Resources
Guides, glossary, and alternatives
Plain-language answers, buyer's guides, and honest vendor comparisons for MSPs and lean IT teams. Everything Lavawall® has written, in one place.
Buyer's guides
How to choose software for a framework, a platform, or a job to be done.
Best application control without a kernel driver (2026)
Kernel-driver app control risks BSODs, driver-signing breakage and RDS instability. What to look for in kernel-free a…
Best Australian Essential Eight software for MSPs (2026)
The ASD Essential Eight is the world's most prescriptive security baseline. Here is what to look for in Essential Eig…
Best CIS Controls v8 implementation tools for MSPs (2026)
CIS Controls v8 are the most pragmatic prioritised cybersecurity controls in the industry, used by cyber insurance, g…
Best CMMC 2.0 software for MSPs (2026)
CMMC 2.0 readiness is now a hard requirement for MSPs serving US Department of Defense supply-chain clients.
Best cross-platform patch management for MSPs (Windows, macOS, Linux) (2026)
Most patch tools are Windows-first and bolt on macOS and Linux, leaving silent gaps. What to look for in cross-platfo…
Best cybersecurity tools for Canadian MSPs (2026)
Canadian MSPs work under PIPEDA, Quebec Law 25, BC and Alberta PIPA, health acts, and CPCSC. What to look for in cybe…
Best GRC tools for MSPs (2026)
Choosing GRC as an MSP differs from SaaS: you need multi-tenant isolation, frameworks beyond SOC 2, white-label clien…
Best HIPAA compliance software for MSPs (2026)
MSPs serving US healthcare clients manage HIPAA Security Rule and Privacy Rule controls across many tenants, without…
Best ISO 27001 software for MSPs (2026)
ISO 27001 is the international information-security management-system standard most enterprise procurement requires a…
Best Microsoft 365 breach detection tools for MSPs (2026)
M365, Entra, Azure and Defender give rich logs most MSPs cannot triage fast. What to look for in an M365 breach-detec…
Best Microsoft 365, Entra ID & Azure configuration backup tools for MSPs
Microsoft tenants get breached at the config layer: CA policies, OAuth grants, NSG and transport rules. The best M365…
Best multi-tenant remote support tools for MSPs (2026)
Browser-based, multi-tenant remote support with country-restricted access on by default, bundled with the rest of the…
Best NIST CSF 2.0 software for MSPs (2026)
NIST Cybersecurity Framework 2.0 has become the lingua franca of cyber-insurance assessments and broad enterprise sec…
Best ransomware detection tools for MSPs (2026)
Ransomware groups now target MSPs and stage tooling for weeks before encrypting. The best detection tools catch the s…
Best RMM augmentation tools for MSPs (2026)
Your RMM handles scripting and patching, not security, GRC, or cloud breach detection. What RMM augmentation tools do…
Best SaaS discovery and shadow-AI detection tools for MSPs (2026)
Your firewall log shows thousands of SaaS hostnames. Most are noise. A few are unsanctioned ChatGPT, Claude, or Gemin…
Best security awareness training for MSPs (2026): Canada, US, UK, Australia & EU
The best security awareness training for MSPs in 2026, rated on Canada, US, UK, Australia and EU coverage, phishing s…
Best smart helpdesk for MSPs (2026)
Per-named-agent pricing with unlimited tickets is the MSP standard. Add device-context tickets, AI KB suggestions, an…
Best SOC 2 software for MSPs (2026)
MSPs delivering SOC 2 readiness need multi-tenant evidence collection, AICPA Trust Services Criteria mapping, and aud…
Best vulnerability scanning tools for MSPs (2026)
MSP vulnerability management must scale across tenants without enterprise pricing and produce evidence insurers and C…
Glossary: what is…
Plain-language definitions of the frameworks, laws, and concepts that come up in MSP security and compliance.
SPF, DMARC, and DKIM explained with Lavawall®
Learn what SPF, DKIM, and DMARC are, why they protect your email from spoofing and phishing, and how Lavawall® checks…
What is Akira ransomware? Definition, components, and why it matters
Akira is a ransomware-as-a-service group active since 2023, hitting SMBs, healthcare practices, and accounting firms…
What is Alberta Health Information Act (Alberta HIA)? Definition, components, and why it matters
The Alberta Health Information Act governs collection, use, and disclosure of health information by custodians in Alb…
What is Alberta PIPA (Personal Information Protection Act)? Definition, components, and why it matters
Alberta PIPA is Alberta's private-sector privacy law, substantially similar to PIPEDA. Alberta was first in Canada to…
What is Application control? Definition, components, and why it matters
Application control lets only approved software run and blocks everything else. Learn the components, why it matters,…
What is Australian Essential Eight? Definition, components, and why it matters
The Australian Essential Eight is eight cybersecurity mitigation strategies from the ASD / ACSC, with three Maturity…
What is BC E-Health (Personal Health Information Access and Protection of Privacy) Act? Definition, components, and why it matters
The BC E-Health Act (SBC 2008 c. 38) governs designated provincial Health Information Banks like CareConnect and Phar…
What is BC HIA (a common term, but not a single BC statute)? Definition, components, and why it matters
BC HIA is not a single statute. BC health-information privacy runs through BC PIPA, FIPPA, and the BC E-Health Act, a…
What is BC PIPA (Personal Information Protection Act)? Definition, components, and why it matters
BC PIPA is British Columbia's private-sector privacy law, substantially similar to PIPEDA. Mandatory breach notificat…
What is Bill C-8 (Critical Cyber Systems Protection Act)? Definition, components, and why it matters
Bill C-8 is Canada's Critical Cyber Systems Protection Act (CCSPA), requiring designated operators of vital federal s…
What is CIS Controls v8 (Center for Internet Security Critical Security Controls)? Definition, components, and why it matters
CIS Controls v8 are the 18 prioritised cybersecurity controls from the Center for Internet Security, grouped into Imp…
What is CMMC 2.0? Definition, components, and why it matters
CMMC 2.0 is the US Department of Defense contractor cybersecurity certification program, built on NIST SP 800-171 a…
What is configuration drift?
Configuration drift is the gradual divergence of a system from its intended baseline. In M365, Entra ID, and Azure it…
What is CPCSC (Canadian Program for Cyber Security Certification)? Definition, components, and why it matters
CPCSC is Canada's emerging contractor cybersecurity certification program, aligned with US CMMC 2.0 and built on th…
What is Cross-platform patch management? Definition, components, and why it matters
Cross-platform patch management keeps OS, app, and firmware patches current across Windows, macOS, and Linux from one…
What is Entra ID backup?
Entra ID backup captures Microsoft Entra ID configuration (Conditional Access, roles, app registrations) so changes c…
What is GRC for MSPs? Definition, components, and why it matters
GRC for MSPs is the discipline of mapping a managed-service provider's technical and process controls to compliance f…
What is HIPAA (Health Insurance Portability and Accountability Act)? Definition, components, and why it matters
HIPAA is US federal law governing the privacy and security of protected health information (PHI): Security Rule safeg…
What is ISO/IEC 27001? Definition, components, and why it matters
ISO/IEC 27001 is the international standard for information-security management systems (ISMS). Certification is issu…
What is ITDR (Identity Threat Detection and Response)? Definition, components, and why it matters
ITDR detects and responds to attacks on identity systems like Microsoft 365, Entra ID, and Google Workspace. Learn ho…
What is M365 configuration backup? Definition, scope, why it matters
M365 configuration backup snapshots a Microsoft 365 tenant's policies, roles, app registrations, and Intune profiles…
What is NIST CSF 2.0 (NIST Cybersecurity Framework version 2.0)? Definition, components, and why it matters
NIST CSF 2.0 is a voluntary, risk-based cybersecurity framework built around six functions: Govern, Identify, Protect…
What is PCI DSS (Payment Card Industry Data Security Standard)? Definition, components, and why it matters
PCI DSS is the security standard every organisation storing, processing, or transmitting payment card data must meet.…
What is Per-named-agent helpdesk pricing? Definition, components, and why it matters
Per-named-agent helpdesk pricing means a fixed monthly fee per named technician for unlimited tickets. Definition, co…
What is PIPEDA (Personal Information Protection and Electronic Documents Act)? Definition, components, and why it matters
PIPEDA is Canada's federal private-sector privacy law: ten Fair Information Principles, consent, reasonable safeguard…
What is RMM augmentation? Definition, components, and why it matters
RMM augmentation layers security, GRC, and analytics on top of your existing RMM instead of replacing it. Learn what…
What is Shadow AI? Definition, components, and why it matters
Shadow AI is staff use of unsanctioned generative-AI tools. Learn the risks, why it matters, and how Lavawall® surfac…
What is SOC 2 (System and Organization Controls 2)? Definition, components, and why it matters
SOC 2 is an attestation report issued by an AICPA-licensed independent auditor, evaluating an organisation's controls…
What is Tier 3 cybersecurity augmentation? Definition, components, and why it matters
Tier 3 cybersecurity augmentation puts senior CISSP/CISA expertise on demand as an extension of an MSP or lean IT tea…
What is XDR (Extended Detection and Response)? Definition, components, and why it matters
XDR correlates detection across endpoint, identity, email, network, and cloud for broader context than EDR. Learn how…
Alternatives & comparisons
How Lavawall® compares to the tools MSPs switch from, with honest notes on where each one wins.
Lavawall®: The Alternative to Action1: Patch management comparison for MSPs
Action1 is a free-tier-friendly cloud-native patch management tool. Lavawall® overlaps on patching but adds 15+ frame…
Lavawall®: The Alternative to Atera: RMM augmentation comparison for MSPs
Atera is an all-in-one RMM and PSA priced per technician. Lavawall® is a multi-tenant cybersecurity, GRC, and analyti…
Lavawall®: The Alternative to AutoElevate: Privilege management and admin elevation comparison for MSPs
AutoElevate (CyberFOX) is an admin-elevation tool that lets standard users request and receive privilege escalation f…
Lavawall®: The Alternative to Automox: Patch management comparison for MSPs
Automox is a cloud-native cross-platform patch tool with reasonable Windows, macOS, and Linux coverage. Lavawall® ove…
Lavawall®: The Alternative to Auvik: Network monitoring comparison for MSPs
Auvik is an MSP-focused network monitoring and management platform. Lavawall® is the security, GRC, and analytics pla…
Lavawall®: The Alternative to AvePoint Cloud Backup: config backup for MSPs
AvePoint Cloud Backup is enterprise-grade M365 content + config backup with BYOK encryption and Microsoft 365 Backup…
Lavawall®: The Alternative to Blackpoint Cyber: Managed detection comparison for MSPs
Blackpoint Cyber is a managed detection and response (MDR) provider with M365 monitoring. Lavawall® is the broader MS…
Lavawall®: The Alternative to Bomgar / BeyondTrust: Remote support and privileged access comparison for MSPs
Bomgar (now BeyondTrust Remote Support) is a polished privileged remote-access platform aimed at large enterprises. L…
Lavawall®: The Alternative to Cayosoft Guardian: M365, Entra ID, Azure config backup for MSPs
Cayosoft Guardian is the strongest direct competitor for Microsoft 365, Entra ID, and AD configuration backup & rollb…
Lavawall®: The Alternative to CIPP: managed SaaS vs self-hosted M365 management for MSPs
CIPP is a free, open-source self-hosted M365 management platform for MSPs. Lavawall® is a managed-SaaS configuration…
Lavawall®: The Alternative to ConnectSecure (formerly CyberCNS): Vulnerability scanning comparison for MSPs
ConnectSecure (formerly CyberCNS) is an MSP-focused vulnerability scanning and PCI / CIS reporting platform. Lavawall…
Lavawall®: The Alternative to ConnectWise Automate: RMM augmentation comparison for MSPs
ConnectWise Automate is a deep, scriptable RMM with a long history in mid-to-large MSPs. Lavawall® is a multi-tenant…
Lavawall®: The Alternative to Datto RMM. RMM and patch management comparison for MSPs
Datto RMM (now part of Kaseya) is widely deployed across MSPs. Lavawall® natively integrates with Datto RMM as a depl…
Lavawall®: The Alternative to Drata. GRC and continuous compliance evidence comparison for MSPs
Drata is a strong GRC evidence-collection platform aimed primarily at SaaS and tech companies pursuing SOC 2, ISO 270…
Lavawall®: The Alternative to Dropsuite Entra Backup (NinjaOne) for MSPs
Dropsuite Entra Backup (a NinjaOne company) is a direct competitor for Microsoft Entra ID configuration backup. Lavaw…
Lavawall®: The Alternative to Huntress. Managed detection comparison for MSPs
Huntress is a managed-EDR / identity threat detection and response (ITDR) / security-awareness platform with a 24/7 S…
Lavawall®: The Alternative to Hyperproof. GRC platform comparison for MSPs
Hyperproof is a compliance-program-management platform popular with mid-market enterprises. Lavawall® delivers multi-…
Lavawall®: The Alternative to Kaseya VSA. RMM augmentation comparison for MSPs
Kaseya VSA is a long-standing MSP RMM with deep IT-operations automation. Lavawall® augments Kaseya VSA with cross-pl…
Lavawall®: The Alternative to KnowBe4 PhishAlert & Microsoft Defender: Phishing Reporter Comparison for MSPs
KnowBe4 PhishAlert requires broad mailbox OAuth permissions (Mail.ReadWrite, Mail.ReadWrite.Shared, Mail.Send, Mail.S…
Lavawall®: The Alternative to Liongard: MSP attestation comparison for MSPs
Liongard is an MSP-focused attestation and configuration-discovery platform. Lavawall® overlaps in attestation and Sa…
Lavawall®: The Alternative to ManageEngine ADAudit Plus: AD reporting for MSPs
ManageEngine ADAudit Plus is a deep AD audit archive. Lavawall® covers AD and M365 user reporting plus patching, GRC,…
Lavawall®: The Alternative to Microsoft Defender XDR: Microsoft-native security comparison for MSPs
Microsoft Defender XDR (Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud App…
Lavawall®: The Alternative to Microsoft Intune: Endpoint management comparison for MSPs
Microsoft Intune is Microsoft's MDM / endpoint management platform. Lavawall® complements Intune for MSPs by adding m…
Lavawall®: The Alternative to N-able Cove: config backup vs mailbox backup for MSPs
N-able Cove Data Protection backs up Microsoft 365 mailbox, OneDrive, SharePoint, and Teams content. Lavawall® backs…
Lavawall®: The Alternative to N-able (N-central / N-sight), RMM augmentation comparison for MSPs
N-able N-central and N-sight are mature MSP RMMs with strong patch automation, network monitoring, and automation. La…
Lavawall®: The Alternative to Netwrix Auditor for AD, file & M365 activity
Netwrix Auditor covers AD, file, and M365 activity for enterprise audit archives. Lavawall® covers the same plus patc…
Lavawall®: The Alternative to NinjaOne, RMM and patch management comparison for MSPs
NinjaOne is a popular MSP RMM with strong patching and remote access. Lavawall® is built to either replace your RMM o…
Lavawall®: The Alternative to Quest Change Auditor for AD and M365 activity for MSPs
Quest Change Auditor is an enterprise AD / file / Exchange audit platform. Lavawall® covers MSP-channel activity moni…
Lavawall®: The Alternative to Secureframe, GRC platform comparison for MSPs
Secureframe is a compliance-automation platform aimed at SaaS startups chasing SOC 2 and ISO 27001. Lavawall® is mult…
Lavawall®: The Alternative to KnowBe4, Proofpoint & Mimecast Security Awareness Training Comparison for MSPs
KnowBe4, Proofpoint, and Mimecast charge per seat for US-centric generic courses. Lavawall® includes Canada, US, UK,…
Lavawall®: The Alternative to Syncro MSP (RMM augmentation comparison for MSPs)
Syncro is an all-in-one RMM + PSA + invoicing platform popular with smaller MSPs. Lavawall® augments Syncro with mult…
Lavawall®: The Alternative to ThreatLocker (application control and zero-trust endpoint allowlisting comparison for MSPs)
ThreatLocker is a well-known kernel-driver-based application control and ringfencing platform. Lavawall® delivers app…
Lavawall®: The Alternative to Vanta (GRC and continuous compliance evidence comparison for MSPs)
Vanta is a strong GRC evidence-collection platform aimed primarily at SaaS and tech companies pursuing SOC 2 and ISO…
Lavawall®: The Alternative to Varonis (file activity monitoring for MSPs)
Varonis is a data-security platform with deep content classification. Lavawall® covers file activity monitoring MSPs…
Lavawall®: The Alternative to Webroot (bundled AV / endpoint protection comparison for MSPs)
Webroot is a low-cost antivirus product commonly bundled with MSP tooling. Lavawall® is not an AV. It monitors Webroo…
Lavawall®: The Alternative to Zendesk (helpdesk / ticketing for MSPs comparison for MSPs)
Zendesk is a polished, general-purpose helpdesk used by some MSPs as their PSA. Lavawall® Help Desk Pro is built spec…