Episode Description
Your client wants you to “make us compliant,” but nobody on their side will approve policies, review risks, or chase employees. Then a questionnaire shows up and suddenly everyone needs twelve months of evidence by Friday.In this episode, we talk about where MSP responsibility ends, why executive ownership matters, and how routine evidence collection keeps compliance from turning into a fire drill.Takeaways:• Compliance needs an internal executive owner who can make decisions and unblock people.• If leadership refuses to participate, the MSP may need to walk away instead of absorbing the risk.• Evidence collection should match the risk and the system, not run on one arbitrary cadence.• Useful evidence can include screenshots, reports, tickets, meeting records, backup tests, and access reviews. Screenshots should show enough context to identify the system and time.We answer:• Our client keeps delegating compliance to us. What can the MSP own, what must the client own, and what happens if they refuse?• Every questionnaire becomes a fire drill. What evidence should a small business and its MSP collect routinely before anyone asks for it?Make sure to follow the podcast or ask your own questions at:https://blacksmithinfosec.com/nisty/