By: Linda Brown
Winning in business today means taking cybersecurity seriously. However, many businesses still see it as a secondary concern. “Security needs to be front and center. Every decision should be security-driven,” says Jeff Borello, CEO of Andromeda Technology Solutions, who wants that mindset to change.
On the MSP 1337 podcast with host Chris Johnson, Borello explained why cybersecurity needs to be at the core of business operations.
A Lifelong Commitment to Technology
Borello’s technology journey started at age 12 with a Radio Shack computer, inspiring his lifelong commitment to innovation. Today, his company, Andromeda, stands out for excellence in cybersecurity, proactive IT management, and operational reliability. With over $9 million in annual revenue and more than 500 clients, the firm continues to grow rapidly.
Why Cybersecurity Frameworks Matter
Borello strongly recommends adopting formal cybersecurity standards like NIST 800-171. This framework helps businesses protect sensitive data and satisfy insurance requirements.
“Our journey with NIST 800-171 began about 18 months ago,” Borello explained, “partially pushed by our insurance company, but also by our determination to lead by example.”
He thinks these frameworks will soon become required for all companies—not just those facing regulations. Insurance providers have already started demanding clear proof of good cybersecurity practices because cyber threats keep growing.
Insurance Questionnaires Cause Problems
Borello shared his frustration with how insurers handle cybersecurity questionnaires. Often, these documents reduce complex issues to simple yes-or-no answers. Businesses sometimes misunderstand what insurers expect.
He highlighted multi-factor authentication (MFA) as an example. Insurance companies might ask a vague question like, “Do you use MFA?” without explaining clearly what they mean.
Borello mentioned the Travelers Insurance case, where the insurer sued a company for incomplete MFA implementation after a cybersecurity incident. He said this case shows why clear communication is critical.
Businesses should answer insurance questionnaires honestly. “Be transparent,” he advised, “use them as an opportunity to improve your security.”
Changing How Businesses Think About IT
Borello sees a clear gap between companies that value IT and those that ignore it. Many businesses treat cybersecurity as an unnecessary cost—until they suffer an attack.
“This mindset leads to neglect and unnecessary vulnerabilities,” Borello said. Often, companies only take security seriously after something goes wrong.
To encourage responsibility, Andromeda now requires clients to have cybersecurity insurance. This makes businesses take security more seriously.
Stopping Unauthorized Software
Borello also tackled the widespread issue of uncontrolled software installations, often known as shadow IT. To fix this, Andromeda adopted a zero-trust policy. Now, no one can install software without clear approval.
This approach significantly reduced vulnerabilities in client networks.
Looking Ahead
Borello urges businesses to take cybersecurity seriously before it’s too late. With threats increasing and insurance rules getting stricter, strong cybersecurity practices like NIST 800-171 are becoming essential—not optional.
“Every business should put security front and center,” he emphasized. “It’s about protecting your operations and your future.”
Disclaimer: The information provided is for general informational purposes only and should not be construed as professional advice. Manufacturers should consult with qualified IT professionals for specific guidance tailored to their individual needs and circumstances.
Published by Anne C.



