UK IT Channel News | IT Channel Oxygen
  • News
  • Topics
    • Oxygen 250
    • Vendor
    • Partner
    • Distributor
    • Indepth
    • Sustainability
    • M&A
    • People Moves
    • AI
    • Tech trends
  • About Us
  • Partner with us
  • KOcycle Zone
Members
Must-Know Distributors
Oxygen 250
No Result
View All Result
  • News
  • Topics
    • Oxygen 250
    • Vendor
    • Partner
    • Distributor
    • Indepth
    • Sustainability
    • M&A
    • People Moves
    • AI
    • Tech trends
  • About Us
  • Partner with us
  • KOcycle Zone
No Result
View All Result
UK IT Channel News | IT Channel Oxygen
No Result
View All Result
Home Partner Content

“GenAI is a much more powerful force for good than it is for bad” – experts clash on cybersecurity’s biggest questions

Elastic's Transforming SecOps event sees expert panel do battle on five hot topics

Oxygen staff by Oxygen staff
4 December 2024
in Partner Content, Cybersecurity
“GenAI is a much more powerful force for good than it is for bad” – experts clash on cybersecurity’s biggest questions
Share on LinkedinShare on Twitter

How do channel partners best go about building a cybersecurity practice, who is winning the GenAI cybersecurity race out of the industry or cybercriminals, and what does Putin’s cyber sabre rattling really mean for the channel?

These were among the big cybersecurity questions tackled yesterday by two experts on a panel hosted by IT Channel Oxygen.

The event – entitled Transforming SecOps – was organised by Elastic, an enterprise search vendor that is pushing into a Security Information and Event Management (SIEM) space that has seen huge consolidation in 2024.

It was attended by over 50 representatives from GSIs, consultancies, VARs and MSPs.

At the London shindig, David Goff, Partner Development Manager at Elastic, said:

“Over the last few quarters, we’ve gone top-right in quadrants and have got to number four in SIEM market share. We’re the fastest-growing SIEM provider in the market as well, so everything is set up for quite an exciting time at Elastic.”

Here we bring you highlights from the opening panel session, which saw IT Channel Oxygen put some red-hot cybersecurity questions to Elastic UKI VP, Massimo Merlo, and Kevin Robertson, Founder and COO of Elastic partner Acumen Cyber.

Big question #1

How can resellers and MSPs best go about either starting, or growing, a cybersecurity business – should the buy, build or partner?

“Do it right, or don’t do it at all,” Kevin Robertson, Acumen Cyber

Kevin Robertson, Elastic event
Kevin Robertson, pictured left

Robertson said customers can easily tell which MSPs do cybersecurity badly or just with revenue in mind.

“I’m quite biased, as I run a specialised security business, but I think it’s very difficult to do it right unless it’s your only focus,” he explained.

“That’s not advocating against GSIs or the big MSPs doing it as part of their core business, but you do need specialised skills and to invest a lot of time, effort and money into it.

“There’s been plenty of bad press recently on MSPs, and I think the government is certainly planning on ensuring things like the NIS2 regulations apply to the MSP space.”

“Buy what you can, partner where you need to, and absolutely build where your sweet spot is,” Massimo Merlo, Elastic

Responding to the same question, Elastic’s Merlo advised partners to take a mix-and-match approach.

“When you break it down, it’s actually a combination of all three. If I was introducing a car to the market I wouldn’t develop my own spark plugs. So there are elements you would buy because they’re well understood,” he said.

Big question #2

When it comes to GenAI, who is winning the race – is it the cybersecurity industry, or the cybercriminals?

“GenAI is on balance a much more powerful force for good than it is for bad,” Kevin Robertson, Acumen Cyber

Robertson said that the most sophisticated pieces of malware and ransomware are written by highly skilled individuals, and not AI.

“I don’t think it’s the case that just because GenAI is a thing that all of a sudden there’s going to be this influx of ransomware,” he said.

“I would say the shoe is on the other foot from a defensive point of view, because – as anyone who’s worked in a SOC will know – 90% of your day as a defensive engineer is spent doing stuff that is mundane or repetitive, and that’s where AI is becoming really powerful. It can eliminate the worst parts of your job, and get those bits automated, so you can focus on the more difficult and enjoyable parts.

“The security risks to AI, especially GenAI, are in my view more about accidental misuse or abuse of the actual GenAI LLMs and technologies themselves.”

Big question #3

With Cisco buying Splunk, and LogRhythm and Exabeam merging, just how jumpy are partners in the wake of recent SIEM market consolidation?

“Where’s the innovation; where’s the openness?” Massimo Merlo, Elastic

Elastic branding

Merlo claimed recent SIEM sector M&A has been driven by larger vendors’ desire to “buy revenues”. He questioned what will happen to the innovation within the acquired brands.

“Our innovation has largely been driven by that massive [open source] community,” he added.

“Maybe some of those other products weren’t as open or agile, but at least they had the benefit of having that one-to-one communication. [For partners], now it’s like, ‘whoah!, I’ve lost all that innovation and agility and now I don’t even have a partner manager that cares about me because I’m such a small fish’.

“It’s a golden opportunity for us at Elastic to show our differentiation.”

“Consolidation will lead to an almost like-it-or-lump-it type methodology. There’ll be so little to choose from when the dust settles,” Kevin Robertson, Acumen Cyber

Robertson said recent M&A will mean partners are faced with “three-to-four”, rather than “eight-to-ten”, competitive products in the SIEM space.

“One of the reasons we love Elastic is because it’s rooted in open source,” he added.

“Even now it’s a commercialised organisation, that’s still prevalent. We can still jump onto Slack and talk to hundreds if not thousands of people about issues and problems.

“And it’s not just a SIEM platform – it was rooted in search. It’s actually a platform that stands separately from the others on the market where they are now too much set into one path. And that consolidation only makes it worse.”

Big question #4

All the nationals ran a story last month saying Putin plans to cripple the UK with cyberattacks. Are SMBs at risk when it comes to these nation state attacks?

“It’s the second, third and fourth waves that will see the big impact,” Kevin Robertson, Acumen Cyber

It was a big ‘yes’ to this question from Robertson, at least once the zero days become public exploits.

“That’s when they start to get replayed against all sorts of organisations,” he explained.

“If we look at when the [Russia-Ukraine conflict] started, ransomware attacks globally actually went down a bit, as the focus was entirely on Ukraine and Russia. But six months after that died down, it ratcheted up again. Maybe on the first wave you don’t have to worry [as an SME], but the impact will come as more and more innovative techniques become commonplace.”

“If you were going to attack something, would you go for the big fortress, or take out all the outlying things?,” Massimo Merlo, Elastic

Merlo agreed, saying state-sponsored attackers would in some ways be smarter to target smaller businesses.

“You could cripple a big bank by crippling all its smaller customers. That would arguably be a smarter way of doing it,” he explained.

“So, absolutely, they have cause to be concerned, and in some respects probably [more so than large enterprises] because big organisations can afford the skills and tech to baton down the hatches.”

This article was produced in association with Elastic and is classified as partner content. What is partner content? See more here.

Tags: Elasticfeatured
Previous Post

“Stay tuned” – Hupp exits CDW

Next Post

7 killer quotes that rocked IT distribution in 2024

Related Posts

Richard Eglon, Nebula
Partner Content

Could satellite networks like Starlink be the channel’s next supernova?

6 May 2025
Paul Hamilton, HALO at McLaren Technology Centre 2
Partner Content

‘We’re ambitious, but we don’t want to have 20,000 people’ – HALO CEO explains channel push

1 May 2025
Angus Shaw, Brigantia
M&A

‘Brilliant’ – Brigantia sells up to ‘perfect counterpart’

30 April 2025
Jenny Latimer, Highgate IT Solutions
Careers & Skills

‘So…have I converted you?’ – Highgate reveals all on 4-day week’

30 April 2025
Circular IT giant Foxway eyes global growth with new leadership
Partner Content

Case study: Nailing 0% landfill with Blancco

24 April 2025
Consensus team at KOcycle Braintree HQ
Partner Content

A site visit with Servium

24 April 2025
ITAD Summit 2025
Partner Content

ITAD Summit 2025

24 April 2025
Podcast: Natilik and KOcycle talk sustainable lifecycle services
Partner Content

Podcast: Natilik and KOcycle talk sustainable lifecycle services

24 April 2025
Next Post
7 killer quotes that rocked IT distribution in 2024

7 killer quotes that rocked IT distribution in 2024

Follow Us

IT Channel Oxygen keeps you informed on the UK IT channel and its sustainable transformation. Learn more

  • About
  • Our Team
  • Partner with us
  • Privacy Policy
  • Terms & Conditions
  • News
  • Cookie Policy (UK)

© 2025 IT Channel Oxygen

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
View preferences
{title} {title} {title}
No Result
View All Result
  • Oxygen 250
  • Must-Know Distributors
  • Member area
  • KOcycle Zone
  • Big Interview
  • News
  • Indepth
  • About
  • Partner with us

© 2025 IT Channel Oxygen