POPULARITY
Send us Fan MailSaurabh Sandhir, CEO and Co-Founder of Kipling Secure, joins Joey Pinz for a sharp conversation on AI risk, MSP opportunity, and the personal journey from India to Silicon Valley leadership. Saurabh shares how his early exposure to engineering, Atari BASIC, IIT Delhi, Purdue, Juniper, Ericsson, Nokia, and Nuage Networks shaped the way he thinks about technology, business, and leadership.The conversation moves into one of the most important issues facing businesses today: unmanaged AI. Saurabh explains how AI adoption is creating new risks around shadow AI, sensitive data exposure, AI-specific attacks, and misleading content. His message is clear: AI should not be blocked, but it must be governed.For MSPs and MSSPs, Saurabh sees a major opportunity. Kipling Secure helps service providers turn AI risk into a new recurring revenue stream through AI Detection and Response built for multi-tenant MSP workflows.The episode closes with a thoughtful discussion on discipline, identity, humility, and why lasting consistency comes from who you are—not just what you force yourself to do. Top 3 Highlights
Today’s headline news for Canadian IT solution providers: [Blumira]: The company on Tuesday launched Hearth, a vendor-agnostic AI command center that Blumira says can intelligently reason across security tools and services an organization already uses. The platform is available in the Pax8 Marketplace, giving MSPs a unified interface to monitor and respond across multi-vendor environments. Read the announcement on Business Wire [Vistera]: The Vancouver-based company on Tuesday unveiled a professional services platform powered by Vero, a multi-agent orchestration layer that Vistera says brings legal, HR, and finance expertise to Canadian SMBs in British Columbia, Alberta, and Ontario. Every output is reviewed by a senior Canadian-qualified professional before delivery, with outcomes priced at $700 each or through monthly plans. Learn more on Vistera [CrowdStrike]: Justin Bradley, senior alliances manager for MSSP aggregators at CrowdStrike, warned attendees at XChange August this week that the group behind Akira ransomware — referred to as Punk Spider — has increased attacks by 134 percent over the past year, specifically targeting SMBs through MSPs. The group buys VPN credentials on the dark web, uses MFA fatigue to gain access, and dumps Entra IDs before deploying ransomware. Read more on CRN [ConnectSecure]: The company on Tuesday added M365 Auto Remediation, AI-powered training assessments, and Patch 360 to its MSP platform, allowing providers to automatically remediate supported Microsoft 365 security findings across multiple tenants. Read more on Channel Dive [GTIA]: The Global Technology Industry Association warned at ChannelCon last week that customers are deploying AI faster than MSPs can deliver security and governance, and announced a new Managed Intelligence Alliance to develop standards and accreditations for AI services. Read more on Channel Dive [NetRise]: The company on August 3 launched its Discovery Partner Program to expand software supply chain security through MSSPs, VARs, and distributors. Read the announcement on PR Newswire [Verizon]: Channel chief and vice president of indirect partner sales Mark Tina is leaving the telecommunications company after 23 years to become vice president of national partner sales and distribution at health insurer Humana. Read more on Channel Dive Read Full Transcript Welcome to The Buzz from ChannelBuzz.ca, I’m Robert Dutt, today is Thursday, August 13, and here’s what’s happening in the channel today. Blumira on Tuesday launched Hearth, a vendor-agnostic AI command center that the company says can intelligently reason across security tools and services an organization already uses. According to Blumira, the platform is designed to unify visibility and response across the workspace without requiring a rip-and-replace approach, giving lean IT teams a single interface to monitor disparate tools. Hearth is available in the Pax8 Marketplace, positioning it for MSPs that provision through that platform. Blumira is pitching the offering as a way to reduce tool sprawl and alert fatigue for teams that lack enterprise-scale resources. A unified reasoning layer across multi-vendor stacks could cut down on the context-switching that slows incident response for Canadian MSPs, though the value will depend on integration depth and the accuracy of the AI-driven reasoning. Vistera on Tuesday unveiled a Canadian-built professional services platform powered by Vero, a multi-agent orchestration layer that the company says brings legal, HR, and finance expertise to small and medium-sized businesses at a predictable cost. The Vancouver-based company is targeting Canadian SMBs in British Columbia, Alberta, and Ontario with outcomes priced at $700 each or through monthly plans, a fraction of the typical hourly rates at large firms. According to Vistera, every output is reviewed and signed off by a senior Canadian-qualified professional before it reaches the client, with credential verification and regulatory standing checks built into the workflow. The platform handles intake, research, and preparation through AI agents while preserving human oversight for final judgment. Canadian MSPs should watch how this model lands, as it could create new partnership opportunities around SMB advisory services or introduce competitive pressure in the professional services space. CrowdStrike this week warned attendees at XChange August that prolific ransomware groups are specifically targeting MSPs and their SMB customers. According to Justin Bradley, senior alliances manager for MSSP aggregators at CrowdStrike, the group behind Akira ransomware — referred to as Punk Spider — has increased its attacks by 134 percent over the past year with an emphasis on SMBs. Bradley said the group’s typical strategy involves buying VPN credentials on the dark web, then using MFA fatigue to gain initial access, escalating privileges, and dumping Entra IDs before deploying ransomware. He also noted that CrowdStrike is tracking two break-off groups from Scattered Spider, dubbed Cordial Spider and Snarky Spider, which have been known to impersonate MSPs to trick customers into launching remote access tools. The intelligence underscores the urgency for Canadian MSPs to harden identity controls and monitor for MFA abuse, particularly as credential theft continues to fetch thousands of dollars on dark web markets. In Brief – ConnectSecure says its new M365 Auto Remediation tool lets MSPs approve and automatically apply fixes across multiple customers for supported Microsoft 365 security findings. The Global Technology Industry Association warns at ChannelCon that customers are deploying AI faster than MSPs can secure it, and says it is launching a Managed Intelligence Alliance to set standards for AI services. NetRise says its new Discovery Partner Program will expand software supply chain security through MSSPs, VARs, and distributors. Verizon confirms channel chief Mark Tina is leaving after 23 years to become vice president of national partner sales and distribution at Humana. Full details and links in the show notes or the blog post. That’s how we’re seeing the headlines today. I’m Robert Dutt for ChannelBuzz.ca, thanks for listening. Have a great day.
Craig Patterson, global channel chief at Exabeam For years, SIEM has been one of those technologies that looked good in theory but was genuinely hard to build a profitable managed service around. Deal-by-deal discount negotiations, licensing structures built for enterprise resale rather than recurring managed services revenue, and no predictable floor on margin. For many MSPs, the math just never worked. Exabeam – the combined company formed from the merger of the original Exabeam and LogRhythm – is making a direct play to change that. Global channel chief Craig Patterson and senior director of service provider alliances Peter Stratis join In The Channel to walk through the new MSSP commercial framework inside the recently launched APEX Partner Program. Two new licensing pathways: a single-pool capacity model for high-volume, multi-tenant environments serving SMB and mid-market clients, and a federated subscription model that isolates customer environments for compliance and data sovereignty requirements. For Canadian MSSPs navigating PIPEDA, OSFI E-21, or Protected B, that second model is the one to pay close attention to. Peter Stratis, senior directof of server provider alliances at Exabeam The conversation also covers Sherpa, Exabeam’s new AI-powered partner enablement platform – a move away from the traditional LMS toward an always-on coaching tool that can join partner sales calls in real time – and Agent Behavior Analytics, Exabeam’s new capability for detecting malfunctioning, misaligned, and subverted AI agents inside customer environments, included at no additional cost. The standout line from Peter Stratis – who called this his first-ever podcast appearance – is the one worth writing down: “We treated our service providers like resellers, unfortunately.” The new framework is a direct acknowledgment of that history, and an attempt to rebuild the commercial relationship from the ground up. Read Full Transcript Robert Dutt: Hello and welcome to In The Channel from ChannelBuzz.ca, bringing news and information to the Canadian IT channel community for the last 16 years. I’m Robert Dutt, editor of ChannelBuzz.ca and your host for the show. If you’ve been in the channel for any length of time, you know that SIEM has always been one of those technologies that seems great in theory but has been genuinely hard to build a profitable managed service around. Licensing models that weren’t built for multi-tenancy, unpredictable costs, discount structures that made margin planning more of a guessing game than a business model. A lot of MSPs have looked at the security operations space and quietly backed away for exactly those reasons. Exabeam, the combined company that emerged out of the merger of Exabeam and LogRhythm, is making a direct play to change that. They have overhauled their channel program into what they’re calling the APEX Partner Program and at the centre of it is a new commercial framework built specifically for managed security service providers. Two distinct pathways: one for high-volume multi-tenant environments and one built with compliance and data sovereignty in mind. For Canadian MSPs navigating PIPEDA, OSFI E-21 and Protected B requirements, that second lane is worth paying close attention to. I’ve got two Exabeam executives here to walk us through it. Craig Patterson is Exabeam’s global channel chief and Peter Stratis is the senior director of service provider alliances, the person who’s been working directly with MSSPs to build this out from the ground up. Let’s get right into it. My chat with Craig Patterson and Peter Stratis. Gentlemen, thank you for taking the time. Craig Patterson: Thank you, Robert. Super excited to be on here with you today, my friend. Peter Stratis: Thank you. Robert Dutt: Craig, can you just kick us off with a quick version of where Exabeam sits right now? You know, you guys went through a significant merger with LogRhythm not that long ago. Now you’re pushing an updated partner program. For solution providers who maybe haven’t been following closely, what does the combined company look like from a channel perspective? Craig Patterson: The short answer, my friend, is that we’re sitting in an amazing place. We’re absolutely in a good place positioning to really drive value to our partner community. And so to give you a little more context around that, like you asked, we’ve spent the last 12 months really kind of rethinking, reimagining the whole partner ecosystem in a way to create value for all of our partners globally. And so there was a number of things we went through over the last 12 months. We spent a lot of time really going to this assessment loop, understanding everybody’s perspective. So we did that by having very strategic conversations with our top-tier partners. We did some survey work. We looked at the broad landscape in terms of the trends that the partners are really looking for in these modern channel programs. So all of that really became this assessment loop. The output of that is that really became the foundation for what we built here with APEX. And so with APEX, the Exabeam APEX Partner Program, what you have here is you have a program that’s really centered on value that’s really focused on solving a problem that exists in our market today around enablement. And so when you think about enablement today, I’ve written a lot of articles on this. Most enablement programs really don’t drive to the level of outcome that companies are looking to have. Outcomes like conversion rates, outcomes like time to first deal, outcome rates like retention rates, all these things. And so what we’ve done is we’ve really focused on enablement as the key catalyst to really drive value to our partners. And so with that, we’ve launched new enablement programs really with a focus on increasing their competency level so we can align to those outcomes we’re looking to have with our company’s operating plan. And so there’s a lot of thought that’s got into this. The short answer is we have a program that’s built on value. It aligns to where the market is going and what partners are really asking for. Robert Dutt: Peter, your title as senior director of service provider alliances is a pretty specific role. Can you tell us a little bit about what that looks like sort of on a day-to-day basis and the big problems that you’re focused on? Peter Stratis: Sure thing. Thanks, Robert. Well, I’ve been with Exabeam for about eight years now and service providers have always been a key component of not only our channel strategy, but our go-to-market and just from our net new revenue perspective. After our merger with LogRhythm, that actually continues and if anything, it’s only been more emphasized because both from an on-prem and from a cloud perspective, we see the MSSPs being a strong driver of that strategy of our go-to-market. So over the last eight years, we’ve seen that trend of not only on net new revenue, net new logos being a major part of our business, but then how do, to Craig’s point, how do we support them? To be quite honest, in the past, it was quite difficult. We really didn’t have any kind of structured pricing for these partners. It was, to say the least, it was more of a resale program that had some discounts tied to it. So through Craig’s efforts, through our whole surveys and our intent to really go after this market and treat them the way they should be treated, he mentioned that we did these surveys. We asked internally, what do you look for in a service provider partner? We asked externally what these partners were looking for from us. And that’s when in building the APEX Partner Program here at Exabeam, we also took into account what service providers would look for in a new partner program. So that’s everything from pricing to support. Craig mentioned enablement. Enablement is a huge part of that, where they felt in the past they were just lumped up as just a regular partner. Now we have supported APIs, documented APIs that most, if not all, of our partners are using as part of their foundation for their services. So we’ve really come a long way and continue actually to build upon that, as you’ll see throughout 2026 and beyond. Robert Dutt: Okay, let’s get into the framework itself. You guys positioned it at launch as solving commercial and operational friction for MSSPs. Curious, what did you hear that friction looked like in practice? What were MSSPs telling you was broken or was a big challenge? Craig Patterson: Yeah, so I’ll take a stab at this and I’ll let Peter give more context. So a lot of this came out during that assessment phase. Robert, we’re talking to the MSSPs globally. I’m like, what’s working? What’s not working? What would they like to see incorporated into the MSSP program 2.0? So a lot of the feedback we heard was really around the flexibility. Being able to have a license that is catering to all the customer demand they have beneath. So it’s really giving them the flexibility to buy that one license and carve it up as they see fit. And giving them more flexibility on the commercial terms. That was a lot of the commentary we heard. The other thing we heard was really they wanted more value as it leads to the enablement side. So obviously getting them enabled on the pre-sales side, but more importantly on the post-sales side. So they could actually drive those implementations, drive the management and really help those customers create a lot of value. And so I think those were kind of the big levers that I heard from those assessments. And then in practice, Peter can give you some more context in terms of how we’re putting all this together. Peter Stratis: Yeah, thanks Craig. A lot of what we heard from the service provider community in the past was friction. So when they’re trying to price out their services and our product and etc., they were seeing friction at onboarding. They were seeing friction in trying to predict their margin on deals. As mentioned, not airing any dirty laundry here. It was more like a resale program. So we gave discounts and there were very opportunistic discounts on a deal-by-deal basis. So they didn’t build predictable service models around it in the past. And then you always hear the buzzword, multi-tenancy. We kept on getting asked about our multi-tenant roadmaps, etc. We’re looking at this framework as a way of solving for that. We continue to make feature enhancements into the platform that will strive for that multi-tenancy. But the way we’re solving for it is by these two pathways. One is that single license, pooled capacity, data segregation model. And the other is that federated workflow that we announced where it’s more for, whether you’re within data sovereignty, if in different regions or just different use cases from a compliance perspective, whether it’s healthcare or finance, and you have to keep these environments isolated. We have a plan and we worked with our MSSPs specifically to have these kind of pathways. So we heard from our MSSPs and we actually developed these two pathways with them in mind. So they were in the design phase and in the rollout phase for both federated and the single pool capacity. Robert Dutt: The federated model is such an interesting one, I think, for the Canadian market, specifically data sovereignty, huge topic. And there are specific compliance requirements, PIPEDA, OSFI E-21, Protected B status. It means that a lot of Canadian MSSPs can’t just kind of throw everything into one pool. Was that the sort of thing that was explicitly on the radar when you built this out or a happy coincidence of the architecture and the feedback that you heard along the way? Peter Stratis: It’s actually a little of both, right? So it just so happened to be the maturity of our platform. Even from our Exabeam New Scale platform, we went from an on-prem hardware appliance way back in 2012, to our version 1.0 was a SaaS product, to our native cloud. It was always a single-tenant solution. So it worked well for certain service providers that had the capacity. They had their APIs and their own platforms that could manage this solution. As you heard more and more about multi-tenancy and the need for data sovereignty and all that, we still had a big part of our MSSPs were asking for this single license pooled capacity. So we structured it in a way where for midsize organizations or even some small, medium business, you still have that single pool capacity using data segregation. You lose some of the customization, but you could actually solve for a lot of those customers in that model. And then you have another plan with the federated. So the more mature MSSPs are running both models in some capacity. They could still run that single license for their SMB play. And then for either large enterprise or very compliance-driven customers that want those isolated environments, they have that flexibility. And that’s what we built a framework around. Obviously, that’s one point of feedback that sort of directly informed the framework. Robert Dutt: You guys have said that this whole thing was built, as you said, with direct collaboration with your MSSP partners rather than kind of coming down on high. I’m curious along with what you’ve touched on already, what actually changed as a result of going through that process? What did you go in thinking you’d build and how did it come out differently because of what partners told you along the way to building it? Craig Patterson: Yeah. So I think there’s a lot of things that have been addressed. Obviously, the packaging and the commercial aspects as Peter was describing, but think about some of the fundamental problems in terms of partners want this path to profitability, right? Really understanding how they can create margin. That was one thing. Another path is like, how do I become enabled with Exabeam? And how do I stay informed in terms of where you’re going? Another problem we wanted to solve. So I think it’s a lot around the financial aspects of doing business with us. A lot of it’s around becoming enabled, becoming more knowledgeable on all the new features and releases that we’re dropping. And so those were some of the big fundamentals that we wanted to solve in the APEX framework. And then beneath that, obviously, is the whole MSSP play. And that’s what Peter’s been talking about. So you can probably give a little more context on that. Peter Stratis: Yeah. As mentioned, there is no one-size-fits-all. So the feedback we were getting was obviously their security platform was important to them. Some of them had an in-house platform they built on their own. And there’s ways of differentiating. So basic SIEMs are just going after alert monitoring. So how can I differentiate my service if I’m a service provider? Well, there’s ways of going to market, but also there were things we needed to do in the back office from a platform perspective to make those possible. So making our behavioral analytics available in these models so they can actually differentiate their services. As I said, we have a history of actually adding features quarter-over-quarter, month-over-month. So that’s not stopping. We didn’t announce necessarily multi-tenancy to the world. We announced a commercial framework for that. So you’ll continue to see on a month-to-month, quarter-over-quarter basis, features added to support not only the commercial framework, but the underlying platform to make it easier for service providers to add that operational efficiency, to add those differentiators from a product portfolio as well. Robert Dutt: Let’s talk about the economics underneath there. You use the term predictable margins as a phrase that shows up in the messaging. SIEM has historically been a tough service to make money on. Licensing models that didn’t fit the managed services motion, unpredictable costs on data ingestion, those sorts of things. What specifically changes for an MSSP’s P&L under the framework? Craig Patterson: Yeah. So I think there’s really two components here. The first is the whole financial package associated to the MSSP partners. And the second is the discounting framework. And so let’s maybe start with the discounting framework. One of the observations that we made during this whole assessment phase was the vast majority, Robert, of all of our deals were flowing through this non-standard process, which means the discounts that were aligned to the traditional framework were not putting the MSSP partners in a position to actually transact. And so what we did is we went through and we re-looked at the discounting framework and sort of realigned it based upon our actual data points. We looked at the last 12, 24 months, the discounts that were being derived to actually transact. And we sort of rebuilt the entire discounting framework for our company in a way that really empowers the MSSP partners now to have enough discount to actually transact without going to this non-standard queue. So what does it mean? Well, we really kind of flipped the script. Instead of 80% being non-standard, we believe 80% will flow through the standard process now because we’ve built the discounts in a way to align with what the market is looking for. That’s kind of the key component number one. And then as it relates to the discounting side, we reimagined how those discounts are calculated. And so now you kind of have your standard program discount. So that’s based upon your tier. So top-tier MSSP partners get the highest level discount. The second is deal registration. Obviously, they put the deal reg in that ties to a discount. Those are both standard common things. But what’s new, which is what you care about. What is new? Well, we’ve aligned the third discount based to their competency level. And so we measure that based upon certifications. And so if you think back to those choose-your-own-adventure books as a kid, we’re really giving the partners their own choose-your-own-adventure. And if they want to drive to the highest level discount, well, simply, MSSP partners got to go take all of our certifications, pre-sales and post-sales, so they have the highest level of competency to drive our services in the market. And our thesis around that is partners that have higher certifications, they’re going to be more active, they’re going to be more interested, they’re going to drive more pipeline. And if we do this the right way, Robert, they’re actually going to convert at a higher percentage, we’re going to see shortened sales cycles, all of which align to the operating plan of our company. So it’s kind of those two fundamental things that were addressed through that process. And then I’m sure Peter can fill in the detail for you. Peter Stratis: Yeah, if I can actually elaborate on that. Thanks for that, Craig. And just some historical context, Robert, as mentioned in the past, we treated our service providers like resellers, unfortunately, so it was very deal-specific in terms of what they were getting on a deal-by-deal basis from a discount. So the economics of it was they really couldn’t rationalize their margin predictability on an overall services basis. And you know, different regions go to market different ways. In Europe, Asia, Latin America, predominantly, it’s all SIEM as a service and MSSP owns the license. In the Americas, both US and Canada, we saw a lot of proliferation in the past of customer-owned licenses. So the MSSP would resell the license, and consequently, just provide managed services wrap on top of that. Not only do we see more of that MSSP-owned model now where it’s SIEM as a service in the US and Canada. So it’s proliferated itself throughout all the regions. Now with these frameworks, we actually are able to build these economics, the margin predictability, as Craig mentioned, because now they know as a standard, what they’re going to be selling for. So especially as we do this federated model, and even the single license, you know what your price is across the board, you know what license you’re buying, you know what price you’re buying it for, you know, the more customers you add to these models, the more your profitability will increase as well. So it continues to grow from a pure profit play. Partners want to know what their margin would be as their customer licenses grow. And this is exactly what the framework did. Robert Dutt: This is sort of a broader question around MSP/MSSP distinctions as opposed to directly about the framework. But there’s a distinction worth drawing between an MSP trying to bolt a security practice onto the existing managed services business and the established MSSP who’s been at this for a year or who has built it up. Are those two different conversations for you? And if so, what are the different entry points and care-abouts? Peter Stratis: So it’s interesting, not only because of this announcement, even prior to it, the announcement of the APEX Partner Program here at Exabeam caused a lot of interest from partners and different kinds of partners. The traditional MSP, when inquiring, it was kind of hard when we were vetting them that they had no security practice of their own. So oftentimes they would actually outsource that security to an MSSP, to a classic MSSP, or maybe just resell services from those other organizations. We see that, we see a lot of interest from MSPs with that. And we see VARs or resellers come to us that want to build managed service practices as well. So we look at both of these in two different ways. One, how can we take care of these partner inquiries now, and then how can we grow with these organizations? So both MSPs and resellers that are interested in managed services now, our first inkling is to try to introduce them to our current managed service base. These people have the experience, they have the certifications, they have the technical knowledge. We’ve seen that move from a lot of MSP partners actually having channels of their own. So they actually sell their MDR or MSSP services through a channel of resellers or MSPs. But then if that’s our first step with these type of partnerships, then it’s like, how can we grow within your organization? How can we help you get the technical skills required? Because for a true MSP to have success, not only in SIEM, but just security as a service, you can’t just train one or two people, you need the 24-by-7 support, you need the tier one and tier two level of support services as well. So you have to grow your organization or outsource it to people that are already prepared to handle that. So that MSP play, we actually see it more and more going towards our current managed security service providers and getting that as a resource. Craig Patterson: Just to add a little more context to that too. So this actually becomes a very interesting point for the distributors worldwide as well. Because a lot of what they provide in terms of value is helping those MSPs in terms of deployment and management of the services. And so we’ve gone through the vetting process globally, looking at all of our distributors and we’ve handpicked our strategic distributors around the world. So if we have MSPs that want to come into the program, but they’re not ready on that post-sale side, well, guess what? That can become the role of the distributor. And secondarily, this is where the enablement really comes into play as well. And so that’s why we’ve built very specific paths on enablement, pre-sales and post-sales, where partners can choose their own adventure. “Hey, if I want to get going on the pre-sale side, well, guess what? I can simply resell.” Or, “Hey, I want to really start focusing on the post-sales services implementation.” I can start to take the enablement around those courses to become more of an expert to really give me those new capabilities. And so there’s a whole conversation around what we’re doing on enablement with our brand new Sherpa that’s really given a lot of these partners those capabilities. Robert Dutt: On the note of Sherpa, an AI-powered tool for partners, it’s essentially a virtual channel account manager in terms of enablement, onboarding, that sort of thing, especially for an MSSP who’s new to SIEM. How does it change the friction of getting started with Exabeam as their platform? Craig Patterson: You’re going to love this. You’re going to love this. So we’ve sort of reimagined all of the enablement. Again, when you look at traditional enablement, it’s like most enablement is built in these LMS platforms. Like, “Hey, partner, go log on to this LMS platform, get your certification, and then we expect you to actually know what the hell you’re doing.” Reality is that’s not what happens. They log on to the LMS platforms. They fast-forward as quickly as they can to the end. They turn the volume down. And then when the quiz comes, they use AI to answer the questions. And so they just find a way to get the certification. The reality is none of that helps them be better in life or actually raise their competency. And so that’s a problem we took on head-on with Sherpa. And so Sherpa was built in a way to really change the way partners learn with the whole goal of raising their competency level so they can be better on the market. And there was really like three use cases we were trying to solve with the emergence of Sherpa. The first is like you think about this global ecosystem that Peter and I have. We have 3000 partners. The partner ecosystem looks different. We have VARs. We have MSPs. We have MSSPs. We have distributors. We have the trusted advisor market as well. All of them have different needs in terms of where they are from a learning perspective. And so the first use case, Robert, is simply like a tool to be able to ask questions. What are the use cases? How do I position this? Why is SIEM or UEBA better than the competition? Just an always-on tool for partners to ask questions. And so that was kind of use case one. And then the cool thing around that is you think about the ecosystem being very global in nature. The other problem with LMS platforms is I’ve got partners in Japan. Well, that means the LMS platform they log on to needs to be able to talk to them in Japanese. And so the beauty with Sherpa, it does all the translation for us. And we’ve got 15 plus languages that are now live in Sherpa. Partners in Japan are talking to it. We got partners in India and all over the world really asking questions in terms of how we position our services. And that integration can be done by just logging on to our portal. You’ll see a bot pop up. They can just simply ask a question. It integrates in Teams, integrates in Slack. So that was use case number one. Use case number two was we reimagined the whole enablement certification platform. And so it’s a very dynamic learning experience. And so the way it happens is you log on, there’s a topic that you like, you click on that, you start learning, it asks you questions, it asks you to position services, and then you record your answer to how you’re actually positioning those services or the features. And it gives you feedback like, “Robert, you did really good on this aspect, but next time you should use this and this.” Or, “Robert, if you’re talking to a customer that’s in this vertical, you should talk about this use case because that’ll help resonate.” And so the whole certification process has been rebuilt and that’s the second use case. The third use case, this is a game changer. And this really goes to your question. And it’s an always-on coach. And so partners are now able to invite Sherpa to calls. And so as they’re having those conversations with customers, and the customer may say something or give them an objection, well, in the background, Sherpa will give them the answer to that objection and say, “Customer said this, talk to them about this.” Or, “Have you shared this new feature that was just released in the quarterly launch?” So it’s like this always-on coach, always-on assistant to really give them what they need. And then we’re putting it on this innovation roadmap. And so every single quarter, we’re launching new innovation in Sherpa. As an example, we’re now launching our LinkedIn integration. So if you’re an MSSP partner, you log on to Sherpa, you’re connected to LinkedIn, it’s going to ask you, if Sherpa can look through your network to find customers that may be a good fit for our services. And then it’ll say, “Okay, great. We found these contacts. Should we go ahead and write the campaign? Should we write a campaign that you can use to send to those customers in your ecosystem on LinkedIn?” And so quite honestly, I think we’re bleeding edge in terms of really being able to use AI and adopt AI in a way to drive good outcomes, well beyond where most companies are with their simple ChatGPT things like that. We’re actually driving outcomes. Robert Dutt: The rise of AI baked into the partner program and partner tools is a fascinating space for me to watch. And that certainly, you make a compelling case for the role of Sherpa there. That sounds really interesting. A quick one on the product side, not directly related here, but just out of curiosity, Exabeam just dropped Agent Behavior Analytics in your April release, sort of extending behavioral detection to AI agents, ChatGPT usage, Copilot activity, those kinds of things. For an MSSP looking to take this to market as a service, is it a new revenue line? Is it an upsell? Or is this sort of becoming table stakes that clients expect to see bundled into what you’re doing for them? Craig Patterson: I’m glad you asked. It was just recently at RSA, the conference, obviously AI is the buzzword, but what do you do with that? When we presented the agentic behavior analytics to a lot of our partners or potential new customers, the question that was often asked was, “Well, how much is this extra?” And that’s not how we license our product. So the behavior analytics has been part of our solution since our inception from our analytics model. So specific to AI, this is going to be, you could differentiate your service from other service providers by using this behavior analytics, but by no means is it an extra cost on the MSSP’s behalf. So they’re going into an organization that has a thousand users, human entities, and overnight they now have 10,000 non-human entities. We look at and model all of them using our analytics. So now you actually have at least a basis of what’s normal from a behavior standpoint for both non-human and human entities. So we really change the game, but haven’t changed the pricing along with it. So it comes naturally within our platform. So no change for me as a partner, but if I can find a way to upsell based on it, all the better. If not, I add additional features. Hopefully my customer is more happy. Peter Stratis: I was just going to say, if you look at the macro trends we’re seeing, this is the number one conversation that’s being had right now, especially like you look at the financial sector. Every single company is facing this problem. And so this really, not only does it give them a new use case to go after, I think it just makes the overall security services of Exabeam more relevant based upon what’s happening in the overall market, which all that makes the revenue stickier, makes those conversations more impactful that those MSSP partners are having. Craig Patterson: Yeah. Well, what I’m going to mention is operational efficiency and service differentiation is what’s key to our MSSPs and their success. So the license is foundational. And now that we’ve actually solved for being predictable from a margin perspective, how can they differentiate themselves, making them operationally efficient using automation, using our threat detection, and then also the service differentiation. And the other thing too, just thinking through this a little bit, I mean, there’s different AI agents that exist out there that are doing different things. You think about the malfunctioning agent, the one that’s just off base and it’s doing things that are just incorrect based upon the fundamentals or foundation of the AI agent. That’s one thing that gets addressed by looking at the abnormal behavior. The second is the misaligned agent, the ones that are pursuing goals in a way that could negatively impact the company. And that gets a little bit more scary. But really what gets scary is those subverted agents, the ones that have been hijacked that are actually causing harm. And so you think about all those different use cases that are happening, and that’s the beauty of what we just released is our new ABA, sort of creating this new category in the market. That’s really what our ABA is looking for, is all those different things that are happening, whether it’s misused, misaligned, or subverted. All that can be detected through this new agent behavior. Robert Dutt: Okay, last question for me. If I’m an MSP who’s been sitting on the sidelines, I’ve been thinking about them or are upgrading my security operations practice. What’s one thing that you wish I understood about the opportunity and the economics, but I probably don’t at this point? Peter Stratis: It’s all about how they actually start off. They’re interested in selling managed security, but they don’t know that they have to standardize their delivery model. They can’t make it where every customer is custom, because that’s when that price predictability goes away. So everything from onboarding to customizing your offering has to go away. You might be able to do it for a certain amount of customers, but you have to build a model that’s repeatable. Automation is going to be very important to that. And then finally, you could add optional add-ons, but you have to resist the temptation to over-customize everything. The great thing about what Craig has done with the APEX Partner Program and the way we built it out here at Exabeam is it supports all of this through all the enablement efforts. So Craig mentioned all the enablement built into the program, but then we have certification tracks. So we’ll help you along in that process. And we have everything from APIs and the use case and the scripts to help you automate that track for you to make it easier, but just don’t jump in and try to do a custom solution for each customer. Robert Dutt: Gentlemen, I thank you very much for your time. Once again, I appreciate your walking us through the commercial framework. Craig Patterson: Thank you, Robert. Appreciate it. Peter Stratis: Thank you, Robert. Robert Dutt: There you have it. Craig Patterson and Peter Stratis from Exabeam. I’d like to thank Craig and Peter for their time today. And a special note, this was Peter’s first podcast appearance. You never would have known it. A few things I’ll leave you with. First, if Peter’s candid admission landed for you — that Exabeam used to treat service providers like resellers with opportunistic deal-by-deal discounts that made it impossible to build a predictable margin — sit with that for a moment. Not unique to Exabeam. That was the industry. And it goes a long way to explaining why so many MSPs have struggled to make managed SIEM work as a business. The new framework is a direct attempt to fix that math. Two pathways: a single-pool capacity model that works well for SMB and mid-market clients, and a federated model that isolates environments for compliance-heavy customers. The discounting structure has been rebuilt from the data up with the goal of moving 80% of deals through a standard process. Up from what Craig described as the opposite of that. The Sherpa AI tool is worth watching closely, not just as a training platform replacement, but as an always-on coach that can actually sit in on partner sales calls and surface real-time objection handling. The LinkedIn integration is coming next, and it starts looking less like an LMS and more like a business development tool. And the closing advice I’ll leave you with is Peter’s. If you’re an MSP thinking about entering the security space, standardize your delivery model before you take on your first customer. Resist the urge to customize every environment. That’s exactly where price predictability and profitability goes away. Thanks as always for listening. In The Channel is available on Apple Podcasts, Spotify, YouTube, and all the major podcast directories. If you’re finding value in the show, leave a rating or review. It goes a long way to helping other folks in the channel find us. Until next time, I’m Robert Dutt for ChannelBuzz.ca, and I’ll see you in the channel.
By Doug Green “It was an ecosystem experience that I hadn't seen in a while.” CloudFest Americas is returning to Miami with a broader mission: bring together the cloud, hosting, domain, MSP and corporate IT communities in one place—and make the experience feel less like a conventional trade show and more like a working industry festival. In this Technology Reseller News podcast, recorded at GTIA ChannelCon 2026, Anthony Pombal of CloudFest and Mark Crall of MSP Global preview CloudFest Americas, scheduled for November 11–12 at Ice Palace Studios in Miami. The event is expected to attract approximately 2,000 attendees from North America and Latin America. CloudFest Americas is derived from the long-running CloudFest event held at Europa-Park in Germany. Its audience includes cloud service providers, web agencies, hosting companies, MSPs, MSSPs, software and hardware vendors, corporate IT teams and other organizations looking for alternatives to the largest hyperscale platforms. Pombal says the event is particularly relevant for companies seeking new products, services, partners and routes to market. Exhibitors can reach what he describes as the alternative cloud service provider market, along with web developers, hosting providers, managed service providers and businesses evaluating new infrastructure and software options. The event is also co-located with NamesCon, creating a point of convergence between the cloud, hosting and domain-name communities. That overlap reflects a broader shift in the market as MSPs, hosting companies and cloud providers increasingly compete, partner and build services across what were once separate technology categories. Crall says his experience at MSP Global in Barcelona demonstrated the value of bringing those communities together in a vendor-agnostic setting. Rather than focusing only on product pitches, the event combined technology education, thought leadership, lessons from industry practitioners and informal community building. “To see that happen in an agnostic environment and actually learn something at the same time while having fun is kind of cool,” Crall says. CloudFest Americas is designed around that same model. In addition to its exhibit floor and conference content, the Miami event will include a server-throwing competition, a domain auction, giveaways and locally inspired activities in the Wynwood arts district, including a live mural created by a graffiti artist. The program will also feature forward-looking content and smaller community discussions. A new area called the Florida Room is planned as a birds-of-a-feather-style forum where groups can exchange ideas, discuss operating challenges and share practical lessons without turning every session into a sales presentation. For technology resellers and MSPs, the event offers an opportunity to look beyond familiar vendor ecosystems. The convergence of cloud infrastructure, managed services, cybersecurity, software, hosting and domain technologies is creating new partnership and recurring-revenue possibilities for channel companies willing to explore adjacent markets. Watch the podcast to learn how CloudFest Americas is building a cross-market community for cloud providers, MSPs, hosting companies, technology vendors and corporate IT leaders—and why Miami may become an important November meeting point for the wider channel ecosystem. Event details: CloudFest Americas, November 11–12, Ice Palace Studios, Miami.
Today’s headline news for Canadian IT solution providers: TD SYNNEX appoints Chris Fabes as President of Canada: TD SYNNEX announced today that Chris Fabes has been appointed President of Canada, with responsibility for driving the company’s distribution strategy and accelerating customer growth across the Canadian market. Fabes brings more than two decades of IT channel leadership, most recently from SHI where he led a multi-year strategic growth initiative across Canada, and previously from Lenovo where he served as Canadian channel chief and helped triple channel revenue to more than $1.2 billion. He succeeds Mitchell Martin, who retired earlier this year after more than 36 years with the company. Huntress warns of massive Azure CLI password spray attacks: A new Huntress report published Monday warns that threat actors have been running massive password spray attacks against Microsoft Azure Command Line Interface accounts, making more than 81 million attempts between June 12 and June 26, 2026. According to Huntress, attackers are exploiting a loophole in Azure CLI that does not support multifactor authentication, allowing them to target service accounts and non-human identities that are often poorly monitored. Huntress has reported the issue to Microsoft. MSSPs face employee retention problem driven by invisible work, says Guardz: MSSPs are facing a significant employee retention challenge driven by what the report calls “invisible work” – security analysts spending hours on manual data correlation and reporting that customers never see. Guardz, in announcing a new agentic reporting capability, said the problem is burning out analysts who feel their work lacks visible impact. The new tool uses an AI agent to automatically turn blocked threats and client risk data into formatted reports that MSPs can present to SMB customers. ManageEngine launches developer marketplace: ManageEngine has launched a developer marketplace for integrations, extensions, and AI agents across its IT management platforms. The marketplace is designed to allow partner-developers, independent software vendors, and customers to build and distribute add-ons. GAM Tech ranks No. 97 on 2026 MSP 501, No. 1 in Western Canada: GAM Tech has climbed to No. 97 globally on the 2026 MSP 501 and ranks No. 1 in Western Canada, according to the company. The MSP 501 list recognizes managed service providers based on metrics including recurring revenue, profit margin, and operational efficiency. Read Full Transcript Welcome to The Buzz from ChannelBuzz.ca, I’m Robert Dutt, today is Tuesday, July 21, 2026, and here’s what’s happening in the channel today. TD SYNNEX has appointed Chris Fabes as President of Canada, filling the role left by Mitchell Martin who retired earlier this year after more than thirty-six years with the company. In a statement, TD SYNNEX said Fabes brings more than two decades of IT channel leadership across vendor, distributor, and customer perspectives. He most recently led a multi-year strategic growth initiative at SHI across Canada, and before that served as Canadian channel chief at Lenovo, where he helped triple channel revenue to more than one point two billion dollars in three years. TD SYNNEX North America president Reyna Thompson said Fabes’ end-to-end understanding of the Canadian technology market makes him well positioned to lead the Canada business into its next chapter. The appointment comes at a time when TD SYNNEX has been expanding its vendor relationships in Canada, including recent global distribution deals with Fortinet and HPE. Canadian partners will be watching how Fabes shapes the distributor’s local strategy, particularly around AI, cybersecurity, and cloud marketplace growth. A new Huntress report published Monday warns that threat actors have been running massive password spray attacks against Microsoft Azure Command Line Interface accounts, making more than eighty-one million attempts between June 12 and June 26, 2026. According to Huntress, attackers are exploiting a loophole in Azure CLI that does not support multifactor authentication, allowing them to target service accounts and non-human identities that are often poorly monitored. The company said most affected accounts were from large enterprises with complex cloud footprints, and that MSPs managing customer Azure environments are particularly exposed because these CLI accounts often fall outside normal identity monitoring workflows. Huntress has reported the issue to Microsoft. The research underscores a growing tension in identity security: as organizations lock down human-facing accounts with MFA, attackers are shifting to non-human identities and service accounts that lack the same protections. Canadian MSPs with hybrid Azure and Microsoft 365 clients should be reviewing whether their RMM and identity tools are catching CLI-level authentication anomalies. MSSPs are facing a significant employee retention challenge, but salary is not the primary driver. According to a ChannelE2E feature published today, the main issue is what the report calls “invisible work” – security analysts spending hours on manual data correlation, reporting, and threat context that customers never see. Guardz, in announcing a new agentic reporting capability, said the problem is burning out analysts who feel their work lacks visible impact. The new tool uses an AI agent to automatically turn blocked threats, security activity, and client risk data into formatted reports that MSPs can present to SMB customers. Guardz is positioning the feature as a way to reduce the manual reporting burden while simultaneously demonstrating security value to clients. For Canadian MSPs, the issue is worth noting because talent retention in security operations is already tight, and any tool that reduces invisible overhead while improving client communication is likely to get attention from understaffed SOC teams. In Brief – ManageEngine launches a developer marketplace for integrations, extensions, and AI agents. GAM Tech ranks number ninety-seven globally on the two thousand twenty-six MSP five hundred one and number one in Western Canada. Later today on In The Channel, my conversation with Mark Sutor of Access Group and the Trust X Alliance on the Global Leadership Summit, the TXA AI agent, and the idea of distributor-as-platform is available now. That’s how we’re seeing the headlines today. I’m Robert Dutt for ChannelBuzz.ca, thanks for listening. Have a great day.
Today’s headline news for Canadian IT solution providers: OpenAI Partner Network: OpenAI‘s inaugural Partner Network is officially live as of July 15, with vice president of strategic global partnerships Colleen Kapase confirming the three-tier program is backed by $150 million in channel investment. Partners can progress through Select, Advanced, and Elite tiers while earning specializations in areas like Codex, cybersecurity, and AI agents. OpenAI says it aims to train 300,000 certified consultants by year-end and is recruiting solution providers of all sizes that can put AI systems into production. OpenAI Carbon60 MSP 501: Carbon60, a Toronto-based managed cloud services provider, has been named to the 2026 MSP 501 at position 206, ranking among the world’s top managed services firms by revenue and operational discipline. The company has built a differentiated practice around Canada-first sovereign cloud and Azure expertise, and the ranking follows a broader push by Canadian MSPs to demonstrate global competitiveness in compliance-heavy verticals. Carbon60 RecordPoint channel-first: RecordPoint has launched a global partner program that CRN describes as a channel-first move, enabling resellers, consultancies, and systems integrators to resell, co-sell, and refer its data and AI governance platform. Partners will receive enablement, joint sales support, and platform access to build practices around data retention, compliance, and AI-ready data classification. Channel Insider Blackpoint Cyber 2026 threat report: Blackpoint Cyber has released its 2026 Annual Threat Report, finding that attackers are increasingly exploiting trusted IT tools rather than using perimeter breaches. The report highlights abuse of remote monitoring and management platforms, VPNs, and identity credentials as primary vectors. ChannelPro Network Managed security market growth: Acronis and Omdia project the global managed security market will grow from $93 billion in 2025 to $106 billion in 2026, a 14.4 percent increase. The growth reflects sustained demand for outsourced security operations among mid-market organizations that lack internal SOC capacity. RAMageddon pressures PC refresh: Industry analysts and OEMs continue to signal significant PC RAM price increases through 2026 due to the ongoing memory supply shortage. Channel partners should advise clients on refresh timing and alternative configurations to manage budget impact. CNET Exabeam MSSP licensing: Exabeam has expanded its APEX partner program with pooled and federated licensing options designed specifically for MSSPs. The new framework is intended to reduce onboarding friction and simplify compliance across multi-tenant security operations centers. Security Brief Read Full Transcript Welcome to The Buzz from ChannelBuzz.ca, I’m Robert Dutt, today is Thursday, July 16, and here’s what’s happening in the channel today. OpenAI’s inaugural Partner Network is officially live as of yesterday, July 15, with the company backing the three-tier program with $150 million in channel investment. Vice president of strategic global partnerships Colleen Kapase confirmed the program is open to solution providers of all sizes, not just global systems integrators. Partners can progress through Select, Advanced, and Elite tiers based on sales performance, technical capability, and deployment experience. The program includes specializations in Codex, cybersecurity, and AI agents. OpenAI says it aims to train 300,000 certified consultants by the end of 2026, and is actively recruiting solution providers that can put AI systems into production. Philip Larson, senior director of the OpenAI Partner Network and a former Google Cloud channel leader, said the program is designed to reward partners for the value they create with customers. Canadian VARs and MSPs with existing AI practices should evaluate the program alongside their current AWS, Google, and Microsoft partnerships, as the specializations in Codex and AI agents may create differentiation in automation-heavy verticals. Carbon60, a Toronto-based managed cloud services provider, has been named to the 2026 MSP 501 at position 206, marking the company as one of the world’s top managed services firms by revenue and operational discipline. The ranking, published by Channel Futures, evaluates financial health, operational maturity, and recurring revenue growth. Carbon60’s inclusion follows a broader trend of Canadian MSPs demonstrating global competitiveness in specialized infrastructure and compliance-heavy verticals. The company has built a differentiated practice around Canada-first sovereign cloud and deep Azure expertise. As Canadian public sector and healthcare clients face stricter data residency requirements, sovereign cloud capabilities are becoming a key differentiator for domestic MSPs seeking to compete with larger global firms on government and enterprise contracts. RecordPoint has gone channel-first with the launch of a global partner program enabling resellers, consultancies, and systems integrators to resell, co-sell, and refer its data and AI governance platform. The program arrives as AI adoption drives a surge in demand for data governance across regulated industries. RecordPoint says partners will receive enablement, joint sales support, and platform access to build practices around data retention, compliance, and AI-ready data classification. CRN reports that the move represents a strategic shift for the company. Canadian partners serving regulated industries like finance, government, and healthcare may find particular opportunity as clients confront unstructured data sprawl ahead of AI deployments. In Brief – OpenAI commits $150 million to launch its inaugural Partner Network with tiered AI specializations. Acronis and Omdia project the managed security market will reach $106 billion in 2026. Blackpoint Cyber’s 2026 Annual Threat Report highlights attackers hiding inside trusted IT tools and RMM platforms. RAMageddon memory shortages continue to pressure PC pricing and enterprise refresh cycles. Exabeam adds pooled and federated licensing options to its APEX partner program for MSSPs. Full details and links in the show notes or the blog post. Later today on In The Channel, we’re talking specialist distribution in Canada with Carrie Hopkins of Exclusive Networks. We get into the Ignition program, what broadliners can’t deliver, and why the model might feel familiar to channel veterans. And if you haven’t heard it yet, yesterday we wrapped our HPE Discover 2026 arc with HPE vice president of North America channels Jeremiah Jenson. He talks about the quote-cycle win, the Canadian angle on data sovereignty, and what partners should stop doing. That’s how we’re seeing the headlines today. I’m Robert Dutt for ChannelBuzz.ca, thanks for listening. Have a great day.
Today’s headline news for Canadian IT solution providers: Microsoft July 2026 Patch Tuesday fixes 570 flaws, 3 zero-days: Microsoft released its July 2026 Patch Tuesday update addressing 570 vulnerabilities including 3 zero-days, according to BleepingComputer. The zero-day status means MSPs should prioritize these patches immediately for client environments. With 570 total fixes to stage, test, and deploy, Canadian partners managing regulated clients in healthcare, finance, and provincial government face a compressed vulnerability response window this week. Citrix Platform Flex opens a new services opportunity: Citrix is introducing Platform Flex, a persona-based pricing model that gives partners room to build consulting, workforce assessment, and migration services around how customers actually use the platform. According to ChannelE2E, the shift lets partners attach higher-margin services to each deployment by right-sizing workloads to user personas. The new model is particularly relevant in the Canadian mid-market, where virtual desktop and app delivery standardization has been strong but differentiation has been thin. AI compliance is becoming an operational blind spot for MSPs: AI compliance should not be treated as a policy exercise that happens once and then sits on a shelf. According to Terry Irons on ChannelE2E, the value for MSPs is operationalizing compliance around AI data handling, model access, and prompt logging. Canadian MSPs already navigating Law 25 and PIPEDA amendments will recognize the pattern: the regulation exists, but the recurring revenue opportunity lies in helping customers stay inside the lines as the technology changes. CMMC third-party audits paused but the opportunity isn’t: The Department of Defense has pressed pause on third-party audits for the Cybersecurity Maturity Model Certification, but the compliance requirements themselves remain in place for defense contractors. According to ChannelE2E, that gap creates an opening for MSPs and MSSPs to expand compliance services. Canadian partners serving cross-border contractors or aerospace supply chain clients should expect renewed advisory conversations. Progress confirms ShareFile zero-day behind Storage Zone shutdown: Progress confirmed a ShareFile zero-day flaw was behind the Storage Zone shutdown, BleepingComputer reports. Partners managing client file-sharing infrastructure should assess exposure and confirm whether affected Storage Zone configurations are in their environments. MSSP Alert Top 250 application opens for 2026: The MSSP Alert Top 250 MSSP list application process is open for 2026. ChannelE2E offers guidance on what judges look for and which mistakes could hurt a ranking. Changes in the Channel tracks leadership moves for July 6-10: ChannelE2E tracked leadership changes and shakeups across the channel for the week of July 6-10. Read Full Transcript Welcome to The Buzz from ChannelBuzz.ca, I’m Robert Dutt, today is Wednesday, July 15, and here’s what’s happening in the channel today. Microsoft released its July 2026 Patch Tuesday update addressing 570 vulnerabilities across the portfolio, including 3 zero-days. According to BleepingComputer, the zero-day patches should be prioritized immediately for client environments. The scale of the release means MSPs need to stage patch deployment carefully. With 570 fixes to validate and deploy, technicians are managing a large surface area without disrupting business operations. Canadian partners managing regulated clients in healthcare, finance, and provincial government should expect compressed vulnerability response windows this week. Law 25, PIPEDA, and sector-specific frameworks all embed expectations around timely critical patch management, and a July drop of this magnitude tests those service level commitments. Microsoft is positioning the release as part of its regular cycle, but the zero-day status means this is not a routine Tuesday. Partners should be communicating with clients now about maintenance windows and priority sequencing for on-premises and hybrid infrastructure. Citrix is introducing Platform Flex, a persona-based pricing model that moves away from one-size-fits-all licensing and gives partners room to build consulting, workforce assessment, and migration services around how customers actually use the platform. According to ChannelE2E, the shift lets partners attach higher-margin services to each deployment by right-sizing workloads to user personas rather than simply renewing seat counts. The new model is particularly relevant in the Canadian mid-market, where virtual desktop and app delivery standardization has been strong but differentiation has been thin. Platform Flex creates a natural entry point for partners to conduct usage assessments, recommend persona transitions, and bundle ongoing optimization services. It also gives partners a way to defend margins against pure license resale by making the consulting layer part of the renewal conversation. Citrix is positioning Platform Flex as a way to reduce customer shelfware, but the partner angle is that it turns every renewal cycle into a services engagement. AI compliance should not be treated as a policy exercise that happens once and then sits on a shelf. According to Terry Irons on ChannelE2E, the value for MSPs is operationalizing compliance around AI data handling, model access, and prompt logging. As customers deploy more AI tools, the governance gap between experimentation and controlled scale is widening, and MSPs that treat AI governance as a document creation exercise risk missing the continuous monitoring requirement. Canadian MSPs already navigating Law 25 and PIPEDA amendments will recognize the pattern: the regulation exists, but the recurring revenue opportunity lies in helping customers stay inside the lines as the technology changes. The piece suggests that MSPs who build AI compliance into their existing security operations center workflows, rather than treating it as a separate consulting project, will capture more of that spend. The shift from one-time policy to ongoing operational control is the same transition the channel has already made with security, and AI is now following that path. In Brief – CMMC third-party audits are paused but the channel opportunity isn’t. Progress confirms a ShareFile zero-day flaw behind the Storage Zone shutdown. MSSP Alert Top 250 application opens for 2026 ranking. Changes in the Channel tracks leadership moves for the week of July 6-10. Full details and links in the show notes or the blog post. Later today on In The Channel, we close out our HPE Discover 2026 coverage with vice president of North America channel and partner ecosystem Jeremiah Jenson, talking about the 30-day quote validity, Canadian partner influence, and the push for data center networking growth. And if you haven’t heard it yet, yesterday’s episode featured Curtis Dery from Xerox IT Solutions on HPE financing, GreenLake wins, and why AI is a digital goldmine for the channel. That’s how we’re seeing the headlines today. I’m Robert Dutt for ChannelBuzz.ca, thanks for listening. Have a great day.
El nombramiento de Jonathan Berger como Senior Vice President, Global Channels and Alliances marca una nueva etapa para SonicWall en su estrategia mundial de partners. Su llegada refuerza el enfoque de la compañía hacia MSPs, MSSPs y resellers que buscan crecer con servicios gestionados, ingresos recurrentes y mayor rentabilidad en ciberseguridad.
Today’s headline news for Canadian IT solution providers: HPE Discover 2026 kicks off: HPE Discover 2026 opens today at The Venetian in Las Vegas with the Partner Growth Summit, the partner-exclusive day that precedes the main conference. The General Session – “The Power of One” – is led by HPE channel head Simon Ewington and focuses on HPE’s unified partner strategy under the HPE Partner Ready Vantage program, spanning networking, cloud, and AI. This is the first Partner Growth Summit since HPE’s $14 billion Juniper Networks acquisition closed, and HPE is presenting partners with a fully unified portfolio story for the first time. ChannelBuzz.ca is on the ground all week: Tuesday’s Buzz will feature a full Partner Growth Summit recap, and In The Channel this week features a multi-part series with Jeremiah Jenson, HPE’s vice president of North America channel and partner ecosystem, covering the Discover announcements in depth. Cato Networks launches integration hub: Cato Networks has launched a new Technology Partner Program and a Platform Integration Hub, debuting with more than 100 out-of-the-box integrations with third-party security, cloud, and networking solutions. The SASE provider says the program is designed to simplify how partners and customers connect Cato’s platform with existing enterprise technology stacks. The move is significant for Canadian MSPs and MSSPs: a robust integration catalog reduces the custom API work that often slows deployment and increases delivery costs, making it easier to position Cato alongside the broader tools in a customer’s security environment. Checkmarx flags CISO compliance pressures: A new 2026 Future of Application Security Report from Checkmarx, based on a survey of more than 2,000 developers and CISOs, found that 95 per cent of CISOs report being pressured to suppress or delay compliance-related security issues when business deadlines loom. The research also highlights how AI-generated code is expanding the attack surface faster than many security teams can manage. For Canadian MSSPs, the data reinforces the value of independent, third-party security oversight – and the case for structured application security as a managed service. Dataminr and TD SYNNEX partner on AI cyber defense: Dataminr has signed a strategic distribution agreement with TD SYNNEX, making Dataminr for Cyber Defense available to more than 35,000 North American resellers. The platform combines external risk signals with internal telemetry to help security teams prioritize threats in real time. For Canadian partners already working with TD SYNNEX, the deal adds an AI-driven threat intelligence offering to the distributor’s security portfolio at a time when customers are asking for earlier warning around cyber risk. inforcer launches Microsoft 365 TDR platform: inforcer has launched inforcer Threat Detection and Response, a new platform that gives MSPs a single environment to manage detection, incident response, and reporting across the full Microsoft 365 estate – including Entra, Defender, Purview, Teams, and SharePoint. According to the company, the platform’s advantage is its existing policy and configuration context for each tenant, which it says allows the detection engine to separate real threats from alert noise. The product launched in early access at Pax8 Beyond last week. ConnectSecure introduces Patch 360: ConnectSecure has launched Patch 360, a patch management solution designed specifically for MSPs. According to the company, the platform gives MSPs more control over patch prioritization, testing, and approval workflows, and is designed to reduce deployment risk while accelerating patching across operating systems and third-party applications. NetRise launches Discovery Partner Program: Software supply chain security firm NetRise has launched the Discovery Partner Program for VARs, MSSPs, distributors, and systems integrators. The program provides partners access to the NetRise Platform, which analyzes compiled software artifacts – including binaries, firmware, and containers – to identify components and risks that may not appear in source-code scans or vendor-provided SBOMs. NetRise is positioning the program as a way for partners to address growing customer demand for independent software supply chain verification. Read Full Transcript This episode of The Buzz is brought to you by HPE Discover 2026. HPE Discover runs June 15 to 18 at The Venetian in Las Vegas. Discover what’s next at hpe.com/discover. Welcome to The Buzz from ChannelBuzz.ca, I’m Robert Dutt, today is Monday, June 15th, and here’s what’s happening in the channel today. The biggest event on HPE’s calendar opens today at The Venetian Convention and Expo Center in Las Vegas, and ChannelBuzz.ca is on the ground for the full week. But before the main conference opens to the broader audience tomorrow, today belongs exclusively to the channel. The HPE Partner Growth Summit – the partner-only day that kicks off Discover week – is underway as you’re hearing this. The centrepiece is the General Session called “The Power of One,” led by HPE channel head Simon Ewington alongside a lineup of HPE senior executives. The name captures the message HPE is sending its partner ecosystem heading into the back half of 2026: one comprehensive portfolio, one unified program under HPE Partner Ready Vantage, and one integrated experience across networking, cloud, and AI. The afternoon breakout agenda is dense – covering GreenLake and hybrid cloud, Aruba networking with AI, monetizing accelerated compute and agentic workloads, and HPE’s evolving service provider story. It’s also worth noting the context: this is the first Partner Growth Summit since HPE’s $14 billion acquisition of Juniper Networks cleared regulatory review and officially closed. Partners are getting their first look at a fully unified networking and compute story from a company that can now tell it cleanly. We’re bringing you the announcements as they happen all week. In just a couple of hours on In The Channel, I’ll help you get ready for Discover, as I preview the event with the help of none other than Jeremiah Jenson, HPE’s vice president of North American channel and partner ecosystem. Tomorrow on The Buzz, we’ll have all the news from Partner Growth Summit, and tomorrow’s In The Channel will also feature Jenson, as we take a deeper dive into the HPE’s partner programs and where he sees the biggest opportunities for the channel right now. Be sure to stick with us all week as we bring you full coverage from Vegas. Cato Networks is expanding its ecosystem with the launch of a new Technology Partner Program and a Platform Integration Hub. The SASE provider says the hub debuts with more than 100 integrations out of the box, offering streamlined connectivity with third-party security, cloud, and networking solutions. According to Cato, the program is designed to simplify how partners and customers integrate its platform with existing enterprise technology stacks, reducing friction and speeding up deployments. A vendor-led integration effort at this scale matters for the channel. As enterprise environments grow more layered and complex, MSPs rely on platforms that connect cleanly to an existing stack rather than requiring months of custom API work. Out-of-the-box integrations mean less time troubleshooting compatibility and more time delivering security outcomes to clients. It’s worth noting that Cato’s channel chief said earlier this year that seven out of ten deals the company closes are already partner-led. A stronger integration story could deepen that dependence on the channel by making it easier for MSPs and MSSPs to position Cato alongside the other tools in a customer’s security stack. A report released last week by application security vendor Checkmarx is putting hard numbers on a dynamic that security-focused channel partners have likely been seeing for some time. The 2026 Future of Application Security Report, based on a survey of more than 2,000 developers and CISOs, found that 95 per cent of CISOs say they have been pressured to suppress or delay compliance-related security issues when business deadlines loom. Compounding the problem: the adoption of AI-generated code is accelerating, which Checkmarx says is multiplying the attack surface in production environments faster than many security teams can manage. The business case for external, independent security oversight has rarely been clearer. When internal security leaders are being overruled on vulnerability management, an MSP or MSSP operating as a neutral third party – accountable to security outcomes rather than product launch timelines – steps into a genuine gap. The data also validates the case for application security as a structured managed service. As AI-generated code becomes standard in the development pipeline, organizations that can’t close that gap internally will need to find a partner who can. In Brief – Dataminr and TD SYNNEX have signed a distribution agreement that makes Dataminr for Cyber Defense available to more than 35,000 North American resellers through TD SYNNEX’s channel network. Security vendor inforcer has launched inforcer Threat Detection and Response, a new platform designed to give MSPs a single environment to manage detection, incident response, and reporting for Microsoft 365. ConnectSecure has introduced Patch 360, a patch management solution built specifically for MSPs that the company says reduces deployment risk while accelerating patching across operating systems and third-party applications. NetRise has launched the Discovery Partner Program, targeting VARs, MSSPs, distributors, and systems integrators with software supply chain security capabilities built around compiled binary analysis rather than source code or vendor-provided SBOMs. Full details and links in the show notes or the blog post. That’s how we’re seeing the headlines today. I’m Robert Dutt for ChannelBuzz.ca, thanks for listening. Have a great day.
Today’s headline news for Canadian IT solution providers: ConnectWise Platform: ConnectWise yesterday unveiled what it calls the industry’s first purpose-built platform for Predictive IT, unifying PSA, RMM, cybersecurity, automation, workflow orchestration, and native agentic AI into a single execution layer for managed services. CEO Manny Rivelo described it as a fundamental shift from reactive IT management to an AI-native operating model. The company also released new operational benchmark modeling based on a representative MSP with approximately $3M in annual managed services revenue, showing the productivity and economic impact it says AI-driven automation can deliver. Cavelo Cora AI Security Analyst: Kitchener, Ontario-based Cavelo has introduced Cora, an AI Security Analyst integrated into its data security posture management platform and positioned specifically for MSPs and MSSPs. Cavelo says Cora analyzes security telemetry and translates it into a guided remediation action plan in seconds, tailored by role. The tool targets the operational gap between risk visibility and actual remediation – without requiring additional headcount. Radiant Logic and Zscaler Partnership: Radiant Logic and Zscaler have announced a technology partnership aimed at solving the Day 1 access problem in mergers and acquisitions. By integrating RadiantOne’s identity data fabric with the Zscaler Zero Trust Exchange, the companies say acquiring organizations can securely connect newly onboarded employees to applications from the moment a deal closes, regardless of disparate identity systems. ConnectSecure Patch 360: ConnectSecure is launching Patch 360, a patch management platform built for MSPs that introduces pilot-first validation, risk-based prioritization using CISA Known Exploited Vulnerabilities and EPSS scoring, controlled rollouts with approval workflows, and integrated rollback – replacing what the company describes as a “deploy-and-hope” model with a “test-and-trust” framework. NTT DATA and Google Cloud: NTT DATA is expanding its AI partnership with Google Cloud, launching a dedicated Gemini Enterprise practice to help enterprise clients move AI deployments from pilot to production at scale. Descope Agentic Identity Hub: Identity platform Descope is announcing enhancements to its Agentic Identity Hub today, extending its tools for managing authentication and access for autonomous AI agents. Checkmarx CISO Research: Checkmarx has released research surveying more than 2,000 developers and CISOs, finding that 95 percent of CISOs report facing internal pressure to suppress software compliance findings. Read Full Transcript Welcome to The Buzz from ChannelBuzz.ca, I’m Robert Dutt, today is Tuesday, June 9, 2026, and here’s what’s happening in the channel today. ConnectWise yesterday unveiled what it is calling the industry’s first purpose-built platform for the era of Predictive IT. The ConnectWise Platform brings together PSA, RMM, cybersecurity, automation, workflow orchestration, and native agentic AI into what the company describes as a single intelligent execution layer for managed services. CEO Manny Rivelo positioned it as a fundamental shift away from the labor-intensive, disconnected systems that have defined MSP operations for decades, toward what ConnectWise calls an AI-native operating model. To support the launch, the company released new operational benchmark modeling showing the productivity and economic impact it says AI-driven automation can have on MSP operations. In their model, a representative managed services firm with approximately three million dollars in annual revenue could see measurable transformation across their first stages of the Predictive Intelligence journey. This is a significant platform bet from one of the largest players in the MSP tooling market, and the framing around “Predictive IT” is clearly a narrative ConnectWise intends to own. In the security space, Kitchener, Ontario-based Cavelo has introduced Cora, an AI Security Analyst integrated directly into its data security posture management platform. Positioned specifically for MSPs and MSSPs, Cora functions as an AI agent that analyzes security telemetry to identify, prioritize, and recommend remediation steps for cyber risks across client environments. Rather than adding more alerts to the dashboard, Cavelo says the tool translates security data into a guided action plan in seconds, tailored to the specific roles of frontline technicians and senior security leaders. The development targets a well-documented operational gap between risk visibility and remediation – allowing service providers to reduce manual investigation time and offer clients clear, actionable intelligence without increasing headcount. Radiant Logic and Zscaler have formed a strategic partnership designed to address the Day 1 access challenges commonly found in mergers and acquisitions. By integrating RadiantOne’s identity data fabric with the Zscaler Zero Trust Exchange, the companies are aiming to eliminate the complex network and identity merge projects that typically stall productivity following a deal close. The joint solution allows acquiring organizations to securely connect newly onboarded employees to necessary applications from day one, regardless of disparate Active Directory or HR systems. In a market where M&A activity among IT service providers shows no sign of slowing, this integration offers a repeatable framework for reducing the downtime and cyber risk associated with bringing acquired entities onto a managed environment – which is a practical and recurring service challenge for many MSPs in the field. In Brief – ConnectSecure launches Patch 360, a patch management platform for MSPs built on pilot-first testing, risk-based vulnerability prioritization, and integrated rollback controls. NTT DATA expands its AI partnership with Google Cloud, launching a dedicated Gemini Enterprise practice to help organizations move deployments from pilot to production scale. Descope is announcing enhancements today to its Agentic Identity Hub, aimed at helping organizations manage access for autonomous AI agents. Checkmarx research of more than 2,000 developers and CISOs finds 95 percent of CISOs report facing pressure to suppress software compliance findings. Full details and links in the show notes or the blog post. Later today on In The Channel, we have a conversation about the launch of the AWS Partner Innovation Hub in Toronto, with AWS Canada’s Martin Brazonet and CGI’s Dinesh Bhavsar on the challenge of moving AI from proof-of-concept to production. And if you haven’t heard it yet, check out our conversation with Earl Gosick from ESTI Consulting Services, recorded at Dell Technologies World, on why the AI story is really a storage story – that one is on the feed now. That’s how we’re seeing the headlines today. I’m Robert Dutt for ChannelBuzz.ca, thanks for listening. Have a great day.
Today’s headline news for Canadian IT solution providers: Dell PowerStore Elite and the reimagined data center: Yesterday at Dell Technologies World, Dell Technologiesintroduced Dell PowerStore Elite, a new enterprise storage platform delivering up to 3x performance over the prior generation and an industry-best 6:1 data reduction guarantee. The platform packs 5.8 petabytes into a single 3U chassis using standards-based E3 NVMe flash, and introduces Dell Cyber Detect, which identifies ransomware with 99.99% accuracy and pinpoints the last known clean copy for recovery. PowerStore Elite ships in July 2026; Cyber Detect for PowerStore follows in Q3. The broader Day 2 announcement also included 11 new PowerEdge servers, expanded Dell Private Cloud support for Broadcom, Microsoft, and Nutanix stacks, Dell PowerProtect One for simplified cyber resilience, and two new automation products: the Dell Automation Platform and Dell Automation Studio. Jeff Clarke’s tokenomics keynote: In Tuesday’s Day 2 keynote at DTW, Dell COO Jeff Clarke presented a set of ten fundamental shifts from the past year whose through-line is what he called tokenomics. The math: model prices fell 80% per token; token consumption is up 10x; GenAI software spend tripled. Net effect – AI is getting more expensive for most organizations, not less. Clarke illustrated the stakes with a concrete example: one developer running a single agentic use case on the public cloud can burn approximately $3,400 per day in token costs; the same workload runs at zero incremental cost on on-premises infrastructure. Clarke confirmed Dell moved its own operations to on-prem after internal token costs became untenable, and described work underway on what he called “token routing” – an orchestration layer that would automatically direct tasks to either a deskside AI workstation or data center hardware based on workload. He closed with three imperatives: know your token consumption, find your super users, and lead the operating model change or be disrupted by it. Intezer launches Amplify Partner Program: Intezer has officially launched its Intezer Amplify Partner Program, naming channel veteran Mark Daggett as vice president of global channels and alliances. The program formalizes Intezer’s channel investment as demand for AI-driven security operations grows and the talent gap in security operations continues to widen. According to Intezer, the program is designed to help MSSPs and solution providers step in where internal security teams lack the capacity to operationalize AI-powered alert triage and threat investigation, translating the company’s platform capabilities into managed and co-managed service offerings. Check Point agentic network security orchestration: Check Point announced an agentic network security orchestration platform on Monday designed to replace decades of rule-based complexity, reducing network policy management from months of manual effort to minutes of verified, automated action. The announcement is part of a broader Check Point push into agentic security capabilities across its Infinity platform. Zendesk unveils Autonomous Service Workforce: At its annual Relate conference, Zendesk announced the Autonomous Service Workforce, a product vision built around specialized AI agents priced per resolution rather than per seat. Key launches include a no-code Agent Builder, omnichannel coverage with shared context, and a real-time Quality Score applied to every interaction – human or AI. Riverbed extends Aternity AIOps: Riverbed has released new Aternity digital experience (DEX) capabilities positioning AIOps as proactive disruption prevention rather than reactive monitoring, giving IT teams predictive intelligence before end-user experience degrades. WinMagic brings zero trust to legacy OT: WinMagic has introduced Continuous Identity Assurance, a hardware-bound approach to endpoint identity that extends zero trust controls to air-gapped systems and legacy operational technology environments traditionally outside the reach of modern identity platforms. Read Full Transcript Welcome to The Buzz from ChannelBuzz.ca, I’m Robert Dutt, today is Wednesday, May 20, 2026, and here’s what’s happening in the channel today. Continuing coverage from Dell Technologies World in Las Vegas, where yesterday’s Day 2 product announcements shifted the spotlight from the partner program to the infrastructure portfolio. The headline item was Dell PowerStore Elite, which Dell is positioning as a new class of enterprise storage platform built for what it calls an AI-era data center. According to the company, PowerStore Elite delivers up to three times the performance of the previous generation through software-driven improvements, and backs it all with what Dell describes as an industry-best 6:1 data reduction guarantee – up from 5:1 – a number it says carries real weight in today’s supply-constrained flash market. The platform packs up to 5.8 petabytes of effective capacity into a single 3U chassis using industry-standard E3 NVMe flash rather than proprietary drives, giving partners and their customers more flexibility on cost and sourcing. The cyber resilience angle is where it gets interesting for MSPs. Dell is introducing Dell Cyber Detect for PowerStore, which inspects data at the byte level and is positioned as being able to identify ransomware with 99.99% accuracy – surfacing the last known clean copy so organizations can recover fast. That capability will be available in Q3 2026. PowerStore Elite itself is set for global availability in July. The broader data center announcement also included 11 new PowerEdge servers spanning both air-cooled and liquid-cooled environments, expanded Dell Private Cloud support for Broadcom, Microsoft, and Nutanix software stacks, and two new automation products: the Dell Automation Platform, which pairs AI agents with a conversational interface for infrastructure deployment and management, and Dell Automation Studio for building custom, full-stack orchestration workflows. Nearly 20,000 customers already run PowerStore globally, and Dell is emphasizing that existing deployments can cluster with PowerStore Elite without disruption – a meaningful selling point for partners managing live customer environments. The second big story out of Las Vegas yesterday is one that deserves some unpacking. During his keynote, Dell’s chief operating officer Jeff Clarke laid out what he called ten fundamental changes in the past twelve months – and the thread running through the whole list is a single concept: tokenomics. The numbers Clarke presented tell a story that’s easy to miss if you only hear the headline. Model prices have fallen roughly 80% per token in the last year – sounds like great news. Except token consumption is simultaneously up ten times. And GenAI software spend has tripled in twelve months. The net effect is that AI is actually getting more expensive for most organizations, not less. Clarke made it concrete with a single example: one developer, one agentic use case, building a software tool. On the public cloud, that use case can run up roughly $3,400 a day in token costs. Running the equivalent workload on on-premises infrastructure with local models? Zero incremental dollars. Clarke went further and confirmed that Dell itself made the shift to on-premises AI after its own token costs became untenable – which is a different kind of endorsement than anything you hear from a keynote stage. He also flagged something worth watching: Dell is working on what he called token routing, an orchestration layer that would automatically determine whether a given task is better handled by a deskside AI workstation or by data center infrastructure. He was clear it’s still in development, but it signals where Dell sees the intersection of its PC and server businesses heading. Clarke closed his keynote with three actionable imperatives: know your token consumption, find your super users, and lead the operating model change or be disrupted by it. That first one is the real challenge for most organizations – and the one an MSP or trusted advisor can walk into and own. Away from Las Vegas now, and Intezer has officially launched its Intezer Amplify Partner Program, naming industry veteran Mark Daggett as vice president of global channels and alliances to lead the effort. The program formalizes the company’s channel investment at a moment when demand for AI-driven security operations is accelerating. Intezer’s pitch to the channel is essentially a gap-filling argument: internal security teams are drowning in alert volume while the talent required to triage and investigate those alerts remains in short supply. The Amplify program is designed to equip partners to step into that gap, delivering Intezer’s automated alert triage and threat investigation capabilities as a managed or co-managed offering. The appointment of a dedicated channel VP is the clearest signal yet that Intezer is treating the channel as a primary route to market, not a secondary one. Partners building out managed security or MSSP practices looking to differentiate around AI-augmented SOC capabilities have another option worth a closer look. In Brief – Check Point launches an agentic network security orchestration platform it says collapses months of manual policy work into minutes of verified action. Zendesk unveils its Autonomous Service Workforce at the Relate conference, introducing per-resolution AI agent pricing and a no-code Agent Builder. Riverbed announces new Aternity digital experience capabilities designed to shift AIOps from reactive visibility to proactive disruption prevention. WinMagic introduces Continuous Identity Assurance, anchoring identity verification in hardware to extend zero trust protocols to air-gapped and legacy OT environments. Full details and links in the show notes or the blog post. Later today on In The Channel, still from the show floor at Dell Technologies World, I sit down with Rob Emsley, director of cyber resilience marketing at Dell Technologies, on why 97% of cyber attacks now specifically target the backup infrastructure – and what it actually means to build a resilience strategy around the concept of the minimum viable company. And if you haven’t heard yesterday’s episode yet, check out my conversation with Alan Ashby, Dell’s senior director of Americas data center presales and specialty sales, on the practical infrastructure realities of the AI boom – from a deskside AI workstation for an SMB to consolidating 13 legacy servers into one. That’s how we’re seeing the headlines today. I’m Robert Dutt for ChannelBuzz.ca, thanks for listening. Have a great day.
Enterprises today are managing increasingly complex cybersecurity environments across cloud, AI systems, applications, endpoints, and enterprise networks. As AI adoption accelerates, organizations are under pressure to secure AI-driven environments while responding to faster and more sophisticated threats. In this episode of the Zinnov Podcast, Rajat Kohli, Partner, Zinnov speaks with Michael Khoury, Vice President, Global Ecosystem Partners, Palo Alto Networks, about the shift from point products to platform-led cybersecurity strategies and what it means for enterprises, partners, MSSPs, hyperscalers, and global system integrators. Michael Khoury shares perspectives on how enterprises are navigating cybersecurity complexity in an AI-first world, and how ecosystem models are evolving alongside it. The conversation explores: • Why AI is accelerating platform-led cybersecurity • The rise of MSSPs and cloud marketplaces as key routes to market • How enterprises are reducing security complexity through platformization • What differentiates advanced ecosystem partners in the AI era Tune in now.
Cameron Tousley, director of MSP channels for ESET North America For most MSPs, the quarterly client conversation looks something like this: here are the alerts we handled, here is your uptime number, here is a dashboard of things we blocked. Useful, certainly – but not exactly the stuff of trusted advisor relationships. Cameron Tousley, director of MSP channels for ESET North America, has a phrase for the upgrade: move from statistical talks to threat briefings. In this episode of In The Channel, he and Pedro Kertzman, threat intelligence specialist at ESET, join host Robert Dutt to explain what that actually looks like in practice – and why the window for MSPs to make that transition may be narrowing. Pedro Kertzman, threat intelligence specialist at ESET The occasion is ESET’s eCrime Reports, a threat intelligence offering that tracks cybercriminal activity at the affiliate level – the individuals buying malware-as-a-service and executing the actual attacks. Kertzman explains why that granularity matters: affiliates signal tactical shifts before attacks scale, giving security-forward MSPs a genuine early-warning advantage. Tousley adds the client conversation layer: knowing that a specific threat group is targeting your customer’s vertical via a specific attack method is a meaningfully different conversation than “we blocked 4,000 threats this month.” There’s also an uncomfortable wrinkle for MSPs specifically: as Pedro notes, affiliates increasingly exploit MSP tooling itself as a vector – compromising credentials to access managed environments quietly, hitting dozens of small clients while staying well below the radar of law enforcement attention focused on high-profile infrastructure targets. For the smaller MSP without a dedicated analyst, the entry point is more accessible than it sounds. Indicators of compromise can be automated directly into client firewalls without a full threat intelligence platform. WeLiveSecurity and the live threat feed built into ESET Protect offer a low-barrier starting point for shops that are earlier in their security maturity journey. Tousley’s closing frame is the one worth sitting with: the Canadian MSP market is being reshaped by consolidation at a pace that isn’t slowing. The independents that survive will be the ones having more sophisticated conversations with their clients. Evolve or sell. Read Full Transcript Robert Dutt: Hello and welcome to In The Channel from ChannelBuzz.ca, bringing news and information to the Canadian IT channel community for the last 16 years. I’m Robert Dutt, editor of ChannelBuzz.ca, and your host for the show. Cyber Threat Intelligence, CTI, has long been framed as an enterprise discipline. Dedicated team, security operations center, analysts who live in the data. But the threat landscape doesn’t really respect that boundary anymore. The tooling is getting more accessible, the attacks are getting more targeted at smaller organizations, and as we’ve talked about on the show before, the MSP stack itself has become a threat vector. So the question for the typical Canadian MSP isn’t really “Is threat intelligence relevant to me?” It’s “What do I actually do with it?” To dig into that, I sat down with two people from ESET. Cameron Tousley is director of MSP channels for ESET North America, and he lives squarely in the business conversation around what MSPs need to grow and differentiate. Pedro Kertzman is ESET’s resident CTI subject matter expert, and I’ll note that Pedro usually sits on the other side of the interview chair as the host of his own podcast on threat intelligence. So this was a bit of a role reversal for him. We talked about ESET’s eCrime reports, the idea of tracking cyber criminal activity at the affiliate level rather than just the group level, what proactive threat intelligence actually looks like for a 15-person MSP shop, and what Cameron described as the “evolve or sell” reality facing the MSP market right now. Let’s get right into it. Cameron, Pedro, thanks for joining us. I appreciate it. Cameron Tousley: Thanks for having us. Pedro Kertzman: Great to be here. Robert Dutt: Before we get into what ESET is specifically bringing to market, Cameron, can you give our listeners a sense for where the threat intelligence conversation is right now in the channel? Is this still primarily an enterprise kind of discussion or has something really shifted in terms of how MSPs and MSSPs are thinking about and talking about CTI? Cameron Tousley: I think that the market is evolving as a whole, no matter if you’re in the SMB segment or enterprise. I mean, it’s evolving everywhere. The beautiful thing is technology is getting cheaper, it’s getting more accessible. People are able with the advent of AI to kind of do more with less staff and things like that, and then allow their staff to kind of become more specialized. Enter in the topic of CTI. I just think that there’s an appetite from certain, and probably more evolving larger MSPs, to start incorporating more for their clients. I think they’ve always probably wanted to educate them, but it’s always that, “Hey man, just make sure I have uptime and the help desk is active when I need it.” And that’s the conversation. Fast forward to now and it’s becoming a little bit more relevant to want to consume CTI. So I’ll kind of start there and I’ll take a pause. I don’t know if Pedro’s got any other comments on that. Pedro Kertzman: No, I 100% agree. I think the threat landscape now with the maturity of the CTI offerings, MSPs can see that the things they’re trying to protect their customers against are more clearly explained and delivered in a way that they can see through CTI offerings now. So I think it’s just a natural evolution within the cybersecurity space to start leveraging that expertise as well. Robert Dutt: Without getting too far into pure positioning, how would you characterize what differentiates your approach to threat intelligence, sort of at the methodology level? What’s the philosophy behind how you’re researching and tracking threats and what you’re bringing to market with this CTI package? Cameron Tousley: Yeah, I’d say first off, our reach. We’re a global company. We have a product line, yeah, but we have 11 threat intel centers and those are also R&D centers too. So it’s a wealth of knowledge. Then we have researchers outside of that that are just remote, and so our tentacles are everywhere and that means something for somebody choosing a cybersecurity vendor or a platform because our researchers, they’re looking at a bunch of different avenues. They’re looking at the major threat acting groups. We have an offering we’ll talk about here in a few minutes, that centers on tracking affiliates because malicious activity, malware-as-a-service, is just like MSPs provide a service. So if I’m an affiliate—and I’ll define that real quick, an affiliate being the people that are buying the malware service and then going and distributing it and causing zero-day attacks—those are affiliates. So the real key part is what they do, not necessarily always the major malware-as-a-service group because that’s just one large avenue, but then you can’t predict what your customers are going to go and do on the black market. So yeah, I think we have a really exciting offering on our threat intelligence called eCrime and it comes in a feed and reports and it’s amazing. It really centers on the affiliate level and that is going to help get the conversations to be more quality with customers. It’s going to help an MSP who provides more, let’s call it reactive security at best, generalized services—which no knock against them, that’s just the model—and that’s going to help propel them into the more proactive security and having more quality cybersecurity-forward conversations with their customers of all sizes. Robert Dutt: Let’s delve a little bit more into that. Can you walk me through a scenario, even hypothetical or composite, where that affiliate-level insight would practically change the outcome for an MSP or one of their customers? How does this show up for an MSP basically? Pedro Kertzman: Yeah. So basically, I’ll take a step back a little bit just to explain how this threat ecosystem works. So the affiliates will be the ones really on the end of the line bringing that malware they got from a quote-unquote threat actor market or affiliate programs, more technically speaking per se, but they will be the ones delivering or sending that payload forward to whatever companies that they are trying to attack. So knowing how these guys work is basically going to give the companies, and the MSPs of course working for their security, the ability to stop the attack in the early stages, because the affiliates will be the ones trying to break in, acquire through whatever methods—credentials stolen or compromised credentials. So they are responsible, quote-unquote, within these affiliate programs to get the foot inside the door. So if you’re knowledgeable about how they act, what kind of techniques they use to get that foot in, you’re basically stopping the attacks before they actually become super massive, widespread attacks or super dangerous attacks. It’s kind of the proactive security instead of the reactive security. Cameron Tousley: Yeah, that’s a good comment. And then I’ll just throw one more little thing on that. I was talking about the conversations you can have with your clients, everything Pedro said, plus it’s like, you could have a specific conversation about, “Hey, this is what we blocked this month, but these are the threat acting groups, and here are the patterns, here’s the kind of malware that’s out there right now. By the way, you’re in the healthcare vertical, this threat acting group is targeting healthcare and doing this specific type of attack—happens to be phishing or fileless or whatever the complex attack is.” So they got to get really granular in the conversation. It can’t just be a super high-level one, because then your user’s not going to know what to do with that information. But if you coach them on the end-of-the-line issue and where it’s sourcing from, to Pedro’s point, you get ahead of that attack early, you might even prevent stuff that would have normally been a real headache. Robert Dutt: And you need to position yourself at least somewhat as the hero in so much as you’re saying, “Here’s the people who are attacking you, here’s what they’re doing, here’s what we’re doing proactively to counter that.” Cameron Tousley: Absolutely. Yeah, that’s a huge value to your end customer. The one that normally would have not cared about security and it’s more of an annoyance, now they’re paranoid about it, just like the MSP, just like the vendors, we’re all trying to get ahead of it. So I think that that provides a lot of value, and the average MSP is probably not going to do that. So you don’t necessarily have to go spend a ton of money, you just have to consume the information that’s out there maybe for free, and then maybe some of the paid services like the eCrime reports without buying our full threat intelligence platform, you can just do that. And that is like a huge value on its own to track exactly what we’re talking about right now. Robert Dutt: So taking a step back, I think some of this certainly informs and colors the question we go to ask, but I’m a 15-person MSP somewhere. I’ve got solid endpoint protection, an RMM stack I like, maybe managed SOC coverage, that kind of model. What’s the case, in addition to what we’ve already discussed, for why threat intelligence should be on my radar as a distinct capability I need to think about, bring to my customers and offer? Pedro Kertzman: Yeah, I think especially because again, talking specifically about the eCrime reports, we’re talking about the ones that are really perpetrating the attacks or executing the attacks. When you understand how your adversaries really act, you don’t need to always rely on the expertise of a super senior CTI analyst. There are ways that also, depending on your vendor, you can automate the expertise to just be pumping, let’s say, IOCs or IP addresses into your existing end users’ firewalls. If you manage a bunch of other firewalls for your end users, you can pump that eCrime knowledge into those firewalls in the form of IP addresses, domains, and things like that. But understanding that it’s going to be a proactive approach so they don’t get a foot in the door first, it’s kind of that decision beforehand that will give the MSPs, or MSSPs with 15 or so employees, that kind of extra leverage against those frontline attackers. Robert Dutt: I’m really interested in the idea of using intelligence and these eCrime reports as a client-facing tool, not just something that’s consumed internally, especially for that smaller MSP—something that you’re using in your QBR or whatever business review you have with customers to show your value. I’m curious, is that something you’re seeing happening today or is it a realistic use case, or is it a stretch for most MSPs right now? Cameron Tousley: I think it’s realistic. Now, let’s set the tone here. An MSP, they may not have the budget nor the expertise nor the staff to be buying a full-blown threat intelligence offering even like ours, but they can use certain parts of it like the eCrime reports. So that’s a good jumping-in point for the MSPs that are growing, or if you have 15 people on staff and there’s a good deal of them on the technical side, you may want to run your SOC in-house. Maybe that’s something you want to do. I think for them, the maturing MSP and definitely the MSSP, a threat intelligence offering is something that you will probably want to consume if you’re doing everything in-house. Now, I think there’s an argument for even if you’re going to go out-of-house and use the vendor, I still think there are free sources. We have customers that are using free platforms but running a paid feed through it. This is really dynamic. It’s flexible. It can fit to every different audience for the most part, except for the ones who are just not staffed for it and they’re probably outsourcing everything and they just don’t want to do it. They know that they are never going to be able to staff a 24×7 team and they’re also never going to be able to consume as much information as is coming in. But there are also other free resources, like I said, associated with our threat intelligence platform, like the eCrime reports, but there’s white papers that we produce. There are periodic threat reports. We do all kinds of analysis. And then on our welivesecurity.com blog, we publish all kinds of free information. And the really cool thing for existing ESET customers is through our ESET security platform, ESET Protect, we run a live feed through there and it shows you like, “Hey, here’s the latest news on WeLiveSecurity. Here is something you need to be aware of, there’s a vulnerability in the wild.” So we run some of the security stuff and this news right through a window inside of our platform, which I think is really big value added. Pedro Kertzman: Awesome. Yeah, I would add, if I can, Rob, we do have monthly digests as well on the CTI offerings, even for not super deep-down technical people. Let’s say more executives or CSMs, let’s say account managers on the MSSP or MSP side. It’s kind of an executive-ready type of report. So it’s more about the threat landscape overview. I think it helps them show that they are expanding their offerings on the security side and they’re knowledgeable about it as well. Again, doesn’t need to go in the nitty-gritty like in the weeds of IOCs and all that, but understanding, for example, that now the ecosystem on the other side is somebody providing the malware, somebody going and executing it. So just to show how they see these movements, I think it’s sometimes important enough to show that they are expanding their coverage for their end users. Robert Dutt: The reports, the eCrime reports, have been in the market about a month now, I guess. I’m curious what you’re actually hearing from MSPs and MSSPs as they’re digging into them. Are people using them the way you expected or are there surprises that you’re seeing in how they’re engaging, what they’re doing, how they’re thinking about this information? Pedro Kertzman: That’s a good question. I think because of the name, we got out of the gate with police forces reaching out to us, but in theory, it’s not the best kind of deep analysis that we’re going to give them, because they have a lot of expertise. So then we have the APT reports that would bring more detailed analysis for them. So it was interesting to see that people are kind of eager on the end-user side to see how the threat landscape, especially related to financial crimes or eCrime, are really, let’s say, hot right now. The MSPs are kind of following that trend, not as jumping on like the police forces were, but they are starting to inquire about the new eCrime reports for sure. Cameron Tousley: Yeah, I’d agree. I think the defender agencies, I’ll call them, the ones that are fighting the same battle we are, but maybe physically, but now they’re fighting the eCrime too. As they’re learning, this is a great tool for them. We find that they’re excited about it. It’s relatively new, so we’re going to see more and more adoption of it. But plenty of people who are in evaluation are like, “Hey, can I run a free month of this? I want to check it out and see what I’m going to get.” And we’re getting a lot of good feedback on it right now. I’d say on the MSSP/MSP side, again, it’s new for them too. And they do a lot of different things. So for them, they’re like, “I need to slice out some time to check this out as well because this is interesting. I don’t know if anybody else is really doing anything quite like this.” So for them to be able to check it out and add it to their offering, I think what’s going to happen is that they’ll get hooked on something like that and they’ll want more. And we’re already working on more. So our teams are hard at work. We’re adding new feeds, new reporting structures, new ways to consume it. And reasonably priced packages and things like that. Even ones where you have somebody on retainer where you can go to and get a very long deep dive on what you’re reading periodically throughout any given month. So I think with that, you’ll see a lot of internal IT large agencies adopt it. I think you’ll see some MSSPs adopt it. And you might even see some general MSPs who are evolving up that chain do the same thing. So it’s kind of a report and an offering for everybody there. Pedro Kertzman: Yeah, I think you mentioned something important, Cam. We do offer trials for the eCrime reports as well, right? If they want to test it out. Cameron Tousley: Yeah, try it before you buy it. Yeah. Robert Dutt: It sounds like you’re also thinking about ways that you can slice this, dice this, package it out to that smaller MSP or that MSP who’s not a pure-play security player going forward. I was going to ask, what do you see as coming next in CTI and in your eCrime reports? I think that’s certainly a hint. Anything else that you see sort of in the pipeline or where you’d like it to go, where partners would like to see it go? Cameron Tousley: Yeah, I’ll take a stab at this one because my heart’s near and dear to the MSP community. That’s what I’ve been working in. That’s a segment for quite a long time now for ESET. And so what I’m reading and what I’m theorizing on is that there’s other kinds of technologies that are pretty complex, have gotten more simple in the way that they’re still doing complex processes, like an EDR, right? It’s an investigative tool, and then you pair it with AI and then things become easier for the team managing it. I think it’s going to be the same thing here where you’re going to have an AI paired with it, which we have our own agentic AI agent in this offering now, which is very, very cool, and it’s built in our security platform. But for this, I think it’s going to make consuming information easier, generalizing it, summarizing it, and making sure you can spin it into a quick executive summary. My theory is click of a button, right? So I’m going to have a dashboard. I’m going to say, “Hey, I want an executive summary on this event.” So you’re basically just filtering, and then the end result is you hit that AI generate button and then it generates something that’s quality, and you can do it at various user levels, maybe various role levels. I’ll hit the CTO button or I’ll hit the CEO button and they’ll be a little bit different, obviously. So I think that it’s going to get simpler and managed intelligence as a service, that’s next. It’s already a term that’s being thrown out there a little bit if you look for it. So it’s just not mainstream yet. And I think it will be here in a short period of time. Pedro Kertzman: A hundred percent. And just to double down a little bit as well, Rob. I think especially for the smaller MSPs, let’s say you hit a critical infrastructure, you stop a pipeline or anything like that, you’re going to have federal agencies going after you, right? But then when you hit a mom-and-pop shop, nobody really cares. And those guys are often served through these smaller MSPs. So I think getting a better understanding of the threat landscape that especially targets those small businesses, I think it’s just a natural progression of the change in the threat landscape. Robert Dutt: Well, and you bring up a point that I kind of pulled on a little bit with your friend, Tony Anscombe, not too long ago. There’s so much data about how many attacks right now are taking advantage of the MSP tooling as a threat vector. And so I think that also speaks to a need for an MSP who wants to be mature and responsible about these kinds of things to have a better grip on who’s looking, what they’re looking at, and how that maps to what they’re doing. Pedro Kertzman: A hundred percent. And just to link this specifically about eCrime and affiliates, affiliates would be the ones exploiting those RMM tools, right? Because it’s something that is already deployed in the environment. If they get the credentials that got stolen for whatever reason, they have access to those tools and then they can deploy malware that they bought from those affiliate programs inside of the victim’s networks. Robert Dutt: And it’s funny, almost a reversal of back in the day, I can remember as a Mac user, there was a saying that Apple engaged in security through obscurity. What you describe is almost the opposite of that. It’s insecurity to a degree through obscurity. In that if I’m an attacker, I know that if I go after Colonial Pipeline to use your example, I’m all over the front page and there’s going to be a lot of government agencies who have a lot of serious, serious questions for me. If I take out an MSP tool that gives me access to a bunch of very small clients though, maybe I fly under the radar just a little bit more. Cameron Tousley: Oh yeah. Robert Dutt: This is my last question. If there’s one shift in thinking that you’d want a Canadian MSP to walk away with after this conversation, in terms of how they think about these reports, in terms of how they think about the role of threat intelligence in their business, you know, one thing they should reconsider about how they’re approaching their security practice, what would that be? Pedro Kertzman: So I think first, Rob, that’s kind of more of a mindset type of thing. CTI still sounds super complex to a lot of people. I would say there are two main flavors. One, if you really want to dig into techniques and all that, yes, you can get fairly technical and sophisticated, but there are really simple ways to ingest cyber threat intelligence into existing automated tools. You can, of course, do a POC with one, two, whatever vendors you want to do. Once you find that real value for your customers, your end users, then it’s automated. We’re talking about data feeds ingesting directly into a firewall. If you don’t have a CTI central brain kind of thing, which the market knows as a TIP (threat intel platform), you don’t need to go that route, the sophisticated route. There are simple ways to use threat intelligence. And honestly, it’s super valuable because it’s just, again, automated. You’re outsourcing the knowledge to the vendor directly who’s going to execute that, like a firewall, for example. Cameron Tousley: Yeah, I think that’s some really good commentary. And I have a lot of business conversations with MSP business owners and I follow the market, and the consolidation, there’s tons of it. And there has been for a few years, but it’s just insane right now. And I think that there’s this thing going around, it’s like, look, evolve or sell. Because you have the advent of AI and that’s speeding everything up tenfold. And just don’t be afraid. If you want to continue to run your business, don’t worry, you’re going to have clients out there in your locale that probably love you. But they’re also going to have people calling them as these other MSPs get bigger, and these national ones that swallow other little smaller companies and then their go-to market will be, “Well, let’s go down market, down market,” because we can’t always go up market, that’s pretty hard to do. But down market is like shooting fish in a barrel kind of thing. So that means it’s a risk for the smaller MSPs that are not going to sell out, that want to be in business another 10 or 15 years. So don’t be afraid, utilize AI to research it. They say don’t use AI as Google, I disagree a little bit, but you can use it for a lot of things. This can summarize: what is this offering? Can I use it? Ask it really basic questions to get acquainted, and then take the next step and call your vendor and just have a conversation with them and say, “What are all my options? I am in this locale, I serve these kind of verticals, here’s my sizing, here’s the tools I use.” You’ve got to throw everything out on the table because then your vendor, somebody like a technical or business contact, can jump in and say, “Look, I think that you should check out this part of this larger offering. And here’s what I’ll do for you. And here’s what you’re going to do. We’ll give you a game plan, right? You’re going to trial it in the following ways, we’re going to pair you up with a technical person to teach you a little bit and be your co-pilot—Microsoft gets enough press.” But really kind of jump in, try it out. Don’t be afraid. Because if you want to be around another 10 or 15 years, you have to make the leap. And you don’t have to do anything big, but you have to start adopting some of this security-forward thinking so that you can have threat briefings with your clients and not statistical talks. There was just that MSP summit and there was actually a panel on what the next gen of MSPs is doing. And it was funny to hear it because they’re like, “Well, we’re focused on outcomes.” And I totally agree, but I know some of the older MSPs are like, “Well, we’re focused on outcomes too.” But I think it’s the talk track. You’re all saying the same thing, but you need some more complex tools in some ways to be able to have these more outcome-based discussions. Like, “Hey, I not only blocked X amount of threats, I kept your uptime up in this way, and that allowed you to keep productivity up. So by my clock here, you were able to achieve all those things that you wanted to achieve in our initial meeting, we’re on track.” That’s the conversation you want to have in addition to that little bit of the threat briefings peppered in. Robert Dutt: All right. Some great advice there. Gentlemen, thank you both for taking the time. I appreciate it. Cameron Tousley: Thank you, Rob. Pedro Kertzman: Great to be here. Cameron Tousley: Absolutely. It was a pleasure. Thanks so much. Robert Dutt: There you have it, Cameron Tousley and Pedro Kertzman from ESET. I’d like to thank both Cameron and Pedro for their time. They did exactly what we set out to do with this conversation, kept it firmly in the strategy lane with technical depth in service of the business point rather than the other way around. A few things to leave you with. The framing that stuck with me most was Cameron’s distinction between statistics talk and threat briefings. The idea that your quarterly client review shifts from “here’s how many threats we blocked” to “here’s the specific group targeting your vertical right now. Here’s how their affiliate operates, and here’s what we’ve already done about it.” That’s a real upgrade in how an MSP demonstrates value. It moves you from uptime vendor to trusted advisor and that’s a conversation your competitors probably aren’t having yet. On the technical side, Pedro’s explanation of affiliate-level tracking is worth sitting with. The headline ransomware groups get the attention, but it’s the affiliates, the ones buying malware-as-a-service and doing the actual execution who determine the tactics on the ground. Tracking them is what gives you an early warning before the attack scales. And as I noted during the conversation, there’s a certain logic in how attackers exploit the MSP model specifically. Go after the tooling, stay under the radar, quietly compromise a hundred small clients instead of one high-profile target. Obscurity in that scenario is working against you. For the smaller MSP who’s heard all of this and thought, “I’m not staffed for this,” Pedro’s entry point is worth considering. You don’t need a full threat intelligence platform or a dedicated analyst to start. Automate the ingestion of indicators of compromise directly into your clients’ firewalls. Let the tooling do the work. It’s not glamorous, but it’s real, actionable and it’s a lot more than most of your competitors are doing. And Cameron’s closing thought, “evolve or sell,” is the frame I’d put around all of it. The consolidation wave hitting the MSP market right now is not slowing down. The shops that survive as independents will be the ones that have more sophisticated conversations with their customers. Threat intelligence is one of the things that helps you have those conversations. If you found this one useful, please follow or subscribe to the podcast wherever you listen. We’re on Apple Podcasts, Spotify, YouTube, all the major podcast directories. Ratings and reviews are always appreciated. Until next time, I’m Robert Dutt for ChannelBuzz.ca and I’ll see you in the channel.
Today’s headline news for Canadian IT solution providers: SonicWall is making its Gen 8 security platform available in virtualized environments for the first time with the launch of the NSv XS, a subscription-based virtual firewall purpose-built for MSPs and MSSPs delivering managed security to small and distributed environments. The NSv XS supports VMware ESXi, Hyper-V, KVM, AWS, Azure, and Proxmox and ships in three service tiers designed around recurring revenue models. The top tier adds co-managed security from SonicWall’s SonicSentry NOC team plus embedded cyber warranty coverage through Cysurance. SonicWall’s 2026 Cyber Protect Report found high and medium severity attacks surged 20.8% last year, and with 52% of enterprises now running most of their infrastructure in the cloud, the NSv XS is explicitly designed to close that gap. Huntress and specialty insurance firm Acrisure have launched a new cyber insurance program offering eligible organizations access to Cyber or Tech E&O policies with no deductible and a streamlined application process. Organizations running qualifying Huntress Managed EDR and ITDR solutions may benefit from simplified underwriting – demonstrating active security posture translates to better insurance terms. The two companies are positioning the program as a response to growing AI-driven cyber threats and an alternative to the traditionally complex process of securing adequate cyber coverage. Intruder has released its 2026 Attack Surface Management Index, based on anonymized data from 3,000 customers. The headline number: 26% of organizations have exposed MySQL databases, a known target for ransomware and data extortion. Midmarket companies in the 5,000-10,000 employee range take an average of 56 days to remediate exposures – nearly four times slower than small enterprises. Banks closed gaps in an average of 11 days; insurance and pharma firms averaged more than 40. The report frames this against the emergence of autonomous AI models capable of independently discovering zero-day vulnerabilities – which makes a 56-day remediation window a meaningful risk. ThreatDown has launched identity threat detection and response for MSPs, adding credential-based attack detection to its managed security stack. ITDR joins ThreatDown‘s existing endpoint protection capabilities as attackers increasingly target identity infrastructure rather than devices directly. Cycode has announced new capabilities for AI-driven development, declaring “shift left is dead” and repositioning its application security platform around the AI development lifecycle. The move reflects a broader rethinking of where security fits as AI-generated code accelerates development velocity and introduces new risk vectors. Toronto-based MSP roll-up AYCE Capital has acquired a cybersecurity advisory firm to anchor a portfolio-wide center of excellence in vCISO and managed security operations. The move signals a push to build differentiated security capabilities across its MSP portfolio rather than sourcing them piecemeal. MSPAlliance has launched new service lines under its Cyber Verify program, expanding the compliance and assurance framework available to managed service providers. The additions give MSPs more structured pathways to demonstrate security and operational maturity to enterprise and regulated-industry clients. Read Full Transcript Welcome to The Buzz from ChannelBuzz.ca, I’m Robert Dutt, today is Wednesday, May 13, 2026, and here’s what’s happening in the channel today. SonicWall yesterday announced the NSv XS, a new virtual firewall extending its Gen 8 platform to cloud environments, with managed service providers and MSSPs as the primary target. The product allows partners to deploy firewall security wherever customer workloads run – public cloud, private cloud, branch offices, and distributed infrastructure – under a management model designed for multi-tenant operations. According to SonicWall, the NSv XS carries the same Gen 8 security engine found in its physical appliances into a lightweight virtual form factor, which the company says closes a growing gap as customer environments increasingly span both physical and cloud boundaries that legacy appliances can’t follow. The announcement is a practical one for the channel: a cloud-native firewall with the Gen 8 engine that can be managed centrally simplifies both the sales conversation around security coverage and the operational overhead of delivering it across heterogeneous customer environments. Also yesterday, Huntress announced a partnership with insurance firm Acrisure to connect cybersecurity posture directly to cyber insurance outcomes for eligible organizations. Under the program, customers running the Huntress managed security platform can access Cyber and Tech Errors and Omissions policies through Acrisure with no deductible – with policy terms tied to the customer’s verified security posture rather than a generic underwriting baseline. According to Huntress, the program is built on the premise that organizations that have actually deployed layered security controls should not be underwritten at the same rates as those that haven’t. The arrangement is worth watching for solution providers who have been looking for cyber insurance integrations that go beyond co-marketing – this one appears to operationalize the connection between managed security delivery and insurance terms in a way that could strengthen both the MSP’s value proposition and the client’s risk profile. Intruder rounded out a busy Tuesday by releasing its 2026 Attack Surface Management Index, drawing on anonymized data from 3,000 organizations to assess how quickly companies are identifying and closing their exposed attack surfaces. The headline finding: more than one in four organizations still have MySQL databases exposed and accessible from the internet – a foundational configuration risk that the report says reflects a broader struggle to maintain visibility over sprawling and distributed infrastructure. According to Intruder, the data shows that human remediation is falling further behind the pace of automated exploitation, a trend the company calls the “Mythos Era” – a period in which attacker tooling has measurably outpaced defender workflows. The report gives solution providers a concrete, data-backed framework to bring into client conversations, particularly for customers still relying on point-in-time scanning rather than continuous monitoring. In Brief – ThreatDown yesterday launched an identity threat detection and response platform, extending its security stack to cover credential-based attacks across Microsoft Entra ID, Okta, and Active Directory. Cycode is declaring “shift left is dead,” releasing new agentic development lifecycle security capabilities designed to protect AI-driven software pipelines from code generation through deployment. Toronto-based AYCE Capital yesterday announced the acquisition of a cybersecurity advisory firm to anchor a portfolio-wide security center of excellence. MSPAlliance last week added Service Lines to its Cyber Verify platform, letting MSPs map audited controls directly to the services they deliver for cleaner, client-ready compliance reporting. Full details and links in the show notes or the blog post. Later today on In The Channel, we’re sitting down with Steve Petryschuk from Auvik to dig into their 2026 IT Trends Report and what the data reveals about the gap between AI ambition and AI maturity in managed services. And if you haven’t heard it yet, yesterday’s episode is a good one – Joel Abramson from Top Down Ventures joins me to discuss the close of their C$38 million MSP-focused founders fund and why they believe managed service providers are the primary delivery vehicle for AI to the small and mid-market. That’s how we’re seeing the headlines today. I’m Robert Dutt for ChannelBuzz.ca, thanks for listening. Have a great day.
Identity is at the center of nearly every modern breach, but when IAM responsibilities are shared with MSSPs, where does trust end and accountability begin? In this episode of CISO Stories, Jessica Hoffman sits down with Dr. Dustin Sachs to explore the human side of identity and access management, including cognitive bias, automation, privilege creep, and the hidden risks of "blind trust" in real-world security operations. Visit https://cisostoriespodcast.com for all the latest episodes! Show Notes: https://cisostoriespodcast.com/csp-224
Send us Fan MailSnehal Antani, CEO and Co-Founder of Horizon3.ai, addressed the tactical reality of AI-driven adversary behavior. AI has drastically accelerated the attacker's “OODA loop” (Observe, Orient, Decide, Act), citing a documented case of an autonomous compromise occurring in just 77 seconds. Beyond the technical speed, the discussion touched on geopolitical shifts, including Iranian targeting of dual-use infrastructure and a projected surge in unpatched vulnerabilities (CISA KEVs) for late 2026.To counter these hyper-automated threats, Horizon3.ai is leveraging its channel partners and MSSPs to deploy advanced defensive tactics, such as deception technology and data poisoning. By empowering partners to move beyond traditional scanning and into active, autonomous defense, Horizon3.ai aims to neutralize AI-driven exploits before they can be weaponized against civilian and corporate infrastructure.See our past interview with Horizon3: https://www.e-channelnews.com/horizon3-ai-grows-its-global-partner-program/Horizon3.ai recently released new research on how organizations measure security—and whether those metrics reflect real resilience against attackers. The findings reveal a clear gap between tracking completed work and actually stopping real-world threats.Key findings include:Only 11% of practitioners validate or patch within 24 hours of a CISA or ENISA known exploited vulnerability alert, many take a week or more to confirm if they're even exposed93% of CISOs say they could prove their organization took reasonable, validated steps to prevent a breach, yet only 30% patch and then test to confirm the risk was actually removed97% of CISOs are confident their endpoint protection would detect lateral movement or privilege escalation, yet only 12% have validated EDR effectiveness in the last three months
Tim Coach, chief evangelist at Cynomi For most managed service providers, the security services story has followed a familiar arc: endpoint protection, email security, security awareness training. Each category added value, then became table stakes. Third-party risk management – TPRM – is what comes next, and according to Cynomi Chief Evangelist Tim Coach, it may be the stickiest revenue category yet. The case is straightforward. Every business relies on a web of vendors, software providers, and service partners. Each one is a potential vulnerability. And most SMBs have no formal process for knowing how well those third parties are managing their own security – or what happens to them downstream if one of those vendors gets breached. Research from Cynomi suggests 45 percent of organizations will face supply chain attacks, and 30 percent of data breaches already involve a third party. The attack surface has shifted to the things organizations trust most. For Canadian MSPs, the regulatory pressure is specific and near-term. OSFI’s Guideline E-21, with a September 2026 compliance deadline for federally regulated financial institutions, puts third-party oversight explicitly on the agenda. The cascade effect on their vendors – and the MSPs serving those vendors – is already in motion. Perhaps the sharpest signal in this conversation: cyber underwriters are now denying SMB coverage not because of anything the SMB did, but because they are connected to an MSP. The managed service provider, long positioned as the path to better insurance outcomes, has become a risk factor in its own right. Coach’s recommended first move for any MSP building into TPRM isn’t a vendor questionnaire – it’s a Business Impact Analysis. Understand how the client actually makes money, which vendors are critical to those revenue processes, and what an hour of downtime costs. That reframes the conversation from technical widgets to revenue, cost, and risk – the language every business owner speaks. – UPLOAD AUDIO Read Full Transcript Robert Dutt: Hello and welcome to In The Channel from ChannelBuzz.ca, bringing news and information to the Canadian IT channel for the last 16 years. I’m Robert Dutt, editor of ChannelBuzz.ca, your host for the show. My guest today is Tim Coach, Chief Evangelist at Cynomi, a vCISO platform purpose-built for MSPs and MSSPs. Tim brings an unusually grounded perspective to the space. He’s an engineer by training who spent nearly two decades building, running, and consulting on managed service practices before landing at Cynomi after seeing the platform first-hand and recognizing it could have solved one of his biggest operational headaches as an MSP owner – the CISO bottleneck, the point at which growth stalls because the security function can’t scale without adding expensive headcount. That personal history shapes everything he thinks about TPRM, third-party risk management, which is increasingly being talked about as the next major revenue category for MSPs after human cyber risk. Today we’re talking about what building a TPRM practice actually looks like, why cyber insurance has quietly flipped the MSP value equation, and why the right starting point isn’t a vendor questionnaire at all. Let’s get right into it, my chat with Tim Coach. Tim, thanks for taking the time. I appreciate it. Tim Coach: I absolutely love to be on. Thanks so much for having me, and for having Cynomi on your webinars. We’re always happy to do these things and educate the community. Robert Dutt: You’ve spent a long time in and around the MSP community. How did you end up at Cynomi specifically, and what was it about the opportunity around TPRM that pulled you in? Tim Coach: TPRM was eventually in the process – let me back up. What got me into the community was my engineering background. I went to college for what was called network communications back in those days. Basically I’m a network guy – I always point at the front-end programming guy and say, “It’s your fault,” and the programming guy says, “No, no, it’s the network’s fault.” So I did that for a large-scale nationwide company for many years, and then I fired my MSP. The owner was like, “Well, if you’re so good, why don’t you come over here and run this?” And I said okay. It took me about 24 hours to realize I didn’t have a clue what was going on – the place was chaos. But through process and procedure, and a military background, I knew I could get it under control. I ended up with a business partner from that experience, and we spent about 20 years rebuilding and consulting with MSPs. About five years ago, I just needed something different. The kids were a little older. I started looking at what else was out there, talked to a couple of mentors in the space – I’m sure if I mentioned their names everyone would know them – and they said, “You should come over and do this.” So I jumped. I went to work for a Canadian company, grew them quite a bit in the first year, then moved to an Australian company, grew them, and then went back to consulting for a short time. David from Cynomi was recommended to me as a consulting connection. We were going back and forth and he said, “Why don’t you come on board?” And I said, “I’m not really interested in selling a widget” – and it’s a security widget, right? There are so many great widgets and great personalities in the security space already. Probably not my jam. But he said, “No, no – let’s look at it.” And he showed me what Cynomi did, and I was blown away. The reason I was blown away is that at my most successful MSP, we hit a stopping point in our growth. The reason was our CISO – and this was before CISO was even a cool term. He was our bottleneck. Not because he was inefficient as a person, but because of the way he had to work: 80 pages of Excel spreadsheets and hours and hours of questionnaires. When I first saw Cynomi, I thought, “Here’s a way I could have doubled the size of my company with the same staff, the same CISO.” That’s what really inspired me to come on board – seeing that dashboard and connecting it to the personal pain I’d experienced around the security bottleneck. Now with the addition of TPRM, that excites me even more, because back in my MSP days I had a lot of bank clients, and banks are SOC 2 all over the place. Part of SOC 2 is that you have to have TPRM – you have to be responsible for everybody in the chain. So now we’ve built out a platform that lets the MSP, MSSP, ITSP, or whatever SP you want to put in front of those letters, easily manage vendor relationships and understand where clients are in their security posture. Robert Dutt: You may not feel it’s cool, but it’s certainly foundational security. Tim Coach: And that’s the problem, right? That’s why we’re still talking about security – because nobody knows how to talk business. They all talk widgets, bits and bobs: here’s this cool firewall, MDR, XDR. But you know what your clients don’t care about? The widgets. They care about being secure. Until we can bridge that gap – until Cynomi brings something that says, here’s an easy way to get to the data and details you need, here’s CISO-level intelligence so the MSP can translate it into business terms for the doctor’s office, the manufacturing company, whatever vertical you want – we’re going to keep having this same conversation. Robert Dutt: Let’s do a little bit of that with TPRM itself. Let’s take a step back and look at it from the viewpoint of an MSP who’s heard the acronym but hasn’t really dug in yet. Third-party risk management – what are we actually talking about, and what problem does it solve? Tim Coach: What a lot of people need to understand – and I try to say this in a way that’s easy to grasp – is: manage security first, and compliance becomes a default. What I mean is that you need a baseline, whether it’s CIS Controls, Cyber Essentials Plus, CMMC 2.0, one of the financial frameworks, HIPAA, whatever applies. You need a baseline you’re actively managing your security against. In the process of meeting that baseline, compliance follows. What we’re increasingly seeing is that certification bodies, auditors, and insurance underwriters all want to see that your solutions and partners are just as secure as you are. I was at Canalys Barcelona last year and someone made a statement that blew me away: for the first time ever, we’re seeing insurance underwriters deny coverage to an SMB because they’re connected to an MSP – and the MSP is what they consider the risk. We went from being the most important people in the room, essential workers, to being the risk factor. And on top of that, helping clients with their insurance has been one of our foot-in-the-door conversations for the last decade. That’s where TPRM comes in. The frameworks and insurance underwriters now want to see not just that you’re secure, but that everyone you’re working with is secure. The problem has always been how you manage that. Back in my day, you had to call the vendor, find the right person, ask for evidence of their SOC 2 compliance, get bounced around, end up with legal, sign an NDA, and eventually get the report. Now people share that information a bit more freely, but you still need a central place to manage it – so when an auditor or insurance broker asks, you can point to it and say, “Here it is.” We do a community call every Wednesday at noon Eastern, and we’ve had a gentleman on a couple of times who has written books specifically on TPRM. He’s sounding the alarms – not bad alarms, just “it’s coming.” But like a lot of SMBs, MSPs are having to drag their clients toward where they need to be. Once you make it easy for the MSP, you make it easy for the SMB, and you finally have a way to prove you’re taking those measures. Robert Dutt: Supply chain attacks have certainly been a theme in the channel for a while – Kaseya, SolarWinds, MOVEit. But TPRM as a formal managed service element feels newer. The insurance side sounds like a big driver. What else changed to make it go from a theoretical concern to something MSPs can actually build a practice around? Tim Coach: I firmly believe you cannot be a business partner without knowing how your partner makes money and how you need to protect them. I can’t protect them if I don’t know what they’re using. It’s the old adage: if two people are managing something, nobody’s managing it. TPRM is really the next step for the ITSP to move from a transactional relationship to a true business partnership – ensuring that everyone your clients are using is also protected. Because what happens is what always happens: it doesn’t matter what you have hard-coded in the contract about not being responsible for X. When something goes wrong, the SMB comes back and says, “But I thought you were managing this.” We go over it in the contract reviews, sure, but the conversation still happens. When you’re genuinely talking business – saying, “I’m going to protect how you operate quarter after quarter, year after year” – you’re protecting their entire environment, not just your piece of it. That’s when you move to a real business relationship instead of a sales relationship where every conversation is an upsell or a cross-sell. We’ve done it to ourselves a little bit, honestly. It’s like an insurance agent in Oklahoma trying to sell hurricane insurance. That’s not what we should be doing as business partners. TPRM allows us to have a full understanding of the client’s environment and make sure everything is protected – or at minimum, that the gaps are known by everyone. Robert Dutt: Cynomi has described TPRM as the next major revenue category after human cyber risk. Can you walk me through what the recurring revenue model actually looks like, and what makes it sticky? Tim Coach: Everything leads to MRR – that’s business. But you have to start with a project. You need to understand where the client is in their security journey before you can manage them ongoing. SMBs don’t do things for free, and neither do our partners. This is a revenue generator. But it’s a revenue generator because it actively has to be managed. I always say: I can’t throw a server at security. I can’t throw a firewall at it and declare myself secure. The best analogy I’ve heard for security is a block of Swiss cheese. There are holes, and you can stick a fork through those holes quite a way. But if you slice that block and turn every slice 90 degrees, the holes are still there – they’re just not as deep or vulnerable. That’s TPRM. There is no set-it-and-forget-it. It has to be actively managed, and that active management is where the recurring revenue lives. Robert Dutt: What does a typical engagement look like early on, for an MSP starting from zero with a client? Where does the work begin, and what surprises people about the scope as they go deeper? Tim Coach: Everything begins with an assessment. With Cynomi’s tools, we can use Cyber Essentials Plus or CIS Controls as a self-regulating baseline and add a couple of hours to the initial assessment to incorporate the security piece. We all do assessments upfront to understand what we’re getting into – or what needs to be fixed before we really dig in. Once you’re in the security layer, the next step is TPRM. And TPRM brings with it something I think is critically important: the Business Impact Analysis. It’s not enough to ask, “What does your client do?” They make dog food – do they? Or is that just the end product? When I was an MSP, I had a metal manufacturer that cut and stamped metal. But if you asked their CFO what the business was, he’d say, “Making pallets – I make more on pallets than on the stamping work.” I used this example in a presentation just yesterday. Years ago I was walking through a manufacturer’s facility and asked about a machine: “What does that one do?” “That runs the software that completes our product.” “Why isn’t it plugged into the network?” “It’s a Windows 98 machine.” “Why are you still running that?” “Because it runs decade-old German software that costs ten million dollars to replace. And we only have that one machine.” If you’re not walking through and genuinely understanding how they make money, you don’t know where the risks are. And that’s what TPRM forces you to do. Ideally, I’d love to sell a project that includes a full security assessment, a BIA, TPRM, BCP, IR planning, all of it from day one. But it doesn’t happen that way. You have to phase it. Once you understand the BIA and what they’re actually doing, you understand where the software and systems that carry real business risk are, and you can start building that into their security posture. It’s the same principle: why hack an individual when you can hack the software that manages all the individuals? Why try to crack one account when you can compromise an MSP’s RMM tool and get access to everybody? If you go into a business without understanding their software environment and vendor posture, you at minimum need to be able to tell them where the risks are. Because the language they speak is revenue, cost, and risk. TPRM is a risk if it’s not being managed – and that’s why we’re seeing so much attention on it lately, even though some of us have been doing this for decades. We just used to call it vendor management. Robert Dutt: We’ve talked a lot on the show about MSP tools as an attack surface – RMM agents, remote access tools, backup platforms. The MSP is supposed to be managing the client’s vendor risk, but the MSP’s own toolchain is also someone else’s third-party risk. How should MSPs be thinking about that? Tim Coach: It comes back to the BIA again. What are they using? What’s creating the security gaps, and how do you build better overall management around it? There’s a project in there, but every project should lead to MRR – period. It still has to be managed. Remember when Exchange servers went away and everyone panicked about where the revenue was going to go? There was still an entire environment to manage. We always made some revenue on hardware, though that’s gotten harder – the real money is in managing the ongoing environment. TPRM is the same thing: it’s a significant security gap in the overall posture of your clients, and that gap has to be actively managed. Robert Dutt: Pushing on that a little further – TPRM platforms are pulling in a pretty comprehensive map of an organization’s vendor ecosystem: the gaps, what’s been remediated, basically a full picture of the landscape. If one of those platforms gets compromised, that’s not just a breach – that’s a pretty rich target list for an attacker. How do you think about that? Tim Coach: Think about a CNC factory. Their job is building molds to produce a specific part, and the software on their server has all the schematics fully built out. What happens if that software gets hacked? You lose all the schematics for the CNC machine – so suddenly you can’t produce anything. And if the attacker gets in early enough in the process, the downstream supply chain impact goes way beyond that one facility. That’s the risk. If you’ve got $200,000 five-axis CNC machines – and I may have a little experience with this – and you’re not protecting the software running them, and you don’t understand from a TPRM perspective what the vulnerabilities look like, that’s an ongoing, persistent risk. You always have to be managing it. Robert Dutt: Sitting where Cynomi is, how do you think about the security side of running a TPRM solution, and what should MSPs be asking vendors in this space about that? Tim Coach: Efficiency. How efficient can you make it? I’ll probably get in trouble for saying this, but we’ve essentially stupid-proofed the first few levels. We’ve built it out for you. And look – I know AI is a word we’ve managed to avoid for about the last half hour, but AI is meant to enhance the human. It’s a tool. What we’ve done at Cynomi is build AI agents and intelligence into the platform to make this work manageable at a lower labor level. If I can take work that previously required a CISO – an expensive asset – and bring it down to a tier-two technician, my margins go up because my labor costs go down. That said, we’re not replacing the CISO. I used to work with a company that built a component for Apache helicopters – no public-facing anything. If a tier-two tech runs a report showing no web security for that client and flags it as a critical gap, the CISO might be the only person who knows that client has no public-facing presence by design. That context matters. The CISO still needs to be the final approval layer. What Cynomi has done is open up bandwidth for other people to do the groundwork, so you can grow your company without adding another six-figure salary. When your staff becomes more efficient, the CISO is less of a bottleneck – which was the original problem we started with. Robert Dutt: For the Canadians listening, there are some very specific regulatory drivers on the table right now. OSFI’s Guideline E-21 has a September 2026 compliance deadline for federally regulated financial institutions. Can you talk about the role you see TPRM playing in responding to that kind of regulation? Tim Coach: What we’re seeing is that the insurance underwriters, auditors, and regulators are the ones setting the standard, and the industry has to meet it – but the industry isn’t yet at a point where it can easily meet a TPRM standard. So what will probably happen, whether it’s Canada, the US, the UK, or EMEA, is a pattern we’ve seen before: they’ll release a guideline, there’ll be a period of voluntary adoption, and then they’ll give it teeth. Like HIPAA – they threw it out there, and eventually it got enforcement. The thing I’ve always loved is watching the auditors, because they’re typically running a couple of years ahead of the regulation. If you stop treating auditors like your mortal enemy – “they’re here to expose everything I’m doing wrong” – and start paying attention to what they’re flagging, you can get ahead of the game. Auditors are a leading indicator. It’ll always come down to government forcing the policy, and then insurance trying to find a way out of paying claims when it’s not followed. But if you’re watching the auditors and TPRM is showing up in their reviews, you already know what’s coming. Robert Dutt: For an MSP listening to this and thinking, “I should be doing this” – what’s the realistic first move? Not the ideal end state, but the practical starting point? Tim Coach: Start with the BIA – the Business Impact Analysis. Research suggests every SMB has three to five critical processes that drive about 80% of their revenue. Do they actually know what those are? Probably not. They make dog food. They take care of kids. Whatever it is – they don’t actually know how they make money. I have an old client who’s also a friend – he works in retirement planning. If you asked how he makes money, you’d assume it’s from managing portfolios. It’s not. He makes money by selling the policy, and the insurance company pays him a commission on that. If you don’t start by understanding the BIA, you don’t really know what solutions your clients are dependent on. Start with: who is your critical software outside of us? Who maintains it? Do we have a relationship with them? Does it connect directly to how you make money? And tie it to cost of downtime. If a doctor’s office goes down for four hours – and in a medical practice you call them providers, not doctors, right? Speaking their language, not ours – what does that cost? If the pallet machine on an assembly line goes down, and that pallet machine is the only thing holding product so the rest of the line can keep moving, what’s the cost per hour? If you don’t know that, you don’t actually understand how to service your client. You’re still talking bits and bobs instead of revenue, cost, and risk. Robert Dutt: Future-looking question to wrap up: where do you see this category going over the next couple of years? Is TPRM a standalone practice, or does it fold into a broader vCISO or governance offering? Tim Coach: I think it’s going to be both. For more mature MSPs, it’ll be baked right into their silver, gold, and platinum packages – TPRM is just part of what you get at a certain tier. For others, especially those that aren’t at a full vCISO-as-a-service level yet, it’ll be available as a standalone – a meaningful piece of the security posture they can deliver to clients without committing to the full stack. Growth and maturity, right? As people build their practices, the more advanced will have it embedded. But there’s also a real path for someone starting out to say, “I need to at least get this piece right, because it’s critical to the overall security posture of my clients.” Robert Dutt: Fascinating. It’s an interesting area of technology and – to your greater point – business. I appreciate you taking the time to share some thoughts on how service providers can get involved. Tim Coach: Thanks for having me on. I always appreciate it. Robert Dutt: There you have it – Tim Coach from Cynomi. I’d like to thank Tim for taking the time today. He’s been around the MSP space long enough that when he points at something and says it’s the next thing, it’s worth listening. A few things I want to make sure land from this conversation. The first is the Business Impact Analysis as the true starting point. Before you think about vendor questionnaires or risk scoring tools, you need to understand how your client actually generates revenue – which processes drive the majority of the business, and which vendors are load-bearing in that equation. That’s not a security conversation. That’s a business conversation. And that’s the shift that moves an MSP from tool vendor to genuine business partner. The second is the insurance signal. When underwriters start denying SMB coverage not because of something the SMB did, but because they’re connected to an MSP – that’s a warning and an opportunity in the same breath. MSPs who can demonstrate they’re actively managing their clients’ third-party risk have a new and better story to tell. And the frame to carry with you: security first, compliance becomes a default. Build the practice to the right security baseline and the compliance checkboxes largely take care of themselves. In The Channel is available on Apple Podcasts, Spotify, YouTube, and most major podcast directories. If you’re finding value here, ratings and reviews are always appreciated – they help other people in the Canadian IT channel find the show. Until next time, I’m Robert Dutt for ChannelBuzz.ca, and I’ll see you in the channel.
Today on Defender Fridays, Katherine McNamara, Cybersecurity Technical Solutions Architect at Cisco, joins us to discuss how AI and ML adoption in enterprise infrastructure has expanded the attack surface for AI-driven systems.She'll walk through the security challenges unique to generative AI and ML-based architectures, and cover the four critical components: Model, Data, Application, and System, that organizations need to secure to maintain integrity.Katherine works for Cisco as a Cybersecurity Systems Engineer by day and by night, she's labbing and trying new things with the resources she has available. Katherine loves technology and getting her hands into the CLI or trying something new. She holds a Bachelors of Science and Masters of Information Security and Assurance from Western Governors University as well as several industry certifications. Register for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.io/Follow LimaCharlieSign up for free: https://limacharlie.io/LinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie
Jeff McJunkin, Founder of Rogue Valley Information Security, joins Defender Fridays to talk AI-powered code scanning for vulnerabilities. Jeff walks through real examples including using AI to find privilege escalation bugs in the Linux kernel.Jeff McJunkin is the founder of Rogue Valley Information Security, a consulting firm specializing in penetration testing and red team engagements. Jeff found the offensive side of cyber security very alluring during one the first penetration tests of his career. Feeling the challenge of host defenses like AV and centralized logging, and, at the time, knowing nothing about AV evasion or avoiding events that are likely to cause alerts, it was all very exciting. The challenge of successfully accomplishing the goal of that pen test, using essentially only native tools, was addictive for Jeff. He was hooked. Since those first penetration tests, Jeff has gone on to become an expert in the field, doing assessments for Fortune 100 companies, architecting two major versions of Core NetWars Experience, and contributing a vast amount of material to SANS Penetration Testing.Register for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.io/Follow LimaCharlieSign up for free: https://limacharlie.io/LinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie
Today, Dylan Williams, Co-Founder and Chief Research Officer at Spectrum Security, joins Defender Fridays to dig into that exact problem: self-evaluating agents, trajectory analysis, and what improvement looks like in production.Learn more at https://www.spectrum.security/Register for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.io/Follow LimaCharlieSign up for free: https://limacharlie.io/LinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie
Joshua Neil, Co-Founder of Alpha Level, dives into a more sophisticated understanding of AI SOCs. Join the conversation about this industry change on Defender Fridays.Dr. Joshua Neil, has been a pioneer in applying machine learning to cybersecurity since 2000, starting his journey at Los Alamos National Laboratory. There, he co-developed Pathscan, a network anomaly detection system capable of spotting attacks that slip past traditional defenses. In 2014, he and CEO Mike Pozmantier took that innovation to market by licensing Pathscan to Ernst & Young (EY), turning deep research into enterprise impact.That experience exposed a hard truth: anomaly detection is powerful at catching unknown threats - but on its own, it creates too much noise. Josh went on to tackle the other half of the problem, alert overload, through leadership roles at Microsoft and Securonix, gaining firsthand insight into the real-world struggles of security teams.In 2023, Josh and Mike launched Alpha Level to bring both worlds together: pairing the depth of anomaly detection with the precision of behavioral threat signals. The result? A platform that reduces false positives, adapts to your environment, and lets teams focus on real threats—before they become breaches. Learn more here: https://alphalevel.ai/Learn more at reconinfosec.comRegister for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.io/Follow LimaCharlieSign up for free: https://limacharlie.io/LinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie
This week on Defender Friday we are joined by Andrew Cook, CTO of Recon InfoSec, to talk about what it means to build a strong security team and why hiring builders is always a good bet.As the CTO of Recon InfoSec, a leading provider of managed security operations, Andrew oversees the technical vision, strategy, and execution of their services and solutions. He has more than a decade of experience in threat hunting, digital forensics, network defense, and capability development.Andrew's mission is to provide customers with the expertise they need to confidently and effectively respond to incidents, protect their organizations, and enhance their resilience. He has a proven track record of delivering high-quality results, leading and mentoring teams, and collaborating with partners across the industry and the government. Andrew is also a former Air Force officer, with national-level contributions and a passion for technical leadership.Learn more at reconinfosec.comRegister for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.io/Follow LimaCharlieSign up for free: https://limacharlie.io/LinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie
David Burkett, Cloud Security Researcher at Corelight, is back on Defender Fridays this week to discuss thinking in pipelines for AI agents.As a dedicated and highly experienced Cloud Detection Engineer and Security Architect, David has the privilege of working at a Fortune 50 Company where he leverages his extensive background in cybersecurity to protect digital assets. With a proven track record of building three different Cyber Security Operations Centers for multiple MSSP/MDR providers.David's expertise is backed by a strong set of GIAC certifications, including GCTI, GCIA, GPYC, and GCED... among others. He's proud to have been part of a large overall security team that won the prestigious James S. Cogswell Outstanding Industrial Security Achievement Award from the Defense Counterintelligence and Security Agency. Our security operations center was recognized as being among the top 1% of cybersecurity programs for all cleared facilities.In addition to his hands-on experience, David has consulted for over 40 Fortune 500 Companies and Large Federal Organizations, helping them manage their SOAR platforms and playbooks. As a strong believer in knowledge sharing and collaboration, he's also an active contributor to the open-source detection security project known as Sigma. Learn more at https://corelight.com/Register for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.io/Follow LimaCharlieSign up for free: https://limacharlie.io/LinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie
Every vendor at RSAC Conference 2026 will have an autonomous SOC story. Subo Guha, Senior Vice President of Product Management at Stellar Cyber, has been building the real thing for over a decade -- and he has one question every buyer should ask at every booth: can your platform explain why it reached its verdict? Stellar Cyber's autonomous SOC provides a full case summary for every true positive, showing the forensic evidence chain, threat intelligence correlations, and specific observables that led to the conclusion. SOC analysts can review, challenge, or override -- and that feedback loop is how the system improves. The threat landscape has shifted in ways that validate Stellar Cyber's original architecture. LLM-generated attacks have collapsed the time to launch a sophisticated phishing campaign from weeks to minutes. Stellar Cyber was built to serve the mid-market and the MSSPs that protect it -- organizations that face identical threats to enterprises but without enterprise resources. A unified, multi-tenant platform means MSSPs onboard new customers in minutes. An open data ingestion engine works with whatever tools are already in place -- no EDR lock-in, no rip-and-replace. At the center of the platform is a correlation engine that transforms thousands of individual alerts into a manageable set of high-confidence cases. An identity compromise driving lateral movement across dozens of alerts becomes one case with a clear recommended action. Subo describes this as the difference between drowning in noise and focusing on decisions that actually require human judgment -- and it is the foundation the autonomous SOC layer is built on. Subo is direct about what the hype gets wrong: the claim that organizations can dramatically cut SOC headcount because AI has it covered is not happening. The realistic version of autonomous SOC is a force multiplier -- digital agents handle the continuous, high-volume triage work that consumes analyst hours, freeing humans for the cases that require context and institutional knowledge. A system that automates without explainability does not reduce risk. It relocates it. Stellar Cyber will be at booth S327 in the South Hall at RSAC Conference 2026, right at the bottom of the escalator. Live autonomous SOC demonstrations will be running throughout the event, with real-world results from customers already in production. The team also has a barista on site -- a detail Subo was particularly keen to mention for Marco Ciappelli. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Subo Guha, Senior Vice President of Product Management, Stellar Cyberhttps://www.linkedin.com/in/suboguha/ RESOURCES Learn more about Stellar Cyber: https://stellarcyber.ai RSAC Conference 2026 Coverage: https://www.itspmagazine.com/rsac-2026-conference-san-francisco-usa-cybersecurity-event-infosec-conference-coverage Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS Subo Guha, Stellar Cyber, Sean Martin, brand story, brand marketing, marketing podcast, brand spotlight, autonomous SOC, Open XDR, MSSP security platform, AI-driven security operations, agentic AI cybersecurity, threat detection and response, RSAC Conference 2026, SOC analyst tools, multi-tenant security platform, LLM-generated attacks, security operations center, SIEM NDR unified platform Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Saurabh Shintre, Founder and CEO of Realm Labs, is on Defender Fridays today to discuss securing AI from within.Saurabh previously led the AI security research at Splunk and Symantec. He has been at the forefront of AI security research for nearly a decade with multiple publications and patents and regularly features on public forums on issues regarding security and AI. Saurabh holds a PhD from Carnegie Mellon. Learn more at https://www.realmlabs.ai/Register for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.io/Follow LimaCharlieSign up for free: https://limacharlie.io/LinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie
John V, AI risk, safety, and security at the Institute for Security and Technology (IST), joins Defender Fridays today. John's work spans AI red teaming, adversarial machine learning, AI evals and validation, and AI risk assessment, including policy work at the intersection of AGI and nuclear strategic stability. Learn more at https://securityandtechnology.org/Register for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.ioFollow LimaCharlieSign up for free: https://limacharlie.ioLinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie
What does it take to turn the dream of an autonomous SOC into something organizations can actually deploy? Subo Guha, Senior Vice President of Product Management at Stellar Cyber, joins Sean Martin to share how the company's AI-driven security operations platform is making that vision a reality. Stellar Cyber serves SOC teams across more than 50 countries, with a primary focus on MSPs and MSSPs supporting the underserved mid-market, though marquee enterprise customers like Canon are also part of the portfolio.How can agentic AI change the way SOC teams handle alert overload? Guha describes what he calls a "digital army" of AI agents that work around the clock to automate alert triage and catch phishing attacks. The system filters 70 to 80 percent of incoming alerts, allowing analysts to focus on the 20 percent that matter most. With attackers using AI to launch faster and more frequent campaigns, Stellar Cyber takes a human-augmented approach, meaning the AI learns from analyst interactions and continuously guides the SOC team toward faster, more accurate remediation.Why does this matter for MSPs operating on thin margins? Guha explains that the autonomous SOC capability layered on top of Stellar Cyber's XDR platform allows MSSPs to serve more customers, reduce mean time to repair, and grow their tenant base without proportionally increasing staff. When MSSPs grow revenue, Stellar Cyber grows alongside them, creating a mutually beneficial model that ultimately means more organizations get protected.This is a Brand Highlight. A Brand Highlight is a ~5 minute introductory conversation designed to put a spotlight on the guest and their company. Learn more: https://www.studioc60.com/creation#highlightGUESTSubo Guha, Senior Vice President of Product Management, Stellar Cyber @LinkedInRESOURCESLearn more about Stellar Cyber: https://stellarcyber.aiAre you interested in telling your story?▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlightKEYWORDSSubo Guha, Stellar Cyber, Sean Martin, brand story, brand marketing, marketing podcast, brand highlight, autonomous SOC, agentic AI, security operations, XDR, NDR, MSSP, MSP, alert triage, AI-driven security, Open XDR, Gartner Magic Quadrant, phishing detection, SOC automation Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
What does it take to turn the dream of an autonomous SOC into something organizations can actually deploy? Subo Guha, Senior Vice President of Product Management at Stellar Cyber, joins Sean Martin to share how the company's AI-driven security operations platform is making that vision a reality. Stellar Cyber serves SOC teams across more than 50 countries, with a primary focus on MSPs and MSSPs supporting the underserved mid-market, though marquee enterprise customers like Canon are also part of the portfolio.How can agentic AI change the way SOC teams handle alert overload? Guha describes what he calls a "digital army" of AI agents that work around the clock to automate alert triage and catch phishing attacks. The system filters 70 to 80 percent of incoming alerts, allowing analysts to focus on the 20 percent that matter most. With attackers using AI to launch faster and more frequent campaigns, Stellar Cyber takes a human-augmented approach, meaning the AI learns from analyst interactions and continuously guides the SOC team toward faster, more accurate remediation.Why does this matter for MSPs operating on thin margins? Guha explains that the autonomous SOC capability layered on top of Stellar Cyber's XDR platform allows MSSPs to serve more customers, reduce mean time to repair, and grow their tenant base without proportionally increasing staff. When MSSPs grow revenue, Stellar Cyber grows alongside them, creating a mutually beneficial model that ultimately means more organizations get protected.This is a Brand Highlight. A Brand Highlight is a ~5 minute introductory conversation designed to put a spotlight on the guest and their company. Learn more: https://www.studioc60.com/creation#highlightGUESTSubo Guha, Senior Vice President of Product Management, Stellar Cyber @LinkedInRESOURCESLearn more about Stellar Cyber: https://stellarcyber.aiAre you interested in telling your story?▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlightKEYWORDSSubo Guha, Stellar Cyber, Sean Martin, brand story, brand marketing, marketing podcast, brand highlight, autonomous SOC, agentic AI, security operations, XDR, NDR, MSSP, MSP, alert triage, AI-driven security, Open XDR, Gartner Magic Quadrant, phishing detection, SOC automation Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
This week on Defender Fridays, Farshad Abasi, Founder and CEO of Forward Security and Eureka DevSecOps, discusses how AI can help us set a new standard in app and cloud security. Farshad brings over 27 years of industry experience to the forefront of cybersecurity innovation. His professional journey includes key technical roles at Intel and Motorola, evolving into senior security positions as the Principal Security Architect for HSBC Global, and Head of IT Security for the Canadian division. Farshad's commitment to the field extends to his role as an instructor at BCIT, where he imparts his wealth of knowledge to the next generation of cybersecurity experts. His diverse experience, which spans startups to large enterprises, informs his approach to delivering adaptive and reliable solutions.Engaged actively in the cybersecurity community through roles in BSides Vancouver/MARS, OWASP Vancouver/AppSec PNW, and as a CISSP designate, Farshad's vision and leadership continue to drive the industry forward. Under his guidance, Forward Security is setting new standards in application and cloud security. Learn more at https://www.eurekadevsecops.com/ and https://forwardsecurity.com/Register for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.ioFollow LimaCharlieSign up for free: https://limacharlie.ioLinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie
This week Brandon Min, Founder and CEO of Herd Security, joins Defender Fridays to discuss how human risk management needs to rebrand with empathy.Brandon is the co-founder and CEO of Herd Security, where they help security teams drive employee engagement in security, making a more resilient organization. Humans have been the #1 target of organizational cyber attacks; however, security teams, organizations, vendors, and leaders have vilified them. At Herd, they believe security should be led with empathy and care. Building trust amongst users that will drive their engagement in security. Building herd immunity from cyber attacks. Learn more at https://herdsecurity.io/Register for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.ioFollow LimaCharlieSign up for free: https://limacharlie.ioLinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie
Send us a textThe weakest link is often sitting on the edge, blinking away with expired firmware and no vendor support. We kick off with a blunt reality check on outdated firewalls, load balancers, and IoT gateways, and why waiting two years to retire them is a gift to attackers. From there, we guide you through Domain 7.7 with a practical blueprint for operating and maintaining detective and preventive measures that actually hold up under pressure.We unpack firewall fundamentals with clear, real‑world tradeoffs: when a simple packet filter is enough, when stateful inspection and deep packet inspection earn their keep, and how a WAF stops the web attacks your L3/L4 controls will miss. You'll hear how RTBH can deflect denial‑of‑service floods upstream, and why segmentation is your best friend for reducing blast radius—whether you use internal segmentation firewalls for R&D, Purdue‑style tiers for industrial networks, or controlled air gaps for the most sensitive systems. In the cloud, we separate security groups from true firewalls and show how to stitch policies across hybrid environments without creating blind spots.Detection makes prevention smarter, so we break down IDS versus IPS in plain language. Baseline first, then block with intent to avoid outages. We compare host‑based and network‑based sensors, explain where to place them, and share tactics for cutting alert noise. You'll also get straight talk on allowlists and blacklists, the right way to maintain them, and why stale entries cause the ugliest outages. We explore sandboxing for safe detonation and learning, and give an unvarnished take on honeypots and honeynets—where they help, where they waste time, and what legal lines to respect.Not every team can build a 24x7 SOC, so we outline how MSSPs can extend your coverage with clear SLAs and ownership. Endpoint anti‑malware remains non‑negotiable, but tool sprawl is a trap—choose a strong EDR and manage it well. Finally, we dive into AI and machine learning: how they supercharge detection, triage, and response—and how adversaries use them too. The throughline is simple: shrink attack surface, raise signal quality, and respond faster than threats can pivot. If this helps you secure one more edge box or tune one more control, share it with a teammate, subscribe for more practical walkthroughs, and drop a review so we can keep raising the bar together.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Most orgs have a major blind spot: the browser.This week on Defender Fridays, we're joined by Cody Pierce, Co-Founder and CEO at Neon Cyber, to discuss why browser security remains a critical gap, from sophisticated phishing campaigns that bypass traditional controls to shadow AI tools operating outside your security perimeter.Cody began his career in the computer security industry twenty-five years ago. The first half of his journey was rooted in deep R&D for offensive security, and he had the privilege of leading great teams working on elite problems. Over the last decade, Cody have moved into product and leadership roles that allowed him to focus on developing and delivering innovative and differentiated capabilities through product incubation, development, and GTM activities. Cody says he gets the most joy from building and delivering products that bring order to the chaos of cyber security while giving defenders the upper hand.About This SessionThis office hours format brings together the LimaCharlie team to share practical experiences with AI-powered security operations. Rather than theoretical discussions, we demonstrate working tools and invite the community to share their own AI security experiments. The session highlights the rapid evolution of AI capabilities in cybersecurity and explores the changing relationship between security practitioners and automation.Register for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.ioFollow LimaCharlieSign up for free: https://limacharlie.ioLinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie
Join us for a special Defender Fridays Office Hours session where the LimaCharlie team demonstrates the new Agentic SecOps Workspace (ASW) and explores what's possible when AI agents operate security infrastructure directly.At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.What We'll DiscussIn this hands-on session, we showcase real working implementations of AI in cybersecurity operations. From reverse engineering malware to automated rule tuning and infrastructure management, we demonstrate how AI agents are transforming security workflows from concept to production-ready tools in hours instead of days.Key TopicsAutomated malware analysis and decompilation without traditional manual reverse engineering workflowsRule tuning at scale: Investigating noisy detections, writing false positive rules, and deploying them autonomouslyInfrastructure automation: Setting up data sources, configuring tenants, and managing security operations through AI agentsThe permission model: Balancing AI capability with human oversight and approval workflowsReal-world applications: Custom reporting, detection coverage analysis, and operational time savingsAbout This SessionThis office hours format brings together the LimaCharlie team to share practical experiences with AI-powered security operations. Rather than theoretical discussions, we demonstrate working tools and invite the community to share their own AI security experiments. The session highlights the rapid evolution of AI capabilities in cybersecurity and explores the changing relationship between security practitioners and automation.Register for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.Why LimaCharlie?Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.Try the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.ioFollow LimaCharlieSign up for free: https://limacharlie.ioLinkedIn: / limacharlieio X: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie
Multi‑stage AiTM phishing and BEC campaign abusing SharePoint SmarterMail auth bypass flaw now exploited despite patch The problem of AI agents emerges at Davos Huge thanks to our sponsor, Dropzone AI All week we've talked about alert fatigue, MTTR, and the math that's breaking your SOC. Here's the proof. Dropzone AI is trusted by over 300 global enterprises and MSSPs. Named a Gartner Cool Vendor. Recognized in the Fortune Cyber 60. And backed by $37 million in Series B funding. But they're not stopping at a single agent. They're building toward fully agentic SOC teams where human engineers are augmented with specialized AI agents for threat hunting, detection engineering, and forensics. Your team deserves a backup that never sleeps. Book a demo at dropzone.ai. Find the stories behind the headlines at CISOseries.com.
First Topic - Podcast Content Plans for 2026 Every year, I like to sit down and consider what the podcast should be focusing on. Not doing so ensures every single episode will be about AI and nobody wants that. Least of all, me. If I have one more all-AI episode, my head is going to explode. With that said, most of what we talk about in this segment is AI (picard face palm.png). I think 2026 will be THE defining year for GenAI. Three years after the release of ChatGPT, I think we've hit peak GenAI hype and folks are ready for it to put up or shut up. We'll see winners grow and get acquired and losers pivot to something else. More than anything, I want to interview folks who have actually seen it work at scale, rather than just in a cool demo in a vendor sandbox. Also on the agenda for this year: The battle against infostealers and session hijacking: we didn't have a good answer in 2025. When is it coming? Will it include Macs, despite them not having a traditional TPM? The state of trust in outsourcing and third party use (Cloud, MSSPs, SaaS, contractors): 2025 was not a good year for third parties. Lots of them got breached and caused their customers a lot of pain. Also, there's the state of balkanization between the US and... the rest of the entire world. Everyone outside the US seems to be trying to derisk their companies and systems from the Cloud Act right now. Vulnerability management market disruption: there are half a dozen startups already plotting to disrupt the market, likely to come out of stealth in 2026 Future of the SOC: if it's not AI, what is it? What else??? What am I missing? What would you like to see us discuss? Please drop me a line and let me know: adrian.sanabria@cyberriskalliance.com Topic 2: The state of cybersecurity hiring This topic has been in the works for a while! Ayman had a whole podcast and book focused on all the paths people take to get into security. Jackie worked with WiSys on outlining pathways into a cybersecurity career. Whether you're already in cyber or looking for a way in, this segment crams a lot of great advice into just 15-20 minutes. Segment resources: Ayman's personal guide for getting into security https://www.wicys.org/wp-content/uploads/2025/10/WiCyS-Pathways-in-Cyber-PDF-9.24.25.pdf News Finally, in the enterprise security news, Fundings and acquisitions still strong in 2026! Santa might be done delivering gifts, but not protecting Macs! ClickFix attacks Weaponized Raspberry Pis MongoDB incidents for Christmas Top 10 Cyber attacks of 2025 US gets tough on nation state hackers? Brute force attacks on Banks An AI Vending Machine All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-441
First Topic - Podcast Content Plans for 2026 Every year, I like to sit down and consider what the podcast should be focusing on. Not doing so ensures every single episode will be about AI and nobody wants that. Least of all, me. If I have one more all-AI episode, my head is going to explode. With that said, most of what we talk about in this segment is AI (picard face palm.png). I think 2026 will be THE defining year for GenAI. Three years after the release of ChatGPT, I think we've hit peak GenAI hype and folks are ready for it to put up or shut up. We'll see winners grow and get acquired and losers pivot to something else. More than anything, I want to interview folks who have actually seen it work at scale, rather than just in a cool demo in a vendor sandbox. Also on the agenda for this year: The battle against infostealers and session hijacking: we didn't have a good answer in 2025. When is it coming? Will it include Macs, despite them not having a traditional TPM? The state of trust in outsourcing and third party use (Cloud, MSSPs, SaaS, contractors): 2025 was not a good year for third parties. Lots of them got breached and caused their customers a lot of pain. Also, there's the state of balkanization between the US and... the rest of the entire world. Everyone outside the US seems to be trying to derisk their companies and systems from the Cloud Act right now. Vulnerability management market disruption: there are half a dozen startups already plotting to disrupt the market, likely to come out of stealth in 2026 Future of the SOC: if it's not AI, what is it? What else??? What am I missing? What would you like to see us discuss? Please drop me a line and let me know: adrian.sanabria@cyberriskalliance.com Topic 2: The state of cybersecurity hiring This topic has been in the works for a while! Ayman had a whole podcast and book focused on all the paths people take to get into security. Jackie worked with WiSys on outlining pathways into a cybersecurity career. Whether you're already in cyber or looking for a way in, this segment crams a lot of great advice into just 15-20 minutes. Segment resources: Ayman's personal guide for getting into security https://www.wicys.org/wp-content/uploads/2025/10/WiCyS-Pathways-in-Cyber-PDF-9.24.25.pdf News Finally, in the enterprise security news, Fundings and acquisitions still strong in 2026! Santa might be done delivering gifts, but not protecting Macs! ClickFix attacks Weaponized Raspberry Pis MongoDB incidents for Christmas Top 10 Cyber attacks of 2025 US gets tough on nation state hackers? Brute force attacks on Banks An AI Vending Machine All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-441
First Topic - Podcast Content Plans for 2026 Every year, I like to sit down and consider what the podcast should be focusing on. Not doing so ensures every single episode will be about AI and nobody wants that. Least of all, me. If I have one more all-AI episode, my head is going to explode. With that said, most of what we talk about in this segment is AI (picard face palm.png). I think 2026 will be THE defining year for GenAI. Three years after the release of ChatGPT, I think we've hit peak GenAI hype and folks are ready for it to put up or shut up. We'll see winners grow and get acquired and losers pivot to something else. More than anything, I want to interview folks who have actually seen it work at scale, rather than just in a cool demo in a vendor sandbox. Also on the agenda for this year: The battle against infostealers and session hijacking: we didn't have a good answer in 2025. When is it coming? Will it include Macs, despite them not having a traditional TPM? The state of trust in outsourcing and third party use (Cloud, MSSPs, SaaS, contractors): 2025 was not a good year for third parties. Lots of them got breached and caused their customers a lot of pain. Also, there's the state of balkanization between the US and... the rest of the entire world. Everyone outside the US seems to be trying to derisk their companies and systems from the Cloud Act right now. Vulnerability management market disruption: there are half a dozen startups already plotting to disrupt the market, likely to come out of stealth in 2026 Future of the SOC: if it's not AI, what is it? What else??? What am I missing? What would you like to see us discuss? Please drop me a line and let me know: adrian.sanabria@cyberriskalliance.com Topic 2: The state of cybersecurity hiring This topic has been in the works for a while! Ayman had a whole podcast and book focused on all the paths people take to get into security. Jackie worked with WiSys on outlining pathways into a cybersecurity career. Whether you're already in cyber or looking for a way in, this segment crams a lot of great advice into just 15-20 minutes. Segment resources: Ayman's personal guide for getting into security https://www.wicys.org/wp-content/uploads/2025/10/WiCyS-Pathways-in-Cyber-PDF-9.24.25.pdf News Finally, in the enterprise security news, Fundings and acquisitions still strong in 2026! Santa might be done delivering gifts, but not protecting Macs! ClickFix attacks Weaponized Raspberry Pis MongoDB incidents for Christmas Top 10 Cyber attacks of 2025 US gets tough on nation state hackers? Brute force attacks on Banks An AI Vending Machine All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-441
First Topic - Podcast Content Plans for 2026 Every year, I like to sit down and consider what the podcast should be focusing on. Not doing so ensures every single episode will be about AI and nobody wants that. Least of all, me. If I have one more all-AI episode, my head is going to explode. With that said, most of what we talk about in this segment is AI (picard face palm.png). I think 2026 will be THE defining year for GenAI. Three years after the release of ChatGPT, I think we've hit peak GenAI hype and folks are ready for it to put up or shut up. We'll see winners grow and get acquired and losers pivot to something else. More than anything, I want to interview folks who have actually seen it work at scale, rather than just in a cool demo in a vendor sandbox. Also on the agenda for this year: The battle against infostealers and session hijacking: we didn't have a good answer in 2025. When is it coming? Will it include Macs, despite them not having a traditional TPM? The state of trust in outsourcing and third party use (Cloud, MSSPs, SaaS, contractors): 2025 was not a good year for third parties. Lots of them got breached and caused their customers a lot of pain. Also, there's the state of balkanization between the US and... the rest of the entire world. Everyone outside the US seems to be trying to derisk their companies and systems from the Cloud Act right now. Vulnerability management market disruption: there are half a dozen startups already plotting to disrupt the market, likely to come out of stealth in 2026 Future of the SOC: if it's not AI, what is it? What else??? What am I missing? What would you like to see us discuss? Please drop me a line and let me know: adrian.sanabria@cyberriskalliance.com Topic 2: The state of cybersecurity hiring This topic has been in the works for a while! Ayman had a whole podcast and book focused on all the paths people take to get into security. Jackie worked with WiSys on outlining pathways into a cybersecurity career. Whether you're already in cyber or looking for a way in, this segment crams a lot of great advice into just 15-20 minutes. Segment resources: Ayman's personal guide for getting into security https://www.wicys.org/wp-content/uploads/2025/10/WiCyS-Pathways-in-Cyber-PDF-9.24.25.pdf News Finally, in the enterprise security news, Fundings and acquisitions still strong in 2026! Santa might be done delivering gifts, but not protecting Macs! ClickFix attacks Weaponized Raspberry Pis MongoDB incidents for Christmas Top 10 Cyber attacks of 2025 US gets tough on nation state hackers? Brute force attacks on Banks An AI Vending Machine All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-441
The threat that puts you out of business probably won't look like a movie hack, it'll look like a normal email from your CEO. In this episode of the Registered Investment Advisor Podcast, Seth Greene interviews Scott Alldridge, CEO of IP Services and bestselling author of the VisibleOps series, who explains how modern cybercrime actually works and why most small and mid-sized companies are far more vulnerable than they think. Scott shares real breach stories, including how something as simple as leaving a printer password as “1234” led to a $187,000 theft and forced a firm into a merger. He breaks down why cybersecurity is now a board-level issue, how AI is being weaponized by attackers, and what leaders need to be doing right now to protect their data, their money, and their survival. Key Takeaways: → Most companies think “we're too small to be a target,” but attackers actively go after businesses with as few as 100 employees — and even under $1M in revenue. → Only about 1 in 7 cybersecurity breaches ever gets reported, so what you read in the news is a tiny fraction of what's actually happening. → A single weak password (like “1234” on a networked printer) can give a threat actor a doorway into your entire system. → Attackers don't smash and grab; they sit quietly for weeks or months, watch how you communicate, then imitate leadership to trigger wire transfers that look totally normal. → The “human layer” is still the biggest risk: phishing, social engineering, and reused or weak credentials are where most compromises begin. Scott Alldridge has spent three decades on the frontlines of cyber warfare—turning escalating threats into competitive advantage for business leaders. As co-founder of the IT Process Institute and creator of the globally adopted VisibleOps framework (400,000+ copies sold), he shaped how enterprises worldwide secure and scale technology. His Amazon bestseller, VisibleOps Cybersecurity, is the definitive roadmap for integrating Zero Trust principles into real business results. Today, as CEO of IP Services, one of America's most trusted MSSPs, Scott helps executives verify—not just trust—their cybersecurity posture. Driven by both expertise and altruism, Scott's mission is to ensure businesses of all sizes are resilient and protected—not only to safeguard revenue, but to prevent the devastating personal and professional fallout of cyberattacks. A globally recognized thought leader with 618K+ social media followers, he leverages his platform to raise awareness, share real-world breach stories, and arm leaders with actionable strategies that save companies before it's too late. Connect With Scott: Website: https://ipservices.com/ Instagram: https://www.instagram.com/scottalldridge1/ LinkedIn: https://www.linkedin.com/in/scott-alldridge-1a976/ FREE OFFERSText "Secure25" to 1-541-359-1269 to receive your free Visible Ops Executive Companion book and a free Penetration Scan Test (first 3 listeners only) Learn more about your ad choices. Visit megaphone.fm/adchoices
The threat that puts you out of business probably won't look like a movie hack, it'll look like a normal email from your CEO. In this episode of the Registered Investment Advisor Podcast, Seth Greene interviews Scott Alldridge, CEO of IP Services and bestselling author of the VisibleOps series, who explains how modern cybercrime actually works and why most small and mid-sized companies are far more vulnerable than they think. Scott shares real breach stories, including how something as simple as leaving a printer password as “1234” led to a $187,000 theft and forced a firm into a merger. He breaks down why cybersecurity is now a board-level issue, how AI is being weaponized by attackers, and what leaders need to be doing right now to protect their data, their money, and their survival. Key Takeaways: → Most companies think “we're too small to be a target,” but attackers actively go after businesses with as few as 100 employees — and even under $1M in revenue. → Only about 1 in 7 cybersecurity breaches ever gets reported, so what you read in the news is a tiny fraction of what's actually happening. → A single weak password (like “1234” on a networked printer) can give a threat actor a doorway into your entire system. → Attackers don't smash and grab; they sit quietly for weeks or months, watch how you communicate, then imitate leadership to trigger wire transfers that look totally normal. → The “human layer” is still the biggest risk: phishing, social engineering, and reused or weak credentials are where most compromises begin. Scott Alldridge has spent three decades on the frontlines of cyber warfare—turning escalating threats into competitive advantage for business leaders. As co-founder of the IT Process Institute and creator of the globally adopted VisibleOps framework (400,000+ copies sold), he shaped how enterprises worldwide secure and scale technology. His Amazon bestseller, VisibleOps Cybersecurity, is the definitive roadmap for integrating Zero Trust principles into real business results. Today, as CEO of IP Services, one of America's most trusted MSSPs, Scott helps executives verify—not just trust—their cybersecurity posture. Driven by both expertise and altruism, Scott's mission is to ensure businesses of all sizes are resilient and protected—not only to safeguard revenue, but to prevent the devastating personal and professional fallout of cyberattacks. A globally recognized thought leader with 618K+ social media followers, he leverages his platform to raise awareness, share real-world breach stories, and arm leaders with actionable strategies that save companies before it's too late. Connect With Scott: Website: https://ipservices.com/ Instagram: https://www.instagram.com/scottalldridge1/ LinkedIn: https://www.linkedin.com/in/scott-alldridge-1a976/ FREE OFFERSText "Secure25" to 1-541-359-1269 to receive your free Visible Ops Executive Companion book and a free Penetration Scan Test (first 3 listeners only) Learn more about your ad choices. Visit megaphone.fm/adchoices
Discover how industry veteran Larry Meador, Cavelo's new Channel Chief, is transforming the MSP channel. Cavelo empowers Managed Service Providers with a unified Attack Surface Management and Data Security Posture Management platform—offering automated data discovery, classification, vulnerability management, and compliance-ready solutions. Built for MSPs and MSSPs, Cavelo helps partners reduce cyber risk, streamline operations, and deliver scalable, data-first security services that boost profitability and client trust. Full Video Podcast Link: https://youtu.be/D6xFmrlUXDY --------------------------------------------------- Connect with us! --------------------------------------------------- MSP Unplugged https://mspunplugged.com/ Paco Lebron from ProdigyTeks:Powered by MSP Owners Group Email: paco@mspunplugged.com Rick Smith from Renactus Technology Email: rick@mspnplugged.com Justin Gilliam from Bacheler Technologies https://www.linkedin.com/in/justin-gilliam-96288a56
Building a cyber security team isn't optional anymore; it's the difference between recovering from ransomware and going out of business. In this episode, Curtis and Prasanna explain why hardening your backup infrastructure is only half the battle. You need professionals who know how to configure XDR systems without drowning you in false positives, blue teams to defend your environment, and red teams to test whether your defenses actually work. They cover the role of MSSPs, incident response planning, cyber insurance requirements, and why attempting ransomware response on your own is like those old TV warnings: "Don't try this at home." If you've been following their series on backup basics and system hardening, this episode ties it all together with the human element that makes or breaks your recovery plan.
All links and images can be found on CISO Series. Check out this post by Christofer Hoff of Truist for the discussion that is the basis of our conversation on this week's episode co-hosted by David Spark, the producer of CISO Series, and Caleb Sima, builder, WhiteRabbit. Joining them is Crystal Chatam, vp of cybersecurity, Speedcast. In this episode: Understanding the fundamentals The grift of superficial expertise Hands-on experience matters A vulnerability at the leadership level Huge thanks to our sponsor, Stellar Cyber By shining a bright light on the darkest corners of security operations, Stellar Cyber empowers organizations to see incoming attacks, know how to fight them, and act decisively – protecting what matters most. Stellar Cyber's award-winning open security operations platform includes AI-driven SIEM, NDR, ITDR, Open XDR, and Multi-Layer AI™ under one unified platform with a single license. With ⅓ of the global top 250 MSSPs and over 14,000 customers worldwide, Stellar Cyber is one of the most trusted leaders in security operations. Learn more at https://stellarcyber.ai/.
Jim McDonald and Jeff Steadman sit down with Mike Reiring of RSM at InfoSec World 2025 to explore how managed service providers are reshaping IT and identity operations. They dig into the differences between MSPs and MSSPs, how to choose the right partner, and how AI is transforming help desks, problem management, and security monitoring. The conversation closes with a fun dive into Mike's passion for photography and how creativity ties into continuous learning in tech.Connect with Mike: https://www.linkedin.com/in/mreiring/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.comChapters00:00 Intro – Live from InfoSec World 202502:00 Meet Mike Reiring of RSM04:30 Evolution of Managed Service Providers06:30 Shared Accounts, Identity, and Security Maturity09:00 Vendor Gaps and Federated Access Challenges11:30 What Makes a Good MSP Partner13:00 The Cost and Effort of Changing Providers16:30 MSP vs MSSP – Key Differences18:30 Coordination Between Managed Providers21:30 Top 3 Questions to Ask Your MSP25:00 Identity Ownership: IT or Security?27:30 Licensing, Active Directory, and Hidden Accounts30:00 RFP Challenges and Procurement Pitfalls32:00 Measuring Risk and Reducing Identity Exposure34:30 Vendor Management and Shadow IT Risks35:00 How AI Is Transforming MSP and MSSP Operations38:30 AI, Problem Management, and the Future of Help Desks42:30 Photography, Creativity, and Continuous Learning48:00 Closing Thoughts and IDAC OutroKeywordsIDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Mike Reiring, RSM, InfoSec World 2025, Managed Service Provider, MSP, MSSP, AI in Cybersecurity, Help Desk, Identity Management, Managed Identity, Partner Transparency, IT Outsourcing, Risk Reduction, Problem Management, Active Directory, DaVinci Resolve, Photography in Tech, Identity Governance, Cybersecurity Podcast
We weigh the promise and peril of the AI agent economy, pressing into how overprovisioned non-human identities, shadow AI, and SaaS integrations expand risk while go-to-market teams push for speed. A CMO and a CFO align on governance-first pilots, PLG trials, buyer groups, and the adoption metrics that sustain value beyond the sale.• AI adoption surge matched by adversary AI• Overprovisioned agents and shadow AI in SaaS• Governance thresholds before budget scale• PLG trials, sandbox, and POV sequencing• Visualization to reach the aha moment• Buying groups, ICP, and economic buyer alignment• Post‑sales usage, QBRs, NRR and churn signals• Zero trust limits and non-human identities• Breach disclosures as industry standards• Co-sourcing MSSP with in-house oversightSecurity isn't slowing AI down; it's the unlock that makes enterprise AI valuable. We dive into the AI agent economy with a CMO and a CFO who meet in the messy middle. The result is a practical blueprint for moving from hype to governed production without killing momentum.We start by mapping where controls fail: once users pass SSO and MFA, agents often operate beyond traditional identity and network guardrails. That's how prompts pull sensitive deal data across Salesforce and Gmail, and how third‑party API links expand the attack surface. From there, we lay out an adoption sequence that balances trust and speed. Think frictionless free trials and sandboxes that reach an immediate “aha” visualization of shadow AI and permissions, then progress to a scoped POV inside the customer's environment with clear policies and measurable outcomes. Along the way, we detail the buying group: economic buyers who sign and practitioners who live in the UI, plus the finance lens that sets pilot capital, milestones, and time-to-value expectations.We also challenge sacred cows. Zero trust is essential, but attackers increasingly log in with valid credentials and pivot through integrations, so verification must include non-human identities and agent-to-agent controls. Breach disclosures, far from being a greater threat than breaches, are foundational to ecosystem trust and faster remediation. And while MSSPs add critical scale, co-sourcing—retaining strategic oversight and compliance ownership—keeps accountability inside. If you care about ICP, PLG motions, PQLs, NRR, or simply reducing AI risk while driving growth, this conversation turns buzzwords into a playbook you can run.Vamshi Sriperumbudur: https://www.linkedin.com/in/vamsriVamshi Sriperumbudur was recently the CMO for Prisma SASE at Palo Alto Networks, where he led a complete marketing transformation, driving an impact of $1.3 billion in ARR in 2025 (up 35%) and establishing it as the platform leader. Chithra Rajagopalan - https://www.linkedin.com/in/chithra-rajagopalan-mba/Chithra Rajagopalan is the Head of Finance at Obsidian Security and former Head of Finance at Glue, and she is recognized as a leader in scaling businesses. Chithra is also an Investor and Advisory Board member for Campfire, serving as the President and Treasurer of Blossom Projects.Website: https://www.position2.com/podcast/Rajiv Parikh: https://www.linkedin.com/in/rajivparikh/Sandeep Parikh: https://www.instagram.com/sandeepparikh/Email us with any feedback for the show: sparkofages.podcast@position2.com
The threat that puts you out of business probably won't look like a movie hack, it'll look like a normal email from your CEO. In this episode of Sharkpreneur, Seth Greene interviews Scott Alldridge, CEO of IP Services and bestselling author of the Visible Ops series, who explains how modern cybercrime actually works and why most small and mid-sized companies are far more vulnerable than they think. Scott shares real breach stories, including how something as simple as leaving a printer password as “1234” led to a $187,000 theft and forced a firm into a merger. He breaks down why cybersecurity is now a board-level issue, how AI is being weaponized by attackers, and what leaders need to be doing right now to protect their data, their money, and their survival. Key Takeaways: → Most companies think “we're too small to be a target,” but attackers actively go after businesses with as few as 100 employees — and even under $1M in revenue. → Only about 1 in 7 cybersecurity breaches ever gets reported, so what you read in the news is a tiny fraction of what's actually happening. → A single weak password (like “1234” on a networked printer) can give a threat actor a doorway into your entire system. → Attackers don't smash and grab; they sit quietly for weeks or months, watch how you communicate, then imitate leadership to trigger wire transfers that look totally normal. → The “human layer” is still the biggest risk: phishing, social engineering, and reused or weak credentials are where most compromises begin. Scott Alldridge has spent three decades on the frontlines of cyber warfare—turning escalating threats intocompetitive advantage for business leaders. As co-founder of the IT Process Institute and creator of the globally adopted VisibleOps framework (400,000+ copies sold), he shaped how enterprises worldwide secure and scale technology. His Amazon bestseller, VisibleOps Cybersecurity, is the definitive roadmap for integrating Zero Trust principles into real business results. Today, as CEO of IP Services, one of America's most trusted MSSPs, Scott helps executives verify—not just trust—their cybersecurity posture. Driven by both expertise and altruism, Scott's mission is to ensure businesses of all sizes are resilient and protected—not only to safeguard revenue, but to prevent the devastating personal and professional fallout of cyberattacks. A globally recognized thought leader with 618K+ social media followers, he leverages his platform to raise awareness, share real-world breach stories, and arm leaders with actionable strategies that save companies before it's too late. Connect With Scott Aldridge: Website: https://ipservices.com/ Instagram: https://www.instagram.com/scottalldridge1/?hl=en LinkedIn: https://www.linkedin.com/in/scott-alldridge-1a976/ Learn more about your ad choices. Visit megaphone.fm/adchoices
The threat that puts you out of business probably won't look like a movie hack, it'll look like a normal email from your CEO. In this episode of Sharkpreneur, Seth Greene interviews Scott Alldridge, CEO of IP Services and bestselling author of the Visible Ops series, who explains how modern cybercrime actually works and why most small and mid-sized companies are far more vulnerable than they think. Scott shares real breach stories, including how something as simple as leaving a printer password as “1234” led to a $187,000 theft and forced a firm into a merger. He breaks down why cybersecurity is now a board-level issue, how AI is being weaponized by attackers, and what leaders need to be doing right now to protect their data, their money, and their survival. Key Takeaways: → Most companies think “we're too small to be a target,” but attackers actively go after businesses with as few as 100 employees — and even under $1M in revenue. → Only about 1 in 7 cybersecurity breaches ever gets reported, so what you read in the news is a tiny fraction of what's actually happening. → A single weak password (like “1234” on a networked printer) can give a threat actor a doorway into your entire system. → Attackers don't smash and grab; they sit quietly for weeks or months, watch how you communicate, then imitate leadership to trigger wire transfers that look totally normal. → The “human layer” is still the biggest risk: phishing, social engineering, and reused or weak credentials are where most compromises begin. Scott Alldridge has spent three decades on the frontlines of cyber warfare—turning escalating threats intocompetitive advantage for business leaders. As co-founder of the IT Process Institute and creator of the globally adopted VisibleOps framework (400,000+ copies sold), he shaped how enterprises worldwide secure and scale technology. His Amazon bestseller, VisibleOps Cybersecurity, is the definitive roadmap for integrating Zero Trust principles into real business results. Today, as CEO of IP Services, one of America's most trusted MSSPs, Scott helps executives verify—not just trust—their cybersecurity posture. Driven by both expertise and altruism, Scott's mission is to ensure businesses of all sizes are resilient and protected—not only to safeguard revenue, but to prevent the devastating personal and professional fallout of cyberattacks. A globally recognized thought leader with 618K+ social media followers, he leverages his platform to raise awareness, share real-world breach stories, and arm leaders with actionable strategies that save companies before it's too late. Connect With Scott Aldridge: Website: https://ipservices.com/ Instagram: https://www.instagram.com/scottalldridge1/?hl=en LinkedIn: https://www.linkedin.com/in/scott-alldridge-1a976/ Learn more about your ad choices. Visit megaphone.fm/adchoices
I used to think "Always Be Closing" was outdated, sleazy sales advice, but I've completely changed my mind. In this video, I break down why ABC is actually the foundation of consultative selling for MSSPs and B2B sales. The truth is, every single step in your sales process—from discovery calls to assessments to proposals—should be designed with one goal: moving the deal forward and closing the sale. I'll show you the simple framework I use to redesign sales processes, explain why most salespeople are treating discovery and assessments like information gathering instead of closing opportunities, and reveal the biggest mistake I see during proposals that kills deals. If you're in MSP sales or any B2B selling, this reframe will change how you approach every interaction with prospects.//Welcome to Repeatable Revenue, hosted by strategic growth advisor , Ray J. Green.About Ray:→ Former Managing Director of National Small & Midsize Business at the U.S. Chamber of Commerce, where he doubled revenue per sale in fundraising, led the first increase in SMB membership, co-built a national Mid-Market sales channel, and more.→ Former CEO operator for several investor groups where he led turnarounds of recently acquired small businesses.→ Current founder of MSP Sales Partners, where we currently help IT companies scale sales: www.MSPSalesPartners.com→ Current Sales & Sales Management Expert in Residence at the world's largest IT business mastermind.→ Current Managing Partner of Repeatable Revenue Ventures, where we scale B2B companies we have equity in: www.RayJGreen.com//Follow Ray on:YouTube | LinkedIn | Facebook | Twitter | Instagram
Send us a textIn this episode of Joey Pinz Discipline Conversations, Joey sits down with Scott Fuhriman, cybersecurity veteran and leader at Inveri, live from the MSP Summit in Orlando.Scott shares his 25+ years of cybersecurity experience, explaining how Inveri's runtime integrity technology, born from NSA research, helps MSPs and MSSPs detect hidden in-memory attacks, rootkits, and advanced threats that traditional tools miss. He highlights why protecting this overlooked layer is crucial to preserving revenue, preventing churn, and maintaining customer trust.The conversation also touches on Scott's personal discipline journey — from starting as a young PC tech overwhelmed by information to building a career through self-study, mentorship, and consistency. He and Joey discuss how MSPs can choose the right vendors, strengthen their security stacks, and enable long-term resilience in a competitive market.
Stellar Cyber Revolutionizes SOC Cybersecurity Operations with Human-Augmented Autonomous Platform at Black Hat 2025 A Stellar Cyber Event Coverage of Black Hat USA 2025 Las VegasAn ITSPmagazine Brand Story with Subo Guha, Senior Vice President Product, Stellar Cyber____________________________Security operations centers face an unprecedented challenge: thousands of daily alerts overwhelming analyst teams while sophisticated threats demand immediate response. At Black Hat USA 2025 in Las Vegas, Stellar Cyber presented a revolutionary approach that fundamentally reimagines how SOCs operate in the age of AI-driven threats.Speaking with ITSPmagazine's Sean Martin, Subo Guha, Senior Vice President of Products at Stellar Cyber, outlined the company's vision for transforming security operations through their human-augmented autonomous SOC platform. Unlike traditional approaches that simply pile on more automation, Stellar Cyber recognizes that effective security requires intelligent collaboration between AI and human expertise.The platform's three-layer architecture ingests data from any source – network devices, applications, identities, and endpoints – while maintaining vendor neutrality through open EDR integration. Organizations can seamlessly work with CrowdStrike, SentinelOne, Sophos, or other preferred solutions without vendor lock-in. This flexibility proves crucial for enterprises navigating complex security ecosystems where different departments may have invested in various endpoint protection solutions.What sets Stellar Cyber apart is their autonomous SOC concept, which dramatically reduces alert volume from hundreds of thousands to manageable numbers within days rather than weeks. The platform's AI-driven auto-triage capability identifies true positives among thousands of false alarms, presenting analysts with prioritized "verdicts" that demand attention. This transformation addresses one of security operations' most persistent challenges: alert fatigue that leads to missed threats and burned-out analysts.The revolutionary AI Investigator copilot enables natural language interaction, allowing analysts to query the system conversationally. An analyst can simply ask, "Show me all impossible travel incidents between midnight and 4 AM," and receive actionable intelligence immediately. This democratization of security operations means junior analysts can perform at senior levels without extensive coding knowledge or years of experience navigating complex query languages.Identity threat detection and response (ITDR) emerged as another critical focus area during the Black Hat presentation. With identity becoming the new perimeter, Stellar Cyber integrated sophisticated user and entity behavior analytics (UEBA) directly into the platform. The system detects impossible travel scenarios, credential attacks, and lateral movement patterns that indicate compromise. For instance, when a user logs in from Portland at 11 PM and then appears in Moscow 30 minutes later, the platform immediately flags this physical impossibility.The identity protection extends beyond human users to encompass non-human identities, addressing the growing threat of automated attacks powered by large language models. Hackers now leverage generative AI to create credential attacks at unprecedented scale and sophistication, making robust identity security more critical than ever.Guha emphasized that AI augmentation doesn't displace security professionals but elevates them. By automating mundane tasks, analysts focus on strategic decision-making and complex threat hunting. MSSPs report dramatic efficiency gains, scaling operations without proportionally increasing headcount. Where previously a hundred thousand alerts might take weeks to process, requiring extensive junior analyst teams, the platform now delivers actionable insights within days with smaller, more focused teams.The platform's unified approach eliminates tool sprawl, providing CISOs with real-time visualization of their security posture. Executive reporting becomes instantaneous, with high-priority verdicts clearly displayed for rapid decision-making. This visualization capability transforms how security teams communicate with leadership, replacing lengthy reports with dynamic dashboards that convey risk and response status at a glance.Real-world deployments demonstrate significant operational improvements. Organizations report faster mean time to detection and response, reduced false positive rates, and improved analyst satisfaction. The platform's learning capabilities mean it becomes more intelligent over time, adapting to each organization's unique threat landscape and operational patterns.As organizations face increasingly sophisticated threats powered by generative AI, Stellar Cyber's human-augmented approach represents a paradigm shift. By combining AI intelligence with human intuition, the platform delivers faster threat detection, reduced false positives, and empowered security teams ready for tomorrow's challenges. The company's commitment to continuous innovation, evidenced by rapid feature releases between RSA and Black Hat, positions them at the forefront of next-generation security operations. Learn more about Stellar Cyber: https://itspm.ag/stellar-cyber--inc--357947Note: This story contains promotional content. Learn more.Guest: Subo Guha, Senior Vice President Product, Stellar Cyber | https://www.linkedin.com/in/suboguha/ResourcesLearn more and catch more stories from Stellar Cyber: https://www.itspmagazine.com/directory/stellarcyberLearn more and catch more stories from our Black Hat USA 2025 coverage: https://www.itspmagazine.com/bhusa25Learn more about ITSPmagazine Brand Story Podcasts: https://www.itspmagazine.com/purchase-programsNewsletter Archive: https://www.linkedin.com/newsletters/tune-into-the-latest-podcasts-7109347022809309184/Business Newsletter Signup: https://www.itspmagazine.com/itspmagazine-business-updates-sign-upAre you interested in telling your story?https://www.itspmagazine.com/telling-your-story