Dan speaks with Sean Farrow of Arctic Wolf about the fast-changing MSP cybersecurity landscape and Sean’s move from a 15-year MSP career, most recently as security practice lead, to the vendor side. Sean explains how gaps in an MSP’s Microsoft-based SOC portfolio led him to Arctic Wolf for vendor-agnostic coverage, and discusses the pressure of keeping pace with shifting best-of-breed tools and integrations. They explore MSP commercial realities such as packaging, pricing, margin predictability, and the need to reduce operational friction by delivering outcome-driven, true-positive tickets. Sean outlines Arctic Wolf’s vendor-neutral approach and security concierge service, and previews a streamlined MSP-only offering expected around September that aims to simplify scoping, improve price competitiveness, reduce requirements like a mandated network sensor, and introduce more on-demand digital concierge capabilities, while still pulling data across the attack surface.
00:00 Welcome and Setup
02:03 Sean MSP Background
03:41 Keeping Up With Security
05:07 Why Move Vendor Side
06:19 Pricing Sponsor Break
08:33 Life at Arctic Wolf MSP
11:22 Arctic Wolf MSP Model
12:55 Streamlined Offering Changes
16:10 Posture Improvement Examples
19:52 Launch Plans and Wrap
Listen on Spotify or Apple Podcasts
Connect with Shaun Farrow on LinkedIn by clicking here – https://www.linkedin.com/in/shaunfarrow/
Connect with Daniel Welling on LinkedIn by clicking here – https://www.linkedin.com/in/danielwelling/
Connect with Adam Morris on LinkedIn by clicking here – https://www.linkedin.com/in/adamcmorris/
Visit The MSP Finance Team website, simply click here –https://www.mspfinanceteam.com/
MSP Glossary: MSP Finance Glossary Explained | MSP Finance Team
We look forward to catching up with you on the next one. Stay tuned!
Transcript:
Dan: [00:00:00] Sean, welcome to the podcast.
Shaun: Thank you. It’s a pleasure to be here.
Dan: And we were talking, as we often do in the green room, about, what we wanted to cover off on this episode. And, this is really gonna be a game of two halves, excusing the, world Cup football pun, which is, relevant at the time of recording, if not at the time of release. And,the first half, I’m really intrigued by your background, having, made the move from, an end user focus business, delivering it services towards a vendor.
And the, the second part of our, conversation, will hopefully focus on,just what Arctic Wolf are doing around the, the S-M-E-M-S-P, part of the market. And,and I know there’s some interesting developments there to,to unpack. So, talk to me a little bit about,what you, what your role involved, immediately before, moving [00:01:00] to the dark side.
Shaun: Okay, thank you. so yeah, I was with an MSP for about 15 years and just before I made that transition across to the dark side, I was the security practise lead and that meant that I had a kind of oversight of the portfolio, but also ensuring the success of that, right? So under making sure our customers were happy with that, that experience, and making sure ultimately, that we weren’t walking away from deals because something wasn’t a good fit, like hoping to have a good fit for any customer. the, my kind of introduction to Arctic Wolf, that came from a, a gap really in that portfolio where we, at the MSP had, we’d been working with Microsoft Services for a long time. We were CSP and there were Microsoft based SOC services that we delivered. [00:02:00] But, not all customers wanted to leverage that, tool set.
And sometimes, they’d have existing contracts or commitments where they’d want to use that instead. And rather than having to walk away from those because no one wants to say, oh, I’ve gotta walk away from this deal, your sales leader’s gonna be unhappy about that. Sales team are gonna be unhappy about wasting that time.
we decided to look at the market and understand whether it was suitable to bring something else into our portfolio.
Dan: Okay. and the I guess the, the backdrop to this always is, is the nothing standing still, right? you,you assume a strategy and have a product set and a stack and a specialisation. A standardisation, and 12 months later it’s outta date. we did do, do, did you feel the pressure of the, the pace of that development.
Shaun: Yeah, absolutely. I mean, you’ve just gotta speak to most, [00:03:00] most it people nowadays. And when now there’s a pretty good consensus that things like, defender for Endpoint as an AV is now a very good product and it’s up there best of breed. but if you speak to ’em about, you know, five, 10 years ago, they’ll tell you, oh, that was the first thing I’d get rid of, right?
Like, there’s been a massive change there. And it’s the same throughout most pillars of technology. And we see that at Arctic Wolf as well with kind of integrations. We have to keep an eye on what is suddenly doing well in the market and what’s gaining market traction. for example, abnormal ai, right?
the historical kind of best of breed email providers. Mimecast, Proofpoint, we’ve had those integrations for a long time. Abnormal AI is a newer integration, but it’s just seen such strong adoption in the market.
Dan: And so you,that, that was sort of how you found Arctic Wolf then by going out to the market, looking for something, vendor, ag agnostic. what made, interested to know what made [00:04:00] the change, ’cause you had a long career at,at the IT services business you were with.
what was the, what was the attraction?
Shaun: Yeah, so the attraction was twofold. in truth, I probably stayed a bit longer because I was very comfortable and, you know, the people made the workplace for me and I had an office I would go down to, and it was very social. and I do, I still miss that today, I would say. But I’d moved from a very technical role historically into more of a customer facing role, closer to the sales side of the organisation.
but at the time I was supporting more than just a core security focus. so it was my desire to move more into, a specific area, so Soc, MDR, et cetera, security Operations as it is now. And also the ability to get a bit more technical, ’cause I’ve moved away from the actual, creating labs, creating demos, that sort of thing where I [00:05:00] can put stuff together and demonstrate the efficacy of something or the benefit of the product.
And just a new challenge as well, to be honest.
Dan: Sure. and I think that second from last point about becoming more technical, I think that’s something that, MSP owners, I’m sure struggle with as, as they,navigate the phases of MSP ownership, perhaps starting as a technician, an engineer, then becoming a sales person, then becoming a leader, and ultimately a shareholder, which is the lifecycle, stages that I see.
And especially for in my own experience, when,I used to learn from the people around me, the, the intricacies of topics, which then gave me confidence describing, communicating those to the end users. And once I wasn’t there in that environment with, with a technical team that I could just dip in and out of,I started [00:06:00] to lose my confidence in the topic.
And, and so I absolutely understand about wanting to, retain that, that strong technical background,or involvement to,and you can’t know everything about everything, right? And so you’ve gotta, you’ve gotta pick a horse at some point. So, very interesting. and so, talk, talk to me a little bit about, what life is like now, what the diff what the difference is, ha having, having been in end user IT services business, focused and like, presumably you are still talking to end users,at Arctic Wolf.
Yeah, to some degree. So when I came across, although I’d been working with the Arctic Wolf organisation already because I’d onboarded them into the portfolio, I actually moved into the MSP specific division, Arctic Wolf, which in the UK is only been, like an entity for about a year or so.
Shaun: Now, I would say, in the US it’s the MSP [00:07:00] model’s been in play and it’s about eight years old in the US for MSP. But,it’s exciting because there’s real kind of growth opportunity, both from a personal perspective, but also from a, a business perspective. And I feel like I have a very good understanding of what it’s like to be on the MSP side, obviously based on my background.
And that has enabled me to have slightly different conversations with, prospective partners and existing partners around, you know, enablement or packaging or that sort of thing, and an appreciation of the, kind of the challenges they have. So I guess an example of that would be when they’re comparing us maybe to their existing solution where we say we’re security operations and we’re outcome driven, meaning that we are gonna give a true positive ticket.
We are not giving all the tickets, like any alert that we see, we’re not just passing that across. You know, the, the quality of that ticket really matters because firstly, you don’t want false positives. But secondly, if there’s lots of back and forth to like, clarify [00:08:00] stuff, then ultimately that’s time and that is therefore money, right?
And MSPs are typically the people I’ve worked with and speak to at least are usually very busy. You know, they’re not typically resource heavy. so if you can reduce some of that back and forth, then fantastic. And those are some of the conversations, right? How can we reduce the friction all the way through operationally from the sales cycle, but also operationally in the background as well.
Dan: Yeah, really interesting. and I guess you, you touched on there around the packaging, you know, an important part for an MSP is,being able to establish what their margin will be and,and how likely it is to achieve that predictive margin. Because if they think they’re gonna make a certain level and then,are burdened with additional workload that they weren’t expecting, then their margin will suffer.
And in reality, they’re probably not staff for it anyway. So it’s,it’s not like they’ve got this,abundance of, resource to, [00:09:00] to apply. So, I mean, may, maybe that’s, that takes us into the second half. and, and so, how do you reassure potential partners,about that point, and what can you tell us about the, the, the, the new MSP model?
Shaun: Yeah, so kind of Arctic Wolf in general. as an organisation and the services that we provide, we are known really for two things in the industry, and that’s vendor neutrality. I mentioned that before, the last 14 years, we’ve said, actually we’ll meet you where you are. You bring us, the tooling that you are using.
We are not gonna displace that. We are looking to tie into that tooling and aggregate that resource. the other thing that we are known for is the security concierge service. and that’s a, a team of individuals that are aligned in the MSP model to the MSP on our other models that are aligned directly to the customer.
But their focus is around improving an organization’s security posture. So again, they can deliver that [00:10:00] to the MSP and A MP can deliver that on propagate through to their customers on kind of their terms. or on the resale side and MSP plus models that we have, then they’re working directly with the customer because ultimately if you improve the security posture, if you improve the readiness of an organisation for an in, an incident of some sort, then the impact of that incident is minimised and often the threat is mitigated.
I guess in terms of our, what we’re bringing to market later this year and the merit of the vendor Neutralities Universal, right? That doesn’t really change. And the MSP market segment will appreciate that. and that’s not gonna change. But the friction that we do sometimes see is when we’re, we are being compared based on our platform, which for us, we want to, ingest data from like anything and everything in terms of the attack surface.
So like every facet of the attack surface, if you like. but we’re often compared with other vendors that may have entered the [00:11:00] MDR market, coming from like a, just an endpoint perspective. So they now have a sock that’s looking at endpoint and maybe they can tie in some identity. Hopefully they can tie in some identity, but it’s quite a different kind of, offering ultimately.
and that can cause us some challenges, obviously commercially, but also operationally, right? we really want to see the entire picture. and so we are looking at a, a streamlined service which will reduce kind of the, the friction in the sales cycle and sim simplify things like customer scoping and but also allow us to compete, price wise more effectively.
So, the, we have the same platform, but at the moment we have a requirement for a, a sensor like a network sensor, which is gonna pull data from what’s happening in the network outside of even a typical device and server and things. But also that concierge, you know, people working with you on calls.
We are looking to build out more of a digital concierge and have it more on demand. So still [00:12:00] access to all the best practises, still access toll, collect that data and give back a presentation. But on the, the MSP partners timescale and through kind of their lens. And ultimately by not having the requirement for that sensor mandated, you can still get really good attack surface coverage.
’cause we still wanna pull in data from like the firewall, externally endpoint servers identity. But we don’t need that necessarily, need that specific sensor piece. there is a, you know, a slight reduction in coverage, but if you’re comparing it to other, you know, rps in industry, we’re still exceptionally good in that area, and that’s gonna allow us to reduce the, the time it takes to quote stuff, and also the operational burden on the backend as well.
Dan: Right. really interesting. and I’m sure these are the frictions that you found, in, in the market I’m sure are frictions that the MSPs will have in term with their, [00:13:00] their clients as well. And,the simplification of being able to quote, and provide a, a price so that you don’t lose momentum in a discussion.
and, so that you can properly qualify in an in or out,with efficiency. but accepting that if,you really want to be comparing apples with apples. and I think that’s, certainly that’s one of the challenges as the, the security landscape has evolved over, over recent years.
not everybody’s understanding and appreciation of it has evolved at the same pace. And,and I think that’s probably part of the reason why you’ve got such a, a huge variety of solutions and approaches out there,which, which will all need to be reconciled some somehow. so, you,you mentioned, so a couple of questions you mentioned about [00:14:00] improving the security posture of the end client.
could you gimme a couple of examples of the sort of things they, they might be, and is that one of the things that’s then, reduced or perhaps more self-service under the new streamlined approach?
Shaun: Yeah. So, as I say at the moment, I don’t have like a full understanding of what the offering will be because it’s not being launched until around September. but the sorts of things that we are discussing today will be, I guess a nice easy, straightforward example is like SPF records, right? So an SPF record is around email and it’s something you publish to the world to say, if you want to email me, look at this record, and it tells you where to send that mail.
Now, from an IT perspective, you know, maybe you’ve got, hopefully you’ve got an email protection vendor, maybe it’s Mimecast, Proofpoint, whomever it might be, and you have an SPF record there. And what may seem very logical is to have that first pick as that email provider or filtering service, and then you might have [00:15:00] a third pick, which is not a preferred one, but if the first one was broken, the second one would work, or that third pick would work.
And it’s quite common to see that and people are doing that because they think that gives them some resilience. But in actual fact, what that’ll mean to an attacker is I would just email that underlying infrastructure directly and that allows me to completely bypass the metal filtering. so things like that, like it’s just a best practise thing.
It’s just, you know, improving your security. But if you don’t know, if you’re only thinking from maybe an IT lens, like this is the sort of stuff that can be very helpful. And ultimately you are helping, hard and earn organisation security just by highlighting that kind of minimal thing. And I guess if you think about that sort of thing, but on a much grander scale, a good example would be conditional access.
So there’s, unfortunately, MFA is no longer like a silver bullet. There was a time when absolutely to on MFA would be the first recommendation, and that still is a [00:16:00] recommendation by the way. But now, you know, session cookies being stolen from malware or people managing to fish you to get that session cookie.
With that, they can often impersonate you and take data out of the cloud or 3, 6, 5 or whatever. But there’s a setting you can change to mean that suddenly only devices that you manage on under your kind of ecosystem can access your data. But without changing that setting, any, any device in the world could access your data if they have that session cookie.
So, you know, that attack surface, the difference between your 200 machines at Mr customer, the, the customer has compared to the, you know, 50 million devices that probably existed globally. that’s a massive difference. And again, it’s not, it’s not rocket science, it’s just going through best practises and highlighting it and understanding, you know, what does that look like for the tenants that you manage as a, as an MS.
Dan: Okay, super. [00:17:00] And,and certainly,the first example you gave of, Irv DDNS records, you know, being a great,a great conversation opener,because they, those records are publicly available, so you don’t even have to,be,have a level of privileged access, to, to a client to assess that.
out of interest, do you, do you use that sort of information, your, prospecting processes, out of interest?
Shaun: I, I think that’d be the sort of thing that we may talk about with our MSP partners. I don’t believe it’d be something that we would look to gather ourselves for our own prospecting, purposes.
Dan: Okay. Okay. Fair enough. okay. And,as you say, the new programme is,is due in September, and,over, over the summer, probably some of those details will be firmed up. what,what will be the route to market? are you planning a launch or,any events, that we might, might look forward to?
Shaun: That is a great question. is not one that I know the answer to right now, unfortunately. but yeah, it’s the, it’s expected [00:18:00] to be released to the market in September. you’re absolutely right. There’ll be a lot more information around it over the upcoming months and it’s really gonna be aligned to MSP only, at this time.
Dan: Okay, super. so pro, probably around,the time in the episode to offer a shameless plug if someone doesn’t wanna wait until September and a forth forthcoming, launch announcement. someone wants to carry on the conversation how best to get in contact with you.
Shaun: Yeah. I’m on LinkedIn, so feel free to reach out on there. obviously over the coming weeks we’ll have, I’m sure we’ll have information being published from the wider group onto LinkedIn. but yeah, probably LinkedIn’s the easiest way to get into contact with me.
Dan: Superb. Sean, it’s been, really interesting talking to you and,look forward to hopefully connecting again later in the year and hearing more about the new programme when it’s launched.
Shaun: Great stuff. Thank you very much.
Dan: Thank you.

