Summarize with AI
Open this article in your favorite AI assistant for a quick summary.
by Charles Weaver
Introduction
Until today, there has been no significant motivation through public policy for organizations to adopt proactive IT management and cybersecurity practices. A new and simple public policy technique, however, may be capable of producing dramatic change across organizations of all sizes utilizing a concept we can classify as managed services immunity.
Many cyber regulations and public policies have yet to produce meaningful change in reducing cyber-attacks or improving cyber defenses amongst public and private sector organizations. A quick look at the cyber insurance industry and its inconsistent approach to MSPs (Managed Service Providers) and end-user organizations should provide ample evidence of the work remaining to be done.
MSPs have been, and remain today, agents of cyber risk reduction. For the past three decades, MSPs have provided invaluable services to their clients in a variety of ways, including IT (Information Technology) infrastructure, security, and data protection, all achieving technology and business outcomes.
Since the beginning of managed services in the early 1990s, MSP's have made recommendations to their customers based on industry best practices. These recommendations, however, are not always followed. There are a variety of reasons why the recommendations of an MSP may not be implemented by the client: budget, complexity of use, and lack of perceived value, may all be accurate reasons for the failure of a client to adopt industry best practices and effective cybersecurity measures.
Reactive to Proactive Cyber Management
Public policy needs to promote proactive IT management and cybersecurity measures. The good news is the global community is already moving in this direction.
Indeed, nearly all major global cybersecurity frameworks and legislation are promoting a model of IT management which can only be described as proactive in nature. Put differently, it is impossible to meet these global cyber frameworks without first proactively managing IT. A reactive IT management posture simply will not meet the current cyber frameworks we see today.
NIST, CMMC, ISO 27001, Trust Services Criteria (SOC 2), Cyber Verify (Unified Certification Standard for Cloud & Managed Service Providers), GDPR, UK Cyber Essentials, data breach notification laws/rules, and others, all point in the same general direction: achieving improved cyber defensive postures from enterprise down to SMB (Small to Medium Business) organizations.