惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

H
Hackread – Cybersecurity News, Data Breaches, AI and More
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
V
V2EX
T
The Blog of Author Tim Ferriss
腾讯CDC
Hugging Face - Blog
Hugging Face - Blog
雷峰网
雷峰网
爱范儿
爱范儿
GbyAI
GbyAI
H
Help Net Security
I
InfoQ
罗磊的独立博客
酷 壳 – CoolShell
酷 壳 – CoolShell
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
人人都是产品经理
人人都是产品经理
J
Java Code Geeks
Microsoft Security Blog
Microsoft Security Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
N
Netflix TechBlog - Medium
Last Week in AI
Last Week in AI
宝玉的分享
宝玉的分享
云风的 BLOG
云风的 BLOG
Project Zero
Project Zero
P
Privacy & Cybersecurity Law Blog
A
Arctic Wolf
Know Your Adversary
Know Your Adversary
G
Google Developers Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
T
Tor Project blog
V
Vulnerabilities – Threatpost
Y
Y Combinator Blog
WordPress大学
WordPress大学
V
Visual Studio Blog
博客园_首页
G
GRAHAM CLULEY
K
Kaspersky official blog
T
Tailwind CSS Blog
T
Threat Research - Cisco Blogs
博客园 - Franky
D
Docker
Security Latest
Security Latest
I
Intezer
有赞技术团队
有赞技术团队
Application and Cybersecurity Blog
Application and Cybersecurity Blog
博客园 - 【当耐特】
B
Blog RSS Feed
T
The Exploit Database - CXSecurity.com
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻

Todyl Blog

CyberChef: How to Decode & Decrypt Malicious Scripts (Step-by-Step Guide) Achieving Zero Trust with SASE: A Practical Roadmap for Modern Network Securityso like MSP Security Maturity Assessment: Why 79% of MSPs Are Stuck in 2025 The Rising Threat of Malicious AI: What Every Organization Needs to Know Iran Cyber Threat 2026: What SMBs and MSPs Need to Know The OneStart AI Browser Deception Cyber Insurance Requirements Based on Industry Why Third-Party Security Certification Is Your MSP's Competitive Edge Why Cyber Insurance Carriers Are Shifting to Security Assurance Iran Conflict and Cyber Risk: What North American Organizations Need to Know ‍ Why Cyber Resilience Requires Security, Compliance, and Insurance MSP Security Services: How to Position Identity Protection as Competitive Advantage Identity Security Gap Assessment: A Step-by-Step Guide for MSPs How Credential Theft Attacks Are Costing MSP Clients Millions Do I Need Cyber Insurance as a Small Business? Advanced Persistent Threats (APTs) Explained Preparing for CMMC Level 1: What Your Organization Needs to Do The Real Cost of Doing Nothing in Cybersecurity MSP Security: Build vs Buy SOC The Rise of a Cybercrime Alliance: What LockBit, Qilin, and DragonForce Mean for Business Risk Cyber Threat Recovery Strategies for MSPs What MSPs Need to Know about CIRCIA Final Rule ClickFix: The Evolution of Copy-Paste Social Engineering Akira Ransomware: Threat Assessment of a Scalable RaaS Operation The Dos and Don’ts of Applying for a Cyber Insurance Policy What Is Threat Hunting? A Practical Guide for MSPs and SMBs The Business Case for Cyber Threat Management Evaluating Free and Open Source SIEM Tools in 2026 How organizations can combat BEC Using SASE to help meet cyber insurance requirements Introducing the Anomaly Framework Stopping Identity Threats with ITDR through MXDR Security Operations Over Tools Beyond Tools: A Strategic Approach to Data Security Cyber Threat Response Strategies for MSPs Threat Advisory: Email Account Compromise BECs In the Wild: When Millions of People Are Expecting the Same Email Michigan and Wisconsin Proposed Age Verification Bills and the Impact on VPNs and SASE: What You Need to Know Cyber Threat Detection Strategies for MSPs Cyber Threat Prevention Strategies for MSPs Simplifying CMMC Level 1 with Todyl GRC How to Complete Your CMMC Level 1 Self-Assessment: A Step-by-Step Walkthrough Cyber Threats Don't Take Time Off How MSPs Build Lasting Client Relationships Through Proactive Operations Risk Management for MSPs: Why Business Context Changes Everything 5 Pillars for Security Program Growth in 2025 One Action MSPs can take to Address Risk and Secure Clients Building Resilience in a Perimeter-less World with Defense-in-Depth Aligning Technology Implementation to Business Outcomes Top 5 Myths about Cybersecurity How Conditional Access Transforms Your Cybersecurity Program Why MSPs need to embrace a prescriptive model How Texas SB 2610 Positions MSPs as Strategic Risk Advisors Simplifying cybersecurity maturity with managed cloud SIEM Addressing firewall vulnerabilities Understanding the Pitfalls of RDP MSP Zero-Day Response Plan: When Security Tools Can't Help You Old is Gold: Tackling Persistent Vulnerabilities How MXDR drives operational efficiencies Using SASE for secure remote access How to find the best endpoint security solution The Cyber Insurance Crisis: Why MSPs and Their Clients Are Struggling What to ask of a prospective endpoint security vendor Thinking Red, Acting Blue: Turning Attack Tactics in Your Favor Zero-Day Attacks and False Alarms: Lessons for MSPs Dissecting the Recent Rise in 2025 Zero Days MSP Security Monitoring Strategy: Identity and Cloud Blind Spots Introducing the Todyl Community: A Collaborative Platform for MSPs Threat Advisory: PDFast Freeware Compromise Navigating Today’s Cybersecurity Threat Landscape: Where MSPs Should Start Threat Advisory: Understanding the Recent SonicWall SSL VPN Vulnerability and How to Protect Your Clients Threat Advisory: SQL Injection in FortiClient CVE-2023-48788 The Importance of SSL Inspection Navigating Compliance Frameworks: Common Challenges and Effective Solutions Making the most of SASE Web Filtering Iran & Middle-East Geopolitical Shifts: Emerging Cyber Risks for SMBs MSP Security KPIs That Matter: Beyond Vanity Metrics to Business Outcomes MSP Challenges Looking into 2025 Combining EDR and NGAV for Defense-in-Depth Starting Your Security Framework Journey: A Practical Implementation Guide Cyber Insurance vs. Warranties: Key Risk Management Elements Akira Ransomware: A Persistent Threat to MSP Operations Transforming Cyber Insurance for MSPs and Their Clients Two Truths, Double Whammy: Why Vulnerability Remediation Needs a Rethink Using LAN ZeroTrust for segmentation The role of SIEM in incident response Partner Spotlight: 917 Solutions Threat Advisory: Business Email Compromise Campaign using OVPN for Obfuscation Beyond Implementation: Creating an Ongoing Security Framework Program ClickFix: Fake Captcha Leads to Real Damage Streamlining Security and Compliance Information Gathering with Assessments EpiBrowser: A Sophisticated PUP Masquerading as Chromium Partner Spotlight: AnchorSix Tips to Help MSPs Set Goals for the New Year How SIEM helps detect insider threats Massive Wave of Network Security Vulnerabilities Demands Immediate Action FortiJump: The FortiManager Zero-Day Vulnerability Explained Use cases of SASE: Software-defined perimeter Threat Advisory: LightPerlGirl Malware Why MSPs Must Prioritize CIS Critical Security Controls v8.1 for Client Success
Partner Spotlight: GoTech IT Solutions
Ken Patterson · 2026-01-09 · via Todyl Blog

I sat with President of GoTech IT, Chris Gotstein, to dig into the challenges facing his growing business and hear his thoughts on the MSP cybersecurity landscape. With increasing compliance requirements and a lack of small business security awareness, Chris knows that providing effective, affordable services helps everyone succeed. These are his key takeaways.

Tell us about your business, where you operate, and who you serve.

Chris Gotstein: I started GoTech IT Solutions back in 2013. I had a small office in the Upper Peninsula (UP) of Michigan and then about six years later, I opened another office down in Milwaukee, Wisconsin where I'm currently located.

We provide managed IT services to small businesses in the Milwaukee area and in the central UP with an emphasis on the manufacturing sector, accounting firms, and financial advisors. We're also starting to work with construction companies, plumbers, and electricians. We've found a good niche with these service-type businesses and manufacturing because they rely on having working systems all the time and need them to be secure and compliant.

With new FTC regulations coming out, both our accounting and financial advisor clients are seeing more compliance scrutiny. We're able to provide the correct solutions to meet and exceed the compliance requirements that they have.

With all those requirements, what are you doing to ensure they stay protected?

CG: A lot of research to see what we need in place to make sure clients are compliant because it's changing all the time. We have multiple systems, taking an “onion” approach to cybersecurity with multiple layers.

We're leveraging Todyl to help with a lot of that compliance. As we get further along in the evolution of compliance, we need more controls. We need systems that both protect our clients but also record and report on each control to prove we're doing everything correctly. We have policies to back up all the compliance requirements, and we use the Todyl GRC module to simplify it.

How is Todyl helping you face the challenges you experienced before using the platform?

CG: Mostly a place to start. With compliance, we’ve wondered, “Okay, where do we even begin? What policies and tools do we need to have in place?”

Todyl GRC helps lay it all out for us. We check boxes according to the clients’ compliance regulations and it gives a list of what we need to do. Then, we can drill down into each control to plan how we'll meet the clients’ needs. It’s made our lives a lot easier because now we're just focusing on implementation and getting our clients compliant, not worrying about each individual rule. It's already built for us and Todyl maintains it and keeps it up to date.

Can you share a real-world example of a security challenge that kept you up at night?

CG: Jeez… There's a lot of challenges. The biggest is probably convincing small business owners that they need security. When we talk to prospective clients, we try to keep things as down to earth as possible, but they still don't understand that they are a target.

Customers often say, “I'm too small, nobody wants my data or cares about my business.” That's not true. There's value to what you're doing. If there wasn't, you wouldn't be in business. Don't tell me that your data, product, or service isn't valuable enough that somebody doesn’t want to steal from you.

We as an industry and the media in general don’t do a good job of reporting small incidents. The FBI doesn't even look at anything under $250,000. Even a $10,000 incident can wipe out a small business, but nobody seems to care, say anything, or help.

It’s challenging to convince a business owner that these things can, and most likely will, happen to them without protections in place. Sometimes, I look at their infrastructure without security or even MFA and wonder, “How have you not gotten hacked? How much will you lose when an incident happens?”

That keeps me up at night. People aren't aware of the vulnerabilities in their own business.

From your perspective, what made Todyl stand out compared to other security solutions?

CG: First is the all-inclusive agent. It lowers the footprint on workstations so we’re as efficient as possible. I don't want eight agents, all doing something different and sucking resources for our clients. The single, modular agent means we can add things where we need them.

Todyl GRC… honestly, it's the most comprehensive and simplistic compliance module I've seen. It's not overly complicated. I don't have to spend weeks getting things set up. I can simply activate the module and start going through each control. I'm getting to work right away instead of spending hours learning the process and how the system works. We just implement it, and we're good to go.

The price point also works out well for us and for our clients, and the fact that Todyl continues to develop the product is huge.

Tell us about a time, if there was one, that Todyl help you stop a security threat or prevent a major issue for a client.

CG: Thankfully, we haven’t had a major one yet. We've been using Todyl SASE for about 2 years now, and it’s stopped malicious websites and links dead in their tracks. Giving our clients additional protection wherever they go is a game changer for us.

Since implementing Todyl, how has your security offering evolved and how has that impacted your business growth?

CG: We, as an industry, talk about packaging and pricing nonstop. In the last couple of years, I've had the mindset of serving just one best-in-class package to our clients.

Talking to clients and prospects, however, it became clear we needed more flexibility with our services. With Todyl, I can activate modules where I need them without rolling out a whole new client or agent.

I sell tiered packages now. My base package includes Todyl EDR and SASE, or maybe just Todyl EDR, and that's it. My middle pack is SASE, EDR, and a couple of other modules, and then I can also layer compliance on top at any point along the way.

The fact that I can activate things and package them separately to work best for the client and help them grow into compliance is huge. Normally, we would be charging upwards of $1000 a month for compliance. With Todyl, I can package it for $100 a month. It gets our clients the compliance and protection that they need at a price they can afford.

How have the clients have been responding? What are they saying about the level of protection that you guys are providing?

CG: It’s been a lot of “no news is good news.” I don't know if I've ever had a client say, “The level of protection you've given us is second to none.” Most clients see the value we bring because we communicate what we're doing with them.

We can show them our protections and the value of them with reports. Once we start deploying more compliance controls, there may be stuff they may not fully understand, but it's a robust report, a robust program they realize is worth paying for. They know they’ll be compliant and get the protection they need.

Our reports are eye-opening to the end user. They may not say they appreciate it directly, but there's definitely some wide eyes when they're looking at them.

For other MSPs out there that are struggling getting into cybersecurity, what advice would you give them?

CG: Pick a tool that not only works well for your clients, but for your own pricing and your business. Everyone says that techs love tools. I was guilty of it myself. We had 10 different tools to do 10 different things, and sometimes we had 10 different tools to do 5 different things, and they overlapped.

Todyl’s flexibility and modularity help meet and exceed the needs of our clients. Plus, Todyl invests so much back into developing new tools and features. Those are the things I look for. I've gone through a ton of vendors who either add things that aren’t useful to an MSP whatsoever or get bought up by larger companies and we never hear from them again.

Todyl has a really good product. It fits our pricing and our package models. It allows me to give value to our clients that is affordable to them, but it's also all in one package, one pane of glass. When it comes to cybersecurity solutions, the more things that are integrated and talking to each other, the easier it is to track down problems. With Todyl, I can see everything.

Building on that, for those people who are on the fence about Todyl, what would you say to them?

CG: For us, it was one of the easier products to get into. We got a ton of support getting on board and understanding the product. Todyl Support has been great. When we put a ticket in, we get a response pretty darn quick.

Ultimately, the product just works. Sure, we've had some headaches with it; all software has problems. But I will say, for the problems that we’ve had, Todyl identified them, worked with us, and got it fixed within a couple of weeks. That's unheard of with larger vendors; things just don't get fixed in a timely fashion. Todyl cares about us and continues supporting us, not only by providing a good solution, but by fixing the problems that come up along the way. It speaks volumes compared to other vendors.

And the price is right. We have the modular support to activate whatever we want so I can minimize the amount of time my guys are spending in a tool. It just works, which is what I want. And, when there is a problem, we have a quick resolution to get it taken care of.