Binary Defense & Palo Alto Expand XSIAM MDR Capabilities

thumbnail Binary Defense & Palo Alto Expand XSIAM MDR Capabilities

The new collaboration offers implementation, co-managed, and fully managed security operations services tailored to Cortex XSIAM customers.

Written By: Franklin Okeke
Jun 12, 2025
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Palo Alto Networks is deepening its security services ecosystem through a new partnership with Binary Defense, a managed detection and response (MDR) provider. 

Announced Tuesday, the collaboration will bring Binary Defense’s MDR expertise directly into customer instances of Cortex XSIAM, Palo Alto’s AI-powered platform for security operations.

Under the agreement, Binary Defense will offer three levels of support: implementation services for onboarding and tuning XSIAM, co-managed MDR for shared operational responsibility, and fully managed MDR for organizations seeking end-to-end, expert-led coverage.

Flexible Support Models for XSIAM Environments

Implementation services will include log source mapping, use case configuration, alert tuning, and data integration to speed up deployment. 

The co-managed option enables internal security teams to maintain complete visibility and control, while Binary Defense handles alert triage and investigations. 

In the fully managed model, Binary Defense acts as an extension of the customer’s security team, delivering 24/7 threat hunting, detection, and response inside their XSIAM environment.

“XSIAM represents a transformative shift in how security operations are managed,” said Dave Kennedy, chief hacking officer at Binary Defense. “We’re proud to help organizations deploy, tune, and run XSIAM more effectively.”

Addressing SOC Skill Gaps and Scaling Challenges

The partnership targets security teams facing talent shortages, operational gaps, or complex hybrid environments. Both companies believe that offering flexibility across support models will help organizations modernize their Security Operations Centers (SOCs) without sacrificing visibility or control.

“Together with this new offering, we’re delivering joint customers an AI-driven security operations platform and services that help them stop breaches,” said Anar Desai, VP of North America channel sales at Palo Alto Networks.

The partnership comes at a time when cybersecurity teams face immense pressure to manage growing volumes of threats with limited resources. 

As attackers become more sophisticated, adopting AI-driven detection and response capabilities has become critical for organizations striving to stay ahead.

Earlier this year, Palo Alto Networks and Kyndryl announced their own collaboration. Revisit the news that announced a SASE-based partnership.

thumbnail Franklin Okeke

Franklin Okeke is an author and tech journalist with over five years of IT experience. Coming from a software development background, his writings span cybersecurity, AI, cloud computing, IoT and software development. In addition to pursuing a Master's degree in Cybersecurity & Human Factors from Bournemouth University, Franklin has two published books and four academic papers to his name. His writing also appears regularly in Enterprise Networking Planet, Techopedia, ServerWatch, The Register and other leading technology publications.

Recommended for you...

Channel Vet Frank Rauch Joining Morphisec in Advisory Role

Channel vet Frank Rauch joins Morphisec’s advisory board to boost MSSP strategy and partner growth with a prevention-first cybersecurity focus.

Jordan Smith
Jul 29, 2025
Azul Debuts Managed Services Program for Java-Focused Partners

Azul empowers MSPs with sublicensable Java insights, enabling code cleanup, vulnerability detection, and license compliance via Intelligence Cloud.

Jordan Smith
Jul 29, 2025
Nasuni Launches File IQ and Ops IQ for Smarter Data Ops, AI

New File IQ Premium and Ops IQ tools aim to help enterprises uncover file activity, system trends, and AI-ready insights across unstructured data

Franklin Okeke
Jul 29, 2025
Commvault Doubles Down on AI Data Security With Satori Deal

Commvault acquires Satori Cyber, adding real-time data access controls and AI governance to boost cyber resilience across multi-cloud environments.

Allison Francis
Jul 28, 2025
Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.