Get NIST-y
Get NIST-y is a podcast that breaks compliance out of the checkbox trap and turns it into a real security advantage. No fluff, no FUD—just practical strategies to make compliance work for your MSP.
- Indexed episodes, last 90 days
- 13
- Latest publication
- Sep 29, 2026
- Audience
- Checking…
- Earliest in this view
- Jul 7, 2026
Latest episodes
Beyond the Badge: GTIA Trustmark, SOC 2, and MSP Maturity (opens the original)
Read excerpt
Following NIST or CIS is useful, but does it prove your MSP can actually operate under pressure? Chris "CJ" Johnson from GTIA joins us to talk about the Cybersecurity Trustmark , what security maturity looks like in practice, and why proof of controls is not the same as mature governance. Takeaways: Why the Trust Mark focuses on maturity, governance, leadership, and culture Why “we have a SOC 2” means very little until you look at what is actually in scope Why MSPs can help clients manage risk w
Minimum Viable Security: Build It and Keep It Running (opens the original)
Read excerpt
Antivirus, backups, and MFA are a start. They won't tell you how payroll runs when the check printer is inaccessible or keep your risk register current six months later. This week, Jared and Mike talk about what a small business actually needs and how to keep that work going. - Identify the client's critical data and the processes that keep the business running. - Check the less obvious dependencies, from break-glass accounts to the payroll check printer. - Use CIS Implementation Group 1 as a st
Your MSP Is Not the Client's Unpaid Compliance Department (opens the original)
Read excerpt
It started with one questionnaire. Now you're the compliance department, and apparently that's included in the flat rate. On Get NIST-y, Blacksmith InfoSec's cybersecurity and compliance podcast for MSPs, we're talking about who owns the program and who pays for the work. - Name one executive owner at the client before work starts. Your day-to-day contact doesn't have to be that person. - Check the contract before charging for new work. Catching up on patching you already owed is different from
AI Policy After the Horse Has Already Left the Barn (opens the original)
Read excerpt
AI adoption happened before most clients wrote the rules. That does not make an AI policy useless. It changes the job from trying to stop AI to governing the tools already in use, training people to make better decisions, and protecting sensitive data. Takeaways: - Why governance, education, and security are the only realistic levers left - How the data, platform, subscription tier, and vendor agreement determine whether a prompt is acceptable - Why AI output still needs human validation, especi
New York Compliance: What the MSP Owns and What It Doesn't (opens the original)
Read excerpt
Following NIST does not automatically cover New York-specific rules, and that does not mean your MSP needs to become a law firm. We sort out where legal counsel belongs, what the client must own, and which responsibilities an MSP can safely take on. We also thank our listeners for helping Get NIST-y win an MSP Influencer award.Takeaways:• Keep lawyers focused on legal and privacy questions, not every security policy detail.• Put one client executive in charge of the security program and risk.• T
Publishing over time
Last 90 days. Choose a month to open its work.
Recurring subjects
Named in the text we hold. One piece can cover several.
Not enough subject data for this period yet.
Audience
No verified audience measurement yet.
About this data
Counts cover the work we have indexed. Tone needs enough text and a confident classification. Excerpts and episode notes are not full articles or transcripts.
Identity or attribution wrong? Suggest a correction.