The cybersecurity market’s growth curve looks enviable on paper. North America’s managed security services market is projected to climb from $7.5 million in 2025 to $45 million by 2032, an 11 to 12% annual growth rate.
But Roddy Bergeron, cybersecurity technical fellow at Sherweb, warns MSPs not to confuse market tailwinds with maturity.
“The global average cost of a breach is $4.5 million,” he said during a ChannelCon 2025 panel. “The U.S. average is 10 and a half million—two and a half times higher. That has to do with increased regulation and increased pressure. And that’s good news in a way because there’s going to be more money in the market. But we still have huge challenges.”
Those challenges, Bergeron argued, aren’t primarily technical. They’re human. And if MSPs want to build RRRAD cybersecurity programs—resilient, responsible, ready, accountable and defensible—they must start with people, not products.
Resilience: Trust Your People to Fail, and Expect Them to Have Lives
“Every successful security program is built with four legs: People, process, policies and tools,” Bergeron said. “And I put these in specific order because tools are the last thing you should be talking about.”%20(1).jpg?width=335&height=223&name=ChannelCon2025_7015-lowres%20(1)%20(1).jpg)
That inversion is deliberate. Bergeron spends most of his time hammering home people issues: The lack of leadership development, the fragility of the workforce pipeline and the need to treat employees as human beings during crises.
“Building leadership is hard,” he said. “You take them out of their comfort zone and you let them fail, because nothing humbles a person more than a failure. Nothing builds integrity or character like learning from a mistake.”
The I’m Not Doing That Generations, Plural
As for challenges and grit, Bergeron did skewer the education system some for holding students’ hands until they’re unprepared for the workplace. He pointed to middle schoolers who already dismiss college as too expensive and misaligned with their goals.
But he highlights a generational shift toward lifestyle priorities over paycheck size. Maybe there’s some grit aversion, but there’s also some I’m not going to toil at a job I hate like my parents did attitude.
“The younger generation doesn’t want to put up with the bullshit,” he said. “They will call you out and they’ll not come work for you. So again, it doesn’t mean bend over backwards and give them the world. It means you have to meet them somewhere and meeting them somewhere involves talking about their lifestyle.”
Bergeron pushes MSPs to rethink hiring.
“People with bartending experience, front-of-house experience, customer service experience will make better help desk techs than someone that went into a four-year degree program,” he said. “Disagree with me. That’s my hot take for the day.”
And when incidents strike, he insists MSPs cannot lose sight of the human toll.
At a nursing home breach, Bergeron recalled, staff were minutes away from dispensing life-critical medications without digital records. At an aviation company, the first question wasn’t about system recovery—it was “when do I get paid?”
“In every single disaster recovery plan I’ve done, I have never addressed how do you pay salaries,” he said. “We do not focus on that enough.”
Effective Policies Are Living Documents, Not Dust-Gathering Docs Meant for Binders
Bergeron’s second pillar—policies— comes with its own blunt warning.
“If you’re just writing a policy for the sake of having a thick piece of paper or a thick stack of documents on a shelf that collects dust, you’re doing it wrong,” he said.
Policies should address confidentiality, integrity, availability, plus authentication and non-repudiation. They should begin by defining the problem, then be designed, adopted, implemented and regularly reviewed.
Templates are fine, he notes, but only if customized to the organization.
“Please update it, make it your own, use your own words,” he said. “Don’t just take the template and be like, ‘I have a policy now.’ That’s not how it works.”
Processes That Don’t Suck
Clear, repeatable processes aren’t just about efficiency—they’re about quality of life.
Bergeron tells MSPs to write instructions “so clear a salesperson can read it and know what to do.”
Automation should follow once processes are nailed down. And the 80/20 rule should guide priorities: Fix the 20% of tasks that drive 80% of the pain.
His litmus test? Ask staff “what sucks.”
“We started asking, what sucks? What do you hate to do? We called it quality of life improvements,” he said. “Not only what can save you time, but what saves your staff headaches.”
Bergeron also insisted processes themselves need a process: Documentation, peer review and centralized repositories to make knowledge accessible across teams.
Yup, You Read It Right: Technology Last
A vendor himself, Bergeron showed remarkable disdain for the way vendors sell. “I hate when vendors get in front of a stage and say, let’s talk about your stack,” he said. “I’ll tell you, the only person that cares about your stack is you and your vendors because they’re trying to sell you more stuff. And I’m saying that as a vendor.”
Clients, he said, care about outcomes. They want revenue protected, not acronyms recited. That’s why vendor risk management is where MSPs should focus.
“How many people go back and check the permissions their vendors have, not just their IT vendors, but your accounting firms?” he asked. “We trust our vendors way too much to be doing the right thing.”
He warned against taking SOC 2 reports at face value, calling many of them “full of garbage.” Instead, MSPs must dig into scope, controls and what’s actually being enforced.
Responsibility, Not Excuses
If there’s one principal hill Bergeron will die on when it comes to working with MSPs, it’s responsibility—contractual, operational and social. He advocated putting the RACI model (responsible, accountable, consulted, informed) directly into MSAs.
“If you’re not telling your clients who’s responsible for what, then you’re responsible for it,” he said.
And he insisted MSPs acknowledge duties that no contract can waive.
“We should not have to have the minutia of making sure that that human social contract is still enforced,” Bergeron said. “If I hand you a sensitive piece of data, you’re going to protect it. I feel like that is a no-brainer for most people. We can’t let contracts say otherwise.”
KPIs Are Clues, Not Contracts
Bergeron closed with a cautionary note on key performance indicators. “Most of the time we say, good numbers go up, it’s good; good numbers go down, it’s bad. But it’s not how KPIs work,” he said. “KPIs are an indicator that something’s changed and we still need to go investigate them.”
A technician with low billable hours might actually be doing critical security research. A drop in reported vulnerabilities might reflect a reporting glitch, not a safer environment. “Don’t just take it at face value,” he warned. “Always do your full investigation.”
The Church of the Rising Tide
Bergeron ended on a rallying cry: MSPs must elevate each other and the industry. “You are all now members of the Church of the Rising Tide,” he told his panel audience. “You need to go and hold people accountable—vendors, your fellow MSPs, call them out on bad practices. Always praise in public and chastise in private. Help us elevate this space.”
For him, the math is clear: Technology will keep evolving, but unless MSPs fix the human side—leadership, workforce, relationships, responsibility—the cybersecurity market’s growth won’t mean maturity.
“Technology will always fix technology,” he said. “But the human piece is where we’re going to continue to fail, and things aren’t going to get better until we fix the human problems.”
Learn more about GTIA Cybersecurity Programs.

