Latest news, blog posts, and announcements from MSP software vendors. 141 updates from the last 30 days in Compliance & Risk Management.
141 items from vendors in this category. The summary is written from their titles and summaries, nothing else.
This post helps distinguish true expert-led penetration tests from automated scans, providing MSPs with critical questions to ask providers when sourcing or delivering pentesting services for their clients.
Read moreThis post details how Kaseya's solutions assist IT teams, including MSPs, in streamlining Microsoft management, enhancing security, and efficiently recovering critical data to reduce operational complexity.
This Focus Friday blog post delivers TPRM insights on critical vulnerabilities found in commonly deployed technologies such as Citrix NetScaler, MikroTik RouterOS, and WordPress, offering valuable intelligence for MSPs to assess and manage risks within their client environments.
Read moreThis article discusses the limitations of traditional security questionnaires and proposes more effective alternatives. MSPs can use these insights to improve their own vendor assessment processes and better advise clients on evaluating third-party risks.
Read moreWazuh partnered with Cyber Guard Pro, a cybersecurity and compliance solutions provider, enhancing security visibility for enterprises and demonstrating Wazuh's growing ecosystem of partners.
Read moreThis article provides key questions and considerations for MSPs to evaluate when renewing or selecting security awareness training programs for their clients, helping ensure optimal value, effectiveness, and compliance.
Read moreNINJIO has launched Sensei AI, a new feature allowing users to convert any document into custom security awareness training content. This offers MSPs a powerful tool to efficiently tailor educational materials and expand their service offerings to clients.
Read moreThis article explores findings from a survey of over 1,100 IT and security professionals, highlighting key challenges like human error, budget constraints, workload, and skills gaps, providing valuable insights for MSPs managing client security operations.
Read moreThis article explains new AI assurance laws in California and their implications for organizations building AI. MSPs can leverage this information to provide informed guidance to clients on navigating emerging AI governance and compliance requirements.
Read moreA comprehensive compilation of over 16,500 rules and 5,300 decoders from 110+ community sources offers MSPs a centralized resource to enhance client security detection and operational efficiency.
Read moreProofpoint's threat research team details how China-aligned TA419 actors are using advanced impersonation techniques, including AI, which provides valuable threat intelligence for MSPs to inform clients about evolving AI-driven risks and strengthen their defenses.
Read moreNetwrix research indicates that a majority of healthcare organizations are exposed to security risks from inadequately governed AI agents and other non-human identities, providing critical insights for MSPs serving the healthcare sector to help clients mitigate these vulnerabilities.
Read moreThis community compliance pack helps MSPs meet Saudi Essential Cybersecurity Controls (ECC-2:2024) using native Wazuh capabilities, streamlining compliance for clients without extra agents.
Read moreThe FBI declares a major incident after the FBIJobs.gov breach as Pentagon database attack exposes data of nearly three million individuals. This provides MSPs with crucial insights into current high-profile cyber threats to inform their security strategies.
Read moreThis guide offers prescriptive steps for MSPs to help small defense contractors meet CMMC Level 1 requirements, navigating critical compliance for the defense supply chain. It provides practical insights for MSPs supporting government contractors.
Read moreAn open-source asset management layer, INVENTORY, built on Wazuh's SysCollector data, provides MSPs with enhanced computer park management capabilities for their clients.
Read moreA new report highlights the increasing use of audio and video deepfakes in social engineering attacks, an important threat intelligence update for MSPs to understand and communicate to their clients.
Read moreKnowBe4’s Agent Risk Manager now integrates with the Claude Compliance API, enabling MSPs to monitor client Claude AI activity for risks and enhance AI agent security for their customers.
Read moreBreach Secure Now's 'Lock It Down' campaign for Cybersecurity Awareness Month 2026 provides a comprehensive resource for MSPs to leverage in delivering essential security awareness training and reinforcing good habits for their clients.
Read moreThis article details Qualys TruRisk's two layers of patch control, offering valuable insights for MSPs managing Microsoft updates for clients, particularly in handling problematic patches to ensure system stability and security.
Read moreCoalition highlights critical Citrix NetScaler zero-day vulnerabilities and patches, urging MSPs to be aware of actively exploited threats that may impact client environments.
Read moreCoalition proactively alerted policyholders about two critical Citrix zero-day vulnerabilities being exploited in the wild, providing early warnings essential for MSPs managing client security and Citrix environments.
Read moreWazuh partnered with AI Cyber Consulting, an MSSP specializing in education and small businesses, strengthening SOC services by leveraging Wazuh for their managed security solutions.
Read moreProofpoint is pursuing FedRAMP High Authorization, which is crucial for MSPs serving government or highly regulated clients, allowing them to offer solutions that meet stringent federal security and compliance standards for data security and insider threat management.
Read moreThis article offers guidance on preparing for healthcare compliance audits, an essential understanding for MSPs supporting healthcare clients with their IT and security needs.
Read moreThis article explores the risks, uses, and corporate implications of mouse jigglers, a topic relevant to MSPs for advising clients on security policies, monitoring employee behavior, and maintaining compliance in remote and hybrid work environments.
Read moreRecently updated, this guide offers practical advice on formatting and writing effective Standard Operating Procedures (SOPs), a critical resource for MSPs to ensure consistent service delivery and operational efficiency.
Read moreThis article explores strategies for MSPs to manage policy exceptions within client Microsoft 365 environments while maintaining robust audit trails, ensuring compliance and operational flexibility for their managed services.
Read moreThis TPRM analysis highlights critical vulnerabilities, particularly in ScreenConnect, a key remote access tool for many MSPs, along with common client infrastructure components like Citrix NetScaler and Apache Tomcat, providing actionable intelligence for vendor remediation and client security.
Read moreThis post highlights that most MFA implementations are susceptible to real-time proxy phishing attacks, emphasizing the need to assess whether MFA can be relayed, not just if it's present. MSPs should take note to strengthen client security against advanced phishing techniques.
Read moreA new 'GhostCode' phishing kit is actively targeting sales teams with phony business inquiries, offering MSPs crucial and actionable threat intelligence to protect their clients' sales departments from sophisticated attacks.
Read moreThis article provides a strategic guide to Customer Relationship Management systems, focusing on their relevance for IT and cybersecurity leaders, which is highly applicable for MSPs managing client relationships and their data security.
Read moreThis article explains how MSPs and MSSPs can leverage GRC (Governance, Risk, and Compliance) as a growth engine by focusing on segmentation, packaging, and delivery models.
Read moreThis post provides MSPs with actionable strategies to leverage Cybersecurity Awareness Month to boost Q4 sales and strengthen client engagements. It offers valuable business and marketing insights specifically for managed service providers looking to capitalize on industry events.
Read moreThis article addresses the critical risk when a trusted cybersecurity platform used by MSPs to protect clients becomes compromised, urging providers to scrutinize their security tools and supply chain. It's highly relevant for MSPs needing to maintain the integrity of their own and their clients' security stacks.
Read moreThis announcement means Proofpoint's data security solutions are now accessible via AWS Marketplace, simplifying procurement and deployment for MSPs who leverage AWS for their clients or internal operations.
Read moreThis Optery Dispatch highlights increasing phishing, email defense evasion, and executive impersonation threats. MSPs can use these insights to better educate clients and refine their cybersecurity strategies against evolving attack vectors.
Read moreThis article provides MSPs with practical indicators and strategies to evaluate the effectiveness of their Quarterly Business Reviews (QBRs) and ensure they contribute to customer success and retention.
Read moreThis article discusses 'EvilTokens Device Code Phishing,' a sophisticated threat that doesn't require password theft. MSPs should review this to understand advanced phishing tactics and enhance client protection strategies.
Read moreThis article explores how AI assistants are becoming new attack surfaces, providing MSPs with critical insights into emerging security risks to consider when managing clients' AI implementations and infrastructure.
Read moreThis week's digest of major cybersecurity incidents provides MSPs with insights into ongoing threat landscapes relevant to protecting their clients.
Read moreA comprehensive guide to Remote Desktop Protocol (RDP) is highly relevant for MSPs, as RDP is a fundamental tool for remote support and management, and understanding its uses and security implications is crucial for their operations.
Read moreOptery has partnered with Carahsoft to offer its personal data removal services to the public sector. This partnership signifies new opportunities for MSPs serving government clients to integrate data privacy solutions.
Read moreThis article discusses the complexities of navigating various compliance frameworks (like CMMC, HIPAA, and NIST) in the evolving landscape of AI. It offers critical insights for MSPs on how AI impacts existing cybersecurity and compliance requirements, crucial for advising clients and adapting service offerings.
Read moreThis article discusses the challenges of navigating various compliance frameworks (CMMC, HIPAA, NIST, ISO) in the context of AI, providing industry insights crucial for MSPs to advise clients and adapt their cybersecurity services to evolving regulations.
Read moreThis article highlights the critical need for resilient incident response plans when primary security tools are compromised, offering valuable strategic insights for MSPs managing client cybersecurity and operational continuity.
Read moreThis article discusses cybersecurity rules impacting the Premier League, providing valuable industry insights for MSPs on compliance and best practices that can be applied to clients in various sectors, especially those with high public profiles or specific regulatory landscapes.
Read moreA sideloaded package turns a Microsoft-signed binary into an OAuth token theft tool, bypassing common phishing defenses. This critical security insight is highly relevant for MSPs managing client Microsoft environments, detailing detection methods.
Read morePC Matic's sponsorship of a Zero Trust focused show indicates their commitment to advanced security frameworks, signaling potential product developments or strategic partnerships that could be valuable for MSPs designing secure client environments.
Read moreThis post announces the Thoropass MCP server, a new product that uses AI to connect audit context and reduce manual evidence work, offering a tool MSPs could leverage for more efficient client or internal compliance audits.
Read more