<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Cork's Substack]]></title><description><![CDATA[Cyber confidence and business continuity for MSPs and the businesses they protect.]]></description><link>https://blog.corkinc.com</link><image><url>https://substackcdn.com/image/fetch/$s_!R8Xj!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F374bb124-1483-4acf-8930-865ec1002ca6_215x215.png</url><title>Cork&apos;s Substack</title><link>https://blog.corkinc.com</link></image><generator>Substack</generator><lastBuildDate>Sun, 13 Sep 2026 18:49:02 GMT</lastBuildDate><atom:link href="https://blog.corkinc.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Cork Cyber]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[corkcyber@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[corkcyber@substack.com]]></itunes:email><itunes:name><![CDATA[Cork Cyber]]></itunes:name></itunes:owner><itunes:author><![CDATA[Cork Cyber]]></itunes:author><googleplay:owner><![CDATA[corkcyber@substack.com]]></googleplay:owner><googleplay:email><![CDATA[corkcyber@substack.com]]></googleplay:email><googleplay:author><![CDATA[Cork Cyber]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[The Bottleneck Was Never Your Tools]]></title><description><![CDATA[One connected question replaces a morning of clicking.]]></description><link>https://blog.corkinc.com/p/the-bottleneck-was-never-your-tools</link><guid isPermaLink="false">https://blog.corkinc.com/p/the-bottleneck-was-never-your-tools</guid><dc:creator><![CDATA[Cork Cyber]]></dc:creator><pubDate>Tue, 08 Sep 2026 15:02:10 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!8QGN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63bdea80-eb6c-4452-8068-7fe00003b9af_1680x944.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8QGN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63bdea80-eb6c-4452-8068-7fe00003b9af_1680x944.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8QGN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63bdea80-eb6c-4452-8068-7fe00003b9af_1680x944.png 424w, https://substackcdn.com/image/fetch/$s_!8QGN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63bdea80-eb6c-4452-8068-7fe00003b9af_1680x944.png 848w, https://substackcdn.com/image/fetch/$s_!8QGN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63bdea80-eb6c-4452-8068-7fe00003b9af_1680x944.png 1272w, https://substackcdn.com/image/fetch/$s_!8QGN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63bdea80-eb6c-4452-8068-7fe00003b9af_1680x944.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8QGN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63bdea80-eb6c-4452-8068-7fe00003b9af_1680x944.png" width="1456" height="818" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/63bdea80-eb6c-4452-8068-7fe00003b9af_1680x944.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:818,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2356224,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.corkinc.com/i/214058150?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63bdea80-eb6c-4452-8068-7fe00003b9af_1680x944.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8QGN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63bdea80-eb6c-4452-8068-7fe00003b9af_1680x944.png 424w, https://substackcdn.com/image/fetch/$s_!8QGN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63bdea80-eb6c-4452-8068-7fe00003b9af_1680x944.png 848w, https://substackcdn.com/image/fetch/$s_!8QGN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63bdea80-eb6c-4452-8068-7fe00003b9af_1680x944.png 1272w, https://substackcdn.com/image/fetch/$s_!8QGN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63bdea80-eb6c-4452-8068-7fe00003b9af_1680x944.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em><span>It&#8217;s a reporting day</span></em><span>.</span></p><p><span>A client wants a security posture summary. You log into the EDR for coverage. The RMM for the endpoint list. The email security tool for mailbox status. The backup platform to confirm the last good restore point. The identity tool for MFA. Then you paste it all into one place, reconcile the parts that disagree, and format it into something you can actually send.</span></p><p><span>That&#8217;s half a morning for one client. Multiply it across a book of dozens.</span></p><p><span>The work isn&#8217;t hard. It isn&#8217;t interesting either. It&#8217;s just where a huge share of your hours go.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://blog.corkinc.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://blog.corkinc.com/subscribe?"><span>Subscribe now</span></a></p><h4><strong><span>The bottleneck came from somewhere else</span></strong></h4><p><span>Your tools aren&#8217;t slow. The data isn&#8217;t missing. The bottleneck is you, in the middle, moving between consoles, reconciling by hand, and updating copies of presentations you already created.</span></p><p><span>That&#8217;s the real ceiling on an MSP. It&#8217;s why serving more clients has always meant hiring more people, and why the smallest teams feel it worst. Every client you add multiplies the stitching. The tools scale fine. The manual assembly doesn&#8217;t.</span></p><h4><strong><span>What actually changes when tools connect</span></strong></h4><p><span>The last post we published covered MCP, the common way an assistant connects to the tools and data you already run. Here&#8217;s why that matters on a Tuesday morning:</span></p><p><span>When your tools are reachable through that layer, retrieval and reconciliation stop being your job. You ask in one prompt: </span><em><span>Give me the posture summary for this client across all their tools, and show me where coverage is missing</span></em><span>. The assistant goes and gets it from every connected source and hands back the assembled answer. The morning of clicking becomes a sentence, a quick review, and maybe some back and forth to prepare for showtime.</span></p><p><span>Notice what didn&#8217;t change. You still read the answer with a professional eye. You still decide what it means and what to do about it. What&#8217;s gone is the hour of mechanical work sitting between you and the point where your judgment is worth more.</span></p><h4><strong><span>What flexibility looks like</span></strong></h4><p><strong><span>Capacity without headcount: </span></strong><span>When per-client reporting drops from hours to minutes, the same lean team covers more clients well. That&#8217;s growth that doesn&#8217;t require hiring ahead of revenue.</span></p><p><strong><span>Answers during the call: </span></strong><span> A client asks something pointed. Instead of &#8220;let me pull that together and get back to you,&#8221; you ask it live and answer before you hang up.</span></p><p><strong><span>Consistency (which is the quiet one):</span></strong><span> When thorough costs hours, thorough goes to your biggest accounts and everyone else gets skipped. When thorough costs a sentence, every client gets the same treatment. The small client stops slipping through.</span></p><p><strong><span>More questions, asked more often:</span></strong><span> The right questions are answered proactively. You catch a client drifting in the wrong direction this month instead of finding out at the next incident.</span></p><h4><strong><span>Follow the thread instead of building a report</span></strong></h4><p><span>Start broad. Which of my clients are worst on email security right now? Read the answer, then narrow. Of those, which also have no working backup? Then act. </span><em><span>Draft me a plain summary I can send each of them</span></em><span>.</span></p><p><span>No new report to build, no new view to configure. You&#8217;re thinking out loud and the data keeps up with you. A fixed screen never did that.</span></p><h4><strong><span>It removes the administrative tax, not the expertise</span></strong></h4><p><span>This doesn&#8217;t replace knowing your craft. The assistant assembles the picture. Reading it correctly, weighing the tradeoffs, and deciding what a client actually needs is still the work, and it&#8217;s still yours.</span></p><p><span>What goes away is the retrieval tax. The unbillable, unrewarding hours spent gathering and reconciling before any thinking can start. Spending your scarcest resource, expert attention, on copy and paste was never a good trade.</span></p><p><em><span>One thing so it isn&#8217;t a surprise later</span></em><span>: This only works if something has already reconciled your tools. Point an AI assistant at a dozen disconnected consoles and you get a dozen disconnected answers plus the same reconciliation problem, now with an extra step. This can result in reading the output the way you&#8217;d read a report from a junior tech. Of course, always check it before you send it.</span></p><h4><strong><span>Where Cork fits</span></strong></h4><p><span>Cork has already done the reconciliation. We connect the tools you run into one cross-referenced source of truth, and we expose an MCP connection on top of that. Your question runs against the whole picture instead of one tool at a time, using whatever assistant your team prefers.</span></p><p><span>If you&#8217;re on the client side of this, it explains something you&#8217;ve probably noticed about the best providers. They answer fast, they show up to the review with real analysis instead of a canned deck, and nothing seems to take a week. That isn&#8217;t a bigger team behind the scenes. It&#8217;s a shorter distance between a question and its answer.</span></p><h4><strong><span>The distance is the whole point</span></strong></h4><p><span>The old promise was more dashboards. More screens, more places to look. The real win turns out to be the opposite. Collapse the distance between a question and its answer until there&#8217;s almost nothing left of it.</span></p><p><span>That distance is where MSP hours go to die. Closing it is what operational flexibility actually means, and it&#8217;s available now with the tools you already own.</span></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.corkinc.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Cork's Substack! Subscribe for free to receive new posts about cybersecurity.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[The Cyber Insurance Gap Hiding in Your Client Base]]></title><description><![CDATA[Most SMBs underestimate it, and your book is no exception.]]></description><link>https://blog.corkinc.com/p/the-cyber-insurance-gap-hiding-in</link><guid isPermaLink="false">https://blog.corkinc.com/p/the-cyber-insurance-gap-hiding-in</guid><dc:creator><![CDATA[Cork Cyber]]></dc:creator><pubDate>Tue, 01 Sep 2026 14:27:29 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!s30O!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febe8ce44-26a3-47e4-a399-cfdd15cfe578_1860x1860.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!s30O!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febe8ce44-26a3-47e4-a399-cfdd15cfe578_1860x1860.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!s30O!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febe8ce44-26a3-47e4-a399-cfdd15cfe578_1860x1860.png 424w, https://substackcdn.com/image/fetch/$s_!s30O!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febe8ce44-26a3-47e4-a399-cfdd15cfe578_1860x1860.png 848w, https://substackcdn.com/image/fetch/$s_!s30O!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febe8ce44-26a3-47e4-a399-cfdd15cfe578_1860x1860.png 1272w, https://substackcdn.com/image/fetch/$s_!s30O!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febe8ce44-26a3-47e4-a399-cfdd15cfe578_1860x1860.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!s30O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febe8ce44-26a3-47e4-a399-cfdd15cfe578_1860x1860.png" width="1456" height="1456" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ebe8ce44-26a3-47e4-a399-cfdd15cfe578_1860x1860.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1456,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:495613,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.corkinc.com/i/213605424?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febe8ce44-26a3-47e4-a399-cfdd15cfe578_1860x1860.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!s30O!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febe8ce44-26a3-47e4-a399-cfdd15cfe578_1860x1860.png 424w, https://substackcdn.com/image/fetch/$s_!s30O!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febe8ce44-26a3-47e4-a399-cfdd15cfe578_1860x1860.png 848w, https://substackcdn.com/image/fetch/$s_!s30O!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febe8ce44-26a3-47e4-a399-cfdd15cfe578_1860x1860.png 1272w, https://substackcdn.com/image/fetch/$s_!s30O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febe8ce44-26a3-47e4-a399-cfdd15cfe578_1860x1860.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>Ask a room of MSPs how many of their clients carry cyber insurance, and it is unlikely that you will get a clean number back. What comes through instead is a pattern. A lot of small and midsize businesses do not carry it, and most of the ones who skip it have never really understood why it matters in the first place. The exact percentage moves around. The underlying truth does not. For the majority of SMBs, cyber insurance is either absent or barely understood. That gap is sitting somewhere in your client base right now.</span></p><p><span>Most MSPs treat that gap as an awkward subject. Something adjacent to their job, a little outside their lane, a conversation easier to leave alone. That instinct is understandable, and it is also backwards. </span><em><span>The under-covered part of your book is not a problem to work around. It is the most valuable conversation you are not having.</span></em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://blog.corkinc.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://blog.corkinc.com/subscribe?"><span>Subscribe now</span></a></p><h4><span>Why the gap gets avoided</span></h4><p><span>At face-value, the avoidance makes sense. Insurance feels like someone else&#8217;s product. Bringing it up feels like selling something you are not licensed to sell. The conversation itself can feel heavy, so it slips down the list behind the ticket queue and the next onboarding.</span></p><p><span>However, MSPs must step back and look at what the gap actually means. It is real financial exposure sitting on clients whose security you are already responsible for managing. If one of those uninsured clients takes a ransomware hit or a wire fraud loss, the fallout does not stay neatly in their lane. It becomes your emergency, your late nights, and often your blame, whether or not the incident was anything you could have prevented. The gap is already your problem. The only question is whether you engage with it before an incident or while evaluating the aftermath.</span></p><h4><span>It is the same instinct you already trust</span></h4><p><span>Here is the reframe that makes it easy. </span></p><p><span>You already sell clients tools they do not fully use on day one. You recommend the backup, the EDR, the security training, all because you know the client needs the protection even when they have not asked for it. Closing the insurance and financial protection gap is the same instinct, pointed at the same goal. Protect the client, and strengthen the relationship in the process.</span></p><p><span>The easiest version of this conversation is not the client who is already covered. It is the one who is not. They are at risk whether they know it or not. You are the person they already trust with this category. You do not have to manufacture a need. You just have to point out the one is already there.</span></p><h4><span>The line you do not cross</span></h4><p><span>This only works if you are clear about what you are and are not doing, so say it plainly to yourself and to the client. You are not becoming an insurance broker. MSPs are not permitted to sell insurance or advise clients on what policy to buy, and you should not try.</span></p><p><span>What you can do is different and entirely within bounds. You can start the conversation. You can show a client where they actually stand on security posture, which is where any honest insurance discussion should begin. Then, you can connect them to a broker who specializes in this, so the actual insurance decision is made by someone qualified to make it. You are the facilitator who opens the door, never the advisor who walks them through it. Held to that line, the conversation is a service, not a sales pitch.</span></p><h4><span>What makes the gap closeable</span></h4><p><span>Two things turn this from a nice idea into something a client can act on.</span></p><ol><li><p><strong><span>Visibility into posture:</span></strong><span> An insurance conversation that starts with &#8220;here is what your security actually looks like right now&#8221; is a real conversation. One that starts with a generic warning is not. Being able to show a client their posture, clearly and specifically, is what gives the discussion weight and gives a broker something concrete to work from.</span></p></li><li><p><strong><span>Financial protection as a wrapper around the whole thing</span></strong><span>: This is where Cork Protect fits. It provides financial coverage toward specific covered incidents, things like ransomware, wire transfer fraud, and SMS phishing scams, including coverage toward a client&#8217;s cyber insurance deductible if a covered incident occurs. It is worth being precise here, because overpromising helps no one. The coverage applies to defined incident types, and the deductible benefit only pays off for a client who actually carries a policy. </span><em><span>Named accurately, it is a genuine layer of financial resilience you can place on a client&#8217;s account regardless of where they land on insurance itself.</span></em></p></li></ol><h4><span>Everyone comes out ahead</span></h4><p><span>Play it forward and both kinds of client benefit. The uninsured client goes from fully exposed to carrying real financial protection, and gains a clear-eyed view of whether a policy makes sense for them. The already-insured client gets a sharper picture of their posture and, often, a better-structured relationship with their coverage. Either way, you did not attempt to sell insurance. In both cases, you delivered something valuable, which is exactly the kind of thing that earns the right to a pricing conversation later. Value first. Price second.</span></p><p><span>If you are on the client side reading this, the takeaway is calmer than the usual cyber insurance noise. Most businesses like yours either skip this entirely or carry it without fully understanding it, so you are not alone either way. The point is not to panic-buy a policy. It is to know where you actually stand, and to have protection in place either way.</span></p><h4><span>The most valuable conversation in your book</span></h4><p><span>The under-covered part of your client base is not a gap to tiptoe around. It is a room full of people who trust you, carry a real exposure, and have not been given a clear, low-pressure way to think about it. Being the one who opens that door, honestly and within your lane, is some of the highest-value work available to you right now. </span></p><p><span>The gap was never the obstacle. It was the opening.</span></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.corkinc.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Cork's Substack! Subscribe for free to receive new posts about cybersecurity.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[What’s Actually Getting Exploited in Your Industry]]></title><description><![CDATA[Why risk concentrates in your industry&#8217;s everyday tools.]]></description><link>https://blog.corkinc.com/p/whats-actually-getting-exploited</link><guid isPermaLink="false">https://blog.corkinc.com/p/whats-actually-getting-exploited</guid><dc:creator><![CDATA[Cork Cyber]]></dc:creator><pubDate>Tue, 25 Aug 2026 15:11:37 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!hiIu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06147b55-b2b7-48f3-ada1-55b94d4d6a62_1024x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hiIu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06147b55-b2b7-48f3-ada1-55b94d4d6a62_1024x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hiIu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06147b55-b2b7-48f3-ada1-55b94d4d6a62_1024x768.png 424w, https://substackcdn.com/image/fetch/$s_!hiIu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06147b55-b2b7-48f3-ada1-55b94d4d6a62_1024x768.png 848w, https://substackcdn.com/image/fetch/$s_!hiIu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06147b55-b2b7-48f3-ada1-55b94d4d6a62_1024x768.png 1272w, https://substackcdn.com/image/fetch/$s_!hiIu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06147b55-b2b7-48f3-ada1-55b94d4d6a62_1024x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hiIu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06147b55-b2b7-48f3-ada1-55b94d4d6a62_1024x768.png" width="1024" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/06147b55-b2b7-48f3-ada1-55b94d4d6a62_1024x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:525294,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.corkinc.com/i/212608996?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06147b55-b2b7-48f3-ada1-55b94d4d6a62_1024x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hiIu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06147b55-b2b7-48f3-ada1-55b94d4d6a62_1024x768.png 424w, https://substackcdn.com/image/fetch/$s_!hiIu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06147b55-b2b7-48f3-ada1-55b94d4d6a62_1024x768.png 848w, https://substackcdn.com/image/fetch/$s_!hiIu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06147b55-b2b7-48f3-ada1-55b94d4d6a62_1024x768.png 1272w, https://substackcdn.com/image/fetch/$s_!hiIu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06147b55-b2b7-48f3-ada1-55b94d4d6a62_1024x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p><span>&#8220;Patch everything&#8221; is not a strategy. It is a wish. Every environment has more vulnerabilities than any team can close in a week, which means the real question is never whether you have vulnerabilities. It is which ones actually matter, and where to point your limited time first.</span></p><p><span>The reassuring news is that risk is not random. It has a shape. A lot of what creates that shape is set by something as mundane as what industry your client is in, and what ordinary software everyone in that industry happens to run.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://blog.corkinc.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://blog.corkinc.com/subscribe?"><span>Subscribe now</span></a></p><h4><span>Every industry has a signature</span></h4><p><span>Look across a large number of managed environments and a pattern emerges that is hard to unsee. Each industry tends to have a characteristic piece of software that shows up, again and again, as the most common carrier of active vulnerabilities. It is rarely exotic or particularly interesting. It is almost always something boring and everywhere.</span></p><p><span>In the environments Cork sees across its partner base, the patterns break down along a few clear lines.</span></p><p><span>Remote access and VPN clients dominate several sectors. Cisco Secure Client turns up as the most common vulnerable software in construction, in finance and insurance, and in retail, among others. SonicWall NetExtender leads in health care and in real estate. These are the tools everyone connects through to get work done, which is exactly why they are both everywhere and attractive to threat actors.</span></p><p><span>PDF readers own another large slice. Adobe Acrobat Reader and Foxit PDF Reader are the top vulnerable software in education, public administration, arts and entertainment, information, and transportation. Every desktop has one. Almost nobody thinks of it as security-critical. It opens files from outside the organization all day long.</span></p><p><span>Database servers show up in the industries built on data. Microsoft SQL Server is the most common vulnerable software in manufacturing and in professional, scientific, and technical services, sitting quietly behind the line-of-business applications those firms depend on.</span></p><h4><span>Why the &#8220;boring&#8221; software is the risky software</span></h4><p><span>There is a reason the pattern lands on ordinary tools rather than flashier ones.</span></p><p><span>First, they are everywhere. A vulnerability in software installed on one machine is a footnote. The same vulnerability in software installed on every machine is a campaign waiting to happen.</span></p><p><span>Second, they handle untrusted input or face the internet. A VPN client is a front door by design. A PDF reader opens documents from strangers all day. A database server is the thing worth stealing. These are not incidental targets. They are the point.</span></p><p><span>Third, they patch on their own schedule, not the operating system&#8217;s. Everyone has a process for OS updates. Far fewer have a reliable process for keeping the PDF reader, the VPN client, and the database engine current across a whole client base. That gap between &#8220;we patch&#8221; and &#8220;we patch everything&#8221; is where the exposure lives.</span></p><h4><span>Not all vulnerabilities are equal: the KEV signal</span></h4><p><span>This is where a single idea does more prioritization work than any scanner. Known Exploited Vulnerabilities.</span></p><p><span>The KEV catalog, maintained by the US Cybersecurity and Infrastructure Security Agency and VulnCheck , is a list of vulnerabilities confirmed to be under active exploitation in the real world. Not theoretical. Not &#8220;could be dangerous.&#8221; Being used, right now, by actual attackers.</span></p><p><span>That distinction changes how you triage. A vulnerability with a scary score that nobody is exploiting can wait. However, a vulnerability on the KEV list is a door someone is actively trying to walk through. When one of those lands in the everyday software your industry runs on, that is not a maintenance item. That is the thing to prioritize fixing today.</span></p><p><span>When you put the two ideas together, you get a genuinely short, genuinely useful list. </span></p><ul><li><p><span>Which of my clients run the software my industry is most exposed on?</span></p></li><li><p><span>Which of those carry an actively exploited vulnerability that is still unpatched? </span></p></li></ul><p><span>Answer those questions, and you have found the handful of things most likely to cause a real incident. This prioritization gets you ahead of everyone still trying to patch everything at once.</span></p><h4><span>Turning the pattern into action</span></h4><p><span>The obstacle has never been the concept. It has been the legwork. Answering that question the manual way means inventorying software across every client, cross-referencing it against exploited-vulnerability lists, and figuring out what is actually patched. For a small team across a large book, that is not realistic to do often, so it does not get done.</span></p><p><span>This is where surfacing vulnerabilities across the connected stack earns its keep. Cork finds the software vulnerabilities living across the tools you already run, ties them to specific endpoints and clients, and lets you act on them, including pushing patches through your RMM and package managers rather than touching each machine by hand. The prioritization stops being a research project and becomes a working list.</span></p><p><span>If you are on the client side of this, the takeaway is a question worth asking your provider. What are the common exposures for a business like mine, and are we carrying any that are actively being exploited right now? A provider who can answer that clearly is one who is triaging by real-world risk, not by whatever the scanner happened to sort to the top.</span></p><h4><span>Risk has a shape, so use it</span></h4><p><span>The point of all this is not to fear a specific product. Cisco, SonicWall, Adobe, Foxit, and Microsoft build software the entire economy runs on, and being common is not the same as being bad. It is that risk concentrates, predictably, in the tools an industry cannot operate without.</span></p><p><span>That predictability is a gift. It means you do not have to defend everything equally. You can look at what your industry actually runs, find the pieces carrying vulnerabilities the world is actively exploiting, and start prioritizing there. </span></p><p><span>Patch by priority, not by panic. The list is more reasonable to manage than it feels.</span></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.corkinc.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Cork's Substack! Subscribe for free to receive new posts about cybersecurity.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Your Security Data Can Answer Questions Now]]></title><description><![CDATA[A plain-language introduction to MCP for MSPs.]]></description><link>https://blog.corkinc.com/p/your-security-data-can-answer-questions</link><guid isPermaLink="false">https://blog.corkinc.com/p/your-security-data-can-answer-questions</guid><dc:creator><![CDATA[Cork Cyber]]></dc:creator><pubDate>Tue, 18 Aug 2026 14:11:11 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Wtbl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F340b8a25-b2c4-4f96-9d59-3aa93b879e47_1376x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Wtbl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F340b8a25-b2c4-4f96-9d59-3aa93b879e47_1376x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Wtbl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F340b8a25-b2c4-4f96-9d59-3aa93b879e47_1376x768.png 424w, https://substackcdn.com/image/fetch/$s_!Wtbl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F340b8a25-b2c4-4f96-9d59-3aa93b879e47_1376x768.png 848w, https://substackcdn.com/image/fetch/$s_!Wtbl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F340b8a25-b2c4-4f96-9d59-3aa93b879e47_1376x768.png 1272w, https://substackcdn.com/image/fetch/$s_!Wtbl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F340b8a25-b2c4-4f96-9d59-3aa93b879e47_1376x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Wtbl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F340b8a25-b2c4-4f96-9d59-3aa93b879e47_1376x768.png" width="1376" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/340b8a25-b2c4-4f96-9d59-3aa93b879e47_1376x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1376,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:668171,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.corkinc.com/i/211615586?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F340b8a25-b2c4-4f96-9d59-3aa93b879e47_1376x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Wtbl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F340b8a25-b2c4-4f96-9d59-3aa93b879e47_1376x768.png 424w, https://substackcdn.com/image/fetch/$s_!Wtbl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F340b8a25-b2c4-4f96-9d59-3aa93b879e47_1376x768.png 848w, https://substackcdn.com/image/fetch/$s_!Wtbl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F340b8a25-b2c4-4f96-9d59-3aa93b879e47_1376x768.png 1272w, https://substackcdn.com/image/fetch/$s_!Wtbl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F340b8a25-b2c4-4f96-9d59-3aa93b879e47_1376x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>Think about how you get an answer out of your stack today. Let&#8217;s say a client asks a fair question: are all of our machines actually protected? To answer it honestly, you log into the EDR and pull a list. Log into the RMM and pull another. Export both. Line them up in a spreadsheet. Find the machines that appear in one and not the other. An hour later you have an answer that includes information from just two of your security tools, and it is already slightly out of date.</span></p><p><span>The data was never the problem. It was all right there. The problem was the work of getting an answer out of it. That is the specific thing that is changing, and the name for what is changing it is MCP.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://blog.corkinc.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://blog.corkinc.com/subscribe?"><span>Subscribe now</span></a></p><h4><span>What MCP actually is (and what it isn&#8217;t)</span></h4><p><strong><span>What it is:</span></strong><span> MCP stands for Model Context Protocol. Strip away the acronym and it is a simple idea. It is a common way for an AI assistant to connect to the tools and data you already use.</span></p><p><span>The useful analogy is USB-C. Before a universal connector existed, every device needed its own special cable, and nothing quite fit together. MCP is that universal connector, but for AI platforms. It gives an assistant a standard way to plug into a system, ask it for information, and get a structured answer back. Once a tool speaks MCP, any assistant that speaks MCP can work with it.</span></p><p><span>That last point matters more than it sounds. MCP is not tied to one AI company or one product. It is an open standard, which means you are not locking yourself into a single vendor&#8217;s assistant to get the benefit. You can use the tool you prefer today and a different one next year, and the connection to your data still works.</span></p><p><strong><span>What it isn&#8217;t: </span></strong><span>MCP is not a new dashboard to learn. There is no console to master. The interface is a plain-language question. It is not a replacement for your tools. </span><em><span>MCP is the layer that lets you ask about them, not a substitute for them.</span></em></p><p><span>Also, it is not your data being handed off somewhere to train a model. A connection through MCP is you pointing your own assistant at your own systems to answer your own questions. You stay in control of what it can see and what it can do.</span></p><h4><span>Why this matters for an MSP specifically</span></h4><p><span>Every MSP lives the same reality. You do not have a data shortage. You have a data-scattered-across-a-dozen-tools problem. The friction is never finding whether the answer exists. It is assembling it from pieces that live in different places and do not talk to each other.</span></p><p><span>That is exactly the friction MCP removes. Instead of logging into each tool and stitching the pieces together by hand, you ask a question once, and an assistant connected through MCP pulls what it needs from the connected sources and hands you the answer. </span><em><span>The hour of exporting and reconciling becomes a sentence.</span></em></p><p><span>Picture the questions you would actually ask:</span></p><ul><li><p><span>Which clients have an endpoint missing EDR right now? </span></p></li><li><p><span>Which mailboxes got added this month but never made it into the email security policy? </span></p></li><li><p><span>Which of my clients are trending in the wrong direction on their security posture? </span></p></li></ul><p><span>These are the questions you already want answered and rarely have time to chase down. MCP is what makes them a quick ask instead of an afternoon.</span></p><h4><span>Where Cork fits</span></h4><p><span>Here is why this pairs naturally with the way Cork already works.</span></p><p><span>The value of asking a question across your stack depends entirely on something behind the scenes having already unified that stack. If your tools are still a dozen separate islands, an assistant has a dozen separate places to go and no way to reconcile them, and that&#8217;s only if it&#8217;s possible to connect into them directly. Cork has already done that reconciliation. It connects to the tools you run and cross-references them into one source of truth.</span></p><p><span>So, when you connect your AI platform of choice to Cork through its MCP connection, you are not querying one tool at a time. You are asking questions against the whole cross-referenced picture, the same unified view that surfaces your coverage gaps and your wasted spend. Since Cork&#8217;s connection is built to be assistant-agnostic, you bring whatever AI tool your team already prefers.</span></p><p><span>Regarding the questions you may usually ask, here&#8217;s how Cork answers them:</span></p><blockquote><p><strong>Which clients have an endpoint missing EDR right now?</strong><br>Cork is already matching every device your RMM sees against every device your EDR sees, so the answer is the list of machines that appear in one and not the other, with how long each has been that way.<br><br><strong>Which mailboxes got added this month but never made it into the email security policy?</strong><br>Cork tracks every inbox in the tenant against what the email security tool is actually covering, and stamps each gap with the date it opened, so scoping it to this month is part of the same question.<br><br><strong>Which of my clients are trending in the wrong direction on their security posture?</strong><br><a href="https://help.corkinc.com/articles/2538334656-cork-score?lang=en">Cork scores</a> every client daily and keeps the history, so the answer is which scores moved down and which specific gap moved them.</p></blockquote><h4><span>The one honest caveat</span></h4><p><span>An answer is only as good as the data underneath it. This is the through-line of everything in this series. If your visibility is incomplete, a fast answer just gets you to a wrong conclusion faster. Getting the stack seen clearly comes first. Once it is, the ability to question it in plain language is what turns that visibility into something you use every day rather than a report you glance at once a quarter.</span></p><p><span>It is also worth saying that the assistant gives you the answer, not the decision. It can tell you which endpoints are exposed. Deciding what to do about them is still your job, and should be what you bring to the table.</span></p><h4><span>The shift worth noticing</span></h4><p><span>For years, the promise was better dashboards: More screens, more charts, more places to look. The shift underneath MCP is different. It moves you from hunting for answers to simply asking for them, reducing the need for tabbing between dashboards and learning what pages to export.</span></p><p><span>If you are not an MSP but you rely on one, this is quietly good news for you too. It means the provider protecting your business can answer real questions about your environment in minutes instead of days, which is the difference between security you are told about and security you can actually see. This also gives them more times to consider how technology can impact your business needs.</span></p><p><span>This post is the on-ramp to discussing the real value an MCP connection can bring. In a later piece we will get concrete about what it looks like to go from ten open dashboards to a single question, and how that reshapes the daily work. For now, take a look at the </span><a href="https://recipes.corkinc.com/"><span>Prompt Distillery</span></a><span> we created to get our partners started.</span></p><p><em><span>Your security data can answer questions now. You just have to ask.</span></em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.corkinc.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Cork's Substack! Subscribe for free to receive new posts about cybersecurity.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[The Money Hiding in Your Tool Stack]]></title><description><![CDATA[How visibility turns wasted spend into recovered margin]]></description><link>https://blog.corkinc.com/p/the-money-hiding-in-your-tool-stack</link><guid isPermaLink="false">https://blog.corkinc.com/p/the-money-hiding-in-your-tool-stack</guid><dc:creator><![CDATA[Cork Cyber]]></dc:creator><pubDate>Tue, 11 Aug 2026 14:43:08 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!_Uhz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d404c00-9e9a-4180-b4bc-ede03607e154_2912x1632.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_Uhz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d404c00-9e9a-4180-b4bc-ede03607e154_2912x1632.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_Uhz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d404c00-9e9a-4180-b4bc-ede03607e154_2912x1632.png 424w, https://substackcdn.com/image/fetch/$s_!_Uhz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d404c00-9e9a-4180-b4bc-ede03607e154_2912x1632.png 848w, https://substackcdn.com/image/fetch/$s_!_Uhz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d404c00-9e9a-4180-b4bc-ede03607e154_2912x1632.png 1272w, https://substackcdn.com/image/fetch/$s_!_Uhz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d404c00-9e9a-4180-b4bc-ede03607e154_2912x1632.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_Uhz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d404c00-9e9a-4180-b4bc-ede03607e154_2912x1632.png" width="1456" height="816" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2d404c00-9e9a-4180-b4bc-ede03607e154_2912x1632.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:816,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:468632,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.corkinc.com/i/210660951?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d404c00-9e9a-4180-b4bc-ede03607e154_2912x1632.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_Uhz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d404c00-9e9a-4180-b4bc-ede03607e154_2912x1632.png 424w, https://substackcdn.com/image/fetch/$s_!_Uhz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d404c00-9e9a-4180-b4bc-ede03607e154_2912x1632.png 848w, https://substackcdn.com/image/fetch/$s_!_Uhz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d404c00-9e9a-4180-b4bc-ede03607e154_2912x1632.png 1272w, https://substackcdn.com/image/fetch/$s_!_Uhz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d404c00-9e9a-4180-b4bc-ede03607e154_2912x1632.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>Somewhere in your client base right now, a tool is checking in, reporting for duty, and doing nothing useful. Nobody is using it. Nobody remembers turning it on. And every month, it bills.</span></p><p><span>This is not an edge case. It is one of the most common and least discussed line items in a managed services business. The tools you stop needing rarely announce it. They just keep running, and keep charging.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://blog.corkinc.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://blog.corkinc.com/subscribe?"><span>Subscribe now</span></a></p><h4><span>How the waste gets in</span></h4><p><span>Two situations create almost all of it, and both are routine.</span></p><p><strong><span>The first is offboarding.</span></strong><span> A client leaves, or a set of users gets cut, and the accounts get closed on the front end. But the seat in the EDR, the mailbox in the email security tool, the endpoint in the backup platform, those do not always get cleaned up in the same motion. The client is gone. The license is not. It keeps checking in, and it keeps appearing on the bill, sometimes for months.</span></p><p><strong><span>The second is tool migration.</span></strong><span> You move a client from one platform to another. The new tool goes in, everyone confirms it is working, and the project is declared done. What often does not happen is the last step: fully decommissioning the old tool on every machine. A handful of endpoints keep running the platform you thought you left behind. Two tools now cover the same job. You pay for both.</span></p><p><span>Neither of these is negligence. They are the natural residue of a busy operation where the urgent work is standing things up, not tearing them down.</span></p><h4><span>Why you cannot see it from inside any one tool</span></h4><p><span>The reason this spend stays hidden is the same reason coverage gaps stay hidden. Each tool only sees itself.</span></p><p><span>The old platform left running after a migration is, from its own point of view, perfectly healthy. It is installed, it is checking in, its dashboard is green. It has no idea it was supposed to be retired. It will report itself as active indefinitely, because nothing inside it knows the decision to replace it was ever made.</span></p><p><span>The only way to catch it is to look across tools at once. To line up what is still checking in against what should still be there, and flag the difference. That comparison is exactly what no single console can perform, which is why the waste survives quarter after quarter in stacks that otherwise look well run.</span></p><h4><span>This is recoverable money, not a sunk cost</span></h4><p><span>Here is the part that changes how you think about it. This is not spend you have to accept. </span><em><span>It is money sitting inside a stack you already own, waiting to be found.</span></em></p><p><span>Cross-reference your connected tools against a time window, say 60 or 90 days, and ask a direct question. What is still checking in that has no business doing so? The seats that outlived an offboarding. The platform that survived a migration. Draw a line at, for example, day 91, and anything still reporting past it that should have been retired becomes a candidate to cut.</span></p><p><span>For a lot of MSPs the first pass alone recovers enough to pay for the effort several times over. This is not a one-time cleanup. Run the same comparison on a rhythm and the waste never gets the chance to accumulate again.</span></p><h4><span>The client-facing upside</span></h4><p><span>Recovered margin is the obvious win. The less obvious one is what this does for client trust.</span></p><p><span>Most QBRs are a mix of reassurance and upsell. A savings finding is neither. It is you walking into the room and handing the client money back, with a clear reason attached. You were paying for this, it was doing nothing, we turned it off. There is no spin to see through. It is the kind of moment that makes a client believe you are watching their spend as closely as their security, which is exactly the relationship that survives a budget review.</span></p><p><strong><span>There is a security angle too.</span></strong><span> Every orphaned tool and stale license is one more thing in the environment that nobody is managing. Clearing them out does not just cut cost. It shrinks the surface area of things that can quietly break, get exploited, or muddy the picture when you are trying to see the stack clearly.</span></p><h4><span>How Cork surfaces it</span></h4><p><span>This is one of the places the cross-referencing approach pays off in plain dollars. Since Cork connects to the tools you already run and compares them against one another, it can surface savings opportunities directly. The licenses still checking in that map to no active need. The leftovers from offboarding and migration. The seats you are paying for and not using.</span></p><p><span>The output is not another report to interpret. It is a list of specific things you can act on, tied to specific clients, with the wasted spend attached. Some partners leveraging this today think of it less as a savings feature and more as a decommissioning tool, because that is what it does. It tells you what to turn off.</span></p><h4><span>The audit worth running this quarter</span></h4><p><span>You can start without any new tooling at all. Pick your three largest clients. For each, list every security tool you believe is active, then check it against what is actually checking in today. Look specifically for anything tied to a user who left or a platform you migrated away from.</span></p><p><span>Whatever you find is money you were spending for nothing, and now get back. Do it once and it is a nice recovery. Build it into how you run, and it becomes a permanent line of margin you were leaving on the table.</span></p><p><span>You cannot recover spend you cannot see. The good news is that seeing it is the hard part, and it is very findable.</span></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.corkinc.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Cork's Substack! Subscribe for free to receive new posts about cybersecurity.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Installed Is Not the Same as Working]]></title><description><![CDATA[A tool can be installed and still do nothing.]]></description><link>https://blog.corkinc.com/p/installed-is-not-the-same-as-working</link><guid isPermaLink="false">https://blog.corkinc.com/p/installed-is-not-the-same-as-working</guid><dc:creator><![CDATA[Cork Cyber]]></dc:creator><pubDate>Tue, 04 Aug 2026 14:49:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ivRI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f7aceea-a61b-425b-accf-aa1261e8c2a1_640x360.gif" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ivRI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f7aceea-a61b-425b-accf-aa1261e8c2a1_640x360.gif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ivRI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f7aceea-a61b-425b-accf-aa1261e8c2a1_640x360.gif 424w, https://substackcdn.com/image/fetch/$s_!ivRI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f7aceea-a61b-425b-accf-aa1261e8c2a1_640x360.gif 848w, https://substackcdn.com/image/fetch/$s_!ivRI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f7aceea-a61b-425b-accf-aa1261e8c2a1_640x360.gif 1272w, https://substackcdn.com/image/fetch/$s_!ivRI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f7aceea-a61b-425b-accf-aa1261e8c2a1_640x360.gif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ivRI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f7aceea-a61b-425b-accf-aa1261e8c2a1_640x360.gif" width="640" height="360" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4f7aceea-a61b-425b-accf-aa1261e8c2a1_640x360.gif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:360,&quot;width&quot;:640,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:309462,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/gif&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.corkinc.com/i/209260545?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f7aceea-a61b-425b-accf-aa1261e8c2a1_640x360.gif&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ivRI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f7aceea-a61b-425b-accf-aa1261e8c2a1_640x360.gif 424w, https://substackcdn.com/image/fetch/$s_!ivRI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f7aceea-a61b-425b-accf-aa1261e8c2a1_640x360.gif 848w, https://substackcdn.com/image/fetch/$s_!ivRI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f7aceea-a61b-425b-accf-aa1261e8c2a1_640x360.gif 1272w, https://substackcdn.com/image/fetch/$s_!ivRI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f7aceea-a61b-425b-accf-aa1261e8c2a1_640x360.gif 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>Most monitoring answers one question. Is the tool installed, yes or no? Green check, you&#8217;re covered. Red X, go reinstall. It is clean, it is binary, and it is where a surprising amount of risk hides.</span></p><p><span>Since </span><em><span>installed</span></em><span> and </span><em><span>working</span></em><span> are not the same question. A tool can be deployed on every endpoint you expect, show up as present in your RMM, and still be quietly failing to do the one job you are paying it to do.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://blog.corkinc.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://blog.corkinc.com/subscribe?"><span>Subscribe now</span></a></p><h4><span>A story most MSPs will recognize</span></h4><p><span>Here is a pattern that plays out more often than anyone likes to admit.</span></p><p><span>A client was certain their EDR was deployed everywhere. Their RMM confirmed it. The agent showed installed across every endpoint, so as far as the team was concerned, those machines were protected. </span><strong><span>Case closed.</span></strong></p><p><span>Then they started getting flagged that the tool was not checking in on a set of those same assets. The pushback was immediate: It is installed, I can see it right there. The reply was the part that stuck. We are not telling you it is not installed. </span><em><span>We are telling you it is not checking in.</span></em><span> Then, an audible pause fills the room. </span><em><span>Those are two different things.</span></em></p><p><span>The tool was there. It just was not working. We can&#8217;t expect everything to work the way it is the day it was installed, that&#8217;s just not how technology works. Once they dug in and fixed it, a wave of tickets that had been quietly piling up closed out. The experience changed how they ran monitoring from that day forward. The question was no longer &#8220;is it installed.&#8221; It was &#8220;is it connected and actually reporting.&#8221;</span></p><h4><span>Installed, configured, working: three different questions</span></h4><p><span>It helps to separate what a green checkmark actually promises from what you assume it promises.</span></p><p><span>Installed means the software is present on the machine. That is all it means. It does not mean the agent is checking in. It does not mean it is configured correctly. It does not mean it is sending data anywhere that anyone is watching. And it does not mean it is catching what it is supposed to catch.</span></p><p><span>Each of those is a separate condition, and a tool can pass the first and fail the rest. An EDR agent that stopped checking in after an OS update. A backup that runs on schedule but has been silently failing for six weeks. An email security policy applied to the domain but never extended to a batch of new mailboxes. In every case the dashboard says present. Reality says exposed.</span></p><h4><span>Why the binary view feels safe</span></h4><p><span>RMM and single-tool dashboards are built to answer the binary question, and they answer it well. Installed or not installed. That simplicity is exactly why it feels reassuring, and exactly why it is incomplete.</span></p><p><span>A yes-or-no view cannot tell you about degradation. It cannot tell you the agent went dark three days ago, because from its point of view the agent is still technically there. It cannot tell you that two tools disagree about the same machine. The binary view is comfortable precisely because it never surfaces the uncomfortable middle, the place where a tool is installed, looks fine, and has stopped doing its job.</span></p><p><span>That comfort has a name worth being honest about. It is the assumption that deployed equals protected. Most of the time it holds. The trouble is that the times it does not are invisible until something forces them into view.</span></p><h4><span>What it costs when installed is not working</span></h4><p><span>A tool that is installed but not working is in some ways worse than a tool you know is missing, because a known gap gets fixed and an invisible one just sits there waiting to be exploited.</span></p><p><span>The risk is obvious once you say it out loud: </span><strong><span>the endpoint everyone believed was covered is the one with no live protection</span></strong><span>. If an incident lands there, it lands on the machine that was at risk while appearing in compliance. If that client carries financial protection where that control is required for coverage, an unresolved gap on the exact asset that was compromised is precisely the kind of thing that can put a claim in jeopardy&#8230; at the worst possible moment.</span></p><p><span>Every one of those silent failures is generating friction in an MSPs operations:</span></p><ul><li><p><span>Tickets that do not quite add up. </span></p></li><li><p><span>Alerts that never fire, because the thing that should fire them is offline.</span></p></li><li><p><span>Teams spend real hours chasing the symptoms of a tool that simply stopped reporting, without ever suspecting the tool itself.</span></p></li></ul><p>These points represents a quieter cost that is rarely considered.</p><h4><span>Monitor connection, not just presence</span></h4><p><span>The shift is not complicated, but it changes everything downstream. Stop monitoring whether tools are installed. Start monitoring whether they are connected and reporting.</span></p><p><span>That means treating &#8220;checking in&#8221; as the real signal, not &#8220;present.&#8221; It means cross-referencing your tools against each other, so when your RMM says a machine exists but your EDR has not heard from it in days, that disagreement surfaces on its own instead of waiting for an incident to reveal it. The gaps that matter almost always live in the space between two tools, and no single tool can see that space.</span></p><p><span>This is the layer Cork Vantage sits on. Rather than asking each tool whether it is installed, Cork watches whether the tools you already run are actually checking in, and flags the assets where they are not. Not &#8220;the agent is missing,&#8221; but &#8220;the agent is there and has gone quiet.&#8221; That is the alert that closes tickets before they become incidents, and it is the difference between a stack you assume is working versus proving that everything is in place as expected.</span></p><h4><span>The question to ask this week</span></h4><p><span>Pick one tool you consider fully deployed across your client base. Now ask a harder question about it. Not &#8220;is it installed everywhere,&#8221; but &#8220;</span><em><span>is it checking in and reporting everywhere, today?</span></em><span>&#8221;</span></p><p><span>If the answer is a confident yes, backed by something more than a green checkmark, you are in good shape. If the honest answer is &#8220;it should be,&#8221; that gap is worth finding now, on your terms, rather than during an incident on someone else&#8217;s.</span></p><p><span>Installed is a starting point. Working is the whole game.</span></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.corkinc.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Cork's Substack! Subscribe for free to receive more posts about cybersecurity!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Cybersecurity Vulnerabilities from Unpatched VPNs and Software]]></title><description><![CDATA[How MSPs can identify exploited CVEs and prevent ransomware, data theft, and patient care disruption.]]></description><link>https://blog.corkinc.com/p/cybersecurity-vulnerabilities-from</link><guid isPermaLink="false">https://blog.corkinc.com/p/cybersecurity-vulnerabilities-from</guid><dc:creator><![CDATA[Cork Cyber]]></dc:creator><pubDate>Tue, 28 Jul 2026 18:42:14 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!R8Xj!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F374bb124-1483-4acf-8930-865ec1002ca6_215x215.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><span>Would you feel comfortable knowing your healthcare provider has been using known-exploited versions of VPN software putting all of your personal information at risk? Software that many businesses rely on to function such as VPNs, PDF readers, and browsers are all silent gateways that attackers can take advantage of to infiltrate.</span></p><p><span>At Cork Cyber, we proactively monitor over a million devices to safeguard against threats. As part of this effort, we analyze software inventories across these devices that come from RMMs and other tools to identify vulnerabilities and potential risks. Discover how your industry&#8217;s sanitation practices compare to others and uncover potential, concerning issues within your own environment that you might be overlooking.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://blog.corkinc.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://blog.corkinc.com/subscribe?"><span>Subscribe now</span></a></p><h4><span>Which industries are managing these vulnerabilities the best?</span></h4><p><span>When we look at the different vulnerabilities among sectors, one industry stands out for its effective sanitization of software vulnerabilities compared to the rest: </span><strong><span>educational services</span></strong><span>. Out of a sample of 7,000 devices, only 15.2% devices found to have a vulnerability (routine to critical). This sector&#8217;s success is driven by a conversion towards cloud-centric OS environments (such as ChromeOS) and centralized management tools. Chromebooks alone were found to reduce support labor by 92% in comparison to standard desktops and laptops. In comparison to the healthcare and social assistance sector, the difference is alarming. In a much larger sample size of 38,793 devices we found more than a third (34.4%) of devices contained some sort of vulnerability. A device in a healthcare setting is more than twice as likely to be vulnerable as one in a classroom, despite much more at stake. For context, across all sectors we found on average 29.3% of devices are considered vulnerable.</span></p><h4><span>So, what exactly are triggering these alarms?</span></h4><p><span>When we look beyond the standard browser-based threats that affect every user, the most critical risks are seen in the operational tools industries rely on daily: VPNs, PDF Readers, and database management systems. While browser vulnerabilities are frequent, they are often low in severity due to auto-updates. Many times a user has multiple browsers installed in which they keep their browser of choice updated, while the other browsers remain out of date due to never opening them. The real &#8220;silent killers&#8221; are the infrastructure tools that facilitate remote work and storage; software that is often trusted, installed, and then </span><strong><span>forgotten</span></strong><span>.</span></p><p><span>In the healthcare sector, our most concerning finding is the massive prevalence of vulnerable SonicWall NetExtender clients (1,358 devices). Just this year there has been a surge in attacks where threat actors have exploited defects such as CVE-2024-40766 and CVE-2024-53704 to bypass multi-factor authentication entirely. By targeting these unpatched clients, attackers can hijack active SSL VPN sessions to infiltrate into networks with the same permissions as a doctor or administrator. A breach here doesn&#8217;t stop a sale or cause downtime, it puts patient care and safety at risk. If an unpatched NetExtender client lets ransomware in, it could lock up patient histories, delay surgeries and more, making the management of these vulnerabilities an absolute necessity. In 2025 it was found that 72% of U.S. healthcare organizations that faced a cyberattack had a disruption to patient care.</span></p><p><span>The financial and construction sectors face a different but equally dangerous VPN hurdle, with a heavy reliance on Cisco Secure Client (formerly AnyConnect). These industries often rely on Cisco because of it being a trusted industry standard for enterprise security, however, its large prevalence also makes it a prime target. When hundreds of devices are left unpatched, it makes a backdoor into the network much easier. A compromised VPN could allow attackers to steal proprietary blueprints and bid data in the construction industry. In finance the stakes are even higher with the ability to steal clients&#8217; financial records. In 2025 the &#8220;Velvet Ant&#8221; group targeted many sectors, including financial, to steal sensitive records and intellectual property by exploiting Cisco vulnerabilities and others. By utilizing these specific VPN flaws, they were estimated to have stolen over $244 million by late 2025.</span></p><p><span>However not all threats come via remote access tools. The professional, scientific, and technical services sector as well as the manufacturing sector&#8217;s danger lies deep within the backend. For Microsoft SQL Server 2019 alone, we found 2,768 vulnerable devices in the former and 1,028 vulnerable devices in the latter. Leaving these vulnerabilities unattended can allow hackers to not only steal sensitive client records, they can also deploy ransomware to encrypt the database files. The compromised business is then threatened to either pay a ransom fee or have their files leaked on the internet and files remain encrypted. It&#8217;s very easy for this to lead to the end of many small businesses. Half of all small businesses only have enough cash to stay open on average for 27 days with no income. Meanwhile, the average length of recovery for a ransomware attack in 2025 was up to 27 days.</span></p><p><span>Lastly, out of date PDF readers were the third biggest point of entry among various sectors. While these tools are viewed as harmless utilities, a single unpatched reader can turn a routine document review into a full network compromise. We found 161 devices in the educational services sector with a Foxit PDF Reader vulnerability as well as 341 devices utilizing Adobe Acrobat Reader in the public administration sector with a vulnerability. Threat actors have been seen exploiting these flaws and embedding malicious code into what seems to be innocent PDF assignments or administrative forms. When a teacher or administrator opens the file, the exploit triggers silently in the background executing code that can deploy spyware like Recmos RAT (remote access trojan) to harvest credentials. Not only does this compromise personal administrative records, but it also affects student records alike. RAT&#8217;s such as Recmos allow webcams and microphones to be remotely activated which can also threaten the safety of minors.</span></p><h4><span>Do you truly know what lives on your network?</span></h4><p><span>The vulnerabilities we&#8217;ve discussed so far on SQL servers, corporate VPNs, and PDF readers are all business-critical tools. It comes as no surprise they are installed; they are essential for operations. But the question every business leader and MSP must ask is: are you aware of everything else?</span></p><p><span>Some businesses allow individuals to bring their own device (BYOD), but if devices aren&#8217;t properly monitored and sanitized, the corporate networks drastically become at risk. It takes only one compromised device running unauthorized or vulnerable software to bridge the gap between a secure environment and the public internet. While analyzing vulnerabilities and software inventories we&#8217;ve found many employees treating company assets like personal laptops, introducing significant risk.</span></p><p><span>One of the most frequent unauthorized categories we observed was the presence of personal VPNs. We found about 4,000 instances of ExpressVPN, NordVPN, Surkshark, and Private Internet Access installed on corporate workstations. While employees may have legitimate reasons to have these installed, it creates a &#8220;blind spot&#8221; where data can be exfiltrated (or malware introduced) without the security team ever seeing it happen.</span></p><p><span>Even more concerning was the presence of torrent clients (such as Deluge uTorrent) and other peer-to-peer file sharing software. This isn&#8217;t just a potential legal issue regarding copyrighted material, it&#8217;s a direct pipeline for identity theft. According to a 2024 report by Flare, nearly 41% of all stolen credentials sold on the Dark Web originated from devices infected via pirated software and P2P games.</span></p><p><span>However not every unauthorized app we found was &#8220;malicious&#8221;, more so reminders that everyone is human. Across all industries we found thousands of installs of Spotify and other personal media software. We also checked for the presence of applications associated with gaming such as Steam, Epic Games, and Discord. While gaming software is more expected in education environments, its prevalence in the information sector (also seen in other business orientated sectors) exposes a critical gap in endpoint management.</span></p><p><span>MSPs must take it upon themselves to better enforce strict software policies on corporate assets. Whether operating under a BYOD policy or simply failing to lock down corporate hardware, the lack of proper monitoring and sanitization puts networks at drastic risks. They need to both block unauthorized executables and question why recreational software is being run on devices intended for secure business operations.</span></p><h4><span>What can you do to be aware of these issues?</span></h4><p><span>Awareness is the first line of defense; you cannot patch what you do not know exists. The NIST Cybersecurity Framework (CSF) 2.0 is a great reference to ensure you are checking all boxes. In short you need to: maintain a complete software inventory, implement continuous vulnerability monitoring, and adopt an enterprise patch strategy. <br><br>Continuous monitoring can feel like a massive undertaking, largely because standard RMMs fall short. Most tools focus strictly on Windows updates and popular apps like Chrome, leaving you to manually track patches for everything else. To bridge this gap, Cork developed its own software vulnerabilities tool to help provide suggestions and comprehensive visibility that traditional RMMs miss.</span></p><p><span>Rather than focusing solely on popular applications, Cork evaluates your </span><strong><span>entire</span></strong><span> software inventory. It maps your software against official vulnerabilities from the National Vulnerability Database (NVD) by NIST and cross-references them with emerging threats actively being exploited and identified on the dark web. Instead of just flagging the problem that others miss, Cork also gives clear remediation steps for each CVE that is detected and the easiest way to solve the vulnerability.</span></p><div><hr></div><p><em><span>Visit </span><a href="http://corkinc.com"><span>corkinc.com</span></a><span> to learn more, or </span><a href="https://hubs.la/Q049XKvY0"><span>schedule a live demo with the team</span></a><span> to see your hidden vulnerabilities today.</span></em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.corkinc.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Cork's Substack! Subscribe for weekly articles about cybersecurity!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[The Stack You Can See Is the Stack You Can Trust]]></title><description><![CDATA[Tool sprawl hides your risk and quietly drains your margin.]]></description><link>https://blog.corkinc.com/p/the-stack-you-can-see-is-the-stack</link><guid isPermaLink="false">https://blog.corkinc.com/p/the-stack-you-can-see-is-the-stack</guid><dc:creator><![CDATA[Cork Cyber]]></dc:creator><pubDate>Tue, 21 Jul 2026 14:03:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!hxsk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fca7360-9af6-4796-984a-87a87637a00f_2800x2000.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hxsk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fca7360-9af6-4796-984a-87a87637a00f_2800x2000.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hxsk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fca7360-9af6-4796-984a-87a87637a00f_2800x2000.png 424w, https://substackcdn.com/image/fetch/$s_!hxsk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fca7360-9af6-4796-984a-87a87637a00f_2800x2000.png 848w, https://substackcdn.com/image/fetch/$s_!hxsk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fca7360-9af6-4796-984a-87a87637a00f_2800x2000.png 1272w, https://substackcdn.com/image/fetch/$s_!hxsk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fca7360-9af6-4796-984a-87a87637a00f_2800x2000.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hxsk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fca7360-9af6-4796-984a-87a87637a00f_2800x2000.png" width="1456" height="1040" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7fca7360-9af6-4796-984a-87a87637a00f_2800x2000.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1040,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:425951,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://blog.corkinc.com/i/207470517?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fca7360-9af6-4796-984a-87a87637a00f_2800x2000.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hxsk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fca7360-9af6-4796-984a-87a87637a00f_2800x2000.png 424w, https://substackcdn.com/image/fetch/$s_!hxsk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fca7360-9af6-4796-984a-87a87637a00f_2800x2000.png 848w, https://substackcdn.com/image/fetch/$s_!hxsk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fca7360-9af6-4796-984a-87a87637a00f_2800x2000.png 1272w, https://substackcdn.com/image/fetch/$s_!hxsk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fca7360-9af6-4796-984a-87a87637a00f_2800x2000.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p><span>Ask an MSP how many security tools they run across their client base, and watch the pause before the answer. Most can name the big ones without thinking. EDR, RMM, email security, backup, identity. Then the list gets fuzzy. There&#8217;s the platform they migrated off last year that might still be checking in somewhere. The tool one client insisted on. The point solution that came with an acquisition. The trial that quietly converted to a paid plan.</span></p><p><span>That pause is the whole problem. If you can&#8217;t say with confidence what is deployed on every endpoint today, you can&#8217;t protect it, you can&#8217;t prove it, and you are almost certainly paying for pieces of it you no longer use.</span></p><h4><span>Nobody built this stack on purpose</span></h4><p><span>No MSP sat down and designed a sprawling toolset. It grew by accretion.</span></p><p><span>Every new threat in the last five years added a tool. Every acquisition added a tool. Every uncomfortable QBR where a client asked a question you couldn&#8217;t answer added a tool. Here is the part that does the damage: almost nothing ever gets removed. Tools go in. They rarely come out.</span></p><p><span>The result looks reassuring from the outside. A long list of capabilities. A console for everything. A vendor for every category. On paper, it reads as comprehensive.</span></p><p><span>Underneath, it is a different picture. The same growth that made the stack look complete is what makes it impossible to see clearly. You are not running one system. You are running a dozen systems that don&#8217;t talk to each other, each with its own console, its own definition of &#8220;covered,&#8221; and its own idea of what a healthy client looks like.</span></p><h4><span>One pane of glass per product</span></h4><p><span>The industry sold MSPs on the single pane of glass for years. What most teams actually got was one pane of glass per product.</span></p><p><span>Each tool shows you its own slice of reality and nothing else. Your EDR tells you about the endpoints it knows about. Your RMM tells you what it has an agent on. Your email security reports on the mailboxes it protects. None of them tell you where they disagree. And the disagreements are exactly where the risk lives.</span></p><p><span>Consider a simple question. Is every endpoint you bill for actually protected by every tool it should have? To answer that honestly, you would need to line up your RMM inventory against your EDR coverage against your backup reporting against your identity platform, and find the places where one tool sees a device the others don&#8217;t. No single console can do that, because no single console can see outside itself. So the question usually goes unanswered, and &#8220;installed&#8221; gets treated as &#8220;working&#8221; until something proves otherwise.</span></p><h4><span>The two costs of not seeing</span></h4><p><span>A stack you can&#8217;t see clearly bills you twice.</span></p><p><strong><span>The first cost is risk.</span></strong><span> Coverage gaps hide in the seams between tools. A device that fell out of the RMM but still shows in the EDR. A new employee whose mailbox never got added to the email security tool. A client environment from a migration that was never fully cut over. Each gap is small. Each is invisible unless something cross-references the tools against each other. And each is the kind of gap that turns into an incident, or into a denied claim at the exact moment a client needed their protection to hold.</span></p><p><strong><span>The second cost is money</span></strong><span>, and it is more immediate than most teams realize. Orphaned agents keep checking in. Licenses for clients you offboarded months ago keep billing. The platform you migrated away from is still running on a handful of machines nobody flagged. This is spend leaving the business every month for tools delivering zero value. And you cannot recover spend you cannot see.</span></p><p><span>For a lot of MSPs, closing that second gap alone pays for the effort of getting visibility in the first place. </span><em><span>It is found money sitting inside the stack you already own.</span></em></p><h4><span>If you rely on an MSP, this is your question too</span></h4><p><span>If you are not an MSP but you depend on one, this matters to you directly. You are trusting a provider to keep your business secure, and the honest test of that trust is not the length of their tool list. It is whether they can show you, clearly, what is protecting you right now and where the gaps are.</span></p><p><span>The best providers welcome that question. They can pull up a single view of your environment, point to what is covered, name what is not, and tell you what they are doing about it. A provider who can only answer one tool at a time, or who needs a week to assemble the picture by hand, is telling you something important about how well they can see their own operation, and by extension yours.</span></p><h4><span>Visibility is the foundation, not a feature</span></h4><p><span>Here is the reframe that changes how you run a security practice. Visibility is not one more capability to bolt onto the stack. It is the layer underneath everything else, the thing that makes the rest of the stack trustworthy.</span></p><p><span>You can&#8217;t remediate a gap you don&#8217;t know exists. You can&#8217;t prove protection to a client from a dozen disconnected reports. You can&#8217;t recover wasted spend you can&#8217;t find. </span><em><span>You can&#8217;t have the confident business conversation, the kind that actually truly impacts a clients business, when you are not sure what is running.</span></em></p><p><span>This is the whole idea behind how Cork approaches the problem. Rather than adding another tool with another console, Cork connects to the tools you already run and cross-references them against one another, agentless and API-based. The point is not more data. It is one source of truth across the stack, so the coverage gaps surface on their own, the wasted licenses become visible, and &#8220;what is actually deployed&#8221; stops being a question you have to guess at. From there, financial protection has something solid to sit on, because you can proactively prove the posture behind it.</span></p><p><span>That is the shift from a stack you hope is working to a stack you can prove is working with confidence.</span></p><h4><span>Start with one honest question</span></h4><p><span>You don&#8217;t need a project plan to begin. You need one honest question, asked across your whole client base at once. What is actually deployed and checking in right now, and where do my tools disagree?</span></p><p><span>If you can answer that today, you are ahead of most of the market. If you can&#8217;t, that gap is not a failing. It is the most valuable place you could point your attention this quarter. Everything else in a security practice, the protection, the proof, the profitability, gets easier the moment you can see clearly.</span></p><p><span>The tools you can&#8217;t see are not neutral. They are the ones costing you, in risk and in dollars. Seeing them is where the work starts.</span></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.corkinc.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Cork's Substack! Subscribe to receive weekly posts about cybersecurity!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Cybersecurity Is a Journey. Most Companies Can't Tell You Where They Are on the Map]]></title><description><![CDATA[A simple framework for measuring your security posture, and actually knowing whether it's improving]]></description><link>https://blog.corkinc.com/p/cybersecurity-is-a-journey-most-companies</link><guid isPermaLink="false">https://blog.corkinc.com/p/cybersecurity-is-a-journey-most-companies</guid><dc:creator><![CDATA[Cork Cyber]]></dc:creator><pubDate>Thu, 16 Jul 2026 13:16:12 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!R8Xj!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F374bb124-1483-4acf-8930-865ec1002ca6_215x215.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Ask most business leaders a straightforward question. Are you safer today than you were six months ago? Almost none of them can answer it.</p><p>They can tell you what they bought. The firewall. The antivirus. The email filter. What they can&#8217;t tell you is whether any of it is working, whether the gaps from last year are closed, or whether the number that matters most, their actual risk, is moving in the right direction.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.corkinc.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Cork's Substack! Subscribe for free to receive new posts from us!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>That is the problem with how most organizations think about security. They treat it as a project. Something you do once, check off, and forget. But security was never a destination you arrive at. It is a posture you hold, and posture drifts the moment you stop paying attention.</p><h4>The mindset shift</h4><p>Three ideas sit underneath everything else.</p><p>Security is an ongoing process, not a set-and-forget purchase. Your attack surface grows every time you add a device, hire an employee, or turn on a new cloud app. What was enough last year can be dangerously thin today.</p><p>Security has to be woven into how you operate, not bolted on afterward. Every hire, every purchase, every onboarding step either strengthens your posture or quietly weakens it.</p><p>And most important: you cannot improve what you cannot measure. Without a way to score where you stand, &#8220;getting more secure&#8221; is a feeling, not a fact.</p><p>So how do you measure something as sprawling as security posture? You break it into dimensions you can actually see.</p><h4>The four dimensions of security posture</h4><p>A complete picture of your security health comes from four questions. Each one is a lens. Together they are a system.</p><p><strong>1. Are your controls actually working?</strong> Not licensed. Not purchased. Working. This is where the first gap almost always shows up. A firewall nobody monitors is not protection. EDR that never got deployed to that one forgotten laptop is not coverage. The details matter here, and they compound: multi-factor authentication alone blocks over 99 percent of automated credential attacks, and more than 90 percent of attacks still start in the inbox.</p><p><strong>2. Are policies being followed?</strong> The human layer is where most breaches actually happen. Verizon&#8217;s Data Breach Investigations Report puts it at 82 percent of breaches involving a human or policy element. Training completions, access reviews, policy acknowledgments. This is unglamorous work, and it is also the difference between a defensible organization and an exposed one.</p><p><strong>3. Are known weaknesses getting fixed?</strong> Attackers do not need a zero-day when you have left the front door open for a month. Roughly 60 percent of breaches exploit vulnerabilities that are already more than 30 days old. Measuring posture here means knowing your patch windows and holding to them. Critical issues in a day or two. High within a week. Nothing important left to drift.</p><p><strong>4. What does your history tell you?</strong> Past incidents and claims are not just scars. They are a signal. A pattern of incidents points directly at gaps in the first three dimensions, and it shapes something with real dollars attached: your insurability, your premiums, and the terms carriers are willing to offer you at all.</p><h4>Why all four, together</h4><p>Here is the part people miss. No single dimension tells the truth on its own.</p><p>A company can have a beautiful security stack and terrible patching habits. Another can pass every compliance check and still have no MFA on a critical account. Strength in one area does not cover weakness in another. You need all four in view at once.</p><p>And when you measure them consistently over time, you get the thing that actually matters. Not a snapshot. A trajectory. You stop asking &#8220;are we secure,&#8221; a question with no honest answer, and start asking &#8220;are we getting safer,&#8221; a question you can prove.</p><h4>From four questions to one number</h4><p>This is the thinking behind the Cork Cyber Score. We take these dimensions and turn them into a single, trackable baseline, the way a credit score turns your financial health into one number you can actually work with and improve over time.</p><p>The idea is simple: pick your dimensions, measure them honestly, and watch the direction of travel. The organizations that treat security as something measurable, rather than something they hope is handled, are the ones that sleep better at night.</p><p>Security is a journey. The least you can do is know where you stand on the map.</p><div><hr></div><p><em>This is the first in a series where we break down how modern organizations measure, track, and improve their cyber posture. Follow along, and <a href="https://www.corkinc.com">visit Cork&#8217;s website</a> to learn more!</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.corkinc.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Cork's Substack! Subscribe for free to receive new posts from us!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>