Video: Blackpoint Cyber CEO on Why MSPs Need Better MDR in 2024

Blackpoint Cyber Founder and CEO Jon Murchison explains why MSPs won’t win by focusing on SIEM.

Written By
Katie Bavoso
Katie Bavoso
Jul 5, 2024
1 minute read

Transcription

hey Channel insiders I'm your host pety boso and welcome to this very special episode of Channel Insider partner POV brought to you by blackpoint cyber and I'm joined by the man himself John burches CEO and founder of blackpoint cyber it is such an honor to have you here today thank you so much thank you Katie really appreciate the invite absolutely so why don't we first talk talk about blackpoint cyber from your perspective when you talk about it to people what do you say about blackpoint cyber and how do you describe it at our cor we really a software company basically we write all the software we use and then we wrap it in a 24/7 thread op Center we deploy it if we see bad guys you know they're trying to rans whereare you or breaken your Cloud we stop them you know before they cause damage that's really our kind of core mission that we started with um you know as this industry has been evolving there's still a huge out shortage in competent it skills and even worse in security and I think as an industry one of the things that's going on it's a great growth industry right now it's growing about 11 12% kager North America um but it's professionalizing rapidly and so our whole strategy is really a platform play where we have MDR we have application control we have exposure management and our whole strategy really is to offload as much of the security work from an MSP as possible it's very specialized uh then we can go to market together you know we can grow our businesses together and I think you know as a lot of Investments coming into this market and private Equity M which is a good thing uh it's great the industry is growing naturally but it also means it's going to become more sophisticated and if you don't start becoming verticalized focus is MSP if you don't start doing Security First You're quickly you're going to be in a maybe uh less competitive position compared to where the industry is and so a lot of our strategies best security in the world we're the fastest MDR in the world we evented MDR for Microsoft 365 and asure single sign we're the first to ever do it and then we're pairing that with like big education on the business side and true Partnerships uh to grow so that's kind of blacko at its core so you have such a fascinating background and I'd like to touch on that a little bit because as the founder of this company clearly there was something missing to you there was a Missing Link in the industry that you said I can fill this I can help people can you talk to me about the birth of blacko cyer you know I was a division one athlete at Maryland as a tennis player and a marketing major that's all I had right and my I was the youngest of four and my brother got me into networking so I started as a network engineer and doing a lot of Cisco type work but I was always interested in the intelligence community and I was down in Maryland which is where the National Security Agency is so I ended up um at the National Security Agency and at the time it was never you know acknowledged publicly but in more of our offens of cyber unit where you know we leverage offens of cyber to solve you know kind of critical National Security intelligence questions that we had to have so I spent 12 years you know so doing that and a bunch of other jobs in that space I kind of especially encounter proliferation you know I jokingly say you know we're kind of the bad guys for the right team for 12 years I was getting to a point where I'd done some of the coolest jobs you could possibly do and see just amazing things and travel you know to some interesting places in the world and I actually got injured um not in work it was a dumb accident to be totally clear it's an embarrassing story skiing down at dirt bike trail but you know I ended up blowing out both my knees well at that time I was approached by a company that wanted to buy my government business and we were also making some very special software back then um I decided to sell it spun it out into a new entity uh did a lot more Nas security work with our software for for several years but eventually I wanted to take a crack at building what I would want to use to do defense haven't been an offensive guy and I didn't believe in seam Technologies Security inent Management for catching hackers um and I really felt there was a lot more we could we could do in this game so we spent three years and a lot of money building out this platform and then we came to Market in mid 2019 in the MSP space so really it was a little bit of a winding Journey you know but uh ultimately you know we're one of the fastest growing cyber security companies in the game I want to point out where we are right now we are at PX Beyond 2024 you have spoken to so many partners in just the 24 hours that you've been on site yes what are you hearing from them as far as how blackpoint has been able to help them solve customer challenges and what are those customer chall challenges in 2024 yeah I think you know there's there's internal challenges and then there's kind of go to market challenges and obviously PX a beond this was our best event last year Roi I I love this event we see so many partners here aa's done amazing things with the with their Marketplace and their partnership with Microsoft Microsoft is prominent in every msp's ecosystem and it continues year over year to get more and more important and I think you know for us because we've done this kind of platform sweet play of trying to offset so many products and we stayed very focused on Microsoft we've become kind of the goto MDR sakaa service ecosystem for folks that are running they're heavy in the Microsoft ecosystem specifically 365 Azure and so I think our simplification of that our efficacy obviously I've had so many partners come I had one in in uh in a meeting today and we saved two of his kind of electrical supply distribution companies well those go down really hard in a ransomware event imagine figuring out where all your parts are and your inventory it just all falls apart uh so that's been really exciting to hear firsthand um you on board so many partners I've met so many I've never met before which has been incredible but I think at the end of the day we simplify it and then we've been selling together with our msps to help their adoption rate in their customers the other Trend I'm seeing is and I tend to see this with like larger msps and really fast growing ones the ones that are all in on the Microsoft latest and greatest co-pilot automation you name it uh they're leveraging our security program to enter midmarket companies that are much larger because they can follow with Kang services so that's a really cool Play We like seeing uh in the industry because I think the security stack that aot of the midmarket is running it's kind of an Enterprise stack that's really expensive and slow and the efficacy is not that high and so the msps have a huge advantage to move up market and disrupt credit way and that's pretty exciting having those conversations absolutely let's keep going down that road in the opportunities there first of all it's 2024 how critical are MDR Solutions still it's not necessarily a new term it's not a new term I would say the term has also now been applied to everything where the r is not real like an email is not R phone call is not R it's like stopping the event to me I look at it this way how many companies in 2024 can operate when their it systems are down Cloud if your Cloud infrastructure is breached uh or on getting Mass ransoms the stakes are so high it's part of your brand as well I mean if an MSP has a customer that didn't buy the advanced Security package and got rans word they're still going to blame the MSP so to me it's absolutely critical I think it's something that you just can't operate without anymore in 2024 and that's where you're starting to see insurers start asking now they used to just ask EDR MFA vulnerability management now they're starting to ask do you actually have a real MDR uh or xdr platform so when we consider manage to protection and response there are a lot of solutions out there but when you think about it where do you see most of those Solutions fall short and how does black white cyber say we can do this better absolutely I see two general camps right and I think we're trying to find the goldilock solution I either see a really loaded stack which is kind of traditional seam based stack that has lots of network Telemetry very expensive very timec consuming to setup efficacy really really low so I see folks that you know to me if you're MDR providers core system to the catch and make sense of a hacker and amount to response is a seam I would argue it's too expensive and too slow right so I think that's one area where these were traditional mssp services that overnight MDR got hot and everyone rebranded but the r is not there like the actual response is not there or what I see is what I would call EDR run as a service uh which is some very good offerings out there the problem is there's been a trend with hackers to use less and less malware and so when you think about um you know if you think about what a hacker does I need to or what an IT person does I need to put data on machine take data off machine install software what does a ransomware operator do the same thing so what we've watched is a huge shift to where thread actors are using MSP tools to accomplish the job because they're legit and allowed and edrs just are completely blinded to it so with us we love EDR technology I mean we technically are an EDR technology cuz we're detecting and responding but when it comes to like malware engines um we integrate with every major EDR and it's orchestrated with our agents um so we can see their view of the world and our view of the world love the technology but now in in our onframe responses they're missing 55 to 75% of the time depends month on month if we're ever going to get an alert from them and it's our technology because we focus very heavily on lateral movement live off the land we see privileged Behavior live in what they're doing and that so if you're going to do an elite level you have to have a cloud operation you need to see those alerts in context with your on Prem CU we're seeing Cloud breaches to use things like InTune to get on Prem and you have to have a beautiful marriage of malware detection and tradecraft detection so if you just rely on EDR rounds a service you're going to miss all the live off the land stuff if you do this big heavy bloated seam you know Enterprise stack it's very expensive it's not competitive and it doesn't work very well so I think The Sweet Spot the gold delocks is sort of in the middle of those tools highly orchestrated fast to deploy no reboots not relying on massive log volume and doing just enough logging and Analysis to make to to check compliance boxes I think is the more appropriate way and I I'm seeing other large security vendors start signaling this up Market too how are you helping your MSP Partners find New Market opportunities with MDR this year and Beyond especially for those small to midsize customers does that's really where we see a sweet spot yeah absolutely I mean for us several things you know when we on board our partners we like to to coell we have a unit called our adversary Pursuit Group which is doing continuous uh threat intelligence reporting as well as threat research including reverse engineering we get notices out I think what's really good about that group is we're taking really technical saves we've been doing and then breaking it down into basically a story that a Layman can understand because think about it we're selling the construction companies lawyers you these are not pros at it security and I think really we never sell through fear we have to sell through facts and understanding I think a lot of people have perception I'm too small no one's going to Target me and they don't understand the vast majority of rware attacks are not targeted you're a target of opportunity because of a vulnerability because someone found credits and things like that so I think we help msps provide perspective to their target audience uh and we help coell and then we also have a lot of uh you know kind of good business hygiene courses that we offer our msps to up their skill in running a business any of them that you can talk about right now yeah absolutely so uh we have something we launched called blackpoint University I think we have 15 courses in there we have another six or eight dropping really soon I look at it this way like at the end of the day we have to be El lead at security that's a gimi we have to be a real partner where we know each other that's that's another given but if it's a real partnership we want to go to market more effectively together we want to help our msps standardize their business model get focused on verticals learn about smart orc design so we have courses that are everything from leadership courses to front the fun leite generation courses and they're all written by former MSP owners professionals who have kind of run it at an elite level um so they've been there they know the game they've been there it's one reason I my chief client officer is a gentleman named Mike eastep Mike ran a really successful MSP called Becca uh out of Atlanta but then he built blue Alliance which was one of the first uh kind of acquisition platform place and brew that over you know to to a large large Revenue number and ran it at the pro levels and I was fortunate enough uh the timing was right where I got to bring him on so he handles our Community our client success blacko University but he's basically our interpreter to make sure we're actually delivering msps what they really need to solve their problems while also trying to uplift and Coach them into the model we see of the fastest growing most successful msps amazing well going right on from there and maybe shift towards what we shouldn't be doing right you're a big proponent of software information event management technology just throwing more at that is not the way to go yeah I mean here's the deal you look at you know Insurance do you have a seam compliance do you have a seam it's all good intention but let's be honest the compliance insurance industry by the time you know they requirements hit paper it's usually dated the reality is we absolutely have to retain logs and off logs it's great for compliance CU listen it's a cost of doing business you have to deal with it the second part is if God forbid there is an event you can put the pieces together much much quicker um and so I think ultimately what you don't want to do is rely on that that is your core system to triage Advan to mount to response because they're too slow and too expensive so moving on from there we have to talk about AI we cannot talk about artificial intelligence with AI in mind how is it impacting your customer security and what is blackpoint doing to help its msps combat some of the new threats that are now involved in the game because of AI yeah absolutely so a couple things where's AI most useful uh for an adversary right now yes you can write malware with it you can write scripts and things like that the number one way you know you generally get into a company is by social engineering employed we can all seen the emails where we read it and we say that doesn't sound like an American from my company wrote it for example AI gener of AI specifically has allowed folks to cut that language R I would have much more believable stuff and a lot of it is actually used to drive a breach or a breach is more of a legal term but malicious access into like a cloud Microsoft 365 environment so the big Trend the attack volumes up way way higher in 365 in insurer makes sense it's so darn useful and we're running the world on it um I think when you think about AI I think every MSP should be looking at how can I automate how can I leverage AI for service tests whatever anything that still preserves a great customer experience and allows you to get more efficiencies for the dollar you spend is worth it co-pilot obviously is one of those tools and it's we're really starting to see it pop up in msvs the thing is though you know we invented MDR for 365 there's not many people doing it and very few doing it well you have to think about how do I Harden protect this house that is going to get even more important when I have copilot and all my Automation and so I think the biggest thing we're trying to do is say listen we need to get you ready for AI and ready for all the goodness that co-pilot's going to bring you and it has to start by securing the highest attacked infrastructure right now so higher efficacy on the social engineering side we have to make sure it's protected and obviously with with our Cloud response product uh it's kind of what we do every day we're doing hundreds of responses a week moving on to talk about uh some history some recent history for blacko cyber a year ago you made a $90 million investment specifically into your msps that was backed by ban capital and Excel and that is just a lot of money to say that this is going towards our MSP Partners can you point to any benchmarks from then to a year later which you can say this is how we're showing that dedication to our msps yeah so I mean first off we launched blackpoint University immediately we started in in investing in that we're originally a Maryland based company in fact our new headquarters just open in Denver today I don't think we announced that so uh uh but we're breaking news yeah we we brought on a a chief technology and product officer uh he was most recently the the deputy CTO at tenal uh so other Investments we're making is we have so many product and software capabilities coming out over the next year we just tripled down on that we triple down on uh you know kind of customer success and enablement and we've just been growing really rapidly since then which has allowed us to bring out a lot more msps we obviously launched this P partnership with pax8 um you know which is really helping us you know grow in the United States and also internationally so for us we're just reinvesting it right back into the business at a much much faster rate to support growth your msps have so much now to work with thanks to that investment that you made with that I really want to know a success story in which we talk about the customer side and your msps backed by blacko cyber were're able to help one of them do you have a success story you could share with me yeah I have I have one that's a little atypical for the MSP space so generally the MSP space is attacked by uh more like cyber criminal groups rant sare groups syndicates things like that we do get some Nation stfe activity where intelligence services are going because you think about we protect and msps are working in the defense industrial base they might be working with political organizations I mean they support everything you can imagine and so we had a a quite prominent uh more larger upm market customer uh they frequently got nation state attention so this particular customer uh has a lot of eyeballs on it and and they're International as well and so a bunch of folks went to a conference very prominent conference uh all of them had an MFA bypass attack on them all 11 of them we were able to successfully stop that in a few minutes so they got nowhere we knew from the Telemetry we were seeing this was not a normal group and we all were pretty sure it was probably the Chinese uh just because of some of the trade craft they used to log in the next day they were a hybrid environment so they had exchange server on Prem as well we noticed an exchange server got hit uh laterally spread so that mean the threat actor had privilege credential and use that to install software on the on the file server they put persistance techniques we caught it right away um interesting part is it was running top tier EDR technology which is fine that's normal uh we all looked at each other and said wait a minute that exchange service patched that was uh that was the last exchange zero day months before it was public uh and the interesting part is you know that was an example if you just focus on malware if you just use EDR technology you would have been blind to that if you didn't have like a ability to do MDR Microsoft 365 you would have been completely blind to that attack you would have been a victim you know that was one of Chinese top tier intelligence agencies um that was conducting this attack and and our technology was was the sole reason it was detected and and stopped so that was probably a really technical one we also did one I believe for a municipality so like you know a small City uh where they leveraged a breach um into you know off Cloud environment and used InTune to push malware down on PR so that's another Trend that's happening where Cloud infrastruct we used to hit on Prim we're able to basically catch it and see it both sides and stop and I I know there's not another company right now that could do that so those are two like really nuanced versions that I was really proud of what is next for black points are you going to take a year off and just kind of not do any crazy things no no we're going to push we're going to push we have some major Refreshers of products coming we have a whole new line of offerings that is going to be coming out you know to help with hygiene and things like that um the other thing that we're going to see coming is a much more robust partner program and certification programs that are coming so we're investing a lot more in how can we help our partners grow in addition to new tech amazing well John thank you for your time sincerely today it's been such a pleasure likewise I really appreciate it thank you to everybody watching and listening at home as always you can find us on channel insider.com our YouTu YouTube page at Channel Insider newws and Trends John subscribes yeah and you can also find us on your preferred podcast platform thank you so much for watching I'm Katie boso and I'll see you next time

This transcript was generated automatically from the video's captions and may contain errors.

Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

In this episode of Channel Insider: Partner POV, brought to you by Blackpoint Cyber, Founder and CEO Jon Murchison explains what’s threatening end user customers in 2024 and what solutions managed service providers should be investing in to better protect their clients. Murchison also explores the impact of AI on businesses and the new risks it’s introduced in recent months. Plus, one year after dedicating $190 million to the growth and development of its MSP partners, how is Blackpoint Cyber making good on this investment? Murchison and host Katie Bavoso discuss the new Blackpoint University, increased go-to-market resources for partners, success stories, and much more. 

Katie Bavoso

Katie Bavoso is a 2017 Regional New England Emmy-nominated broadcaster with over a decade of professional content creation, production, hosting, and interviewing experience. Starting her career off in TV news, she pivoted to the IT channel to help connect vendors, solutions and services providers, and IT buyers through exciting video content and storytelling. Katie is now the host of Channel Insider: Partner POV, a video and podcast series shining a light on the most innovative solution providers of the IT channel.

Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.