How Kaseya is Helping MSPs Evolve Security Operations

Transcription

Hi channel insiders. Welcome back for another episode of partner POV. Today I'm joined by JV Varma, the vice president of product on the security suite at Kaseya. We dive into a topic that's on the minds of a lot of MSPs right now, cyber resilience. Specifically, we talk about how MSPs have traditionally approached security both from an operating model and from a tech stack. Why neither of those are really working in today's landscape and most importantly what partners can do to rethink the underlying security approaches they've always taken to customers to better address the needs of those customers in today's threat landscape.

Thank you as always for watching. Let's get to the episode. I am joined now by JV. JV, thank you so much for taking some time. >> Of course, glad to be here Victoria. >> Perfect. Let's kick things off with the why behind this conversation. So from your perspective, why is now the time that MSPs should be rethinking both their security operating model and the tool stack they use to support it? >> Yeah, great question. You know Victoria, I would say that it comes down to two forces colliding at the same time.

On one side, you know, the threat landscape has really industrialized. Ransomware as a service that you can really subscribe to. AI has made fishing faster, cheaper, more convincing and attackers have figured out that MSPs are really a force multiplier. You know, compromise one MSP and you get a doorway into dozens of businesses downstream. And on the other side, you know, the the way that they have traditionally responded to that, you know, bolting on one point tool every time a new threat shows up, that has really simply hit a wall.

I talk to MSPs every week, you know, who are managing, you know, 10, 12, 15 different consoles. You know, and they're drowning in alerts. They are paying for overlapping tools and their, you know, technicians are spending a lot lot of time swiveling swiveling sharing between products than actually protecting clients. There's a third piece, you know, the customer has changed. You know, cyber insurance carriers are really asking harder questions. Clients are in just asking, "Will you guys will you keep the bad guys out?" You know, they are asking when something gets through, how fast can you get me back up?

You know, that's a cyber resilience question. And then the reactive incident driven model cannot just answer it. So, the honest truth is the old approach is really unsustainable both operationally and economically. And you know, the MSPs who rethink it now are really going to the ones who are going to be pulling ahead in the future. >> I know you mentioned it a little bit in there, but let's dive a bit deeper. When you think about what that traditional security operating model for most MSPs looks like today, what is that model a bit more specifically?

And where do you most often see it break down and fall short of what MSPs actually need to deliver? >> If I'm being candid, I would say that the typical model is is a patchwork. You know, there's an EDR from one vendor, email security from another, there's a backup from a third vendor, and then there's an RMM and PSA. They don't really talk to any of them. And on the business side, security is typically sold ala carte. You know, every client has slightly different mix, and that's always typically negotiated deal by deal.

So, where does it break down? In fact, three places I would say. You know, first, every gap between tools is a place where an alert falls through or where a technician has to manually stitch these information together. Second is really with the people. You know, most MSPs are running lean teams. You simply cannot be an expert, you know, running 12 different platforms. So, each tool end up getting half configured and a half configured security tool kind of gives you a false sense of protection, which is arguably worse than having no tool at all.

And and finally, I would say the third one is and this is really the one that people miss. You know, it's really the conversation with the customer. So, when every client has a different stack, you cannot tell a consistent story about, you know, what is covered, what is what isn't. So, the only time the security gets discussed is really after something goes wrong. So, that's that trap, you know, and and it's it's baked right into that fragmented model that that we are really dealing with. >> So now, let's think about that fragmented tech stack for MSPs who want to create a different approach to that tech stack, rebuild it, so to speak.

How should MSPs decide what to integrate, what to consolidate, and what, if anything, they should keep specialized? >> The answer isn't really consolidate everything. I would say that the the answer is really start from the outcome and not the tool itself. I would tell every MSP to ask three questions about every product in the stack, you know, number one, does this tool actually share data and workflows across the rest of my stack or is it really an island, right?

Two, can my whole team operate that tool really well or is it just the one person who set it up? And and then finally, you know, does it actually map to a service I sell at scale? So, if a tool fails all of those tests, it's a consolidation candidate and in my experience, the core of the stack, the endpoint, email, security, backup, patching, documentation, this is where the overlap is the highest and the integration matters the most. So, that's where I would say the consolidation pays off fastest.

I would say the integration is for the tools that are genuinely strong, but need to feed your central workflow. So, if you want to keep something specialized, that's fine, but that should be an exception and it should earn its keep, right? Like take compliance tool for your health care clients, where a vertical actually demands it. So, the measuring stick I would say through all All this is the total cost of operation, the license plus the labor plus the risk that it has.

So, sticker price alone, you know, will likely going to light you every time. >> For MSPs who then rethink their tech stack, how does that impact the way that partners can then approach standardized ongoing services components for their customers? >> I would say this is where it gets really exciting, you know, consolidation isn't really the goal. It's the enabler. Once your stack is unified, standardization becomes finally possible, right? Now, you can define a security baseline that every client gets.

Same tool, same configuration, same runbooks. You package that into tiered offerings, you know, you could say good, better, best instead of kind of negotiating a very custom deal with every client. And that really transforms the business, I would say. Onboarding a new client goes down from like weeks to days. Your technicians work one way across all the accounts, so quality, that's very important, becomes repeatable, right? And training gets much more easier.

Your margins will improve. You're delivering a product, not actually a series of custom projects, right? But I think the the biggest shift is in client conversation. It really stops being, you know, would you like to add this security option and becomes, you know, hey, this is how we protect everyone who we serve. So, that re-frames the security as a continuous ongoing service, something that is revenue generating for the MSPs, offering continuous protection for the client instead of just a one-time purchase that gets revisited after a single incident, right?

So, that's how I would approach it. >> Let's dive in a bit on that security component specifically. We live in a very different security landscape and threat landscape than maybe a few years ago. So, how should MSPs consider expanding beyond more traditional endpoint approaches to consider identities, users, securing SaaS applications, cloud resources, and ultimately the data that underpins all of that. >> The first thing to internalize is that endpoint is just one door into the business, and increasingly it's not even the front door.

You know, attackers would rather log in than break in. So, I would tell the MSPs to expand in layers. So, start with identity because most of the breaches today starts with a stolen credential. That means you have to have MFA for everybody, you know, conditional access, you know, monitoring for compromised credentials including any exposure in dark web. So, then comes really the user layer, you know, email security plus security awareness training, phishing simulation exercises because your users are tested by attackers every day whether you train them or not.

Then comes SaaS, right? I mean, this is a biggest blind spot. Microsoft 365 and the Google Workspace need their own backup and configuration monitoring. A lot of clients actually assume that, you know, Microsoft is backing up their data, and it and it is not. At least not the way that you think. So, you know, from there the cloud infrastructure posture, you know, finally the data encryption, backup, recovery, and everything that is actually has to be tested.

Here's the critical caveat, right? I mean, if you build all these layers with disconnected point products, you have just created a fragmentation problem at a at a very large scale. So, the expansion only works if it happens inside a unified platform and a single workflow. >> I want to go back to something that you mentioned earlier when we were kind of discussing the the traditional approaches MSPs take, and that's the concept of cyber resilience.

When you think about that term, right? How do you define it? What do you think it should mean to MSPs? And then as that next step, how should they start measuring that resilience and communicating that to their customers? >> Resilience is going to have to start with an honest admission, you know, some incidents are really going to happen. Resilience is really measuring your ability to absorb a hit without it being your business-ending event, I would say.

So, in in practice, that means, you know, hardened baselines, real detection and response coverage, immutable backups that ransomware cannot touch. And then, I would say most importantly, recovery capability that you have actually tested, right? A backup that you have never restored is just a hope, right? I mean, it's not a plan in place. So, on measurement, the industry has to move from an activity-based metric to an outcome-based metric. So, nobody is in the business is safer because you closed 1,000 tickets, right?

I mean, there are metrics that matter, like things like time to detect, time to recover, the percentage of clients who meets your security baseline. So, number of customers who have MFA, you know, who have patch coverage. Have you actually done a backup recovery test? Have you passed it, right? And then, try to communicate that in the business language, you know, bring it to your quarterly business reviews. Hey, look, here is your risk score, and here is how your risk score has trended down.

Here is the downtime that you have avoided. Here is where you stand with respect to your insurance requirement. So, when you do all of these things together, right? I mean, security stops being an invisible cost, and the client really understands that this is an investment, there's a visible, measurable return, and your relationship with your client completely changes once you take that approach. >> Well, with all of this in mind, I'm curious for the MSPs who maybe are watching this video or just generally thinking that it might be time to rethink security to your point, right?

What is that first step that you think partners should take, put into action, bite off the small part first, and how do you see partners successfully taking that step to reconsider what security looks like? >> Yeah, I I would start with an honest assessment, right? I mean, it's not a purchase, So, the instinct is to go something bright and shiny. Um I would resist that. First, you know, do an inventory. What do you have, right? How many tools, how many consoles, do they overlap, what are the gaps, right?

So, and that's going to be an eye-opener. So, how many technician hours get burned every week switching across these, right? Most MSPs, I would say, have never actually added that number up. And when you do that, it's going to be shocking. And the second thing is define the standard, right? And you can get a lot of help on this. Decide what baseline protection you believe is required for every client that you service. You know, write it down. And then work backwards, I would say, to the smallest set of tools that can deliver it.

Third, don't boil the ocean, right? I mean, pick one area to standardize first, you know, endpoint plus backup is a very common, very sensible starting point. And prove the model with a segment of your client base, and then you can expand from there. And then finally, you know, bring your clients along the journey. Reframe your QBRs. You know, it should be really about risk and resilience, so that commercial conversations, they they are maturing alongside with the technical conversations that you're having.

So, I would say that if you do all of these things, the tooling decisions will almost make for themselves. >> Well, Jv, as we start to wrap our time up together, I do also want to ask how Kaseya is helping position MSPs and enabling them for success in this new security world we live in. And if partners want to learn more than what you're about to tell me in this answer, where they should go to contact Kaseya. >> Yeah, everything what we have talked today, consolidation, standardization, resilience, that's exactly the problem that Kaseya 365 is built to solve.

So, it it gives MSPs one subscription that covers manage, secure, and recover, you know, your RMM, your endpoint security, your backup, working with a single workflow instead of very different consoles, right? And and it's priced so that standardizing across your entire client base can actually be very economically viable for you. And that's the piece that I would say is missing in the industry. And from there, you know, the broader IT complete platform that extends that same integrated approach across identity, email security, SAS backup, dot web monitoring, compliance, you know, and a lot of it integrations and automations built in.

And they are not just bolted on to each other, right? So, for partners who want to learn more, I would start with kaseya.com. Reach out to your account manager if you're already a partner of ours. Explore the other tool sets in our portfolio. And honestly, come and see us in person, you know, come to Kaseya Connect or one of the local Kaseya Connects that we hold across various regions. You can see our platform first hand and you know, hear from the peers that you have already using it. >> Perfect.

Well, JV, I want to thank you again so much for joining me today. For everybody watching this, if you want to see more episodes of Partner POV or read our coverage of Kaseya, Kaseya 365 and more, you can head to channelinsider.com. JV, thanks again. >> Thanks so much.

This transcript was generated automatically from the video's captions and may contain errors.

Kaseya’s JV Varma explains how MSPs can modernize security models, strengthen cyber resilience, and move beyond reactive security practices.

Aug 19, 2026
1 minute read
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Organizations are facing advanced security risks and complex threat landscapes, and traditional MSP models aren’t keeping up with them.

In this episode of Partner POV, Kaseya’s Vice President of Product Management for the Security Suite, JV Varma, details how legacy tool stacks and reactive security practices are keeping MSPs from unlocking the full potential of their teams.

Varma and Victoria Durgin also dig deeper into how MSPs can change their business models and technology to achieve cyber resiliency moving forward.

This episode is sponsored by Kaseya.

Victoria Durgin

Victoria Durgin is a technology communications professional and editorial leader specializing in channel technology, cloud marketplaces, managed service providers (MSPs), technology distribution, and partner ecosystems. As Managing Editor of Channel Insider, she oversees editorial strategy and content development focused on helping technology vendors, solution providers, and channel partners navigate an evolving IT landscape. With nearly a decade of experience spanning technology journalism, corporate communications, content strategy, and digital publishing, Victoria has developed deep expertise in the business side of technology. Her work includes creating executive thought leadership content, industry analysis, case studies, and channel-focused reporting that helps organizations better understand market trends, partner relationships, and technology buying decisions. Before leading Channel Insider, Victoria built experience across local journalism, business reporting, social media communications, and corporate marketing. She has worked closely with technology vendors, cloud providers, and managed service organizations to develop content that highlights industry innovation, business growth strategies, and successful channel partnerships. Her portfolio includes case studies featuring mid-sized MSPs across the United States, Canada, and Australia. Victoria's work has appeared in Channel Insider, The Valley Ledger, and Medium. She holds a Bachelor of Arts in Communications and Environmental Studies from Susquehanna University. Through her reporting and editorial leadership, she helps technology professionals stay informed about the trends, challenges, and opportunities shaping the global IT channel.

Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.