POPULARITY
“Digital accountability is here.” In this special Technology Reseller News and Cloud Communications Alliance podcast, Tommy Sheahan, CEO of CompleteSMS, discusses the growing compliance burden around application-to-person messaging—and the opportunity it creates for service providers. CompleteSMS, formerly Red Oxygen, has been in the SMS market for more than 25 years. The company helps businesses, software vendors and channel partners manage messaging compliance, registration, delivery and cost allocation. Sheahan says sending business text messages is no longer as simple as connecting to an API and sending traffic. Organizations increasingly need to document who they are messaging, why they are messaging them, how consent was obtained, what content is being sent and how opt-outs are handled. “We help businesses get compliant, stay compliant and manage the costs associated with that compliance,” Sheahan says. CompleteSMS also monitors messaging activity to help identify cases where approved traffic begins drifting into another use case, potentially creating delivery problems or compliance risk. The company's services are particularly relevant for smaller organizations that do not have dedicated messaging compliance teams. For MSPs, MSSPs, CPaaS providers and other channel partners, Sheahan says that complexity can become a business opportunity. CompleteSMS can help partners manage registration and ongoing compliance while also allocating campaign, carrier and messaging costs to individual customers. “We can help turn this from a cost center into a profit center,” Sheahan says. The regulatory environment is also becoming more complex globally, with different messaging requirements emerging across countries and individual U.S. states. For enterprises, Sheahan's message is straightforward: do not assume an internal compliance team understands the rapidly changing rules surrounding business SMS. Visit CompleteSMS.com to learn more and start a free trial.
Today’s headline news for Canadian IT solution providers: KnowBe4 names Kurt Mills channel chief: KnowBe4 has appointed Kurt Mills as channel chief, according to an announcement scheduled for release this morning. The company says Mills will lead the evolution of its global partner programs, operations, and channel routes to market. Mills brings more than 25 years of cybersecurity channel experience from roles at Trellix, Check Point Software Technologies, Mimecast, FireMon, and Blue Coat Systems. In a statement, KnowBe4 CEO Bryan Palma said partner ecosystem growth is central to the company’s mission and that Mills’ deep channel expertise will be instrumental as KnowBe4 expands its market reach. CBTS launches Forge Agents: CBTS, the $1.3 billion technology services company, is launching Forge Agents today. The platform is designed to move mid-market and regulated organizations from AI pilots to custom agents running securely in production within days. CBTS says the platform includes 187 prebuilt artifacts and 34 cross-industry blueprints, with support for Anthropic, Google, AWS, Cisco, and on-premises environments. The company developed the platform using lessons from deploying AI internally across more than 2,300 employees and reports achieving full return on investment within three months. Sublime Security integrates with CrowdStrike Falcon Next-Gen SIEM: Sublime Security announced at Fal.Con 2026a new integration with CrowdStrike Falcon Next-Gen SIEM. The integration brings email security signals into the SIEM so analysts can correlate email-based threats with endpoint, identity, cloud, and threat intelligence data in one unified workflow. According to Sublime Security, AI-generated attack content is up roughly five times in the past year, and 90 percent of malicious emails are now customized to their target. The integration lets analysts trigger remediation and deploy organization-specific detection coverage directly from a Falcon investigation. DefensX expands browser security for MSPs: DefensX has expanded its secure web browser suite with new AI governance capabilities designed to help MSPs govern AI usage and protect customer data at the browser layer, according to eChannelNEWS. Mondoo launches endpoint inventory and governance tools: Mondoo has launched inventory and governance tools for endpoint security, giving security teams visibility and control over shadow AI tooling on company endpoints, as reported by eChannelNEWS. Canada imposes counter-tariffs on U.S. tech goods: Canada will impose 15 percent counter-tariffs on U.S.-origin electronics including smartphones, gaming consoles, and appliances effective September 8, though major enterprise IT infrastructure is largely exempt, according to the Department of Finance Canada. Prophet Security finds 46% of internal AI SOC builds deprecated: Prophet Security’s 2026 State of AI in Security Operations report found that 46 percent of organizations’ internal AI SOC builds were ultimately deprecated, replaced with commercial technology, or never reached production, suggesting a significant channel opportunity for MSSPs and integrators. Prophet Security Commvault and CrowdStrike extend AI automation: Commvault and CrowdStrike have extended their integration to automate cyber recovery actions within CrowdStrike’s Charlotte agentic SOAR workflows, available now to joint customers. PRNewswire Read Full Transcript Welcome to The Buzz from ChannelBuzz.ca, I’m Robert Dutt, today is Tuesday, September 1, 2026, and here’s what’s happening in the channel today. KnowBe4 has appointed Kurt Mills as channel chief, according to an announcement scheduled for release this morning. The company says Mills will lead the evolution of its global partner programs, operations, and channel routes to market. Mills brings more than 25 years of cybersecurity channel experience from roles at Trellix, Check Point Software Technologies, Mimecast, FireMon, and Blue Coat Systems. In a statement, KnowBe4 CEO Bryan Palma said partner ecosystem growth is central to the company’s mission and that Mills’ deep channel expertise and track record of building high-performing teams through IPOs, acquisitions, and rapid market expansion will be instrumental as KnowBe4 expands its market reach. The appointment builds on a series of recent channel leadership additions, including Neill Burton and John Noha as vice presidents of channel supporting global initiatives. Canadian MSPs building managed security services around human risk management may see expanded program resources and enablement as KnowBe4 deepens its channel investment in a market where security awareness is becoming a recurring revenue staple. CBTS, the $1.3 billion technology services company, is launching Forge Agents today. The platform is designed to move mid-market and regulated organizations from AI pilots to custom agents running securely in production within days. Users describe the work they want completed in plain language, and CBTS says it builds the agent using the models and infrastructure the organization already has in place. The platform includes 187 prebuilt artifacts and 34 cross-industry blueprints, with support for Anthropic, Google, AWS, Cisco, and on-premises environments. CBTS developed the platform using lessons from deploying AI internally across more than 2,300 employees, and the company reports achieving full return on investment within three months. Mid-market Canadian clients are struggling to move AI from pilot to production, and CBTS’s template-driven approach gives channel partners a services wrapper they can build around. Sublime Security announced yesterday at Fal.Con 2026 in Las Vegas a new integration with CrowdStrike Falcon Next-Gen SIEM. The integration brings email security signals into the SIEM so analysts can correlate email-based threats with endpoint, identity, cloud, and threat intelligence data in one unified workflow. According to Sublime, AI-generated attack content is up roughly five times in the past year, and 90 percent of malicious emails are now customized to their target, making static detection increasingly inadequate. The integration lets analysts trigger remediation and deploy organization-specific detection coverage directly from a Falcon investigation, rather than waiting for the next vendor update cycle. Sublime says the integration gives analysts full, editable visibility into detection logic with no black box or vendor ticket required. The tighter correlation between email and endpoint detection should help Canadian MSPs compress response time from days to hours for clients without in-house security operations centers. In Brief – DefensX has expanded its secure web browser suite with new AI governance capabilities designed to help MSPs govern AI usage and protect customer data at the browser layer. Mondoo has launched inventory and governance tools for endpoint security, giving security teams visibility and control over shadow AI tooling on company endpoints. Canada will impose 15 percent counter-tariffs on U.S.-origin electronics including smartphones, gaming consoles, and appliances effective September 8, though major IT infrastructure is largely exempt. Prophet Security’s 2026 State of AI in Security Operations report found that 46 percent of organizations’ internal AI SOC builds were ultimately deprecated, replaced, or never reached production. Commvault and CrowdStrike have extended their integration to automate cyber recovery actions within CrowdStrike’s Charlotte agentic SOAR workflows, available now to joint customers. Full details and links in the show notes or the blog post. Later today on In The Channel, Frank Balonis from Kiteworks joins me to break down what Canadian partners need to know about the Canadian Program for Cyber Security Certification, and why the window to get ahead of Level 2 requirements is already closing. And if you haven’t heard it yet, my conversation with Jason Wieser from Calero on why technology expense management might be the MSP practice you’ve been overlooking. That’s how we’re seeing the headlines today. I’m Robert Dutt for ChannelBuzz.ca, thanks for listening. Have a great day.
Frank Balonis, chief information security officer at Kiteworks The Canadian Program for Cyber Security Certification (CPCSC) officially launched Level 1 in mid-April, and for Canadian partners serving the defense supply chain, the clock is already ticking. In this episode of In The Channel, Kiteworks chief information security officer Frank Balonis joins us to break down what the framework covers, where it differs from its U.S. counterpart, and what lessons from the CMMC rollout mean for Canadian MSPs and MSSPs. Balonis explains that while CPCSC is closely modeled on CMMC and shares the same NIST 800-171 foundation, the two frameworks diverge on one critical point: data sovereignty. Canadian defense data must remain in Canada, and partners who understand that requirement – along with the encryption and key-control implications that come with it – have a real advantage. The bigger opportunity, Balonis argues, lies in the cross-border play. Canadian partners who have already advised clients through CMMC preparation have built the muscle memory to tackle CPCSC. Those same partners can help Canadian defense suppliers meet Level 1 self-assessment requirements now, identify the “skeletons in the closet” before third-party audits arrive, and position themselves for the Level 2 requirements expected in 2027. Unlike CMMC, which paused and relaunched as 2.0, CPCSC is already live with a shorter runway. Balonis notes that CMMC has driven roughly half of Kiteworks’ deal flow over the last 18 months, and Canadian partners who start now can avoid the scramble that caught many U.S. contractors flat-footed. His core advice for partners: start with governance, not dashboards. Understanding where client data lives, how it is protected, and being able to demonstrate that control is the real work that will differentiate advisory relationships from product pitches. Read Full Transcript Robert Dutt: Hello and welcome to In The Channel from ChannelBuzz.ca, bringing news and information to the Canadian IT channel community for the last 16 years. I’m Robert Dutt, editor of ChannelBuzz.ca, and your host for the show. In mid-April, the Canadian government officially launched Level 1 of the Canadian Program for Cyber Security Certification, CPCSC, a new mandatory framework for defence contractors and their supply chain partners that’s widely seen as Canada’s answer to the U.S. CMMC program. For Canadian MSPs and MSSPs, it represents a significant and time-sensitive services opportunity, but one that comes with a shorter runway and a critical data sovereignty twist that its U.S. counterpart never had to address. To understand what the framework actually covers, how it differs from CMMC, and what lessons Canadian partners can borrow from the U.S. rollout, I sat down with Frank Balonis. He’s the chief information security officer at Kiteworks, where he’s spent years working with partners and defence contractors through CMMC preparations, and now he’s turning that experience toward the Canadian market. Let’s get right into it. My chat with Frank Balonis. Frank, thanks for taking the time. I appreciate it. Frank Balonis: Glad I could be here. Robert Dutt: Before we get into the policy stuff, let’s orient the audience a little bit. Kiteworks has been around for a long time and started under a different name, Accellion, which folks may remember. But can you kind of give me the nickel tour of where you’re at and what you do as a company today? Frank Balonis: Today, Kiteworks is positioned to protect and govern data in all channels in and out of an environment, provide governance to understand who, what, and where at all times for any data leaving your environment or coming in, to ensure sensitivity requirements and things of that nature across the board. Robert Dutt: Interesting place to be in right now because with AI and regulations around it and so many other things, governance is becoming a really big word. Frank Balonis: Yes, it is. And there’s so many aspects when you take into account AI and agents and chatbots, also possibly interacting with all that data coming in and out. It’s a bigger and bigger field out there. Robert Dutt: And tell me a little about your role. It’s kind of unusual to have a CISO as a guest voice on the show. A lot of folks tend to send channel chiefs, marketing folks, product type folks. Just given the nature of this conversation, why does it make sense to have the CISO be the person driving the conversation with partners? Frank Balonis: Well, mainly because of all the frameworks and requirements around that. And my unique position here at the company has grown throughout the years as I’ve been here for over 20 years, working through the company from the very beginning. So most of my experience is working with customers and the channel, all of our partners, and ensuring a successful deployment of the product and making sure it’s doing what it needs for them and their own end users. Robert Dutt: Okay. Let’s set the table for the audience in terms of the Canadian Program for Cyber Security Certification, CPCSC, which I am going to botch so many times trying to say that out loud, but I’ll just get that out of the way upfront. Officially launched Level 1 in mid-April. It’s an ongoing process. For a partner who hasn’t been following this space closely, can you give us kind of the rough definition on what exactly it’s covering and why does it matter right now? Frank Balonis: Well, what it’s covering is – actually the bigger thing to know is it’s very much a partner framework that’s based on the U.S. CMMC platform, which revolves around government defence contractors in protecting the sensitive data and working with the defence and the government, both in Canada and the U.S. It’s actually based on the same framework as CMMC. So it’s really important to know because they’ve been seeing from up north what the U.S. has been going through for the last 18 months, and hopefully they’ll be able to take some lessons learned from that entire process. Robert Dutt: I understand there are some technical differences between the two, including the fact that Canada is using a slightly newer version of the underlying NIST standards. How close is the Canadian standard that’s rolling out to the U.S.-based CMMC that is in fact in play right now, and where does that comparison kind of break down? Frank Balonis: The biggest and first breakdown of that is it compares quite a bit, actually. It’s very – like you said, it’s just a newer version of the original that it’s based on. So it’s extremely similar. The one divergent part is the data sovereignty for Canada that is put in place. The CMMC in the U.S. is more about protecting the data. It doesn’t matter where it’s at rest, as long as it’s properly protected and governed by the controls put in place. Whereas the Canadian – and I have an issue as well with the CPCSC framework – there’s data sovereignty, which means it must remain in Canadian land and maintain that sovereignty. Robert Dutt: Who are we talking about when we say folks who are involved as Canadian defence suppliers here? The first thing that pops to mind are the big defence companies, the Lockheed Martins of the world, but there’s also a pretty big SMB world here. I guess I want to get into what does the actual supply chain look like and how that’s relevant to the MSP and MSSP community that’s listening to us. Frank Balonis: Yeah, so it applies to everyone who is doing business and processing sensitive data between their own organization and the government defence agency. So it can be the big, large – the Boeings of the world, the General Dynamics – but it is also the small SMB, even a five-person company that is doing some special design work for software, hardware, whatever it might be. They’re all tied into the same framework. Now, there’s going to be various levels. As you mentioned, Level 1 is in play right now. Level 2 will be later and so on until Level 3, very much similar to CMMC. So it varies depending on what type of data and what industry they’re in, but it affects all of them. Robert Dutt: How do those levels ramp over time? What’s the dividing line between Level 1, Level 2, Level 3? Frank Balonis: Well, Level 1 starts out with a self-assessment where an organization will have to look at the framework, the controls, and self-assess and attest to meeting those requirements. As you move into Level 2, you will have to have a third party – a C3PAO – to perform these audits. And when Level 3 comes out as it’s finalized, it is only the defence organization that can do those audits. And that’s still, as you mentioned, in progress. Robert Dutt: Okay. So it’s sort of a measure of who keeps track of it and how rigorous that attestation is. Got it. You rightly point out the really big wrinkle on the Canadian side of things: data sovereignty. It means you can’t just take Protected B data in Canada and put it on a U.S.-hosted cloud environment, make sure everything’s as locked down as it needs to be, and call it done. How big a deal is that in practice compared to what you saw with CMMC in the States? And what does it mean for partners to have to include that in their calculus and their thinking? Frank Balonis: Well, the good news is that from what I’ve seen in all the customers and partners we’ve been working with, although it’s not a hard requirement with CMMC, most of them are trying to – it makes it easier to answer that question if you know that it’s where it’s at in the U.S. and safe. So the bigger issue in Canada would be more reliant on: there are cloud services, colocation facilities, things of that nature. You can also do a hybrid as long as the data remains in Canada within your own area or within a hosted facility. Of course, there are also concerns of the CLOUD Act and issues in that manner. And that’s why you would need to ensure that you are specifically – these can be addressed with other technologies such as encryption at rest and things of that nature that would protect you from having to worry about that. Robert Dutt: That’s kind of a generally overhanging concern though. It’s not necessarily specific to this particular regulation. It’s an industry-wide thing if I’m not mistaken. Frank Balonis: 100%. I deal with this globally all the time and we work together to provide the right tooling and controls to ensure that you can meet the data sovereignty and you do not have to be concerned about the CLOUD Act. Robert Dutt: That must be a super fun challenge given the array of countries that have various regulations that are going in various directions at various times and the propensity of those to change. Frank Balonis: Yes. That’s why the important part that we always work with our customers and partners on is understanding that – making sure that the customer, the end user itself, that organization has full control of their data by controlling the keys, maintaining awareness and control of where the data is, how it’s stored. It allows them to address any framework or global requirements. Robert Dutt: So let’s take away some of the lessons if we can from CMMC and that experience. You guys have been living with CMMC since the early days of the rollout, working with defence contractors, partners through the whole experience. Looking back, what actually happened in the U.S. market when it landed and became law of the land? Did the partner community step up and help solve the problem? Was it chaos? What did we experience? Frank Balonis: Actually, a little bit of all of the above really. There was a lot of chaos. There’s still a lot of chaos, honestly. As you understand the scope and the breadth of all of the companies that are going to be in focus for both of these frameworks, there’s still a lot to be learned. But there are a number of partners and MSPs that have understood really where to lock in on what these requirements are. At the end of the day, in the U.S., for instance, the CMMC was actually just another enforcement of something that was already required of the contractors with the NIST SP 800-171. They were already required to meet those. CMMC was just a more rigid framework that has to be completed, whether it’s your own self-attestation or third party. So there’s the aspect of that. Once you understand these requirements have already existed and that the main point of this is governance and evidence to prove that you are following these controls – where the organizations focused on that, as opposed to just trying to cover everything, they succeeded in making this a successful program for a number of our customers. And I’ve seen it in how they work with other companies and vendors to do the same thing. So focusing on the governance part is where it needs to happen. Robert Dutt: Any other common threads that you saw among partners who built successful practices around CMMC, or around customers who are subject to CMMC? What did those partners do differently – technical services, different service models, a go-to-market thing, a combination of any of that? Frank Balonis: There was a lot of go-to-market. We see not only with just us as a vendor, but other partner vendors that we have working with our partners to build an entire framework to help meet the needs of CMMC. Technologies like Kiteworks and other security platforms, they can meet a majority of the controls, but there are some areas that it doesn’t make sense or it just doesn’t fit, that they can meet all the controls. So bringing all of those together and understanding the controls and staying focused on those was what drove the success that we’ve seen in putting together an entire ecosystem to properly provide the evidence and the governance over the platform and your environment. Robert Dutt: Okay. Your own data for the CMMC experience shows some pretty sobering numbers – less than half of contractors feel prepared for Level 2 and more than half still haven’t done a gap analysis. I’m curious if you think Canada is tracking along a similar way. Are there any signs that we’re better prepared because folks have been able to sit back and watch the experience in the U.S. and kind of seeing where the mines are in the minefield? Frank Balonis: Yes, I think they’re going to be in a better place as long as you learn from history and are able to move forward. As we see in the close proximity of the two countries, the fact that those two frameworks were actually purposely built off the same framework for that commonality – I’m already working with partners and customers from Canada that need to meet the CMMC requirements. So those organizations already have a leg up because they already have all of these things in place. Now they may have to make adjustments because of the sovereignty rule that we talked about earlier, but it allows them to quickly address these needs. So as long as they’ve been paying attention to the neighbours down south and enacting these things, they’ll have a leg up on where the U.S. was a few years ago with CMMC. The downside is they have a shorter runway to do it because CMMC launched and then they paused and then they launched again with CMMC 2.0 and they built through all of that. Whereas CPCSC is already live and continuing to move forward, and you have to meet requirements as soon as this summer and sooner than later you’re going to have Level 2 requirement and a Level 3 requirement, depending of course where you are and what data you’re working with. So it’s something one has to be on top of fairly quickly if one is affected or working with organizations that are. Robert Dutt: Absolutely. And a lot of the partners – one of us actually earlier working with a partner that is out of Canada to provide services for CMMC – we have these partners that understand exactly how you need to move forward in addressing these things. So as long as the partners have a very good future of being able to help their customers, as long as they’ve been paying attention, they’ll be able to help these organizations that don’t have a compliance person, they’re too small of an organization, they don’t have all of these things in place, and they are going to have to rely on these partners to help them out. I wanted to expand a little bit on what you were talking about with the kind of cross-border opportunity. You flagged it with partners who are in Canada, who today have some experience working with CMMC, they’ve built up some of the muscle memory to deal with CPCSC as it comes online. I imagine somewhere down the road in the not too distant future, by the sounds of it, we’re going to have Canadian partners who are CPCSC certified, who are therefore partially down the road to understanding and being able to solve for CMMC. How much of that – how real is that cross-border bidding opportunity and how should a partner be thinking about positioning that? Frank Balonis: I think there’s a real opportunity there because the partners up north might not have been able to be the third-party auditors for CMMC, but they could be the advisors. As long as they’re working through all of that, they could take their experience from being advisors to their customers to prepare for CMMC and convert that into the ability to actually work with auditors for the CPCSC and help implement that. Where, again, a number of our customers utilize this – since there isn’t that sovereignty requirement with CMMC and there is that natural instinct of an organization that wants to stay completely in control, they already have their data up in Canada, which means they’ve already got a framework in place to meet the CMMC requirements for the U.S. and they can easily convert that to CPCSC very, very easily. So the best advice I could give to an organization is to properly vet and find a partner that has that experience and can quickly work with you to get you up to speed because, as we mentioned, they have a much shorter runway to get there. They can’t start at the beginning. They have to find someone that’s already been doing this for a while. Robert Dutt: If I’m a Canadian MSSP or a security-focused VAR listening to this right now, I’ve got a general security practice. Maybe I’ve been doing some compliance work in regulated industries. Where do I actually start with this? What’s the first conversation I should be having with my clients and what does engagement around CPCSC or CMMC look like in practice? Frank Balonis: It really starts with understanding whether they know where their data is and how that data is being protected. That is the biggest part of all of that. Working with the partner to understand what these requirements look like, where their data is, is the first place that I would really focus on because, again, the most important part is not a dashboard but the governance and the evidence of it and making sure that you control this. Robert Dutt: What’s kind of the best practice guideline, shall we say, for timelines? I imagine because of the nature of this, it’s not the kind of thing you want to be looking at that deadline and planning to slide in right at the deadline to reach compliance. You want to have some runway to make sure that all of your assumptions along the way have been correct, shall we say? Frank Balonis: If I was an organization up in Canada right now, I’d already be looking for a partner to help. Maybe not specifically setting any kind of deadlines other than the fact that you understand certain requirements are going to be in effect this summer. So the sooner you get on this, the faster, the better. So yesterday is the time to start on this, but if you can’t start yesterday, start today. That’s the best advice I could give because there’s always going to be those skeletons in the closet of, “Oh, I forgot about this,” or “Where is that?” As you start walking through the framework with your partners and understanding the controls, you are going to uncover things that you need to address as quickly as possible. Very similar to CMMC, you will have very little room to have any kind of out-of-control controls, so to speak, any findings or nonconformities depending on what framework you’re looking at and what type of audit. The area for margin is very small. Robert Dutt: Along that note, the last one for me: Level 1 is self-assessment, which is relatively accessible, I would think. But Level 2, you’re getting third-party assessments and that clock is ticking toward April 2027. Sort of along the same lines as the last question, but what’s basically your message to the Canadian partner community about the window of opportunity that exists right now? Frank Balonis: I would, for the folks that are going to be required for Level 2, I would do the Level 1 as soon as possible for you to understand where your gaps are. And you can attest to have your controls in place, because when Level 2 comes, the more information you already have by running through your own internal audit, which is effectively what a Level 1 is, the quicker you’ll be able to close those gaps and understand what you need to do before 2027 comes up on you. I personally, we’re working on consolidating a huge number of audits into a single one, and I’m already nervous that we’re three months away and still looking at a few things to complete all of them. We’ve done all of these individually, but we’re bringing them together, and that’s where you start seeing your gaps in between different organizations, different architectures. So the sooner you understand where you are, the sooner you can close those gaps and meet the requirements for Level 2. Robert Dutt: Sound advice. I appreciate it. Thanks for taking the time to walk us through the situation as it is and the opportunity out there for partners. Frank Balonis: My pleasure. I’m glad I could do this today. Robert Dutt: There you have it. Frank Balonis from Kiteworks. I’d like to thank Frank for his time. A couple of things from that conversation that I think are worth sitting with. First, the urgency. Balonis was clear that unlike CMMC, which paused, restarted, and gave the market time to catch its breath, CPCSC is already live and moving toward Level 2 third-party assessments. If you are a Canadian partner waiting for the phone to ring, you are already behind the partners who started this work six months ago. Second, the governance point. The line that stuck with me was that the important part is not a dashboard, but the governance and the evidence of it. In a market that loves to sell tools, the real compliance opportunity is advisory: helping clients understand where their data lives, how it is protected, and being able to demonstrate that control. That is a services play, not a product play. And third, the cross-border angle. Canadian partners who built CMMC advisory muscle with U.S. clients have a head start that is actually hard to replicate. The frameworks share the same foundation, and the sovereignty requirement is a wrinkle, not a wall. The firms that can bridge both sides of the border are going to be the ones that win the long-term compliance relationships. I’d like to thank you as always for listening to the show. Follow or subscribe wherever you get your podcasts – Apple Podcasts, Spotify, YouTube, most directories. Ratings and reviews are always appreciated and always help. Until next time, I’m Robert Dutt for ChannelBuzz.ca, and I’ll see you in the channel.
Merger and acquisition activity within the MSP sector has accelerated, with data cited indicating a 73% year-over-year increase in transactions for 2026 compared to 2025. Jay McBain's reported statistics also highlight strong international momentum, particularly in EMEA, and a marked 800% rise in acquisitions specifically targeting managed security service providers (MSSPs). While the consolidated figures suggest heightened activity in large, visible deals, several participants noted that the true frequency of smaller, unreported transactions likely exceeds official tallies, underlining persistent underrepresentation in sector reporting. According to podcast contributors, small MSP deals often go untracked in industry data, despite anecdotal evidence that hundreds or thousands of such transactions occur annually. Larger deals, such as a $20 million transaction mentioned, receive public acknowledgment, but the majority of M&A activity is conducted without broad disclosure. The consolidation trend among larger entities—exemplified by Charter's $34 billion merger with Cox and ScanSource's $220 million acquisition of MicroAge—has resulted in fewer choices for business clients, though new regional providers are emerging as market gaps appear. Secondary discussions addressed operational and governance topics relevant to MSPs. The adoption and enforcement of AI acceptable use policies (AUPs) was emphasized as an accountability measure for clients whose employees are integrating AI tools into workflows. Additional topics included the stabilization of supply chain pricing by major vendors Dell and HPE, who have committed to 30-day price locks amidst recent volatility, and tactical sales advice regarding quote expiration to manage project timelines and risk exposure. For MSPs and IT leaders, these developments entail both opportunity and risk management considerations. M&A trends point to increased scrutiny and potential market concentration, emphasizing the need for transparency and due diligence in both dealmaking and vendor relationships. The recommended adoption of AI AUPs reflects heightened governance expectations, aiming to mitigate operational and reputational risks. Meanwhile, shifts in vendor pricing policies and resale practices invite closer review of contract terms to ensure financial stability and customer accountability. What if my clients resist change? Question of the Week: What is the best CRM for small MSPs? It depends on the size of the MSP and what you need the CRM to do. Popular options include Zoho, Pipedrive, HubSpot, and Campaign Monitor.Zoho: https://www.zoho.com/Pipedrive: https://www.pipedrive.com/HubSpot: https://www.hubspot.com/Campaign Monitor: https://www.campaignmonitor.com/ I, MSPs & Channel Trends: Is AI replacing the need for MSPs? Discuss M&A activity, AI acceptable-use policies, and supply-chain challenges.M&A Trends: https://www.linkedin.com/posts/jaymcbain_ma-activity-across-managed-services-is-accelerating-share-7490450073336799232-SHiL/ ScanSource to Acquire MicroAge: $220.5M acquisition expands cloud, cybersecurity, data center, and AI services.https://www.scansource.com/about/press-releases/2026/scansource-to-acquire-microage Charter Completes Cox Merger: The $34.5B deal creates a cable and broadband giant serving roughly 37 million customers.https://www.linkedin.com/news/story/charter-completes-cox-merger-creating-cable-giant-7531516/ Dell Matches HPE's 30-Day Price Quote Validity: The change gives partners more pricing stability amid rising memory costs.https://www.crn.com/news/channel-news/2026/hpe-extends-price-quote-validity-to-30-days-partners-cheer-new-pricing-stability Tales from the Field: How do you handle a customer dispute over a $100 item when they threaten legal action? Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Send us Fan MailSaurabh Sandhir, CEO and Co-Founder of Kipling Secure, joins Joey Pinz for a sharp conversation on AI risk, MSP opportunity, and the personal journey from India to Silicon Valley leadership. Saurabh shares how his early exposure to engineering, Atari BASIC, IIT Delhi, Purdue, Juniper, Ericsson, Nokia, and Nuage Networks shaped the way he thinks about technology, business, and leadership.The conversation moves into one of the most important issues facing businesses today: unmanaged AI. Saurabh explains how AI adoption is creating new risks around shadow AI, sensitive data exposure, AI-specific attacks, and misleading content. His message is clear: AI should not be blocked, but it must be governed.For MSPs and MSSPs, Saurabh sees a major opportunity. Kipling Secure helps service providers turn AI risk into a new recurring revenue stream through AI Detection and Response built for multi-tenant MSP workflows.The episode closes with a thoughtful discussion on discipline, identity, humility, and why lasting consistency comes from who you are—not just what you force yourself to do. Top 3 Highlights
Today’s headline news for Canadian IT solution providers: [Blumira]: The company on Tuesday launched Hearth, a vendor-agnostic AI command center that Blumira says can intelligently reason across security tools and services an organization already uses. The platform is available in the Pax8 Marketplace, giving MSPs a unified interface to monitor and respond across multi-vendor environments. Read the announcement on Business Wire [Vistera]: The Vancouver-based company on Tuesday unveiled a professional services platform powered by Vero, a multi-agent orchestration layer that Vistera says brings legal, HR, and finance expertise to Canadian SMBs in British Columbia, Alberta, and Ontario. Every output is reviewed by a senior Canadian-qualified professional before delivery, with outcomes priced at $700 each or through monthly plans. Learn more on Vistera [CrowdStrike]: Justin Bradley, senior alliances manager for MSSP aggregators at CrowdStrike, warned attendees at XChange August this week that the group behind Akira ransomware — referred to as Punk Spider — has increased attacks by 134 percent over the past year, specifically targeting SMBs through MSPs. The group buys VPN credentials on the dark web, uses MFA fatigue to gain access, and dumps Entra IDs before deploying ransomware. Read more on CRN [ConnectSecure]: The company on Tuesday added M365 Auto Remediation, AI-powered training assessments, and Patch 360 to its MSP platform, allowing providers to automatically remediate supported Microsoft 365 security findings across multiple tenants. Read more on Channel Dive [GTIA]: The Global Technology Industry Association warned at ChannelCon last week that customers are deploying AI faster than MSPs can deliver security and governance, and announced a new Managed Intelligence Alliance to develop standards and accreditations for AI services. Read more on Channel Dive [NetRise]: The company on August 3 launched its Discovery Partner Program to expand software supply chain security through MSSPs, VARs, and distributors. Read the announcement on PR Newswire [Verizon]: Channel chief and vice president of indirect partner sales Mark Tina is leaving the telecommunications company after 23 years to become vice president of national partner sales and distribution at health insurer Humana. Read more on Channel Dive Read Full Transcript Welcome to The Buzz from ChannelBuzz.ca, I’m Robert Dutt, today is Thursday, August 13, and here’s what’s happening in the channel today. Blumira on Tuesday launched Hearth, a vendor-agnostic AI command center that the company says can intelligently reason across security tools and services an organization already uses. According to Blumira, the platform is designed to unify visibility and response across the workspace without requiring a rip-and-replace approach, giving lean IT teams a single interface to monitor disparate tools. Hearth is available in the Pax8 Marketplace, positioning it for MSPs that provision through that platform. Blumira is pitching the offering as a way to reduce tool sprawl and alert fatigue for teams that lack enterprise-scale resources. A unified reasoning layer across multi-vendor stacks could cut down on the context-switching that slows incident response for Canadian MSPs, though the value will depend on integration depth and the accuracy of the AI-driven reasoning. Vistera on Tuesday unveiled a Canadian-built professional services platform powered by Vero, a multi-agent orchestration layer that the company says brings legal, HR, and finance expertise to small and medium-sized businesses at a predictable cost. The Vancouver-based company is targeting Canadian SMBs in British Columbia, Alberta, and Ontario with outcomes priced at $700 each or through monthly plans, a fraction of the typical hourly rates at large firms. According to Vistera, every output is reviewed and signed off by a senior Canadian-qualified professional before it reaches the client, with credential verification and regulatory standing checks built into the workflow. The platform handles intake, research, and preparation through AI agents while preserving human oversight for final judgment. Canadian MSPs should watch how this model lands, as it could create new partnership opportunities around SMB advisory services or introduce competitive pressure in the professional services space. CrowdStrike this week warned attendees at XChange August that prolific ransomware groups are specifically targeting MSPs and their SMB customers. According to Justin Bradley, senior alliances manager for MSSP aggregators at CrowdStrike, the group behind Akira ransomware — referred to as Punk Spider — has increased its attacks by 134 percent over the past year with an emphasis on SMBs. Bradley said the group’s typical strategy involves buying VPN credentials on the dark web, then using MFA fatigue to gain initial access, escalating privileges, and dumping Entra IDs before deploying ransomware. He also noted that CrowdStrike is tracking two break-off groups from Scattered Spider, dubbed Cordial Spider and Snarky Spider, which have been known to impersonate MSPs to trick customers into launching remote access tools. The intelligence underscores the urgency for Canadian MSPs to harden identity controls and monitor for MFA abuse, particularly as credential theft continues to fetch thousands of dollars on dark web markets. In Brief – ConnectSecure says its new M365 Auto Remediation tool lets MSPs approve and automatically apply fixes across multiple customers for supported Microsoft 365 security findings. The Global Technology Industry Association warns at ChannelCon that customers are deploying AI faster than MSPs can secure it, and says it is launching a Managed Intelligence Alliance to set standards for AI services. NetRise says its new Discovery Partner Program will expand software supply chain security through MSSPs, VARs, and distributors. Verizon confirms channel chief Mark Tina is leaving after 23 years to become vice president of national partner sales and distribution at Humana. Full details and links in the show notes or the blog post. That’s how we’re seeing the headlines today. I’m Robert Dutt for ChannelBuzz.ca, thanks for listening. Have a great day.
Craig Patterson, global channel chief at Exabeam For years, SIEM has been one of those technologies that looked good in theory but was genuinely hard to build a profitable managed service around. Deal-by-deal discount negotiations, licensing structures built for enterprise resale rather than recurring managed services revenue, and no predictable floor on margin. For many MSPs, the math just never worked. Exabeam – the combined company formed from the merger of the original Exabeam and LogRhythm – is making a direct play to change that. Global channel chief Craig Patterson and senior director of service provider alliances Peter Stratis join In The Channel to walk through the new MSSP commercial framework inside the recently launched APEX Partner Program. Two new licensing pathways: a single-pool capacity model for high-volume, multi-tenant environments serving SMB and mid-market clients, and a federated subscription model that isolates customer environments for compliance and data sovereignty requirements. For Canadian MSSPs navigating PIPEDA, OSFI E-21, or Protected B, that second model is the one to pay close attention to. Peter Stratis, senior directof of server provider alliances at Exabeam The conversation also covers Sherpa, Exabeam’s new AI-powered partner enablement platform – a move away from the traditional LMS toward an always-on coaching tool that can join partner sales calls in real time – and Agent Behavior Analytics, Exabeam’s new capability for detecting malfunctioning, misaligned, and subverted AI agents inside customer environments, included at no additional cost. The standout line from Peter Stratis – who called this his first-ever podcast appearance – is the one worth writing down: “We treated our service providers like resellers, unfortunately.” The new framework is a direct acknowledgment of that history, and an attempt to rebuild the commercial relationship from the ground up. Read Full Transcript Robert Dutt: Hello and welcome to In The Channel from ChannelBuzz.ca, bringing news and information to the Canadian IT channel community for the last 16 years. I’m Robert Dutt, editor of ChannelBuzz.ca and your host for the show. If you’ve been in the channel for any length of time, you know that SIEM has always been one of those technologies that seems great in theory but has been genuinely hard to build a profitable managed service around. Licensing models that weren’t built for multi-tenancy, unpredictable costs, discount structures that made margin planning more of a guessing game than a business model. A lot of MSPs have looked at the security operations space and quietly backed away for exactly those reasons. Exabeam, the combined company that emerged out of the merger of Exabeam and LogRhythm, is making a direct play to change that. They have overhauled their channel program into what they’re calling the APEX Partner Program and at the centre of it is a new commercial framework built specifically for managed security service providers. Two distinct pathways: one for high-volume multi-tenant environments and one built with compliance and data sovereignty in mind. For Canadian MSPs navigating PIPEDA, OSFI E-21 and Protected B requirements, that second lane is worth paying close attention to. I’ve got two Exabeam executives here to walk us through it. Craig Patterson is Exabeam’s global channel chief and Peter Stratis is the senior director of service provider alliances, the person who’s been working directly with MSSPs to build this out from the ground up. Let’s get right into it. My chat with Craig Patterson and Peter Stratis. Gentlemen, thank you for taking the time. Craig Patterson: Thank you, Robert. Super excited to be on here with you today, my friend. Peter Stratis: Thank you. Robert Dutt: Craig, can you just kick us off with a quick version of where Exabeam sits right now? You know, you guys went through a significant merger with LogRhythm not that long ago. Now you’re pushing an updated partner program. For solution providers who maybe haven’t been following closely, what does the combined company look like from a channel perspective? Craig Patterson: The short answer, my friend, is that we’re sitting in an amazing place. We’re absolutely in a good place positioning to really drive value to our partner community. And so to give you a little more context around that, like you asked, we’ve spent the last 12 months really kind of rethinking, reimagining the whole partner ecosystem in a way to create value for all of our partners globally. And so there was a number of things we went through over the last 12 months. We spent a lot of time really going to this assessment loop, understanding everybody’s perspective. So we did that by having very strategic conversations with our top-tier partners. We did some survey work. We looked at the broad landscape in terms of the trends that the partners are really looking for in these modern channel programs. So all of that really became this assessment loop. The output of that is that really became the foundation for what we built here with APEX. And so with APEX, the Exabeam APEX Partner Program, what you have here is you have a program that’s really centered on value that’s really focused on solving a problem that exists in our market today around enablement. And so when you think about enablement today, I’ve written a lot of articles on this. Most enablement programs really don’t drive to the level of outcome that companies are looking to have. Outcomes like conversion rates, outcomes like time to first deal, outcome rates like retention rates, all these things. And so what we’ve done is we’ve really focused on enablement as the key catalyst to really drive value to our partners. And so with that, we’ve launched new enablement programs really with a focus on increasing their competency level so we can align to those outcomes we’re looking to have with our company’s operating plan. And so there’s a lot of thought that’s got into this. The short answer is we have a program that’s built on value. It aligns to where the market is going and what partners are really asking for. Robert Dutt: Peter, your title as senior director of service provider alliances is a pretty specific role. Can you tell us a little bit about what that looks like sort of on a day-to-day basis and the big problems that you’re focused on? Peter Stratis: Sure thing. Thanks, Robert. Well, I’ve been with Exabeam for about eight years now and service providers have always been a key component of not only our channel strategy, but our go-to-market and just from our net new revenue perspective. After our merger with LogRhythm, that actually continues and if anything, it’s only been more emphasized because both from an on-prem and from a cloud perspective, we see the MSSPs being a strong driver of that strategy of our go-to-market. So over the last eight years, we’ve seen that trend of not only on net new revenue, net new logos being a major part of our business, but then how do, to Craig’s point, how do we support them? To be quite honest, in the past, it was quite difficult. We really didn’t have any kind of structured pricing for these partners. It was, to say the least, it was more of a resale program that had some discounts tied to it. So through Craig’s efforts, through our whole surveys and our intent to really go after this market and treat them the way they should be treated, he mentioned that we did these surveys. We asked internally, what do you look for in a service provider partner? We asked externally what these partners were looking for from us. And that’s when in building the APEX Partner Program here at Exabeam, we also took into account what service providers would look for in a new partner program. So that’s everything from pricing to support. Craig mentioned enablement. Enablement is a huge part of that, where they felt in the past they were just lumped up as just a regular partner. Now we have supported APIs, documented APIs that most, if not all, of our partners are using as part of their foundation for their services. So we’ve really come a long way and continue actually to build upon that, as you’ll see throughout 2026 and beyond. Robert Dutt: Okay, let’s get into the framework itself. You guys positioned it at launch as solving commercial and operational friction for MSSPs. Curious, what did you hear that friction looked like in practice? What were MSSPs telling you was broken or was a big challenge? Craig Patterson: Yeah, so I’ll take a stab at this and I’ll let Peter give more context. So a lot of this came out during that assessment phase. Robert, we’re talking to the MSSPs globally. I’m like, what’s working? What’s not working? What would they like to see incorporated into the MSSP program 2.0? So a lot of the feedback we heard was really around the flexibility. Being able to have a license that is catering to all the customer demand they have beneath. So it’s really giving them the flexibility to buy that one license and carve it up as they see fit. And giving them more flexibility on the commercial terms. That was a lot of the commentary we heard. The other thing we heard was really they wanted more value as it leads to the enablement side. So obviously getting them enabled on the pre-sales side, but more importantly on the post-sales side. So they could actually drive those implementations, drive the management and really help those customers create a lot of value. And so I think those were kind of the big levers that I heard from those assessments. And then in practice, Peter can give you some more context in terms of how we’re putting all this together. Peter Stratis: Yeah, thanks Craig. A lot of what we heard from the service provider community in the past was friction. So when they’re trying to price out their services and our product and etc., they were seeing friction at onboarding. They were seeing friction in trying to predict their margin on deals. As mentioned, not airing any dirty laundry here. It was more like a resale program. So we gave discounts and there were very opportunistic discounts on a deal-by-deal basis. So they didn’t build predictable service models around it in the past. And then you always hear the buzzword, multi-tenancy. We kept on getting asked about our multi-tenant roadmaps, etc. We’re looking at this framework as a way of solving for that. We continue to make feature enhancements into the platform that will strive for that multi-tenancy. But the way we’re solving for it is by these two pathways. One is that single license, pooled capacity, data segregation model. And the other is that federated workflow that we announced where it’s more for, whether you’re within data sovereignty, if in different regions or just different use cases from a compliance perspective, whether it’s healthcare or finance, and you have to keep these environments isolated. We have a plan and we worked with our MSSPs specifically to have these kind of pathways. So we heard from our MSSPs and we actually developed these two pathways with them in mind. So they were in the design phase and in the rollout phase for both federated and the single pool capacity. Robert Dutt: The federated model is such an interesting one, I think, for the Canadian market, specifically data sovereignty, huge topic. And there are specific compliance requirements, PIPEDA, OSFI E-21, Protected B status. It means that a lot of Canadian MSSPs can’t just kind of throw everything into one pool. Was that the sort of thing that was explicitly on the radar when you built this out or a happy coincidence of the architecture and the feedback that you heard along the way? Peter Stratis: It’s actually a little of both, right? So it just so happened to be the maturity of our platform. Even from our Exabeam New Scale platform, we went from an on-prem hardware appliance way back in 2012, to our version 1.0 was a SaaS product, to our native cloud. It was always a single-tenant solution. So it worked well for certain service providers that had the capacity. They had their APIs and their own platforms that could manage this solution. As you heard more and more about multi-tenancy and the need for data sovereignty and all that, we still had a big part of our MSSPs were asking for this single license pooled capacity. So we structured it in a way where for midsize organizations or even some small, medium business, you still have that single pool capacity using data segregation. You lose some of the customization, but you could actually solve for a lot of those customers in that model. And then you have another plan with the federated. So the more mature MSSPs are running both models in some capacity. They could still run that single license for their SMB play. And then for either large enterprise or very compliance-driven customers that want those isolated environments, they have that flexibility. And that’s what we built a framework around. Obviously, that’s one point of feedback that sort of directly informed the framework. Robert Dutt: You guys have said that this whole thing was built, as you said, with direct collaboration with your MSSP partners rather than kind of coming down on high. I’m curious along with what you’ve touched on already, what actually changed as a result of going through that process? What did you go in thinking you’d build and how did it come out differently because of what partners told you along the way to building it? Craig Patterson: Yeah. So I think there’s a lot of things that have been addressed. Obviously, the packaging and the commercial aspects as Peter was describing, but think about some of the fundamental problems in terms of partners want this path to profitability, right? Really understanding how they can create margin. That was one thing. Another path is like, how do I become enabled with Exabeam? And how do I stay informed in terms of where you’re going? Another problem we wanted to solve. So I think it’s a lot around the financial aspects of doing business with us. A lot of it’s around becoming enabled, becoming more knowledgeable on all the new features and releases that we’re dropping. And so those were some of the big fundamentals that we wanted to solve in the APEX framework. And then beneath that, obviously, is the whole MSSP play. And that’s what Peter’s been talking about. So you can probably give a little more context on that. Peter Stratis: Yeah. As mentioned, there is no one-size-fits-all. So the feedback we were getting was obviously their security platform was important to them. Some of them had an in-house platform they built on their own. And there’s ways of differentiating. So basic SIEMs are just going after alert monitoring. So how can I differentiate my service if I’m a service provider? Well, there’s ways of going to market, but also there were things we needed to do in the back office from a platform perspective to make those possible. So making our behavioral analytics available in these models so they can actually differentiate their services. As I said, we have a history of actually adding features quarter-over-quarter, month-over-month. So that’s not stopping. We didn’t announce necessarily multi-tenancy to the world. We announced a commercial framework for that. So you’ll continue to see on a month-to-month, quarter-over-quarter basis, features added to support not only the commercial framework, but the underlying platform to make it easier for service providers to add that operational efficiency, to add those differentiators from a product portfolio as well. Robert Dutt: Let’s talk about the economics underneath there. You use the term predictable margins as a phrase that shows up in the messaging. SIEM has historically been a tough service to make money on. Licensing models that didn’t fit the managed services motion, unpredictable costs on data ingestion, those sorts of things. What specifically changes for an MSSP’s P&L under the framework? Craig Patterson: Yeah. So I think there’s really two components here. The first is the whole financial package associated to the MSSP partners. And the second is the discounting framework. And so let’s maybe start with the discounting framework. One of the observations that we made during this whole assessment phase was the vast majority, Robert, of all of our deals were flowing through this non-standard process, which means the discounts that were aligned to the traditional framework were not putting the MSSP partners in a position to actually transact. And so what we did is we went through and we re-looked at the discounting framework and sort of realigned it based upon our actual data points. We looked at the last 12, 24 months, the discounts that were being derived to actually transact. And we sort of rebuilt the entire discounting framework for our company in a way that really empowers the MSSP partners now to have enough discount to actually transact without going to this non-standard queue. So what does it mean? Well, we really kind of flipped the script. Instead of 80% being non-standard, we believe 80% will flow through the standard process now because we’ve built the discounts in a way to align with what the market is looking for. That’s kind of the key component number one. And then as it relates to the discounting side, we reimagined how those discounts are calculated. And so now you kind of have your standard program discount. So that’s based upon your tier. So top-tier MSSP partners get the highest level discount. The second is deal registration. Obviously, they put the deal reg in that ties to a discount. Those are both standard common things. But what’s new, which is what you care about. What is new? Well, we’ve aligned the third discount based to their competency level. And so we measure that based upon certifications. And so if you think back to those choose-your-own-adventure books as a kid, we’re really giving the partners their own choose-your-own-adventure. And if they want to drive to the highest level discount, well, simply, MSSP partners got to go take all of our certifications, pre-sales and post-sales, so they have the highest level of competency to drive our services in the market. And our thesis around that is partners that have higher certifications, they’re going to be more active, they’re going to be more interested, they’re going to drive more pipeline. And if we do this the right way, Robert, they’re actually going to convert at a higher percentage, we’re going to see shortened sales cycles, all of which align to the operating plan of our company. So it’s kind of those two fundamental things that were addressed through that process. And then I’m sure Peter can fill in the detail for you. Peter Stratis: Yeah, if I can actually elaborate on that. Thanks for that, Craig. And just some historical context, Robert, as mentioned in the past, we treated our service providers like resellers, unfortunately, so it was very deal-specific in terms of what they were getting on a deal-by-deal basis from a discount. So the economics of it was they really couldn’t rationalize their margin predictability on an overall services basis. And you know, different regions go to market different ways. In Europe, Asia, Latin America, predominantly, it’s all SIEM as a service and MSSP owns the license. In the Americas, both US and Canada, we saw a lot of proliferation in the past of customer-owned licenses. So the MSSP would resell the license, and consequently, just provide managed services wrap on top of that. Not only do we see more of that MSSP-owned model now where it’s SIEM as a service in the US and Canada. So it’s proliferated itself throughout all the regions. Now with these frameworks, we actually are able to build these economics, the margin predictability, as Craig mentioned, because now they know as a standard, what they’re going to be selling for. So especially as we do this federated model, and even the single license, you know what your price is across the board, you know what license you’re buying, you know what price you’re buying it for, you know, the more customers you add to these models, the more your profitability will increase as well. So it continues to grow from a pure profit play. Partners want to know what their margin would be as their customer licenses grow. And this is exactly what the framework did. Robert Dutt: This is sort of a broader question around MSP/MSSP distinctions as opposed to directly about the framework. But there’s a distinction worth drawing between an MSP trying to bolt a security practice onto the existing managed services business and the established MSSP who’s been at this for a year or who has built it up. Are those two different conversations for you? And if so, what are the different entry points and care-abouts? Peter Stratis: So it’s interesting, not only because of this announcement, even prior to it, the announcement of the APEX Partner Program here at Exabeam caused a lot of interest from partners and different kinds of partners. The traditional MSP, when inquiring, it was kind of hard when we were vetting them that they had no security practice of their own. So oftentimes they would actually outsource that security to an MSSP, to a classic MSSP, or maybe just resell services from those other organizations. We see that, we see a lot of interest from MSPs with that. And we see VARs or resellers come to us that want to build managed service practices as well. So we look at both of these in two different ways. One, how can we take care of these partner inquiries now, and then how can we grow with these organizations? So both MSPs and resellers that are interested in managed services now, our first inkling is to try to introduce them to our current managed service base. These people have the experience, they have the certifications, they have the technical knowledge. We’ve seen that move from a lot of MSP partners actually having channels of their own. So they actually sell their MDR or MSSP services through a channel of resellers or MSPs. But then if that’s our first step with these type of partnerships, then it’s like, how can we grow within your organization? How can we help you get the technical skills required? Because for a true MSP to have success, not only in SIEM, but just security as a service, you can’t just train one or two people, you need the 24-by-7 support, you need the tier one and tier two level of support services as well. So you have to grow your organization or outsource it to people that are already prepared to handle that. So that MSP play, we actually see it more and more going towards our current managed security service providers and getting that as a resource. Craig Patterson: Just to add a little more context to that too. So this actually becomes a very interesting point for the distributors worldwide as well. Because a lot of what they provide in terms of value is helping those MSPs in terms of deployment and management of the services. And so we’ve gone through the vetting process globally, looking at all of our distributors and we’ve handpicked our strategic distributors around the world. So if we have MSPs that want to come into the program, but they’re not ready on that post-sale side, well, guess what? That can become the role of the distributor. And secondarily, this is where the enablement really comes into play as well. And so that’s why we’ve built very specific paths on enablement, pre-sales and post-sales, where partners can choose their own adventure. “Hey, if I want to get going on the pre-sale side, well, guess what? I can simply resell.” Or, “Hey, I want to really start focusing on the post-sales services implementation.” I can start to take the enablement around those courses to become more of an expert to really give me those new capabilities. And so there’s a whole conversation around what we’re doing on enablement with our brand new Sherpa that’s really given a lot of these partners those capabilities. Robert Dutt: On the note of Sherpa, an AI-powered tool for partners, it’s essentially a virtual channel account manager in terms of enablement, onboarding, that sort of thing, especially for an MSSP who’s new to SIEM. How does it change the friction of getting started with Exabeam as their platform? Craig Patterson: You’re going to love this. You’re going to love this. So we’ve sort of reimagined all of the enablement. Again, when you look at traditional enablement, it’s like most enablement is built in these LMS platforms. Like, “Hey, partner, go log on to this LMS platform, get your certification, and then we expect you to actually know what the hell you’re doing.” Reality is that’s not what happens. They log on to the LMS platforms. They fast-forward as quickly as they can to the end. They turn the volume down. And then when the quiz comes, they use AI to answer the questions. And so they just find a way to get the certification. The reality is none of that helps them be better in life or actually raise their competency. And so that’s a problem we took on head-on with Sherpa. And so Sherpa was built in a way to really change the way partners learn with the whole goal of raising their competency level so they can be better on the market. And there was really like three use cases we were trying to solve with the emergence of Sherpa. The first is like you think about this global ecosystem that Peter and I have. We have 3000 partners. The partner ecosystem looks different. We have VARs. We have MSPs. We have MSSPs. We have distributors. We have the trusted advisor market as well. All of them have different needs in terms of where they are from a learning perspective. And so the first use case, Robert, is simply like a tool to be able to ask questions. What are the use cases? How do I position this? Why is SIEM or UEBA better than the competition? Just an always-on tool for partners to ask questions. And so that was kind of use case one. And then the cool thing around that is you think about the ecosystem being very global in nature. The other problem with LMS platforms is I’ve got partners in Japan. Well, that means the LMS platform they log on to needs to be able to talk to them in Japanese. And so the beauty with Sherpa, it does all the translation for us. And we’ve got 15 plus languages that are now live in Sherpa. Partners in Japan are talking to it. We got partners in India and all over the world really asking questions in terms of how we position our services. And that integration can be done by just logging on to our portal. You’ll see a bot pop up. They can just simply ask a question. It integrates in Teams, integrates in Slack. So that was use case number one. Use case number two was we reimagined the whole enablement certification platform. And so it’s a very dynamic learning experience. And so the way it happens is you log on, there’s a topic that you like, you click on that, you start learning, it asks you questions, it asks you to position services, and then you record your answer to how you’re actually positioning those services or the features. And it gives you feedback like, “Robert, you did really good on this aspect, but next time you should use this and this.” Or, “Robert, if you’re talking to a customer that’s in this vertical, you should talk about this use case because that’ll help resonate.” And so the whole certification process has been rebuilt and that’s the second use case. The third use case, this is a game changer. And this really goes to your question. And it’s an always-on coach. And so partners are now able to invite Sherpa to calls. And so as they’re having those conversations with customers, and the customer may say something or give them an objection, well, in the background, Sherpa will give them the answer to that objection and say, “Customer said this, talk to them about this.” Or, “Have you shared this new feature that was just released in the quarterly launch?” So it’s like this always-on coach, always-on assistant to really give them what they need. And then we’re putting it on this innovation roadmap. And so every single quarter, we’re launching new innovation in Sherpa. As an example, we’re now launching our LinkedIn integration. So if you’re an MSSP partner, you log on to Sherpa, you’re connected to LinkedIn, it’s going to ask you, if Sherpa can look through your network to find customers that may be a good fit for our services. And then it’ll say, “Okay, great. We found these contacts. Should we go ahead and write the campaign? Should we write a campaign that you can use to send to those customers in your ecosystem on LinkedIn?” And so quite honestly, I think we’re bleeding edge in terms of really being able to use AI and adopt AI in a way to drive good outcomes, well beyond where most companies are with their simple ChatGPT things like that. We’re actually driving outcomes. Robert Dutt: The rise of AI baked into the partner program and partner tools is a fascinating space for me to watch. And that certainly, you make a compelling case for the role of Sherpa there. That sounds really interesting. A quick one on the product side, not directly related here, but just out of curiosity, Exabeam just dropped Agent Behavior Analytics in your April release, sort of extending behavioral detection to AI agents, ChatGPT usage, Copilot activity, those kinds of things. For an MSSP looking to take this to market as a service, is it a new revenue line? Is it an upsell? Or is this sort of becoming table stakes that clients expect to see bundled into what you’re doing for them? Craig Patterson: I’m glad you asked. It was just recently at RSA, the conference, obviously AI is the buzzword, but what do you do with that? When we presented the agentic behavior analytics to a lot of our partners or potential new customers, the question that was often asked was, “Well, how much is this extra?” And that’s not how we license our product. So the behavior analytics has been part of our solution since our inception from our analytics model. So specific to AI, this is going to be, you could differentiate your service from other service providers by using this behavior analytics, but by no means is it an extra cost on the MSSP’s behalf. So they’re going into an organization that has a thousand users, human entities, and overnight they now have 10,000 non-human entities. We look at and model all of them using our analytics. So now you actually have at least a basis of what’s normal from a behavior standpoint for both non-human and human entities. So we really change the game, but haven’t changed the pricing along with it. So it comes naturally within our platform. So no change for me as a partner, but if I can find a way to upsell based on it, all the better. If not, I add additional features. Hopefully my customer is more happy. Peter Stratis: I was just going to say, if you look at the macro trends we’re seeing, this is the number one conversation that’s being had right now, especially like you look at the financial sector. Every single company is facing this problem. And so this really, not only does it give them a new use case to go after, I think it just makes the overall security services of Exabeam more relevant based upon what’s happening in the overall market, which all that makes the revenue stickier, makes those conversations more impactful that those MSSP partners are having. Craig Patterson: Yeah. Well, what I’m going to mention is operational efficiency and service differentiation is what’s key to our MSSPs and their success. So the license is foundational. And now that we’ve actually solved for being predictable from a margin perspective, how can they differentiate themselves, making them operationally efficient using automation, using our threat detection, and then also the service differentiation. And the other thing too, just thinking through this a little bit, I mean, there’s different AI agents that exist out there that are doing different things. You think about the malfunctioning agent, the one that’s just off base and it’s doing things that are just incorrect based upon the fundamentals or foundation of the AI agent. That’s one thing that gets addressed by looking at the abnormal behavior. The second is the misaligned agent, the ones that are pursuing goals in a way that could negatively impact the company. And that gets a little bit more scary. But really what gets scary is those subverted agents, the ones that have been hijacked that are actually causing harm. And so you think about all those different use cases that are happening, and that’s the beauty of what we just released is our new ABA, sort of creating this new category in the market. That’s really what our ABA is looking for, is all those different things that are happening, whether it’s misused, misaligned, or subverted. All that can be detected through this new agent behavior. Robert Dutt: Okay, last question for me. If I’m an MSP who’s been sitting on the sidelines, I’ve been thinking about them or are upgrading my security operations practice. What’s one thing that you wish I understood about the opportunity and the economics, but I probably don’t at this point? Peter Stratis: It’s all about how they actually start off. They’re interested in selling managed security, but they don’t know that they have to standardize their delivery model. They can’t make it where every customer is custom, because that’s when that price predictability goes away. So everything from onboarding to customizing your offering has to go away. You might be able to do it for a certain amount of customers, but you have to build a model that’s repeatable. Automation is going to be very important to that. And then finally, you could add optional add-ons, but you have to resist the temptation to over-customize everything. The great thing about what Craig has done with the APEX Partner Program and the way we built it out here at Exabeam is it supports all of this through all the enablement efforts. So Craig mentioned all the enablement built into the program, but then we have certification tracks. So we’ll help you along in that process. And we have everything from APIs and the use case and the scripts to help you automate that track for you to make it easier, but just don’t jump in and try to do a custom solution for each customer. Robert Dutt: Gentlemen, I thank you very much for your time. Once again, I appreciate your walking us through the commercial framework. Craig Patterson: Thank you, Robert. Appreciate it. Peter Stratis: Thank you, Robert. Robert Dutt: There you have it. Craig Patterson and Peter Stratis from Exabeam. I’d like to thank Craig and Peter for their time today. And a special note, this was Peter’s first podcast appearance. You never would have known it. A few things I’ll leave you with. First, if Peter’s candid admission landed for you — that Exabeam used to treat service providers like resellers with opportunistic deal-by-deal discounts that made it impossible to build a predictable margin — sit with that for a moment. Not unique to Exabeam. That was the industry. And it goes a long way to explaining why so many MSPs have struggled to make managed SIEM work as a business. The new framework is a direct attempt to fix that math. Two pathways: a single-pool capacity model that works well for SMB and mid-market clients, and a federated model that isolates environments for compliance-heavy customers. The discounting structure has been rebuilt from the data up with the goal of moving 80% of deals through a standard process. Up from what Craig described as the opposite of that. The Sherpa AI tool is worth watching closely, not just as a training platform replacement, but as an always-on coach that can actually sit in on partner sales calls and surface real-time objection handling. The LinkedIn integration is coming next, and it starts looking less like an LMS and more like a business development tool. And the closing advice I’ll leave you with is Peter’s. If you’re an MSP thinking about entering the security space, standardize your delivery model before you take on your first customer. Resist the urge to customize every environment. That’s exactly where price predictability and profitability goes away. Thanks as always for listening. In The Channel is available on Apple Podcasts, Spotify, YouTube, and all the major podcast directories. If you’re finding value in the show, leave a rating or review. It goes a long way to helping other folks in the channel find us. Until next time, I’m Robert Dutt for ChannelBuzz.ca, and I’ll see you in the channel.
By Doug Green “It was an ecosystem experience that I hadn't seen in a while.” CloudFest Americas is returning to Miami with a broader mission: bring together the cloud, hosting, domain, MSP and corporate IT communities in one place—and make the experience feel less like a conventional trade show and more like a working industry festival. In this Technology Reseller News podcast, recorded at GTIA ChannelCon 2026, Anthony Pombal of CloudFest and Mark Crall of MSP Global preview CloudFest Americas, scheduled for November 11–12 at Ice Palace Studios in Miami. The event is expected to attract approximately 2,000 attendees from North America and Latin America. CloudFest Americas is derived from the long-running CloudFest event held at Europa-Park in Germany. Its audience includes cloud service providers, web agencies, hosting companies, MSPs, MSSPs, software and hardware vendors, corporate IT teams and other organizations looking for alternatives to the largest hyperscale platforms. Pombal says the event is particularly relevant for companies seeking new products, services, partners and routes to market. Exhibitors can reach what he describes as the alternative cloud service provider market, along with web developers, hosting providers, managed service providers and businesses evaluating new infrastructure and software options. The event is also co-located with NamesCon, creating a point of convergence between the cloud, hosting and domain-name communities. That overlap reflects a broader shift in the market as MSPs, hosting companies and cloud providers increasingly compete, partner and build services across what were once separate technology categories. Crall says his experience at MSP Global in Barcelona demonstrated the value of bringing those communities together in a vendor-agnostic setting. Rather than focusing only on product pitches, the event combined technology education, thought leadership, lessons from industry practitioners and informal community building. “To see that happen in an agnostic environment and actually learn something at the same time while having fun is kind of cool,” Crall says. CloudFest Americas is designed around that same model. In addition to its exhibit floor and conference content, the Miami event will include a server-throwing competition, a domain auction, giveaways and locally inspired activities in the Wynwood arts district, including a live mural created by a graffiti artist. The program will also feature forward-looking content and smaller community discussions. A new area called the Florida Room is planned as a birds-of-a-feather-style forum where groups can exchange ideas, discuss operating challenges and share practical lessons without turning every session into a sales presentation. For technology resellers and MSPs, the event offers an opportunity to look beyond familiar vendor ecosystems. The convergence of cloud infrastructure, managed services, cybersecurity, software, hosting and domain technologies is creating new partnership and recurring-revenue possibilities for channel companies willing to explore adjacent markets. Watch the podcast to learn how CloudFest Americas is building a cross-market community for cloud providers, MSPs, hosting companies, technology vendors and corporate IT leaders—and why Miami may become an important November meeting point for the wider channel ecosystem. Event details: CloudFest Americas, November 11–12, Ice Palace Studios, Miami.
Today’s headline news for Canadian IT solution providers: TD SYNNEX appoints Chris Fabes as President of Canada: TD SYNNEX announced today that Chris Fabes has been appointed President of Canada, with responsibility for driving the company’s distribution strategy and accelerating customer growth across the Canadian market. Fabes brings more than two decades of IT channel leadership, most recently from SHI where he led a multi-year strategic growth initiative across Canada, and previously from Lenovo where he served as Canadian channel chief and helped triple channel revenue to more than $1.2 billion. He succeeds Mitchell Martin, who retired earlier this year after more than 36 years with the company. Huntress warns of massive Azure CLI password spray attacks: A new Huntress report published Monday warns that threat actors have been running massive password spray attacks against Microsoft Azure Command Line Interface accounts, making more than 81 million attempts between June 12 and June 26, 2026. According to Huntress, attackers are exploiting a loophole in Azure CLI that does not support multifactor authentication, allowing them to target service accounts and non-human identities that are often poorly monitored. Huntress has reported the issue to Microsoft. MSSPs face employee retention problem driven by invisible work, says Guardz: MSSPs are facing a significant employee retention challenge driven by what the report calls “invisible work” – security analysts spending hours on manual data correlation and reporting that customers never see. Guardz, in announcing a new agentic reporting capability, said the problem is burning out analysts who feel their work lacks visible impact. The new tool uses an AI agent to automatically turn blocked threats and client risk data into formatted reports that MSPs can present to SMB customers. ManageEngine launches developer marketplace: ManageEngine has launched a developer marketplace for integrations, extensions, and AI agents across its IT management platforms. The marketplace is designed to allow partner-developers, independent software vendors, and customers to build and distribute add-ons. GAM Tech ranks No. 97 on 2026 MSP 501, No. 1 in Western Canada: GAM Tech has climbed to No. 97 globally on the 2026 MSP 501 and ranks No. 1 in Western Canada, according to the company. The MSP 501 list recognizes managed service providers based on metrics including recurring revenue, profit margin, and operational efficiency. Read Full Transcript Welcome to The Buzz from ChannelBuzz.ca, I’m Robert Dutt, today is Tuesday, July 21, 2026, and here’s what’s happening in the channel today. TD SYNNEX has appointed Chris Fabes as President of Canada, filling the role left by Mitchell Martin who retired earlier this year after more than thirty-six years with the company. In a statement, TD SYNNEX said Fabes brings more than two decades of IT channel leadership across vendor, distributor, and customer perspectives. He most recently led a multi-year strategic growth initiative at SHI across Canada, and before that served as Canadian channel chief at Lenovo, where he helped triple channel revenue to more than one point two billion dollars in three years. TD SYNNEX North America president Reyna Thompson said Fabes’ end-to-end understanding of the Canadian technology market makes him well positioned to lead the Canada business into its next chapter. The appointment comes at a time when TD SYNNEX has been expanding its vendor relationships in Canada, including recent global distribution deals with Fortinet and HPE. Canadian partners will be watching how Fabes shapes the distributor’s local strategy, particularly around AI, cybersecurity, and cloud marketplace growth. A new Huntress report published Monday warns that threat actors have been running massive password spray attacks against Microsoft Azure Command Line Interface accounts, making more than eighty-one million attempts between June 12 and June 26, 2026. According to Huntress, attackers are exploiting a loophole in Azure CLI that does not support multifactor authentication, allowing them to target service accounts and non-human identities that are often poorly monitored. The company said most affected accounts were from large enterprises with complex cloud footprints, and that MSPs managing customer Azure environments are particularly exposed because these CLI accounts often fall outside normal identity monitoring workflows. Huntress has reported the issue to Microsoft. The research underscores a growing tension in identity security: as organizations lock down human-facing accounts with MFA, attackers are shifting to non-human identities and service accounts that lack the same protections. Canadian MSPs with hybrid Azure and Microsoft 365 clients should be reviewing whether their RMM and identity tools are catching CLI-level authentication anomalies. MSSPs are facing a significant employee retention challenge, but salary is not the primary driver. According to a ChannelE2E feature published today, the main issue is what the report calls “invisible work” – security analysts spending hours on manual data correlation, reporting, and threat context that customers never see. Guardz, in announcing a new agentic reporting capability, said the problem is burning out analysts who feel their work lacks visible impact. The new tool uses an AI agent to automatically turn blocked threats, security activity, and client risk data into formatted reports that MSPs can present to SMB customers. Guardz is positioning the feature as a way to reduce the manual reporting burden while simultaneously demonstrating security value to clients. For Canadian MSPs, the issue is worth noting because talent retention in security operations is already tight, and any tool that reduces invisible overhead while improving client communication is likely to get attention from understaffed SOC teams. In Brief – ManageEngine launches a developer marketplace for integrations, extensions, and AI agents. GAM Tech ranks number ninety-seven globally on the two thousand twenty-six MSP five hundred one and number one in Western Canada. Later today on In The Channel, my conversation with Mark Sutor of Access Group and the Trust X Alliance on the Global Leadership Summit, the TXA AI agent, and the idea of distributor-as-platform is available now. That’s how we’re seeing the headlines today. I’m Robert Dutt for ChannelBuzz.ca, thanks for listening. Have a great day.
Today’s headline news for Canadian IT solution providers: OpenAI Partner Network: OpenAI‘s inaugural Partner Network is officially live as of July 15, with vice president of strategic global partnerships Colleen Kapase confirming the three-tier program is backed by $150 million in channel investment. Partners can progress through Select, Advanced, and Elite tiers while earning specializations in areas like Codex, cybersecurity, and AI agents. OpenAI says it aims to train 300,000 certified consultants by year-end and is recruiting solution providers of all sizes that can put AI systems into production. OpenAI Carbon60 MSP 501: Carbon60, a Toronto-based managed cloud services provider, has been named to the 2026 MSP 501 at position 206, ranking among the world’s top managed services firms by revenue and operational discipline. The company has built a differentiated practice around Canada-first sovereign cloud and Azure expertise, and the ranking follows a broader push by Canadian MSPs to demonstrate global competitiveness in compliance-heavy verticals. Carbon60 RecordPoint channel-first: RecordPoint has launched a global partner program that CRN describes as a channel-first move, enabling resellers, consultancies, and systems integrators to resell, co-sell, and refer its data and AI governance platform. Partners will receive enablement, joint sales support, and platform access to build practices around data retention, compliance, and AI-ready data classification. Channel Insider Blackpoint Cyber 2026 threat report: Blackpoint Cyber has released its 2026 Annual Threat Report, finding that attackers are increasingly exploiting trusted IT tools rather than using perimeter breaches. The report highlights abuse of remote monitoring and management platforms, VPNs, and identity credentials as primary vectors. ChannelPro Network Managed security market growth: Acronis and Omdia project the global managed security market will grow from $93 billion in 2025 to $106 billion in 2026, a 14.4 percent increase. The growth reflects sustained demand for outsourced security operations among mid-market organizations that lack internal SOC capacity. RAMageddon pressures PC refresh: Industry analysts and OEMs continue to signal significant PC RAM price increases through 2026 due to the ongoing memory supply shortage. Channel partners should advise clients on refresh timing and alternative configurations to manage budget impact. CNET Exabeam MSSP licensing: Exabeam has expanded its APEX partner program with pooled and federated licensing options designed specifically for MSSPs. The new framework is intended to reduce onboarding friction and simplify compliance across multi-tenant security operations centers. Security Brief Read Full Transcript Welcome to The Buzz from ChannelBuzz.ca, I’m Robert Dutt, today is Thursday, July 16, and here’s what’s happening in the channel today. OpenAI’s inaugural Partner Network is officially live as of yesterday, July 15, with the company backing the three-tier program with $150 million in channel investment. Vice president of strategic global partnerships Colleen Kapase confirmed the program is open to solution providers of all sizes, not just global systems integrators. Partners can progress through Select, Advanced, and Elite tiers based on sales performance, technical capability, and deployment experience. The program includes specializations in Codex, cybersecurity, and AI agents. OpenAI says it aims to train 300,000 certified consultants by the end of 2026, and is actively recruiting solution providers that can put AI systems into production. Philip Larson, senior director of the OpenAI Partner Network and a former Google Cloud channel leader, said the program is designed to reward partners for the value they create with customers. Canadian VARs and MSPs with existing AI practices should evaluate the program alongside their current AWS, Google, and Microsoft partnerships, as the specializations in Codex and AI agents may create differentiation in automation-heavy verticals. Carbon60, a Toronto-based managed cloud services provider, has been named to the 2026 MSP 501 at position 206, marking the company as one of the world’s top managed services firms by revenue and operational discipline. The ranking, published by Channel Futures, evaluates financial health, operational maturity, and recurring revenue growth. Carbon60’s inclusion follows a broader trend of Canadian MSPs demonstrating global competitiveness in specialized infrastructure and compliance-heavy verticals. The company has built a differentiated practice around Canada-first sovereign cloud and deep Azure expertise. As Canadian public sector and healthcare clients face stricter data residency requirements, sovereign cloud capabilities are becoming a key differentiator for domestic MSPs seeking to compete with larger global firms on government and enterprise contracts. RecordPoint has gone channel-first with the launch of a global partner program enabling resellers, consultancies, and systems integrators to resell, co-sell, and refer its data and AI governance platform. The program arrives as AI adoption drives a surge in demand for data governance across regulated industries. RecordPoint says partners will receive enablement, joint sales support, and platform access to build practices around data retention, compliance, and AI-ready data classification. CRN reports that the move represents a strategic shift for the company. Canadian partners serving regulated industries like finance, government, and healthcare may find particular opportunity as clients confront unstructured data sprawl ahead of AI deployments. In Brief – OpenAI commits $150 million to launch its inaugural Partner Network with tiered AI specializations. Acronis and Omdia project the managed security market will reach $106 billion in 2026. Blackpoint Cyber’s 2026 Annual Threat Report highlights attackers hiding inside trusted IT tools and RMM platforms. RAMageddon memory shortages continue to pressure PC pricing and enterprise refresh cycles. Exabeam adds pooled and federated licensing options to its APEX partner program for MSSPs. Full details and links in the show notes or the blog post. Later today on In The Channel, we’re talking specialist distribution in Canada with Carrie Hopkins of Exclusive Networks. We get into the Ignition program, what broadliners can’t deliver, and why the model might feel familiar to channel veterans. And if you haven’t heard it yet, yesterday we wrapped our HPE Discover 2026 arc with HPE vice president of North America channels Jeremiah Jenson. He talks about the quote-cycle win, the Canadian angle on data sovereignty, and what partners should stop doing. That’s how we’re seeing the headlines today. I’m Robert Dutt for ChannelBuzz.ca, thanks for listening. Have a great day.
Today’s headline news for Canadian IT solution providers: Microsoft July 2026 Patch Tuesday fixes 570 flaws, 3 zero-days: Microsoft released its July 2026 Patch Tuesday update addressing 570 vulnerabilities including 3 zero-days, according to BleepingComputer. The zero-day status means MSPs should prioritize these patches immediately for client environments. With 570 total fixes to stage, test, and deploy, Canadian partners managing regulated clients in healthcare, finance, and provincial government face a compressed vulnerability response window this week. Citrix Platform Flex opens a new services opportunity: Citrix is introducing Platform Flex, a persona-based pricing model that gives partners room to build consulting, workforce assessment, and migration services around how customers actually use the platform. According to ChannelE2E, the shift lets partners attach higher-margin services to each deployment by right-sizing workloads to user personas. The new model is particularly relevant in the Canadian mid-market, where virtual desktop and app delivery standardization has been strong but differentiation has been thin. AI compliance is becoming an operational blind spot for MSPs: AI compliance should not be treated as a policy exercise that happens once and then sits on a shelf. According to Terry Irons on ChannelE2E, the value for MSPs is operationalizing compliance around AI data handling, model access, and prompt logging. Canadian MSPs already navigating Law 25 and PIPEDA amendments will recognize the pattern: the regulation exists, but the recurring revenue opportunity lies in helping customers stay inside the lines as the technology changes. CMMC third-party audits paused but the opportunity isn’t: The Department of Defense has pressed pause on third-party audits for the Cybersecurity Maturity Model Certification, but the compliance requirements themselves remain in place for defense contractors. According to ChannelE2E, that gap creates an opening for MSPs and MSSPs to expand compliance services. Canadian partners serving cross-border contractors or aerospace supply chain clients should expect renewed advisory conversations. Progress confirms ShareFile zero-day behind Storage Zone shutdown: Progress confirmed a ShareFile zero-day flaw was behind the Storage Zone shutdown, BleepingComputer reports. Partners managing client file-sharing infrastructure should assess exposure and confirm whether affected Storage Zone configurations are in their environments. MSSP Alert Top 250 application opens for 2026: The MSSP Alert Top 250 MSSP list application process is open for 2026. ChannelE2E offers guidance on what judges look for and which mistakes could hurt a ranking. Changes in the Channel tracks leadership moves for July 6-10: ChannelE2E tracked leadership changes and shakeups across the channel for the week of July 6-10. Read Full Transcript Welcome to The Buzz from ChannelBuzz.ca, I’m Robert Dutt, today is Wednesday, July 15, and here’s what’s happening in the channel today. Microsoft released its July 2026 Patch Tuesday update addressing 570 vulnerabilities across the portfolio, including 3 zero-days. According to BleepingComputer, the zero-day patches should be prioritized immediately for client environments. The scale of the release means MSPs need to stage patch deployment carefully. With 570 fixes to validate and deploy, technicians are managing a large surface area without disrupting business operations. Canadian partners managing regulated clients in healthcare, finance, and provincial government should expect compressed vulnerability response windows this week. Law 25, PIPEDA, and sector-specific frameworks all embed expectations around timely critical patch management, and a July drop of this magnitude tests those service level commitments. Microsoft is positioning the release as part of its regular cycle, but the zero-day status means this is not a routine Tuesday. Partners should be communicating with clients now about maintenance windows and priority sequencing for on-premises and hybrid infrastructure. Citrix is introducing Platform Flex, a persona-based pricing model that moves away from one-size-fits-all licensing and gives partners room to build consulting, workforce assessment, and migration services around how customers actually use the platform. According to ChannelE2E, the shift lets partners attach higher-margin services to each deployment by right-sizing workloads to user personas rather than simply renewing seat counts. The new model is particularly relevant in the Canadian mid-market, where virtual desktop and app delivery standardization has been strong but differentiation has been thin. Platform Flex creates a natural entry point for partners to conduct usage assessments, recommend persona transitions, and bundle ongoing optimization services. It also gives partners a way to defend margins against pure license resale by making the consulting layer part of the renewal conversation. Citrix is positioning Platform Flex as a way to reduce customer shelfware, but the partner angle is that it turns every renewal cycle into a services engagement. AI compliance should not be treated as a policy exercise that happens once and then sits on a shelf. According to Terry Irons on ChannelE2E, the value for MSPs is operationalizing compliance around AI data handling, model access, and prompt logging. As customers deploy more AI tools, the governance gap between experimentation and controlled scale is widening, and MSPs that treat AI governance as a document creation exercise risk missing the continuous monitoring requirement. Canadian MSPs already navigating Law 25 and PIPEDA amendments will recognize the pattern: the regulation exists, but the recurring revenue opportunity lies in helping customers stay inside the lines as the technology changes. The piece suggests that MSPs who build AI compliance into their existing security operations center workflows, rather than treating it as a separate consulting project, will capture more of that spend. The shift from one-time policy to ongoing operational control is the same transition the channel has already made with security, and AI is now following that path. In Brief – CMMC third-party audits are paused but the channel opportunity isn’t. Progress confirms a ShareFile zero-day flaw behind the Storage Zone shutdown. MSSP Alert Top 250 application opens for 2026 ranking. Changes in the Channel tracks leadership moves for the week of July 6-10. Full details and links in the show notes or the blog post. Later today on In The Channel, we close out our HPE Discover 2026 coverage with vice president of North America channel and partner ecosystem Jeremiah Jenson, talking about the 30-day quote validity, Canadian partner influence, and the push for data center networking growth. And if you haven’t heard it yet, yesterday’s episode featured Curtis Dery from Xerox IT Solutions on HPE financing, GreenLake wins, and why AI is a digital goldmine for the channel. That’s how we’re seeing the headlines today. I’m Robert Dutt for ChannelBuzz.ca, thanks for listening. Have a great day.
El nombramiento de Jonathan Berger como Senior Vice President, Global Channels and Alliances marca una nueva etapa para SonicWall en su estrategia mundial de partners. Su llegada refuerza el enfoque de la compañía hacia MSPs, MSSPs y resellers que buscan crecer con servicios gestionados, ingresos recurrentes y mayor rentabilidad en ciberseguridad.
Today’s headline news for Canadian IT solution providers: HPE Discover 2026 kicks off: HPE Discover 2026 opens today at The Venetian in Las Vegas with the Partner Growth Summit, the partner-exclusive day that precedes the main conference. The General Session – “The Power of One” – is led by HPE channel head Simon Ewington and focuses on HPE’s unified partner strategy under the HPE Partner Ready Vantage program, spanning networking, cloud, and AI. This is the first Partner Growth Summit since HPE’s $14 billion Juniper Networks acquisition closed, and HPE is presenting partners with a fully unified portfolio story for the first time. ChannelBuzz.ca is on the ground all week: Tuesday’s Buzz will feature a full Partner Growth Summit recap, and In The Channel this week features a multi-part series with Jeremiah Jenson, HPE’s vice president of North America channel and partner ecosystem, covering the Discover announcements in depth. Cato Networks launches integration hub: Cato Networks has launched a new Technology Partner Program and a Platform Integration Hub, debuting with more than 100 out-of-the-box integrations with third-party security, cloud, and networking solutions. The SASE provider says the program is designed to simplify how partners and customers connect Cato’s platform with existing enterprise technology stacks. The move is significant for Canadian MSPs and MSSPs: a robust integration catalog reduces the custom API work that often slows deployment and increases delivery costs, making it easier to position Cato alongside the broader tools in a customer’s security environment. Checkmarx flags CISO compliance pressures: A new 2026 Future of Application Security Report from Checkmarx, based on a survey of more than 2,000 developers and CISOs, found that 95 per cent of CISOs report being pressured to suppress or delay compliance-related security issues when business deadlines loom. The research also highlights how AI-generated code is expanding the attack surface faster than many security teams can manage. For Canadian MSSPs, the data reinforces the value of independent, third-party security oversight – and the case for structured application security as a managed service. Dataminr and TD SYNNEX partner on AI cyber defense: Dataminr has signed a strategic distribution agreement with TD SYNNEX, making Dataminr for Cyber Defense available to more than 35,000 North American resellers. The platform combines external risk signals with internal telemetry to help security teams prioritize threats in real time. For Canadian partners already working with TD SYNNEX, the deal adds an AI-driven threat intelligence offering to the distributor’s security portfolio at a time when customers are asking for earlier warning around cyber risk. inforcer launches Microsoft 365 TDR platform: inforcer has launched inforcer Threat Detection and Response, a new platform that gives MSPs a single environment to manage detection, incident response, and reporting across the full Microsoft 365 estate – including Entra, Defender, Purview, Teams, and SharePoint. According to the company, the platform’s advantage is its existing policy and configuration context for each tenant, which it says allows the detection engine to separate real threats from alert noise. The product launched in early access at Pax8 Beyond last week. ConnectSecure introduces Patch 360: ConnectSecure has launched Patch 360, a patch management solution designed specifically for MSPs. According to the company, the platform gives MSPs more control over patch prioritization, testing, and approval workflows, and is designed to reduce deployment risk while accelerating patching across operating systems and third-party applications. NetRise launches Discovery Partner Program: Software supply chain security firm NetRise has launched the Discovery Partner Program for VARs, MSSPs, distributors, and systems integrators. The program provides partners access to the NetRise Platform, which analyzes compiled software artifacts – including binaries, firmware, and containers – to identify components and risks that may not appear in source-code scans or vendor-provided SBOMs. NetRise is positioning the program as a way for partners to address growing customer demand for independent software supply chain verification. Read Full Transcript This episode of The Buzz is brought to you by HPE Discover 2026. HPE Discover runs June 15 to 18 at The Venetian in Las Vegas. Discover what’s next at hpe.com/discover. Welcome to The Buzz from ChannelBuzz.ca, I’m Robert Dutt, today is Monday, June 15th, and here’s what’s happening in the channel today. The biggest event on HPE’s calendar opens today at The Venetian Convention and Expo Center in Las Vegas, and ChannelBuzz.ca is on the ground for the full week. But before the main conference opens to the broader audience tomorrow, today belongs exclusively to the channel. The HPE Partner Growth Summit – the partner-only day that kicks off Discover week – is underway as you’re hearing this. The centrepiece is the General Session called “The Power of One,” led by HPE channel head Simon Ewington alongside a lineup of HPE senior executives. The name captures the message HPE is sending its partner ecosystem heading into the back half of 2026: one comprehensive portfolio, one unified program under HPE Partner Ready Vantage, and one integrated experience across networking, cloud, and AI. The afternoon breakout agenda is dense – covering GreenLake and hybrid cloud, Aruba networking with AI, monetizing accelerated compute and agentic workloads, and HPE’s evolving service provider story. It’s also worth noting the context: this is the first Partner Growth Summit since HPE’s $14 billion acquisition of Juniper Networks cleared regulatory review and officially closed. Partners are getting their first look at a fully unified networking and compute story from a company that can now tell it cleanly. We’re bringing you the announcements as they happen all week. In just a couple of hours on In The Channel, I’ll help you get ready for Discover, as I preview the event with the help of none other than Jeremiah Jenson, HPE’s vice president of North American channel and partner ecosystem. Tomorrow on The Buzz, we’ll have all the news from Partner Growth Summit, and tomorrow’s In The Channel will also feature Jenson, as we take a deeper dive into the HPE’s partner programs and where he sees the biggest opportunities for the channel right now. Be sure to stick with us all week as we bring you full coverage from Vegas. Cato Networks is expanding its ecosystem with the launch of a new Technology Partner Program and a Platform Integration Hub. The SASE provider says the hub debuts with more than 100 integrations out of the box, offering streamlined connectivity with third-party security, cloud, and networking solutions. According to Cato, the program is designed to simplify how partners and customers integrate its platform with existing enterprise technology stacks, reducing friction and speeding up deployments. A vendor-led integration effort at this scale matters for the channel. As enterprise environments grow more layered and complex, MSPs rely on platforms that connect cleanly to an existing stack rather than requiring months of custom API work. Out-of-the-box integrations mean less time troubleshooting compatibility and more time delivering security outcomes to clients. It’s worth noting that Cato’s channel chief said earlier this year that seven out of ten deals the company closes are already partner-led. A stronger integration story could deepen that dependence on the channel by making it easier for MSPs and MSSPs to position Cato alongside the other tools in a customer’s security stack. A report released last week by application security vendor Checkmarx is putting hard numbers on a dynamic that security-focused channel partners have likely been seeing for some time. The 2026 Future of Application Security Report, based on a survey of more than 2,000 developers and CISOs, found that 95 per cent of CISOs say they have been pressured to suppress or delay compliance-related security issues when business deadlines loom. Compounding the problem: the adoption of AI-generated code is accelerating, which Checkmarx says is multiplying the attack surface in production environments faster than many security teams can manage. The business case for external, independent security oversight has rarely been clearer. When internal security leaders are being overruled on vulnerability management, an MSP or MSSP operating as a neutral third party – accountable to security outcomes rather than product launch timelines – steps into a genuine gap. The data also validates the case for application security as a structured managed service. As AI-generated code becomes standard in the development pipeline, organizations that can’t close that gap internally will need to find a partner who can. In Brief – Dataminr and TD SYNNEX have signed a distribution agreement that makes Dataminr for Cyber Defense available to more than 35,000 North American resellers through TD SYNNEX’s channel network. Security vendor inforcer has launched inforcer Threat Detection and Response, a new platform designed to give MSPs a single environment to manage detection, incident response, and reporting for Microsoft 365. ConnectSecure has introduced Patch 360, a patch management solution built specifically for MSPs that the company says reduces deployment risk while accelerating patching across operating systems and third-party applications. NetRise has launched the Discovery Partner Program, targeting VARs, MSSPs, distributors, and systems integrators with software supply chain security capabilities built around compiled binary analysis rather than source code or vendor-provided SBOMs. Full details and links in the show notes or the blog post. That’s how we’re seeing the headlines today. I’m Robert Dutt for ChannelBuzz.ca, thanks for listening. Have a great day.
Today’s headline news for Canadian IT solution providers: ConnectWise Platform: ConnectWise yesterday unveiled what it calls the industry’s first purpose-built platform for Predictive IT, unifying PSA, RMM, cybersecurity, automation, workflow orchestration, and native agentic AI into a single execution layer for managed services. CEO Manny Rivelo described it as a fundamental shift from reactive IT management to an AI-native operating model. The company also released new operational benchmark modeling based on a representative MSP with approximately $3M in annual managed services revenue, showing the productivity and economic impact it says AI-driven automation can deliver. Cavelo Cora AI Security Analyst: Kitchener, Ontario-based Cavelo has introduced Cora, an AI Security Analyst integrated into its data security posture management platform and positioned specifically for MSPs and MSSPs. Cavelo says Cora analyzes security telemetry and translates it into a guided remediation action plan in seconds, tailored by role. The tool targets the operational gap between risk visibility and actual remediation – without requiring additional headcount. Radiant Logic and Zscaler Partnership: Radiant Logic and Zscaler have announced a technology partnership aimed at solving the Day 1 access problem in mergers and acquisitions. By integrating RadiantOne’s identity data fabric with the Zscaler Zero Trust Exchange, the companies say acquiring organizations can securely connect newly onboarded employees to applications from the moment a deal closes, regardless of disparate identity systems. ConnectSecure Patch 360: ConnectSecure is launching Patch 360, a patch management platform built for MSPs that introduces pilot-first validation, risk-based prioritization using CISA Known Exploited Vulnerabilities and EPSS scoring, controlled rollouts with approval workflows, and integrated rollback – replacing what the company describes as a “deploy-and-hope” model with a “test-and-trust” framework. NTT DATA and Google Cloud: NTT DATA is expanding its AI partnership with Google Cloud, launching a dedicated Gemini Enterprise practice to help enterprise clients move AI deployments from pilot to production at scale. Descope Agentic Identity Hub: Identity platform Descope is announcing enhancements to its Agentic Identity Hub today, extending its tools for managing authentication and access for autonomous AI agents. Checkmarx CISO Research: Checkmarx has released research surveying more than 2,000 developers and CISOs, finding that 95 percent of CISOs report facing internal pressure to suppress software compliance findings. Read Full Transcript Welcome to The Buzz from ChannelBuzz.ca, I’m Robert Dutt, today is Tuesday, June 9, 2026, and here’s what’s happening in the channel today. ConnectWise yesterday unveiled what it is calling the industry’s first purpose-built platform for the era of Predictive IT. The ConnectWise Platform brings together PSA, RMM, cybersecurity, automation, workflow orchestration, and native agentic AI into what the company describes as a single intelligent execution layer for managed services. CEO Manny Rivelo positioned it as a fundamental shift away from the labor-intensive, disconnected systems that have defined MSP operations for decades, toward what ConnectWise calls an AI-native operating model. To support the launch, the company released new operational benchmark modeling showing the productivity and economic impact it says AI-driven automation can have on MSP operations. In their model, a representative managed services firm with approximately three million dollars in annual revenue could see measurable transformation across their first stages of the Predictive Intelligence journey. This is a significant platform bet from one of the largest players in the MSP tooling market, and the framing around “Predictive IT” is clearly a narrative ConnectWise intends to own. In the security space, Kitchener, Ontario-based Cavelo has introduced Cora, an AI Security Analyst integrated directly into its data security posture management platform. Positioned specifically for MSPs and MSSPs, Cora functions as an AI agent that analyzes security telemetry to identify, prioritize, and recommend remediation steps for cyber risks across client environments. Rather than adding more alerts to the dashboard, Cavelo says the tool translates security data into a guided action plan in seconds, tailored to the specific roles of frontline technicians and senior security leaders. The development targets a well-documented operational gap between risk visibility and remediation – allowing service providers to reduce manual investigation time and offer clients clear, actionable intelligence without increasing headcount. Radiant Logic and Zscaler have formed a strategic partnership designed to address the Day 1 access challenges commonly found in mergers and acquisitions. By integrating RadiantOne’s identity data fabric with the Zscaler Zero Trust Exchange, the companies are aiming to eliminate the complex network and identity merge projects that typically stall productivity following a deal close. The joint solution allows acquiring organizations to securely connect newly onboarded employees to necessary applications from day one, regardless of disparate Active Directory or HR systems. In a market where M&A activity among IT service providers shows no sign of slowing, this integration offers a repeatable framework for reducing the downtime and cyber risk associated with bringing acquired entities onto a managed environment – which is a practical and recurring service challenge for many MSPs in the field. In Brief – ConnectSecure launches Patch 360, a patch management platform for MSPs built on pilot-first testing, risk-based vulnerability prioritization, and integrated rollback controls. NTT DATA expands its AI partnership with Google Cloud, launching a dedicated Gemini Enterprise practice to help organizations move deployments from pilot to production scale. Descope is announcing enhancements today to its Agentic Identity Hub, aimed at helping organizations manage access for autonomous AI agents. Checkmarx research of more than 2,000 developers and CISOs finds 95 percent of CISOs report facing pressure to suppress software compliance findings. Full details and links in the show notes or the blog post. Later today on In The Channel, we have a conversation about the launch of the AWS Partner Innovation Hub in Toronto, with AWS Canada’s Martin Brazonet and CGI’s Dinesh Bhavsar on the challenge of moving AI from proof-of-concept to production. And if you haven’t heard it yet, check out our conversation with Earl Gosick from ESTI Consulting Services, recorded at Dell Technologies World, on why the AI story is really a storage story – that one is on the feed now. That’s how we’re seeing the headlines today. I’m Robert Dutt for ChannelBuzz.ca, thanks for listening. Have a great day.
Today’s headline news for Canadian IT solution providers: Dell PowerStore Elite and the reimagined data center: Yesterday at Dell Technologies World, Dell Technologiesintroduced Dell PowerStore Elite, a new enterprise storage platform delivering up to 3x performance over the prior generation and an industry-best 6:1 data reduction guarantee. The platform packs 5.8 petabytes into a single 3U chassis using standards-based E3 NVMe flash, and introduces Dell Cyber Detect, which identifies ransomware with 99.99% accuracy and pinpoints the last known clean copy for recovery. PowerStore Elite ships in July 2026; Cyber Detect for PowerStore follows in Q3. The broader Day 2 announcement also included 11 new PowerEdge servers, expanded Dell Private Cloud support for Broadcom, Microsoft, and Nutanix stacks, Dell PowerProtect One for simplified cyber resilience, and two new automation products: the Dell Automation Platform and Dell Automation Studio. Jeff Clarke’s tokenomics keynote: In Tuesday’s Day 2 keynote at DTW, Dell COO Jeff Clarke presented a set of ten fundamental shifts from the past year whose through-line is what he called tokenomics. The math: model prices fell 80% per token; token consumption is up 10x; GenAI software spend tripled. Net effect – AI is getting more expensive for most organizations, not less. Clarke illustrated the stakes with a concrete example: one developer running a single agentic use case on the public cloud can burn approximately $3,400 per day in token costs; the same workload runs at zero incremental cost on on-premises infrastructure. Clarke confirmed Dell moved its own operations to on-prem after internal token costs became untenable, and described work underway on what he called “token routing” – an orchestration layer that would automatically direct tasks to either a deskside AI workstation or data center hardware based on workload. He closed with three imperatives: know your token consumption, find your super users, and lead the operating model change or be disrupted by it. Intezer launches Amplify Partner Program: Intezer has officially launched its Intezer Amplify Partner Program, naming channel veteran Mark Daggett as vice president of global channels and alliances. The program formalizes Intezer’s channel investment as demand for AI-driven security operations grows and the talent gap in security operations continues to widen. According to Intezer, the program is designed to help MSSPs and solution providers step in where internal security teams lack the capacity to operationalize AI-powered alert triage and threat investigation, translating the company’s platform capabilities into managed and co-managed service offerings. Check Point agentic network security orchestration: Check Point announced an agentic network security orchestration platform on Monday designed to replace decades of rule-based complexity, reducing network policy management from months of manual effort to minutes of verified, automated action. The announcement is part of a broader Check Point push into agentic security capabilities across its Infinity platform. Zendesk unveils Autonomous Service Workforce: At its annual Relate conference, Zendesk announced the Autonomous Service Workforce, a product vision built around specialized AI agents priced per resolution rather than per seat. Key launches include a no-code Agent Builder, omnichannel coverage with shared context, and a real-time Quality Score applied to every interaction – human or AI. Riverbed extends Aternity AIOps: Riverbed has released new Aternity digital experience (DEX) capabilities positioning AIOps as proactive disruption prevention rather than reactive monitoring, giving IT teams predictive intelligence before end-user experience degrades. WinMagic brings zero trust to legacy OT: WinMagic has introduced Continuous Identity Assurance, a hardware-bound approach to endpoint identity that extends zero trust controls to air-gapped systems and legacy operational technology environments traditionally outside the reach of modern identity platforms. Read Full Transcript Welcome to The Buzz from ChannelBuzz.ca, I’m Robert Dutt, today is Wednesday, May 20, 2026, and here’s what’s happening in the channel today. Continuing coverage from Dell Technologies World in Las Vegas, where yesterday’s Day 2 product announcements shifted the spotlight from the partner program to the infrastructure portfolio. The headline item was Dell PowerStore Elite, which Dell is positioning as a new class of enterprise storage platform built for what it calls an AI-era data center. According to the company, PowerStore Elite delivers up to three times the performance of the previous generation through software-driven improvements, and backs it all with what Dell describes as an industry-best 6:1 data reduction guarantee – up from 5:1 – a number it says carries real weight in today’s supply-constrained flash market. The platform packs up to 5.8 petabytes of effective capacity into a single 3U chassis using industry-standard E3 NVMe flash rather than proprietary drives, giving partners and their customers more flexibility on cost and sourcing. The cyber resilience angle is where it gets interesting for MSPs. Dell is introducing Dell Cyber Detect for PowerStore, which inspects data at the byte level and is positioned as being able to identify ransomware with 99.99% accuracy – surfacing the last known clean copy so organizations can recover fast. That capability will be available in Q3 2026. PowerStore Elite itself is set for global availability in July. The broader data center announcement also included 11 new PowerEdge servers spanning both air-cooled and liquid-cooled environments, expanded Dell Private Cloud support for Broadcom, Microsoft, and Nutanix software stacks, and two new automation products: the Dell Automation Platform, which pairs AI agents with a conversational interface for infrastructure deployment and management, and Dell Automation Studio for building custom, full-stack orchestration workflows. Nearly 20,000 customers already run PowerStore globally, and Dell is emphasizing that existing deployments can cluster with PowerStore Elite without disruption – a meaningful selling point for partners managing live customer environments. The second big story out of Las Vegas yesterday is one that deserves some unpacking. During his keynote, Dell’s chief operating officer Jeff Clarke laid out what he called ten fundamental changes in the past twelve months – and the thread running through the whole list is a single concept: tokenomics. The numbers Clarke presented tell a story that’s easy to miss if you only hear the headline. Model prices have fallen roughly 80% per token in the last year – sounds like great news. Except token consumption is simultaneously up ten times. And GenAI software spend has tripled in twelve months. The net effect is that AI is actually getting more expensive for most organizations, not less. Clarke made it concrete with a single example: one developer, one agentic use case, building a software tool. On the public cloud, that use case can run up roughly $3,400 a day in token costs. Running the equivalent workload on on-premises infrastructure with local models? Zero incremental dollars. Clarke went further and confirmed that Dell itself made the shift to on-premises AI after its own token costs became untenable – which is a different kind of endorsement than anything you hear from a keynote stage. He also flagged something worth watching: Dell is working on what he called token routing, an orchestration layer that would automatically determine whether a given task is better handled by a deskside AI workstation or by data center infrastructure. He was clear it’s still in development, but it signals where Dell sees the intersection of its PC and server businesses heading. Clarke closed his keynote with three actionable imperatives: know your token consumption, find your super users, and lead the operating model change or be disrupted by it. That first one is the real challenge for most organizations – and the one an MSP or trusted advisor can walk into and own. Away from Las Vegas now, and Intezer has officially launched its Intezer Amplify Partner Program, naming industry veteran Mark Daggett as vice president of global channels and alliances to lead the effort. The program formalizes the company’s channel investment at a moment when demand for AI-driven security operations is accelerating. Intezer’s pitch to the channel is essentially a gap-filling argument: internal security teams are drowning in alert volume while the talent required to triage and investigate those alerts remains in short supply. The Amplify program is designed to equip partners to step into that gap, delivering Intezer’s automated alert triage and threat investigation capabilities as a managed or co-managed offering. The appointment of a dedicated channel VP is the clearest signal yet that Intezer is treating the channel as a primary route to market, not a secondary one. Partners building out managed security or MSSP practices looking to differentiate around AI-augmented SOC capabilities have another option worth a closer look. In Brief – Check Point launches an agentic network security orchestration platform it says collapses months of manual policy work into minutes of verified action. Zendesk unveils its Autonomous Service Workforce at the Relate conference, introducing per-resolution AI agent pricing and a no-code Agent Builder. Riverbed announces new Aternity digital experience capabilities designed to shift AIOps from reactive visibility to proactive disruption prevention. WinMagic introduces Continuous Identity Assurance, anchoring identity verification in hardware to extend zero trust protocols to air-gapped and legacy OT environments. Full details and links in the show notes or the blog post. Later today on In The Channel, still from the show floor at Dell Technologies World, I sit down with Rob Emsley, director of cyber resilience marketing at Dell Technologies, on why 97% of cyber attacks now specifically target the backup infrastructure – and what it actually means to build a resilience strategy around the concept of the minimum viable company. And if you haven’t heard yesterday’s episode yet, check out my conversation with Alan Ashby, Dell’s senior director of Americas data center presales and specialty sales, on the practical infrastructure realities of the AI boom – from a deskside AI workstation for an SMB to consolidating 13 legacy servers into one. That’s how we’re seeing the headlines today. I’m Robert Dutt for ChannelBuzz.ca, thanks for listening. Have a great day.
Enterprises today are managing increasingly complex cybersecurity environments across cloud, AI systems, applications, endpoints, and enterprise networks. As AI adoption accelerates, organizations are under pressure to secure AI-driven environments while responding to faster and more sophisticated threats. In this episode of the Zinnov Podcast, Rajat Kohli, Partner, Zinnov speaks with Michael Khoury, Vice President, Global Ecosystem Partners, Palo Alto Networks, about the shift from point products to platform-led cybersecurity strategies and what it means for enterprises, partners, MSSPs, hyperscalers, and global system integrators. Michael Khoury shares perspectives on how enterprises are navigating cybersecurity complexity in an AI-first world, and how ecosystem models are evolving alongside it. The conversation explores: • Why AI is accelerating platform-led cybersecurity • The rise of MSSPs and cloud marketplaces as key routes to market • How enterprises are reducing security complexity through platformization • What differentiates advanced ecosystem partners in the AI era Tune in now.
Identity is at the center of nearly every modern breach, but when IAM responsibilities are shared with MSSPs, where does trust end and accountability begin? In this episode of CISO Stories, Jessica Hoffman sits down with Dr. Dustin Sachs to explore the human side of identity and access management, including cognitive bias, automation, privilege creep, and the hidden risks of "blind trust" in real-world security operations. Visit https://cisostoriespodcast.com for all the latest episodes! Show Notes: https://cisostoriespodcast.com/csp-224
Today on Defender Fridays, Katherine McNamara, Cybersecurity Technical Solutions Architect at Cisco, joins us to discuss how AI and ML adoption in enterprise infrastructure has expanded the attack surface for AI-driven systems.She'll walk through the security challenges unique to generative AI and ML-based architectures, and cover the four critical components: Model, Data, Application, and System, that organizations need to secure to maintain integrity.Katherine works for Cisco as a Cybersecurity Systems Engineer by day and by night, she's labbing and trying new things with the resources she has available. Katherine loves technology and getting her hands into the CLI or trying something new. She holds a Bachelors of Science and Masters of Information Security and Assurance from Western Governors University as well as several industry certifications. Register for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.io/Follow LimaCharlieSign up for free: https://limacharlie.io/LinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie
Jeff McJunkin, Founder of Rogue Valley Information Security, joins Defender Fridays to talk AI-powered code scanning for vulnerabilities. Jeff walks through real examples including using AI to find privilege escalation bugs in the Linux kernel.Jeff McJunkin is the founder of Rogue Valley Information Security, a consulting firm specializing in penetration testing and red team engagements. Jeff found the offensive side of cyber security very alluring during one the first penetration tests of his career. Feeling the challenge of host defenses like AV and centralized logging, and, at the time, knowing nothing about AV evasion or avoiding events that are likely to cause alerts, it was all very exciting. The challenge of successfully accomplishing the goal of that pen test, using essentially only native tools, was addictive for Jeff. He was hooked. Since those first penetration tests, Jeff has gone on to become an expert in the field, doing assessments for Fortune 100 companies, architecting two major versions of Core NetWars Experience, and contributing a vast amount of material to SANS Penetration Testing.Register for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.io/Follow LimaCharlieSign up for free: https://limacharlie.io/LinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie
Today, Dylan Williams, Co-Founder and Chief Research Officer at Spectrum Security, joins Defender Fridays to dig into that exact problem: self-evaluating agents, trajectory analysis, and what improvement looks like in production.Learn more at https://www.spectrum.security/Register for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.io/Follow LimaCharlieSign up for free: https://limacharlie.io/LinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie
Joshua Neil, Co-Founder of Alpha Level, dives into a more sophisticated understanding of AI SOCs. Join the conversation about this industry change on Defender Fridays.Dr. Joshua Neil, has been a pioneer in applying machine learning to cybersecurity since 2000, starting his journey at Los Alamos National Laboratory. There, he co-developed Pathscan, a network anomaly detection system capable of spotting attacks that slip past traditional defenses. In 2014, he and CEO Mike Pozmantier took that innovation to market by licensing Pathscan to Ernst & Young (EY), turning deep research into enterprise impact.That experience exposed a hard truth: anomaly detection is powerful at catching unknown threats - but on its own, it creates too much noise. Josh went on to tackle the other half of the problem, alert overload, through leadership roles at Microsoft and Securonix, gaining firsthand insight into the real-world struggles of security teams.In 2023, Josh and Mike launched Alpha Level to bring both worlds together: pairing the depth of anomaly detection with the precision of behavioral threat signals. The result? A platform that reduces false positives, adapts to your environment, and lets teams focus on real threats—before they become breaches. Learn more here: https://alphalevel.ai/Learn more at reconinfosec.comRegister for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.io/Follow LimaCharlieSign up for free: https://limacharlie.io/LinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie
This week on Defender Friday we are joined by Andrew Cook, CTO of Recon InfoSec, to talk about what it means to build a strong security team and why hiring builders is always a good bet.As the CTO of Recon InfoSec, a leading provider of managed security operations, Andrew oversees the technical vision, strategy, and execution of their services and solutions. He has more than a decade of experience in threat hunting, digital forensics, network defense, and capability development.Andrew's mission is to provide customers with the expertise they need to confidently and effectively respond to incidents, protect their organizations, and enhance their resilience. He has a proven track record of delivering high-quality results, leading and mentoring teams, and collaborating with partners across the industry and the government. Andrew is also a former Air Force officer, with national-level contributions and a passion for technical leadership.Learn more at reconinfosec.comRegister for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.io/Follow LimaCharlieSign up for free: https://limacharlie.io/LinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie
David Burkett, Cloud Security Researcher at Corelight, is back on Defender Fridays this week to discuss thinking in pipelines for AI agents.As a dedicated and highly experienced Cloud Detection Engineer and Security Architect, David has the privilege of working at a Fortune 50 Company where he leverages his extensive background in cybersecurity to protect digital assets. With a proven track record of building three different Cyber Security Operations Centers for multiple MSSP/MDR providers.David's expertise is backed by a strong set of GIAC certifications, including GCTI, GCIA, GPYC, and GCED... among others. He's proud to have been part of a large overall security team that won the prestigious James S. Cogswell Outstanding Industrial Security Achievement Award from the Defense Counterintelligence and Security Agency. Our security operations center was recognized as being among the top 1% of cybersecurity programs for all cleared facilities.In addition to his hands-on experience, David has consulted for over 40 Fortune 500 Companies and Large Federal Organizations, helping them manage their SOAR platforms and playbooks. As a strong believer in knowledge sharing and collaboration, he's also an active contributor to the open-source detection security project known as Sigma. Learn more at https://corelight.com/Register for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.io/Follow LimaCharlieSign up for free: https://limacharlie.io/LinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie
Every vendor at RSAC Conference 2026 will have an autonomous SOC story. Subo Guha, Senior Vice President of Product Management at Stellar Cyber, has been building the real thing for over a decade -- and he has one question every buyer should ask at every booth: can your platform explain why it reached its verdict? Stellar Cyber's autonomous SOC provides a full case summary for every true positive, showing the forensic evidence chain, threat intelligence correlations, and specific observables that led to the conclusion. SOC analysts can review, challenge, or override -- and that feedback loop is how the system improves. The threat landscape has shifted in ways that validate Stellar Cyber's original architecture. LLM-generated attacks have collapsed the time to launch a sophisticated phishing campaign from weeks to minutes. Stellar Cyber was built to serve the mid-market and the MSSPs that protect it -- organizations that face identical threats to enterprises but without enterprise resources. A unified, multi-tenant platform means MSSPs onboard new customers in minutes. An open data ingestion engine works with whatever tools are already in place -- no EDR lock-in, no rip-and-replace. At the center of the platform is a correlation engine that transforms thousands of individual alerts into a manageable set of high-confidence cases. An identity compromise driving lateral movement across dozens of alerts becomes one case with a clear recommended action. Subo describes this as the difference between drowning in noise and focusing on decisions that actually require human judgment -- and it is the foundation the autonomous SOC layer is built on. Subo is direct about what the hype gets wrong: the claim that organizations can dramatically cut SOC headcount because AI has it covered is not happening. The realistic version of autonomous SOC is a force multiplier -- digital agents handle the continuous, high-volume triage work that consumes analyst hours, freeing humans for the cases that require context and institutional knowledge. A system that automates without explainability does not reduce risk. It relocates it. Stellar Cyber will be at booth S327 in the South Hall at RSAC Conference 2026, right at the bottom of the escalator. Live autonomous SOC demonstrations will be running throughout the event, with real-world results from customers already in production. The team also has a barista on site -- a detail Subo was particularly keen to mention for Marco Ciappelli. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Subo Guha, Senior Vice President of Product Management, Stellar Cyberhttps://www.linkedin.com/in/suboguha/ RESOURCES Learn more about Stellar Cyber: https://stellarcyber.ai RSAC Conference 2026 Coverage: https://www.itspmagazine.com/rsac-2026-conference-san-francisco-usa-cybersecurity-event-infosec-conference-coverage Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS Subo Guha, Stellar Cyber, Sean Martin, brand story, brand marketing, marketing podcast, brand spotlight, autonomous SOC, Open XDR, MSSP security platform, AI-driven security operations, agentic AI cybersecurity, threat detection and response, RSAC Conference 2026, SOC analyst tools, multi-tenant security platform, LLM-generated attacks, security operations center, SIEM NDR unified platform Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Saurabh Shintre, Founder and CEO of Realm Labs, is on Defender Fridays today to discuss securing AI from within.Saurabh previously led the AI security research at Splunk and Symantec. He has been at the forefront of AI security research for nearly a decade with multiple publications and patents and regularly features on public forums on issues regarding security and AI. Saurabh holds a PhD from Carnegie Mellon. Learn more at https://www.realmlabs.ai/Register for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.io/Follow LimaCharlieSign up for free: https://limacharlie.io/LinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie
John V, AI risk, safety, and security at the Institute for Security and Technology (IST), joins Defender Fridays today. John's work spans AI red teaming, adversarial machine learning, AI evals and validation, and AI risk assessment, including policy work at the intersection of AGI and nuclear strategic stability. Learn more at https://securityandtechnology.org/Register for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.ioFollow LimaCharlieSign up for free: https://limacharlie.ioLinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie
What does it take to turn the dream of an autonomous SOC into something organizations can actually deploy? Subo Guha, Senior Vice President of Product Management at Stellar Cyber, joins Sean Martin to share how the company's AI-driven security operations platform is making that vision a reality. Stellar Cyber serves SOC teams across more than 50 countries, with a primary focus on MSPs and MSSPs supporting the underserved mid-market, though marquee enterprise customers like Canon are also part of the portfolio.How can agentic AI change the way SOC teams handle alert overload? Guha describes what he calls a "digital army" of AI agents that work around the clock to automate alert triage and catch phishing attacks. The system filters 70 to 80 percent of incoming alerts, allowing analysts to focus on the 20 percent that matter most. With attackers using AI to launch faster and more frequent campaigns, Stellar Cyber takes a human-augmented approach, meaning the AI learns from analyst interactions and continuously guides the SOC team toward faster, more accurate remediation.Why does this matter for MSPs operating on thin margins? Guha explains that the autonomous SOC capability layered on top of Stellar Cyber's XDR platform allows MSSPs to serve more customers, reduce mean time to repair, and grow their tenant base without proportionally increasing staff. When MSSPs grow revenue, Stellar Cyber grows alongside them, creating a mutually beneficial model that ultimately means more organizations get protected.This is a Brand Highlight. A Brand Highlight is a ~5 minute introductory conversation designed to put a spotlight on the guest and their company. Learn more: https://www.studioc60.com/creation#highlightGUESTSubo Guha, Senior Vice President of Product Management, Stellar Cyber @LinkedInRESOURCESLearn more about Stellar Cyber: https://stellarcyber.aiAre you interested in telling your story?▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlightKEYWORDSSubo Guha, Stellar Cyber, Sean Martin, brand story, brand marketing, marketing podcast, brand highlight, autonomous SOC, agentic AI, security operations, XDR, NDR, MSSP, MSP, alert triage, AI-driven security, Open XDR, Gartner Magic Quadrant, phishing detection, SOC automation Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
What does it take to turn the dream of an autonomous SOC into something organizations can actually deploy? Subo Guha, Senior Vice President of Product Management at Stellar Cyber, joins Sean Martin to share how the company's AI-driven security operations platform is making that vision a reality. Stellar Cyber serves SOC teams across more than 50 countries, with a primary focus on MSPs and MSSPs supporting the underserved mid-market, though marquee enterprise customers like Canon are also part of the portfolio.How can agentic AI change the way SOC teams handle alert overload? Guha describes what he calls a "digital army" of AI agents that work around the clock to automate alert triage and catch phishing attacks. The system filters 70 to 80 percent of incoming alerts, allowing analysts to focus on the 20 percent that matter most. With attackers using AI to launch faster and more frequent campaigns, Stellar Cyber takes a human-augmented approach, meaning the AI learns from analyst interactions and continuously guides the SOC team toward faster, more accurate remediation.Why does this matter for MSPs operating on thin margins? Guha explains that the autonomous SOC capability layered on top of Stellar Cyber's XDR platform allows MSSPs to serve more customers, reduce mean time to repair, and grow their tenant base without proportionally increasing staff. When MSSPs grow revenue, Stellar Cyber grows alongside them, creating a mutually beneficial model that ultimately means more organizations get protected.This is a Brand Highlight. A Brand Highlight is a ~5 minute introductory conversation designed to put a spotlight on the guest and their company. Learn more: https://www.studioc60.com/creation#highlightGUESTSubo Guha, Senior Vice President of Product Management, Stellar Cyber @LinkedInRESOURCESLearn more about Stellar Cyber: https://stellarcyber.aiAre you interested in telling your story?▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlightKEYWORDSSubo Guha, Stellar Cyber, Sean Martin, brand story, brand marketing, marketing podcast, brand highlight, autonomous SOC, agentic AI, security operations, XDR, NDR, MSSP, MSP, alert triage, AI-driven security, Open XDR, Gartner Magic Quadrant, phishing detection, SOC automation Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
This week on Defender Fridays, Farshad Abasi, Founder and CEO of Forward Security and Eureka DevSecOps, discusses how AI can help us set a new standard in app and cloud security. Farshad brings over 27 years of industry experience to the forefront of cybersecurity innovation. His professional journey includes key technical roles at Intel and Motorola, evolving into senior security positions as the Principal Security Architect for HSBC Global, and Head of IT Security for the Canadian division. Farshad's commitment to the field extends to his role as an instructor at BCIT, where he imparts his wealth of knowledge to the next generation of cybersecurity experts. His diverse experience, which spans startups to large enterprises, informs his approach to delivering adaptive and reliable solutions.Engaged actively in the cybersecurity community through roles in BSides Vancouver/MARS, OWASP Vancouver/AppSec PNW, and as a CISSP designate, Farshad's vision and leadership continue to drive the industry forward. Under his guidance, Forward Security is setting new standards in application and cloud security. Learn more at https://www.eurekadevsecops.com/ and https://forwardsecurity.com/Register for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.ioFollow LimaCharlieSign up for free: https://limacharlie.ioLinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie
This week Brandon Min, Founder and CEO of Herd Security, joins Defender Fridays to discuss how human risk management needs to rebrand with empathy.Brandon is the co-founder and CEO of Herd Security, where they help security teams drive employee engagement in security, making a more resilient organization. Humans have been the #1 target of organizational cyber attacks; however, security teams, organizations, vendors, and leaders have vilified them. At Herd, they believe security should be led with empathy and care. Building trust amongst users that will drive their engagement in security. Building herd immunity from cyber attacks. Learn more at https://herdsecurity.io/Register for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.ioFollow LimaCharlieSign up for free: https://limacharlie.ioLinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie
Send us a textThe weakest link is often sitting on the edge, blinking away with expired firmware and no vendor support. We kick off with a blunt reality check on outdated firewalls, load balancers, and IoT gateways, and why waiting two years to retire them is a gift to attackers. From there, we guide you through Domain 7.7 with a practical blueprint for operating and maintaining detective and preventive measures that actually hold up under pressure.We unpack firewall fundamentals with clear, real‑world tradeoffs: when a simple packet filter is enough, when stateful inspection and deep packet inspection earn their keep, and how a WAF stops the web attacks your L3/L4 controls will miss. You'll hear how RTBH can deflect denial‑of‑service floods upstream, and why segmentation is your best friend for reducing blast radius—whether you use internal segmentation firewalls for R&D, Purdue‑style tiers for industrial networks, or controlled air gaps for the most sensitive systems. In the cloud, we separate security groups from true firewalls and show how to stitch policies across hybrid environments without creating blind spots.Detection makes prevention smarter, so we break down IDS versus IPS in plain language. Baseline first, then block with intent to avoid outages. We compare host‑based and network‑based sensors, explain where to place them, and share tactics for cutting alert noise. You'll also get straight talk on allowlists and blacklists, the right way to maintain them, and why stale entries cause the ugliest outages. We explore sandboxing for safe detonation and learning, and give an unvarnished take on honeypots and honeynets—where they help, where they waste time, and what legal lines to respect.Not every team can build a 24x7 SOC, so we outline how MSSPs can extend your coverage with clear SLAs and ownership. Endpoint anti‑malware remains non‑negotiable, but tool sprawl is a trap—choose a strong EDR and manage it well. Finally, we dive into AI and machine learning: how they supercharge detection, triage, and response—and how adversaries use them too. The throughline is simple: shrink attack surface, raise signal quality, and respond faster than threats can pivot. If this helps you secure one more edge box or tune one more control, share it with a teammate, subscribe for more practical walkthroughs, and drop a review so we can keep raising the bar together.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Most orgs have a major blind spot: the browser.This week on Defender Fridays, we're joined by Cody Pierce, Co-Founder and CEO at Neon Cyber, to discuss why browser security remains a critical gap, from sophisticated phishing campaigns that bypass traditional controls to shadow AI tools operating outside your security perimeter.Cody began his career in the computer security industry twenty-five years ago. The first half of his journey was rooted in deep R&D for offensive security, and he had the privilege of leading great teams working on elite problems. Over the last decade, Cody have moved into product and leadership roles that allowed him to focus on developing and delivering innovative and differentiated capabilities through product incubation, development, and GTM activities. Cody says he gets the most joy from building and delivering products that bring order to the chaos of cyber security while giving defenders the upper hand.About This SessionThis office hours format brings together the LimaCharlie team to share practical experiences with AI-powered security operations. Rather than theoretical discussions, we demonstrate working tools and invite the community to share their own AI security experiments. The session highlights the rapid evolution of AI capabilities in cybersecurity and explores the changing relationship between security practitioners and automation.Register for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.ioFollow LimaCharlieSign up for free: https://limacharlie.ioLinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie
Join us for a special Defender Fridays Office Hours session where the LimaCharlie team demonstrates the new Agentic SecOps Workspace (ASW) and explores what's possible when AI agents operate security infrastructure directly.At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.What We'll DiscussIn this hands-on session, we showcase real working implementations of AI in cybersecurity operations. From reverse engineering malware to automated rule tuning and infrastructure management, we demonstrate how AI agents are transforming security workflows from concept to production-ready tools in hours instead of days.Key TopicsAutomated malware analysis and decompilation without traditional manual reverse engineering workflowsRule tuning at scale: Investigating noisy detections, writing false positive rules, and deploying them autonomouslyInfrastructure automation: Setting up data sources, configuring tenants, and managing security operations through AI agentsThe permission model: Balancing AI capability with human oversight and approval workflowsReal-world applications: Custom reporting, detection coverage analysis, and operational time savingsAbout This SessionThis office hours format brings together the LimaCharlie team to share practical experiences with AI-powered security operations. Rather than theoretical discussions, we demonstrate working tools and invite the community to share their own AI security experiments. The session highlights the rapid evolution of AI capabilities in cybersecurity and explores the changing relationship between security practitioners and automation.Register for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.ioFollow LimaCharlieSign up for free: https://limacharlie.ioLinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie
Multi‑stage AiTM phishing and BEC campaign abusing SharePoint SmarterMail auth bypass flaw now exploited despite patch The problem of AI agents emerges at Davos Huge thanks to our sponsor, Dropzone AI All week we've talked about alert fatigue, MTTR, and the math that's breaking your SOC. Here's the proof. Dropzone AI is trusted by over 300 global enterprises and MSSPs. Named a Gartner Cool Vendor. Recognized in the Fortune Cyber 60. And backed by $37 million in Series B funding. But they're not stopping at a single agent. They're building toward fully agentic SOC teams where human engineers are augmented with specialized AI agents for threat hunting, detection engineering, and forensics. Your team deserves a backup that never sleeps. Book a demo at dropzone.ai. Find the stories behind the headlines at CISOseries.com.
First Topic - Podcast Content Plans for 2026 Every year, I like to sit down and consider what the podcast should be focusing on. Not doing so ensures every single episode will be about AI and nobody wants that. Least of all, me. If I have one more all-AI episode, my head is going to explode. With that said, most of what we talk about in this segment is AI (picard face palm.png). I think 2026 will be THE defining year for GenAI. Three years after the release of ChatGPT, I think we've hit peak GenAI hype and folks are ready for it to put up or shut up. We'll see winners grow and get acquired and losers pivot to something else. More than anything, I want to interview folks who have actually seen it work at scale, rather than just in a cool demo in a vendor sandbox. Also on the agenda for this year: The battle against infostealers and session hijacking: we didn't have a good answer in 2025. When is it coming? Will it include Macs, despite them not having a traditional TPM? The state of trust in outsourcing and third party use (Cloud, MSSPs, SaaS, contractors): 2025 was not a good year for third parties. Lots of them got breached and caused their customers a lot of pain. Also, there's the state of balkanization between the US and... the rest of the entire world. Everyone outside the US seems to be trying to derisk their companies and systems from the Cloud Act right now. Vulnerability management market disruption: there are half a dozen startups already plotting to disrupt the market, likely to come out of stealth in 2026 Future of the SOC: if it's not AI, what is it? What else??? What am I missing? What would you like to see us discuss? Please drop me a line and let me know: adrian.sanabria@cyberriskalliance.com Topic 2: The state of cybersecurity hiring This topic has been in the works for a while! Ayman had a whole podcast and book focused on all the paths people take to get into security. Jackie worked with WiSys on outlining pathways into a cybersecurity career. Whether you're already in cyber or looking for a way in, this segment crams a lot of great advice into just 15-20 minutes. Segment resources: Ayman's personal guide for getting into security https://www.wicys.org/wp-content/uploads/2025/10/WiCyS-Pathways-in-Cyber-PDF-9.24.25.pdf News Finally, in the enterprise security news, Fundings and acquisitions still strong in 2026! Santa might be done delivering gifts, but not protecting Macs! ClickFix attacks Weaponized Raspberry Pis MongoDB incidents for Christmas Top 10 Cyber attacks of 2025 US gets tough on nation state hackers? Brute force attacks on Banks An AI Vending Machine All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-441
First Topic - Podcast Content Plans for 2026 Every year, I like to sit down and consider what the podcast should be focusing on. Not doing so ensures every single episode will be about AI and nobody wants that. Least of all, me. If I have one more all-AI episode, my head is going to explode. With that said, most of what we talk about in this segment is AI (picard face palm.png). I think 2026 will be THE defining year for GenAI. Three years after the release of ChatGPT, I think we've hit peak GenAI hype and folks are ready for it to put up or shut up. We'll see winners grow and get acquired and losers pivot to something else. More than anything, I want to interview folks who have actually seen it work at scale, rather than just in a cool demo in a vendor sandbox. Also on the agenda for this year: The battle against infostealers and session hijacking: we didn't have a good answer in 2025. When is it coming? Will it include Macs, despite them not having a traditional TPM? The state of trust in outsourcing and third party use (Cloud, MSSPs, SaaS, contractors): 2025 was not a good year for third parties. Lots of them got breached and caused their customers a lot of pain. Also, there's the state of balkanization between the US and... the rest of the entire world. Everyone outside the US seems to be trying to derisk their companies and systems from the Cloud Act right now. Vulnerability management market disruption: there are half a dozen startups already plotting to disrupt the market, likely to come out of stealth in 2026 Future of the SOC: if it's not AI, what is it? What else??? What am I missing? What would you like to see us discuss? Please drop me a line and let me know: adrian.sanabria@cyberriskalliance.com Topic 2: The state of cybersecurity hiring This topic has been in the works for a while! Ayman had a whole podcast and book focused on all the paths people take to get into security. Jackie worked with WiSys on outlining pathways into a cybersecurity career. Whether you're already in cyber or looking for a way in, this segment crams a lot of great advice into just 15-20 minutes. Segment resources: Ayman's personal guide for getting into security https://www.wicys.org/wp-content/uploads/2025/10/WiCyS-Pathways-in-Cyber-PDF-9.24.25.pdf News Finally, in the enterprise security news, Fundings and acquisitions still strong in 2026! Santa might be done delivering gifts, but not protecting Macs! ClickFix attacks Weaponized Raspberry Pis MongoDB incidents for Christmas Top 10 Cyber attacks of 2025 US gets tough on nation state hackers? Brute force attacks on Banks An AI Vending Machine All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-441
First Topic - Podcast Content Plans for 2026 Every year, I like to sit down and consider what the podcast should be focusing on. Not doing so ensures every single episode will be about AI and nobody wants that. Least of all, me. If I have one more all-AI episode, my head is going to explode. With that said, most of what we talk about in this segment is AI (picard face palm.png). I think 2026 will be THE defining year for GenAI. Three years after the release of ChatGPT, I think we've hit peak GenAI hype and folks are ready for it to put up or shut up. We'll see winners grow and get acquired and losers pivot to something else. More than anything, I want to interview folks who have actually seen it work at scale, rather than just in a cool demo in a vendor sandbox. Also on the agenda for this year: The battle against infostealers and session hijacking: we didn't have a good answer in 2025. When is it coming? Will it include Macs, despite them not having a traditional TPM? The state of trust in outsourcing and third party use (Cloud, MSSPs, SaaS, contractors): 2025 was not a good year for third parties. Lots of them got breached and caused their customers a lot of pain. Also, there's the state of balkanization between the US and... the rest of the entire world. Everyone outside the US seems to be trying to derisk their companies and systems from the Cloud Act right now. Vulnerability management market disruption: there are half a dozen startups already plotting to disrupt the market, likely to come out of stealth in 2026 Future of the SOC: if it's not AI, what is it? What else??? What am I missing? What would you like to see us discuss? Please drop me a line and let me know: adrian.sanabria@cyberriskalliance.com Topic 2: The state of cybersecurity hiring This topic has been in the works for a while! Ayman had a whole podcast and book focused on all the paths people take to get into security. Jackie worked with WiSys on outlining pathways into a cybersecurity career. Whether you're already in cyber or looking for a way in, this segment crams a lot of great advice into just 15-20 minutes. Segment resources: Ayman's personal guide for getting into security https://www.wicys.org/wp-content/uploads/2025/10/WiCyS-Pathways-in-Cyber-PDF-9.24.25.pdf News Finally, in the enterprise security news, Fundings and acquisitions still strong in 2026! Santa might be done delivering gifts, but not protecting Macs! ClickFix attacks Weaponized Raspberry Pis MongoDB incidents for Christmas Top 10 Cyber attacks of 2025 US gets tough on nation state hackers? Brute force attacks on Banks An AI Vending Machine All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-441
First Topic - Podcast Content Plans for 2026 Every year, I like to sit down and consider what the podcast should be focusing on. Not doing so ensures every single episode will be about AI and nobody wants that. Least of all, me. If I have one more all-AI episode, my head is going to explode. With that said, most of what we talk about in this segment is AI (picard face palm.png). I think 2026 will be THE defining year for GenAI. Three years after the release of ChatGPT, I think we've hit peak GenAI hype and folks are ready for it to put up or shut up. We'll see winners grow and get acquired and losers pivot to something else. More than anything, I want to interview folks who have actually seen it work at scale, rather than just in a cool demo in a vendor sandbox. Also on the agenda for this year: The battle against infostealers and session hijacking: we didn't have a good answer in 2025. When is it coming? Will it include Macs, despite them not having a traditional TPM? The state of trust in outsourcing and third party use (Cloud, MSSPs, SaaS, contractors): 2025 was not a good year for third parties. Lots of them got breached and caused their customers a lot of pain. Also, there's the state of balkanization between the US and... the rest of the entire world. Everyone outside the US seems to be trying to derisk their companies and systems from the Cloud Act right now. Vulnerability management market disruption: there are half a dozen startups already plotting to disrupt the market, likely to come out of stealth in 2026 Future of the SOC: if it's not AI, what is it? What else??? What am I missing? What would you like to see us discuss? Please drop me a line and let me know: adrian.sanabria@cyberriskalliance.com Topic 2: The state of cybersecurity hiring This topic has been in the works for a while! Ayman had a whole podcast and book focused on all the paths people take to get into security. Jackie worked with WiSys on outlining pathways into a cybersecurity career. Whether you're already in cyber or looking for a way in, this segment crams a lot of great advice into just 15-20 minutes. Segment resources: Ayman's personal guide for getting into security https://www.wicys.org/wp-content/uploads/2025/10/WiCyS-Pathways-in-Cyber-PDF-9.24.25.pdf News Finally, in the enterprise security news, Fundings and acquisitions still strong in 2026! Santa might be done delivering gifts, but not protecting Macs! ClickFix attacks Weaponized Raspberry Pis MongoDB incidents for Christmas Top 10 Cyber attacks of 2025 US gets tough on nation state hackers? Brute force attacks on Banks An AI Vending Machine All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-441
The threat that puts you out of business probably won't look like a movie hack, it'll look like a normal email from your CEO. In this episode of the Registered Investment Advisor Podcast, Seth Greene interviews Scott Alldridge, CEO of IP Services and bestselling author of the VisibleOps series, who explains how modern cybercrime actually works and why most small and mid-sized companies are far more vulnerable than they think. Scott shares real breach stories, including how something as simple as leaving a printer password as “1234” led to a $187,000 theft and forced a firm into a merger. He breaks down why cybersecurity is now a board-level issue, how AI is being weaponized by attackers, and what leaders need to be doing right now to protect their data, their money, and their survival. Key Takeaways: → Most companies think “we're too small to be a target,” but attackers actively go after businesses with as few as 100 employees — and even under $1M in revenue. → Only about 1 in 7 cybersecurity breaches ever gets reported, so what you read in the news is a tiny fraction of what's actually happening. → A single weak password (like “1234” on a networked printer) can give a threat actor a doorway into your entire system. → Attackers don't smash and grab; they sit quietly for weeks or months, watch how you communicate, then imitate leadership to trigger wire transfers that look totally normal. → The “human layer” is still the biggest risk: phishing, social engineering, and reused or weak credentials are where most compromises begin. Scott Alldridge has spent three decades on the frontlines of cyber warfare—turning escalating threats into competitive advantage for business leaders. As co-founder of the IT Process Institute and creator of the globally adopted VisibleOps framework (400,000+ copies sold), he shaped how enterprises worldwide secure and scale technology. His Amazon bestseller, VisibleOps Cybersecurity, is the definitive roadmap for integrating Zero Trust principles into real business results. Today, as CEO of IP Services, one of America's most trusted MSSPs, Scott helps executives verify—not just trust—their cybersecurity posture. Driven by both expertise and altruism, Scott's mission is to ensure businesses of all sizes are resilient and protected—not only to safeguard revenue, but to prevent the devastating personal and professional fallout of cyberattacks. A globally recognized thought leader with 618K+ social media followers, he leverages his platform to raise awareness, share real-world breach stories, and arm leaders with actionable strategies that save companies before it's too late. Connect With Scott: Website: https://ipservices.com/ Instagram: https://www.instagram.com/scottalldridge1/ LinkedIn: https://www.linkedin.com/in/scott-alldridge-1a976/ FREE OFFERSText "Secure25" to 1-541-359-1269 to receive your free Visible Ops Executive Companion book and a free Penetration Scan Test (first 3 listeners only) Learn more about your ad choices. Visit megaphone.fm/adchoices
The threat that puts you out of business probably won't look like a movie hack, it'll look like a normal email from your CEO. In this episode of the Registered Investment Advisor Podcast, Seth Greene interviews Scott Alldridge, CEO of IP Services and bestselling author of the VisibleOps series, who explains how modern cybercrime actually works and why most small and mid-sized companies are far more vulnerable than they think. Scott shares real breach stories, including how something as simple as leaving a printer password as “1234” led to a $187,000 theft and forced a firm into a merger. He breaks down why cybersecurity is now a board-level issue, how AI is being weaponized by attackers, and what leaders need to be doing right now to protect their data, their money, and their survival. Key Takeaways: → Most companies think “we're too small to be a target,” but attackers actively go after businesses with as few as 100 employees — and even under $1M in revenue. → Only about 1 in 7 cybersecurity breaches ever gets reported, so what you read in the news is a tiny fraction of what's actually happening. → A single weak password (like “1234” on a networked printer) can give a threat actor a doorway into your entire system. → Attackers don't smash and grab; they sit quietly for weeks or months, watch how you communicate, then imitate leadership to trigger wire transfers that look totally normal. → The “human layer” is still the biggest risk: phishing, social engineering, and reused or weak credentials are where most compromises begin. Scott Alldridge has spent three decades on the frontlines of cyber warfare—turning escalating threats into competitive advantage for business leaders. As co-founder of the IT Process Institute and creator of the globally adopted VisibleOps framework (400,000+ copies sold), he shaped how enterprises worldwide secure and scale technology. His Amazon bestseller, VisibleOps Cybersecurity, is the definitive roadmap for integrating Zero Trust principles into real business results. Today, as CEO of IP Services, one of America's most trusted MSSPs, Scott helps executives verify—not just trust—their cybersecurity posture. Driven by both expertise and altruism, Scott's mission is to ensure businesses of all sizes are resilient and protected—not only to safeguard revenue, but to prevent the devastating personal and professional fallout of cyberattacks. A globally recognized thought leader with 618K+ social media followers, he leverages his platform to raise awareness, share real-world breach stories, and arm leaders with actionable strategies that save companies before it's too late. Connect With Scott: Website: https://ipservices.com/ Instagram: https://www.instagram.com/scottalldridge1/ LinkedIn: https://www.linkedin.com/in/scott-alldridge-1a976/ FREE OFFERSText "Secure25" to 1-541-359-1269 to receive your free Visible Ops Executive Companion book and a free Penetration Scan Test (first 3 listeners only) Learn more about your ad choices. Visit megaphone.fm/adchoices
Discover how industry veteran Larry Meador, Cavelo's new Channel Chief, is transforming the MSP channel. Cavelo empowers Managed Service Providers with a unified Attack Surface Management and Data Security Posture Management platform—offering automated data discovery, classification, vulnerability management, and compliance-ready solutions. Built for MSPs and MSSPs, Cavelo helps partners reduce cyber risk, streamline operations, and deliver scalable, data-first security services that boost profitability and client trust. Full Video Podcast Link: https://youtu.be/D6xFmrlUXDY --------------------------------------------------- Connect with us! --------------------------------------------------- MSP Unplugged https://mspunplugged.com/ Paco Lebron from ProdigyTeks:Powered by MSP Owners Group Email: paco@mspunplugged.com Rick Smith from Renactus Technology Email: rick@mspnplugged.com Justin Gilliam from Bacheler Technologies https://www.linkedin.com/in/justin-gilliam-96288a56
Building a cyber security team isn't optional anymore; it's the difference between recovering from ransomware and going out of business. In this episode, Curtis and Prasanna explain why hardening your backup infrastructure is only half the battle. You need professionals who know how to configure XDR systems without drowning you in false positives, blue teams to defend your environment, and red teams to test whether your defenses actually work. They cover the role of MSSPs, incident response planning, cyber insurance requirements, and why attempting ransomware response on your own is like those old TV warnings: "Don't try this at home." If you've been following their series on backup basics and system hardening, this episode ties it all together with the human element that makes or breaks your recovery plan.
All links and images can be found on CISO Series. Check out this post by Christofer Hoff of Truist for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Caleb Sima, builder, WhiteRabbit. Joining them is Crystal Chatam, vp of cybersecurity, Speedcast. In this episode: Understanding the fundamentals The grift of superficial expertise Hands-on experience matters A vulnerability at the leadership level Huge thanks to our sponsor, Stellar Cyber By shining a bright light on the darkest corners of security operations, Stellar Cyber empowers organizations to see incoming attacks, know how to fight them, and act decisively – protecting what matters most. Stellar Cyber's award-winning open security operations platform includes AI-driven SIEM, NDR, ITDR, Open XDR, and Multi-Layer AI™ under one unified platform with a single license. With ⅓ of the global top 250 MSSPs and over 14,000 customers worldwide, Stellar Cyber is one of the most trusted leaders in security operations. Learn more at https://stellarcyber.ai/.
Jim McDonald and Jeff Steadman sit down with Mike Reiring of RSM at InfoSec World 2025 to explore how managed service providers are reshaping IT and identity operations. They dig into the differences between MSPs and MSSPs, how to choose the right partner, and how AI is transforming help desks, problem management, and security monitoring. The conversation closes with a fun dive into Mike's passion for photography and how creativity ties into continuous learning in tech.Connect with Mike: https://www.linkedin.com/in/mreiring/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.comChapters00:00 Intro – Live from InfoSec World 202502:00 Meet Mike Reiring of RSM04:30 Evolution of Managed Service Providers06:30 Shared Accounts, Identity, and Security Maturity09:00 Vendor Gaps and Federated Access Challenges11:30 What Makes a Good MSP Partner13:00 The Cost and Effort of Changing Providers16:30 MSP vs MSSP – Key Differences18:30 Coordination Between Managed Providers21:30 Top 3 Questions to Ask Your MSP25:00 Identity Ownership: IT or Security?27:30 Licensing, Active Directory, and Hidden Accounts30:00 RFP Challenges and Procurement Pitfalls32:00 Measuring Risk and Reducing Identity Exposure34:30 Vendor Management and Shadow IT Risks35:00 How AI Is Transforming MSP and MSSP Operations38:30 AI, Problem Management, and the Future of Help Desks42:30 Photography, Creativity, and Continuous Learning48:00 Closing Thoughts and IDAC OutroKeywordsIDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Mike Reiring, RSM, InfoSec World 2025, Managed Service Provider, MSP, MSSP, AI in Cybersecurity, Help Desk, Identity Management, Managed Identity, Partner Transparency, IT Outsourcing, Risk Reduction, Problem Management, Active Directory, DaVinci Resolve, Photography in Tech, Identity Governance, Cybersecurity Podcast
We weigh the promise and peril of the AI agent economy, pressing into how overprovisioned non-human identities, shadow AI, and SaaS integrations expand risk while go-to-market teams push for speed. A CMO and a CFO align on governance-first pilots, PLG trials, buyer groups, and the adoption metrics that sustain value beyond the sale.• AI adoption surge matched by adversary AI• Overprovisioned agents and shadow AI in SaaS• Governance thresholds before budget scale• PLG trials, sandbox, and POV sequencing• Visualization to reach the aha moment• Buying groups, ICP, and economic buyer alignment• Post‑sales usage, QBRs, NRR and churn signals• Zero trust limits and non-human identities• Breach disclosures as industry standards• Co-sourcing MSSP with in-house oversightSecurity isn't slowing AI down; it's the unlock that makes enterprise AI valuable. We dive into the AI agent economy with a CMO and a CFO who meet in the messy middle. The result is a practical blueprint for moving from hype to governed production without killing momentum.We start by mapping where controls fail: once users pass SSO and MFA, agents often operate beyond traditional identity and network guardrails. That's how prompts pull sensitive deal data across Salesforce and Gmail, and how third‑party API links expand the attack surface. From there, we lay out an adoption sequence that balances trust and speed. Think frictionless free trials and sandboxes that reach an immediate “aha” visualization of shadow AI and permissions, then progress to a scoped POV inside the customer's environment with clear policies and measurable outcomes. Along the way, we detail the buying group: economic buyers who sign and practitioners who live in the UI, plus the finance lens that sets pilot capital, milestones, and time-to-value expectations.We also challenge sacred cows. Zero trust is essential, but attackers increasingly log in with valid credentials and pivot through integrations, so verification must include non-human identities and agent-to-agent controls. Breach disclosures, far from being a greater threat than breaches, are foundational to ecosystem trust and faster remediation. And while MSSPs add critical scale, co-sourcing—retaining strategic oversight and compliance ownership—keeps accountability inside. If you care about ICP, PLG motions, PQLs, NRR, or simply reducing AI risk while driving growth, this conversation turns buzzwords into a playbook you can run.Vamshi Sriperumbudur: https://www.linkedin.com/in/vamsriVamshi Sriperumbudur was recently the CMO for Prisma SASE at Palo Alto Networks, where he led a complete marketing transformation, driving an impact of $1.3 billion in ARR in 2025 (up 35%) and establishing it as the platform leader. Chithra Rajagopalan - https://www.linkedin.com/in/chithra-rajagopalan-mba/Chithra Rajagopalan is the Head of Finance at Obsidian Security and former Head of Finance at Glue, and she is recognized as a leader in scaling businesses. Chithra is also an Investor and Advisory Board member for Campfire, serving as the President and Treasurer of Blossom Projects.Website: https://www.position2.com/podcast/Rajiv Parikh: https://www.linkedin.com/in/rajivparikh/Sandeep Parikh: https://www.instagram.com/sandeepparikh/Email us with any feedback for the show: sparkofages.podcast@position2.com
The threat that puts you out of business probably won't look like a movie hack, it'll look like a normal email from your CEO. In this episode of Sharkpreneur, Seth Greene interviews Scott Alldridge, CEO of IP Services and bestselling author of the Visible Ops series, who explains how modern cybercrime actually works and why most small and mid-sized companies are far more vulnerable than they think. Scott shares real breach stories, including how something as simple as leaving a printer password as “1234” led to a $187,000 theft and forced a firm into a merger. He breaks down why cybersecurity is now a board-level issue, how AI is being weaponized by attackers, and what leaders need to be doing right now to protect their data, their money, and their survival. Key Takeaways: → Most companies think “we're too small to be a target,” but attackers actively go after businesses with as few as 100 employees — and even under $1M in revenue. → Only about 1 in 7 cybersecurity breaches ever gets reported, so what you read in the news is a tiny fraction of what's actually happening. → A single weak password (like “1234” on a networked printer) can give a threat actor a doorway into your entire system. → Attackers don't smash and grab; they sit quietly for weeks or months, watch how you communicate, then imitate leadership to trigger wire transfers that look totally normal. → The “human layer” is still the biggest risk: phishing, social engineering, and reused or weak credentials are where most compromises begin. Scott Alldridge has spent three decades on the frontlines of cyber warfare—turning escalating threats intocompetitive advantage for business leaders. As co-founder of the IT Process Institute and creator of the globally adopted VisibleOps framework (400,000+ copies sold), he shaped how enterprises worldwide secure and scale technology. His Amazon bestseller, VisibleOps Cybersecurity, is the definitive roadmap for integrating Zero Trust principles into real business results. Today, as CEO of IP Services, one of America's most trusted MSSPs, Scott helps executives verify—not just trust—their cybersecurity posture. Driven by both expertise and altruism, Scott's mission is to ensure businesses of all sizes are resilient and protected—not only to safeguard revenue, but to prevent the devastating personal and professional fallout of cyberattacks. A globally recognized thought leader with 618K+ social media followers, he leverages his platform to raise awareness, share real-world breach stories, and arm leaders with actionable strategies that save companies before it's too late. Connect With Scott Aldridge: Website: https://ipservices.com/ Instagram: https://www.instagram.com/scottalldridge1/?hl=en LinkedIn: https://www.linkedin.com/in/scott-alldridge-1a976/ Learn more about your ad choices. Visit megaphone.fm/adchoices
The threat that puts you out of business probably won't look like a movie hack, it'll look like a normal email from your CEO. In this episode of Sharkpreneur, Seth Greene interviews Scott Alldridge, CEO of IP Services and bestselling author of the Visible Ops series, who explains how modern cybercrime actually works and why most small and mid-sized companies are far more vulnerable than they think. Scott shares real breach stories, including how something as simple as leaving a printer password as “1234” led to a $187,000 theft and forced a firm into a merger. He breaks down why cybersecurity is now a board-level issue, how AI is being weaponized by attackers, and what leaders need to be doing right now to protect their data, their money, and their survival. Key Takeaways: → Most companies think “we're too small to be a target,” but attackers actively go after businesses with as few as 100 employees — and even under $1M in revenue. → Only about 1 in 7 cybersecurity breaches ever gets reported, so what you read in the news is a tiny fraction of what's actually happening. → A single weak password (like “1234” on a networked printer) can give a threat actor a doorway into your entire system. → Attackers don't smash and grab; they sit quietly for weeks or months, watch how you communicate, then imitate leadership to trigger wire transfers that look totally normal. → The “human layer” is still the biggest risk: phishing, social engineering, and reused or weak credentials are where most compromises begin. Scott Alldridge has spent three decades on the frontlines of cyber warfare—turning escalating threats intocompetitive advantage for business leaders. As co-founder of the IT Process Institute and creator of the globally adopted VisibleOps framework (400,000+ copies sold), he shaped how enterprises worldwide secure and scale technology. His Amazon bestseller, VisibleOps Cybersecurity, is the definitive roadmap for integrating Zero Trust principles into real business results. Today, as CEO of IP Services, one of America's most trusted MSSPs, Scott helps executives verify—not just trust—their cybersecurity posture. Driven by both expertise and altruism, Scott's mission is to ensure businesses of all sizes are resilient and protected—not only to safeguard revenue, but to prevent the devastating personal and professional fallout of cyberattacks. A globally recognized thought leader with 618K+ social media followers, he leverages his platform to raise awareness, share real-world breach stories, and arm leaders with actionable strategies that save companies before it's too late. Connect With Scott Aldridge: Website: https://ipservices.com/ Instagram: https://www.instagram.com/scottalldridge1/?hl=en LinkedIn: https://www.linkedin.com/in/scott-alldridge-1a976/ Learn more about your ad choices. Visit megaphone.fm/adchoices
I used to think "Always Be Closing" was outdated, sleazy sales advice, but I've completely changed my mind. In this video, I break down why ABC is actually the foundation of consultative selling for MSSPs and B2B sales. The truth is, every single step in your sales process—from discovery calls to assessments to proposals—should be designed with one goal: moving the deal forward and closing the sale. I'll show you the simple framework I use to redesign sales processes, explain why most salespeople are treating discovery and assessments like information gathering instead of closing opportunities, and reveal the biggest mistake I see during proposals that kills deals. If you're in MSP sales or any B2B selling, this reframe will change how you approach every interaction with prospects.//Welcome to Repeatable Revenue, hosted by strategic growth advisor , Ray J. Green.About Ray:→ Former Managing Director of National Small & Midsize Business at the U.S. Chamber of Commerce, where he doubled revenue per sale in fundraising, led the first increase in SMB membership, co-built a national Mid-Market sales channel, and more.→ Former CEO operator for several investor groups where he led turnarounds of recently acquired small businesses.→ Current founder of MSP Sales Partners, where we currently help IT companies scale sales: www.MSPSalesPartners.com→ Current Sales & Sales Management Expert in Residence at the world's largest IT business mastermind.→ Current Managing Partner of Repeatable Revenue Ventures, where we scale B2B companies we have equity in: www.RayJGreen.com//Follow Ray on:YouTube | LinkedIn | Facebook | Twitter | Instagram
Send us a textIn this episode of Joey Pinz Discipline Conversations, Joey sits down with Scott Fuhriman, cybersecurity veteran and leader at Inveri, live from the MSP Summit in Orlando.Scott shares his 25+ years of cybersecurity experience, explaining how Inveri's runtime integrity technology, born from NSA research, helps MSPs and MSSPs detect hidden in-memory attacks, rootkits, and advanced threats that traditional tools miss. He highlights why protecting this overlooked layer is crucial to preserving revenue, preventing churn, and maintaining customer trust.The conversation also touches on Scott's personal discipline journey — from starting as a young PC tech overwhelmed by information to building a career through self-study, mentorship, and consistency. He and Joey discuss how MSPs can choose the right vendors, strengthen their security stacks, and enable long-term resilience in a competitive market.
Stellar Cyber Revolutionizes SOC Cybersecurity Operations with Human-Augmented Autonomous Platform at Black Hat 2025 A Stellar Cyber Event Coverage of Black Hat USA 2025 Las VegasAn ITSPmagazine Brand Story with Subo Guha, Senior Vice President Product, Stellar Cyber____________________________Security operations centers face an unprecedented challenge: thousands of daily alerts overwhelming analyst teams while sophisticated threats demand immediate response. At Black Hat USA 2025 in Las Vegas, Stellar Cyber presented a revolutionary approach that fundamentally reimagines how SOCs operate in the age of AI-driven threats.Speaking with ITSPmagazine's Sean Martin, Subo Guha, Senior Vice President of Products at Stellar Cyber, outlined the company's vision for transforming security operations through their human-augmented autonomous SOC platform. Unlike traditional approaches that simply pile on more automation, Stellar Cyber recognizes that effective security requires intelligent collaboration between AI and human expertise.The platform's three-layer architecture ingests data from any source – network devices, applications, identities, and endpoints – while maintaining vendor neutrality through open EDR integration. Organizations can seamlessly work with CrowdStrike, SentinelOne, Sophos, or other preferred solutions without vendor lock-in. This flexibility proves crucial for enterprises navigating complex security ecosystems where different departments may have invested in various endpoint protection solutions.What sets Stellar Cyber apart is their autonomous SOC concept, which dramatically reduces alert volume from hundreds of thousands to manageable numbers within days rather than weeks. The platform's AI-driven auto-triage capability identifies true positives among thousands of false alarms, presenting analysts with prioritized "verdicts" that demand attention. This transformation addresses one of security operations' most persistent challenges: alert fatigue that leads to missed threats and burned-out analysts.The revolutionary AI Investigator copilot enables natural language interaction, allowing analysts to query the system conversationally. An analyst can simply ask, "Show me all impossible travel incidents between midnight and 4 AM," and receive actionable intelligence immediately. This democratization of security operations means junior analysts can perform at senior levels without extensive coding knowledge or years of experience navigating complex query languages.Identity threat detection and response (ITDR) emerged as another critical focus area during the Black Hat presentation. With identity becoming the new perimeter, Stellar Cyber integrated sophisticated user and entity behavior analytics (UEBA) directly into the platform. The system detects impossible travel scenarios, credential attacks, and lateral movement patterns that indicate compromise. For instance, when a user logs in from Portland at 11 PM and then appears in Moscow 30 minutes later, the platform immediately flags this physical impossibility.The identity protection extends beyond human users to encompass non-human identities, addressing the growing threat of automated attacks powered by large language models. Hackers now leverage generative AI to create credential attacks at unprecedented scale and sophistication, making robust identity security more critical than ever.Guha emphasized that AI augmentation doesn't displace security professionals but elevates them. By automating mundane tasks, analysts focus on strategic decision-making and complex threat hunting. MSSPs report dramatic efficiency gains, scaling operations without proportionally increasing headcount. Where previously a hundred thousand alerts might take weeks to process, requiring extensive junior analyst teams, the platform now delivers actionable insights within days with smaller, more focused teams.The platform's unified approach eliminates tool sprawl, providing CISOs with real-time visualization of their security posture. Executive reporting becomes instantaneous, with high-priority verdicts clearly displayed for rapid decision-making. This visualization capability transforms how security teams communicate with leadership, replacing lengthy reports with dynamic dashboards that convey risk and response status at a glance.Real-world deployments demonstrate significant operational improvements. Organizations report faster mean time to detection and response, reduced false positive rates, and improved analyst satisfaction. The platform's learning capabilities mean it becomes more intelligent over time, adapting to each organization's unique threat landscape and operational patterns.As organizations face increasingly sophisticated threats powered by generative AI, Stellar Cyber's human-augmented approach represents a paradigm shift. By combining AI intelligence with human intuition, the platform delivers faster threat detection, reduced false positives, and empowered security teams ready for tomorrow's challenges. The company's commitment to continuous innovation, evidenced by rapid feature releases between RSA and Black Hat, positions them at the forefront of next-generation security operations. Learn more about Stellar Cyber: https://itspm.ag/stellar-cyber--inc--357947Note: This story contains promotional content. Learn more.Guest: Subo Guha, Senior Vice President Product, Stellar Cyber | https://www.linkedin.com/in/suboguha/ResourcesLearn more and catch more stories from Stellar Cyber: https://www.itspmagazine.com/directory/stellarcyberLearn more and catch more stories from our Black Hat USA 2025 coverage: https://www.itspmagazine.com/bhusa25Learn more about ITSPmagazine Brand Story Podcasts: https://www.itspmagazine.com/purchase-programsNewsletter Archive: https://www.linkedin.com/newsletters/tune-into-the-latest-podcasts-7109347022809309184/Business Newsletter Signup: https://www.itspmagazine.com/itspmagazine-business-updates-sign-upAre you interested in telling your story?https://www.itspmagazine.com/telling-your-story