Huntress VP Andrew Kaiser Reflects on a Decade of Cybersecurity Trends
Andrew Kaiser, vice president of sales for Huntress, looks back and ahead on the cybersecurity trends that shaped the company as it marks its 10th anniversary.
Transcript
Hey guys. Thanks Withrow. We're here with Andrew Kaiser, who's VP of Sales for Huntress, and we're talking about, well, the 10th anniversary of a company that has often been at the forefront of whole, this push for managed services around security, ai, and all kinds of fun stuff.
Andrew, welcome the show. Mike. Thank you for having me.
You know, as you think back in time, does this cybersecurity landscape look anything like you might have first imagined or thought about? I mean, the world seems to be a different place, but I don't know, it's, then again, sometimes I feel like we're playing a big game of back to the Future, but what's your take on what's going on here? Y you know, I, uh, um, so I've been in the cybersecurity space since 2010 and was at another, uh, security company prior to Huntress for about maybe eight or nine years.
Um, and back then cybersecurity was, you know, deploy an antivirus and have a firewall and you're good. And today you could probably come up with a list of 40 or 50 different, um, types of security solutions that you should have if you wanted to consider yourself fully secure. So, you know, it's a moving target and it's something that I think every year, um, has evolved as quickly as the attackers and their methods have evolved.
Mm-hmm. It's clear that things are more complex, more challenging, and the attackers are getting access to more advanced tools. Um, can we win this game?
I mean, I feel like a lot of folks will complain, and I'm sure you hear these complaints where they're like, we keep throwing money at this, but we don't seem to be making a lot of progress. You know, uh, the, the challenge is that, um, from the attacker side, you only have to win once. So you can fail 99 times and on attempt number a hundred, um, if you get through, well, you know, you win as a defender, we have to be right every time.
And, uh, being right every time is just literally impossible. So it, it, it really comes down to, um, you know, having layers, um, making sure that you plan for, um, you know, catastrophe. But it is a, a really hard place to be.
And, you know, there is no silver bullet. So at the end of the day, it's, it's really about just being resilient. It feels like we're now in another iteration of that arms race just described, and this time it involves ai.
Um, is this just the latest investments that we need to make? Or, and, and I guess the question I have, is security becoming a larger percentage of the overall budget, or is it still relatively even? We just have to keep reinvesting at the same levels to ensure that we're relevant and able to fight the fight?
So I think, uh, so a, a few thoughts actually. Um, so first, you know, there's lots of talk about, uh, AI attacks and, um, you know, like gender gener generative AI being used in like phishing attacks, for example. And, and that stuff is absolutely scary as hell.
Um, some of the stuff that, that you hear about businesses that are tricked into wiring money when, you know, the AI generated CEO has sent you a video asking for that request, like, like that stuff is really gonna be hard to protect against at scale. What's wild though, is most organizations, and, and this is everyone from your 20 person law office to, you know, your 500 employee organization that, um, you know, has an IT team that is trying to, you know, own the security budget and the security stack. 'cause you don't have dedicated security personnel.
We're talking about 99% of businesses, um, most of them are not equipped to handle the attacks of yesterday and the ones that were dealing with today. So, you know, I think there is a little bit of buzz going on about protecting against AI based attacks. Um, but I do think that it will make certain types of attacks, um, more prevalent and probably, um, you know, if if nothing else, it's a good thing that it's gonna talked about because it will mean that there is more budget for cybersecurity programs at organizations that probably need it.
One thing I do feel that has changed and arguably for the better is there seems to be less tension between managed service providers and internal IT and security teams, and maybe they're all finally working a little more collaboratively together, or are we finally all on the same team? You know, I, I think we're going in that direction. Um, years ago, and this goes back to maybe pre COVID, let's say, so 2018, um, ish, there was a lot of talk of, um, this transition or this convergence, uh, between MSPs and MSPs.
So you're a managed service provider and your managed security service provider. And I think what's changed over the last maybe five or six years is this acknowledgement that, um, most MSPs, 99% of managed service providers are not going to become managed security service providers. They're not gonna build their own soc, they're not going to, you know, do their own threat hunting.
They're going to partner with vendors like Huntress, um, and, you know, kind of outsource that security component. And I think that that shift in mindset also, um, trickles down to the way that managed service providers work with IT administrators and IT teams. Um, you know, having, um, um, portions of your stack, uh, co-managed by an MS P has becoming a lot more popular.
Um, it administrative, uh, you know, orgs realizing that they can't do everything themselves and they have to outsource some of that maybe security to a third party. Um, just to make sure that you're not trying to do more than you're equipped to is just becoming more normal. And I do think that there is, um, uh, a, a better understanding that this is a team sport now compared to five years ago.
Mm-hmm. I also feel like the term m MSP is becoming a little more challenging to ascertain what that means exactly when asking the question because, um, used to be MSPs, you know, they generally built their own stack and they had their own data centers and their own knocks. And now I will see people who I used to call resellers calling themselves MSPs 'cause they're reselling some sort of, um, cybersecurity platform from some vendor somewhere that is offering it as a managed service.
Is there a difference in the quality of the managed services that you get? And how do I distinguish between, you know, those that are adding value by rolling some additional capability versus merely just reselling something I could buy as a SaaS app myself? Yeah, it's a great question.
Um, I do think that there is a lot of, um, a lot of value for an organization that resells products to try to, uh, pivot some of their business to reoccurring revenue. So we have seen, um, you know, organizations that would traditionally resell products, um, try to kind of dip their toe into that managed component and, and convert some of that revenue into reoccurring revenue. Um, but you know, you said it, there is a big difference in value between reselling a service that somebody else manages and, you know, maybe checking some boxes versus all of the expertise and the bed strength that your, you know, true play MSP has.
So, you know, again, for years, um, there have been vendors that have talking about how the, um, you know, heck, it started with the, the transition to the cloud was gonna put MSPs at a business. Well, hey, MSPs are here. The clouds have been around for a while, they're not going anywhere.
Um, and I think that as technology evolves, as security evolves, that, um, you know, managed service providers will evolve as well and figure out how to make sure that the value they're adding is value that, you know, organizations can't get without having that expertise, uh, from outside of their own organizations. So from where you sit, what does the next 10 years look like? Because you'll hear about how the internal teams are gonna use AI agents and the MSPs are gonna use AI agents and maybe my AI agent, we'll call your AI agent and you and I'll meet for drinks at five, and that'll be that.
So, uh, you know, no matter what my prediction is, it'll be wrong. So I'll, I'll, I'll, I'll start off with that. Um, I'll give you maybe our take on AI first and, and then a bit maybe of, of where I think, um, the industry will go.
So, uh, hunts does not think that AI is going to overtake, um, the job of the really smart security analysts that are doing the threat hunting and the, the, you know, looking for the, the needle in the haystack. So we have no intention of replacing our soc uh, the security operations center with AI agents. Um, we definitely are looking at some interesting use cases of how we can use AI to make those people more efficient, um, to make their jobs easier, to make it easier for them to find that needle in a much bigger haystack.
And I think there's some cool use cases there, but at the end of the day, at least with security, uh, you know, I, I think that when, you know, put yourself in the, in the business owner's shoes on the other end of, of the attack, uh, who is calling up their security partner on the worst day of their professional life and asking for help, if the person on our side is an AI agent talking to that business owner that's trying to figure out like if they can continue to operate this week and make payroll, if, if you're talking to an AI agent, you're looking for a new security partner right away. And I think that there is some truth to that, even when you consider non-security. So just in managed services and, you know, what's they do for small businesses, um, I'm sure that there will be places where you can, um, uh, you know, be more efficient with the use of ai, but it's gonna be hard to replace that human component of the relationship that, um, you know, small and mid-sized organizations just really love.
Mm-hmm. You know, you run sales, so if something goes wrong, it's always your fault, but Yes. Are there, Are there things you wish more customers would do to become savvier about working with MSPs to kind of make this thing a little more successful in a way that maybe, maybe not guaranteed, but not fraught with as much risk either?
Huh, that's a good question. Um, I think that a lot of, uh, businesses, um, you know, probably don't put enough thought into all managed service providers are not created equally. So, you know, again, going back 15 years when, um, security was really just, you know, install antivirus, deploy a firewall, and, uh, you know, you're now secure, um, there are still a lot of managed service providers that are deploying tools, um, promising that they are managing those tools and, you know, kind of, um, uh, using hope as a strategy that nothing goes wrong.
So I do think that it's challenging for your average organization to, um, you know, qualify and, and understand am I working with a managed service provider that actually has a, um, you, you know, a real security practice and, and works with, uh, best in breed vendors and, you know, has an incident response plan for, for that day when everything breaks and, and eventually does go wrong, versus the one that deploys the tool, um, and collects the monthly bill and, and, um, you know, hopes that that will continue to go well for them. So it is a, a challenging, uh, thing for the, the, the end customer to make sure that they're working with a provider that really has a plan put together. Hmm.
Um, as you kind of think about the future of cybersecurity, um, is it gonna get melded more into the management of IT operations or will it always be a distinct category? Because, you know, there's always been a shortage of cybersecurity expertise and it seems like we're trying to deputize everybody, which is a good thing. 'cause now everybody's responsible for security, but does that mean if everybody's responsible, nobody's responsible?
Yeah, it's a fair point. Um, so at Huntress, for example, um, we knew from day one that we didn't want to build solutions for the 1% of companies that have dedicated security personnel. So our target market has always been the other 90% of, or 99% of businesses that do not have dedicated security staff who you could literally give them some of the really expensive and fancy endpoint security tools and they just wouldn't know what to do with them.
Or if they deployed them, they wouldn't know how to manage them. So I think the, the place where, you know, it's kind of changing is that organizations are starting to admit and realize that just by buying a tool and checking the box that you have it on a cyber, um, cyber insurance policy is not enough. And if you don't have the resources to manage those of house, which most organizations do not have and will not have that, you have to have somebody doing that on your behalf.
And whether that's a vendor like us, um, you know, somebody else that is offering, um, you know, the, the management of somebody else's technology, um, or you outsource it to some other organization, it, it just isn't enough to deploy tools anymore. And I think, as you mentioned earlier, the, the threats and the, the security landscape is getting more attention to the media, um, especially when it, you know, ties to the AI buzz, um, that just makes, uh, you know, the business owners more, uh, in the loop of, of how big these risks and challenges are. How do I evaluate one managed security service provider versus another?
Because a lot of them will say the same thing, and then eventually people get a little frustrated and they're like, well, we'll just pick the lowest cost one. How do I know which one is, um, you know, better in a way that I can make some sort of qualitative assessment? Yeah.
So, um, you know, first off, you mentioned, you know, kind of picking the lowest cost one, I can almost guarantee you that picking the lowest cost one is not gonna be the one that you should pick. Um, so that's an easy place to start. Um, now that's not saying go for the one that's most expensive, but, um, you know, the same question could be asked about MSPs or, or any sized organizations that are looking at a vendor like interest that's gonna be, um, a security partner.
And, you know, there are so many vendors out there and so many MSPs out there that will recycle the same messaging and, and tell the same stories. My favorite thing to do when we enter one of these conversations is, um, you know, tell them to ask their peers. So, uh, go in the community, ask your peers, ask your competitors, um, find out, um, you know, what was it like when things did go, um, Brian and, and s**t hits the fan?
And, uh, you know, get, get some stories that are not from the vendor. I mean, listen, if, if you ask me as a vendor, as a VP of sales for a, for like a recommendation on, on a referral, I've got a hundred people that I can refer you to. But if you go in the community and you ask for real life stories about what it's like working with a certain provider, you will get awesome feedback about, you know, the good, the bad, the ugly, and everything in between.
Mm-hmm. Um, one of the things that does come up frequently is, um, what is gonna be the, the role of the MSP going forward, how much of it will be managed as a service, particularly in security, because there is a thought process that says, look, I'm never gonna have enough people to manage this myself. Never gonna do this properly.
So maybe this is not core expertise and it's not differentiated value. So maybe the whole thing should just be run as a service. Maybe, um, you know, I'll go back to that transition to the cloud example I gave earlier.
Um, I mean, heck, how many years has it been since we've talked about how everything's moving to the cloud? It's gotta be 15, 16, 20, almost. Um, and you know, back then there was this talk of how MSPs that don't embrace the cloud are gonna be gone.
And, you know, now, 20 years later, I think we can agree everyone's embraced the cloud. It's part of most of the solutions that we, um, we interact with. But, uh, you know, most businesses are still here, at least the ones that, that are, uh, you know, providing those services are still here.
So with security, uh, and, and m MSPs, I, I think the things labs absolutely change. Um, you know, I think that budget will start to transition from the endpoint to the identity. Um, that's something that I think we expect to happen a lot over the next few years.
Um, but at the end of the day, there will never be enough security personnel to, um, staff and, and work at these small and mid-sized organizations, you know, the, the 99% of businesses that can't do this themselves. And unless that changes somehow, I, I think that, um, uh, this industry will continue doing quite well. All right.
Last question. You've been around here 10 years now. Congratulations on that point, by the way.
But a lot of security companies have come and gone since then, and every morning we wake up, there seems to be yet another acquisition. So, um, do you think people need to take into appreciation the longevity of a company and say, Hey, there's something to that that adds value? You know, I, I like to think so.
Um, bias since we've, um, you know, now got 10 years under our belts, um, you know, for us, maintaining independence has been one of the most important things from, from day one of, of, of, of, um, you know, getting to know the founders. And, um, that can only happen if you're growing and, um, you know, kind of making sure that you're building a healthy business that the investors will kind of stay out of. Uh, I I would like to think that we know how to build a security business and, and keep our customers and partners safe a lot better than any kind of venture capitalist or private equity firm.
So for us, you know, we've raised hundreds of millions of dollars and, um, it's always been important that that money does not come with, um, somebody telling us how to build our business and keep our customers safe. So, uh, to answer your question, yes, absolutely. The longevity, the, the track record, the growth, um, is important.
And for us, it's been one of those things. It's been a differentiator since we've been able to kind of call the shots and write our own roadmap and, you know, make decisions that aren't always popular with investors, but have, um, helped us build a really healthy and fast growing company. All right, folks, you heard it here, hunters, it's entering its teenage years, so let's stick around and see what happens in the next decade.
Right. Awesome. Andrew, thanks for being on the show.
Appreciate you having me, Mike. Take care. All right.
And back to you guys in the studio.