in Azure CLI that does not support multifactor authentication, allowing them to target service accounts and non-human identities that are often poorly monitored. The company said most affected accounts were from large enterprises with complex cloud footprints, and that MSPs managing customer Azure environments are particularly exposed because these CLI accounts often fall outside normal identity monitoring workflows. Huntress has reported the issue to Microsoft. The research underscores a growing tension in identity security: as organizations lock down human-facing accounts with MFA, attackers are shifting to non-human identities and service accounts that lack the same protections. Canadian MSPs with hybrid Azure and Microsoft 365 clients should be reviewing whether their RMM and identity tools are catching CLI-level authentication anomalies. MSSPs are facing a significant employee retention challenge, but salary is not the primary driver. According to a ChannelE2E feature published today, the main issue is what the report calls “invisible work” – security analysts spending hours on manual data correlation, reporting, and threat context that customers never see. Guardz, in announcing a new agentic reporting capability, said the problem is burning out analysts who feel their work lacks visible impact. The new tool uses an AI agent to automatically turn blocked threats, security activity, and client risk data into formatted reports that MSPs can present to SMB customers. Guardz is positioning the feature as a way to reduce the manual reporting burden while simultaneously demonstrating security value to clients. For Canadian MSPs, the issue is worth noting because talent retention in security operations is already tight, and any tool that reduces invisible overhead while improving client communication is likely to get attention from understaffed SOC teams. In Brief – ManageEngine launches a developer marketplace for integrations, extensions, and AI agents. GAM Tech ranks number ninety-seven globally on the two thousand twenty-six MSP five hundred one and number one in Western Canada. Later today on In The Channel, my conversation with Mark Sutor of Access Group and the Trust X Alliance on the Global Leadership Summit, the TXA AI agent, and the idea of distributor-as-platform is available now. That’s how we’re seeing the headlines today. I’m Robert Dutt for ChannelBuzz.ca, thanks for listening. Have a great day.
Today’s headline news for Canadian IT solution providers: OpenAI Partner Network: OpenAI‘s inaugural Partner Network is officially live as of July 15, with vice president of strategic global partnerships Colleen Kapase confirming the three-tier program is backed by $150 million in channel investment. Partners can progress through Select, Advanced, and Elite tiers while earning specializations in areas like Codex, cybersecurity, and AI agents. OpenAI says it aims to train 300,000 certified consultants by year-end and is recruiting solution providers of all sizes that can put AI systems into production. OpenAI Carbon60 MSP 501: Carbon60, a Toronto-based managed cloud services provider, has been named to the 2026 MSP 501 at position 206, ranking among the world’s top managed services firms by revenue and operational discipline. The company has built a differentiated practice around Canada-first sovereign cloud and Azure expertise, and the ranking follows a broader push by Canadian MSPs to demonstrate global competitiveness in compliance-heavy verticals. Carbon60 RecordPoint channel-first: RecordPoint has launched a global partner program that CRN describes as a channel-first move, enabling resellers, consultancies, and systems integrators to resell, co-sell, and refer its data and AI governance platform. Partners will receive enablement, joint sales support, and platform access to build practices around data retention, compliance, and AI-ready data classification. Channel Insider Blackpoint Cyber 2026 threat report: Blackpoint Cyber has released its 2026 Annual Threat Report, finding that attackers are increasingly exploiting trusted IT tools rather than using perimeter breaches. The report highlights abuse of remote monitoring and management platforms, VPNs, and identity credentials as primary vectors. ChannelPro Network Managed security market growth: Acronis and Omdia project the global managed security market will grow from $93 billion in 2025 to $106 billion in 2026, a 14.4 percent increase. The growth reflects sustained demand for outsourced security operations among mid-market organizations that lack internal SOC capacity. RAMageddon pressures PC refresh: Industry analysts and OEMs continue to signal significant PC RAM price increases through 2026 due to the ongoing memory supply shortage. Channel partners should advise clients on refresh timing and alternative configurations to manage budget impact. CNET Exabeam MSSP licensing: Exabeam has expanded its APEX partner program with pooled and federated licensing options designed specifically for MSSPs. The new framework is intended to reduce onboarding friction and simplify compliance across multi-tenant security operations centers. Security Brief Read Full Transcript Welcome to The Buzz from ChannelBuzz.ca, I’m Robert Dutt, today is Thursday, July 16, and here’s what’s happening in the channel today. OpenAI’s inaugural Partner Network is officially live as of yesterday, July 15, with the company backing the three-tier program with $150 million in channel investment. Vice president of strategic global partnerships Colleen Kapase confirmed the program is open to solution providers of all sizes, not just global systems integrators. Partners can progress through Select, Advanced, and Elite tiers based on sales performance, technical capability, and deployment experience. The program includes specializations in Codex, cybersecurity, and AI agents. OpenAI says it aims to train 300,000 certified consultants by the end of 2026, and is actively recruiting solution providers that can put AI systems into production. Philip Larson, senior director of the OpenAI Partner Network and a former Google Cloud channel leader, said the program is designed to reward partners for the value they create with customers. Canadian VARs and MSPs with existing AI practices should evaluate the program alongside their current AWS, Google, and Microsoft partnerships, as the specializations in Codex and AI agents may create differentiation in automation-heavy verticals. Carbon60, a Toronto-based managed cloud services provider, has been named to the 2026 MSP 501 at position 206, marking the company as one of the world’s top managed services firms by revenue and operational discipline. The ranking, published by Channel Futures, evaluates financial health, operational maturity, and recurring revenue growth. Carbon60’s inclusion follows a broader trend of Canadian MSPs demonstrating global competitiveness in specialized infrastructure and compliance-heavy verticals. The company has built a differentiated practice around Canada-first sovereign cloud and deep Azure expertise. As Canadian public sector and healthcare clients face stricter data residency requirements, sovereign cloud capabilities are becoming a key differentiator for domestic MSPs seeking to compete with larger global firms on government and enterprise contracts. RecordPoint has gone channel-first with the launch of a global partner program enabling resellers, consultancies, and systems integrators to resell, co-sell, and refer its data and AI governance platform. The program arrives as AI adoption drives a surge in demand for data governance across regulated industries. RecordPoint says partners will receive enablement, joint sales support, and platform access to build practices around data retention, compliance, and AI-ready data classification. CRN reports that the move represents a strategic shift for the company. Canadian partners serving regulated industries like finance, government, and healthcare may find particular opportunity as clients confront unstructured data sprawl ahead of AI deployments. In Brief – OpenAI commits $150 million to launch its inaugural Partner Network with tiered AI specializations. Acronis and Omdia project the managed security market will reach $106 billion in 2026. Blackpoint Cyber’s 2026 Annual Threat Report highlights attackers hiding inside trusted IT tools and RMM platforms. RAMageddon memory shortages continue to pressure PC pricing and enterprise refresh cycles. Exabeam adds pooled and federated licensing options to its APEX partner program for MSSPs. Full details and links in the show notes or the blog post. Later today on In The Channel, we’re talking specialist distribution in Canada with Carrie Hopkins of Exclusive Networks. We get into the Ignition program, what broadliners can’t deliver, and why the model might feel familiar to channel veterans. And if you haven’t heard it yet, yesterday we wrapped our HPE Discover 2026 arc with HPE vice president of North America channels Jeremiah Jenson. He talks about the quote-cycle win, the Canadian angle on data sovereignty, and what partners should stop doing. That’s how we’re seeing the headlines today. I’m Robert Dutt for ChannelBuzz.ca, thanks for listening. Have a great day.
In this episode of The IT Experts Podcast, I hosted an MSP Insights Roundtable on AI, automation, and observability at scale, bringing together three brilliant guests, Joe Burns, Fiona Challis, and Nick Horner. What struck me straight away was how all three agreed on one thing before we even got into the detail. AI, automation, and observability only work when you understand your own processes first. Joe walked us through how his MSP, Reformed, built its operational maturity by identifying repetitive tasks, spotting where human error crept in, and asking his team what they actually disliked doing. Only once that groundwork was done did he bring in automation, including an early AI triage system on the service desk, and it paid off. Nick added a perspective I loved, describing how starting small with clients avoids the scope creep that can derail an automation project before it even gets going. He shared a story about a modest HR automation that grew organically once the client saw the value for themselves, and how bringing end users into the process from day one builds the kind of trust that makes AI, automation, and observability actually stick. Getting genuine buy in, as Nick put it, turns a nervous stakeholder into a project sponsor rather than a blocker. Fiona introduced an idea I keep coming back to, becoming your own customer zero, assessing your own readiness before you ever take an AI conversation to a client. She told us most MSPs score only two or three out of five on her readiness assessment, which shows how much foundational work is still undocumented across our sector. We spent time discussing how observability has changed, moving away from juggling dashboards across Microsoft 365, PSA, and RMM tools towards a single intelligent layer that pulls everything together securely and quickly. Nick made the point that speed and accuracy no longer need a dedicated Power BI specialist, and Fiona reminded us that the ROI conversation always starts with measuring a baseline before you change anything. One of my favourite moments came from Joe, describing a law firm that spent three to four hours every week cross checking court lists against their case management system, a task his team solved with an agent in fifteen minutes. Fiona echoed this, encouraging MSPs to lead with one practical win rather than an overwhelming pitch, because solving a single small problem tends to open the door to many more conversations. We also got into the tension between compliance and outcome. Fiona argued that clients buy the outcome AI delivers rather than the technology itself, and Joe pushed back with honest feedback from his law firm clients, who want compliance answered first given how sensitive that sector is to reputational risk. Both agreed that governance needs to be built into the foundations of any deployment rather than bolted on afterwards. Drawing on Daniel Priestley's thinking around demand and supply tension, Joe warned us against pouring all our energy into operational capacity while neglecting sales and marketing, a gap that can quietly erode margins even as efficiency improves. Fiona picked this up with real enthusiasm, describing how AI and automation can make selling feel far more natural, framing every client conversation as a business problem to solve rather than a service to pitch. She introduced the three pillars she coaches MSPs towards, capacity, experience, and revenue, and stressed the importance of owning your intellectual property rather than giving away your hard built agents for free. We closed by sharing how each of us measures success, from outcome-based tracking to client and employee satisfaction scores, before final takeaways. Nick urged everyone to embrace the shift and stay ahead of the curve, Joe reminded us that capacity means nothing without the ability to sell it, and Fiona encouraged listeners to stop overthinking and take the first step. I came away from this session convinced, more than ever, that AI, automation, and observability can genuinely transform an MSP, provided the fundamentals are respected along the way. Connect with Fiona Challis through LinkedIn and website. Connect with Joe Burns through LinkedIn and website. Connect with Nick Horner through LinkedIn. Make sure to check out our Ultimate MSP Growth Guide, a free guide that walks you through a proven process to take your MSP from stuck to scalable, without working even more hours. It's 44 pages rammed with advice, insights and inspiration to help you decide what support is available to you now if you want to grow and scale your business. Click HERE to get your copy. Connect on LinkedIn HERE with Ian and also with Stuart by clicking this LINK And when you're ready to take the next step in growing your MSP, come and take the Scale with Confidence MSP Mastery Quiz. In just three minutes, you'll get a 360-degree scan of your MSP and identify the one or two tactics that could help you find more time, engage & align your people and generate more leads. If you're serious about growth and want to explore what this could look like for your MSP, you can book a Right Fit Clarity Call with us HERE. OR To join our amazing Facebook Group of over 400 MSPs where we are helping you Scale Up with Confidence, then click HERE Until next time, look after yourself and I'll catch up with you soon!
EPISODE SNAPSHOT Welcome to The Bryan Air Podcast. Career intelligence for pilots. We break down executive moves, economic forces, and the technology reshaping how pilots are trained, assessed, and employed. Boardroom decisions land on your flight deck. We translate them first. No corporate spin. Just the intelligence pilots actually need. Last week thousands of you weighed in on South Africa's new SARS traveler declaration. This week Ryan actually ran it, live, on a charter through Vic Falls, and his verdict might surprise you. Then the bigger story: between now and March 2027, borders on three continents are switching to facial recognition, and crews are first in line to hand over their faces. Add Airbus's new forecast calling for 42,060 new aircraft by 2045, and the question becomes simple. Is your career ready for the world that's coming? In this episode of The Bryan Air Podcast, Bryan Roseveare and Ryan Parrock analyse the SARS traveler declaration, facial recognition and biometric borders, the global pilot shortage, and the Airbus 20-year forecast. TIME-STAMPED FLIGHT PLAN 00:00 Podcast intro and this week's flight plan 00:55 Ryan runs the SARS declaration app on a real charter to Vic Falls 03:34 Another barrier to entry? The travel declaration debate continues 06:27 Back in the cockpit after six years: Ryan returns to commercial flying 08:33 Flying the flight a week early: the mental prep charter work demands 12:08 Airbus calls for 42,060 new aircraft by 2045 and the pilot shortage is real 16:38 Your face becomes your passport: biometric borders rise on three continents 20:50 EasyJet's 7.26 billion takeover bid and Embraer's best quarter in 16 years 22:45 A Ukrainian pilot's story and what the media doesn't show you 26:48 Silverstone delivers a cracker and it's good to be back in studio 28:08 Closing, a beer owed, and Sunday's SAA fuel-gate TV teaser JOIN THE BRYAN AIR COMMUNITY Bryan Air is a career intelligence ecosystem for pilots. Sign up free to receive our weekly newsletter covering the disruption of AI in aviation, career strategy, and the analysis that does not make it into the episodes. Sign Up Free → https://bryanairpodcast.com/ FREE PILOT CAREER ASSESSMENT Where are you in your career? The Flight Plan is our free, AI-powered career intelligence tool. Answer 8 questions about your situation and get a personalised strategic assessment with specific moves tailored to where you are right now. Take the Free Assessment → https://pilotcareerintelligence.netlify.app/ RISK MANAGEMENT & DECISION MAKING SIMULATOR Practise structured decision-making using live flights. Our AI-powered simulator lets you work through RMM and T-DODAR frameworks on real Flightradar24 data, with AI-generated scenarios and personalised debriefs. Built by Bryan Roseveare for pilots who want to sharpen the skills that matter most when things go wrong. Early bird: $29 one-time. Lifetime access. Try the Simulator → https://bryanair.tools/ LINKS Bryan Air — Career Intelligence for Pilots → https://bryanairpodcast.com/ Free Pilot Career Assessment → https://pilotcareerintelligence.netlify.app/ Risk Management & Decision Making Simulator → https://bryanair.tools/ Bryan Roseveare → https://www.bryanroseveare.com/ Watch on YouTube → https://www.youtube.com/@BryanAirPodcast Support on Patreon → https://www.patreon.com/bryanair #AviationPodcast #BryanAir #PilotLife #FacialRecognition #PilotShortage
EPISODE SNAPSHOT Welcome to The Bryan Air Podcast. Career intelligence for pilots. We break down executive moves, economic forces, and the technology reshaping how pilots are trained, assessed, and employed. Boardroom decisions land on your flight deck. We translate them first. No corporate spin. Just the intelligence pilots actually need. From 1 July, every traveler in and out of South Africa must file an online SARS declaration inside a 24-hour window before departure. Children included, and multi-stop itineraries make the timing even messier. With visas already strangling inbound business travel, Bryan asks the question nobody in government seems to be asking: why add another barrier at the border? Then IATA's May numbers show the world flying less for a second straight month while African carriers grow fastest with the emptiest cabins, and Emirates launches a geo-targeted recruitment drive aimed squarely at South African pilots. Necessary admin or self-inflicted damage? You decide. In this solo episode of The Bryan Air Podcast, Bryan Roseveare breaks down South Africa's new SARS travel declaration, IATA's May air traffic results, and aviation careers opening up at Emirates, Riyadh Air, and Air Europa. TIME-STAMPED FLIGHT PLAN 00:00 This week's headlines: SARS declarations and IATA's May numbers 00:56 South Africa's new SARS travel declaration explained 01:24 Why one more barrier to travel is the wrong move right now 04:35 Inside the form: the 24-hour window, multi-stop catches, and kids 07:45 IATA May traffic: global demand down 2.2%, Africa fastest-growing at 6.6% 11:32 Pilot hiring signals: the recovery is starting to show 14:00 Emirates: 56 weekly SA flights and a targeted hunt for South African pilots 17:14 Air Europa lands in Joburg and Riyadh Air opens three new routes 20:04 Air Peace takes its first E175 and why Nigeria matters to African aviation 21:22 Wrap up plus a new All-Weather Operations Simulator coming next week JOIN THE BRYAN AIR COMMUNITY Bryan Air is a career intelligence ecosystem for pilots. Sign up free to receive our weekly newsletter covering the disruption of AI in aviation, career strategy, and the analysis that does not make it into the episodes. Sign Up Free → https://bryanairpodcast.com/ FREE PILOT CAREER ASSESSMENT Where are you in your career? The Flight Plan is our free, AI-powered career intelligence tool. Answer 8 questions about your situation and get a personalised strategic assessment with specific moves tailored to where you are right now. Take the Free Assessment → https://pilotcareerintelligence.netlify.app/ RISK MANAGEMENT & DECISION MAKING SIMULATOR Practise structured decision-making using live flights. Our AI-powered simulator lets you work through RMM and T-DODAR frameworks on real Flightradar24 data, with AI-generated scenarios and personalised debriefs. Built by Bryan Roseveare for pilots who want to sharpen the skills that matter most when things go wrong. Early bird: $29 one-time. Lifetime access. Try the Simulator → https://bryanair.tools/ LINKS Bryan Air — Career Intelligence for Pilots → https://bryanairpodcast.com/ Free Pilot Career Assessment → https://pilotcareerintelligence.netlify.app/ Risk Management & Decision Making Simulator → https://bryanair.tools/ Bryan Roseveare → https://www.bryanroseveare.com/ Watch on YouTube → https://www.youtube.com/@BryanAirPodcast Support on Patreon → https://www.patreon.com/bryanair #AviationPodcast #BryanAir #PilotLife #SouthAfrica #Emirates
⭐ FEATURED: INTERACTIVE WORLD CUP TRAVEL TRACKER We built a live dashboard so you can see exactly how far every team is flying between base camp and match city. Compare Curacao's punishing 6,284 miles against Mexico's easy 625, and find out which teams the draw quietly handed the hardest road. Explore the Tracker → https://bapworldcuptracker.netlify.app/ EPISODE SNAPSHOT Welcome to The Bryan Air Podcast. Career intelligence for pilots. We break down executive moves, economic forces, and the technology reshaping how pilots are trained, assessed, and employed. Boardroom decisions land on your flight deck. We translate them first. No corporate spin. Just the intelligence pilots actually need. You assume the World Cup stars are living the dream in their own Gulfstreams. They are not. One team is crisscrossing 6,500 miles to chase the trophy while another barely flies 600, and this week one squad took five hours to cover 127 miles. The glamour arrival jets flew straight back out, and what is left is a brutal month of base camp shuttles on Southwest and JetBlue, recovery rooms fitted into charters, and a system running short on the one thing money cannot buy fast: crew and air traffic controllers. We track every mile, expose who got the hardest draw, and explain why the game may finally have outgrown the system that has to fly it. So who is really flying red-eyes before kickoff? In this episode of The Bryan Air Podcast, Bryan Roseveare and Ryan Parrock break down the aviation logistics behind the first three-country World Cup, FIFA's base camp shuttle rule, charter costs and the private jet surge, stadium flight restrictions, and the crew and ATC shortages strangling the system around Newark. TIME-STAMPED FLIGHT PLAN 00:00 One team flies 10x further than another 00:27 Welcome and the Super Brew curse 01:13 The first three-country World Cup, 48 teams, 16 cities 03:27 Arrivals, livery jets and the million-tracker Brazil flight 05:38 FIFA Rule 18.3 and the base camp shuttle 07:17 73,000 private jets expected on final day 10:48 The travel tracker: Curacao 6,284 miles vs Mexico 625 15:28 Altitude, heat and doing recovery in the air 18:08 Why crew and ATC are the real bottleneck 23:13 Aviation news: EasyJet, Endeavor, Trump Force One, Ryanair, Qatar 28:41 Iran, oil and the fight for stability 32:04 Wrap up and sign off JOIN THE BRYAN AIR COMMUNITY Bryan Air is a career intelligence ecosystem for pilots. Sign up free to receive our weekly newsletter covering the disruption of AI in aviation, career strategy, and the analysis that does not make it into the episodes. Sign Up Free → https://bryanairpodcast.com/ FREE PILOT CAREER ASSESSMENT Where are you in your career? The Flight Plan is our free, AI-powered career intelligence tool. Answer 8 questions about your situation and get a personalised strategic assessment with specific moves tailored to where you are right now. Take the Free Assessment → https://pilotcareerintelligence.netlify.app/ RISK MANAGEMENT & DECISION MAKING SIMULATOR Practise structured decision-making using live flights. Our AI-powered simulator lets you work through RMM and T-DODAR frameworks on real Flightradar24 data, with AI-generated scenarios and personalised debriefs. Built by Bryan Roseveare for pilots who want to sharpen the skills that matter most when things go wrong. Early bird: $29 one-time. Lifetime access. Try the Simulator → https://bryanair.tools/ LINKS World Cup Travel Tracker Dashboard → https://bapworldcuptracker.netlify.app/ Bryan Air — Career Intelligence for Pilots → https://bryanairpodcast.com/ Free Pilot Career Assessment → https://pilotcareerintelligence.netlify.app/ Risk Management & Decision Making Simulator → https://bryanair.tools/ Bryan Roseveare → https://www.bryanroseveare.com/ Watch on YouTube → https://www.youtube.com/@BryanAirPodcast Support on Patreon → https://www.patreon.com/bryanair #AviationPodcast #BryanAir #PilotLife #WorldCup2026 #PrivateJet
Send us Fan MailIn this special Pax8 Beyond '26 feature of Partnerships Unraveled, we sit down with Gene Kim, Vice President of Managed Service Providers at Absolute Security. With a career spent on both sides of the channel as a service provider and now leading Absolute's MSP motion, Gene brings a grounded view of what MSPs need to deliver real business continuity in an AI-driven world.Gene opens with the story of building Absolute's MSP motion from the ground up. The company has a long enterprise track record, with 40% of the Fortune 500, 80% of the top airlines, and nearly all of the largest state and local governments as customers, and its presence in the MSP community is now being built with the same intent. He walks through how Absolute's technology, embedded in the BIOS and firmware of more than 600 million devices from Dell, Lenovo, HP, and 25 other manufacturers, is already deployed in MSP fleets today. The opportunity is in activating that capability and showing MSPs how it strengthens their service delivery.From there, the conversation moves into where Absolute fits in the AI era and the shift toward managed intelligence providers. As MSPs add automation, orchestration, and chat layers across their stack, every one of those capabilities relies on the underlying tools being up and available. Absolute keeps the RMM, EDR, encryption, and backup tools resilient through automated self-healing, which Gene frames as a foundational layer for any MSP's AI strategy. He also reframes the customer conversation around business continuity, where the question is how quickly the business is back up.Gene closes on what he calls a winning formula for MSPs: pairing prevention with recovery and resilience to build differentiated, outcome-driven service offerings that capture new business and grow customer mind share._________________________Learn more about Channext
A significant regulatory development affecting MSPs was discussed: the US Government ordered the suspension of access to the Fable 5 and Mythos 5 AI models by any foreign national, including those inside and outside the United States, citing national security authorities. As reported in the Anthropic company statement, this directive forced abrupt discontinuation of these AI tools for all customers, regardless of business impact. The decision resulted in the sudden loss of access to custom-built AI applications and business process automation tools that MSPs and their clients had integrated into daily operations. Immediate disruptions included the cessation of SEO and analytics engines, RMM automation, and bespoke backup solutions that relied on the now-restricted AI platforms. Further clarification showed these suspensions are tied to concerns about potential backdoor access, disputed by Anthropic but acted upon due to US Government findings. Additional context revealed Amazon—the largest investor in Anthropic and a direct competitor—alerted federal authorities to the supposed vulnerability. Stock prices of competitive AI offerings in China reportedly rose by 48% following the announcement, indicating market reactivity to perceived US regulatory risks. The episode underscored that AI model dependencies—whether managed internally by MSPs or by third-party vendors—can introduce sudden continuity hazards if access or legal standing is rapidly altered. Adjacent discussions evaluated operational models for MSP service offerings. Contrasting perspectives highlighted the tradeoff between providing a single comprehensive managed services plan, designed for streamlined staff training and high-touch customer experience, versus offering a tiered set of plans (“good, better, best”) that, according to shared data, can result in about 70% higher revenue through client segmentation and option-based sales. The choice was framed as fundamentally cultural, influencing both workforce structure and scalability, with differing risk and complexity profiles for technical delivery and sales management. Key implications for MSPs and IT leaders include the need for explicit risk assessments around reliance on AI platforms and third-party tools. Business continuity planning should contemplate not only technical redundancy but also legal and regulatory exposures to abrupt vendor or governmental action. When building service portfolios, organizations should align plan standardization or diversification with internal capacity, capability for sales-driven growth, and staff training. Establishing clear governance for evaluating the ongoing viability and risk exposure of both internally developed and vendor-supplied technology is critical for operational resilience in an environment of rapid regulatory change. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
The core structural shift highlighted in this episode is the commoditization of AI model platforms and concurrent consolidation at the vendor and platform layer, forcing Managed Service Providers (MSPs) to move their value proposition above reselling models to orchestrating, governing, and verifying AI outputs. The discussion references the rising concentration and valuation of platforms such as NinjaOne—a founder-led, profitable RMM platform with a $12.3 billion valuation and 70% year-over-year growth—and Pax8 building business toolkits that draw more operational functions onto their rails. At the same time, major AI developers like OpenAI are entering the channel more directly by launching partner programs aimed at MSPs and consultants. The most consequential development is the confirmed shift from reselling AI models to managing their outputs and risks. Glean surveyed 6,000 digital workers and found that while AI delivers approximately 11 hours of weekly time savings, nearly 6.4 hours are reclaimed by “bot sitting”—the human intervention required to supply context, verify, and correct AI outputs. This hidden labor raises a risk scenario: two-thirds of workers admit to releasing unchecked AI outputs, and Ivanti found that only 42% of IT environments actually have a named owner for each AI agent, despite 85% claiming so—a 43-point gap in accountability. Asana and Deloitte further reinforce the issue, reporting frequent cost overruns and unmanaged autonomous AI deployments among enterprise and SMB environments. Supporting developments underscore this governance and accountability gap. TechCrunch cited that ChatGPT's AI market share has dropped below 50% as the field becomes more interchangeable and less differentiated by underlying model. Vendors such as Anthropic and OpenAI, recognizing model commoditization, are seeking revenue through high-volume partner channels, blurring the lines between vendor and channel competitor. According to Asana, more than 80% of UK IT leaders encountered unplanned AI costs, and over half reported business harm from autonomous AI actions, shifting operational and liability risks squarely onto MSPs and IT service providers. Operationally, these trends compel MSPs to take explicit ownership of the orchestration and governance layer, rather than relying on tool reselling. The transcript advises mapping every AI-driven decision or output that reaches client endpoints and identifying who verifies these outputs before customer exposure. Failing to address these governance blanks does not avoid work but shifts it to unbilled, post-incident cleanup, often with financial, legal, or compliance consequences. Effective MSPs will need to price, document, and regularly review their verification, orchestration, and risk assumption, positioning these as standalone, billable services to manage risk and maintain margin as AI platforms commoditize and vendor dependencies rise. 00:00 Bigger Platforms, Unwatched AI 03:44 The Vendor Walks Into the Channel 05:56 Govern It or Absorb It 08:52 Why Do We Care? Supported by: ScalePad Sign up for the SMB Online Conference: www.smbonlineconference.com
The episode highlights a structural shift from automation that suggests actions to automation that executes actions autonomously, thereby transferring substantial operational risk and accountability to technology vendors and their AI-driven platforms. This transition is exemplified by Atera's deployment of their autonomous AI agent, Robin, which is positioned to handle a significant proportion of Tier 1 and complex Tier 2 IT tickets for managed service providers (MSPs). The company's commercial strategy, including performance guarantees, signals an increased expectation that AI can assume core IT operational responsibilities that were traditionally reserved for human engineers. Atera has introduced a policy wherein Robin is guaranteed to autonomously close at least 50% of all Tier 1 and complex Tier 2 tickets within 90 days of onboarding, or fees are waived. According to Atera, this commitment is supported by a backend analysis of MSP tickets and live demonstrations using historical data. The company asserts that Robin's mean time to repair is approximately 120 seconds, that onboarding is managed collaboratively, and that the rollout is more akin to hiring and training a human engineer than a standard software deployment. This approach is backed by patent filings and a business model integrating AI as the foundation rather than an add-on. The episode further examines the implications of mandatory AI bundling in Atera's redefined RMM and PSA platform offering. The company has faced pushback from segments of the MSP community dissatisfied with bundled AI services and associated pricing changes, particularly from those wishing to maintain control over their technology stack. Atera responds by describing a re-conceptualization of their platform as inherently AI-driven, distinguishing between “platform AI” and the autonomous Robin agent, and clarifying that preexisting AI users would not incur additional costs. There is also discussion around the impact of automation on human roles and the need for new approaches to training and accountability, particularly for junior staff. For MSPs and IT service providers, these developments signal an increase in infrastructure dependency on vendor-managed AI agents, as well as new layers of contract risk linked to performance guarantees and platform integration. The operational reality described involves a significant reduction in required headcount, a shift in staff responsibilities from routine incident response to higher-order business and security tasks, and the necessity for designated internal management of AI tools. There remain unresolved concerns about skill degradation and the long-term risks of over-automation, including the narrower pathways through which junior personnel may acquire foundational experience. Sponsored by: ScalePad https://scalepad.com/dave/ Nerdio https://nerdio.co/MSP-Radio Sign up for the SMB Online Conference: www.smbonlineconference.com
Automation as Core Strategy: Aarin Bailey on RPA, AI, and Scaling MSP OperationsOn the Evolved Radio podcast, Todd interviews Aarin Bailey, COO at Webit Services and former COO at MSP Bots, about treating automation as a core MSP operating strategy. Aarin describes how his automation focus accelerated around COVID by chaining PowerShell scripts, later expanding into Python, GUIs, and modular systems connected via RESTful APIs, with much of the computation running outside the RMM on servers (including SQL and Python) while the RMM remains mainly a monitoring and job-push layer. They discuss whether RMM is a “zombie product,” the ongoing role of PSA/ticketing as a system of record, and managing complexity through separate modules and staff literacy in Python/RPA. Aarin explains build-vs-buy decisions driven by ROI and fit, cites automated triage/dispatch with ~98% accuracy and shifting token costs, argues AI should augment rather than replace humans, and emphasizes documentation, playbooks, and focusing on operational “bad” anomalies. They also cover client tolerance for AI, limiting client-facing AI after hallucinated ticket notes, skepticism about voice AI, and concerns about AI economics and subsidies.This episode is brought to you by Opsleader Pro. A place for MSP owners and managers to get the systems and tools they need to build a stable and growing MSP. Part group coaching, part peer group, everything you need to run a successful MSP. (00:00) - Automation First Mindset (01:10) - Aaron Origin Story (05:04) - From Scripts to Platforms (05:41) - Beyond the RMM Beehive (08:35) - Is RMM a Zombie (12:14) - Managing Complexity Safely (14:33) - Build vs Buy ROI (19:39) - Token Costs and Pair Coding (23:49) - AI Security Reality Check (27:34) - Scaling with Playbooks (30:12) - Hunt the Bad Stuff (30:59) - Blueprints Before Automation (32:46) - Ticket Volume and Vision (33:32) - Saying No as Integrator (35:44) - Healthy Disagreement Dynamics (37:08) - Client Facing vs Backend AI (40:05) - AI Hallucinations and Guardrails (43:05) - Voice AI and Live Answer (46:06) - Costs and Subsidized AI Era (49:26) - Outcome First and RPA Focus (51:36) - Wrap Up and Thanks
EPISODE SNAPSHOT Welcome to The Bryan Air Podcast. Career intelligence for pilots. We break down executive moves, economic forces, and the technology reshaping how pilots are trained, assessed, and employed. Boardroom decisions land on your flight deck. We translate them first. No corporate spin. Just the intelligence pilots actually need. SAA just made a move that should put every South African pilot on alert. The airline has applied to have pilots, cabin crew, and key operational staff declared an essential service, and if it lands, your constitutional right to strike goes with it. Because the Labour Relations Act regulates the function and not the company, a ruling in SAA's favour would not stop at SAA. It would reach across the whole industry and bind every airline whose crews do the same job. We break down whether the bid actually has legs, why the legal threshold is narrower than SAA hopes, and what it really signals about the pressure building behind the scenes. In this episode of The Bryan Air Podcast, Bryan Roseveare and Ryan Parrock break down SAA's essential services bid and what it means for pilot strike rights, the launch of Riyadh Air, Qatar and Emirates strategy in a disrupted Middle East, a fake Air Canada captain, and the latest South African Airways aviation news. TIME-STAMPED FLIGHT PLAN 00:00 Intro and this week's headlines 00:38 Why we dug the 2010 Bafana shirts out of the cupboard 02:01 A quick favour before we get into it 02:36 SAA moves to declare pilots and cabin crew essential 05:01 Riyadh Air gets airborne: first 787 flights tracked live 07:03 Renewed conflict and what it means for regional airspace 08:56 Qatar, Oneworld, and the Philadelphia to Doha problem 10:13 Why Emirates is flying half-empty first class on purpose 13:31 The Air Canada captain arrested for flying without a licence 15:22 Fatal Gulfstream G200 crash in the Dominican Republic 16:54 Into the crew room: your comments this week 18:00 A Ryanair pilot of 10 years unloads on O'Leary 19:29 The real story on Ryanair crew pay and conditions 21:00 Is O'Leary a genius or a villain? We debate it 22:17 The hard question: so why not just leave? 23:32 Never resign with only one job lined up 24:26 Moving to the Middle East: an insider's honest advice 26:44 The bikes, the toys, and the money lessons we learned late 30:38 Starlink in the cockpit: connectivity versus sanctuary 33:30 Is in-flight WiFi killing the magic of flying? 36:13 Why the airport feels like anxiety, not adventure 38:16 Bafana Bafana and the World Cup sign off JOIN THE BRYAN AIR COMMUNITY Bryan Air is a career intelligence ecosystem for pilots. Sign up free to receive our weekly newsletter covering the disruption of AI in aviation, career strategy, and the analysis that does not make it into the episodes. Sign Up Free → https://bryanairpodcast.com/ FREE PILOT CAREER ASSESSMENT Where are you in your career? The Flight Plan is our free, AI-powered career intelligence tool. Answer 8 questions about your situation and get a personalised strategic assessment with specific moves tailored to where you are right now. Take the Free Assessment → https://pilotcareerintelligence.netlify.app/ RISK MANAGEMENT AND DECISION MAKING SIMULATOR Practise structured decision-making using live flights. Our AI-powered simulator lets you work through RMM and T-DODAR frameworks on real Flightradar24 data, with AI-generated scenarios and personalised debriefs. Built by Bryan Roseveare for pilots who want to sharpen the skills that matter most when things go wrong. Early bird: $29 one-time. Lifetime access. Try the Simulator → https://bryanair.tools/ LINKS Bryan Air, Career Intelligence for Pilots → https://bryanairpodcast.com/ Free Pilot Career Assessment → https://pilotcareerintelligence.netlify.app/ Risk Management and Decision Making Simulator → https://bryanair.tools/ Bryan Roseveare → https://www.bryanroseveare.com/ Watch on YouTube → https://www.youtube.com/@BryanAirPodcast Support on Patreon → https://www.patreon.com/bryanair
The episode identifies a growing governance gap as a central structural issue for MSPs and IT service providers, driven by rapid AI adoption through subscription-based tools and platforms. Rather than being introduced as controlled, IT-led initiatives, AI services are entering organizations piecemeal—often through end users and business units—undermining established accountability and management practices. This dynamic is exemplified by ConnectWise's dismantling of its ASIO platform in favor of a new AI-native operating layer designed to unify PSA, RMM, security, and automation functions, and by clients independently layering on AI-powered tools without centralized oversight or cost control. A primary example of ungoverned risk involves unsustainable AI cost exposure. According to Axios and TechCrunch, an enterprise amassed around $500 million in a single month on Anthropic's Claude due to unlimited, unmonitored usage. Freshworks' survey of over 12,000 IT professionals quantifies the industry's operational friction, finding mid-market companies waste about 25% of AI budgets on complexity, for a total of $16 billion in annual waste. Despite 89% of respondents planning to increase AI spend, only 15% have actively integrated these tools into daily workflows—revealing widespread governance lag behind adoption. Supporting developments highlight the breadth and persistence of this governance deficit. Organizations such as the Linux Foundation have responded by forming the Tokenomics Foundation to standardize AI cost tracking. Meanwhile, AI tool adoption is occurring outside IT, leading to agent sprawl, unclear permissions, and cost scaling linked to agent behavior rather than headcount. Roll-up strategies in adjacent sectors—such as Thrive Holdings' $1 billion commitment to consolidate accounting firms under an AI operational platform—demonstrate capital's move toward operationally governed, AI-enabled service models, suggesting a parallel risk for IT providers. For MSPs and IT leaders, these trends underscore the urgency of operationalizing AI governance as a billable, contractual service rather than an informal or embedded support task. Risks include absorbing liability for unmanaged AI usage, exacerbated operational complexity, and relinquishing margin to platform or capital entrants. Practical steps involve conducting AI tool audits, inventorying agent access and spend, instituting usage controls, and reframing account segmentation around governance and liability exposure. MSPs who define, price, and contract for governance can mitigate inherited risk and avoid being displaced by vendors or capital-backed consolidators. 00:00 ConnectWise Rebuilds 03:59 Ungoverned Agents 06:06 Roll-Up Warning 09:38 Why Do We Care? Supported by: Moovila ScalePad
EPISODE SNAPSHOT Welcome to The Bryan Air Podcast. Career intelligence for pilots. We break down executive moves, economic forces, and the technology reshaping how pilots are trained, assessed, and employed. Boardroom decisions land on your flight deck. We translate them first. No corporate spin. Just the intelligence pilots actually need. This week is a tale of two stories, and if you are a South African pilot sitting in a Gulf hold pool you have to decide which one is true. Story one is the barrel: Iran put drones into Kuwait International days after it reopened, EASA still says do not overfly Iran, Iraq or Lebanon, and BA has pulled most of the Middle East until October. Story two is the window: the UAE has declared its airspace normal, Emirates is back to three quarters of its flying, Qatar rebuilds past 150 destinations from 16 June, and the recruitment roadshows are still running. We get into why your start date keeps slipping, why you should not resign before you have a firm date, and where the work is right now if you are stuck waiting. So which is it, the barrel or the window? In this episode of The Bryan Air Podcast, Bryan Roseveare and Ryan Parrock break down the Gulf hiring delays hitting South African pilots, the Middle East recovery timeline carrier by carrier, and the hidden contract and charter opportunities back home. TIME-STAMPED FLIGHT PLAN 00:00 Tale of two stories: barrel or window 01:55 The uncertainty pilots are actually living with 04:33 Roadshows still running and what that signals 08:14 Why your Gulf start date keeps slipping 09:33 Do not resign before you have a firm date 11:39 International market update and European Air Cargo collapse 12:26 The hidden contract jobs nobody talks about 17:19 Charter flying: the reality check at this stage of a career 20:35 Aviation news roundup begins 22:42 Middle East flight updates and the Kuwait strike 23:11 Champions League and the Emirates versus Qatar shirt war 24:27 World Cup SuperBrew plans 25:03 Bafana visa chaos at the airport 27:14 China stalls Airbus to clear the runway for COMAC 28:16 Qantas Project Sunrise takes its first test flight 29:04 Pilot shoutouts and fresh hires 30:35 Air Europa launches Madrid to Johannesburg 31:28 Captains Announcement: the wearable AI surveillance threat 37:24 F1 leaderboard and signoff JOIN THE BRYAN AIR COMMUNITY Bryan Air is a career intelligence ecosystem for pilots. Sign up free to receive our weekly newsletter covering the disruption of AI in aviation, career strategy, and the analysis that does not make it into the episodes. Sign Up Free → https://bryanairpodcast.com/ FREE PILOT CAREER ASSESSMENT Where are you in your career? The Flight Plan is our free, AI-powered career intelligence tool. Answer 8 questions about your situation and get a personalised strategic assessment with specific moves tailored to where you are right now. Take the Free Assessment → https://pilotcareerintelligence.netlify.app/ RISK MANAGEMENT & DECISION MAKING SIMULATOR Practise structured decision-making using live flights. Our AI-powered simulator lets you work through RMM and T-DODAR frameworks on real Flightradar24 data, with AI-generated scenarios and personalised debriefs. Built by Bryan Roseveare for pilots who want to sharpen the skills that matter most when things go wrong. Early bird: $29 one-time. Lifetime access. Try the Simulator → https://bryanair.tools/ LINKS Bryan Air — Career Intelligence for Pilots → https://bryanairpodcast.com/ Free Pilot Career Assessment → https://pilotcareerintelligence.netlify.app/ Risk Management & Decision Making Simulator → https://bryanair.tools/ Bryan Roseveare → https://www.bryanroseveare.com/ Watch on YouTube → https://www.youtube.com/@BryanAirPodcast Support on Patreon → https://www.patreon.com/bryanair #AviationPodcast #BryanAir #PilotLife #PilotJobs #MiddleEastAviation
Forced arbitration clauses have become embedded as a dominant mechanism in technology vendor contracts, shifting legal risk and accountability away from large vendors and reducing recourse options for managed service providers (MSPs) and IT service firms. This structural change, present in agreements with RMM and PSA vendors as well as hyperscalers such as Microsoft, Amazon, and Google, establishes a private dispute resolution system that operates beyond the traditional court system and is typically non-negotiable for smaller partners. The shift is evidenced by data and case studies outlined by Brendan Ballou. According to supplied figures, while consumers win in 89% of small claims court cases, their success rate drops to between 20% and 30% in arbitration, and even less—sometimes as low as 0.2%—for certain arbitration providers. Arbitration clauses are enforced even in extreme cases, as illustrated by a notable instance involving Disney, in which a forced arbitration clause was applied following a consumer's prior account registration. Legal precedent as far back as the 2011 Supreme Court decision referenced by Brendan Ballou has broadened the Federal Arbitration Act well beyond its 1925 origins, further entrenching this system. Additional developments reference increased litigation in the 1980s, often cited as justification for expanding arbitration, though he attributes much of the legal caseload surge to government actions rather than consumer or employee lawsuits. The technology industry's broad adoption of arbitration, especially in contracts where MSPs have little or no room to negotiate, further cements these power imbalances. Alternatives such as mediation are discussed as potentially less risky, but their adoption remains limited. The operational implications for MSPs, IT service providers, and IT leaders include heightened contract risk and reduced leverage in vendor disputes. Arbitration clauses limit access to open legal processes, restrict discovery rights, and are prone to bias in favor of vendors with repeat arbitrator relationships. For MSPs reliant on large platforms and suppliers, this creates ongoing exposure and complicates risk management. Mitigating measures—such as leveraging peer coordination for "mass arbitration" or negotiating for post-dispute mediation rather than pre-dispute forced arbitration—require proactive planning but may remain unavailable in standard vendor agreements. Supported by:MoovilaHaloPSA
EPISODE SNAPSHOT Welcome to The Bryan Air Podcast. Career intelligence for pilots. We break down executive moves, economic forces, and the technology reshaping how pilots are trained, assessed, and employed. Boardroom decisions land on your flight deck. We translate them first. No corporate spin. Just the intelligence pilots actually need. South African airlines are about to lose another wave of pilots. With no real career layers left locally between the regionals and the long-haul foreign jobs, our pilots have once again become the industry's cheapest, best-trained export. Meanwhile Starlink at 33,000 feet has rewired long-haul flying, Ryanair has wiped out 1.4 billion in pandemic debt, and passengers are starting to tip airline crew. Are you ready for the next 12 months in a South African right seat? In this episode of The Bryan Air Podcast, Bryan Roseveare and Ryan Parrock break down the South African pilot exodus, Starlink in the cockpit, UK pilot salaries in 2026, Ryanair becoming debt-free, an easyJet power bank diversion, the Air India Express runway edge takeoff scare in Muscat, automated taxi bots at Schiphol, and the impact of the Middle East conflict on South African tourism. TIME-STAMPED FLIGHT PLAN 00:00 Cold Open And This Week's Flight Plan 00:43 Starlink First Impressions From An Air France A350 02:09 Why Starlink Makes In-Flight WiFi Feel Brand New 02:54 Every Airline That Has Already Switched To Starlink 05:01 Why O'Leary Refuses To Put Starlink On Ryanair 06:03 The Hidden Cost Of Being Connected At 33,000ft 08:00 Starlink In The Cockpit: A Pilot Distraction Problem 11:27 The Paris Tipping Trap And Hidden Service Charges 13:38 A Charles de Gaulle Nightmare And The Captain Who Saved It 17:56 Passengers Are Now Tipping Airline Crew 21:05 Should Pilots Actually Be Tipped? 22:25 UK Pilot Salaries In 2026: The New Numbers 24:20 Why South African Pilots Are About To Leave Again 28:40 Ryanair Paid Off 1.4 Billion And Is Now Debt Free 29:51 The EasyJet Power Bank That Diverted A Plane To Rome 31:40 Air India Express Tried To Take Off On The Runway Edge 32:14 Middle East Conflict, SA Tourism And Etihad's Joburg Return 34:14 Schiphol's Automated Taxi Bots Are Live 36:59 FIFA World Cup Liveries And A New Bryan Air SuperBru 39:20 Wrap And Sign-Off JOIN THE BRYAN AIR COMMUNITY Bryan Air is a career intelligence ecosystem for pilots. Sign up free to receive our weekly newsletter covering the disruption of AI in aviation, career strategy, and the analysis that does not make it into the episodes. Sign Up Free → https://bryanairpodcast.com/ FREE PILOT CAREER ASSESSMENT Where are you in your career? The Flight Plan is our free, AI-powered career intelligence tool. Answer 8 questions about your situation and get a personalised strategic assessment with specific moves tailored to where you are right now. Take the Free Assessment → https://pilotcareerintelligence.netlify.app/ RISK MANAGEMENT AND DECISION MAKING SIMULATOR Practise structured decision-making using live flights. Our AI-powered simulator lets you work through RMM and T-DODAR frameworks on real Flightradar24 data, with AI-generated scenarios and personalised debriefs. Built by Bryan Roseveare for pilots who want to sharpen the skills that matter most when things go wrong. Early bird: $29 one-time. Lifetime access. Try the Simulator → https://bryanair.tools/ LINKS Bryan Air - Career Intelligence for Pilots → https://bryanairpodcast.com/ Free Pilot Career Assessment → https://pilotcareerintelligence.netlify.app/ Risk Management and Decision Making Simulator → https://bryanair.tools/ Bryan Roseveare → https://www.bryanroseveare.com/ Watch on YouTube → https://www.youtube.com/@BryanAirPodcast Support on Patreon → https://www.patreon.com/bryanair #AviationPodcast #BryanAir #PilotLife #SouthAfricanAviation #Starlink
EPISODE SNAPSHOT Welcome to The Bryan Air Podcast. Career intelligence for pilots. We break down executive moves, economic forces, and the technology reshaping how pilots are trained, assessed, and employed. Boardroom decisions land on your flight deck. We translate them first. No corporate spin. Just the intelligence pilots actually need. Cape Town went off the air on Monday. Gusts over 50 knots, crews diverting to PE, East London, and even back to Joburg, and a Turkish long-haul thrown into the mix. Ryan unpacks his shift into the charter market while the Middle East ripples through the industry, and we get into why FlySafair's on-time performance is not luck, it is strategy you can study. Then we go global: Trump's 200-aircraft China deal, Singapore Airlines printing $2.4 billion in revenue, $49.5 million awarded in the Ethiopian 302 case, and Google preparing to launch AI data centres into orbit by 2027. The hiring floodgates are about to open. Are you ready when they do? In this episode of The Bryan Air Podcast, Bryan Roseveare and Ryan Parrock analyse Cape Town weather diversions, FlySafair's on-time performance strategy, China's 200-aircraft Boeing order, Ethiopian 302 compensation, Singapore Airlines record results, French Bee pilot strikes, and Google's plan for AI data centres in orbit. TIME-STAMPED FLIGHT PLAN 00:00 Cleared for Approach 00:13 Welcome Back to the Studio 00:43 Ryan's Charter Market Pivot 02:13 Cockpit Casual Backs the Spirit Pilots 03:39 Cape Town Shuts Down: Wild Weather Hits 05:53 What Pilots Actually Pay for Tickets 07:45 The FlySafair OTP Strategy Decoded 09:14 Hiring Floodgates About to Open 11:19 Trump, China, and 200 Boeings 12:12 $49.5M Awarded in Ethiopian 302 Case 12:39 Singapore Airlines Hits $2.4B Revenue 13:29 Why Japan Is on the Travel Radar 15:16 Google Sends AI Data Centres to Orbit 17:38 French Bee Pilots Plan to Strike 18:54 Verstappen, the Nürburgring, and Springboks 20:31 Paris Bound: Air France Review Incoming 20:55 Outro and Subscribe JOIN THE BRYAN AIR COMMUNITY Bryan Air is a career intelligence ecosystem for pilots. Sign up free to receive our weekly newsletter covering the disruption of AI in aviation, career strategy, and the analysis that does not make it into the episodes. Sign Up Free → https://bryanairpodcast.com/ FREE PILOT CAREER ASSESSMENT Where are you in your career? The Flight Plan is our free, AI-powered career intelligence tool. Answer 8 questions about your situation and get a personalised strategic assessment with specific moves tailored to where you are right now. Take the Free Assessment → https://pilotcareerintelligence.netlify.app/ RISK MANAGEMENT & DECISION MAKING SIMULATOR Practise structured decision-making using live flights. Our AI-powered simulator lets you work through RMM and T-DODAR frameworks on real Flightradar24 data, with AI-generated scenarios and personalised debriefs. Built by Bryan Roseveare for pilots who want to sharpen the skills that matter most when things go wrong. Early bird: $29 one-time. Lifetime access. Try the Simulator → https://bryanair.tools/ LINKS Bryan Air — Career Intelligence for Pilots → https://bryanairpodcast.com/ Free Pilot Career Assessment → https://pilotcareerintelligence.netlify.app/ Risk Management & Decision Making Simulator → https://bryanair.tools/ Bryan Roseveare → https://www.bryanroseveare.com/ Watch on YouTube → https://www.youtube.com/@BryanAirPodcast Support on Patreon → https://www.patreon.com/bryanair #AviationPodcast #BryanAir #PilotLife #CapeTownWeather #FlySafair
EPISODE SNAPSHOT Welcome to The Bryan Air Podcast. Career intelligence for pilots. We break down executive moves, economic forces, and the technology reshaping how pilots are trained, assessed, and employed. Boardroom decisions land on your flight deck. We translate them first. No corporate spin. Just the intelligence pilots actually need. This week, three stories stacked on top of each other and they tell two completely different versions of where this industry is heading. IATA put hard numbers on the Gulf War, with Middle Eastern traffic down 58.6 percent year-on-year and global growth slowing to 2.1 percent in March. India's three biggest airlines wrote to their own government saying they are days from grounding aircraft as fuel rises from 40 percent to 60 percent of operating costs. Spirit folded. The UAE flipped its airspace switch back on and Emirates restored 96 percent of its network. Which story are you actually flying in? In this episode of The Bryan Air Podcast, Bryan Roseveare and Ryan Parrock break down the IATA fuel shock report, India's airlines on the brink, the UAE airspace reopening, Spirit Airlines folding, the BA taxi pilot job paying 100,000 dollars a year, the United 767 truck strike at Newark, and Japan Airlines testing humanoid robots on the ramp. TIME-STAMPED FLIGHT PLAN 00:00 ATC Cold Open 00:13 Headlines: Three Stories Stacked on Top of Each Other 00:55 Quick Favour Before We Roll 01:49 IATA Report: The Fuel Shock in Hard Numbers 04:28 Charter Pricing and Why Surcharges Are Now Standard 06:41 Why Europe Could Be Cheaper Than Cape Town This December 09:13 India: Three Major Airlines Days From Grounding 10:56 Spirit Airlines Folds and What It Means for Crew 12:47 UAE Airspace Reopens After Three Months Closed 16:33 Five Months Profit Share at Emirates? The Buzz 18:47 The 100,000 Dollar BA Taxi Pilot Gig at Chicago O'Hare 20:43 UK Government Lets Airlines Drop Slots Over Fuel Shortages 21:19 The United 767 That Smacked a Truck at Newark 22:54 Japan Airlines Tests Humanoid Robots on the Ramp 25:31 F1 Miami, UFC, and the Weekend Ahead 28:28 The Final Take: Which Story Are You Flying In? 30:08 Sign Off JOIN THE BRYAN AIR COMMUNITY Bryan Air is a career intelligence ecosystem for pilots. Sign up free to receive our weekly newsletter covering the disruption of AI in aviation, career strategy, and the analysis that does not make it into the episodes. Sign Up Free → https://bryanairpodcast.com/ FREE PILOT CAREER ASSESSMENT Where are you in your career? The Flight Plan is our free, AI-powered career intelligence tool. Answer 8 questions about your situation and get a personalised strategic assessment with specific moves tailored to where you are right now. Take the Free Assessment → https://pilotcareerintelligence.netlify.app/ RISK MANAGEMENT AND DECISION MAKING SIMULATOR Practise structured decision-making using live flights. Our AI-powered simulator lets you work through RMM and T-DODAR frameworks on real Flightradar24 data, with AI-generated scenarios and personalised debriefs. Built by Bryan Roseveare for pilots who want to sharpen the skills that matter most when things go wrong. Early bird: 29 dollars one-time. Lifetime access. Try the Simulator → https://bryanair.tools/ LINKS Bryan Air, Career Intelligence for Pilots → https://bryanairpodcast.com/ Free Pilot Career Assessment → https://pilotcareerintelligence.netlify.app/ Risk Management and Decision Making Simulator → https://bryanair.tools/ Bryan Roseveare → https://www.bryanroseveare.com/ Watch on YouTube → https://www.youtube.com/@BryanAirPodcast Support on Patreon → https://www.patreon.com/bryanair #AviationPodcast #BryanAir #PilotLife #IATA #FuelShock
EPISODE SNAPSHOT Welcome to The Bryan Air Podcast. Career intelligence for pilots. We break down executive moves, economic forces, and the technology reshaping how pilots are trained, assessed, and employed. Boardroom decisions land on your flight deck. We translate them first. No corporate spin. Just the intelligence pilots actually need. Sitting across from Willie Walsh in Singapore, I asked the question every pilot, parent, and cadet is asking right now: will pilot jobs still exist in 10 to 15 years. His answer was honest, sharp, and not what the pilotless hype crowd wants to hear. This bonus reel pulls the highlights from IATA's World Data Symposium 2026: Walsh on the broader career paths most pilots ignore, the 1.4 billion people and only 50 wide bodies sitting in India, real-time turbulence data going straight to your iPad, why aviation is teaching the rest of tech how to govern AI, the honest truth about SAF, and a reminder that the right job at the right time is not always the heavy metal. If you are trying to read where this industry is actually heading, start here. In this bonus episode of The Bryan Air Podcast, Bryan Roseveare shares highlights from IATA WDS 2026 in Singapore featuring Willie Walsh (IATA Director General), Kim McCauley, David Fairman, Dr. Marie Owens Thompson, and Al McCauley on pilotless aircraft, pilot career outlook, AI in aviation, sustainable aviation fuel, and the future of the flight deck. TIME-STAMPED FLIGHT PLAN 00:00 Welcome to the bonus reel 00:22 Why IATA Singapore mattered 01:09 The pilotless hype check no one wants to hear 02:08 Will pilot jobs still exist in 10 to 15 years 04:43 A quick favour and a thank you 06:08 Willie Walsh on the broader career paths most pilots ignore 08:46 1.4 billion people, 50 wide bodies: India and Africa unpacked 09:39 Kim McCauley on nowcasting turbulence straight to your iPad 11:38 David Fairman on cybersecurity, agentic AI, and aviation as the benchmark 14:20 Dr. Marie Owens Thompson on SAF and the silo problem 16:24 Al McCauley on situational awareness and choosing the right job at the right time 20:15 Wrap up, resources, and what is coming next JOIN THE BRYAN AIR COMMUNITY Bryan Air is a career intelligence ecosystem for pilots. Sign up free to receive our weekly newsletter covering the disruption of AI in aviation, career strategy, and the analysis that does not make it into the episodes. Sign Up Free → https://bryanairpodcast.com/ FREE PILOT CAREER ASSESSMENT Where are you in your career? The Flight Plan is our free, AI-powered career intelligence tool. Answer 8 questions about your situation and get a personalised strategic assessment with specific moves tailored to where you are right now. Take the Free Assessment → https://pilotcareerintelligence.netlify.app/ RISK MANAGEMENT AND DECISION MAKING SIMULATOR Practise structured decision-making using live flights. Our AI-powered simulator lets you work through RMM and T-DODAR frameworks on real Flightradar24 data, with AI-generated scenarios and personalised debriefs. Built by Bryan Roseveare for pilots who want to sharpen the skills that matter most when things go wrong. Early bird: $29 one-time. Lifetime access. Try the Simulator → https://bryanair.tools/ LINKS Bryan Air — Career Intelligence for Pilots → https://bryanairpodcast.com/ Free Pilot Career Assessment → https://pilotcareerintelligence.netlify.app/ Risk Management and Decision Making Simulator → https://bryanair.tools/ Bryan Roseveare → https://www.bryanroseveare.com/ Watch on YouTube → https://www.youtube.com/@BryanAirPodcast Support on Patreon → https://www.patreon.com/bryanair
EPISODE SNAPSHOT Welcome to The Bryan Air Podcast. Career intelligence for pilots. We break down executive moves, economic forces, and the technology reshaping how pilots are trained, assessed, and employed. Boardroom decisions land on your flight deck. We translate them first. No corporate spin. Just the intelligence pilots actually need. SAA is back in the headlines, and not for the reasons anyone at home wants. The Auditor General has flagged the airline as a going concern with material uncertainty, and SA Technical's financials are reportedly too severe to even audit. That one lands hard locally. Globally, the bigger signal is Lufthansa cutting 20,000 short-haul flights this summer because the fuel maths no longer works. Bryan and Ryan translate what all of it means for your roster, your contract, and your next career move. In this episode of The Bryan Air Podcast, Bryan Roseveare and Ryan Parrock break down SAA's going concern warning, Lufthansa cutting 20,000 flights, the Pratt and Whitney GTF Advantage engine, the US pilot mental health bill, and a Dubai WhatsApp arrest every crew member should know about. TIME-STAMPED FLIGHT PLAN 00:00 Welcome Back: The Stories That Matter This Week 01:05 Singapore Recap: What Stood Out 01:55 Quick Favour: Hit Subscribe 02:25 SAA Leadership Exit: Lamola Out, Acting CEO In 03:11 Parliament Fallout: AG Flags Going Concern 05:29 What This Means for SAA Pilots and Crew 10:38 Lufthansa Cuts 20,000 Flights as Fuel Maths Break 12:51 Fuel Surcharges and Geopolitical Uncertainty 19:28 Pratt and Whitney GTF Advantage Gets EASA Nod 21:11 US Senate Advances Pilot Mental Health Bill 27:57 Dubai WhatsApp Arrest: What Every Crew Needs to Know 30:05 Top Gun 3 Rumour: Maverick Might Be Back 31:45 Captain's Announcement: WhisperFlow for Pilots 37:02 Wrap Up and the Updated Flight Plan Tool JOIN THE BRYAN AIR COMMUNITY Bryan Air is a career intelligence ecosystem for pilots. Sign up free to receive our weekly newsletter covering the disruption of AI in aviation, career strategy, and the analysis that does not make it into the episodes. Sign Up Free → https://bryanairpodcast.com/ FREE PILOT CAREER ASSESSMENT Where are you in your career? The Flight Plan is our free, AI-powered career intelligence tool. Answer 8 questions about your situation and get a personalised strategic assessment with specific moves tailored to where you are right now. Take the Free Assessment → https://pilotcareerintelligence.netlify.app/ RISK MANAGEMENT & DECISION MAKING SIMULATOR Practise structured decision-making using live flights. Our AI-powered simulator lets you work through RMM and T-DODAR frameworks on real Flightradar24 data, with AI-generated scenarios and personalised debriefs. Built by Bryan Roseveare for pilots who want to sharpen the skills that matter most when things go wrong. Early bird: $29 one-time. Lifetime access. Try the Simulator → https://bryanair.tools/ LINKS Bryan Air — Career Intelligence for Pilots → https://bryanairpodcast.com/ Free Pilot Career Assessment → https://pilotcareerintelligence.netlify.app/ Risk Management & Decision Making Simulator → https://bryanair.tools/ Bryan Roseveare → https://www.bryanroseveare.com/ Watch on YouTube → https://www.youtube.com/@BryanAirPodcast Support on Patreon → https://www.patreon.com/bryanair #AviationPodcast #BryanAir #PilotLife #SAA #Lufthansa
Tightening budget constraints and rising data trust requirements are increasing operational pressure on managed service providers by shifting risk and accountability downward through the service chain. Developments in both the European and US markets, together with supply chain volatility and heightened scrutiny of where and how data is handled, are forcing MSPs to redefine both service delivery and governance models. According to Speaker A, MSPs focusing on auditability, clear data residency, and sovereignty will remain viable, while those relying on traditional narratives or ambiguous transformation pitches risk being sidelined. The episode points to evidence from several reports: Politico notes that 8 out of 10 Europeans do not trust US or Chinese firms with their data, highlighting explicit concerns over data location and custodianship. Concurrently, the U.S. Chamber of Commerce Small Business Index, cited by Axios, shows declining confidence among American small businesses, with only 37% expecting new investments and 53% listing inflation as their top challenge. Further, Channel Insider flags “memflation,” with DRAM and NAND prices expected to rise 125% and 243% respectively by 2026, intensifying margin pressure and pricing risk for operators. Additional risk drivers come from both operational and technical layers. Speaker A references the Blackpoint Cyber 2026 threat report, which attributes most breaches to the abuse of trusted credentials and tools—such as RMM solutions and SSL VPNs—rather than new vulnerabilities. Governance gaps are also worsened by declining white-collar hiring, as cited by Gallup and Axios, reducing internal capacity for vendor reviews, incident follow-up, and process controls. Increased automation and outsourcing in response to these gaps tend to create more dependency chains and larger blast radii, making explicit governance even more important. For MSPs, these findings point to operational needs that go beyond technical capability. Contract terms must address volatile input costs directly, with shorter quote validity and explicit repricing clauses. Governance processes should include audit-ready data maps, clear documentation of subprocessors, and proactive credential management. Without these measures, MSPs risk being treated as interchangeable commodities and exposed to margin compression and heightened liability from external compliance and trust requirements. 00:00 SMB Caution 03:48 Coordination Crunch 06:24 RMM Exposed 09:36 Why Do We Care? Supported by: Zero Networks HaloPSA
Today we are joined by Selena Larson, Threat Researcher from Proofpoint research team and co-host of Only Malware in the Building, talking about their work on "(Don't) TrustConnect: It's a RAT in an RMM hat." Proofpoint uncovered TrustConnect, a malware-as-a-service platform posing as a legitimate remote monitoring and management (RMM) tool, but actually functioning as a remote access trojan (RAT) sold to cybercriminals for $300/month. The operation used a fake business website, legitimate-looking certificates, and branded installers (like fake Microsoft Teams or Zoom apps) to trick victims, while providing attackers with full remote control, file transfer, and surveillance capabilities. Although parts of its infrastructure were disrupted, the threat actor quickly rebounded with new variants, highlighting both the resilience of the operation and its deep ties to the broader cybercriminal ecosystem abusing RMM tools. The research and executive brief can be found here: (Don't) TrustConnect: It's a RAT in an RMM hat Learn more about your ad choices. Visit megaphone.fm/adchoices
3 Days, 1 Conference, Every Question Answered | IATA WDS 2026 Live
Today we are joined by Selena Larson, Threat Researcher from Proofpoint research team and co-host of Only Malware in the Building, talking about their work on "(Don't) TrustConnect: It's a RAT in an RMM hat." Proofpoint uncovered TrustConnect, a malware-as-a-service platform posing as a legitimate remote monitoring and management (RMM) tool, but actually functioning as a remote access trojan (RAT) sold to cybercriminals for $300/month. The operation used a fake business website, legitimate-looking certificates, and branded installers (like fake Microsoft Teams or Zoom apps) to trick victims, while providing attackers with full remote control, file transfer, and surveillance capabilities. Although parts of its infrastructure were disrupted, the threat actor quickly rebounded with new variants, highlighting both the resilience of the operation and its deep ties to the broader cybercriminal ecosystem abusing RMM tools. The research and executive brief can be found here: (Don't) TrustConnect: It's a RAT in an RMM hat Learn more about your ad choices. Visit megaphone.fm/adchoices
How are organized crime rings infiltrating our supply chains, and is your vetting process strong enough to stop a "Trojan driver" from walking off with your high-value loads? Tune in to this episode as "The Fraud Girl" Danielle Spinelli from GenLogs breaks down the exploding crisis of freight fraud and cargo theft. We discuss the nitty-gritty of why a tight market is the best time to sharpen your brokerage skills, the importance of building authentic carrier relationships, and the terrifying reality of cyber-enabled theft costing the industry millions. Danielle shares her expert insights on everything from driver-level vetting to sophisticated RMM hacks targeting small to mid-sized fleets. If you're a transportation pro looking to protect your business and stay ahead of the latest fraudulent trends, you cannot afford to miss this discussion on the front lines of logistics security! About Danielle Spinelli Danielle Spinelli is the Director of Partnerships at Genlogs with over a decade of experience in logistics, specializing in carrier sales, vetting, and cargo theft prevention. After 8 years as a Carrier Sales Broker and later educating brokers and shippers on compliance at MyCarrierPortal, she now focuses on partnerships and industry collaboration to raise awareness around cargo theft and promote data-driven prevention strategies. Danielle also hosts the Tell Me Everything podcast, where she shares insights on cargo theft, logistics trends, and supply chain security. Connect with Danielle Website: https://www.genlogs.io/ LinkedIn: https://www.linkedin.com/in/daniellespinelli11/
Lots of cottage cheese and empanadas in #RMM, training at Planet Fitness, lifting for cycling, random fevers and The View is back with more retardation.Power Up Here: https://swolenormous.com
EPISODE SNAPSHOT Welcome to The Bryan Air Podcast. Boardroom decisions land on your flight deck — we translate them first. We break down executive moves, economic forces, and the technology reshaping how pilots are trained, assessed, and employed. No corporate spin. Just the career intelligence pilots actually need. Jet fuel prices have doubled in three weeks. Brent crude is above $100 a barrel. Airlines are canceling thousands of flights and slapping surcharges on tickets. And yet Emirates is still selling seats while smoke from a drone strike billows over the Dubai skyline. In this episode, we dig into what the fuel shock actually means for pilots on the line, from South Africa's 21-day strategic reserve to European carriers killing green fuel mandates because they cannot afford regular kerosene. We ask the question a father called in to ask us: should his kid stay in flight school? And we look at whether this crisis reshuffles the deck for airlines like British Airways who are already adding capacity while Gulf carriers absorb the hit. In this episode of The Bryan Air Podcast, Bryan Roseveare and Ryan Parrock analyse the Middle East fuel crisis, jet fuel price shock, South Africa's supply vulnerability, Dubai airspace safety, pilot career strategy during conflict, British Airways market repositioning, and the growing role of AI in airline rostering ahead of the Singapore aviation symposium. ✈ TIME-STAMPED FLIGHT PLAN 00:00 Bryan Air decision training tool: practise cockpit decisions on live flights 01:09 Episode intro and why this week is not sugarcoated 01:58 Jet fuel doubles in three weeks: the numbers airlines do not want you to see 03:43 South Africa runs on imported fuel with 21 days of reserves 06:20 Should your kid go to flight school? A father calls in for honest advice 10:42 Drones hit Dubai fuel tanks and Emirates keeps flying through the smoke 16:08 British Airways adds 10% more flights while Gulf carriers take the hit 18:30 What smart pilots do when the industry enters survival mode 19:59 Singapore AI symposium preview: rostering algorithms and the death of the roster clerk bribe 25:46 F1 SuperBru standings update and predictions for Japan 28:05 Live show announcement and how to send us your questions
(Presented by TLPBLACK: High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.) Huntress threat intelligence analyst Greg Linares shares insights on the modern ransomware ecosystem, including how crews operate like businesses and why Akira, Medusa, RansomHub, and Qilin cause so much damage. Plus, signs of overlap between ransomware and nation-state activity, what “time to ransom” really means for defenders, and why techniques like ClickFix and credential theft keep working at scale. The conversation also covers the surge in RMM tool abuse, how “living off the land” attacks can unfold without traditional malware, and the basic defenses smaller organizations can prioritize.
Cybercrime's escalation has reached a projected $12.2 trillion annual impact by 2031, with a notable surge in remote monitoring and management (RMM) tool abuse—up 277% year-over-year, according to Huntress and supporting vendor reports. Attackers utilize legitimate IT tools to facilitate stealthier ransomware and phishing campaigns, amplifying structural vulnerabilities within MSP technology stacks. Key metrics from Acronis, WatchGuard, and Vectra AI indicate a shift to smaller, more evasive malware campaigns, longer times to ransomware deployment (averaging 20 hours), and widespread unaddressed security alerts, raising questions about the adequacy of current defenses and incident response practices. Vendor-supplied threat intelligence further shows that MSPs' reliance on signature-based platforms and insufficient visibility leaves them exposed to evolving attack techniques. Data reviewed suggests phishing footholds can quickly compromise cross-client environments, and legal ramifications heavily fall on the service provider when RMM or monitoring tools act as entry points. Notably, only about 58-60% of organizations report full visibility across their systems, with a majority of alerts remaining unaddressed, underscoring gaps in operational maturity and preparedness. Adjacent coverage highlighted Microsoft Copilot's repeated security control failures within regulated environments, specifically its inability to enforce sensitivity labels and boundaries across emails—most recently affecting the UK's National Health Service. The lack of vendor-announced architectural changes calls into question the viability of deploying AI tools in compliance-driven contexts. Separately, political and public backlash against surveillance technologies (such as Flock cameras) demonstrates that unchecked data collection is no longer a manageable passive risk, as data becomes increasingly actionable and retains liability beyond technical considerations. The practical takeaway for MSPs and IT leaders is a need to prioritize audit, documentation, and enforcement of controls within their technology stacks, especially where vendor tools or AI-driven automation intersect with compliance and client trust. Preserving operational optionality and scrutinizing vendor terms—particularly data sharing and architectural enforcement—are essential to reduce exposure. Waiting for vendor patches, disregarding documented control failures, or underestimating public scrutiny elevate liability across legal, reputational, and client relationship domains. Four things to know today: 00:00 Vendor Threat Reports Converge on One Risk MSPs Can't Outsource: The RMM as Breach Vector 05:11 Copilot Failed Compliance Controls Twice in Eight Months — A Patch Won't Fix That 07:03 Flock Backlash Exposes the Liability Hidden in Every Vendor Data-Sharing Contract 09:42 GTDC Summit: Distributors Pitch AI On-Ramp as Hyperscalers Compress Their Margin Sponsored by:
How do I know if the software I'm installing is legit? Crims created a fake RMM tool to gain access to business networks, Ransomware attacks, Why is Cloudflare blocking me? Security Cam Talk, AI Generated passwords, Want's to remote into PC for Quickbooks work.
How do I know if the software I'm installing is legit? Crims created a fake RMM tool to gain access to business networks, Ransomware attacks, Why is Cloudflare blocking me? Security Cam Talk, AI Generated passwords, Want's to remote into PC for Quickbooks work.
Dutch authorities warn Russia is escalating hybrid operations across Europe. Ransomware shuts down the University of Mississippi Medical Center. PayPal notifies customers of a data breach. The FBI says ATM jackpotting is on the rise. An FBI confidential informant had a hand in online fentanyl sales. TrustConnect malware masquerades as a legitimate remote monitoring and management tool. Researchers uncover the first Android malware to integrate generative AI. A critical zero-day hits Grandstream VOIP phones. The IRS slashes IT staff and technology executives. Our guest is James Turgal, a 22-year FBI vet and VP of global cyber risk and board relations at Optiv, discussing the latest wave of tax scams and IRS fraud. DOGE dudes deliver DEI deathblows. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by James Turgal, a 22-year FBI vet and VP of global cyber risk and board relations at Optiv, discussing the latest wave of tax scams and IRS fraud. Selected Reading Russia stepping up hybrid attacks, preparing for long standoff with West, Dutch intelligence warns (The Record) University of Mississippi Medical Center Suffers Cyberattack, Closes All Clinics, Cancels Services (Mississippi Free Press) PayPal discloses data breach that exposed user info for 6 months (Bleeping Computer) FBI: Over $20 million stolen in surge of ATM malware attacks in 2025 (Bleeping Computer) An FBI ‘Asset' Helped Run a Dark Web Site That Sold Fentanyl-Laced Drugs for Years (WIRED) (Don't) TrustConnect: It's a RAT in an RMM hat (Proofpoint US) PromptSpy ushers in the era of Android threats using GenAI (We Live Security) CVE-2026-2329: Critical Unauthenticated Stack Buffer Overflow in Grandstream GXP1600 VoIP Phones (FIXED) (Rapid 7) DOGE bites taxman (The Register) DOGE Bro's Grant Review Process Was Literally Just Asking ChatGPT ‘Is This DEI?' (Techdirt) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
In a podcast recorded at ITEXPO / MSP EXPO, Doug Green, Publisher of Technology Reseller News, spoke with Rick Bekers, CEO of Channel Sales Pro, about how MSPs and technology vendors can design effective channel programs that accelerate growth while avoiding common pitfalls. Bekers brings more than four decades of experience to the conversation, including 35 years as an MSP owner, time leading a Technology Services Distributor (TSD), and years as a consultant helping vendors and service providers enter and scale through the channel. He emphasized that channel programs—whether built by vendors or MSPs evolving into “master MSPs”—require specialized expertise. “Trying to build a channel program on your own can slow you down by 18 months to three years,” Bekers said, noting that missteps and trial-and-error often delay revenue and partner momentum. The discussion focused on how Channel Sales Pro engages with MSPs seeking to expand. Bekers described a structured discovery and gap analysis process designed to align channel strategy with business goals, followed by execution that leverages established industry relationships. Drawing on his own experience running an MSP, he stressed the importance of solid operational foundations—repeatable processes, PSA and RMM tools, and consistent onboarding—to prevent burnout and customer churn as firms scale. “You don't want to try to scale a program on broken processes,” he explained. Bekers also delivered a direct message to MSP founders who feel stuck managing growth alone. By standardizing operations and seeking experienced guidance, MSPs can move from reactive, exhausting growth cycles to predictable, repeatable expansion. His confidence in the model is underscored by a performance guarantee tied to measurable revenue outcomes, reinforcing his belief that disciplined channel strategy can deliver returns within months. Visit https://www.channelsales.pro/
Jace Inman and RMM on Sub FM 7th February 2026 - https://www.sub.fm
OpenAI's direct investment and technical involvement with Thrive Holdings, specifically through its partnership with SHIELD Technology Partners, presents a new precedent for AI's integration into the managed service provider (MSP) space. Unlike prior private equity roll-ups or traditional organic growth, this move involves embedding OpenAI's models and engineers directly within SHIELD's platform, an entity that has rapidly acquired and integrated nine MSPs and executed two $100 million funding rounds. The arrangement is characterized by efforts to optimize MSP operations through proprietary AI automation, raising immediate questions around operational dependency and the shifting locus of software control.According to Seth Robinson, this approach signals OpenAI's attempt to navigate both consumer and enterprise technology markets—a dynamic seen previously in mobility—and reflects the broader tension between individual AI use cases and deeply integrated stack solutions. The initiative may accelerate operational scale, but it also introduces new operational risks by centralizing key components of service delivery and support within a single AI-driven platform, potentially affecting vendor lock-in, data governance, and continuity of MSP business models.Parallel developments highlight new vendor integration strategies among MSP-focused software providers. One example is Lexfold's AI documentation system, which, rather than integrating directly with core PSA and RMM tools, utilizes intermediary platforms such as Scalepad and Liongard for data access. Seth Robinson emphasizes that these alternative integration points may alter an MSP's center of operational gravity and complexity management, underscoring the need to assess not just functional outcomes but also system dependencies and brittleness introduced by new integration paths.For MSPs and IT leaders, these trends underscore the necessity of rigorous due diligence in vendor relationships, clarity on operational dependencies, and attention to the long-term implications of AI-enabled automation. Management—not elimination—of complexity remains central, with the risk of oversimplification leading to commoditization and loss of differentiation. Moreover, advances in AI should prompt greater scrutiny about talent pipelines, upskilling strategies, and the potential risks of eroding early-career roles, which may impact long-term service quality and resilience. Careful evaluation of integration points, data integrity, and operational control is recommended to mitigate the practical and organizational risks emerging from these developments.
Bob Miller, CEO and Founder of IRGame, is a technology entrepreneur with 30+ years of experience across cybersecurity and emerging technologies. He's a pioneer in using AI-powered gamification for incident response (“IR”) training, designed specifically for busy executives who can't spend full days in training but must make high-stakes decisions quickly during real crises. IRGame puts executive teams through realistic scenario such as ransomware, data breaches, business email compromise, and AI-related incidents, so they can practice decision-making under pressure. Returning to Lafayette and building startups Bob graduated in 1988 from University of Louisiana – Monroe in Computer Science and Math. He moved back to Louisiana from San Jose around 2010 and chose Lafayette as home. Almost immediately, the Lafayette Economic Development Authority (LEDA) contacted him about helping build a startup accelerator. With experience across roughly 10 startups, he became founding director of what he named the Opportunity Machine, where his title was “Head Machinist”). Bob later continued mentoring via the Accelerator Board. After three years, engineer and entrepreneur Bill Fenstermaker recruited him to help commercialize products at Fenstermaker & Associates. Bob worked on projects including a custom GIS system and underwater acoustics, following earlier work in areas like satellite systems. Later he became COO at Waitr in its early stage, helping scale from about 300 to 3,000 employees in roughly 12–14 months, the kind of operational scaling challenge he's often brought in to manage. He then joined a local managed service provider and helped transform it into a managed security service provider, an experience that directly led to IR Game. Why IR Game exists Bob identified a persistent problem: many organizations resist spending time and money on cybersecurity because they don't understand it and lack an emotional connection because they have never experienced a crisis. Traditional tabletop training exercises meant to train a business team on how to respond during a crisis (paper scenarios, PowerPoint presentations, and sitting around a conference table discussing solutions) have existed for decades, but they're time-consuming (often 80–90 hours to prepare) and require pulling people into a room for a full day, which makes them expensive and hard to scale. If it's hard, many companies simply don't do it. Bob attended a cybersecurity conference and participated in a tabletop designed for managed service providers, an exercise that was “fundamentally terrifying” and eye-opening. A worst-case Managed Service Provider (“MSP”) scenario is when a third-party tool, especially remote monitoring and management (RMM) software, gets compromised. That can lead to ransomware across an MSP's entire customer base simultaneously. The exercise illustrated IRGame's central insight: about 80% of incident response is non-technical in nature: financial consequences, shutdown decisions, customer impact, employee panic, communications, reputational and legal exposure. Bob brought the tabletop back to his company and ran it with 80 of 130 employees, customizing it with real customer names, revenue figures, and tenure. Even with a mature incident response plan and twice-yearly practice, they discovered a dozen needed changes. That convinced him that if a well-prepared security organization learns that much from a scenario, “everybody can.” The breakthrough: turning tabletop into an online multiplayer game During that exercise, a longtime software collaborator of Bob’s mentioned he still had a dormant game app framework built years earlier for a high-school project with Bob's daughter. He believed he could convert the paper tabletop into an online multiplayer experience in a weekend. After running the in-person tabletop on Thursday, he demonstrated a working browser-based multiplayer version on Sunday. They showed it to cybersecurity tabletop authors and industry influencers, Matt Lee and Ethan Tancredi, who were shocked by how quickly the tabletop content had been transformed into a functional digital game. Soon after, they invited about 20 people to test it. The early version looked rough, like a 1980s text adventure, but it worked. The response was far stronger than expected: participants reported intense emotional engagement and immediate practical takeaways. One government participant said it left him rattled, with pages of notes and a need for a drink; an MSP in Hawaii asked when he could use it with customers. That became a monthly community practice program: they've run 25+ free games, putting 1,000+ people through the system. As demand grew—especially from providers wanting to use it with customers—IRGame chose to commercialize. IR Game mirrors tabletop training but compresses it into a high-intensity, guided simulation. A scenario is narrated like scenes in a movie. Participants answer opening questions to get teams communicating quickly, which is critical because incident response requires fast coordination. Players assume roles and must allocate limited resources to tasks. Challenges pile up faster than teams can handle them, forcing prioritization and tradeoffs, just like real incidents. A key design element is pressure: a relentless timer counts down; there's no pause button. This stress reveals the truth: under pressure, people become more honest about gaps in their preparedness. That's valuable because organizations often sugarcoat weaknesses—until a simulation forces real reactions. Bob explained an example crisis scenario: a business email compromise (which he says is currently a dominant incident type). A financial firm discovers a customer wired money to a “new account” supposedly sent by the CFO, yet the CFO didn't send it. As the story unfolds, participants learn the compromise likely affected many customers, not just one. The game surfaces operational realities executives often miss: internal rumors, uncontrolled communications, legal exposure triggered by words like “breach,” and the need for an “event mode” communications policy that calms the organization and prevents chaos. AI scenarios and new risks IRGame also focuses on emerging AI-related risks. Miller says they ran what they described as the first AI incident scenario at a national security conference (IT Nation Secure) and now maintain multiple AI scenarios. The point is not to create fear, but to provide a safe environment to practice decisions around new threat patterns. Practical cybersecurity guidance for individuals and small businesses Bob emphasizes that cybersecurity is no longer optional and that AI strengthens attackers as well as defenders. He predicts that in 2026 smaller businesses will face increased targeting, because automation lets “two dudes and a dog” run campaigns that once required larger teams, making up revenue in volume rather than big single payouts. He also notes that cybercriminal ecosystems now resemble legitimate businesses, including tools, support, and organizational structure. Bob recommends baseline controls that are realistic for small organizations: unique passwords, password managers, multi-factor authentication, training on phishing, cyber insurance, and economical endpoint monitoring (EDR/MDR). These measures raise the cost for attackers so they move on to easier targets, though no control is perfect. On password managers, Bob uses Keeper and mentions 1Password and others. He strongly warns against saving passwords in browsers. He also flags emerging concerns about AI-enabled browsers that maintain a large “context window” across many sites, potentially increasing risk if compromised. On online exposure to your information, such as emails and staff info on websites, he advises sharing only what's necessary. Data can be scraped and used for phishing and impersonation. Deepfakes and better-written scams are making social engineering harder to detect. He also notes that much personal data is already exposed through breaches, citing Louisiana's DMV breach as an example of widespread data loss where every licensed driver's Social Security Number was compromised. Incident response planning and insurance pressure A recurring theme: organizations need an incident response plan and must practice it, especially as cyber insurers increasingly demand proof. In a room of 50+ attorneys he spoke to recently, Miller found only three had a plan, and none practiced it. He warned that future claims could be denied if companies claim they had plans but don't demonstrate practice. Trying IRGame for free IRGame offers free public sessions: the last Friday of every month, sign-up available via their website. Miller notes they also post recordings and content online (LinkedIn and YouTube). Visit https://www.irgame.ai/ for more information and to sign up for a free public session. You can also see how IRGame works by visiting its youtube channel at https://www.youtube.com/@IRGameify Personal note: music and creativity Outside cybersecurity, Miller is a musician, primarily blues/rock, and often appears on video with guitars behind him. He draws a parallel between software development and music: both require creativity within rules. He argues policies and procedures aren't bureaucracy—they're like scales and tempo: structure that enables effective performance under pressure.
Wild experience with Spam in RMM...didn't know people actually buy that stuff, how to deal with elbow pain and other injuries in your programming, and the wild eyes are back.Join The SwoleFam https://swolenormousx.com/membershipsDownload The Swolenormous App https://swolenormousx.com/swolenormousappMERCH - https://papaswolio.com/Watch the full episodes here: https://rumble.com/thedailyswoleSubmit A Question For The Show: https://swolenormousx.com/apsGet On Papa Swolio's Email List: https://swolenormousx.com/emailDownload The 7 Pillars Ebook: https://swolenormousx.com/7-Pillars-EbookTry A Swolega Class From Inside Swolenormous X: https://www.swolenormousx.com/swolegaGet Your Free $10 In Bitcoin: https://www.swanbitcoin.com/papaswolio/ Questions? Email Us: Support@Swolenormous.com
Sail the seas of tech and AI with experience and confidence. Gavin Garbutt, Co-Founder and Chairman of Augmentt shares how MSPs must evolve to secure and manage Microsoft 365 and SaaS environments. Adopt a security-first mindset, and dramatically increase technician capacity through standardized Microsoft security best practices; through a unified Microsoft Security Management Platform designed for MSPs. Gavin outlines why “blocking and tackling” fundamentals—leveraging audits and maintaining a consistent security posture—remain critical as MSPs prepare for AI-driven growth. Key Highlights: How Augmentt represents the “next generation of RMM” for Microsoft 365, Intune, Defender and SaaA visibility. Intune Autopilot enables MSPs to standardize, audit, and deploy policies across multiple tenants. 'Secret Sauce' for fostering successful partner and customer relationships. Series A funding, strategic partnerships and marketplace strategy (including Pax8) accelerate innovation and scale. Gavin's vision for unified security, AI enablement, and helping MSPs become more profitable. The charge to go from being reactive to becoming proactive; for 10,000 users per tech and 5x revenue per tech. From sailing the open seas to navigating the channel's next wave, this conversation delivers practical insight for MSP leaders planning for 2026 and beyond. Visit augmentt.com/ to learn more and to take advantage of a free security audit report & tool. Timestamps: Audit as a Best Practice 13:31 Quickfire Questions 32:45 What to Expect 36:26
The episode reviews the outcomes of predictions made for 2025, highlighting the evolving role of automation and AI in Managed Service Providers (MSPs). Key findings indicate that while generative AI has improved data accessibility, it has not fully resolved existing reporting issues related to data quality and governance. Additionally, the anticipated widespread adoption of autonomous IT systems among small and medium-sized businesses (SMBs) has not materialized, as many still rely on traditional remote monitoring and management (RMM) tools. The episode emphasizes that AI governance and advisory services have become central to modern MSP offerings.Further analysis reveals that while AI-driven legal services gained traction, MSPs have not widely adopted these as packaged offerings. Instead, they have focused on AI compliance and regulatory advisory services. The discussion also touches on the mixed results of fraud prevention becoming a standard service, with significant growth in some sectors but uneven adoption across the board. The episode concludes with a scorecard of predictions, noting a few clear successes in AI governance and readiness consulting, while highlighting a notable miss regarding decentralized MSP models.Looking ahead to 2026, the episode presents several predictions that reflect the increasing importance of automation in IT services. It suggests that MSPs whose revenue models still depend heavily on human labor will face pressure to adapt, as automation becomes the primary driver of service scalability. The discussion also raises concerns about accountability in automation, predicting that individuals may be held responsible for failures in automated systems, emphasizing the need for robust governance frameworks.The implications for MSPs and IT service leaders are significant. As automation becomes the production system for IT services, providers must focus on governance, risk management, and advisory roles to differentiate themselves in a competitive landscape. The episode underscores the necessity for MSPs to evolve their service offerings and business models to align with these trends, ensuring they remain relevant and capable of delivering value in an increasingly automated environment.
Alex Berninger, Senior Manager of Intelligence at Red Canary, and Mike Wylie, Director, Threat Hunting at Zscaler, join to discuss four phishing lures in campaigns dropping RMM tools. Red Canary and Zscaler uncovered phishing campaigns delivering legitimate remote monitoring and management (RMM) tools—like ITarian, PDQ, SimpleHelp, and Atera—to gain stealthy access to victim systems. Attackers used four main lures (fake browser updates, meeting invites, party invitations, and fake government forms) and often deployed multiple RMM tools in quick succession to establish persistent access and deliver additional malware. The report highlights detection opportunities, provides indicators of compromise, and stresses the importance of monitoring authorized RMM usage, scrutinizing trusted services like Cloudflare R2, and enforcing strict network and endpoint controls. The research can be found here: You're invited: Four phishing lures in campaigns dropping RMM tools Learn more about your ad choices. Visit megaphone.fm/adchoices