Subscribe to the Next Level BizTech podcast, so you don’t miss an episode!
Amazon Music | Apple Podcasts | Listen on Spotify | Watch on YouTube
In this Cybersecurity Edition of Inside the Win, VP of Cybersecurity Sumera Riaz sits down with senior engineer Josh Hazelhorst to break down how a simple circuit renewal at seven locations grew into a $17K MRR deal—complete with dual disparate circuits, a Fortinet NextGen SD-WAN refresh, outsourced firewall management, and a clear runway to XDR/SIEM/SOAR.
You’ll learn:
• How to partner with an existing MSP instead of competing with them
• Why “everything is connected to everything” opens cross-sell opportunities
• How to move a client from MPLS to SD-WAN without a costly rip-and-replace
• How platform consolidation (fewer devices, fewer portals) lowers spend and lifts the burden off thin IT teams
• How to position security as certainty—not just another product
Watch to see how solving the network problem the right way set up a SOC and XDR conversation for the future.
Video Transcript
Transcript is auto-generated.
Welcome to Inside the Win. We’ll break down real world wins, showing you exactly how strategic partnership with our experts empowers you to tackle your most ambitious opportunities with confidence. Let’s jump in.
Hi, everyone. I’m Sumera Riaz, vice president of cybersecurity at Telarus. This is the cybersecurity edition of Inside the Win. With me today is Josh Haselhorst, one of our senior engineers.
Josh, welcome to the show. So this deal started as a circuit purchase, and it finished with a client running fewer devices, handing their firewall management to a to a, third party and, an SD WAN refresh.
So give us the shape of this one.
Yeah. And this is I I mean, we’re kind of famous in engineer in in Telarus engineering with building these, what I call, wrap accounts or or upsells or or cross selling or whatever. But in our world, everything is connected to everything. Right?
So RTA came to us and said, hey. This specific customer is coming up on contract renewal for some for their their circuits at seven locations. Originally, they bought circuits through a voice company that no longer sells circuits, and this was probably five years ago. So the circuit’s pretty expensive.
Right? So we were just gonna replace the circuits. Well, it turns out that the customer we talked to was not actually the customer. The customer we talked to was the guy that ran the MSP that supported the customer.
And, just circuits. Right? So we just start digging into conversation. Right? Is is what kind of bandwidth do you need?
Do you need DIA? Do you need, you know, fiber? Do you need broadband? Do you need, you know, a secondary for resiliency or failover?
You know, doing the common conversation of what kind of circuits, what applications are gonna flow over these circuits, how do these circuits need to behave. That starts going into the I don’t want failover and failback conversation. I want 100% uptime. I wanna be able to use both circuits simultaneously.
I wanna be able to split tunnel applications, yada yada yada. Right? Well, this is screaming SD WAN. So, of course, my first my first question is what kind of routers do you have?
What kind of firewalls do you have? Last thing we wanna do is force a customer into a rip and replace and spend more money. If they already have a platform that can do things like link aggregation and load balancing, then we don’t have to sell them something else. Right?
But in this case, they had older firewalls that only did fail over and fail back.
So the next conversation was, okay. We need to talk about those firewalls. Who’s your firewall guy for this for this customer? And the MSP said, well, it’s me.
Yeah. I said, well well, great. So you’re the MSP, and it’s a one man shop. So it’s a one man shop MSP managing several clients.
This just happens to be one. Right? Yep. So he was also the security guy. So he runs everything for this organization.
And we determined that his existing firewalls will not do what he wants for the circuits. So now we gotta do circuits, dual disparate circuits from two different suppliers. We gotta terminate them into a SD WAN next gen firewall. And since it’s one guy Yep.
This needs to be done as a service. Right? He needs somebody that’s got 247365 eyes on glass that are doing real advanced threat hunting. Right?
They can actually mitigate real time anomalies. One guy, whether it’s, you know, the customer or the customer’s team or an outsourced MSP, one guy doesn’t have the capacity to stare at firewall logs and hunt for anomalies. I don’t care if it’s in one location or 2,700 locations. One guy cannot do this.
This takes a team of people. Right?
100%. So you’ve made some very powerful points there. Let me pull out a couple of threads so we can kinda dive into those. First one that stood out to me was there was already an MSP at play in this deal. And the partner didn’t shy away turn away, but they still ventured to help this client right size and right tech. Tell us about that original situation, with a circuit purchase, finding out there’s already an MSP at play. How did you get how did you and the partner enter this deal without stepping on any toes?
Yeah. A great point. Again, we work with MSPs and VARs and integrators all the time that come into the Telarus ecosystem just for this. Sometimes they get over their skis, technically.
Sometimes they’re not certified in that specific platform that the customer requires. Sometimes it’s just too big for them. They might have the chops, but they don’t have the manpower operationally. Right?
In this case, it was the same conversation. The original conversation was a little bit of a conflict. Right? It’s no.
I’m the MSP. This is my customer. Just give me the circuits. Okay. We’ll do that.
But our TA softly talking to the MSP came to an agreement and understanding of, yes, you’re the MSP supporting this client and your client base.
Yep.
But you don’t have 14 people in a sock to to hunt for anomalies. So why don’t we just partner together? So the TA made the MSP a partner of the TA. So now we’re on one team.
That is so powerful. And it serves the end client better because the client is familiar with that MSP already.
Yeah. The client don’t have to make a change. He loves his existing MSP, but now he’s got the power of the Telarus engineering, Telarus portfolio behind him.
Anybody can buy tool sets. I mean, you see it every day in cyber sec. People just buy marketing. They buy things.
They buy conflicting tech, overlapping tech, all these stuff. But now he’s got coaching and guidance for him for all of his customers. Yes. And he’s gonna get paid.
The customer’s gonna pay for his MSP services, but he’s also gonna get paid for everything that we bring into the onto the table.
That is so powerful. Now tell us about the visibility factor. He was a one man show or a thin IT team, and he was able to kinda create that extension of his bench by bringing us in.
Yeah. A 100%. And and today’s model before engaging us, the way he manages his customers are trouble calls. Somebody has a problem.
They pick up the phone. They call him. Internet’s down. Pick up the phone. Call him.
Can’t connect to my printer. Pick up the phone. Call him. Can you imagine one guy if he has ten, twelve clients like this?
Oh my god. Your entire job is putting out fires.
Exactly. And I was reading the stats. It’s 5,000 alerts a day right now on average that a midsized company is seeing coming in. Yeah. And they are operating with less than seven people in an IT team.
And how do you know what’s really sinister?
How do you know what’s really malicious? How do you know if it’s false positive? Like, you don’t. You have to look into it. But how do I look into it when I’m a couple of people on a team? I like, I don’t have time. I’m putting out fires.
Exactly. Tell us about the client. How big were they? Were they multilocations? What was the scenario that you walked into?
Yeah. And this one, this was a financial company doing financial services, insurance mostly.
Seven locations, no IT staff. Their entire IT staff was this one guy, I got a guy MSP, who happened to be really good at what he does and high certified, very, very knowledgeable, just just strapped for time. You know what I mean?
Yep. 100%.
Yeah. So seven locations. So what we ended up doing was dual circuits at each location from two different carriers terminated into a Fortinet next gen firewall.
The reason we went for that next gen firewall is because of the requirements. The requirements was simplification and elegance. And what I mean by that is I can’t have an Aruba switch and a Ubiquiti access point and a Palo Alto firewall. Why?
Because this guy can’t what we call swivel sharing portals. He can’t have 15 different admin tools. He needs to consolidate those into very, very few. So we talk about family types.
Right? And you can do all in with Meraki family, all in with a Meagan family, all in with a SonicWall family, all in with a Fortinet family, all in with a Ubiquiti family. You know, friends don’t have friends by Ubiquiti, but in certain aspects they fit. Right?
So those were the families.
The customer didn’t care what color the box was, whether it was red, yellow, blue, green, or white. But the MSP, he’s the daily management guy. He’s gotta be able to get in these interfaces. So it wasn’t a Meraki versus a Fortinet versus a conversation.
Right? It was a he’s more familiar with Fortinet than he is with the other platforms. 100%. Yes.
The platforms became irrelevant. It was it was what what was his comfort level in getting into the Fortinet manager to be able to do config changes?
100%. Yeah. So most advisers, when we hear the clients say, hey. We manage our own firewalls. We often treat that as a closed door. What signal tells you that it’s an open one?
For me, it’s a do you have twenty four seven, three sixty five eyes on glass? Do you have data forensics guys? Do you have data analyst guys? Do you have SOC analyst guys?
Do you have guys that can actually get into those logs and figure out if this is malicious, if if it’s severe, if it’s just a false positive, what’s important, what’s not important? If they come back and they say, yeah. We got two dudes doing this. Yeah.
No. I’m sorry. This takes 13 people doing this, not two.
100%.
It it’s not a technical limitation. It is now or or technical risk for for my a countermeasure standpoint. It’s a logistics operations risk. And you and I see this every day. It’s all on I got the smartest guys on staff. I got three of me. That that’s not enough.
No. It’s not. No. It’s not enough. 100%. So they wanted MPLS gone, but they needed private layer two backbone for the business critical applications. How did the backbone serve as, as a service?
And then the OTT gateway design, did it solve for what they were looking for?
It solved everything they were looking for except for a couple of pieces. There’s still a couple missing elements that we’re still going to wrap in.
The beauty is because they went at platform as a service, like in a Fortinet ecosystem
Like they didn’t have XDR. They didn’t have EDR. They don’t have the budget for it right now. Well, guess what?
You don’t need to create a whole new project next quarter. Right? You can already budget for it, and you just go into your Fortinet ecosystem and activate the control. That’s okay.
Have the money to to hire a SOC analyst and build a SOC for twenty four seven visibility. But since they’re in their Fortinet ecosystem, they can activate FortiGuard Labs that’ll do it for you for a monthly fee. So Exactly. It can just grow.
As their requirements grow, they don’t have to go buy, go reRFP things. They already have it. They just have to activate the the the control.
It’s already an approved vendor and approved OEM on their list, and then just land and expand that.
And that’s 100%. Such a great Now from that backbone piece, they still kept their MPLS links. They’re using SD WAN IP sec tunnels for site to site connectivity. In case an MPLS link breaks, I’m still connected.
So what? However, later down the line, those business critical applications are now going to migrate to a cloud service. So I no longer need that MPLS. Just give me a direct connect into Azure, you know, OCP, whatever it happens to be.
That’s awesome. When you proposed this, were there any objections that they made or, any any gotchas that they brought up that, hey. This one, you know, this way might be a little more difficult. This is easier. Like, kind of a path of least resistance. Did you find one?
Yeah. Thousands. Yeah. Thousands of I don’t want to, and here’s why. And the first one was like everybody.
Right? Price. Oh my god. Don’t afford an ecosystem. It cost me more money than my firewall today.
So we kinda have to take a step back, and and if this wasn’t even the MSP conversation, this was the c suite of the organization that MSP supported.
It looks more expensive, but you’re getting rid of your existing routers. You’re getting rid of your existing firewalls and service agreements and contracts. Now we have created simplification and elegance. You can do anything you want. You can properly budget for next evolution of cyber stack.
You can get rid of your MPLS as soon as you you go cloud on on that critical application. Are you sure it’s more money? Absolutely not. It’s way less money. It looks more upfront, but it is not because now I get to decommission all this other stuff.
And it’s an OpEx cost because it’s made of services.
Yep. 100%.
Yep. That is amazing. So fewer devices and fewer portals, lower spend, Is there one that you think move the clients, to actually purchase a solution? And what in your professional opinion, what would you what would you say?
Two things. One, for the executives of the of the client, we didn’t really sell a product. Right? We sold them certainty.
Yes. You don’t have to worry about holes and gaps in your organization. Everything is covered. From the MSP side, it was literally, you guys just made my job easier.
Like, the customer doesn’t have to know that my job is no longer hard or difficult. You guys made it easier by putting in a platform that I can comanage, and now I can go get other clients, and I have the time.
That is awesome. So with advisers listening, so let’s say they have a client today on MPLS with a data center move coming. What would you say is one question they can ask on their next call with their client?
I would think, like, we get it all the time as I have an MSP or I have a guy
Or I’ve already got that as a managed service. Every MSP on the planet has a hole in gap somewhere in their portfolio. Somewhere.
Whether it’s physical security, cameras, access controls, identity access management, they they specialize in their bread and butter. Maybe it’s switch route server storage. Maybe it is cybersecurity. But there’s a hole somewhere, which means I’ve got an MSP. Doesn’t mean the TA is out. It means the TA needs to partner with that MSP to fill those holes in the gaps so the MSP can serve their client even better without having to lift a finger.
Yes. And if you I mean, if there’s a network or a data center or even CX conversations our advisers are having right now, security should be a part of that. Yeah. It security always elevates that conversation, and it helps the client see you know, kinda look at the bigger picture and and see if we’re expanding our attack surface, how are we going to protect this this new Yeah. We’re adding.
100%. They just they need to understand that that we’re here to help. Yes. I know TAs, and we’re out to, you know, make money. Right? Out and make commission. But at the end of the day, our entire job is working for the client and protecting them from themselves in most cases.
Exactly. I mean, we I love you know, what our leadership says is we leave people and companies better than when we found them. Yeah.
And that’s that’s a wonderful Yeah.
100%. So never be afraid of I got a guy or I got an MSP. Great. Find out who that partner is or that MSP.
Partner with them. Figure out where they live and where their swim lanes are and be that augmentation of their practice to their customers. That’s gold. Why?
It’s also a lead source because they’re gonna bring you all of their clients.
Exactly. Josh, thank you so much for your time. The story of this account is not finished yet because there’s a sock and an XDR conversation sitting right in front of them. And it exists, yeah, and it exists because, our our Telarus team, we solve for the network problem the right way.
Had we just said, okay. Let’s get some circuits. It probably would have been a maybe a 2 or $3,000 a month MRR for the partner.
We’re at 17,000 MRR right now, and we probably have another three projects, maybe four more projects coming.
That is so awesome. That is a very good soar powerful story and a great win of cross selling from a network deal right into security and, so much more there to unpack.
When we’re talking to organizations about anything tech, everything is connected to any everything. So if they bring you in on circuits, the circuits connect to a router or a firewall. We need to talk about routers and firewalls. If we’re talking about voice, the voice connects to users and communication platforms.
How are they connecting to the host of the voice platform? How are they securely remotely connecting? Stuff like that because now that starts the ZTNA conversation. My point is everything is connected to everything.
So make sure you’re asking the questions not just on what they came to you for But the why. What is it doing? Why are we doing this? How does it need to behave? How do we secure it?
That $1,000 a month deal will turn into a $10,000 a month deal overnight.
Yes. So such a great perspective on that, and thank you. So four points to walk away is visibility that they did not have before. So troubleshooting, it stops being guesswork. Operational burden lifted off of a thin IT team. Firewalls are now outsourced. Pure devices, pure portals, two vendors collapsed into one collapsed into one platform, and then lower spend with a run for the runway into a security set solution, an XDR SIM SOAR without a rip and a replace.
There you go.
Yes. So that’s that’s awesome, and that’s a powerful story. And, everyone, that’s a wrap. Thank you for joining us today. We’ll see you on the next Inside the Wind.