View Transcript
Episode Description
The dominant mechanism addressed is the development of a self-regulatory framework for IT service providers, specifically as Texas A&M University's Global Cyber Research Institute (GTIA) launches the Consortium for Responsible IT Services (CRITS). This signals a move toward organized self-governance and standard-setting within the MSP sector, in contrast to direct government-imposed regulation. The initiative is designed to shift the industry from fragmented standard adoption toward collective risk and professional accountability, using academic infrastructure and industry funding as its operational backbone.
According to statements from Cole Knuth, GTIA’s facilitation of CRITS involves university-hosted development and company funding, with the intention to produce a publication outlining operational and cybersecurity standards for IT service providers. The university has committed both its name and financial resources, making CRITS a formal legal construct enabled by Texas A&M’s research arm. The initial executive sponsors are large industry players—New Charter, Pax8, and The 20—but there is not yet independent MSP participation under 25 employees. The first member meeting is scheduled to occur alongside the GCRI Summit in October.
The episode contrasts CRITS with prior efforts to establish industry standards, noting previous initiatives by the MSP Alliance, NSITSP, and GTIA’s own Cybersecurity Trustmark, none of which achieved broad acceptance or regulatory recognition. Cole Knuth attributes this lack of traction to fragmented grassroots approaches or top-down lobbying, asserting that CRITS aims for a “middle out” model by aggregating MSP voices to build legitimacy and influence before external regulation is enacted. The consortium’s design includes the possibility of recognizing existing certifications rather than displacing them, and emphasizes eventual inclusion of smaller and independent MSPs in governance.
For MSPs and IT leaders, the practical implications include increased pressure to participate in the development and adoption of industry standards to mitigate liability risk and avoid externally imposed rules. Operational challenges are likely to include the need for resource allocation to compliance initiatives, cost uncertainties regarding participation and auditing, and navigating evolving governance requirements as standards are defined. Smaller MSPs face the risk of exclusion unless explicit mechanisms are created for their input and representation, and the structure of CRITS may lead to new layers of compliance complexity and scrutiny, particularly as the consortium transitions from initial large-member funding to broader industry engagement.
Supported by:
💼 All Our Sponsors
MSP Radio is supported by our partners:
ABC Solutions · CometBackup · Guardz · HaloPSA · LogMeIn · OpenText · Pax8 · Proofpoint · Rythmz · ScalePad · TimeZest · Transit AI · USecure
Supporting the IT services community through insights, analysis, and transparency.
🚀 Join Business of Tech Plus
Get exclusive access to investigative reports, vendor analysis, leadership briefings, and more.
👉 https://businessof.tech/plus
🎧 Subscribe to the Business of Tech
Want the show on your favorite podcast app or prefer the written versions of each story?
📲 https://www.businessof.tech/subscribe
📰 Story Links & Sources
Looking for the links from today’s stories?
Every episode script — with full source links — is posted at:
🎙 Want to Be a Guest?
Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:
💬 https://www.podmatch.com/hostdetailpreview/businessoftech
🔗 Follow Business of Tech
LinkedIn: https://www.linkedin.com/company/28908079
YouTube: https://youtube.com/mspradio
Bluesky: https://bsky.app/profile/businessof.tech
Instagram: https://www.instagram.com/mspradio
TikTok: https://www.tiktok.com/@businessoftech
Facebook: https://www.facebook.com/mspradionews
Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.