554 episodes
- The episode scrutinized the operational impact of accelerated patch velocity, largely attributed to AI-driven vulnerability discovery. Microsoft’s patch release cadence has intensified, as evidenced by the increase from 200 patches in June to 900 patches in September. Despite this uptick, panelists noted that patch delivery is now consolidated—vulnerabilities are addressed through a single cumulative update per cycle rather than via hundreds of discrete patches. This structural change reduces exposure to widespread outages, but risk must still be evaluated based on deployment timing and organizational context.
Delaying patch deployment by at least one week post-release was advocated as a harm-reduction strategy. The rationale is that “dead body Wednesday”—the day following Patch Tuesday—commonly reveals unforeseen operational disruptions. Forum monitoring and the identification of industry-specific tolerances are recommended, supported by the observation that most incidents arise from edge cases or latent infrastructure flaws exposed by reboot cycles rather than patch malfunction itself. The role of Microsoft in acknowledging and remediating issues was discussed, with a particular emphasis on the lag between incident emergence and vendor acknowledgment.
A secondary focus addressed the expanded risk surface beyond Windows, emphasizing IoT, networking, and edge devices. The lack of standardized, automated patching for non-Windows assets, such as security cameras, printers, and other IoT endpoints, multiplies the challenge for practitioners. Neither firmware nor update methodologies are unified, necessitating manual intervention and physical connectivity in many cases. The episode further touched on IT governance concerns, particularly around excessive permissioning, data management, and the tendency for access requests to escalate rather than contract over time, exacerbating organizational risk.
For MSPs and IT service providers, key implications center on risk-managed operations. Patch deployment processes should be routinely assessed and customized based on client risk profiles, infrastructure complexity, and historic pain points. Increased vulnerability discovery via AI necessitates enhanced organizational discipline around both patch timing and post-patch monitoring. Security governance—especially regarding permissions scopes, data segmentation, and the extensibility of third-party integrations—was underscored as an operational priority. Comprehensive asset management and organizational awareness of fragmented patch ecosystems, especially in IoT and edge contexts, will be essential for maintaining resilience and accountability.
What should I do differently now that AI is throwing us so many patches?
Show Rundown & Banter: Amy is joined by longtime Microsoft MVP Susan Bradley, the “Patchaholic,” to discuss Microsoft updates, patching, and what IT professionals need to watch.
Question of the Week: How should MSPs change their patching strategy in the age of AI? Microsoft’s updated guidance calls for short quality-update deferrals and faster installation deadlines.
https://learn.microsoft.com/en-us/windows/deployment/windows-autopatch/references/policies-quality-updates
Tales from the Field: When reimaged machines started failing — Susan shares a story involving Dell machines and unexpected failures.
Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising. - Public speaking for technical professionals and the development of practical business process automation using AI were identified as areas with tangible operational impacts for MSPs. Structured preparatory practices, such as rehearsals and simulated audiences, were described as beneficial for reducing employee apprehension and improving presentation quality, according to Amy Babinchak. Applying a process-oriented approach, including content development and reference to audience-specific expertise, can support staff development, help mitigate presentation anxiety, and promote more effective communication of technical concepts.
Process automation and AI monetization were explored through concrete examples. Amy Babinchak outlined several applications, including contract obligation tracking through AI agents, automated identification and drafting of overdue invoice notifications via read-only accounting system access, and AI-driven verification of job site photographs. Each was presented as a method for improving operational efficiency and reducing manual workload, with an emphasis on direct business outcomes such as time savings and risk reduction. The discussion cautioned that routine use of generative AI for basic tasks like search and email drafting does not readily produce measurable value unless integrated into broader workflow optimizations.
The episode also addressed marketing tactics relevant to year-end business cycles and inventory management. James Kernan recommended executing inventory reduction campaigns, such as open-box or scratch-and-dent sales, to address stock overages. The timing of client upgrade campaigns was connected to product end-of-life events, specifically referencing Windows Server 2016 and SQL Server 2016, as opportunities to drive sales while reducing client risk associated with unsupported software. The conversation further covered managed service delivery models, identifying potential risks and tradeoffs in offshoring, automation, and outsourcing core client-facing services.
For MSPs and IT leaders, the operational implications are clear: public speaking proficiency and client communication should be built intentionally, involving structured practice to reduce risk of poor delivery. AI and automation initiatives should prioritize process alignment and quantifiable outcomes, not just adoption for novelty’s sake. Inventory and lifecycle management present opportunities for improving both sales and client relationships, but require a disciplined approach to timing and messaging. Regular review of outsourced or automated functions is encouraged, with attention to maintaining a personal client interface and managing the organizational and reputational risks of dehumanized service.
How can I become a better public speaker?
Show Rundown & Banter: What’s new?
Question of the Week: How can I become a better public speaker? Focus on preparation, simple slides, eye contact, pauses, practice, breathing, and handling mistakes.
AI Interest to AI Impact: Help clients move from experimenting with AI to delivering measurable results.
https://www.channele2e.com/perspective/msps-need-to-push-clients-past-ai-experimentation
Marketing Tips – Year-End Campaigns: Promote open-box/year-end projects, address Microsoft end-of-support deadlines, follow up with late payers, and host casual client events.
https://learn.microsoft.com/en-us/lifecycle/end-of-support/end-of-support-2026
Outsourcing Service Delivery: What should MSPs outsource — answering calls, dispatch, L1/L2 support, L3 escalation, or out-of-state projects?
GTIA Acquires ASCII: What does the acquisition mean for the MSP community and channel?
NinjaOne Browser Security: Discuss NinjaOne’s new browser-based security offering and what it could mean for MSPs.
Tales from the Field: Timing is Everything.
Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising. - Microsoft's Copilot platform has recorded a 33% growth, growing its user base from 20 million to 30 million seats in a three-month period, according to reported company data. Increased adoption is attributed in part to Microsoft's strategy of bundling Copilot licenses with existing products. Copilot lacks custom code-generation features, instead focusing on business process optimization and employee productivity. Microsoft's switch from OpenAI to Anthropic as the underlying model for Copilot reflects a shift toward features that align more closely with user workflow support.
Supporting this development, comments noted that Fortune 500 and Fortune 1000 organizations are increasing their adoption of Copilot. Analysts highlighted Microsoft’s historical pattern of entering competitive spaces from a less dominant position and gradually increasing market presence. This strategy, combined with integration into widely used platforms, has contributed to the acceleration of Copilot’s uptake. The focus of the current Copilot version remains on facilitating business tasks rather than technical automation.
A secondary discussion covered marketing challenges for MSPs in a business environment shaped by the proliferation of AI tools. Peer group insights stressed that traditional digital marketing channels such as search and online advertisements are declining in effectiveness, with leaders instead reporting positive results from personalized outreach methods. Techniques identified as effective include public speaking at local business events, distributing real-time security and AI tips via email and video, and leveraging social media with authentic, direct content. Separately, a new CISA Insider Threat Guide was highlighted for its practical utility in offboarding, job change, and broader operational security processes.
For MSPs and IT service providers, the reported trends emphasize the need to adjust operational approaches in both services delivered and go-to-market strategies. The rapid expansion of Copilot signals increased customer expectations for workflow-integrated AI features and raises questions of vendor dependency and differentiation. At the same time, the diminishing value of broad digital marketing highlights the risks of relying on legacy lead-generation channels. Instead, practical field examples and security case studies suggest a shift toward higher accountability, lateral risk management, and more direct forms of engagement to mitigate threats and maintain competitiveness.
AI Killed Marketing- Now What?
Show Rundown & Banter: What’s up? End of boating season and football season.
Question of the Week: AI killed marketing! What’s actually working now?
CISA Insider Threat Guide: How MSPs can help clients detect insider threats, manage employee offboarding, secure access, and build an ongoing insider threat program.
https://www.cisa.gov/
Get Clients Ready for Copilot: Copilot adoption is growing. Discuss readiness reports, data governance, and security guidance before rollout.
AI Solves a Difficult Math Problem: OpenAI reportedly solved the Navier–Stokes problem using AI agents. Is this progress for mathematics, or could it weaken human scholarship?
Tales from the Field: The case of the underquoted bids — a security investigation reveals an employee leaking quotes to a competitor
Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising. - The episode centers on operational best practices and core risk factors for MSPs preparing to sell their businesses. The discussion highlights that a business must be able to function independently of its owner, with Amy emphasizing that the most important prerequisite for sale is organizational self-sufficiency. Buyers prioritize businesses that can maintain their operations, client relationships, and financial health following a change in ownership. The need for clean, auditable financials and contract organization is underscored as key requirements for reducing risk and promoting transaction confidence.
Further guidance is provided regarding exit strategy planning and business positioning. Owners are advised to clarify the desired type of exit—such as complete disengagement versus remaining in the business post-sale—and to consider factors such as buyer preference and legacy concerns. Both buyer and seller risk are increased by high client concentration, undefined leadership teams, and missing or ambiguous vendor commitments. Steady, incremental growth—rather than stagnation or decline—was cited as a marker of business stability and a factor that increases attractiveness to potential acquirers.
Adjacently, the conversation addresses developments relevant to technology and operational security. The discussion notes Microsoft’s release of updates to address over 400 vulnerabilities in Windows in a single month, which represents a four to ten times increase over the previous year’s counts for the same periods. The accelerating pace of vulnerability discovery and exploitation, driven in part by adversarial and defensive use of AI, is causing traditional patching regimens to become inadequate. Amy described this collapse of the patch window as a significant industry risk, with particular exposure in under-patched IoT and embedded systems.
MSPs and IT decision makers are advised to update succession and sale-readiness practices, stressing the importance of organizational hygiene, data transparency, and realistic self-assessment. The acceleration of security threats and increased complexity of vendor landscapes indicate that risk management processes must evolve rapidly. Owners should prioritize eliminating operational dependencies, ensuring rigorous contract and financial management, and modernizing their approach to security and resilience to preserve value—both for ongoing business health and as preparation for potential sale or transition.
What are the top 10 things I should do before I sell my business?
Question of the Week: Top 10 things to do before selling your MSP — prepare the business, finances, operations, team, customers, legal documents, and due diligence.
Facebook’s $17B Settlement: What does it mean for tech companies and accountability?
https://www.azag.gov/press-release/attorney-general-mayes-announces-largest-big-tech-settlement-history
MSP Market & PSA Trends: Jay McBain’s latest market-share and growth trends.
Microsoft Patching: 400+ vulnerabilities fixed in August. What does this mean for MSPs and proving value?
https://www.techrepublic.com/article/news-microsoft-august-2026-patch-tuesday/
Marketing for MSPs: What’s actually working for lead generation?
https://www.connectwise.com/resources/msp-marketing-report
AI Agent Safety: Key safety rules for using AI agents and meeting assistants.
Tales from the Field: Why are you selling — burnout or retirement? Get your story straight.
Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising. How Local MSPs Can Outshine Big Nationals: Tips, Accreditation, and Insurance Essentials
03/09/2026 | 21 mins.A primary development addressed is the increasing scrutiny and demands from cyber insurance providers on MSPs and their clients. Amy highlighted a case where an insurer canceled a client policy after the MSP could not produce comprehensive reports and logs verifying device management for all endpoints, including BYOD and personal devices. This incident underscores rising expectations from insurers for documented security controls covering all systems interacting with sensitive data, and the risk of coverage denial when undisclosed devices or unmanaged endpoints are discovered following a breach.
Supporting discussion featured the operational gaps many MSPs face, especially regarding the management of BYOD and personal devices. Amy and James both emphasized that insurance companies are increasingly insistent on verifiable evidence that data protection policies apply to every device with data access. Failure to comply with these mandates, or misrepresenting coverage in pre-insurance questionnaires, may not only result in claim denials but also expose the MSP to downstream liability and litigation risk. They also stressed the need for clear contractual exclusions and robust internal insurance for the MSP to mitigate risk transfer.
A secondary theme centered on the competitive pressure local and regional MSPs face from consolidation through roll-ups and the expansion of national firms. Both speakers identified differentiating on local presence and community engagement, such as sponsoring local events or supporting local causes, as key strategies for smaller providers. Additional discussion covered the new NSITSP accreditation and CE program, designed to establish a credentialing framework for MSPs, analogous to existing models in law and accounting. Amy suggested that the ability to market accredited status would address client needs for objective quality comparison between providers.
Takeaways for MSPs, IT service providers, and decision-makers include the importance of establishing precise, documented security controls aligned with insurance requirements, especially for unmanaged or BYOD endpoints. Clear, detailed contractual language is necessary to define service boundaries and liabilities. Maintaining up-to-date accreditations and engaging in ongoing staff education were discussed as foundational to both risk management and market differentiation. Finally, operational alignment with insurance, accreditation, and community expectations represents both a risk-reduction tool and a practical framework for navigating consolidation and regulatory scrutiny in the current environment.
How do I protect my MSP from roll-ups and national firms?
Question of the Week: How do I protect my MSP from competition from roll-ups and big national firms? Lean into being local, unique, and personal.
NSITSP CE Program: NSITSP launches CE-accredited programs, with Bigger Brains, IT Services University, and Karl Palachuk among the first providers. What does this mean for MSPs, and who is leading education in our industry?
https://nsitsp.org/education/
Cyber Insurance Controls: Insurers are demanding more than security controls—they want a complete inventory of every device touching client data, including BYOD and contractor devices. What MSPs need to know.
https://www.channelpronetwork.com/2026/08/26/cyber-insurance-device-requirements-what-msps-need-to-know/
Tales from the Field: The computer that turns itself off — a story from Nathan Fay.
Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
More Business podcasts
Trending Business podcasts
About SMB Community Podcast
Podcasts, articles, and reference materials for Managed Service Providers. Produced by MSP Radio
Podcast websiteListen to SMB Community Podcast, A Bit of Optimism and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


SMB Community Podcast
Scan code,
download the app,
start listening.
download the app,
start listening.
SMB Community Podcast: Podcasts in Family





























