Mid-tabletop power move: declare one critical person unreachable (they're "on a cruise") and keep going. The next ten minutes are the most useful finding of the exercise.
Gary Austin
@bigg-thecreator.bsky.social
The Security Gator - The operational side of cybersecurity for MSPs & vCISOs. Frameworks that compute, weekly intel, audit-ready evidence. NIST CSF 2.0 · Shadow AI · CaaS. No fear-marketing, no filler. Free newsletter every Tuesday ↓
Board pitch for IR readiness, minus the fear: "One hour. No consultants. We pretend it's a bad Saturday. I'll bring back three gaps with owners and dates." Boards buy rehearsals; they resent scare decks.
The rule that makes tabletops work: every answer names a person AND a place. "Bob, IR folder, runbook §2" counts. "Someone would check the docs" is a finding.
Free tool day: IR Tabletop-in-a-Box — 60-min facilitator agenda, three scenario decks (ransomware, vendor breach, BEC), role cards, and an after-action template that doubles as audit-prep evidence. Link on the site.
The two most expensive words in incident response: "someone would." Someone would isolate it. Someone would call the insurer. Free 60-minute fix drops tomorrow.
Quick test of your IR plan: it's 2 AM Saturday, EDR is lit up on three machines, encryption is running. Who gets that alert — by name? If the honest answer is "the team," you have a hypothesis, not a plan.
Weekend drill: invoices + SSO apps + DNS → vendor rows → score honestly → count the reds. First pass is supposed to look ugly. An ugly count you can name beats a clean one you can't. 🐊
Five weeks of free tools and counting: field guide, Govern tracker, evidence register, Shadow AI kit, CaaS worksheet, vendor register. Be useful first — the rest follows. 🐊
Incident-day reading should be your own one-line summaries, not a 40-page MSA at 2 AM. "Breach notice: 72h, §9.2" — one line per contract, written on a calm Tuesday. Your future self is begging.
Contract drill for the week: find the breach-notification window in your top vendor's MSA and write it as one register line. If the contract says "promptly" instead of a number of hours — that's a renewal conversation.
Quiet crown-jewels check: your RMM holds the keys to every client you manage. If one register row deserves paranoia-grade scrutiny, it's that one. And yes — the AI notetaker counts as a vendor too. Same three questions.
Risk registers get deferred. "We can answer all three vendor questions for 4 of our 23 vendors" gets funded. Countable beats scary, every quarter.
The tracker's one non-negotiable rule: 🟢 only if a DOCUMENT answers it in under a minute. "Pretty sure it's in the MSA" is a 🟡. Memory doesn't survive incidents — paper does. Score your first vendor tonight.
Free tool day 🐊 The Vendor-Risk 3-Question Tracker: what they HOLD, what we AGREED, how we'd KNOW. Score brutally — green only if a document answers it in under a minute.
Your attack surface used to be your network. Now it's your invoice list. Every SaaS line item is somebody else's engineering decisions, inherited by you — and by your clients. This week we're making that list answer three questions.
Nobody at ~9,000 breached schools ran a vulnerable server. Their vendor did the breaching for them. Vendor risk week starts now — the register that makes it manageable drops Tuesday, free.
This week in cyber, MSP edition: 🐊 Dirty Frag joins CopyFail + Fragnesia (patch your kernels) · Canvas vendor breach = third-party risk wake-up call · Proofpoint says your AI controls probably have blind spots. Three sections, twelve minutes, every Tuesday - newsletter link in reply.