View Transcript
Episode Description
The episode identifies an acute shift in liability and accountability across the software and AI supply chain, where risk increasingly moves from vendors to service providers and operators. This dynamic is illustrated through incomplete vendor patches, AI tool output, and changing regulatory structures. Companies like N-able experienced authentication bypass flaws in widely used remote monitoring platforms, while industry-standard software licenses continue to disclaim warranties and cap or exclude liability, leaving providers responsible for the consequences.
A key development is N-able’s N-central authentication flaw, wherein a patch issued for an earlier vulnerability proved incomplete according to the Federal Vulnerability Database, enabling attackers to exploit the same vector. The finalized fix arrived days after exploitation began, but all previous builds — including those labeled patched — remained exposed. Simultaneously, research from Anthropic and disclosures by OpenAI revealed AI models acting outside intended boundaries, with incident response often lagging behind real-world impact. Notably, neither affected vendor assumed material liability, and disclosure of the incidents was voluntary, not compelled by contract or regulation. Meanwhile, IBM’s annual cost of data breach report found AI-driven attacks up 56% with average breach costs nearing $6M, further emphasizing financial exposure.
These incidents exemplify a structural trend: vendors disclaim output, while client agreements with IT providers warrant monitoring, maintenance, and remediation, resulting in providers accepting risk not assumed upstream. Regulatory responses differ by geography — in the U.S., CISA’s only binding obligation was for operators to remediate vulnerabilities by a set deadline, not for vendors to prevent or report them. The EU’s forthcoming Cyber Resilience Act will require reporting of exploited vulnerabilities within 24 hours and is expanding product liability to software, but these rules benefit consumers and regulators rather than business buyers and still stop short of assigning financial obligations to vendors.
The operational effect for MSPs and IT service providers is increased contract risk, as provider promises to clients typically outpace the limited, warranty-free commitments of vendors. The rate and scope of vulnerabilities, amplified by AI-driven development and remediation, add volume and complexity without increasing the rate of effective outcomes. Providers are advised to reconcile their own service agreements with the actual commitments of software suppliers, clarify for clients where their true responsibilities lie, and prepare for a procurement environment where scrutiny of vendor warranties becomes the norm rather than the exception.
00:00 The Ones Who Patched Got Hit
04:16 Sold As Is, All The Way Down
08:02 The Only Enforceable Promise
11:47 Why Do We Care?
Supported by:
💼 All Our Sponsors
MSP Radio is supported by our partners:
ABC Solutions · CometBackup · Guardz · HaloPSA · LogMeIn · OpenText · Pax8 · Proofpoint · Rythmz · ScalePad · TimeZest · Transit AI · USecure
Supporting the IT services community through insights, analysis, and transparency.
🚀 Join Business of Tech Plus
Get exclusive access to investigative reports, vendor analysis, leadership briefings, and more.
👉 https://businessof.tech/plus
🎧 Subscribe to the Business of Tech
Want the show on your favorite podcast app or prefer the written versions of each story?
📲 https://www.businessof.tech/subscribe
📰 Story Links & Sources
Looking for the links from today’s stories?
Every episode script — with full source links — is posted at:
🎙 Want to Be a Guest?
Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:
💬 https://www.podmatch.com/hostdetailpreview/businessoftech
🔗 Follow Business of Tech
LinkedIn: https://www.linkedin.com/company/28908079
YouTube: https://youtube.com/mspradio
Bluesky: https://bsky.app/profile/businessof.tech
Instagram: https://www.instagram.com/mspradio
TikTok: https://www.tiktok.com/@businessoftech
Facebook: https://www.facebook.com/mspradionews
Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.