Sebastian Abbinanti: The AI Security Mistake SMBs Keep Making
About this episode
Sebastian Abbinanti is President of The Isidore Group, a Chicago-based MSP he founded in 2014, and his core claim is that the belief we are too small to be a target is what gets small businesses breached. He argues that a smaller company faces more risk, not less, because it lacks the resources to defend or recover from an attack. The AI danger he sees most is a company giving Copilot or Claude access to its entire SharePoint before the data is classified, so the tool can surface the CEO salary to any junior employee who asks.
His team runs AI inside a private Azure OpenAI container that stores nothing, keeps only metadata in its logs, and sets gates so level one technicians cannot pull risky suggestions. Every recommendation still needs human approval. He also treats cutting corners on security as a form of malpractice.
In this conversation
- Why "we're too small to be a target" leaves SMBs wide open to ransomware and breaches
- Why an MSP should act like your IT department, CIO, and CSO, not just another vendor
- The AI risk he sees most: giving Copilot or Claude access to all of SharePoint before the data is classified
- How his team runs AI safely in a private container that stores nothing, with a human approving every recommendation
- Why he treats cutting corners on security as malpractice
- Why culture, and only working with people he likes, is his most valuable asset
Full transcript
Welcome back to another episode of the Agentee Digital Podcast. Today we're joined by a special guest, the president at the Isidore Group, Sebastian Abbinanti. Sebastian, it's great to have you here today.
Thank you for having me on. I really appreciate the opportunity to meet you and and have this podcast together.
Great, so for people hearing about you for the first time, who is Sebastian?
Well, I am the president of the Isidore Group. we founded the Isidore Group in 2014, and our our whole purpose behind what we do here at the Isidore Group is to help our clients be better at what they do best. that kind of translates into a lot of the experience that I've had in my life. personally, I've I've been in IT now for over 30 years and
Mm.
I I really cut my teeth in the industry in K through twelve education, and then had a very strong focus towards networking and network security, ultimately bringing me to the foundation of the Isidore Group, which is a MSP that's vertically agnostic, but we really focus heavily on security and cybersecurity and compliance for a lot of our clients. So we've got clients in various different industries, but a lot of them
have compliance and and regulatory bodies that govern how they maintain and process data. So that's an area that I I I was uniquely qualified and we kind of build a company around that.
Mm-hmm. Interesting. And so what happened in 2014? What what you know what was the kind of inflection point or moment where you s you know said that you will start your own thing?
Yeah, so I I was working for a company and the company just wasn't really doing well. And it was it was one of those things where I had an honest conversation with one of my clients and he kind of urged me to to go off and begin my own venture. I was getting ready to make a move to another organization and at this point I had spent a lot of my career in networking, but I had just kind of really moved into more of the organizational management and really understanding how
Mm.
To better migrate IT service providers into more of managed services providers. So that's something I had done for the company that I was with there. And they were having some ownership struggles. So ultimately, it was it was time for me to jump ship. And after I did that, I was able to really build something that I could be proud of. I I know right off the bat, my number one goal was obviously to to really
focus on helping our clients, but but also an internal focus. I wanted to build a company that I wanted to work for. Not just one that I wanted to own, not just one that I wanted to run, but one that I would want to work for. And I wanted to make sure that that became a part of our culture. So for us, internally speaking, when it comes to our staff, our culture is our most valuable asset and it's something that we prize. We we make it a point to only hire people that add to our culture
Hm.
Even being culture neutral is not enough.
Hmm. Yeah, that's that's a great rule to stick by to, you know, create a environment where only where you would like to work. That's a great rule. And y like regarding you know the CMMC compliance and data breach insurance, those are kind of the things that I see you posted
about kind of the main thing that SMBs are getting wrong. So what is one thing that you see boutique operators in your space still underestimate about security and compliance that actually costs them later?
Absolutely. You know, it's it's kind of surprising to me that after all these years the ransomware tax have have have really been at the forefront of most small businesses minds since about 2012 And we're still having conversations with with small business owners and and even some medium sized business executives.
That think that the size of their organization really has an impact on whether or not they're going to be targeted. The the reality is that the net is just so wide that most people don't realize that you do not have to be a $300 million company in order to be an attack for a to be an attractive target for a threat actor. And when you when you misgauge that, what ends up happening is you put yourself in a vulnerable position that
without realizing that your size actually increases your vulnerability, right? The fact that you do not have the resources to throw at defending an active attack or at remediating the effects of that attack after the fact. So, you know, this is a situation where, you know, an ounce of prevention is worth a pound of cure to use the tired old cliche. But it it's it's actually true. And what I find is that oftentimes
Hm.
Managed services providers are trying to cater to the client's wants and not necessarily drawing a hard line in the sand to make sure that the client need is clear. For us, one of the principal rules of client acquisition is that we only work with people I like. And ultimately what that means to me is that I can't be more invested in your company than you are.
So when we look at clients that come to us and say, well, we're a trucking company, so if it doesn't involve trucking, we don't want to spend money. Well that's fine, but if your trucks have nowhere to go because your dispatch software is not functioning or the server infrastructure is down or you know, something worse, you've had a data breach and now your clients don't want to use you because you have a reputational issue. These are kinds of issues that IT service providers can't always solve at the back end.
I can't fix your reputation. I can't fix the financial fallout. I can fix the actual device that may have gone down and I can certainly stop the attack after it started, but that doesn't necessarily mean that I can recover your business to the point in which it was before. What I can do is help prevent those kinds of things from happening ahead of time. And I think when managed services providers focus again on just getting that client and really understanding that.
they're you know they're lean and they don't want to spend money in these areas and and it's not a real issue for them. It is and I and I equate that to malpractice on a lot of MSPs and MSSPs when they sit there and say, well, you know, you really do not need to be monitoring your Microsoft environment or yeah, even though we do log in, we don't necessarily need to use a multi-factor authentication simply because it's just too cumbersome for the CEO. Well, that's not really a good excuse. And ultimately
Mm.
The way I look at it and what I tell my people all the time is that we're responsible for countless thousands of lives downstream from us. Right? There's so much that's put on us to maintain and to secure. And the same is true for all of our clients. You are responsible as a business owner for all of the data you process for every employee that works for you, and all the data that you process for every client you have, and everyone that works for those clients too.
Mm.
So when you look at it from that perspective, you really understand that security is everyone's problem and it's something that we all need to be mindful of and pay attention.
Hmm. Yeah. Yeah. And like you know most most IT firms I feel like they they pitch speed and uptime. what do you think these SMBs need from a technology partner?
I think they need honesty. I I think they need a technology partner who's going to tell them exactly how it is. These are the risks. Without any of the hyperbolic, scary, you know, the ransomware attackers hiding in the closet piece, right? I'm kind of done with the you know, advertisements with the dark room and the guy in the hoodie. I know we have some of those too out there. I'm sure you can find them, but
You know, we're kind of done with that. That's not what it's about. We're not looking to scare people. We're again, our goal is to make people better at what they do best. And that means that there are certain things that I can do better than a small business that's not in IT can do. And by leveraging those different aspects of experience and expertise, we can really build something great together. So when we look at what a MSP is, they should not function as a vendor in a traditional sense. And we'd love to throw around this.
Mm-hmm.
term partner, but it's it's its meaning has been diminished over time. Ultimately, what I want to position the Isidore Group as, as an internal component of a company, as internal resources, as that in-house IT department, that in-house CIO and that in-house CTO and that in-house CSO. So when we when we look at that from that perspective, we then take ownership of our client.
And we then take ownership of their environments and we take ownership of their processes, and we certainly take ownership of their security. So, as important as uptime is, because obviously, what's the point if you can't use it? As important as it is, the idea here is that it's twofold. When we're looking at uptime as just keeping things running, then we're missing the bigger picture. We need to make sure that we're not just keeping things running, but we're keeping things running well. We're keeping things running securely and we're keeping things running in a way that's sustainable and
scalable as the business needs to change.
Hmm.
Sebastian, what do you think about the use of AI? in the work that you do, for example, where do you see the biggest benefit and is there a place where you see it still kind of lacking?
Well, I think for me, when I look at where is AI lacking, I I look at it from a security perspective. That's really kind of how I'm built. So if we're looking at the lack of of AI, this is one of the things that I've struggled with my entire life. I've worked with a lot of developers, I've worked with a lot of people that like to push things to the bleeding edge, and that's fantastic. It really drives progress, but also functionality isn't the whole picture, right? Security is a big piece of that too.
And what we typically find with all of these technologies is we typically jump before we look down. And when we're doing that, we don't really have an eye to security. So I have a lot of clients that are looking to talk to AI. And Microsoft's been pushing Copilot. and we've got clients that are just like, yeah, I wanna I wanna give Claude access to my entire SharePoint. Like, well, you know, maybe we should look at your entire SharePoint first, right? Let's look and see what Claude's actually gonna have access to before you just make that determination.
Because you don't realize that without having put the proper time and and and and and attention to actual security, actually classification of data, put putting those kinds of efforts on the back burner and just jumping into AI, AI is gonna do exactly what you tell it to do. And if you're gonna tell it to go ahead and index all of this information and then answer questions based on it.
Mm.
yeah, there's really no reason why, if there's a document that's got the CEO's salary on it, that the AI won't be able to bring that up to any low-level employee that asks for it. And that's just a reputational, internal reputational issue. That doesn't even begin to talk about some of the other information that can be out there. You know, we work with law enforcement agencies. We have strict policies and governance as to how we maintain any data we obtain from our clients.
Mm.
If we didn't have those, the potentiality for that kind of information to be accessible to AI, where AI can learn on it, or somebody who shouldn't have access to it could report on it, that's problematic. So what ends up happening is that in a lot of businesses, you see this huge push to adopt AI without taking the time to put the necessary safeguards and precautions in place. So that's where we spend a lot of our time when we're preparing AI for our clients. Internally,
We use AI a lot and it's not just an enhanced Google search. Oftentimes we'll use AI for report productions and we'll use AI to summarize information and even make suggestions. So we use AI for our ticket triaging, but we use it so that it only makes suggestions. At the end of the day, our staff must approve the recommendations that it makes. There's no automation where it just makes decisions for us.
And on the same token, we are not going to unleash AI on our clients to solve technical problems. There's too much nuance out there, and AI is not at the point in which it can think the way that we want it to think. But also from you know a a more anthropological or anthropological perspective, AI doesn't have a soul. So a lot of the things that govern the way that we act and some of the things that we do don't necessarily exist in AI.
So, to the point in which you are making a decision that has an ethical bound or a moral component, I don't trust AI there either. So ultimately, what it really comes down to is having an understanding of the awesomeness of the power of this technology and understanding the limitations that it has as well, and making sure that we solve for those limitations. When we're looking at processing data, when we're looking at storing data, when we're looking at clients that have compliance requirements.
Mm.
It's a whole different ball of wax and AI was not built with that in mind. So having a trusted partner that understands AI and understands compliance is really key if you're in any industry that requires any compliance. And the reality is with all these new FTC regulations that have come out, obviously HIPAA is another piece of it. And the concern with PII, every organization is in that environment. There is some regulation that manages
that that that that is re or some regulation that every single organization has to comply with. And where AI is concerned, the risk is just too high to not have somebody who can really help you navigate those waters.
Hmm. Yeah, it's it's funny that you said that because I also sometimes find myself outsourcing you know the brain part, the thinking to AI while I know that AI is only interpreting you know information that's on the internet. It's not it cannot think on its own, but it it makes it seems like it's thinking, but it's not. So yeah.
That's
And the reality is that these these AI companies have made it so conversational that it it acts like your buddy or your therapist or your priest. And and and the reality is is that you kinda have to keep that in check, right? you know, I I I I I see that all the time, that even as as we start to use it, not understanding that, okay, this is after all a tool.
Yeah. Yeah, yeah.
Hm.
Right. We're we're using this. It's a it's at at best it's an inference engine. right? It's it's able to infer what you're asking, it's able to to process information very quickly. its coding capabilities are fantastic as well. But one of the biggest limitations that we see with all these vibe coders, the the role of the business analyst and systems analyst, AI can't do that. Right? You still need somebody to be able to manage
the development process. You still need somebody that's going to be able to really have an understanding for process alignment. And while AI is has made great, great strides forward with UI and UX, I've got to say, from what I've seen, there's still quite a bit to be desired there. And it takes some time to work with your people to understand ergonomically what makes sense where. And you know, what what what's going to provide the best efficiency? How do we get this information
displayed, what information is over the top, right? Those are big things too. And to insist upon logging, like as a security guy, I want to see every record about everything that ever happened. And that's not that's not natural in most coding environments when you're using AI. It's things it can do, but you really have to have an understanding of what you're asking it to do. And and really have an understanding of what application architecture is going to look like even in that
Now imagine what this looks like when it comes to security. If you're really not asking the right questions, you're not going to get the right answers. It really comes down to response quality is based on prompt quality. And if you don't know the right questions to ask and just think that AI is going to, you know, think for itself, it's not. It's going to do exactly what you ask it to do. And if you're limited in your scope of your prompt, its response is going to be limited to the scope of your prompt.
Hmm. Yeah, that's that's a great tip. You know, I I think the length of your prompt really correlates to how good the output will be. At least that's what I found. So how how are you what's what's the goal with I know you already mentioned it, but
Absolutely.
What's the near future goal of Isidore Group in this year?
AI is a new frontier, and what we're seeing is that I mean, you can spend 10 minutes on Instagram and you can see that that everywhere you turn, there is some AI agency out there trying to help clients do incorporate AI in some way. The the reality is that it's a it has to be a holistic approach or businesses stand to lose way too much. You know, I I I see all of these people talking about eugenic AI.
And and having you know open claw just kind of function as its own customer service rep or whatever it is. I'm a little terrified by that. And I'm in the industry and I understand the safeguards that we can put in place, and still that's what we do. For example, we use we use an internal system that we've created that allows our our technicians to quickly process tickets that come through.
And we have some AI that's built into it, like I said initially in the triaging process. We have some tools that provide diagnostic information to our client, to our text that's built into it. But we also have the ability for the tech to sit there and ask the AI a question about a particular issue. And we can actually determine what we send to the AI for that. Now, in this case, we're using we're using Azure OpenAI. And the reason we're doing that is because every single conversation stays within our
Mm-hmm.
private Azure container. Everything. And as a matter of fact, we actually don't store any of that information. We just maintain metadata of the law in our logs of the information that's sent. And we do not let the AI maintain any information. So every time we send a request, we're sending quite a bit of information along with it so that the AI can make a reasonable inference and then dump it so that it's not maintained. It's not learning on it. It's not using that information for anything. But we've also put up
gates for our level one technicians too, because there's no reason to believe that you ask the AI a question and it won't give you registry edits or other kinds of of suggestions that a level one technician is not qualified to perform at the Isidore Group. So we've put those gates in place as well. And that is one of the ways that we're able to do that. Now we can do that for our clients too and we have where
Mm.
We can create a prompt library. We can limit the scope. We can make sure that we put these safeguards in place so that when they're using AI, the responses that come back are limited to what should be capable for the person asking that that question. Those kinds of things really make a big difference. But again, this is not something that just happens out of the box. These are things that you're going to have to work with somebody who understands AI.
understands compliance, understands your business, so that we can build those proper safeguards around it. It's it's just a different world now, and we really have to have an eye for it.
Mm.
Interesting, interesting. And you probably have a lot of experience right from doing this over the years. So looking back kind of on on the experience that you've gathered over the years, if you would start the Isidore Group today, is there something that you would do particularly different?
Hmm. It's a really good question. So
I'm the type of person that looks at where things are today and if I'm happy with them, I'd sit I I my response would generally be, if I had to go back and do it all over again, I'd do my best efforts to make sure I don't change a thing so I'd end up where I am today. I I think that that generally that is the case. Are there lessons that we learned along the way? Absolutely. Are there things that I wish we would have done different initially? Sure. But when I look back on it, even those mistakes
those errors and judgments that we've made along the way, they've really helped us, they've really helped shape who we are today. And I I'm one of those people who truly believes that we learn more from our mistakes than we do from our successes. So I don't know if I would necessarily want to go back and change anything in in any large regard. I'm I'm really happy with the company that we've built here. I'm really happy with the the work that we're able to do and the great people that work for us.
Mm.
the attention that we've always spent on helping our coworkers develop themselves in their own field. one of the things that we're really big p passionate about is that we want our our technicians to obtain and maintain certifications to the extent that we actually pay for training and we pay for those certifications and and they can be quite costly. So you know and essentially what we're doing is is we're taking our staff and we're making them
more marketable and more expensive, but and we're paying for that. But ultimately it's making them better and they're able to deliver a higher quality of service to our clients. And that's really what's important to us. We'll take the the the backside risk of that. But ultimately I'd say if we had to do it all over again, I'm happy to accept all of our successes and all of our failures for helping us find additional success. So yeah, I don't think I changed a thing.
Hm.
That's great. Okay, and Sebastian, for people listening that would like to contact you or you know, reach out or just check out the Isidore Group and what you guys are up to, where should they go?
So best place to start out is on our website. So you go to Isidore Group dot com. That's I S I D O R E Group dot com. And check us out there. There's quite a bit of information and it's easy to get in touch with us. You can see a lot about what we do. we are based in the Chicagoland area, but we've got clients coast to coast and we have since our inception. it's one of the things that really kind of differentiates us is that we we spend a a good amount of of
time making sure that our clients have built in resilience to the extent that even if they are three thousand miles away, we can still support them. So you know, that's that's the the the key there. But yeah, check us out online, www dot isidoregroup dot com or give us a call at 630-884-8840. Either way.
Well no. Well so you've heard it guys and thank you for joining Sebastian.
Thank you very much for having me. I appreciate the time.