Hey channel insiders, welcome back to channel insider partner POV. I'm your host Katie Bavoso. Today I'm sitting down with Feder Rico Terroski, the founder and CEO of Quorum Cyber, an MSSP founded in 2016 in Scotland that's grown to more than 400 employees across several countries. We dig into how Feder Rico grew the company, how he's leading through the AI tool explosion, and how education is a core pillar of Quorum Cyber's internal team and client approach.
Plus, learn why the security provider is allin on Microsoft. Hi, Federico. How are you? Welcome. Thank you, Katie. It's great to be here. Thank you so much. It's great to have you. Uh, we were commenting earlier just about your background being so cool and I I know that you in particular are a bit there's like a little bit of a collector in you. A little bit of dare I say some some nerdiness about certain subjects. I just a teeny bit. We all have it.
Can't work in this industry without it. We keep it undercover. We keep it under cover. Well, I'll make you bring it out in here. I know that you actually are a video gamer. Uh, are there any games that you're playing right now or one that maybe just lives rentree in your head when you're having those days where you daydream about one? I'm sure some of the community will actually like this, but the there's been a relaunch of a remastered game that we used to play ages ago when I was a teenager called Oblivion.
And for those of you that downloaded the remaster, I'm reliving my teen years again. Maybe that's aging myself. Maybe it's a bit 20s, but we won't go there. And it's just brilliant. It's just it takes me back in time and it's been absolutely fantastic to play it. Is that part of the Elder Scrolls universe? Yeah, The Elder Scrolls universe. Very good. I'm impressed. Very well done. I I have to say in my household, my husband is also going through a bit of a renaissance as well because he's playing the remastered uh Resident Evil game, whichever one that is, but the one that came out.
So, he mentioned to me the other day about Elder Scrolls also having a remastered. So, I am keeping up whether it be just between him and I, but for me, I'm just the person that constantly goes back and plays Pokemon Snap as sort of like a therapy. So, that's the level of video game that you can expect from me. Hey, it's absolutely fine. The judgment free zone. Uh just just play something. It's great to have have that gene still alive. Exactly. Well, I'm so glad you agree and I'm so glad this is off to such a fun start.
But I promise I brought you here today to talk about Quorum Cyber and to talk more about business. So let's talk more about Quorum. You founded the company in 2016 and you're a threat management company at its core and exclusively a Microsoft shop. Can you tell me why you started and a bit about Quorum Cyber's core mission? Yeah, sure. Uh so you basically nailed it. We set out with a mission to deliver great security outcomes using Microsoft technologies.
This is been my career, right? I've always been in cyber. I'd been a part of another startup that started in 2010 and I guess I had something that I wanted to do a bit closer to my way, my ethos or more within my, you know, sphere of influence. So I always had the buck to go back and do it again. So I came back from the Middle East to start core and cyber and this is just before Microsoft had gone fully into the security space. So you could see the writing on the wall or there was a bit of an intuition but it was before the kind of tech stack that now Microsoft is well known for was fully available.
So before the Sentinel days and defender days and all those technology stacks, but my hypothesis was that the three cloud data giants were eventually going to be great at this because people and companies wouldn't move their data and their identities and their workloads to environments they couldn't protect. And once the data giants Microsoft, Google, Amazon realized that this was one of the enablers for people to move their their data and their workflows to their environment, this is something that they were going to have to really take seriously. and why would they leave third parties to fill that gap when they had more kind of access to their own telemetry.
So between that kind of reading of the landscape and Microsoft's really strong presence in the identity space with Active Directory and what would become Azure Active Directory, I thought there's a really high chance that Microsoft's going to be at least a significant player there, if not the winner of that kind of moment. So we decided to build a company entirely around the Microsoft stack and use that to deliver outcomes acknowledging that most customers would find it difficult to unlock the full potential of all of that.
So that's our role. We kind of we're the glue between the outcome and the Microsoft tech stack. And we'll talk more in a minute about Microsoft and how going all in there has actually turned out really wonderful for you. There's a whole bunch of recognitions that I do want to go over, but would you also dig in a little bit about clarity for me? Your clarity delivery platform. How is that a differentiator for Quorum? How would you define it? It's been it's been huge actually.
We've invested we were doing the math something like 8 million or plus 8 million over the last couple of years in developing clarity. So so fresh data actually I don't think many people seen that. The way that we think about the problem was when you look at the competitive landscape there are organizations there that are solving it with their own tools uh and building almost like competitor products to Microsoft. We decided to go on the Microsoft route.
There are people that are solving it through people and just really heavy big teams and there are people that are just fully Microsoft but and full automation trying to to nothing but technology and automation. I think we always made a conscious choice to live somewhere in the middle the intersection of all those three vend diagrams. So great Microsoft technology great people powered by great technology that we control and un unleashes the combination of the two and that's really where clarity lives.
Clarity is that engine that helps customer experience the service but also helps our teams get the best out of the Microsoft technologies and be able to work at scale. So that connective tissue is really what's helped us achieve the kind of growth, the margin, the retention that we've experienced particularly over the last two three years when the investment really delivered what we've been building over the years previous to that. So it's been really lovely to see it develop as a bit of a crazy idea. a lot of convincing to do to my boards and my teams without a lot of return in the first early years.
So it was a bit of a hope or a prayer, a bit of an investment, a punt if you want like many things in startup land. But to see it really pay off and I remember the day like there's a board meeting uh probably about 3 years ago where we saw the platform really delivering more than what the human equivalent would have been able to. It was a marked diagram that just it tipped over the okay clarity really made the difference to more than 50% of the things we would have had to do by hand and at that point we were really rewarded with okay now we get it now we really see it in the numbers as well what it does for our story so it's been it's been really great I love getting the opportunity to speak to CEOs and leaders that are also the founders of their own companies because it gives me that opportunity to ask about the ways at which you were able to convince people of certain things.
So, you mentioned having to convince your board and your team. What was that conversation that sort of brought them over the fence to say this is a good idea and something we'll invest this time and money in even though we won't see an immediate return. What was that conversation that was able to to be had? Super question and I don't know if I have a straight answer. I mean, our CFO was always probably the the best partner. Greg Akin, our CFO, who's been with us since we were 30ome people, I think.
So, he's been he's seen most part of the journey. He's always kept us really honest, right? And in his articulation of his role is fascinating. He says, "The CFO is the storyteller. All we can do is through data, through numbers, tell the story of what we've done. We're not the ones doing, we're the ones telling the story. And the story shows up in the numbers." It's really romantic view of finance, which I always kind of connected with. So, we knew that whatever we did had to be a way to show up in the numbers.
We we had to be able to bring forward evidence that it mattered whether it was through customer satisfaction or employee satisfaction or gross margin or retention. We had to find the ways to tell that story in the numbers. So he's always kept us really disciplined to look we can make investments. We can take risks. Some things might work out and some things might not. But you need to give me something that at some point we all agree before is what we're trying to optimize or maximize or do.
So I think working really closely with him really made sure that we had very early agreements to what did good look like and what did we expect this to return even if it was a further down the line and then it was just a matter of letting it play out and adjusting course as we saw some of the assumptions working out and some of the assumptions were not working out. So I think to to answer your question, how did I bring them on board? I think working really transparently with finance helped so that it wasn't a kind of blackbox development thing that did magic but it was really connected to the health of the business.
That really helped being really iterative on what was working and what wasn't early so that it wasn't decision made invest two years later did it work or did it not? It was much quicker feedback cycles than that. All that helped build momentum and then thankfully the business was growing right all the way through the business has been growing well and we received multiple investment rounds and so it we haven't been constrained where you're having to make those decisions and go okay guys we can't we can't take this risk anymore so we've had a bit of oxygen to do that and that was a predicate of the investment so each of the investors that came on board at their time a big part of the story was we want to keep investing in this platform that we believe is going to be a key differentiator so when you put all that together I think that's what's enabled us to maintain this investment Even at the times where we had nothing tangible to show for it, now that we're well past that and we are showing the margin, retention, the cross selling opportunity, the customer satisfaction, it's a lot easier right in retrospect now to do it.
But I guess the question is now how do we keep it going? Where do we do next with it and where do we think we can take it next which is part of what we're addressing now? Absolutely. Well, I teased this earlier and I have to say congratulations several times over because you've had a lot of recognition from Microsoft. Quorum Cyber was recently announced as the winner of the security MSSP of the year award within the sixth annual Microsoft security excellence awards in 2025.
That is amazing. What do these kinds of awards mean to you from a vendor uh a gigantic vendor like Microsoft recognizing you and and I should really make sure the audience understands you're no small potatoes in this. You're over 400 people strong. you're across several different countries and so you're a larger organization, a larger MSSP, but when it comes to the recognition that Microsoft gives you for something like this, knowing you're going up against literally everyone else, what does it mean to you and what how do you tell that story to your customers so that they understand the level of commitment and investment that you're making?
As you can imagine, it's incredible to to get that recognition, right? Even to be nominated. This is the third year we've been in a number of categories. So, it's it was great to just be nominated before that. And if you think about it, three years ago when we were I think it was the first time we were nominated in in this particular award, we were probably a third of the size we are today. So, it was even more incredible that we were being recognized to get there to now winning some of the bigger awards like the uh security provider of the year.
It's incredible. I think it does more to our teams than anybody else. Uh to be honest, I've always enjoyed what it means for the people that don't get to see the warm fuzzy light of Microsoft paying attention to them that they're doing the hard work. They're in the hard yards in the offices and they don't normally get exposed to the conversations I have where the executives whether with an award or not are really loving the work that we do and the customer stories and all that.
I get a lot of that, right? So, you get that positive reaffirmation all the time. The teams don't. They're they're just busy doing the job. So these awards do magic for that cultural side of things for for their validation of this matters. We're making a difference and a huge behemoth like Microsoft is paying attention. So I think I think the biggest thing that it does is for our people it's it's fantastic in terms of customer differentiation go to marketing.
I mean it helps. I've always been relatively skeptical as to does a customer really buy from us instead of the the company next door because we have an award. I don't know. I mean it's branding. It helps solidify the money. does help us. To your point, I think we're more well known in the UK because that's where we started and we had most of our revenue in the US. We're we're a growing US and Canada. We're a growing business. These things really help dial up the brand presence and that's that's fantastic for us and it's it's ideal.
But if I had to pick one benefit, certainly would be the cultural benefit and they're they're magical for for that. Oh, I love that. Well, congratulations on that level again. Really exciting. You did talk about uh the expansion that you're working on by the way coming more into the US. You say you're more wellknown in the UK, but you are driving deeper into the US market. Talk to me a little bit about that plan like how deep into that are we right now and what is the overall goal that you're trying to to get to?
Yeah, it's absolutely fair to say we we were started in the UK and UK is still will forever be our biggest market or certainly our primary market, right? That's our home base and we will always have our home base. When we did the investment with Charles Bank in May 24, a big part of the hypothesis for that investment and the story for that investment was the international expansion. We'd been in the US really for about a year, a year and a half before that deal.
And that was all organic. Like that was we hadn't gone out and built a sales team or a go to market team. It really been Microsoft recommending us to customers, word of mouth, the community. But we saw that our our our solution fit and our model fit what what the mid-market small enterprise market was needing in the US. So the Charles market investment was really predicated on cool let's go do this now at scale and that was a combination of both organic and inorganic.
So we did the deal in May 24 and then we went straight into doing two acquisitions. So we acquired a Canadian business called Defenda three months after the investment and that's a business that brought about a hundred Microsoft security experts and a number of customers both in Canada and the US. It's a really quick way to expand and to show force and to really demonstrate that we are wanting to be a significant player biggest player one could say in North America.
Uh and they were very much like us managed security services Microsoft only. So perfect DNA, perfect culture fit. It was just ideal. you couldn't find a better deal. And three months after that, closing on 31st of December, literally the end of the year, uh we acquired a second business, a company called Kiru that focuses on instant response, very different acquisition. So they're 16 year old firm and they have a ton of relationships with insurance firms and legal firms.
They deal with thousands of incidents a year and that matches exactly what we do in the UK, right? So about a third of our business was coming through the door of us being an instant responder and the only global partner Microsoft has that does instant response with Microsoft only. So buying Q was a direct growth objective. This is how do we how do we become involved in the incident economy in North America. How we capture a lot more and because we have this unique differentiation of the Microsoft story we are now the only player in North America that does IR only on Microsoft.
So, it's a really great way of giving the market something different than the traditional Crowd Strike Sentinel one offering. Microsoft is now one of the biggest players in the space and there's no other service provider servicing for that. So, that's a huge part of how we focused our kind of immediate growth in North America. Such exciting stuff. How do you stay consistent across every country that you're doing business in? Then cyber security as we know is really complex.
It's difficult and it's also not siloed. It also has to go handinhand with compliance. It has to go handinhand with several other factors. So when you're thinking about that, knowing that you're up against different requirements country to country, what's the secret to staying consistent or what challenge are you always prepared for when you walk into something like that? It's hard. Um I think the legalities and the compliance comp friction or complexities of moving into a new territory are something you really have to think aggressively about when you're looking to expand to a new country.
And whatever you do, you're going to come across a crisis that you couldn't even imagine. So I think there's it's just being really aware that you're going to have to spend a lot of cycles and energy doing that. Well, at a kind of go to market fit product identity level who we are. My obsession has been there's a phrase that I continuously repeat to the teams is don't obsess over the products that we sell or what it is that we do. Obsess over the problems that we solve.
If we fall in love with the problems that we solve, we will then be able to pivot, to change our portfolio, to adapt it, to kill products that just don't resonate anymore and bring new products for as long as we keep that obsession over what is the solution, what is the problem that we solve and how do we solve that problem with our solutions. This has kept us really agile in evolving our portfolio and taking new things to market really quickly because we saw that there were better ways of fixing problems.
And that's something that we baked into the heart of how we do innovation, including expansion, right? There has to be a problem that we're obsessed and in love with. If not, shouldn't be doing it. And that's just not us. I can definitely hear the passion. And that's my favorite thing about the conversation is the problem solving because at this point I don't know if I could ever point to a success story where somebody went, "Yeah, we just got really into selling this one thing based on how it sold it." It no, that that can't be what you build your company on.
So I I definitely agree with that. And it leads me to think speaking of problems, we've seen such an explosion of AI tools in the last two years. It's just been massive. It kicks off with things like chat GPT at a consumer level and just goes on from there for for all the things that we could not have time to go over right now. But considering that, how has that impacted you as a security company? And are there any particular tools in your portfolio right now that you're seeing grow faster in relation to this explosion of AI tools?
Great question and I can I can go into a philosophical rant here a little bit. So I I I agree and I think it's interesting that you bring it in the context of falling in love with a problem, right? I think in many ways AI was a solution looking for a problem at the beginning and people were looking they're still looking for that killer app of AI. In the same way that blockchain was a great technology that solved nobody's problem, right? There was a a and we had to start finding how do we use it for good.
The difference is I think I do think AI is revolutionary in how it enables us to do things better, differently, new things. So I think it just gives us a collection of freedoms that we we now need to learn how we use specifically as we've divided our world into three different streams if you want in our AI strategy. One is about working with Microsoft solution sets security compiler compiler for security and and the rest of the Microsoft solution sets.
We're working with customers. We're helping them implement it but it's probably the one that we are the least uh aggressive about and I'm very transparent about that. I think there are other partners that are doing more in it and that's great. again the problems that we're here to solve just just didn't match that as much as as it could have today. I think as it evolves as a producing side, we're going to see it a lot more. Right? I think in 18 months it's going to be ubiquitous.
It's going to be everywhere. Uh but it but it's going through that development phase right now. Right? The second stream is how do we use AI internally to deliver our services better and that includes Microsoft products as well, but that also includes a whole bunch of bespoke AI solutions that we're building for ourselves. How do we do better data investigations? How do we do better instant response? How do we enrich our intelligence? How do we analyze trends across our different investigations?
It's a huge universe of just doing our job better that AI has been fantastic about. And then the third stream is about how do we protect our customers use of AI. So as businesses build their own LLMs, their own applications to disrupt their own businesses, not a lot of security been designed around that and we believe that they're starting to expand their attack surface quite dramatically creating these big LM, the big monsters that are not necessarily well protected.
So I think we're putting probably most of our focus is how do we adapt our existing services, our MXDR service, instant response service or threat hunting service to better cover those assets to expand their awareness. So we can do now things like injection attacks into LLM, data excfiltration attacks, privacy breaches when things are trying to be consumed in ways that are not how the business designed them. We're trying to really focus on those collections of anxieties that most of our customers have.
So that's that's where we're probably spending most of our AI cycles if you wanted the most. No, I appreciate that. I think that's really important to consider when you're looking at it in those three streams, especially as you explained there. I think that also breaks it down into how to prioritize it because as you mentioned in the beginning of that philosophically, it was very much uh a solution looking for a problem. And I still notice people trying to say, well, how is this going to save or make me money in any really measurable way?
So I I see a lot of people honestly wasting a lot of time and energy on AI tools that don't really fit to them at all and it could do more damage than you realize it it could in the beginning I think so I mean we've had this discussion very openly with Microsoft right they're trying to co-share the risk with partners and and there's a huge difference as to how their partners are funded and our capability to fund pure R&D whereas Microsoft has has deeper pockets right so we as a service provider particularly corum cyber are obsessed over.
Look, if it helps a customer be better, do better, achieve, I'm all in, right? We'll be with you all the way in. If we're at pure exploration territory, I need to be so conservative about how I spend those cycles because the opportunity cost of what I could be doing with that time somewhere else. I only get so many shots at Target given what we have as capabilities. And to your point, we're not a small partner. We're wellunded, well resourced. We're doing M&A.
So we're probably at the kind of mid to top end of their partner ecosystem. They're a huge collection of partners that don't even have these freedoms or resources. So it's a more difficult model for Microsoft. But it's great that they're engaging. I mean the difference I guess one of the reasons I've enjoyed the Microsoft relationship so much is how they treat their partners and how much they're partner centric. I don't think every other hyperscaler at that size is is that open to working with partners and to listening to hey we just can't keep up with your R&D budget. on a like forl like basis because you were just not funded in the same way.
So, you know, it's been it's been great. And you asked before if I'd seen any other product kind of take over or be benefit from from the wave of AI. It's been incredible. But our data security practice, which is not something that you would have or intuitively combined with AI has blown up, right? So people realized that in order for them to implement AI solutions, particularly M365 Copilot and that collaboration suite that Microsoft created, they really needed to get their data security in order, the data labeling, the data marking and all that universe Microsoft treats under a product name called Purview.
So we've had a managed security service with Purview doing insider risk detection, data leakage and that's probably tripled in over the last 6 months, nine months in terms of pipeline opportunities. we can see people really focusing on the dependencies uh and the upstream problems before they get to really maximize their investment in AI. So that's been super helpful and I'm sure other partners have seen it too. No, and I I agree about that and I I'd love to take a step back to you talking about the Microsoft relationship for a moment there.
You spoke very highly of them just now. I'd love to know from your experience as a partner, how do you feel that they are engaging with you in a way that they're listening to your concerns about things like AI and just generally about the way that you're leveraging their tools? As I love the way you put it as kind of that co-risk relationship with them. Again, my experience is end of one, right? So, I haven't worked with some of the other hyperscalers.
So I can only share my experience with Microsoft and maybe I'm being unfair in in assessing the other ones without having experiences firsthand but Microsoft has a whole organization dedicated to partner success. Right? So they're not just doing this as part of their day jobs. Their entire teams whose entire bonus and comp depends on partner success and our us partners being successful with them. So that's a huge level of investment and commitment Microsoft makes to activating partners.
It goes from nurturing partners to promoting them to manage partners and and then through all the tiers. The the association that that we got the award, MISA, the Microsoft Intelligence Security Association, sees a beautiful pyramid of something like hundreds of thousands of partners at the bottom to a few select ones at the very top of which we're lucky to be in. But imagine what the thickness of that pyramid is. You're talking about hundreds and thousands of organizations and Microsoft caters for all of them.
They create spaces for uh strategic meetings, quarterly meetings, technical meetings. It is incredible the access that you get. And this is something I always reflect with customers. Customers are really used to seeing the Microsoft sales side, the licensing, the consumption, the product. They don't really get to see everything that's underneath the waterline of that tip of the iceberg, which is the technical teams, the partner teams, the program teams.
There's so much more that I'm desperately trying Microsoft to talk more about because customers are just so used to interacting with the account manager and there's a universe of capability underneath it. A huge part of which is activation of partner. So as a partner there's always more you want uh but honestly you couldn't ask for more in terms of a willing partner to be challenged even at that size. the fact that we are in those rooms challenging strategy, providing input and and co-working on how do we go to market better, how do we derisk, it's incredible that they're that open to that collaboration.
Thank you for digging more into that. I I want to go back to talking more about your tools over at Quorum Cyber and I guess actually more specifically about the verticals those tools typically serve. I always like to kind of peel through the industries and vertical pages of the various partners that I speak to just to see like what stands out to me. You always see a lot of manufacturing, you always see a lot of retail, very very large in general.
One that stood out to me for yours was housing associations. And as somebody who I'm I'm a homeowner now, I've been a renter. I've paid HOAs in my in the past. It's it's a lot that stands out to me right away as from the consumer side. For you, why is that an offering that you specify under your vertical page? Great question. Quorum cyber history has been plagued with things we decided to do and worked out. things we decided to do and didn't work out and things we never expected to be involved in and just became incredibly great for us as an opportunity.
Housing associations is a great example of that. Higher education is another one. So when we set up our go to market strategy verticals we knew we could help to your point manufacturing was there, financial services was there, public sector was there. One of the ways that we've always been reactive to market need those problems that we obsess over is we are what we call thread led. We follow the market of where thread actors are focusing. If thread actors are focusing on an industry, I need to be there because that's my job.
I protect people from bad guys, right? That's that's fundamentally at the basic what we do. So we follow the bad guys and we're there when before hopefully they are there. And housing associations was one of those verticals in the UK. There was a campaign going back a couple of years where a ransomware outfit really went after all the housing associations because if you think about them, they're high capital businesses, relatively unknown. are not in the spotlight for high security, high resilience businesses.
They haven't traditionally invested a lot in cyber. So, they were a super rich target for financially motivated cyber crime. So, Microsoft actually sent us our first couple of uh contacts when those organizations were getting breached themselves. We developed some really good track record helping them through that crisis and building great relationships and it blew up from there and then they started all recommending each other and like at Domino we just became one of probably the biggest providers for cyber security for the housing association sector.
It's been a great story for how reacting to the problems that we saw really helps us develop our business in ways that we couldn't have anticipated almost verbatim. The same story happened with higher education when I think now it was a more intellectual property motivated actor starting a massive campaign hacking most universities in the UK primarily at the time and again the same story. Microsoft brought us on board to help some of those customers go through that really bad day that situation.
We did great work and that started unleashing a network of opportunities and and now again we have dozens of higher education establishments under our protection. So very much reacting to market need. I find that so interesting. So thank you for digging into that for me. My pleasure. It leads me to to ask and it doesn't have to be under the same vertical but is there a success story with a customer that stands out to you in which you go this is a really great example to show the kind of value that we provide our customers?
Yeah, anecdotes are always fun. I I'm incredibly lucky again in this industry when you get to work in instant response outside of everything else you do when you get involved in somebody's worst day and you help them through that and then you take them through that moment they resolve that but then they become a customer for life they become you become a real partner and you help them never achieve that again it's a really fulfilling story and fortunately a lot of those people don't want their logos mentioned right understandable understandable without mentioning the logo a really great story was an automotive so it's a competitive automotive brand one of the ones that you would know that you see racing in F1 and we're doing a proof of concept actually had two partners uh doing a proof of concept for their solutions at the time and we did it during race day our so that they could see it working live and as we were doing our proof of concept we discovered industrial espionage in in a really important computer of a really important engineer in the team uh and we were able to not only contain that but actually I mean you can't ask for a better proof of concept than going back to the customer well it's not just a proof of concept but we just stopped this from happening needless to say they signed almost on the spot and it was a great story and we're we're all incredibly proud of the work we do.
So those kind of moments where you really get to see a combination of how how great the teams are and the technology is but with that lack of just that moment that richness of that moment where everything unlocks and it just works is is beautiful. And the more traditional side of the house going back to Notting House housing associations Notting Hill Genesis has been really one of our strongest advocates. They've been a one of the biggest they're one of the biggest housing associations in the UK and they really undertook this idea of resilience journey right again they started with an incident and they were very open about it but then it went on to how do we not get here again how do we manage risk better so from one product I think they probably bought everything we've ever sold we've had a relation with them for years and to see a team that learns so much from a moment and that really promises to themselves never to be there again it's just really incredibly fulfilling ing you you get a sense that you really contributed and it's one of the reasons I like MCM market.
You can really help. These are organizations that really need a partner. They're not these behemoths that are unmovable objects where you can't ever affect strategy. These are people that really really need help. They have their own business to run and they want a partner who can come in and hold their hands through all of this. And I'd like to believe that that's where we show up at our best and not only what we do, but how does it feel to do it with us?
That's one of the things we've always been really key to differentiate on. I also want to talk a bit more about kind of your philosophical approach to how you run Quorum Cyber. As we've been talking, again, I pointed out your passion for this, for what you do, and that has honestly just become so much more prevalent during this interview. It's impossible to not get excited talking to you about these subjects, even though some of them are the scariest subjects that we can go over.
And a lot of that goes back to we discussed your passion for education. You're very big on educating your people at your company and you're big on you're you're not as into buying talent across the industry. That was a term you used with me. You're more into educating and investing in the people that you have. Can you kind of explain that philosophy a bit more to me and why has it worked out so well for you? Yeah, sure. And look, I don't want to masquerade it as philanthropy uh because it's not there's a there's a pure harsh commercial benefit, right?
But it just happens that it also benefits everybody. So those are the best kind. We made to your point a very early decision that in and everybody will know in this industry is hard to hire, right? The there's this perception that there's 3.5 million empty seats that can be filled. I don't know if that's legitimate and I've always had this thought that that might be real for industry, but I think security providers find it a bit easier because we're more interesting for the candidates.
They get to see many different customers, many different problems. Whereas if you're the department for motor vehicles, probably filling that seat is a bit more difficult, right? Nothing wrong with the DMB, but you know the more traditional organizations might have a harder storytelling to do to candidates than a cyber security firm that is working on the latest greatest hacks, right? It's it's just a little bit more interesting. So I don't think the security market is constrained for security players.
However, we're still fighting for the same talent and we still need more of it. So very early on, we hired John Wallace, our chief people officer, uh when we were 20 people, I think, and we made that call that we we're going to grow our people. we're not going to buy them because we want to be able to shape and mold not just the technical knowledge but the cultural uh ability and the cultural way of being and how we want them to work with our customers and with each other.
So we started Cororum Cyber in Scotland for exactly that reason. We created great strategic relationships with some of the local universities and we've worked really hard to make sure that we take as many people as we can from university and then we put them through a pretty structured approach. It goes everything from two years at the longest where they do rotations over different parts of the business all the way to more accelerated programs for more senior more experienced people.
But that gives an idea most of our junior talent if you could call it that comes in through that avenue. And then that starts giving them all the tools and experience and the cultural makeup of how we want them to show up. It also gives them the Microsoft story. There aren't many places to learn the technologies that we use and the solutions that we use. We became a huge Microsoft security creation engine and then that starts feeding the rest of the organization.
So one of the great success stories we have is about 30% I think is the current metric of internal roles gets fulfilled from internal people. So we're not having to go to market. We get to see those people go into engineering or instant response or even commercial roles, right? But that gives us a consistency. It feels core and cyber all the way through. You're not having to change cultural behaviors from other players that just do things differently, right?
So that was something that really mattered to us. A we want to build people. We want to really be a force for good and the contribution here and we know we get head-hunted and that's a benefit right because for every person that gets headunted and gets a career somewhere else 10 other people want to have that story too. So it keeps the cycle really well flowing. So to us it's just has worked out incredibly well and I cannot recommend it enough for any other partner or any other company doing it.
It does require an investment. You do have to put a lot of focus on creating an academy which is what we've done. The apprenticeship programs, the graduate apprenticeships, all of this takes time and like most things like the clarity investment, you don't see the return of that immediately. It's a it's a bit of a longer term story. So, you probably need to know what your objectives are, your long-term objectives, how how much you're willing to wait for some of these to bear fruit.
But, uh, now we're probably four or five years into that investment and the difference is incredible. We do not have to compete for talent in the market. We're known for a great trainer. Yes, we get head hunted and that's okay. That's that's part of the benefit of it. People get a career out of this and that's not that's not a problem for us. We see it as a benefit. I would say that that also relates to your philosophy about how you educate your customers.
You you had you told me uh in in the previous call that a lot of people that come in, customers that come in often think they need to buy more solutions and invest more into their security stack by just making it bigger and bulkier. And you often have to say you have what you need, you just don't know how to use it. How does that set you apart? And obviously I don't know if you could speak so much to how it's different internally at other places because you don't work there, but how do you feel that sets you apart as a provider?
No, look uh you were paying attention. Well done. Uh yes, I think there are commercial incentives as well that we don't have like we made some very specific decisions. For example, we don't sell licenses. We don't sell Azure consumption. We're not a CSP partner which removes some of those not conflict of interest but you know incentives align behaviors. So we are not incentivized to sell licenses. I really just want to get the right outcome for the customer.
That's ultimately what my commitment is. And at that point we have our obligation to maximize what they've already had on the ground before asking them or suggesting them to buy something else that that they need access to. So that's a key part of our go to market is our job is to squeeze the most amount of value of what you already have. This industry has been plagued by it being too easy to sell. People people have been forced this blank checkbook especially instant response right the moment of instant response is a moment of massive vulnerability for the customer on the other side and there's this habit of okay what do we need to buy in order to fix this and 99% of the times customers had it they just hadn't deployed it correctly it hadn't been utilized correctly connected correctly so a huge part of how we choose to show up to that moment is not stop worst thing to do right now is to buy technology that you don't know how to implement you don't know how to use this is not the time there might come a time where New technology, new controls might be required.
This is definitely not it. So let's right now contain the fire. Let's then learn what could have been done different. Let's gap analysis to what you currently have and then we can figure out together if you're willing to make an investment and whether that return of investment, the benefit of investment as we talk about it is to measure to that investment. But right now is not the time. So we really love that approach. We think it gets some people ask me but surely Microsoft for example your biggest partner is interested in you positioning the Christmas tree of options and the customer. you're wrong.
And again, one of the reasons I love working with them, Microsoft knows that a solution bought under duress or without a clear evidence of value is a customer that's going to churn further down the line because they will not have received the value that they wanted to. So Microsoft is super great to work with in that if you think that this customer needs to go slower, if you think that solution is not right for them, 100% behind you all the way because they know that they need customers getting value, not just getting licenses.
And I think that's something we need to change. A lot of customers have been sold these great bundle deals where they bought things that they didn't even know we were getting and then you see them buying competitive products. Sometimes they have two or three times the same capability under different logos when at the same time budgets are being constrained. So we like to be a difference in that ecosystem and and that's partly how we go to market is the maximizing value from existing investment before you ever look at bringing any new solutions.
I think that's something something that is especially important for growing providers to remember for growing managed service providers especially because I do hear a lot about ones that even they get caught up in the kind of the Christmas tree as you said of options. You go to all these conferences and trade shows and you see so much technology out there and sometimes you get caught up in thinking you need to partner and add to your portfolio when really what you're doing is just sort of doubling up on on the amount of solutions that are in there already with different vendors.
And you have to pay attention. You have to educate yourself. You have to kind of start at a way where you go what does this address and then we'll move on from there to say let's go to the next thing once we think that's that's taken care of. And I think there's some really great ways to connect it to strategy. So to contend there like a lot of the time people saying but you're leaving money on the table. So there's there's two two quick answers for me there.
One is if if your job is to be a value added reseller. If you're have our if you're a big distribution totally different story, right? I'm talking specifically to people that look like us in a managed security service provider specific section. If you get revenue that then churns, that's going to affect your valuation more than you never had having had that revenue to begin with. And that's something that we're whenever we do a deal, part of the criteria is are we going to lose this customer in two years?
Because if we are at whatever next event we're doing with the next investor, we're going to have to explain why we had an uptick and then a downgrade. And that is a really tricky story to tell. So even at a finance executive level, not every piece of revenue is good revenue. And really being strict and disciplined about what is good revenue, what is a good customer has served us really well in our story of investments. So, if nothing else, and that's how you want to look at the success or not of a decision, I I I stand by this 100%.
We're really disciplined about what's good revenue and not every pound is worth getting. And just be aware that you want to be able to tell a story with the numbers to to Greg's point and that story has to be well, you would like it to be as good as it can and customers turnurning because they didn't get value of your service certainly not a good thing. However much you might need cash at some point and I've been there and we've all been there, right?
And sometimes cash wins over strategic long-term outcomes. I completely get that. Well, I think your strategic long-term outcomes have done very well for you. So, I think at this pointing to those in particular are the success story rather than the ones where you said we need cash now. Considering our time here, Federico, I really want to make sure that I I get to know where we can learn more about Quorum Cyber. But please tell me first, what can we expect from you in the rest of the year?
We got a lot more 2025 to go. So, what's next for your business this year? We are at the almost end of our financial year. So financial year is very rarely runs from June. Don't ask questions. It's fine. H. So what we wanted to make sure we did was really focus on maximizing the integration potential of the two businesses we bought as well as a whole bunch of new executive team that we're bringing to to the equation to really maximize how do we use what we had with Chorum Cyber and what came in through the acquisition of KU and Defender.
So the whole objective was aiming towards the end of May, beginning of June where we wanted that that transition period completely done and dusted. So we're put that behind. That's our last financial year and looking forward. We have all these ingredients. So this year is a lot about how do we now bake the cake. We have all the ingredients. We want to be the biggest, the best thread management security company in the Microsoft space for mid-market UK, North America.
So you should see us really come out swinging with all of the capability we've not acquired really heavily differentiating on Microsoft really heavily differentiating on the threat capability and the threat intelligence team that we have which is great some of these are some of the key messages you're going to see we're doing great work with private equity as a sector with insurance with legal firms so a lot more focus on those channels where we've had really great success stories and new products right so there's an identity product coming out there's a lot of the work we're doing in OT that is becoming a universe in itself.
Yeah, we're not staying quiet. Let's put it that way. Great to know. Well, speaking of not staying quiet, where can we go to learn more about you and get to know Quorum Cyber? Easiest place is quorumcyber.com. That's our main website, but I would also love to point you to helpfightbullies.com. Both of them are the same. And that's our talent page, and that's where you can find more about careers, development, progression, the talent, the people we have in the company, our values.
So, we try to keep them separate. So there's very much one that is to market about our offerings and our services, but then really our entire academy and the universe of our people development is under helpbullies.com. I love that. Oh, I love that. Thank you so much. It's been such a pleasure getting to speak to you and getting to know you and Quorum Cyber Federico and I just wish you the best of luck through the rest of the year. Thank you for the opportunity, Katie.
It's been great. Thank you so much to Federico for joining me today and thank you for watching or listening. You can check out every episode of Channel Insider PartnerPV on channelinsider.com or watch us on YouTube at youtube.com/ channelinssider_news and trends. You can also listen to us as a podcast wherever you get your podcasts. Don't forget to like, subscribe, and follow wherever possible so you never miss an episode. Once again, I'm Katie Bavoso and I'll see you next time.
This transcript was generated automatically from the
video's captions and may contain errors.