Can businesses still rely on cybersecurity strategies that were designed for a very different threat environment?
In this episode of Tech Talks Daily, I speak with Matt Knell from ESET about why many managed service providers and businesses are being forced to rethink what effective cybersecurity looks like in 2026. As cybercriminals become faster, more sophisticated, and increasingly powered by AI, many of the approaches that once provided reassurance are struggling to keep pace.
Matt shares why the idea of "good enough" security is becoming increasingly difficult to defend. While endpoint protection remains an important part of any security strategy, he explains why technology alone is no longer enough. Organizations must continually review, update, and strengthen their defenses rather than assuming that yesterday's protections will be sufficient tomorrow.

Our conversation explores the lasting impact of ransomware and the lessons businesses continue to learn from high-profile incidents. From major retailers to global manufacturers, attacks are creating operational disruption, financial losses, and reputational damage on a scale that few organizations would have imagined a decade ago.
We also discuss one of the industry's most persistent challenges: the cybersecurity skills gap. Finding experienced security professionals remains difficult, while retaining talent has become equally challenging. Matt explains how managed detection and response services are helping MSPs extend their capabilities without having to build and maintain large security operations teams.
AI naturally plays a major role in the discussion. While cybersecurity vendors use AI to improve threat detection and response, attackers are also leveraging the technology to accelerate and sophisticate phishing campaigns, social engineering, and other forms of cybercrime. Matt explains why businesses must remain realistic about both opportunities and risks.
Another theme throughout the episode is the growing expectation that cybersecurity should be treated as a business issue rather than purely an IT concern. Regulations, cyber insurance requirements, supply chain scrutiny, and customer expectations are all increasing pressure on organizations to demonstrate stronger security practices and greater resilience.
We also discuss ESET PRIVATE and why more organizations are seeking security services tailored to their specific operational needs. Rather than relying on a standard package, many businesses are looking for solutions that align with their industry requirements, compliance obligations, risk profile, and long-term objectives.
Finally, Matt reflects on the conversations emerging from ESET's recent partner conference and shares his perspective on the topics shaping cybersecurity priorities for the coming year. AI, resilience, compliance, and business education continue to dominate discussions as organizations look for practical ways to strengthen their defenses.
If you're an MSP, IT leader, business owner, or anyone responsible for protecting digital operations, this episode offers a timely look at the challenges facing organizations today and the steps many are taking to prepare for what comes next.
Is your organization still relying on security strategies designed for yesterday's threats, or have you adapted to today's cyber risks?
Useful LInks
Connect with Matt Knell
Please check the partners of the Tech Tech Talks Network
Learn more about the NordLayer Browser

[00:00:00] - [Speaker 0]
As someone that records 65 plus interviews a month, I've personally seen a huge increase in browser based attacks over the past year, whether that be phishing, malicious extensions, account takeovers. The list is long, And it's all happening where people spend most of their time inside the browser. So NordLayer's new business browser, that's built to address exactly that. It blocks malicious sites before they load. It limits risky behaviors like uncontrolled downloads or data sharing and gives you visibility into how your team interacts with web apps.
[00:00:36] - [Speaker 0]
And it also helps you stay compliant by controlling access and enforcing policies without the need to rely on multiple disconnected tools. So for anyone listening that is thinking seriously about reducing risk in SaaS heavy environments, this feels like a smarter and more focused approach. And you can learn more about it by visiting nordlair.com/browser. Let me know what you think. But now, let me introduce you to today's guest.
[00:01:05] - [Speaker 0]
How prepared is your business for a cyber attack? An attack that doesn't happen during office hours and one that arrives through a trusted supplier and bypasses the tools that you thought were protecting it. Well, for many organizations, this question has become uncomfortably real over the past few years as ransomware attacks, AI driven phishing campaigns, and supply chain breaches all continue to disrupt businesses of every size. Well, my guest today believes the era of good enough security is officially over. His name's Matt Nell, and he's from a company called ESET.
[00:01:46] - [Speaker 0]
And together, we're gonna talk about why traditional endpoint protection alone is no longer giving businesses the level of resilience that they think it does. With more than twenty seven years in cybersecurity and not to mention responsibility for leading ESET's UK business, Matt is someone that has seen firsthand how the threat landscape has evolved from isolated malware incidents into highly coordinated attacks that are capable of shutting down entire factories, crippling retailers, and costing organizations billions. So today, we will talk about why MSPs are now carrying far greater responsibility for protecting customers, especially as The UK cybersecurity and resilience bill raises expectations around supply chain security and operational accountability. And I think there's also an important discussion that be had around mindset because, yeah, many businesses still treat cybersecurity as an IT issue instead of a business continuity issue despite growing pressures from insurers, regulators, customers demanding proof of cyber resilience, etcetera. So my guess will argue that proactive planning, layered security strategies, and visibility across networks and employee education, how all these things are becoming fundamental business requirements rather than just optional extras.
[00:03:13] - [Speaker 0]
So if you've ever wondered why so many organizations are still being caught out despite investing in cybersecurity tools, today's episode will offer a very honest look at where businesses are still falling short and where they need to change next. But enough for me. Let me introduce you to my guest right now. So thank you for joining me on the podcast today. For everyone listening, can you tell them a little about who you are and what you do?
[00:03:41] - [Speaker 1]
No problem at all. So I have the pleasure of running the ESET business in The UK, which I've been doing so for the last two and a half years. So fundamentally leading our sales, marketing, technical support teams, supporting our 60,000 plus business customers in The UK. So it's been a fantastic two and a half years. Previously or today, over twenty seven years working in cybersecurity and leading vendors in the field across channel, high touch end user sales, very much channel person, everything whether it's, you know, even through end user sales working with and through the channel.
[00:04:22] - [Speaker 0]
And you guys are described as a pioneer of antivirus and you've created award winning threat detection software, throughout there. And I've got to ask because you you've I read before you joined me on the podcast today that you said that good enough security is effectively dead for MSP. So what's changed? Was there a specific tipping point where those traditional approaches simply stop being sufficient against modern threats? Was it AI or or something else?
[00:04:51] - [Speaker 0]
What's changed here? What was that tipping point?
[00:04:53] - [Speaker 1]
AI is obviously getting plenty of of coverage. We had our ESET World Conference in Berlin last week. AI, as you can imagine, was a huge topic. And I think quite nicely balanced in terms of how AI is being used by, you know, cybersecurity vendors like us to help in the protection, but obviously also by the cyber criminals and how that is making those attacks more quicker in terms of what they can produce, what they can then do with that data once it's exfiltrated out, etcetera. But obviously also how inaccurate AI still is.
[00:05:28] - [Speaker 1]
But, you know, AI is a big buzzword. From my perspective, if you were talking about the change, the tipping point, whatever it may be, you can probably go back eight, ten years ago. I don't know if WannaCry Yeah. Rings any bells with yourself and and and 21 listening. And I think what WannaCry did and what Ransomware has done and still doing is the major impact it has on any organization that gets hit.
[00:05:57] - [Speaker 1]
Anyone that's been through that, it is quite a horrendous experience, a very stressful experience. It takes a lot of time to recover and is very costly. So you could be a small business of 50 users and that could run into tens of thousands of pounds to your business whether you've got cyber insurance or not, is another aspect of I suppose of tipping points in terms of compliance regulations and things like that making the change. But certainly the threat landscape continues to evolve, but I think you could go back a number of years and I think ransomware continues to be a very costly and disruptive attack to any business. Jaguar Land Rover, Marks and Spencer's, you know, I I say if you went into those organizations and said to Marks and Spencer's you couldn't take an online order for nearly three months, that have probably laughed you out and rightly so.
[00:06:47] - [Speaker 1]
But it did, it happened. Jaguar Land Rover couldn't build a car for five weeks, it's staggering. But we're working with small businesses every day that are getting hit, that are then spending days, weeks recovering and sometimes not recovering and that's the harsh reality and that's what doesn't get into the public domain is obviously how many businesses are being impacted and worst case scenario. So yeah. So going forward for MSPs, the new cybersecurity and resilience bill, which is coming, is gonna put a lot more onus onto MSPs, a lot more stringent controls.
[00:07:21] - [Speaker 1]
But obviously, from the government's perspective around supply chain attacks, critical infrastructure, that responsibility falling onto MSPs to make sure that they are doing everything that is expected of them because obviously it cost the economy so much money. Jaguar Land Rover was the example where there was a huge bailout put in place because it wasn't just obviously Jaguar Land Rover's company, but there are many thousands of businesses that support them. So yeah. So all the attacks, all the threats, all the AI, the resilience, the demand on cyber insurance, and ultimately the expectation from a customer to an MSP that if anything happens, they're the ones that are expected to be protecting them. So, yeah, I think the the world has evolved and changed a huge amount in the last ten years.
[00:08:09] - [Speaker 0]
It really has. And I think if you look at the economic impact of that Jaguar Land Rover attack, I think it was something like 1,900,000,000 in the end, is just phenomenal. And going back to, as you said, where it all began, I remember the WannaCry incident very well too. I think that was during my last few weeks of my IT job before going full time into this back in 2017. And I think for many years, many businesses have believed that endpoint protection alone was enough to stay reasonably safe.
[00:08:37] - [Speaker 0]
And why does that thinking no longer hold up in today's threat landscape? I mean, talking about those incidents should be enough. But for people that are still sat on the fence, why do they need to be taking this more seriously?
[00:08:48] - [Speaker 1]
I think if you do basic cybersecurity and have good cybersecurity hygiene, there's a lot still to be said for endpoint protection as as you defined it. I think the challenge often is that these solutions are deployed, let's say someone deployed it today, you know, in in in twelve months, twenty four months, etcetera. Are they gonna have made many changes to that? We still see that phishing attacks, you know, we talked about AI, but phishing attacks still very prevalent. People aren't patching, so vulnerabilities, the doors are being left open.
[00:09:25] - [Speaker 1]
So often it's a question of even if you've got security in play, are you doing the basics well? Are you patching? Are you ensuring it's up to date? Is it deployed in every machine inside your network? Which sounds simple, basic, but so often not the case.
[00:09:42] - [Speaker 1]
So I think what's not happening is people are not reviewing and looking at their security infrastructure along with the level of threat. You know, it used to be you couldn't trust what you were reading. Now it's you can't trust what you see. So all the stuff that's going on with the new sophistication is huge. Again, going back to ESET World last week, one of our security advisers presenting on how he could get a job using facial recognition to completely change in coming up with fake p passports, fake LinkedIn accounts, and doing live interviews as both as man and a woman and getting the jobs.
[00:10:20] - [Speaker 1]
So it it it's becoming very difficult for organizations to stay ahead of all of those threats but even doing the basics well. And if you think about the way that the attacks happen is that that however they get in, whether that is a front door being left open, they get in, they're doing, you know, reconnaissance work for weeks, for months in there, and often organizations don't even know there and then hitting at, you know, weak points, weekends, nighttime, seasonal holidays, etcetera, etcetera. So, you know, when you see the high profile attacks that do make it, atypically, it's happened at a weekend or it's happened at Christmas. It's happened when people are vulnerable. So you need the solutions.
[00:11:02] - [Speaker 1]
You need the expertise of the people to understand what the threat information that's coming to you is, and you need to be doing the basics well.
[00:11:11] - [Speaker 0]
And just to par even more pressure on businesses, I think one of the biggest challenges across the industry is the much or highly documented cyber security skills gap. So how can MSPs realistically protect their customers when experienced security talent is both expensive and difficult to find? And then they on on the flip side of that, they could, invest in existing talent and get them trained up. But as soon as they put qualification on their LinkedIn, there's a good chance they could be taken as well. So what's the answer here?
[00:11:41] - [Speaker 1]
Well, you're spot on. There is a massive gap in in terms of that. So even if you wanted to hire, probably very difficult too. And then as you say, to retain that that skill becomes very difficult. And that's why for vendors like ESET and for our managed detection and response service that obviously we now provide, it's a huge help to any MSP because they don't need to have that investment which is both costly in people but also in terms of the technology that needs to sit behind that.
[00:12:13] - [Speaker 1]
So it's not just the people but there's a huge outlay in the technology to be able to deliver a twenty four seven threat service. So managed text and response allows ESET MSPs to adopt that service to enhance and sit on top of what they're already delivering. So if they're delivering that sort of security one zero one service and that standard operational doing the basics well as we talked about And atypically, office hours, then you can lean on the vendors who have made that investment and get that twenty four seven overlay support using MDR. So that's the biggest and huge investment. And we've seen that from an ESET perspective.
[00:12:53] - [Speaker 1]
The UK MSP business has been the fastest growing and fastest adopting of MSPs taking on ESET MDR, which is fantastic. And NAC, the beauty of that is the return on investment is incredibly quick. If you were to build that yourself, both people and the technology, you're talking months, a year to get that set up very quickly by outsourcing to ESET and putting that in. You're you're up and running in weeks, if not days. Huge advantages for MSPs.
[00:13:24] - [Speaker 0]
And as we alluded to earlier, attackers are increasingly using automation and AI and highly targeted social engineering. They're all throwing thousands of AI agents into the mix. So from from your perspective here, what does a properly layered security strategy look like for a business this year and beyond?
[00:13:42] - [Speaker 1]
I think the bit of advice I always give is be proactive. You know, don't wait and then act because that's what atypically we see is that people make an improved investment in cybersecurity once they've been attacked. So you go through the cost and the pain of being attacked and then you improve your cyber resilience, which is again frustrating and and you've been through the pain. Yeah. Cyber criminals are are looking always to, as you say, attack using different resources and looking for those vulnerabilities and weaknesses.
[00:14:17] - [Speaker 1]
So first of all, to reiterate, do the basics well. Make sure your solution is deployed. Work with your partners. Work with your vendors to ensure that you are checking on that. So, you know, we work very closely with MSPs to make sure we're delivering health checks to them, to their customers.
[00:14:32] - [Speaker 1]
But actually what you've got, you know what's deployed, you know it's being configured correctly, and things are turned off or turned on according to what your environment needs. And then make sure that you're educating your business both in terms of, you know, your employees, the board, and understanding what the risks are. You know, and ask yourself the question, you know, if our digital world was cut off, what would that mean? And to most, it would be quite catastrophic. So then back to the proactive bit, look at the elements where you can make quick and easy wins in terms of bolstering your cyber defenses.
[00:15:08] - [Speaker 1]
So, you know, you need to have the basic protection in place. You need to then have the visibility of what's going on inside of your network. And that's where you then need things like managed text response and the experts to help make sense of what of that's coming in. If you've just got a team of IT generalists, then, you know, they're not cybersecurity specialists. So you need the people as well as the technology in order to make sense of what's going on and doing that twenty four seven.
[00:15:35] - [Speaker 1]
Because 70% of the attacks that happen are happening outside of the work working hours. So just doing it Monday to Friday is not gonna help at all. And yeah. And work proactively with your partners and with your vendors to really understand what you've got on the road maps that are available. So that's my probably answer to that.
[00:15:55] - [Speaker 1]
You could then get into technology and what you would need to do in terms of what solutions you, you know, you have in place on top of that. But make sure you are ready to react and know what your next steps are gonna be. So being resilient, a, ideally proactively, but also you've got a plan if the, you know, if the worst case was to happen. Who would you call? What would be the first phone call you make?
[00:16:17] - [Speaker 1]
Have you got an instant response plan? Has that been tested? Do you know what you would do if the worst case happened? So all of those things are the things that should be being put in place and you should be able to answer those questions. Have cyber insurance?
[00:16:32] - [Speaker 1]
You know, if you go back to Jacob Land Rover, my understanding is they didn't have cyber insurance. So if an organization of that size and that impact when something does happen, if you're a small mid sized organization, are you big enough to be able to survive the worst case scenario?
[00:16:50] - [Speaker 0]
So a special thank you to Denodo for supporting the Tech Talks Network and helping us keep these conversations going because moving beyond AI pilots all starts with connecting your models to trusted enterprise data. So if you're ready to move beyond AI pilots, Denodo can help you connect your AI models to trusted enterprise data in real time. So you can scale faster and reduce risk. So if you're interested in turning AI into business value, simply visit denodo.com. And I love busting myths on this podcast.
[00:17:28] - [Speaker 0]
I think one thing that's important to highlight is there isn't a one size fits all off the shelf product that will just make everybody's problems go away. And I'm hearing more and more organizations are asking for security that's more tailored to their operational environment rather than just this generic off the shelf protection that we've seen in the past. So how does ESET private how does that reflect this shift towards more customized cyber resilient strategies? Because this seems to be a trend that that seems to be increasing.
[00:17:56] - [Speaker 1]
Fundamentally, as you described, really, which is the ESET private is very much tailored towards organizations and typically larger organizations, you said that want a more tailored fit for their organizations which could be around threat intelligence, it could be particular environments that they need protecting that are outside the norm, greater regulations upon them, so they need that greater visibility, want that greater visibility. So ESET private is very much that which is not to sell off the shelf solutions as ESET have got, but being able to work with any organization to sit around the table and truly understand what it is they're trying to achieve in cybersecurity and whether that is bespoke solutions or services to enable to deliver that and typically working with those organizations over a longer term period as well. So typically, these are three, five plus year contracts that we're working on. But exactly as you described, know, the ability to deliver something that is not something you can just go and buy online or direct through a channel partner.
[00:19:09] - [Speaker 0]
And traditionally, have seen cybersecurity as an IT problem rather than a business continuity issue. There's been problems with the board seeing value in what if rather than what will happen. I'm curious. Is that changing? Are you seeing attitudes changing at leadership level, especially after the the rise in ransomware supply chain attacks and now an AI enabled threats?
[00:19:30] - [Speaker 0]
Are they starting to see the value now?
[00:19:33] - [Speaker 1]
Very much so. It is changing. Still a huge long way to go is probably the the best way I can describe it. If we go back three, five years ago when sort of the the managed detection response era was really starting atypically. You know, that first sort of twelve, eighteen months, it was very much reactive.
[00:19:54] - [Speaker 1]
So people were investing in that once, as I said, you know, you've been through the pain, you've been hit, then investment came. So we're starting to see a lot more proactive investments, people starting understand the value of that. Cyber insurance has kind of helped with that as well. Cyber insurance is been evolving hugely in the last number of years in terms of how the insurers have looked at it, realizing what they've paid out, huge sums of money. So the demands from them in terms of what they expect you to have in place is driving that as well.
[00:20:27] - [Speaker 1]
And one of the things I think from our perspective as well as a cybersecurity vendor is also helping organizations understand the ROI that comes with investing in it. Because I think often cybersecurity is that necessary evil, I need to have it, as opposed to allowing it to be a a proactive business enabler and help you win more business because I think that's the world changing as well. Back to Jaguar Land Rover and I I mentioned that a few times because it's the one that has had the most publicity. But the amount of businesses that were impacted in that is that you need to be resilient. You need to have have what is your cyber security posture.
[00:21:09] - [Speaker 1]
What are you doing? Do you have certifications? Do you have cyber insurance? So there's a whole heap of demand coming into the market. And again, we're trying to educate where cyber security, although it's a must have, you can put it as part of how you can improve your business, win new business, and obviously, you'll just stay in business as well.
[00:21:32] - [Speaker 0]
And I think the MSP market itself is also evolving rapidly with customers expecting more proactive monitoring, response and advisory services, etcetera. And as someone that's right in the heart of this space, I'm curious, how are you seeing this changing the relationship between MSPs, vendors like ESET, and and end customers? Are you seeing any big changes here?
[00:21:54] - [Speaker 1]
Definitely. I think how we work with and manage MSPs, I suppose, has fundamentally changed in this last couple of years. You know, as a vendor, we've got to manage MSPs very different to a VAR or or other types of partners. So how we manage and engage and help MSPs understand the threat landscape. So we work very hard in the education in terms of what the threats landscape looks like, working hard in the commercial offerings that we put together for them and then their customers.
[00:22:24] - [Speaker 1]
We're working a lot closer with MSPs through to their customers as well. So often it's been as an MSP, a vendor treats them as like the customer and the MSP and their customers are at arm length. So we're certainly seeing a lot more MSPs wanting to work with us and with their customers to help provide that education direct to the customer, to help the customer understand why they need to be bolstering their cybersecurity. Because often what we do here is obviously the challenge continues to be the financial one, putting more money and more funding into cybersecurity protection. So working very closely with the MSPs and their customers has become a key factor for us in the last twelve months and very successful.
[00:23:06] - [Speaker 1]
There's a lot of consolidation in the MSP market, so we're seeing a lot of consolidation. So that proactive, that education, that management, dedicated account managers aligned to our strategic MSP has become crucial to our success and continued growth in terms of the MSPs that we sign up, but also the solution stack and the services stack that they're selling to their customers.
[00:23:30] - [Speaker 0]
And earlier in our conversation, you mentioned the conference in Berlin this week. What themes or conversations were dominating the show floor this year? And what did those conversations might maybe tell us about where cybersecurity priorities are heading next? What were the big takeaways there?
[00:23:47] - [Speaker 1]
As I said, AI was a huge one in terms of the threat landscape in there. I think some of the other elements that we were looking at is how each nation is approaching that regulations, so NIST two, etcetera, across EU. But how then we're working closely together to help fight against the cyber threats, which is very interesting and great to see. Also, how then businesses and specifically SMBs themselves are looking at cybersecurity and the threat and their understanding of the threat, the investment, where they potentially feel that they sit themselves in their awareness of that and what they're doing about it. And that was quite enlightening in terms of probably perception and reality.
[00:24:36] - [Speaker 1]
So yeah. So I think customer perception. But yeah. I think AI was the biggest topic. And then two, very much learning from customers.
[00:24:44] - [Speaker 1]
We had a lot of customers in the audience as well and what their learnings are and their concerns and certainly looking at what they're looking ahead to the future in terms of what's worrying them. And like I say, a lot of that is around compliance and a lot of that is around AI and a lot of that is around educating their business on the need to do more.
[00:25:04] - [Speaker 0]
And for everybody listening that wants to find out more information about what was talked about at that ESET partner conference or stay up to date with information coming out of ESET or connect with you or your team, anywhere in particular you'd like me to point everyone listening?
[00:25:18] - [Speaker 1]
Oh, yes, please. That's very kind. So eset.com/uk,uk page, where we've obviously got a lot of our case studies, customers, and partner case studies, and information very much tailored towards The UK market. A lot of stuff around certain verticals as well, education, retail, finance, etcetera. And, obviously, follow myself on LinkedIn and ESET UK.
[00:25:41] - [Speaker 1]
So, yeah, those hopefully will be ideal places to go to get more information on what we're doing and how we can support.
[00:25:48] - [Speaker 0]
Well, we covered a lot there in thirty minutes. Especially, I mean, why good enough security is officially dead for MSPs? Big message there. Why basic endpoint protection no longer cuts it for businesses, but how MSPs can close that cybersecurity gap, cybersecurity skills gap. So I'll include links to everything that you mentioned there.
[00:26:07] - [Speaker 0]
I encourage everyone listening to go over to techtalksnetwork.com. There'll be a blog post associated with this episode and links to everything. So check that out, and please share your stories with me. But more than anything, Matt, thank you for bringing this story to life today.
[00:26:21] - [Speaker 1]
My pleasure. Thank you. One of the many things I
[00:26:23] - [Speaker 0]
loved about the conversation today is how cybersecurity has quietly shifted from being a technology problem into a business survival issue. Because those attacks making headlines may involve global brands like Jaguar Land Rover or Marks and Spencer's, but behind these stories are thousands of smaller businesses facing the exact same threats with far fewer resources at their disposal. And I think Matt made an important point that many organizations still wait until after an attack before investing seriously in their cyber resilience. And, of course, by then, the financial damage, the operational disruption, and reputational fallout, all these things have already happened. So that reactive approach really feels unsustainable in a world where AI is making attacks faster, more convincing, and more automated than ever before.
[00:27:19] - [Speaker 0]
But the role of modern MSP but the role of the modern MSP, that's changing rapidly too from IT support provider to strategic security partner. And with all these things come enormous pressure around expertise, visibility, and accountability. So if today's episode gave you a few things to think about, I'll add links to Matt, Esset, and the resources we discussed. They'll all be waiting for you on the blog post associated with this episode at techtalksnetwork.com. And, please, I'd love to hear your perspective.
[00:27:55] - [Speaker 0]
Has cybersecurity become a boardroom priority in your organization yet, Or are too many businesses still underestimating the risks until it's too late? Well, when you're at Tech Talks Network, you'll also find a button to record me a voice message. I'd love to hear from you, but I'm afraid I've taken up far too much of your time today. Time for me to go now. I'll return again tomorrow with another guest.
[00:28:18] - [Speaker 0]
Bye for now.

