• Forging Trust
  • Posts
  • GRC Capabilities MSPs Need + Must-Have Policy Management Features

GRC Capabilities MSPs Need + Must-Have Policy Management Features

IT channel and business news with a focus on regulatory compliance.

In partnership with

đź’» 9 Policy Management Features That Matter Most to MSPs

Regulated organizations generate more policies than ever, and most of those policies live in shared folders, inboxes, or outdated wikis where no one can track what's current, who approved it, or whether anyone read it. For MSPs delivering compliance management software services to clients in healthcare, finance, and government, helping those clients get policy management right creates both immediate operational value and long-term client retention…

The GTM Playbook HubSpot Had to Acquire

Warmly ran pipeline, outreach, and lead scoring on autopilot for hundreds of startups — before a single sales hire.

HubSpot acquired them for it. Now the cofounders are walking you through the exact system, live, before they disappear into product. Join the Builder Session on August 12.

Leave with an agentic GTM stack you can replicate this week. Plus HubSpot Credits when you join HubSpot for Startups.

🎙️ Podcast: Cyber Safe Harbor, Bad Tech Laws, and the MSP Voice

Starting an MSP takes less red tape than opening a hair salon. That gets awkward when lawmakers write cybersecurity rules without enough input from people who actually run IT services. This time, our guest explains how MSPs can help shape smarter state policy before a well-intended bill becomes a technical mess.…

🔥 8 GRC Capabilities MSPs Need in 2026

Regulatory pressure on your clients keeps climbing. So does the demand for you to prove their security posture to auditors, insurers, and upstream vendors. Blacksmith InfoSec helps MSPs turn that pressure into a structured, scalable compliance-as-a-service offering. But whether you use Blacksmith or another platform, certain GRC capabilities separate tools that help you scale from tools that become bottlenecks…

⚠️ Threat Updates

đź”´ INC Ransomware Chains SonicWall SMA 1000 Zero-Days for Root Access (8/5/26)

SonicWall has disclosed two actively exploited vulnerabilities in its SMA 1000 secure access appliances — CVE-2026-15409, a critical (CVSS 10.0) unauthenticated SSRF, chained with CVE-2026-15410, a high-severity (CVSS 7.2) code injection flaw — that together deliver unauthenticated remote code execution as root. Attackers exploited these as zero-days since at least June 22, 2026, weeks before the July 14 patch, and CISA has added both CVEs to its Known Exploited Vulnerabilities catalog. INC Ransomware — the 4th most active group Blacksmith has tracked in 2026, with 252 attacks across sectors globally — has emerged as the most prominent operator of this exploit chain, using it to harvest credentials, move laterally, and detonate ransomware inside victim networks. For MSPs and ITSPs, this is a supply-chain nightmare: SMA 1000 appliances are trusted, provider-managed gateways into numerous downstream client environments, and root access on a single appliance lets attackers intercept traffic, dump credentials for every connected user, disable security controls, and pivot into the MSP's own management infrastructure — putting the entire client book at simultaneous risk of exfiltration and encryption. » More Info

đź”´ TA488 Weaponizes Outlook Web Access Half-Click XSS to Drop OWAReaper Implant (8/5/26)

Proofpoint has disclosed a July 2026 campaign in which Russia-aligned threat actor TA488 (Void Blizzard / Laundry Bear) is exploiting CVE-2026-42897, a cross-site scripting flaw in Outlook Web Access, as a "half-click" exploit — simply opening the email in OWA is enough to detonate arbitrary JavaScript and deploy a novel browser-based implant called OWAReaper. The lures are deliberately banal (supply-chain notes, tourism metrics, gas-market updates) with no links or attachments, designed to be skimmed and dismissed rather than reported, and the campaign has hit government, telecom, financial, hospitality, and aerospace targets across the US and Europe. Infrastructure dates back to March 2026 — two months before Microsoft's out-of-band patch — suggesting TA488 burned this as a zero-day. OWAReaper is the dangerous part: it runs entirely inside the OWA browser context with no host footprint, steals autofill credentials and OAuth tokens from any add-in with ReadWriteMailbox permissions, and establishes server-side persistence by granting the low-privilege "Default" Exchange user Owner-level access to every mail folder — meaning credential rotation and full device reimaging will not evict the actor. » More Info

🗨️ Parting Words

“It is better to be hated for what you are than to be loved for what you are not.” — André Gide

Find the Blacksmith Team…

…on demand with 
Get NIST-y on Spotify!

Are you a vCISO or MSP looking to operationalize security programs? Let’s discuss how Blacksmith Infosec proves that compliance is an opportunity, not a struggle that has to be packaged in FUD!