ChannelBuzz.ca

ChannelBuzz.ca

Cutting through the noise for Canadian VARs and MSPs

  1. 2h ago

    The Buzz: CyberFOX buys Optimize365, Microsoft secures Windows AI agents, AWS cuts Marketplace fees

    Today’s headline news for Canadian IT solution providers: CyberFOX acquires Optimize365 to expand Microsoft 365 security: CyberFOX has acquired Optimize365, adding continuous Microsoft 365 tenant monitoring and security hardening to its growing portfolio.Optimize365 helps organizations identify configuration problems, monitor changes and strengthen Microsoft 365 environments. For MSPs managing dozens or hundreds of customer tenants, that addresses a familiar challenge: keeping security configurations consistent as settings, permissions and requirements change.The acquisition extends CyberFOX beyond its existing privileged access management, password management, DNS filtering and SASE offerings. It follows the company’s acquisition of Timus Networks earlier this year and its September distribution agreement with TD SYNNEX covering North America.The broader story is CyberFOX’s effort to assemble more of the managed security stack under one vendor. The opportunity for MSPs is potentially simpler security management, although the value will depend on how successfully the acquired products are integrated. Financial terms weren’t disclosed, and the announcement doesn’t establish immediate Canadian distribution arrangements for Optimize365. Microsoft puts security boundaries around Windows AI agents: Microsoft has outlined its hybrid-intelligence strategy for Windows, combining local and cloud AI capabilities while giving agents greater ability to work with applications and files.A particularly significant development is Microsoft Execution Containers, or MXC, now generally available on Windows 11.MXC allows developers and administrators to establish policy-enforced boundaries around the resources an AI agent can access, including files, networks and desktop interactions. Those restrictions are enforced independently of the agent’s own instructions, helping limit the consequences of unexpected or inappropriate actions.Microsoft also introduced new AI-focused hardware, including the Nvidia-powered Surface Laptop Ultra. For solution providers, the bigger opportunity may be helping customers manage AI agents as they become part of everyday computing. That includes determining which agents can operate, what information they can access, and how their activity should be monitored and governed. AWS reduces Marketplace fees for professional services: AWS has lowered fees for professional services sold through AWS Marketplace, reducing the standard listing fee from 2.5 percent to 0.5 percent.The company has also introduced a zero-percent base listing fee for qualifying professional services sold as part of multi-product solutions. Additional fees, including those associated with Channel Partner Private Offers and regional requirements, may still apply.The changes, announced in September and highlighted in recent channel coverage, are intended to make AWS Marketplace more attractive for partners selling implementation, migration, consulting and other professional services alongside cloud technology.For Canadian solution providers, the significance is straightforward: lower transaction costs can improve the economics of selling services through Marketplace, particularly when those services accompany larger software or infrastructure deals. The move also reinforces the growing importance of cloud marketplaces as procurement channels for services, not simply software subscriptions. Partners still need to understand the applicable fee structure and eligibility requirements before assuming a particular transaction qualifies for the lowest rate. In Brief Check Point flags sensitive-data exposure through GenAI: Check Point Research’s September threat reportfound that one in every 39 enterprise GenAI prompts posed a high risk of sensitive-data leakage. Network and IT infrastructure information was the most frequently observed sensitive-data category, appearing at 71 percent of organizations in the dataset. The findings reinforce the importance of AI-use policies, data controls and employee guidance for MSP customers. Securonix adds AI-agent behavioral detection: Securonix has introduced Advanced Behavioral Analytics, extending behavioral monitoring to AI agents as well as human users. The company says the technology can identify unexpected agent actions, unusual data access and other activity that may be technically permitted but operationally suspicious. Consequential response actions remain subject to human approval. Accenture and Dell establish private AI business group: Accenture and Dell Technologies have expanded their partnership with a dedicated business group focused on private, hybrid and sovereign AI deployments. Accenture plans to train more than 3,000 practitioners on Dell technology, combining infrastructure with consulting, integration and industry expertise. The move underscores the growing importance of implementation and services in enterprise AI projects. Upscale introduces networking architecture for mixed AI infrastructure: Upscale has announced Token Fabric, combining networking silicon, systems and software to connect different types of AI accelerators. The company is targeting hyperscalers, neoclouds and enterprises building heterogeneous AI infrastructure, with general availability planned for early 2027. Read Full Transcript Welcome to The Buzz from ChannelBuzz.ca, I’m Robert Dutt, today is Friday, October 9, 2026, and here’s what’s happening in the channel today. CyberFOX is continuing to assemble a broader security platform for MSPs, this time with the acquisition of Optimize365. The deal adds Microsoft 365 security monitoring and hardening to a CyberFOX portfolio that already includes privileged access management, password management, DNS filtering and secure access. Optimize365 focuses on a familiar problem for MSPs: keeping Microsoft 365 environments securely configured as settings, permissions and user requirements change. For a service provider managing dozens or hundreds of customer tenants, those changes can create a substantial ongoing security and administrative burden. And the acquisition is interesting in the context of what CyberFOX has been doing this year. In June, it acquired Timus Networks to add SASE and zero-trust network access. Then, at the end of September, it signed a North American distribution agreement with TD SYNNEX covering its existing security portfolio. We covered that distribution agreement here on The Buzz last week. Now CyberFOX is extending its reach from devices, credentials and network connections into Microsoft 365 itself. There’s a clear strategy developing: bring together more of the tools that smaller IT teams and MSPs need to manage security across their customers. Optimize365 will continue operating under its existing brand for now, with integration into CyberFOX’s partner program and product roadmap planned over the coming quarters. Of course, buying the pieces of a security platform and integrating them into a genuinely simpler operating environment are two different things. That’s the question worth watching as CyberFOX brings these acquisitions together. Financial terms weren’t disclosed, and there’s no announcement yet about whether the newly acquired technology will be available through the company’s Canadian distribution relationship. Microsoft, meanwhile, is laying the groundwork for a Windows environment in which AI agents can do considerably more work on behalf of users. And that means Windows needs a new set of security controls. At its Windows event Wednesday, Microsoft outlined what it calls hybrid intelligence, combining AI processing on local devices with cloud-based models depending on the task. The company also introduced new AI-focused hardware, including the Surface Laptop Ultra, powered by Nvidia technology. But for solution providers, the more consequential development may be Microsoft Execution Containers, or MXC. MXC is now generally available. It allows developers and administrators to establish policy-enforced boundaries around what an AI agent can access and do. For example, an agent might be allowed to read and modify files in a particular project directory, but not access personal documents or change system settings outside its assigned task. Those restrictions are enforced outside the agent itself. That’s important because an AI agent can make a decision that seems reasonable in the context of its task but still goes beyond what a user or administrator intended. Microsoft is also working to distinguish agent activity from human activity through Entra, and to extend Agent 365 management capabilities to agents running locally on devices. Those additional identity and management capabilities are still coming. For partners, the implication is that managing AI agents could become part of everyday endpoint management. Customers will need help deciding which agents are allowed, what resources they can access, how their activity is monitored and who remains accountable when something goes wrong. That’s a much bigger opportunity, and responsibility, than simply deploying another AI application. And AWS is making it considerably cheaper for partners to sell professional services through AWS Marketplace. The cloud provider has reduced its standard Marketplace listing fee for professional services private offers from two and a half percent to half a percent. And for qualifying multi-product solutions that combine professional services with other paid products, the base listing fee on the services component can fall all the way to zero. There are some qualifications. Channel Partner Private Offers can still carry an additional half-percent fee, and regional fees may also apply. The lower standard fee applies to new private offers, rather than retroactively changing existing agreements. The standard reduction was introduced earlier this year, and AWS highlighted the br

    The Buzz: CyberFOX buys Optimize365, Microsoft secures Windows AI agents, AWS cuts Marketplace fees
  2. 1d ago

    Flare launches partner program to take cyber threat intelligence downmarket

    John Williamson, CRO at Flare Cyber threat intelligence may traditionally be associated with large enterprises and dedicated security teams, but Montreal-based Flare sees an opportunity for MSPs and other channel partners to bring those capabilities to a much broader customer base. The cybersecurity vendor recently launched a new partner program as it looks to expand its channel business and give partners more support for selling — and building services around — its threat intelligence platform. In this edition of In The Channel, Flare chief revenue officer John Williamson and director of partner marketing Eunice Leung join us to discuss the company’s growing channel ambitions and where cyber threat intelligence can fit in an MSP‘s security portfolio. Eunice Leung, director of partner marketing at Flare For Flare, the opportunity starts outside the customer’s traditional security perimeter. While organizations have invested heavily in protecting their own infrastructure, attackers may be working with information found elsewhere, including exposed credentials, leaked data and other information available across the clear and dark web. That creates an opportunity for partners to help customers understand what attackers can see about them — and turn that intelligence into something actionable. Williamson and Leung discuss why Flare believes that opportunity is moving beyond the largest enterprises, how MSPs can make CTI accessible to customers that don’t have dedicated threat intelligence teams, and where the technology fits alongside existing security offerings. They also detail Flare’s new partner program, the resources the company is putting behind its channel push, and the opportunity for partners to go beyond simply reselling the platform by wrapping their own managed and professional services around it. We also discuss what kinds of partners Flare is looking for, how the company plans to work with its channel as it grows, and why the Canadian cybersecurity vendor sees partners as central to its next stage of expansion. Read Full Transcript Robert Dutt: Welcome to In The Channel from ChannelBuzz.ca, bringing news and information to the Canadian IT channel community for the last 16 years. I’m Robert Dutt, editor of ChannelBuzz.ca, and your host for the show. Today, we’re talking about a Montreal-based company that’s been growing quickly in the threat intelligence space and just formalized its channel strategy. Joining me are John Williamson, chief revenue officer at Flare, and Eunice Leung, director of partner marketing at Flare. We’re going to talk about Ignite, their new partner program, what it means for Canadian MSSPs and resellers, and why identity has become the central battlefield in cybersecurity. Let’s get right into it, my chat with John Williamson and Eunice Leung of Flare. John, Eunice, thanks for taking the time. Nice to chat with you. I appreciate it. John Williamson: Our pleasure. Robert Dutt: John, you guys have been growing for years now — triple-digit growth, 300-plus clients, half of them MSSPs. That’s pretty impressive. Why formalize the program now? What were you seeing in the business that made this the right moment to go from ad hoc or organic working with MSSPs to the more structured program? John Williamson: It’s a great question. I think a lot of it has to do with probably the most obvious talking point that dominates the airwaves these days, and that was AI. I think, as we have been for many years from our founding, when we were really focused on the dark web — at that time it was primarily Tor, or The Onion Router, and potentially fraud and identity theft, things of that nature — from that time, we’ve been focused as an identity-first cyber threat intelligence platform. And the reason for the release of this partner program at this time is this really coming to a head. We had made a bet that identity was going to be the last frontier, the last attack surface standing. And because of the way AI has progressed, it’s really made it much more dynamic for vulnerability assessments and scanning and exploitation. Technical barriers have been demolished and are continuing to be shortened. For us, though, the human and non-human identity element is still highly subject to risk. And so for us, we’ve kind of hit a particular, call it momentum, with the business. And as we’ve grown and scaled — 150 people, we’re growing very quickly, to your point, we’ve experienced double- and triple-digit growth — we felt that it was time to really formalize our channel partnerships. You’d mentioned, I know in our previous conversation, we were talking about how many MSSP partners we do have, which is anomalous. I mean, we have more than probably most. And I think that’s also a testament to how we’ve been dialing in our program since the beginning. It’s not like this Ignite program is ushering in anything revolutionary in regard to how we’ve developed products, how easy it is to use, how it can be deployed through channel partnerships, both resellers and MSSPs. But we’ve entered a point where we’re starting to really understand how those are optimized, how resellers can leverage the timing, the AI backdrop, to sell more of these types of products, how MSSPs can so easily integrate this and take advantage of identity remediation, and how, importantly, both of them can sell something very different. We’ve really, over the last — and this puts the end on your question — we’ve really rounded the corner on a promise that we’ve been making for quite some time. Threat intelligence up to this point has largely been, “Look at me. Look at me. You need to know this.” And it’s informational. One of our vision goals was, let’s put a closed loop on it. How about we tell you, “Hey, instead of you have an identity that’s been breached,” what if we could say, “Hey, you have an identity that’s been breached, and we validated against your live identity access management system, and we’ve prioritized it for automated remediation. Would you like us to take action? We can reset those passwords right now, or we can revoke that session.” That’s the last turn for us that’s really given us the impetus to say, “Let’s formalize a program. We’ve got a great product. We’ve been growing very quickly. It’s differentiated in the marketplace. Let’s now take a channel-first attitude and say, let’s really make sure that the program is designed for success and scale.” Robert Dutt: You mentioned the role of identity and the importance of identity figuring prominently in the decision to go this way, and it certainly maps with what I’m seeing both from you and your peers in the vendor community and in the halls at partner conferences this year. Identity is showing up so much more on the security side of things. I’m curious how you are seeing the kind of questions, the kind of sophistication your partners are coming at identity with, changing as it’s become more prominent and as the tools from yourself and others have evolved. John Williamson: It’s funny that it’s not as if it’s changed, it’s just that AI has industrialized it. It’s kind of one way of looking at it. The leverage — and as we’ve talked about, this is synchronous warfare. I mean, it’s AI against AI. It’s good versus bad. But what it’s done is it’s created the dynamics where attacks on identities have multiplied, primarily because of just the sheer scale. Phishing kits, infostealer kits, these things are being deployed en masse because of how quickly they can be developed. One of the things we’ve talked about, too, is how AI against AI — I think it’s now 70, almost 80%. I think it was 78% of all companies, this is kind of a global standard, have deployed AI in their security technology stack. So the ability to automatically remediate technical vulnerabilities and patch management and whatnot. Microsoft is releasing patches now, and there’s over 800, I think, in the last Microsoft patch remediation. That was as much as they used to do in a year, and you’ve probably seen these. And you can see the acceleration of AI. However, this industrialization of AI, particularly as it relates to credential attacks, number one, it’s making it much more scalable. And it’s really an area that’s actually increasing. That is the human element. Humans are still subject to phishing. They’re subject to infostealer malware by malicious links, and it’s happening en masse. But I think, importantly too, AI has had another effect, and that is that, in many ways, the whole concept of identities is shifting. Not only is it human identities, but I don’t know if you’re familiar with NHI, or non-human identities, the sheer magnitude of the proliferation of non-human identity. So again, these are things that are just starting to become evident. And I think that’s where — and again, I’m obviously Flare and I represent Flare — but I think Flare is particularly well positioned, obviously, for this. We’ve been planning for this for quite some time. And I think our channel program is really a way for us to be able to scale the distribution of our capabilities. Robert Dutt: Eunice, Ignite is positioned specifically around, as John said, both MSSPs and resellers, which are two different camps that increasingly — there’s some interchange and intermingling. The multi-tenant platform, obviously a big part of your pitch. When you were designing the program, what did you learn from the existing folks, those 300-odd MSSPs you’ve been working with, about what they actually need and want versus kind of the vendor-side lens of what the program should be? Eunice Leung: What our partners really wanted to see from us was what it would look like to have a scalable growth path with Flare, primarily. And so we built

    Flare launches partner program to take cyber threat intelligence downmarket
  3. 1d ago

    The Buzz: TD SYNNEX buys BlueStar, HPE launches ProLiant Gen13, and Cisco puts AI agents in Webex

    Today’s headline news for Canadian IT solution providers: TD SYNNEX agrees to acquire BlueStar: TD SYNNEX has entered a definitive agreement to acquire specialty distributor BlueStar, adding expertise in automatic identification and data capture, operational technology, mobility, RFID, point-of-sale, digital signage, networking, robotics and security. BlueStar has an established Canadian operation with locations in Montreal, the Toronto area and Vancouver, giving the transaction direct relevance to Canadian VARs serving retail, warehousing, logistics and other specialized markets. Financial terms were not disclosed, and the companies will continue operating independently pending regulatory approval. TDSynnex News HPE launches its first ProLiant Gen13 servers: HPE has introduced the first four ProLiant Gen13 systems, powered by sixth-generation AMD EPYC processors and aimed at workloads ranging from virtualization and analytics to AI inference and agentic AI. The lineup includes the 1U DL525, the GPU-dense DL585a and two OCP-based high-density systems, while iLO 8 adds automatic drive encryption, multi-person authorization and expanded post-quantum readiness. The first system arrives later this year, with the remainder following in 2027, and HPE is making the new generation eligible for its 90/9 Advantage financing program. Hewlett Packard Enterprise Cisco puts AI agents directly into Webex: At WebexOne, Cisco unveiled a broad set of agentic collaboration and intelligent-workplace updates, including Claude Managed Agents and collaborative agents that can join Webex spaces, meetings and calls to carry out multi-step work across Webex and third-party applications. Cisco is also introducing RoomOS 27, adding native Google Meet support alongside Webex, Microsoft Teams and Zoom, and extending workplace management through Cisco Cloud Control. Dialog, meanwhile, brings long-running AI-agent workflows and persistent customer context to the Webex customer-experience platform. Cisco Newsroom In Brief Canadian AI adoption outruns governance: New CPA Canada research based on responses from 5,000 Canadian CPAs finds organizational AI use rose from 5 percent in 2023 to 43 percent in 2026. But only 45 percent of respondents report having a formal AI policy, and 34 percent say their organization has implemented employee training or a formal AI strategy, leaving a potentially significant governance and advisory gap for technology providers. GlobeNewswire EfficientIP sees malware overtake phishing in DNS threat data: EfficientIP’s H1 2026 DNS Threat Intelligence Report, based on analysis of more than 150 billion DNS transactions per day, says malware nearly doubled from the second half of 2025 and became its largest DNS threat category. Daily malware activity climbed from 8 million hits in January to 32.6 million in April, while rising domain-generation-algorithm activity appeared earlier, suggesting DNS telemetry can provide warning before malware campaigns accelerate. EfficientIP TD SYNNEX takes KUKA robots to European partners: TD SYNNEX and KUKA have signed a distribution agreement giving partners access to KUKA autonomous mobile robots, initially in the U.K., France, Spain and Benelux. The distributor will provide enablement, technical training and demand-generation support, with collaborative robots, education packages and industrial software expected to follow; Canada is not part of the initial rollout. KUKA Switzerland BlueVoyant names John Hultman CRO: BlueVoyant has appointed former Druva chief revenue officer John Hultman as CRO, putting him in charge of global sales and revenue operations. Hultman’s previous roles include Americas sales leadership at Cohesity and nearly two decades at Dell EMC. Read Full Transcript Welcome to The Buzz from ChannelBuzz.ca, I’m Robert Dutt, today is Thursday, October 8, 2026, and here’s what’s happening in the channel today. TD SYNNEX has agreed to acquire BlueStar, a specialty distributor with a significant presence in Canada. BlueStar specializes in some corners of the channel that sit outside traditional broadline IT distribution: automatic identification and data capture, mobility, RFID, point-of-sale, digital signage, networking, robotics and security. And this one matters directly in Canada. BlueStar has Canadian operations in Montreal, the Toronto area and Vancouver, serving VARs in markets including retail, hospitality, warehousing, transportation, logistics and healthcare. For TD SYNNEX, the acquisition adds specialized expertise in technologies that increasingly connect traditional IT with physical operations. That’s particularly interesting as areas like warehouse automation, edge computing and robotics begin overlapping more heavily with the infrastructure and AI practices already familiar to solution providers. In fact, TD SYNNEX separately announced Wednesday that it’s taking KUKA autonomous mobile robots to partners in several European markets. Put the two announcements together and there’s a pretty clear direction of travel toward operational technology and physical AI. Financial terms for the BlueStar acquisition weren’t disclosed. It’s a definitive agreement rather than a completed deal, and the companies will continue operating independently while it goes through regulatory approval. HPE has introduced the first four systems in its next generation of ProLiant servers. ProLiant Gen13 starts with sixth-generation AMD EPYC processors and covers a pretty wide range of infrastructure. At one end is the DL525, a 1U single-socket server with as many as 256 CPU cores. At the other is the DL585a, which supports two EPYC processors and as many as eight double-wide PCIe GPUs for AI inference, model fine-tuning and other accelerated workloads. HPE is also introducing two dense Open Compute Project-based systems aimed at AI and high-performance computing. But the generational change isn’t only about feeding more AI into the data centre. HPE is adding new security features through iLO 8, including automatic self-encrypting drives, two-person authorization for high-impact administrative actions and expanded post-quantum cryptography readiness. Compute Ops Management also gets new power-management and low-touch onboarding capabilities. That’s useful territory for infrastructure partners because customers don’t necessarily need a dedicated AI server project to enter the Gen13 refresh cycle. Virtualization, analytics, databases and conventional infrastructure modernization are still part of the pitch, with AI capacity available as requirements evolve. Availability is staggered. The DL525 is due later this year, the DL585a in early 2027, and the two dense systems later in 2027. HPE is also making Gen13 available through its 90/9 Advantage financing program. And Cisco is turning Webex into a workplace not only for people, but for AI agents. At WebexOne Wednesday, Cisco announced that Claude Managed Agents are coming to Webex, along with collaborative AI agents that can participate directly in spaces, meetings and calls. The idea is that instead of someone privately asking an AI tool for help and then bringing the answer back to the team, the agent becomes part of the shared workspace. A user might ask an analytics agent for data inside a Webex space, then hand the result to another agent to update a presentation. Cisco says those agents will also be able to carry out multi-step work across Webex and third-party applications, with identity, security and governance controls around what they’re allowed to access and do. There’s also a substantial physical-workplace piece. RoomOS 27 will add native Google Meet support to Cisco collaboration hardware alongside Webex, Microsoft Teams and Zoom, while Cisco Cloud Control increasingly brings collaboration devices, networking and workplace intelligence into one management layer. And in customer experience, Cisco is introducing Dialog, designed to let AI agents maintain customer context and keep working across systems even after an individual conversation ends. For partners, the bigger story may be that Cisco isn’t treating collaboration, networking, room systems and AI as separate practices. It’s increasingly trying to make the workplace itself one managed technology environment. In Brief – CPA Canada says organizational AI use among respondents has increased from five percent in 2023 to 43 percent this year, while fewer than half report having a formal AI policy. EfficientIP says malware has overtaken phishing as the largest category in its DNS threat data, with daily malware activity quadrupling between January and its April peak. TD SYNNEX has signed a European distribution agreement with KUKA for autonomous mobile robots, backed by partner training and enablement. BlueVoyant has named former Druva chief revenue officer John Hultman as its new CRO. Full details and links in the show notes or the blog post. And if you haven’t heard it yet, Wednesday’s In The Channel introduces Kurt Mills, KnowBe4’s new channel chief, and looks at his plans for distribution, partner programs and the company’s MSP business. We’ll have more new conversations coming soon on In The Channel. That’s how we’re seeing the headlines today. I’m Robert Dutt for ChannelBuzz.ca, thanks for listening. Have a great day.

    The Buzz: TD SYNNEX buys BlueStar, HPE launches ProLiant Gen13, and Cisco puts AI agents in Webex
  4. 2d ago

    KnowBe4 channel chief Mills looks to bring greater focus, distribution to partner strategy

    Kurt Mills, senior vice president of Global Channel Sales at KnowBe4 Kurt Mills is just a few weeks into his new role as global channel chief at KnowBe4, but he’s already identified some significant changes he believes can help the company reach its next stage of growth. Mills, who most recently led global channels at Trellix, tells In The Channel that KnowBe4 has built a very large partner community, but one where a relatively small percentage of partners account for most of the business. His goal is to build a more focused, “segment optimized” channel, while making greater use of distribution to support the company’s long tail of partners. That will include changes to KnowBe4’s partner program and pricing structure, as well as greater field coverage. And Mills says that need to be present in the market applies particularly to Canada, where relationships with partners and MSPs can’t effectively be built remotely. MSPs are another area where Mills sees room for improvement. Asked what he would tell an MSP that knows KnowBe4 but hasn’t figured out how to make money with the company, his answer is direct: “We can do better.” In this edition of In The Channel, Mills discusses his plans for KnowBe4’s channel, what he learned transforming the partner business at Trellix, the company’s evolving distribution strategy, opportunities around AIDA and AI-driven security and partner services, and what needs to change to build a stronger MSP business. Read Full Transcript **Robert Dutt:** Hello, and welcome to In The Channel from ChannelBuzz.ca, bringing news and information to the Canadian IT channel community for the last 16 years. I’m Robert Dutt, editor of ChannelBuzz.ca and your host for the show. Kurt Mills is the new channel chief at KnowBe4, the company you probably already know for security awareness training, though they’d like you to think of them now as digital workforce security. Kurt’s held channel leadership roles at Trellix, Check Point, Mimecast, FireMon and Blue Coat. He’s basically done the full cybersecurity channel tour. He joined KnowBe4 about a month ago. He’s still very much getting the lay of the land, but he came in with a clear diagnosis: too many partners, too much non-standard pricing, not enough presence in the field. He’s also walking into an interesting company moment. Brian Palma has been CEO for about a year and a half. The company is owned by Vista Equity Partners, and the product story is expanding from phishing simulations toward AI agent security and a broader human risk platform. Let’s get right into it, my chat with Kurt Mills from KnowBe4. **Robert Dutt:** Kurt, thanks for taking the time. I appreciate it. **Kurt Mills:** Yeah, it’s a pleasure to be here, Robert. I always enjoy talking to our friends across the pond there in Toronto and look forward to, like I said, having a good hang today. **Robert Dutt:** We were discussing, dear listener, before we got into this, that Kurt is located in Chicago, and exchanged some of the Great Lakes weather dynamics, as it were, which are a constant topic of conversation. You’ve spent a long time in the industry, most recently running global channels at Trellix, where you made it to SVP. You’ve done Check Point, Mimecast, Blue Coat, FireMon. What was it about this moment and about KnowBe4 specifically that made you say, “Yeah, this is the next fit?” **Kurt Mills:** Yeah, well, let’s start by saying when you mention all those, it makes me feel a little bit old, Robert. But yeah, 25 years in the industry, and you learn a lot over that time. I will say it’s gone fast. But when I say you learn a lot, you learn a lot about the type of cultures, the leadership and the opportunities that you want to participate in. And for me, that means it starts with leadership. Having the opportunity to work with Brian Palma, our CFO and a few others here, again, was a really exciting opportunity for me. When you take that and you really look at the bones of this company and the opportunity to scale through a billion dollars, that’s what I like to do. I like to find companies with good bones, and maybe, Robert, they have just a lever or two that they need to pull to get to that next level of growth. And in many cases, that comes from the channel. **Robert Dutt:** How much of your job do you see as kind of preserving what works there versus looking for those opportunities to find the scale? I’m just curious because KnowBe4 has traditionally had that kind of identity as Stu’s company, with Kevin Mitnick as the face. Now Brian’s been in the chair for a while — I know a familiar face to you — and you’re coming in as channel chief. I’m curious where the balance between optimize for scale and maintain the founder’s company kind of sits for you right now. **Kurt Mills:** Yeah, well, like I said, they’ve done an amazing job as far as good bones, getting it to a certain point. But as you know, there are certain levers when we talk about channel where the growth started to slow down a little bit with the model they had, which was very much an inside-out type model. In the worlds that I’ve come from, you have to be present to win, and that’s a big part of it. But ultimately it is a balance, because I don’t want to distract from the great amount of energy this company has. It’s very infectious. I’ve had the opportunity to spend time in our Clearwater office as well as our D.C.-area office over the last few weeks, and it just blows me away how much energy there is through that place. It just kind of resonates. So I want to make sure I maintain that, with the idea of evolving the company in such a way from a channel perspective that we are really improving our coverage, bringing in certain best practices from the industry. I had a background in Mimecast, as you highlighted, and so I was used to working against or competing against KnowBe4 in the past. And I think what we did very well in my past days is make sure we had the right partners selling the right solutions to the right customers. But we also made sure we focused on the right partners and had the coverage, as far as being available and present from a channel perspective, and then really the enablement piece. Weaving those pieces in, if you will, Robert, to complement what was already going on here as a company. **Robert Dutt:** At Trellix, you were there in the aftermath of the big merger of McAfee and FireEye coming together, trying to build a unified channel, unified story out of those pieces. KnowBe4 is a very different kind of situation. It’s one product line, very strong brand recognition, but maybe the challenge is around building that enterprise channel over time. Without asking you to choose which of your children you love the most, which challenge do you prefer? **Kurt Mills:** Again, there are a lot of similarities between the two, believe it or not, although they came to where they are in very different fashions. In both cases, they needed to evolve as a company. One was taking two giants together and trying to integrate them, and there was a lot to do there. In the case of KnowBe4, they are adding solutions to be what we’ll call a fully integrated solution. But in both cases, it’s really a matter of: how do you do that? I wouldn’t say there’s a favourite one over the other. I’m here at KnowBe4 now, so that’s where I’m excited to be. But when all is said and done, it’s about how do you evolve a company and move a ship in the next direction. **Robert Dutt:** Speaking of that evolution, the language or the message of the company has shifted a bit of late. Security awareness training used to be the byline, the mantra. Now it’s much more about digital workforce security, securing humans and AI agents. For Canadian partners who are listening, what does that mean in terms of how they position you to their customers? Is this still kind of a compliance checkbox kind of sale, or do you see the conversation moving up the stack a bit? **Kurt Mills:** Let me start by going back to the whole Trellix thing. It’s always still about where, how and when do you win, right? When you’re talking to partners, the speeds and feeds are interesting, but they really want to understand how you win. And so that’s the really big component of what we’re trying to do here as we move the ship. As it relates to the Canadian partners, it’s how do you leverage all different types of routes to market? I know from working in Canada for many, many years, it’s not just about the reseller community. It’s about the MSPs, how you leverage the hyperscalers, for instance, like AWS and others, as well as distribution. And so there is an opportunity here at KnowBe4 to make sure we are leveraging all these different channel routes to market, those levers, if you will, to make sure we get to a point here, hopefully early in the new year, where we’re really focused on scale, leverage and growth. What I’m trying to do, Robert, between now and then is set the table to serve up dinner for our Canadian partners, as well as our partners globally. **Robert Dutt:** Speaking of the Canadian market, from what I can see, Canada represents around five percent of the customer base. The Canadian channel market, as you suggest, is very heavily MSP-driven. A lot of mid-market and SMB customers, obviously given the nature of the nation. How are you thinking about Canada? Is this kind of a mini-America market, or is there a distinct strategy, programs, maybe distinct distribution for Canada that fits because it is a little bit different than just take the American strategy and shrink it? **Kurt Mills:** Yeah, and again, I don’t know if there’s an American strategy versus a Canada strategy, but I’ll go back to my original comments: you’ve got to be present to win. Certainly in Canada, the relationships ar

    KnowBe4 channel chief Mills looks to bring greater focus, distribution to partner strategy
  5. 2d ago

    The Buzz: Frontline buys KL Software, WatchGuard expands AI security, and Dell tackles the AI data gap

    Today’s headline news for Canadian IT solution providers: Frontline Managed Services buys KL Software: Frontline Managed Services has acquired KL Software Technologies and KLoBot, adding Microsoft 365, Azure, Copilot, application engineering and legal technology expertise. The acquisition also becomes the foundation for Frontline Intelligent Applications, a new business combining advisory and implementation work with ongoing managed application services. WatchGuard expands AI security and secure access for MSPs: WatchGuard announced a series of Unified Security Platform updates at its IMPACT North America partner event. The changes include additional AI-driven security operations and the WatchGuard Access App, which brings AuthPoint identity and FireCloud secure access into a common client and management experience. Dell tackles the enterprise AI data problem: CRN reports on a major expansion of Dell Technologies’ AI Data Platform, including new agentic context capabilities, Nvidia-accelerated data preparation, multi-tenancy and managed PowerScale for Microsoft Azure. Dell sees partners playing a significant role in helping customers prepare, govern and integrate enterprise data for AI, with new certifications and training also planned. In Brief AWS puts partner credentials behind its $1 billion FDE push: AWS global channel chief Ruba Borno tells CRNthat new partner credentials will support the company’s $1 billion investment in forward-deployed engineering for agentic AI. It follows yesterday’s Buzz look at Anthropic’s $100 million investment in deployment skills, adding to the evidence that AI channel opportunities are moving beyond access to models and toward the expertise needed to put them into production. Kaseya puts human error atop its security concerns: Kaseya’s 2026 Cybersecurity Report found 68 percent of respondents consider human error their biggest security concern. The research is based on responses from 1,132 MSPs and IT professionals across more than 60 countries. Ricoh begins strategic review: Ricoh says it has launched a strategic review led by independent outside directors. The review comes as the workplace technology company reassesses its strategic direction and profitability. SignWell lands TD SYNNEX distribution: SignWell has signed a distribution agreement with TD SYNNEX that makes its SaaS and API-based electronic-signature platform available to TD SYNNEX resellers in the United States. The deal gives TD SYNNEX partners access to SignWell’s e-signature tools and developer APIs, although the agreement is explicitly U.S.-only. Read Full Transcript Welcome to The Buzz from ChannelBuzz.ca, I’m Robert Dutt, today is Wednesday, October 7, 2026, and here’s what’s happening in the channel today. Frontline Managed Services is expanding deeper into Microsoft cloud, applications and AI with the acquisition of KL Software Technologies and its KLoBot affiliate. The deal brings KL Software’s Microsoft 365, Azure, SharePoint, Copilot, application development and legal technology expertise into Frontline, an MSP focused specifically on law firms. Frontline is also creating a new business called Frontline Intelligent Applications around the acquisition. It will combine consulting and implementation with ongoing managed application services, covering everything from Microsoft platform strategy and AI readiness to document management and application modernization. KL Software says it works with more than 30 Am Law firms, while its applications are used by law firms and legal departments in the United States, Canada, the U.K., Europe and India. What’s interesting here is the shape of the acquisition. Frontline isn’t simply buying another MSP to add customers or geographic reach. It’s buying specialized application and engineering expertise and turning that into a managed-services practice. That’s another example of MSP consolidation moving beyond simply getting bigger. In specialized markets like legal services, the value increasingly comes from combining operational knowledge with deep expertise around the applications, cloud platforms and AI tools customers actually use. Financial terms weren’t disclosed. WatchGuard is expanding its Unified Security Platform with new AI security and secure-access capabilities aimed specifically at MSPs. The company announced the updates Monday at its IMPACT North America partner event in Nashville. Among the changes is additional AI-driven security operations, including capabilities designed to identify risky configurations and identity threats. WatchGuard is also introducing the WatchGuard Access App, which brings its AuthPoint identity technology and FireCloud secure-access capabilities into a single client, sign-in and management experience. WatchGuard’s pitch is that MSPs increasingly have to manage network security, endpoint security, identity and secure access as one operational problem rather than as a collection of separate products. That’s significant for service providers because consolidation only really pays off if it reduces technician workload. Putting more security products under one vendor logo doesn’t accomplish much on its own; integrating deployment, visibility and management potentially does. The new capabilities begin rolling out this month. We’ll have considerably more from WatchGuard soon on In The Channel, when CEO Joe Smolarski joins us to discuss how AI is changing both cybersecurity and the MSP security business. And Dell Technologies is going after one of the less glamorous but increasingly important problems in enterprise AI: getting a company’s data ready for AI to actually use. Dell is expanding its AI Data Platform with new capabilities around agentic context, Nvidia-accelerated data preparation, multi-tenancy and cloud storage, including managed PowerScale for Microsoft Azure. The idea is to give enterprises a more unified way to prepare, govern and make their data available to AI systems, rather than leaving information scattered across different platforms and formats. And there’s a substantial channel angle here. Dell executives tell CRN that partners have an opportunity to help customers prepare and integrate their data, build AI applications around it and then move those projects into production. Dell also plans new certifications and training around the platform. That’s important because the AI conversation is increasingly moving past simply having access to models and infrastructure. Customers have spent the last few years experimenting. Getting useful AI into production means dealing with the much messier questions of where enterprise data lives, whether it’s usable, how it’s governed and how applications and agents get access to it. For solution providers, that’s potentially a much larger and stickier services opportunity than simply supplying the hardware underneath an AI project. In Brief – AWS is putting new partner credentials behind its one-billion-dollar forward-deployed engineering push for agentic AI, following yesterday’s look at Anthropic’s investment in the same emerging deployment skill set. Kaseya says 68 percent of respondents to its new cybersecurity report rank human error as their biggest security concern. Ricoh has launched an independent-director-led strategic review of its global business. SignWell has signed a distribution agreement with TD SYNNEX in the United States. Full details and links in the show notes or the blog post. Later today on In The Channel, we’ll meet Kurt Mills, KnowBe4’s new channel chief, and talk about his plans for the company’s partner business. And if you haven’t heard it yet, Tuesday’s In The Channel looks at Barracuda’s approach to agentic AI and security with Brian Downey. That’s how we’re seeing the headlines today. I’m Robert Dutt for ChannelBuzz.ca, thanks for listening. Have a great day.

    The Buzz: Frontline buys KL Software, WatchGuard expands AI security, and Dell tackles the AI data gap
  6. 3d ago

    Barracuda to MSPs on AI security: Don’t wait for customers to ask

    Brian Downey, senior vice president, product management and marketing at Barracuda AI governance may not be at the top of every SMB customer’s agenda yet. Barracuda‘s Brian Downey argues that’s exactly why MSPs should be talking to them about it now. Barracuda recently expanded its AI security capabilities with tools designed to discover Shadow AI, monitor the use of AI applications and help prevent sensitive information from being shared with large language models. The company is targeting many of those capabilities at the under-resourced organizations and MSPs that make up its traditional customer and partner base. In this edition of In The Channel, Downey discusses the launch and new Barracuda research into the AI skills gap. One interesting finding: MSP-managed organizations were more likely than self-managed businesses to acknowledge gaps in their ability to secure and govern AI. Downey suggests that may reflect greater awareness rather than greater risk. Businesses already working with MSPs have recognized where they need outside expertise — and AI may represent the next opportunity for those service providers to demonstrate it. He compares today’s opportunity around Shadow AI discovery to the early days of dark web monitoring, when MSPs could show customers previously unseen evidence of their security exposure and use that discovery to begin a broader conversation. Barracuda is taking a similar approach by making Shadow AI discovery and other AI Data Security capabilities available to its customers, with paid capabilities adding monitoring and controls around how employees use AI services. For MSPs, Downey argues the opportunity goes beyond reselling another security product. AI discovery can open the door to conversations about governance, compliance and acceptable use, and potentially create a new recurring managed service. And his message to MSPs waiting until they’ve developed deep AI expertise is straightforward: their customers probably know even less. In our conversation, we discuss Barracuda’s approach to AI security, how MSPs can monetize the opportunity, the role compliance could play in driving adoption, and why Downey believes AI governance could eventually become another standard component of the managed services stack. Read Full Transcript **Robert Dutt:** Hello, and welcome to In The Channel from ChannelBuzz.ca, bringing news and information to the Canadian IT channel for the last sixteen years. I’m Robert Dutt, editor at ChannelBuzz.ca and your host for the show. AI security is quickly becoming another challenge for MSPs to help their customers navigate. But there’s an interesting wrinkle. Many SMB customers may not even know how much AI is already being used inside their organizations, what information employees are putting into those tools, and what risks that creates. Welcome to the fun world of Shadow AI. Barracuda believes that gives MSPs an opportunity to get ahead of the conversation. The company recently introduced new AI security capabilities aimed at discovering Shadow AI, monitoring how AI tools are being used, and helping organizations prevent sensitive information from finding its way into large language models. I recently caught up with Brian Downey from Barracuda to talk about the new offerings, some new research into the AI skills gap among mid-market businesses, and why he sees parallels between today’s AI governance opportunity and the early days of managed security. We also discuss how MSPs can turn visibility into an advisory conversation, why they shouldn’t wait for customers to start asking about AI governance, and whether securing AI could ultimately become as standard a part of the managed services stack as backup or MDR. Let’s get right into it, my chat with Brian Downey. **Robert Dutt:** Brian, thanks for taking the time. I appreciate it. **Brian Downey:** No, I appreciate it, Rob. It’s great to be here. **Robert Dutt:** You were the voice of the Barracuda One announcement back in March, and this feels like kind of the second chapter of that story. Can you maybe start by setting the scene a bit? What is AI Data Security from Barracuda? And can you talk about why you felt this is kind of a standalone product rather than a modular component within One? **Brian Downey:** Yeah, absolutely. Barracuda has been really focusing on the same thing for a long time, which is: How do we provide effective security services for the under-resourced organization? As we started looking at that two years ago, we saw the platformization happening around security, and we saw the value that people would get through increased information from a single vendor, being able to correlate more information, and also reduce the complexity of managing multiple tools. That’s what spurred Barracuda One. It was meant to take a lot of the different visibility that we had as an organization and pull that together in a single place. As we started doing that, we really started honing in on what people want to know about their security and what risks they have. They wanted to understand where their biggest risks were. What we’ve seen over the last 18 months is AI is one of those biggest risks. Being able to figure out what people are doing with AI, how they’re using it, and helping people with that was a really critical area where we saw a big opportunity and something we could help with. So it built directly on our Barracuda One story and really started providing different levels of solutions around that. They ranged from things that we saw as features to things that we saw as products. We recently released some that we put as features within Barracuda One for all of our customers. And what you’re hearing now is that we’ve also released a product set associated with this as well. **Robert Dutt:** You guys are calling this an industry first, and this is getting to be a hot space, obviously — AI-related security, governance, that whole thing. What are you guys first with here? Is it the capability? Is it who it’s packaged for? A little bit of both? What do you see as the place you’re planting the flag in that regard? **Brian Downey:** Yeah, absolutely. It’s an intersection of two things. When we looked at AI security, there are a lot of tools out there, and like I said, we have some natively in Barracuda One to give you visibility. What we really tried to focus on here was being able to support the entire AI security lifecycle. We wanted to be able to understand what was happening. We wanted to be able to put monitoring controls in place, and then actually allow people to use things and monitor that usage so we could respond if something happens. That entire security lifecycle view of AI is something that’s very rare. And when we looked at it in the space that we play in, really having a focus on the under-resourced — ensuring that you’re providing tools that are easy to use and buy and deploy, some of the things Barracuda has been known for within our customer base — it was that intersection that was really unique. That’s where we really saw it as the first of its kind. We haven’t seen anything else that’s really targeted at our types of customers that also looks at that full AI lifecycle. **Robert Dutt:** You guys released some research around the same time here, around the same kind of topic matter, talking about 38 percent of mid-market IT leaders today saying their teams lack the skills to secure the AI already in use. I was actually a little bit surprised the number was that low, quite frankly, given where we’re at with AI and Shadow AI and all that. Curious if you had any surprises in the data as you looked through it. **Brian Downey:** There were some surprises in the data. Like you said, I was actually more surprised that there were more organizations that had a level of maturity than I expected. I think that was a really good thing. It was a pleasant surprise for me, seeing that this was front of mind and that people were expecting it. I’d say through our conversations, though, the thing that really struck me was that even as we got into details around what people were doing, even people who thought they had taken steps to protect themselves, it’s just the overwhelming landscape of AI that usually ended up being the Achilles heel. We talked to customers who said, “Yep, we saw these risks, so we blocked ChatGPT.” But they’re not even thinking about the thousands of other applications that could have the exact same risk as ChatGPT. You can start to see the overwhelming nature of the problem in this space. That was a really interesting angle I hadn’t expected: that people would either minimize the scope a bit, or even if they saw the full scope, the overwhelming nature they felt around it. **Robert Dutt:** Here’s one that I thought was interesting. Your MSP-managed customers said they were more likely to report a skills gap than organizations handling it alone. I think it was around 40 percent versus around 30 percent. Is that a confession or is that a compliment? Do you think it’s a matter that MSP-managed customers are more aware of the situation or more exposed? **Brian Downey:** I think MSP-managed customers are more aware of their own situation. They’ve already taken the step to get support from an external vendor, being the MSP. So I think they’re aware that they have challenges and gaps, which I think is good. It’s always good to be aware of where your strengths and weaknesses are, where you need help, and what you want to do internally and externally. I think that’s where we saw a little more comfort in the admission from some of those customers. I’m not sure the numbers are as different among people who are managing themselves, but I think people might be a little more shy to bring that out as openly as people who have already started working with

    Barracuda to MSPs on AI security: Don’t wait for customers to ask
  7. 3d ago

    The Buzz: Broadcom explains Insight’s VMware removal, Schneider bids for PTC, and Anthropic invests in deployment skills

    Today’s headline news for Canadian IT solution providers: Broadcom explains Insight’s VMware removal: CRN reports that Broadcom attributes Insight’s North American deauthorization to unmet program requirements. Insight emphasizes its continuing cloud expertise. The new explanation follows September’s removal; partner and customer continuity remain the practical issues. Schneider agrees to acquire PTC: The definitive agreement values PTC’s equity at approximately US$22.6 billion, with enterprise value of US$23.7 billion. The combination links industrial engineering software with Schneider’s operational technology business. Closing is expected by Q3 2027, subject to approvals. Anthropic invests in deployment skills: Claude Frontier Academy carries a $100 million commitment and a target of 10,000 engineers by the end of 2027. Training includes assessments and a 12-week workplace residency. CRN’s interview with Steve Corfield explores the customer and partner strategy. In Brief – CData adds an AI control point: CRN reports that Connect AI Gateway is available through an early access program. The company says it governs agent connections, permissions and requests across enterprise systems; claimed productivity improvements remain vendor assertions. Helix becomes independent: Montagu has completed its majority acquisition of Helix through a BMC carve-out first announced in June. KKR retains ownership of BMC and a minority stake in Helix; the completion changes ownership without establishing new partner terms. Partner Tech earns checkout integration certification: The company’s public announcement confirms certification for integration with Verifone Commander. Partner Tech says retailers can add self-checkout alongside their existing payment, fueling and loyalty infrastructure, offering an integration opportunity for retail specialists. Augmentt outlines its Microsoft expansion: Ontario-based Augmentt is deepening Microsoft integrations and compliance capabilities, CEO Derik Belair tells CRN. This is an update on how the company is using its 2025 Series A funding, rather than a new financing announcement. Read Full Transcript Welcome to The Buzz from ChannelBuzz.ca, I’m Robert Dutt, today is Tuesday, October 6, 2026, and here’s what’s happening in the channel today. Broadcom is explaining why Insight lost its VMware resale authorization in North America, and the explanation puts partner requirements back in the spotlight. CRN reported Monday that Broadcom’s Laura Falko says Insight did not meet the program’s requirements. Insight previously described the decision as Broadcom narrowing its partner ecosystem. Responding to Falko, Insight says its VMware and hybrid cloud expertise remain part of its customer offering. The removal itself was reported in September. The new development is Broadcom’s explanation and Insight’s response. Insight has told CRN it will complete booked work and continue client-funded VMware and Cloud Foundation services through October 31. Its EMEA authorization remains in place. For partners here, the practical question is continuity: who can sell the next renewal, who can deliver the services, and what happens if those are different companies? A top partner badge does not settle those questions. Schneider Electric has agreed to buy PTC for 205 U.S. dollars a share in cash, valuing its equity at about 22.6 billion U.S. dollars. Including the enterprise-value calculation, the figure is 23.7 billion. Announced Monday, the agreement brings PTC’s product design and lifecycle software into Schneider’s energy and industrial technology business. Schneider says the combination will connect information about how products are designed and built with how equipment and operations perform. For integrators serving manufacturers, that creates a potential bridge between engineering systems and the operational technology on the factory floor. Delivering that bridge will depend on implementation, data integration and the eventual product roadmap. This is an agreement, not a completed acquisition. Closing is expected by the third quarter of 2027, subject to shareholder and regulatory approvals. Partners have time to assess the implications; the announcement does not establish new Canadian partner terms. Anthropic is committing 100 million dollars to Claude Frontier Academy, with a target of training ten thousand deployment engineers by the end of 2027. Announced Friday, the program starts with in-person training and a practical assessment. Engineers who pass then lead a real Claude project at their own organization during a twelve-week residency, with another assessment at the end. Initial participants include major consulting firms and enterprise customers. CRN’s interview with channel chief Steve Corfield makes clear that the academy is intended for customers as well as partners. The channel significance is the emphasis on delivering a working system: choosing a use case, getting through security review, and handing it over to the business. Those are services skills that a software license does not supply. Access is by nomination through an Anthropic account team or partner manager. The company lists initial cohorts in San Francisco, New York and London; it has not announced a Canadian cohort in this launch. In Brief – CRN reports that CData’s Connect AI Gateway is in early access, adding a control point for the models, tools and enterprise data used by AI agents. Montagu has completed its majority acquisition of Helix from BMC, making the service and operations management business independent while KKR retains a minority stake. Partner Tech says its self-checkout platform has earned Verifone Commander integration certification, allowing retailers to add checkout lanes alongside their existing systems. Augmentt CEO Derik Belair tells CRN the Ontario vendor is using its existing funding to deepen Microsoft integrations and help MSPs build security and compliance services beyond Microsoft 365. Full details and links in the show notes or the blog post. Later today on In The Channel, Barracuda’s Brian Downey joins me to discuss Shadow AI, protecting sensitive data, and how MSPs can turn AI governance into an advisory opportunity. And if you haven’t heard it yet, BeyondID’s Arun Shrestha is on In The Channel discussing the combination with Toronto’s KeyData Cyber, Okta’s services opportunity, and identity security for MSPs. That’s how we’re seeing the headlines today. I’m Robert Dutt for ChannelBuzz.ca, thanks for listening. Have a great day.

    The Buzz: Broadcom explains Insight’s VMware removal, Schneider bids for PTC, and Anthropic invests in deployment skills
  8. Oct 1

    Oktane 2026: BeyondID CEO Arun Shrestha on KeyData Cyber, AI agents, and the identity opportunity for MSPs

    Arun Shresthra, co-founder and CEO of BeoyndID In The Channel caught up with Arun Shrestha, co-founder and chief executive officer of BeyondID, at Okta’s Oktane 2026 conference in Las Vegas. Shrestha has been part of the Okta story since 2012, when Okta’s co-founders recruited him to build the company’s customer success and professional services organization, and he founded BeyondID in 2017. The company is one of fewer than three dozen Okta Apex partners worldwide – the top tier of Okta’s partner program – and a repeat Okta partner of the year. Last year, Toronto-based KeyData Cyber acquired BeyondID, creating one of North America’s largest pure-play identity security services firms. Shrestha laid out the thesis: KeyData brings two decades of Canadian market credibility, including deep Canadian federal government work, while BeyondID brings the US-market Okta practice, with more than 500 joint Okta customers before the deal. BeyondID remains the brand for the US market and Okta-focused work. Shrestha says Okta’s move to accelerate the transition of professional services to partners follows the partner ecosystem playbook of Microsoft and Amazon, and notes that 20 to 30 percent of BeyondID’s business already flows through the reseller channel, with partners including SHI, CDW, Carahsoft and World Wide Technology. For MSPs wondering whether identity is their business, his advice: pick one or two practice areas and get really good at them, and pick a top platform to build on. The conversation also dug into Okta for AI agents and non-human identity. Shrestha’s pitch to MSPs: treat AI agents like employees. “If the agent’s going rogue, we know how to shut it down. Just like the employees, if they misbehave, you’re out the door. Same with the agents.” Read Full Transcript Robert Dutt: Hello and welcome to In The Channel from ChannelBuzz.ca, bringing news and information to the Canadian IT channel community for the last sixteen years. I’m Robert Dutt, editor of ChannelBuzz.ca, and your host for the show. Today, we continue our coverage of last week’s Okta Oktane conference in Las Vegas, and my guest has been part of the Okta story almost from the beginning. Arun Shrestha is co-founder and chief executive officer of BeyondID, one of fewer than three dozen Okta Apex partners worldwide – the top tier of Okta’s partner program – and a repeat Okta partner of the year. Arun was recruited by Okta’s co-founders back in 2012 to build out the company’s customer success and professional services organization, before striking out on his own to found BeyondID. Last year, BeyondID was acquired by KeyData Cyber, a Toronto-based identity security firm with deep Canadian federal government credentials, making the combined organization one of the largest pure-play identity security services firms in North America – and a lot more Canadian than your average Okta Apex partner. That matters for our audience, because Okta is accelerating the handoff of professional services to the channel, and every client of every MSP is starting to deploy AI agents that need identities of their own. We’ll talk about the KeyData combination, what Apex actually means for a partner, what Okta’s partner-first shift looks like from an Apex partner’s seat, and what MSPs should be doing about identity – including identity for AI agents – in the years ahead. Let’s get right into it, my chat with Arun Shrestha. Robert Dutt: Arun, thanks for taking the time. I really appreciate it. I know it’s probably a busy week here at Oktane. Arun Shrestha: Pleased to be here, Rob, and very excited to be sharing a few thoughts on this. Robert Dutt: Before we started recording, you shared a little bit of your journey, and I want to get into the elevator pitch for BeyondID. But before we even get into that, can you tell us about your long-standing history with Okta? Arun Shrestha: Absolutely, pleasure to. Okta, to me, is like a passion and something you want to pursue in life. I found a North Star, which is Okta – what Okta’s done. I started my journey of 30-plus years back in San Francisco, in the space of technology, and I worked for many companies like Microsoft and Oracle. I was recruited by the co-founders of Okta to help build customer success and professional services back in 2012. 2012 was the year where nobody thought identity in the cloud was the normal thing, and I was brought on to help, in fact, one of the Fortune 500 customers of Okta – the first one – to help them migrate off of CA SiteMinder to Okta. That’s how my journey started. Along the way, I brought on many folks that I worked with in the past who believed in me to come join this small startup that was funded by a16z and others. I’m really glad that the co-founders found me, and I was able to be part of that journey. It’s been a phenomenal experience and journey for the last 15, 16 years. Robert Dutt: And partway through that journey, you decided to not be part of Okta as an organization anymore, and you set up a partner organization. For those – especially our audience of MSPs and resellers who may not be familiar with BeyondID – can you give me the elevator pitch? What do you actually do, who do you do it for, that kind of thing? Arun Shrestha: Absolutely. The name, by design, is BeyondID – it’s supposed to be: take the ID, and take the imagination to a different degree. What BeyondID does is really simplify the ways companies need to adopt modern technology and architectures around identity management, so they can move faster, connect with all technologies, and build very secure and resilient infrastructure for not only what’s today, but what’s in the future – including where we’re all heading, which is agentic. Robert Dutt: You guys are one of less than three dozen Apex partners worldwide, the top tier of partners, and you’ve been partner of the year multiple times. For the uninitiated, what does Apex actually mean in practice for you as an organization, and why does it matter to customers? Arun Shrestha: I think about this as a practitioner: any craft that you want to be absolutely the best at, you have to practice everything. One of the things Okta did in the early years – especially the last several years – is establish various tiers of partnership based on the merits of what partners have accomplished. The Apex partnership means not only that you’re able to materially help customers and make sure they’re successful; it’s actually helping Okta grow this business and spread Okta’s greatness across a lot of companies. It includes things like the experts who know Okta inside and out, and how we can really help companies navigate through very complex stuff into simplifying what Okta does best with the identity platform. And it also ties back to how many customers are successful over a period of time – we measure all of that. So if you achieve a couple of these critical metrics, you get to be Apex. Robert Dutt: Last year you guys came together with KeyData Cyber out of Toronto, itself an identity security firm. How has that changed your go-to-market in Canada? Are you building out a stronger Canadian presence for the BeyondID side of things, or is it more about combining the capabilities across the board? Arun Shrestha: A bit of many of the things you’ve just mentioned. I’ll tell you two or three basic theses of why the private equity firm that owns us actually decided that this would be the right merger. In Canada, KeyData has been around for over 20 years. They’re a well-established organization, they’ve done exceptionally well in the Canadian market, and they’re a well-known brand in Canada. But going to the US is a very different ball game, as you know. And then, Okta is obviously the biggest vendor in this space when it comes to the pure identity play and the US market. So we were looking at partnering and bringing in an organization that had a strong presence in the area that they are growing, but they need to grow faster, with Okta being that core play in the market in the US. We actually represented all of that. Prior to the acquisition, we had already done business with over 500 joint Okta customers, so that gives you the size and scale of what we’ve done and accomplished – and that goes back to the Fortune 10 companies down to the smallest company you can probably find. So it made sense for KeyData to make sure that there is a good merger of an organization that brings both the Canadian and US market – the North American market. I believe that for what we do, in a specialized market, we’re one of the largest in the space of what we do now. So it sort of remains BeyondID in the US market. Robert Dutt: That’s correct. KeyData obviously has quite deep Canadian federal government credentials. Is there spillover between that and what you guys do, both in federal government stateside as well as enterprise and mid-market? Arun Shrestha: Yes. Clearly, we play in various market segments, as well as industries – obviously government, as well as highly regulated industries like financial services, healthcare services, federal government, state and local government. We offer services to all of those, and we have practices across those various segments, because we realize we need to specialize and understand the customer base in every industry, including federal government, in terms of what identity management could mean. So we’ve got those practices built out. BeyondID is a brand within KeyData Cyber that is solely focused on Okta. Robert Dutt: For a Canadian MSP who’s listening to this – do you guys have a channel play? Is there an opportunity for co-delivery partners in Canada, or is it primarily a direct-to-enterprise kind of market for you guys, hand in hand with Okta? Arun Shrestha: We’re probably one of those – I would call it a Swiss Army k

    Oktane 2026: BeyondID CEO Arun Shrestha on KeyData Cyber, AI agents, and the identity opportunity for MSPs

About

Cutting through the noise for Canadian VARs and MSPs