Ep.225 Inside the Win: From CapEx to OpEx — Turning a Firewall Refresh into a Managed Cybersecurity Win

Subscribe to the Next Level BizTech podcast, so you don’t miss an episode!
Amazon Music | Apple Podcasts | Listen on Spotify | Watch on YouTube

In this episode of Inside the Win, Jason Kaufman sits down with Senior Field Solutions Engineer Joshua “Haas” Hazelhorst to unpack a real-world cybersecurity win. Learn how engineering expertise and creative partner playbooks turned a stalled, capital-intensive firewall refresh into a fully managed, 100% Opex service — delivering stronger security, predictable monthly revenue, and a delighted customer. We break down vendor deal-registration pitfalls, SD‑WAN vs. next‑gen firewall tradeoffs, financing challenges, and how to position partners as trusted advisors.

What you’ll get from this episode:

  • Practical tactics to convert transactional hardware deals into recurring managed services
  • How to navigate vendor registrations and partner politics without losing the deal
  • Real examples of financing options and operational considerations for small customers

Who this episode is for:
Technology Advisors, MSPs, solutions architects, and cybersecurity leaders who want to increase MRR, reduce sales friction, and deliver real risk reduction for customers.

Transcript is auto-generated.

Welcome to Inside the Win. We’ll break down real world wins, showing you exactly how strategic partnership with our experts empowers you to tackle your most ambitious opportunities with confidence. Let’s jump in.

Alright. Thank you everybody for joining us for another Inside the Win. My name is Jason Kaufman, Principal Solutions Architect. And with me today, I have senior field solutions engineer Joshua Haselhorst, also known as Has.

Many different movie names, nicknames, whatever you wanna call them. I’m sure he’ll accept it. But Haselhorst one of the greater personalities on this team, and I wanted to bring him on as one of our cybersecurity experts. Little did you know about Haselhorst, he also has some cybersecurity certifications and one of our experts.

And today, Haselhorst, I’d love to ask you, is there a deal that you would like to discuss and give some insights into this win so partners can relate to it and think of this when they’re talking to their customers? So Haselhorst, field is yours, sir.

Yeah, yeah. And I probably have hundreds of cybersecurity use cases, but normally the ones that I get involved in can get potentially really, really hairy because there’s a lot of moving pieces on a lot of moving parts. But in this particular one, and the reason I wanna talk about this particular one is because it really accentuates the Telarus power, the Telarus engineers ecosystem of how much pull we actually have with not only just suppliers, but the actual underlying OEMs. And when we talk about underlying OEMs, what a lot of people don’t understand is there’s two different distribution models in tech.

Distribution model one is what I call parts departments.

I already know what I wanna buy, Here’s the SKUs I wanna buy.

And this is like the CDW Insight SHI model.

Reseller VAR Integrator kind of world is where that reseller goes and buys the parts and the pieces, the hardware and and software, whatever services, from the OEM. But OEMs don’t sell directly to customers anymore. They don’t ship out of their own warehouses. They’re shipping all their products, pieces, all their SKUs to distributors like Tech Data, Ingram Micro, Comstore, Avnet, Sennix, Western NRG, whatever.

And then want somebody else to take on the risk.

Just want to sell the The goal in traditional DSD is hopefully there’s service add ons, hopefully there’s professional services, hopefully there’s installation stuff like that.

But in a lot of cases it’s client owned, client managed. I know what I want, I want to buy this SKU, just get it to me.

But here’s the problem.

In traditional DSD, say I’m a VAR reseller and one, I have to be certified and authorized to resell that specific product or that specific OEM.

So once I hear or get wind of a deal, the first thing that reseller does is registers a deal with the underlying OEM. I’ll give you an example. Maybe I’m a Cisco Gold D VAR. A Gold D VAR means the highest level Cisco certification and engineering that that VAR has. There are a lot of hoops that that VAR has to go to, to get to that gold level status. But a gold level VAR, let’s just say gets forty two percent off list.

Beautiful, right? So I go look at retail, it’s twenty thousand dollars I get forty two percent off this.

So now I have margin that now I can add to and resell to the customer. But if I register that project with Cisco, and I’m just using Cisco as an example, this is with every hardware software vendor. I register with, I no longer get forty two percent off, now I get fifty six percent off. So now I buy through DSD at fifty six percent off, every other VAR on the planet is now locked out.

Since they’re gold VARs, they can get forty two percent off list, but now I get fifty six percent. So I win all the time. So we have a lot of these, a lot of our partners and agents come in, hey, customer wants to buy blank, blank, blank. And the first question is, is this already registered with a VAR?

Because if it is, sometimes we can’t even get price. Some OEMs will allow price parity. Some OEMs will allow what they call dual registration. But the majority of the larger household brand OEMs, registration is locked to whoever registered it first.

So there’s a dirty little trick of those little resellers. Say in this case, we’re gonna talk about this firewall project, but okay, I have a firewall project. Here’s the existing OEM I’m using, and now I need to upgrade. What those resellers will do is they’ll go figure out based on the capacity of that specific firewall vendor, okay, now I’m gonna go get you registered through Cisco and Palo Alto and Checkpoint and WatchGuard and Sophos.

They’re blind register it with every next gen firewall manufacturer on the planet.

The customer changes his mind, you know what, I don’t want SonicWall anymore, now I want Palo.

Sweet, I got you locked in. You gotta buy Paolo from me because nobody else can compete, right? So it’s a dirty little trick.

Well, this instance, this particular customer had older gen, Gen six, next gen SonicWall firewalls.

The partner brought me to the conversation because the customer wanted to do, I now have business critical applications that require one hundred percent application uptime. Failover and failback methodology is no longer a fit.

So I went in and I had conversations with him and taught him what SD WAN platforms do, what appliance based SD WAN platforms do, cloud based, on prem next gen firewalls. What can do what? What can Checkpoint do? What can SonicWall do?

What can Paolo do? What can Cisco do? We determined that if you’re an on prem and you want on prem firewalls in pairs that now you need managed or co managed, the newer gen firewalls can do true SD WAN. They can do forward error correction, they can do dynamic pass selection.

The biggest difference between those platforms and like a OTT or an appliance based SD WAN, like a BigLeaf, like a VeloCloud, like a Juniper, is I create application flow rules based on application family types, which can include hundreds and hundreds of applications. And in next gen firewall, in order to configure SD WAN properly for application rerouting real time, I have to go into my configuration tool and configure individual applications of how I need them to perform and behave. That’s the biggest difference between a next gen firewall SD WAN and you’ll hear from marketing guys, oh, next gen firewalls don’t do true SD WAN.

Okay, yes they do. It’s just a harder configuration, takes a little bit more time, right? So I’m teaching this guy what this stuff does. We kind of come to find out and determine that there’s a couple of things.

This was a SonicWall house. You can either upgrade your existing SonicWall to Gen seven or Gen eight.

We can do a rip and replace. If we’re gonna do a rip and replace, now we can go look at checkpoints and Palos and Ciscos and Fortinets and competitive landscape. But the customer really determined, I’m of used to the ecosystem, the My SonicWall portal. So he said, it possible we can just upgrade SonicWall Gen six to SonicWall Gen eights, but I have no idea how to do the configurations that you just talked about, Haselhorst. So can you bring me a partner that can deliver this in a one hundred percent managed service? He said the other thing I was trying to do prior to bringing me in is was actually trying to buy my own firewalls and my own services.

But every time I would go through a credit review with finance, I wouldn’t get approved.

My company has not given me any CapEx. So I gotta figure out how to do this in a one hundred percent monthly OpEx.

So the original request came in just to refresh and get new hardware. But after digging in, he found out there were some problems and the customer didn’t know how to manage it. So just a hardware refresh wasn’t gonna get them where they needed to be. And then also their credit score wasn’t great enough to go purchase on their own or get a lease for it.

So there’s a lot of problems here that you’re uncovering by the partner bringing you in and now you’re making the partner shine by showing, hey, we’re uncovering all these problems with what the initial scope was looking like. Let’s expand that. So yeah, back to you, Haselhorst. What was the next step on that?

Yeah, so from a technology level, we did our job, right? We determined based on your specific use case, this is the right tech.

And based on the right tech, the next evolution is who is the correct supplier that delivers that tech to you, Mr. Customer, managed the way you needed it managed, managed the way you need logistics and operations and risk needed it managed. But now I got this financial risk component and this whole logistics world and politics world of I need to do this but I don’t have any money.

So how do we do this? We got to wrap this into a monthly service. So the first thing that we did was, okay, let’s get a SonicWall MSP, MSSP in our ecosystem to take this on. Beautiful.

So we went into our ecosystem and I helped them determine which one or ones we should register with. But remember the registration rules, only one player is gonna get deal reg. So who’d you choose?

Give me the mind of who’d you choose?

So I wanna say the suppliers names because there became more political problems. The first supplier we brought to the table said, absolutely, we can absolutely do this, but we’re not going to eat the financial obligation of buying the equipment for the customer and delivering it as a service. The customer needs to buy the equipment. They can buy it through us, but they need to buy the equipment and then we’ll manage it for a monthly subscription.

That’s not really what we ask for. I don’t have any money. I can’t buy the equipment to begin with. So then we had to go back the well, but back to the well wasn’t as simple as let’s just bring in another MSP. Why? Because it’s registered. Registration is locked with the OEM.

Oh no. So what do we do? Well, luckily in our engineering ecosystem, we know a lot of the underlying OEMs and have personal relationships with a lot of these underlying OEMs. So I went to the global director of this particular underlying OEM and said, Hey, I need a favor. I know this isn’t a normal thing, but this can’t get delivered the way the customer needs it delivered. I need you to move that deal registration from this MSP over to this other MSP who already validated and verified that they will buy the equipment, they will eat the financial burden, and then they will deliver for monthly service.

Great, we got it done.

And then at the eleventh hour, that other MSP said, Oh, no, no, no, no, no, no, you misunderstood. We’ll manage it and co manage it for the customer, but they gotta buy the equipment through us, through DSD, we’re not gonna buy it for them.

So back to the same thing. But now what I gotta do?

I gotta- That sounds very similar to the first MSP.

Now I gotta lean back into my OEM contacts and say, okay, I need you just one more time. Because now I have this other MSP that said, we are bigger, we are badder, we have way more money. We’re a global operator, we’re a platinum partner. We do this all day long. We will buy from DSD, then we will sell it to the customer for a monthly subscription. Customer has no CapEx requirements. It’s just gonna be blank on month, right?

Let me ask you, this one sounds familiar. Does that supplier start with an N?

No. Okay. I was trying to get my guessing hat on.

The final supplier actually starts with a Q.

Okay. But that final supplier did the same thing. They came back to me and said, Josh, I can’t get DealReg because this other MSP has DealReg. There’s nothing I can do here.

Can’t even get pricing. So then I had to go back to my OEM relationship, personal relationships and say, I need you to do this again. I need your help on this. Within two days, it got it done.

We’re delivering it as a service. It’s one hundred percent OpEx. This is a deal that is long gone, long and the two, six weeks later, the partner has given up by now.

Enough. This is not a project. The customer don’t have any money. We can’t do anything.

We gotta wait until he gets some budget. No, no, no, no. The Telarus engineering team comes to the rescue, saves the world, saves everybody’s life, delivering as a service. It’s twenty ks in MRR.

Bingo.

But we also make the partner look really good here by finding out of the box ways to get something done that technically is not a technical issue.

It is a sales ban issue, but we still figured out how to get it done because we have technical resources we can call and get it figured out. But the part to really shine here though.

Imagine this, and I feel bad for end users. Imagine the end user goes in Google’s next gen firewalls and sees a bunch of marketing nonsense and then calls his sales rep that he normally buys from. And this happened to that CDWS HI Insight rep. How would he have gotten as deep as we could get to actually get this thing through the knothole for not only the customer but the partner?

So we come in in a parachute and we rescued everybody. Now it took a little time and a little political knob turning, but at the end of the day, the customer got exactly what he wanted. One hundred percent OpEx, one hundred percent managed for him. And now it’s not just, I just replaced a couple of firewalls.

It was I replaced a bunch of not only next gen on prem firewalls, but pairs and big iron firewalls also in my core data centers. And then now I added managed detection and response, endpoint detection and response, security operation center as a service. So we got to not only do what the original request was, but now we got to add on advanced cybersecurity services to help him protect his organization. Because he’s a small two man shop.

There’s no way he can give twenty fourseven, three sixty five eyes on glass on firewall logs, endpoint anomalies. So now we’ve got him this whole ecosystem of something he can actually consume and get him to the level that he needed to be without having to go back to the well and figure out, I guess I don’t get money for another two years and I got holes in my organization. So yeah, dude, the partner looks like a hero, we look like a hero and the customer is I mean, he’s in hog heaven.

Not all deals get that hairy, but when they do, if these partners didn’t have support like you and me and other guys in the Telarus engineering ecosystem, the project’s just dead. It’s just not happening. Call me in three years. You know what I mean?

Yeah, so let’s summarize that up.

We started off with the engagement of just a hardware refresh. Before we’re talking about complexities, if you had to estimate kind of what would that look like from an NRC perspective? A one time CapEx, a one time payment to the partner if all went well, what would that look like?

So I think the original, if we just did the numbers and how much all the hardware and software would cost the customer in a CapEx world, I think we were right around the seventy grand mark. Seventy grand mark.

So seventy grand one time payment.

Before all the add ons we were able to do Yeah.

Yeah. I’m gonna land the plane there. But we we turned that in with some extra white glove support and bringing in the HOS factor. We’re gonna get a t shirt that says that HOS factor just like Haselhorst. So we brought that in that expertise and you turn that into with the partner an MRC of what did it turn into with Quest? I was supposed to say the name but they start with a q and I’m sure it’s West after that.

What did that turn into for an MRC?

We’re right around ten grand.

Ten grand? So a seventy grand MRC with very minute commissionable capabilities to a ten grand MRC expanded into full cybersecurity stack on top of as a service hardware, customers happy they got what they wanted, got what they needed and landed expanded from there just by pulling into Telarus engineering. And the partner is I’m sure they’re pretty happy or they got the thank you card and everything.

So the partner doesn’t even know all of the backend world that it took to this point.

Had the customer had CapEx or had decent credit, right?

Seventy grand in gear, It would have been lucky to buy that at a two, maybe a five percent margin on an NRC, which would have made a partner payment of, I don’t know, one hundred and twenty six for the whole project after six to nine weeks of working on this. Now, ten grand a month, roughly twenty percent MRR, He’s making two grand a month.

Everybody Before we tell people to go find customers with bad credit because that’s the secret sauce to this opportunity, Let’s shift it and say, hey, Telarus engineering, what we do very well with conjunction with a partner is take what was just a hardware purchase of a one time engagement, something hyper transactional and we turn that to an ongoing monthly and now a trusted advisor. And why trusted advisors exist is to take you from what you thought you needed from a transaction to a true partnership. And finding out ways outside the box to get you what you truly need, which is not just the hardware, but a way to procure it and also a way to manage it that you didn’t have beforehand. So make it actually effective to where you’re actually getting the ROI. That’s hyper important here. And it’s a hassle factor.

One hundred percent. And most sellers don’t realize that when we’re talking cybersecurity, we’re not talking blinky lights and parts and pieces and this logo versus that logo. We’re talking about risk. We’re talking about risk management.

We’re talking about logistics and operational risk. But when we’re doing, most of the time this comes in formal framework when I’m doing risk management, but I also have a logistics operational risk and a financial risk. What most sellers don’t consider is that whole financial risk world. Is there a way?

We already took the technical control risk. We’re good there, right? But now I’ve got these other risks that we need to figure out for the customer. And most sellers don’t even get to that point. They either give up, punk, the deal’s dead or whatnot. But a lot of times, with just a little ingenuity and a little creative thought, we can get these things done.

Yep. Thank you, Has. That’s a that’s a great breakdown. You know, think of us for any time you need something to think outside the box, throw it over. We’ll see if we can figure it out.

But, you know, this is a great another episode of Inside the Win with Josh Haselhorst, senior field solution engineer and cybersecurity expert and outside the box thinker and Hasel Genius right in front of you. You heard the steps. You heard the thought process. You know, make sure you leverage us on Telarus engineering. Again, my name is Jason Kaufman, principal solutions architect. Thank you, Josh.

Say thanks to the crowd and everybody listening around the world.

Thanks all. Talk soon. Engage us. Engage us often. We can help.