Vendor channel consolidation continues to shape decision-making for MSPs, as the industry evaluates tradeoffs between integrated security stacks and maintaining best-of-breed toolsets. The episode’s discussion centers on the role of platform consolidation, referencing Guardz as an example of a provider leveraging third-party engines like SentinelOne for EDR and Check Point/Avanan for email, shifting focus from proprietary tool development to deep integration and operational unification. This shift reflects broader industry movement away from fragmented tooling toward unified security operations designed specifically for MSP and SMB environments.
The primary evidence highlighted is the operational friction and compromises created by legacy all-in-one approaches, which often involved aggregating standalone tools without meaningful integration, leading to inefficiencies and substandard outcomes. Doni Brass detailed Guardz’s initial strategy of building proprietary AV and EDR products, ultimately conceding the inability to match specialist vendors’ effectiveness. The current Guardz model combines licensing and unified management for technologies like SentinelOne, managed through a single point of support and tied together with an identity-centric architecture. The operational benefit, according to Doni Brass, is streamlined onboarding, reduced tool sprawl, and simpler day-to-day management.
Supporting developments reinforcing the structural channel consolidation theme include user poll data indicating a split among MSPs: some using under three security vendors, others supporting four to eight, and a minority historically managing as many as 15. The discussion also addresses the risks associated with consolidation—namely increased dependency on single-vendor platforms, reduced flexibility to swap components, and potential compliance shortcomings for high-regulation sectors such as CMMC-restricted defense contractors. Doni Brass acknowledged Gardz’s lack of CMMC certification and identified large, mature MSPs with internal SOCs as less likely to benefit from consolidated stacks unless targeting downmarket segments.
For operators, the main implications concern assessment of operational risk, contract liability, and long-term agility. Single-platform solutions can simplify onboarding and management but may introduce lock-in, especially if multi-year contracts are involved. Doni Brass recommended favoring short-term agreements and avoiding exposing specific vendor brands in client-facing deliverables to maintain stack flexibility. Growing reliance on unified platforms demands thorough trial evaluation and continued scrutiny of channel strategy and compliance postures, as vendor pivots and regulatory expectations can change with little notice. Careful governance remains necessary to mitigate both strategic and operational downside.
Sponsored by:
Guardz
Book a Demo:
guardz.com/book-a-demo-v5/?utm_source=Davesobel&utm_medium=Webinar&utm_campaign=Davesobel
💼 All Our Sponsors
MSP Radio is supported by our partners:
ABC Solutions · CometBackup · Guardz · HaloPSA · LogMeIn · Mailprotector · OpenText · Pax8 · Proofpoint · Rythmz · ScalePad · TimeZest · Transit AI · USecure
Supporting the IT services community through insights, analysis, and transparency.
🚀 Join Business of Tech Plus
Get exclusive access to investigative reports, vendor analysis, leadership briefings, and more.
👉 https://businessof.tech/plus
🎧 Subscribe to the Business of Tech
Want the show on your favorite podcast app or prefer the written versions of each story?
📲 https://www.businessof.tech/subscribe
📰 Story Links & Sources
Looking for the links from today’s stories?
Every episode script — with full source links — is posted at:
🎙 Want to Be a Guest?
Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:
💬 https://www.podmatch.com/hostdetailpreview/businessoftech
🔗 Follow Business of Tech
LinkedIn: https://www.linkedin.com/company/28908079
YouTube: https://youtube.com/mspradio
Bluesky: https://bsky.app/profile/businessof.tech
Instagram: https://www.instagram.com/mspradio
TikTok: https://www.tiktok.com/@businessoftech
Facebook: https://www.facebook.com/mspradionews
Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
[00:00:10] Consolidating your security stack is one of the most consequential calls you make as a managed service provider. And almost everything written about it is marketing. So we're going to do a little something unusual for a vendor-sponsored session. We're going to argue about it. I'm Dave Sobel, host of The Business of Tech. This webinar is sponsored by Guardz. They're paying for the session and they do not get to approve the questions.
[00:00:36] That's the deal. And I wanted you to hear it from me as we start rather than wonder about it. My guest today is Dave Cava. He's the SVP of product strategy and community at guards. Donnie, welcome to the show. Yeah, thanks for having me. Excited to dive into this conversation with you. Likewise. And we're going to make sure it's a conversation. So audience, drop your questions into the Q&A panel as we go.
[00:01:02] We'll get to as many as we can and we like the more pointed you can make them, the better. We're going to definitely have time for that. I'm going to be keeping an eye on the questions list, but we have dedicated time at the end of that. Now, I want to start by finding out where our audience is. I'm going to put up a poll here asking, I'd like to get a sense from the audience of how many security vendors are actually in your stack.
[00:01:27] So go ahead and vote. You can scan the QR code and put in your answer to how many security vendors are in the stack. But Donnie, let's let's dive right in here, right? Because all in one is almost close to a slur in this industry. Like an MSP hears it and what they picture is five things that check five boxes and none of them are the thing they would have bought on purpose. Right. And that reputation comes from kind of the history. Somebody sold that product and somebody deployed it.
[00:01:54] But I don't think the one vendor versus many is the real divide. I think the real divide is between consolidation that replaces the tools you already trust with weaker substitutes and consolidation that keeps the good engines underneath and unifies everything above them. They're different products. So let's start with the earned part. Like, what do you think happened in this industry? Like they got wrong about all in one. And what does that bad version end up looking like?
[00:02:24] Yeah, it's a great question. I think, you know, the most successful all in ones or platform approaches have come on the enterprise level. Right. And I think what first went wrong was some assumptions that enterprise tools would be a fit in the MSP world. I think most MSPs just struggle with that. Certainly there are some mature MSPs out there with the infrastructure and the teams and the operations to handle it. But I think most mostly on the MSP level, those enterprise tools are just not a fit.
[00:02:52] So that's the first thing I think that that went wrong on that front. Going a little bit deeper, I think a lot of the consolidation came from, you know, buying up different products and trying to bring them together. That bringing together promise was never fulfilled. So you've got a bunch of different products that might have been good on their own front. Some might have had compromises, but or been compromises, not had compromises.
[00:03:15] But at the end of the day, if you're not unifying the experience around it and really connecting the dots, then you're not bringing the value of that consolidation. So how do I test that a little bit? Like if you're an operator thinking about that, how do you test like the difference of somebody that's built it to be integrated or focused that way versus the idea where it's kind of check boxes? Like how do you look at a platform and tell that it preserves that best of breed from one that's just doing the substitutions like the enterprise level version?
[00:03:45] I mean, I think you've got to live in it, right? You've got to you've got to dive in. I mean, trial experiences, POCs, that's the only way to truly understand a product starting with yourself, maybe a couple of your smaller clients to get a feel and build that trust. But, you know, I always recommend that. I think there's again, there's many approaches to the all in one consolidation. There's the approaches of, you know, build it all from scratch.
[00:04:10] The approaches of, you know, just be the consolidator and bring in third party technologies. And then there's blends of that in between. And I think each of those have benefits and trade offs. And I think what, you know, where guards landed and what we built, and I'm happy to share more about that journey and that story. But what we built and where we landed, I believe found that sweet spot. And we've proven it in the success we've had and our growing customer base on that front.
[00:04:36] Well, we'll say a little bit more. I mean, you're the person thinking about product strategy. Talk to me a little bit about the way you framed that problem. You know, the way you looked at the different approaches and how you landed the way you've chosen. Yeah, maybe the better best way to frame it is what went wrong and honest conversation about it. So I think when we started, we really were of the belief, right? We were born in the age of AI, really of the belief that we can build anything ourselves and catch up and pass even the
[00:05:06] you know, the best companies out there. So, you know, our platform approach was from day one, like the goal of guards was always to, you know, to focus on the core security controls that every MSP needs, you know, email, endpoint, cloud data, you know, awareness training, like, you know, really to focus on it all. And we learned some hard lessons that you can't build it all that good enough is not good enough.
[00:05:33] That there's an expectation of great, you know, when it comes to security that there isn't a willingness to compromise on that front. So when we first built, we built our own email, we built our own endpoint protection and we had visions of that endpoint protection becoming an EDR started off as you know, managed managed antivirus.
[00:05:51] And we started, you know, invested a lot in trying to expand that. What we found is specifically with email and endpoint, that the commoditization of those technologies of those security controls, really shaped the way the industry was looking at it. And it just didn't make sense for us to try to compete in those areas, right? Like as fast as we could build and evolve and do cool things. We saw that the big companies out there who were doing it right.
[00:06:16] You know, we weren't going to be able to catch them. And what we decided was, let's find those best of breeds partnerships and bring them to the MSP community in a way that allows them to more effectively execute on that security. Because for example, Sentinel one was our choice for EDR partnership. Like Sentinel one is, you know, by far and away to me, you know, one of the best EDRs on the market for many, many reasons.
[00:06:43] But a lot of MSP struggle with it because it's not always built for them, right? So the provisioning, the deployment, the onboarding, like all of that is able to be streamlined. So the value that guards could bring on top of that came in that form. How can we help them better get onboarded, get provisioned, get it set up, and then manage it for them in a way that helps them execute on their security strategy?
[00:07:07] So that's the approach we took as a value add for SentinelOne. And we did something very similar for Checkpoint Avanan on the email front. Gotcha. Now you're, if your answer is the partnerships or the layers, we need to make that concrete, right? So when Sentinel one is the engine underneath your platform, who owns that relationship? Who does the MSP call? Who owns the roadmap? What happens, you know, if there's the issues within the partnership? How do you guys manage that?
[00:07:31] Yeah. Yeah, we toured around with different models for the integrate, like to integrate and we decided that integration was not what the market wanted. Right. There are some situations where it makes sense to bring your own and we accommodate that. But really, you know, with these partnerships, we took the view that we have to make sure we're bringing value on top of it. It's not a license resell and it's not an integration. It's more than that. So we deeply embedded these technologies into guards.
[00:07:58] So when you're buying a Guardz license, you're also getting an S1 license and, you know, a Checkpoint license for Avanon. So first off, first and foremost, the licensing and that relationship is owned on the guard side. So you need support, you need help, you need whatever it's coming from us. And then from there, again, the value add we're bringing there and our core guards technology is really what makes the difference.
[00:08:23] So, you know, everything from our, you know, the way we're unifying the stack, we own an identity layer. So that's ITDR along with things like security awareness training and phishing simulations. We have a dark web scan, seeing if there are lead credentials, you know, exposure, external exposure. So looking at, you know, what's, you know, what is exposed to the web, any kind of known CVEs or other vulnerabilities. You know, is your mail server configured correctly?
[00:08:50] Like we're looking at all of that about the organization, but tying everything else back to the individual users. And that's a lot of the IP of guards is putting the identity at the center and tying all the detections and response capabilities back to that identity. So whether it's happening on the endpoint, in the email, with the data, in the cloud behavior, whatever it is, we're tying it all back to that identity.
[00:09:12] And we know so much about the posture of that identity that we're able to act fast and build that benchmark that helps us really understand when there's an anomaly or a real threat underway. Gotcha. Okay. That makes a little bit of sense. So I want to, I want to fall back. Let's get a sense from the audience about where they stand up. We've got an even 50 50 split here on how many are in the stack. Some less than three others in that four to eight range. Diane, that's really good. By the way, he's always going to ask, like, talk to me a little bit.
[00:09:42] You obviously talked to a number of MSPs. Give me a sense of, like, how these numbers and this audience falls in with some of the, what you've been seeing in the larger industry. Yeah. I mean, I think the vendor sprawl, tool sprawl problem is still one of the leading issues in the industry. I've seen customers, you know, towards that, a lot closer to that 15 mark. So before they, you know, before they jump on with guards. So the fact that we're able to bring a subset, a core subset of that together is really valuable.
[00:10:10] The, the, the, the numbers I'm seeing there indicate that there's a lot of consolidation happening in the industry, which to me is a really good sign. I think, you know, in general security operations is way more effective when you're able to focus within the stack. Gotcha. Which I would, I would tend to agree with you there is, is in particular, like less is more oftentimes when it comes to this. Now we've made a bit of the case for the good version. I want to make a bit of the case around the, the other time.
[00:10:36] So every argument I see for consolidation is also an argument against something. Right. And that's what I want to talk about. Like, where do you think consolidation genuinely doesn't pay? Like in your category, like, is there a profile of an MSP who should not consolidate? Yeah. I mean, look at the, the, the, the core argument usually against consolidation is around putting all your eggs in one basket. Right.
[00:11:04] Like, right. There's a standard security principle on that front. And the truth is there's a trade off there. Right. All it, all, you know, whenever the idea of consolidating comes up, it's like, well, what do you lose out on? And that you could potentially be losing out from a technology front as you posed earlier. Like, are you settling for less technology? We've solved that by partnering with best of breed tools in the industry to make sure that that's not the case.
[00:11:29] We, you know, the other argument is, is that in the trade off is, you know, how valuable is it to you to save the time of your technicians and the day-to-day way that they operate? So if you're, if they're wasting the time and the effort toggling between different dashboards, learning new tools, onboarding a new technician requires training them on four or five different tools. Invoicing causes the pain of all the different tool, all the different, you know, separate invoices.
[00:11:56] So all of that reduces the effectiveness of someone's operations, right? It reduces, you know, how well you can execute on that security stack. So the consolidation is a trade off directly for the operational benefits, I would say that you get. There's also a cost savings benefit, of course, to consolidation, but that, that to me, pales in comparison to the operational benefits financially that you get. So, okay. So first off, it's worth calling that out. Like, sure.
[00:12:22] That's, that's one of the, that's one of the biggest things, but who, so where does that become not a fit? So to me, that, that operational trade off is maybe less important in a very large, very mature MSP. Someone who has built their own sock has the established operations to execute on, you know, whatever tools they want. They have the personnel and the systems to manage that. And if that's the case, they could look at guards and say, that's not what we need.
[00:12:49] That the solving the problem of, of, you know, tool sprawl is not our primary problem, but there is a cost implication that still exists there. So we have seen even those customers where I would say it just might not be a fit for what they're offering today. We've found a fit at times with those customers as they may want to move down market, right? They, they're up market in their, you know, where they're larger customer base, where their price makes sense, but they might have a subset of that customer base that they can't serve because they price them out.
[00:13:18] Their, their operations are too expensive or their team, their stack is too expensive. So often we've gotten a foot in the door as a company with those large, with those, you know, more mature or larger MSPs by helping them shift and have an offering to move down market. They put a couple of technicians on guards and then they have an alternative offering. And the mindset going into that relationship has often been, you know, what we'll, you know, what we'll do is we'll then try to move them up to our more expensive stack or a more mature stack.
[00:13:48] And what I've actually seen is the reverse often happens, where is that they find, hey, guards can be a better fit for more of their customer base. And they, and we've seen some shift and change there, but okay. That's, that's the, the sunny side on it for us. I'll answer your question with one more non fit. Let's call it. And I, and I think that someone who's very heavy on you know, like CMMC type defense contractors, compliance needs, then the consolidated stack gets more complicated. The, the ability to support that is more complex.
[00:14:18] We currently are not CMMC compliant, just to be clear on that particular one. But even if we were, that story is still more complex because you have to factor in, in this case, different vendors and what that means and what the operations look like potentially where that data might live across those different vendors. So it's not that it's impossible to do. It's just that it's not always the right fit for, for our particular customer base. Gotcha. And a reminder for those watching, if you've got a question, throw it into the Q and A box.
[00:14:42] We will definitely be taking those, but I want to ask a question specifically of the audience here too, because I want to get a sense. How long does it take to onboard a client to your security stack? Like this is part of the, part of the complexity here. Let's go ahead and get a sense from that scan, the QR code and put in there. But while our audience is asking, Donnie, I want to ask you something about what an area of cost that I don't think people always price in.
[00:15:08] Because when you do consolidate, you mentioned that you lose the ability to swap one component without disturbing the rest. Right. I want to think about that in the perspective of like two to three years down the road. Right. So you're in, you're two years in and an operator is thinking about, Hey, I now have a need to make a change on that.
[00:15:28] Is there something that there that they can think about early on day one to be planned better positioning for that year two when they're considering like, Hey, now I've got a need. Yeah. Like, I mean, in general, I would stay away from multi-year contracts. I think those, those are kind of a poison in our industry.
[00:15:47] You know, we, we stick by one year contracts or we have a month to month option, both directly called a self-serve option or through some of our distributors like Pax8, who offer such month to month. But I think Synchro also offers month to month, which is great. But, but I think the, the preparation for those kinds of changes is coming organically in the industry.
[00:16:11] I think we're certainly experiencing the need to open the garden a little bit more today. We have a, I would call it a curated garden. So specific vendors that we chosen to partner with. And, and, and, you know, if you want to use our stack, that's the only way to get the full value out of our stack, but we're opening that garden up a little bit, right? We're, we're letting people bring their own licenses of different things as they need and still leverage our core technology around connecting the dots.
[00:16:36] And I think that's an important part of how we're approaching it. And in general, I'm seeing that in the industry. I think more and more companies are opening up to, to play nice, let's call it. And I think AI allows that. I think the, you know, MCPs and just more mature APIs and you know, the, I think we're entering an almost seamless world with federated search and other kinds of technologies that, that really help make that a reality.
[00:17:00] I think that promise has been there in the past. But connectors were always sort of the blocker. And I think that, that barrier to entry is lowering. Gotcha. Now let's go ahead and let's hear it's here from the audience. I want to get a sense of how long it does take people to, to, to onboard. Let's, let's see. Oh, it's spread a little bit. Good thing. Nobody's more than a week. So that's, that's good to hear, but it's sort of, it spreads. But for most seems less, you know, less than a day. Again, I'm going to ask Donnie, you talk to a lot of people.
[00:17:29] Is this in line with how you think it should be to onboard with somebody or what the industry is experiencing? Should be. I mean, you know, the one week is scary. You know, even the idea that you're dedicating a day on the security side to onboard someone is, is, is, you know, is a burden like over time and depending on the scale of the company that can take a lot out of it.
[00:17:53] I think, you know, the way SAS products have evolved over time is something that guards specifically learned from. When we saw, when we approached this, we said, we don't have to do things the way the security industry has traditionally done it. You don't have to have sort of a hand holding onboarding experience with a customer success rep who can, you know, cover up all the problems with the onboarding flow and, you know, push buttons behind the scenes to make everything work as it needs to.
[00:18:20] And then we said, you know, we took a much more self onboarding approach every, you know, tried to remove all the friction points. And that's actually what we've done with our partnerships as well is saying, well, you know, onboarding certain tools can be heavy. Let's try to find the ways we can reduce that friction, automate as much of that as possible. So gotcha. Donnie, I'm going to go ahead and throw this question because it is a follow up to what we had. We were just talking about because John here is asking about, are you working on becoming a CMMC or FedRAM compliant? Like where, where is that on the roadmap?
[00:18:50] Yeah, it's on our longer term roadmap. So it's not something I can put a date to or anything and we can't officially commit to that. But, but we absolutely have enough customers who are asking for it and it's clearly the market needs. So we need to get there. I'm not sure a hundred percent if we'll take the approach of FedRAM versus just, you know, going for CMMC compliance. You know, one of the challenges for us is of course, is that we don't just offer a product, but we also offer an MDR service.
[00:19:15] So we have a follow the sun model for that teams around the world with eyes on screens to make sure that we cover, you know, every time zone and operate as efficiently as possible on the MDR side of things. So we'd have to restructure that in a way that makes sense for CMMC compliance. Again, it's there. It's a, it's a big enough requirement that I believe we will do it, but I can't tag a timeline on it.
[00:19:39] Gotcha. Now, I also want to bring something up that you brought up with me before we, we actually, as we were prepping for all this. So this is for the audience. This is not something I'm surprising them with. And I want to be a little bit precise because I actually dug into our community analysis. We've looked to thousands of community posts over the last year and guards comes up at about one full percentage point of those conversations. And the average sentiment is what I would describe as mildly positive, which is, is a, which in this community is almost raving fans because it's, it's a hard community to win over.
[00:20:08] And when operators bring guards up unprompted, they very much describe the organization accurately. Sent one and check one underneath price below the sum of the parts, like that integrated whole, your argument is being made for you by people that are not necessarily paying. Right. That's our analysis. And the, so the product argument is not any of the kind of conversation, but there, but there was a bit that I wanted to ask where back in late March,
[00:20:34] there was a bit of cold outreach that went badly and the thread that followed ended up being about outreach cadence, contact, and the piece that I wanted to ask you about, which is channel conflict worry. Right. And then because they brought up the fact that there was concern that you sell, that you sell direct while you also sell through MSP. So that's the one I wanted to ask you on because that trust is the piece that is important. You're asking an MSP to put their client relationship inside your platform.
[00:21:03] So they understand, do you sell direct and where's the line on, on how guards engage it? Yeah. Okay. I'll address some of that. Straight on. So, so first off with the, the sentiment in general, I, I, when it comes to product sentiment, I think our, it's, it's been great. Actually, I've been really happy with what I've seen. You know, the one pushback of course is, is the exact conversation we're having, you know, the all in one versus best of breed.
[00:21:27] And I think, you know, I hope we've, we've discussed enough about that. I'm happy to, again, continue to answer more questions, especially from the audience. If you guys have more, the friction points I've seen the most in the community has been around, you know, aggressive marketing or sales tactics. And that's certainly something we're always trying to fine tune and revise. And, and I think there's a lot we can learn from those conversations, even if they're not the most tactful conversations, we, we still do our best to learn from them.
[00:21:55] And I believe that, that we can improve and we continue to do so. And our leadership puts a lot of pressure on it. And, and I personally try and responsible for those community conversations.
[00:22:07] But, you know, to the last point around selling direct. So that that's not something that that we're doing at all. I can say like, you know, right now, at this moment, I can say we do not sell direct to small and medium sized businesses, or enterprises, we are 100% solely focused on MSPs.
[00:22:26] I can't promise that will be the truth, going into, you know, forever and into the future. As we've seen in the industry, companies make pivots and changes and, and make those shifts. Those are not in the plans, I can say that we're not talking about making those changes.
[00:22:40] We again are laser focused on the MSP community. When I joined guards from the moment I joined right right around the time we started selling into the market, the decision was made across our leadership team that the right way to properly secure small and medium sized businesses was through the MSP channel. We deeply believe that and we're going to continue to invest in that I don't see that changing anytime in the near future. Well, I think that is an incredibly honest answer. And that's the best the best you can definitely ask for that. And I'm going to tell everybody for we also want to talk about the next year, and we're going to talk about that.
[00:23:10] So, as we would like to get a little bit of a broader sense from you. Tell us what your biggest pain point is in security. Go ahead and put that one in chat that way we can get to hear a little bit of the different answers that come from the community because we really would like to get a sense of what your biggest pain is in security. So put that in the chat. If you continue to have questions directly for Donnie or for me, go ahead and put that in the Q&A panel.
[00:23:32] Now, the other thing that was interesting before we spoke and we were prepping for this is you told me something that I really didn't expect for somebody who does what you do. You said you did not think that the unified story is a differentiator a year from now. You pointed directly at a competitor, right? I talked about Huntress in the example and the SIM, the MSP connector. And you thought that as the gap closes, it's going to close across the board.
[00:23:58] And so I'd like to spend the last portion of our conversation kind of talking about some of that, too, because we've spent a lot of time talking about consolidation. But you have a little bit of a thought on where this is going. Like if you think that this role is changing a little, tell me a little bit about the way you think the direction is going to go. Yeah. Yeah, it's a big question, by the way. We spent a lot of time, you know, product strategy is part of my title here. And I spent a lot of time trying to anticipate, you know, where technology is going, what's changing in the future.
[00:24:29] You know, what are the differentiators? What's unique? And per that conversation, I, you know, I really believe one of the biggest values Guards brings today is that unification. But we can see that happening everywhere, right? That word unified is on everyone's website now and platformization is happening, you know, in many, many areas. I think we do it one of the best out there. And I think that's part of the value we bring.
[00:24:54] But if I'm honest about what things look like a year from now, and I mentioned it a bit in, in where I think the real value in consolidation is, and that's in the operation side of things. I also think that's where the real value in a security offering lies, that it's less about, you know, you know, I would frame what we do as workspace security, right?
[00:25:17] We're bringing together, you know, EDR, ITDR, email, security awareness training, phishing simulations, the data, the cloud, like, bringing that all together. That workspace security world, that's a Gartner definition, is important. But what matters more is the MSP's ability to execute on the security stack. And I think AI is changing that world significantly.
[00:25:39] I think it's less about kind of going in and investigating things and making a decision and responding to it, and more about building a system that operates for you. Right now, I think we're very, even with AI right now, we're very much human in the loop, meaning that loop only happens when the human completes it, or authorizes it. And we're going to fast become human over the loop, where humans still need to manage and make sure that things are operating how they want.
[00:26:06] But a lot more decisions are going to be made autonomously or automatically. And it has to, like, I think there's a journey to get there, a journey to build the trust in the tools that are going to bring them there. And also a journey in to make sure those systems operate how the MSPs want.
[00:26:21] And I think, so that operational piece, executing on a security strategy, automating the right things, keeping themselves involved in the decisions that are most relevant for them, and interacting with the data in a way that they can also interpret it, share with their clients, wrap it up in ways that make sense for the other stakeholders.
[00:26:44] I think all of that becomes more of the focus than actually the detection and response should largely be happening autonomously. And the audience is already saying documentation is one of the things that they're continuing to feel that pain point around insecurity. So it's something to think about. Oh, interesting. Now, for those, I'm going to ask you to expand a little bit on workspace security, particularly for those that are not as steep in the Gartner lore as say you or I are. Talk a little bit about what that means. Like, what are we focusing on when we talk about workplace security?
[00:27:13] Yeah, workspace security. It's really the evolution of XDR in a way, you know, the promise of XDR was always bringing all this stuff together, but it really just became managing a million policies. And I don't think that management of policies was ever an effective way to build a security platform or security offering. And it certainly wasn't was never or hasn't been a fit for most MSPs.
[00:27:37] But at the end of the day, you still need to secure a bunch of stuff like, you know, the end of the day, the employee is sitting down in front of their computer. That's the endpoint. They're logging into their email means email security. They're logging into the cloud environment. Now they're doing a bunch of stuff as a cloud identity. They're interacting with their data. They are, you know, installing something back onto that device. All of that are the vulnerabilities or the attack surface that needs to be secured.
[00:28:05] And how you wrap that, how you bundle that together can be very, very different. Someone who wants to get and choose their best point solutions. That's great. But are you able to connect the dots? Are you able to see that attack chain as it unfolds? Most people would say no, unless they're investing in a SIM and a SOAR and a bunch of other technologies to execute on that. So workspace security is the idea. Let's bring this together, build a detection or response engine around all of it.
[00:28:30] So you can really see that attack chain as it unfolds and connect the dots, execute, respond in real time. So everything has to be actionable, not just, hey, here's an alert that you should know about. It's really about actionable responses and that sort of 24 seven MDR service on top of it. Another big piece that I think is exploding in workspace security is AI usage and control.
[00:28:55] The cool thing about AI usage and control is, you know, it's not sort of separate from that EDR, ITDR and email or what's now browser as well, web security. It's actually dependent on those. So to effectively do AI usage and control to see what AI is in use shadow AI or whatever you want to call it, that requires, you know, ITDR to see what's happening in the cloud and email to see what subscriptions are running and endpoint to see what's installed in the device.
[00:29:23] And of course, the browser to see what's being accessed through the web. So this AI usage and control place is going to be a big part of where that technology goes in the future. Now, you also have a line that I really like security is only as good as your ability to operationalize it. Yeah. Tell me what does that mean like over the next 12 months for an operator? Like what does a day actually look like? Are there principles and guidance? What do you mean with that direction? Yeah, it's a driving principle in what we've built.
[00:29:53] So for guards, it means, you know, streamlined deployments and set up as much as possible. That set up process should be seamless, painless, minutes, not hours. Right. And then it also means set and forget. So tell the system how you want it to work for you and then let it operate on that front as much as possible. You shouldn't have to jump in and take action and be involved in things that can be automated.
[00:30:19] And, you know, at the end of the day, it is also looking at, you know, what we can do agentically, what, you know, autonomous analysts can be running in the system and doing the things that take minutes or tens of minutes out of the day of the average technician. And what triage can be run agentically behind the scenes in order to shorten the time of detection to the time of response. And to, you know, assist the humans with, you know, silver platter of of enriched data that they need to make their decision.
[00:30:49] Right. I saw an analogy recently, you know, an air traffic controller isn't, you know, pulling out the manual every time they have to make a decision. They have five very specific data points on the screen in front of them at all times. So they can make very pointed decisions. I would say an MDR analyst is in a very similar scenario where they need to make a decision fast and having the right data, serve to them in the right way is really, really important. And, you know, an agentic triage process can really assist in that setting that up. Right.
[00:31:19] And that's really context. Right. A lot of people talk about knowledge graphs with AI, but the context graph, I would say, is as important or more important in the moment of decision. Gotcha. And I want to keep the conversation going. I got a couple more of it. Make sure to throw any questions that you have as an audience into the question tab. We've got time at the end that I'll take any that are active. I got a couple more that I want to ask about. And it's a little bit of a reality check. So we've been doing a lot of research across about 3000 MSPs.
[00:31:46] And right now we show about 65.8% make no mention of AI anywhere in their marketing. That's not a bad implementation. It's literally no mention at all. You and I were talking about this beforehand and you sort of nodded and agreed. Give me a little bit of a sense of the way you're thinking about AI as it applies to what you're doing in security and what that means for MSPs. Yeah. In my mind, I break it down a lot. I break it down like to a few categories of AI in our product.
[00:32:16] But then as a small business ourselves, I also think about how I use AI in my day to day and how every small business on the planet is probably moving in that direction. So within the product, I think about it as generative AI, right? What can we use AI to quickly generate and whether that's data for reporting or whether it's in our case, phishing simulations or summaries of incidents, right?
[00:32:39] So that generative AI is really important. Then there's the more, let's call it AI assistant approach, the co-pilots, the chat assistant that you can have in order to ask questions, to dive in, to research, to even go as far as threat hunting, forensic deep dives, all of that can be done with those types of interactions. And then there's the truly agentic approach to things, right? Which is setting up agents to do things autonomously.
[00:33:06] You know, in our platform, we do that with our autonomous analysts. So there are certain incidents where you can basically have playbooks that guards predefined that are running in those incidents and can take things end to end. So typically, that's how I think of things. There is a fourth, which I think is coming in the not so distant future. That's A to A, agent to agent.
[00:33:26] And that's, you know, if I imagine every technician has their own agent of choice running in their local system, wanting to communicate either through MCP or APIs or other integration with the different systems that they're working with. So I do imagine the not so distant future, this A to A or agent to agent approach as part of the workflow. So that's how I look at kind of productized AI in the world that I'm living.
[00:33:53] But the truth is, for an MSP talking to an SMB, that doesn't really matter. Like none of that really hits. They don't care how many humans behind the scene had to do something versus how many, you know, agents were running. And the truth is, the same goes on our side with our MDR. Like, how much does an MSP care that we have this awesome agentic triage pipeline?
[00:34:17] At the end of the day, the outcome is what matters. And the outcome that we believe we can only get with this process is, is that reduced time to detection and time to response and rich data. So, so we see the value in it. At the end of the day, the MSP only cares about the outcome. The small business cares about the same, keep me secure, right? So they don't care about any of that stuff. But the opportunity for the MSP is to be, you know, as PAX8 calls it, the MIP, right?
[00:34:42] Instead of calling it like the, the, the managed service providers and managed intelligence provider. And there's a whole world I think that's opening up MSPs if they position themselves right to guide their customer base through this. And part of it is security. Part of it is helping them make good decisions to keep their environment secure. Shadow AI, AI usage and control is part of that conversation.
[00:35:03] But it also should be enabling those small businesses to use, to, to use AI, to automate the things in their day to day and to do so with their trusted professional, right? To not try to figure it out themselves. And I hope, and I believe that most MSPs who are going to be the most successful in the future will embrace that. So. Well, interestingly, Jason threw in there, the generative AI was one of his big security concerns and he's literally said, can't trust it.
[00:35:30] So I want to ask something as we were prepping for this, you were talking about AI usage and shadow AI control partnership as part of the, the near term. Can you give us a little bit of sense of, of where that fits in the, in your plans? Yeah, we have something coming soon. I'm just going to give a teaser. Cause I don't want to expose too much, but, but we, we, we are diving into the world of web. We are actually have the opportunity to wrap up our time here together. So I'm going to make this kind of the last question for you, Donnie.
[00:35:57] And I want to make it actionable for the, for the audience, for somebody who is listening and is going to make that consolidation decision in the next 90 days or so. Like what's the one thing they should do first. And the one thing they should stop doing. Oh, wow. Good question. So I guess if we're thinking about what, what to do first I, you know, I would say learn the product, dive in, feel it, experiencing it, experiencing it yourself to me.
[00:36:27] And I I've seen some people, you know, purchase products blind just like, you know, love the marketing and the messaging and jump right in. And then I say dive in there and feel it and experience it on yourself. That that's, that's the most important thing. Um, and as far as what not to do, um, or what to avoid, Oh, that's a good one.
[00:36:46] Um, you know, I'll give a piece of advice, take it for what, for what it is. I think, um, you know, but the, the MSPs that I've seen that have been most successful, um, in, in selling security or communicating the security value to their customers. They typically don't, um, put line items in their security offering to their clients. They have their packages that they require. So if you're want it services, you're getting security services.
[00:37:15] Uh, maybe, maybe they still separate those as two line items, but the underlying technology, I would say, keep that as your, you know, as your own, um, build the trust with the vendors you want. Technology is changing fast. You're going to see a lot of changes in the next six months to one to a year. And, uh, you know, I believe deeply in the guards approach and I believe if you're, you know, the opportunity to keep your stack flexible, uh, to be able to make that change.
[00:37:40] You know, certainly you want to inform your clients and keep them in a loop when you make changes, but you should reserve the right to do so. And when you put the line items of exactly what technology is in your invoice, I think it limits you a little bit in making those changes. But take that for what, for what you will. I I've never operated an MSP directly. I've just been living in this world for, for, uh, well, a decade or so. Fair. Donnie, thank you so much. This has been a really honest conversation and I really appreciate you being the willingness to take the, the hard questions on this.
[00:38:10] I'm going to make sure this is our time. If you're listening to the podcast version of it and you're interested in a demo, it's in the show notes. We're going to keep that QR code up at the end. Donnie again, thank you so much for joining us. This has been the business of tech sponsored today by guards. Appreciate you joining us and I will see you next time. Thanks for a great conversation.
[00:38:47] Produced by picture this video, part of the MSP radio network.

