We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.
Aug 20, 2026 · 40 min · 12 segments
!https://i0.wp.com/channelbuzz.ca/wp-content/uploads/2026/03/Tony-Anscombe.jpeg?resize=300%2C169&ssl=1 Tony Anscombe, chief [security](https://channelbuzz.ca/tag/security/ "Posts tagged with…
!https://i0.wp.com/channelbuzz.ca/wp-content/uploads/2026/03/Tony-Anscombe.jpeg?resize=300%2C169&ssl=1 Tony Anscombe, chief [security](https://channelbuzz.ca/tag/security/ "Posts tagged with Security") evangelist at ESET ESET’s 2026 SMB Cyber Readiness Index surveyed 700 cybersecurity decision-makers across the United States and Canada, and the findings tell a story that should matter deeply to the Canadian MSP channel: the businesses that have been breached the most feel the most confident, cyber insurers are increasingly becoming managed security providers, and the gap between AI anxiety and actual threat reality is as wide as ever. In this episode of In The Channel, ESET Chief Security Evangelist Tony Anscombe returns to unpack the datat. The conversation opens on what Anscombe calls the “confidence paradox” — 91 percent of US SMBs and 88 percent of Canadian SMBs with multiple incidents in the past year report high confidence in their cyber resilience, compared to those with fewer or no incidents. Anscombe argues this is not mere resilience theater: live incident response functions as an unplanned exercise, and organizations that survive it genuinely understand their own capabilities better. For MSPs, the takeaway is to replicate that experience through simulation — taking anonymized real-world incidents from one client and running them as tabletop exercises for another. The discussion then turns to the insurance-MSP nexus, which Anscombe describes as a collapsed fence rather than a competitive boundary. The report finds that 35 percent of US SMBs and 27 percent of Canadian SMBs now outsource security directly to their cyber insurer, yet the same report flags monoculture risk: if three or four major insurers rely on the same one or two security products, a single exploit could compromise an entire portfolio. Anscombe suggests MSPs should embrace the shift by building relationships with insurance brokers, getting their services pre-authorized to lower client premiums, and differentiating on holistic ownership of the security stack rather than ceding the [MDR](https://channelbuzz.ca/tag/mdr/ "Posts tagged with MDR") layer alone. On AI, the perception gap remains stubborn. AI-powered malware ranks as the top concern for roughly one-third of SMBs in both markets, yet [phishing](https://channelbuzz.ca/tag/phishing/ "Posts tagged with Phishing"), weak passwords, and unpatched vulnerabilities remain the actual leading causes of breaches. Anscombe brings fresh research on malicious AI skills and shadow AI — unverified code that employees attach to agents inside the network — and notes that over half of organizations still lack a formal AI usage policy. For MSPs, walking into a client with a draft AI governance framework is an immediate, billable conversation starter. Finally, the episode closes on training cadence and business risk framing. While 90 percent of SMBs call awareness training critical, Anscombe argues the annual checkbox model is broken. He recommends monthly five-to-fifteen-minute micro-learning modules tied to seasonal phishing themes, and urges MSPs to reframe their pitch from “cyber risk” to “business risk” — because the clients who are buying insurance and increasing security budgets are doing so to mitigate [financial](https://channelbuzz.ca/tag/financial/ "Posts tagged with Financial") loss, not to chase technical metrics. **Read Full Transcript** **Robert Dutt:** Hello and welcome to In The Channel from ChannelBuzz.ca, bringing news and information to the Canadian IT channel community for the last 16 years. I’m Robert Dutt, editor of ChannelBuzz.ca, and your host for the show. Today, we’re digging into the results of ESET’s 2026 SMB Cyber Readiness Index, which surveyed hundreds of small and medium-sized businesses across the United States and Canada on their cyber resilience, insurance habits and AI readiness. With me, as usual, is Tony Anscombe, ESET’s chief security evangelist. If you’ve listened to the show before, you know Tony is a regular here. He always brings a perspective that manages to be both deeply technical and deeply practical for the MSPs and resellers in our audience. We’re going to talk about a few things that jumped out at me from the report: the strange confidence paradox that says the more breaches you’ve had, the more confident you feel; the collision course between cyber insurance and the MSP channel; why AI-powered malware dominates the headlines while phishing and weak passwords continue to do the actual damage; and why Tony thinks the smartest MSPs might soon be talking less about cyber risk and more about business risk. Let’s get right into it. My chat with Tony Anscombe. **Robert Dutt:** Tony, thanks for taking the time. I appreciate it. **Tony Anscombe:** It’s always a pleasure to come and talk to you, Rob. Always a pleasure, and you’ve been on this show more than just about anyone else. **Robert Dutt:** The report you put out shows a really striking pattern: the more breaches an SMB has suffered, the more confident it feels in its cyber resilience. I think the figure was 91% of US SMBs and 88% of Canadian SMBs with multiple incidents in the past year saying they were confident, compared with lower numbers among those with zero or one incident. You wrote that attacks are becoming the new norm. That’s something we’ve talked about before, and it has become a common mindset in the industry. I’m curious: is that confidence among organizations that have been breached multiple times earned, or is it simply normalization? For MSPs watching this in their client base, how do you tell the difference between genuine maturity and what we might call resilience theater – self-delusion, or simply wanting to look better than you really are? **Tony Anscombe:** First, let’s break that down a little bit. We have people who have been attacked once, people who have been attacked twice, and then there are those who don’t know whether they’ve been attacked. That’s a bit worrying, although it may simply mean that the wrong person answered the question. As you said, if somebody has been attacked twice, they have greater confidence in their cyber resilience plan than somebody who has only been attacked once. From the end user’s perspective, they are the ones answering the question. That tells me that after they have been attacked once, they understand the game. They understand what incident response involves. They know what they need to have in place and how to assemble the team when an incident occurs. They feel more confident because, in effect, they have done a live exercise. **Robert Dutt:** Although it wasn’t an exercise, was it? They dealt with a live incident. **Tony Anscombe:** Exactly. If it had been an exercise, the organizations that had not yet been attacked, or had only been attacked once, might have had greater confidence. But I think the lower confidence is simply a result of not having the experience needed to feel confident. If you and I went out to shoot arrows at an archery target on Saturday, the second time we did it, we’d be better than the first time. The third time, we’d be better than the second. **Robert Dutt:** Well, I’d hope we would be better. **Tony Anscombe:** Or we could be axe throwing, or whatever it might be. My point is that you get better the more you do something, or you understand what you’re doing more clearly. So how does this apply to MSPs? For me, the lesson is that you need to run real-life simulations to give people that confidence. Take a real incident from one of your customers, walk across to another customer, remove anything that should not be disclosed, and put that scenario firmly on their table. Run it as an incident. Give them a real-world example of how an incident unfolds and unpack it for them. That gives them confidence in two ways. First, it shows that you, as an MSP, know how to deal with the situation. Second, it gives them a grounding in exactly what other customers have experienced when incidents unfold. They can gain from the experience of others. I think it’s about running what you might call a tabletop exercise, although for me it’s really an incident simulation. My takeaway for any MSP would be to offer an incident simulation to your customers, rather than simply presenting it as a tabletop exercise. Doing tabletop exercises is not new. But an incident simulation based on a real-world event gives it more weight. **Robert Dutt:** When you talk to MSPs, are you seeing many that are taking what they’ve learned from a real-world experience with one customer, abstracting it enough that they aren’t giving away anything they shouldn’t, and then using it as a repeatable training exercise with other customers? **Tony Anscombe:** No, I don’t think I’ve seen much of that. But I also think MSPs and people in our industry are so busy running from hello to post that they don’t have time to stop and think about putting something together in quite that way. The other thing I’d say is that cyber insurers do most incident response very well these days. If an MSP has a relationship with a specific cyber insurer, I would go to that insurer and say, “Can we borrow your incident response team’s experience to run a simulation with our customers?” It helps the insurer as well. It can reduce their costs when an incident happens if everyone already knows what they are doing. There are multiple parties that could be involved in this. **Robert Dutt:** The interplay between cyber insurance and the MSP channel is fascinating to me. According to the report, a little over a third of US SMBs that outsource security are getting their MDR directly from their cyber insurance provider. In Canada, the figure is closer to a quarter. The report also notes that roughly three-quarters of US businesses and two-thirds of Canadian businesses are concerned about single-vendor ecosystems – a kind of security monoculture. So insurers are both absorbing the risk and providing the services intended to prevent it. For MSPs, is this a partnership opportunity, a competitive threat, or something else entirely? Where do you see this relationship going? **Tony Anscombe:** It is interesting because if you talk to somebody on the cybersecurity side of the fence, they will say, “No, no, we’re cybersecurity.” On the insurance side of the fence, they will say, “No, no, we’re insurance.” But the fence has come down. These days, you’re stepping over a pebble, not even a fence post. Look at what cyber insurers are now providing. For example, a proactive cyber insurer will send [vulnerability](https://channelbuzz.ca/tag/vulnerability/ "Posts tagged with vulnerability") notifications. They know what hardware and software a customer is running. When they see a CVE, they send that information directly to the customer. That is an MSP function. A lot of the services insurers are now providing are services that MSPs have traditionally provided. The crossover is quite intense. For me, as an MSP, I think you need to embrace it. Insurers are collecting more and more data. They are underwriting more and more financial risk and mitigating that risk for businesses. Therefore, MSPs need to be part of that. What does that look like? If I were an MSP, I might rely on a vendor’s MDR service, or I might run my own stack and operate my own MDR service. Both models exist. I would have the services I provide pre-authorized by the insurer. That could mean lower premiums for the customer. It shows that you understand the business requirement to mitigate financial risk, and it shows the customer that you understand the insurance side of the equation. The message to the customer is: “You understand my business, and you are lowering my premium by making sure your services are certified or approved by the insurer.” So I think the MSP needs to get involved. The numbers you mentioned were shocking to me. The number of people carrying cyber insurance was not surprising. It is above 80% in both the United States and Canada. What did surprise me was the number of people buying MDR directly from the insurer, cutting out the MSP, reseller or other intermediary. In Canada, that number was 27%, and I think it is growing. The model is customer to broker to cyber insurer, with the insurer providing the MDR directly. That creates the monoculture you mentioned. If three or four insurers in the market are doing this and, between them, they use two products – which is what we’re actually seeing, because insurers tend to focus on one or two products – then a sophisticated attacker who finds a vulnerability in one of those products could potentially affect an insurer’s entire portfolio. There might not even be enough incident response capacity to handle all the affected customers because the insurer would be dealing with a widespread problem across its entire book of business. **Robert Dutt:** That sounds like the same problem we’ve seen in recent years with MSP tools being used as an attack vector, but at a higher level of scale because of the size of the insurance players backing these services. **Tony Anscombe:** Absolutely. People may wonder how somebody who works for a vendor can say that the market needs more diversity. But that’s exactly what cybersecurity needs. There needs to be a mix of vendors in the marketplace. Diversity creates better security. **Robert Dutt:** So how does an MSP deal with this? How do you build a healthy, diversified security ecosystem? What do you say when a customer says, “My insurer is providing MDR as part of my policy. Why should I pay you separately?” How does an MSP demonstrate its value in that situation? **Tony Anscombe:** MDR is one part of the solution. Security comes in many layers and many forms. The MSP may be providing the identity and access management solution, the firewall, and other pieces of the cybersecurity puzzle. An enterprise may need all of those things. If the insurer is providing one piece of the puzzle, the MSP can still be the one organization that owns and manages the entire environment. Typically, you go with one MSP because one person owns all of it. The insurer will never own all of it, but the MSP can. You have to show that value to the customer. You can say, “I can look after all of this. I can make sure it runs together seamlessly. I can provide incident reporting from one source rather than two different sources, so you don’t have to correlate separate reports.” If there is an incident involving multiple parts of the infrastructure, having one organization with visibility across all of those areas is better than having one provider managing MDR and another handling access management. I think MSPs are in a good position. However, I understand why customers want their insurer to provide MDR directly. It makes claims easier. If there is an incident, the insurer is already involved because it provided the security service. It also means the insurer understands the customer’s environment. If I were an MSP today, I would be very tempted to develop a close relationship with a local broker. If I were a large enough MSP, I might even consider starting an insurance brokerage or having a broker on staff – somebody who really understands how to talk about finance, business risk and financial mitigation. **Robert Dutt:** That’s a pretty significant stretch for a lot of MSPs, but with the industry moving toward cyber insurance and the importance of it increasing, I can see the argument. **Tony Anscombe:** That’s why I would say smaller MSPs should talk to local brokers. You could become the cybersecurity expert for the broker. I can tell you now that if you go into many brokerages, there are very few people who understand cybersecurity in depth. **Robert Dutt:** Let’s get back to some of the differences between the United States and Canada. Canadian SMBs are somewhat less likely to carry cyber insurance – 78% compared with 86% in the United States. They are also less likely to have insurer-mandated controls – 41% compared with 55%. On the positive side for our audience, when Canadian businesses outsource security, 38% still go to a traditional MSP, compared with roughly a quarter in the United States. Is Canada behind the United States in terms of market maturity and adoption [trends](https://channelbuzz.ca/tag/trends/ "Posts tagged with Trends"), or is it simply more cautious? What should MSPs take from those differences as an indicator of what may be coming? **Tony Anscombe:** I think the differences are relatively small. It is probably about market maturity. I also think Canada may suffer less from the class-action lawsuit scenario, where businesses need insurance to protect against that type of legal consequence. But the numbers are relatively small. I think any business today that has an online presence of any type needs to mitigate its financial risk. Cyber insurance is becoming normalized in the same way that directors’ liability insurance or fire and theft insurance is normal for a business. Cyber insurance is becoming a normal part of operating a business. **Robert Dutt:** SMBs in both countries rank AI-powered malware as their top concern, at about one-third on both sides of the border. But the actual leading causes of breaches are phishing, weak passwords, unpatched vulnerabilities and insufficient monitoring – the same issues we’ve been talking about for years. Obviously, AI is starting to affect the scale and nature of those attacks, whether by helping criminals craft better attacks or scale them more effectively. But why is the gap between perception and reality so stubborn? What does it mean for how MSPs should be talking to their clients about the actual risks they face today? **Tony Anscombe:** First, you need to address the actual causes. The incidents unfolding today are primarily caused by vulnerable systems, exploitation of vulnerabilities, phishing, credential theft and the other issues we’ve been talking about for years. The shocking finding in the Canadian data was that weak passwords ranked just behind phishing, which was number one, and were only one percentage point behind. I want to reach out to every MSP, every customer and every Canadian: if you’re still relying on passwords, please don’t. This should not still be causing incidents. Please make that change. My rant is over. If we look at the overall media trend and the attacks that are getting attention, traditional phishing attacks are no longer interesting to the press. The familiar attack where somebody loses credentials through phishing and then has their systems compromised has become normalized and moved to the back pages of the magazine. **Robert Dutt:** I say that as somebody who still thinks in terms of physical magazines. **Tony Anscombe:** Exactly. But if I open a technology site today, I can guarantee that it will be talking about AI-powered malware, AI attacks or problems with AI agents. I’ve just come back from Black Hat, where the conversation was primarily about the risk of AI. That included questions about OpenAI’s model going rogue, other vendors’ models going rogue, the discovery of vulnerabilities and the automatic development of exploits to take advantage of those vulnerabilities – all being done by AI engines. I can understand why AI is at the top of the list. But you cannot forget what is attacking you today. You still need to prepare for the newer threats, but if you take your eye off phishing, the cybercriminals will come back and hit you hard. It remains a known and tested way to compromise an organization. Don’t take your eye off what is actually happening while looking only at the new threats. **Tony Anscombe:** Let me also offer an opinion on the recent discussion about an AI system going rogue. Was it really a rogue agent? Did the AI go off and do something independently? No. A human tasked it with doing something, tasked it incorrectly and did not provide all the data it needed. There were links in the files provided to the AI agent, which meant it needed to find a way onto the internet to locate what it was looking for. The system was mis-tasked. My point is that AI agents today are human-controlled. The guardrails they operate within are also human-controlled. Does that mean it was a rogue agent, or does it mean it was a badly tasked agent? I see it as a human failing. **Robert Dutt:** I think we also need to keep some context here. **Tony Anscombe:** We have just published more research on AI skills. AI skills can be malicious or suspicious, in much the same way we see other threats unfold. AI skills are tools or pieces of code that attach to an AI agent to give it a particular capability. They may be unverified, unchecked pieces of code that an employee brings into the organization, attaches to an agent and runs inside the network. Organizations need protection against this type of activity. It is also a conversation MSPs should be having with customers to demonstrate that they understand the latest AI risks and how to manage and prevent them. I think this is an important educational opportunity and a good topic for discussion. If you have nothing else to talk to a customer about this month, talk to them about AI skills. It is a good conversation starter. **Robert Dutt:** It gives MSPs a way to demonstrate that they are ahead of the curve and paying attention to emerging risks. What else should the channel be doing to become that trusted bridge between what customers want to do with AI and getting it done safely? **Tony Anscombe:** Another issue is the lack of AI usage policies. I recently delivered a webinar for one of our regions. We asked a poll question during the webinar, and a couple of hundred people responded. There was no statistical relevance to the poll, but 54% answered negatively when asked whether their organization had an AI usage policy. Some respondents said they did not know. So the actual number may have been closer to 60%. This is a big opportunity. As an MSP, go in and help companies craft an AI policy. Help them have the conversation around shadow AI use, what a policy should look like and what they should protect against. This is about protecting against data leakage through a large language model or other AI tool. It is about protecting against somebody using an AI agent and AI skills in the wrong way. There are many conversations to be had. That would be a great service for an MSP to offer: helping a company develop a policy that provides security across the organization. **Robert Dutt:** To your point about some organizations not knowing whether they have a policy, or not knowing what that policy says, I’ve seen research showing differences of opinion within the same organization. You ask the executive suite whether the company has an AI safety policy, and they say yes. You ask the people working on the front lines, and they say, “What policy?” **Tony Anscombe:** The longer you leave it, the more employees will go off and do their own thing. Once they’ve done that, it becomes much harder to get them back to doing what you want them to do. The sooner you address it, the better. **Robert Dutt:** Another opportunity area is security awareness training. It is the leading budget priority for SMBs. More than 90% call it critical or very important, and about half are planning to increase their investment. At the same time, phishing remains the top cause of breaches. Where is the gap between investment in training and the effectiveness of that training in getting people to change their passwords and avoid phishing attacks? For MSPs that recommend or offer these programs, what should they look for to determine whether they are achieving behavior change rather than simply checking a compliance box? **Tony Anscombe:** If a customer tells an MSP, “I need to do cybersecurity awareness training once a year,” that is probably an insurance requirement. The MSP needs to go back to the customer and say, “I understand that this is a compliance requirement for your insurance. But I would also recommend doing this more frequently and running simulations.” Think about the times of year when phishing campaigns tend to increase. You see tax-filing phishing, Thanksgiving phishing and back-to-school phishing. That may sound [consumer](https://channelbuzz.ca/tag/consumer/ "Posts tagged with Consumer")-oriented, but there are also themes in the business calendar. You see shipping and delivery phishing involving companies such as DHL at certain times of the year. I would identify those times and create a plan. The organization can do its major annual training, but then it can add smaller modules throughout the year. Perhaps employees complete a short module every month or every six weeks. Or run a simulation tied to a topical theme. For example, before Thanksgiving, send simulated phishing emails to see whether employees identify them. I would put cybersecurity in front of employees about once a month, even if it is only a 15-minute session with 10 questions or a quick refresher based on recent phishing emails. I would do it much more frequently. A proactive plan like that from an MSP could be very effective. **Robert Dutt:** How much buy-in are you seeing for that more aggressive monthly cadence, compared with the annual “I’ve completed the checkbox, so I’m good to go” approach? **Tony Anscombe:** When the training is delivered in short snippets – a five- or 10-minute window each month – I think people respond to it more positively. That is different from seeing a compliance notice land in your inbox and thinking, “I have to do that four-hour training again.” People try to figure out how to fast-forward through the video, which I’m sure most people do. If it is only five or 10 minutes, people are more likely to take it seriously. You’re not taking them away from their work for very long, and it hopefully does not increase the investment too much beyond the compliance requirement. **Robert Dutt:** This was a surprise to me, particularly among US SMBs. Your report found that larger SMBs – those with 500 to 1,000 endpoints – are significantly less likely to deploy advanced protective measures such as threat detection and response than smaller organizations. The figure was roughly 25% compared with about one-third. Scale does not necessarily mean maturity. What is happening at that size? Are Canadian MSPs seeing the same thing with their [growth](https://channelbuzz.ca/tag/growth/ "Posts tagged with Growth")-stage or larger customers? **Tony Anscombe:** That’s a good question. I think it may be an anomaly in the data. The only explanation I can think of is that it may be easier for a company with 100 seats to say, “We’re going to adopt an advanced protection service such as MDR.” For a company with 500 seats, it becomes more difficult. It may have remote offices or other factors that complicate deployment. It may also view the solution as much more expensive. I can’t look at that data and say I have the definitive answer. I suspect the MSPs listening to this podcast may have a better explanation for why larger companies are more reluctant to adopt advanced solutions. But I think that will change. We talked earlier about vulnerabilities and AI. I think those issues will cause more companies to adopt advanced solutions more quickly. Look at the last three months of Patch Tuesday updates. We all know what Patch Tuesday is, even if it means your Windows machine doesn’t work properly for a day while it downloads all the updates. There were about 150 patches three months ago. There were approximately 150 to 200 two months ago. This month, there were 600. That is happening because AI models are finding vulnerabilities very quickly, and those vulnerabilities have to be patched quickly. It is only going to get worse in the short term. I think companies are going to recognize that they need advanced security solutions that include [patch management](https://channelbuzz.ca/tag/patch-management/ "Posts tagged with patch management"), EDR and MDR, whether they operate those services themselves or use a managed provider. I think the market will change naturally, and the AI conversation will accelerate that change. **Robert Dutt:** More than 80% of SMBs in both countries agree that cyber warfare and global conflict pose a threat to their business. That’s a huge number, especially when this is a group that still does not see supply chain risk as a top concern, even though supply chain attacks and dependencies are increasingly common. Is this heightened geopolitical awareness making SMBs more security-conscious, particularly with the conflicts happening around the world, or is it simply adding anxiety without moving the needle on what they are actually doing? **Tony Anscombe:** There are several things in that question. Take semiconductors, for example. If we talk about supply chain, supply chain can mean many things. It can refer to a supply chain attack, or it can refer to the way supply chain problems affect a business. It is becoming harder to get chipsets, and even buying hardware is becoming more expensive. If you look at where some conflicts around the world have been attempting to strike, I’ve noticed that in the last couple of months several have targeted data centers. That is targeted warfare. If you take out the data centers of AWS or another major provider, you don’t just affect a company’s [retail](https://channelbuzz.ca/tag/retail/ "Posts tagged with Retail") deliveries. You take down large parts of the internet, along with the cloud applications running in those data centers. If I were a small business, I would view those conflicts as increasingly relevant. If somebody starts taking down data centers, making infrastructure more expensive or disrupting access to hardware and services, that creates a real business challenge. So I think it is partly general awareness. Do SMBs think that one of these organizations is going to attack them directly? I would guess that only certain sectors believe they may be targeted directly – particularly businesses in critical infrastructure. Of course, critical infrastructure includes a surprisingly broad range of businesses. It can include food delivery as well. **Robert Dutt:** DoorDash is clearly critical infrastructure. Otherwise, how are you going to get your tea or dinner? **Tony Anscombe:** Exactly. That’s modern reality. When an attacker takes out a shared resource, such as a public cloud data center, it does not matter whether your individual business was the intended target. You can still be offline or affected. You only need to take down a data center somewhere in the world that is handling DNS resolution. It does not even have to be the application itself. It can be the route to the application you need. **Robert Dutt:** If there is one message you want MSPs to take from this report and bring back to their clients, what would it be? The data seems to come down to the same point: breaches are still fundamentally caused by human error, basic security hygiene and a failure to monitor the situation and address gaps. Is the industry’s obsession with the next big threat distracting from the work that matters most and keeps businesses running? **Tony Anscombe:** My big takeaway, if I read between the lines of the report, is that this is really a business risk issue. We talk about cyber resilience and cyber risk. I think businesses are talking about business resilience. They are talking about mitigating financial losses and dealing with the things that affect their operations, rather than focusing on things that affect their cybersecurity in isolation. The two things are closely related. But as an MSP, I would start focusing the conversation on business risk. Understand the customer’s business, and then explain what a cyber incident could mean for that business. What kind of outage could it cause? What could it take offline? How could it affect revenue or operations? Talk about the issue from a business standpoint rather than a purely cybersecurity standpoint, because I think that is what people are increasingly concerned about. The growth in cyber insurance shows that businesses are trying to mitigate financial risk, not just cyber risk. **Robert Dutt:** To wrap things up, if you’re a Canadian MSP with 50 or 100 SMB-focused clients and you can change only one thing about how you talk to those clients after reading this report, what should it be? **Tony Anscombe:** I would have to say that they should only talk to their customers about ESET. **Robert Dutt:** That’s an obvious answer. **Tony Anscombe:** Exactly. No, seriously, although I played down the AI risk slightly and said you also need to focus on the real threats, I think it is important to show that you understand the future risk from AI. Be bold enough to have open conversations about where the industry might go. You need to be seen as the technology visionary – the person who understands where technology may go and what the future risks may be. That is the person I would have the most confidence in if I were a small business owner. Keep up with the technology and have meaningful conversations. That can also help because some SMBs may be looking to deploy AI. Every business owner is thinking, “I need to do something with AI.” Having meaningful conversations about how to secure AI, and the things businesses need to think about, puts an MSP in a very strong position. **Robert Dutt:** Have a plan for the future, and execute on the important things today as well. **Tony Anscombe:** Absolutely. **Robert Dutt:** All right. Some great insights in there, as usual. Thank you once again for taking the time, Tony. **Tony Anscombe:** Always a pleasure. My pleasure, Rob. I look forward to the next one. **Robert Dutt:** There you have it, Tony Anscombe from ESET. I’d like to thank Tony for his time and for continuing to be one of the most thoughtful voices in the channel on what actually matters for partners on the ground when it comes to security. I’d also like to thank ESET Canada for its ongoing support of the site, and thank you for listening. A few things I’m taking away from this one. First, the confidence paradox is real, but it is not necessarily theater. Live incident response genuinely builds capability. The lesson for MSPs is to manufacture that experience through simulations and tabletop exercises, using real but anonymized incidents from their client base to show other customers what an actual breach feels like. Second, the insurance-MSP relationship is not going away. Tony is right that the fence has come down. The opportunity is not to fight insurers, but to become the cybersecurity expert that brokers and underwriters do not have, or to get your services pre-authorized by insurers so you can help lower premiums while retaining the client relationship. Third, the fundamentals still matter more than the headlines. AI-powered malware is the perceived top threat, but phishing, weak passwords and unpatched vulnerabilities remain the actual entry points. Tony’s prescription of monthly, five- to 15-minute micro-training modules tied to real seasonal phishing themes is something any MSP could put into practice within a week. Finally, the AI policy gap is a significant and immediate service opportunity. If more than half of businesses still do not have an AI usage policy, the MSP that walks in with a draft framework is not just selling security. It is selling sanity. If you got value from this episode, please follow or subscribe to the podcast wherever you listen, including Apple Podcasts, Spotify, YouTube and most major podcast directories. Ratings and reviews really do help us reach more people in the Canadian channel community. Until next time, I’m Robert Dutt for ChannelBuzz.ca, and I’ll see you in the channel.
!https://i0.wp.com/channelbuzz.ca/wp-content/uploads/2026/03/Tony-Anscombe.jpeg?resize=300%2C169&ssl=1 Tony Anscombe, chief [security](https://channelbuzz.ca/tag/security/ "Posts tagged with…
Tony AnscombeGuest
Robert DuttHost