Get NIST-y is a podcast that breaks compliance out of the checkbox trap and turns it into a real security advantage. No fluff, no FUD—just practical strategies to make compliance work for your MSP. Each week, we'll dive into compliance topics based on real questions from our MSP partners and subscribers.
Your client knows about the security gap. They understand the recommendation. And they still say no.
Now what?
This week on Get NIST-y, Jared and Mike talk about when risk acceptance is legitimate, when it still means the client isn't compliant, who actually has authority to sign off on company risk, and why compensating controls and policy exceptions need to be reviewed instead of becoming permanent infrastructure.
Because a “risk-based approach” doesn't mean every risk magically gets fixed. It means somebody understands the tradeoff, makes the decision, owns it, and documents the hell out of it.
Want to get your own questions answered? Head over to https://blacksmithinfosec.com/ask (https://blacksmithinfosec.com/ask)
29 Sept 2026
Beyond the Badge: GTIA Trustmark, SOC 2, and MSP Maturity
Following NIST or CIS is useful, but does it prove your MSP can actually operate under pressure? Chris "CJ" Johnson from GTIA (https://gtia.org) joins us to talk about the Cybersecurity Trustmark (https://gtia.org/membership/cybersecurity-programs/trustmark), what security maturity looks like in practice, and why proof of controls is not the same as mature governance.
Takeaways:
Why the Trust Mark focuses on maturity, governance, leadership, and culture
Why “we have a SOC 2” means very little until you look at what is actually in scope
Why MSPs can help clients manage risk without pretending they can own it
How simple outage and tabletop exercises expose gaps that policies miss
We answer:
If we already follow CIS and NIST, what does the GTIA Trust Mark actually add?
Can MSPs use the Trust Mark as a security baseline or shared responsibility model for clients?
Make sure to follow the podcast or ask your own questions at:
https://blacksmithinfosec.com/nisty/ (https://blacksmithinfosec.com/nisty/)
22 Sept 2026
Minimum Viable Security: Build It and Keep It Running
Antivirus, backups, and MFA are a start. They won't tell you how payroll runs when the check printer is inaccessible or keep your risk register current six months later. This week, Jared and Mike talk about what a small business actually needs and how to keep that work going.
- Identify the client's critical data and the processes that keep the business running.
- Check the less obvious dependencies, from break-glass accounts to the payroll check printer.
- Use CIS Implementation Group 1 as a starting point, then keep improving.
- Schedule user audits, policy reviews, and risk assessments as recurring work.
We answer:
- What should a 50-person company with antivirus, backups, and MFA be doing repeatedly to have a minimum viable security program?
- How do you keep that program alive when policies go stale, evidence goes missing, and nobody updates the risk register?
Make sure to follow the podcast or ask your own questions at: https://blacksmithinfosec.com/nisty/ (https://blacksmithinfosec.com/nisty/)
Reach and audience
Public platform figures. Ratings count people who left a rating, not total listeners.
Apple Podcasts (US)
5.0 / 5
2 ratings
Spotify
5.0 / 5
10 ratings
Contact Get NIST-y
Guest appearances
Books guests
Based on episode analysis; this does not confirm that the show is currently accepting guests.
Host of Get NIST-y?
Claim your podcast to manage its listing and keep your show details accurate.
Pod Engine is an independent podcast discovery and analytics service and is not affiliated with or endorsed by this podcast. Artwork and show content belong to their owners. Full legal notice.
Explore this show Podcast research with Pod Engine