At a recent luncheon, Trevor Hardy scattered QR codes around the building without explaining what they were. According to the founder and CEO of NEXTGen IT, more than 600 people scanned those codes. The links were harmless, but the exercise perfectly illustrated the danger of omnichannel threats. People routinely act on digital prompts because they look familiar and feel trustworthy.
That instinct is becoming a bigger problem for small and midsize businesses. Along with phishing emails, attackers can also reach employees through text messages, Microsoft Teams, LinkedIn, QR codes, phone calls and convincing audio or video impersonations. Artificial intelligence gives them the speed and polish to move across those mediums without the telltale mistakes that once gave scams away.
Hardy and Keith Johnson Jr., executive vice president of Obviam, discussed what that shift means for MSPs during a recent ChannelPro Deep Dive online event. Together, they painted a clear picture of the threat. They also gave sage advice on how MSPs must:
- Protect the way clients establish trust
- Build the operational capacity to respond
- Sell the outcome rather than a pile of products
Attackers have moved beyond the inbox
Email security is essential, but it cannot carry the entire defense in an omnichannel world. Johnson said identity sits above the individual channels because an attacker may impersonate the same person through several of them. MSPs need visibility into who is authenticating, from which device and location, and whether that identity’s behavior or privileges suddenly change.
Hardy put the change in sharper terms. “We’ve spent the last decade as MSPs securing the inbox while attackers moved on to securing our trust,” he said.
AI has accelerated that change. An attacker can research an organization, study how an executive communicates and build a credible impersonation far faster than before. “AI didn’t invent social engineering, but it definitely industrialized it,” Hardy said.
That makes recognition a weak security control. A familiar face on a video call, a recognizable voice on the phone or a message that sounds exactly like the CEO can no longer prove who is on the other end. “Recognition is no longer the authentication,” Johnson warned.
The practical response starts with process. A payment request, payroll change or credential reset should be verified through a separate, trusted channel. Employees also need permission to pause and question an unexpected request. Security awareness training still has a role, but the lesson must move beyond spotting a suspicious email to independently verifying a consequential request.
Build the response before adding the tools
The technology stack has to widen with the threat. “Defenders need the automation as well,” Johnson said, pointing to endpoint detection and response, active monitoring, vulnerability management and patching as the foundation. Hardy also emphasized managed detection and response (MDR), SaaS monitoring and immutable backups.
Still, both speakers argued, another product will not fix a weak operating model. The more revealing question is what happens at 2:30 a.m. Who receives the alert? Who investigates it? Who understands the cyber insurance requirements, preserves evidence and communicates with the client?
Those questions also help an MSP decide when to bring in an MSSP or another security partner. Hardy’s threshold echoes back to the question: Partner when a client’s risk exceeds the MSP’s 2:30 a.m. capability. The MSP can remain the client’s trusted lead while a specialist supplies around-the-clock monitoring, incident response or forensic expertise.
That partnership can also help prevent an expensive mistake. Wiping an infected system and restoring a clean backup sounds sensible, but it can destroy evidence needed by investigators or a cyber insurance carrier. A written incident response plan should establish authority, escalation paths, client responsibilities and evidence-handling procedures before anyone is staring at a live breach.
Contracts need the same clarity. If an agreement doesn’t mention a security task, the client may assume the MSP is handling it. MSPs should spell out what the provider covers, what the client must do and where a vendor or insurer enters the process.
Use the ‘Grandma Test’ and other clear communication
The revenue opportunity begins with a conversation about business risk, not fear. Johnson advised MSPs to connect security to the outcomes executives already care about, such as avoiding downtime, improving operational decisions and meeting insurance requirements. Recent news headlines already provide plenty of frightening examples. Clients need a roadmap, not another scare tactic.
Hardy uses what he calls the “Grandma Test.” If he cannot explain an issue so his 95-year-old grandmother would understand it, he must rephrase it. That means translating ransomware into an inability to operate, vulnerabilities into the likelihood of downtime and technical controls into the business problem they reduce. “Security isn’t fundamentally a skill set problem anymore. It’s a translation problem,” he said.
The same thinking should shape the offer. NEXTGen IT sells three packages: core services, a remote-only option and an advanced cybersecurity option. Hardy does not create a separate SKU for every tool because clients are not buying a contest between product names. “We’re not selling products. We’re selling outcomes,” he emphasized.
Turn security outcomes into recurring revenue
For an MSP building a similar practice, an assessment is a practical place to start.
- It creates a baseline for the client’s security maturity.
- It identifies the most meaningful gaps.
- Plus, it supports a phased plan.
Recurring services around continuous exposure management, more frequent vulnerability reviews, identity and SaaS monitoring, MDR, incident response preparation and backup validation can then follow that plan. Regular scorecards and business reviews can show what changed and remind the client what the service is accomplishing.
“If we’re solving meaningful problems and we’re demonstrating that value to our customers, then the revenue typically will follow,” Johnson said.
Embracing a zero-trust approach may be the most important lesson in the omnichannel era. Attackers are exploiting trust across every available path. MSPs can answer by becoming the partner that verifies, watches, responds and explains what it all means in language the client can act on.
Zero Trust is no longer optional; it’s the new baseline for cybersecurity. Join us for an interactive virtual event on December 2nd to learn how MSPs can implement Zero Trust frameworks that strengthen defenses, simplify compliance, and open the door to scalable, premium security services.
As ChannelPro’s online director and tech editor for over a decade, Matt Whitlock has spent years blending sharp tech insight with digital know-how. He brings more than 25 years’ experience working in the technology industry to his reviews, analysis, and general musings about all things gadget and gear.
Images: DALL-E















