Cyber Bites: 5 Minutes of Advice from GTIA Cybersecurity Member Experts

By GTIA

Oct 31, 2025

Share this post

Road signs for advice, support, guidance and help

October is Cybersecurity Awareness month and GTIA members are doing their part to promote public awareness of cybersecurity issues and the importance of protecting digital information and systems. Check out these short Cyber Bites videos, each offering a key piece of advice, guidance or support in an effort to  provide practical tips and tools to protect personal information, digital assets and online privacy. 

Search #GTIACyberBites on LinkedIn!

Nett Lynch, CISO at Kraft & Kennedy and Emperor of Legion, breaks down what a Virtual Chief Information Officer actually does, why it’s not just glorified IT support and how the best VCIOs become trusted strategic advisors.

 

 

 

 

 

 

Corey Kirkendoll, president & CEO at 5K Technical Services, shares how AI is transforming cybersecurity from reactive to predictive.

 

 

 

 

 

 

Hena Kless, senior solutions consultant at LastPass, shares a chilling Halloween-themed warning about the rise of voice phishing attacks—and how MSPs can fight back. 

 

 

 

 

 

 

Natalie Suarez, principal solutions advisor at ConnectWise, shares real-world examples of how deepfakes and rogue AI agents are reshaping the cybersecurity threat landscape—from fake video calls to sabotaged codebases.

 

 

 

 

 

 

Patrick Burgess, co-founder and CEO, ClearBenchmark Ltd., explains why cybersecurity frameworks aren’t just checklists—they’re roadmaps for building trust, improving service delivery, and guiding clients toward secure outcomes.

 

 

 

 

 

 

John Paul Buccat, network and infrastructure support at  Acuutech, explains in both English and Tagalog why the GTIA ISAO is more than just a cybersecurity network—it's a frontline defense for MSPs.

 

 

 

 

 

 

Kevin Zwaan, ethical hacker, red teamer and founder of Hackers Love, shares what it really means to be a hacker in today’s cybersecurity landscape and why MSPs and businesses need to stop fearing hackers and start collaborating with them.

 

 

 

 

 

 

Jonathan Braley, director of threat intelligence, IT-ISAC, explains the difference between ISACs and ISAOs—and why both are vital for sharing cyberthreat intelligence.

 

 

 

 

 

 

Matthew Lang, director, cyber security practice at SVAM International Inc., urges MSPs to rethink their cybersecurity starting point: data classification. Knowing what data you have is foundational to every framework, policy and protection strategy.

 

 

 

 

 

 

Oli Thordarson, CEO of Alvaka, lays out five compelling reasons why cyber breach insurance is no longer a “nice to have.” He explains how insurance helps organizations of all sizes manage risk, recover faster and avoid financial devastation.

 

 

 

 

 

 

Paul Croker, founder and CEO, 18iT, makes patch management sound like rock and roll. In this fast-paced breakdown, he explains why patching isn’t just about Windows updates, but every device, app and firmware your business relies on. 

 

 

 

 

 

 

Jason Hahn, IT operations manager at Computer Solutions, urges MSPs to treat client onboarding as the beginning of a security-first relationship—not the end. He outlines how proactive post-contract practices protect clients and deepen trust.

 

 

 

 

 

 

Aaron Jacobs, principal sales engineer at Sophos breaks down the rise of identity token theft and MFA downgrade attacks. Discover how attackers bypass outdated authentication—and how to stop them before they succeed.

 

 

 

 

 

 

Frank Raimondi, VP, IGI Channel Alliances & Partnerships, clarifies the difference between assessments, management and testing—and why continuous vulnerability management is key to compliance and resilience.

 

 

 

 

 

 

Ashley Cooper, COO of CyberDrain, tackles the hidden costs of operational chaos in MSP environments. She explains how misaligned awareness—not bad intent—often causes breakdowns between systems, teams and tools.

 

 

 

 

 

 

Spencer Pollock, data privacy and cybersecurity attorney at McDonald Hopkins, outlines how your pre-breach policies and post-breach actions shape legal and regulatory outcomes—and why documentation is your best defense.

 

 

 

 

 

 

Degly Mendez, CEO of Avanzar IT Systems, shares a practical framework for smarter IT budgeting: Run, Protect, Grow. He explains how MSPs and SMBs can turn budgeting into a strategic decision system.

 

 

 

 

 

 

Chris Loehr, EVP and CTO at CFC Response / Solis, shares essential advice for MSPs navigating the complex world of incident reporting, including the key steps to stay compliant and avoid costly missteps. 

 

 

 

 

 

 

Matt Lee, senior director of security and compliance at Pax8, breaks down the shift to identity-centric security and how modern authentication methods like FIDO and TPM can protect users without adding friction.

 

 

 

 

 

 

Josh Hohbein, information security lead at CentrexIT, breaks down the GTIA Trustmark and why it matters. He explains how clarity, credibility and capability turn cybersecurity from a checklist into a culture—and why independent validation is key to building client confidence.

 

 

 

 

 

 

Paul Croker, founder and CEO, 18iT, offers practical tips to secure mobile devices—from encryption and app permissions to MDM tools—before they become cyber liabilities.

 

 

 

 

 

 

Jason Slagle, president at CNWR, explains why defining your ideal client profile is critical in cybersecurity—and how aligning services to client size and risk can improve protection and profitability.

 

 

 

 

 

 

Steve Brining, TRU partner technology evangelist at Acronis, explains why MSPs must treat client regulatory obligations as their own—and how to become a trusted compliance partner through transparency and readiness.

 

 

 

 

 

 

Wade Kilgore, CTO at Axxys Technologies, Inc., shows how clearly defined roles and mutual accountability reduce risk and improve client relationships in cybersecurity service delivery.

 

 

 

 

 

 

Jürgen Ebner, ICTE - Managed Services, explains why small businesses are prime targets for cyberattacks—and shares three simple steps every leader should take to protect their organization.

 

 

 

 

 

 

Ann Westerheim, founder and president at Ekaru, explains why cybersecurity culture matters more than tools. Discover how awareness, habits and shared responsibility protect your organization.

 

 

 

 

 

 

Dave Alton, chief technology officer, Strategic Information Resources, shares how community support and small daily actions build real security acumen and resilience for ITSPs, MSPs and SMBs.

 
 
 
 
 
 
 
 
 
 
 
Brad Powell, co-founder and captain of revenue, ThreatCaptain, breaks down the universal language of risk—business, technical, compliance and human—and shows how framing risk clearly helps leaders build resilience.
 

 

 

 

 

 

 

Jason Comstock, president, Clarity Technology Solutions, explains how to build a “healthy state of paranoia” around email and train teams to spot phishing threats using bite-sized, repeatable education.

 

 

 

 

 

 

Tish Williams, partnerships manager, Token, highlights the power of biometric MFA in protecting digital identities, reducing phishing risk and supporting compliance across industries.

 

 

 

 

 

 

Charles Love, director of operations, ShowTech Solutions, shares why MSPs must use the same security tools they sell. Learn how internal practices shape credibility and customer protection.

 

 

 

 

 

 

Henry Timm, CEO, Phantom Technology Solutions, outlines four trends reshaping cybersecurity for MSPs—from AI-powered threats to compliance as a competitive edge—and shares how GTIA helps providers stay ahead.

 

 

 

 

 

 

Bookmark this page and check back all month as we add new Cyber Bites!

Learn about GTIA Cybersecurity Programs.

Related Posts:

Aaron Jacobs says winning the GTIA Cybersecurity Leadership Award is both an honor and a reflection of the hard work and commitment he's put into helping businesses across ANZ strengthen their cybersecurity posture.
By Scott Campbell / Oct 18, 2024

5 Questions with Aaron Jacobs: 2024 GTIA - ANZ Cybersecurity Leadership Award Winner

When it comes to cybersecurity incidents, Aaron Jacobs isn’t one to sit on the sidelines. As a senior global solutions engineer, security operations, at Sophos, Jacobs is a first responder when a new threat emerges, tasked with investigating and analyzing situations that can help better protect MSPs and their clients.
Street sign
By Haines Eason / Oct 21, 2025

Cybersecurity’s Main Street Problem: The Small Business Disconnect

Ann Westerheim is blunt about the disconnect she sees every day. As founder of Ekaru, a cybersecurity-focused MSP in Boston, she spends much of her time trying—and sometimes failing—to convince small business owners that they’re at risk. “People only see headlines for what’s happening with big business and they’re not seeing the headlines for what’s happening with small business,” she said. That perception gap runs deep. When a Fortune 500 company gets breached, it makes national news. But when a ten-person accounting firm loses its client data in a phishing scam, no one outside the victims and their clients will ever hear about it. For the business owner, though, the damage is existential. Small businesses are hardly a niche: They account for roughly half of the U.S. economy, 40% of private payroll and a quarter of government contract work. Yet their cyber defenses can be shockingly weak, and their owners may also shockingly believe they are “under the radar.” That illusion is costly. In Massachusetts alone, Westerheim points to half-million-dollar losses at Arlington schools and the town of Franklin due to simple business email compromise scams.