HITT-Securing the Cloud and the Shared Responsibility Model

In this featured conversation held during Cybersecurity Awareness Month, representatives from ECI and Telarus discuss strategies for securing public cloud environments. The ECI team, including Dan Jones, Justin Wiley, and Dylan Estes, outlines their approach as a Modern Intelligence Service Provider (MISP), emphasizing the integration of MSP, MSSP, and digital services. The discussion covers a structured seven-step framework for cloud readiness, covering everything from initial use-case assessment and network topology to identity management and ongoing vulnerability scanning. Key technical topics include managed XDR, governance, risk, and compliance (GRC) using the Sinomi platform, and the importance of securing the entire stack from end users to the cloud hosting environment. The speakers also highlight the business value of cloud migration and the shifting landscape of decision-making roles within organizations.

Transcript is auto-generated.

Alright. Let’s turn it into today’s featured conversation. We have four great guests joining us to talk about cloud security and the shared responsibility model. Please welcome Chad Muckenfuss, VP of cloud Dan Jones, SVP of North American sales Justin Wiley, director of channel and alliances, and Dylan Estes, director of product management at ECI. Chad, Dan, Justin, Dylan, welcome. I will go ahead and send over to you.

Great. Thank you, Cass. Well, good morning, everyone. I really appreciate you joining us today on the Tuesday call.

As most of you are aware, October is cybersecurity awareness month. And what we wanna do is highlight each week this month, each of our practice areas, mine being cloud specifically. And who better to talk about cloud and security than one of our exclusive suppliers, which is ECI? So today, joining us, as Cash said, we have Dan Jones, Justin Wiley, and Dylan Estes, joining us.

And we wanna talk through the whole process of how to secure the cloud specifically. Obviously, we have the ability to secure local networks. We have the ability to leverage SASE and SD WAN. For that aspect, we have the different endpoint detection and recovery.

We have EDR, MDR, XDR, all of the things. How does this work together? And what we’re gonna discuss today is a step by step process of how ECI looks at a customer’s cloud environment, public cloud specifically, and how you can leverage ECI’s expertise in and around the ability to secure that alongside of the end customer. So let’s go to the next slide, and we’ll kick things off here.

Dan, you wanna…

Who’s…

Sorry. This may be Justin kicking things off. Apologies. Justin’s gonna kick us off here. No problem.

And and one bit of information. So Justin and I, I consider neighbors. We both live in South Jersey together. And the nice thing is we get to see each other fairly regularly.

So without further ado, Justin, why don’t you talk us through who ECI is and your exclusive relationship with Telarus? And then we’ll have Dan do a a bit. And then the important thing is Dylan showing us all the details and specifics.

Absolutely. You hit the nail on the head, and and thanks for the great introduction, Chad. Although I would say now is not a great time to be bragging about being from the Philadelphia region. Sports wise, we’ve been really struggling, but that’s neither here nor there. So just a bit about ECI. Very nice to meet everybody. I’ve been with the firm for fifteen years, and you’ll find, as you work with ECI, that’s pretty common.

A lot of the folks here have been here even longer than I have. You’ll see that across the 900 plus employees that we have. On the right hand side, you’ll see some of our locations. We have about 18 offices globally now headquartered in New York City with a a host of domestic places. And then I would say the the big operating spots, abroad are especially London and Singapore and Hong Kong.

As you can see, we’ve been in business for over thirty years. We have around a thousand clients. Our net promoter score hovers around 50, which is really great. That’s about 15 points above industry standard for, an MSP like ourselves.

And you just see some just, you know, highlights at the bottom there and 60,000 devices monitored across our knock and sock. One thing to call out specifically is of our about a thousand employees that we have, over 800 of them are engineers. So we are very engineering focused. You’ll hear that today when we get to Dylan’s piece about securing the public cloud. You can move to the next slide.

So what is ECI? We are what’s considered a MISP, a modern intelligence service provider, and that is more than just a buzzword. That is understanding the complexities between the MSP, MSSP, and digital services groups, the three pillars of our business. So if you’re looking at this slide, you’ll see cloud and IS in in slide number… I’m sorry, in pillar number two. You’ll see cyber and compliance in pillar number three and data and AI in pillar number four. The first pillar, the managed AI, is where we bring all of those things together.

So in the number two pillar, that’s gonna be all of your MSP services, twenty four seven, three sixty five, monitoring and management of all network systems, supporting end users, securing hardware, software licensing, and managing those assets, pretty much anything that you would expect from an MSP to keep the lights on with some, you know, nuanced things that we can carve out and do a little bit more bespoke. In that second pillar… Go ahead, Chad.

No. I was just gonna say, Justin, one of the key things here… And and we can blitz through this fairly quickly. But one of the key things that we’re seeing over and over again is the blending of the different practice areas specifically here, and you’re… You are recognizing that in the marketplace. The marketplace is driving that out there. The customers are saying, well, cloud impacts… I I I have a security impact and vulnerabilities with cloud, but I need to have cloud.

AI is kind of the overarching umbrella over top of all of this now, which is is affecting CX, my my my voice calls, my contact center.

The network needs to drive all of this, and I need to secure the network and also make sure that the speeds are are correct to handle everything that’s going on. You know, it’s it’s it’s something like this, and I love the the MISP moniker because it’s one of the things that really is is moving the needle forward with a lot of customers. They need somebody that understands all of these aspects. So go ahead. Continue.

Yeah. I mean, well, you just kind of hit the nail on the head and summarized the slide perfectly. So, like, I think the difference between somebody who’s an MSP that does MSSP services and somebody who’s a true MISP is that these are all independent silos that can operate individually or they can be combined together. But what we’re noticing the most in the marketplace is the customers that come to us to say, hey.

I wanna implement some sort of AI solution on on Dylan’s team. And Dylan’s team understanding the complexities from a cybersecurity and compliance perspective, from an enterprise public cloud perspective, from a support perspective of how to really integrate that solution and be end to end rather than just a point solution that are transactional. Right? ECI, we don’t consider our, we we call them clients, not customers because we don’t wanna be transactional.

We wanna be in deep with who we’re working with.

Yeah. Absolutely. And, again, it’s it’s it’s key to be able to to have individual offerings and offer the whole package. Because a lot of times, one of these four is where the entrance point is for that customer, and then the ability to to grow that relationships…

Relationship once that, trust is established there. And, ECI is fantastic about doing that. Just as a side note, as we move to the next slide, in cloud, there’s a 40% growth rate from when the initial contract is signed to typically two to three years later when that contract renews. So 40% growth in cloud services between initial signature and and renewal of the contract.

So that’s a big number to keep in the back of your mind as a partner when you’re selling cloud services.

Cool. Yeah. That’s Now I’m gonna kick it kick it over to Dan for this one. Yeah.

Sure. So so that’s a great point, Chad. And when you when you talk about, you know, doing business with with ECI, you know, first off, we have a a a great amount of respect for Telarus and their partners. We are exclusive.

We feel like, you know, this is the best of the best, and and and so you should expect the same from us. Right? You know, we wanna be diligent in everything that we do. We wanna bring the right solutions to market that are easy to consume and easy to digest.

So when we talk about, you know, cloud and and and high availability and cost controls, you know, we’re we’re always looking for the, you know, types of accounts that wanna be standardized. Right? So we, you know, we approach everything with security and compliance. Right?

High availability is built into our offerings, and cost control is is something that’s super important. We are not a big, hey. We’re gonna just hit you with T and M and all these un…

You know, hidden charges. We’re very transparent. Everything’s upfront, and you are gonna know what, you know, what you spend. So when we look at, different prospects, you know, we’re always trying to uncover where the secret costs.

Right? And and with ECI, there’s no secret. Right? It’s it’s all transparent. It’s really looking at the current providers and making sure we see their t and m bills and things like that to make sure that, you know, we have a true picture of what the true costs are, and and we’re comparing apples to apples.

Right? You know, we are a 24 by seven shop. We have a follow the sun model. We’re English first speaking in all of our locations.

So our help desks are located in New York, Manchester, well as The Philippines. So collaboration across all regions and business units is super important.

You know, you’ll hear Dylan talk about AI. We use AI in our business too. It really helps the collaboration and and and those types of things. So, you know, we consume…

We eat our own dog food here at ECI. Right? So we’re always gonna make sure that, you know, everything that we’re passing out through the clients and through our offerings that we’re using ourselves. And, obviously, compliance alignment is always gonna be super important.

You know, when I think about, you know, cybersecurity month, I I I look at what ECI offers. Right? We have three pillars of business, you know, cloud offering, you know, MSSP, MSP, and then you have our digital and AI. And, you know, security and compliance, know, rises above it all.

Right? So, we wanna make sure that we’re providing that solution, best cost value as well as, you know, best customer experience possible…

Client experience possible.

Yeah. For sure. And you guys drive that. I mean, it it…

There’s a lot of due diligence that goes into many of the meetings upfront, with with our partners and subsequently their customers to get an understanding of what the layout looks like for that customer specifically. There’s been a lot of questions in the chat here and a couple of them just to address quickly. You know, cloud migrations. So customer has aging on prem infrastructure and the ability to come in, assess what those applications are, and what best locations to move them to.

Is it a public cloud transition, or is it a private cloud transition? And and having the resources like you do at ECI to be able to block that out for the customer and be able to help them make that move to the right…

For the right workloads to the right cloud positioning.

Yeah. So that’s a really great point. So it is…

From a sales process for ECI, when we look at, you know, that transition, we call it onboarding. Right? That’s a really, great way for us to modernize a client, right, for a very affordable price. If somebody’s gonna be, you know, onboarding to our managed services, part of the onboarding, we’re gonna wanna take on those projects.

We’re gonna wanna bring the on prem to the cloud. We’re gonna wanna move those workloads. We’re gonna wanna, you know, get their purview set up, their SharePoint, all those, you know, good things and…

At a really affordable price. So I…

We’ll…

We’re we’re taking, you know, at cost, if not less, you know, to to do this type of modernization to get these peep…

Folks onto our managed services. So there’s a real opportunity there to show a lot of value.

Great. Let’s go to the next slide and and keep the conversation rolling here.

So full stack cybersecurity. You came… You as ECI came on board as cybersecurity provider originally a couple years ago.

One of the great stories that I love to highlight is that you have been the fastest growing supplier in Telarus’ history joining the… Joining us here. So that’s something to take note of because that that isn’t just from a specific product set. That’s more from a partner and customer experience level that’s driving that forward. So kudos to you all for that, but, talk us through this and and talk us through your full stack cybersecurity.

Is that Dylan that’s gonna drive that?

I mean, like, from from a cloud perspective, yes. I can definitely talk about, like, managed XDR and and what we do from, like, a cloud security perspective. So managed XDR is our SIM program. That’s where we ingest logs from endpoint edge, which is like the network edge devices, right, like VMs, really all, and then do anomalous detection and and proactive detection on on those different devices.

So that can be identity related. That could be public IP related. That could be ATTCK related. But that gives you a a really good kinda overall coverage of what your landscape is in the cloud and on prem for any sort of, like, security related event and to automatically…

You know, for us to detect and fix it at the source. We also provide, like, reactive insights onto what had happened, write full comprehensive reports based on, like, what had occurred. We provide that to you as part of the service and and to all of our clients.

From a, like, security assessment perspective, we’re doing both, like, project based and ongoing managed services focused on security assessment of cloud, of devices, of on prem devices as well.

So that can include enabling, like, native detection tools, things like iBOS, Azure Policy, Defender for Cloud, some AWS native tooling as well that can really provide policy requirements that, you know, one, are are are default to those cloud tenants, but, two, that we also configure specifically for what we identify as best practice. We go and fix those efforts. We optimize tenants to be secure and best practice for usage… Intended usage such as, like, public facing or private only or network protected, what applications can access, what users can access. So, really, from the security perspective, we’re doing we’re doing all of that above. And then, you know, Dan, maybe you wanna cover GRC?

Yeah. So gov… Governance of risk is a another great offering, you know, that that has been a a real growth driver for us. So besides… You know, it’s one thing, you know, for your cybersecurity, 24 by seven, three sixty five, eyes on glass, hands on keyboard, identify, protect, detect, respond, and recover. That’s… That that… Those are table stakes. Governance and risk is is now taking your environment and taking your your business policies and your and your group policies and putting them in a program that allows you to manage towards different frameworks. Right? Whether it’s NIST or ISO two… Twenty seven zero one.

You know, we also handle all your vulnerabilities, scans, remediation, all your group policies, all your your your business policies, all those things, your your vendor due diligence, all those things are are in a program. We use Sinomi as our as our, platform, and it’s it’s a it’s a great platform. We measure our clients against not only each other, but against, different benchmarks in in in different verticals to make sure they’re they’re always a step ahead of their, competitors. So GRC, again, you know, phenomenal law program and and something that, you know, we’re always looking forward to demoing for our our potential clients.

I think one of the key things to highlight here is that it’s it’s the whole aspect of cybersecurity for the customer. So it’s it’s the end users. It’s all the people that are flipping open their flipping open their laptop in a Starbucks to log on and start utilizing whatever applications are necessary for them to do their job on a daily basis. And it goes all the way through not only from those end users, but it goes all the way through to where are those applications being housed.

Is it Azure? Is it, you know, on prem servers? Is it a private cloud scenario? And securing all of that from beginning to end, and not just securing it from a reactionary standpoint, but also from a proactive standpoint too.

Right, guys?

Yep. Absolutely. And and and for the sellers on the call, you know, one one way to look at cybersecurity with ECI very simply is we have something what’s called the cyber bundle. So it it it provides your, you know, 24 by seven, three sixty five, you know, eyes on glass, hands on keyboard, SIM sock, but it also includes your, you know, phishing and training.

It also includes your dark web monitoring, your asset classification. So it gives you that full cyber program, in in one product set. So, again, one stack. So I think, you know, for the sellers, that’s a a great way to approach the clients with a cyber bundle and and cover all your compliance needs on the, on the XDR side.

Great. Great. So let’s move to the next slide, and we’ll, we’ll continue the conversation in and around the the, cloud readiness aspect of things. And and, Dan and Dylan, I’ll I’ll let you go back and forth with how this works. But it’s it’s a it’s a seven step process, framework that you have here. Can you, can you kinda talk us through this and and what this looks like?

Yeah. Absolutely. So we meet clients where they’re at. Right? Like, usually, when clients are moving to the cloud, they’re doing it with, like, a purpose of a custom application that they wanna deploy to the cloud that maybe they had hosted on prem or maybe it’s newly developed.

Definitely with vibe coding increasing in popularity as much as we’ve seen, there’s a lot more demand for moving to the cloud and and hosting your applications. And, of course, with that comes kind of the nuances of security risk, right, and proper setup of cloud configuration and resources for those those applications. So, really, like, what we do is we look at it from a use case perspective, like, what type of application are you looking to host, what purpose does it serve, what types of users does it serve, And then we go through what we call an enterprise development and deployment checklist and come at it from, like, a security perspective of, okay.

Well, what network topology do you need? Right? We’re probably going to recommend a hub and spoke.

Do we recommend a web application firewall to you? Right? Do you not need one because you have a site to site tunnel setup? Right?

Do you require a network firewall? Are we going to outbound… Like, IP whitelist outbound IP ranges? Right? So that becomes part of it.

Security… Secure access. So from both, like, the internal developers, right, and whoever may access those resources to, you know, deploy their code, right, as part of the development team and or the users who access the application itself.

Is there MFA enabled? Is there role based access control? Are those applications registered in Entr as well, right, so that, ultimately, whenever that application needs to enable that access for end users, that there’s an authentication process with that application to Entra. And then, of course, like, we’re adding in what we consider to be important baseline vulnerability scanning as well on the cloud as well. So, like, we’re typically… We are leveraging Azure policy. We’re leveraging Defender for Cloud. Not only is that gonna look at specific configuration items to make sure that no no public IPs are exposed, that there’s no compromised credentials or anything like that from an access perspective.

But it’s also going to do that on an ongoing basis, right, and provide the client with that type of confidence.

We also see, like, managed devices. Right? So sometimes there’s sensitive data. If a client has sensitive data, then ultimately, there’s likely a need for a managed device so you can set some endpoint controls around what can be done with data through that application and and on that endpoint specifically. Typically, we’re doing that within Microsoft Purview or Microsoft partner. So, of course, like, there’s a common theme, which is the Microsoft service stack to to do a lot of the security.

And then from a development perspective, it gets very nuanced. There’s scanning of dependencies and scanning of code as part of, like, a pipeline process to promote code.

There’s Key Vault and secret preparation. So managing secrets, not exposing secrets, utilizing API calls to access secrets specifically.

Their service selection. Right? So, like, enabling potentially, like, high availability for a pass versus, like, VM.

Is there Doctor required? Is there regulatory requirements? So kind of like… Like I mentioned, we we really treat it as almost like a checklist based on what the requirement is of the client in the application, and then we recommend, you know, basically how to manage and log and and maintain proper observability of your applications once you deploy into the cloud, do it securely, and then manage it on an ongoing basis.

Great. I think one of the key things here is really just because of these seven steps, and cybersecurity can get very very difficult to understand for a lot of the the the laypeople that aren’t in this day in and day out. But, again, what it does is it it not only protects what’s outlined here when you say protect IP and assets. Like, it…

That is this…

The actual hardware, the services, the users, all that kind of stuff. And then, again, you have the ability to, you know, bring in the secure access of it. So that person that I described in the beginning that’s flipping open their flipping open their laptop at Starbucks, and you look at how many Starbucks Wi Fi options there are out of Starbucks, not all of them are real, obviously. So that secure access part of it and and all the the rest of it, it’s those building blocks that really bring the secure network wrapper, for lack of a better term, around their cloud, actual cloud posture or their their cloud offerings to their end users in that organization.

I love the fact that, you know, again, we’re looking at this not only from a reactive protection type of thing, but a but a defensive posture too. And you said that in in in, you know, the the seventh option there, the seventh layer is you’re defending from threats. So this is an active situation where you are protecting the end users, the customer’s data, their their cloud instances all across the board, which is which is great. Are there…

Again, some some, I know we’re gonna get into some some examples here.

Do we wanna move to the next one? Because I think it takes this slide and builds on it here. So why don’t you talk us through this one as well?

Yeah. So I I think this kind of aligns pretty well with the last slide as well. But, really, what this kinda tells the story of is that we start with an initial project or an initial engagement to get the client comfortable with what we can bring to the table. So that usually looks like prediscovery, right, where we’re asking them questions to help qualify what we would consider, like, a scope that involves configuration. Right? Like, we commit to configuration within our project builds.

That’s usually looking like an assessment, a remediation plan.

And then as, you know, as part of the remediation plan and the configuration that we do, right, either, you know, like, if it’s large enough, I guess, separately, right, but usually as part of it, testing of that remediation plan, and then ultimately deploying those changes and and monitoring those changes over time. Our goal, as I’m sure as it is with with most of you got your US partners, is managed services. Right? Like, we want managed service engagements, but, typically, we’re starting off with that single engagement.

We’re building trust. And then applications are an ongoing effort. Right? Like, once you deploy your application to the cloud, there’s refactoring.

There’s this proactive security.

There’s alert notifications and response.

There’s fine tuning. Right? There’s dependency management. So all of that are really considered ongoing efforts. And if the application is going to expand, which typically they do, right, you know, we wanna be there to help from the cloud side. We also provide app dev support as well, but really, like, you know, starting with that initial engagement and getting to managed services is is our goal here.

Great. So let’s go into some examples. Because as Tim Basa likes to say, numbers tell and stories sell. So let’s let’s take a look at the next slide here and go into some great examples of how this all comes together as an actual opportunity.

Yep. And so Go ahead. Yeah. Yeah. So, like, an example right here would be that many clients are starting kind of with that on prem posture, potentially, like, they have, you know, servers on prem.

They have a private data center, but they’re exploring the cloud. We’re constantly, you know, working with them or or define within a project, go to them, and work with them to see what exactly their intended…

Intention is for the cloud. Is there an ROI component? Identifying that ROI component as part of the presales effort.

And ultimately trying to really help them validate why a move to the cloud would make sense.

Then what we’re doing is we’re looking at existing state. We’re looking at gap analysis between existing state and intended state for the cloud.

You know, as the ascension… Assessment mentions, a big part of that is service selection. Right? Like, that can be quite a a black box for clients. So whether or not you utilize a VM or a PaaS or Kubernetes, right, and containers and what the cost benefit is of of each of those decisions.

Different database services when really, like, within the native cloud, there’s so many different options, right, to meet many different requirements. So, like, we’re helping with that kind of service mapping to use case discussion.

And then identifying, you know, like, like, where there is impact. Right? So, really, a lot of, like, this language actually below this is mostly landing zone language. When you’re coming to the cloud, what’s really important is setting it up properly right from the start. Right? So what that looks like is typically multiple accounts or multiple subscriptions to have proper segregation into, like, dev test versus prod, different groupings of accounts, right, so that you can have cost parameters and cost insights and controls around that or identity based controls around that different organization.

As we mentioned, potentially, like network controls that are default and set up so that, you know, users can access resources. Like, developers can access resources privately from networks via, like, site to site tunnels, right, or Azure Bastion as an… As a potential example, peered VNets, peered VPCs, right, so that, like, traffic is centralized. You’re not duplicating services. So you’re also taking, like, an approach that we do, which is, like, maximizing the benefit for the client by minimizing cost. Right? So not, like, recreating different services instead just leveraging them within, a hub VPC and having all traffic flow through there and really, you know, configuring those proper routing policies.

So, you know, all of this kind of goes into what are you trying to do from an application perspective, what are your goals, and then taking our knowledge of what cloud services is in each tenant and identifying what we think is the best path and and best practice to a well fund…

One… Well founded architecture as well. I I think it goes hand in hand, Dylan, and thank you. That… That’s a a great detailed explanation of how you you helped this company specifically.

But I think it goes hand in hand with with what we as Telarus are are talking about this year, which is outcome based selling. Like, what is the business outcome that that customers are looking for in their in their cloud posture, in their in their changes, whether it be from on prem to private public cloud or whether it be in securing their cloud, what outcomes are they looking for, and no longer specific, targeted tool sets because they’re so so drastic, a change in who is buying from the customer’s perspective. Have you seen this where it’s it’s now a group of people typically that’s buying as opposed to just dealing with an IT guy or CIO or a CFO.

It’s a whole group of people that are involved in these outcomes and changes that are overall business affecting. Are you seeing that in the marketplace now as you’re as you’re growing as you’re growing and moving through the market around the world?

Yeah. 100%. And I think, you know, to what I mentioned earlier, vibe coding is really kinda contributing to that. Right?

The fact that, like, more people are developers than ever or want to contribute to development life cycles more than ever, so they have a set. Right? Like, they want to be a part of the conversation. They wanna understand more about, like, the the expanded details of how you ultimately manage a application once you need to deploy it, right, and have it running on infrastructure.

So, yes, 1100%. It used to just be an IT guy who would traverse and kind of give those requirements to us that were coming from business teams, or maybe they had someone, like, doing product, like, as a a single point of contact internally. We still see that, but a lot more than ever, we’re kind of seeing finance, marketing executives, right, participating and and wanting to, you know, be a part of this conversation and and cloud migration discussion.

Yeah. I think that’s great. We’re gonna jump to the last slide of your presentation because we’re up against…

And the next…

What? Skip one more. Yeah. There we go. So we can go over contact information here.

And I do wanna let, everyone know that we are going to share the ECI slide deck, when we send out the follow-up email. So, we’re coordinating that on the Telarus side. So you will have access to a couple of the slides that we didn’t get to today because of time, but, you guys wanna talk about where you’re located around the world and and how to get in touch with you.

Yeah. Absolutely. So I am the… I am at the disposal of anybody on this call being the director of channel. So you can reach me at [email protected]. Also, throw my cell phone in the chat.

This way, if anybody feels more comfortable texting, you can text me.

Chad can attest to the fact that I’m very connected and very ready to roll. If you need anything, let me know. You want marketing materials? You want slides from this deck? You wanna register a deal? You want access to the smart guys like Dylan and Dan? I’m happy to help.

Yeah. Well, we appreciate, again, the relationship immensely with ECI.

We thank you, Dan, Dylan, and Justin, for for joining us today and going through how to secure a customer’s cloud presence and be able to talk them through the whole process and really establish a trust factor as you, as you help customers really understand what what securing a cloud is about.