network security experts

Mandatory Security Baselines: What MSPs Must Require of Their Clients

Mandatory Security Baselines: What MSPs Must Require of Their Clients

For years, managed service providers (MSPs) could treat security as a menu items:

  • Firewalls here,
  • Backups there,
  • Multi-factor authentication (MFA) if the client was willing to pay for it.

Why isn’t this still a good plan?

Regulators, cyber insurers, and federal guidance are converging on a simple expectation: MSPs are responsible for setting a mandatory security floor beneath every client relationship, not an optional upsell.

I want to tell you why “optional” security no longer works for our clients.

MSPs sit at the center of the supply chain, with privileged access into dozens or hundreds of client networks. That concentration of access is exactly why threat actors target providers directly, a risk the Cybersecurity and Infrastructure Security Agency (CISA) formally warned about in its joint advisory on protecting MSPs and their customers (CISA AA22-131A).

A single compromised MSP credential can cascade into ransomware across every client tenant it touches, which is why regulators increasingly hold the provider, not just the client, accountable for baseline hygiene.

That accountability is showing up in contract language and audit requirements.

HIPAA’s proposed 2026 Security Rule updates would require business associates — including MSPs — to prove MFA, encryption, and semiannual vulnerability scanning are actually operating, not merely documented. PCI DSS 4.0.1, mandatory since March 2025, now demands quarterly scans and continuous change-detection evidence. CMMC 2.0 is extending third-party assessment requirements to defense-sector clients starting in November 2026. Add in the FTC Safeguards Rule and a growing patchwork of state privacy laws, and the message is consistent: policies alone no longer satisfy anyone.

What belongs in the baseline

Across these frameworks, a common floor of controls has emerged as the practical minimum an MSP should mandate, not recommend, for every client, regardless of contract tier:

  • Phishing-resistant MFA on all administrative and remote-access accounts, moving beyond SMS or push-based approval.
  • Endpoint detection and response (EDR) with 24/7 monitoring, rather than legacy signature-based antivirus alone.
  • Centralized logging and SIEM coverage sufficient to reconstruct an incident timeline.
  • Documented, tested backups with offline or immutable copies and a defined recovery time objective.
  • Privileged access management, including just-in-time elevation instead of standing admin rights.
  • A patch management cadence with defined SLAs for critical vulnerabilities.
  • A written, exercised incident response plan — not a template that has never been tested.

CISA’s Cross-Sector Cybersecurity Performance Goals restate much of this same list as a voluntary baseline for critical infrastructure organizations, and it’s increasingly the yardstick auditors and cyber insurers reach for even outside regulated sectors.

Making the baseline actually mandatory

The hardest part isn’t defining the baseline — it’s enforcing it. Two mechanisms are becoming standard practice among mature MSPs. First, contracts should state plainly that these controls are conditions of service, not add-ons, with any client refusal captured in a signed risk-acceptance waiver that shifts liability back to the client. Second, evidence should be continuous rather than annual: MFA coverage reports, scan results, and backup test logs generated on a recurring schedule, not produced only when an auditor asks.

That shift — from attestation to continuous, evidence-backed operation — is the throughline across every framework touching MSPs right now. Providers that build it into their service delivery model, rather than bolting it on before an audit, will be the ones still standing when the next regulatory deadline or the next ransomware advisory lands.

Sources
Protecting Against Cyber Threats to Managed Service Providers and their Customers — CISA AA22-131A
MSP Compliance: The Complete Guide to Meeting Security and Regulatory Standards in 2026 — Huntress

Expensive to Retrieve

VMware’s Price Revolution: How Broadcom’s Changes Are Reshaping Mid-Market IT Strategy

Feeling Renewal Pain

Bottom Line: Broadcom’s acquisition of VMware has triggered dramatic price increases of 800-1,500% for many customers, forcing mid-market organizations to urgently evaluate alternatives like Microsoft Hyper-V to maintain cost-effective virtualization infrastructure.

Since Broadcom acquired VMware in November 2023, the virtualization landscape has undergone seismic shifts that are particularly devastating for small and medium-sized enterprises (SMEs). What began as a strategic acquisition has evolved into a pricing revolution that’s forcing thousands of mid-market organizations to fundamentally reconsider their IT infrastructure strategies.

The Scale of the Price Shock

The numbers are staggering. Some customers report price increases ranging from 800% to 1,500%, while some organizations face even more dramatic hikes. AT&T claimed Broadcom offered them a 1,050% price increase, transforming their annual VMware costs from manageable to prohibitive overnight. For context, these aren’t modest adjustments—they represent a complete overhaul of the economic equation that made VMware attractive to mid-market clients.

The pricing transformation isn’t just about higher numbers. Broadcom has fundamentally restructured how VMware products are sold and licensed. The company eliminated approximately 8,000 individual product SKUs, consolidating them into just two primary bundled offerings: VMware Cloud Foundation (VCF) and vSphere Foundation. This consolidation forces customers to purchase entire suites rather than selecting specific components they actually need.

The Mid-Market Squeeze

Mid-market organizations are caught in a particularly painful position. Unlike enterprise customers who might already use multiple VMware products and could potentially benefit from bundling, smaller companies typically relied on standalone solutions like vSphere Essentials Plus—which Broadcom has now discontinued. These organizations suddenly find themselves forced into enterprise-grade bundles that include features like NSX networking and vSAN storage they never requested or needed.

The new core minimums compound the problem. Starting April 2025, VMware enforces a minimum 72-core license subscription for products like vSphere Standard, up from the previous 16-core minimum. For organizations running smaller deployments or edge locations, this means paying for licenses that far exceed their actual needs. It’s like being forced to buy a truck when you only need a bicycle.

The transition from perpetual licenses to subscription-only models adds another layer of financial pressure. Many mid-market companies relied on the predictable, one-time costs of perpetual licenses that could be amortized over several years. The new subscription model transforms capital expenditures into ongoing operational costs, fundamentally altering budget planning and cash flow management.

We’ve actually run into instances where Broadcom is quoting OVER published list price for clients that they feel they can extort with a higher cost.

The Search for Alternatives

Faced with these dramatic changes, mid-market organizations are actively exploring alternatives, with Microsoft Hyper-V emerging as the most compelling option for many. The appeal is both strategic and economic.

Cost Advantages: Hyper-V is included with Windows Server licenses at no additional cost, providing immediate relief from VMware’s pricing pressure. For organizations already invested in Microsoft’s ecosystem, this represents enormous potential savings. While enterprises might need additional management tools like System Center Virtual Machine Manager, the base virtualization capabilities come without separate licensing fees.

Technical Maturity: Modern Hyper-V has evolved far beyond its early limitations. Windows Server 2025 includes significant enhancements to GPU partitioning for AI workloads and improved scalability that now supports up to 24TB of host memory—actually surpassing VMware in some specifications. Features like Live Migration, high availability clustering, and robust security through Shielded VMs provide enterprise-grade capabilities that match much of what VMware offers.

Integration Benefits: For organizations running Windows-centric environments, Hyper-V offers seamless integration with Active Directory, Group Policy, and Azure cloud services. This tight integration often translates to simplified management and reduced administrative overhead compared to managing separate VMware infrastructure alongside Microsoft systems.

Migration Feasibility: While migrating from VMware to any alternative requires careful planning, Hyper-V’s similarities in core virtualization concepts make the transition more approachable than some alternatives. Many organizations are discovering that their Windows-based workloads migrate relatively smoothly to Hyper-V environments.

Strategic Considerations for Mid-Market Leaders

The decision to migrate away from VMware shouldn’t be taken lightly, but the current pricing environment makes exploration essential. Organizations should conduct thorough assessments of their current VMware usage, identifying which features are truly necessary versus those that could be replaced with alternative solutions or eliminated entirely.

The migration window is critical. Existing VMware customers still operating under older support agreements have time to plan, but that window is closing. Organizations should begin testing alternatives immediately, even if they ultimately decide to remain with VMware under new terms.

For many mid-market companies, this crisis presents an unexpected opportunity to modernize their infrastructure approach. Some are discovering that moving workloads to public cloud platforms or adopting hybrid strategies provides better economics than either VMware or on-premises alternatives.

Looking Forward

Broadcom’s transformation of VMware reflects a deliberate strategy to focus on larger, more profitable customers while shedding smaller accounts. For mid-market organizations, this reality demands urgent action. The days of affordable, flexible VMware solutions for smaller deployments appear to be ending permanently.

The good news is that alternatives like Hyper-V have matured significantly and can now handle most workloads that previously required VMware. Combined with cloud-native solutions and modern infrastructure approaches, mid-market organizations have viable paths forward—but only if they act decisively.

The virtualization landscape is experiencing its most significant disruption in decades. Organizations that move quickly to evaluate and implement alternatives will be best positioned to maintain cost-effective, capable infrastructure. Those who delay risk being trapped in unsustainable licensing agreements that could constrain their growth and innovation for years to come.

The revolution is here. The question isn’t whether change is coming—it’s whether your organization will lead or follow in responding to it.

Microsoft confirms KB5036893 and KB5036892 patches break VPNs

Microsoft’s recent patches, KB5036893 and KB5036892, released April 9th, 2024, has been impacting VPNs for both Windows 10 and Windows 11 machines.

This issue affects all currently supported versions of Windows: Windows 10 21H2 and 22H2; Windows 11 versions 21H2, 22H2, and 23H2; and Windows Server 2008, 2008 R2, 2012, 2012 R2, 2016, 2019, and 2022.

Microsoft is working on a fix, but it seems to be impacting VPN connections backed by TPM certificates.

To uninstall the update, press the Start button and search for ‘Settings’. On the screen that appears, click on ‘Windows Update’ and find and tap on the ‘Update history’ option. Here, you will see a list of installed updates. If you are on Windows 11, find the KB5036893 update and uninstall it. However, those on Windows 10 will have to find and uninstall the KB5036892 update.

Alternatively, Use the command DISM /online /get-packages to find the name of the April update package (specifically the LCU “cumulative” package) and use the DISM/Remove-Package command line option to begin the uninstall process. Detailed instructions are listed at the bottom of Microsoft’s KB5036893 support page.

VDI infrastructure

Virtual Desktop Infrastructure (VDI) adding security to your organization

Virtual desktop infrastructure (VDI) has many benefits (among them):

  • A scalable infrastructure: Virtual desktops have become more appealing due to the cloud. By using adaptable infrastructure to provide resources as needed, the consolidation of the full VDI desktop infrastructure onto a host server lowers overall costs because businesses don’t have to purchase or maintain the necessary hardware.
  • Management structure: The virtual desktop infrastructure allows administrators to patch, maintain, and modify all virtualized desktops simultaneously. As a result, there is no need to repair and maintain the entire network of desktop computers on an individual basis. Moreover, in the event of a major disruption, the data center has all information backed up and supported.
  • Enhanced Security: VDI desktop services allow organizations to preserve and protect their sensitive information because the data isn’t stored on the users’ individual devices but within the data center. If the employee’s laptop, desktop, or other device is compromised, the hacker cannot access the organization’s data. Of course, the effectiveness of the security will depend upon the IT team’s vigilance regarding system management, and the authentication process for the remote users has to be rigid and scrupulously maintained.
  • Improved user experience. Employees are allowed to use the device of their choice in the manner of their choice, making the remote working experience easier and more convenient.
  • Lower cost. The overheads for maintaining legacy hardware will be lowered considerably due to the reduced need to upgrade and maintain in-office hardware.

Our team, in conjunction with our skilled engineers at GCSIT, can help your organization plan, procure, implement and support your VDI solution.

VMware code execution flaw CVE-2021-21972

There is a newly disclosed code-execution vulnerability in VMware vCenter.  VMware was quick to release a patch (within a day) and it can be found here.

The severity of this vulnerability as well as the fact that there are exploits available for both Windows and Linux servers, kicked off a flurry of mass scanning for vulnerable vCenter Servers.

Code execution, no authorization required

CVE-2021-21972 allows hacker with no authorization to upload files to vulnerable vCenter servers that are publicly accessible over port 443, researchers from security firm Tenable said. Successful exploits will result in hackers gaining unfettered remote code-execution privileges in the underlying operating system. The vulnerability stems from a lack of authentication in the vRealize Operations plugin, which is installed by default.

The flaw has received a severity score of 9.8 out of 10.0 on the Common Vulnerability Scoring System Version 3.0. Mikhail Klyuchnikov, the Positive Technologies researcher who discovered the vulnerability and privately reported it to VMware, compared the risk posed by CVE-2021-21972 to that of CVE-2019-19781, a critical vulnerability in the Citrix Application Delivery Controller

Ransomware and the impact to your business

Everyday, you read another story about how a company has been hit by a ransomware attack, which potentially can disrupt your business, services to your clients and livelihood of your employees.

Just last week it was announced another company, Forward Air, was hit by a ransomware attack, which disrupted services and impacted revenue.  This attack was attributed to a group “Hades”.  Forward Air, a trucking company from Tennessee, posted revenues of $1.4 billion in  2019 and employs more than 4300.

The ransomware note, resembles a similar note used by another ransomware group known as “REvil”, also known as “Sodin”.

Hades Tor site

 

This is a Sodinokibi variant that was first seen in early 2019.  Sodinokibi is what is known as ransomware-as-a-service, basically a software package which is catered by underground vendors to threat actors providing them a ransomware platform tool.

Companies are limited in their ability to defend against this type of exploitation, especially if they do not have full time IT staff or contracted Managed Service Providers that focus on security.  Your organization must follow the following guidelines to help mitigate your exposure:

  • Patch aggressively so vulnerabilities are eliminated and access routes are contained
  • Enable endpoints with tools that automatically detect and respond to infections before they become systemwide
  • Enable network threat intelligence tools to detect anomalies in your network traffic
  • Make sure emails are screened for malicious payloads and links
  • Minimize access levels by employees to perform their job functions

If you have been hit by ransomware, or just want to assess your company’s state of preparedness, reach out to us to discuss your needs.

LMJ is a full service Managed Service Provider, with offices in Alaska and California.