Podcast Episode

[59] – Special Episode Recorded Live from the Acronis #CyberFit Summit in Miami. FT – Dave Sobel and Karl Palachuk

Recorded live and in person at the Acronis #CyberFit Summit in Miami, Chris and Rayanne are joined by Dave Sobel and Karl Palachuk for a special face-to-face episode.

Show transcript

Welcome to PSA Impact, your podcast for all things PSA, RMM, and MSP, with your hosts, Raeanne Buccianico and Chris Timm. Learn how to get the most out of your PSA tool and manage your business by maximizing profitability and increasing efficiency within your MSP business. Let's listen in. Hello, everyone, and welcome to a special episode of PSA Impact with your hosts, myself, Chris Timm, and my co-host, Raeanne Buccianico. We are coming to you live from the Acronis CyberFit Summit in Miami Beach.

And it is a special episode, indeed, because, one, it's the first time we're recording this while we're in the same room, and so it's really great to see you live and in person and instead of Zoom. And two, we also have two very special guests with us. Awesome. So, without further ado, do you want to tell our listeners who our special guests are and what the topics are that we're talking about today? Sure.

So, today I have Dave Sobel, and we also have Karl Palachuk. And neither of you have to introduce yourselves, but I'm going to give you that opportunity anyway. Do you want to say killin' it? Like, one, two, three. Killin' it!

We laugh because we do another podcast together with our colleague, Ryan Morris. Of course, Karl's written a ton of books. I now make a jerk of myself on podcasts and have lots of opinions. That's a quick way of telling what we do. Yeah.

Well, it's your opinions, I think, that intrigued me to ask you to join us today because I've got a lot of questions, or we both have a lot of questions, and we want to touch on three very specific topics. And the first one is going to be about the vendor foothold in the IT community. Second then, Chris will start asking questions about cybersecurity, and then we're going to wrap it up with some predictions. Okay? Okay.

So, I think it'll be a lot of fun, and just jump right in and talk, you know, with whatever comes to mind. So we've got two major vendors having a strong foothold in the IT community. My first question is, how large do they have to get before they're no longer relatable to the MSP, and are they already there? Oh, well, the easy answer is they're already there, in my opinion. So I think there's a point at which the focus is no longer on customers or vendors or partners.

It's only on money and widgets. When you get to the point when it's all about money and widgets, the customer service becomes irrelevant, and the end user becomes irrelevant. And I do think that at least two of the vendors in our space are there. See, I come out on the other side of this. They're all unrelatable, and they're all relatable.

It's simply a matter of who to who. So I've posited a lot that thinking really needs to be about the type of vendor and the type of provider and the matchups. This industry has benefited from lots of founder-led organizations with lots of vendors that were also founder-led. The transition from those vendors to become equity and finance-led or public is a natural progression for those organizations, yet feels unnatural for the still founder-led business that is used to them looking one way. We've done business with Microsoft for as long as we've been in business.

They're exactly the same as they've always been. They really have. From a financial point of view, they've always been public. They have executed slightly different strategies, and then you may fit or not into their strategy. I would say this.

You can't give good customer service without knowing exactly who your client is. And all vendors start out small, and they know exactly who their client is. And then as they grow, they're like, oh, we need more clients. We need more people to sell stuff to. And then they lose sight of who their end user is.

And that, in my opinion, is what happened to Microsoft. Maybe. But I think it changed. See, I think that's what happened. And the actual disconnect is what it is.

All vendors are a match for some customer. It's just when you aren't that customer anymore, perhaps, then it feels uncomfortable. Right. Well, that is what happened to Microsoft. So do you think that the time is right for smaller vendors to come in and start to compete against the large conglomerates?

I mean, is there a market for them, for the smaller MSPs, because there's a vendor out there that might now relate to them? So Ryan's not here, but he would talk about what we call disruption really is find a place where nobody is doing it well, get a toehold, and then exploit that like crazy. That opportunity is everywhere in this industry. And the bigger that these companies get, the more of those toeholds emerge. And I also think that the massive growth of cybersecurity just leaves so many gaps that need to get filled.

And anybody who fills those gaps has a toehold to grow. And remember that the market conditions have changed. So we're sort of dancing around it. So I'm just going to throw it out there. Like, if you're talking about the RMM space, right, which is the one that everyone loves to talk about, because they're intensely passionate about their RMM tools, right, they all care so deeply about it.

I'd make the argument that that tool space is no longer relevant, that actually that's not an important toolkit anymore. And so thus, is it right for disruption? Well, I'm not sure I'd put money there if I was building a new product, because I don't think that's a valuable product space anymore. I think mature companies are milking what's left in it. But if I was disruptive, I would not.

And by the way, I have told investors this. They call me and ask. I said, don't put money there, because I don't think that's the space. I'm much more interested in a space like SaaS management, which I think is where things are in the future. If I was looking, I would say, like, look, incumbent players aren't investing there.

They're holding on and milking the maturity in their current space. They're not putting money into SaaS. I think that's where the growth is. If I was looking to be disruptive, that's where I'd put my money. Yeah, I don't think there's any disruption available in the RMM space.

I agree with that completely. I think disruption is in everything else within our space. Exactly. There's always a space, and Carl's exactly right, and Ryan would be the one to say, there's always a space for disruption. The trick is you've just got to identify the right ones, and then you've got to have a good piece of that.

Right. See, RMM has been a race to the bottom for 15 years. Yeah, and they found it. Right. And the proof that they found it is that Microsoft, which has now renamed Intune into something else and then renamed it back to Intune, that's what they're offering instead of an RMM.

And SolarWinds has said, yeah, we're not going to compete with them. We're just going to adopt that as our RMM. Or, by the way, and I'll call it out from our friends here at Cronus this morning, in the keynote, we're talking about security, security security, and then offhandedly, Patrick, the CEO, drops, oh, and we've got that management and automation, too. He completely dismissed the whole space. Because it's a checkbox.

Right. Oh, yeah, yeah, yeah, we have that, too. It's not actually strategically important. He's got it. He happily has it, but just goes, oh, yeah, yeah, yeah, let me check the box.

We check the checkbox. It's not actually an important piece. Well, while we're on the topic of Acronis, do you think that Acronis is interested, or maybe even some other large vendor, interested in entering the PSA market? Oh, well, obviously. I mean, part of Acronis' job is to build everything into one big bundle and have as few agents as possible.

They don't have to build another agent in order to have a successful PSA. So with what they're doing with automation, they're just doing tickets through automation and so forth. So they're an inch away from being a PSA. Yeah. I mean, Acronis is a funny space for me in that I think it's overblown on its importance because it's important for the PSA vendors for you to feel that it's important.

Just going to put it out there that you're on the PSA Impact Podcast. You're right. Let me read first what I just said. But that's, by the way, my statements are all true about the vendor importance of it. I don't think any one of us would argue with the fact of you need good business operations in your business.

You need a system and a process for doing that. That could be pen and paper, right? A good process does not require a complicated tool set. It is much more about the discipline of the process than it is the tool. A good tool makes you very good at doing that.

Those I think are very, very true, and I think it's important to select a good tool. But am I bound to the PSAs, and I'm putting that in air quotes for you listeners, meaning implied by that, ConnectWise and Autotask? They're fine pieces of software that are now 20 years old. There's also ServiceNow. There's also implementations of Financial Force against Salesforce.

There's also a slew of smaller players. Run your business in a way that makes a ton of profit. I will say we are blessed to have an industry in which we have CRMs built specifically for our industry. In my mind, it is critical to have a good PSA and to use it every day. That's the key to success.

There are too many people who have a PSA, but they don't have processes to make it successful. Carl's point is the super important one because he's talking about having it and then using it correctly. There are too many people that go, I own it. Now I have checked the checkbox. Okay.

That's why you need PSA consultants, right? There you go. Just a question around the PSA and RMM. Do you think that PSA companies on their own without an RMM element, are they kind of doomed? Are they dead?

Do you think PSA should be something on its own or should we – I think if you've got a great PSA that doesn't have an RMM, you might actually have an advantage. I think that the smaller companies that don't say buy a thousand products from me, they just say buy one product. I think that they have a serious advantage because they are able to say, I will be able to change stuff for you and I don't have to worry that it's got to integrate with all these other things, right? It's hard because folks like ConnectWise. ConnectWise competes with Salesforce on Salesforce's model.

They're all about the API. But if you say, I've got a standalone product and it's going to be awesome and kick-ass and we will listen to our users and we will fix it as needed, I think there will always be a market for that. The trick to that is understanding the financials of the vendor on this, right? The reason that it is harder to be a standalone PSA player is you are selling just to the MSP, the consumer of the product. The reason they like products like RMM, backup, email security, all these other things is that it is the difference between a sell-to product and a sell-through product.

Sell-to is you sell one level down. You sell to the person that consumes it. They buy some licenses and they go. A sell-through product is amplified. You are getting the ability to do all of the growth of the customers on the other side.

It's, by the way, why this whole space is awesome. It's because if you're a software vendor in this space, you have an army of MSPs, IT service providers, that are going out and selling on your behalf and exploding your reach. But you need sell-through. RMM is an example. You have lots of endpoints and every time they add a new customer, you grow.

Not true with the PSA. They only grow when it grows by engineer or whatever that license is. To answer your question, it's just financially harder. Is it better? I don't know.

I haven't figured that math out. The vendor is just a lot harder. It's why they are incentivized to do the two together. The PSA tools that do have them joined together, normally their model is that they sell per endpoint rather than per agent or per engineer. Right.

It's because it's better money. The math makes much more sense for the software vendors. To your question, if they can solve a way that makes them money and drives more revenue, then that's the decision that will go along with it. It gets back to customer service. You can have any model you want as long as you make money.

Southwest has a very different model from Delta. They have two different sets of customers. You can have a PSA that is focused on individuals and markets in a way that's different from everybody else. As long as they are making money, it's all good. By the way, Carl has highlighted such an important point here.

Identifying the right customer to consume that. There isn't one answer. There are a gazillion different ones. Today, there are more types of IT service providers than there were 10 years ago. As every new generation graduates from high school and college, they've got a different way of looking at the world and they need a different tool.

Does a $36 million multi-location, multi-country MSP look the same as a $4 million one? Looks the same as a $500,000? No, they're totally different. They've got different challenges, different leadership changes, different HR department problems. The processes you guys are recommending and working with the building look totally different.

The tool may not be the same. Let's move on to security concerns within the industry. What do you think the number one security concern is for MSPs and business owners? It should be liability. Being left holding the bag.

That is the number one thing. One of the biggest things that's happened in the last five years, but really more like five to seven years, is that the vendors have figured out that they need to lock down their agreements so that they are not liable for anything that happens remotely related to their software. MSPs have not caught up with that. They have not done the same thing in their agreements. There's this gap where the only person who can be held accountable for a major incursion is the MSP, not the vendor, and certainly not the client.

Like it or not, people always say, my clients love me, they would never sue me. Nope, but their insurance company sure as hell will. By the way, you've been selling trust for the past 20 years. You go in, you're a traditional MSP, you've grown up the old school style. Literally part of the old school sales pitch on this is, I will take responsibility for all things technology.

We get in the DeLorean, we go back and talk about the way we sold managed services. Part of it is, we will take responsibility for all of that. Well, and the big $1.7 million case from 2020 is basically, you said, we'll take care of the security, you take care of your business. Okay, well. We trusted you to do that and you didn't, and now we're suing you.

So like, literally your question on cyber is like, the number one is that pressure of being trapped in the middle. You're trapped between a customer who wants to offload the risk and the vendor who wants to accept as little of it as possible. So I'll start there. I think one of the things that you look for is vendors that are more interested in a collaboration around that. There are vendors that offer warranties, that couple product plus insurance.

There are strategies around this to take a different approach, but I think to answer your question, the number one concern is being stuck holding the bag. You know, that's really interesting because the MSPs are being held accountable and they didn't even recognize that these things were happening to them and now they're so far deep into it. That's why I think the MSA, the Master Services Agreement, everybody's now scrambling, how do we get this updated and reworded? So then if they do that, who will be holding the bag? Do we then push the liability out to the client?

Somebody's got to hold that bag. The really good news is that eventually, and I don't know how we get there because there's going to be a shakedown, but eventually what's going to happen is you will not get insurance unless you do certain things. And when you do those certain things, you will have relieved the MSP of the liability and the vendors of the liability. And so it will be the client's insurance company eventually is going to have to say, look, I'm going to make it more and more expensive every year. Like insurance is going to be ridiculously expensive, but I'm also going to make sure you have to go through this checklist and if you don't, we are not paying out a nickel.

So it becomes the MSP's job to verify that everything on that list actually got done. And we've had a lot of years of insurance companies insuring people without making them do anything. They just believed and of course nothing got remediated. And then we've had MSPs who have sold these contracts and not done the remediation. And those bad actors need to grow up.

And so there's a big day coming. Yeah, and it's funny because I'll throw in, remember the movie War Games? Love that movie. I love that movie. And you know the only way to win is to not play the game, right?

So I will challenge the assumption on your question. Why do you plan that you're going to need to go down this route of insurance and claims? Why are you not planning that when the breach happens, you simply run your emergency preparedness plan and tell the hackers to F off? Like run that plan, right? And your strategy is we have planned for the emergency downtime.

We understand what we're going to do. We have really good battery. But that's kind of a 9-11 question. You only plan for the stuff that you've thought of beforehand. And then afterwards you plan for the next thing that you hadn't thought of.

Because I have always said, every time I hear about some ransomware, like, oh, God, why do they just have a BDR? Push a button, get back in business, and we're all good. But that doesn't do anything for the exfiltration of data. That doesn't do anything for somebody holding them hostage. But you've hit on the interesting bit.

So part of your strategy as a business, and I think there is value in consultants, IT consultants working with customers on this, is making sure you are only collecting the data you need. Be in the data governance business and also make sure that you are only collecting the things you need. That you're making sure that in the event that information is exposed, that you have done the bits to reduce the damage. Because it will get out. The data always gets out.

Remember also that what we just went through in the last few years is what all of our clients are about to go through. Like, if you're an attorney, people are after not the attorney's data, but the attorney's data is all of their clients. The accountant's data is all of the accountant's clients. And that's really becoming a big thing. Like now, the insurance company is like, oh shit, that's going to happen with accounting.

We should start nailing those guys. And I mean, we've seen breaches in vendor software, password leaks, that kind of thing. And what do MSPs need to do to protect their client data? Because all of that is obviously sitting in the PSA tool. And now you've got all these vendors integrating into the PSA tool.

So what does an MSP need to do to make sure that they are protecting their client data? Recognize it's going to get out. That is actually my simple answer is you cannot win that battle. You cannot win the protect battle. What you can do is minimize it.

And I'm not being dismissive of saying like, I'm not saying leave the locks of doors of the house open. But everyone always likes the house analogy saying, well, would you buy locks? Of course I'd buy locks. Of course I'd close my door. But in my home, if I accidentally leave the lock open for five seconds, a horde of attackers do not stream in the front door, right?

Like I cannot be that good. But what I can do is I can make sure that I have done the things properly to minimize it, and I've also planned for the incident and know this is what's going to happen. This is the execution of the plan on the other side. I'm going to invoke my insurance. I'm going to have the bits in line, and I'm going to know that that is part of what happens.

And I'm going to plan that side of it. And Carl is right. It won't be perfect. Yeah, and I think that we as an industry need to literally do everything we can to work with the insurance companies to say, look, let's build something where we say we offer these services. If you say yes, there's a price and there's a checklist.

If you say no, good to go. I'm relieved of liability. The insurance company is relieved of liability, right? You said that you don't want to do this. And so it's not that you're giving up by saying that it's going to be released.

You don't have any control over that. That's the future. And if you assume it will be released, then at least you can build some kind of a response around that. Exactly. Well, I mean, so what I always say to my consulting clients is, you know, when they've got stuff integrating in, make sure that you're locking down those API accounts as best you can, right?

Because by default, the API accounts have full admin access. And I see everyone just leave them on. So, you know, if a third-party product gets breached, then it can access the PSA and delete all the data and all that kind of stuff. So, you know, that's the first step, I think, is to go in and just make sure that all of those API accounts that are integrating in are locked down as best you possibly can. Or be very aggressive about which of those trusts you're actually willing to do.

Do you need to integrate with every single vendor for every single thing? Right. It's kind of like – it's like a phone app, you know. Do you really need that? Do you really need that?

Do you really need that? And I would encourage particularly the savvy business owners are going to do a cost calculus of, you know what, I do value all that data. And perhaps, just perhaps, a person keying that in is worth it because then I have not exposed and I have managed that data security. Because data entry people, lasso check, pretty cheap. A lot cheaper than breach insurance in some cases.

I will also say that, you know, when I had MSP, we switched PSAs three times. We switched RMMs three times. If you have good processes, any PSA will get those done for you. And so you, in my opinion, I think you should not put so much stuff into your PSA that it makes it impossible to move. And all the stuff you don't put in your PSA increases your, you know, your happiness on the day that you get breached.

Carl Stahman has literally just revalidated our first conversation of saying you should invest in doing it really well on the process side. Be really good on the process. The tool will flow naturally, but then you can replace it too. And so you invest in doing that really well. But don't use your PSA as a dumping ground for all the information for all of your clients and like, oh, where can I put all the secure information I have in the entire universe?

I'll put it in that one thing. And again, think to – you've got a model to think about. Think about the model of, you know, I'm going to throw in the U.S. government security, right? They have a tiered model, right? There's secret.

There's top secret. Then there's secure compartmentalized, which is only need to know by the right people at the right time, briefed in, briefed out. Not all data has to be managed by all people at all times. Don't whine about vendors who give themselves the highest level of authority when they don't need it. And it's only because they're too lazy to program individual – but we do the exact same thing with our technicians.

Oh, you know, somebody might need that. Somebody might need the password to that attorney's personal email. So we'll put it in the PSA. So perhaps they should follow a process and ask for it. Yeah, I can't tell you how many times I've gone into a PSA and saw, like, the entire staff all has system admin rights.

Because they didn't really understand how to set up, you know, the different security levels. Or they didn't bother to take the time to look at that a little more in depth. But back to your comment, Dave. You were saying about, you know, what apps do they really need, right? So are you saying best of breed, but not all of the eggs in one basket, right?

So what I'm talking about, I guess, is more about vendor bloat on the end. I'll call it tool bloat, right? Okay, tool bloat. Because it's my experience that we're all kind of engineer types by background, right? We like buying new shinies.

We like new toys. We like new – and every single time you easily will fall for the, well, if I have one more tool, it'll solve it all out, right? And you end up with this giant collection of tools. I'm a little less worried about the raw number of vendors and much more worried about the raw number of tools, right? Because it's just real easy to fall into this thing of I just need to have them all and then it will magically solve itself.

I did a webinar about this a couple of years ago and I literally took a picture of my kitchen drawer, that kitchen drawer, right? We just got like two or three different kinds of corkscrews and, you know, it's got a bunch of stuff and a lot of overlap in what they do. But you know what? There's a lot of those tools I haven't used in years and I should just throw the damn things away. Right.

But we don't do that. House cleaning is well with the tools that we paid for because there's always one little thing we want to keep and it's like – So there is some value in having less vendor relationships because as humans, it's easier to manage those less relationships, right? But you want to separate my process of running my business, i.e. the sales people I must interact with, the invoicing I must interact with, versus the technical integrations and the technical tool sets because I think they are actually two different things. And I mean the thing about tool bloat is you're saying, you know, it's bad enough that MSPs don't set up their PSA correctly. Now they've got all these other tools that they've also got to set up correctly and none of those are doing what they should be doing and they're thinking it's solving whatever problem and they're just buying another tool because it's cool.

I mean like I have teased for so long that half of these little tools are things that should have been features in the PSA or the RMM. Right. And they just should have done it like – but actually, you can probably get 60% or 70% of the way there with the core functionality of the tool you already have. Maybe you just ought to spend your time there and be better at using the tools you have than thinking you need yet another one. Well, we're also intoxicated by automation.

So if I could buy one little bit of automation, like for something I do seven times a year, maybe I don't really need to buy that at all. I mean but if you buy it and then you never set up the automation side of the thing, what's the point? But you set up the user and he's got unlimited control. And by the way, you're spending money. That impacts SG&A at the very minimum.

You are spending money on that thing. Shall we move on to predictions because I want to make sure that we have some time. Uh-oh. Okay. So I've got some questions, just some basic questions of like where do you think life is going in the future?

My first question is will ransomware stop? And if so, how? Well, no. And what will replace it? I don't think ransomware will stop.

I think if we are good, we can try to make it irrelevant. I think right now that the technology that we need to make ransomware irrelevant has existed for over 20 years. We just need to have everybody have a good backup and disaster recovery system. And that's going to be different for different sized companies, but all that technology exists. So ransomware can be made irrelevant.

Cyber security, different story altogether. Right? There's lots of threats besides ransomware. But I think ransomware has already morphed into its next generation with extortionware and other things. And the bad guys have now got agents that have been sitting dormant inside our machines for 15, sometimes 20 years.

So the next generation is going to be getting rid of old code in the backup so that when we restore, we don't restore all of those weaknesses exactly to where they were the day before we got ransomware. Yeah. Carl is totally right on this. And on top of that, extortionware is already here. That's the next gen.

Business email compromise being the next bit. And I've just railed against tools. I am actually hopeful that some of the move on standards around things like past keys is going to go a long way to helping with some of these problems. We are a long way from that becoming a thing. Even though the technology is rolling out, user adoption is going to lag forever because of just all of the things with users.

But I think this is going to be a continual cat and mouse game for those of us at a low level. I will say that I'm going to throw in the other curveball of I'm hopeful that what we're starting to see at a governmental level is now going to start doing. Some of the White House just had its second round of ransomware summits talking about cybersecurity. There is actually a State Department division devoted to dealing with diplomacy around cyber. It's now specifically been cited as a factor in the Ukraine conflict.

In an interview I just listened to recently, we're talking about we knew about the day they were invading Ukraine because Microsoft told the U.S. government that they'd seen the spike that they were expecting in business email compromise. A day before the tanks rolled. Governments are playing a role in here. I know it's popular to be dismissive of all that stuff, but government works over time. They will get more to it.

It's just going to take a while. Do you think a global solution is actually possible? Do you think that the United States can collaborate with other countries and other countries can collaborate with the United States to actually come up with a global solution or is this an individual? I don't know about a big, big solution, but for specific problems, I think we can come up with something. I always think of the analogy of EDI, electronic data interchange.

It started with big companies like Sears saying, if you want to sell to Sears, you have to take EDI. So then all these manufacturers started doing EDI and then they went to smaller stores and said, if you want to sell our products, you have to do EDI. We can do that and they've recently railed against SMTP. SMTP has been outdated for roughly 25 years. Why are we still using it?

Well, we're using it because everybody on earth uses it. Well, okay. Let's stop doing that. But that starts with the big companies have to say, no more SMTP. You have to do IMAP or whatever.

Let's move to a new standard. And to give an example, it's a funny conversation I'll say. I literally had this argument with somebody recently who was like, well, I've been working on that for 40 years. I've been trying to get rid of SMTP. And I said, yeah, but you know what's changed?

The cost of email problems has actually skyrocketed with business email compromise. We're now in a situation where the cost of that as an attack vector has changed the dynamics of that product, right? And whereas 10 years ago, 15 years ago, well, you know, like it's not that big. But now it's a specific attack vector. And if you layer on, if we're going into predictions, we're actually in a world where SMTP has also been centralized.

Most email flows through Gmail and Google Workplace, Microsoft 365. Those two companies saying we are going to move to a new secure identified standard for email. Boom. Done. Right.

Done. Everyone else is then forced to. That's actually a benefit as well as a potential problem, right? I'm not going to dismiss the downside, but we want to make that change. Well, and it would actually be pretty easy to say, I don't care if you're in some little bitty area over here.

I'm going to read the email headers. And if it went through an SMTP server, I'm just going to nuke it. Like I will vaporize non-secure email. Right. Or label it different.

I mean, the first versions could be like I have secure email integrated into my Gmail or M365, right? Where there's, I get icons saying these are verified. We can verify these users. Well, what would happen is actually that it would say, do you want to open this? We recognize that it is SMTP.

And if you say yes, it brings up a VIC-20 emulator and displays your email. I want mine to be a Commodore 64. But so we can do those things. We've thrown out, in my rant, we throw out SDTV for HD. We threw out AM radio for FM.

We have made major transitions in lots of communication technologies. We can do any of the things we talk about. We have to have the motivation. Generally, that's financial. Right.

But there are spaces where it's civic. Where we as society have said it's important enough that we're going to do it. So obviously we're here at Acronis. So what do companies like Acronis and other security companies, where do they need to focus their efforts in the future, do you think? I will say Acronis has done a spectacular job on two fronts.

One is reducing the number of APIs. Like they've literally, you know, instead of seven agents, you get two agents. And they're both built by the same company. So that goes a long ways to not having all these other things. If you want APIs to connect to other tools, you can use those.

The other front is that they clean up backups while they're at rest. And that allows you to have a clean restore to the extent that it's possible. Right. You can't clean stuff you don't know about. But it's a huge move in the right direction.

So I think they're doing great stuff on those fronts, in my opinion. I'm going to be snarky for a second and say these vendors do not need my advice. They are really smart at creating. They are really smart on these things. So that said, I will say that the measurement I look at for most vendors right now is, do they have a healthy balance of build versus buy?

And I'm looking for a healthy balance. You can't do all of one or all of the other. You do need to do that. There are times where you're going to buy, you know, knowledge or investment or growth. But there's other things you need to build.

You need to be doing both. That is hard. That's why they make a lot of money. And I think the problems for me come, you create situations of disruption when you over-rotate on one of those two things. That you have either invested too much in just building and think you can solve all problems, or you go too far on just buy and you are not driving the ecosystem forward and you are leaving your flank exposed for disruption.

The other thing is that a lot of the bigger vendors, especially when they turn to private equity or to public money, they stop and start their development. They're like, oh, we have to freeze all development while we merge with another company. We're going to freeze all our development while we do this, we do that. And I think that having, you know, larger companies, older companies like Microsoft, they've got a budget for development and it never stops. Right.

It goes up and down a little bit, but it never, ever, ever stops. And I think that's huge because if you say we're just going to put this on hold and we're not going to fix anything and we're not going to reinvent anything for the next two years, that's a disaster in technology where things are growing exponentially. So that was really, that was cool. Thanks, guys. And what we always love to do is have a little bit of fun with our guests at the end.

So what I'm going to do is ask you both some random questions. And I've got a random question generator here. So I'll start with you, Dave. If you could speak only one word today, what would you say? Well, I can't use the censored ones.

Because if I could only say one word, I'm reasonably confident it would be a swear word. Because it gets really annoying. I know what that word would be. It probably starts with an F. It's probably the word I would choose, too.

Really loudly. Exactly. And I would get it out. I'm going to go with it. That's my answer.

Okay, good. Right. For you, Carl, what was the best thing before sliced bread? Oh. The best thing before sliced bread had to be peanut butter.

Because you could put it on a whole loaf. And you'd eat the whole loaf. Yeah. Hell, yes. I might have gone with the knife.

You know, because the knife is the one that actually slices the bread. It's the precursor to the sliced bread. All right. So, well, thank you guys so much for taking time out of the Corona Cyber Fit Summit to spend on our podcast. And that's all I've got today, Chris.

Yeah. That's all I've got. Thanks very much, guys. I really appreciate it. I love talking to both of you guys.

Thank you. Dave and I rarely get the chance to argue with each other. I know. It never happens. So we really appreciate it.

Yes. We appreciate you inviting us to Spar on your podcast. It's really cool. So all that's left for me to say is the PSA is the key to your business success. So go out and make an impact on your world today.

Thanks, Chris. Great to see you. Thanks again. Thanks, guys. Thank you for joining us today on PSA Impact.

We hope you've learned something and that you'll join us next time when we answer new questions posed by our listeners.

Want help putting this into practice?

Get in touch and we'll talk through how it applies to your MSP.

Let's Talk

← Back to all content