Home / Insights
Security assessment insights for MSPs.
Practical, answer-first guidance for understanding what agentless domain and Microsoft 365 assessments can show, where their boundaries are, and how to turn observations into better client conversations.
Practical guidance for MSP owners, sales leaders, vCIOs, security consultants, and technicians.
Domain Security
Microsoft 365
Shadow AI
3AM Test
Compliance
MSP Growth
Revenue Engine
The strongest MSP sales motion is not a better pitch. It is a better way to separate what you observed, what you inferred, and what still needs consent.
Steve Copeland
Revenue Engine
A domain assessment can reveal useful public signals. It cannot prove identity controls, recovery readiness, or what is happening inside a tenant.
Steve Copeland
Revenue Engine
A public scan earns attention when it teaches the prospect something useful and volunteers its own limits.
Steve Copeland
Revenue Engine
Ticket counts describe MSP activity. A scorecard helps the client decide what should happen next.
Steve Copeland
Findings That Sell Themselves
Publishing DMARC is easy. Reaching enforcement safely requires sender discovery, monitoring, and staged change.
Steve Copeland
Operator Playbook
Evidence becomes a sales motion only when preparation, consent, review, and follow-up run on a repeatable cadence.
Steve Copeland
Revenue Engine
A better first meeting does not require a bigger promise. It requires two or three defensible observations, a clear statement of what they do not prove, and a safe next step the prospect can choose.
Steve Copeland
Revenue Engine
Security questionnaires often ask owners to recall technical controls they cannot personally verify. Consented tenant evidence can replace part of that guesswork, as long as the MSP records...
Steve Copeland
Revenue Engine
The public-signal path observes information an organization already exposes to the internet. It is useful for opening a conversation, but it is intentionally narrower than a separately scoped and...
Steve Copeland
Revenue Engine
MSP owners already know how to assess a problem and explain a recommendation. The missing piece is usually an evidence-led process that moves from meeting to assessment, review, proposal, and...
Steve Copeland
Insurance Wedge
A cyber-insurance application can be used as a control inventory: identify what evidence exists, who owns each answer, and which gaps need work before renewal. It cannot guarantee eligibility,...
Steve Copeland
Insurance Wedge
The attestation gap is the distance between what an organization says is true and what its current evidence supports. Closing it means verifying technical answers, documenting operational answers,...
Steve Copeland
Insurance Wedge
Insurance renewal creates a natural deadline for an evidence review. Start early enough to verify technical controls, document operational processes, and give the client time to decide how to...
Steve Copeland
Findings That Sell Themselves
An unfamiliar app grant is not proof of compromise. It is a review item. The useful questions are who published it, who consented, what permissions it holds, when it was last active when that...
Steve Copeland
Findings That Sell Themselves
Tenant evidence can identify AI-related applications, publishers, consent context, permission scopes, and accountable owners when those fields are available. It cannot prove prompts, content,...
Steve Copeland
Findings That Sell Themselves
License assignment is not the same as value. A defensible review compares assigned seats, account state, business role, and the activity reports Microsoft makes available before recommending a change.
Steve Copeland
Findings That Sell Themselves
SCOUTz can surface technical concentration such as privileged roles, delegates, mail routing, and tenant dependencies. Business dependencies—bank portals, payroll access, saved credentials, and...
Steve Copeland
Findings That Sell Themselves
Business email compromise often begins with valid credentials and trusted access rather than a malware alert. The practical review is identity-first: MFA coverage, legacy access paths, risky...
Steve Copeland
Findings That Sell Themselves
End-of-life planning requires an authoritative device, operating-system, or application inventory. That is managed-client work or an approved post-engagement data source—not a claim a public...
Steve Copeland
Findings That Sell Themselves
A disabled or inactive account with an assigned license is a review signal, not automatic proof of waste. Validate employment status, retention needs, shared-workflow dependencies, and available...
Steve Copeland
Trust Position
SCOUTz is designed to derive security-posture evidence from configuration and metadata rather than employee documents, message bodies, or file content. The exact permissions, purpose, retention,...
Steve Copeland
Trust Position
Good security products are defined by the data they decline to collect as much as the features they ship. Our filter is simple: identify the evidence needed, request the minimum practical...
Steve Copeland
Trust Position
Consent is useful only when it is informed and reversible. Before a tenant assessment, the customer should be able to see what is requested, why it is needed, what is retained, and how access can...
Steve Copeland
Trust Position
The 3AM Test becomes actionable when every question has an owner, evidence source, current status, and next test date. Some answers come from technical evidence; others require service records,...
Steve Copeland
Trust Position
Fear may get attention, but it does not create a durable decision process. Present the condition, consequence, evidence, boundary, and next choice without predicting catastrophe.
Steve Copeland
Trust Position
A passive public assessment should have a documented boundary: approved sources, ordinary observation methods, organization-level data, and clear stop conditions. Anything deeper belongs in a...
Steve Copeland
Trust Position
An honest assessment separates diagnosis from action. Every finding should show its evidence, collection boundary, accountable owner, and recommended next step while leaving remediation decisions...
Steve Copeland
Operator Playbook
Outside-in signals are estimates of visible posture. Consented tenant evidence is stronger, but it is still point-in-time and coverage-dependent. When sources disagree, check collection time,...
Steve Copeland
Operator Playbook
One consented assessment can inform several business questions, but it cannot answer every operational dependency. Mark each conclusion Observed, Inferred, or Attested so the client sees where...
Steve Copeland