Skip to content
HeyJared

Get NIST-y

Get NIST-y is a podcast that breaks compliance out of the checkbox trap and turns it into a real security advantage. No fluff, no FUD—just practical strategies to make compliance work for your MSP.

Podcast · By Blacksmith InfoSec · English · Official site

Indexed episodes, last 90 days
13
Latest publication
Sep 29, 2026
Audience
Checking…
Earliest in this view
Jul 7, 2026

Latest episodes

  1. Episode · Sep 29, 2026

    Beyond the Badge: GTIA Trustmark, SOC 2, and MSP Maturity (opens the original)

    Episode notes

    Read excerpt

    Following NIST or CIS is useful, but does it prove your MSP can actually operate under pressure? Chris "CJ" Johnson from GTIA joins us to talk about the Cybersecurity Trustmark , what security maturity looks like in practice, and why proof of controls is not the same as mature governance. Takeaways: Why the Trust Mark focuses on maturity, governance, leadership, and culture Why “we have a SOC 2” means very little until you look at what is actually in scope Why MSPs can help clients manage risk w

  2. Episode · Sep 22, 2026

    Minimum Viable Security: Build It and Keep It Running (opens the original)

    Episode notes

    Read excerpt

    Antivirus, backups, and MFA are a start. They won't tell you how payroll runs when the check printer is inaccessible or keep your risk register current six months later. This week, Jared and Mike talk about what a small business actually needs and how to keep that work going. - Identify the client's critical data and the processes that keep the business running. - Check the less obvious dependencies, from break-glass accounts to the payroll check printer. - Use CIS Implementation Group 1 as a st

  3. Episode · Sep 15, 2026

    Your MSP Is Not the Client's Unpaid Compliance Department (opens the original)

    Episode notes · Critical tone

    Read excerpt

    It started with one questionnaire. Now you're the compliance department, and apparently that's included in the flat rate. On Get NIST-y, Blacksmith InfoSec's cybersecurity and compliance podcast for MSPs, we're talking about who owns the program and who pays for the work. - Name one executive owner at the client before work starts. Your day-to-day contact doesn't have to be that person. - Check the contract before charging for new work. Catching up on patching you already owed is different from

  4. Episode · Sep 8, 2026

    AI Policy After the Horse Has Already Left the Barn (opens the original)

    Episode notes

    Read excerpt

    AI adoption happened before most clients wrote the rules. That does not make an AI policy useless. It changes the job from trying to stop AI to governing the tools already in use, training people to make better decisions, and protecting sensitive data. Takeaways: - Why governance, education, and security are the only realistic levers left - How the data, platform, subscription tier, and vendor agreement determine whether a prompt is acceptable - Why AI output still needs human validation, especi

  5. Episode · Sep 1, 2026

    New York Compliance: What the MSP Owns and What It Doesn't (opens the original)

    Episode notes

    Read excerpt

    Following NIST does not automatically cover New York-specific rules, and that does not mean your MSP needs to become a law firm. We sort out where legal counsel belongs, what the client must own, and which responsibilities an MSP can safely take on. We also thank our listeners for helping Get NIST-y win an MSP Influencer award.Takeaways:• Keep lawyers focused on legal and privacy questions, not every security policy detail.• Put one client executive in charge of the security program and risk.• T

Publishing over time

Last 90 days. Choose a month to open its work.

Recurring subjects

Named in the text we hold. One piece can cover several.

Not enough subject data for this period yet.

Audience

No verified audience measurement yet.

About this data

Counts cover the work we have indexed. Tone needs enough text and a confident classification. Excerpts and episode notes are not full articles or transcripts.

Identity or attribution wrong? Suggest a correction.

See coverage about Get NIST-y