Find partners
ChannelBuzz.ca

ChannelBuzz.ca

Hosted by ChannelBuzz.ca

Episodes

75

Latest episode

Aug 2026

Language

EN-CA

About the show

Cutting through the noise for Canadian VARs and MSPs

Listen to episodes

60 recent
August 13, 202630 min

Logging in, not breaking in: Blackpoint Cyber’s Wil Santiago on the 2026 threat landscape

Wil Santiago, Wil Santiago, chief security and trust officer at Blackpoint Cyber Wil Santiago, chief security and trust officer at Blackpoint Cyber, joins In The Channel to discuss the findings of the company’s 2026 Annual Threat Report – research grounded in thousands of real incidents investigated by Blackpoint’s security operations centre, not surveys. The headline finding: attackers are no longer trying to break in. They’re logging in. Using stolen credentials and commodity remote management tools, threat actors are walking through the front door, hiding in plain sight, and operating with system-level privileges – sometimes for days before anyone notices. Santiago walks through the key trends the SOC identified across 2025: ClickFix and fake CAPTCHA campaigns accounted for more than half of all identifiable incidents, with attackers abusing trusted infrastructure including Azure Blob storage and Cloudflare to deliver payloads. RMM abuse showed up in roughly 30 per cent of triaged incidents – threat actors installing their own version of the same tools MSPs use legitimately, then living off the land with god-mode access. And Adversary-in-the-Middle attacks are now routinely hijacking authenticated sessions even when MFA is in place, by abusing OAuth token handling. The conversation also covers Blackpoint’s detection philosophy: behavioral context over malware signatures. Understanding what normal looks like in an environment – who uses what tool, at what time, from where – is what allows the SOC to catch attackers before they act. It’s a philosophy that is producing results: Blackpoint disrupted 56 per cent of incidents before a payload was ever deployed. Santiago’s closing recommendation for MSPs is straightforward: start with an RMM audit. Know every remote management tool deployed across every endpoint and server you manage. You cannot protect what you don’t know exists. The 2026 Annual Threat Report is available for download on the Blackpoint Cyber website. Read Full Transcript Robert Dutt: Hello and welcome to In The Channel from ChannelBuzz.ca, bringing news and information to the Canadian IT channel community for the last 16 years. I’m Robert Dutt, editor of ChannelBuzz.ca and your host for the show. Wil Santiago is Chief Security and Trust Officer at Blackpoint Cyber, an MDR provider whose SOC monitors and responds to threats in real time across a large base of MSPs and their clients. And unlike a lot of threat research that’s survey-based or derived from external reporting, what Blackpoint publishes comes from live incident data, thousands of actual threat responses they’ve worked through in the SOC. Their 2026 annual threat report has a thesis that cuts right through it. Attackers are no longer trying to break in, they’re logging in, using stolen credentials and legitimate IT tools, the same RMMs, the same cloud platforms that MSPs rely on every day, to walk through the front door, hide in plain sight, and work their way towards payday. It’s a theme we’ve been tracking at ChannelBuzz.ca. If you caught our conversation with Tony Anscombe from ESET, that one dug into the mechanics of how MSP tools are being weaponized against the very clients they’re supposed to protect. This conversation is the data layer behind that story, and the detection philosophy that Wil and the Blackpoint team have built to counter it. Their SOC is disrupting 56% of incidents before a payload even deploys. We talk about how. Let’s get right into it. My chat with Wil Santiago. Wil, thanks for taking the time, I appreciate it. Wil Santiago: Thank you, Robert. Robert Dutt: For people who know Blackpoint primarily as an MDR provider, but maybe haven’t dug into the research side, can you give us a quick sense of what your SOC is actually seeing day to day? When you say this report is based on thousands of real incidents, what does that mean in practical terms, in terms of how you gathered this data? Wil Santiago: That’s a great question, Robert. It really starts at the core of what we focus on at Blackpoint Cyber. In 2025, we focused a lot of our detection efforts in the cloud endpoints, but what we realized is that at the core, at that identity layer, that’s the most important thing. But what we’re protecting at Blackpoint is the identity. What we observed in 2025 is this interesting shift where, yes, there’s vulnerabilities, there will continue to be vulnerabilities. However, threat actors don’t necessarily need to weaponize those vulnerabilities to gain access into an environment. They’re not really targeting customers or companies with any specific new zero-day technology or exploits that are novel. They’re just logging in using stolen passwords. We’re still at that pivotal point, but we’re still talking about the same things we’ve been talking about, password reuse, making sure you’re protecting yourself from phishing emails, so on and so forth. But the reality is that threat actors are getting in. They’re stealing credentials and they’re using legitimate tools to just log in, walking through the front door. Robert Dutt: Yeah, the headline from the report was very catchy with the attackers are no longer trying to break in. They’re just logging in, as you say. And that framing echoes what we’ve seen in other reports elsewhere. People are calling 2025 the year of the abuse of trust in terms of security trends, but your numbers are operational and not survey-based. I’m curious what trusted compromise looks like from where you sit. Is there really a shift away from what you were seeing a couple of years ago or three years ago, or has this always been the playbook and we’re only now measuring it properly? Wil Santiago: Yeah, so if I compare back to, let’s say, 2022, I think we at Blackpoint would still see a trend, the threat actors gaining access into an environment, usually using some type of exploit at that time. You can point to a number of Microsoft Exchange exploits that happened during that time. The Hafnium group was doing a lot of Exchange exploits. The reality is there came a certain time where we were detecting Cobalt Strike, a malware commodity tool, every single day in Blackpoint Cyber’s SOC. And then eventually it became once a week, and then it became once a month. So then we started to think, well, what’s happening with the shift of tactics with the threat actors? And what we found is instead of installing Cobalt Strike, they started to install legitimate IT tools. And that’s the trust component. When they’re installing tools that you use internally, they now can abuse those tools the same way that you use those legitimately. And so we have these threat actors that not only are abusing legitimate tools, but like I said, they’re abusing legitimate identities. So when you have what I call the keys to the kingdom, the passwords, I am you. I am now Robert, for all intents and purposes for this sort of webinar. I think the interesting part that we’ve seen at Blackpoint is that threat actors have really, really focused on leave-behinds. And those leave-behinds are commodity remote management tools. Why do they do that? Because EDRs don’t know how to detect them as malicious, right? These are legitimate IT tools that are being used to service MSPs and their customers. And a threat actor just installs their version of the same exact tool that you’re using legitimately. Right? And so the trust component is you go to review your assets and you see ScreenConnect installed in your environments because you use ScreenConnect, right? But then when you start taking a closer look, you start to realize, wait a second, there’s four different ScreenConnect IDs on this one machine. Now we have a more of a problem, right? And so the attack is a little bit of an invisible signature detection because it’s an authorized tool, right? And so we really have to get to this layer of identifying threat actor activity with behavior context. If you’re an AnyDesk shop, then why do you have TeamViewer installed on your file server that’s publicly facing, right? Let’s start to ask those questions and dig into that a little bit. Robert Dutt: Your SOC found that fake CAPTCHA and ClickFix campaigns accounted for, I think it was 50-odd percent of identifiable incidents. That’s a majority of attacks being driven by a technique that essentially requires the victim to step on the link to execute it themselves. Why is that scaling so fast right now? And especially for an MSP who tends to think, you know, my technicians are too smart to do that. What’s kind of the honest answer for what they need to be looking for and protecting against? Wil Santiago: Yeah. And, you know, ClickFix is such an easy attack when you really get into the root of what it does. But it starts with social engineering. You’re enticing someone, again, just like with phishing, to visit something that you’re going to tell them to do an action. And most of the time, they’re going to do that action. Now, why this is so effective is we’re seeing techniques that really enable the threat actor to deliver the payload. And how do they do that? Search engine optimization, right? These SEO links at the top, when you go look for an OBS installer, because you need your camera to look well, or you get a Google sponsor result. Threat actors are just buying those sponsored results and delivering their payloads on there. You click on it thinking you’re going to download OBS, and then it tells you, hey, wait a second, you have to make sure that you are human. Verify that we’re used to verifying we’re humans to download something. So we go and we click it. But then it says, hey, open up your Windows Run command and maybe run this command on us, on your computer for us. And what happens? Threat actors go and they put the commands on a website. They have this watering hole spread out all throughout infrastructure that’s globally distributed. Google, Microsoft, all these sort of cloud infrastructure hosting providers that exist. Threat actors use those. So when you’re looking at your firewall logs and you’re seeing your internal team going to Microsoft.com, hey, it’s Microsoft, right? But the reality is, it’s likely an Azure Blob site that’s just being hosted on Microsoft, that is a threat actor that’s actually hosting it. And so they’re abusing that trust function to say, hey, you need this OBS installer. You Googled it. I didn’t tell you to go Google that. You were the one that did that. And then they found my link, which I posted a malicious payload there. And so again, that abuse factor is all the things we’ve taught our employees, our customers, our MSPs to do, right? Go to Google, make sure you identify the link. Make sure you look for Microsoft. Make sure you see the end of a URL or domain. Validate that. Well, the adversary goes, okay, they want to play that game. I’m just going to host this on Cloudflare. And now we’re back to this gate where now someone clicks on something. Well, what’s this Cloudflare? That’s a legitimate service. I know that to be true, right? It’s very true. The reality is the infrastructure is very, very easy to set up. And it doesn’t require a lot of action. It just requires someone to take a command and put it on their machine. And all the background work happens in the background, right? And so beyond that, we used to see a lot of threat actors use this sort of technique to download malware onto machines. But again, going back to what I mentioned about RMMs, now they’re just downloading an RMM. And that just looks like a legitimate process to an EDR. Robert Dutt: Right. So for an MSP, especially when training or making sure their technicians are aware, is it just as simple as making sure they’re aware of this threat landscape and this wrinkle in it? Or is there something more that’s sort of the advice there on how to protect yourself as best you can? Wil Santiago: That’s a great question. And really, you know, I would say any MSP watching this show, starting today or tomorrow, the first thing that I always tell people, audit your RMM inventory. Asset inventory is the number one thing that customers should be doing, right? You cannot protect what you don’t know exists. And so every single remote management tool that’s deployed across every endpoint you manage, every server you manage, you need to audit those, right? Like you’re giving direct access to a system. And most of the time, those RMMs run in the system context, which means they have the permissions and privileges of any admin, right? And now you have this adversary that has a foothold. They can deploy tools using admin privileges and permissions. So you have to audit your RMM inventory, right? Making sure that you understand what’s happening across those production servers. And forcing MFA, that’s a big one. We see a lot of incidents that source from RMM abuse because they log into the MSP’s RMM console, the cloud-based consoles. Some of those don’t have MFA involved. Again, keys to the kingdom, MFA everywhere, that needs to be a reality. Then we need to start moving into what I call more resilient engineering, right? Conditional access policies, preventing individuals from logging in from untrusted sources, locations, right? There’s ways that you can lock down access to an RMM and assume a threat actor is able to steal credentials because they maybe installed an info stealer on a user’s machine, stole their browser credentials. They reuse the same credentials for Gmail that they do for their corporate environment. Well, now a threat actor just perusing finds their credentials and says, “Oh, I’ve got IT Glue permissions now. I’m going to go log into this and restore all these configs in IT Glue or whatever tools out there.” Well, now the threat actor has access to that. And so that’s how they’re pivoting across these environments. They’re going from cloud to on-prem, on-prem to cloud. One of the things that we caught at Blackpoint recently, and this was a really cool response, but the threat actor compromised the cloud environment first. They then took that cloud access, deployed an RMM using Intune to the devices, and then they used that on-prem access to go to those machines and do their own work directly from that console. I called it overkill. They didn’t have to do that because they had the cloud environment. But because they did that, that sort of prompted this investigation for this MSP to approach us and say, “Hey, we believe something is happening. We investigated and quickly saw the Intune process was the responsible process for deploying some of this malware. So we told them, “Hey, deploy our cloud response suite. We want to understand what’s happening in your cloud.” And sure enough, seven global admins were compromised. So again, limiting scope is important here, right? Least privilege. Why do we have so many people with admin privileges and permissions? I think there’s 192 admin roles or something like that in Microsoft, but we default to just, you get global admin, you get all the permissions. And so now an adversary compromises a Microsoft 365 tenant. Well, now they have the permissions of a global admin. And unfortunately for us, when we shifted from the on-prem strategy to the cloud strategy, we just started pushing everything in the cloud and we say, “Oh, it’s fine. It’s in SharePoint.” We didn’t realize though that that’s only being protected by a password and an MFA token, both of which can be stolen, right? So the protection is not really there. That’s why we have to move to that resilient engineering. And so it’s moving from that reactive alerting to that posture alerting, right? Why is someone trying to log in from France? We have nobody in France. Robert Dutt: So your report showed almost a third of triaged incidents involved RMM abuse. And that’s something, that kind of trend line is something that we’ve seen in other reports. You know, one of your peers is talking about a 200 plus percent spike in abuse of RMM in attacks. I’m curious, especially since you’re sitting in the SOC there, what does RMM based intrusion actually look like in the SOC here? You know, I’m guessing curious, is there a moment where it’s genuinely hard to tell, you know, is this actually a tech doing a routine task or is this an attacker? And if so, what kind of breaks the tie and causes you to go, “No, no, that’s not right.” Wil Santiago: Yeah. Well, there’s kind of two ways to look at it, right? We have threat actors that are compromising MSP RMM tools. These are tools that are owned, managed by the MSP. They’re usually protected with some cloud login, whether they self-host it or they have the vendor host it for them. Threat actors can log into those systems with a password and a username, right? So we see a lot of brute forcing of those systems, especially if they’re self-hosted systems, they usually don’t have the protections of the vendors. They don’t put a WAF in front of them. And so they’ll try to brute force them and just log in, right? Those are few and far between, to be quite honest. We don’t see those as often, but what we do see often is, again, they gain access into an environment, usually by compromising a VPN. Now they’re on the network. Now they can move throughout that network as they’re on the VPN, and they’ll usually find a foothold. And if they have a credential like a local admin, they’ll take that one foothold and then they’ll distribute their RMM across that entire fleet of the network with one command from that foothold. So for us, when we’re looking at RMM deployments, MSPs deploy RMMs in a certain manner and format. They’re not deploying an RMM at two o’clock in the morning on a Saturday when they’re a US-based company. And oh, by the way, they just logged in from a Chinese-based IP, right? So again, there’s indicators that are very clear cut of like, okay, this deployment of RMM tools absolutely malicious. Most of those cases come to the case of, you know, we have application control within Blackpoint that allows us to alert when someone is installing a new application that’s unauthorized. And so what we tell our MSPs to do is, hey, set up your policies that if you’re a Ninja RMM shop, you cannot have any other installations of any other RMM. ScreenConnect is not going to be involved. And so that allows us and affords us the ability to do is, when we get that alert that says someone’s attempting to install a ScreenConnect, we can go back and sort of recreate the path of how do they get here. And what that allows us to really get into is, again, that response, right? And that response is preventing the installation of the RMM, eradicating the threat actor by isolating the machine, making sure you remove their footholds, getting those SSL VPNs off of the public facing internet, and having that exposure management reduced, right? And so when we look at RMM abuse in practice, once they get that RMM installed, again, they’re living off the land with system privileges. System privileges is something that most people tend to understand, but it’s just keys to the kingdom. You are God mode at that point. You can do whatever you feel to deploy and ultimately spread your access with that level of access, right? And so they’ll use it for backdoors. And oftentimes, they may compromise the environment and say, “You know what? I’m busy.” We’ve actually seen this over the holidays where they go take their breaks. Just like everyone else does. It’s Christmas. I’ve done a lot of hacking. So they leave their leave-behind tools and they come back. That’s their access factor. Again, it’s one of those things where they’re hiding in plain sight. Robert Dutt: You touched on MFA a little while ago and the report flagged the use of adversary-in-the-middle attacks. AiTM attacks that let threat actors hijack authenticated sessions, even when the MFA is there. So I guess what’s the message to MSPs who are thinking, “All right, if we just get MFA everywhere, we’re good, we’re covered.” Wil Santiago: Token protection, right? MFA is great. You have to have it. But understand that there’s flaws in the way that MFA communicates to servers. And so the whole way that an adversary-in-the-middle attack works is by abusing OAuth. And OAuth is a standard protocol of just making sure that we understand how systems should communicate for authentication. And what’s really nice about that is we can take that offensive research and then make defensive practices towards that. And so token protection is really huge there. There are a lot of built-in protections in Microsoft that allow you to invalidate session tokens after a certain period of time. Every hour you could refresh these tokens. You now, again, when you get to this resilient engineering, you start to push the adversary to be a little bit more aggressive. And that’s your detection mechanism. When you allow an adversary to move unfettered throughout a network, they’re going to move unfettered throughout a network. But the moment that you give them that sort of, “Eh, stop here. Let me see your ID.” Then they start to get a little uneasy. They’re like, “Wait a second. I don’t know how to move anymore.” And so specifically in MFA, when we talk about session hijacking and session tokens, the token protection aspect is really important because that’s a conditional access policy that you can implement. And most people do not implement those conditional access policies. Now, there’s a slew of them that work in conjunction with each other. But the idea here is your tokens will likely be compromised at some point. If you are duped into clicking one of these phishing links, it’s very easy to steal a session token. So we have to move past that. Now that we know that’s going to happen, how do we prevent the adversary from actually using those session tokens successfully? And that’s where invalidating the sessions comes in, having the session protection, conditional access policies, protected devices, things of that sort. That prevents them from being able to use those session tokens. Robert Dutt: A stat that I keep looking at in the report was that you guys managed to disrupt in the SOC 55, 56 percent of incidents before a payload was deployed. It’s a real number. That’s pretty significant. I guess what is disrupted before the payload hits mean operationally? And what does it tell us about where the detection opportunity actually lives? Because it sounds like the window isn’t did malware execute? It’s something a lot earlier. Wil Santiago: That’s exactly right. When we look at the cyber kill chain, we want to start pushing our adversaries as far left of boom as possible. Right. And so when you hear about this whole right of boom concept, basically, you’ve met your match. And now boom, you’ve now been impacted. Right. And so there’s a lot of indicators of compromise that we can start to hone in on. That will give us an understanding of whether this is legitimate or illegitimate. Right before an adversary even types the command. And again, that’s the context. And the context is what the SOC is really understanding of a customer. Where do they operate? What are their hours of operation? Where are they globally distributed? What’s the infrastructure they use? What are the tools they use? How did they use those tools? Did they deploy tools every Thursday at 2 p.m.? So there’s this constant checklist that they’re doing every single day to understand this. And so when we talk about living off the land, threat actors are trying to execute commands. Right. They’re just trying to sit there. We’re typing on a keyboard command line. Hey, I’m not going to introduce any new factors to my intrusion. I’m just going to live off the land. Ultimately, they want to deploy a payload at the end of all of that. But if they deploy a payload too early in their kill chain, they risk getting caught. Right. And so what they’ll do is they’ll stage everything. They’ll compromise an endpoint. They’ll add a persistent backdoor user. They’ll deploy some small scripts to enumerate the network. Just to get an understanding of what’s happening. But they’ll usually stage those in like a C:\Users\Music folder. And that’s their staging environment. So you can catch them. And we’ve caught at Blackpoint a number of threat actors where their toolkits are still on the machine because we caught them so early left of boom that legitimately all they did was log into a machine, try to mount a share, but it failed. And then that failed share mount is like, wait a second. They have never tried to mount a share on this file server ever. And then you call the MSP and they’re like, yeah, Monday through Friday, our hours are from eight to three and it’s seven p.m. at Thursday. Right. Well, now the context of the intrusion starts to become a little bit more apparent. And so we have to do this very quickly. The reality is for us, behavioral context, it matters more than ever. That is the true bread and butter for stopping threat adversaries is understanding the behaviors in the context of which they employ to compromise the network or compromise an endpoint. And so we focus a lot of our threat intelligence and our adversarial intrusion analysis based off of what hack or tradecraft is. We always say this internally, you cannot protect what you don’t know how to hack. So we spend a lot of our time recreating these attacks, understanding where do we catch them? And one of the things that we found is in those early development cycles of understanding the behaviors of an adversary, we found key indicators of like, wait, that is a very high fidelity indicator that before an adversary even gets on a keyboard, we’ve already caught them. They don’t know that yet. Right. And so that’s a little bit of our secret sauce there. But the reality is that secret sauce was created because we thought like threat actors and we sort of recreated what they did in controlled environments and testing environments to then to make sure the detection and the efficacy of what they’re doing is caught within our product. Robert Dutt: So this is a bit of a sidebar, but it was a new term, at least to me. You flagged Etherhiding in the report, attackers embedding malicious logic and blockchain smart contracts to manage compromised sites. Can you walk me through that real quick? And how real is this in terms of how widely it’s being deployed today? And why does it matter for detection purposes? Wil Santiago: It’s a newer term. You know, I would like to say that we have way too many terms in security and security, you know, sort of like we’re trying to be cool. The reality is this is a technique that leverages transactions on a public blockchain to basically retrieve malicious payloads. Right. And so this is another sort of trend that an adversary is using where they’re just retrieving a payload from something that is trusted. In this case, cryptocurrency. A lot of people trust cryptocurrency. A lot of people trust public blockchains. And so the idea here is that, you know, threat actors are usually going to utilize some type of social engineering and then that social engineering is going to get you to come to like a WordPress site through that WordPress site. They’re going to basically have scripts that you’re going to download and ultimately run. Innocuously. Now, when that happens, you download something that you think is OBS, like the example I gave earlier, it’s actually a JavaScript payload. Well, that JavaScript payload goes and reaches out and it pulls a malicious payload from the ether blockchain. Right. And so that’s that aspect of there’s function calls that we’ve identified within Blackpoint that are related to that remote management of pulling payloads from that blockchain. My personal opinion of this sort of technique is, you know, it gives a lot of advantage to the threat actors in terms of stealth and flexibility. But it is one of those techniques that is complicated for majority of what we see at Blackpoint. Most threat actors are not getting to that complicated level of compromising. They’re just hosting malware on a compromised WordPress site of a legitimate company that they’ve co-opted the passwords for. Right. And again, we see threat actors from different angles. 90 percent of what we see sort of today is cybercrime related. Right. So you have a lot of the fake CAPTCHA, the ClickFix lures, the Etherhiding stuff. The reality is at the end of that payload, we see everything from Etherhiding to Cobalt Strike to ransomware and compromise. The way that they get to that sort of compromise is kind of the same, though. Robert Dutt: Last one for me, if an MSP is listening to this and they’ve just absorbed that, you know, more than half of the attacks they’re going to see start with legitimate credentials, their own tools are showing up in about a third of incidents. MFA isn’t necessarily a guarantee. Where do you start? You know, what’s the one thing they probably aren’t doing today that would meaningfully move the needle for them in terms of making sure things are as locked down, as protected as is possible? Wil Santiago: That’s a great question. I like to say we should probably be spending most of our time right now really focusing on posture and posture management, reducing the attack surface. Right. How do you how do you start? Where do you start reducing the attack surface? This is where frameworks really come into play. And there’s some really great frameworks that are really prescriptive out there. One of them is the Center for Internet Security Controls, CIS version 8.1. It’s very prescriptive and it starts from the very top, right? External facing assets and applications. How do you lock those down? Cloud assets and applications, internal assets, user accounts, passwords, right? And it gives you a prescriptive way to deal with incidents. Beyond that, there’s kind of this like practical implementation groups that they have, right? And so you can start by implementing the CIS Controls with implementing one Implementation Group, right? You don’t have to implement them all. And so I think there’s a subset of Implementation Groups that can be used, but it’s about identifying, you know, what of these sort of subset groups will really resonate with your organization and your maturity level, right? And so I tell most people, look at IG1, start with the essentials. If you’ve already fit the bill on that, then move to IG2, right? But the reality is IG1 is going to give you that foundational security for organizations. And then IG2 and IG3 are going to be a little bit more advanced for more complex things. Most people are probably in that IG1, but they probably could benefit from some of the things in the IG2, the Implementation Groups there. That’s really going to help you really target your defenses against ransomware. That’s going to help you sort of approach a risk-based approach. That’s another thing that, you know, all risk is not the same, right? Risk is treated differently. And it’s important for anyone running a security team to help understand how should I prioritize my risk, right? Where is my risk going to really give me issues if a threat actor gets into it? And therefore, I always say, start there. We all know what keeps us up at night. So that’s the areas that we need to focus on. Robert Dutt: All right. Some sage advice and some sobering numbers as well. I appreciate your taking the time and walking us through some good stuff. Wil Santiago: Thank you, Robert. I really appreciate it. Robert Dutt: There you have it. Wil Santiago from Blackpoint Cyber. I’d like to thank Wil for his time today and for bringing some real energy to what can sometimes be pretty dense subject matter. And of course, I’d like to thank you for listening. The data in this conversation is worth thinking about. More than half of the attacks Blackpoint’s SOC starts with someone simply logging in, using credentials that were stolen sometimes long ago, and that users are still reusing across platforms. A third of triaged incidents involve RMM tools, the same tools your techs are using right now to manage endpoints. And MFA, as much as we’ve come to rely on it, is no longer the finish line it once appeared to be. The antidote Wil describes is behavioral context, understanding what normal looks like in an environment so you can spot when something legitimate is being done illegitimately. Not “Is this malware?” But “Is this person, using this tool at this hour from this location, doing something they’ve never done before?” That’s a fundamentally different way about thinking of detection, and it’s why the human element in the SOC still matters. And I’ll add one thing that Wil mentioned after we wrapped the recording. It’s a dimension of this fight that doesn’t get talked about often enough. Blackpoint’s work doesn’t stop at detection and response. They’re actively working to identify and disrupt adversary infrastructure, notifying law enforcement, including, he noted, Canadian authorities, with the specific goal of making cybercrime economically painful. The logic is straightforward. If your infrastructure gets taken down every time you try to run a campaign, the math of operating a criminal enterprise starts to change. That’s offense, and it sounds like they’re playing it. If you’re finding the show valuable, I’d encourage you to follow or subscribe to the podcast. You can find us on Apple Podcasts, Spotify, YouTube, all the major directories. A rating review always helps. Until next time, I’m Robert Dutt for ChannelBuzz.ca, and I’ll see you in the channel.

August 13, 20264 min

The Buzz: Blumira launches universal AI security command center, Vistera brings AI professional services to Canadian SMBs, and CrowdStrike warns on ransomware targeting MSPs

Today’s headline news for Canadian IT solution providers: [Blumira]: The company on Tuesday launched Hearth, a vendor-agnostic AI command center that Blumira says can intelligently reason across security tools and services an organization already uses. The platform is available in the Pax8 Marketplace, giving MSPs a unified interface to monitor and respond across multi-vendor environments. Read the announcement on Business Wire [Vistera]: The Vancouver-based company on Tuesday unveiled a professional services platform powered by Vero, a multi-agent orchestration layer that Vistera says brings legal, HR, and finance expertise to Canadian SMBs in British Columbia, Alberta, and Ontario. Every output is reviewed by a senior Canadian-qualified professional before delivery, with outcomes priced at $700 each or through monthly plans. Learn more on Vistera [CrowdStrike]: Justin Bradley, senior alliances manager for MSSP aggregators at CrowdStrike, warned attendees at XChange August this week that the group behind Akira ransomware — referred to as Punk Spider — has increased attacks by 134 percent over the past year, specifically targeting SMBs through MSPs. The group buys VPN credentials on the dark web, uses MFA fatigue to gain access, and dumps Entra IDs before deploying ransomware. Read more on CRN [ConnectSecure]: The company on Tuesday added M365 Auto Remediation, AI-powered training assessments, and Patch 360 to its MSP platform, allowing providers to automatically remediate supported Microsoft 365 security findings across multiple tenants. Read more on Channel Dive [GTIA]: The Global Technology Industry Association warned at ChannelCon last week that customers are deploying AI faster than MSPs can deliver security and governance, and announced a new Managed Intelligence Alliance to develop standards and accreditations for AI services. Read more on Channel Dive [NetRise]: The company on August 3 launched its Discovery Partner Program to expand software supply chain security through MSSPs, VARs, and distributors. Read the announcement on PR Newswire [Verizon]: Channel chief and vice president of indirect partner sales Mark Tina is leaving the telecommunications company after 23 years to become vice president of national partner sales and distribution at health insurer Humana. Read more on Channel Dive Read Full Transcript Welcome to The Buzz from ChannelBuzz.ca, I’m Robert Dutt, today is Thursday, August 13, and here’s what’s happening in the channel today. Blumira on Tuesday launched Hearth, a vendor-agnostic AI command center that the company says can intelligently reason across security tools and services an organization already uses. According to Blumira, the platform is designed to unify visibility and response across the workspace without requiring a rip-and-replace approach, giving lean IT teams a single interface to monitor disparate tools. Hearth is available in the Pax8 Marketplace, positioning it for MSPs that provision through that platform. Blumira is pitching the offering as a way to reduce tool sprawl and alert fatigue for teams that lack enterprise-scale resources. A unified reasoning layer across multi-vendor stacks could cut down on the context-switching that slows incident response for Canadian MSPs, though the value will depend on integration depth and the accuracy of the AI-driven reasoning. Vistera on Tuesday unveiled a Canadian-built professional services platform powered by Vero, a multi-agent orchestration layer that the company says brings legal, HR, and finance expertise to small and medium-sized businesses at a predictable cost. The Vancouver-based company is targeting Canadian SMBs in British Columbia, Alberta, and Ontario with outcomes priced at $700 each or through monthly plans, a fraction of the typical hourly rates at large firms. According to Vistera, every output is reviewed and signed off by a senior Canadian-qualified professional before it reaches the client, with credential verification and regulatory standing checks built into the workflow. The platform handles intake, research, and preparation through AI agents while preserving human oversight for final judgment. Canadian MSPs should watch how this model lands, as it could create new partnership opportunities around SMB advisory services or introduce competitive pressure in the professional services space. CrowdStrike this week warned attendees at XChange August that prolific ransomware groups are specifically targeting MSPs and their SMB customers. According to Justin Bradley, senior alliances manager for MSSP aggregators at CrowdStrike, the group behind Akira ransomware — referred to as Punk Spider — has increased its attacks by 134 percent over the past year with an emphasis on SMBs. Bradley said the group’s typical strategy involves buying VPN credentials on the dark web, then using MFA fatigue to gain initial access, escalating privileges, and dumping Entra IDs before deploying ransomware. He also noted that CrowdStrike is tracking two break-off groups from Scattered Spider, dubbed Cordial Spider and Snarky Spider, which have been known to impersonate MSPs to trick customers into launching remote access tools. The intelligence underscores the urgency for Canadian MSPs to harden identity controls and monitor for MFA abuse, particularly as credential theft continues to fetch thousands of dollars on dark web markets. In Brief – ConnectSecure says its new M365 Auto Remediation tool lets MSPs approve and automatically apply fixes across multiple customers for supported Microsoft 365 security findings. The Global Technology Industry Association warns at ChannelCon that customers are deploying AI faster than MSPs can secure it, and says it is launching a Managed Intelligence Alliance to set standards for AI services. NetRise says its new Discovery Partner Program will expand software supply chain security through MSSPs, VARs, and distributors. Verizon confirms channel chief Mark Tina is leaving after 23 years to become vice president of national partner sales and distribution at Humana. Full details and links in the show notes or the blog post. That’s how we’re seeing the headlines today. I’m Robert Dutt for ChannelBuzz.ca, thanks for listening. Have a great day.

August 12, 202629 min

From order takers to order makers: Sanjib Sahoo on Ingram Micro’s AI revenue intelligence momentum

Sanjib Sahoo, executive vice president and president of the Global Platform Group at Ingram Micro In this episode of In The Channel, we sit down with Sanjib Sahoo, EVP and President of the Global Platform Group at Ingram Micro, to unpack the “AI Revenue Intelligence” strategy that is currently driving the distributor’s record momentum. Sahoo discusses the evolution of the Xvantage platform from a digital infrastructure vision to a fully trained intelligence layer featuring over 400 proprietary models. A key highlight is the impact of the recently announced Xvantage Integration (XI) Hub and the MCP (Model Context Protocol) Server. Sahoo describes MCP as the “USB-C for AI,” allowing partners to securely connect their own AI agents—whether running on Claude, ChatGPT, or Gemini—directly to Ingram Micro’s data mesh. Key discussion points include: The 4x Conversion Metric: How AI-surfaced insights are drastically outperforming traditional sales motions in converting quotes to orders. Democratizing AI: Why small MSPs are becoming the fastest adopters of the MCP Server to bypass complex, expensive ERP system integrations. Operational Efficiency: Real-world examples of partners saving 1,500 hours annually by reducing complex quoting cycles from days to mere seconds. The Human Shift: How the role of the Ingram associate is pivoting from transactional fulfillment to training algorithms and high-value solutioning. For partners looking to get started, Sahoo recommends visiting the Xvantage Developer Portal to explore how to “think big and act small” when it comes to AI adoption. Read Full Transcript Robert Dutt: Hello and welcome to In The Channel from ChannelBuzz.ca, bringing news and information to the Canadian IT channel community for the last 16 years. I’m Robert Dutt, editor of ChannelBuzz.ca and your host for the show. Today, we’re joined by a man who’s effectively the architect of the modern digital Ingram Micro. Sanjib Sahoo is the EVP and president of the Global Platform Group at Ingram Micro and the visionary behind Xvantage. We’re coming off a week where Ingram reported record Q2 results, and Sanjib joins me to talk about why AI revenue intelligence is the engine behind those numbers. We dig into the recently launched XI Hub and MCP server—tools that are allowing even the smallest MSPs to connect their own AI assistants directly to Ingram’s data mesh. We talk about how this is saving early adopters up to 1,500 hours a year and why Sanjib thinks the industry is moving from a world of order takers to order makers. Let’s get right into it. My chat with Sanjib Sahoo. [MUSIC] Robert Dutt: Sanjib, thanks for taking the time. I appreciate it. Sanjib Sahoo: Absolutely, it’s a pleasure to be here. Robert Dutt: You guys just came off record Q2 results. A big part of that is the idea of what you guys are calling AI revenue intelligence. For the folks on the ground, what does that term actually mean? Is this about Ingram’s revenue, partner revenue, or sort of the intelligence sitting between those two fields? Sanjib Sahoo: Absolutely. If you look at it, intelligence is the key that connects the lifecycle in the channel. What we have been doing in the last year or couple of years is building functionality with Xvantage. But that is the infrastructure. What we have done is train our intelligence layer. All the models we have built—more than 400 models—and the intelligent integrations that we have built, it all added to that AI layer. Today, that AI layer goes out, looks at all the quotes, looks at multiple parameters, and then stack-ranks opportunities for our sales team to go and outreach our partners. It’s changing the sales motion where we are moving from order takers to order makers. That is converting at almost four times the rate that traditional distribution converted those quotes to orders. That actually has high-quality revenue. And most importantly, it is really giving us a way to close our cycles faster. That is that AI-led revenue—primarily intelligent revenue—that we are doing. Robert Dutt: That 4x number is pretty striking. You’ve been the architect of Xvantage since the beginning—it’s been your baby. Based on what you described, it’s safe to say we’ve gone from vision well into the momentum phase. I’m curious: what’s the biggest difference in the conversations you’re having with partners today versus, say, even the beginning of the year? Sanjib Sahoo: I think our partners are understanding more and more that this is not another platform or a tool for doing distribution better. This is a way for them to leverage that intelligence that Ingram Micro has from being in business for more than 45 years. It’s about leveraging insights to drive their business. Ultimately, where we want to move, Robert, is away from just selling products to selling outcomes by intelligence. I think more and more, that intelligence is the new relationship and value that we can create. The platform is immaterial; the experience is great, but the intelligence is what they need to drive operations. Robert Dutt: I’m curious how you have found the channel’s aptitude or ability—how is the channel prepared for this move towards intelligence? What is the biggest opportunity for the average MSP at this moment to jump on? Sanjib Sahoo: I think the channel is changing. The entire tech ecosystem is no longer linear. It’s more about solutioning, ecosystem orchestration, and demand gen. We need to scale the “long tail”—the small MSPs and the VARs—and that requires a lot of automation. Let me ask you a question. What is the operating system you have on your phone? You might know it’s iOS or Android, but you don’t know the exact version, right? Does it matter? No. But the operating system is what does the disk cleanup and the CPU optimization. Without that, it doesn’t work. We want Xvantage to be that agnostic operating system of the channel that solves all these complexities of SKU ingestion, billing, attaching, and reconciliation, powered by intelligence. This leads to our announcement about MCP. We have spent too much time on system integration; now we are connecting and combining intelligence. Robert Dutt: Let’s get into that. You’ve recently announced XI Hub and the MCP server layer. You guys have positioned this as “operationalizing AI” for the channel. In plain English, how do those two pieces work together to let an MSP connect their own AI to Ingram’s data? Sanjib Sahoo: Absolutely. If I’m a small MSP or an SMB, I don’t have a lot of IT budget. System integration takes a long time. But today, you can quickly write a quick agent or use your own LLMs. How do you connect that to an Xvantage or Ingram Micro without a massive integration? That is MCP. MCP is connecting intelligence to intelligence—agent to agent—versus system integration. It bypasses the complexity. I recently heard of a partner who got connected with MCP within an hour and is already driving value. Data helps you run the business, but intelligence helps you grow the business. Imagine if an MSP can get that constant intelligence from us for renewals or bundles—fulfillment happens as a byproduct, but intelligence is the value. Robert Dutt: You’ve described MCP as the “USB-C for AI.” Why was it important for Ingram to go through MCP and use an open standard like that, rather than building a “walled garden” approach? Sanjib Sahoo: Because a custom approach takes a long time. This is the fastest way to abstract your systems. Imagine you have ChatGPT or Claude and you connect it securely to Ingram Micro’s Xvantage to run your business. That’s amazing. We have architected it this way because ERPs can answer what, but they can’t answer why. Our architecture—with the real-time data mesh, AI Factory, and headless engines—really creates an environment where MCP can work much faster. Robert Dutt: If I’m an MSP and I’m plugging in an AI assistant to my business systems and to your live data, my first thoughts are going to be security and data leakage. How do the XI Hub and MCP server keep that data secure? Sanjib Sahoo: We have a lot of work going into security—data segregation, multiple protocols for how we expose data. We have different protocols for read versus write. We have been very careful about the details for obvious reasons, but there is a massive focus on security. Robert Dutt: You guys have talked about some incredible numbers—early adopters saving 1,500 hours annually and radically reducing quoting cycles. What was the partner doing manually that an MCP-connected assistant can do for them now? Sanjib Sahoo: They can get instant access to insights and figure out any question they have without needing to invest in extra OpEx or partners to do those activities. That saves them a lot of hours. But it’s also about growth. We see that Xvantage-integrated partners are doing much more business with us. It’s transactional efficiency and growth opportunities. Robert Dutt: When it comes to quoting, how is AI reducing the cycle? Is it fetching data faster or actually suggesting configurations? Sanjib Sahoo: MCP itself isn’t doing the quoting. We have worked hard to build a custom quoting engine in Xvantage as one of our headless engines. It takes complexity out and does the vendor integrations from config to order. MCP is just the pipe giving you the data from that engine. The complexity is solved by the Xvantage infrastructure; you’re just taking advantage of it by connecting with the MCP layer. Complex quotes that used to take days can now be done in minutes or seconds. Robert Dutt: Now that XI Hub and the MCP server are out there, what’s been the most unexpected or novel way that you’ve seen a partner use it? Sanjib Sahoo: I thought the big customers or the mid-market would lead, but I’m seeing a lot of traction with the “long tail”—small customers. It makes sense because they don’t have the budget to invest in heavy IT. They are connecting to MCP, looking at data, looking at renewals, and getting insights. Some are doing it in less than an hour. It really surprised me how this “relationship fabric” is giving them value through AI rather than just through sales calls. Robert Dutt: For those smaller partners—that 10-person MSP—what’s the on-ramp? How “AI-ready” do they need to be? Sanjib Sahoo: They can be ready pretty fast. There are so many models available. They know their own context, and if they plug into us, they can drive their business in a very different way. The XI Hub and MCP server are strategic components of a broader vision to democratize enterprise AI in the channel. The future of distribution is not just moving products; it’s about connecting intelligence across the tech value chain. Robert Dutt: You’ve talked about the move from “sell-in” to “sell-with.” Does this change the role of the Ingram associate or the account rep? If AI is doing the quoting, how does the human role shift? Sanjib Sahoo: There is always a human role. First, they are training the algorithms to make the intelligence better every day. Second, they can focus on being proactive rather than reactive. They focus on high-value, high-complexity solutioning with the customer rather than basic operations. We are focusing on the exceptions rather than transactional connectivity. Robert Dutt: You often talk about “mindset over skillset.” If a partner wants to capture this opportunity, what’s the one big mindset shift they need to make? Sanjib Sahoo: Think big and act small. Focus on the 60% chance to succeed versus the 40% chance to fail. AI is not perfect, but interacting with it every day makes it better. Data helps you run your business, but intelligence helps you grow it. We need our partners to move from instinct to intelligence. Robert Dutt: Looking at the rest of the year, what is the next big milestone for Xvantage? Sanjib Sahoo: The next “hub moment” will be about how we improve the intelligence every day to drive outcomes. We will always build features, but I want to celebrate intelligently operating this channel. We are moving from a platform for distribution to a platform company that does distribution. Robert Dutt: Last one. If I’m a partner who hasn’t yet looked at the Xvantage developer portal or XI Hub, where do I start? Sanjib Sahoo: You can Google the Xvantage Developer Portal or talk to your account manager. Some are figuring it out on their own, but we are there to help. Let’s work together to transform this industry. Robert Dutt: Brilliant. I appreciate you taking the time to walk us through this. Sanjib Sahoo: Absolutely, Robert. Thank you so much. Robert Dutt: There you have it, Sanjib Sahoo from Ingram Micro. I’d like to thank Sanjib for his time. It’s not often you get a peek under the hood of a platform handling four petabytes of data to see exactly how it’s changing the day-to-day life of the partner. The big takeaway for me was the 4x metric—AI-driven insights are converting at four times the rate of traditional sales motions. For the MSP, the message is clear: the long tail isn’t being left behind here. In fact, if you don’t have a massive IT budget, the MCP server might be your fastest way to operationalize AI without a developer team. I’d like to thank you for listening. You can find the podcast on Apple Podcasts, Spotify, YouTube, and most major directories. Ratings and reviews go a long way. Until next time, I’m Robert Dutt for ChannelBuzz.ca, and I’ll see you in the channel.

August 12, 20264 min

The Buzz: Expel extends MDR to AI attack surface, Huntress warns on autonomous adversaries, and Myriad360 crosses $1 billion

Today’s headline news for Canadian IT solution providers: Expel MDR for AI attack surface: Expel has launched what it says is the first managed detection and response service covering the full AI attack surface, extending its SOC capabilities to threats launched with AI, employee AI misuse, and exposure inside AI systems themselves. The company announced the expansion at Black Hat 2026, adding an Anthropic Claude integration that pulls enterprise compliance signals and prompt content into Expel’s detection pipeline. Expel’s operators work the prompt content itself to surface intent, not just activity, and the company has mapped its detection library to 13 of 16 MITRE ATLAS tactics. Expel Huntress CEO on autonomous adversary: Huntress CEO Kyle Hanslovan is warning that autonomous, AI-powered attacks have moved from theoretical concern to active reality. In an interview with CRN, Hanslovan cited OpenAI‘s disclosure that its AI agents compromised the Hugging Face platform during testing, as well as subsequent Anthropic disclosures about its Claude Mythos 5 model, as evidence that autonomous hacking is already happening. Huntress, which recently crossed $250 million in annual recurring revenue, has built its business around protecting smaller organizations that lack enterprise-scale security teams. CRN Myriad360 acquires F3 Technology Partners: Myriad360 has acquired the assets of F3 Technology Partners, a Connecticut-based healthcare IT solution provider, pushing the combined organization past $1 billion in estimated annual revenue. While Myriad360 is U.S.-based, the firm services the Canadian market through its global logistics and international business operations. F3 brings deep healthcare vertical expertise to Myriad360’s portfolio, reinforcing a trend of mid-market consolidation that is creating a new class of “Super-VARs” with the scale to compete for multinational enterprise business. CRN Nutanix MCP server: Nutanix has released an open-source MCP server for the Nutanix Cloud Platform, enabling AI assistants including GitHub Copilot, Claude Code, and Cursor to automate cloud operations through the Prism v4 API. The move follows Ingram Micro’s MCP server launch for its Xvantage marketplace and reflects growing channel investment in the Model Context Protocol as a standard for AI-tool integration. Nutanix Halo AI Studio and MCP push: PSA vendor Halo unveiled AI Studio and MCP integrations at XChange August, giving MSPs tools to build AI agents for service desk, sales, customer success, reporting, and quarterly business reviews. The company also launched an MCP server to act as a central interface across MSP tools. Halo partner John Douglass of Pileus Technologies said the AI Studio capabilities are “a game changer” for automating service delivery. CRN CRN Annual Report Card winners: CRN announced the winners of its 2026 Annual Report Card at XChange August, with solution providers grading vendors across 23 technology categories. Notable winners included HPE in cloud computing and servers, Nvidia in GPUs, Exabeam in AI security, and Scale Computing in hybrid cloud infrastructure. Complete scores will be published on CRN.com on October 5. CRN Liquidware CommandCTRL 1.5: Liquidware launched CommandCTRL 1.5 with AI-powered endpoint diagnostics and browser-based remote control across Windows, macOS, Linux, and thin clients. The update adds AI Insights that interpret endpoint telemetry and extends remote support capabilities to browser-based sessions without requiring a client installation. Liquidware Read Full Transcript TRANSCRIPT TO COME

August 11, 202638 min

Exabeam rebuilds its MSSP commercial model to fix the economics of managed SIEM

Craig Patterson, global channel chief at Exabeam For years, SIEM has been one of those technologies that looked good in theory but was genuinely hard to build a profitable managed service around. Deal-by-deal discount negotiations, licensing structures built for enterprise resale rather than recurring managed services revenue, and no predictable floor on margin. For many MSPs, the math just never worked. Exabeam – the combined company formed from the merger of the original Exabeam and LogRhythm – is making a direct play to change that. Global channel chief Craig Patterson and senior director of service provider alliances Peter Stratis join In The Channel to walk through the new MSSP commercial framework inside the recently launched APEX Partner Program. Two new licensing pathways: a single-pool capacity model for high-volume, multi-tenant environments serving SMB and mid-market clients, and a federated subscription model that isolates customer environments for compliance and data sovereignty requirements. For Canadian MSSPs navigating PIPEDA, OSFI E-21, or Protected B, that second model is the one to pay close attention to. Peter Stratis, senior directof of server provider alliances at Exabeam The conversation also covers Sherpa, Exabeam’s new AI-powered partner enablement platform – a move away from the traditional LMS toward an always-on coaching tool that can join partner sales calls in real time – and Agent Behavior Analytics, Exabeam’s new capability for detecting malfunctioning, misaligned, and subverted AI agents inside customer environments, included at no additional cost. The standout line from Peter Stratis – who called this his first-ever podcast appearance – is the one worth writing down: “We treated our service providers like resellers, unfortunately.” The new framework is a direct acknowledgment of that history, and an attempt to rebuild the commercial relationship from the ground up. Read Full Transcript Robert Dutt: Hello and welcome to In The Channel from ChannelBuzz.ca, bringing news and information to the Canadian IT channel community for the last 16 years. I’m Robert Dutt, editor of ChannelBuzz.ca and your host for the show. If you’ve been in the channel for any length of time, you know that SIEM has always been one of those technologies that seems great in theory but has been genuinely hard to build a profitable managed service around. Licensing models that weren’t built for multi-tenancy, unpredictable costs, discount structures that made margin planning more of a guessing game than a business model. A lot of MSPs have looked at the security operations space and quietly backed away for exactly those reasons. Exabeam, the combined company that emerged out of the merger of Exabeam and LogRhythm, is making a direct play to change that. They have overhauled their channel program into what they’re calling the APEX Partner Program and at the centre of it is a new commercial framework built specifically for managed security service providers. Two distinct pathways: one for high-volume multi-tenant environments and one built with compliance and data sovereignty in mind. For Canadian MSPs navigating PIPEDA, OSFI E-21 and Protected B requirements, that second lane is worth paying close attention to. I’ve got two Exabeam executives here to walk us through it. Craig Patterson is Exabeam’s global channel chief and Peter Stratis is the senior director of service provider alliances, the person who’s been working directly with MSSPs to build this out from the ground up. Let’s get right into it. My chat with Craig Patterson and Peter Stratis. Gentlemen, thank you for taking the time. Craig Patterson: Thank you, Robert. Super excited to be on here with you today, my friend. Peter Stratis: Thank you. Robert Dutt: Craig, can you just kick us off with a quick version of where Exabeam sits right now? You know, you guys went through a significant merger with LogRhythm not that long ago. Now you’re pushing an updated partner program. For solution providers who maybe haven’t been following closely, what does the combined company look like from a channel perspective? Craig Patterson: The short answer, my friend, is that we’re sitting in an amazing place. We’re absolutely in a good place positioning to really drive value to our partner community. And so to give you a little more context around that, like you asked, we’ve spent the last 12 months really kind of rethinking, reimagining the whole partner ecosystem in a way to create value for all of our partners globally. And so there was a number of things we went through over the last 12 months. We spent a lot of time really going to this assessment loop, understanding everybody’s perspective. So we did that by having very strategic conversations with our top-tier partners. We did some survey work. We looked at the broad landscape in terms of the trends that the partners are really looking for in these modern channel programs. So all of that really became this assessment loop. The output of that is that really became the foundation for what we built here with APEX. And so with APEX, the Exabeam APEX Partner Program, what you have here is you have a program that’s really centered on value that’s really focused on solving a problem that exists in our market today around enablement. And so when you think about enablement today, I’ve written a lot of articles on this. Most enablement programs really don’t drive to the level of outcome that companies are looking to have. Outcomes like conversion rates, outcomes like time to first deal, outcome rates like retention rates, all these things. And so what we’ve done is we’ve really focused on enablement as the key catalyst to really drive value to our partners. And so with that, we’ve launched new enablement programs really with a focus on increasing their competency level so we can align to those outcomes we’re looking to have with our company’s operating plan. And so there’s a lot of thought that’s got into this. The short answer is we have a program that’s built on value. It aligns to where the market is going and what partners are really asking for. Robert Dutt: Peter, your title as senior director of service provider alliances is a pretty specific role. Can you tell us a little bit about what that looks like sort of on a day-to-day basis and the big problems that you’re focused on? Peter Stratis: Sure thing. Thanks, Robert. Well, I’ve been with Exabeam for about eight years now and service providers have always been a key component of not only our channel strategy, but our go-to-market and just from our net new revenue perspective. After our merger with LogRhythm, that actually continues and if anything, it’s only been more emphasized because both from an on-prem and from a cloud perspective, we see the MSSPs being a strong driver of that strategy of our go-to-market. So over the last eight years, we’ve seen that trend of not only on net new revenue, net new logos being a major part of our business, but then how do, to Craig’s point, how do we support them? To be quite honest, in the past, it was quite difficult. We really didn’t have any kind of structured pricing for these partners. It was, to say the least, it was more of a resale program that had some discounts tied to it. So through Craig’s efforts, through our whole surveys and our intent to really go after this market and treat them the way they should be treated, he mentioned that we did these surveys. We asked internally, what do you look for in a service provider partner? We asked externally what these partners were looking for from us. And that’s when in building the APEX Partner Program here at Exabeam, we also took into account what service providers would look for in a new partner program. So that’s everything from pricing to support. Craig mentioned enablement. Enablement is a huge part of that, where they felt in the past they were just lumped up as just a regular partner. Now we have supported APIs, documented APIs that most, if not all, of our partners are using as part of their foundation for their services. So we’ve really come a long way and continue actually to build upon that, as you’ll see throughout 2026 and beyond. Robert Dutt: Okay, let’s get into the framework itself. You guys positioned it at launch as solving commercial and operational friction for MSSPs. Curious, what did you hear that friction looked like in practice? What were MSSPs telling you was broken or was a big challenge? Craig Patterson: Yeah, so I’ll take a stab at this and I’ll let Peter give more context. So a lot of this came out during that assessment phase. Robert, we’re talking to the MSSPs globally. I’m like, what’s working? What’s not working? What would they like to see incorporated into the MSSP program 2.0? So a lot of the feedback we heard was really around the flexibility. Being able to have a license that is catering to all the customer demand they have beneath. So it’s really giving them the flexibility to buy that one license and carve it up as they see fit. And giving them more flexibility on the commercial terms. That was a lot of the commentary we heard. The other thing we heard was really they wanted more value as it leads to the enablement side. So obviously getting them enabled on the pre-sales side, but more importantly on the post-sales side. So they could actually drive those implementations, drive the management and really help those customers create a lot of value. And so I think those were kind of the big levers that I heard from those assessments. And then in practice, Peter can give you some more context in terms of how we’re putting all this together. Peter Stratis: Yeah, thanks Craig. A lot of what we heard from the service provider community in the past was friction. So when they’re trying to price out their services and our product and etc., they were seeing friction at onboarding. They were seeing friction in trying to predict their margin on deals. As mentioned, not airing any dirty laundry here. It was more like a resale program. So we gave discounts and there were very opportunistic discounts on a deal-by-deal basis. So they didn’t build predictable service models around it in the past. And then you always hear the buzzword, multi-tenancy. We kept on getting asked about our multi-tenant roadmaps, etc. We’re looking at this framework as a way of solving for that. We continue to make feature enhancements into the platform that will strive for that multi-tenancy. But the way we’re solving for it is by these two pathways. One is that single license, pooled capacity, data segregation model. And the other is that federated workflow that we announced where it’s more for, whether you’re within data sovereignty, if in different regions or just different use cases from a compliance perspective, whether it’s healthcare or finance, and you have to keep these environments isolated. We have a plan and we worked with our MSSPs specifically to have these kind of pathways. So we heard from our MSSPs and we actually developed these two pathways with them in mind. So they were in the design phase and in the rollout phase for both federated and the single pool capacity. Robert Dutt: The federated model is such an interesting one, I think, for the Canadian market, specifically data sovereignty, huge topic. And there are specific compliance requirements, PIPEDA, OSFI E-21, Protected B status. It means that a lot of Canadian MSSPs can’t just kind of throw everything into one pool. Was that the sort of thing that was explicitly on the radar when you built this out or a happy coincidence of the architecture and the feedback that you heard along the way? Peter Stratis: It’s actually a little of both, right? So it just so happened to be the maturity of our platform. Even from our Exabeam New Scale platform, we went from an on-prem hardware appliance way back in 2012, to our version 1.0 was a SaaS product, to our native cloud. It was always a single-tenant solution. So it worked well for certain service providers that had the capacity. They had their APIs and their own platforms that could manage this solution. As you heard more and more about multi-tenancy and the need for data sovereignty and all that, we still had a big part of our MSSPs were asking for this single license pooled capacity. So we structured it in a way where for midsize organizations or even some small, medium business, you still have that single pool capacity using data segregation. You lose some of the customization, but you could actually solve for a lot of those customers in that model. And then you have another plan with the federated. So the more mature MSSPs are running both models in some capacity. They could still run that single license for their SMB play. And then for either large enterprise or very compliance-driven customers that want those isolated environments, they have that flexibility. And that’s what we built a framework around. Obviously, that’s one point of feedback that sort of directly informed the framework. Robert Dutt: You guys have said that this whole thing was built, as you said, with direct collaboration with your MSSP partners rather than kind of coming down on high. I’m curious along with what you’ve touched on already, what actually changed as a result of going through that process? What did you go in thinking you’d build and how did it come out differently because of what partners told you along the way to building it? Craig Patterson: Yeah. So I think there’s a lot of things that have been addressed. Obviously, the packaging and the commercial aspects as Peter was describing, but think about some of the fundamental problems in terms of partners want this path to profitability, right? Really understanding how they can create margin. That was one thing. Another path is like, how do I become enabled with Exabeam? And how do I stay informed in terms of where you’re going? Another problem we wanted to solve. So I think it’s a lot around the financial aspects of doing business with us. A lot of it’s around becoming enabled, becoming more knowledgeable on all the new features and releases that we’re dropping. And so those were some of the big fundamentals that we wanted to solve in the APEX framework. And then beneath that, obviously, is the whole MSSP play. And that’s what Peter’s been talking about. So you can probably give a little more context on that. Peter Stratis: Yeah. As mentioned, there is no one-size-fits-all. So the feedback we were getting was obviously their security platform was important to them. Some of them had an in-house platform they built on their own. And there’s ways of differentiating. So basic SIEMs are just going after alert monitoring. So how can I differentiate my service if I’m a service provider? Well, there’s ways of going to market, but also there were things we needed to do in the back office from a platform perspective to make those possible. So making our behavioral analytics available in these models so they can actually differentiate their services. As I said, we have a history of actually adding features quarter-over-quarter, month-over-month. So that’s not stopping. We didn’t announce necessarily multi-tenancy to the world. We announced a commercial framework for that. So you’ll continue to see on a month-to-month, quarter-over-quarter basis, features added to support not only the commercial framework, but the underlying platform to make it easier for service providers to add that operational efficiency, to add those differentiators from a product portfolio as well. Robert Dutt: Let’s talk about the economics underneath there. You use the term predictable margins as a phrase that shows up in the messaging. SIEM has historically been a tough service to make money on. Licensing models that didn’t fit the managed services motion, unpredictable costs on data ingestion, those sorts of things. What specifically changes for an MSSP’s P&L under the framework? Craig Patterson: Yeah. So I think there’s really two components here. The first is the whole financial package associated to the MSSP partners. And the second is the discounting framework. And so let’s maybe start with the discounting framework. One of the observations that we made during this whole assessment phase was the vast majority, Robert, of all of our deals were flowing through this non-standard process, which means the discounts that were aligned to the traditional framework were not putting the MSSP partners in a position to actually transact. And so what we did is we went through and we re-looked at the discounting framework and sort of realigned it based upon our actual data points. We looked at the last 12, 24 months, the discounts that were being derived to actually transact. And we sort of rebuilt the entire discounting framework for our company in a way that really empowers the MSSP partners now to have enough discount to actually transact without going to this non-standard queue. So what does it mean? Well, we really kind of flipped the script. Instead of 80% being non-standard, we believe 80% will flow through the standard process now because we’ve built the discounts in a way to align with what the market is looking for. That’s kind of the key component number one. And then as it relates to the discounting side, we reimagined how those discounts are calculated. And so now you kind of have your standard program discount. So that’s based upon your tier. So top-tier MSSP partners get the highest level discount. The second is deal registration. Obviously, they put the deal reg in that ties to a discount. Those are both standard common things. But what’s new, which is what you care about. What is new? Well, we’ve aligned the third discount based to their competency level. And so we measure that based upon certifications. And so if you think back to those choose-your-own-adventure books as a kid, we’re really giving the partners their own choose-your-own-adventure. And if they want to drive to the highest level discount, well, simply, MSSP partners got to go take all of our certifications, pre-sales and post-sales, so they have the highest level of competency to drive our services in the market. And our thesis around that is partners that have higher certifications, they’re going to be more active, they’re going to be more interested, they’re going to drive more pipeline. And if we do this the right way, Robert, they’re actually going to convert at a higher percentage, we’re going to see shortened sales cycles, all of which align to the operating plan of our company. So it’s kind of those two fundamental things that were addressed through that process. And then I’m sure Peter can fill in the detail for you. Peter Stratis: Yeah, if I can actually elaborate on that. Thanks for that, Craig. And just some historical context, Robert, as mentioned in the past, we treated our service providers like resellers, unfortunately, so it was very deal-specific in terms of what they were getting on a deal-by-deal basis from a discount. So the economics of it was they really couldn’t rationalize their margin predictability on an overall services basis. And you know, different regions go to market different ways. In Europe, Asia, Latin America, predominantly, it’s all SIEM as a service and MSSP owns the license. In the Americas, both US and Canada, we saw a lot of proliferation in the past of customer-owned licenses. So the MSSP would resell the license, and consequently, just provide managed services wrap on top of that. Not only do we see more of that MSSP-owned model now where it’s SIEM as a service in the US and Canada. So it’s proliferated itself throughout all the regions. Now with these frameworks, we actually are able to build these economics, the margin predictability, as Craig mentioned, because now they know as a standard, what they’re going to be selling for. So especially as we do this federated model, and even the single license, you know what your price is across the board, you know what license you’re buying, you know what price you’re buying it for, you know, the more customers you add to these models, the more your profitability will increase as well. So it continues to grow from a pure profit play. Partners want to know what their margin would be as their customer licenses grow. And this is exactly what the framework did. Robert Dutt: This is sort of a broader question around MSP/MSSP distinctions as opposed to directly about the framework. But there’s a distinction worth drawing between an MSP trying to bolt a security practice onto the existing managed services business and the established MSSP who’s been at this for a year or who has built it up. Are those two different conversations for you? And if so, what are the different entry points and care-abouts? Peter Stratis: So it’s interesting, not only because of this announcement, even prior to it, the announcement of the APEX Partner Program here at Exabeam caused a lot of interest from partners and different kinds of partners. The traditional MSP, when inquiring, it was kind of hard when we were vetting them that they had no security practice of their own. So oftentimes they would actually outsource that security to an MSSP, to a classic MSSP, or maybe just resell services from those other organizations. We see that, we see a lot of interest from MSPs with that. And we see VARs or resellers come to us that want to build managed service practices as well. So we look at both of these in two different ways. One, how can we take care of these partner inquiries now, and then how can we grow with these organizations? So both MSPs and resellers that are interested in managed services now, our first inkling is to try to introduce them to our current managed service base. These people have the experience, they have the certifications, they have the technical knowledge. We’ve seen that move from a lot of MSP partners actually having channels of their own. So they actually sell their MDR or MSSP services through a channel of resellers or MSPs. But then if that’s our first step with these type of partnerships, then it’s like, how can we grow within your organization? How can we help you get the technical skills required? Because for a true MSP to have success, not only in SIEM, but just security as a service, you can’t just train one or two people, you need the 24-by-7 support, you need the tier one and tier two level of support services as well. So you have to grow your organization or outsource it to people that are already prepared to handle that. So that MSP play, we actually see it more and more going towards our current managed security service providers and getting that as a resource. Craig Patterson: Just to add a little more context to that too. So this actually becomes a very interesting point for the distributors worldwide as well. Because a lot of what they provide in terms of value is helping those MSPs in terms of deployment and management of the services. And so we’ve gone through the vetting process globally, looking at all of our distributors and we’ve handpicked our strategic distributors around the world. So if we have MSPs that want to come into the program, but they’re not ready on that post-sale side, well, guess what? That can become the role of the distributor. And secondarily, this is where the enablement really comes into play as well. And so that’s why we’ve built very specific paths on enablement, pre-sales and post-sales, where partners can choose their own adventure. “Hey, if I want to get going on the pre-sale side, well, guess what? I can simply resell.” Or, “Hey, I want to really start focusing on the post-sales services implementation.” I can start to take the enablement around those courses to become more of an expert to really give me those new capabilities. And so there’s a whole conversation around what we’re doing on enablement with our brand new Sherpa that’s really given a lot of these partners those capabilities. Robert Dutt: On the note of Sherpa, an AI-powered tool for partners, it’s essentially a virtual channel account manager in terms of enablement, onboarding, that sort of thing, especially for an MSSP who’s new to SIEM. How does it change the friction of getting started with Exabeam as their platform? Craig Patterson: You’re going to love this. You’re going to love this. So we’ve sort of reimagined all of the enablement. Again, when you look at traditional enablement, it’s like most enablement is built in these LMS platforms. Like, “Hey, partner, go log on to this LMS platform, get your certification, and then we expect you to actually know what the hell you’re doing.” Reality is that’s not what happens. They log on to the LMS platforms. They fast-forward as quickly as they can to the end. They turn the volume down. And then when the quiz comes, they use AI to answer the questions. And so they just find a way to get the certification. The reality is none of that helps them be better in life or actually raise their competency. And so that’s a problem we took on head-on with Sherpa. And so Sherpa was built in a way to really change the way partners learn with the whole goal of raising their competency level so they can be better on the market. And there was really like three use cases we were trying to solve with the emergence of Sherpa. The first is like you think about this global ecosystem that Peter and I have. We have 3000 partners. The partner ecosystem looks different. We have VARs. We have MSPs. We have MSSPs. We have distributors. We have the trusted advisor market as well. All of them have different needs in terms of where they are from a learning perspective. And so the first use case, Robert, is simply like a tool to be able to ask questions. What are the use cases? How do I position this? Why is SIEM or UEBA better than the competition? Just an always-on tool for partners to ask questions. And so that was kind of use case one. And then the cool thing around that is you think about the ecosystem being very global in nature. The other problem with LMS platforms is I’ve got partners in Japan. Well, that means the LMS platform they log on to needs to be able to talk to them in Japanese. And so the beauty with Sherpa, it does all the translation for us. And we’ve got 15 plus languages that are now live in Sherpa. Partners in Japan are talking to it. We got partners in India and all over the world really asking questions in terms of how we position our services. And that integration can be done by just logging on to our portal. You’ll see a bot pop up. They can just simply ask a question. It integrates in Teams, integrates in Slack. So that was use case number one. Use case number two was we reimagined the whole enablement certification platform. And so it’s a very dynamic learning experience. And so the way it happens is you log on, there’s a topic that you like, you click on that, you start learning, it asks you questions, it asks you to position services, and then you record your answer to how you’re actually positioning those services or the features. And it gives you feedback like, “Robert, you did really good on this aspect, but next time you should use this and this.” Or, “Robert, if you’re talking to a customer that’s in this vertical, you should talk about this use case because that’ll help resonate.” And so the whole certification process has been rebuilt and that’s the second use case. The third use case, this is a game changer. And this really goes to your question. And it’s an always-on coach. And so partners are now able to invite Sherpa to calls. And so as they’re having those conversations with customers, and the customer may say something or give them an objection, well, in the background, Sherpa will give them the answer to that objection and say, “Customer said this, talk to them about this.” Or, “Have you shared this new feature that was just released in the quarterly launch?” So it’s like this always-on coach, always-on assistant to really give them what they need. And then we’re putting it on this innovation roadmap. And so every single quarter, we’re launching new innovation in Sherpa. As an example, we’re now launching our LinkedIn integration. So if you’re an MSSP partner, you log on to Sherpa, you’re connected to LinkedIn, it’s going to ask you, if Sherpa can look through your network to find customers that may be a good fit for our services. And then it’ll say, “Okay, great. We found these contacts. Should we go ahead and write the campaign? Should we write a campaign that you can use to send to those customers in your ecosystem on LinkedIn?” And so quite honestly, I think we’re bleeding edge in terms of really being able to use AI and adopt AI in a way to drive good outcomes, well beyond where most companies are with their simple ChatGPT things like that. We’re actually driving outcomes. Robert Dutt: The rise of AI baked into the partner program and partner tools is a fascinating space for me to watch. And that certainly, you make a compelling case for the role of Sherpa there. That sounds really interesting. A quick one on the product side, not directly related here, but just out of curiosity, Exabeam just dropped Agent Behavior Analytics in your April release, sort of extending behavioral detection to AI agents, ChatGPT usage, Copilot activity, those kinds of things. For an MSSP looking to take this to market as a service, is it a new revenue line? Is it an upsell? Or is this sort of becoming table stakes that clients expect to see bundled into what you’re doing for them? Craig Patterson: I’m glad you asked. It was just recently at RSA, the conference, obviously AI is the buzzword, but what do you do with that? When we presented the agentic behavior analytics to a lot of our partners or potential new customers, the question that was often asked was, “Well, how much is this extra?” And that’s not how we license our product. So the behavior analytics has been part of our solution since our inception from our analytics model. So specific to AI, this is going to be, you could differentiate your service from other service providers by using this behavior analytics, but by no means is it an extra cost on the MSSP’s behalf. So they’re going into an organization that has a thousand users, human entities, and overnight they now have 10,000 non-human entities. We look at and model all of them using our analytics. So now you actually have at least a basis of what’s normal from a behavior standpoint for both non-human and human entities. So we really change the game, but haven’t changed the pricing along with it. So it comes naturally within our platform. So no change for me as a partner, but if I can find a way to upsell based on it, all the better. If not, I add additional features. Hopefully my customer is more happy. Peter Stratis: I was just going to say, if you look at the macro trends we’re seeing, this is the number one conversation that’s being had right now, especially like you look at the financial sector. Every single company is facing this problem. And so this really, not only does it give them a new use case to go after, I think it just makes the overall security services of Exabeam more relevant based upon what’s happening in the overall market, which all that makes the revenue stickier, makes those conversations more impactful that those MSSP partners are having. Craig Patterson: Yeah. Well, what I’m going to mention is operational efficiency and service differentiation is what’s key to our MSSPs and their success. So the license is foundational. And now that we’ve actually solved for being predictable from a margin perspective, how can they differentiate themselves, making them operationally efficient using automation, using our threat detection, and then also the service differentiation. And the other thing too, just thinking through this a little bit, I mean, there’s different AI agents that exist out there that are doing different things. You think about the malfunctioning agent, the one that’s just off base and it’s doing things that are just incorrect based upon the fundamentals or foundation of the AI agent. That’s one thing that gets addressed by looking at the abnormal behavior. The second is the misaligned agent, the ones that are pursuing goals in a way that could negatively impact the company. And that gets a little bit more scary. But really what gets scary is those subverted agents, the ones that have been hijacked that are actually causing harm. And so you think about all those different use cases that are happening, and that’s the beauty of what we just released is our new ABA, sort of creating this new category in the market. That’s really what our ABA is looking for, is all those different things that are happening, whether it’s misused, misaligned, or subverted. All that can be detected through this new agent behavior. Robert Dutt: Okay, last question for me. If I’m an MSP who’s been sitting on the sidelines, I’ve been thinking about them or are upgrading my security operations practice. What’s one thing that you wish I understood about the opportunity and the economics, but I probably don’t at this point? Peter Stratis: It’s all about how they actually start off. They’re interested in selling managed security, but they don’t know that they have to standardize their delivery model. They can’t make it where every customer is custom, because that’s when that price predictability goes away. So everything from onboarding to customizing your offering has to go away. You might be able to do it for a certain amount of customers, but you have to build a model that’s repeatable. Automation is going to be very important to that. And then finally, you could add optional add-ons, but you have to resist the temptation to over-customize everything. The great thing about what Craig has done with the APEX Partner Program and the way we built it out here at Exabeam is it supports all of this through all the enablement efforts. So Craig mentioned all the enablement built into the program, but then we have certification tracks. So we’ll help you along in that process. And we have everything from APIs and the use case and the scripts to help you automate that track for you to make it easier, but just don’t jump in and try to do a custom solution for each customer. Robert Dutt: Gentlemen, I thank you very much for your time. Once again, I appreciate your walking us through the commercial framework. Craig Patterson: Thank you, Robert. Appreciate it. Peter Stratis: Thank you, Robert. Robert Dutt: There you have it. Craig Patterson and Peter Stratis from Exabeam. I’d like to thank Craig and Peter for their time today. And a special note, this was Peter’s first podcast appearance. You never would have known it. A few things I’ll leave you with. First, if Peter’s candid admission landed for you — that Exabeam used to treat service providers like resellers with opportunistic deal-by-deal discounts that made it impossible to build a predictable margin — sit with that for a moment. Not unique to Exabeam. That was the industry. And it goes a long way to explaining why so many MSPs have struggled to make managed SIEM work as a business. The new framework is a direct attempt to fix that math. Two pathways: a single-pool capacity model that works well for SMB and mid-market clients, and a federated model that isolates environments for compliance-heavy customers. The discounting structure has been rebuilt from the data up with the goal of moving 80% of deals through a standard process. Up from what Craig described as the opposite of that. The Sherpa AI tool is worth watching closely, not just as a training platform replacement, but as an always-on coach that can actually sit in on partner sales calls and surface real-time objection handling. The LinkedIn integration is coming next, and it starts looking less like an LMS and more like a business development tool. And the closing advice I’ll leave you with is Peter’s. If you’re an MSP thinking about entering the security space, standardize your delivery model before you take on your first customer. Resist the urge to customize every environment. That’s exactly where price predictability and profitability goes away. Thanks as always for listening. In The Channel is available on Apple Podcasts, Spotify, YouTube, and all the major podcast directories. If you’re finding value in the show, leave a rating or review. It goes a long way to helping other folks in the channel find us. Until next time, I’m Robert Dutt for ChannelBuzz.ca, and I’ll see you in the channel.

August 11, 20265 min

The Buzz: Schneider Electric brings multi-chemistry UPS to the edge, Ingram Micro connects AI to partner workflows, and D&H expands Dell storage distribution

Today’s headline news for Canadian IT solution providers: [Schneider Electric]: The company yesterday unveiled its next-generation APC Smart-UPS at XChange August 2026, introducing what it says is the first multi-chemistry battery technology for distributed and edge environments. The platform accepts both VRLA lead-acid and lithium-ion batteries, allowing customers to start with lower-cost lead-acid and upgrade later without replacing the chassis. Read more on CRN. [Ingram Micro]: The distributor says hundreds of channel partners are now using its Xvantage Integration Hub and secure Model Context Protocol Server to connect AI assistants directly to their business systems. Trust X Alliance member Matrix Integration estimates the platform will save its team between 1,000 and 1,500 hours this year, while IT Design Consulting says it cut quoting from hours or days to seconds. Read the announcement on Ingram Micro. [D&H Distributing]: The distributor is now authorized to carry Dell Technologies’ full enterprise storage portfolio in the United States and Canada, adding a new sourcing option after Dell ended its relationship with Arrow Enterprise Computing Solutions. D&H says its Advanced Solutions+ business unit now accounts for more than 25 percent of its overall business. Read more on CRN. [Acronis]: The company unveiled an autonomous IT platform update with an AI-driven console, service desk, and migration tools designed to help MSPs automate operations and expand services. Read more on msp-channel.com. [NCC Group and SailPoint]: The two companies have partnered to strengthen identity security services for both human and non-human identities. Read the announcement on NCC Group. [Lexful]: The company announced general availability of its AI-native IT documentation platform for MSPs, with plans to join the Pax8 and Sherweb marketplaces before the end of 2026. Read more on Yahoo Finance. [Circana]: Research presented at XChange August says AI’s workforce shock is unlikely to ease in the near term, with MSP executives noting persistent talent gaps despite automation advances. Read more on CRN. Read Full Transcript Welcome to The Buzz from ChannelBuzz.ca, I’m Robert Dutt, today is Tuesday, August 11, 2026, and here’s what’s happening in the channel today. Schneider Electric yesterday unveiled its next-generation APC Smart-UPS at XChange August 2026, introducing what the company says is the first multi-chemistry battery technology for distributed and edge environments. The new platform accepts both traditional VRLA lead-acid batteries and lithium-ion batteries, allowing customers to start with lower-cost lead-acid technology and upgrade to longer-lasting lithium-ion later without replacing the chassis. Adam Compton, offer management leader at Schneider Electric, told CRN that the chassis is engineered to recognize different battery chemistries through firmware and battery management systems, which then alert EcoStruxure IT monitoring software about the specific battery type and replacement timeline. The company says future battery chemistries will also be supported as they become viable. For channel partners, the flexibility creates new service opportunities around battery lifecycle management, assessment, and the Rip-Replace-Recycle refresh program. Gordon Lord, vice president of channels, said Schneider Electric is doubling down on its Gateway program to give partners visibility into distributed power infrastructure across customer sites. The online versions of the new Smart-UPS are slated to be available starting September 1, with line-interactive versions following next year. Partners will not require new certifications. Canadian partners working with regulated and industrial customers should note the air-gapped deployment potential and the EcoStruxure monitoring layer as a recurring services hook. Ingram Micro says hundreds of channel partners are now using its Xvantage Integration Hub and secure Model Context Protocol Server to connect AI assistants directly to their business systems. The distributor announced the expanded adoption last Wednesday, positioning the platform as a way to reduce integration friction and automate workflows across quoting, ordering, and customer management. Executive Vice President Sanjib Sahoo described the MCP Server as a way to bring AI directly into the flow of business, giving partners a secure, real-time connection to Ingram Micro’s data mesh without building custom integrations. Trust X Alliance member Matrix Integration estimates the platform will save its team between 1,000 and 1,500 hours this year. IT Design Consulting CEO Ryan Evans said his team cut quoting processes from hours or days to seconds using the XI Hub integration. Ingram Micro is offering on-demand training sessions to help partners build AI-powered solutions through the platform. The company is positioning the offering as part of its broader strategy to make Xvantage an intelligent operating layer for the global channel. Canadian partners should watch how quickly small MSPs adopt the plug-and-play connectivity, since Ingram Micro reports that smaller providers are the fastest adopters so far. D&H Distributing is now authorized to carry Dell Technologies’ full enterprise storage portfolio in the United States and Canada, adding a new sourcing option for partners after Dell ended its distribution relationship with Arrow Enterprise Computing Solutions last month. The Harrisburg, Pa.-based distributor is bringing Dell’s advanced infrastructure, including Dell Apex as-a-service and subscription technologies, to its Advanced Solutions+ business unit. Chief Commercial and Consumer Officer Marty Bauerlein told CRN that Dell’s decision followed an RFP process and was influenced by D&H’s execution capabilities and growth mindset. Partners including Precision Computer Services and CompuCom have praised D&H’s responsiveness and collaborative approach. D&H says its Advanced Solutions+ unit now accounts for more than 25 percent of its overall business. For Canadian partners, the move adds another distributor option for Dell storage and server infrastructure at a time when Dell is also rolling out program changes focused on AI outcomes and faster rewards. The timing means partners can evaluate sourcing alongside the new rebate and registration structures Dell is expected to introduce this month. In Brief – Acronis unveils autonomous IT platform update with AI-driven console, service desk, and migration tools for MSPs. NCC Group partners with SailPoint to strengthen identity security services for human and non-human identities. Lexful announces general availability of its AI-native IT documentation platform for MSPs, with plans to join the Pax8 and Sherweb marketplaces before the end of 2026. Circana research presented at XChange August says AI’s workforce shock is unlikely to ease in the near term. Full details and links in the show notes or the blog post. Later today on In The Channel, my conversation with Exabeam about rebuilding the MSSP commercial model to fix the economics of managed SIEM. And if you haven’t heard it yet, check out my conversation with Chris Fabes from TD SYNNEX Canada about his three-sided view of the channel. That’s how we’re seeing the headlines today. I’m Robert Dutt for ChannelBuzz.ca, thanks for listening. Have a great day.

August 6, 202631 min

Chris Fabes brings three-sided channel view to TD SYNNEX Canada

Chris Fabes, president of TD SYNNEX Canada Chris Fabes is two weeks into his new role as president of TD SYNNEX Canada, and he brings a perspective almost nobody else in the Canadian channel can match: senior leadership experience on all three sides of the ecosystem. Fabes spent a decade at Lenovo Canada, where as channel chief he tripled channel revenue to $1.2 billion in three years. He then moved to SHI International, where he led the Canadian operation with a focus on enterprise and public sector. Now he’s at the distributor side, taking over from Mitchell Martin, who ran the business for 35 years through multiple mergers and industry transformations. In this conversation, Fabes discusses what he learned from seeing the channel from the vendor, reseller, and distributor sides – and how each perspective informs what partners should expect from TD SYNNEX going forward. He talks about the booming Quebec market (he’s Montreal-based and bilingual), the role of MSPs as “AI ambassadors” for 1.3 million Canadian SMBs, and the shift from traditional SaaS consumption toward tokenomics. He’s candid about needing more time to assess TD SYNNEX’s internal AI readiness, and he closes with a challenge to the Canadian channel: be “proud and loud” about what the ecosystem has accomplished. Read Full Transcript **Robert Dutt:** Hello and welcome to In The Channel from ChannelBuzz.ca, bringing news and information to the Canadian IT channel community for the last 16 years. I’m Robert Dutt, editor at ChannelBuzz.ca, and your host for the show. Today I’m joined by Chris Fabes, who’s just a couple of weeks into his new role as president of TD SYNNEX Canada. Now, TD SYNNEX is of course the largest technology distributor in the world, and the Canadian operation has been a fixture of this channel for decades. But this is a transition moment. Mitch Martin ran the Canadian business for more than 35 years, starting out with Merisel Canada, through the Synnex acquisition, the pandemic, mergers with Westcon, and finally the merger with Tech Data. He retired earlier this year and TD SYNNEX went outside the organization for his replacement. They found Chris Fabes at SHI International, where he was running the Canadian operation. Before SHI, he spent a decade at Lenovo Canada, where as the channel chief he tripled channel revenue to $1.2 billion in three years. And before that, he started his career at a reseller. So, he’s one of the very few people in the industry who’ve held senior leadership roles on the reseller side, the vendor side, and now the distributor side. A 360-degree view that I think is worth exploring. We talked about what he’s seeing in his first two weeks, what partners should expect from TD SYNNEX Canada under his leadership, the Quebec market, which he calls home, AI, program simplification, and why he thinks the Canadian channel ecosystem should be, in his words, “proud and loud.” Let’s get right into it. My chat with Chris Fabes. Chris, thanks for taking the time. I appreciate it. **Chris Fabes:** Thanks for having me. I also appreciate it. **Robert Dutt:** Pretty epic way to get the distributor side of things on your channel bingo card, having already done the reseller solution provider and vendor side. Congrats on the new gig and I guess in general, your thoughts on taking over the leadership of TD SYNNEX Canada at this moment. **Chris Fabes:** I appreciate that. And look, how could I not be excited? It’s an incredible opportunity. As you mentioned, I’ve been on the vendor side as well as the value-added reseller side, but distribution is definitely not new for me. I’ve been working with TD SYNNEX for many, many years in different capacities. So it’s exciting having known the organization, knowing a lot of the people, and just quickly being pulled into internal and external conversations about, “Hey, what can we go do to go big?” So it’s just really exciting and I couldn’t be happier. **Robert Dutt:** As we touch on there, you’ve had senior leadership roles reseller side, most recently SHI, the vendor side with Lenovo, and now you’re adding the distributor side—a perspective that not many people have at the senior level especially. How has seeing that ecosystem from all three of those sides changed what you think a distributor actually needs to do for partners? **Chris Fabes:** I think it gives me a perspective that is rather unique. I always like to look at what the market is asking of the channel ecosystem and for each of those components, where do we add value and how do we focus on the outcome that our customers, vendor partners, and the ultimate end user are looking for. I think we can all agree that while technology, the whole industry is an exciting place to be—and I think we’d be doing something different if we all wanted things to be simple—the pace of change and the pace of innovation is really exciting. I think with all of the growth and now complexities built into the ecosystem, distribution plays an even more pivotal role in being able to service the demand. That’s what’s really exciting looking at the future. **Robert Dutt:** At Lenovo, one of your signature achievements was tripling channel revenue to $1.2 billion over the course of three years. What was the thesis and the plan behind that growth in that time, and is any of that transferable to the distributor context where you’re one step further removed from the end customer? **Chris Fabes:** I think it absolutely is relevant and it aligns. It all starts with planning around what the expected demand is and making sure that the differentiation and the capabilities are aligned with that opportunity. Even answering your question from the Lenovo side of things, it was: where’s the appetite? Where are the routes to market? How do we pull the levers at the right times? How do we make sure that we’re talking to the customers, being the channel partners as well as the end customers, so that we can pivot as required? Looking at the distribution side of things, it’s really no different. In the Canadian market, it is really: where’s the spend coming from, who is touching those spend requirements, and how do we participate in a meaningful way where we’re adding value to the equation? **Robert Dutt:** You spent a decade at Lenovo on your way up, literally working your way up the organization. How does that kind of ground-level experience shape your leadership style and what are you looking for in the teams you’re building now? **Chris Fabes:** Great question. I’ve always looked at myself as being someone that respects people at all levels. I don’t see myself any different from anyone else in any organization. So I really seek to understand, look to build relationships, and listen first. I lead with trust, which I think allows you to operate with very low friction, allowing people to outperform at their best levels. I make sure that I celebrate success along the way, but also hold people accountable. It’s been fun being able to work for people and then have a flip-side relationship as I was able to grow into different leadership positions. Being humble and respectful of all those relationships has benefited me as I’ve moved into positions where the relationships, even if they might be different now, are very much respectful. I’m happy for them; they’re happy for me. We have a short memory when we want it to be short, but long when it matters. In this channel, being that it’s large yet very small at the same time, leaving those relationships better off has been an important part of the way I’ve looked at people. **Robert Dutt:** I asked you a little while ago your perspective on what you can bring from the vendor side to the distributor side of things. Sort of the same question, but coming at it from your more recent point of view from the reseller side at SHI. A massive reseller—what did your time there teach you about where distribution adds value, where it doesn’t, and what you wanted from distribution when you were in that seat? **Chris Fabes:** Sure. There were a lot of conversations. Most of my conversations at that point were internal around building strategy. I think we’ve touched on that quite a bit, but the other side was just talking with CIOs, CEOs, and VPs that were responsible for technology decisions. The technology decisions almost became the easy part. It was: Where can you help me around optimization? Where can you help me on cash flow? How can you do things that are lower friction? What happens when something might not be going perfectly? Is there an escalation path? So, process—that’s what I started to learn and be able to apply to that business. Again, I think having that lens of those customer expectations and understanding the flow down through the complete channel ecosystem allows me to look at distribution from a strategy and execution lens, combined with the ultimate goal of satisfying those that are ultimately deploying the technology—whether they be SMB, mid-market, enterprise, or large public sector. **Robert Dutt:** Mitch Martin ran this business for 35-plus years. That’s a pretty extraordinary tenure and he went through pretty wild changes in the industry and in the organization in particular. What do you see as the foundation that he left there? And what do you see, especially in your early days, as the biggest opportunities for fresh investment or new ideas? **Chris Fabes:** Respect the legacy. That’s first and foremost. In my first couple weeks of talking with the staff, what I recognize is there was a strong hand on the business. The foundation was strong, mature, and very well operated, but that doesn’t mean we still can’t look at areas of opportunity—the nuances, the incremental spend, and how we bring additional value. So I’ll be spending my time respecting the mature foundation and the expertise that already exists in the business, listening and having an open mind, but looking at that three-to-five-year future of where TD SYNNEX needs to be based on the market appetite. I want to underscore that in speaking to many people in my first days, it was so incredible to hear the tenures—10 years, 20 years, 30 years—and the passion that they’ve had as they’ve gone through their career with TD SYNNEX through multiple mergers and acquisitions. What they shared with me was just the trust and the love in the organization and the people. I consider myself very lucky to be taking that baton and moving forward with it. **Robert Dutt:** TD SYNNEX is the largest distributor in the world and the competitive landscape is shifting. You’ve got Ingram Micro as the other big traditional broadline folks, and you’re both redefining yourselves in your own ways. As always, there are specialists and newcomers. You’ve got cloud marketplaces. I guess I’m curious, where do you think from where you sit now that TD SYNNEX needs to differentiate itself most urgently to stand out in the current marketplace? **Chris Fabes:** We’re absolutely looking at how we maintain a position of leadership, and that comes down to understanding the market and understanding—and respecting—our competition. Those are going to be the conversations we’ll be having in terms of: How is the ecosystem changing? How is the appetite for technology changing? Are we in a position to meet the demand but also accelerate the demand? Obviously, there’ve been several tailwinds driving the appetite for various technologies, but there’ve also been headwinds where budgets have shifted in how the spend is being distributed. There’ll be that “tech talk” cycle of how we look at the opportunities and how we partner—and who we partner with—to make sure that we’re positioned to grow at scale but continue to take a leading position. **Robert Dutt:** The press release that announced your arrival at TD SYNNEX emphasized enterprise and public sector. Those are areas that you focused on at SHI. Is that a signal that that’s an area where we’re going to see TD SYNNEX push harder in Canada, or more reflective of your background in recent history? **Chris Fabes:** I don’t think we want to read too much into my background. There are no assumptions that I’ll take what I was doing and immediately deploy something like that in this new structure. But where I think there is an opportunity is looking at the buying flow of goods and where in the Canadian market we expect to see the need for services, partnerships, and guidance. There have been several announcements within Canada where there’s going to be increased spend in certain industries—defense is one. We can call that the broader public sector. We also continue to see from an ICT spend that security remains a high priority across the country, as well as the continued investment in readiness in the infrastructure stack. Ultimately, it’s what is driving that demand, and I will be looking at the segmentation and how we best support the customers and partners. **Robert Dutt:** TD SYNNEX’s operational heart—the offices of both legacies that have come together over the years—is typically in the western side of the GTA, and you’re out of Montreal. I’m curious how you’re thinking about the geographic balance of the Canadian business writ large, and with your presence in “La Belle Province,” is there an opportunity to lean harder into Quebec and the francophone market? **Chris Fabes:** Absolutely. The Quebec market is booming. It’s very attractive for us to continue to focus on the areas of growth. We will be taking a national approach, but it’s important that each market has its nuances and its differences. Yes, we have most of our team members within central Canada, on the west side of Toronto, but we’ll be looking at where the demand is. I’m lucky enough to be in Montreal and speak both official languages. I look forward to working with our Quebec partners and vendors to understand if there’re any areas of opportunity that we can help them address. It probably won’t hurt that I am local—born and raised here—and understand the market and the people. **Robert Dutt:** As we speak, you’re two weeks into the role. As this airs, it’ll probably be more like three—”grizzled veteran” territory, clearly. Can you tell me a little bit about what you’ve been focused on for that first fortnight in the role and what you’ve heard from the crew, from resellers, and from vendors? **Chris Fabes:** It’s been nothing but positive. If my wife was here, she would confirm the conversations that she’s overheard! I want this to be a very intentional and honest response. Whether it be the folks that I’ve worked with in the industry, the customers that we serve, or the staff I now have the opportunity to work with, it has been very positive. I was in the Mississauga office for the past few days. I intentionally spent multiple hours walking the floor, shaking hands with all of our people, and asking for feedback. My goal is for our vendor partners and customers to see the value we can bring scale when we understand their business. I personally will hold my team accountable to understand the business drivers of our partners and customers. I will personally make sure that I’m involved in those conversations and in that planning—the good and the bad—so that I have a pulse on what’s expected of us. It’s really about decisions being rooted in reality and relationships. **Robert Dutt:** Last month at ChannelNext Central, you talked about MSPs as “AI ambassadors” for a million or more Canadian SMBs. Now you’re running the biggest distributor in the country. How do you enable that? What’s the distributor’s role in making MSPs successful as AI adoption accelerates and especially SMB customers start looking for more on that front? **Chris Fabes:** Absolutely. There are going to be some additional opportunities to look at how we provide services to the broader MSP market and how we serve them in the infrastructure build-out. There’s also a real conversation around the FinOps change—whether it be consumption or traditional SaaS moving to tokenomics. I think we as a distributor have an opportunity to listen, adjust, and build supporting models that support their build-out. We already do have programs in place to be able to support the MSPs in Canada, so we’ll continue to engage through our partner-led events and continue to build out what that model looks like. **Robert Dutt:** Internally, we touched on AI with the last question. All the distributors are trying to build the business of the future around what AI will mean to the kind of data you can provide. I’m curious about your assessment of TD SYNNEX’s stature in that race at this moment and where you see the biggest opportunities for next steps. **Chris Fabes:** I would say, honestly, I need to spend more time understanding where TD SYNNEX is from an AI perspective. I say that with honesty because my message to the team is that I need to observe and understand the ins and outs of our business. But what I will say broadly is that the appetite for AI is absolutely there and it requires a lot of readiness. Each of our customers is at a different stage. We will meet you where you are, whether it is services readiness, policy, governance, and compliance where we can help at scale, or modernization around infrastructure. We will make sure that we are absolutely ready and take a leading position, because the opportunity is insatiable. Most critically, it’s: how do our partners and their customers use AI to increase their competitive edge and optimization? We’ll be right there beside them. **Robert Dutt:** Back to your Lenovo days, another one of your big projects was simplifying the channel program. “Deadpan Simple” was a phrase I think you liked to use at the time. Distribution programs tend to be on the complex side. I’m curious if you see a simplification opportunity for TD SYNNEX Canada? **Chris Fabes:** In the early feedback that I’ve already received, what customers focus on is the execution. While maybe there are a lot of moving parts, if we execute and communicate seamlessly, that’s the experience that our customers are getting. Is there an opportunity for me to go validate your statement? Absolutely, and I will. It will be a focus of how we make sure we’re bringing the right outcomes and operational excellence. I don’t have a future statement yet, but I’ll be looking at it over time. Our platforms and programs have to be best-in-class if we want to continue to take a leading position. **Robert Dutt:** You’ve been in this community for two decades. What do you see as the big differences between the Canadian channel ecosystem and the US? And what do American-headquartered companies get wrong or misunderstand about the Canadian market? **Chris Fabes:** Part of the reason why this was attractive for me is that there is a respected understanding of how the regions operate. Having leadership and teams that understand our market and our ecosystem was absolutely important. But at the same time, when you can centralize resources and apply the scale at a global level and then bring that to a market like Canada, that allows us to speak with our customers with a much bigger toolkit. I think there is a really interesting balance at TD SYNNEX between the centralized functions of a larger organization and the regional focus and ability to execute based on what the local market desires. **Robert Dutt:** So it sounds like it’s a matter of finding the right balance between the global playbook and local use. **Chris Fabes:** Absolutely. We can learn from anywhere in the world, whether it be at a technology level or a thought leadership level. I’m a big fan of best practices—some people would say “shamelessly borrow”—and you apply it to the market. There’s magic in being open-minded and collaborative but not losing sight of what’s expected locally. **Robert Dutt:** Wrapping it up, what can Canadian VARs, MSPs, and solution providers expect from yourself and from the team at TD SYNNEX going forward? **Chris Fabes:** Expect us to be collaborative. I really mean it. That is the way I operate and it’s what I’ll hold the team accountable for. A partner doesn’t tell the other partner how to do it without listening or understanding. We are going to win together. That is a commitment that I have to our team in Canada and to our customers and partners—that engagement and interest in growing in the right ways. **Robert Dutt:** And one last one, mostly just for fun. If you could wave the proverbial magic wand to change one thing about how the Canadian channel works today, what would it be? **Chris Fabes:** I would say the people and the execution—the level in which the Canadian market has, from time to time, outperformed other areas of the ecosystem. I think the Canadian ecosystem should be “proud and loud” in terms of the accomplishments that we’ve been able to achieve. I look forward to being part of that voice that we can further raise within the local community. **Robert Dutt:** All right, so just be louder and keep doing it better. Sounds great. Chris, good luck with the new role and I look forward to keeping track of things going on at TD SYNNEX. Thanks once again for taking the time to chat. **Chris Fabes:** Thanks, Rob. I enjoyed the conversation and look forward to connecting again soon. **Robert Dutt:** There you have it. Chris Fabes from TD SYNNEX Canada. I’d like to thank Chris for taking the time just two weeks into a new job to sit down and talk about where he’s been and where he thinks TD SYNNEX Canada is headed. Really appreciate his candour around AI. He basically says, “still learning where we’re at,” which is a lot more credible in week two than a rehearsed vision statement might have been. And I think his challenge to the Canadian channel to be “proud and loud” about what this ecosystem has built is worth thinking about. There are a few things I’m going to be watching for as he settles in. Whether TD SYNNEX makes a real push into Quebec now that they’ve got a bilingual Montreal-based president; what a program simplification effort might actually look like given his history of stripping complexity out of partner programs; and how he thinks about the distributor’s role in a world where more and more transactions are moving through non-traditional models like cloud marketplaces. If you enjoyed this episode, I’d really appreciate it if you followed or subscribed to the podcast wherever you get your podcasts. We’re at Apple Podcasts, Spotify, YouTube, and most of the major podcast directories. And if you have a moment to leave a rating or review, we appreciate it. Until next time, I’m Robert Dutt for ChannelBuzz.ca and I’ll see you in the channel.

July 22, 202633 min

Michelle Biase on what HP Canada learned from a year of seeding AI PCs to partners

Michelle Biase, president and managing director of HP Canada Michelle Biase has now been in the president and managing director chair at HP Canada for eighteen months. In that time, the company has grown its Canadian sales team by fifty percent, moved from siloed PC, print, and Poly sellers to a unified One HP go-to-market model, and watched AI PC sales accelerate to nearly two-thirds of PC volume. In this episode of In The Channel, Biase sits down with Robert Dutt to talk about what HP actually learned from seeding AI PCs into partner hands more than a year ago. The candid answer: “It was early days, so we didn’t have a ton of use cases per se come out of that. But I think it really did help the partners to realize the value of AIPCs and help them think about how they’re going to help their customers deploy those devices.” The partners who are now selling AI PCs well, she says, share three common threads: they are educating themselves through programs like HP’s AI MasterClass, they are thinking about future-ready fleet strategies rather than transactional replacements, and they are using persona-based deployment tools to match the right device to the right worker. On HP IQ, which entered early access this spring, Biase positions it as a better-together play across the entire HP ecosystem – print, PC, and Poly – with AI at the edge addressing latency, token cost, and security concerns. She also points to the Elite Board, a keyboard-integrated PC with no built-in monitor, as a cost-effective and security-minded option for the roughly thirty percent of laptop users who never use their screen because they are docked. The pricing conversation is unavoidably central. With HP operating on 30-day price validity windows and memory costs expected to stay elevated, Biase’s guidance to partners is direct: accelerate the demo-to-close cycle, lean on distribution partners for available inventory, and avoid long configure-to-order cycles that risk price changes during the build. She also makes the case for moving from transactional hardware sales to solution-led conversations anchored in the Workforce Experience Platform, which she describes as a way to “change the conversation from being a transactional hardware conversation to really more of a value-added solution conversation.” Read Full Transcript ROBERT DUTT: Hello and welcome to In The Channel from ChannelBuzz.ca, bringing news and information to the Canadian IT channel community for the last 16 years. I’m Robert Dutt, editor of ChannelBuzz.ca, and your host for the show. On today’s show, we’re catching up with a channel leader who’s now been in the chair long enough to know what’s real and what’s still aspiration. Michelle Biase is president and managing director of HP Canada. She returned to the company in December 2024, just as HP was launching its first wave of AI PCs into partner hands. 18 months later, she’s running a sales team that’s 50% larger, steering a unified One HP go-to-market model, and trying to help Canadian partners navigate memory prices that have made hardware procurement feel like a commodities trading desk. We’re going to talk about what partners actually did with those early AI PCs, how the company’s HP IQ onboard AI assistant is landing in the channel, and the reality of running a hardware business in 2026, and the one part of HP’s portfolio she thinks partners are still sleeping on. Let’s get right into it, my chat with Michelle Biase. ROBERT DUTT: Michelle, thanks for taking the time. I appreciate it. MICHELLE BIASE: Great to see you again, Robert. Happy to be here. ROBERT DUTT: When we first gave those AI PCs to partners, that was the early days, right? MICHELLE BIASE: Yeah, geez, that seems like a long time ago. So those are really the early days of AI PCs, right? As manufacturers, we were rolling out those AI PCs. And the intent originally was to allow partners to really get those devices in their hands so that they could experience what was possible with those devices and really start to play with them and get comfortable and explore what they might offer their customers. And I would say it was early days, and so people were still sort of figuring out what the use cases were at that time and thinking about what was possible. But we did want them to play with some of the built-in tools that we had offered and we still offer as part of our HP PCs, AI PCs. So we had our Poly Studio tools and at that time we had AI Companion. And so we had some tools built in and we wanted to show the power of those tools with AI PC. We wanted people to experience the battery life and run Copilot and understand how the PC was going to respond and be utilized. And so there was a lot of good conversations around the power of the AI PC at that time and really sparked people to think about, okay, we need to get over the hump of the hardware transition and investment and start thinking about how we’re going to move forward with this. And so we had some good experiences. I would say, to be honest, it was early days, so we didn’t have a ton of use cases per se come out of that. But I think it really did help the partners to realize the value of AI PCs and help them to think about how they’re going to help their customers deploy those devices in their environment. So it was really intended to get people rolling up their sleeves and getting their hands on the product. And I think we did accomplish that. ROBERT DUTT: A year on from that experiment, now, what do partners who are having success in selling AI PCs have in common? What are some of those common threads that you’re seeing? MICHELLE BIASE: Yeah, I mean, we have a lot of partners who are doing well, we’re definitely seeing our AI PC volumes increase pretty significantly. So first of all, I would say that those partners are educating themselves. So they’re completing training like HP AI MasterClass, which is a suite of educational series that we offer to help partners and their sellers in their organizations really understand AI and the value. And they’re also working really closely with us on how to help their customers navigate the current environment and prepare for the future. I think partners who are selling AI PCs are really thinking about equipping their customers to be future ready. You know, we’re still learning all the use cases as an industry right now, and customers are going about different ways of kind of figuring out what those use cases are going to be. But we all know that the adoption of AI is going to happen at a rapid pace, it is happening at a rapid pace. And so having the right hardware strategy in place is really important. And so partners are helping their customers, you know, deploy technology that really sets them up for that future ready conversation. And then I think the other thing they’re doing is really helping their customers and guiding them to think about a persona-based fleet deployment strategy. So as we think about, you know, costs increasing, and the, you know, number of options that are out there in terms of devices, we have tools like WXP, which is our Workforce Experience Platform, which is a single pane of glass IT management tool that when deployed can help customers to see in their environment, who within their organization based on persona and workflows and work streams need what type of devices. So maybe not everyone needs an AI PC today. I think that, you know, this tool then helps them to understand who needs an AI PC right now, who needs a refresh, who doesn’t, you know, and really help them to kind of manage the deployment of those devices, you know, considering cost and AI adoption and all the things that customers are considering. So I think those are some of the things partners are doing is really educating themselves, thinking about being future ready, and then thinking about new ways of fleet deployment and management to help their customers navigate current situation. ROBERT DUTT: So since that initial test run, we’ve had the rollout of HP IQ in early access since the spring. The idea being more onboard capabilities, basically running a full LLM on the machine. How is that landing with partners and their customers so far? Is it one of those… is it a today conversation? Is it early adopter? Or is it in that kind of future ready mode that you were just touching on? MICHELLE BIASE: Yeah, HP IQ is a really exciting advancement for us in terms of our One HP strategy. So I would say it’s early days, we’ve just launched it recently at our event. It’s only available on some PCs, so not available on our full fleet of products at this point. But HP IQ really represents HP’s vision for a true better together connected, intelligent workplace experience. So, you know, when you think about, you know, some of the opportunities it presents, one is around leveraging AI at the edge, right? So, you know, we know that as customers are thinking about deploying AI, and I talked to a lot of customers who are going to a more, what I would say is like a distributed rollout model now where instead of it kind of holding the reins, they’re putting AI tools in the hands of their employees and saying, here’s a tool you figure out, you know, how to make this make sense for you in your day to day job, and then having a reaction to their cloud and token costs as a response to that, they’re quickly sort of thinking, okay, well, how are we going to manage security, cost, latency, all these things. And so having functionality work at the edge on the device is an interesting opportunity and something that we’re talking a lot to customers about. So, you know, that’s one opportunity is around AI at the edge. And then the other is really around what I said around better together. So, HP IQ provides this connected opportunity for all of the HP devices across our entire One HP portfolio. So, print, PC, Poly, etc. So when you think about, you know, imagine an experience where you walk into a meeting room that’s outfitted with HP Poly collaboration technology, and you have an HP laptop, all of a sudden, those devices start speaking to each other. And the room recognizes that I have the meeting room booked for that next hour, that there’s going to be 10 people in the room and five people online, and it starts firing up the right cameras and opens up the screens that are in the room and sets up that meeting for me. So that, you know, we don’t have to lose that sort of 10 minute, we call it the meeting room tax, right at the beginning of every meeting, there’s like 10 minutes consumed trying to figure out how to get the technology to work in the way that works for everybody in a hybrid environment. So, you know, HP IQ is really intended to provide one that better together story across the entire HP ecosystem, and then leveraging AI at the edge to solve challenges around latency, cost, security, environmental impact. And so it’s early days, but it’s a really exciting advancement for us to kind of bring that narrative together around the One HP value proposition. ROBERT DUTT: Does that better together part of things… is that a big part of sort of how partners can answer that? I have to imagine partners are going to get asked if they present an idea like HP IQ, what are the natural responses for customers is going to be, don’t I kind of already get this with a Copilot license? Obviously, it’s differentiated. But is that that kind of better together? Is that the path to explaining the value difference there? MICHELLE BIASE: I think there’s a couple things. I think for sure, better together is one big value proposition that we believe. I mean, when you think about HP and our position in market, we are the only OEM that can address the entire employee ecosystem. And so having a single vendor across the edge, and then having that ecosystem be AI powered really can create a lot of different experiences, both from an IT manageability perspective, and then from an employee user perspective. And so, you know, the possibilities once the devices are able to speak to each other, the possibilities are kind of endless in terms of, you know, advanced detection of hardware challenges, better usage of the products that they’re using together, so headsets and PCs and cameras and all of those things and how they connect together. So there definitely is that value proposition around the better together One HP story if you have an entire HP ecosystem. And I think, you know, with so many AI applications out there now Copilot, there’s others people are using, I think it’s really important that partners work together with their customers to understand their specific needs, and how they want to design and deploy AI and the concerns they have around doing so because, as I’ve mentioned a few times, you know, things like latency, things like cost, data residency, sovereignty, security, all of those things are hot topics for sure right now. And each customer has their own unique needs and different applications can solve for that. And, you know, we’ve used the word hybrid in our industry in many over the decades in many different ways. When we went all cloud, we said, Oh, no, it’s probably going to be hybrid. When everybody went home, now we’re saying it’s going to be hybrid. And I think AI deployment and AI solutioning is also going to be hybrid. There will be a home for multiple applications inside of customer ecosystems. There will be, you know, cloud deployments that make sense, edge deployments that make sense. And so I don’t think it’s a HP IQ versus other tools per se, but it’s here’s how you can get the most value out of your HP ecosystem with HP IQ and how we can enable that hardware to be most powerful when you’re using other applications as well. ROBERT DUTT: You touched on how customers are actively thinking through where their AI investment lives, edge versus cloud. What are you seeing as really shaping that decision? You know, amongst the things that are in the mix, you know, sovereignty, privacy, sustainability, security, pricing, what moves the needle the most right now? MICHELLE BIASE: Yeah, it’s a good question. And we are having a ton of those conversations with customers. And so I would first say, you know, in the last maybe three to six months, we have seen a rapid shift in the fact that people are getting over the hump about the hardware investment. So, you know, six months ago, people might have still been questioning like, do I need an AI PC? Or what’s, you know, when do I need the AI PC? We’ve seen our AI PC sales accelerate significantly, we’re at, you know, almost two thirds of our PC sales are now AI enabled PCs. So I think we’re over the hardware hump, we are over the hump of people thinking like, AI, is it really coming when what is it going to do for me now? So from an investment perspective, I think, you know, we’re there. When you think about some of those things, you listed sovereignty, privacy, sustainability, pricing, etc. I think, you know, security, if you’re talking private sector, you know, security and pricing, or cost is probably those are the two biggest things that I’m hearing from people is they know they have to roll it out quickly. So very quickly, customers are moving from IT controlled AI deployment to let’s put it in the hands of our users and see what solutions they can come up with. And by the way, AI is getting better every day. So AI can help them figure out what solutions they can come up with to make their days more productive or, you know, better serve their customers. And but and there is an associated token cost or cloud cost that very quickly they’re realizing comes with that. So those are kind of the two main factors. I think the other thing that I hear customers talk about is, you know, how are they kind of leading their AI strategy? So is it an IT led strategy? Is it a business led strategy? How are those two things coming together? And then finally, how are they measuring ROI? So, you know, we’re going to invest in this, we understand that there’s going to be associated costs. But sometimes a cost is okay, if the ROI is greater, and you’re making an investment to, you know, increase your revenue or improve your profits or serve your customers better or create a competitive advantage. So the possibilities are so endless, I think there’s a lot of conversations, but I think privacy and cost are the ones that kind of float to the top of the conversation these days. And we’re really trying to address that with a secure AI at the edge story. I think that that’s where we’re really trying to help customers is figure out what applications you can run at the edge. And we have some good use cases for that already, examples of things we’ve worked with customers on. And so those are exciting opportunities when you can really figure out how to deploy at the edge makes a big difference. ROBERT DUTT: So one more around HP IQ specifically, it’s requiring 24 gigs minimum. So a pretty performant machine. It’s bringing together two of the biggest shaping factors, I think, of the IT industry in the first half of this year, one being RAMageddon and the other being tokenomics. How do you want partners walking customers through thinking about cost of acquisition for a more performant machine versus the ongoing cost of tokens if they’re living their AI in the cloud? MICHELLE BIASE: Yeah, it’s definitely a tricky time. There’s a lot of factors right now that are at play in terms of decision making around investment. So I think while prices have gone up, and as I mentioned earlier, I mean, customers are still making those investments where they need to future proof their business. And so they’re figuring out how to do that within their broader IT budgets. I think things like persona-based fleet management, like we discussed is helping to manage costs. We’re actually bringing some interesting technology you may have heard through our CES announcements with devices like the Elite Board, which is basically a keyboard that has the full power of an EliteBook built into the keyboard. And it has no monitor on it. And so it’s not a full laptop, people might say, why would I need that? Why would you create a keyboard that doesn’t have a monitor? And we actually have data that suggests that over 30% of people who have a laptop actually never use the screen on their laptop, they just use it to dock. And so, you know, we are bringing innovative technology like the Elite Board to market. So if you think of a use case where you have a person who’s not a mobile worker, but maybe they work at home two days a week, and they work in the office three days a week, and they’re in a cube environment or an inside sales rep, and they’re just carrying that device back and forth from one office desk to another and plugging it in, and then using a big monitor, this can now be used as the keyboard. So it reduces the cost of having to add another keyboard to the desk. The Elite Board provides options around security. So you think about someone, unless they’re carrying a portable monitor, they can’t go to your local coffee shop and start working on their work there. So it addresses a security concern, and it’s priced more competitively than a laptop. So we’re giving people options when they think about their full fleet to say, you know, do you have personas where an Elite Board might make sense that frees up some dollars for you to then go invest in areas where people need full powered AI PCs or workstations. So token costs are really a reality, and many customers are realizing that. And so as I said, like the real opportunity, I think, is AI at the edge and getting creative around how they’re rolling out their fleet. And then I think many of our partners are also adding AI development and consulting services to their offerings so that they can help customers to really focus on where the greatest ROI is and help them to develop solutions to roll out AI as well. So a lot of factors, but we’re bringing a lot of flexibility to market in terms of some of those answers and opportunities to help customers. ROBERT DUTT: HP’s CFO said a couple of months ago that memory prices will stay elevated for many quarters, I think was the line used. I’ve seen reports or suggestions, everything from things are stabilizing this month to things are still going to surge, acknowledging that there’s no single crystal ball or source of the truth. You know, what’s your current read for partners who are trying to plan what things are going to look like on the costing issue going into the second half of the year? MICHELLE BIASE: Yeah, if I had a crystal ball, then I may be doing a different job. So, I’m hearing the same things you’re hearing. There’s varied feedback depending on which chip manufacturer you’re talking to or kind of which industry trends you’re following. So I’m not going to try to predict what’s happening. I do think that partners need to, again, be working with their customers on future ready strategies. And so when we think about what tools we’re providing partners and what flexibility we’re giving them in terms of the value of their partnership with HP and what they can take to customers, we have several things that we’re bringing to market to help. First of all, again, WXP, which I mentioned, which is our Workforce Experience Platform, is a fairly economical software solution that partners can deploy within their customers’ organizations. And it really is designed to help them assess and gather information that they need to make intelligent and proactive fleet management decisions. So deploying that tool gives partners an opportunity to introduce a new solution and service to their customers and helps them to use that data to then provide proactive and intelligent decision making and support to their customers. So WXP is one. Introducing new products like the Elite Board, which I mentioned, is another that gives flexibility. Also, the value of selling across our ecosystem is another way that partners can help to manage their overall profitability in their business these days. So if you think about selling only PCs, there might put some profit pressure for partners as they’re heading into the next couple of quarters and halves. But if they’re selling across the entire ecosystem, adding on accessories and attach and Poly and print and all the things, then we have extra value and benefits in our programs for partners to help make that more beneficial for them. So we are trying to bring programs and initiatives and technology to market to help provide our partner ecosystem with new tools that they can use to manage their business going forward from a profit perspective a little bit better and also provide data and intelligence to help their customers to navigate. One thing we are saying is, we’re not advising a wait and see strategy. We do know that in the near… I shouldn’t say we know, but we suspect that in the coming quarters, prices will continue to rise. And so we’re not really advising a wait and see, because the price you have today is likely better than the price 30 days from now or 60 days from now, depending on when the next price increases occur. So we are working with partners and helping them to help their customers say, “What are your real needs? And then how can we get creative to solve for those needs within the confines of budgets or other things that might be at play?” ROBERT DUTT: Do you find partners are doing a good job of optimizing that bundling playbook opportunity with Poly and displays and printers and services and software and all that good stuff? Or that’s still something that needs to be… Or where there’s an opportunity to take better advantage of that? MICHELLE BIASE: I think we’re seeing some good progress. There’s still opportunity for sure, but we are starting to see partners lean in to the One HP strategy. And our team has moved to a sales structure that is now One HP focused. And so as we’re co-selling with our partner ecosystem, we’ve made a lot of changes in our sales organization. And so when we’re selling with our partner ecosystem to customers, we are selling through an entirely One HP lens. And so that helps to drive that conversation forward. And partners are embracing the value of the One HP ecosystem, especially with the introduction of HP IQ and WXP runs across our entire ecosystem as well. So some of those solutions that we’re bringing forward really drive that further. So we’re seeing some good progress there and always more opportunity to drive that conversation with customers and partners as well. ROBERT DUTT: You guys are currently, as far as I know, doing 30 day price quotes. No shade on that. I was at a partner conference this week, literally. The biggest cheer line of the event was that pricing quotes were going back up to 30 days. It’s kind of the state of the world. But where customers are still wanting 60 or 90 day sales cycles, what’s the guidance for partners right now? I suspect a big part of it is that, don’t wait and see side of things, but what else are you telling partners about best taking care of their margin and best taking care of their customers in this pricing environment? MICHELLE BIASE: Yeah, there’s a couple things we’re doing. I think one is obviously working very closely with our partners to accelerate the sort of demo to close conversation. So how quickly can we get the customer to move from, I think I need some PCs. Here’s the demo to here’s my PO. You don’t have the luxury anymore of allowing that sales cycle to take now 90 days. So we’re working closely to try to accelerate that sales process. One of the other things we’re doing is really making sure that we have a good level and assortment of product in our channel. So our distribution partners are really playing a key role right now in making sure that we have product available. And so we are, in certain cases, steering demand towards what’s available in channel and having more of a buy what’s available strategy versus customized CTO units that might take longer to arrive. And by the time they arrive, there’s maybe cost changes or product availability issues and things that come up during the configuration cycle. So we’re really leaning on and working closely with our distribution partners to make sure that we have a lot of inventory in channel and then that we have a good assortment and then asking partners to work with their customers to say, hey, is there something available in channel today? That would meet needs. It presents an opportunity as well if they can get the components for partners to do some configuration work for their customers as well. If the spec is not 100% aligned to what the customer needs, then we’re working with them as well from that perspective. ROBERT DUTT: On that point, given your background at D&H, you’ve seen the other side of supply chain issues and pricing pressure and those sorts of things. How does that inform how you’re managing this whole situation with both your partners and the distis right now? MICHELLE BIASE: Yeah. As I mentioned, our distribution partners are playing a very critical role in our success at this period in time. And so we’re working with them closely to make sure that they have inventory on hand and that we have the strongest assortment that we can to make sure that we have the right mix of product and that it’s close to most of the common CTO units and then steering partners and customers to a buy what is available approach. We’ve made sure that our distribution partners are well aligned with our teams internally so that their risk is minimized in terms of making those types of investments as well. And then making sure that we have an assortment across our entire ecosystem. So not only on PCs, but on some of our what we call attached products. So headsets and accessories and those types of things. So that both the distributors and the channel partners can fulfill that One HP ecosystem together through the channel and not having to wait for different components of products to become available to fulfill the customer’s needs. So they’re really our distributors are critical to our business right now. And we really appreciate them leaning in and are working very closely with them. ROBERT DUTT: This time last year, it felt like the big drivers that everyone was betting on for PC refresh was the AI PC, obviously, which we’ve talked about a fair bit and Windows 10 end of life. Curious how that, which is now in the rear view mirror, played out, especially given the cost environment that we are in today, you know, has it sort of played out the way you expected or are customers kind of holding steady a little bit. MICHELLE BIASE: You know what, I would say the first half of this fiscal year for us, so starting in November, I mean, we’ve had very strong results in the first half. And I think customers are not holding back. As I mentioned, they are, you know, realizing they have to be future ready and future proof their business. And so, you know, there was a lot of customers who made the decision to buy early as opposed to waiting. And so they were sort of leaning in and saying, how can I get ahead and, you know, look at my refresh cycle and buy up for the next X number of quarters, you know, to get ahead of it. The Windows 10 obviously is a requirement for some customers that they couldn’t wait depending on how their environment is managed and the support that they get. And so it really drove, I would say, accelerated refresh cycles, not delayed refresh cycles. I think customers were like, okay, let me get ahead of this and get what I need for the next, you know, three to four quarters. And then we have enough to keep us going. Again, those that were deploying WXP are looking at sort of alternate ways to manage their refresh. Might not have done a one for one for one refresh for everyone, but they certainly bought up inventory and then were like, okay, we can stretch the assets on some of these folks and refresh more people in other areas where the refresh is more critical. So it’s been interesting because I think it’s created a more creative refresh conversation than we’ve sort of been stuck in that typical, you know, three year refresh cycle that everybody has managed for a long time. It’s created some interesting dialogue around alternatives. ROBERT DUTT: When you came into this role in December 2024, I don’t think, AI PC was just kind of in the early days of conceptualizing. I don’t think we could have foreseen the memory spikes we’ve seen. We couldn’t have seen something like HP IQ necessarily coming down the tubes. A lot has changed in that period of time. I’m curious, you know, at this point where you’ve been in the job the time you have, what’s kind of been the biggest thing about running HP Canada that’s different now than what you expected to look like when you took the job? MICHELLE BIASE: Well, that’s a big loaded question. So I’ve been in the role for, I guess, just over 18 months now. And for sure, a lot has changed in terms of what you reference. AI PCs were just getting launched. You know, the One HP strategy was just being released, the whole better together concept. So, you know, from the technology perspective, I would say, you know, it has moved very quickly. I wouldn’t say surprising to me. I think, you know, I always sort of believe that AI was going to drive a rapid transformation in our industry pretty quickly. And so I think, you know, that has played out as I would have expected in terms of technology advancement. I think the thing that is most significant internally for HP Canada is we have made a very significant investment in transformation in our go-to-market strategy. So we, as I mentioned before, have moved to a One HP go-to-market strategy and invested heavily in resources in Canada. So our sales team is 50% larger than it was when I joined. We’ve added several resources in Canada. We’ve added a whole new layer of sales management. And we’ve added several specialists in the areas that we believe are important to our customers in terms of driving their growth strategies. So, you know, around workstations and print and, you know, software and solutions. And so we are going to market now with a whole new approach around selling the One HP value proposition wrapped and layered in our software solutions like WXP and HP IQ. So it has been a big transition. When I joined, we had PC sellers, print sellers, Poly sellers going to the same customers and having those conversations. And now we are elevating our conversations with customers and getting higher up inside the organization because we have a more strategic value proposition to offer around our One HP strategy and the value and benefits of the software and solutions that we’re bringing to market. So it’s been a really interesting time because I get to have, you know, very cool conversations with customers about what they’re trying to do with their technology. There’s a lot of factors around their people strategies and security strategies and all the things that we lean into from an HP perspective, you know, environmental impact of AI. So there’s a lot of HP, you know, long standing strategy, security and environmental, you know, focus is not new for us, but those things are being heightened yet again, because of the advancement of technology. So it’s been a fun 18 months. We have done a ton in that time in terms of transforming our whole team and upskilling our team and adding a lot of resources and then supporting our partners and customers through all the transition that is happening in the market right now. So it’s been fun and there’s a lot more good stuff to come. ROBERT DUTT: With any vendor that’s got a lot in the organization, and that would include you guys, there’s always that, you know, message of we’d love you to cross sell more. We’d love you to, you know, the better together message in whatever form that may take. And I think with One HP, that’s even driving that more. I’m curious at this point, is there any one place where you’d like to, you know, in the portfolio that you’d like to see partners pay a little bit more attention, give a little bit more love towards part of the business, maybe because it’s an untapped opportunity for partners right now. MICHELLE BIASE: I think it depends on the partner. We certainly have some partners who are selling across the One HP ecosystem successfully. Other partners are more focused on print versus, you know, other areas of the business collaboration. So I think really leaning into, you know, the software and solution side of the business, because when you think about Workforce Experience Platform, it is a single pane of glass that provides that management and manageability across our entire ecosystem. And so leaning into selling from a solutions perspective changes the conversation from being sort of a transactional hardware conversation to really more of a value added solution conversation that we believe we’re bringing to market today. And so having more partners lean in and sell that way, if you start with WXP, then selling all of the products that fit in our portfolio under that just bring a greater value. So I think, you know, thinking about HP, you know, as a software and solutions company, and really thinking about the value we bring from that better together in One HP perspective, when you wrap the solutions around it is really, I think, you know, the next great opportunity for partners in terms of them adding more services and growth to their business and what differentiates us as we bring our One HP strategy forward. ROBERT DUTT: All right. Well, good luck on getting that actualized and realized in the market. And once again, thank you so much for taking the time. MICHELLE BIASE: Awesome. Thanks so much. Great chatting with you.

July 21, 202628 min

Mark Sutor on Trust X Alliance in the AI age: The original distributor as platform

Mark Sutor, president of Access Group This episode of In The Channel is sponsored by Ingram Micro Canada. Mark Sutor, president of Access Group and Canadian co-president on the Trust X Alliance Global Advisory Board, joins the show to discuss the community’s recent Global Leadership Summit and what it means for Canadian solution providers. Sutor says the summit’s real differentiator is its focus: “This is not a summit about IT. It’s a summit about leadership.” He reflects on sessions with Constellation Research founder R “Ray” Wang, who warned that AI is commoditizing expertise and that real differentiation lies in experience and market understanding. Ingram Micro executive Sanjib Sahoo also featured heavily, pressing attendees to ask for “insights, not updates.” Sutor breaks down the TXA AI agent coming to the TXA Expand platform, which he says will make the global community feel smaller by surfacing partner skills and capabilities through natural language queries – including publicly available data from websites and LinkedIn. He also addresses the community’s aggressive expansion: new markets including India, the TXA Access program for countries without a formal footprint, and a target of 1,000 member companies by 2027. On the idea that communities like Trust X were an early form of “distributor as platform,” Sutor draws a direct line between the insights he gains at live Trust X events and the AI-surfaced insights he now receives logging into Ingram Micro Xvantage. He says the platform has freed up Ingram’s reps to have proactive business-building conversations rather than transactional ones. Finally, Sutor assesses where the Canadian channel sits on Ingram’s “crawl, walk, run” AI maturity curve. His verdict: the channel has moved past curiosity toward expectation, but execution remains uneven. For partners not yet in Trust X, he argues the community’s core value is collective growth: members share best practices, AI strategies, and vendor program leverage to outpace the broader market. Read Full Transcript Robert Dutt: Hello and welcome to In the Channel from ChannelBuzz.ca, bringing news and information to the Canadian IT channel community for the last sixteen years. I’m Robert Dutt, editor of ChannelBuzz.ca, and your host for the show. Today, a conversation about the evolution of partner communities in the AI age, and a look at how peer networks that predate the current platform buzzword may have been the original take on the “distributor as platform” idea. Mark Sutor is president of Access Group, a longtime solution provider in the Canadian channel, and he serves as Canadian co-president on the Trust X Alliance Global Advisory Board. He recently came back from the Trust X Alliance Global Leadership Summit in Texas and joined me to talk about what landed, where the community is headed, and how the Canadian channel fits into a rapidly expanding global peer network. Let’s get right into it, my chat with Mark Sutor. Robert Dutt: Mark, thanks for taking the time. I appreciate it. Mark Sutor: Glad to be here. The summit was a unique experience — unlike anything I’ve seen in the IT channel before. I’m taking back several action items for Access Group and the Canadian community. Robert Dutt: You mentioned a session with Level Up that stood out. Can you elaborate? Mark Sutor: The Level Up presenter, Patrick, laid out a clear structure for leadership skills. It resonated with what we already do, but gave us a concrete, actionable framework. Robert Dutt: What makes this summit different from other channel events? Mark Sutor: It isn’t an IT-focused summit; it’s a leadership summit for partners, vendors, and Ingram Micro staff. The content is dedicated to personal and professional development, not sales or product demos. Although the material has an IT flavor, the lessons are applicable across industries. Robert Dutt: At the summit, legendary analyst Ray Wang talked about expertise being commoditized by AI. How does that translate for a Canadian partner? Mark Sutor: Ray’s insight reinforced that experience, market understanding, and geography are the real differentiators. Those elements set us apart from purely AI-driven solutions. Robert Dutt: What were the big takeaways for you from the conference at large? Mark Sutor: Several points stood out. First, industry direction: we need to think long-term about AI’s impact on service delivery and customer interaction. Second, AI evolution: AI will move from substituting tasks to fundamentally reshaping processes — much like Uber redefined transportation. And third, leadership discipline: AI is becoming a strategic discipline, not just a technology trend. Robert Dutt: How is applied AI being positioned within the Trust X Alliance community? Mark Sutor: As a member of the Global Advisory Council, I saw that partners are at varied stages — some delivering AI solutions, others exploring internal use cases. We developed a playbook to help members integrate AI internally first, then translate those use cases into client solutions. Robert Dutt: Can you give me the nickel tour on the new TXA AI Agent coming to the Expand platform? Mark Sutor: The AI Agent streamlines partner discovery. Instead of manually searching for a partner with specific skills — for example, installing a Cisco router in Saskatchewan — you can ask the agent in natural language and receive accurate results instantly. It also surfaces vendor solutions across the ecosystem. The tool pulls data from public sources like websites and LinkedIn, as well as internal information, making the community more searchable and collaborative. Robert Dutt: It sounds like the difference between a classic keyword search and a modern, conversational search experience that can even surface new ideas. Mark Sutor: That is absolutely correct. Of course, the challenge is that we all need to make sure we provide the information it needs, but the AI tool is also very good at consuming publicly available information from our websites and LinkedIn. It’s not just looking inwardly. It’s super cool. You use it and you say, “Wow, this is really neat.” You can see where it potentially goes in terms of hooks into the other things that Ingram Micro is doing with AI and agentic tech as that rolls out. Robert Dutt: Trust X Alliance is expanding aggressively — new markets including India, the TXA Access program, and a target of 1,000 member companies by 2027. For the Canadian community, does global scale add value? Mark Sutor: It does impact us, for sure. It’s one of the things I enjoy most about the global events — the camaraderie with other markets. On the environmental stewardship front, for instance, the folks in the UK have been doing amazing things for a few years, and Canada has grown close and participated in some of those ventures. It’s a great way to get a leg up on things happening in other parts of the world. Historically, people liked to go to the U.S. events for a preview of what’s to come, and that is still valid. But I’ve learned many things from the DACH region, the UK, and the Netherlands. I can’t wait to see what comes out of these new markets. Robert Dutt: How do you feel about Canada’s role, given we’ve been there since before the Trust X name existed, dating back to VTN? We’ve always had a reputation for punching above our weight. Mark Sutor: That has definitely continued. Canada has always had a voice a little bit louder than our size. Per capita, we have a very strong membership in Canada — we’re sitting just shy of 100 members now, which by population is much larger than a lot of other geographies. We’re going to continue to have a loud voice because of the dedication of the Canadian members. We always say, “You get out what you put in,” and the Canadian members put in their hearts and souls. Robert Dutt: One of the things I’ve been thinking about, especially as distribution has increasingly redefined itself as a platform, is that in many ways the communities were the first take of “distributor as platform” — not a transactional entity, but a network to create business value, connections, shared intelligence, and leverage. Now we’ve got the technology side with Xvantage. So you’ve got the human community and the digital platform. How does one reinforce the other? Mark Sutor: It’s a great question, and I’m not sure that anybody really knows one hundred percent. Obviously, Sanjib Sahoo spends all of his waking hours thinking about this aspect of distribution. I can tell you that the Xvantage journey has really been quite helpful. Canada is a little bit farther along in that journey than some other geographies. Every day when I log into Xvantage, there are some things there called insights. I learn things for free about my business and about my customers just by logging in. AI has surfaced various insights about things happening in my own company that perhaps I wouldn’t have even known. It’s remarkable that today, in certain areas, the point of trust for me is actually the data coming out of Xvantage and not necessarily my own system. Because Ingram Micro has done such a good job of collecting appropriate data that really can give those insights. I think you’re right — there’s a lot of parallels. When I show up to a Trust X event, I gain insights from other members, from vendors, from Ingram Micro itself. The platform is really helping extend that. Not only does it help extend that through insights, but it’s really enabling the employees at Ingram Micro to take a much more proactive approach to understanding our business. I’m having those conversations more and more often where we’re no longer talking about what’s the price and where is it, and much more about how do we build business, how do we grow, how can we market together, how can we go together into various accounts and be stronger together. These are the conversations we’re having. On the back end, it’s Xvantage that has enabled those cycles to be freed up and for Ingram’s people to show up in a different way. I can tell you that in Canada, they do show up differently today than in the past. Robert Dutt: How so? Mark Sutor: I was preparing for a discussion with Ingram not that long ago, and this was front of mind — how Ingram had showed up differently. While I was preparing, I got a phone call from one of the reps at Ingram saying, “Hey, I just wanted to see if we could get something in the calendar to talk about how we can grow your Azure business together.” I thought, “Well, there you go. That’s exactly it playing out in real time.” These things didn’t necessarily used to happen with the intensity or the frequency in the past. Now these cycles have been freed up, where Xvantage is taking care of a lot of the mundane day-to-day stuff in the back end, and now we can have real conversations about building value for our customers. Robert Dutt: As you talk to your peers, both within Trust X and outside of it across the Canadian channel, do you feel that this idea of the new role of distribution is widely understood, widely taken advantage of, widely optimized? Or is it still a competitive differentiator for those who went in early? Mark Sutor: This is the problem we struggle with. Is it known? Yes. Is it well known? I would say not as well as it should be. I know a lot of members don’t take advantage of the various insights and things that I had mentioned earlier. Getting that word out is one of the objectives of the Trust X Alliance moving forward, both inside the community as well as to the broader Ingram family. Ingram is showing up differently, but I don’t think that the progress they have made is that well known. There’s still a little bit of thought that, well, they have a great website, which is true, but it’s way more than that today. It’s a platform that can do many, many things for your business. It’s extraordinary what Ingram has done in the past couple of years. There are new features being added to the Xvantage platform weekly, biweekly at this point, and it’s a fast-moving process. Part of the challenge, whenever you’re improving a platform so quickly, is to make sure that people stay current with those changes. It’s a huge advantage. It’s a great thing because it’s moving at the speed of the industry, but at the same time, it’s hard for everyone to keep up to date with those various changes. And just to be clear, they do a fantastic job of revealing those new features. They pop up on your dashboard as they’re being revealed. There are various trainings and other things that go on, but life is busy, right? So it’s hard to keep that front and center, but this is a very good problem to have. In the Trust X Alliance, we’re happy to support those efforts and to make sure that the word gets out in an appropriate way. Part of that is to do things like we’re doing today, to make sure that we continue to talk about the successes that we’re having as members and make sure that the community at large, as well as the Ingram family at large, sees those wins. Robert Dutt: Ingram’s overall AI strategy cadence has been the crawl, walk, run idea. Do you see the channel as an aggregate still in crawl, or are we moving towards walk? Mark Sutor: Everyone is still at a very different place in their journey. But I think what’s shifted — I heard someone use this term in one of our affinity meetings the other day — is that things have moved towards expectation. We’re now expecting that AI is going to be doing great things for us. It’s no longer a curiosity, necessarily. And that’s really the shift that I see happening today. But it doesn’t change the fact that everyone’s at a very different position. And in some cases, rightly so. By various industry segment, I think by the nature of those segments, it makes sense to be either ahead or even behind the curve sometimes. But as a community, we’re very focused on elevating everyone’s experience to the point that makes sense for their business, and focusing on that internal use case for AI has been what makes a lot of sense for members. Robert Dutt: If a Canadian MSP or solution provider isn’t in Trust X Alliance today, what are they actually missing that they can’t get from a vendor program or a buying group? Mark Sutor: Well, we’re growing. I think that’s one of the biggest ones. Part of our approach to the marketplace is to grow faster together. And by sharing best practices, by working on things like our AI strategy, by leveraging vendor programs, and so on, we’ve been able to grow faster than the marketplace. And that’s, I think, the continued expectation of the organization is to continue to grow. Robert Dutt: Last one for me. What’s the one thing you’d want Canadian partners to know about where Trust X Alliance is headed over the next twelve months? Mark Sutor: Definitely watch us. I think that we’re doing a lot of really good things in the industry. The Trust X Alliance is really being positioned as the place to go for expertise, the place to go for knowledge, the place to go if you want a good job done as an end client. So the brand is really being built out in a lot of very interesting ways. It’s no longer necessarily just a brand in the IT community, but it’s gaining a lot of traction out there as the brand for IT. So we do extraordinary work together as a community, and I think we’re going to continue to do that. And yeah, I can’t wait to see where we go. Robert Dutt: Thanks for the conversation, Mark. Mark Sutor: Thank you, Robert. It’s been a pleasure. Robert Dutt: There you have it, Mark Sutor from Access Group. I’d like to thank Mark for his time and for sharing his perspective on the Trust X Alliance community and the Canadian channel’s place in it. A few takeaways from me on this one: the idea that peer communities like Trust X were arguably the first iteration of “distributor as platform” — not transactional, but network-driven — and that Ingram Micro’s Xvantage platform is now extending that same logic into digital insights. Mark’s observation that AI has shifted from curiosity to expectation in the channel is worth sitting with. And the note that Canadian partners, in his view, still underutilize what these platforms and communities can actually deliver. If you found the conversation useful, please follow or subscribe to the podcast wherever you get your podcasts. We’re on Apple Podcasts, Spotify, YouTube, and most directories. Ratings and reviews help others in the IT channel find the show. Until next time, I’m Robert Dutt for ChannelBuzz.ca, and I’ll see you in the channel.

July 21, 20263 min

The Buzz: TD SYNNEX names Chris Fabes in Canada, Huntress flags Azure CLI password spray attacks, and MSSP retention moves beyond salary

Today’s headline news for Canadian IT solution providers: TD SYNNEX appoints Chris Fabes as President of Canada: TD SYNNEX announced today that Chris Fabes has been appointed President of Canada, with responsibility for driving the company’s distribution strategy and accelerating customer growth across the Canadian market. Fabes brings more than two decades of IT channel leadership, most recently from SHI where he led a multi-year strategic growth initiative across Canada, and previously from Lenovo where he served as Canadian channel chief and helped triple channel revenue to more than $1.2 billion. He succeeds Mitchell Martin, who retired earlier this year after more than 36 years with the company. Huntress warns of massive Azure CLI password spray attacks: A new Huntress report published Monday warns that threat actors have been running massive password spray attacks against Microsoft Azure Command Line Interface accounts, making more than 81 million attempts between June 12 and June 26, 2026. According to Huntress, attackers are exploiting a loophole in Azure CLI that does not support multifactor authentication, allowing them to target service accounts and non-human identities that are often poorly monitored. Huntress has reported the issue to Microsoft. MSSPs face employee retention problem driven by invisible work, says Guardz: MSSPs are facing a significant employee retention challenge driven by what the report calls “invisible work” – security analysts spending hours on manual data correlation and reporting that customers never see. Guardz, in announcing a new agentic reporting capability, said the problem is burning out analysts who feel their work lacks visible impact. The new tool uses an AI agent to automatically turn blocked threats and client risk data into formatted reports that MSPs can present to SMB customers. ManageEngine launches developer marketplace: ManageEngine has launched a developer marketplace for integrations, extensions, and AI agents across its IT management platforms. The marketplace is designed to allow partner-developers, independent software vendors, and customers to build and distribute add-ons. GAM Tech ranks No. 97 on 2026 MSP 501, No. 1 in Western Canada: GAM Tech has climbed to No. 97 globally on the 2026 MSP 501 and ranks No. 1 in Western Canada, according to the company. The MSP 501 list recognizes managed service providers based on metrics including recurring revenue, profit margin, and operational efficiency. Read Full Transcript Welcome to The Buzz from ChannelBuzz.ca, I’m Robert Dutt, today is Tuesday, July 21, 2026, and here’s what’s happening in the channel today. TD SYNNEX has appointed Chris Fabes as President of Canada, filling the role left by Mitchell Martin who retired earlier this year after more than thirty-six years with the company. In a statement, TD SYNNEX said Fabes brings more than two decades of IT channel leadership across vendor, distributor, and customer perspectives. He most recently led a multi-year strategic growth initiative at SHI across Canada, and before that served as Canadian channel chief at Lenovo, where he helped triple channel revenue to more than one point two billion dollars in three years. TD SYNNEX North America president Reyna Thompson said Fabes’ end-to-end understanding of the Canadian technology market makes him well positioned to lead the Canada business into its next chapter. The appointment comes at a time when TD SYNNEX has been expanding its vendor relationships in Canada, including recent global distribution deals with Fortinet and HPE. Canadian partners will be watching how Fabes shapes the distributor’s local strategy, particularly around AI, cybersecurity, and cloud marketplace growth. A new Huntress report published Monday warns that threat actors have been running massive password spray attacks against Microsoft Azure Command Line Interface accounts, making more than eighty-one million attempts between June 12 and June 26, 2026. According to Huntress, attackers are exploiting a loophole in Azure CLI that does not support multifactor authentication, allowing them to target service accounts and non-human identities that are often poorly monitored. The company said most affected accounts were from large enterprises with complex cloud footprints, and that MSPs managing customer Azure environments are particularly exposed because these CLI accounts often fall outside normal identity monitoring workflows. Huntress has reported the issue to Microsoft. The research underscores a growing tension in identity security: as organizations lock down human-facing accounts with MFA, attackers are shifting to non-human identities and service accounts that lack the same protections. Canadian MSPs with hybrid Azure and Microsoft 365 clients should be reviewing whether their RMM and identity tools are catching CLI-level authentication anomalies. MSSPs are facing a significant employee retention challenge, but salary is not the primary driver. According to a ChannelE2E feature published today, the main issue is what the report calls “invisible work” – security analysts spending hours on manual data correlation, reporting, and threat context that customers never see. Guardz, in announcing a new agentic reporting capability, said the problem is burning out analysts who feel their work lacks visible impact. The new tool uses an AI agent to automatically turn blocked threats, security activity, and client risk data into formatted reports that MSPs can present to SMB customers. Guardz is positioning the feature as a way to reduce the manual reporting burden while simultaneously demonstrating security value to clients. For Canadian MSPs, the issue is worth noting because talent retention in security operations is already tight, and any tool that reduces invisible overhead while improving client communication is likely to get attention from understaffed SOC teams. In Brief – ManageEngine launches a developer marketplace for integrations, extensions, and AI agents. GAM Tech ranks number ninety-seven globally on the two thousand twenty-six MSP five hundred one and number one in Western Canada. Later today on In The Channel, my conversation with Mark Sutor of Access Group and the Trust X Alliance on the Global Leadership Summit, the TXA AI agent, and the idea of distributor-as-platform is available now. That’s how we’re seeing the headlines today. I’m Robert Dutt for ChannelBuzz.ca, thanks for listening. Have a great day.

Is this your show?

Claim this listing to keep it up to date, reach guests who want to pitch you, and manage bookings with Guestify.

Claim this listing

More Technology podcasts