“Every business owner who hires an MSP should ask one question: what are you doing to protect me from your own tools?”
Who They Brought In
Anthony Gerasch and Ryan Carter run Unique Computing Solutions out of the Chicagoland area, an MSP Anthony founded in January 1997 that is approaching its 30th year in business. Anthony started as a programmer and moved into managed services around 2003. Ryan has been with the company for close to a decade. Together they built a security-first operation before leading with security was the standard, and they have the CMMC journey and the decade-long SOCSoter partnership to back it up. They also co-host the Business Owners IT Podcast, which gives them a second channel for educating the clients their direct work reaches. Between them they cover the full stack: Anthony on operations, tooling, and the business of running a clean MSP, and Ryan on compliance, frameworks, and the gap between what companies think their security looks like and what it actually is.
What Got Loud
- The one question every business owner should ask their MSP and almost never does: what are you doing to protect me from your own tools
- Anthony’s Active Directory walk-through: the moment a client says we are fine, he opens the directory and starts asking who each user is, and the answers are always bad
- A one-man electrician shop let a stranger into his Microsoft 365 in exchange for a free website build. What happened next is the clearest possible argument for not skipping the basics
- AI governance does not exist yet and companies are using 14 different AI agents in a single meeting with zero policy around any of them
- Why AI for compliance is an 80% solution at best, and the 20% it cannot do is the part that gets you in court
The Rundown
Anthony’s security-first position is not a tagline. It is a condition of being a client. If a business does not have the basic security stack in place, Unique Computing Solutions does not bring them on. He is direct about why: an MSP that is not secure does not just put itself at risk, it puts every client it touches at risk. His analogy is as clean as it gets. A bad doctor can kill someone. A bad MSP can do serious damage at scale and most business owners have no idea. The question he wants every business owner to be asking before they sign with an MSP is not what can you do for me. It is what are you doing to make sure your access to my systems cannot be turned against me.
The identity conversation is where the episode gets granular. Ryan walks through what it actually looks like when a company says they are good and he opens Active Directory. Former employees still active. Accounts renamed instead of disabled. Five domain admins including Jennifer, who left. No one knows why she had domain admin rights in the first place. The companies that are most confident tend to have the most exposure, and the small ones are not exempt. Five users can have just as much wrong as five hundred. The reason is always the same: nobody is watching and nobody knows what right looks like. Anthony’s fix is a baseline. If you do not know what your environment is supposed to look like, you will never catch a deviation. And a deviation is exactly how a breach starts.
The electrician story is the episode in a single anecdote. A one-man shop was offered a free website in exchange for access to his Microsoft 365. He said yes. The attacker used his account to register impersonation domains using his credit card, assigned Exchange licenses to themselves, and started sending phishing emails impersonating major companies. The victim had no idea until he was locked out of his own account. Anthony’s team recovered his access through an old account that had never been cleaned up. The point is not just that it happened. It is that it happens because Microsoft 365 is handed to people who do not know what securing it actually requires. Out of the box the security score starts at around 40 percent and the target is 70. Most small businesses buy it for email and stop there.
The AI governance discussion is where Anthony and Ryan agree most sharply. Every meeting Anthony joins has AI agents attending from every participant’s company, all different brands, all different configurations, with no organizational policy governing any of it. Ryan’s position on AI for compliance is consistent with what Melissa sees from the SOCSoter side: it is an 80 percent solution and the 20 percent it cannot handle is the nuanced, business-specific piece that compliance actually requires. An AI tool will search your email and return answers it thinks are correct. If you do not know what the correct answer actually is, you will submit a compliance document with errors and not know it until something goes wrong.
Real Talk
If you have not walked through your own Active Directory recently and asked who every user is and whether their access level makes sense, do that before your next client meeting. The most confident organizations are almost always the most exposed.
Catch It
Listen to the full episode on Apple Podcasts, Spotify, or wherever you get your podcasts. If this conversation made you think twice about your own security posture, let’s talk. Visit socsoter.com

