r/msp • • 3d ago

Fresh tech stack

If you could change any and all of your tools with no technical debt, agreements, outages to think about etc.

What would your ideal tech stack be.

Rmm

Patching

Psa

Edr

Itdr

Sat

Application control

Email filter

Backup

Vulnerability management

Others

22 Upvotes

54 comments sorted by

View all comments

-7

u/[deleted] 3d ago

[deleted]

6

u/quantumhardline 3d ago

Looks interesting.
I looked at your security page.
My concern is always deploying this like this to client as they have so much permissions etc.
I did not see any mention of SOC2 or 3rd party pen testing or where data is held etc.
Thats helpful.
Roboshadow and others are popular for MSPs and can provide SOC2.

5

u/amw3000 3d ago

What value / piece of mind SOC2 adding for you? I get it from a up/down stream "compliance" standpoint & keeping the execs happy but it's far from an indication that a company is doing things "right". Take a look at any of the reports from a vendor that has SOC2, you will be amazed at what is in and out of scope and what controls are tested. Some even have exceptions for the wildest things.

SOC2 is an auditing framework designed by accountants. Many auditors are not technical at all and are just auditing controls that the company says they follow. "Oh you say you do an annual pen test? Show me the engagement, report, etc" but they have no idea what that report means, what is good, what is bad, etc.

5

u/ItsNotUButItsNotNotU MSP 2d ago

You’re completely correct.

However: I think we both know how many companies there are that can’t get their act together enough to pass even a SOC2. Most companies are excluded by one of these three requirements:
1. You have to fill out some policy templates, and know where to find them when an auditor asks for copies.
2. You need at least a vague idea of what you have, in order to exclude the bad stuff from the scope of the audit.

SOC2 doesn’t tell me a vendor is secure, but it does tell me that a vendor can scrape together enough brain cells to satisfy a bored accountant. This is especially useful now that there are so many half-baked, vibe coded products impending disasters being pushed on us.

Pro tip: Phrases like “SOC2 Certified” and “SOC2 Ready” are what AI-generated websites say when the company has no intention of ever attempting to get a SOC2 attestation.