Transcript
Hey, thanks so much for having me. From M365 management to cyber resilience, the next evolution for MSPs. M365 management is table stakes for most MSPs today. What's driving the shift towards cyber resilience? Yeah, great question. If you think about how long Microsoft 365 has been around or how the Microsoft infrastructure in general has been around from a collaboration perspective, organizations are facing a big challenge in that they've been using it for so long that they probably don't know for the most part what exists inside of the environment and thus really what their risk profile is as it relates to the application. So now they're kind of forced with having to understand what would it make up or how would they think about a minimally viable company if a data breach were to happen. What we're seeing within Rubrik is that these attacks are happening at the identity layer and one of the first things they're going after is 365. And because we haven't gone through and understand what the data is, it makes that attack surface that's much more broad. And understanding what has actually been touched or impacted is a significant challenge. So it's really now become table stakes to have a mechanism in place from a cyber resiliency perspective to be able to build back their minimally. So when an MSP says we manage Microsoft 365, what's typically missing from the conversation? Yeah, so management to me is, okay, well we have mechanisms to be able to maybe help you provision sites or grant access and those kinds of things. What really is missing is what is the practice or what is the recovery strategy should there be a data loss event. And historically, managing 365 meant, well, we'll give you mechanisms to be able to manage a recycle bin or create a retention policy or implement an archive. But the conversations now really need to be around, well, what's the data recovery plan? Because if you look at the shared responsibility within Microsoft, there isn't this really standard ability to recover data or recover data in mass. So when you talk about managing the environment for a customer or managing 365 as a whole, the whole data recovery component now needs to be brought in place. Who are the stakeholders? How do you think about critical data? And what is the strategy should there be some kind of breach that were to take place? For an MSP that's ready to make that shift, where should they start? Yeah, that's a really, really great question. So it really starts with just asking some more questions of your customers and understanding how they're utilizing 365. Is it tied into critical business processes? Is it something that without it could impact and have downstream impacts? Are there things that you're utilizing from maybe a Dynamics 365 perspective or Power Platform or other integrations that would be detrimental to an organization should the service be not available or data not being involved? So I think it's just really asking questions and learning more of how organizations rely on the 365 infrastructure day to day. Obviously, us at Rubrik have a tremendous amount of experience and knowledge around what those questions are and how to position those questions within different individuals within a corporation. C-level executives may have different perspectives than an IT director, etc. So I think it's really key to understand some of those things as it relates to usage. And even if an organization, let's say, would say, well, we wouldn't really consider Microsoft 365 a Tier 1 or a Tier 0 application, that may not be the case if you peel back the onion a little bit and ask them more about what would be their control and command and communication mechanisms should there be an outage. You'll find that most times that's going to be Microsoft 365. So even if it's not going to be something that is application specific or dependent, it's something that is very critical as it relates to the communication or orchestration of activities through a cyber event. So looking ahead, where do you see the biggest opportunities for MSPs that embrace cyber as resilience? I think the opportunity is massive and significant. You know, you can be that trusted advisor that organizations are looking for. The attack landscape within 365 is, I think, more dire than ever. And companies are looking for ways to be led and understand, how can I build this into my practice or build this into my requirements from an MSP? Because, again, if you think about what makes up a minimally viable company, collaboration applications in 365 are definitely going to be a part of that. So it's going to allow you to really set yourself apart and ask more questions other than, well, what's your strategy from a data recovery perspective? More as, you know, talk to me about how 365 is utilized. And if you really understand their business, if they're a manufacturing organization or a healthcare organization or finance, how are things kind of tied in from a Microsoft 365 perspective? As you provision SharePoint sites, are you utilizing other plugins to feed data in? What are some of the dependencies you think that exist within that? And if you were to have an outage or have a data loss, who would you prioritize in terms of recovery? These are very insightful questions that can really position you in a unique way that can really see and open a significant amount of opportunities, not only from a licensing perspective, but kind of managing the overall infrastructure and experience for your customer. Eddie, thank you. You have it from Eddie Wasowski, our VP at Rubrik. Eddie, thanks for joining. I'm Nawaz Ali. Thanks for joining MSP Anspruch. Thanks so much.