When Is a Security Platform Not a Security Platform?
When it’s a collection of products rather than fully unified, according to Sophos. Plus: Why partner program sat’s down and an AI consultant who wants to partner with MSPs rather than replace them.
In security these days, there are platforms and then there are platforms.
Or so says Sophos, anyway. The older, more familiar ones of the kind MSPs know and love have long helped users consolidate vendor relationships, save money, and most importantly, achieve security outcomes no multi-vendor collection of point products could hope to match. The new kind, according to Sophos, updates those benefits in ways made mandatory by the speed and novelty of today’s AI-fueled threats.
You’ve read about the speed part of that here multiple times of late. “Threat actors are using AI to iterate unfamiliar tradecraft at a pace that used to take weeks,” said Alexandra Rose, currently head of global affairs, policy, and partnerships at Sophos and formerly chief operations officer at the NSA, during a recent press briefing. “You go from something that took a significant amount of time to something that they can iterate on in days, minutes, seconds.”
Those attacks are no longer isolated events most of the time either, she added. “They move across identity, email, endpoint, and network.”
You therefore can’t defend against them without “visibility that spans control points and a response capability fast enough to act inside the attacker’s window, not after it,” says Rob Harrison (pictured), SVP of product management at Sophos. “Waiting for a human to correlate signals across five different consoles no longer keeps pace.”
As for the novelty part of the new threat landscape, just ask OpenAI and Hugging Face.
“We hit this inflection point back in November of 2025,” observed Sophos CEO Joe Levy during that press briefing. “The frontier models advanced from rudimentary assistance to agents that now carry out multi-step work on their own.”
Indeed, just days ago, Cato described a lab experiment in which AI planned and executed a complete end-to-end attack chain in 40 minutes based on a single, simple prompt. Frontier models are getting both more creative and more autonomous in increasingly unnerving ways.
Which brings us to the recently unveiled Sophos Fusion. Sophos calls it an “AI-native cybersecurity defense system.” I call it a platform, albeit a next-gen, AI-era one featuring much, much closer and more powerful integrations than its predecessors Sophos Cloud and Sophos Central.
Because in security these days, there are integrations and then there are integrations.
The integration engine in Sophos Central, called Security Heartbeat, is a “signaling protocol,” according to Harrison, that lets individual products respond separately to threat detections anywhere in the suite. If the endpoint protection module, for example, spots a compromised device, the firewall automatically isolates it.
“Useful, but narrow,” Harrison says.
Fusion, by contrast, shares the underlying data itself. “Telemetry, detections, investigations, and response actions all draw from the same layer, so coordination happens at the level of investigation and reasoning, not just alert-passing,” Harrison explains.
Shared context and synchronized action, however, are just two of four attributes that in Sophos’s view make Fusion a system rather than collection of products. “Agentic autonomy with human governance” is the third, according to Raja Patel, the company’s president of product and marketing. “The system can investigate and respond on its own inside boundaries that our analysts set and continuously calibrate with people accountable for the output.” The fourth attribute, he adds, is Fusion’s continuous learning loop.
“Every threat seen across the more than 625,000 organizations we protect makes every other customer’s defense smarter,” Patel says.
All four characteristics are powered by AI, which Levy calls “the connective tissue that lets first- and third-party endpoint, firewall, email, cloud, network, and identity reason and act as one, so the whole becomes stronger than the sum of its parts.”
It’s a vision with obvious parallels to what other big names in security have been up to, and realizing it has been a pretty significant undertaking. But not, according to Harrison, a rip-and-replace operation. Like the AI-native platform ConnectWise unveiled last month, Fusion is a mostly but not entirely new version of its forerunner.
“It’s an architectural rebuild wrapped in a familiar front door,” Harrison says, meaning that “existing Sophos Central customers move across automatically, same login, no migration project.” But it’s also, he insists, more than just a version upgrade.
“The underlying architecture has changed significantly,” Harrison says.
Because yesterday’s architectures have grown ill-suited to today’s opportunities and threats. AI has the potential both to radically improve productivity for MSPs and to obliterate their clients. The key to enjoying the former while avoiding the latter is rethinking what platform must mean in the future.
Don’t blame AI for sliding partner program satisfaction
Back in March, I shared some then barely public research from GTIA that included a troubling fact: partner satisfaction with their vendors is declining.
Not to a degree worth panicking about, mind you. 74% of the partners GTIA surveyed called themselves satisfied with their vendors. But that’s down from 88% just a year earlier, and the percentage of partners describing themselves as very satisfied has dropped by more than half, from 39% to 18%.
The question, of course, is why, and GTIA can’t say conclusively yet. Carolyn April, the group’s vice president of research and market intelligence, has a hypothesis though, and it touches on vendor partner programs.
“It’s about alignment and the changes that are going on in the marketplace today with AI,” she says. “The types of priorities that are important to [IT solution providers] and the things they want to see in a partner program, for instance, they’re different now.”
I’ve had a chance in the past couple weeks to test that theory with two people who spend most of their time studying and optimizing partner programs. Both concur with April’s suspicion that growing dissatisfaction with partner programs is responsible for growing dissatisfaction with vendors. Neither believes AI is the problem with partner programs.
“I don’t believe that AI is causing discontent,” says Ryan Morris (pictured), chief channel program strategist at Channel Mastered, the consultancy I help lead. It’s exaggerating discontent that was already there.
Danielle Ibran, senior analyst for infrastructure channels at IDC, agrees. “We can’t blame it all on AI,” she says, or even most of it. Satisfaction with partner programs, as others at IDC have discussed here in recent years, is wobbly these days for a number of reasons, including the facts that vendors don’t reward them for influencing versus closing deals and continue to slot members into function-specific buckets like reseller, solution provider, and software developer even though the average channel partner, according to IDC data, identifies with 2.8 such labels.
“They’re all doing a little bit of everything,” Ibran says. “That’s where the issue with the programs is today.”
Agentic security startup 7AI, which launched a multi-model partner program last week, gets it, as do companies I’ve written about here before like Cisco and Barracuda. Cisco, however, is a good example of why you don’t see more tech companies following suit. Building the Cisco 360 program was the kind of deeply complex, inevitably controversial undertaking that large vendors especially are understandably slow to take on.
“These programs, obviously, are humongous and they manage on a global basis,” Ibran observes. Changing them takes time.
Which gets to a larger point helpful in understanding the partner frustration GTIA is registering. Vendors almost universally offer product-related training. But AI isn’t a product, or even product category. It’s a huge, complex, and radically new technology category that will leave behind anyone in the channel unwilling to embrace an equally new outcome-oriented, consultative business model. Pax8’s among a still modest number of companies that know it.
“Nobody’s teaching that stuff,” Morris says. “Almost everybody’s pretty good at product training. Many have gotten pretty good at services training. Few have ventured into the business model training.”
Or kept up with an ongoing shift in the channel toward new, higher value, stickier revenue streams, adds Ibran, noting that 55.7% of the money partners make globally today comes from their own IP.
“Partners are seeking higher margins and defensible differentiation,” she says. “AI plays a key role here.”
Ibran would like to see more vendors reflect that fact by offering AI-specific education in areas like FinOps as well as managed service blueprints for recurring IP-led revenue in fields like AgentOps. Measuring partners more for delivering verified end user business results versus accumulating certifications would be helpful too, as would rewarding them more for pre-sales functions like solution scoping and design.
Morris, for his part, has another suggestion for vendors: Stop using AI as a substitute for people.
“More and more of the partner community and more partner questions are being dealt with by an FAQ bot as opposed to a real human,” he says. That works fine (and sometimes better than fine) with consumers, he notes, because they only need help occasionally.
“A partner doing business with a vendor has interactions every single day at some level,” Morris says. “If you put half or more of your question base into an automated response, a partner will get an automated response every single day from you, which is a really clear indication that you’ve disconnected from me in the relationship.” The better path, as some in the industry understand, is to augment and enhance person-to-person relationships via AI instead.
“Don’t get rid of your channel account managers. Empower them with AI to do even more and to automate manual tasks so that they can spend more time doing human touch with the partners in the relationship,” Morris says. “A partner’s going to feel that they get more human attention than they did in the past, not less.”
Get ready to think through similar issues more or less indefinitely, Ibran warns channel chiefs. AI moves fast and changes continuously.
“You almost have to get into a startup mindset,” she says. “Things are going to evolve, and I think you’re going to have to evolve with the market.”
What’s MSP as a Service?
So much was going on at Pax8’s Beyond event last month that we didn’t get a chance to air the interview Erick Simpson, my business partner and co-host on the MSP Chat podcast, recorded there with Juan Fernandez about his new MSP as a Service venture until this week. Worth the wait, IMO. Check out the whole episode here and all of our other equally interesting episodes here.
What makes AI consultants different from most MSPs
It’s come up a few times here in recent weeks that SMBs aren’t sitting around waiting for someone to pitch them an AI solution. Some of them are placing outbound calls to IT providers, including companies they’ve never spoken with before, asking for help launching AI initiatives. Guess what happens if you get one of those calls but have nothing to offer.
“MSPs would be foolish not to assume that these really progressive, technology-forward businesses aren’t going out and talking to alternatives who can provide them with AI services,” says John Bush.
He knows, too, because he’s one of them.
Bush is founder of Dallas-based AI consultancy wave4. If you’re a Channelholic regular, you’ve read about AI consultants here before. They’re the people phoning up your clients if you’re an MSP and offering them workflow-transforming, time-saving, money-making AI solutions you don’t provide, making them in theory a competitive threat. Well, I’ve spoken with one now, and he’d much rather be your partner than your replacement.
Bush cut his teeth on AI while building enterprise security solutions for KPMG. “I think all of us working in technology always had the suspicion this is going to be a thing,” he says of AI. “The question was always when.” And the answer became obvious a little over a year ago as he watched engineers on his team put AI coding tools to work.
“They were doing work that would have taken them a week in like an hour,” Bush (pictured) says. That was his “AI light bulb moment,” he continues, and it had nothing to do with the enterprise.
“There’s this huge opportunity with smaller businesses who just don’t have a lot of technical talent or knowledge of all this,” Bush says.
wave4 is the “AI transformation partner” he created to fill that yawning gap. Early on, the company just asked clients what kind of AI solution they were looking for, and built it.
“What you realize is that most businesses don’t know enough about this stuff to be able to make informed decisions about what they really need,” Bush says.
As a result, client engagements these days begin with a thorough onsite assessment of a company’s people, processes, and technology, Bush says. “That allows us to unearth the solutions and the opportunities that exist for them to use AI.”
Those solutions and opportunities vary from helping businesses embed Microsoft Copilot in their workflows to building custom CRM solutions. “We’re training some of their employees to become power users who can do some of this themselves as well,” Bush says.
wave4 bills its work at rates low enough to be affordable by SMBs but high enough, when combined with the company’s extensive use of AI tooling, to deliver substantial margins, he adds.
“I’ve kept this very lean so I can come in around that, let’s say, high four- to low five-figure range, depending on what the scope of work is,” Bush explains, noting that he has two developers and two part-time consultants on staff at present. Their work involves skills an above-average MSP’s best technicians usually lack, even if their employer encourages them to spend five hours a week acquiring them.
“I’m doing twice that in a day,” Bush says. “It’s just a reps thing, ultimately. Just having more time on task.”
That said, Bush is fully aware of where his expertise ends. wave4 knows which AI tools to use (his favorites currently are Claude Code, Codex, Oz, and Hermes Agent) and when to use them, and it knows how to speak with SMB decision-makers about pain points and business goals in their own language. It knows nothing about standing up and supporting an IT infrastructure.
And doesn’t intend to learn—Bush is partnering with an MSP in California at present to fulfill that need for his clients, and wants to partner with more.
“This allows them to have something they can offer to their clients tomorrow and be able to provide all of the consulting, training, and implementation that their clients are already asking for,” he says. It gets him warm sales leads. “We can really solve each other’s problems in a lot of ways.”
Nor should potential partners worry about wave4 mastering IT services and stealing their clients someday, Bush continues. Indeed, if anyone should be concerned about the future, it’s him. AI consulting is an MSP’s game to lose.
“A lot of these businesses have never bought an AI service before, so working with someone who’s already done good technology services for them is a big advantage,” Bush says. “They have the trust element.”
Over on The Business of Tech
Host Dave Sobel’s pondering what happens when MSPs who fail to keep pace with increasing cyberinsurance requirements end up losing cybersecurity business to the insurers themselves (a phenomenon I’ve pondered too):
“So here’s the choice, and it’s about staying on the right side of a line that keeps rising. You can be the provider who keeps every client continuously above what carriers require to stay insurable—treating the insurability floor as your standard, watching it climb, and moving each client up before the renewal or the claim finds them below it. Or you can keep selling a fixed security stack while the floor rises underneath it—and become the vendor the insurer bundles past, the day your client’s coverage, not your contract, is what defines ‘secure.’”
Microsoft weighs in on the SaaSpocalypse
Hat tip to Robert Scott, CEO and co-founder of AI-powered MSP contract intelligence vendor Monjur, for calling my attention to this story, which got some coverage in the legal trade press and as far as I can tell pretty much nowhere else.
Which is strange, because it feeds directly into the ongoing debate about whether SaaS is doomed. As I’ve written here before, a lot of software categories will be impacted if not erased by LLMs, but others clustered in particular around risk and focus (as in subject matter specialization) are in better shape.
Legal software is one of the categories I labeled a safe investment bet, and here’s some evidence that it remains so courtesy of Harvey, one of the vendors I named in my piece: the roughly 2,000 people in Microsoft’s legal department are Harvey’s latest users.
A nice win for Harvey but notable as well because Microsoft has recently introduced Copilot functionality for lawyers, following in the actual footsteps of Anthropic and rumored footsteps of OpenAI. All of those tools are probably handy, too, but at least in Microsoft’s judgment, when real attorneys need to do real work in which errors will have real consequences, they need something a lot more robust than Copilot.
Also worth noting
The new ChatGPT for small businesses program gives end users access to hands-on training and in-person AI academies, among other resources.
Ivanti has added predictive remediation and autonomous patch management to its Autonomous Endpoint Management platform.
Axonius has added an AI agent and MCP Server to its Asset Cloud solution.
AvePoint has added new agentic AI governance, backup and recovery, and multicloud data protection functionality to its Confidence Platform.
Cobalt has introduced Autonomous Pentest, a continuous offensive security solution designed to deliver actionable findings within 24 hours.
Palo Alto Networks intends to acquire observability vendor Embrace to add new digital experience monitoring capabilities to its platform.
Cato Networks has integrated its Cato SASE Platform with the CrowdStrike Falcon platform to enhance threat detection and accelerate investigations and response.
Barracuda has added new training, certification, and marketing resources to its Partner Success Program.
Keyfactor has added value-based incentives, enhanced co-selling, a post-quantum security certification, and more to its partner program.
Coro has appointed Dor Avrahami its VP of product, Itzik Shachar its VP of R&D, and Ingo Schaefer its VP of sales for EMEA.
Chris Fabes is the new president of TD SYNNEX Canada.
The Channel Marketing Association has appointed Roisin Monaghan of ServiceNow and Taylor Wiggins of Axonius to its executive board.







