MSP Mastery Podcast
Welcome to MSP Mastery Podcast, the podcast for IT leaders, MSP owners, and service delivery professionals who want to elevate performance, improve processes, and stay ahead in the fast-changing managed services landscape.
MSP Mastery Podcast
Brenton Johnson on Agentic AI, Security Governance and Building a More Mature MSP
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Welcome to MSP Mastery, the podcast for MSP owners and leaders who want to build a better MSP.
I am Jeni Clift, joined by my husband and long time business partner, Nick Clift. Together, we draw on our experience to explore what is really working in thriving MSPs.
In this episode, we welcome back Brenton Johnson, Managing Director of Uptake Digital. Brenton joins us for a wide ranging conversation about agentic AI, operational maturity, cybersecurity, governance and the people and processes behind effective technology services.
Brenton shares how his team has moved beyond using AI as a prompting tool and is building human supervised agentic processes. He explains why useful AI depends on having good context, including structured information about clients, vendors, systems and past decisions. He also describes how curated documents can support service desk triage and help teams find relevant information without searching through large volumes of unstructured data.
The conversation looks at where AI can help and where human judgement remains essential. Brenton talks about reviewing scripts, limiting permissions, testing safely, following change management and recognising that AI may miss important details about a customer environment. He also shares why he favours tools that make data accessible and why he does not believe MSPs should build their own RMM.
We explore the changing relationship between IT and security. Brenton explains that IT is fundamentally about keeping people working, while cybersecurity requires businesses to understand who has access to what, what data they hold and what risks they are prepared to accept. He makes the case that security is a business capability and governance responsibility, not simply a technical task for IT.
Here is what we covered together:
✅ Moving from AI prompting to human supervised agentic processes
✅ Helping a team adopt AI and bringing people along with a technology change
✅ Why accessible data and open tools can help MSPs work more effectively with AI
✅ Using structured client and vendor context to support service desk triage
✅ Creating useful documentation from service desk tickets and change records
✅ Keeping human review, clear permissions and change management in AI enabled work
✅ Why Brenton does not recommend MSPs build their own RMM
✅ The continuing need for experienced developers to make important architecture and security decisions
✅ Understanding security as a business capability, shaped by risk, governance and budget
✅ Helping customers find a realistic balance between security needs and investment
✅ Why customer communication matters when security changes affect staff and business processes
✅ How business maturity, standardisation and good coordination between teams are connected
✅ The different challenges MSPs face as customer organisations grow
✅ Taking an incremental approach to improving operational maturity
✅ The value of peer groups for people working through difficult business and leadership challenges
We created this podcast to share real conversations and hard won lessons from people who understand the challenges of the MSP industry, and to offer ideas that can help you build a business that is both profitable and fulfilling.
Follow Brenton on Linkedin: Brenton Johnson
Read more episode notes at mspmastery.blog
Watch on YouTube at youtube.com/MSPMastery
Listen to the audio podcast at youtube.com/MSPMasteryAudio
Fundamentally, IT is about keeping people working. And then they go, okay, well, now we need to do a security capability. And security is all around who has access to what and the data and all this sort of stuff and really understanding risk. The more mature the business, the more it is standardized. The junior developers, the people who write code, they're gone. We don't really write code anymore. No one writes code anymore. Security through obscurity was really good back in the day before the internet. But now with the internet, security through obscurity is essentially obsolete.
SPEAKER_00Welcome to MSP Mastery, the podcast for MSP owners and leaders who want to build a better MSP. I'm Jenny Clift, and alongside my longtime business and life partner Nick, we draw on our 60 plus user combined experience to explore what's really working in thriving MSPs. Our goal with this podcast is to share the real stories and hard-won lessons that inspire and add genuine value to our industry, helping you build a business that is both profitable and fulfilling. This is MSP Mastery. Is Nick, myself, and today's returning special guest joining us again today because we pretty much recorded the whole episode last time before I could get a question in. So today I'm determined to ask at least two. So Brenton Johnson, the managing director of Uptake Digital, someone we've known for many years. He brings a thoughtful, independent perspective to the MSP industry and is not afraid to challenge the usual way of doing things. Brenton is passionate, as we spoke about in our last episode, about people, culture, leadership, but and also creating better outcomes for both clients and his team. We really enjoyed our first conversation with him and are delighted to welcome back to MSP Mastery. Brenton, welcome.
SPEAKER_01Thanks for having me back. Good luck for asking me questions this time around. I'm wishing you guys all the best.
SPEAKER_02No, it'll be fine, mate. It's been a few months, so you know. Yeah, we've I think I've seen you a couple of times, maybe at SMB OT in between. But yeah, it was good.
SPEAKER_00Okay, so let's start off as always, just sharing your personal and professional best from the last few months since we've seen you.
SPEAKER_01Yeah, look, for us, I feel like we've hit another level in AI. So we can actually I think everyone can sort of see the vision of where it was going, but now we have built out the data and the context and the tools, and now we're actually seeing this agentic future and how it can be done safely, professionally. It's been a huge change for us. And we've really moved from that sort of using it as a a prompting tool, or maybe it's pulling in some information to largely human in-the-loop agenc processes, and we're moving towards that really, really quickly. The big unlocker for me on that was just getting the team on board. And it was if you wanted a story for EOS, trying to get someone to adopt a new piece of technology in a really good way. It's like the visionary knows exactly what it all needs to look like, how it works, and then they're like, Why don't you guys get this? It's you could write a book on AI adoption on EOS at uptake, I reckon, because it's it just followed the exact same process, same paint.
SPEAKER_02I was gonna say it's a it's a journey, isn't it? Because you can have the great ideas and the inspiration. But the and the secret to good businesses uh is is able the ability to propagate that vision through the whole team. So I'd be really interested to hear how you did that. Because the AI thing is interesting because we do that conversation, it comes up with a lot of our clients that we meet with, and some of them are very anti-id, like, oh my god. Like there's one software development company we work with, and the guy's been there forever, and he doesn't touch AI at all. He sees it as a big, bad threat. And they go, well, yeah, if you don't learn how to use it safely, then that yeah, sorry, the threat is to you. If you don't learn how to use it safely, you're you're the one that's going to be made irrelevant.
SPEAKER_01Yeah, as for my personal best, things are still very good. Like we've just got really strong relationships with people on the team, having those tougher conversations internally, a bit more conflict, but in the right way. Things really good at home. So I don't know, I feel like I'm in a really good space at the moment. Uh I'd still love to have another hour in the day. That'd be nice sometimes. But also like, I don't know, it feels like I'm in a very uh very good p place at the moment, and I'm feeling very optimistic about things. I'm feeling more optimistic than I have probably all year, to be honest. So I think you know, I'm in a really good space, and I think it's reflecting out in the sort of work that I'm doing as well.
SPEAKER_00Okay, I'm gonna start with a question. As opposed to last time, where I think we're at 45 minutes, went, oh my god, I haven't actually asked a question. So let's start with tools, because in our last conversation when I went back and actually listened to it to to get today's questions, we kind of touched on this, but we really didn't get to dig into it as much as I would have liked to, because you've mentioned that you don't really use many of the traditional MSP tools that everyone else relies on as we did in our MSP. So what do you use instead and why did you go down that path?
SPEAKER_01Yeah, because I suppose when we started we weren't an MSP. So, for example, we use Zendesk for our ticketing system. It's got a very open API integrated with just about every tool on the market. We have a legacy pricing plan that makes eyes water when I tell them how much we pay for it compared to their ConnectWires bill. And yeah, we've just because we've had it, it's one of the first tools I ever bought. We've had it for such a long time that we're built on top of it and it's become like a ConnectWires for us. So it's like ConnectWise out of the box does this, but no one has the same ConnectWires. And once you get in there and build out exactly what you want, you get exactly what you want. So we've done the same thing with Zendesk. We've used Continuum in the past, they got bought by ConnectWires. We moved to Synchro, we've used Synchro, mainly just for running scripts and stuff, it's pretty good at that. Use Action One for patching. We moved to that because we found that none of the major tools really did a great job of patching. Action one seemed to do a very good job of it. So we move to that. Yeah, we've been using that for a while now and getting really good results. Uh the thing that we really liked about that tool was being able to see this sort of grid with colours on it, and it would tell you whether the patching is in SLA or not. So you would take a screenshot of this thing and send to the client, go, here's where patching's at. We're fixing this, we're fixing that, or we need money to fix these things because they're not really in scope and managed services. And yeah, clients instantly understand colours. They're really good at red, amber, green.
SPEAKER_02Yeah, no one wants a red button, do they?
SPEAKER_01Well, no one wants to send that to their board, so they're like, they go, what should I put in my board report? And I'm like, Well, you should really put patching status, and here's the SLO that we work with, and it's been good because it keeps us accountable as well, and it provides a really a really easy way for us to, well, for me to go and make sure that the team is doing what they're doing. So, yeah, look, we use a whole bunch of other tools, but yeah, we don't use Halo, we use ConnectWise. Makes it very hard when you go to MSP bots and they go, we can't work with you. But there's a lot of tools that we can't really work with. That being said, coming into the agentic era, we look like geniuses because all of our data is an open tool. One of my core beliefs is that you should be able to get your data out really easily, you should be able to API connect to it. When we do value vendor evaluation, that's a very key consideration. And yeah, because of that, now we can pull all of our data out into markdown files, run out of markdown files. We still need our tools to do the work, but being able to pull that context down onto disk. Like we pulled all the Zendesk tickets out, put them into a SQL light database. Well, I didn't I don't know how to do that, but AI did that for us, and now I have an offline copy of everything we've ever done. There's hundreds of thousands of comments in there, and it can just do it. So, yeah, so I guess it is a little bit different, you know, make the automation rather than say using Roost, although we're looking at Roost at the moment. Again, like main value of Roost is connecting to Halo, connecting to Connect Wires. And now with AI, I'm like, well, I can build connectors really quickly for these tools and use an 8-n or just API calls or scripts or whatever. So our ability to stand things up, we're far less dependent on the vendors than we've ever been. But it also doesn't mean you go and throw all your tools out because there's quite there's millions of dollars development in these things. There's lots of security, there's lots of this and that. So it is about making the right decisions on that stuff. You know, maybe something like CSAT, you might want to build your own tool. We use Nice Reply. But you know, on something like an RMM, I don't think MSP should be building their own RMM. I don't think MSP should be doing anything like that. But as far as like core knowledge database, you do need something that works really nicely with AI. So if your tool doesn't really have a good AI conversation, then you're in trouble. So that's where we're at.
SPEAKER_02And I think I think you're right with the because I've not seen anybody effectively use the built-in knowledge base in a commercial PSA to add value to ticket triage and solving the ticket because it's so dependent on the format and the way the engineers uh put the notes onto the tickets, it's like it's crazy. Whereas now with Ageny Gola, you can actually start to interpret those notes and look for some patterns and and bits and pieces. So I think the open uh openness of it is uh a good idea. So yeah, Brian, the the question the thing I want to kind of not not really challenge you on, just a question is that going down the RMM path, if my memory doesn't serve me correctly, most of the bulk breaches uh with MSPs have been through a compromised RMM. So wouldn't it be more logical to write your own that no one else knows about? That would you'd be less likely, less attack surface from that perspective to be more secure?
SPEAKER_01Or am I just dreaming in security we call that security through obscurity? So it does have a name. Security through obscurity was really good back in the day before the internet, but now with the internet, security through obscurity is essentially obsolete. It would be that old thing of like, we're gonna have a file share, it's not gonna have a password on it, but no one knows the how to find it, so it's secure. That's not you can't run a modern enterprise like that. The challenge is that as soon as you go into software development, I don't really care how good your model is, its ability to really understand corporate architecture, enterprise security, et cetera, it just can't do it yet. Even the frontier Astra models, they can do a very good job of like telling you problems with it, but fundamental architecture decisions are still being made by developers. And I think this is what people found out when they sacked all their developers, and then they realized, well, actually, we need developers more than ever. We just need really good developers now. So it's the junior developers that the people who write code, they're gone. We don't really write code anymore. No one writes code anymore. But the frontier, so the top developers, they're busier than they've ever been because they're the ones that are going there and going, okay, well, should we build our own RMM? Should we not build our RMM? How does that security model work? How do we make sure that you know we're doing the right things? And then as soon as your customer has to go through some sort of compliance audit, you have nothing to point them to.
SPEAKER_02So now you're creating Oh no, I'm not I'm not suggesting people should write their I'm not suggesting people should write their own RMM, but just sort of like for the audience, not for you, uh Nick, but it's very tempting.
SPEAKER_01I I think you've really hit on the nerve of it's very tempting because it's very easy for people to go and build these things and get them work, but to get them to scale and on the customer environments, I think, is a different thing.
SPEAKER_02I've heard of people and I mean whether you think Intune is an RMM or not, but I've heard of MSPs not using uh a secondary RMM, but but just using Intune for the Microsoft Stack and their own custom developed script and processes around that. And I'm assuming that that's where your own AI kind of harness or framework could work with Intune to a degree, although you wouldn't really want to give it full right admin rights to your in tune environment in case it had a hallucination, decided to delete everything. I don't know. Interesting thing, yeah.
SPEAKER_01Yeah, a good way, midway point is you can ask AI to write scripts that put things into Office 365 for you. So if you want to configure Office 365 the same way, and you can read a PowerShell script, but maybe you can't write it, or we can't all be Robert Crank. But yeah, if you can read it and you can go, okay, I'll it's changing this, or I don't really understand that, and then you get another model to review it and explain to you what the script is doing. So you get that sort of adversarial review across. Now you're getting to a high level of certainty. Also, you're deploying out all these policies without assignment, and then you're manually assigning them. So you can go and have a look at the portal, and it will show you in the portal all of the controls getting set. If you don't know what those controls are, you probably shouldn't be doing it. And it sort of goes back to that senior engineer, senior software developer conversation before. It's like, hey, like if you don't understand what these things do and what the customer environment is going to be like, and you don't follow a proper change management process, then it doesn't matter how agentic you are, right? Because there's always going to be those little things that that senior engineer knows, they know you know where the dead bodies are hidden, they know how it all works. And unless you've done a really good job of documenting that AI doesn't know. And it's more likely to miss stuff like that. I found sometimes is really good at picking up and it picks up little things like that, but sometimes it misses it. So you kind of do need to work together with the AI. You can't just sort of say, oh well, AI will deal with that or whatever. But there there is some really healthy middle grounds, I think, where you may not have you know a full comfort level of doing that. But maybe you can say, well, let's use Grokbot, for example. Not saying you should use Grokbot. Let's say you use Grokbot for an agentic experience because it's really easy to set up. But the permissions of the tools that you give it are read-only, or maybe you only give it access to the demo demo tenant, for example. You go, okay, well, my risk appetite is I don't really care what happens in the demo tenant. It's I'm just going to let it run in that, give it credentials to that. It goes, builds out the environment, and then I'm going to go run a tool like SIP over the top of it, SIP, and then pull out that config and put it somewhere else. But when you look at things like that, I would say 95, 98% of what you're doing, it should all be standard stuff. And you should be looking to industry leaders like Robert and Telpin and all the rest of them, who are doing all of this, right? Nick Ross, another one. They're doing all of this work. So you're much better off just buying their work that's already been validated, tested, deployed on thousand MSPs. That's a much better way of doing it rather than trying to do growing. But every now and again you do have that weird issue of where you need to assume link for someone, you need to do this. It's like, all right, let's just bring you back to the old days, Nick.
SPEAKER_02Yeah, and I think the old days, yeah, thanks, mate. I was trying not to say that today. But I remember back in the old days, you know, when we used PC PC Anywhere and we we had to we had a cluster of modems that we would dial into our remote sites and do all like kind of scripting that way manually before we discovered RMMs. But yeah, it's interesting because I think the advantage with AI and agentic work and that stuff, and it's an example of what we've done ourselves. We I built a basically a a mini CRM PSA just to run our own workflow internally. There's only three of us at the moment, and uh we so we manage the podcast, we do some other bits and pieces, some consulting coaching clients and and a bit of content work. And it's so I just built this thing and it was really we use advocacy for that because it's got every model in it, and it just helps you. And the great thing about it is we can I can deploy something, get it to write the release notes and explain what we've changed for this week, give it to everyone, and then get feedback and and within uh you know 24 hours of the feedback, I can make a change and iterate it and and it's all internal for us, right, in our industry environment. So very conscious that uh to make a product you could resell to someone externally, that's a completely different kettle of fission. Uh yeah, you've got to go through your security process and scalability and uh all of that stuff. Whereas to do a to to solve a tool problem uh internally in your own business, uh the vibe coding stuff works pretty well to proof of concept. But then if you're gonna roll it out onto a client's environment, then that's where you've got to go through all like the security stuff you were mentioning. And so I think everyone should be uh experimenting in this space, but yeah, be very careful. It's like rolling it into a live customer and just going, I wonder what happens if I do this.
SPEAKER_00Go test it on a customer and see what happens.
SPEAKER_01Well, yeah, our comfort level is very much we will keep the files on disk, we trust Claude, we trust Codex, Chat GPT, because Microsoft trusts them, basically. Microsoft's bringing Grok in, it's already in Copilot Studio. Once Microsoft trusts Grok, maybe I'll trust Rocket as well, but maybe I won't. So our trust level is like our own devices where we run scripts and we add files and we run essentially everything as a markdown file, very inspired by Linux. There's a model that's a model from Google called OKS, which helps you sort of define your document structure front matter, the metadata essentially. So there's a lot of like stuff around markdown files. You can use Obsidian as a viewer over the top of it, and then it can build the relationships and make that sort of more human-friendly. And with all of that, you still haven't gone off to the internet, you don't have an unencrypted database with no authentication on it that AI put there and ran out of tokens before it could do the security piece. Like all of this is stuff, right? You don't have all these problems. It's very simple. Everyone understands text documents. It's been on the computer since computer started. Like everyone knows how this works. There's no complexity to it, there's no software development capability that's required to support it. It's just files on disk. And I think you can achieve a hell of a lot. Like our triage process is largely automated now. We have about 3,000 documents that we've created with AI, based everything on our vendors and everything on our customers, except certain things where I don't want AI to know. We still keep some of the stuff away from AI just because it's, you know, you you don't necessarily want all your customers' data to be going off, even if you do trust the vendor. So yeah. And when we have the triage process run, we have a triage.md in both vendor and the client, goes off, checks that, pulls in the context that needs. So it might be like key contacts on holiday, put in the triage MD or the agent's MD, and then we can pull all that context in, and now we have a contextual solution. So it's like we use Huntress for our for our MDR, has really good MCP read-only. It goes off, goes, okay, Huntress isn't installed, you can alert for it, but sometimes just takes like a couple of minutes, but the alert triggers. So it goes off, checks the MCP, because that's it knows to do that from the triage.md, and the Huntress thing pulls it back, says it is installed, close the ticket. I can verify it's here. Here's the serial number, here's the host name, etc. And I I think standardizing is also very helpful. So all the device names are standardized, everything's standardized, everything's got unique identifiers on it. Like we're running it like it like an enterprise ISO deployment because it's easier because the AI already knows all this stuff. So it's just easier to align with what it already knows, rather than trying and teach it some hokey way that you've been doing it in your business, because you know, you can't do it in an airpro way.
SPEAKER_02And I was gonna say, I think that's something people don't realize is that you don't actually need to train the current AI models on how to fix a technical problem. They already know how to do all that stuff. It's just the uniqueness of the way you've got yours configured and and all you know connected together in your clients' environments that they need the the the knowledge on because the AIs have already consumed all the knowledge on how to fix every problem Microsoft's ever had in its history of life, and the same with Linux and the same with servers and the same with all that kind of stuff. So you don't I thought at the very start of this journey that we'd have to teach them like a literally like a two-year-old trainee, but it's there's a the even the base level of the base models has got a fairly good technical uh ability, I suppose, to solve the technical problem. And it's more about the context of how you want your workflow to work. So that's cool.
SPEAKER_01And what it needs, to your point, Nick, is it needs context. So it needs to know how does this connect to that, right? And when I go and look at ISO and have a look at like running you know a proper enterprise IT environment, that it's all the same stuff, right? So we made that decision to go pretty hard on that. Like our front matter might have 25 different fields in it. We do data classification on Every document now. We have audience, we have this, we have that, like we're running. Like I could not get anyone to get all this work done because just way too much work for an MSP and our customers wouldn't pay for that, right? But with the AI doing things like that, it's really just write the policy once, review its work, and then fix policy. But things like data classification, it's really, really good at that. It's like it it knows this is a HR document. You don't have to explain it. Hey, this is a HR document. And I think this reasoning level that's increased and particularly being noticeable this year has really opened everyone's eyes up to oh, all these crazy whack jobs that said AI is going to take over the world, we can sort of see how that's gonna happen. Because if you can provide the right context, you know, if they know that this is a staff member and this this conversation is about this, then you're gonna get really good results. But if it goes, oh, Brenton had a conversation about some guy called Joe, this happened, that happened, I don't know what this document's about. And that's what we we spend a lot of time doing. So we have databases for all of our clients, all of our vendors, uptake database. We're constantly pulling data in from Zendesk and other sources, and we're structuring that data in YAML files so AI can pull that data without having to go and search for it.
SPEAKER_02So it's like what managed services must be burning billions of token trees.
SPEAKER_01I wouldn't say billions, but this is probably, I'd say it's probably about 60% of our token burn or 60% of my token burn is actually just documenting at the moment. That's how we got to our 3,000 files. But now that we've got a good scaffold, it's really quite easy. It's like I'll give you a really good example that everyone should do. Go to your service desk software, pull every conditional access ticket for a client, build a document that explains exactly what changed, why it changed, whatever. If you don't know, come back and ask questions and it'll come back and go, we don't know why this change is here because the conversation happened in a meeting and the meeting transcripts gone, we can't sign any teams, whatever. It's like no worries, I will sit here and I'll answer these questions, right? So you go from having disparate tickets that has to go look up every time to a really tightly curated document with ticket numbers, change records, why the change was made, who approved it, all of this stuff. Like, I would kill for that, but I'm like, I'm not gonna pay an engineer, you know, 180 bucks an hour to sit there and create this documentation that they're probably not gonna have the time to go and read and review and look back to because the work's not that complicated, to be honest. But now that I have it and I can feed it into the AI, we're doing conditional access review, and it's like, oh, interesting. Oh, it might interfere with this one. What happened with this? Or you get security questionnaires, or you do this. So rather than sort of having to do all that work manually, you build out the context for the client and you say, Here, here is the context for the client, off we go, and you end up with much, much better outcomes than if you just keep prompting it. And I think this is where most people are stuck, they're stuck in the I can go get my MCPs doing this and this and this, but they're not pulling that core context down into curated documents, and that's a secret because you've only got million tokens of context window, you don't want it flooded with a whole bunch of stuff, you don't want to have to look through everything to try and find different things. That's why it gets inconsistent and misses stuff. If you have very focused tasks, like build me out conditional access documentation, I need to know this. And you go, go research some, you know, top Gs in the industry who know how this stuff works. Or what does ISO say about this? And then it says, this is what you should have in your documentation. I'll go, cool. So much better than me sitting there IDAD. Well, it is, and then and the the speed in which I can get something like that up, and now that becomes a template document, and then you say, right, I'm now happy with what that looks like for that client, create a template of that, build a skill around that, and then do it for all my other clients, and then build a freshness process to go and make sure that that's kept up to date. So you you end up calling linting, yeah, how I can technical terms, but very exciting space to be in.
SPEAKER_02Yeah, yeah, I can tell it it's interesting because I it's it's the you know, with AI and the work you do with that these days, you've got to describe where you are, give it the context of where you are, and give it the description and and the dream of where you want to get to, but forget about how it's gonna happen in the middle. When I started doing it, I thought I was trying to think logically how I would do it and give it instructions and I'll go to do this, do that. Now that's completely wrong. It's gonna it's gonna figure it out way better than I can. And yeah, it'll get it wrong some of the time. You just go back and no, no, that's don't go down that path to do this, do this, and you just give it a bit of a prompt back and a slap it around the ears and say go back and do it that way. But yeah, it's interesting. Yeah, it's good.
SPEAKER_01Yeah, and using like there's a skill we use called plan with files, and it just pulls all of the all of the stuff down, it writes it all into files as it goes, and that's a really, really strong skill for us. It runs our tokens halfway, it can pick up because it's all on disk rather than sitting in a context window. So there's one piece of advice for people getting started. It's like write stuff to disk, use cowork, and actually get things onto your device in markdown format. That's the best thing you can do.
SPEAKER_00So I want to just quite touch quickly on security, and then I'm gonna get back into AI. With all of the, you know, we talked about earlier MSPs getting compromised through RMMs, and I know security is a passion of yours. What are the most common security gaps you see now with AI, with the changes that are happening, and I guess the the way that the hackers are improving their systems, probably using AI to get even better? But how what are those most common security gaps you see, and how are you helping clients close them before it's too late?
SPEAKER_01It's a good question. I think you're dead right in the sense that it's getting more risky than ever. The risk is increasing, not decreasing on cybersecurity. And while we have tools like AI that can do amazing things and get security in order and really do a lot of that legwork that like, you know, like I was saying, data classification never would have happened, but now we're doing it right. So while we have all of that sort of automation and security on that side, there's also the other side of, well, the hackers are getting it. Also, the people doing this automation aren't necessarily skilled at it. So in the past, your senior engineer would write a script and your junior engineer would run it. Now your junior engineer is writing a script, and then the senior engineer is finding about out about three months later, going, Oh, did you know it does this and this? That's not good. Why didn't you review this? They've just put found some script online, or they've got AI to find something online, and they say make it secure, and they provide this sort of like direction to it, but they haven't actually gone through a proper process. And you know, I can't really blame people for that. I I think it's what we we're always vegan. We talked about last time, it's all leadership and management at uptake. That's what we focus on. And in the AI world, it's like two, three times more important. Governance is now one of the most important functions in our business. Like all we talk about is governance and non-executive director, she loves governance, she loves doing governance. I've never spoken about governance as much in my whole life, but when we're not doing the work anymore, what's left? It's governance, decision making, etc. When I go and look at security issues in businesses, it's all governance. It's all, you know, how much money are we re putting towards this? The actual execution of the security tasks is not the hardest problem. I think most MSPs, particularly with AI now, where they may not have been a bit intimidated, I can't use in-tune, I can't do that. You know, you can sit there now with AI and go, you know, how do I do in-tune? I'm a level one. How do I do in-tune now? I'm a level two. And it can take you through that process of i implementing security controls like ASR, absolutely critical security control. Very difficult for people. I remember Elliot Munro doing a podcast about it, I don't know, before the pandemic. And everyone's like, oh, you know, I'm like, hey guys, like 16 controls, but they used to have this weird way of doing it, Microsoft, and they changed it, and if you put it in the wrong place, you worse outcome or whatever. So there's some nuance to that, but AI will just go, don't do it this way, do it that way. And because it's a pretty established process that's been around for a while now, and that new way is actually kind of an old way now. It's really good at that. But then there's other things where it's very brand new and it's not really up to date. So you get it to research and it gets a bit confused and whatever. So practically speaking, I would say you've got to go back to governance, you've got to go back to sales, you've got to talk to customers about the risk. I feel like an old broken record when I say that. The customers are not buying security. Some of my customers are saying, Well, I want to finish security. And by finish, they mean basically start.
SPEAKER_02Yeah, yeah. Not not worry about it anymore. I don't want to have this conversation. Just make it go away.
SPEAKER_01I would say build the system, right? So security at its at its core is a system and it's a capability in the business. So they need to build a capability for security. And they go, Well, I need a capability in IT. I brought you guys in. You built out that capability in IT. Now we have onboarding, offboarding, process, we have laptop, refresh, we have this, all that core fundamental IT department stuff. That was a huge pain point for them. Their business didn't operate properly. Now all of that is sorted. There's a bit of patching, bit of security, but fundamentally IT is about keeping people working. And then they go, okay, well, now we need to do a security capability. And security is all around who has access to what and the data and all of this sort of stuff, and really understanding risk. So you go from productivity into risk, and risk it's hard to justify in a small business setting. I spent $100,000 addressing risk when the owner's like, well, I would have rather had your car or whatever. So that can be quite challenging. We're lucky because our customers are largely NFPs and they work with us, and most of our referrals come from cybersecurity professionals because they like how we operate and what we do. So we already have a head start on that, but typically they're either too worried about security or not worried enough. Very few are calibrated in the middle, and that whole second phase is about calibrating that middle piece and then building out that sort of bucket and capability and going, okay, shared responsibility model, Luke Owen does a really good job of explaining how to work in this sort of thing. It's like, what is your risk appetite? Where's the shared responsibility model? What are we doing? What are you doing? How much do you want to spend on this problem? Because I can give you security. Security is more expensive to deliver than managed services. To do it properly, do you want to spend that kind of money? Oh no, I want to spend 60 bucks. It's like, okay, well, we can do this and we can do that. It's like there's not necessarily you can't just go to the customer and say, this is what you need, buy that, because that's not how the world works. What you need to do is sit there and go, you know, what is the risk? Here are the products that we can implement, here are the processes, you know, there's certain stuff in your MSP that you need to sort out. Change management is a big one that I see done really poorly, you know, communication with the customer and user verification, another one. These things are kind of hard to solve, and now they're pretty easy. You know, SIP has a button that you can send a notification to the user, like, or maybe you're a smallish MSP where you know all the users, so it's less of an issue, right? So and that's what I mean about calibrating risk and really understanding what the customer's risk is. At 50 or 100 seats, identity access management becomes a real problem because they don't really they're not generally mature enough to handle it. And it was pretty manageable when they were like under 50 seats. They sort of hit 50 to 80 seats, and then it's all of a sudden like we've got thousands of permissions and we have no way of managing them. Um, everyone just had access to things, and people had credit cards, and we have to take all the credit cards off people, so we can't get expenses, and the whole organization just goes through its painful like governance uplift piece, and then you you tax security into that. And then once they get there, then they want to do AI, right? So the customers that want to do AI, they either they want to do the security and do it the proper way, or they're like, I want the outcome from AI to pay for my security program, pay for my IT, which again, like it's a small business environment, it's very hard to be judgy about it. Everyone runs with different margins, different risk profiles. It's not, and their competitors, they're not getting chosen over their competitors for the security posture as a general rule. Not even in MSP, where it's critical. No one comes to me and asks me about my security. They just assume I'm really good at it, and they assume every service provider is a security expert. But I think we can all agree that some are better than others, right? And some are really good at other things, right? Some are good at customer service, some are good at security, some are good at whatever, right? But you can't just assume your MSP is doing a great job with security. Like, I think if you have a few hundred customers, it's almost impossible for you to do security properly. Like you need a security team to manage that many customers, even if they're all ones and twos, because every customer has its own security risk profile. And it's just there's a lot of work. And even with AI, there's really nothing you can do. Whereas with us, we're like 20 customers, it's pretty manageable. You know, it does make it a lot easier, but also it makes it harder to grow because where you take on speculative 5C customers that might grow, might not grow, and not really profitable, but like they keep the techs busy and whatever, you put a line in the sand and go, I'm not going to help those guys, and I'm just going to do work with people who have budget who can invest in IT and security and meet us where we're at, rather than us come down and meet them where they're at, you end up in a different situation. So yeah, so I I don't know what the answer is. I don't think the answer is eliminating service providers that are helping people from getting from nothing to a little bit. I think there's a huge market of that. I think there's a there's a move in the industry at the moment. I think you'll be well across where they're trying to eliminate that layer. But those people that we want to work with who are like, we worked with our service provider, we turned on MFA, we've got devices quote unquote managed now. We've got an RMM agent on it, we have this, we have that, right? Like all of that work, we can't deliver that profitably, like at all. Like it's not even close. And those and the reason it's not profitable is because the customer has no idea what we're doing. So most of the work goes into account management and executing, showing customer, blah, blah, blah, and then uplifting them. It's like, I don't want to do that work. But you can't, so who's going to do that when we try and eliminate all these smaller providers or providers that are more execution focused? Because we're not really what I would call execution focused. We're more strategy and we're like that side of it. We still execute, right? But it's really our focus is the building blocks and driving things forward. And, you know, whereas there's MSPs out there where like 90% of their energy goes into executing for the customer. And they do amazing work. And those customers would not have anywhere near the security they have today. They wouldn't even have MFA if that service provider wasn't in there saying, hey, let's turn this on, let's turn that on. So well, like you've got to go and do the work as well, right? You can't just like talk about all the stuff. You've got to get in there and execute. And when people start, it's very much all execution. And then when you get up the top and you're looking at the top of the mountain, it's a lot more about looking back and going, what can we get rid of? How do we do this? It's far more strategic. And it's a lot more around like, can we eliminate these risks? Can we do this? Can we do that? You're just talking about risk all the time. But you know, if you're sitting on the bottom, you've got nothing, you're still turning on MFA, you haven't figured out what a pass key is. It's all execution. You just need people to do stuff. And this is the one thing that I think MSPs universally are pretty good at. Give them a list of things to do, and they can do it. Absolutely. That's the thing that MSPs are really, really good at.
SPEAKER_02And I I've seen this too. The challenge is, you know, like it's and even security, you know, it's like AI, it's not the technical solution and the execution is not the complicated part. The complicated part is getting people, management, and leadership buy-in to make a decision. Like we can turn all this stuff off and we can make you secure, but understand this happened the other day with an MSP I was talking to that. They were panicking because somebody had lost some documents saved to their desktop on their laptop. I said, How in 2026 is that even possible? Like it's physically uh that is a configuration management issue. That is not a person issue, that is not a technology issue, that is a decision issue. Uh that you did not redirect the folder uh to OneDrive or whatever it was. Then there's so many people out there that still are too scared to implement what is the right thing, and I was probably the bit the other way. We went with our clients, we were we were very much in the execution phase, but we moved into strategy and we would we I remember implementing an email filtering system at a 300-seat customer, and the IT manager wanted it, and blah blah yep, got it all done, put it all in, pulled the trigger, bang, enterprise bargaining unit went on strike. There was a big strike. There was a government department. That process didn't go through HR. You can't change the terms of employment or do anything with our corporate email because we don't have that in our agreement with you. So we had to back it all out. But I learned a big lesson about governance there, and it is about, and that was not a technology problem, that was a people problem. I the IT manager wanted to solve this technical problem because someone was being bullied. They had a lot of complaints. He wanted to capture all the email. We said, Well, there's tools out there that can do that, it can be anonymized or it can be, you know, you've got to be careful with this. No, no, it's all good, just do it. So I did it. And then the HR department and the CEO went, bang, you can't do that. We've got people on strike now. So there's a balance, but a lot of MSPs they struggle with having those conversations with business owners and explaining this is not a super difficult problem to solve technically, but you've got to understand that there'll be a people cost or a business process or you know, like today, we have people working from everywhere all over the world. So conditional access becomes a real problem, right? And management and IT people make decisions that are not communicated to the rest of the organization. So they don't know why they got off the plane in London that they can't access the remote. They ring the help desk and abuse the help desk. And the MSP going, I don't know why you can't local, I don't know what happened, but somebody made a decision to turn on a conditional access policy, didn't tell anyone. So it's a it's that whole circle of involving strategically having the conversation and then having a logical discussion and saying it's gonna cost X dollars to do this. Uh if you want it to be seamless and not impact your business, it's gonna cost five times as much. Your call. Do we have a conversation like adults with the team and say, from now on, you cannot do this? I just see a lot of tickets come in to MSPs for the people that are that shouldn't come in because it's just a decision's not being made.
SPEAKER_00But we or you particularly, Nick, have have issues here in Bali where you you know some of the work that you do start directly with our clients. You are the only one who's working outside of Australia. So uh decisions that they've made in the past to set things up in a certain way uh have now needing to be reviewed because you're in Indonesia.
SPEAKER_02Yeah, and people within the business uh don't even understand that. They have an MSP doing the right thing for them and looking after their security, and it's all well and good, but they didn't even think that. The other two owners of the business there got local admin rights to their machine. I don't, so I can't do anything. But it's amazing how debilitating it is remotely trying to do work when every time you go to do something, I've got to install this uh reader for this type of file or something like something stupid like that. I can't remember what I was trying to do the other day, but I just can't do anything. It's like I can't do it, I can't take a screenshot. I can't um do anything and go, okay, look, log a ticket. Ah, okay. When are you going to figure out what's going on here? Ah, okay, you've got conditional access policy. So now I know what to say to them straight away. I'm working in Bali. There's a conditional access policy. I need admin rights to do this and do that.
SPEAKER_01Yeah, and we're seeing a lot with AI as well, like people running scripts and building software and building websites, and this is not end user behavior. So you have EDR pinging off, going, why is an end user doing this and this now? You've got very very difficult place to navigate because the space is moving so quickly. It's just overall, it's a very challenging place that we're in at the moment. And but I also always go back to like you've got to start and you've got to incrementally build. And when I was in Evolve, we talked they have this thing called operational maturity level, which is how much like Evolve do you run your business? People at high level opportunity operational maturity level, they're running more profitable businesses with happier staff. People at low level are not. And a lot of it is, you know, it might be like, okay, triage. Oh, some guy just looks at tickets to we have a proper process in place, we pull in context, we do this, we do that. So it some of the stuff is quite obvious and linear, but a lot of it just really does reflect back at what. level of maturity that you're at. But the key insight from Evolve is you can't run at two and then go to five. Like you got to go from two to three to four to five.
SPEAKER_02Journey, yeah.
SPEAKER_01Yes. Yeah, yeah. You can't just say I'm going to run at four now because four I think four's like a good sweet spot. Three's pretty good as well. I like we try and run at three for most things. But yeah, it's like I'm going to go work at four. But the problem is it's like okay I'm going to do change management at four. There's all these other things in the business where there's no maturity around that. It's like, well, who's responsible for change management? Oh, we haven't got to that bit yet. It's just whoever's on shift in the day or whatever, right? It's like, okay, well, and I I think that's what happens that organizations go, well, I need to do this specific pro I have this problem. And then someone like me comes in and says, well, I don't know if that's where you should be spending your time. I know that's what your boss told you to do, but it's a kind of got these dependencies that hang off. And you've got to do this hard work on the back end in order to enable that. And it it's like, oh well I I'm responsible for security. I do all the security I'm accountable for it. I'm like, well the board's really the accountable party in the cybersecurity space. What have they delegated down to you? What is your responsibility? And they look at you blankly like what do you mean? I'm the IT guy. I'm like cybersecurity is not an IT problem. It's a cross-functional department like HR that sits across the whole business. And yes IT does to a certain extent but not the same way that risk does. It's like it's really about managing risk and it's really got nothing to do with increasing people's productivity. It's about making sure that someone doesn't bankrupt the company by doing something stupid. There's correct safeguards in place like that's what it's all about. But it's a real mindset shift because the IT person is you know they're really uptime and you know are people happy with IT? These are the metrics. No one asks if people are happy with cybersecurity because it doesn't matter because it's not their job to be liked. It's their job to be hey these are the controls in place. I don't think they should be combative. I think all cybersecurity people need to be collaborative and work through things with an organization. Some are a little bit more technical than others let's call it but at the end of the day like that's the role. It the role is understand the customer risk and apply that to technology and apply that to broader things in the organization like shredding paperwork and whatever. Anything that's data your job is to protect that your job is to make sure the company doesn't get hacked within the budget and the scope and the risk appetite of the board. That's the whole thing but that's a very new idea particularly to a small business that's growing really quickly where I trusted everyone. Everyone was related to me and now and now it's like all these strangers and they live overseas and they're annoying like Nick sometimes they want me want to do this and want to do that and we don't need that here. Why do I need to do it for him?
SPEAKER_02It's like yeah yeah I know how that feels and this guy's used to running a Mac and he's gone got been given this awesome 64 gig HP Z book that's amazing but it doesn't freaking work like it's got so many driver issues with everything it just it's like I can't believe it and you can't fix a driver issue unless you're a local app meeting guy. And of course when you ring up the helk desk and get into remote in it doesn't happen. It only happens when it's me.
SPEAKER_01Yeah we use ThreatLocker and ThreatLocker does my head in right but it's like I'd say the threat locker team they go oh what do you think you know what do you think of ThreatLocker? I'm like I hate it. I hate how good it is at what it does. I hate that it's like the best thing on the market and that it solves this really real problem. It's really good software but I hate it and it's like they go oh oh you're going to get rid of it oh no no I don't want to get rid of it. It's really really good like the software does exactly what it says it should do. The tools are I wouldn't say easy to use but they've been scaled to an MSP place where MSPs don't need to hire a dedicated threat locker person like you could put a senior engineer on it. The technical support is really good all of these things are really good and you go so why do you hate it? I'm like it's just hard it's just a hard piece of technology to run and it requires a high level of maturity from us and from the customer. Again we're committed to it we want to keep using it it's really good. But now that we're in AI it's even worse and we're trying to run it internally and I say well what do you do about developers and they go oh we don't know we don't know how to fix developer problems. Developers can't use threat locker very well. So it's like yeah we want to keep it as restrictive as possible but we need people to still get their work done and to use their acceptance story before it's like if I put it on and all they do is have problems with it now they don't want to engage with security anymore and IT is the enemy and so you have to you have to be able to work with the end user and really go back from the that customer experience and all the way up and I think it's very easy in a small organization and the bigger the organization that gets the harder it is the harder things are to move. It's like try and turn the Titanic and this is why I love small business like under 100 seats you can get a lot done that you can be you can pivot quickly you can be agile. They feel like they're very big businesses sometimes but you'd be surprised what a CEO of a hundred seat organization can do if they put their mind to it.
SPEAKER_02Whereas if you're the CEO of like West Farmers like you just put the strategy in and wait three years like it's interesting you say that because we found that because we did a lot of back in the old days we did a lot of regional government stuff and and the 50 to 100 C was yeah good size but when you got like 200 to 300 it was actually easier. Because they were doing everything exactly the same just more of it and there was less customization what we found and it was easier to sell the dream of standardization because they realized that at that size at 300 star you've got to have standardization in all your business processes not just IT. So they've got a different mindset to standardization. Oh Billy wants three monitors and this mouse and that yeah no that's not that's not what we do here, right? We have a standard setup. You get two or maybe if you're a senior manager you get a lighter laptop because you travel a lot. That's it. There's none none of this customization and all these kind of crap words at a smaller business. Everyone gets what they want which just creates complexity and it goes back to your comment earlier there is definitely a market out there for the execution reactive IT support MSP. Yeah they're not going to be the best at security they're not going to be the most efficient at everything but they're going to answer the phone they're going to fix your technical problems. Yeah you you and me we want there to be no technical problems we want to make the ideal world where everyone's at 99% efficient inside a business whereas there's a lot of businesses out there that don't care. And they go, I just want someone to fix it. And especially when the move to Asia understand that that managed services is not a thing here. They will not pay a recurring fee to prevent a problem it's so cheap to pay someone you know five bucks an hour to come and fix the problem when it happens. And if someone's not working and it's costing five bucks an hour they don't really care.
SPEAKER_00Different story in Australia altogether you know you literally just get more people you know we've worked clients in this region who, you know, really small business under under two million in revenue and they've got six people in accounts what do they do? Well you know the first four weren't that effective so we just got two more. Doesn't matter because labour is so inexpensive here that you just throw more people at it.
SPEAKER_01It's fascinating. Very very different yeah but no I think it definitely speaks that maturity story that Nick was just talking about. So we're on a podcast you you can't see where I'm pointing. So yeah look the the more mature the business the more it is standardized but if you you can have a very mature like we're a really good example of a highly mature business of our size. Now if I was a hundred seat organization we would be more mature in things right by virtue of there's one person who looks after user onboarding and offboarding right and that's their job and all they do is improve that process. We can't have that level of granularity so we're much more get it to 80% and then just focus on the things that differentiate us. But that being said we've chosen not to have a lot of clients we've chosen to grow like really just grow very deliberately and just pick the customers that really resonate with we want as close to best practice and enterprise IT as possible for a business of our size and we're happy to pay a little bit more to get that rigor around change management and get people that like stress and worry about our business and and that's our space but you know if you're in the market of like well I'm three years in business half my staff are giving me headaches all the time I don't even know what I'm supposed to be doing all day. I just need this IT thing to go away and I really don't want to ever think about it ever again. That we're a very bad partner for that because we're calling them every week going when are we rolling out the password manager? And they go, I don't have time for this. Leave me alone. Can't you just do it for us right? Like that's the and and you can have a hundred or two hundred C customer that behaves like that but most of those customers haven't really they've just sort of got lucky and grown like that I think if they've grown slowly over time the the big customers that have grown really quickly they are like small businesses. Like they don't but the ones have been around for 30 years, like a government is a good example where you know they've had these processes over time they've improved them over like you know 30, 40 years. So it's not a it's not a case of five years ago there were five people running around now there's 50 or 100 of them or a thousand of them. It's very much of like oh yeah we've we've had HR sorted out we're on we're proactive in HR right HR we have the right level of staffing we have the right capability in the right seats we have a process for replacing people we have proper processes around interviewing we do this you go into a founder led business that's growing really fast. It's like look we just get people in for interviews I see if they're a good fit I've got a good feel on it. I hire the guy that I like get a lot of people who work here that spring people that work here. It's a fun place to work you know that's it is a lower level of maturity but it's not necessarily wrong for where that business is at and what they're focusing on. They may be wanting to focus on some other area of the business that's less mature that they're trying to improve maturity in there the guys that log a ticket on Monday and say oh Bill started today can we have an account set up for him?
SPEAKER_00Yeah.
SPEAKER_02And it's urgent because he started already started last week he hasn't got a laptop yet exactly what's going on but you'd be surprised some of those big government organizations still don't their HR department still doesn't talk to their IT department. I'm saying how can you possibly have signed an employment contract for someone given at least two weeks notice to start a job and not let IT know that so we we actually did a lot of work with our hospitals and councils on that part of it is guys you need to give help us to help you to be more efficient. Give that person the best experience possible on day one you know not oh here's Bill um oh gee let me clean this shit off this desk here's a desk for you computer I'll have to talk to IT it'll take three four weeks to get a laptop for you.
SPEAKER_01Yeah and I think you're talking hitting on silos that all these big organizations people build their little kingdoms and their little silos and fuzzy said a really good thing at one of the presentations once he's like IT managers are empire builders they love building their little empires little kingdoms and they love having lots of staff and like oh they are like that and they want to run their own little thing right and they don't want to really talk to anyone in the organization and they just want to do their thing right and I think this is what happens and it takes a very very strong leader to do that cross-functional thing and I think this is where tools like EICE are good because it does force the issue right you do have to have the problem management meetings you do have to have issues list like if that gets identified whereas it's very easy to identify risks and put a risk res I think the issues thing is a completely different thing of like hey like we we had this issue the other day where someone had a really poor onboarding experience because we weren't coordinated and then a lot of those that coordination really relies on personal relationships. So it's not a system it's the HI person gets along with the IT person the HR person left and now the relationship's not there and the process falls over. So you know you're still having all of those problems under a thousand seeds like that's that's pretty normal. But you know look the businesses that are doing really well are actively working on building this and then with AI now they should be trying to build it for AI. So AI can take away this transactional stuff out of their life so they can really just focus on the big picture strategy of like what sort of business do we want to be like what are we delivering to our customers? What does value mean for our customers? What does a employee experience feel like? What is the culture here? Like these are the big picture questions that they need to be thinking about but most managers at that size is thinking about like I've got to get this done got this report done the boards asked for that like that's all we're thinking about all day. They're like I don't know who to talk to about this I don't have any peers I don't have anyone to talk to like we're trying to get a bit of a peer group going just with our bigger customers because we've identified like there's no one in the business in their business that really understands what they do. They go well yeah like I do this and I do that but they don't really understand why I'm saying we need to do this in security or we need to do that. Like they don't really get it. They know that I'm doing the right thing by the business and I've got a good relationship with them but they don't really understand why we should spend money on it. And when you're all grabbing from the same pool of money can be really helpful to talk to other people of like yep had that problem here's how I communicated it to that executive here's how you do that. And it works really well for me. My peer group's really helped me a lot. So I'm trying to do a similar sort of thing with our customers who are in that same situation of like I don't know how to solve some of these problems. Like I can't I'm not perfect.
SPEAKER_00I'm still figuring it out you know and we do this with our some of our EOS clients we do a monthly catch up of the integrators because they're all different industries, different locations but they as that integrator role they all have the same challenges of something's happening in my business and I don't know how to solve it. And chances are that one of the other integrators have had some experience in that space and can share it because we don't always have the answers either. So it it there's a lot of value in that of just you know sharing sharing that that information between them. So but let's wrap and I got my two questions in so I think I did well.
SPEAKER_01I think we touched on all the three areas. We're talking about AI we're talking about strategy and we're talking about security and we've got something that I hope people can take away and use and maybe it's only one thing but it's always been it's always great catching up with you both. And yeah I think it's a really important podcast. It's offering something quite important to the industry.
SPEAKER_02That's good thanks mate I appreciate it and we'll no doubt talk again and we'll get some other topical stuff going on. And really good to hear that you're in a really happy place. So maybe there's a a story in that too because there's a lot of people out there running businesses that are not in happy places.
SPEAKER_01Yeah it hasn't always been like that. So I don't know if I'm the poster boy for happiness but um I I think look if the short version of that is just you know help your team and empower your team and try and be a better leader and the rest will follow. But I thought it sounds overly simplistic when I put it like that.
SPEAKER_02Yeah but you know there's always people that are better off and there's always people that are worse off. That's not the lesson we've learnt and you've got to appreciate where you are and use your peer group and use your contacts and if you've got struggles reach out because someone else has already had that struggle or in a similar experience and just talking through it. And that's part of why we want to do this for is to give people the opportunity to talk through challenges they've had and share it and your people get a bit of inspiration and yeah very good. Thanks again thanks again mate appreciate it. Yeah thank you.
SPEAKER_00If this conversation hit home for you or got you thinking head to mspmastery dot blog and keep the conversation going. You'll find all our episodes there and more wisdom from the peers and partners who are shaping the future of our industry. And make sure you subscribe so you don't miss future episodes. We've got plenty more great guests and stories coming your way. Until next time this is MSP Mastery