IT service providers (ITSPs) are staring into the storm. Small and midsize businesses, once considered too small to be targets, now account for nearly half of all cyberattacks. AI has given low-skill adversaries the power to launch highly sophisticated campaigns. Regulators and insurers are cracking down, moving compliance scrutiny down market.
At ChannelCon 2025, Rob McDonald, chief product officer at Cytracom, delivered a blunt message: ITSPs can either drown in this chaos or profit from it. Compliance, he argued, is not just a requirement—it’s the next major revenue engine for the channel.
“Compliance isn’t a box-checking exercise,” McDonald said. “It should be a part of the DNA of your operational model.”
The Threat Landscape Isn’t What It Used to Be
McDonald broke down how cybersecurity challenges have shifted. Attacks today are multimodal: ITSPs must defend endpoints, networks, cloud, hybrid setups and bring-your-own-device environments simultaneously.
“We’re not dealing with single-modal threats anymore,” he said. “We’re facing multiple sophisticated categories all at the same time, which makes it a really unique environment for figuring out how to protect our customers. And let’s forget about protecting them for a second—explaining this threat landscape to them is extremely difficult.”%20(1).jpg?width=305&height=203&name=ChannelCon2025_6701-lowres%20(1)%20(1).jpg)
Supply chain compromises cut deep. McDonald cited the breaches of MOVEit, Microsoft and Okta as examples that shook industry confidence. Long-standing trust in software vendors, he said, is no longer enough.
“When Okta got popped, I thought the internet was going to melt down,” he recalled. “We all rely on Okta for the central identity store. These supply chain attacks completely undermine what those vendors are capable of.”
Insider misuse adds another wrinkle. Employees, under pressure in a strained economy, often turn to unsanctioned SaaS or AI tools just to keep up with workloads. These choices, McDonald warned, open doors for attackers.
“They’re not trying to be nefarious,” he said. “They just want to keep their jobs. But this kind of misuse is just as dangerous as a bad actor because it’s so hard to detect.”
And with SMBs typically running 30 to 50 cloud apps—enterprises more than 300—the sprawl of data across tools makes breaches more likely, harder to contain, and nearly impossible to explain to non-technical business leaders.
AI Levels the Playing Field for Attackers
For McDonald, the most disruptive change is how generative AI has weaponized scale. “The more data you feed these models, the more context they have and the more accurate the attack becomes for that particular target,” he said. “Combine public domain data, data broker files and generative AI, and what you’ve got is a highly personal machine gun that can target any company at scale.”
This dynamic echoes the late 1990s, he argues, when “script kiddies” with minimal skill were able to unleash sophisticated malware written by others. AI has lowered the barrier to entry again — but this time, with vastly more data at attackers’ disposal.
“SMBs think they’re hidden, that they’re too small to matter,” McDonald said. “But attackers don’t need to know your name. They can craft personalized attacks at virtually zero cost.”
That reality, he insists, is the story ITSPs must tell their clients. Fear alone isn’t enough; ITSPs need to frame compliance and operational maturity as protection for what matters most: reputation, customer trust and brand longevity.
Trust, Brand and the Compliance Compass
McDonald rails against viewing compliance as paperwork. For him, frameworks like NIST or CIS are not leashes but lenses—tools ITSPs can use to chart growth strategies and prove maturity. McDonald quoted cryptographer Bruce Schneier: “Security is not a product, it’s a process” and added that “you’ve got to have the conditioning, the muscle memory, the operational maturity to respond—not just assume a tool is going to solve the problem.”
Trust, he continued, is fragile and often overlooked.
“It took you a long time to earn that, didn’t it? It’s lost overnight. It’s lost in buckets,” McDonald said. “Evidence and discipline around maturity is how you hold the line and retain that trust.”
To him, compliance is really about demonstrating proof—not only to regulators and insurers, but also to customers. He sees ITSPs as “the digital bodyguards of this nation,” responsible for protecting the mid-market that makes up nearly 50% of all targeted attacks.
“If you walk into a room with operational maturity, belief in what you’re protecting, that SMB is going to realize their business is more important than they thought,” McDonald said. “That’s when they start to take compliance seriously.”
Insurance, Regulation and Stress-Inducing Scrutiny
Another driver behind this shift is the changing posture of insurers. Think you’re covered? Just because you bought a policy doesn’t mean you’re fully protected in all cases.
“Insurance groups are becoming forensic labs,” McDonald said. “They’re denying anywhere from 40 to 50% of claims. And they will find every reason to deny.”
It’s not about being jaded when it comes to insurance, he cautioned. It’s about proving compliance with evidence. Something as simple as multi-factor authentication applied only to admins rather than all users can void a claim.
At the same time, governments are extending regulatory pressure into the SMB sector. Compliance frameworks are no longer optional, McDonald argued, but a matter of survival. “There are no more free lunches,” he said. “SMBs are facing penalties, attestation requirements and a level of scrutiny they’ve never seen before. Be on the right side of that—prepare your customers with a maturity model.”
From Box-Checking to Business Growth
While the risks are real, McDonald stressed that ITSPs should see them as market opportunity.
Clients are already asking about compliance in RFPs and renewals, and ITSPs that lead with maturity can charge premium rates, retain customers longer and build “retention gravity” by embedding themselves deeply in client operations.
“What you’re really selling your customer is a better night of sleep,” McDonald said. “We’re monetizing trust. You’re not building trust to exploit it. You’re building trust by delivering value so you can harvest that value.”
The path forward, he argued, is incremental but deliberate: Start with data discovery; map where client data lives; apply frameworks; build remediation roadmaps in 3-, 6-, 9-, 12-month increments. Over time, this positions ITSPs not as IT firefighters, but as trusted risk advisors.
“Frameworks are compasses, not straitjackets,” McDonald said. “They guide you, they don’t strangle you. And once you adopt them, you can move from minimal maturity to leadership maturity.”
Keep It (and IT) Human
Though his subject is heavy, McDonald admitted his love for memes, declared that pineapples belong on pizza and anyone against the topping is a “truth denier” and argued that Sneakers is still the best cybersecurity movie ever made.
The levity helps underline his point: Compliance isn’t about doom and gloom. IT and IT security are about humans, including relationships, weaknesses and strengths, getting through tough or even seemingly impossible challenges, and embracing reality. The hard, human work of compliance can turn a chore into competitive advantage.
“You need to see yourself the way I see you—as the digital bodyguards of this nation,” McDonald told the audience. “If you believe that, you won’t burn out. You’ll recognize how important the work is, and your clients will feel that too.”
Lift Your Boat by Lifting Your Clients’
McDonald closed with another quote, this one from sales legend Zig Ziglar: “You don’t have to be great to start, but you have to start to be great.”
For ITSPs, that means shifting mindsets. Compliance isn’t another burden to bear or form to fill out. It’s the backbone of operational maturity, a foundation for trust and a differentiator in a crowded market.
“Burn the boat on Monday,” McDonald urged. “Do the data discovery. Sharpen your sword first, then productize it. The future is not one of less risk—it’s one of a lot more risk. Your customers need you as their trusted risk advisor.”
In other words: Stop seeing compliance as cumbersome chaos. Start seeing it as the ticket to longer-lasting relationships that can lift all boats—yours and your clients.
Get the support you need. Learn more about GTIA Cybersecurity Programs.

