Joe Sykora, CEO of Coro The debate between platform consolidation and best-of-breed point solutions has been running in the MSP community for years. But with AI-driven attack volumes up three to four times year over year, and clients unwilling to absorb price increases, the operational stakes are getting harder to ignore. In this episode of In The Channel, host Robert Dutt speaks with Joe Sykora, chief executive officer of Coro, the Chicago-based cybersecurity platform built for lean IT environments and the MSPs who serve them. Coro’s platform spans 14 security modules – endpoint, email, network, cloud app security, data protection, and more – running on a single agent and a shared data engine. The company is 100% channel, past Series D, and recently recognized by Gartner as a representative vendor in the emerging Workspace Protection category. Sykora brings an unusual background to the CEO chair. He started out running solution provider businesses before moving vendor-side, holding channel leadership roles at Fortinet, Bitdefender, and Proofpoint. One of his first acts as CEO was eliminating Coro’s direct sales motion entirely. The conversation covers Coro’s core consolidation argument – and what Sykora calls the “Frankenstein stacks” that result from stitching together point solutions via API integrations – alongside the platform’s 92-93% automated alert remediation rate, with some partners pushing toward 96%. It also gets into harder territory: Sykora acknowledges on the record that not every Coro module is best in class, and addresses the vendor concentration risk that comes with consolidating that much of a client’s security posture in one place. The episode closes on Coro’s recently launched MCP server integration, which brings security operations directly into AI agent workflows, and the question Sykora took from RSA: is it cybersecurity with AI protection, or AI with cyber? Read Full Transcript Robert Dutt: Hello and welcome to In The Channel from ChannelBuzz.ca, bringing news and information to the Canadian IT channel community for the last 16 years. I’m Robert Dutt, editor of ChannelBuzz.ca and your host for the show. The question of how to build a security stack for small or mid-sized businesses, or for the MSP serving one, hasn’t gotten any simpler. If anything, it’s more crowded than ever. Best-of-breed point solutions for every threat vector, each with their own agent, their own dashboard, and their own data silo. There is no such thing as a single pane of glass in security. My guest today has a different answer, though. Joe Sykora is chief executive officer at Coro, an 11-year-old cybersecurity platform purpose-built for lean IT environments and the MSPs that serve them. Coro covers 14 security functions—from endpoint to email to network, cloud app security, and data protection—under a single agent and a single data engine. The company is 100 percent channel, past Series D funding, and has made no secret of its ambition to be a platform that consolidates what Joe himself called the “Frankenstein stacks” that so many MSPs have been managing for years on the security side. What makes him an interesting person to have this conversation with is that he isn’t coming at it from the product or the engineering side. He started out running solution provider businesses in the 90s, exited two of them, and spent the better part of 15 years in channel leadership roles at Fortinet, Bitdefender, and Proofpoint before taking the CEO chair at Coro last year. Let’s get right into it. My chat with Joe Sykora. Joe, thanks for taking the time. I appreciate it. Joe Sykora: Robert, great to see you. Robert Dutt: You know, most cybersecurity CEOs come up through product, through engineering, or through finance. Your background involves running a solution provider before going vendor-side. I’m curious what the industry looks like from a CEO’s seat when your formative years were on the partner side of the table. Joe Sykora: Sure. Well, it’s been an exciting ride. It started back in the 90s and I’ve been very, very fortunate. I was one of the early adopters. The first company I had was an infrastructure company; we quickly pivoted to security and became a managed security provider in the 90s. I still have a lot of friends that are still out there doing it, but I was one of the early adopters. I was very, very fortunate to be able to exit both of those companies and that got me to the manufacturer side. I started with a little-known company—at the time it was unknown, but most people now know Fortinet. I joined them in 2010 during their IPO and, man, I like to say the rest is history. My role at Fortinet was a little bit different because I did cover primarily the channel, the partner side, which was a huge, huge part of Fortinet’s success. But I also got to dabble on a few other things like operations and the marketing piece. In fact, when we made some of those acquisitions, I got to be the interim CEO as we integrated those in. I never lost my entrepreneurial spirit; if there’s a problem, I like to fix it. I don’t like to just say “that’s the way it’s always been.” I always challenge things no matter where I go. I have the attitude where if the garbage needs to be taken out, I’ll take out the garbage too, right? Because that’s the way I was brought up—very humble beginnings in Ohio. I grew up in farm country, believe it or not. I was one of the first children to get to play around with a Mac and programming in fourth grade. So at a very early age, I got a little bit addicted to computers. The seat right now as CEO is what I’ve been brewing myself for throughout my career. I’ve led go-to-market strategies and I’ve been involved very much on the backend. When this opportunity came up, it was something that I felt I was ready for. I’ve put in a lot of international experience over the last 10 years or so, meeting with partners all over the world and really listening to the different needs they have. But more importantly, I love the channel. I came from the channel. So for me to be able to run a 100 percent channel motion is very unique. One of the first things I did as CEO was kind of kill the direct motion. We had a mixed model and it didn’t make sense for us. So it’s exciting. Of course, there’s other challenges—I spend a lot of my time with boards and financial institutions now—but I still love getting in front of the partners and talking about our story and how we’re different. Sometimes it even leads to giving advice on how to exit companies and what’s important there. Robert Dutt: No doubt a topic of interest for the MSPs listening. For you guys, the platform consolidation pitch is a big one and it’s compelling on paper. One agent, one dashboard, 14 modules. But there’s always that MSP who comes up and says, “All right, the jack of all trades, master of none thing.” How do you answer an MSP who says, “I see your point, but my EDR vendor or my email security specialist is doing better in that particular lane than what Coro can do”? What’s the message to that skeptic? Joe Sykora: Yeah, well, I think things have definitely changed. Again, this is coming from a guy who’s been in cyber now for almost 30 years. For the partners out there, everyone has their tech stack. This isn’t anything new. When I was an MSP, my pitch was “you can’t afford an enterprise platform—not only the licensing, but really managing the platform.” I’m sure a lot of people out there today are doing the same thing. Coro’s different because of the advancements of using AI. I know that’s a topic—I think last week I said we should make a drinking game out of anytime anyone says “AI.” But AI is moving faster than anything we’ve seen out there. Coro is not a new company; we’re 11 years old. Coro was purpose-built for the MSP and SMB—or “Lean IT,” as I like to refer to it. We help operationalize things. Coro is not about looking at each individual module and saying “I have it, I don’t have it.” It’s about putting it all in one agent to stop agent sprawl and putting it all in one dataset. Because it is all our own IP that we spent the last 11 years developing, having clean data going into it is so important. That’s why we’re seeing, on average, about a 92 to 93 percent automation rate of correlating and then remediating automatically. That’s pretty good, and it’s getting better. A year ago we were in the high 80s; we’re now closing in on the mid-90s. I was talking to a partner the other day who was seeing about 96 percent. What that translates to is operational efficiencies. That is time back, and that is money to you as an MSP. We know that the attacks aren’t slowing down—in fact, we’re seeing about a 3X increase already this year. The bad guys are also using AI. If we want to go head-to-head versus your endpoint and EDR vendor, we can. We still test out at five nines. The difference is it’s simpler. I’ve talked to many “enterprise” MSPs who are very proud of their stack, and that’s fine. But then they look at someone like Coro—100 percent channel, guaranteed margins, a lot of support—and it makes sense. The “aha” moment is when they see the operational efficiency of an analyst being able to look at 100 or more clients instead of 20 or 30. We did introduce Coro AI within the product for MSPs who want to look at reporting across all their customers. We’re not an NDR, but we give you NDR results. If you want to do some threat hunting and see what’s going on, you just talk to our AI. The concept is the same as the old UTM or Next-Gen Firewall days, except now I have more modules and I’m in the cloud. And we can coexist. If you have a solution in place, that’s okay. We are a very lightweight client. You can get the results and then, when it comes up