2 min read
#31 - From the Trenches - The CIO Mindset - MSPs, Luck & Learning (Bob Coppedge)
In this From the Trenches episode, Bob Coppedge, Founder & CEO of Simplex-IT, joins Josh Peterson to unpack more than 18 years in managed...
3 min read
Josh Peterson
:
Nov 5, 2025 12:00:00 AM
In this From the Trenches episode of the BMK Vision Podcast, Josh Peterson sits down with Bill Haber for a wide-ranging, executive-level conversation about a topic most MSPs and small businesses dramatically underestimate until it’s too late: cyber risk is not a technology problem—it’s a business survival problem.
This is not a tactical security discussion or a checklist of tools. It’s a sober look at how cyber insurance, risk assessment, and operational discipline actually intersect in the real world—especially when a claim is filed. Josh and Bill unpack why most cyber policies are purchased backwards, how attackers quietly “camp out” inside environments before striking, and why MSPs lose credibility when they sell fear instead of clarity. The discussion ties directly to the execution and accountability framework behind the BMK Vision operating system, where risk, finance, and operations must align if growth is going to be sustainable.
Most businesses believe cyber insurance works like other policies: answer the questions, pay the premium, and you’re covered. Bill explains why that assumption collapses during a claim.
Insurance applications are often completed optimistically. Underwriters may accept the answers—but claims are paid based on evidence, not intent. When controls like MFA, backups, or endpoint protection can’t be proven in practice, coverage erodes quickly.
One of the most practical sections of the episode centers on vocabulary. MSPs routinely use “event,” “incident,” and “breach” interchangeably—often triggering the wrong response at the wrong time.
Bill draws a clear hierarchy: events are signals, incidents are confirmed abnormal activity, and breaches involve malicious actors actively causing harm. Once the word “breach” is used, legal, insurer, and regulatory machinery engages—sometimes before the facts are fully known.
This episode dismantles the myth of smash-and-grab cybercrime. Modern attackers are patient. They sit quietly inside systems, observe transaction patterns, watch cash balances fluctuate, and strike when the payout is maximized.
For MSPs, this reframes security conversations. Basic controls aren’t about perfection—they’re about being inconvenient enough that attackers move on. You don’t have to outrun the lion; you just have to outrun the next business.
Bill is blunt: most cybersecurity sales conversations talk past business owners. Technical jargon, horror stories, and compliance theater create avoidance—not action.
Instead, he advocates a “give value first” model: lightweight, independent risk discovery delivered in business language. When owners can see their specific exposure—and its financial impact—decisions become rational instead of emotional.
Bill Haber is the founder of TechRisk (TEKRISQ), a cyber risk firm helping small and mid-sized businesses assess, remediate, and insure risk based on operational reality—not assumptions. With a background spanning telecom, data platforms, and sensitive-data environments, Bill brings a business-first lens to cybersecurity that resonates with owners and advisors alike.
Connect with Bill on LinkedIn →
Josh Peterson is the CEO of Bering McKinley and host of the BMK Vision Podcast, where he helps MSP owners replace intuition with clarity, discipline, and execution.
Connect with Josh on LinkedIn →
Why do cyber insurance claims get denied?
Because controls described in the application can’t be proven during investigation.
Is cyber risk mainly a technology issue?
No. It’s a leadership, finance, and governance issue that happens to involve technology.
Should businesses always pay ransomware demands?
There are no universal rules—decisions depend on backups, restoration readiness, legal guidance, and insurer involvement.
How can MSPs sell cyber without fear?
Start with independent risk discovery in business language, then prioritize remediation.
Return to the BMK Vision Podcast main page →
2 min read
In this From the Trenches episode, Bob Coppedge, Founder & CEO of Simplex-IT, joins Josh Peterson to unpack more than 18 years in managed...
3 min read
In this Don’t Be That Guy episode of the BMK Vision Podcast, Josh Peterson sits down with Ryan Alter for an executive-level conversation on a metric...
5 min read
In this episode of From the Trenches on the BMK Vision Podcast, Josh Peterson sits down with Mordy Hackel of KJ Technology for an operator-level...