Full Report
Read our webinar recap to learn what Henry Washburn of Huntress and Ian Alexander of Syncro outlined to help MSPs protect SMBs from cybersecurity threats.
Analysis Summary
# Best Practices: Cybersecurity Foundations for MSPs and SMBs
## Overview
These practices address the shift from traditional "perimeter-only" defense to a modern "assume compromise" mindset. They focus on moving away from "tool creep" (buying software without a plan) toward a framework-driven strategy that ensures small and medium businesses have the visibility and response capabilities necessary to survive modern threats.
## Key Recommendations
### Immediate Actions
1. **Adopt an "Assume Compromise" Mindset:** Move away from the belief that basic Antivirus (AV) is sufficient. Acknowledge that attackers will eventually bypass "walls."
2. **Inventory Current Tools:** Map your existing software stack against the five NIST pillars (Identify, Protect, Detect, Respond, Recover) to find gaps or redundancies.
3. **Enable Managed Detection:** Ensure that for every security tool in place, there is a designated person or service (like a Managed EDR) actively watching and interpreting the alerts.
### Short-term Improvements (1-3 months)
1. **Deploy EDR/NGAV:** Transition from signature-based AV to Endpoint Detection and Response (EDR) to monitor for malicious behaviors, not just known file hashes.
2. **Formalize Incident Response (IR):** Draft a basic IR plan that defines who to call and what steps to take when an alert is confirmed as a threat.
3. **Log Protection:** Secure and centralize system logs to ensure they cannot be wiped by an attacker during an intrusion.
### Long-term Strategy (3+ months)
1. **Regular Gap Assessment:** Perform routine testing of the Incident Response plan to identify where the process breaks down.
2. **Backup Integrity Audits:** Move beyond simply "having" backups; implement a schedule for checking the viability and recovery speed of those backups.
3. **Framework Alignment:** Transition the entire security program to be driven by a standard framework (like NIST) rather than reacting to the latest marketing trends or "three-letter acronyms" (XDR, MDR, etc.).
## Implementation Guidance
### For Small Organizations
- **Focus on Managed Services:** Since SMBs often lack a 24/7 internal SOC, prioritize tools that offer a managed component where experts review the alerts for you.
- **Prioritize "Recover":** If resources are limited, ensure your backup and recovery pillar is bulletproof.
### For Medium Organizations (MSPs)
- **Avoid Tool Creep:** Before adding a new "XDR+" solution, tune your existing EDR and RMM tools to fulfill the NIST requirements.
- **Education over Automation:** Train staff to understand *what* the tools are delivering rather than just acknowledging alerts.
### For Large Enterprises
- **Extended Visibility (XDR):** Integrate endpoint data with network and cloud logs to create a unified view of the environment.
- **Compliance Integration:** Align security operations with SOC2, GDPR, or CCPA requirements to meet legal and insurance obligations.
## Configuration Examples
*While specific code was not provided, the following technical configuration logic is recommended:*
- **EDR Configuration:** Set to "Preventative" mode for known malware, but ensure "Detection/Logging" is active for behavioral anomalies (like PowerShell execution by non-admins).
- **Log Retention:** Configure logs to be immutable or sent to a write-once-read-many (WORM) storage location to prevent tampering during a breach.
## Compliance Alignment
- **NIST Cybersecurity Framework (CSF):** The primary recommended structure (Identify, Protect, Detect, Respond, Recover).
- **SOC2 / GDPR / CCPA:** Relevant for data privacy and operational security standards.
- **Cyber Insurance Requirements:** Aligning the stack to meet the evolving demands of insurance providers.
## Common Pitfalls to Avoid
- **Acronym Confusion:** Buying "XDR" thinking it is a magic bullet without understanding that it is often just an extension of EDR.
- **Set-and-Forget Mentality:** Deploying high-end tools but failing to assign someone to monitor the alerts they generate.
- **Tool Overlap:** Paying for multiple tools that perform the same "Protect" function while leaving the "Respond" or "Recover" pillars empty.
## Resources
- **NIST Cybersecurity Framework:** hxxps[://]www[.]nist[.]gov/cyberframework
- **Huntress Blog & Tradecraft:** hxxps[://]www[.]huntress[.]com/blog
- **Syncro MSP Platform:** hxxps[://]syncromsp[.]com/
- **Incident Response Planning Guide:** hxxps[://]support[.]huntress[.]io/hc/en-us