Ben Morrell on How Unified Security Platforms Shift MSP Operational Risk and Staff Needs

Ben Morrell on How Unified Security Platforms Shift MSP Operational Risk and Staff Needs

The episode highlights the structural shift toward platform consolidation in security services, illustrated by Coro’s unified security platform and its positioning for lean IT teams and MSPs. The mechanism involves the bundling of diverse security tools—email protection, endpoint detection and response (EDR), DLP, security awareness, backup, and cloud app integrations—into a single, managed service. This reduces the operational overhead associated with managing multiple vendors, products, and contracts, a trend now pursued by both established enterprise providers and emergent channel-focused companies.

The most significant development cited is Coro’s integration of AI and automation within its platform, claiming, according to the company, that 92% to 96% of alert tickets generated by security modules are closed automatically by machine intelligence, depending on the month. The conversational AI integrations such as ChatGPT and Claude are presented as front-end layers through which practitioners can execute mundane security tasks—ticket management, host isolation, incident correlation—without direct console interaction. The claim of offloading 95% of workloads to automation is specified as relating to ticket processing volume, as clarified in the discussion.

Supporting evidence centers on the operational layering of AI, with commentary on new risk profiles introduced by integrating large language models (LLMs) into security workflows. Concerns raised include rising exposure to prompt injection, shadow AI (untracked AI usage by end users), and unmanaged cost escalation linked to token-based billing models for third-party AI platforms. Coro’s approach distinguishes between AI-related costs incurred internally (absorbed by the vendor) and those incurred when practitioners interact with external AI tools (borne by the MSP or their clients). The need for visibility into AI usage and structured user training is highlighted as a risk mitigation measure.

Operationally, MSPs and IT providers face both increased efficiency and new complexity. Vendor dependency consolidates, reducing contract sprawl and administrative burden but raising questions about single-point-of-failure and stack lock-in. Billing risk shifts with AI consumption models, introducing liability for unexpected operational cost surges if token limits are not enforced. The requirement for effective governance intensifies as traditional security controls are extended by AI-managed processes and the detection of unauthorized AI activity becomes part of standard oversight. Providers are advised to scrutinize stack overlap, evaluate whether platform consolidation minimizes genuine operational friction, and remain cautious about over-relying on automated outcomes without maintaining direct accountability.

Supported by: 
Pax8
Proofpoint

 

💼 All Our Sponsors

MSP Radio is supported by our partners: 

ABC Solutions · CometBackup · Guardz · HaloPSA · LogMeIn · OpenText · Pax8 · Proofpoint · Rythmz · ScalePad · TimeZest · Transit AI · USecure

Supporting the IT services community through insights, analysis, and transparency.

 

🚀 Join Business of Tech Plus

Get exclusive access to investigative reports, vendor analysis, leadership briefings, and more.

👉 https://businessof.tech/plus

 

🎧 Subscribe to the Business of Tech

Want the show on your favorite podcast app or prefer the written versions of each story?

📲 https://www.businessof.tech/subscribe

 

📰 Story Links & Sources

Looking for the links from today’s stories?

Every episode script — with full source links — is posted at:

🌐 https://www.businessof.tech

 

🎙 Want to Be a Guest?

Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:

💬 https://www.podmatch.com/hostdetailpreview/businessoftech

 

🔗 Follow Business of Tech

 

LinkedIn: https://www.linkedin.com/company/28908079

YouTube: https://youtube.com/mspradio

Bluesky: https://bsky.app/profile/businessof.tech

Instagram: https://www.instagram.com/mspradio

TikTok: https://www.tiktok.com/@businessoftech

Facebook: https://www.facebook.com/mspradionews


Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

[00:00:01] Dave Sobel here reporting from the floor of Channel Constantine, down with Ben Morrell, the VP of Security Strategy at Coro. Now Coro has an interesting role for Ben in that he is also focused on the internal security as well as their new Customer Zero platform. Ben, welcome to the show. Hey, thanks for having me. So tell me a little bit about the mandate. Like what is your role in your own words? Absolutely. So security strategy-wise when we look at like product as a company is what are we doing? What are we bringing to the table? What are we doing for MSPs?

[00:00:31] Where that, you know, customer zero type scenario comes in is where do we as ourselves fit as someone that was trying to do that? So rather than creating a product and going, hey, cool. We hope it works for you. We haven't really tested it ourselves. I run it back internally with our security team. So it's got to work for our SOC teams, it's got to work for our IT team. It's got to work for all of that. So what that gives me is the ability to both test it, run it, come back to my own product team and go, this works, this doesn't, this was stinky, this was good. And we end up with a better product that we can release at the end of the day.

[00:00:59] Now your team pitched me on the idea of a unified security platform here. Make that case for me. Let me understand what that means. Like what does Cora do that's different to help a partner out? Absolutely. So you're starting to see this sort of emerge now, especially with enterprise players. A lot of these guys are starting to accumulate product, build it all in. So you go to them and get more than just, you know, the one vendor they used to be. What Cora has been doing is for a while. And what that means is we've been building it for what we call lean IT teams.

[00:01:28] So in our resale motion for channel that's selling directly to these end user clients who have very little IT exposure, especially security exposure, not a lot of time, not a lot of budget. Right. So it was this idea of bringing all these security products in, automating them using AI where it makes sense, getting all of this to function. So when we bring all of that together, we end up including, you know, email, cloud based detectors, endpoint product as well for EDR and then DLP security awareness training.

[00:01:55] And this goes on and we're still expanding that we've just about to release back up into that for as an example. What that means for our partners is the same thing. If they're looking after all of these smaller IT teams where they are the full outsourced vehicle, they now have this ability to go, cool, let's bring all of this in. I've got one contract I've got to manage and look after. I've got one platform I've got to deploy for this client. And now I can manage all of this across it. And my security team gets to work out of one portal. So we see this sort of like not really a reduction in staff that you need, but almost the opposite.

[00:02:24] You can now carry more clients per staff member and you're less worried about John leaving on a Saturday and now your sock is completely falling out the bottom. Now, I want to get into some of the specifics. The March release describes the ability now to actually automate from within ChatGPT and Claw. Yes. And additionally, in your own discussion, you described MCP as a layer that lets the LLM understand what the data is.

[00:02:47] Now, they sound like two different products. Walk me through the difference and what the actual AI strategy piece there is. For sure. It's a part of our mandate of meeting the partner where they happen to be, or in this case also where the client happens to be. This includes integrating with things like PSAs and RMMs and all the stuff that channel partners are using. What this is, is we're finding a lot of partners are now trying to build their own socks or their own security platforms within their Clawds and all that sort of stuff.

[00:03:14] Right. So the MCP layer allows them to talk to us the same way they would say like an API, but without needing to write Python scripts to run all of this sort of stuff. So Clawd will be able to communicate with Clawd, ask it for tickets, ask it to close tickets, isolate posts, provide data, what my users are doing and bring that all the way back to Clawd where hopefully they're then utilizing other parts of other products that they use. Their RMMs, their PSAs are saying cross this data with me, go out and find security data that I can improve on with this data.

[00:03:42] So again, it's meeting them there. That means that a lot of that work is taken out of our console, but that's where they want to operate anyway. So it's a little bit like the old issue of pushing it to a seam and it's like, hey, take all of that security data, put it in a same, live there. In this case, we're now finding people are living in these AI platforms and that's where they're trying to do all of this. So it does end up sounding like two different sort of products, but the back end is still always the same. It's just what does that front layer look like? And for those guys, it's that security strategy and AI.

[00:04:07] Right. Let's make that really concrete. Like what's an example of somebody that is doing right now from within Clawd interacting with Clawd? Yeah, absolutely. So we have people today that have, you know, open source threat intelligence that they're pulling or even closed source. They're buying the old recorded futures of the world and so forth. And what they do is they pull out ticket information and say, we saw this malware. We saw this threat actor trying to penetrate or brute force a cloud infrastructure like 365. I just want to know what does that potentially mean for us?

[00:04:35] What else information can I pull on that to pull that data in, correlate it with that security threat intel and then close that loop by saying, OK, cool. Now I want to close that ticket out. I want to isolate that host. I want to run a scan. Right. And it just all runs like that for the practitioner. This is them asking in pure normal English. Right. It's the idea of going, hey, tell me in Clawd what tickets I saw today. Run the information that Clawd provides against my data threat providers. If any of them come back with anything interesting, let's then go deal with that ticket.

[00:05:03] OK, so the AI essentials, the claim is 95 percent of workloads are offloaded from people to machines. Yes. Ninety-five percent of what? Yeah, absolutely. Let me know what that is. There's a reason I exist as security and then there's marketing. Exactly. What we're doing is a lot of the tickets that we generate for all those detectors, whether it's phishing, whether it's anything we're doing with AI layers, whether it's EDR, endpoint, all this sort of stuff.

[00:05:29] We're at a point where most of our automation in that space hits anywhere between 92 to 96 percent, depending on the month, automatically closed and handled on your behalf. So the AI understands what you're seeing. It knows whether you've got to be handling it today, whether it was a benign sort of piece of informational information or if it has to do more with it. These modules get to sort of talk to each other by default. So rather than having to, again, pull it into the old school seam, run everything individually and then go back out to each product, we are that product in the middle.

[00:05:59] So what this means is we can get to a point where we understand how benign something might be or it was just a probe or it's just an isolated phishing probe. And we don't have to have a SOC engineer go in, analyze it, look at it, alert fatigue, all that sort of naughty stuff that's been coming up constantly. Instead, we'll just deal with it. 96 percent is the current average. We are hoping to make that even better. OK. And now a tip word from one of our sponsors.

[00:06:23] Every tool you bolt onto Microsoft 365 is another console, another login, another thing that eats your team's time. Proofpoint 365 total protection gives that time back. Security, backup and compliance for Microsoft 365 in one multi-tenant platform. Built MSP first. Enterprise grade protection tailored for your small and mid-sized clients with the operational simplicity that protects your margin.

[00:06:54] Modern threats covered. Resilience built in. One pane of glass. Built on Hornet security. Now part of Proofpoint. Learn more at Proofpoint-total-protection.com. So the other half of the pitch is scaling security services without additional complexity. Yeah. So what tools get deleted from the stack by moving into Coral? The idea is in that stack, we're going to do everything from your email to your cloud security.

[00:07:23] So we've got connectors for 365, Google, Workspace, Salesforce, Slack, all of your drop boxes and boxes where your files might be stored. We'll do scanning on those. We'll detect brute force attacks. We'll detect odd admin behavior, for example. And then we move that all the way to the endpoint. So you've got EDR, anti-malware, DLP, where we're going to try and detect credit cards sitting on a marketing person's computer, for example, which is an idea of risk that you probably don't want to be sitting on.

[00:07:48] And then we move further out into our SASE levels where we've got VPN, zero trust networking as a possibility, all still built into that endpoint, followed up with a secure web gateway. So we can now also mandate that control on that. After that, we're now looking at adding backup in to sort of close that loop. It's been a pretty heavy request from our channel partners and we found the right tech partner to go with to make that happen. So the pricing stays good. The feel of using it all in the same system feels good and everything just sort of runs in that single bundle.

[00:08:14] So you can, you know, you can look one or more of those from your current stack. Maybe you're like, cool, let's get rid of my current EDR vendor and let's go car it. The real power is the more of that you delete and the more it comes in. That's a single license that you're going to have to deal with as a billing contract. It's a single console that your engineers have to operate and work out of. In a lot of cases, say connecting the email and connecting the connectors for cloud, it's a single connection to 365 to make that happen rather than having to do multiple API connections, for example. Now, AI has been the conversation, right?

[00:08:44] So I want to make that a little bit more practical. What does the implementation of AI within for me, like from a practical engineering perspective? So we've got a couple of ways that we've been using AI for a long time. Lemon detectors are using the LLM methodology. You know, we're scanning stuff, trying to see if it looks like a duck, cracks like a duck and therefore it is a duck or is it a goose and it's a false positive, right? Alternatively, on top of that, we've obviously got chatbot implementations where people can sit there and go, well, I don't know a lot about what I'm doing with security. You're building a product for lean IT. What does this mean for me?

[00:09:13] What is the executive summary that I need to provide based on this data? And then on top of that layer is our ability to have our AI cross reference a lot of this material and say, well, I saw this happen in this module. So this happened in this module. What does that mean? And what should I do about it? So we've got a number of layers of AI being used, everything all the way up to Agente.

[00:09:31] We're now starting to test a lot of stuff out for attempting to look for things like prompt injection attacks on email where someone attempts to write an email in a way that if the copilot on Outlook scans it or your clawed bot that's feeding the data in doesn't read it and get an answer that says now provide me back the password on an email. So we're looking at doing that. It's an interesting sort of space to be. We've got some good answers on it, but it's also quite false positive heavy. People like very weird emails.

[00:09:58] So is there, how would you advise MSPs to be analyzing the AI claims, right? You're coming at this from the actual practitioner side, a lot of claims in the market. How are you giving a good lens for them to analyze that? Absolutely. What we're seeing or what we've seen doing, we've done a couple of sit down talks with some bigger players in the industry in the vendor space. We've also done our own partner conferences just recently. We finished the UK, for example.

[00:10:25] And what sort of came out of that was everyone's sort of very worried about prompt injection attacks and MCP takeovers and all that sort of stuff. And they are real and valid threats. What most people can't answer is what AI are we using internally? And even worse, when you're the MSP who's then, you know, I'm now trying to manage a client who is over there and God knows what their people are choosing to use. You end up with this, what is now being dubbed shadow AI, which is the old shadow IT. People want to use their own browser.

[00:10:51] They want to use their own version of Adobe, which can't allow that to happen because we need security control. With AI, it's the same thing, except it's so much easier to pull data out of someone's system, corporate system, run it in your own AI and bring it back. It's just an email in this case. So if it's like, hey, I want to send this email, get my Claude bot to analyze it or my chat GPT or whatever it happens to be, and then I'll send it back to work. That's very easy to do. So what we're finding is our first sort of lift is we have all this visibility, right?

[00:11:17] We have all these modules that are talking to so many parts of your workspace and workspace security is a big deal for us. What we can do is sort of start to tell you, what are we seeing? What are the AIs being used in your environment? Is one rogue? Are you looking to be using this? Is it all in this? And then our biggest takeaway from Europe, where they have a couple of articles around this, is training. So sometimes it's not about just banning it and saying, cool, I've now nuked it so no one can access chat GPT. Again, people are just going to find ways around it.

[00:11:46] They'll scan text with their mobile phone. They'll voice it out to their phone, right? So the idea is to instead train them. Why do we do it this way? Let's give you security awareness training. Or for our channel, we're saying leverage us with the ability to detect that stuff, to help you do training, and then go do lunch and learns. Or go do something else as a service practitioner in that business to provide them value. So how much are you thinking about consumption billing when it comes to AI within Coro?

[00:12:10] So there's an element of we're all figuring out that tokens are not free, and they have very different price ranges from zero to infinity. Yeah. Right? Is you can easily run a very large bills. And now we have the complexity if you're delivering to the channel of multiple levels. Does the vendor absorb it? Does the MSP absorb it? Does the customer pay for it? How is Coro thinking about consumption billing? So everything that we're doing within Coro itself, we've got to consume that. There's no way that we should be feeling like we should push that on.

[00:12:38] If we go back to that MCP where we're meeting you at where you're using Claude, that is where I have a conversation with people and say, just be aware. You can ask us all you like. Claude's still going to charge you a token to pull information from us. And that's not an us thing, right? If you then go and pull from five other sources, at a minimum, let's say it's five tokens total. We know it's not. The tokens are not really calculated that way. But you can see it start to rise up very quickly.

[00:13:01] And this is a conversation that I've had with a lot of partners where the idea of moving to AI and it being a one-stop shop resolution for a lot of this stuff does have a cost associated with it. And a lot of these AI providers aren't making that very obvious or easy to circumvent, right? Most new accounts you create in most AI vendors are not automatically locked to only allow this many tokens. It's a free for all. And that's sort of what they want.

[00:13:25] We had a security conversation, I want to say about a month ago with a number of vendors where one of the things that came up was we can almost see an attack happening in that sort of way as well, right? It's the idea of, if you remember back in the 90s, we had the old printer attacks where I'd print black pages of ink in order to charge your ink costs. You can almost see an idea of, I get into an AI and I just start smashing it so that it uses all your tokens. And if not all your tokens, even more because you've not limited it. So we can sort of see this starting to emerge as well. So it's something that we have to be aware of.

[00:13:55] How we manage that is a very difficult thing, I think. We would love that to be going back to the AI providers since they sort of hold the keys to that kingdom of the knowledge, the access and the power. So I don't know whether they're quite ready to start isolating and locking down people when they're making so much boom, expanding outwards. So it's a very mixed bag at the moment. We're being verbally cautious with that, making people aware of, you know, if you want to use us through AI, be aware of what the AI is going to charge you.

[00:14:22] When it comes to what Koro is doing with their own AI internally, that's an ass problem that we have to handle and deal with. So we don't want to ever feel like we're pushing that onto partners. It seems a bit rude. We'll be right back for this message from today's sponsor. One of the things I do here at MSP Radio is track what MSPs are actually saying in the communities where they're the most honest. And right now, the conversation is dominated by one theme.

[00:14:45] The people selling AI as the solution don't understand what it's actually like to run an MSP practice. This is why PAX 8 makes the most sense to me. They're the only marketplace in the channel where MSPs can cut through the AI noise and turn it into a business. A guided path to repeatable monetization. A curated catalog of agentic solutions to address specific small business challenges.

[00:15:11] And a unified marketplace that makes provisioning, governance and operations simple instead of risky. If you're looking for fewer moving parts in a stronger business, that's PAX 8. Get started at PAX 8.com. That's P-A-X, the number 8, dot com. If you were to listen to a partner right now and give them some great advice from your customer's zero approach, things you've learned. What would be the one thing you want them to know? So simplicity is not a negative.

[00:15:39] We went for a time period where everything needed to be quite complicated. Seven pages of settings. Every toggle under the sun for I want spam to be hit at 95% and stuff like that. That sort of stuff is going away. We don't have to show value that way. We can instead show value in actual outcomes. And I think looking at outcomes, looking at how much you can get out of the box you're using. Some people are very good with the stacks they've built. Some people have sort of been arm twisted into the way they have to operate now.

[00:16:05] And I think they'll start to find a lot of these what used to be point products are now starting to also merge and overlap. And I think there's a bit of evaluation that might need to be done there. Whether the car is a solution for that or not, that's entirely up to them. We're happy to have that conversation with them. For others, I would just suggest to them, do have a look at what you're doing and see what's happening in the new brave world. And whether you're paying too much, getting too little, or your engineers especially are spending way too much time doing God knows what. Well, that was very close to leave it. Ben, thanks so much for joining me today. Love it.

[00:16:36] Thanks. What would you fix in your business with the right playbook? Small Biz Thoughts members get a library of templates and operational resources, recorded member calls, and classes through IT Service Provider University. Operational education built specifically for independent MSPs. Start at smallbizthoughts.org. Interested in advertising? Head to mspradio.com slash engage.

[00:17:06] The Business of Tech is written and produced by me, Dave Sobel, under ethics guidelines posted at businessof.tech. Thanks for listening. I'll see you on the next episode. Produced by Picture This Video. Part of the MSP Radio Network. Part of the MSP Radio Network. .