In today’s office technology market, the subject of cybersecurity is anything but theoretical. As the risks multiply and the tactics of attackers change, the office technology channel resellers are on the front lines as customers in law offices, financial institutions, school districts, and more navigate the complexity of office security. This month, I spoke with Jim Peterson, cybersecurity product marketing manager at ConnectWise, to get some expert guidance on the practical side of securing the office.
Changing threats, changing mindsets
Peterson starts with a clear warning: the attacks hitting offices are morphing at an unprecedented rate. “For a long time, SMBs didn’t think they were at risk, so they didn’t apply proper security solutions to keep them protected — that is changing quite a bit. They now understand that the SMB market is a primary point of attack.” This shift in mindset is crucial for office technology resellers, whose clients may assume they are too small to matter but are now seeing that over 52% of all incidents, according to ConnectWise’s market data, hit the SMB sector.
But awareness isn’t enough. Peterson sees underestimation of the sophistication and speed of today’s attacks as the biggest vulnerability in offices. The technologies that were popular a year ago are quickly being outpaced by threats targeting new vectors, from identity to APIs. While many organizations rely on legacy technology for protection, Peterson cautions that attacks don’t follow that pattern. “Attacks will completely morph and change,” he said. “While newer technology will adapt and respond to a lot of those changes, many times the attacks are now targeting solutions like Microsoft 365 and not necessarily the workstation. Those are two separate technologies, which means security strategies must account for both identity and endpoint protection.”
Building a security conversation from technology to people
For resellers supporting offices in verticals like education, healthcare, law, and finance, the cybersecurity sales conversation can be the hardest part. Peterson notes the challenge is that a system implemented only a year ago may now not suffice due to the rapid evolution of threats. Quarterly or triannual reviews are now standard practice, says Peterson, and “not just with the copier dealers, for MSPs in general.”
Those regular touchpoints don’t always go deep enough, either. “Too often, we don’t use that time wisely,” Peterson says. “IT providers traditionally use that time to discuss service delivery to justify our value, versus saying, ‘Here’s what’s coming in the future.’ And most customers want more information than ‘I closed a specific number of tickets for you since we last met.’ For most SMBs, those pieces of information do not help them decide what to do next.” According to Peterson, channel partners must spend more time talking about what’s next, not just what’s been done.
People, processes, and technology — a unified approach
Peterson is adamant that the conversation shouldn’t start and end with technical solutions. “People, process, and technology is always the best solution for any level of protection,” he says. “This is where copier dealers, MSPs, and security professionals excel — we’re all about process and people. The human element matters just as much as the hardware and software.”
What goes wrong? According to Peterson, “We buy technology, and it’s great, it does what it’s supposed to do, but if we don’t keep it updated and we don’t know how to respond to what it’s telling us, we have a real problem. Technology will decay over time and lose its effectiveness if not maintained properly.” In addition, resellers and office technology specialists should look beyond familiar risk areas, like servers, workstations, and firewalls, and cover new threats such as Internet of Things (IoT) devices, supply chain connections, and vendor integrations, which are typically vulnerable areas in SMB technology.
Office security beyond the four walls
Peterson shares that real security now extends well past the physical office. “We can put our arms around everything in the four walls of any business and do a pretty good job there, but we know that at least 50% of the data in the workforce today is outside in the cloud.” Traditional IT pros might overlook protection of these cloud or SaaS solutions, but Peterson encourages expanding research and security. “If we don’t support SaaS or cloud-based solutions for the SMB market, someone else will come in because the workstation, server, and network protection is the easy stuff in today’s world. The cloud and SaaS protection are the hard things because of continual change and who is responsible for security and recovery. Helping shed light on all of the risks an SMB faces is really where security professionals can stand apart.”
Hybrid work and BYOD — continuing challenges
The hybrid office, post-pandemic, introduces new risks and new needs. Office environments now blend remote, hybrid, and BYOD cultures. Peterson observes, “We’ve adapted to that hybrid workforce … oftentimes SMB leaders want teams back in the office, but need to build protection that supports working from anywhere.” Still, BYOD policies and the proliferation of mobile endpoints mean the risk doubles anytime we bring a personal device into it.
While solutions exist, including MFA and remote containerized wiping, “We still have a little way to go in the BYOD world. But we’ve done a pretty good job of making a remote home office secure in today’s world.” Peterson suggests framing conversations with clients around practical advice and security realities, rather than technology buzzwords.
The next wave — emerging threats resellers must watch
What’s coming next? Peterson identifies several emerging threats:
- Phishing and fileless malware: Traditional phishing has gotten an AI upgrade. We cannot spot the fake anymore. Attacks like fileless malware will circumvent a lot of different security technologies, opening SMBs to attacks like ransomware. Delayed weaponization in URL links can also become malicious after several clicks, presenting a new challenge that many SMBs are not prepared to defend.
- Supply chain and API attacks: When an SMB connects its software to your software through an API, we have a risk that the vendor could potentially inject bad information into your environment if you’re not properly monitoring it and protecting it. HVAC, EMR, and other systems that are linked to core networks can introduce vulnerabilities.
- IoT exploitation: Offices are installing devices that improve our efficiency everywhere, but SBMs rarely understand their risks and how to update/segment them for protection.
- SaaS ransomware attacks: Peterson highlights this as the new attack frontier. In the next 12 to 18 months, we expect an increase in SaaS-based ransom attacks. Hackers need to move into the SaaS environment to really make an impact in today’s world, because 50% of the data is there. For example, if OneDrive is connected and I encrypt it locally, that encryption could synchronize up to the cloud, and if your environment is not properly backed up, that data could be lost.
A key point: “Everybody seems to think that the providers are going to solve every security problem — ‘If my data is erased, I’ll just restore it from Microsoft, Dropbox, Box, or any of the hosted environments.’ And yes, those features are relatively easy today, but we have to be prepared for the next level of attack that doesn’t allow that to happen.”
Foundational security principles for resellers
Peterson recommends distilling the security conversation for clients into three big questions:
- How do we stop attacks from coming in? Focus on the business’s unique risks and build sharper barriers — industry, size, workforce, and data all matter.
- If attacks start from within, how do we protect the data inside? Most internal breaches start with negligent or complacent actors, but can also be malicious. Data confidentiality, integrity, and segmentation are essential to limit risk.
- How can we always recover? IT professionals always want to make sure that they are in control of restoration … you never want to hand recovery of your data over to the bad actor. So proper backup and recovery testing is critical.
Peterson’s advice: Avoid jargon, keep conversations scenario-based, and encourage testing and regular review — especially around backup and disaster recovery strategies.
Technology to watch: SIEM, AI-driven security, and vulnerability management
Peterson points out that modern SIEM (security information and event management) is becoming much more than a “log repository.” It’s now a “defense mechanism all its own,” leveraging AI and machine learning to automatically block ransomware and trigger host isolation. “Modern SIEMs can block ransomware and malware attacks. We can do automation for host isolation when it sees a specific event happen. We can do things that are very, very protective in nature.”
Email security has also evolved: “In today’s world, we have modern email security with efficacy hitting 99.9% because of AI-backed review of every email — the system can tell if it’s likely been written by the sender or instead by an AI bot. It’s getting down to understanding who’s creating the message to determine the risk.” Final take: “Holistic solutions solve a problem for a complete technology — protect the inbox, train the user, provide recovery.”
Vulnerability management is broadening to include IoT, APIs, and more supply chain integrations: “The expansion of vulnerability management is giving us a better view into a client’s risks that are out there. So looking at that adaptation and growth will really help provide proper guidance.”
Opportunity for the channel: subscription revenues and business problem-solving
The changing security landscape brings new sales opportunities for office technology dealers. Revenue streams are shifting toward managed services and subscriptions, offering customers predictability on how much they are spending in the year. Peterson sees the best opportunities emerging in managed SaaS protection, which is a people-heavy solution today, but is going to become a higher-margin offering as technology advances. Advising clients on compliance, cyber insurance requirements, and disaster recovery preparation are important value-adds.
Peterson is clear that risk isn’t static and taking on risk is sometimes necessary for business agility. “Anytime an application makes it easy for us to do something, we probably have taken on a risk with that adoption. We’re going to take on risk to make life easier and to be more competitive. We just have to understand that risk so that we can accept it and mitigate it.”
Budgeting, business priorities, and forward planning
As offices prepare for fiscal year-end planning, Peterson leaves the channel with essential advice: “The threat landscape is moving faster than it ever has before, just like technology is moving faster than it ever has before. Setting the right expectations with our clients will remove a lot of headaches.” Resellers and MSPs must focus not only on technical solutions, but on solving their clients’ real business challenges, which is something the channel has excelled at for years.
Education, adaptability, and transparency remain the best tools for success in an unpredictable environment. “Predictability is important, but setting the expectation of what predictability means is the right thing. MSPs have been good at solving technical problems. We also need to solve business problems, because eventually the technology will solve itself.”
Closing thoughts: building the next layer of trust
Peterson’s perspective is a valuable reminder: for office technology dealers, security isn’t just a technical conversation. It’s about being a trusted partner in a constantly shifting environment. As resellers help clients, success will depend on education, holistic solutions, realistic expectation setting, and a rigorous focus on people, process, and technology working together.
For us, the message is clear: securing today’s office is complex but achievable with the right mindset, the right methods, and continuous attention to the business realities behind every technology decision.
Patricia Ames
Patricia Ames is president and senior analyst for BPO Media, which publishes The Imaging Channel and Workflow magazines. As a market analyst and industry consultant, Ames has worked for prominent consulting firms including KPMG and has more than 15 years experience in the imaging industry covering technology and business sectors. Ames has lived and worked in the United States, Southeast Asia and Europe and enjoys being a part of a global industry and community.

