<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-GB"
                       href="https://www.itpro.com/uk/feeds/articletype/feature"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from ITPro UK in Feature ]]></title>
                <link>https://www.itpro.com/uk/feature</link>
        <description><![CDATA[ All the latest feature content from the ITPro  UK team ]]></description>
                                    <lastBuildDate>Wed, 16 Sep 2026 22:30:00 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ How Tottenham Hotspur worked with Salesforce to create the ‘world's best experiences’ for fans ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Tottenham Hotspur FC has a huge fanbase, with millions of loyal, passionate followers across the globe. From Europe to Asia, fans tune in every week to cheer on their team at all hours of the day. </p><p>Yet engaging with these fans is a complicated challenge, according to the club’s chief technology and digital officer, Rob Pickering. </p><p>With a treasure trove of data on fans stretching back decades, the club embarked on a sweeping <a href="https://www.itpro.com/strategy/29899/three-reasons-why-digital-transformation-is-essential-for-business-growth">digital transformation</a> project with Salesforce around 18 months ago. </p><p>The aim here, according to Pickering, was to consolidate data sources and deliver a more engaging digital experience for fans. </p><p>“When you look at our fans, [we have] an incredible fanbase that is global, that is very engaged with the club, and it’s a privilege to work with them,” he told assembled press at Dreamforce 2026. </p><p>“We have the world’s best fans, and I want to make sure they have the world’s best experiences. To do that, we needed to make sure we had enough data to be able to serve them what they need, when they need it, and where they need it.”</p><p>A key component of the club’s engagement with fans lies in the Ask Spurs digital assistant, which provides answers to frequently asked questions on topics such as ticketing, stadium navigation, and details on public transport options. </p><p>With thousands of fans using this service, quality data is critical to providing accurate information. It’s the lifeblood that powers the service and provides users with reliable answers to queries.</p><p>Fan data was spread across an array of disparate sources, however, and individual fans themselves often duplicate profiles, which prevented the club from fully capitalizing on this data to provide bespoke experiences. </p><p>Working with Salesforce, Spurs consolidated more than 35 separate data sources to create a centralized source of truth and a “single fan record”. </p><p>“Across those systems, historically, we had a Rob Pickering, we had an R Pickering, we had an RP,” he said. “The work we’ve been doing with Salesforce over the last 18 months has been bringing that data into a single fan record, which allows us to see every interaction that a fan has with the club into one single record,” he explained. </p><p>“That allows us to see that those fans are the same people,” Pickering added. “The same fan that buys a team shirt, and the same fan that comes to a game, and the same fan that attends one of our third-party attractions on site, like F1 Drive.”</p><h2 id="powering-ask-spurs">Powering Ask Spurs</h2><p><a href="https://www.itpro.com/business/business-strategy/salesforce-announces-huge-partner-program-revamp-with-agentforce-360-launch">Agentforce</a>, Salesforce’s flagship agentic AI service, is what underpins the Ask Spurs assistant. With this, the club was able to build a highly flexible application capable of contending with a global fanbase. </p><p>The digital assistant provides answers in 11 languages and operates 24 hours a day, seven days a week. </p><p>“Our fans are global, so it doesn't necessarily suit them to call us at 930am on a Monday or a Tuesday morning,” Pickering said. “We've got Korean fans who want to speak in Korean and be serviced at what will be 3am our time.”</p><p>Notably, Pickering said that Agentforce is enabling the club to create a more intuitive assistant for fans. It’s evolving from being a simple question and answer chatbot to an agentic assistant. </p><p>“We’re moving from question to answer to question to action, and eventually we’ll go to question to buy something,” he said.  </p><p>“So instead of asking us, say, ‘<em>how do I buy a membership?’</em> In a world of agentic commerce with what we've built with Agentforce and with Commerce Cloud, we could say,<em> ‘I would like to buy a men's home team shirt in medium’</em>, and have that transaction just occur naturally as we would ask Google or other ways to do today.”</p><h2 id="pressing-the-advantage">Pressing the advantage</h2><p>Pickering told <em>ITPro </em>that, long-term, the aim is to transform the assistant into a “fan engagement agent” more akin to other AI-powered assistants in the footballing world. </p><p>In mid-2025, the Premier League signed a deal with Microsoft to roll out the “Premier League Companion”, for example. This is a Copilot-powered assistant that allows users to query various stats on players, clubs, and access thousands of articles and videos. </p><p>Pickering appears to envisage a similar setup for Spurs fans around the World. As an example, he said users could one day request information on how many goals an individual player has scored. Thereafter, the agent will provide them with details and even video content showing said goals. </p><p>Features like these are only one potential area the club is exploring, however. The assistant also has applications for staff working on the frontlines on matchdays and during the various events and concerts Tottenham Hotspur Stadium hosts each year. </p><p>Spurs has hundreds of employees, many of whom interact directly with fans and concert goers. Equipping them with the assistant could simplify their roles, provide them with valuable information, and ultimately benefit fans and attendees. </p><p>“We have dozens of staff that work on a match day,” he said, “Not all of them can know everything about every policy of how things work.”</p><p>“So as we expand the usage of this, not just externally to our fans, but internally to our employees, they'll be able to ask questions they might not know an answer to, and have that answer returned to them in the same way that a fan might if they were at home.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/business/digital-transformation/how-tottenham-hotspur-worked-with-salesforce-to-create-the-worlds-best-experiences-for-fans</link>
                                                                            <description>
                            <![CDATA[ The Premier League football club modernized data processes and leaned on Agentforce to engage with fans ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">KqczVxMziSrP86eyMaze9a</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/esPbGR758LuyKAsroqXdZh-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 16 Sep 2026 22:30:00 +0000</pubDate>                                                                                                                                <updated>Thu, 17 Sep 2026 12:57:19 +0000</updated>
                                                                                                                                            <category><![CDATA[Digital Transformation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/esPbGR758LuyKAsroqXdZh-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[View of the South Stand at Tottenham Hotspur Stadium, with fans holding up a TIFO which reads &quot;North LDN Since 1187&quot;.]]></media:description>                                                            <media:text><![CDATA[View of the South Stand at Tottenham Hotspur Stadium, with fans holding up a TIFO which reads &quot;North LDN Since 1187&quot;.]]></media:text>
                                <media:title type="plain"><![CDATA[View of the South Stand at Tottenham Hotspur Stadium, with fans holding up a TIFO which reads &quot;North LDN Since 1187&quot;.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/esPbGR758LuyKAsroqXdZh-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Tottenham Hotspur FC has a huge fanbase, with millions of loyal, passionate followers across the globe. From Europe to Asia, fans tune in every week to cheer on their team at all hours of the day. </p><p>Yet engaging with these fans is a complicated challenge, according to the club’s chief technology and digital officer, Rob Pickering. </p><p>With a treasure trove of data on fans stretching back decades, the club embarked on a sweeping <a href="https://www.itpro.com/strategy/29899/three-reasons-why-digital-transformation-is-essential-for-business-growth">digital transformation</a> project with Salesforce around 18 months ago. </p><p>The aim here, according to Pickering, was to consolidate data sources and deliver a more engaging digital experience for fans. </p><p>“When you look at our fans, [we have] an incredible fanbase that is global, that is very engaged with the club, and it’s a privilege to work with them,” he told assembled press at Dreamforce 2026. </p><p>“We have the world’s best fans, and I want to make sure they have the world’s best experiences. To do that, we needed to make sure we had enough data to be able to serve them what they need, when they need it, and where they need it.”</p><p>A key component of the club’s engagement with fans lies in the Ask Spurs digital assistant, which provides answers to frequently asked questions on topics such as ticketing, stadium navigation, and details on public transport options. </p><p>With thousands of fans using this service, quality data is critical to providing accurate information. It’s the lifeblood that powers the service and provides users with reliable answers to queries.</p><p>Fan data was spread across an array of disparate sources, however, and individual fans themselves often duplicate profiles, which prevented the club from fully capitalizing on this data to provide bespoke experiences. </p><p>Working with Salesforce, Spurs consolidated more than 35 separate data sources to create a centralized source of truth and a “single fan record”. </p><p>“Across those systems, historically, we had a Rob Pickering, we had an R Pickering, we had an RP,” he said. “The work we’ve been doing with Salesforce over the last 18 months has been bringing that data into a single fan record, which allows us to see every interaction that a fan has with the club into one single record,” he explained. </p><p>“That allows us to see that those fans are the same people,” Pickering added. “The same fan that buys a team shirt, and the same fan that comes to a game, and the same fan that attends one of our third-party attractions on site, like F1 Drive.”</p><h2 id="powering-ask-spurs">Powering Ask Spurs</h2><p><a href="https://www.itpro.com/business/business-strategy/salesforce-announces-huge-partner-program-revamp-with-agentforce-360-launch">Agentforce</a>, Salesforce’s flagship agentic AI service, is what underpins the Ask Spurs assistant. With this, the club was able to build a highly flexible application capable of contending with a global fanbase. </p><p>The digital assistant provides answers in 11 languages and operates 24 hours a day, seven days a week. </p><p>“Our fans are global, so it doesn't necessarily suit them to call us at 930am on a Monday or a Tuesday morning,” Pickering said. “We've got Korean fans who want to speak in Korean and be serviced at what will be 3am our time.”</p><p>Notably, Pickering said that Agentforce is enabling the club to create a more intuitive assistant for fans. It’s evolving from being a simple question and answer chatbot to an agentic assistant. </p><p>“We’re moving from question to answer to question to action, and eventually we’ll go to question to buy something,” he said.  </p><p>“So instead of asking us, say, ‘<em>how do I buy a membership?’</em> In a world of agentic commerce with what we've built with Agentforce and with Commerce Cloud, we could say,<em> ‘I would like to buy a men's home team shirt in medium’</em>, and have that transaction just occur naturally as we would ask Google or other ways to do today.”</p><h2 id="pressing-the-advantage">Pressing the advantage</h2><p>Pickering told <em>ITPro </em>that, long-term, the aim is to transform the assistant into a “fan engagement agent” more akin to other AI-powered assistants in the footballing world. </p><p>In mid-2025, the Premier League signed a deal with Microsoft to roll out the “Premier League Companion”, for example. This is a Copilot-powered assistant that allows users to query various stats on players, clubs, and access thousands of articles and videos. </p><p>Pickering appears to envisage a similar setup for Spurs fans around the World. As an example, he said users could one day request information on how many goals an individual player has scored. Thereafter, the agent will provide them with details and even video content showing said goals. </p><p>Features like these are only one potential area the club is exploring, however. The assistant also has applications for staff working on the frontlines on matchdays and during the various events and concerts Tottenham Hotspur Stadium hosts each year. </p><p>Spurs has hundreds of employees, many of whom interact directly with fans and concert goers. Equipping them with the assistant could simplify their roles, provide them with valuable information, and ultimately benefit fans and attendees. </p><p>“We have dozens of staff that work on a match day,” he said, “Not all of them can know everything about every policy of how things work.”</p><p>“So as we expand the usage of this, not just externally to our fans, but internally to our employees, they'll be able to ask questions they might not know an answer to, and have that answer returned to them in the same way that a fan might if they were at home.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Slicing through the static: why data quality is the channel’s ultimate competitive advantage ]]></title>
                                                                                                <dc:content><![CDATA[ <p>AI-enhanced tools are rapidly being utilized at the cutting edge of modern IT operations. Tasks such as overseeing network complexity at scale and defending against sophisticated cyberattacks are increasingly being entrusted to AIOps platforms and AI-driven security tools, respectively. </p><p>As a result, the repeated use of these platforms has granted channel partners faster access to large yields of data.</p><p>Nevertheless, as Managed Service Providers (MSPs) strive to scale their AIOps and AI-driven security practices for customers, a hard truth is emerging: more data doesn’t necessarily translate to better outcomes. In fact, AI platforms are only ever as effective and reliable as the data they ingest and analyze. Managing sampled, siloed, and fragmented network telemetry across multi-vendor, multi-tenant environments severely limits the effectiveness of partners' managed services, instead amplifying noise and inflating observability costs. This kind of data makes for a brittle blade, undercutting the AI integration designed to improve operational efficiency and strengthen security.</p><p>For channel partners, the priority must shift from data quantity to data quality. The competitive advantage of AIOps is not found in the sheer accumulation of data, but in the ability to finely cut away the noise to achieve high-signal, low-noise telemetry ready to benefit the systems it feeds. Partners who understand this shift are best positioned to help their customers capitalize on AI's true capabilities.</p><h2 id="the-strain-of-fragmented-telemetry">The strain of fragmented telemetry</h2><p>In the era of static, on-premises infrastructure, tracking data was rather straightforward. Applications changed slowly, and a high volume of server logs generally equated to better control over the digital ecosystem. But modern, cloud-based environments have changed this dynamic. Legacy tools now face a data burden they were never designed to process effectively. Despite this radical shift, many service providers still cling to outdated ingestion habits, attempting to collect everything without a clear filtering strategy.</p><p>Rather than creating a unified view of system performance, this approach often results in telemetry being fragmented across multiple disconnected tools, leaving critical insights isolated and difficult to correlate.</p><p>This operational stubbornness can prove expensive. Allowing unrefined, chaotic data to flood telemetry pipelines results in bloated tool investments that actively bury critical performance signals. For MSPs, relying on siloed and sampled data feeds is tantamount to operating blindly. When visibility is fractured, minor glitches go unnoticed until they trigger massive infrastructure failures, disrupting the client's cloud environment and undermining their trust in the provider.</p><p>Furthermore, disconnected monitoring point solutions create a compounding operational problem: an endless, unmanageable barrage of noise. When every tool fires alerts independently, distinguishing a critical systemic failure from routine background noise becomes extremely challenging.</p><p>Without a unified telemetry strategy, IT teams waste valuable time correlating alerts across multiple platforms instead of resolving the underlying issue. This chronic information overload can exhaust frontline technicians, destroying engineering productivity and stalling active threat detection.</p><p>The ensuing organizational toll is heavy. Over time, operators become dangerously dependent on a small group of experts for emergency incident response. These seasoned firefighters become the first and last point of call for late-night rescues and system support. This constant state of reactive crisis management accelerates burnout among top technical talent.</p><p>More importantly, it creates an operational trap in which a partner’s best minds are permanently sidelined, forced to manually prop up broken telemetry systems instead of driving innovation and service improvement. When teams are trapped in this cycle of reactive firefighting, the efficiency and growth promised by advanced AIOps platforms remain out of reach.</p><h2 id="tempering-true-ai-ready-data">Tempering true ‘AI-ready’ data</h2><p>Rather than adopting a patchwork of new tools to manage an ever-expanding data burden, the ultimate solution lies in ensuring telemetry is inherently fit for purpose. A channel partner’s true competitive edge rests on their ability and capacity to deliver solutions that can curate high-signal, low-noise data streams that enable immediate, informed action. </p><p>Telemetry is only truly "AI-ready” when it meets a specific, measurable standard. It must be comprehensive, accurate, contextually enriched, and available in real time. Meeting this baseline eliminates the critical operational blind spots caused by data sampling, fragmented toolsets, and inconsistent collection methods across client networks.</p><p>Maintaining real-time observability is therefore an operational necessity. Without it, customers cannot fully realize the value of investments in network automation and performance optimization. With it, their service assurance improves, threat detection becomes more effective, and operational blind spots are significantly reduced.</p><p>Achieving high-fidelity telemetry requires continuous, packet-level visibility. This provides AI-driven systems with the granular and contextual information needed to establish reliable baselines of normal network behavior, identify anomalies, and help IT teams address issues before they affect performance or disrupt operations.</p><p>AI-ready data must also be contextually enriched and correlated across domains. Raw telemetry can indicate that an event has occurred, but context explains what happened, where it happened, and why it matters. Application-aware insights transform telemetry into actionable intelligence, enabling IT teams to identify root causes faster and prioritize remediation. By delivering this richer context, channel partners convert raw network data into meaningful operational insight.</p><p>When this foundation is in place, its value extends far beyond network performance. AI-ready telemetry becomes the engine behind next-generation security capabilities, creating new opportunities for MSPs to deliver higher-value services and generate more consistent revenue opportunities.</p><h2 id="unsheathing-new-revenue-streams-in-next-gen-threat-detection">Unsheathing new revenue streams in next-gen threat detection</h2><p>The need for AI-ready telemetry becomes even more apparent in cybersecurity. As next-generation cyber threats evolve to evade traditional defenses, AI-driven detection platforms demand complete, accurate, and context-rich telemetry. When security models ingest fragmented telemetry, threats slip through unnoticed, leaving organizations unable to identify malicious activity before it disrupts operations.</p><p>For channel partners, addressing this challenge creates a significant opportunity. By delivering comprehensive, contextual, and actionable network-derived intelligence, partners can develop higher-value threat detection and response services, helping customers identify and respond to malicious activity earlier.</p><p>High-quality telemetry can also reduce false positives, helping MSPs scale their security operations, support more customers, and use their existing resources more efficiently. As clean, high-quality data helps customers demonstrate stronger operational control and support compliance with strict regulations, it also creates another route for partners to provide valuable, recurring services and keep systems audit-ready.</p><h2 id="striking-while-the-iron-is-hot">Striking while the iron is hot</h2><p>The competitive divide across the IT channel won't simply be defined by which partners adopt the most AI into their offerings. The true advantage will lie with those who provide these AI technologies with the precise data quality they need to perform to the best of their abilities.</p><p>AI systems and their potential are readily apparent and available to everyone. However, partners that continue delivering fragmented, sampled, and siloed telemetry into their clients’ AI systems will drive up infrastructure costs, increase operational noise, and ultimately fall behind in operational efficiency and security effectiveness. Instead, the competitive advantage will likely belong to MSPs with the cleanest, most contextual, and most actionable telemetry.</p><p>By shifting their focus from data quantity to data quality – specifically towards AI-ready data, channel leaders can cut through the operational noise and unlock more of the commercial and operational value promised by AI-driven tools.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/business/data-and-insights/slicing-through-the-static-why-data-quality-is-the-channels-ultimate-competitive-advantage</link>
                                                                            <description>
                            <![CDATA[ There's real risk from fragmented telemetry for channel partners... ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5AEmTHvj88MJAWFxBTnSFa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xXsGLKUKXJNoTuf57DcHAL-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 16 Sep 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data and Insights]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Donogh O’Reilly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Mn4QvzinJTRRJyP7QP2E9Y-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xXsGLKUKXJNoTuf57DcHAL-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Digital generated image of cityscape data.]]></media:description>                                                            <media:text><![CDATA[Digital generated image of cityscape data.]]></media:text>
                                <media:title type="plain"><![CDATA[Digital generated image of cityscape data.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xXsGLKUKXJNoTuf57DcHAL-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>AI-enhanced tools are rapidly being utilized at the cutting edge of modern IT operations. Tasks such as overseeing network complexity at scale and defending against sophisticated cyberattacks are increasingly being entrusted to AIOps platforms and AI-driven security tools, respectively. </p><p>As a result, the repeated use of these platforms has granted channel partners faster access to large yields of data.</p><p>Nevertheless, as Managed Service Providers (MSPs) strive to scale their AIOps and AI-driven security practices for customers, a hard truth is emerging: more data doesn’t necessarily translate to better outcomes. In fact, AI platforms are only ever as effective and reliable as the data they ingest and analyze. Managing sampled, siloed, and fragmented network telemetry across multi-vendor, multi-tenant environments severely limits the effectiveness of partners' managed services, instead amplifying noise and inflating observability costs. This kind of data makes for a brittle blade, undercutting the AI integration designed to improve operational efficiency and strengthen security.</p><p>For channel partners, the priority must shift from data quantity to data quality. The competitive advantage of AIOps is not found in the sheer accumulation of data, but in the ability to finely cut away the noise to achieve high-signal, low-noise telemetry ready to benefit the systems it feeds. Partners who understand this shift are best positioned to help their customers capitalize on AI's true capabilities.</p><h2 id="the-strain-of-fragmented-telemetry">The strain of fragmented telemetry</h2><p>In the era of static, on-premises infrastructure, tracking data was rather straightforward. Applications changed slowly, and a high volume of server logs generally equated to better control over the digital ecosystem. But modern, cloud-based environments have changed this dynamic. Legacy tools now face a data burden they were never designed to process effectively. Despite this radical shift, many service providers still cling to outdated ingestion habits, attempting to collect everything without a clear filtering strategy.</p><p>Rather than creating a unified view of system performance, this approach often results in telemetry being fragmented across multiple disconnected tools, leaving critical insights isolated and difficult to correlate.</p><p>This operational stubbornness can prove expensive. Allowing unrefined, chaotic data to flood telemetry pipelines results in bloated tool investments that actively bury critical performance signals. For MSPs, relying on siloed and sampled data feeds is tantamount to operating blindly. When visibility is fractured, minor glitches go unnoticed until they trigger massive infrastructure failures, disrupting the client's cloud environment and undermining their trust in the provider.</p><p>Furthermore, disconnected monitoring point solutions create a compounding operational problem: an endless, unmanageable barrage of noise. When every tool fires alerts independently, distinguishing a critical systemic failure from routine background noise becomes extremely challenging.</p><p>Without a unified telemetry strategy, IT teams waste valuable time correlating alerts across multiple platforms instead of resolving the underlying issue. This chronic information overload can exhaust frontline technicians, destroying engineering productivity and stalling active threat detection.</p><p>The ensuing organizational toll is heavy. Over time, operators become dangerously dependent on a small group of experts for emergency incident response. These seasoned firefighters become the first and last point of call for late-night rescues and system support. This constant state of reactive crisis management accelerates burnout among top technical talent.</p><p>More importantly, it creates an operational trap in which a partner’s best minds are permanently sidelined, forced to manually prop up broken telemetry systems instead of driving innovation and service improvement. When teams are trapped in this cycle of reactive firefighting, the efficiency and growth promised by advanced AIOps platforms remain out of reach.</p><h2 id="tempering-true-ai-ready-data">Tempering true ‘AI-ready’ data</h2><p>Rather than adopting a patchwork of new tools to manage an ever-expanding data burden, the ultimate solution lies in ensuring telemetry is inherently fit for purpose. A channel partner’s true competitive edge rests on their ability and capacity to deliver solutions that can curate high-signal, low-noise data streams that enable immediate, informed action. </p><p>Telemetry is only truly "AI-ready” when it meets a specific, measurable standard. It must be comprehensive, accurate, contextually enriched, and available in real time. Meeting this baseline eliminates the critical operational blind spots caused by data sampling, fragmented toolsets, and inconsistent collection methods across client networks.</p><p>Maintaining real-time observability is therefore an operational necessity. Without it, customers cannot fully realize the value of investments in network automation and performance optimization. With it, their service assurance improves, threat detection becomes more effective, and operational blind spots are significantly reduced.</p><p>Achieving high-fidelity telemetry requires continuous, packet-level visibility. This provides AI-driven systems with the granular and contextual information needed to establish reliable baselines of normal network behavior, identify anomalies, and help IT teams address issues before they affect performance or disrupt operations.</p><p>AI-ready data must also be contextually enriched and correlated across domains. Raw telemetry can indicate that an event has occurred, but context explains what happened, where it happened, and why it matters. Application-aware insights transform telemetry into actionable intelligence, enabling IT teams to identify root causes faster and prioritize remediation. By delivering this richer context, channel partners convert raw network data into meaningful operational insight.</p><p>When this foundation is in place, its value extends far beyond network performance. AI-ready telemetry becomes the engine behind next-generation security capabilities, creating new opportunities for MSPs to deliver higher-value services and generate more consistent revenue opportunities.</p><h2 id="unsheathing-new-revenue-streams-in-next-gen-threat-detection">Unsheathing new revenue streams in next-gen threat detection</h2><p>The need for AI-ready telemetry becomes even more apparent in cybersecurity. As next-generation cyber threats evolve to evade traditional defenses, AI-driven detection platforms demand complete, accurate, and context-rich telemetry. When security models ingest fragmented telemetry, threats slip through unnoticed, leaving organizations unable to identify malicious activity before it disrupts operations.</p><p>For channel partners, addressing this challenge creates a significant opportunity. By delivering comprehensive, contextual, and actionable network-derived intelligence, partners can develop higher-value threat detection and response services, helping customers identify and respond to malicious activity earlier.</p><p>High-quality telemetry can also reduce false positives, helping MSPs scale their security operations, support more customers, and use their existing resources more efficiently. As clean, high-quality data helps customers demonstrate stronger operational control and support compliance with strict regulations, it also creates another route for partners to provide valuable, recurring services and keep systems audit-ready.</p><h2 id="striking-while-the-iron-is-hot">Striking while the iron is hot</h2><p>The competitive divide across the IT channel won't simply be defined by which partners adopt the most AI into their offerings. The true advantage will lie with those who provide these AI technologies with the precise data quality they need to perform to the best of their abilities.</p><p>AI systems and their potential are readily apparent and available to everyone. However, partners that continue delivering fragmented, sampled, and siloed telemetry into their clients’ AI systems will drive up infrastructure costs, increase operational noise, and ultimately fall behind in operational efficiency and security effectiveness. Instead, the competitive advantage will likely belong to MSPs with the cleanest, most contextual, and most actionable telemetry.</p><p>By shifting their focus from data quantity to data quality – specifically towards AI-ready data, channel leaders can cut through the operational noise and unlock more of the commercial and operational value promised by AI-driven tools.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why IT leaders need to be involved in layoff decision-making to avoid AI washing ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Companies are pouring billions into AI initiatives in pursuit of productivity gains. Yet, for many, the payoff isn’t coming soon enough. As a result, layoff announcements attributed to AI investments are coming thick and fast. </p><p>Earlier this year, Monday.com became the latest major tech company to <a href="https://www.sec.gov/Archives/edgar/data/1845338/000117891326003553/zk2635715.htm"><u>announce</u></a> AI layoffs. The restructuring plan, which will see more than 600 jobs, or 20% of the workforce, culled, has been put down to the need to pivot to “a leaner, more focused operating model” and “AI-driven growth strategy”. </p><p>In a <a href="https://www.linkedin.com/pulse/building-mondaycom-its-next-chapter-eran-zinman-cxx4e/"><u>memo published on LinkedIn</u></a>, Monday.com co-founder and co-CEO Eran Zinman stressed that though the company is “seeing significant value from AI internally, this decision was not made to reduce costs or replace people with AI.”</p><p>The layoff trend is set to continue in the short-term – at least in the short-term. A survey released by <a href="https://info.marsh.com/global-talent-trends/2026/"><u>consulting firm Mercer</u></a> in May found that 99% of 825 C-suite leaders expect they will have to reduce their headcount over the next two years. </p><p>However, according to another survey of 600 HR professionals, <a href="https://careerminds.com/blog/cost-of-ai-layoffs"><u>conducted in February by Careerminds</u></a>, a third (32.9%) of respondents said their company had lost critical skills as a result of layoffs blamed on AI. More than a quarter (28.1%) indicated that the employees who had been spared weren’t equipped with the knowledge required to fill the skills gap created by the layoffs. </p><h2 id="it-leaders-are-often-overlooked">IT leaders are often overlooked</h2><p>The data shows that there’s a disconnect between the reasons behind layoffs and their intended impact. The problem is that decisions “are being made in the wrong rooms,” argues Sonali Fenner, a managing director at technology consultancy Slalom focused on strategy and innovation.</p><p>She says that layoffs are typically a response to board pressure to demonstrate the return on investment (ROI) of AI tools and vendor promises of ROI not materializing quickly enough. This means review processes end up being fragmented and rash decisions are made. </p><p>“Finance triggers the review, HR manages the process, operations signs off the business case, and IT is consulted just long enough to answer a feasibility question before the door closes. When the automation underperforms, as it regularly does at the early stage of enterprise AI maturity, nobody is clearly positioned to own the gap between what was promised and what was delivered,” explains Fenner. </p><p>The people within a company who actually understand the AI tools being invested in and what they can and can’t automate tend only to be “consulted as an afterthought”. </p><h2 id="technical-knowledge-can-inform-layoff-decisions">Technical knowledge can inform layoff decisions </h2><p>It makes sense, then, that IT leaders should be involved in layoff decision-making – they sit closest to where AI is actually deployed. For example, they are the ones whose roles involve tracking the ROI of AI, and they have visibility into whether AI has actually delivered the productivity gains layoffs are being justified by. As Fenner puts it: “IT leaders know the difference between what an automation deck says and what the system actually does at 2 am on a Tuesday.”</p><p>David Fischer, chief revenue officer at Luware, a software firm that builds customer service and compliance tools, echoes this. “IT leaders absolutely need a seat at the table when businesses make workforce decisions linked to AI, but they shouldn’t be making those decisions alone,” he says. </p><p>It’s IT leaders’ bread and butter to have a clear read on what AI can automate, where its limitations lie, and where it can support human workers in their roles, Fischer adds. On the other hand, operational and HR leaders are better placed to understand the implications layoffs can have on people and the wider business.</p><p><a href="https://cdn.sanity.io/files/43ea2a5t/resources-new-3/014b8448a0f35889aa33ad1cd9f8a3a251fb954c.pdf"><u>Research released by Cornerstone</u></a> recently found that when CIOs and chief human resource officers (CHROs) work together on workforce planning, changes happen 13% faster. However, while 94% of 2,000 IT and HR leaders surveyed said that a joint approach was becoming a priority, only 35% admitted that AI-related decisions were being made together. </p><h2 id="be-mindful-of-the-conflict-of-interest">Be mindful of the conflict of interest </h2><p>Despite the need to involve IT leaders in layoff decisions, doing so isn’t without its risks, namely a conflict of interest. </p><p>“IT leaders responsible for delivering an AI programme may be under pressure to demonstrate a return on [AI] investment through efficiency gains,” Fischer points out. They may feel incentivized to overstate AI tools’ capabilities. </p><p>Fenner adds: ”The conflict of interest concern is real. IT leaders who championed AI investment carry an inherent risk of overestimating its readiness to justify the spend.” This can lead to unnecessary job cuts. Plus, a loss of the technical knowledge, critical judgment, and oversight human workers use to manage AI outputs, catch errors, fix biases, and maintain accountability.</p><p>“But excluding them from layoff decision-making creates a greater problem: decisions made with an incomplete picture, with no one technically accountable when that picture turns out to be wrong,” she adds. </p><p>Both Fenner and Fischer agree that the companies that get layoffs right are the ones that bring IT leaders to the decision-making table but aren’t letting them sign off on the layoffs. </p><p>Operational and HR leaders who lean on IT leaders’ knowledge about where, in their business, human expertise remains invaluable can ensure that they’re not AI-washing and using AI as an excuse to reduce headcount. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/technology/artificial-intelligence/why-it-leaders-need-to-be-involved-in-layoff-decision-making-to-avoid-ai-washing</link>
                                                                            <description>
                            <![CDATA[ Those who sit closest to where AI is deployed are often overlooked, despite being better placed to determine what AI can automate and where human expertise remains critical ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">C3p9zoAszhWrpDaDF4qeD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/3zjXnJW6hhZxEEGGntzEDQ-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 16 Sep 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Careers and Training]]></category>
                                                    <category><![CDATA[Leadership]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Rich McEachran) ]]></author>                    <dc:creator><![CDATA[ Rich McEachran ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/RRL5GmJQGuXidQxTVcGXXn-320-70.jpeg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/3zjXnJW6hhZxEEGGntzEDQ-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A businesswoman sat at her desk looking sad, with her head in her hand.]]></media:description>                                                            <media:text><![CDATA[A businesswoman sat at her desk looking sad, with her head in her hand.]]></media:text>
                                <media:title type="plain"><![CDATA[A businesswoman sat at her desk looking sad, with her head in her hand.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/3zjXnJW6hhZxEEGGntzEDQ-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Companies are pouring billions into AI initiatives in pursuit of productivity gains. Yet, for many, the payoff isn’t coming soon enough. As a result, layoff announcements attributed to AI investments are coming thick and fast. </p><p>Earlier this year, Monday.com became the latest major tech company to <a href="https://www.sec.gov/Archives/edgar/data/1845338/000117891326003553/zk2635715.htm"><u>announce</u></a> AI layoffs. The restructuring plan, which will see more than 600 jobs, or 20% of the workforce, culled, has been put down to the need to pivot to “a leaner, more focused operating model” and “AI-driven growth strategy”. </p><p>In a <a href="https://www.linkedin.com/pulse/building-mondaycom-its-next-chapter-eran-zinman-cxx4e/"><u>memo published on LinkedIn</u></a>, Monday.com co-founder and co-CEO Eran Zinman stressed that though the company is “seeing significant value from AI internally, this decision was not made to reduce costs or replace people with AI.”</p><p>The layoff trend is set to continue in the short-term – at least in the short-term. A survey released by <a href="https://info.marsh.com/global-talent-trends/2026/"><u>consulting firm Mercer</u></a> in May found that 99% of 825 C-suite leaders expect they will have to reduce their headcount over the next two years. </p><p>However, according to another survey of 600 HR professionals, <a href="https://careerminds.com/blog/cost-of-ai-layoffs"><u>conducted in February by Careerminds</u></a>, a third (32.9%) of respondents said their company had lost critical skills as a result of layoffs blamed on AI. More than a quarter (28.1%) indicated that the employees who had been spared weren’t equipped with the knowledge required to fill the skills gap created by the layoffs. </p><h2 id="it-leaders-are-often-overlooked">IT leaders are often overlooked</h2><p>The data shows that there’s a disconnect between the reasons behind layoffs and their intended impact. The problem is that decisions “are being made in the wrong rooms,” argues Sonali Fenner, a managing director at technology consultancy Slalom focused on strategy and innovation.</p><p>She says that layoffs are typically a response to board pressure to demonstrate the return on investment (ROI) of AI tools and vendor promises of ROI not materializing quickly enough. This means review processes end up being fragmented and rash decisions are made. </p><p>“Finance triggers the review, HR manages the process, operations signs off the business case, and IT is consulted just long enough to answer a feasibility question before the door closes. When the automation underperforms, as it regularly does at the early stage of enterprise AI maturity, nobody is clearly positioned to own the gap between what was promised and what was delivered,” explains Fenner. </p><p>The people within a company who actually understand the AI tools being invested in and what they can and can’t automate tend only to be “consulted as an afterthought”. </p><h2 id="technical-knowledge-can-inform-layoff-decisions">Technical knowledge can inform layoff decisions </h2><p>It makes sense, then, that IT leaders should be involved in layoff decision-making – they sit closest to where AI is actually deployed. For example, they are the ones whose roles involve tracking the ROI of AI, and they have visibility into whether AI has actually delivered the productivity gains layoffs are being justified by. As Fenner puts it: “IT leaders know the difference between what an automation deck says and what the system actually does at 2 am on a Tuesday.”</p><p>David Fischer, chief revenue officer at Luware, a software firm that builds customer service and compliance tools, echoes this. “IT leaders absolutely need a seat at the table when businesses make workforce decisions linked to AI, but they shouldn’t be making those decisions alone,” he says. </p><p>It’s IT leaders’ bread and butter to have a clear read on what AI can automate, where its limitations lie, and where it can support human workers in their roles, Fischer adds. On the other hand, operational and HR leaders are better placed to understand the implications layoffs can have on people and the wider business.</p><p><a href="https://cdn.sanity.io/files/43ea2a5t/resources-new-3/014b8448a0f35889aa33ad1cd9f8a3a251fb954c.pdf"><u>Research released by Cornerstone</u></a> recently found that when CIOs and chief human resource officers (CHROs) work together on workforce planning, changes happen 13% faster. However, while 94% of 2,000 IT and HR leaders surveyed said that a joint approach was becoming a priority, only 35% admitted that AI-related decisions were being made together. </p><h2 id="be-mindful-of-the-conflict-of-interest">Be mindful of the conflict of interest </h2><p>Despite the need to involve IT leaders in layoff decisions, doing so isn’t without its risks, namely a conflict of interest. </p><p>“IT leaders responsible for delivering an AI programme may be under pressure to demonstrate a return on [AI] investment through efficiency gains,” Fischer points out. They may feel incentivized to overstate AI tools’ capabilities. </p><p>Fenner adds: ”The conflict of interest concern is real. IT leaders who championed AI investment carry an inherent risk of overestimating its readiness to justify the spend.” This can lead to unnecessary job cuts. Plus, a loss of the technical knowledge, critical judgment, and oversight human workers use to manage AI outputs, catch errors, fix biases, and maintain accountability.</p><p>“But excluding them from layoff decision-making creates a greater problem: decisions made with an incomplete picture, with no one technically accountable when that picture turns out to be wrong,” she adds. </p><p>Both Fenner and Fischer agree that the companies that get layoffs right are the ones that bring IT leaders to the decision-making table but aren’t letting them sign off on the layoffs. </p><p>Operational and HR leaders who lean on IT leaders’ knowledge about where, in their business, human expertise remains invaluable can ensure that they’re not AI-washing and using AI as an excuse to reduce headcount. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why enterprise software is becoming harder – not easier – to buy ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Enterprise software has never been especially simple to buy, but the commercial side is becoming harder to untangle. AI features can introduce new consumption charges and vendor-specific pricing metrics, while expanding software suites make it harder to isolate the cost and value of individual capabilities.</p><p>To understand how the buying process is changing, <em>ITPro</em> spoke to Haritha Khandabattu, VP Analyst at Gartner, Mickey North Rizza, Group VP for Enterprise Software at IDC, and Faram Medhora, Principal Analyst at Forrester.</p><p>All three describe a market in which the relationship between licence counts and eventual spend is becoming less predictable. IT leaders now have more to work out before they can judge whether a deal will still make sense once the software is in use.</p><h2 id="the-unit-of-software-is-changing">The unit of software is changing</h2><p>For many seat-based enterprise products, the basic maths was relatively easy to follow: multiplying the number of users by the licence price gave buyers a reasonable estimate of spend across the contract term.</p><p>AI consumption models make that calculation trickier.</p><p>Khandabattu says pricing has shifted towards vendor-specific units such as tokens, credits, work units, and currency multipliers, often layered on top of existing seat or subscription charges; those units rarely translate neatly between suppliers. “One vendor’s token isn’t another’s, credits get repriced, and metrics get renamed mid-contract,” she says.</p><p>Consumption pricing also weakens the traditional relationship between user numbers and software spend, according to Khandabattu. A single AI agent can trigger chains of API calls and other metered activity, with usage varying considerably according to the task.</p><p>“A seat is a budget line; an agent is a behavior pattern,” Medhora says. “If buyers do not model the behavior pattern, they have not modeled the cost.”</p><p>Procurement teams can enter negotiations with little production data on how heavily an AI service will actually be used. Forecasting lifetime spend becomes much harder when they have yet to see that consumption at scale.</p><p>Something as simple as a misconfigured agent could burn through many more tokens than procurement teams were expecting, and stopping agents in the act is difficult. </p><h2 id="it-s-becoming-harder-to-know-what-you-re-actually-buying">It’s becoming harder to know what you’re actually buying</h2><p>Pricing is only part of the problem. AI capabilities are being added to software that businesses already use, and organizations are consolidating more functions into larger software suites. Procurement teams need a clear picture of what a new feature adds before paying for another licence or upgrading an existing one.</p><p>Medhora suggests judging AI add-ons by the business outcome they produce, including whether they measurably improve an existing process or provide something the current software estate cannot. “If the answer is only a better-looking prompt box, it is not a value case; it is a packaging exercise,” he says. </p><p>The same capability may already exist elsewhere in a sprawling software estate.</p><p>North Rizza points to the continued accumulation of tools across organizations, often without a complete view of which products are being used or where their functions overlap. </p><p>IDC’s <a href="https://my.idc.com/getdoc.jsp?containerId=US51833924&pageType=PRINTFRIENDLY"><u>research</u></a> also shows businesses consolidating around larger software suites, which can reduce the number of separate vendors while leaving individual capabilities inside those bundles harder to price and track.</p><p>North Rizza highlights moves from perpetual licences towards subscription bundles and AI capabilities folded into renewals. She also points to the importance of preserving portability and exit rights when software is acquired through a wider services contract.</p><p>Buyers also need to consider how the product might be repackaged or renewed, and what replacing it would involve if the commercial terms change.</p><h2 id="procurement-has-to-adapt-to-uncertainty">Procurement has to adapt to uncertainty</h2><p>Khandabattu recommends setting an internal measure of value before comparing vendors, then translating each supplier's pricing units into it. For example, a token, credit, message, or seat can then be expressed as a cost per support ticket resolved, invoice processed, or another meaningful business outcome.</p><p>Khandabattu distinguishes that internal benchmark from vendor-defined outcome pricing, which she says remains immature and can tie buyers to measures whose value is difficult to establish.</p><p>She also advises buyers to test representative workloads rather than relying on vendor calculators. Running production-like tasks can expose how quickly consumption builds up, including cases where what looks like a single action triggers several separately metered steps. </p><p>Modelling that usage over two or three years gives procurement teams a firmer basis for comparing suppliers. Khandabattu also recommends looking at fully loaded costs, including integration, governance, and human oversight, rather than the metered charge alone.</p><p>North Rizza puts estate rationalisation ahead of another purchase or renewal. IT teams should first identify what is already deployed and where functionality overlaps, a process that can also reveal products that can be retired or replaced.</p><p>IDC also <a href="https://my.idc.com/getdoc.jsp?containerId=EUR154783326&pageType=PRINTFRIENDLY"><u>recommends</u></a> treating AI cost governance as an ongoing responsibility shared across IT, finance, engineering, and FinOps rather than a one-off procurement exercise.</p><p>Contract negotiations need to account for that uncertainty as well. </p><p>Khandabattu recommends defining billing units clearly in the contract and pushing for protections against unilateral changes to pricing metrics, alongside measures such as credit rollover where appropriate. </p><p>North Rizza points to modular licensing, meaningful evaluation periods, portability, and exit rights as ways to reduce exposure if usage or vendor strategy changes after deployment. “Don’t wait for pricing models to settle down – build your forecasting discipline now, because the volatility is the new normal, not a transition phase,” North Rizza says.</p><p>Medhora says procurement teams should put greater weight on metering rights and usage visibility, while modelling different commercial scenarios and preserving leverage if they need to exit.</p><h2 id="keeping-control-after-the-contract-is-signed">Keeping control after the contract is signed</h2><p>The buying process increasingly extends through the life of the contract. </p><p>IT leaders need to see how costs develop in production and whether the promised benefits survive real-world use. They also need enough visibility to identify capabilities that are no longer worth paying for.</p><p>A large discount at signing offers limited protection if usage is opaque or the contract is difficult to unwind; a better deal gives the buyer enough visibility to keep measuring value, with room to change course if costs move beyond the original business case.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/software/why-enterprise-software-is-becoming-harder-not-easier-to-buy</link>
                                                                            <description>
                            <![CDATA[ AI add-ons, consumption pricing, overlapping tools, and complex licensing are making software procurement increasingly difficult. This is forcing IT leaders to rethink how they evaluate value and risk ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dFX5NmAbySbuwehuBKmdqH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/joTCHrxyPvfn3ZLe4VTU6e-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 15 Sep 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Max Slater-Robins ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/joTCHrxyPvfn3ZLe4VTU6e-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Female software engineer working on a desktop computer in an office space while male colleague stands over desk checking work on a tablet.]]></media:description>                                                            <media:text><![CDATA[Female software engineer working on a desktop computer in an office space while male colleague stands over desk checking work on a tablet.]]></media:text>
                                <media:title type="plain"><![CDATA[Female software engineer working on a desktop computer in an office space while male colleague stands over desk checking work on a tablet.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/joTCHrxyPvfn3ZLe4VTU6e-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Enterprise software has never been especially simple to buy, but the commercial side is becoming harder to untangle. AI features can introduce new consumption charges and vendor-specific pricing metrics, while expanding software suites make it harder to isolate the cost and value of individual capabilities.</p><p>To understand how the buying process is changing, <em>ITPro</em> spoke to Haritha Khandabattu, VP Analyst at Gartner, Mickey North Rizza, Group VP for Enterprise Software at IDC, and Faram Medhora, Principal Analyst at Forrester.</p><p>All three describe a market in which the relationship between licence counts and eventual spend is becoming less predictable. IT leaders now have more to work out before they can judge whether a deal will still make sense once the software is in use.</p><h2 id="the-unit-of-software-is-changing">The unit of software is changing</h2><p>For many seat-based enterprise products, the basic maths was relatively easy to follow: multiplying the number of users by the licence price gave buyers a reasonable estimate of spend across the contract term.</p><p>AI consumption models make that calculation trickier.</p><p>Khandabattu says pricing has shifted towards vendor-specific units such as tokens, credits, work units, and currency multipliers, often layered on top of existing seat or subscription charges; those units rarely translate neatly between suppliers. “One vendor’s token isn’t another’s, credits get repriced, and metrics get renamed mid-contract,” she says.</p><p>Consumption pricing also weakens the traditional relationship between user numbers and software spend, according to Khandabattu. A single AI agent can trigger chains of API calls and other metered activity, with usage varying considerably according to the task.</p><p>“A seat is a budget line; an agent is a behavior pattern,” Medhora says. “If buyers do not model the behavior pattern, they have not modeled the cost.”</p><p>Procurement teams can enter negotiations with little production data on how heavily an AI service will actually be used. Forecasting lifetime spend becomes much harder when they have yet to see that consumption at scale.</p><p>Something as simple as a misconfigured agent could burn through many more tokens than procurement teams were expecting, and stopping agents in the act is difficult. </p><h2 id="it-s-becoming-harder-to-know-what-you-re-actually-buying">It’s becoming harder to know what you’re actually buying</h2><p>Pricing is only part of the problem. AI capabilities are being added to software that businesses already use, and organizations are consolidating more functions into larger software suites. Procurement teams need a clear picture of what a new feature adds before paying for another licence or upgrading an existing one.</p><p>Medhora suggests judging AI add-ons by the business outcome they produce, including whether they measurably improve an existing process or provide something the current software estate cannot. “If the answer is only a better-looking prompt box, it is not a value case; it is a packaging exercise,” he says. </p><p>The same capability may already exist elsewhere in a sprawling software estate.</p><p>North Rizza points to the continued accumulation of tools across organizations, often without a complete view of which products are being used or where their functions overlap. </p><p>IDC’s <a href="https://my.idc.com/getdoc.jsp?containerId=US51833924&pageType=PRINTFRIENDLY"><u>research</u></a> also shows businesses consolidating around larger software suites, which can reduce the number of separate vendors while leaving individual capabilities inside those bundles harder to price and track.</p><p>North Rizza highlights moves from perpetual licences towards subscription bundles and AI capabilities folded into renewals. She also points to the importance of preserving portability and exit rights when software is acquired through a wider services contract.</p><p>Buyers also need to consider how the product might be repackaged or renewed, and what replacing it would involve if the commercial terms change.</p><h2 id="procurement-has-to-adapt-to-uncertainty">Procurement has to adapt to uncertainty</h2><p>Khandabattu recommends setting an internal measure of value before comparing vendors, then translating each supplier's pricing units into it. For example, a token, credit, message, or seat can then be expressed as a cost per support ticket resolved, invoice processed, or another meaningful business outcome.</p><p>Khandabattu distinguishes that internal benchmark from vendor-defined outcome pricing, which she says remains immature and can tie buyers to measures whose value is difficult to establish.</p><p>She also advises buyers to test representative workloads rather than relying on vendor calculators. Running production-like tasks can expose how quickly consumption builds up, including cases where what looks like a single action triggers several separately metered steps. </p><p>Modelling that usage over two or three years gives procurement teams a firmer basis for comparing suppliers. Khandabattu also recommends looking at fully loaded costs, including integration, governance, and human oversight, rather than the metered charge alone.</p><p>North Rizza puts estate rationalisation ahead of another purchase or renewal. IT teams should first identify what is already deployed and where functionality overlaps, a process that can also reveal products that can be retired or replaced.</p><p>IDC also <a href="https://my.idc.com/getdoc.jsp?containerId=EUR154783326&pageType=PRINTFRIENDLY"><u>recommends</u></a> treating AI cost governance as an ongoing responsibility shared across IT, finance, engineering, and FinOps rather than a one-off procurement exercise.</p><p>Contract negotiations need to account for that uncertainty as well. </p><p>Khandabattu recommends defining billing units clearly in the contract and pushing for protections against unilateral changes to pricing metrics, alongside measures such as credit rollover where appropriate. </p><p>North Rizza points to modular licensing, meaningful evaluation periods, portability, and exit rights as ways to reduce exposure if usage or vendor strategy changes after deployment. “Don’t wait for pricing models to settle down – build your forecasting discipline now, because the volatility is the new normal, not a transition phase,” North Rizza says.</p><p>Medhora says procurement teams should put greater weight on metering rights and usage visibility, while modelling different commercial scenarios and preserving leverage if they need to exit.</p><h2 id="keeping-control-after-the-contract-is-signed">Keeping control after the contract is signed</h2><p>The buying process increasingly extends through the life of the contract. </p><p>IT leaders need to see how costs develop in production and whether the promised benefits survive real-world use. They also need enough visibility to identify capabilities that are no longer worth paying for.</p><p>A large discount at signing offers limited protection if usage is opaque or the contract is difficult to unwind; a better deal gives the buyer enough visibility to keep measuring value, with room to change course if costs move beyond the original business case.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why AI-scale infrastructure depends on a new era of power delivery for MSPs ]]></title>
                                                                                                <dc:content><![CDATA[ <p>As AI initiatives scale, managed service providers are under pressure to help customers deploy new capabilities quickly while enhancing quality and controlling costs. But behind the scenes, engineers are running into a quiet bottleneck—power delivery at a reasonable cost.</p><p>Modern AI compute is increasingly limited by how quickly and efficiently engineers can deliver power to processors, accelerators and memory. For Managed Service Providers (MSPs), that makes power delivery more than an engineering issue. It becomes a strategic consideration that affects capacity planning, operating costs, cooling requirements and the ability to scale customer environments reliably. The challenge is not having enough watts—it’s getting those watts to the right place, with minimal latency, without excess heat, all while managing operational costs to keep revenue in check. </p><p>MSPs that overcome the AI power problem will be the ones that treat power not as an afterthought, but as a foundational pillar of performance, efficiency and scalability.</p><h2 id="why-power-density-matters-to-msp-service-delivery">Why power density matters to MSP service delivery</h2><p>A decade ago, a 200 W GPU was considered massive. Today, single AI accelerators regularly exceed 600 W, and full server boards can draw 5–10 kW. </p><p>That power needs to be delivered across a variety of distances, to multiple voltage domains, and respond in nanoseconds as workloads shift. Every bit of distance, impedance or delay creates loss, droop<del>,</del> and heat, hindering scalability and delivery service. </p><p>In short: as computing density grows, power density becomes the new productivity limiter.</p><p>This shift has also changed how engineers think about system-level design. Instead of optimizing only compute capability, architects must now consider the electrical and thermal realities that shape what is actually achievable. </p><p>High-performance silicon is only as good as the infrastructure that supports it, and many organizations are discovering that traditional power-delivery networks were never designed for bursty, AI-driven workloads. For customers and MSPs alike, these workloads demand not just more power, but more responsiveness and stability than previous generations ever required.</p><h2 id="leveraging-power-innovation-to-build-customer-trust">Leveraging power innovation to build customer trust</h2><p>One emerging approach to this power delivery challenge is moving voltage regulation closer to—or even beneath—the silicon itself. Integrated voltage regulation (IVR) technologies are designed to deliver cleaner, faster, and more localized power that scales with chip demands. </p><p>For MSPs, these advances can support more predictable performance, better energy efficiency, and infrastructure designs that are easier to scale across customer deployments. Some of the positive outcomes associated with these advanced IVR solutions include:</p><ul><li>Higher current density compared with traditional discrete regulators, enabling denser AI infrastructure and serving modern AI workloads.</li><li>Efficiency improvements by reducing long power-delivery paths and associated transmission losses.</li><li>Low thermal resistance to dissipate power losses in a constrained environment, supporting more reliable performance and reduced cooling requirements.</li></ul><p>These improvements are not incremental gains—they enable entire system architectures that were previously constrained by power delivery. This means a more profitable, effective, and efficient infrastructure that MSPs and customers can trust.</p><h2 id="building-delivery-driven-ai-infrastructure">Building delivery-driven AI infrastructure </h2><p>With IVRs and other localized power-delivery technologies, GPUs, CPUs, and custom AI accelerators can sustain higher operating frequencies under dynamic workloads by reducing impedance and minimizing voltage droop. This translates to:<del> </del><u> </u></p><ul><li>Data centers can deliver more compute per watt and reduce cooling overhead, improving the economics of managed AI services.</li><li>Edge and distributed deployments can operate more efficiently, helping MSPs support AI use cases closer to customer environments.</li><li>Compact, modular designs can simplify scaling and make it easier to standardize AI infrastructure across multiple customer deployments.</li></ul><p>Instead of designing around power constraints, system architects can now design with power as an enabler of AI services.</p><h2 id="looking-ahead">Looking ahead</h2><p>As more businesses and MSPs move towards AI to automate workflows and streamline services, power delivery for scaling AI must evolve too. The next wave of competitive advantage will not come only from smarter models or faster chips; it will also come from power architectures that help providers deliver performance, efficiency and control costs-- at scale. </p><p>For MSPs, the opportunity is clear: now is the time to reassess whether your AI infrastructure strategy can support the performance, efficiency and scalability your customers will expect next. </p><p>Providers that invest early in smarter power-delivery architectures will be better positioned to differentiate their services, protect margins and lead customers confidently into the next phase of AI adoption.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/infrastructure/why-ai-scale-infrastructure-depends-on-a-new-era-of-power-delivery-for-msps</link>
                                                                            <description>
                            <![CDATA[ For modern AI compute, power delivery has become key in MSPs' success. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">r2rLMVtU5AGzV6oj4UhLW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZxGSVvG9QQUkeEaRrxwiW3-1920-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 15 Sep 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Infrastructure]]></category>
                                                    <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Noah Sturcken ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/V7CpNPuPsMt7vembTfYoVd-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/ZxGSVvG9QQUkeEaRrxwiW3-1920-80.png">
                                                            <media:credit><![CDATA[AMD]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[AI Infrastructure for Business Impact: Enabling Agentic Intelligence with Scalable Compute]]></media:description>                                                            <media:text><![CDATA[AI Infrastructure for Business Impact: Enabling Agentic Intelligence with Scalable Compute]]></media:text>
                                <media:title type="plain"><![CDATA[AI Infrastructure for Business Impact: Enabling Agentic Intelligence with Scalable Compute]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZxGSVvG9QQUkeEaRrxwiW3-1920-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>As AI initiatives scale, managed service providers are under pressure to help customers deploy new capabilities quickly while enhancing quality and controlling costs. But behind the scenes, engineers are running into a quiet bottleneck—power delivery at a reasonable cost.</p><p>Modern AI compute is increasingly limited by how quickly and efficiently engineers can deliver power to processors, accelerators and memory. For Managed Service Providers (MSPs), that makes power delivery more than an engineering issue. It becomes a strategic consideration that affects capacity planning, operating costs, cooling requirements and the ability to scale customer environments reliably. The challenge is not having enough watts—it’s getting those watts to the right place, with minimal latency, without excess heat, all while managing operational costs to keep revenue in check. </p><p>MSPs that overcome the AI power problem will be the ones that treat power not as an afterthought, but as a foundational pillar of performance, efficiency and scalability.</p><h2 id="why-power-density-matters-to-msp-service-delivery">Why power density matters to MSP service delivery</h2><p>A decade ago, a 200 W GPU was considered massive. Today, single AI accelerators regularly exceed 600 W, and full server boards can draw 5–10 kW. </p><p>That power needs to be delivered across a variety of distances, to multiple voltage domains, and respond in nanoseconds as workloads shift. Every bit of distance, impedance or delay creates loss, droop<del>,</del> and heat, hindering scalability and delivery service. </p><p>In short: as computing density grows, power density becomes the new productivity limiter.</p><p>This shift has also changed how engineers think about system-level design. Instead of optimizing only compute capability, architects must now consider the electrical and thermal realities that shape what is actually achievable. </p><p>High-performance silicon is only as good as the infrastructure that supports it, and many organizations are discovering that traditional power-delivery networks were never designed for bursty, AI-driven workloads. For customers and MSPs alike, these workloads demand not just more power, but more responsiveness and stability than previous generations ever required.</p><h2 id="leveraging-power-innovation-to-build-customer-trust">Leveraging power innovation to build customer trust</h2><p>One emerging approach to this power delivery challenge is moving voltage regulation closer to—or even beneath—the silicon itself. Integrated voltage regulation (IVR) technologies are designed to deliver cleaner, faster, and more localized power that scales with chip demands. </p><p>For MSPs, these advances can support more predictable performance, better energy efficiency, and infrastructure designs that are easier to scale across customer deployments. Some of the positive outcomes associated with these advanced IVR solutions include:</p><ul><li>Higher current density compared with traditional discrete regulators, enabling denser AI infrastructure and serving modern AI workloads.</li><li>Efficiency improvements by reducing long power-delivery paths and associated transmission losses.</li><li>Low thermal resistance to dissipate power losses in a constrained environment, supporting more reliable performance and reduced cooling requirements.</li></ul><p>These improvements are not incremental gains—they enable entire system architectures that were previously constrained by power delivery. This means a more profitable, effective, and efficient infrastructure that MSPs and customers can trust.</p><h2 id="building-delivery-driven-ai-infrastructure">Building delivery-driven AI infrastructure </h2><p>With IVRs and other localized power-delivery technologies, GPUs, CPUs, and custom AI accelerators can sustain higher operating frequencies under dynamic workloads by reducing impedance and minimizing voltage droop. This translates to:<del> </del><u> </u></p><ul><li>Data centers can deliver more compute per watt and reduce cooling overhead, improving the economics of managed AI services.</li><li>Edge and distributed deployments can operate more efficiently, helping MSPs support AI use cases closer to customer environments.</li><li>Compact, modular designs can simplify scaling and make it easier to standardize AI infrastructure across multiple customer deployments.</li></ul><p>Instead of designing around power constraints, system architects can now design with power as an enabler of AI services.</p><h2 id="looking-ahead">Looking ahead</h2><p>As more businesses and MSPs move towards AI to automate workflows and streamline services, power delivery for scaling AI must evolve too. The next wave of competitive advantage will not come only from smarter models or faster chips; it will also come from power architectures that help providers deliver performance, efficiency and control costs-- at scale. </p><p>For MSPs, the opportunity is clear: now is the time to reassess whether your AI infrastructure strategy can support the performance, efficiency and scalability your customers will expect next. </p><p>Providers that invest early in smarter power-delivery architectures will be better positioned to differentiate their services, protect margins and lead customers confidently into the next phase of AI adoption.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The future of AI depends on stronger partner programs — here’s what vendors need to know ]]></title>
                                                                                                <dc:content><![CDATA[ <p>There is little doubt that the channel is going to play a pivotal role during this next phase of enterprise AI adoption. The shift from experimenting with isolated AI projects to implementing intelligent, autonomous operations means that enterprises will be faced with a new level of sophistication and complexity. </p><p>In many cases, helping them solve the AI puzzle will fall squarely on the shoulders of those companies operating in the channel. Their experience, expertise, and problem-solving will be essential to help enterprises make sense of it all. And in doing so, they can tap into one of the fastest-growing areas of IT today. </p><p>In May 2026, <a href="https://www.gartner.com/en/newsroom/press-releases/2026-05-19-gartner-forecasts-worldwide-ai-spending-to-grow-47-percent-in-2026"><u>Gartner</u></a> predicted that AI spending was set to grow by 47% by the end of 2026 as enterprises expand their use of both the GenAI models embedded in existing software applications and the new AI agents within multiple workflows.</p><p>Indeed, Gartner went further, suggesting that up until relatively recently, AI spending has “primarily been driven by technology companies and hyperscalers” with enterprises “yet to really flex their spending potential”. That, says Gartner, looks set to gain momentum. </p><p>If that is the case, then both the channel and vendors have been put on alert because if they are to benefit from this opportunity, it will need more than just local knowledge and the right solutions. It also needs the right partner program to bring it all together. </p><p>Because if nothing else, the AI era has shone a new spotlight on how channel programs work. And with partners becoming increasingly discerning about their network, vendors will have to seriously reassess what a ‘good’ program looks like.</p><h2 id="consistency-drives-scale">Consistency drives scale</h2><p>An ideal, modern partner program is simple. Partners should not have to navigate complex terminology or inconsistent structures across regions. Regardless of whether they are in London, New York, or Singapore, they should all have the same experience.</p><p>In my experience, the most effective programs are those that are both easy to understand and easy to operate within. End customers are looking to move fast, and, as such, partners cannot afford to waste time cutting through unnecessary friction. Crucially, this will also help vendors in the long run as well, since a program that is easy to use ultimately becomes easier to manage.</p><p>It is important for vendors to remember that partners will often have to implement multiple tools for a single solution, meaning small amounts of friction can scale exponentially on more intricate initiatives. For example, a business looking to implement agentic AI will also need a way to constantly feed the agents with up-to-date data, meaning a partner will likely have to install a comprehensive content management system to guarantee the project’s success.</p><p>But that is just the beginning if organizations are going to achieve a truly ‘agentic enterprise’ — an operating model where humans and agents work together seamlessly. They will also likely need multiple solutions across infrastructure, security, governance, and implementation, all collaborating simultaneously to reach that level.</p><h2 id="a-truly-shared-partnership">A truly shared partnership</h2><p>In that same vein, transparency is key to success. Partners should have a clear view of pipeline, performance, and joint execution at all times, which also allows vendors to know clearly what’s working and what needs to change. After all, the basis for any successful business relationship is trust, meaning nothing should feel hidden or arbitrary. </p><p>Partners also need to consider flexibility. Different partners will have different strengths, meaning a good program allows them to engage in ways that suit them and evolve their role over time.</p><p>Ultimately, this boils down to mutual commitment. The relationship works best when it is a two-way street, with partners and vendors acting as a single team. When it is done right, the former commits resources and provides expertise, while the latter offers support, visibility, and incentives. Technology, systems, training, planning, sales motions, and, most importantly, success should be shared wherever possible.</p><h2 id="the-channel-will-not-wait">The channel will not wait</h2><p>In the same way that AI is only as strong as its supporting foundations, channel partners are only as strong as their network. And as organizations move away from isolated AI experiments to intelligent, governed outcomes at scale, that network now matters more than ever. </p><p>Modern partner programs are simple, transparent, flexible, globally consistent, and focused on long-term customer outcomes, with partners treated as strategic collaborators rather than just another sales channel. </p><p>If a vendor’s program falls flat on one of these elements and ends up being the weak link in the chain, they risk missing out. If Gartner is right about the opportunities coming down the road, then enterprises have not even scratched the surface of their spending potential. It is up to vendors now to ensure their programs can help them ride that wave when the time comes.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/technology/artificial-intelligence/the-future-of-ai-depends-on-stronger-partner-programs-heres-what-vendors-need-to-know</link>
                                                                            <description>
                            <![CDATA[ AI transformation depends on the channel, but outdated partner programs threaten progress ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">67BQzgc89LuJC2ZiPTYZK3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zcTvHaWdg6hPbXrWBrXCzc-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 14 Sep 2026 16:19:44 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nanette Lazina ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/4huFLLbbq9iDL5uP9ESgpD-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zcTvHaWdg6hPbXrWBrXCzc-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[artificial intelligence]]></media:description>                                                            <media:text><![CDATA[artificial intelligence]]></media:text>
                                <media:title type="plain"><![CDATA[artificial intelligence]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zcTvHaWdg6hPbXrWBrXCzc-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>There is little doubt that the channel is going to play a pivotal role during this next phase of enterprise AI adoption. The shift from experimenting with isolated AI projects to implementing intelligent, autonomous operations means that enterprises will be faced with a new level of sophistication and complexity. </p><p>In many cases, helping them solve the AI puzzle will fall squarely on the shoulders of those companies operating in the channel. Their experience, expertise, and problem-solving will be essential to help enterprises make sense of it all. And in doing so, they can tap into one of the fastest-growing areas of IT today. </p><p>In May 2026, <a href="https://www.gartner.com/en/newsroom/press-releases/2026-05-19-gartner-forecasts-worldwide-ai-spending-to-grow-47-percent-in-2026"><u>Gartner</u></a> predicted that AI spending was set to grow by 47% by the end of 2026 as enterprises expand their use of both the GenAI models embedded in existing software applications and the new AI agents within multiple workflows.</p><p>Indeed, Gartner went further, suggesting that up until relatively recently, AI spending has “primarily been driven by technology companies and hyperscalers” with enterprises “yet to really flex their spending potential”. That, says Gartner, looks set to gain momentum. </p><p>If that is the case, then both the channel and vendors have been put on alert because if they are to benefit from this opportunity, it will need more than just local knowledge and the right solutions. It also needs the right partner program to bring it all together. </p><p>Because if nothing else, the AI era has shone a new spotlight on how channel programs work. And with partners becoming increasingly discerning about their network, vendors will have to seriously reassess what a ‘good’ program looks like.</p><h2 id="consistency-drives-scale">Consistency drives scale</h2><p>An ideal, modern partner program is simple. Partners should not have to navigate complex terminology or inconsistent structures across regions. Regardless of whether they are in London, New York, or Singapore, they should all have the same experience.</p><p>In my experience, the most effective programs are those that are both easy to understand and easy to operate within. End customers are looking to move fast, and, as such, partners cannot afford to waste time cutting through unnecessary friction. Crucially, this will also help vendors in the long run as well, since a program that is easy to use ultimately becomes easier to manage.</p><p>It is important for vendors to remember that partners will often have to implement multiple tools for a single solution, meaning small amounts of friction can scale exponentially on more intricate initiatives. For example, a business looking to implement agentic AI will also need a way to constantly feed the agents with up-to-date data, meaning a partner will likely have to install a comprehensive content management system to guarantee the project’s success.</p><p>But that is just the beginning if organizations are going to achieve a truly ‘agentic enterprise’ — an operating model where humans and agents work together seamlessly. They will also likely need multiple solutions across infrastructure, security, governance, and implementation, all collaborating simultaneously to reach that level.</p><h2 id="a-truly-shared-partnership">A truly shared partnership</h2><p>In that same vein, transparency is key to success. Partners should have a clear view of pipeline, performance, and joint execution at all times, which also allows vendors to know clearly what’s working and what needs to change. After all, the basis for any successful business relationship is trust, meaning nothing should feel hidden or arbitrary. </p><p>Partners also need to consider flexibility. Different partners will have different strengths, meaning a good program allows them to engage in ways that suit them and evolve their role over time.</p><p>Ultimately, this boils down to mutual commitment. The relationship works best when it is a two-way street, with partners and vendors acting as a single team. When it is done right, the former commits resources and provides expertise, while the latter offers support, visibility, and incentives. Technology, systems, training, planning, sales motions, and, most importantly, success should be shared wherever possible.</p><h2 id="the-channel-will-not-wait">The channel will not wait</h2><p>In the same way that AI is only as strong as its supporting foundations, channel partners are only as strong as their network. And as organizations move away from isolated AI experiments to intelligent, governed outcomes at scale, that network now matters more than ever. </p><p>Modern partner programs are simple, transparent, flexible, globally consistent, and focused on long-term customer outcomes, with partners treated as strategic collaborators rather than just another sales channel. </p><p>If a vendor’s program falls flat on one of these elements and ends up being the weak link in the chain, they risk missing out. If Gartner is right about the opportunities coming down the road, then enterprises have not even scratched the surface of their spending potential. It is up to vendors now to ensure their programs can help them ride that wave when the time comes.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What to expect at Dreamforce 2026 ]]></title>
                                                                                                <dc:content><![CDATA[ <p>With Dreamforce 2026 starting next week, Salesforce has an opportunity to show why it’s still relevant in an era dominated by agentic AI. The key to that could be an “if you can’t beat them, join them” mindset. </p><p>The company has spent most of 2026 fighting a war of words over the so-called <a href="https://www.itpro.com/software/aws-ceo-matt-garman-amazon-quick-software-as-a-service">death of SaaS</a> thanks to the launch of powerful new agents. </p><p>The beginning of 2026 saw a <a href="https://www.itpro.com/technology/artificial-intelligence/why-anthropic-sent-software-stocks-into-freefall">mass sell-off of stock in software companies</a> following the <a href="https://www.itpro.com/technology/artificial-intelligence/everything-you-need-to-know-about-anthropic-claude-cowork">launch of Claude Cowork</a>. The service offered new agents with sector-specific plugins designed to automate tasks across a range of areas, from legal and sales to marketing and data analytics. </p><p>With investors spooked, Salesforce was caught up in the sell-off, but CEO Marc Benioff shrugged off claims of a pending ‘SaaSpocalypse’ in typical fashion. </p><p>Convincing Dreamforce attendees that it’s still fighting fit could be a challenge nonetheless. </p><h2 id="claudeforce-in-the-spotlight-at-dreamforce-2026">Claudeforce in the spotlight at Dreamforce 2026</h2><p>The key to this, in my opinion, lies in <a href="https://www.itpro.com/business/data-and-insights/were-delivering-a-dynamic-interface-that-thinks-reasons-and-acts-three-things-you-need-to-know-about-claudeforce">Claudeforce</a>, launched in partnership with Anthropic earlier this month. Closer collaborative ties with the company touted as a software killer makes perfect sense for the CRM giant. </p><p>This is a partnership that’s multi-faceted and mutually beneficial. It’s not just about integrating Claude within Salesforce’s portfolio of products but also <em>Salesforce within Claude</em>, with new plugins available for customers. </p><p>With this, it’s obvious that Salesforce is pinning its colors to the mast and betting that closer ties with Anthropic will insulate it from future market shocks. </p><p>Anthropic CEO Dario Amodei is on the guestlist at Dreamforce, so I guarantee Benioff will be keen to show off the company’s fashionable new partner and provide customers with a roadmap on how this relationship will expand. </p><p>The happy family image won’t quite cut it though, and customers need real-world examples to get a gauge of how this will benefit them. Claudeforce is in beta with selected customers, so expect to see a steady stream of use-cases and case studies on how this is developing. </p><h2 id="all-roads-lead-to-slack">All roads lead to Slack</h2><p>Slack has come on leaps and bounds since Salesforce acquired it in 2021. The one-time workplace collaboration platform now forms a <a href="https://www.itpro.com/software/slack-is-now-the-key-to-salesforces-agentic-ai-plans">core component of Salesforce’s agentic AI approach</a>. </p><p>Serving as an ‘<a href="https://www.itpro.com/software/dreamforce-2025-whats-an-agentic-os">agentic OS</a>’, Slack is a central point of contact for agents and customer business data within the broader Salesforce ecosystem. I expect this messaging will be drilled home further with Claudeforce on the scene. </p><p>Salesforce claims Slack will be the “intelligent backbone” of Claudeforce, although exactly what that means in practice is still up for debate. I think it’s safe to assume the platform will still retain its role as an agentic OS, but expect to see Salesforce emphasize its position as <em>the </em>critical intersection between core products and Claude. </p><h2 id="opening-things-up">Opening things up</h2><p>Claudeforce might be the start of the show, but I want to see more detail on Headless 360. This is a new architecture for the CRM platform that essentially opens it up without the need for a traditional browser interface, but hasn’t received much attention since its April launch. </p><p>It’s an interesting proposition from Salesforce, enabling enterprises to link data, business logic, and workflows with third-party agents via APIs, <a href="https://www.itpro.com/technology/artificial-intelligence/what-is-model-context-protocol-mcp">model context protocol (MCP) tools</a>, and command-line interfaces (CLIs).</p><p>This approach tracks with what <a href="https://www.itpro.com/business/business-strategy/salesforce-could-become-the-king-of-enterprise-ai-but-only-if-customers-believe-in-its-potential"><u>we’ve seen from Salesforce in recent years</u></a>, with the company focusing heavily on an open ecosystem approach when it comes to AI model choice. </p><p>I do wonder, however, if the noise surrounding Anthropic will drown things out on the Headless 360 front. Users aren’t limited to Claude, but you can bet they’ll be hearing about it more than other options such as OpenAI. </p><p><em>I will be reporting live from Dreamforce 2026 throughout the event, follow my coverage </em><a href="https://www.itpro.com/tag/salesforce"><u><em>here</em></u></a><em> and subscribe to our newsletter for all the latest from San Francisco.</em></p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/business/business-strategy/what-to-expect-at-dreamforce-2026</link>
                                                                            <description>
                            <![CDATA[ Salesforce will be pinning its hopes on the Claudeforce launch resonating with customers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7aVhRzevj4dEKjSENaRRe</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/aT44bSsiSAhAw5qDhvHJEV-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 11 Sep 2026 13:00:19 +0000</pubDate>                                                                                                                                <updated>Fri, 11 Sep 2026 13:00:32 +0000</updated>
                                                                                                                                            <category><![CDATA[Business Strategy]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/aT44bSsiSAhAw5qDhvHJEV-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Entrance to the 2025 Dreamforce conference at the Moscone Center, San Francisco, with attendees queuing up and pedestrians walking past.]]></media:description>                                                            <media:text><![CDATA[Entrance to the 2025 Dreamforce conference at the Moscone Center, San Francisco, with attendees queuing up and pedestrians walking past.]]></media:text>
                                <media:title type="plain"><![CDATA[Entrance to the 2025 Dreamforce conference at the Moscone Center, San Francisco, with attendees queuing up and pedestrians walking past.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/aT44bSsiSAhAw5qDhvHJEV-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>With Dreamforce 2026 starting next week, Salesforce has an opportunity to show why it’s still relevant in an era dominated by agentic AI. The key to that could be an “if you can’t beat them, join them” mindset. </p><p>The company has spent most of 2026 fighting a war of words over the so-called <a href="https://www.itpro.com/software/aws-ceo-matt-garman-amazon-quick-software-as-a-service">death of SaaS</a> thanks to the launch of powerful new agents. </p><p>The beginning of 2026 saw a <a href="https://www.itpro.com/technology/artificial-intelligence/why-anthropic-sent-software-stocks-into-freefall">mass sell-off of stock in software companies</a> following the <a href="https://www.itpro.com/technology/artificial-intelligence/everything-you-need-to-know-about-anthropic-claude-cowork">launch of Claude Cowork</a>. The service offered new agents with sector-specific plugins designed to automate tasks across a range of areas, from legal and sales to marketing and data analytics. </p><p>With investors spooked, Salesforce was caught up in the sell-off, but CEO Marc Benioff shrugged off claims of a pending ‘SaaSpocalypse’ in typical fashion. </p><p>Convincing Dreamforce attendees that it’s still fighting fit could be a challenge nonetheless. </p><h2 id="claudeforce-in-the-spotlight-at-dreamforce-2026">Claudeforce in the spotlight at Dreamforce 2026</h2><p>The key to this, in my opinion, lies in <a href="https://www.itpro.com/business/data-and-insights/were-delivering-a-dynamic-interface-that-thinks-reasons-and-acts-three-things-you-need-to-know-about-claudeforce">Claudeforce</a>, launched in partnership with Anthropic earlier this month. Closer collaborative ties with the company touted as a software killer makes perfect sense for the CRM giant. </p><p>This is a partnership that’s multi-faceted and mutually beneficial. It’s not just about integrating Claude within Salesforce’s portfolio of products but also <em>Salesforce within Claude</em>, with new plugins available for customers. </p><p>With this, it’s obvious that Salesforce is pinning its colors to the mast and betting that closer ties with Anthropic will insulate it from future market shocks. </p><p>Anthropic CEO Dario Amodei is on the guestlist at Dreamforce, so I guarantee Benioff will be keen to show off the company’s fashionable new partner and provide customers with a roadmap on how this relationship will expand. </p><p>The happy family image won’t quite cut it though, and customers need real-world examples to get a gauge of how this will benefit them. Claudeforce is in beta with selected customers, so expect to see a steady stream of use-cases and case studies on how this is developing. </p><h2 id="all-roads-lead-to-slack">All roads lead to Slack</h2><p>Slack has come on leaps and bounds since Salesforce acquired it in 2021. The one-time workplace collaboration platform now forms a <a href="https://www.itpro.com/software/slack-is-now-the-key-to-salesforces-agentic-ai-plans">core component of Salesforce’s agentic AI approach</a>. </p><p>Serving as an ‘<a href="https://www.itpro.com/software/dreamforce-2025-whats-an-agentic-os">agentic OS</a>’, Slack is a central point of contact for agents and customer business data within the broader Salesforce ecosystem. I expect this messaging will be drilled home further with Claudeforce on the scene. </p><p>Salesforce claims Slack will be the “intelligent backbone” of Claudeforce, although exactly what that means in practice is still up for debate. I think it’s safe to assume the platform will still retain its role as an agentic OS, but expect to see Salesforce emphasize its position as <em>the </em>critical intersection between core products and Claude. </p><h2 id="opening-things-up">Opening things up</h2><p>Claudeforce might be the start of the show, but I want to see more detail on Headless 360. This is a new architecture for the CRM platform that essentially opens it up without the need for a traditional browser interface, but hasn’t received much attention since its April launch. </p><p>It’s an interesting proposition from Salesforce, enabling enterprises to link data, business logic, and workflows with third-party agents via APIs, <a href="https://www.itpro.com/technology/artificial-intelligence/what-is-model-context-protocol-mcp">model context protocol (MCP) tools</a>, and command-line interfaces (CLIs).</p><p>This approach tracks with what <a href="https://www.itpro.com/business/business-strategy/salesforce-could-become-the-king-of-enterprise-ai-but-only-if-customers-believe-in-its-potential"><u>we’ve seen from Salesforce in recent years</u></a>, with the company focusing heavily on an open ecosystem approach when it comes to AI model choice. </p><p>I do wonder, however, if the noise surrounding Anthropic will drown things out on the Headless 360 front. Users aren’t limited to Claude, but you can bet they’ll be hearing about it more than other options such as OpenAI. </p><p><em>I will be reporting live from Dreamforce 2026 throughout the event, follow my coverage </em><a href="https://www.itpro.com/tag/salesforce"><u><em>here</em></u></a><em> and subscribe to our newsletter for all the latest from San Francisco.</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why agentic AI requires a new approach to enterprise software testing ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Until now, enterprise software testing has always focused on a relatively straightforward objective: ensuring applications perform as intended before they reach production. Organizations built processes around predictable release cycles, pre-defined workflows, and systems that behaved largely according to expectation.</p><p>The rise of agentic AI, increasingly capable of making decisions, triggering actions, and interacting with multiple systems with limited human intervention, is changing those assumptions. As enterprises begin embedding AI agents into business-critical operations, particularly complex environments such as SAP, the challenge is moving away from simply validating software releases to establishing confidence in autonomous systems that continuously influence business outcomes.</p><p>This shift is forcing organizations to rethink long-held approaches to quality assurance, governance, and risk management. It is also creating a new test for channel partners helping customers modernize complex enterprise environments while simultaneously accelerating AI adoption.</p><h2 id="software-trust-is-becoming-a-board-level-issue">Software trust is becoming a board-level issue</h2><p>One of the most significant changes is that trust in software quality is rapidly becoming a board-level concern, following a trajectory similar to cybersecurity before it. Twenty years ago, security was largely considered a technology problem. Today, it is firmly established as a business risk discussed regularly in boardrooms. Software quality assurance is undergoing the same transition. </p><p>With the consequences of software failures extending far beyond the IT department, influencing customer experiences, supply chains, financial processes, and regulatory reporting, mistakes can directly impact revenue, reputation, compliance, and customer trust. </p><p>As organizations become more dependent on autonomous systems, executives increasingly need assurance that those systems are operating reliably, transparently, and within clearly defined governance frameworks.</p><h2 id="why-agentic-ai-changes-the-risk-equation">Why agentic AI changes the risk equation</h2><p>Our <a href="https://www.tricentis.com/resources/2026-quality-transformation-report"><u>recent research</u></a> suggests many organizations are still finding their way: while 83% trust agentic AI to make release decisions, only 35% feel fully prepared to govern AI agents and autonomous software workflows at scale. This gap highlights a growing recognition that deploying and governing AI are two very different capabilities, and for channel partners, this creates an opportunity to help customers adapt their quality engineering and governance strategies to the unique risks introduced by agentic AI.</p><p>The emergence of agentic AI also introduces a fundamentally different risk profile. Traditional enterprise applications generally behave in predictable ways: organizations can test known workflows, validate expected outcomes, and deploy updates through structured release processes. Agentic systems operate differently; their outputs vary depending on context, data inputs, and interactions with other systems. They can generate new content, recommend actions, and increasingly execute tasks on behalf of users.</p><p>Within complex enterprise environments, where finance, procurement, supply chain, human resources, and customer operations are deeply interconnected, the implications are significant. Whether organizations rely on SAP, Oracle, Salesforce, Microsoft, or a combination of enterprise platforms, a single AI-driven decision can have downstream consequences across multiple business functions. </p><p>The risk extends beyond application defects - there are also inaccurate recommendations, flawed automated decisions, compliance violations, and operational disruption resulting from autonomous actions to consider.</p><h2 id="why-continuous-quality-becomes-essential">Why continuous quality becomes essential</h2><p>This is one reason why traditional testing models are beginning to show their limitations. Many quality assurance approaches were designed for a world where software changed at a manageable pace, and human decision-making remained central to operational processes. Software delivery, transformed by AI-assisted development, increasingly automated workflows, and growing volumes of software changes, is moving faster than quality processes can keep up. </p><p>As a result, continuous quality engineering is becoming an essential component of successful AI transformation initiatives. Rather than treating testing as a final checkpoint before deployment, continuous quality engineering embeds validation throughout the software delivery lifecycle. It enables organizations to continuously assess risk, monitor system behavior, and verify that critical business processes continue operating as intended even as applications, integrations, and AI models evolve.</p><p>This capability is becoming increasingly important for those operating complex business systems. Modern enterprise environments typically span cloud services, third-party platforms, legacy applications, and, increasingly, AI-enabled capabilities. For organizations running large ERP platforms such as SAP, the challenge is amplified by the number of interconnected business processes that must continue to operate reliably.</p><p>Ensuring reliability across this landscape requires far greater visibility than periodic testing alone can provide. Organizations need the ability to validate not just software functionality, but also the integrity of business processes and the behavior of AI-driven systems over time.</p><h2 id="governance-must-be-built-in-not-bolted-on">Governance must be built in, not bolted on</h2><p>At the same time, governance and compliance considerations are becoming increasingly difficult to separate from discussions about AI adoption. </p><p>Many organizations remain in the early stages of introducing AI-powered capabilities into customer-facing products and internal operations. Yet regulators, customers, and stakeholders are already asking difficult questions about accountability, transparency, and control.</p><p>Particularly for enterprises operating in regulated industries, these concerns are acute - they must be able to demonstrate how AI-driven decisions are monitored, what controls exist when systems make mistakes, and how compliance requirements are maintained as autonomous capabilities expand. </p><p>Effective governance cannot be treated as an afterthought or layered once deployment is complete; it must be integrated into software delivery and operational processes from the outset.</p><h2 id="the-opportunity-for-channel-partners">The opportunity for channel partners</h2><p>These developments create an important opportunity for channel partners. As enterprise modernization enters a new phase shaped by AI adoption, customers increasingly need guidance that extends beyond implementation and migration projects. They are looking for trusted advisors who can help them balance innovation with resilience, speed with control, and automation with accountability.</p><p>Alongside discussions about cloud migration, process transformation, and AI adoption, there must be a greater focus on operational trust, quality engineering, governance, and risk management. Success won’t be about deploying autonomous technologies first, but establishing the confidence, visibility, and governance needed to scale them responsibly.</p><p>As agentic AI becomes more deeply embedded within enterprise operations, software quality can no longer function as a standalone checkpoint. It must become a continuous discipline that enables organizations to innovate rapidly while maintaining the trust that modern businesses depend upon. In the years ahead, that balance between speed and trust may prove to be one of the most important competitive differentiators of all<strong> - </strong>both for enterprises themselves and for the partner organizations that help them achieve it.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/technology/artificial-intelligence/why-agentic-ai-requires-a-new-approach-to-enterprise-software-testing</link>
                                                                            <description>
                            <![CDATA[ Continuous quality is becoming essential as autonomous software transforms enterprise operations ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">NDpNhEcgz8xdSpGKeUZt4k</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9hCna3oJCMzCMCug25PcDE-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 11 Sep 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Andrew Power ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GVaSpGmSYoEPLfRAVPS2FU-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9hCna3oJCMzCMCug25PcDE-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Artificial Intelligence Machine Learning Natural Language Processing Data Technology]]></media:description>                                                            <media:text><![CDATA[Artificial Intelligence Machine Learning Natural Language Processing Data Technology]]></media:text>
                                <media:title type="plain"><![CDATA[Artificial Intelligence Machine Learning Natural Language Processing Data Technology]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9hCna3oJCMzCMCug25PcDE-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Until now, enterprise software testing has always focused on a relatively straightforward objective: ensuring applications perform as intended before they reach production. Organizations built processes around predictable release cycles, pre-defined workflows, and systems that behaved largely according to expectation.</p><p>The rise of agentic AI, increasingly capable of making decisions, triggering actions, and interacting with multiple systems with limited human intervention, is changing those assumptions. As enterprises begin embedding AI agents into business-critical operations, particularly complex environments such as SAP, the challenge is moving away from simply validating software releases to establishing confidence in autonomous systems that continuously influence business outcomes.</p><p>This shift is forcing organizations to rethink long-held approaches to quality assurance, governance, and risk management. It is also creating a new test for channel partners helping customers modernize complex enterprise environments while simultaneously accelerating AI adoption.</p><h2 id="software-trust-is-becoming-a-board-level-issue">Software trust is becoming a board-level issue</h2><p>One of the most significant changes is that trust in software quality is rapidly becoming a board-level concern, following a trajectory similar to cybersecurity before it. Twenty years ago, security was largely considered a technology problem. Today, it is firmly established as a business risk discussed regularly in boardrooms. Software quality assurance is undergoing the same transition. </p><p>With the consequences of software failures extending far beyond the IT department, influencing customer experiences, supply chains, financial processes, and regulatory reporting, mistakes can directly impact revenue, reputation, compliance, and customer trust. </p><p>As organizations become more dependent on autonomous systems, executives increasingly need assurance that those systems are operating reliably, transparently, and within clearly defined governance frameworks.</p><h2 id="why-agentic-ai-changes-the-risk-equation">Why agentic AI changes the risk equation</h2><p>Our <a href="https://www.tricentis.com/resources/2026-quality-transformation-report"><u>recent research</u></a> suggests many organizations are still finding their way: while 83% trust agentic AI to make release decisions, only 35% feel fully prepared to govern AI agents and autonomous software workflows at scale. This gap highlights a growing recognition that deploying and governing AI are two very different capabilities, and for channel partners, this creates an opportunity to help customers adapt their quality engineering and governance strategies to the unique risks introduced by agentic AI.</p><p>The emergence of agentic AI also introduces a fundamentally different risk profile. Traditional enterprise applications generally behave in predictable ways: organizations can test known workflows, validate expected outcomes, and deploy updates through structured release processes. Agentic systems operate differently; their outputs vary depending on context, data inputs, and interactions with other systems. They can generate new content, recommend actions, and increasingly execute tasks on behalf of users.</p><p>Within complex enterprise environments, where finance, procurement, supply chain, human resources, and customer operations are deeply interconnected, the implications are significant. Whether organizations rely on SAP, Oracle, Salesforce, Microsoft, or a combination of enterprise platforms, a single AI-driven decision can have downstream consequences across multiple business functions. </p><p>The risk extends beyond application defects - there are also inaccurate recommendations, flawed automated decisions, compliance violations, and operational disruption resulting from autonomous actions to consider.</p><h2 id="why-continuous-quality-becomes-essential">Why continuous quality becomes essential</h2><p>This is one reason why traditional testing models are beginning to show their limitations. Many quality assurance approaches were designed for a world where software changed at a manageable pace, and human decision-making remained central to operational processes. Software delivery, transformed by AI-assisted development, increasingly automated workflows, and growing volumes of software changes, is moving faster than quality processes can keep up. </p><p>As a result, continuous quality engineering is becoming an essential component of successful AI transformation initiatives. Rather than treating testing as a final checkpoint before deployment, continuous quality engineering embeds validation throughout the software delivery lifecycle. It enables organizations to continuously assess risk, monitor system behavior, and verify that critical business processes continue operating as intended even as applications, integrations, and AI models evolve.</p><p>This capability is becoming increasingly important for those operating complex business systems. Modern enterprise environments typically span cloud services, third-party platforms, legacy applications, and, increasingly, AI-enabled capabilities. For organizations running large ERP platforms such as SAP, the challenge is amplified by the number of interconnected business processes that must continue to operate reliably.</p><p>Ensuring reliability across this landscape requires far greater visibility than periodic testing alone can provide. Organizations need the ability to validate not just software functionality, but also the integrity of business processes and the behavior of AI-driven systems over time.</p><h2 id="governance-must-be-built-in-not-bolted-on">Governance must be built in, not bolted on</h2><p>At the same time, governance and compliance considerations are becoming increasingly difficult to separate from discussions about AI adoption. </p><p>Many organizations remain in the early stages of introducing AI-powered capabilities into customer-facing products and internal operations. Yet regulators, customers, and stakeholders are already asking difficult questions about accountability, transparency, and control.</p><p>Particularly for enterprises operating in regulated industries, these concerns are acute - they must be able to demonstrate how AI-driven decisions are monitored, what controls exist when systems make mistakes, and how compliance requirements are maintained as autonomous capabilities expand. </p><p>Effective governance cannot be treated as an afterthought or layered once deployment is complete; it must be integrated into software delivery and operational processes from the outset.</p><h2 id="the-opportunity-for-channel-partners">The opportunity for channel partners</h2><p>These developments create an important opportunity for channel partners. As enterprise modernization enters a new phase shaped by AI adoption, customers increasingly need guidance that extends beyond implementation and migration projects. They are looking for trusted advisors who can help them balance innovation with resilience, speed with control, and automation with accountability.</p><p>Alongside discussions about cloud migration, process transformation, and AI adoption, there must be a greater focus on operational trust, quality engineering, governance, and risk management. Success won’t be about deploying autonomous technologies first, but establishing the confidence, visibility, and governance needed to scale them responsibly.</p><p>As agentic AI becomes more deeply embedded within enterprise operations, software quality can no longer function as a standalone checkpoint. It must become a continuous discipline that enables organizations to innovate rapidly while maintaining the trust that modern businesses depend upon. In the years ahead, that balance between speed and trust may prove to be one of the most important competitive differentiators of all<strong> - </strong>both for enterprises themselves and for the partner organizations that help them achieve it.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AI's operational blind spots ]]></title>
                                                                                                <dc:content><![CDATA[ <iframe allow="clipboard-write" height="200px" width="100%" id="" style="width: 100%; height: 200px;" class="position-center" data-lazy-priority="high" data-lazy-src="https://player.captivate.fm/episode/0572f7e3-48ab-4e48-837f-14fcb80d8a4f/"></iframe><p>Businesses continue to embrace generative AI at a rapid pace. From copilots and chatbots to autonomous agents, an exciting world of new technology is opening up.</p><p>The race to adopt these AI tools isn't without its perils, though. The mantra "garbage in, garbage out" is even more poignant when these systems come into play, with the potential for a cycle of bad data presenting a real risk to organizations.</p><p>On this week's episode, Tim Pfaelzer, SVP and GM EMEA at Veeam, discusses operational blind spots, what they mean for businesses, and how they can balance their desire for a technical edge with data governance.</p><h2 id="highlights">Highlights</h2><p>"Now we're in the third era, which is agentic, which is kind of hyper-accelerating everything that's there to touch your data. It's not like somebody doing something to attack your data. It is multiple agents running simultaneously across hundreds of apps and all the different systems to attack your data within day number one."</p><p>"There are tons of examples that you would probably call worst-case scenario. If you think about, you know a large online retailer that lost all of its backups, all of its production data because of a hallucinating AI agent within nine seconds, resulting in about 10 million lost orders and a 72-hour outage. Those are the type of things we're talking about. And now, if you ask about the worst case, it's not only the direct orders that you lost. It's not only the direct downtime that you have, but there's a next currency to it, and that next currency is the currency of trust."</p><h2 id="links">Links</h2><ul><li><a href="https://www.itpro.com/software/development/ai-assisted-software-development-means-security-teams-need-an-engineering-first-mindset">AI-assisted software development means security teams need an 'engineering-first' mindset</a></li><li><a href="https://www.itpro.com/security/it-leaders-are-facing-major-work-device-blind-spots-and-its-putting-security-at-risk">IT leaders are facing major work device blind spots – and it's putting security at risk</a></li></ul> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/technology/artificial-intelligence/ais-operational-blind-spots</link>
                                                                            <description>
                            <![CDATA[ We talk to Tim Pfaelzer, SVP and GM EMEA at Veeam, about operational blind spots, what they mean for businesses, and how they can balance their desire for a technical edge ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bEqoMMmbAukcLRoG8U4RNU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/L3yygNcdMWLDVdotcp4CaB-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 11 Sep 2026 07:00:00 +0000</pubDate>                                                                                                                                <updated>Fri, 11 Sep 2026 11:30:06 +0000</updated>
                                                                                                                                            <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Bobby Hellard) ]]></author>                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Bobby Hellard&amp;nbsp;is&amp;nbsp;ITPro&#039;s Reviews Editor and has worked on&amp;nbsp;CloudPro and ChannelPro since 2018. In his time at ITPro, Bobby has covered stories for all the major technology companies, such as Apple, Microsoft, Amazon and Facebook, and regularly attends industry-leading events such as AWS Re:Invent and Google Cloud Next.&lt;/p&gt;
&lt;p&gt;Bobby mainly covers hardware reviews, but you will also recognize him as the face of many of our video reviews of laptops and smartphones.&lt;/p&gt;
&lt;p&gt;He has been a journalist for ten years, originally covering sports, before moving into business technology with ITPro. He has bylines in The Independent, Vice and The Business Briefing. Contact him at &lt;a href=&quot;mailto:bobby.hellard@futurenet.com&quot;&gt;bobby.hellard@futurenet.com&lt;/a&gt; or find him on Twitter: &lt;a href=&quot;https://twitter.com/bobbyhellard&quot;&gt;@bobbyhellard&lt;/a&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/L3yygNcdMWLDVdotcp4CaB-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Code lines behind the episode title ]]></media:description>                                                            <media:text><![CDATA[Code lines behind the episode title ]]></media:text>
                                <media:title type="plain"><![CDATA[Code lines behind the episode title ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/L3yygNcdMWLDVdotcp4CaB-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <iframe allow="clipboard-write" height="200px" width="100%" id="" style="width: 100%; height: 200px;" class="position-center" data-lazy-priority="high" data-lazy-src="https://player.captivate.fm/episode/0572f7e3-48ab-4e48-837f-14fcb80d8a4f/"></iframe><p>Businesses continue to embrace generative AI at a rapid pace. From copilots and chatbots to autonomous agents, an exciting world of new technology is opening up.</p><p>The race to adopt these AI tools isn't without its perils, though. The mantra "garbage in, garbage out" is even more poignant when these systems come into play, with the potential for a cycle of bad data presenting a real risk to organizations.</p><p>On this week's episode, Tim Pfaelzer, SVP and GM EMEA at Veeam, discusses operational blind spots, what they mean for businesses, and how they can balance their desire for a technical edge with data governance.</p><h2 id="highlights">Highlights</h2><p>"Now we're in the third era, which is agentic, which is kind of hyper-accelerating everything that's there to touch your data. It's not like somebody doing something to attack your data. It is multiple agents running simultaneously across hundreds of apps and all the different systems to attack your data within day number one."</p><p>"There are tons of examples that you would probably call worst-case scenario. If you think about, you know a large online retailer that lost all of its backups, all of its production data because of a hallucinating AI agent within nine seconds, resulting in about 10 million lost orders and a 72-hour outage. Those are the type of things we're talking about. And now, if you ask about the worst case, it's not only the direct orders that you lost. It's not only the direct downtime that you have, but there's a next currency to it, and that next currency is the currency of trust."</p><h2 id="links">Links</h2><ul><li><a href="https://www.itpro.com/software/development/ai-assisted-software-development-means-security-teams-need-an-engineering-first-mindset">AI-assisted software development means security teams need an 'engineering-first' mindset</a></li><li><a href="https://www.itpro.com/security/it-leaders-are-facing-major-work-device-blind-spots-and-its-putting-security-at-risk">IT leaders are facing major work device blind spots – and it's putting security at risk</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ From tokenmaxxing to valuemaxxing ]]></title>
                                                                                                <dc:content><![CDATA[ <p>In the last few months, several leading tech firms have made a decisive move away from 'tokenmaxxing' – a trend whereby enterprises measure AI usage based on the volume of tokens consumed by employees. </p><p>In May, Amazon quietly retired an internal leaderboard that ranked staff by how many AI tokens they used, while <a href="https://www.itpro.com/technology/artificial-intelligence/what-were-seeing-right-now-is-just-rapid-escalation-in-ai-token-spend-accenture-tells-staff-to-stop-using-ai-for-unnecessary-tasks-amid-surging-costs"><u>Accenture capped routine use of AI tokens i</u></a>n June after one internal tool saw usage rocket 113-fold in just ten weeks. More recently, <a href="https://www.itpro.com/technology/artificial-intelligence/microsoft-has-joined-the-growing-list-of-companies-cracking-down-on-tokenmaxxing"><u>Microsoft</u></a> updated internal guidance this August specifically to curb AI token spend.</p><p>Speaking on the <a href="https://www.itpro.com/technology/artificial-intelligence/the-end-of-tokenmaxxing-and-what-comes-next"><u><em>ITPro.Podcast</em></u></a>, Ninox CEO Frank Böhmer said the wider industry’s gamification had pushed employees to chase visible token counts out of stress and pressure rather than genuine performance. </p><p>While his company had avoided this practice, this well-intentioned but flawed metric has backfired elsewhere, incentivizing staff to optimize for volume over efficient, well-scoped use, leading to costly token burn on low-value tasks.</p><h2 id="a-model-lacking-economic-sustainability">A model lacking economic sustainability</h2><p>Rewarding staff for how much they spent on tokens was never going to be economically sustainable, says Stewart Buchanan, research VP in Gartner’s CIO team. The real-world consequences of unmanaged consumption are stark: <a href="https://www.itpro.com/technology/artificial-intelligence/could-rising-token-costs-boost-interest-in-on-premises-hardware"><u>Uber exhausted its entire 2026 AI</u></a> budget by mid-April, while Dell saw a single 'super user' <a href="https://www.itpro.com/technology/artificial-intelligence/dell-unveils-deskside-agentic-ai-at-dell-technologies-world-2026"><u>developer run up a bill of $3,400 in just 24 hours</u></a> due to high token usage by the AI agents they were running.</p><p>This financial volatility is compounded by potential shifts in pay-per-use pricing. Anthropic, for example, announced it was separating human interaction from agentic and API use in its subscriptions. While this move has currently been paused, Ashish Nadkarni, leader of IDC’s enterprise infrastructure global research domain, believes these kinds of pricing shifts will compel CIOs and tech leaders to become much smarter about how they allocate budgets to developer activities.</p><h2 id="valuemaxxing-and-the-rise-of-tokenomics">Valuemaxxing and the rise of tokenomics</h2><p>Understandably, multiple companies are seeking a different approach, which for many appears to be 'valuemaxxing' – changing the core measurement from raw consumption to business outcomes. While directionally right, Mike Fuller, a member of the technical staff at the Tokenomics Foundation, believes valuemaxxing is as structurally thin as its predecessor.</p><p>"While the road to understanding value runs through unit economics, that’s only half of it," Fuller argues. "Valuemaxxing works on the numerator – what the output is worth. It says nothing about the denominator – what it costs you to produce the intelligence in the first place. That’s an engineering discipline, and where the leverage sits. We would say '<a href="https://www.itpro.com/technology/artificial-intelligence/could-rising-token-costs-boost-interest-in-on-premises-hardware"><u>tokenomics'</u></a> is next, because it covers both."</p><p>Answering what each unit of work costs and whether it landed successfully requires two critical joins:</p><ul><li>Spend to workload: This is being solved. The 1.5 release of FOCUS (the FinOps Open Cost and Usage Specification), expected in December and backed by the FinOps Foundation, will add native AI token tracking and a price sheet dataset. This will allow businesses to compare token spend across different AI providers in a consistent format.</li><li>Workload to outcome, which remains a blind spot. "The industry is still guessing here," Fuller admits. "There’s no standard for connecting a workload to a business result, and there may never be a universal one, because the result differs by business."</li></ul><p>To establish this second join, organizations must tie every prompt to a business outcome, tracking cost and revenue per customer, transaction, or item. "‘Miles per gallon’ is often used as a proxy for this," notes William Fellows, research director at 451 Research. "But the problem when it comes to tokens is there’s no industry agreement yet on what constitutes a mile, a gallon, or indeed the fuel itself."</p><h2 id="shifting-employee-mindsets">Shifting employee mindsets</h2><p>While the industry establishes these frameworks, organizations can begin shifting staff mindsets away from high-volume token consumption immediately, and education is the primary lever for behavioral change, says Fuller.</p><p>When staff understand that the goal isn’t outcomes at any cost – and are equipped to assess the choices that change what an outcome costs – behavior changes naturally. Organizations must transition from measuring sheer usage to answering harder questions, Fuller says:</p><ul><li>Where does AI add genuine value?</li><li>What investments make financial sense?</li><li>What happens to the staff time AI frees up, and who’s responsible for redeploying it?</li></ul><p>Buchanan adds that tech leaders must train staff to identify the most valuable use cases while actively discouraging uneconomic AI habits. “For instance, a simple, rule-based engine can consistently deliver deterministic outcomes without burning costly tokens on complex reasoning and inference. </p><p>“Staff must also learn to discourage perfectionism; developers and analysts frequently run the same prompt repeatedly to perfect an answer, when they should learn to stop at the first adequate response that can be refined manually at a lower cost.”</p><h2 id="redefining-the-operating-model">Redefining the operating model</h2><p>To manage this spend sustainably, enterprises must address where AI budgets actually sit. For HPE CEO Antonio Neri, AI agents should be categorized alongside human resources rather than traditional IT infrastructure.</p><p>"I don’t think of AI agents as an IT cost," <a href="https://www.itpro.com/business/business-strategy/forget-tokenomics-agents-are-a-personnel-cost"><u>Neri told </u><u><em>ITPro</em></u></a>. "I think about the cost of the workforce because, to me, an agent is no different than any other employee I have to hire… it's going to cost me a number of tokens to train an agent to drive the best productivity. If I'm going to spend a million dollars to train an agent, it has to be way more productive than a human. Otherwise, why am I doing that?"</p><p>However, Buchanan warns against over-simplifying this comparison. "We personify and anthropomorphize AI at humanity’s peril," he cautions. "People and AI aren’t identical and interchangeable – people think on a few thousand calories a day, while AI data centers consume gigawatts. Neither HR nor IT manages the business nor its budgets, so we need deeper integration with business financial planning and analytics."</p><p>AI spend must reach board-level discussion as a capital allocation question, Fuller argues. Boards must ask what they’re committing to, over what term, on what pricing assumptions, and what their financial exposure is if a single provider changes its terms.</p><h2 id="the-path-forward-for-cios">The path forward for CIOs</h2><p>While "cost per outcome" is the ideal destination, most CIOs won’t realistically achieve this level of granular tracking within the next 12 months. Instead, the immediate, pragmatic goal for tech leaders must be twofold: identify which AI use cases are actively succeeding against valuable business outcomes, and clearly name the pilot investments that have yet to prove their value.</p><p>Buchanan’s advice is to skip the magic formula; CIOs must partner directly with business leaders to control costs in relation to strategic value. Failing to do so risks creating severe corporate governance challenges through <a href="https://www.itpro.com/technology/artificial-intelligence/shadow-ai-and-the-new-visibility-gap-in-software-development"><u>shadow AI</u></a> across the business. </p><p>By focusing on unit economics, shifting employee behaviors, and integrating AI into the broader financial planning model, enterprises can move past the chaotic era of tokenmaxxing and build a sustainable, value-driven AI strategy.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/technology/artificial-intelligence/from-tokenmaxxing-to-valuemaxxing</link>
                                                                            <description>
                            <![CDATA[ AI needs to be integrated into broader financial planning if firms want to move forward with a strategy that delivers sustainable value ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">y5r2UyeVkUVmbhjsyTY66S</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4k5sqaFTSYzmJVJsTq3VXE-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Sep 2026 07:00:00 +0000</pubDate>                                                                                                                                <updated>Thu, 10 Sep 2026 15:46:24 +0000</updated>
                                                                                                                                            <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keri Allan ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/oJZkdPii464j27ff4GCcoT-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4k5sqaFTSYzmJVJsTq3VXE-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Sovereign AI concept image showing an artificial digitized brain absorbing data from multiple different directions. ]]></media:description>                                                            <media:text><![CDATA[Sovereign AI concept image showing an artificial digitized brain absorbing data from multiple different directions. ]]></media:text>
                                <media:title type="plain"><![CDATA[Sovereign AI concept image showing an artificial digitized brain absorbing data from multiple different directions. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4k5sqaFTSYzmJVJsTq3VXE-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In the last few months, several leading tech firms have made a decisive move away from 'tokenmaxxing' – a trend whereby enterprises measure AI usage based on the volume of tokens consumed by employees. </p><p>In May, Amazon quietly retired an internal leaderboard that ranked staff by how many AI tokens they used, while <a href="https://www.itpro.com/technology/artificial-intelligence/what-were-seeing-right-now-is-just-rapid-escalation-in-ai-token-spend-accenture-tells-staff-to-stop-using-ai-for-unnecessary-tasks-amid-surging-costs"><u>Accenture capped routine use of AI tokens i</u></a>n June after one internal tool saw usage rocket 113-fold in just ten weeks. More recently, <a href="https://www.itpro.com/technology/artificial-intelligence/microsoft-has-joined-the-growing-list-of-companies-cracking-down-on-tokenmaxxing"><u>Microsoft</u></a> updated internal guidance this August specifically to curb AI token spend.</p><p>Speaking on the <a href="https://www.itpro.com/technology/artificial-intelligence/the-end-of-tokenmaxxing-and-what-comes-next"><u><em>ITPro.Podcast</em></u></a>, Ninox CEO Frank Böhmer said the wider industry’s gamification had pushed employees to chase visible token counts out of stress and pressure rather than genuine performance. </p><p>While his company had avoided this practice, this well-intentioned but flawed metric has backfired elsewhere, incentivizing staff to optimize for volume over efficient, well-scoped use, leading to costly token burn on low-value tasks.</p><h2 id="a-model-lacking-economic-sustainability">A model lacking economic sustainability</h2><p>Rewarding staff for how much they spent on tokens was never going to be economically sustainable, says Stewart Buchanan, research VP in Gartner’s CIO team. The real-world consequences of unmanaged consumption are stark: <a href="https://www.itpro.com/technology/artificial-intelligence/could-rising-token-costs-boost-interest-in-on-premises-hardware"><u>Uber exhausted its entire 2026 AI</u></a> budget by mid-April, while Dell saw a single 'super user' <a href="https://www.itpro.com/technology/artificial-intelligence/dell-unveils-deskside-agentic-ai-at-dell-technologies-world-2026"><u>developer run up a bill of $3,400 in just 24 hours</u></a> due to high token usage by the AI agents they were running.</p><p>This financial volatility is compounded by potential shifts in pay-per-use pricing. Anthropic, for example, announced it was separating human interaction from agentic and API use in its subscriptions. While this move has currently been paused, Ashish Nadkarni, leader of IDC’s enterprise infrastructure global research domain, believes these kinds of pricing shifts will compel CIOs and tech leaders to become much smarter about how they allocate budgets to developer activities.</p><h2 id="valuemaxxing-and-the-rise-of-tokenomics">Valuemaxxing and the rise of tokenomics</h2><p>Understandably, multiple companies are seeking a different approach, which for many appears to be 'valuemaxxing' – changing the core measurement from raw consumption to business outcomes. While directionally right, Mike Fuller, a member of the technical staff at the Tokenomics Foundation, believes valuemaxxing is as structurally thin as its predecessor.</p><p>"While the road to understanding value runs through unit economics, that’s only half of it," Fuller argues. "Valuemaxxing works on the numerator – what the output is worth. It says nothing about the denominator – what it costs you to produce the intelligence in the first place. That’s an engineering discipline, and where the leverage sits. We would say '<a href="https://www.itpro.com/technology/artificial-intelligence/could-rising-token-costs-boost-interest-in-on-premises-hardware"><u>tokenomics'</u></a> is next, because it covers both."</p><p>Answering what each unit of work costs and whether it landed successfully requires two critical joins:</p><ul><li>Spend to workload: This is being solved. The 1.5 release of FOCUS (the FinOps Open Cost and Usage Specification), expected in December and backed by the FinOps Foundation, will add native AI token tracking and a price sheet dataset. This will allow businesses to compare token spend across different AI providers in a consistent format.</li><li>Workload to outcome, which remains a blind spot. "The industry is still guessing here," Fuller admits. "There’s no standard for connecting a workload to a business result, and there may never be a universal one, because the result differs by business."</li></ul><p>To establish this second join, organizations must tie every prompt to a business outcome, tracking cost and revenue per customer, transaction, or item. "‘Miles per gallon’ is often used as a proxy for this," notes William Fellows, research director at 451 Research. "But the problem when it comes to tokens is there’s no industry agreement yet on what constitutes a mile, a gallon, or indeed the fuel itself."</p><h2 id="shifting-employee-mindsets">Shifting employee mindsets</h2><p>While the industry establishes these frameworks, organizations can begin shifting staff mindsets away from high-volume token consumption immediately, and education is the primary lever for behavioral change, says Fuller.</p><p>When staff understand that the goal isn’t outcomes at any cost – and are equipped to assess the choices that change what an outcome costs – behavior changes naturally. Organizations must transition from measuring sheer usage to answering harder questions, Fuller says:</p><ul><li>Where does AI add genuine value?</li><li>What investments make financial sense?</li><li>What happens to the staff time AI frees up, and who’s responsible for redeploying it?</li></ul><p>Buchanan adds that tech leaders must train staff to identify the most valuable use cases while actively discouraging uneconomic AI habits. “For instance, a simple, rule-based engine can consistently deliver deterministic outcomes without burning costly tokens on complex reasoning and inference. </p><p>“Staff must also learn to discourage perfectionism; developers and analysts frequently run the same prompt repeatedly to perfect an answer, when they should learn to stop at the first adequate response that can be refined manually at a lower cost.”</p><h2 id="redefining-the-operating-model">Redefining the operating model</h2><p>To manage this spend sustainably, enterprises must address where AI budgets actually sit. For HPE CEO Antonio Neri, AI agents should be categorized alongside human resources rather than traditional IT infrastructure.</p><p>"I don’t think of AI agents as an IT cost," <a href="https://www.itpro.com/business/business-strategy/forget-tokenomics-agents-are-a-personnel-cost"><u>Neri told </u><u><em>ITPro</em></u></a>. "I think about the cost of the workforce because, to me, an agent is no different than any other employee I have to hire… it's going to cost me a number of tokens to train an agent to drive the best productivity. If I'm going to spend a million dollars to train an agent, it has to be way more productive than a human. Otherwise, why am I doing that?"</p><p>However, Buchanan warns against over-simplifying this comparison. "We personify and anthropomorphize AI at humanity’s peril," he cautions. "People and AI aren’t identical and interchangeable – people think on a few thousand calories a day, while AI data centers consume gigawatts. Neither HR nor IT manages the business nor its budgets, so we need deeper integration with business financial planning and analytics."</p><p>AI spend must reach board-level discussion as a capital allocation question, Fuller argues. Boards must ask what they’re committing to, over what term, on what pricing assumptions, and what their financial exposure is if a single provider changes its terms.</p><h2 id="the-path-forward-for-cios">The path forward for CIOs</h2><p>While "cost per outcome" is the ideal destination, most CIOs won’t realistically achieve this level of granular tracking within the next 12 months. Instead, the immediate, pragmatic goal for tech leaders must be twofold: identify which AI use cases are actively succeeding against valuable business outcomes, and clearly name the pilot investments that have yet to prove their value.</p><p>Buchanan’s advice is to skip the magic formula; CIOs must partner directly with business leaders to control costs in relation to strategic value. Failing to do so risks creating severe corporate governance challenges through <a href="https://www.itpro.com/technology/artificial-intelligence/shadow-ai-and-the-new-visibility-gap-in-software-development"><u>shadow AI</u></a> across the business. </p><p>By focusing on unit economics, shifting employee behaviors, and integrating AI into the broader financial planning model, enterprises can move past the chaotic era of tokenmaxxing and build a sustainable, value-driven AI strategy.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The managed service category nobody's named. Yet. ]]></title>
                                                                                                <dc:content><![CDATA[ <p>There's a moment in every tech cycle when a product shifts from a novelty to a standard. The partners who recognize that moment early are typically the ones who end up seeing the best returns. When it comes to agentic AI, we're already at that stage, with a McKinsey report stating that <a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai"><u>62% of organizations</u></a> say they’re at least experimenting with agents, and 23% are deploying and scaling them. </p><p>Those who've been in the game long enough have seen this before. Think back to endpoint management. A decade ago, the partners who moved fast to own device management built durable, recurring revenue. In creating their own frameworks, service level agreements, and accountability models, they set the standard for what ‘managed’ really meant in their markets. </p><p>The interest in endpoint management operated along an S-curve, which saw a slow incubation period, followed by a rapid acceleration of interest. But those who waited found themselves playing catch-up in a category that had already been defined. This same dynamic is unfolding right now with agentic AI. The only difference is that the clock is running a lot faster.</p><h2 id="agent-accountability">Agent accountability</h2><p>AI agents can now act as fully integrated team members. They handle day-to-day work: routing support tickets, assisting in the sales cycle through pipeline forecasting, CRM upkeep, etc., running IT operations, responding to cybersecurity breaches, and much more. However, it’s unclear who runs, governs, and holds accountability for these new workers. </p><p>Let’s say an IT support company deploys an AI agent that auto-routes support tickets from users to the relevant support department. There’s an expectation that the agent will receive the ticket, route the inquiry properly, and report back to the user without any guidance. If a human were handling these tickets, it would be obvious who to report to if something went wrong. The same isn’t immediately obvious with an autonomous agent, which creates an accountability gap.</p><p>This is where Managed Service Providers (MSPs) come in. They're well equipped to guide the partners and vendors they work with who may not be able to handle agent issues on their own, especially considering how new this technology is. Customers deploy the agents, but MSPs should govern them.</p><h2 id="adoption-anxiety">Adoption anxiety</h2><p>There’s been a recent notable change in the questions being asked around AI agents. Six months ago, customers were asking whether they should be adopting AI agents at all, and what ROI they’d see from adopting them. Now, they’re asking whether agents are working properly, and who to call when they aren't. </p><p>While the early adopters have already been through this shift, the next wave of customers are only now reaching it. This is the point where interest turns into widespread adoption. Customers are not wearing tin-foil hats and don’t buy into the fears and hyperbole around AI. Most are AI-curious and open to reviewing and utilizing agents, but are naturally anxious about employing autonomous bots.</p><p>Data is another source of anxiety that MSPs need to address. Our <a href="https://monday.com/w/ai-at-work#download-the-report"><u>AI at Work</u></a> report found that 40% of business directors cited data privacy and security concerns as their top barrier to wider AI adoption. Unlike a chatbot that responds to a prompt, an agent can access systems, use data, and take action on a customer's behalf. </p><p>Organizations need to know what data an agent can access and where human oversight begins. That's where MSPs add value, giving customers the visibility and ongoing monitoring they need to adopt agents with confidence.</p><h2 id="governance-and-the-three-waves-of-ai">Governance and the ‘three waves’ of AI</h2><p>The value of the partner relationship is riding out the waves of AI, then guiding customers through end-to-end implementation. Product knowledge and context are both key for MSPs to really understand a customer's needs. This means learning the business logic, risk tolerance, compliance requirements, and being able to apply that context to every tech decision, from onboarding agents to having them work autonomously alongside employees.</p><p>AI agent governance is a natural extension of that process. An MSP who already knows a customer's workflows, data sensitivities, and operational boundaries is positioned to ask the right questions before deploying agents. They can then course-correct if an agent's behavior starts drifting.</p><p>That last part matters more than most people realize because agents don't exist in a static environment. Processes, regulations, and business priorities are changing in real-time. The same is true for AI adoption, which unfolds in three waves: first, employees using accessible LLMs like ChatGPT at work; second, vibe coding and structured agents that handle specific, simple tasks; and finally, autonomous agents that understand their tasks and self-improve. Navigating these stages is complex, which is where trusted partners come in to ease the burden.</p><h2 id="early-management">Early management</h2><p>MSPs should start by separating upfront work from ongoing management. The initial consulting and deployment phase, starting with understanding a customer's use cases, defining their success criteria, mapping risks, configuring the agent, and going live, is a one-time professional service. </p><p>Ongoing management is where long-term value lies. This includes monitoring agent performance, reviewing outputs for errors, and maintaining an audit trail that keeps the compliance team happy. Additionally, different-sized businesses will have different requirements, and where major providers may have dedicated IT support teams, smaller businesses may not have access to the same support structures. MSPs must individualize their plans for their customers, depending on their needs.</p><p>This ‘agent as managed service’ model maps naturally onto how MSPs already structure their work with customers. In addition to selling devices, MSPs ensure agents are secure, updated, and performing well over time. MSPs ensure that agents are doing their job correctly and remain adaptable. Without continued management, one-time investments into AI agents are unlikely to return real ROI for customers.</p><h2 id="acceleration-has-started">Acceleration has started</h2><p>MSPs that saw the best returns from managing endpoints weren't slow to realize the value, nor did they treat endpoint management as a one-time service. Instead, they created a whole new managed service model. That's the opportunity available to the channel right now with AI agent oversight.</p><p>With the majority of businesses now arriving at agent adoption, this may be the last chance for MSPs to set the standard for an agent management service model. While there is no name for this service model, by managing customer anxieties around agent adoption, offering ongoing support for agents, and adapting services in line with customer needs, forward-looking MSPs will write the rules for agent governance across the channel.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/technology/artificial-intelligence/the-managed-service-category-nobodys-named-yet</link>
                                                                            <description>
                            <![CDATA[ MSPs have a narrow window to set the rules for agent governance ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Z3jjsjK36Q93Dg64Eb8DP8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZxGSVvG9QQUkeEaRrxwiW3-1920-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Sep 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tricia Carroll ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DezBdTrgiseRjU5Ti6hw6h-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/ZxGSVvG9QQUkeEaRrxwiW3-1920-80.png">
                                                            <media:credit><![CDATA[AMD]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[AI Infrastructure for Business Impact: Enabling Agentic Intelligence with Scalable Compute]]></media:description>                                                            <media:text><![CDATA[AI Infrastructure for Business Impact: Enabling Agentic Intelligence with Scalable Compute]]></media:text>
                                <media:title type="plain"><![CDATA[AI Infrastructure for Business Impact: Enabling Agentic Intelligence with Scalable Compute]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZxGSVvG9QQUkeEaRrxwiW3-1920-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>There's a moment in every tech cycle when a product shifts from a novelty to a standard. The partners who recognize that moment early are typically the ones who end up seeing the best returns. When it comes to agentic AI, we're already at that stage, with a McKinsey report stating that <a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai"><u>62% of organizations</u></a> say they’re at least experimenting with agents, and 23% are deploying and scaling them. </p><p>Those who've been in the game long enough have seen this before. Think back to endpoint management. A decade ago, the partners who moved fast to own device management built durable, recurring revenue. In creating their own frameworks, service level agreements, and accountability models, they set the standard for what ‘managed’ really meant in their markets. </p><p>The interest in endpoint management operated along an S-curve, which saw a slow incubation period, followed by a rapid acceleration of interest. But those who waited found themselves playing catch-up in a category that had already been defined. This same dynamic is unfolding right now with agentic AI. The only difference is that the clock is running a lot faster.</p><h2 id="agent-accountability">Agent accountability</h2><p>AI agents can now act as fully integrated team members. They handle day-to-day work: routing support tickets, assisting in the sales cycle through pipeline forecasting, CRM upkeep, etc., running IT operations, responding to cybersecurity breaches, and much more. However, it’s unclear who runs, governs, and holds accountability for these new workers. </p><p>Let’s say an IT support company deploys an AI agent that auto-routes support tickets from users to the relevant support department. There’s an expectation that the agent will receive the ticket, route the inquiry properly, and report back to the user without any guidance. If a human were handling these tickets, it would be obvious who to report to if something went wrong. The same isn’t immediately obvious with an autonomous agent, which creates an accountability gap.</p><p>This is where Managed Service Providers (MSPs) come in. They're well equipped to guide the partners and vendors they work with who may not be able to handle agent issues on their own, especially considering how new this technology is. Customers deploy the agents, but MSPs should govern them.</p><h2 id="adoption-anxiety">Adoption anxiety</h2><p>There’s been a recent notable change in the questions being asked around AI agents. Six months ago, customers were asking whether they should be adopting AI agents at all, and what ROI they’d see from adopting them. Now, they’re asking whether agents are working properly, and who to call when they aren't. </p><p>While the early adopters have already been through this shift, the next wave of customers are only now reaching it. This is the point where interest turns into widespread adoption. Customers are not wearing tin-foil hats and don’t buy into the fears and hyperbole around AI. Most are AI-curious and open to reviewing and utilizing agents, but are naturally anxious about employing autonomous bots.</p><p>Data is another source of anxiety that MSPs need to address. Our <a href="https://monday.com/w/ai-at-work#download-the-report"><u>AI at Work</u></a> report found that 40% of business directors cited data privacy and security concerns as their top barrier to wider AI adoption. Unlike a chatbot that responds to a prompt, an agent can access systems, use data, and take action on a customer's behalf. </p><p>Organizations need to know what data an agent can access and where human oversight begins. That's where MSPs add value, giving customers the visibility and ongoing monitoring they need to adopt agents with confidence.</p><h2 id="governance-and-the-three-waves-of-ai">Governance and the ‘three waves’ of AI</h2><p>The value of the partner relationship is riding out the waves of AI, then guiding customers through end-to-end implementation. Product knowledge and context are both key for MSPs to really understand a customer's needs. This means learning the business logic, risk tolerance, compliance requirements, and being able to apply that context to every tech decision, from onboarding agents to having them work autonomously alongside employees.</p><p>AI agent governance is a natural extension of that process. An MSP who already knows a customer's workflows, data sensitivities, and operational boundaries is positioned to ask the right questions before deploying agents. They can then course-correct if an agent's behavior starts drifting.</p><p>That last part matters more than most people realize because agents don't exist in a static environment. Processes, regulations, and business priorities are changing in real-time. The same is true for AI adoption, which unfolds in three waves: first, employees using accessible LLMs like ChatGPT at work; second, vibe coding and structured agents that handle specific, simple tasks; and finally, autonomous agents that understand their tasks and self-improve. Navigating these stages is complex, which is where trusted partners come in to ease the burden.</p><h2 id="early-management">Early management</h2><p>MSPs should start by separating upfront work from ongoing management. The initial consulting and deployment phase, starting with understanding a customer's use cases, defining their success criteria, mapping risks, configuring the agent, and going live, is a one-time professional service. </p><p>Ongoing management is where long-term value lies. This includes monitoring agent performance, reviewing outputs for errors, and maintaining an audit trail that keeps the compliance team happy. Additionally, different-sized businesses will have different requirements, and where major providers may have dedicated IT support teams, smaller businesses may not have access to the same support structures. MSPs must individualize their plans for their customers, depending on their needs.</p><p>This ‘agent as managed service’ model maps naturally onto how MSPs already structure their work with customers. In addition to selling devices, MSPs ensure agents are secure, updated, and performing well over time. MSPs ensure that agents are doing their job correctly and remain adaptable. Without continued management, one-time investments into AI agents are unlikely to return real ROI for customers.</p><h2 id="acceleration-has-started">Acceleration has started</h2><p>MSPs that saw the best returns from managing endpoints weren't slow to realize the value, nor did they treat endpoint management as a one-time service. Instead, they created a whole new managed service model. That's the opportunity available to the channel right now with AI agent oversight.</p><p>With the majority of businesses now arriving at agent adoption, this may be the last chance for MSPs to set the standard for an agent management service model. While there is no name for this service model, by managing customer anxieties around agent adoption, offering ongoing support for agents, and adapting services in line with customer needs, forward-looking MSPs will write the rules for agent governance across the channel.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What happens to consent when the keys are handed to machines? ]]></title>
                                                                                                <dc:content><![CDATA[ <p>In June, Google disabled a feature in its Analytics platform that stopped personal data from being shared with Google Ads. </p><p>Launched just after <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know"><u>GDPR</u></a> in 2018, Google Signals gave businesses veto over whether Google’s ad network could see their visitor activity. Even if a user consented to being tracked, the final decision lay with the business, and many used it as an extra guardrail, with Google’s Consent Mode, to prevent falling foul of privacy laws. Then in June, Google Signals was gone. </p><p>You could assume the change was minor, especially because Consent Mode was still there to protect a user’s cookie consent choice. Yet straight after the switch, compliance failures across the world's biggest websites increased. </p><p>In the US, <a href="https://www.privado.ai/the-state-of-google-consent-mode-june-15"><u>87% of sites</u></a> were found to be ignoring a user's opt-out signal, up from 81% before the change. In Europe, 56% kept tracking users even after they'd rejected cookies, up from 52%. One vendor changed one setting and elements of an already brittle consent framework began to unravel. </p><p>"If a single vendor can make this change which affects everybody's privacy compliance docket without most noticing,” says Vaibhav Antil, CEO and co-founder of Privado. “Imagine what happens when agents are deployed?" </p><h2 id="handing-the-keys-to-the-machine">Handing the keys to the machine</h2><p>Bot web traffic has already overtaken human web traffic, according to <a href="https://radar.cloudflare.com/traffic#bot-vs-human"><u>Cloudflare’s traffic radar</u></a>, and the number of non-human identities inside organizations outnumber humans by <a href="https://www.businesswire.com/news/home/20250423817886/en/Machine-Identities-Outnumber-Humans-by-More-Than-80-to-1-New-Report-Exposes-the-Exponential-Threats-of-Fragmented-Identity-Security"><u>more than 80 to 1</u></a>. </p><p>These agents are on the web comparing prices, filling in forms and booking appointments. They’re embedded in products, sifting job applications, querying databases, moving money, updating records, and increasingly making decisions that used to need a person to sign off on. Gartner expects <a href="https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027"><u>15% of day-to-day work decisions</u></a> will be made autonomously by AI agents by 2028.</p><p>Yet the approval and consent process behind it all still largely consists of cookie banners, DSAR portals, and preference centres; tools built for a human ticking one box, once, and that consent holding until they say otherwise. AI actors are capable of acting thousands of times a second, or chaining several tools together to complete a single instruction. They need their permission checked before every move, and their actions can leave businesses unable to say, with confidence, what they did, when.</p><p>“A person with too much access is limited by habit, their training, and by their job,” adds Marcus Tommy, co-founder of MALTO Cyber. “An agent has none of that.”</p><h2 id="the-fan-out">The fan-out</h2><p>Take, for example, someone who asks an agent to find out why sales have dropped. “The system can choose an analysis, run it, and generate SQL to investigate it,” explains Maurice Sikkink, CTO at Stormly. It might even reach into an external system for market data. Technically, a human approved the question, but they didn’t explicitly approve every step the agent took to answer it.</p><p>This becomes more stark when agents start connecting systems together. One linked agent might have permission to read customer records in a CRM, and permission to write to a marketing platform – both individually authorized. Yet the moment it starts moving a customer's data between them, it presents a new use of that person's data nobody explicitly consented to.</p><p>And then there’s the issue of revocation and re-authorisation. Revoking permissions can be done for several reasons, from policy changes to someone leaving a job. If an agent's session token or API key is valid for hours after the revocation kicks in, the underlying permission isn’t always automatically revoked. </p><p>"Those credentials haven’t necessarily been stolen," Harry Varatharasan, chief product officer at ComplyCube, says. "The agent might not be malicious. The identity behind them might be perfectly genuine, but the authority is stale.”</p><h2 id="auditability-by-design">Auditability by design</h2><p>Antil's answer, for copilots at least, is what he calls permission inheritance: "If you, the user, are not able to edit settings, then your copilot shouldn't be able to either.” When permission inheritance isn't enough, continues Antil, enterprise IT needs to decide what counts as dangerous, regardless of whether a single employee has permission to perform the task. </p><p>“A business might disable an email-to-Claude connector, for instance, because it's a common route for prompt injection attacks,” he adds.  </p><p>However, even where access is logged and overseen, most systems can prove who had permission to ask the agent to act but not <em>why</em> the agent did what it did once inside. </p><p>Sikkink says this is where the industry is furthest behind. "Authentication tells me someone had access to the project. Attribution tells me that they asked the agent to do it.” What’s missing, he argues, “is a common way of carrying the identity of an original request through the entire chain.” </p><p>Varatharasan calls this idea of carrying identity and authority through the chain as “binding.” "Issuing the credential is only half the problem. Knowing whether you should still trust it is arguably the more important half,” he says. "I don't think the future is simply 'continuously identifying the agent ’. It’s the continuous assurance over the relationship between the individual, the agent, its credentials, its delegated authority and its behaviour." </p><p>Sikkink agrees: “[Not] every intermediate step needs another consent popup. That would make agents almost pointless. The important thing is that the agent stays inside a clearly defined boundary, and that we can reconstruct how it got from the user's request to the result.”</p><h2 id="a-push-for-clarity">A push for clarity</h2><p>From a technical point of view, Tommy argues that what’s needed to fix this largely already exists. “Cloud audit logs record the actor and the action. Token systems know the scope. Append-only log structures are proven technology; they run the public certificate transparency system. What’s missing is the join.”</p><p>In the UK, the <a href="https://www.gov.uk/government/collections/uk-digital-verification-services-trust-framework"><u>Digital Verification Services Trust Framework</u></a> is one attempt to build this join. It sets out guidance on proving delegated authority: what was granted, when and by whom, plus plans for cryptographic checks on signing keys. Under new <a href="https://cppa.ca.gov/announcements/2025/20250923.html"><u>California Consumer Privacy Act regulations</u></a>, businesses using AI for significant decisions must give consumers a pre-use notice, a working opt-out, and the right to ask what the system did and why. </p><p>Antil calls these a step in the right direction, even if they don’t fully cover agentic workflows. Varatharasan adds that these frameworks have the right building blocks but fall short of addressing the bigger, lifecycle issues around revocation, re-authorisation, and continuous risk. </p><p>Ultimately though, Antil expects consent in the age of machines to resolve the way SaaS governance did. First, by applying existing regulations to the problem; second, through the rise of new regulations; and third, he expects “we’ll see a major public failure which will push enterprises to demand more controls and guardrails from vendors.” </p><p>There’s also a future when the governance itself will be automated. “Because agents and copilots have agency, act at machine speed around the clock, and are prone to hallucinations, enterprises will need to match that speed from a governance perspective," concludes Antil.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/technology/artificial-intelligence/what-happens-to-consent-when-the-keys-are-handed-to-machines</link>
                                                                            <description>
                            <![CDATA[ Access is under the spotlight, and things are definitely more complicated in the AI era... ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QsfnoD3wzkXnBJKLTJN2fW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/44ktQKgRvmq93jKSBo3pnB-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 09 Sep 2026 07:00:00 +0000</pubDate>                                                                                                                                <updated>Wed, 09 Sep 2026 10:20:32 +0000</updated>
                                                                                                                                            <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Victoria Woollaston ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/44ktQKgRvmq93jKSBo3pnB-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[AI agent concept image showing a digitized human face disintegrating into hundreds of small individual blocks.]]></media:description>                                                            <media:text><![CDATA[AI agent concept image showing a digitized human face disintegrating into hundreds of small individual blocks.]]></media:text>
                                <media:title type="plain"><![CDATA[AI agent concept image showing a digitized human face disintegrating into hundreds of small individual blocks.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/44ktQKgRvmq93jKSBo3pnB-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In June, Google disabled a feature in its Analytics platform that stopped personal data from being shared with Google Ads. </p><p>Launched just after <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know"><u>GDPR</u></a> in 2018, Google Signals gave businesses veto over whether Google’s ad network could see their visitor activity. Even if a user consented to being tracked, the final decision lay with the business, and many used it as an extra guardrail, with Google’s Consent Mode, to prevent falling foul of privacy laws. Then in June, Google Signals was gone. </p><p>You could assume the change was minor, especially because Consent Mode was still there to protect a user’s cookie consent choice. Yet straight after the switch, compliance failures across the world's biggest websites increased. </p><p>In the US, <a href="https://www.privado.ai/the-state-of-google-consent-mode-june-15"><u>87% of sites</u></a> were found to be ignoring a user's opt-out signal, up from 81% before the change. In Europe, 56% kept tracking users even after they'd rejected cookies, up from 52%. One vendor changed one setting and elements of an already brittle consent framework began to unravel. </p><p>"If a single vendor can make this change which affects everybody's privacy compliance docket without most noticing,” says Vaibhav Antil, CEO and co-founder of Privado. “Imagine what happens when agents are deployed?" </p><h2 id="handing-the-keys-to-the-machine">Handing the keys to the machine</h2><p>Bot web traffic has already overtaken human web traffic, according to <a href="https://radar.cloudflare.com/traffic#bot-vs-human"><u>Cloudflare’s traffic radar</u></a>, and the number of non-human identities inside organizations outnumber humans by <a href="https://www.businesswire.com/news/home/20250423817886/en/Machine-Identities-Outnumber-Humans-by-More-Than-80-to-1-New-Report-Exposes-the-Exponential-Threats-of-Fragmented-Identity-Security"><u>more than 80 to 1</u></a>. </p><p>These agents are on the web comparing prices, filling in forms and booking appointments. They’re embedded in products, sifting job applications, querying databases, moving money, updating records, and increasingly making decisions that used to need a person to sign off on. Gartner expects <a href="https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027"><u>15% of day-to-day work decisions</u></a> will be made autonomously by AI agents by 2028.</p><p>Yet the approval and consent process behind it all still largely consists of cookie banners, DSAR portals, and preference centres; tools built for a human ticking one box, once, and that consent holding until they say otherwise. AI actors are capable of acting thousands of times a second, or chaining several tools together to complete a single instruction. They need their permission checked before every move, and their actions can leave businesses unable to say, with confidence, what they did, when.</p><p>“A person with too much access is limited by habit, their training, and by their job,” adds Marcus Tommy, co-founder of MALTO Cyber. “An agent has none of that.”</p><h2 id="the-fan-out">The fan-out</h2><p>Take, for example, someone who asks an agent to find out why sales have dropped. “The system can choose an analysis, run it, and generate SQL to investigate it,” explains Maurice Sikkink, CTO at Stormly. It might even reach into an external system for market data. Technically, a human approved the question, but they didn’t explicitly approve every step the agent took to answer it.</p><p>This becomes more stark when agents start connecting systems together. One linked agent might have permission to read customer records in a CRM, and permission to write to a marketing platform – both individually authorized. Yet the moment it starts moving a customer's data between them, it presents a new use of that person's data nobody explicitly consented to.</p><p>And then there’s the issue of revocation and re-authorisation. Revoking permissions can be done for several reasons, from policy changes to someone leaving a job. If an agent's session token or API key is valid for hours after the revocation kicks in, the underlying permission isn’t always automatically revoked. </p><p>"Those credentials haven’t necessarily been stolen," Harry Varatharasan, chief product officer at ComplyCube, says. "The agent might not be malicious. The identity behind them might be perfectly genuine, but the authority is stale.”</p><h2 id="auditability-by-design">Auditability by design</h2><p>Antil's answer, for copilots at least, is what he calls permission inheritance: "If you, the user, are not able to edit settings, then your copilot shouldn't be able to either.” When permission inheritance isn't enough, continues Antil, enterprise IT needs to decide what counts as dangerous, regardless of whether a single employee has permission to perform the task. </p><p>“A business might disable an email-to-Claude connector, for instance, because it's a common route for prompt injection attacks,” he adds.  </p><p>However, even where access is logged and overseen, most systems can prove who had permission to ask the agent to act but not <em>why</em> the agent did what it did once inside. </p><p>Sikkink says this is where the industry is furthest behind. "Authentication tells me someone had access to the project. Attribution tells me that they asked the agent to do it.” What’s missing, he argues, “is a common way of carrying the identity of an original request through the entire chain.” </p><p>Varatharasan calls this idea of carrying identity and authority through the chain as “binding.” "Issuing the credential is only half the problem. Knowing whether you should still trust it is arguably the more important half,” he says. "I don't think the future is simply 'continuously identifying the agent ’. It’s the continuous assurance over the relationship between the individual, the agent, its credentials, its delegated authority and its behaviour." </p><p>Sikkink agrees: “[Not] every intermediate step needs another consent popup. That would make agents almost pointless. The important thing is that the agent stays inside a clearly defined boundary, and that we can reconstruct how it got from the user's request to the result.”</p><h2 id="a-push-for-clarity">A push for clarity</h2><p>From a technical point of view, Tommy argues that what’s needed to fix this largely already exists. “Cloud audit logs record the actor and the action. Token systems know the scope. Append-only log structures are proven technology; they run the public certificate transparency system. What’s missing is the join.”</p><p>In the UK, the <a href="https://www.gov.uk/government/collections/uk-digital-verification-services-trust-framework"><u>Digital Verification Services Trust Framework</u></a> is one attempt to build this join. It sets out guidance on proving delegated authority: what was granted, when and by whom, plus plans for cryptographic checks on signing keys. Under new <a href="https://cppa.ca.gov/announcements/2025/20250923.html"><u>California Consumer Privacy Act regulations</u></a>, businesses using AI for significant decisions must give consumers a pre-use notice, a working opt-out, and the right to ask what the system did and why. </p><p>Antil calls these a step in the right direction, even if they don’t fully cover agentic workflows. Varatharasan adds that these frameworks have the right building blocks but fall short of addressing the bigger, lifecycle issues around revocation, re-authorisation, and continuous risk. </p><p>Ultimately though, Antil expects consent in the age of machines to resolve the way SaaS governance did. First, by applying existing regulations to the problem; second, through the rise of new regulations; and third, he expects “we’ll see a major public failure which will push enterprises to demand more controls and guardrails from vendors.” </p><p>There’s also a future when the governance itself will be automated. “Because agents and copilots have agency, act at machine speed around the clock, and are prone to hallucinations, enterprises will need to match that speed from a governance perspective," concludes Antil.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ From AI pilots to profits: The next opportunity for MSPs ]]></title>
                                                                                                <dc:content><![CDATA[ <p>To date, the AI opportunity for managed service providers (MSPs) has largely centered on deployment. While early stages focused on which platforms to buy and how to start piloting, the market has reached a tipping point. Businesses are no longer looking for experiments; they are looking for infrastructure.</p><p>That picture is shifting. Today, most organizations are no longer asking whether AI has value. They are asking a more complex question: how do we make AI part of the way our business actually operates? </p><p>A recent McKinsey report showed <a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai"><u>88% </u></a>of global organizations are now using AI in at least one business function, yet only around one-third have begun scaling it across the enterprise, with the highest-performing focusing on redesigning workflows rather than simply deploying new tools. </p><p>For channel partners, this shift represents the next commercial opportunity. As AI becomes more accessible, selling AI tools is becoming less of a differentiator. The real value is in moving upstream: helping customers redesign workflows, build employee confidence, and embed AI into everyday business operations.</p><h2 id="successful-ai-depends-on-successful-workflows">Successful AI depends on successful workflows</h2><p>Many organizations have already demonstrated that AI works. They've run pilots, tested new use cases, and proved it can deliver productivity gains. Yet many of these projects struggle to scale beyond a single department.</p><p>Our data highlights the scale of that challenge. More than half (<a href="https://www.ringcentral.com/report/2026-agentic-ai-trends.html#get-asset"><u>54%</u></a>) of UK organizations remain in the research, exploration, or pilot phase of AI adoption, while only 16% have fully deployed AI-powered digital workers. The reason is straightforward: AI has often been added as another standalone application instead of being embedded into the everyday workflows where people already spend their time.</p><p>The organizations making the greatest progress are taking a different approach. Rather than asking where they can deploy another AI tool, they're asking where AI can remove friction from everyday work.</p><p>Communications is a natural place to start because every customer conversation, meeting, and interaction generates valuable business intelligence. When AI is embedded into those experiences, it can automatically capture actions, surface insights, reduce administration, and improve customer experiences without employees changing the way they work.</p><h2 id="the-msp-role-is-changing">The MSP role is changing</h2><p>This is where the channel has an opportunity to evolve. Historically, success for enterprises was measured by delivering projects on time and deploying new technology. Increasingly, customers need help answering broader business questions.</p><p>Which processes should change to make AI genuinely useful? How should AI fit into customer service and employee workflows? How do organizations measure whether adoption is actually delivering a return? How do they introduce governance without slowing innovation?</p><p>These are strategic challenges rather than technical ones, and they create opportunities for partners to build much deeper customer relationships.</p><p>Take customer service as an example. Deploying AI to summarize calls or recommend next actions is relatively straightforward. Embedding those capabilities into day-to-day operations, training teams to use them effectively, redesigning processes around them, and measuring their business impact is where long-term value is created.</p><p>That is also where recurring services revenue begins. Helping customers embed AI into everyday operations and refine workflows creates an ongoing partnership, rather than a one-off implementation project.</p><h2 id="learning-from-the-cloud-playbook-when-it-comes-to-ai">Learning from the cloud playbook when it comes to AI</h2><p>When organizations moved to cloud platforms, the biggest opportunity for partners wasn't simply selling licenses. It came from helping customers migrate, redesign processes, improve adoption, and continuously optimize their environments. AI is following much the same trajectory.</p><p>As deployment becomes easier, customers will increasingly look for partners who understand their business rather than simply their technology stack. They'll need trusted advisors who can connect AI to business outcomes, whether that's improving customer experience, increasing employee productivity, or streamlining operations.</p><p>For Managed Service Providers (MSPs), that represents an opportunity to move beyond implementation projects and become long-term strategic partners.</p><h2 id="the-next-phase-of-channel-growth">The next phase of channel growth</h2><p>The AI market is entering its next chapter. The first stage rewarded partners for helping customers buy AI, and the second will reward those who help customers operationalize it.</p><p>Customers don't need or want any more disconnected AI tools. They need AI embedded into the conversations, workflows, and business processes that already power their organizations.</p><p>The partners that help customers make that transition won't simply deliver better AI projects. They'll create stronger customer relationships, unlock new recurring service opportunities, and establish a role that extends well beyond deployment.</p><p>Ultimately, the biggest opportunity for the channel isn't just selling AI tools. It's helping customers change the way work gets done.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/technology/artificial-intelligence/from-ai-pilots-to-profits-the-next-opportunity-for-msps</link>
                                                                            <description>
                            <![CDATA[ MSPs must shift from deploying AI tools to embedding AI into business workflows ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cxng56VHTQFeW6qur3wST9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/bLSsYgswXfVWXGiXgSJvj8-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 09 Sep 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Thomas John ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/uEUVWzoxWvVTryY9qtkrxd-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/bLSsYgswXfVWXGiXgSJvj8-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Conceptual image of a large-scale futuristic data center on a peach grid showcasing a prominent glowing AI cube cluster emerging from an orange container, with extensive colorful wiring linking to surrounding illuminated server racks in precise formations, representing advanced artificial intelligence infrastructure, machine learning networks, and interconnected digital systems in a high-tech conceptual 3D scene with vibrant effects.]]></media:description>                                                            <media:text><![CDATA[Conceptual image of a large-scale futuristic data center on a peach grid showcasing a prominent glowing AI cube cluster emerging from an orange container, with extensive colorful wiring linking to surrounding illuminated server racks in precise formations, representing advanced artificial intelligence infrastructure, machine learning networks, and interconnected digital systems in a high-tech conceptual 3D scene with vibrant effects.]]></media:text>
                                <media:title type="plain"><![CDATA[Conceptual image of a large-scale futuristic data center on a peach grid showcasing a prominent glowing AI cube cluster emerging from an orange container, with extensive colorful wiring linking to surrounding illuminated server racks in precise formations, representing advanced artificial intelligence infrastructure, machine learning networks, and interconnected digital systems in a high-tech conceptual 3D scene with vibrant effects.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/bLSsYgswXfVWXGiXgSJvj8-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>To date, the AI opportunity for managed service providers (MSPs) has largely centered on deployment. While early stages focused on which platforms to buy and how to start piloting, the market has reached a tipping point. Businesses are no longer looking for experiments; they are looking for infrastructure.</p><p>That picture is shifting. Today, most organizations are no longer asking whether AI has value. They are asking a more complex question: how do we make AI part of the way our business actually operates? </p><p>A recent McKinsey report showed <a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai"><u>88% </u></a>of global organizations are now using AI in at least one business function, yet only around one-third have begun scaling it across the enterprise, with the highest-performing focusing on redesigning workflows rather than simply deploying new tools. </p><p>For channel partners, this shift represents the next commercial opportunity. As AI becomes more accessible, selling AI tools is becoming less of a differentiator. The real value is in moving upstream: helping customers redesign workflows, build employee confidence, and embed AI into everyday business operations.</p><h2 id="successful-ai-depends-on-successful-workflows">Successful AI depends on successful workflows</h2><p>Many organizations have already demonstrated that AI works. They've run pilots, tested new use cases, and proved it can deliver productivity gains. Yet many of these projects struggle to scale beyond a single department.</p><p>Our data highlights the scale of that challenge. More than half (<a href="https://www.ringcentral.com/report/2026-agentic-ai-trends.html#get-asset"><u>54%</u></a>) of UK organizations remain in the research, exploration, or pilot phase of AI adoption, while only 16% have fully deployed AI-powered digital workers. The reason is straightforward: AI has often been added as another standalone application instead of being embedded into the everyday workflows where people already spend their time.</p><p>The organizations making the greatest progress are taking a different approach. Rather than asking where they can deploy another AI tool, they're asking where AI can remove friction from everyday work.</p><p>Communications is a natural place to start because every customer conversation, meeting, and interaction generates valuable business intelligence. When AI is embedded into those experiences, it can automatically capture actions, surface insights, reduce administration, and improve customer experiences without employees changing the way they work.</p><h2 id="the-msp-role-is-changing">The MSP role is changing</h2><p>This is where the channel has an opportunity to evolve. Historically, success for enterprises was measured by delivering projects on time and deploying new technology. Increasingly, customers need help answering broader business questions.</p><p>Which processes should change to make AI genuinely useful? How should AI fit into customer service and employee workflows? How do organizations measure whether adoption is actually delivering a return? How do they introduce governance without slowing innovation?</p><p>These are strategic challenges rather than technical ones, and they create opportunities for partners to build much deeper customer relationships.</p><p>Take customer service as an example. Deploying AI to summarize calls or recommend next actions is relatively straightforward. Embedding those capabilities into day-to-day operations, training teams to use them effectively, redesigning processes around them, and measuring their business impact is where long-term value is created.</p><p>That is also where recurring services revenue begins. Helping customers embed AI into everyday operations and refine workflows creates an ongoing partnership, rather than a one-off implementation project.</p><h2 id="learning-from-the-cloud-playbook-when-it-comes-to-ai">Learning from the cloud playbook when it comes to AI</h2><p>When organizations moved to cloud platforms, the biggest opportunity for partners wasn't simply selling licenses. It came from helping customers migrate, redesign processes, improve adoption, and continuously optimize their environments. AI is following much the same trajectory.</p><p>As deployment becomes easier, customers will increasingly look for partners who understand their business rather than simply their technology stack. They'll need trusted advisors who can connect AI to business outcomes, whether that's improving customer experience, increasing employee productivity, or streamlining operations.</p><p>For Managed Service Providers (MSPs), that represents an opportunity to move beyond implementation projects and become long-term strategic partners.</p><h2 id="the-next-phase-of-channel-growth">The next phase of channel growth</h2><p>The AI market is entering its next chapter. The first stage rewarded partners for helping customers buy AI, and the second will reward those who help customers operationalize it.</p><p>Customers don't need or want any more disconnected AI tools. They need AI embedded into the conversations, workflows, and business processes that already power their organizations.</p><p>The partners that help customers make that transition won't simply deliver better AI projects. They'll create stronger customer relationships, unlock new recurring service opportunities, and establish a role that extends well beyond deployment.</p><p>Ultimately, the biggest opportunity for the channel isn't just selling AI tools. It's helping customers change the way work gets done.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The hidden cost of tool sprawl on the channel ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The cybersecurity industry is awash with products.</p><p>Every time a new attack technique is discovered, vendors will rush to develop a product to address the challenge. </p><p>Whether it be malware prevention, privileged access management, next-generation firewalls, or email security platforms, the industry is flooded with platforms promising to improve defences and make it harder for attackers to infiltrate systems.</p><p>But in reality, this has made security very noisy. </p><p>Instead of improving security, the volume of tools organisations must manage has actually amplified risks.</p><p>There are too many alerts coming in to understand and identify threats quickly. Too many platforms to manage, which overburdens resources and amplifies costs, and too many interfaces to navigate, which makes managing security far from seamless.</p><p>Overall, while the objective of the platforms is to strengthen security, the products can actually jeopardise it.</p><p>However, these problems are significantly worse when it comes to Managed Service Providers (MSPs).</p><h2 id="tool-sprawl-in-the-channel">Tool sprawl in the channel</h2><p>Consider an MSP delivering security services to 50 customers.</p><p>One customer may use Microsoft security technologies, another CrowdStrike, while others could have different SIEM, vulnerability management, ticketing, and endpoint security platforms.</p><p>However, the MSP is often forced to operate them all. </p><p>All simultaneously, and all expertly, knowing the capabilities of each platform and how to operate them.</p><p>The MSP must maintain the knowledge, processes, and integrations required to operate across all of the platforms they manage for their clients. However, not only does this create resourcing challenges it also amplifies costs.</p><p>There is the cost of purchasing each platform that clients depend on, plus there is the cost of employees to manage the platforms.</p><p>Furthermore, with MSP staff continually navigating between platform interfaces, this wastes valuable time, reduces productivity, and can make managing security for clients more cumbersome.</p><p>Individually, these delays can appear insignificant. However, across hundreds or thousands of incidents, tickets, and customer interactions, they quickly accumulate.</p><p>Plus, as an MSP grows its customer base, the challenges can become even harder to manage.</p><h2 id="when-growth-introduces-more-complexity">When growth introduces more complexity</h2><p>Every business wants to grow its customer base, but for an MSP this can also mean introducing more tools into their environments.</p><p>If every new customer introduces another combination of technologies, integrations and processes, onboarding customers also introduces additional operational complexity.</p><p>Providers can find themselves in a position where growing the business requires continually adding more people to manage the additional workload.</p><p>This has obvious implications for margins, but it can also put pressure on existing teams. </p><p>Skilled cyber security professionals are already difficult and expensive to recruit. Using their time to perform repetitive administrative tasks or manually move between disconnected platforms is neither efficient nor sustainable.</p><p>Ultimately, the channel therefore needs to look beyond simply adding more technology and consider how existing technologies are operated.</p><p>There will always be customers that want or need different technologies. Channel providers therefore need to find ways to embrace this diversity without allowing it to dictate how efficiently they operate.</p><p>But how can this be achieved?</p><h2 id="the-importance-of-technology-agnostic-platforms">The importance of technology-agnostic platforms</h2><p>One of the best ways to overcome this challenge is by working with partners that deliver technology-agnostic platforms that simplify the management of security for MSPs.</p><p>These platforms can seamlessly integrate with the security platforms MSPs rely on for their customers, but they can be managed via a single dashboard.</p><p>This allows an MSP to more efficiently manage security, but without having to navigate across multiple platforms.</p><p>These platforms can deliver everything a partner needs to track, monitor, and manage the security of their customers, without overburdening resources or amplifying costs.</p><p>Instead, everything can be managed via a single unified platform, reducing complexity and cutting out the chaos of managing multiple solutions.</p><p>A technology-agnostic platform doesn't replace customer investments; it provides a common operational layer across them. </p><p>Analysts can investigate incidents, automate workflows, manage tickets, and monitor security posture from one interface while still supporting whichever technologies each customer has chosen.</p><p>The channel doesn't need fewer security technologies; it needs a better way to operate them. </p><p>MSPs that standardize their operations across diverse customer environments will reduce costs, improve analyst productivity, and deliver a more consistent service. </p><p>In an increasingly competitive market, operational efficiency isn't just an internal advantage; ultimately, it's a differentiator that leads to better security outcomes for customers and healthier margins for MSPs.  </p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/the-hidden-cost-of-tool-sprawl-on-the-channel</link>
                                                                            <description>
                            <![CDATA[ Tool sprawl represents major challenges for MSPs, so how can the issue be tackled? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kcT4H7H39wP47bAapK2amh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ihZG9rnw3t3ZGBiY82SzAN-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Sep 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Gemma Blake ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/pKcnhWn69jhSZfdbR4f9xC-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ihZG9rnw3t3ZGBiY82SzAN-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Software sprawl concept image showing multiple applications all in siloed positions on a digital interace.]]></media:description>                                                            <media:text><![CDATA[Software sprawl concept image showing multiple applications all in siloed positions on a digital interace.]]></media:text>
                                <media:title type="plain"><![CDATA[Software sprawl concept image showing multiple applications all in siloed positions on a digital interace.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ihZG9rnw3t3ZGBiY82SzAN-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The cybersecurity industry is awash with products.</p><p>Every time a new attack technique is discovered, vendors will rush to develop a product to address the challenge. </p><p>Whether it be malware prevention, privileged access management, next-generation firewalls, or email security platforms, the industry is flooded with platforms promising to improve defences and make it harder for attackers to infiltrate systems.</p><p>But in reality, this has made security very noisy. </p><p>Instead of improving security, the volume of tools organisations must manage has actually amplified risks.</p><p>There are too many alerts coming in to understand and identify threats quickly. Too many platforms to manage, which overburdens resources and amplifies costs, and too many interfaces to navigate, which makes managing security far from seamless.</p><p>Overall, while the objective of the platforms is to strengthen security, the products can actually jeopardise it.</p><p>However, these problems are significantly worse when it comes to Managed Service Providers (MSPs).</p><h2 id="tool-sprawl-in-the-channel">Tool sprawl in the channel</h2><p>Consider an MSP delivering security services to 50 customers.</p><p>One customer may use Microsoft security technologies, another CrowdStrike, while others could have different SIEM, vulnerability management, ticketing, and endpoint security platforms.</p><p>However, the MSP is often forced to operate them all. </p><p>All simultaneously, and all expertly, knowing the capabilities of each platform and how to operate them.</p><p>The MSP must maintain the knowledge, processes, and integrations required to operate across all of the platforms they manage for their clients. However, not only does this create resourcing challenges it also amplifies costs.</p><p>There is the cost of purchasing each platform that clients depend on, plus there is the cost of employees to manage the platforms.</p><p>Furthermore, with MSP staff continually navigating between platform interfaces, this wastes valuable time, reduces productivity, and can make managing security for clients more cumbersome.</p><p>Individually, these delays can appear insignificant. However, across hundreds or thousands of incidents, tickets, and customer interactions, they quickly accumulate.</p><p>Plus, as an MSP grows its customer base, the challenges can become even harder to manage.</p><h2 id="when-growth-introduces-more-complexity">When growth introduces more complexity</h2><p>Every business wants to grow its customer base, but for an MSP this can also mean introducing more tools into their environments.</p><p>If every new customer introduces another combination of technologies, integrations and processes, onboarding customers also introduces additional operational complexity.</p><p>Providers can find themselves in a position where growing the business requires continually adding more people to manage the additional workload.</p><p>This has obvious implications for margins, but it can also put pressure on existing teams. </p><p>Skilled cyber security professionals are already difficult and expensive to recruit. Using their time to perform repetitive administrative tasks or manually move between disconnected platforms is neither efficient nor sustainable.</p><p>Ultimately, the channel therefore needs to look beyond simply adding more technology and consider how existing technologies are operated.</p><p>There will always be customers that want or need different technologies. Channel providers therefore need to find ways to embrace this diversity without allowing it to dictate how efficiently they operate.</p><p>But how can this be achieved?</p><h2 id="the-importance-of-technology-agnostic-platforms">The importance of technology-agnostic platforms</h2><p>One of the best ways to overcome this challenge is by working with partners that deliver technology-agnostic platforms that simplify the management of security for MSPs.</p><p>These platforms can seamlessly integrate with the security platforms MSPs rely on for their customers, but they can be managed via a single dashboard.</p><p>This allows an MSP to more efficiently manage security, but without having to navigate across multiple platforms.</p><p>These platforms can deliver everything a partner needs to track, monitor, and manage the security of their customers, without overburdening resources or amplifying costs.</p><p>Instead, everything can be managed via a single unified platform, reducing complexity and cutting out the chaos of managing multiple solutions.</p><p>A technology-agnostic platform doesn't replace customer investments; it provides a common operational layer across them. </p><p>Analysts can investigate incidents, automate workflows, manage tickets, and monitor security posture from one interface while still supporting whichever technologies each customer has chosen.</p><p>The channel doesn't need fewer security technologies; it needs a better way to operate them. </p><p>MSPs that standardize their operations across diverse customer environments will reduce costs, improve analyst productivity, and deliver a more consistent service. </p><p>In an increasingly competitive market, operational efficiency isn't just an internal advantage; ultimately, it's a differentiator that leads to better security outcomes for customers and healthier margins for MSPs.  </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Iran power plant closure is a warning to all businesses: How to respond ]]></title>
                                                                                                <dc:content><![CDATA[ <p>In August, it emerged that a small UK power plant was shut down for four days following a <a href="https://www.itpro.com/security/cyber-attacks/iranian-cyber-attack-on-uk-power-plant-should-concern-every-organization-responsible-for-keeping-this-country-running"><u>cyber attack</u></a> attributed to <a href="https://www.itpro.com/security/cyber-attacks/the-iran-cyber-threat"><u>Iranian hackers</u></a>. It follows multiple <a href="https://www.itpro.com/security/cyber-attacks/attacks-on-us-water-systems-could-be-the-tip-of-the-iceberg-cyber-experts-warn"><u>attacks on water facilities</u></a> in the US, which reports indicate are linked to the latest incident.</p><p>Not much is known about the UK power plant breach, with the government declining to reveal exactly where it took place. It has confirmed the incident involved a small-scale generator, and that the wider energy system was never at risk.</p><p>But a key technical detail is still withheld about whether control systems were directly affected, or if the plant was disconnected merely as a precaution while IT contained the infiltration.</p><p>After the first of its kind attack, the government has written to businesses with advice on the steps they should take to protect themselves. How big is the risk, who does it impact, and how should firms react?</p><h2 id="major-escalation">Major escalation </h2><p>The latest attack is “a major escalation” from the recent campaign targeting water facilities in the US, says Markus Mueller, field CISO at Nozomi Networks. </p><p>He says attacks on peaker plants like this – which are designed to provide power when needed – can be more dangerous because “things happen fast, there is no buffer, and there can be major impacts”.</p><p>Critical national infrastructure is also vulnerable because it often uses legacy technology never meant to be connected to the internet. In the latest incident, the attack path involved a <a href="https://www.itpro.com/security/cyber-attacks/security-researchers-warn-of-ai-powered-plc-attacks-in-wake-of-siemens-advisories"><u>programmable logic controller</u></a> (PLC) that was not secured following basic best practices. </p><p>“If current reporting is correct, this was a publicly exposed PLC that was impacted similarly to what we have seen at US water utilities, where the threat group scans the internet for exposed PLCs using AI-generated scripts,” Mueller tells <em>ITPro</em>.</p><p>The attacker then logs into the PLCs using default credentials and proceeds to take them offline by resetting the programming and changing the password and IP address, “making it inaccessible”, explains Mueller. </p><h2 id="a-risk-beyond-cni">A risk beyond CNI</h2><p>The risk goes beyond critical sectors, into the supply chain, other industries, and to firms that rely on the breached organization.</p><p>While this incident occurred at a power plant, this is also “a clear warning” for “non-utility commercial sectors”, says Mueller. </p><p>He points out that automated scanning scripts used by adversaries “do not differentiate between a power generator, a manufacturing plant, a logistics warehouse, or smart building management systems”. </p><p>Any business relying on connected physical systems or industrial controls is at risk. At the same time, <a href="https://www.itpro.com/security/why-is-supply-chain-resilience-under-the-spotlight"><u>supply chain</u></a> partners and third-party maintenance contractors with remote access into operational technology (OT) environments represent “a major attack vector that adversaries are actively targeting to move laterally into enterprise networks”, says Mueller.</p><p>The risk extends “well beyond” large, regulated energy operators, agrees Martin Riley, CTO at Bridewell. </p><p>He describes how the UK’s energy system is becoming more distributed, with growing reliance on smaller peaker plants, renewable generators, battery storage and other remotely operated assets. </p><p>“Individually, these facilities may represent a small proportion of national capacity, but collectively they are becoming an essential part of how the grid operates,” says Riley.</p><p>“That creates a particular challenge because smaller operators and suppliers may fall outside the regulatory thresholds applied to traditional critical infrastructure, while still having connectivity into systems and services the country depends on.”</p><p>At the same time, James Neilson, SVP of global at OPSWAT, says it is “a lucky escape” that this attack happened at a small power plant and didn’t impact the UK’s wider energy system. </p><p>“<a href="https://www.itpro.com/security/cyber-attacks/crink-attacks-nation-state-hackers--threat-2026"><u>Hostile actors</u></a> now routinely target the UK using cyber attacks, undermining security, the economy and public trust. This form of grey-zone warfare has been present for at least a decade, but sub-threshold activity has increased sharply in recent years.”</p><h2 id="resilience-measures">Resilience measures</h2><p>Following the power plant attack, the UK government and National Cyber Security Center have actively urged organizations running critical infrastructure and industrial facilities to audit internet-facing devices and enforce cyber hygiene. </p><p>“The guidance emphasizes immediately identifying and pulling exposed OT and PLCs off the public internet, eliminating default vendor passwords and enforcing <a href="https://www.itpro.com/technology/how-to-choose-the-best-mfa-methods"><u>multi-factor authentication</u></a> for remote management connections,” explains Mueller.</p><p>At this stage, the most important lesson is “understanding asset exposure, attack paths, and the operational consequences of unauthorized access to industrial control systems”, according to Mueller.</p><p><a href="https://www.itpro.com/security/data-breaches/businesses-need-to-boost-cyber-resilience-heres-how"><u>Resilience</u></a> starts with “understanding how an attacker could move through the organization” and “ensuring a compromise in one part of the environment cannot easily reach systems responsible for physical operations”, says Riley. </p><p>For operational environments, that means strong IT and OT segmentation, tightly controlled remote access and “security controls proportionate to the potential consequences of an incident”, he advises.</p><p>Organizations also need visibility across IT and OT. “If security monitoring operates separately, an attacker may be able to establish themselves in the corporate environment before moving towards operational systems without anyone seeing the complete picture,” warns Riley.</p><p>Know what exposed interfaces you have and harden these by using technology and architecture, advises Ian Thornton-Trump, CISO at Inversion6. </p><p>At the same time, use firewalls with access control and whitelisting capabilities to “ensure any exposed interfaces can only be connected to by specific IP addresses”, he adds.</p><p>Meanwhile, Thornton-Trump advises deploying deception technology to detect the early stages of an attack, including honeypots, as well as taking advantage of the <a href="https://www.ncsc.gov.uk/section/active-cyber-defence/early-warning?utm_source=Google&utm_medium=cpc&utm_campaign=NCSC+Always+On+Search+26&utm_content=EW&gad_source=1&gad_campaignid=24164180098&gbraid=0AAAAACafkIXIMz0NdMPIRtnIL5_4yCA2v&gclid=Cj0KCQjwteTUBhD4ARIsAEYjs3rKYgHyvnTCO_nwP-kaaKHA4eL9O7kDuYTVsEqS606SpC6YLLx_80UaArqYEALw_wcB"><u>NCSC’s early warning</u></a> service.</p><p>It’s also important to know the enemy you are facing. For example, Iranian and other nation-state groups will often hunt out default credentials immediately to achieve “rapid, low-noise access”, says Neilson. </p><p>With this in mind, he advises “assessing and hardening critical systems and infrastructure considering the latest attacks”.</p><p>Firms should train for incident response using tabletop exercises at all levels of operations and management, Thornton-Trump adds. “Have a plan that includes cyber-incident responders on retainer and cybersecurity contacts in other companies in your industry vertical – and identify reinforcements and additional resources if you need them. Prolonged downtime of any sort – cyber or otherwise – is avoidable, predictable, and recoverable.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/cyber-attacks/iran-power-plant-closure-is-a-warning-to-all-businesses-how-to-respond</link>
                                                                            <description>
                            <![CDATA[ After the first attack of its kind, how big is the risk, who does it impact, and how should firms react? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fa9Y6as2Cis8apnLttdDXF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gAZQGXquzahjQHwSbSp9WN-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Sep 2026 07:00:00 +0000</pubDate>                                                                                                                                <updated>Tue, 08 Sep 2026 10:07:02 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kate O&#039;Flaherty ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LUULv6n7VJ3BHPnaoLHHdg-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gAZQGXquzahjQHwSbSp9WN-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Neon blue padlock with code flowing over it, floating above small plinths raised at different heights, each with code underneath their platforms]]></media:description>                                                            <media:text><![CDATA[Neon blue padlock with code flowing over it, floating above small plinths raised at different heights, each with code underneath their platforms]]></media:text>
                                <media:title type="plain"><![CDATA[Neon blue padlock with code flowing over it, floating above small plinths raised at different heights, each with code underneath their platforms]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gAZQGXquzahjQHwSbSp9WN-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In August, it emerged that a small UK power plant was shut down for four days following a <a href="https://www.itpro.com/security/cyber-attacks/iranian-cyber-attack-on-uk-power-plant-should-concern-every-organization-responsible-for-keeping-this-country-running"><u>cyber attack</u></a> attributed to <a href="https://www.itpro.com/security/cyber-attacks/the-iran-cyber-threat"><u>Iranian hackers</u></a>. It follows multiple <a href="https://www.itpro.com/security/cyber-attacks/attacks-on-us-water-systems-could-be-the-tip-of-the-iceberg-cyber-experts-warn"><u>attacks on water facilities</u></a> in the US, which reports indicate are linked to the latest incident.</p><p>Not much is known about the UK power plant breach, with the government declining to reveal exactly where it took place. It has confirmed the incident involved a small-scale generator, and that the wider energy system was never at risk.</p><p>But a key technical detail is still withheld about whether control systems were directly affected, or if the plant was disconnected merely as a precaution while IT contained the infiltration.</p><p>After the first of its kind attack, the government has written to businesses with advice on the steps they should take to protect themselves. How big is the risk, who does it impact, and how should firms react?</p><h2 id="major-escalation">Major escalation </h2><p>The latest attack is “a major escalation” from the recent campaign targeting water facilities in the US, says Markus Mueller, field CISO at Nozomi Networks. </p><p>He says attacks on peaker plants like this – which are designed to provide power when needed – can be more dangerous because “things happen fast, there is no buffer, and there can be major impacts”.</p><p>Critical national infrastructure is also vulnerable because it often uses legacy technology never meant to be connected to the internet. In the latest incident, the attack path involved a <a href="https://www.itpro.com/security/cyber-attacks/security-researchers-warn-of-ai-powered-plc-attacks-in-wake-of-siemens-advisories"><u>programmable logic controller</u></a> (PLC) that was not secured following basic best practices. </p><p>“If current reporting is correct, this was a publicly exposed PLC that was impacted similarly to what we have seen at US water utilities, where the threat group scans the internet for exposed PLCs using AI-generated scripts,” Mueller tells <em>ITPro</em>.</p><p>The attacker then logs into the PLCs using default credentials and proceeds to take them offline by resetting the programming and changing the password and IP address, “making it inaccessible”, explains Mueller. </p><h2 id="a-risk-beyond-cni">A risk beyond CNI</h2><p>The risk goes beyond critical sectors, into the supply chain, other industries, and to firms that rely on the breached organization.</p><p>While this incident occurred at a power plant, this is also “a clear warning” for “non-utility commercial sectors”, says Mueller. </p><p>He points out that automated scanning scripts used by adversaries “do not differentiate between a power generator, a manufacturing plant, a logistics warehouse, or smart building management systems”. </p><p>Any business relying on connected physical systems or industrial controls is at risk. At the same time, <a href="https://www.itpro.com/security/why-is-supply-chain-resilience-under-the-spotlight"><u>supply chain</u></a> partners and third-party maintenance contractors with remote access into operational technology (OT) environments represent “a major attack vector that adversaries are actively targeting to move laterally into enterprise networks”, says Mueller.</p><p>The risk extends “well beyond” large, regulated energy operators, agrees Martin Riley, CTO at Bridewell. </p><p>He describes how the UK’s energy system is becoming more distributed, with growing reliance on smaller peaker plants, renewable generators, battery storage and other remotely operated assets. </p><p>“Individually, these facilities may represent a small proportion of national capacity, but collectively they are becoming an essential part of how the grid operates,” says Riley.</p><p>“That creates a particular challenge because smaller operators and suppliers may fall outside the regulatory thresholds applied to traditional critical infrastructure, while still having connectivity into systems and services the country depends on.”</p><p>At the same time, James Neilson, SVP of global at OPSWAT, says it is “a lucky escape” that this attack happened at a small power plant and didn’t impact the UK’s wider energy system. </p><p>“<a href="https://www.itpro.com/security/cyber-attacks/crink-attacks-nation-state-hackers--threat-2026"><u>Hostile actors</u></a> now routinely target the UK using cyber attacks, undermining security, the economy and public trust. This form of grey-zone warfare has been present for at least a decade, but sub-threshold activity has increased sharply in recent years.”</p><h2 id="resilience-measures">Resilience measures</h2><p>Following the power plant attack, the UK government and National Cyber Security Center have actively urged organizations running critical infrastructure and industrial facilities to audit internet-facing devices and enforce cyber hygiene. </p><p>“The guidance emphasizes immediately identifying and pulling exposed OT and PLCs off the public internet, eliminating default vendor passwords and enforcing <a href="https://www.itpro.com/technology/how-to-choose-the-best-mfa-methods"><u>multi-factor authentication</u></a> for remote management connections,” explains Mueller.</p><p>At this stage, the most important lesson is “understanding asset exposure, attack paths, and the operational consequences of unauthorized access to industrial control systems”, according to Mueller.</p><p><a href="https://www.itpro.com/security/data-breaches/businesses-need-to-boost-cyber-resilience-heres-how"><u>Resilience</u></a> starts with “understanding how an attacker could move through the organization” and “ensuring a compromise in one part of the environment cannot easily reach systems responsible for physical operations”, says Riley. </p><p>For operational environments, that means strong IT and OT segmentation, tightly controlled remote access and “security controls proportionate to the potential consequences of an incident”, he advises.</p><p>Organizations also need visibility across IT and OT. “If security monitoring operates separately, an attacker may be able to establish themselves in the corporate environment before moving towards operational systems without anyone seeing the complete picture,” warns Riley.</p><p>Know what exposed interfaces you have and harden these by using technology and architecture, advises Ian Thornton-Trump, CISO at Inversion6. </p><p>At the same time, use firewalls with access control and whitelisting capabilities to “ensure any exposed interfaces can only be connected to by specific IP addresses”, he adds.</p><p>Meanwhile, Thornton-Trump advises deploying deception technology to detect the early stages of an attack, including honeypots, as well as taking advantage of the <a href="https://www.ncsc.gov.uk/section/active-cyber-defence/early-warning?utm_source=Google&utm_medium=cpc&utm_campaign=NCSC+Always+On+Search+26&utm_content=EW&gad_source=1&gad_campaignid=24164180098&gbraid=0AAAAACafkIXIMz0NdMPIRtnIL5_4yCA2v&gclid=Cj0KCQjwteTUBhD4ARIsAEYjs3rKYgHyvnTCO_nwP-kaaKHA4eL9O7kDuYTVsEqS606SpC6YLLx_80UaArqYEALw_wcB"><u>NCSC’s early warning</u></a> service.</p><p>It’s also important to know the enemy you are facing. For example, Iranian and other nation-state groups will often hunt out default credentials immediately to achieve “rapid, low-noise access”, says Neilson. </p><p>With this in mind, he advises “assessing and hardening critical systems and infrastructure considering the latest attacks”.</p><p>Firms should train for incident response using tabletop exercises at all levels of operations and management, Thornton-Trump adds. “Have a plan that includes cyber-incident responders on retainer and cybersecurity contacts in other companies in your industry vertical – and identify reinforcements and additional resources if you need them. Prolonged downtime of any sort – cyber or otherwise – is avoidable, predictable, and recoverable.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Achieving agility: Converting technology transformation into channel opportunities ]]></title>
                                                                                                <dc:content><![CDATA[ <p>In recent years, there have been tremendous technology developments and industry shifts. The rapid adoption of generative AI has been a significant disruptor, forcing both vendors and the channel to re-evaluate their offerings and take a more agile stance to expand market reach and boost operational efficiency. </p><p></p><p>New business opportunities are being driven by trends such as AI storage integration, cloud sovereignty, and the demand for proactive cybersecurity measures. However, given this rapid pace of change, with some partners still focused on legacy resale and non-proactive, break-fix models, are resellers really in a prime position for success? </p><p>The biggest trap channel partners could fall into is failing to recognise new opportunities and respond with agility. With AI-driven workflows, regulations, and shifting buyer expectations, those who stick to old approaches risk being sidelined and seeing their margins shrink.</p><h2 id="key-industry-and-technology-shifts">Key industry and technology shifts</h2><p>Major trends reshaping the channel landscape include the integration of AI with storage infrastructures, the rise of sovereign clouds for data compliance, and the development of advanced data protection platforms. </p><p>Another area we see skyrocketing is the edge-cloud-hybrid ecosystem. Organizations are seeking to operate across edge, on-premises, and public/hybrid cloud with seamless data mobility and unified management. With multi-cloud and hybrid architectures becoming the norm, especially for backup and disaster recovery (DR), scalability and cost control remain paramount issues for organizations. </p><p>Equally apparent is the need for consistent security and compliance measures across these environments, along with ensuring flexibility to prevent reliance on a single vendor. Data sovereignty, which requires that data be governed by the laws and regulations of the country where it is stored or processed, marks a shift away from generic cloud-first strategies towards more localized management, hybrid-cloud arrangements, and thorough sovereignty evaluations. </p><p>With organizations struggling to balance increasing data volumes against rising infrastructure costs, there is also growth in smart multi-tiered storage. This includes storage analytics and tools for real-time monitoring and automated management to enable visibility across different tiers. With the capability to assign "hot" or frequently accessed data to high-speed, premium storage and "cold" or archival data to more affordable options, organizations can avoid the costly mistake of over-provisioning with high-performance drives.</p><p>Meanwhile, legacy hardware sales and on-prem-only solutions will continue their sharp decline, falling short for partners who rely on them. The shift to cloud and as-a-service models, combined with economic pressures, has made this a low-margin area.</p><h2 id="channel-opportunities-for-business-growth">Channel opportunities for business growth</h2><p>As global data volumes near 200 zettabytes and AI-native technologies become increasingly sophisticated, customers are demanding comprehensive services that extend beyond traditional project-based hardware or standard cybersecurity offerings. </p><p></p><p>Customers are seeking partners who can provide AI-ready, sovereign, and resilient data protection that works seamlessly across on-prem, edge, and cloud.  With this in mind, key growth areas for the channel are:</p><p><strong>AI-driven services and automation </strong></p><p>Cyber-resilient data storage solutions and integrated, AI-powered security platforms are driving significant growth opportunities for channel partners. These companies can tap into new opportunities by providing services focused on AI integration that extend beyond just implementing AI tools. These offerings may include automating IT operations, AI monitoring, and intelligence in data protection. </p><p>The recent geopolitical shift created by the U.S. government’s unprecedented <a href="https://fortune.com/2026/06/16/anthropic-shutdown-sparks-global-scramble-for-sovereign-ai/"><u>export-control directive</u></a> - which restricts global access to the most powerful AI models developed by Anthropic (the prominent US-based AI research and safety company) - has created immediate channel opportunities. If Value-added Resellers (VARs) and Managed Service Providers (MSPs) pivot quickly, they can offer services such as sovereign AI consulting (providing data residency, technological autonomy, and jurisdictional control), regional cloud hosting with sovereign cloud space, as well as advisory services on cross-border regulatory compliance, such as offering risk mitigation audits. </p><p><strong>Hybrid-managed offerings</strong></p><p>Customers are increasingly adopting multi-tiered architectures that integrate edge computing, on-premises systems, and public cloud solutions. This shift calls for seamless data mobility, unified management, and real-time analytics to ensure efficiency. For channel partners, this trend opens new opportunities for designing, managing, and securing these distributed, complex environments.</p><p>The ubiquity of cloud has highlighted a challenge: the importance of operational visibility. Managing data across multiple environments without a unified dashboard has introduced unnecessary complexity and increased the risk of security blind spots. The lack of visibility across edge-cloud-hybrid ecosystems presents an opportunity for partners to act as trusted advisors while also delivering unified management and monitoring across fragmented infrastructures. </p><p><strong>Cybersecurity and compliance-as-a-service</strong></p><p>Cybersecurity continues to be the foremost<a href="https://www.gov.uk/government/publications/cyber-security-sectoral-analysis-2026/cyber-security-sectoral-analysis-2026"><u> growth driver</u></a> for the channel. Providers are already broadening their offerings to counter the rising frequency of cyberattacks, introducing services such as managed detection and response (MDR), ransomware protection strategies, and compliance solutions. With the emergence of AI-driven threats, there is a growing demand for integrated cyber recovery solutions, presenting lucrative opportunities for partners capable of delivering robust managed security services.</p><p>Many opportunities will come from customers who are ready to adopt AI-powered infrastructures and hybrid governance models (the framework that enables managing operations across both physical offices and remote endpoints) in response to data sovereignty pressures. As organizations incorporate AI into their operations, they must address increased security vulnerabilities while ensuring their workloads and data adhere to relevant jurisdictional and privacy laws. Therefore, partners who can offer high-value consulting, data auditing, automation, and managed services, as well as architecting hybrid or sovereign cloud environments, will see the most growth. </p><h2 id="potential-challenges">Potential challenges </h2><p>Obstacles to capitalizing on opportunities in the AI era include a lack of sufficient expertise (the talent gap) and longer sales cycles. The channel could struggle to find people who can manage hybrid ecosystems, navigate compliance, and handle the complexity of AI-driven environments. This is an area where vendors can really add value, especially in helping partners bridge that gap with hands-on training, workshops, and webinars.</p><p>Another hurdle is that most customers, especially outside the enterprise segment, will face tighter budgets and more cautious spending, which could slow adoption and delay new projects.</p><p>There could also be setbacks resulting from vendor complexity, too many tools, programs, and licensing models, which could further slow down the momentum if not simplified early in the year.</p><h2 id="the-path-to-success">The path to success </h2><p>To embrace these new opportunities, the channel must anticipate changes among customers, vendors, and markets. Buying technology is no longer what customers are looking for; they want solutions that deliver resilience, compliance, and sustainability. The channel must move from being generalists to specialists, guiding and supporting customers and accelerating the shift to service-led models in areas like AI and cybersecurity (such as delivering Backup-as-a-Service and cyber recovery).</p><p>Meanwhile, vendors must support this shift by making things easier: offering flexible licensing, providing specialised training and integration tools, and driving closer collaboration with partners. Vendors will also be expected to simplify hybrid and sovereign architectures, provide automation tools, and jointly develop go-to-market initiatives that help partners scale their operations.</p><p>The current industry transformation presents a huge opportunity for channel businesses to shift from just reselling to delivering high-value, integrated solutions. As the rise of AI-native and autonomous storage creates a demand for consulting and managed services, clients will most definitely need expert guidance to implement and manage these complex systems.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/business/business-strategy/achieving-agility-converting-technology-transformation-into-channel-opportunities</link>
                                                                            <description>
                            <![CDATA[ How partners can embrace new growth opportunities in times of technological change ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QeGdKXm69Cq2B5e6UWaKuP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/aAeKTUp9Rq5AaMCtoaJ3AM-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Business Strategy]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Anton Shelepchuk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/7ryN3xabPyem7AVNgVMGpV-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/aAeKTUp9Rq5AaMCtoaJ3AM-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Male and female data engineers discussing strategy and work activities in an office space with sticky notes on a wall in the background.]]></media:description>                                                            <media:text><![CDATA[Male and female data engineers discussing strategy and work activities in an office space with sticky notes on a wall in the background.]]></media:text>
                                <media:title type="plain"><![CDATA[Male and female data engineers discussing strategy and work activities in an office space with sticky notes on a wall in the background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/aAeKTUp9Rq5AaMCtoaJ3AM-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In recent years, there have been tremendous technology developments and industry shifts. The rapid adoption of generative AI has been a significant disruptor, forcing both vendors and the channel to re-evaluate their offerings and take a more agile stance to expand market reach and boost operational efficiency. </p><p></p><p>New business opportunities are being driven by trends such as AI storage integration, cloud sovereignty, and the demand for proactive cybersecurity measures. However, given this rapid pace of change, with some partners still focused on legacy resale and non-proactive, break-fix models, are resellers really in a prime position for success? </p><p>The biggest trap channel partners could fall into is failing to recognise new opportunities and respond with agility. With AI-driven workflows, regulations, and shifting buyer expectations, those who stick to old approaches risk being sidelined and seeing their margins shrink.</p><h2 id="key-industry-and-technology-shifts">Key industry and technology shifts</h2><p>Major trends reshaping the channel landscape include the integration of AI with storage infrastructures, the rise of sovereign clouds for data compliance, and the development of advanced data protection platforms. </p><p>Another area we see skyrocketing is the edge-cloud-hybrid ecosystem. Organizations are seeking to operate across edge, on-premises, and public/hybrid cloud with seamless data mobility and unified management. With multi-cloud and hybrid architectures becoming the norm, especially for backup and disaster recovery (DR), scalability and cost control remain paramount issues for organizations. </p><p>Equally apparent is the need for consistent security and compliance measures across these environments, along with ensuring flexibility to prevent reliance on a single vendor. Data sovereignty, which requires that data be governed by the laws and regulations of the country where it is stored or processed, marks a shift away from generic cloud-first strategies towards more localized management, hybrid-cloud arrangements, and thorough sovereignty evaluations. </p><p>With organizations struggling to balance increasing data volumes against rising infrastructure costs, there is also growth in smart multi-tiered storage. This includes storage analytics and tools for real-time monitoring and automated management to enable visibility across different tiers. With the capability to assign "hot" or frequently accessed data to high-speed, premium storage and "cold" or archival data to more affordable options, organizations can avoid the costly mistake of over-provisioning with high-performance drives.</p><p>Meanwhile, legacy hardware sales and on-prem-only solutions will continue their sharp decline, falling short for partners who rely on them. The shift to cloud and as-a-service models, combined with economic pressures, has made this a low-margin area.</p><h2 id="channel-opportunities-for-business-growth">Channel opportunities for business growth</h2><p>As global data volumes near 200 zettabytes and AI-native technologies become increasingly sophisticated, customers are demanding comprehensive services that extend beyond traditional project-based hardware or standard cybersecurity offerings. </p><p></p><p>Customers are seeking partners who can provide AI-ready, sovereign, and resilient data protection that works seamlessly across on-prem, edge, and cloud.  With this in mind, key growth areas for the channel are:</p><p><strong>AI-driven services and automation </strong></p><p>Cyber-resilient data storage solutions and integrated, AI-powered security platforms are driving significant growth opportunities for channel partners. These companies can tap into new opportunities by providing services focused on AI integration that extend beyond just implementing AI tools. These offerings may include automating IT operations, AI monitoring, and intelligence in data protection. </p><p>The recent geopolitical shift created by the U.S. government’s unprecedented <a href="https://fortune.com/2026/06/16/anthropic-shutdown-sparks-global-scramble-for-sovereign-ai/"><u>export-control directive</u></a> - which restricts global access to the most powerful AI models developed by Anthropic (the prominent US-based AI research and safety company) - has created immediate channel opportunities. If Value-added Resellers (VARs) and Managed Service Providers (MSPs) pivot quickly, they can offer services such as sovereign AI consulting (providing data residency, technological autonomy, and jurisdictional control), regional cloud hosting with sovereign cloud space, as well as advisory services on cross-border regulatory compliance, such as offering risk mitigation audits. </p><p><strong>Hybrid-managed offerings</strong></p><p>Customers are increasingly adopting multi-tiered architectures that integrate edge computing, on-premises systems, and public cloud solutions. This shift calls for seamless data mobility, unified management, and real-time analytics to ensure efficiency. For channel partners, this trend opens new opportunities for designing, managing, and securing these distributed, complex environments.</p><p>The ubiquity of cloud has highlighted a challenge: the importance of operational visibility. Managing data across multiple environments without a unified dashboard has introduced unnecessary complexity and increased the risk of security blind spots. The lack of visibility across edge-cloud-hybrid ecosystems presents an opportunity for partners to act as trusted advisors while also delivering unified management and monitoring across fragmented infrastructures. </p><p><strong>Cybersecurity and compliance-as-a-service</strong></p><p>Cybersecurity continues to be the foremost<a href="https://www.gov.uk/government/publications/cyber-security-sectoral-analysis-2026/cyber-security-sectoral-analysis-2026"><u> growth driver</u></a> for the channel. Providers are already broadening their offerings to counter the rising frequency of cyberattacks, introducing services such as managed detection and response (MDR), ransomware protection strategies, and compliance solutions. With the emergence of AI-driven threats, there is a growing demand for integrated cyber recovery solutions, presenting lucrative opportunities for partners capable of delivering robust managed security services.</p><p>Many opportunities will come from customers who are ready to adopt AI-powered infrastructures and hybrid governance models (the framework that enables managing operations across both physical offices and remote endpoints) in response to data sovereignty pressures. As organizations incorporate AI into their operations, they must address increased security vulnerabilities while ensuring their workloads and data adhere to relevant jurisdictional and privacy laws. Therefore, partners who can offer high-value consulting, data auditing, automation, and managed services, as well as architecting hybrid or sovereign cloud environments, will see the most growth. </p><h2 id="potential-challenges">Potential challenges </h2><p>Obstacles to capitalizing on opportunities in the AI era include a lack of sufficient expertise (the talent gap) and longer sales cycles. The channel could struggle to find people who can manage hybrid ecosystems, navigate compliance, and handle the complexity of AI-driven environments. This is an area where vendors can really add value, especially in helping partners bridge that gap with hands-on training, workshops, and webinars.</p><p>Another hurdle is that most customers, especially outside the enterprise segment, will face tighter budgets and more cautious spending, which could slow adoption and delay new projects.</p><p>There could also be setbacks resulting from vendor complexity, too many tools, programs, and licensing models, which could further slow down the momentum if not simplified early in the year.</p><h2 id="the-path-to-success">The path to success </h2><p>To embrace these new opportunities, the channel must anticipate changes among customers, vendors, and markets. Buying technology is no longer what customers are looking for; they want solutions that deliver resilience, compliance, and sustainability. The channel must move from being generalists to specialists, guiding and supporting customers and accelerating the shift to service-led models in areas like AI and cybersecurity (such as delivering Backup-as-a-Service and cyber recovery).</p><p>Meanwhile, vendors must support this shift by making things easier: offering flexible licensing, providing specialised training and integration tools, and driving closer collaboration with partners. Vendors will also be expected to simplify hybrid and sovereign architectures, provide automation tools, and jointly develop go-to-market initiatives that help partners scale their operations.</p><p>The current industry transformation presents a huge opportunity for channel businesses to shift from just reselling to delivering high-value, integrated solutions. As the rise of AI-native and autonomous storage creates a demand for consulting and managed services, clients will most definitely need expert guidance to implement and manage these complex systems.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why the MSSP model is broken, and how to fix it ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Can small Managed Security Service Providers (MSSPs) outcompete the world’s biggest Systems Integrators (SIs)? It might sound like a fool’s errand. But SIs have a glaring weakness: a generic, heavily standardized approach that fails to move in step with the rapidly evolving threat landscape. There’s an opportunity for smaller, more agile MSSPs, if they’re bold enough to take it.</p><p>Unfortunately, many are failing to take advantage. In fact, they’re making it harder for CISOs to differentiate their offerings by citing inaccurate metrics. These do nothing but confuse prospective customers. But for those MSSPs willing to go against the status quo, the market is there for the taking.</p><h2 id="why-bigger-doesn-t-mean-better-in-cybersecurity">Why bigger doesn’t mean better in cybersecurity</h2><p>The threat landscape stands still for no one. Over the past couple of years, we’ve witnessed an unprecedented weaponization of new technologies by threat actors. AI is being used in victim reconnaissance, social engineering, malware generation, and vulnerability research and exploit development. </p><p>According to <a href="https://www.verizon.com/business/resources/T1f0/reports/2026-dbir-data-breach-investigations-report.pdf"><u>Verizon</u></a>, the median threat actor researched or used AI assistance in 15 different documented techniques last year, with some using as many as 50. <a href="https://labs.cloudsecurityalliance.org/research/csa-whitepaper-collapsing-exploit-window-ai-mtte-20260411-cs/"><u>Researchers are warning</u></a> that the exploitation window is collapsing as a result. <a href="https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026"><u>Google’s most recent M-Trends report</u></a> puts mean-time-to-exploitation at less than seven days. </p><p>This means that SecOps teams live in a world of constant flux. One in which continuous improvements need to be made to the SOC — to swap in and out services and evaluate and reevaluate vendors in order to maintain a good security posture. Now think of a typical SI. They may have deep domain knowledge and plenty of smart people on the books. But their business model is scale, not agility. In fact, they tend to charge punitive fees for any change requests outside the original scope of work.</p><p>Rigid contracts and multiple management layers are a recipe for inertia. That’s bad news for CISO customers at a time when IT infrastructure and threat actor innovation are moving at pace. If you can’t afford to mitigate new risks around agentic AI data leakage or prompt injection, what do you do? Delay investment in the technology? Or accept increased risk? There are no good options.  </p><h2 id="missing-an-open-goal">Missing an open goal</h2><p>This business opportunity should be an open goal for MSSPs. But the truth is that many also adopt a cookie-cutter approach in order to efficiently service as wide a bank of customers as possible. This ultimately erodes the value of a potentially powerful differentiator.</p><p>They make things worse by resorting to disingenuous tricks to outcompete their rivals. They might claim to respond to alerts within 30 minutes, for example. But in reality, that metric is only applied to critical-severity alerts. Those deemed less urgent may take many more hours to respond to. That’s not only insincere. It could be a major security risk at a time when attackers go to deliberate lengths to hide in low-level activity. It’s critically important to spot and stop living-off-the-land techniques like these before they escalate.</p><p>There’s more. It’s also become accepted industry practice today for MSSPs to include automatically assigned and closed alerts when working out Mean Time to Acknowledge (MTTA) and Mean Time to Close (MTTC) — artificially shrinking these values. MSSPs may exclude alerts that weren’t handled within SLA parameters, like those at the weekend. And they may even reset the clock when an alert is escalated between tiers, to make it appear as if SLA targets were met.</p><p>This isn’t just bad practice. It means CISOs can no longer trust the sales pitch. That’s bad news for those who operate differently.</p><h2 id="honesty-and-agility">Honesty and agility</h2><p>Yet if they can get their message out, there is an opportunity for more dynamic MSSPs. They must be honest about SLAs, clearly define the terminology they use, and resist the urge to manipulate metrics. But just as importantly, they should offer services that move in step with the needs of their customers and the changing nature of the threat landscape, to outcompete their larger SI rivals.</p><p>It can be done. Think: red teaming for rogue behavior. Continuous risk reporting that maps findings to best-practice compliance standards. And AI posture management that integrates with SOC playbooks and exposure management dashboards to mitigate risk across the AI attack surface.</p><p>There are some fantastic solution providers out there offering cutting-edge capabilities—from real-time runtime detection to observability and model provenance checks. But no single vendor offers the whole package a SOC needs. That’s where the MSSP can add value. It’s about continuously evaluating what’s out there on the market, and integrating it into a seamless, 24/7 managed service offering. </p><h2 id="protection-for-today-and-tomorrow">Protection for today and tomorrow</h2><p>The MSSP space has never been more important for customers. The accelerating pace of industry regulation, infrastructure, and threat innovation is a testament to that. </p><p>For IT security leaders, the question to ask is not just whether your service provider is good enough right now. It’s whether they have a convincing vision of where security is heading in the future. </p><p>For many organizations, that’s not going to be an SI where only 80% of what they do might be “good enough.” In cyber, 80% is no longer good enough. CISOs need a more dynamic partner to protect their business: for today and tomorrow.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/why-the-mssp-model-is-broken-and-how-to-fix-it</link>
                                                                            <description>
                            <![CDATA[ CISOs are struggling to differentiate between MSSPs due to confusing metrics and SLAs ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">WMGQNfGDo8Dv973X4k2ap7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/b3uNg73ogqmmGDNjaScXE3-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 21:33:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Martin Jakobsen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/5WF2fD8fctFhUR7Zg5UeNm-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Martin Jakobsen is the managing director of Cybanetix and brings over 20 years of experience delivering NOC and SOC services to a wide range of customers. &lt;/p&gt;&lt;p&gt;At Cybanetix, Martin has overseen the company’s growth into a trusted MDR specialist supporting clients across multiple sectors, including large-scale enterprises and public sector organizations. Martin remains focused on expanding Cybanetix’s capabilities and its use of advanced, AI-enabled security operations to deliver practical, intelligence-driven services. &lt;/p&gt;&lt;p&gt;Before Cybanetix, Martin served as managing director of Capita Cyber Security and holds board positions at KonsensIT A/S and CapMon A/S, contributing his expertise in governance and strategic growth.  &lt;/p&gt;&lt;p&gt;He has played a central role in the design and build of some of the UK’s largest government networks and has provided outsourced security operations to multinational enterprises. His combination of technical expertise and leadership has enabled organizations to strengthen their defences and run more resilient security operations. &lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/b3uNg73ogqmmGDNjaScXE3-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Password security concept image showing person logging into an account on a laptop while using password manager authenticator on smartphone.]]></media:description>                                                            <media:text><![CDATA[Password security concept image showing person logging into an account on a laptop while using password manager authenticator on smartphone.]]></media:text>
                                <media:title type="plain"><![CDATA[Password security concept image showing person logging into an account on a laptop while using password manager authenticator on smartphone.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/b3uNg73ogqmmGDNjaScXE3-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Can small Managed Security Service Providers (MSSPs) outcompete the world’s biggest Systems Integrators (SIs)? It might sound like a fool’s errand. But SIs have a glaring weakness: a generic, heavily standardized approach that fails to move in step with the rapidly evolving threat landscape. There’s an opportunity for smaller, more agile MSSPs, if they’re bold enough to take it.</p><p>Unfortunately, many are failing to take advantage. In fact, they’re making it harder for CISOs to differentiate their offerings by citing inaccurate metrics. These do nothing but confuse prospective customers. But for those MSSPs willing to go against the status quo, the market is there for the taking.</p><h2 id="why-bigger-doesn-t-mean-better-in-cybersecurity">Why bigger doesn’t mean better in cybersecurity</h2><p>The threat landscape stands still for no one. Over the past couple of years, we’ve witnessed an unprecedented weaponization of new technologies by threat actors. AI is being used in victim reconnaissance, social engineering, malware generation, and vulnerability research and exploit development. </p><p>According to <a href="https://www.verizon.com/business/resources/T1f0/reports/2026-dbir-data-breach-investigations-report.pdf"><u>Verizon</u></a>, the median threat actor researched or used AI assistance in 15 different documented techniques last year, with some using as many as 50. <a href="https://labs.cloudsecurityalliance.org/research/csa-whitepaper-collapsing-exploit-window-ai-mtte-20260411-cs/"><u>Researchers are warning</u></a> that the exploitation window is collapsing as a result. <a href="https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026"><u>Google’s most recent M-Trends report</u></a> puts mean-time-to-exploitation at less than seven days. </p><p>This means that SecOps teams live in a world of constant flux. One in which continuous improvements need to be made to the SOC — to swap in and out services and evaluate and reevaluate vendors in order to maintain a good security posture. Now think of a typical SI. They may have deep domain knowledge and plenty of smart people on the books. But their business model is scale, not agility. In fact, they tend to charge punitive fees for any change requests outside the original scope of work.</p><p>Rigid contracts and multiple management layers are a recipe for inertia. That’s bad news for CISO customers at a time when IT infrastructure and threat actor innovation are moving at pace. If you can’t afford to mitigate new risks around agentic AI data leakage or prompt injection, what do you do? Delay investment in the technology? Or accept increased risk? There are no good options.  </p><h2 id="missing-an-open-goal">Missing an open goal</h2><p>This business opportunity should be an open goal for MSSPs. But the truth is that many also adopt a cookie-cutter approach in order to efficiently service as wide a bank of customers as possible. This ultimately erodes the value of a potentially powerful differentiator.</p><p>They make things worse by resorting to disingenuous tricks to outcompete their rivals. They might claim to respond to alerts within 30 minutes, for example. But in reality, that metric is only applied to critical-severity alerts. Those deemed less urgent may take many more hours to respond to. That’s not only insincere. It could be a major security risk at a time when attackers go to deliberate lengths to hide in low-level activity. It’s critically important to spot and stop living-off-the-land techniques like these before they escalate.</p><p>There’s more. It’s also become accepted industry practice today for MSSPs to include automatically assigned and closed alerts when working out Mean Time to Acknowledge (MTTA) and Mean Time to Close (MTTC) — artificially shrinking these values. MSSPs may exclude alerts that weren’t handled within SLA parameters, like those at the weekend. And they may even reset the clock when an alert is escalated between tiers, to make it appear as if SLA targets were met.</p><p>This isn’t just bad practice. It means CISOs can no longer trust the sales pitch. That’s bad news for those who operate differently.</p><h2 id="honesty-and-agility">Honesty and agility</h2><p>Yet if they can get their message out, there is an opportunity for more dynamic MSSPs. They must be honest about SLAs, clearly define the terminology they use, and resist the urge to manipulate metrics. But just as importantly, they should offer services that move in step with the needs of their customers and the changing nature of the threat landscape, to outcompete their larger SI rivals.</p><p>It can be done. Think: red teaming for rogue behavior. Continuous risk reporting that maps findings to best-practice compliance standards. And AI posture management that integrates with SOC playbooks and exposure management dashboards to mitigate risk across the AI attack surface.</p><p>There are some fantastic solution providers out there offering cutting-edge capabilities—from real-time runtime detection to observability and model provenance checks. But no single vendor offers the whole package a SOC needs. That’s where the MSSP can add value. It’s about continuously evaluating what’s out there on the market, and integrating it into a seamless, 24/7 managed service offering. </p><h2 id="protection-for-today-and-tomorrow">Protection for today and tomorrow</h2><p>The MSSP space has never been more important for customers. The accelerating pace of industry regulation, infrastructure, and threat innovation is a testament to that. </p><p>For IT security leaders, the question to ask is not just whether your service provider is good enough right now. It’s whether they have a convincing vision of where security is heading in the future. </p><p>For many organizations, that’s not going to be an SI where only 80% of what they do might be “good enough.” In cyber, 80% is no longer good enough. CISOs need a more dynamic partner to protect their business: for today and tomorrow.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Agents on the frontline: How Box is using AI to supercharge cybersecurity ]]></title>
                                                                                                <dc:content><![CDATA[ <iframe allow="clipboard-write" height="200px" width="100%" id="" style="width: 100%; height: 200px;" class="position-center" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/6084320f-0c67-458f-913d-9021d1e8250a"></iframe><p>Findings from Box’s State of AI in the Enterprise survey show 83% of enterprises are now running agents in some capacity. </p><p>These bots are enabling teams to drive productivity and efficiency, but as with any new technology, integration can be a challenge - and a security risk. Recent agent-related incidents in the tech industry have sparked concerns about long-term security implications. </p><p>In this week’s episode of the ITPro Podcast, Ross Kelly and Bobby Hellard speak with Box CISO Heather Ceylan to discuss how Box is using agents internally, and how enterprises can adopt the technology in a safe and secure manner. </p><h2 id="highlights-2">Highlights</h2><p>“I think for security teams, we can finally, you know, start having the capacity to outpace these attackers. So we've got five core areas of investment for agents for our security team in particular that we've invested in over probably the last year, and we're starting to measure ROI on those right now. </p><p>“So the first one is in the SOC. I think that's probably the most obvious choice where we've got a lot of operational work. We see the same kinds of incidents. We're automating the triage, we're automating the enrichment, the log correlation, things like that that take a lot of human effort. </p><p>“But there's still human judgment in the end in terms of what gets escalated to be an incident and what doesn't.”</p><p><strong>Moving fast in the age of agentic AI</strong></p><p>“We're not going to be able to move fast enough. So, we have agents kind of built throughout our software development process, doing those security design and architecture reviews, and if you think about it, it’s way more powerful than a human can be because those agents don't just necessarily call out design flaws; they can enforce fixes for those flaws.”</p><p>“Things are changing quickly. Sometimes it feels like you take two steps forward and then you read something in the news and you're like, oh my gosh, we need to rethink everything. </p><p>“So I think a lot of security teams are really feeling that now and getting a little bit of fatigue from that.“</p><p><strong>The benefits of a multi-model approach</strong></p><p>“One of the things that we're trying to carry across all of these that I wasn't really thinking about a year ago, but I'm thinking a lot about now is having that multi-model approach.</p><p>“We're not in a place where most of the work we do, we can't be reliant on a single model. If you look at vulnerability discovery, we're moving away from being tied to any one specific vendor or any one specific model because you're going to get better results when you take a multi-model approach.”</p><h2 id="related-content">Related content</h2><ul><li><a href="https://www.box.com/en-gb/state-of-ai" target="_blank">The State of AI in the Enterprise report (Box)</a></li><li><a href="https://www.boxinvestorrelations.com/news-and-media/news/press-release-details/2026/Box-Unveils-New-Controls-to-Secure-AI-Agents-Operating-Across-Enterprise-Content/default.aspx">Box unveils new controls to secure AI agents</a></li><li><a href="https://www.itpro.com/security/an-unprecedented-cyber-incident-how-openai-models-breached-hugging-face-and-why-it-could-herald-a-new-phase-of-ai-powered-cyber-crime" target="_blank">How OpenAI models breached Hugging Face</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/the-openai-and-anthropic-containment-breaches-are-a-bit-spooky-but-also-quite-silly">The OpenAI and Anthropic containment breaches are a bit spooky, but also quite silly</a></li><li><a href="https://www.itpro.com/security/cisos-are-keen-on-agentic-ai-but-theyre-not-going-all-in-yet">CISOs are keen on agentic AI, but they’re not going all-in yet</a></li></ul> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/technology/artificial-intelligence/agents-on-the-frontline-how-box-is-using-ai-to-supercharge-cybersecurity</link>
                                                                            <description>
                            <![CDATA[ How can enterprises adopt AI agents in a safe and secure manner? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6i8mKeiENaFS2DBsncZKHE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BzVei4qzbpYpFzexqPAmLi-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 12:31:32 +0000</pubDate>                                                                                                                                <updated>Fri, 04 Sep 2026 15:27:47 +0000</updated>
                                                                                                                                            <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BzVei4qzbpYpFzexqPAmLi-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[&quot;Agents on the front line&quot; over some robot faces]]></media:description>                                                            <media:text><![CDATA[&quot;Agents on the front line&quot; over some robot faces]]></media:text>
                                <media:title type="plain"><![CDATA[&quot;Agents on the front line&quot; over some robot faces]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BzVei4qzbpYpFzexqPAmLi-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <iframe allow="clipboard-write" height="200px" width="100%" id="" style="width: 100%; height: 200px;" class="position-center" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/6084320f-0c67-458f-913d-9021d1e8250a"></iframe><p>Findings from Box’s State of AI in the Enterprise survey show 83% of enterprises are now running agents in some capacity. </p><p>These bots are enabling teams to drive productivity and efficiency, but as with any new technology, integration can be a challenge - and a security risk. Recent agent-related incidents in the tech industry have sparked concerns about long-term security implications. </p><p>In this week’s episode of the ITPro Podcast, Ross Kelly and Bobby Hellard speak with Box CISO Heather Ceylan to discuss how Box is using agents internally, and how enterprises can adopt the technology in a safe and secure manner. </p><h2 id="highlights-2">Highlights</h2><p>“I think for security teams, we can finally, you know, start having the capacity to outpace these attackers. So we've got five core areas of investment for agents for our security team in particular that we've invested in over probably the last year, and we're starting to measure ROI on those right now. </p><p>“So the first one is in the SOC. I think that's probably the most obvious choice where we've got a lot of operational work. We see the same kinds of incidents. We're automating the triage, we're automating the enrichment, the log correlation, things like that that take a lot of human effort. </p><p>“But there's still human judgment in the end in terms of what gets escalated to be an incident and what doesn't.”</p><p><strong>Moving fast in the age of agentic AI</strong></p><p>“We're not going to be able to move fast enough. So, we have agents kind of built throughout our software development process, doing those security design and architecture reviews, and if you think about it, it’s way more powerful than a human can be because those agents don't just necessarily call out design flaws; they can enforce fixes for those flaws.”</p><p>“Things are changing quickly. Sometimes it feels like you take two steps forward and then you read something in the news and you're like, oh my gosh, we need to rethink everything. </p><p>“So I think a lot of security teams are really feeling that now and getting a little bit of fatigue from that.“</p><p><strong>The benefits of a multi-model approach</strong></p><p>“One of the things that we're trying to carry across all of these that I wasn't really thinking about a year ago, but I'm thinking a lot about now is having that multi-model approach.</p><p>“We're not in a place where most of the work we do, we can't be reliant on a single model. If you look at vulnerability discovery, we're moving away from being tied to any one specific vendor or any one specific model because you're going to get better results when you take a multi-model approach.”</p><h2 id="related-content">Related content</h2><ul><li><a href="https://www.box.com/en-gb/state-of-ai" target="_blank">The State of AI in the Enterprise report (Box)</a></li><li><a href="https://www.boxinvestorrelations.com/news-and-media/news/press-release-details/2026/Box-Unveils-New-Controls-to-Secure-AI-Agents-Operating-Across-Enterprise-Content/default.aspx">Box unveils new controls to secure AI agents</a></li><li><a href="https://www.itpro.com/security/an-unprecedented-cyber-incident-how-openai-models-breached-hugging-face-and-why-it-could-herald-a-new-phase-of-ai-powered-cyber-crime" target="_blank">How OpenAI models breached Hugging Face</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/the-openai-and-anthropic-containment-breaches-are-a-bit-spooky-but-also-quite-silly">The OpenAI and Anthropic containment breaches are a bit spooky, but also quite silly</a></li><li><a href="https://www.itpro.com/security/cisos-are-keen-on-agentic-ai-but-theyre-not-going-all-in-yet">CISOs are keen on agentic AI, but they’re not going all-in yet</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Prepare to be dazzled by Lenovo's genuinely innovative ideas at IFA 2026 ]]></title>
                                                                                                <dc:content><![CDATA[ <p>IFA 2026 attendees are in for a treat when they come to the Lenovo stand. I know this because I have already been dazzled by the company's new products at its pre-IFA Innovation event in Berlin. </p><p>One of the biggest issues with IFA is that it's just a big convention center filled with showrooms. It's not really known for keynotes and presentations. You simply have to go and walk around the show floor to see new products and services. </p><p>That doesn't really suit tech companies like Lenovo, with their vast offerings and groundbreaking products. </p><p>And so, much like at <a href="https://www.itpro.com/technology/artificial-intelligence/lenovo-partnership-fifa-world-cup-ces-2026">CES earlier in the year</a>, Lenovo holds its own pre-conference, Lenovo Innovation World, in the same city. Journalists from all over the world are invited to stay in a hotel that also doubles as the event space. We get sneak peeks at the new products being launched, one-to-one time with Lenovo's execs, and also some partner-sponsored events (in this case Intel, AMD, and Nvidia). </p><p>But more than that, Innovation World is true to its name. What we get shown is innovative, whether it's colorful consumer laptops (<a href="https://www.itpro.com/hardware/laptops/the-lenovo-ideapad-vibe-is-a-colorful-assault-on-the-eyes-but-there-is-a-surprising-number-of-features-on-offer-here">IdeaPad Vibe</a>), AI developer-focused desktops (<a href="https://www.itpro.com/hardware/desktops/lenovo-aims-to-wow-developers-with-small-but-mighty-thinkcentre-desktops-at-ifa-2026">ThinkCentre X Ultra</a>), or even a stylus with unique controls (Yoga Tab Pro). </p><p>As its products show, Lenovo doesn't really like to stand still. Nothing is "business as usual". Everything has some new or untested feature. This doesn't mean it's all good; some of it may never be used again. But it's the bravery to try that makes it so interesting. </p><p>And it wouldn't be a Lenovo Innovation World without a <a href="https://www.itpro.com/hardware/lenovo-wows-at-mwc-with-concepts-for-a-modular-thinkbook-and-desktop-ai-devices">proof of concept</a>. For IFA there were two: one is Project Swan, a laptop with an expandable screen. The display slides outwards, growing from 14in to a 17in, similar to the <a href="https://www.itpro.com/hardware/laptops/lenovo-reveals-slick-rollable-screen-concept-and-a-voice-controlled-thinkbook-at-ces-2026-embargo-6th-jan-5pm-pst">rollable screen showcased at CES</a> earlier in the year. </p><p>The other concept, the more groundbreaking one, was Project AeroBlade. Essentially a fanless laptop that uses a vibrating membrane to push air out of the chassis. </p><p>Specifically, this is called the 'Active Flow Thermal Solution' and has been developed by a company called AirJet. The AirJet system replaces the traditional spinning blades with a slim 2.65mm chip that has an ultrasonic membrane. </p><p>This vibrates and pulls air through the device, and then ejects it through tiny slits at the back of the chassis. Without the need for fans and heatsinks, the AreoBlade is one of the thinnest laptops you will see (Lenovo suggests it is under 10mm thick). </p><p>Eric Yu, Lenovo's SVP and GM of its Commercial Product Center and WW SMB Segment, revealed to <em>ITPro</em> that Project Blade will be going into production very soon. Project Swan, however, needs more exploration. Yu explained that his team wants to continue testing its durability and portability. </p><p>There is no guarantee that a proof of concept will make it into production, but it's what you need to see from tech companies. Not just run-of-the-mill releases and annual updates of some iconic money-making brand. But ideas (good and bad) being put to the public. To be innovative, one must also be brave, and that is essentially what Lenovo does best. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/hardware/prepare-to-be-dazzled-by-lenovos-genuinely-innovative-ideas-at-ifa-2026</link>
                                                                            <description>
                            <![CDATA[ Lenovo delights with a fanless laptop, more rollable screens, and a suite of new products that offer something different ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Dju7J7sSRVcBPhUasGLnM4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Egdx4GJhrmvn3E7g8BTLa-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 16:00:00 +0000</pubDate>                                                                                                                                <updated>Fri, 04 Sep 2026 11:15:25 +0000</updated>
                                                                                                                                            <category><![CDATA[Hardware]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Bobby Hellard) ]]></author>                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Bobby Hellard&amp;nbsp;is&amp;nbsp;ITPro&#039;s Reviews Editor and has worked on&amp;nbsp;CloudPro and ChannelPro since 2018. In his time at ITPro, Bobby has covered stories for all the major technology companies, such as Apple, Microsoft, Amazon and Facebook, and regularly attends industry-leading events such as AWS Re:Invent and Google Cloud Next.&lt;/p&gt;
&lt;p&gt;Bobby mainly covers hardware reviews, but you will also recognize him as the face of many of our video reviews of laptops and smartphones.&lt;/p&gt;
&lt;p&gt;He has been a journalist for ten years, originally covering sports, before moving into business technology with ITPro. He has bylines in The Independent, Vice and The Business Briefing. Contact him at &lt;a href=&quot;mailto:bobby.hellard@futurenet.com&quot;&gt;bobby.hellard@futurenet.com&lt;/a&gt; or find him on Twitter: &lt;a href=&quot;https://twitter.com/bobbyhellard&quot;&gt;@bobbyhellard&lt;/a&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Egdx4GJhrmvn3E7g8BTLa-1920-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Lenovo&#039;s Project Swan proof of concept ]]></media:description>                                                            <media:text><![CDATA[Lenovo&#039;s Project Swan proof of concept ]]></media:text>
                                <media:title type="plain"><![CDATA[Lenovo&#039;s Project Swan proof of concept ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Egdx4GJhrmvn3E7g8BTLa-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>IFA 2026 attendees are in for a treat when they come to the Lenovo stand. I know this because I have already been dazzled by the company's new products at its pre-IFA Innovation event in Berlin. </p><p>One of the biggest issues with IFA is that it's just a big convention center filled with showrooms. It's not really known for keynotes and presentations. You simply have to go and walk around the show floor to see new products and services. </p><p>That doesn't really suit tech companies like Lenovo, with their vast offerings and groundbreaking products. </p><p>And so, much like at <a href="https://www.itpro.com/technology/artificial-intelligence/lenovo-partnership-fifa-world-cup-ces-2026">CES earlier in the year</a>, Lenovo holds its own pre-conference, Lenovo Innovation World, in the same city. Journalists from all over the world are invited to stay in a hotel that also doubles as the event space. We get sneak peeks at the new products being launched, one-to-one time with Lenovo's execs, and also some partner-sponsored events (in this case Intel, AMD, and Nvidia). </p><p>But more than that, Innovation World is true to its name. What we get shown is innovative, whether it's colorful consumer laptops (<a href="https://www.itpro.com/hardware/laptops/the-lenovo-ideapad-vibe-is-a-colorful-assault-on-the-eyes-but-there-is-a-surprising-number-of-features-on-offer-here">IdeaPad Vibe</a>), AI developer-focused desktops (<a href="https://www.itpro.com/hardware/desktops/lenovo-aims-to-wow-developers-with-small-but-mighty-thinkcentre-desktops-at-ifa-2026">ThinkCentre X Ultra</a>), or even a stylus with unique controls (Yoga Tab Pro). </p><p>As its products show, Lenovo doesn't really like to stand still. Nothing is "business as usual". Everything has some new or untested feature. This doesn't mean it's all good; some of it may never be used again. But it's the bravery to try that makes it so interesting. </p><p>And it wouldn't be a Lenovo Innovation World without a <a href="https://www.itpro.com/hardware/lenovo-wows-at-mwc-with-concepts-for-a-modular-thinkbook-and-desktop-ai-devices">proof of concept</a>. For IFA there were two: one is Project Swan, a laptop with an expandable screen. The display slides outwards, growing from 14in to a 17in, similar to the <a href="https://www.itpro.com/hardware/laptops/lenovo-reveals-slick-rollable-screen-concept-and-a-voice-controlled-thinkbook-at-ces-2026-embargo-6th-jan-5pm-pst">rollable screen showcased at CES</a> earlier in the year. </p><p>The other concept, the more groundbreaking one, was Project AeroBlade. Essentially a fanless laptop that uses a vibrating membrane to push air out of the chassis. </p><p>Specifically, this is called the 'Active Flow Thermal Solution' and has been developed by a company called AirJet. The AirJet system replaces the traditional spinning blades with a slim 2.65mm chip that has an ultrasonic membrane. </p><p>This vibrates and pulls air through the device, and then ejects it through tiny slits at the back of the chassis. Without the need for fans and heatsinks, the AreoBlade is one of the thinnest laptops you will see (Lenovo suggests it is under 10mm thick). </p><p>Eric Yu, Lenovo's SVP and GM of its Commercial Product Center and WW SMB Segment, revealed to <em>ITPro</em> that Project Blade will be going into production very soon. Project Swan, however, needs more exploration. Yu explained that his team wants to continue testing its durability and portability. </p><p>There is no guarantee that a proof of concept will make it into production, but it's what you need to see from tech companies. Not just run-of-the-mill releases and annual updates of some iconic money-making brand. But ideas (good and bad) being put to the public. To be innovative, one must also be brave, and that is essentially what Lenovo does best. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Should businesses consider using Chinese AI models? ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Chinese AI models are emerging as an increasingly capable alternative to their US-based peers. Recently, Nvidia CEO Jensen Huang <a href="https://www.itpro.com/software/open-source/these-chinese-models-are-excellent-nvidia-ceo-jensen-huang-hails-powerful-new-chinese-ai-models-like-kimi-k3-and-says-dont-be-put-off-by-security-misconceptions"><u>hailed the capabilities</u></a> of Chinese open source AI models amidst growing interest in low-cost options for enterprises. </p><p>At the same time, Hugging Face used an open-weight Chinese AI model to help mitigate the attack by the <a href="https://www.itpro.com/technology/neural-network/after-openai-hugging-face-how-do-it-leaders-need-to-change-the-way-they-think-about-ai"><u>escaped OpenAI agent</u></a>. The Cloud Security Alliance’s (CSA’s) <a href="https://cloudsecurityalliance.org/artifacts/hugging-face-ciso-post-mortem"><u>post-mortem</u></a> following the OpenAI agent escape fiasco detailed why firms should embrace open source and open-weight AI models.</p><p>“The same safety guardrails that keep frontier models from being misused for attacks can also block defenders from using those models to investigate an active one, leaving organizations without a tested open-weight fallback, at a disadvantage exactly when it matters most,” according to the CSA.</p><p>Chinese AI models are highly capable and cheaper than many US alternatives. They often perform on par with closed-source models, as <em>ITPro </em><a href="https://www.itpro.com/software/open-source/open-source-ai-performance-cost-savings-proprietary-models-linux-foundation"><u>reported in November</u></a> last year. </p><p>Yet experts are cautious about the risk they pose. Should businesses consider these models and, if so, which applications can they be used for?</p><h2 id="model-benefits">Model benefits </h2><p>Chinese models include Moonshot AI's <a href="https://forum.moonshot.ai/t/kimi-k3-is-here-our-most-capable-model/480"><u>Kimi</u></a>, Alibaba's <a href="https://qwen.ai/home"><u>Qwen</u></a>, DeepSeek, and Z.ai’s GLM. In most cases, these are best described as <a href="https://opensource.org/ai/open-weights"><u>open-weight</u></a> rather than open source, meaning they can be used by anyone and model weights and inference code are publicly available for download, but the complete training datasets and foundational code remain private. </p><p>Experts think Chinese model capabilities are impressive and improving all the time. “Their reviews and ratings show their capacity is moving toward matching the biggest and best of US frontier AI models,” says Amanda Brock, CEO at OpenUK. </p><p>At the same time, the industry is recognising the biggest <a href="https://www.itpro.com/security/why-patching-velocity-matters-as-claude-mythos-supercharges-vulnerability-discovery"><u>frontier models</u></a> are “not necessarily the best for particular tasks”, says Brock. </p><p>“The open models have reached a point where they are freely sharing some of the tech equivalent to what the closed model companies charge a subscription for and are also freely available to be iteratively developed upon.”</p><p>Capability-wise, the latest generation of Chinese AI models are “genuinely impressive”, says Assaf Morag, cybersecurity researcher at Flare. </p><p>“Based on the benchmarks and independent evaluations available today, many of these models are performing at a level comparable to other leading frontier AI models while often offering lower deployment costs and more open access.”</p><p>Among the benefits, they offer “strong reasoning, coding capabilities and large-context windows”, says Oliver Simonnet, lead cybersecurity researcher at CultureAI. He believes open-weight – and in some cases open source – models also provide better control over deployment, customisation and data residency when hosted within an organization's own infrastructure.</p><p>Chinese labs have said directly that <a href="https://hongkongfp.com/2026/08/10/how-chinese-ai-is-driving-price-competition-among-us-labs/"><u>market share</u></a> matters more than near-term revenue, releasing full weights and technical reports so developers worldwide can adopt and adapt the models freely. </p><p>At a time when enterprises are weighing up the often hefty cost of AI, Sai Molige, senior manager of threat hunting at Forescout, says models such as these now cost between 60% and 90% less to run. “That price gap, not parity on trust or security, is what's driving a real shift in where US developers send their workloads.”</p><h2 id="weighing-up-the-risks">Weighing up the risks</h2><p>Yet some critics have suggested the tools could be used as a ‘backdoor’ for Chinese intelligence services.</p><p><a href="https://www.axios.com/2026/07/20/ai-us-china-open-source-kimi"><u><em>Axios </em></u><u>previously reported</u></a> that the White House could consider imposing restrictions or tight conditions on US firms working with these models. The US government has already <a href="https://theconversation.com/legally-or-not-the-us-government-is-controlling-global-access-to-the-worlds-most-powerful-ai-286118"><u>restricted</u></a> the use of home-grown AI in other countries. </p><p>Nvidia’s Huang thinks firms shouldn’t be put off by security “misconceptions” around Chinese open-weight and open source models. </p><p>Yet beyond the obvious scare-mongering, these models do pose some risks around data privacy and national security.</p><p>Simonnet thinks data privacy is a valid concern: Chinese data-storage laws, political censorship and bias, and training-data uncertainties “remain prominent issues”, he tells <em>ITPro.</em></p><p>The largest risks are often around data governance, supply-chain trust, compliance obligations, and operational security – and this is not necessarily the model weights themselves, says Morag. </p><p>“From a cybersecurity perspective, every external AI service introduces another third-party dependency. The same due diligence applied to cloud providers or SaaS platforms should also apply to AI models, regardless of whether they originate in China, the US or Europe.”</p><p>Self-hosting the models can reduce some of these privacy risks. However, this doesn't remove the risk of model biases or technical vulnerabilities. Indeed, it requires organizations to further secure and maintain the model themselves, which “adds an extra layer of security challenges”, according to Simonnet.</p><p>However, when assessing the risks, the discussion should move beyond simply asking whether a model is Chinese, says Morag. “Organizations need to evaluate where inference occurs, what data leaves their environment, who operates the infrastructure, how updates are delivered, and whether the model can be independently audited.”</p><h2 id="the-verdict">The verdict </h2><p>Despite posing some risks, experts say Chinese models are an option in many cases when compared to frontier alternatives. Open-weight models offer organizations “substantially more control”, says Morag. </p><p>“They can be deployed inside private infrastructure, reducing the need to move sensitive corporate information outside the boundaries of the organization to third-party providers. They also enable independent security testing and auditing, which is difficult or impossible with closed commercial APIs.”</p><p>Closed models, however, generally provide stronger vendor support, as well as managed security controls and predictable service levels, according to Morag. “For many enterprises, the decision should be based on governance requirements and operational maturity, rather than geography alone.”</p><p>Overall, Simonnet has a positive view of Chinese models. He points out they can deliver “strong performance with fewer restrictions at a smaller price”, citing the example of the Hugging Face incident. </p><p>Open-weight models do provide greater control and a way to keep sensitive data within an organization when they are privately hosted, says Simonnet. However, self-hosting requires additional technical expertise and security oversight, he concedes.</p><p>At the same time, he warns that confidential, regulated, or other sensitive data “should not be entered into these services without the proper security, privacy, and governance controls being in place”. </p><p>But for general-purpose, non-sensitive work at scale, the cost case is strong, provided the deployment is self-hosted and audited, says Molige. </p><p>“For code headed for production or government-adjacent systems, companies should scan generated code regardless of which model wrote it, rather than trusting output by source.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/technology/artificial-intelligence/should-businesses-consider-using-chinese-ai-models</link>
                                                                            <description>
                            <![CDATA[ Chinese AI models are highly capable and often low-cost, but experts are cautious about the risks they pose. Should businesses consider these models, and if so, which applications can they be used for? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Gw5cak4erURwot3tzYjoZM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/bLSsYgswXfVWXGiXgSJvj8-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 07:00:00 +0000</pubDate>                                                                                                                                <updated>Fri, 04 Sep 2026 10:08:03 +0000</updated>
                                                                                                                                            <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kate O&#039;Flaherty ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LUULv6n7VJ3BHPnaoLHHdg-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/bLSsYgswXfVWXGiXgSJvj8-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Conceptual image of a large-scale futuristic data center on a peach grid showcasing a prominent glowing AI cube cluster emerging from an orange container, with extensive colorful wiring linking to surrounding illuminated server racks in precise formations, representing advanced artificial intelligence infrastructure, machine learning networks, and interconnected digital systems in a high-tech conceptual 3D scene with vibrant effects.]]></media:description>                                                            <media:text><![CDATA[Conceptual image of a large-scale futuristic data center on a peach grid showcasing a prominent glowing AI cube cluster emerging from an orange container, with extensive colorful wiring linking to surrounding illuminated server racks in precise formations, representing advanced artificial intelligence infrastructure, machine learning networks, and interconnected digital systems in a high-tech conceptual 3D scene with vibrant effects.]]></media:text>
                                <media:title type="plain"><![CDATA[Conceptual image of a large-scale futuristic data center on a peach grid showcasing a prominent glowing AI cube cluster emerging from an orange container, with extensive colorful wiring linking to surrounding illuminated server racks in precise formations, representing advanced artificial intelligence infrastructure, machine learning networks, and interconnected digital systems in a high-tech conceptual 3D scene with vibrant effects.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/bLSsYgswXfVWXGiXgSJvj8-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Chinese AI models are emerging as an increasingly capable alternative to their US-based peers. Recently, Nvidia CEO Jensen Huang <a href="https://www.itpro.com/software/open-source/these-chinese-models-are-excellent-nvidia-ceo-jensen-huang-hails-powerful-new-chinese-ai-models-like-kimi-k3-and-says-dont-be-put-off-by-security-misconceptions"><u>hailed the capabilities</u></a> of Chinese open source AI models amidst growing interest in low-cost options for enterprises. </p><p>At the same time, Hugging Face used an open-weight Chinese AI model to help mitigate the attack by the <a href="https://www.itpro.com/technology/neural-network/after-openai-hugging-face-how-do-it-leaders-need-to-change-the-way-they-think-about-ai"><u>escaped OpenAI agent</u></a>. The Cloud Security Alliance’s (CSA’s) <a href="https://cloudsecurityalliance.org/artifacts/hugging-face-ciso-post-mortem"><u>post-mortem</u></a> following the OpenAI agent escape fiasco detailed why firms should embrace open source and open-weight AI models.</p><p>“The same safety guardrails that keep frontier models from being misused for attacks can also block defenders from using those models to investigate an active one, leaving organizations without a tested open-weight fallback, at a disadvantage exactly when it matters most,” according to the CSA.</p><p>Chinese AI models are highly capable and cheaper than many US alternatives. They often perform on par with closed-source models, as <em>ITPro </em><a href="https://www.itpro.com/software/open-source/open-source-ai-performance-cost-savings-proprietary-models-linux-foundation"><u>reported in November</u></a> last year. </p><p>Yet experts are cautious about the risk they pose. Should businesses consider these models and, if so, which applications can they be used for?</p><h2 id="model-benefits">Model benefits </h2><p>Chinese models include Moonshot AI's <a href="https://forum.moonshot.ai/t/kimi-k3-is-here-our-most-capable-model/480"><u>Kimi</u></a>, Alibaba's <a href="https://qwen.ai/home"><u>Qwen</u></a>, DeepSeek, and Z.ai’s GLM. In most cases, these are best described as <a href="https://opensource.org/ai/open-weights"><u>open-weight</u></a> rather than open source, meaning they can be used by anyone and model weights and inference code are publicly available for download, but the complete training datasets and foundational code remain private. </p><p>Experts think Chinese model capabilities are impressive and improving all the time. “Their reviews and ratings show their capacity is moving toward matching the biggest and best of US frontier AI models,” says Amanda Brock, CEO at OpenUK. </p><p>At the same time, the industry is recognising the biggest <a href="https://www.itpro.com/security/why-patching-velocity-matters-as-claude-mythos-supercharges-vulnerability-discovery"><u>frontier models</u></a> are “not necessarily the best for particular tasks”, says Brock. </p><p>“The open models have reached a point where they are freely sharing some of the tech equivalent to what the closed model companies charge a subscription for and are also freely available to be iteratively developed upon.”</p><p>Capability-wise, the latest generation of Chinese AI models are “genuinely impressive”, says Assaf Morag, cybersecurity researcher at Flare. </p><p>“Based on the benchmarks and independent evaluations available today, many of these models are performing at a level comparable to other leading frontier AI models while often offering lower deployment costs and more open access.”</p><p>Among the benefits, they offer “strong reasoning, coding capabilities and large-context windows”, says Oliver Simonnet, lead cybersecurity researcher at CultureAI. He believes open-weight – and in some cases open source – models also provide better control over deployment, customisation and data residency when hosted within an organization's own infrastructure.</p><p>Chinese labs have said directly that <a href="https://hongkongfp.com/2026/08/10/how-chinese-ai-is-driving-price-competition-among-us-labs/"><u>market share</u></a> matters more than near-term revenue, releasing full weights and technical reports so developers worldwide can adopt and adapt the models freely. </p><p>At a time when enterprises are weighing up the often hefty cost of AI, Sai Molige, senior manager of threat hunting at Forescout, says models such as these now cost between 60% and 90% less to run. “That price gap, not parity on trust or security, is what's driving a real shift in where US developers send their workloads.”</p><h2 id="weighing-up-the-risks">Weighing up the risks</h2><p>Yet some critics have suggested the tools could be used as a ‘backdoor’ for Chinese intelligence services.</p><p><a href="https://www.axios.com/2026/07/20/ai-us-china-open-source-kimi"><u><em>Axios </em></u><u>previously reported</u></a> that the White House could consider imposing restrictions or tight conditions on US firms working with these models. The US government has already <a href="https://theconversation.com/legally-or-not-the-us-government-is-controlling-global-access-to-the-worlds-most-powerful-ai-286118"><u>restricted</u></a> the use of home-grown AI in other countries. </p><p>Nvidia’s Huang thinks firms shouldn’t be put off by security “misconceptions” around Chinese open-weight and open source models. </p><p>Yet beyond the obvious scare-mongering, these models do pose some risks around data privacy and national security.</p><p>Simonnet thinks data privacy is a valid concern: Chinese data-storage laws, political censorship and bias, and training-data uncertainties “remain prominent issues”, he tells <em>ITPro.</em></p><p>The largest risks are often around data governance, supply-chain trust, compliance obligations, and operational security – and this is not necessarily the model weights themselves, says Morag. </p><p>“From a cybersecurity perspective, every external AI service introduces another third-party dependency. The same due diligence applied to cloud providers or SaaS platforms should also apply to AI models, regardless of whether they originate in China, the US or Europe.”</p><p>Self-hosting the models can reduce some of these privacy risks. However, this doesn't remove the risk of model biases or technical vulnerabilities. Indeed, it requires organizations to further secure and maintain the model themselves, which “adds an extra layer of security challenges”, according to Simonnet.</p><p>However, when assessing the risks, the discussion should move beyond simply asking whether a model is Chinese, says Morag. “Organizations need to evaluate where inference occurs, what data leaves their environment, who operates the infrastructure, how updates are delivered, and whether the model can be independently audited.”</p><h2 id="the-verdict">The verdict </h2><p>Despite posing some risks, experts say Chinese models are an option in many cases when compared to frontier alternatives. Open-weight models offer organizations “substantially more control”, says Morag. </p><p>“They can be deployed inside private infrastructure, reducing the need to move sensitive corporate information outside the boundaries of the organization to third-party providers. They also enable independent security testing and auditing, which is difficult or impossible with closed commercial APIs.”</p><p>Closed models, however, generally provide stronger vendor support, as well as managed security controls and predictable service levels, according to Morag. “For many enterprises, the decision should be based on governance requirements and operational maturity, rather than geography alone.”</p><p>Overall, Simonnet has a positive view of Chinese models. He points out they can deliver “strong performance with fewer restrictions at a smaller price”, citing the example of the Hugging Face incident. </p><p>Open-weight models do provide greater control and a way to keep sensitive data within an organization when they are privately hosted, says Simonnet. However, self-hosting requires additional technical expertise and security oversight, he concedes.</p><p>At the same time, he warns that confidential, regulated, or other sensitive data “should not be entered into these services without the proper security, privacy, and governance controls being in place”. </p><p>But for general-purpose, non-sensitive work at scale, the cost case is strong, provided the deployment is self-hosted and audited, says Molige. </p><p>“For code headed for production or government-adjacent systems, companies should scan generated code regardless of which model wrote it, rather than trusting output by source.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Changing channel priorities and the advantage of an ecosystem focus ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The UK channel is entering one of the most consequential periods of change it has faced in over a decade. The Broadcom/VMware acquisition has acted as a catalyst, accelerating changes that were already underway and encouraging partners to address a new reality that the old channel playbook no longer works.</p><p> </p><p>The reshaping of VMware’s traditional partner ecosystem, along with the move to subscription‑only licensing and the subsequent contraction of mid‑tier partner opportunities, has created a vacuum that the market needs to fill.</p><p>However, this disruption can also provide clarity. For those willing to adapt and embrace change, this year represents a structural reset and a chance to modernize virtualization portfolios. Partners can strengthen hybrid cloud capabilities and build new alliances that reflect the needs of a very different customer landscape.</p><h2 id="from-resale-to-services-a-new-channel-economy">From resale to services: A new channel economy</h2><p>The channel is moving decisively away from a resale‑led model and toward a services‑first economy. Customers are looking for partners who act as strategic advisors, who can guide them through migration and manage complex multi‑cloud environments. They are seeking partners that actively optimize their infrastructure over the long term, rather than just selling licenses. </p><p>By changing VMware, Broadcom accelerated the end of an era where broad vendor lists and transactional relationships were enough to compete. UK partners must now decide whether they will evolve into cloud and infrastructure specialists or risk being left behind in a market that has already moved on.</p><p> </p><p>This transformation is happening alongside a broader consolidation across the partner ecosystem. After years of juggling sprawling vendor portfolios and chasing every certification and incentive, partners are now being pushed to focus. With fewer viable vendors in play, partners can finally invest in the relationships that deliver commercial value. </p><p>This is raising expectations across the board. As the generalist reseller falls behind, a channel is emerging defined by sharper positioning and more deliberate ecosystem choices as vendors seek partners with technical depth and consistent execution.</p><h2 id="ecosystem-alignment-as-a-competitive-advantage">Ecosystem alignment as a competitive advantage</h2><p>This means success will hinge on alignment. The partners who prosper will be those who embed themselves within an ecosystem and operate as true extensions of their chosen vendors. This means co‑marketing, co-selling, and delivering with a level of reliability that customers can measure.</p><p>As channel programs mature, customers will increasingly gravitate toward suppliers who demonstrate operational strength and a clear plan for supporting multi‑cloud, AI‑driven, and cost‑optimized environments. In a landscape shaped by consolidation and rising expectations, a well‑structured, high‑performing ecosystem becomes a competitive advantage.</p><p>Across the industry, the vendors making the greatest impact are those helping partners strengthen cyber resilience and accelerate cloud and network modernization. Those who get ahead will also deliver measurable value for customers while unlocking new growth opportunities across the channel. </p><p>The successful vendors will be those who have a commitment to empowering partners with the technology, expertise, and support needed to deliver exceptional outcomes, a model that is increasingly becoming the benchmark for what effective ecosystem leadership looks like.</p><h2 id="the-rise-of-service-centric-models">The rise of service‑centric models</h2><p>At the same time, the channel is undergoing a structural reset that goes beyond VMware. Customers are rethinking their entire approach to infrastructure, resilience, and cloud economics. They want predictability and outcomes over a complicated patchwork of point solutions. </p><p>This is driving the rise of service‑centric ecosystems, where the value lies not in the number of vendors a partner represents, but in the ability to integrate, manage, and optimize across environments without locking customers into a single technology path.</p><p></p><p>Vendor‑agnostic service providers are gaining traction because they offer freedom, which is something that is increasingly rare in the industry. The ability to deliver resilience as a baseline and give customers room to evolve their stack without disruption is becoming a defining differentiator.</p><p>Another trend that is reshaping the channel is resilience‑first architecture. With regulatory pressure increasing and cloud costs rising, organisations are evaluating how they protect and operate their environments. Partners who can deliver integrated continuity, security, and recovery capabilities across clouds, data centers, and edge environments are becoming indispensable. </p><p>Customers want a consistent operational model regardless of where workloads live, and they expect partners to provide it.</p><h2 id="operational-excellence-and-ai-enabled-scale">Operational excellence and AI‑enabled scale</h2><p>Customers are tired of fragmented support models and inconsistent delivery: they want a single operational fabric, predictable SLAs, and clear accountability. This is where ecosystem alignment becomes essential. Partners who can plug into a broader, well‑orchestrated service framework will outperform those trying to stitch together disparate tools and vendors.</p><p>The channel is evolving from “best of breed” to “best of integration,” with the partners who understand this leading the next phase of growth.</p><p>The rise of AI‑enabled operations is also widening the gap between partners who can scale intelligently and those who cannot. Customers now expect proactive monitoring, automated remediation, and data‑driven optimization as standard. The channel’s role is moving from selling technology to delivering continuous service improvement, and that requires platforms capable of ingesting, correlating, and acting on signals across the entire estate. </p><p>Vendor‑agnostic service providers are uniquely positioned here because they can apply AI across heterogeneous environments rather than being constrained by a single vendor’s ecosystem.</p><p>Partners who align themselves with ecosystems that simplify complexity, enhance resilience, and remain vendor‑neutral will be the ones who advance. The winners will be those who help customers navigate choice; who deliver outcomes rather than components; and who build ecosystems designed for the long term.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/business/business-strategy/changing-channel-priorities-and-the-advantage-of-an-ecosystem-focus</link>
                                                                            <description>
                            <![CDATA[ Success increasingly depends on ecosystem alignment instead of broad coverage ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Uf2x5v3VHDncHvGNWRpVdj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UdaJDteRscMb3v8rBNhfCi-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Business Strategy]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Johnny Carpenter ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/AY6HhTh6aYAUoSPF5rJnbc-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UdaJDteRscMb3v8rBNhfCi-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Office workers in a business strategy meeting discussing digital transformation plans with sticky notes placed on glass board.]]></media:description>                                                            <media:text><![CDATA[Office workers in a business strategy meeting discussing digital transformation plans with sticky notes placed on glass board.]]></media:text>
                                <media:title type="plain"><![CDATA[Office workers in a business strategy meeting discussing digital transformation plans with sticky notes placed on glass board.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UdaJDteRscMb3v8rBNhfCi-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK channel is entering one of the most consequential periods of change it has faced in over a decade. The Broadcom/VMware acquisition has acted as a catalyst, accelerating changes that were already underway and encouraging partners to address a new reality that the old channel playbook no longer works.</p><p> </p><p>The reshaping of VMware’s traditional partner ecosystem, along with the move to subscription‑only licensing and the subsequent contraction of mid‑tier partner opportunities, has created a vacuum that the market needs to fill.</p><p>However, this disruption can also provide clarity. For those willing to adapt and embrace change, this year represents a structural reset and a chance to modernize virtualization portfolios. Partners can strengthen hybrid cloud capabilities and build new alliances that reflect the needs of a very different customer landscape.</p><h2 id="from-resale-to-services-a-new-channel-economy">From resale to services: A new channel economy</h2><p>The channel is moving decisively away from a resale‑led model and toward a services‑first economy. Customers are looking for partners who act as strategic advisors, who can guide them through migration and manage complex multi‑cloud environments. They are seeking partners that actively optimize their infrastructure over the long term, rather than just selling licenses. </p><p>By changing VMware, Broadcom accelerated the end of an era where broad vendor lists and transactional relationships were enough to compete. UK partners must now decide whether they will evolve into cloud and infrastructure specialists or risk being left behind in a market that has already moved on.</p><p> </p><p>This transformation is happening alongside a broader consolidation across the partner ecosystem. After years of juggling sprawling vendor portfolios and chasing every certification and incentive, partners are now being pushed to focus. With fewer viable vendors in play, partners can finally invest in the relationships that deliver commercial value. </p><p>This is raising expectations across the board. As the generalist reseller falls behind, a channel is emerging defined by sharper positioning and more deliberate ecosystem choices as vendors seek partners with technical depth and consistent execution.</p><h2 id="ecosystem-alignment-as-a-competitive-advantage">Ecosystem alignment as a competitive advantage</h2><p>This means success will hinge on alignment. The partners who prosper will be those who embed themselves within an ecosystem and operate as true extensions of their chosen vendors. This means co‑marketing, co-selling, and delivering with a level of reliability that customers can measure.</p><p>As channel programs mature, customers will increasingly gravitate toward suppliers who demonstrate operational strength and a clear plan for supporting multi‑cloud, AI‑driven, and cost‑optimized environments. In a landscape shaped by consolidation and rising expectations, a well‑structured, high‑performing ecosystem becomes a competitive advantage.</p><p>Across the industry, the vendors making the greatest impact are those helping partners strengthen cyber resilience and accelerate cloud and network modernization. Those who get ahead will also deliver measurable value for customers while unlocking new growth opportunities across the channel. </p><p>The successful vendors will be those who have a commitment to empowering partners with the technology, expertise, and support needed to deliver exceptional outcomes, a model that is increasingly becoming the benchmark for what effective ecosystem leadership looks like.</p><h2 id="the-rise-of-service-centric-models">The rise of service‑centric models</h2><p>At the same time, the channel is undergoing a structural reset that goes beyond VMware. Customers are rethinking their entire approach to infrastructure, resilience, and cloud economics. They want predictability and outcomes over a complicated patchwork of point solutions. </p><p>This is driving the rise of service‑centric ecosystems, where the value lies not in the number of vendors a partner represents, but in the ability to integrate, manage, and optimize across environments without locking customers into a single technology path.</p><p></p><p>Vendor‑agnostic service providers are gaining traction because they offer freedom, which is something that is increasingly rare in the industry. The ability to deliver resilience as a baseline and give customers room to evolve their stack without disruption is becoming a defining differentiator.</p><p>Another trend that is reshaping the channel is resilience‑first architecture. With regulatory pressure increasing and cloud costs rising, organisations are evaluating how they protect and operate their environments. Partners who can deliver integrated continuity, security, and recovery capabilities across clouds, data centers, and edge environments are becoming indispensable. </p><p>Customers want a consistent operational model regardless of where workloads live, and they expect partners to provide it.</p><h2 id="operational-excellence-and-ai-enabled-scale">Operational excellence and AI‑enabled scale</h2><p>Customers are tired of fragmented support models and inconsistent delivery: they want a single operational fabric, predictable SLAs, and clear accountability. This is where ecosystem alignment becomes essential. Partners who can plug into a broader, well‑orchestrated service framework will outperform those trying to stitch together disparate tools and vendors.</p><p>The channel is evolving from “best of breed” to “best of integration,” with the partners who understand this leading the next phase of growth.</p><p>The rise of AI‑enabled operations is also widening the gap between partners who can scale intelligently and those who cannot. Customers now expect proactive monitoring, automated remediation, and data‑driven optimization as standard. The channel’s role is moving from selling technology to delivering continuous service improvement, and that requires platforms capable of ingesting, correlating, and acting on signals across the entire estate. </p><p>Vendor‑agnostic service providers are uniquely positioned here because they can apply AI across heterogeneous environments rather than being constrained by a single vendor’s ecosystem.</p><p>Partners who align themselves with ecosystems that simplify complexity, enhance resilience, and remain vendor‑neutral will be the ones who advance. The winners will be those who help customers navigate choice; who deliver outcomes rather than components; and who build ecosystems designed for the long term.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How MSSPs can deliver continuous pentesting without hiring more security experts ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Managed Security Service Providers (MSSPs) need continuous security testing and faster risk identification. But the cybersecurity talent shortage makes it harder to expand service delivery through hiring alone.</p><p>The challenge is becoming more urgent as cyber threats continue to grow. More than <a href="https://zerothreat.ai/blog/cyberattack-statistics"><u>2,244 cyberattacks occur every day worldwide</u></a>, according to our research. This creates constant pressure for organizations to identify and address security gaps before attackers do.</p><p>More risk and more demand. Traditional approaches and tools simply can’t keep up.</p><p>That reality is forcing MSSPs to change how they scale security services. The good part is that continuous pentesting no longer requires a proportional increase in headcount. With AI-powered automated penetration testing, MSSPs can expand security coverage, increase testing frequency, and serve more clients without continuously adding security specialists.</p><h2 id="why-continuous-security-coverage-is-getting-harder">Why continuous security coverage is getting harder</h2><p>Managing security for clients used to be like checking a box once a year, but that has changed. Each organization needs continuous security coverage to keep up with the updates they are deploying and the growing number of cyber threats.</p><p>The complexity of today’s applications can’t be tackled by traditional methods because:</p><ul><li>Cloud-native apps and APIs change daily, making annual penetration tests obsolete within weeks.</li><li>Hiring more security experts to manually test every environment is not feasible.</li><li>Attackers now use AI to scan and exploit systems continuously, moving far faster than manual audit cycles.</li></ul><p>As a result, many providers are rethinking how they scale offensive security services without continually expanding their security teams.</p><h2 id="why-hiring-more-people-isn-39-t-a-scalable-security-strategy">Why hiring more people isn't a scalable security strategy</h2><p>Hiring more security experts seems like the obvious way to add to continuous pentesting services. But in reality, fluctuating demand, shortage of skills, and other operational costs can make it difficult to sustain.</p><ol start="1"><li><strong>Skilled security talent is hard to find: </strong>The cybersecurity talent gap remains a major challenge across the industry. Recent ISC2 research found that 95% of organizations report at least one cybersecurity skills gap, while 59% face significant or critical skills shortages. Finding experienced pentesters, application security specialists, and offensive security experts is becoming increasingly tough.</li><li><strong>Hiring costs keep increasing: </strong>Recruiting security professionals is expensive, and other than salary, MSSPs need to account for onboarding, training, certifications, and retention efforts. With high demand for application security and threat exposure management skills, the cost of building larger teams rises with it.</li><li><strong>Client growth often outpaces team growth: </strong>Security teams do not scale at the same rate as client demand. As MSSPs add more customers, each new environment introduces additional assets, attack surfaces, vulnerabilities, and testing requirements. Hiring one person at a time rarely keeps pace with the volume of continuous security assessments clients expect.</li><li><strong>Specialized expertise does not scale easily: </strong>Continuous pentesting demands expertise in web applications, APIs, cloud environments, business logic testing, and risk validation. Building teams with every required specialty can easily become impractical for growing MSSPs.</li><li><strong>More people can create operational bottlenecks: </strong>Adding more heads to the team does not mean improved service delivery. Larger teams require coordination, management, quality assurance, and workflow standardization. In many cases, operational complexity grows faster than productivity, reducing the efficiency gains MSSPs expected from hiring more analysts and testers.</li></ol><p>The key problem with hiring more isn’t just about finding more skilled experts; it’s finding a way to offer continuous security coverage while utilizing the resources efficiently.</p><h2 id="how-mssps-can-provide-continuous-pentesting-without-hiring">How MSSPs can provide continuous pentesting without hiring</h2><p>The most practical way to scale continuous pentesting today is to combine security expertise with AI-powered automated penetration testing that increases coverage, testing frequency, and operational efficiency.</p><p><strong>Automate repetitive security testing tasks:</strong> A large portion of pentesting involves reconnaissance, attack surface discovery, vulnerability validation, and retesting. AI-powered pentesting platforms can help you automate these repeatable tasks so that you can focus on higher-value investigations and risk analysis.</p><p><strong>Integrate security testing into existing pipelines: </strong>You should embed automated testing directly into the client delivery process. This ensures that every configuration change is tested immediately rather than waiting for an annual check. It turns security from periodic, labor-intensive work into an automated process.</p><p><strong>Implement multi-tenant management: </strong>Instead of configuring tests for each client individually, use multi-tenant dashboards. This allows your current engineering or SOC team to centrally schedule automated tests, distribute reports, and track remediation across hundreds of client environments simultaneously.</p><p><strong>Prioritize findings based on real risk:</strong> Use modern AI-powered pentesting platforms that help correlate findings, validate exploitability, and highlight the issues most likely to impact the client. This improves remediation efficiency and helps you deliver clearer security outcomes.</p><p><strong>Utilize white-label reseller tools:</strong> The best way to save time and effort on preparing reports is by using a tool that offers white-labeled reports. The reports are generated by AI-powered tools, and you can keep your Logos & URLs, making sure you deliver professional, client-ready documentation without manual formatting.</p><h2 id="what-mssps-should-look-for-in-a-scalable-continuous-pentesting-solution">What MSSPs should look for in a scalable continuous pentesting solution</h2><p>As client environments grow complex, MSSPs need solutions that can expand security coverage without operational burden. The ideal platform should help teams identify risks faster, validate findings more efficiently, and deliver consistent security outcomes across multiple customers.</p><p>When evaluating a solution, focus on capabilities that support long-term scalability:</p><ul><li>Continuous attack surface monitoring</li><li>AI-assisted vulnerability validation</li><li>Web application, API, cloud, and external asset coverage</li><li>Risk-based prioritization of findings</li><li>Automated retesting and remediation tracking</li><li>Multi-tenant management and reporting</li><li>Integration with existing security workflows and ticketing systems</li></ul><p>The right tool helps security teams spend less time on repetitive testing and more time delivering meaningful risk insights. For MSSPs, that balance is what makes continuous pentesting both operationally sustainable and commercially viable.</p><p>Continuous pentesting is the new basic expectation of clients, and that has turned out to be the new challenge for MSSPs. If they rely only on hiring to offer continuous testing services, it is rarely sustainable in a market already facing a cybersecurity skills shortage.</p><p>The most effective path forward is to combine security expertise with AI-powered automation.</p><p>By automating repetitive testing activities and enabling continuous security validation, MSSPs can support more clients, identify risks faster, and scale their services without compromising the quality of protection they deliver.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/how-mssps-can-deliver-continuous-pentesting-without-hiring-more-security-experts</link>
                                                                            <description>
                            <![CDATA[ MSSPs can scale and strengthen their security posture using AI instead of expanding security teams... ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7sUn7zuCnbDyeX8LYaxNpK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Gmv6VGAN4vkgH2urwaX2Yf-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Sep 2026 22:05:25 +0000</pubDate>                                                                                                                                <updated>Wed, 02 Sep 2026 22:06:31 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dharmesh Acharya ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/UakkT3isdrj83uFs6V7FiW-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Gmv6VGAN4vkgH2urwaX2Yf-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cybersecurity concept image symbolizing third-party data breaches with give padlock symbols and one pictured in red, signifying a security breach.]]></media:description>                                                            <media:text><![CDATA[Cybersecurity concept image symbolizing third-party data breaches with give padlock symbols and one pictured in red, signifying a security breach.]]></media:text>
                                <media:title type="plain"><![CDATA[Cybersecurity concept image symbolizing third-party data breaches with give padlock symbols and one pictured in red, signifying a security breach.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Gmv6VGAN4vkgH2urwaX2Yf-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Managed Security Service Providers (MSSPs) need continuous security testing and faster risk identification. But the cybersecurity talent shortage makes it harder to expand service delivery through hiring alone.</p><p>The challenge is becoming more urgent as cyber threats continue to grow. More than <a href="https://zerothreat.ai/blog/cyberattack-statistics"><u>2,244 cyberattacks occur every day worldwide</u></a>, according to our research. This creates constant pressure for organizations to identify and address security gaps before attackers do.</p><p>More risk and more demand. Traditional approaches and tools simply can’t keep up.</p><p>That reality is forcing MSSPs to change how they scale security services. The good part is that continuous pentesting no longer requires a proportional increase in headcount. With AI-powered automated penetration testing, MSSPs can expand security coverage, increase testing frequency, and serve more clients without continuously adding security specialists.</p><h2 id="why-continuous-security-coverage-is-getting-harder">Why continuous security coverage is getting harder</h2><p>Managing security for clients used to be like checking a box once a year, but that has changed. Each organization needs continuous security coverage to keep up with the updates they are deploying and the growing number of cyber threats.</p><p>The complexity of today’s applications can’t be tackled by traditional methods because:</p><ul><li>Cloud-native apps and APIs change daily, making annual penetration tests obsolete within weeks.</li><li>Hiring more security experts to manually test every environment is not feasible.</li><li>Attackers now use AI to scan and exploit systems continuously, moving far faster than manual audit cycles.</li></ul><p>As a result, many providers are rethinking how they scale offensive security services without continually expanding their security teams.</p><h2 id="why-hiring-more-people-isn-39-t-a-scalable-security-strategy">Why hiring more people isn't a scalable security strategy</h2><p>Hiring more security experts seems like the obvious way to add to continuous pentesting services. But in reality, fluctuating demand, shortage of skills, and other operational costs can make it difficult to sustain.</p><ol start="1"><li><strong>Skilled security talent is hard to find: </strong>The cybersecurity talent gap remains a major challenge across the industry. Recent ISC2 research found that 95% of organizations report at least one cybersecurity skills gap, while 59% face significant or critical skills shortages. Finding experienced pentesters, application security specialists, and offensive security experts is becoming increasingly tough.</li><li><strong>Hiring costs keep increasing: </strong>Recruiting security professionals is expensive, and other than salary, MSSPs need to account for onboarding, training, certifications, and retention efforts. With high demand for application security and threat exposure management skills, the cost of building larger teams rises with it.</li><li><strong>Client growth often outpaces team growth: </strong>Security teams do not scale at the same rate as client demand. As MSSPs add more customers, each new environment introduces additional assets, attack surfaces, vulnerabilities, and testing requirements. Hiring one person at a time rarely keeps pace with the volume of continuous security assessments clients expect.</li><li><strong>Specialized expertise does not scale easily: </strong>Continuous pentesting demands expertise in web applications, APIs, cloud environments, business logic testing, and risk validation. Building teams with every required specialty can easily become impractical for growing MSSPs.</li><li><strong>More people can create operational bottlenecks: </strong>Adding more heads to the team does not mean improved service delivery. Larger teams require coordination, management, quality assurance, and workflow standardization. In many cases, operational complexity grows faster than productivity, reducing the efficiency gains MSSPs expected from hiring more analysts and testers.</li></ol><p>The key problem with hiring more isn’t just about finding more skilled experts; it’s finding a way to offer continuous security coverage while utilizing the resources efficiently.</p><h2 id="how-mssps-can-provide-continuous-pentesting-without-hiring">How MSSPs can provide continuous pentesting without hiring</h2><p>The most practical way to scale continuous pentesting today is to combine security expertise with AI-powered automated penetration testing that increases coverage, testing frequency, and operational efficiency.</p><p><strong>Automate repetitive security testing tasks:</strong> A large portion of pentesting involves reconnaissance, attack surface discovery, vulnerability validation, and retesting. AI-powered pentesting platforms can help you automate these repeatable tasks so that you can focus on higher-value investigations and risk analysis.</p><p><strong>Integrate security testing into existing pipelines: </strong>You should embed automated testing directly into the client delivery process. This ensures that every configuration change is tested immediately rather than waiting for an annual check. It turns security from periodic, labor-intensive work into an automated process.</p><p><strong>Implement multi-tenant management: </strong>Instead of configuring tests for each client individually, use multi-tenant dashboards. This allows your current engineering or SOC team to centrally schedule automated tests, distribute reports, and track remediation across hundreds of client environments simultaneously.</p><p><strong>Prioritize findings based on real risk:</strong> Use modern AI-powered pentesting platforms that help correlate findings, validate exploitability, and highlight the issues most likely to impact the client. This improves remediation efficiency and helps you deliver clearer security outcomes.</p><p><strong>Utilize white-label reseller tools:</strong> The best way to save time and effort on preparing reports is by using a tool that offers white-labeled reports. The reports are generated by AI-powered tools, and you can keep your Logos & URLs, making sure you deliver professional, client-ready documentation without manual formatting.</p><h2 id="what-mssps-should-look-for-in-a-scalable-continuous-pentesting-solution">What MSSPs should look for in a scalable continuous pentesting solution</h2><p>As client environments grow complex, MSSPs need solutions that can expand security coverage without operational burden. The ideal platform should help teams identify risks faster, validate findings more efficiently, and deliver consistent security outcomes across multiple customers.</p><p>When evaluating a solution, focus on capabilities that support long-term scalability:</p><ul><li>Continuous attack surface monitoring</li><li>AI-assisted vulnerability validation</li><li>Web application, API, cloud, and external asset coverage</li><li>Risk-based prioritization of findings</li><li>Automated retesting and remediation tracking</li><li>Multi-tenant management and reporting</li><li>Integration with existing security workflows and ticketing systems</li></ul><p>The right tool helps security teams spend less time on repetitive testing and more time delivering meaningful risk insights. For MSSPs, that balance is what makes continuous pentesting both operationally sustainable and commercially viable.</p><p>Continuous pentesting is the new basic expectation of clients, and that has turned out to be the new challenge for MSSPs. If they rely only on hiring to offer continuous testing services, it is rarely sustainable in a market already facing a cybersecurity skills shortage.</p><p>The most effective path forward is to combine security expertise with AI-powered automation.</p><p>By automating repetitive testing activities and enabling continuous security validation, MSSPs can support more clients, identify risks faster, and scale their services without compromising the quality of protection they deliver.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How seriously is your business taking the 'Q-Day' threat, and can you really be ready by 2029? ]]></title>
                                                                                                <dc:content><![CDATA[ <p>If you can cast your mind back to 1999, the computing world was in a frenzy over the Y2K bug, or Millennium Bug, a coding flaw where systems abbreviated four-digit years to two digits – so, 99 instead of 1999. </p><p>First identified in 1958, the fear was that computers would read '00' as 1900 instead of 2000, potentially crashing global infrastructure. As such, $300 billion (now worth a staggering $600 billion in today's money) was spent to upgrade computers and application programs so they were Y2K-compliant. Because of this monumental effort over many years, the crisis was largely averted.</p><p>In 2026, a similar panic is simmering at a glacial pace. The fear is Q-Day: a hypothetical moment at which quantum computers become so powerful that they can crack encryption algorithms within seconds. Leading industry figures, quantum computing companies, cybersecurity advisors, and even <a href="https://www.govinfo.gov/content/pkg/DCPD-202200355/html/DCPD-202200355.htm"><u>national government agencies</u></a> have been warning about this moment for years — as far back as 1994, when mathematician Peter Shor first published his paper warning about this exact possibility. </p><p>Since then, the threat has felt far away and abstract – with under-pressure businesses spending their precious IT budgets on more immediate threats. </p><p>But in March 2026, Google Quantum AI published research revealing that quantum computers can crack the encryption underpinning Bitcoin using under 500,000 physical qubits. As such, <a href="https://www.itpro.com/security/google-just-revised-its-q-day-timeline-quantum-computers-could-break-existing-encryption-techniques-within-three-years-and-enterprises-are-nowhere-near-ready"><u>Google accelerated its migration timeline</u></a> from the 2030s to 2029. This is simply one example of the industry ramping up the pace of its migration, with another <a href="https://arxiv.org/html/2603.28627v1"><u>March study</u></a> showing quantum computers may need as few as 10,000 qubits to one day break the most secure encryption algorithms. </p><p>But that doesn't seem to have moved the needle very much, with countless businesses still completely unprotected or in the very earliest stages of exploring moves to implement post-quantum cryptography (PQC) or related countermeasures. With the timelines accelerating, why is the business world still so slow to react to these looming threats that lie over the horizon?    </p><h2 id="how-prepared-are-we-for-a-post-quantum-world">How prepared are we for a post-quantum world?</h2><p>Existing research into business preparedness is incredibly bleak. The vast majority (90%) of companies don't have systems in place to defend against quantum security threats, according to <a href="https://www.itpro.com/security/90-percent-of-companies-are-woefully-unprepared-for-quantum-security-threats-analysts-say-they-need-to-get-a-move-on"><u>Bain & Company analysis</u></a>. It's a similar, albeit less extreme, story with <a href="https://www.itpro.com/security/nearly-half-of-enterprises-arent-prepared-for-quantum-cybersecurity-threats"><u>Keyfactor research</u></a> that shows nearly half (48%) aren't ready. </p><p>Juniper Research found that just 27% of global companies will deploy PQC – but only by 2035. Right now, that figure stands at roughly 0.0009%, or just 35,000. Compound these findings with <a href="https://cdn.prod.website-files.com/643b94c382e84463a9e52264/698a5056aa19e254d8105a24_Part_1_2026_Quantum_Readiness_Survey_Report.pdf"><u>QuEra research</u></a> that showed the level of confidence in quantum preparedness actually fell from 65% to 55% between 2025 and 2026, meaning that as the threats become less abstract, businesses are increasingly aware that the measures they've taken may not be sufficient. </p><p>There's a readiness gap – no matter how you interpret the many and various findings. But what does this actually mean in practice and why is there such a large gap? Knowledge is the primary deficit, says Arjun Kudinoor, a doctoral student and NSF Graduate Research Fellow at MIT, as well as quantum security advisor at Protegrity. Many organizations lack the required expertise to understand the risks, prepare existing systems, and identify valuable applications, according to Kudinoor.</p><p>"Businesses must begin developing quantum literacy across technical and executive teams, assessing their exposure to quantum-enabled cybersecurity threats, and identifying problems for which quantum computing could provide a meaningful advantage," he adds. </p><p>But according to Orange Business' quantum-safe network lead and program director of edge computing, Frank de Jong, awareness has increased significantly in the last few years. </p><p>He tells <em>ITPro</em>: "It is impossible to be quantum-ready today, and in my opinion, it is also questionable if you could be completely quantum-safe before 2029. That's why we advise customers to start planning now and prioritize protecting their most valuable assets first. The key is to begin the journey, not to wait for perfect conditions."</p><p>As things stand, some sectors are more prepared than others. The earliest movers were telecoms providers and infrastructure-heavy organizations, with financial services, healthcare and software providers following suit. But it's also true to say that preparedness varies more based on resources and expertise, adds Kudinoor. He explains that firms with strong technical teams, quantum-related budgets, and executives concerned about planning for the threat are moving the fastest.</p><h2 id="avoiding-a-slow-motion-quantum-disaster">Avoiding a slow-motion quantum disaster</h2><p>Quantum computing is difficult to wrap your head around, and it's long been a technology that's some years away from maturation. For that reason, it might be tempting for many to have kicked the issue deep into the long grass. Suja Viswesan, IBM VP of security software, acknowledges this impact. "It can feel overwhelming at the sheer magnitude of possible impact. But the best place to start is by gaining visibility. You can’t fix what you can’t see." </p><p>Businesses, she says, should start small by mapping cryptographic assets – including certificates, secrets and API keys – across their environments. Then, they should prioritize risk and introduce controls such as proxy layers to, as she puts it, "buy time" before full PQC upgrades are available. </p><p>Kohinoor rejects the notion that quantum computing's threats are abstract, telling <em>ITPro</em>: "Much work has been done to estimate the number of qubits, error rates, and error correction methods required to implement such quantum factoring algorithms on quantum hardware." </p><p>The most powerful quantum computers commercially available are only one or two orders of magnitude away from breaking encryption schemes like RSA-2048. Thankfully, he adds, it's "not yet a disaster" because we are still several difficult breakthroughs away from achieving a fault-tolerant cryptographically relevant quantum computer. </p><p>So what's to explain the general malaise in preparing for this eventuality? The answer may lie on the balance sheet – and the IT and security budgets that so many organizations are under pressure to spend on far more immediate threats.</p><p>Although <a href="https://www.itpro.com/infrastructure/gartner-just-revised-its-global-it-spending-projection-for-2026-heres-why"><u>IT spending is expected to hit $6.37 trillion this year</u></a>, 14.2% higher than last year's spend, much of this has been allocated toward either trendier areas or toward more concrete threats. As de Jong puts it, IT budgets are spent "on where the center of attention is".</p><p>"In recent years, this was predominantly AI, and still today, this is where the majority of the “additional” money gets spent," he explains. </p><p>"Transitioning to quantum-safe infrastructure isn't a simple project. It will require substantial, sustained investment over many years. The most urgent call to action for CXOs today is to start planning and allocating substantial budgets for the coming years. This isn't fear-mongering — it's pragmatism. We cannot afford to wait and see."   </p><h2 id="is-it-too-late-to-prepare-for-the-post-quantum-world">Is it too late to prepare for the post-quantum world? </h2><p>The urgency is certainly there, and many experts fear it's far too late to avoid the damage – especially given the rise of <a href="https://www.itpro.com/security/enterprises-arent-moving-fast-enough-on-post-quantum-cryptography-preparations-harvest-now-decrypt-later-attacks-mean-it-could-cost-them"><u>"harvest now, decrypt later" (HNDL) attacks</u></a> – in which cybercriminals steal encrypted data with the intent of cracking it in the years to come using quantum computers. </p><p>But even if that were the case, there's still far more damage that can be done if businesses are sluggish about getting their defenses sorted. In that vein, the experts we interviewed say it's never too late to prepare.</p><p>"As the saying goes, ‘The best time to plant a tree was 20 years ago. The second-best time is now.’ The challenge with cybersecurity threats is that they may or may not affect you, but the fact that they could is sufficient reason to pay attention," de Jong says, but concedes that many will never be fully prepared. </p><p>"Most organizations face 15 years of work to become quantum-safe, but they may have only three years to do it. This means that they need to prioritize and accept the fact that not every asset can be defended at the same level from the start."</p><p>In the last few years, the mood has certainly shifted away from maximum preparedness to damage limitation as the reality has hit the industry that businesses haven't been moving quickly enough. MIT's Kudinoor advises businesses to upgrade all systems to PQC, beginning with the highest priority and most publicly available systems. </p><p>But the reality is that the threats themselves won't all hit at once – despite the 'Q-Day' label implying there's a single moment in the future beyond which there's no return. As IBM's Viswesan explains: "We’ll see it materialize over time, spanning multiple years as different cryptographic systems become vulnerable at different times." </p><h2 id="quantum-readiness-is-all-about-making-haste-slowly">Quantum readiness is all about making haste slowly</h2><p>Given the gradual and unfolding nature of 'Q-Day',  businesses should avoid rushing their decision-making and adopt a balanced and thoughtful approach, whether that's in assessing their estate or engaging with vendors. </p><p>The name for this dilemma – in which you need to act fast but not so fast that you end up making poor decisions – is "festina lente", a Latin term that roughly translates to "hurry slowly". But that's easier said than done.</p><p>"Organizations shouldn't wait to begin the transformation journey, but they also shouldn't rush into decisions. That’s where crypto-agility comes into play," Viswesan continues. </p><p>"Crypto‑agility is the ability to migrate to post-quantum cryptography (PQC), while maintaining the flexibility to make changes without business disruption. Crypto‑agility allows organizations to scale cryptography‑based data protection with confidence, reduce the operational costs associated with managing cryptography, and meaningfully lower long‑term security risk."</p><p>What about quantum companies themselves? After all, aren't they causing the problem in the first place? As de Jong says, the supply chain is already seeing a lot of countermeasures embedded into products by design, for example, quantum-safe features in the systems that cloud companies provide. </p><p>Pro bono support may also be available to smaller companies without the budgets or expertise to fight this battle. But, he says, the problem is likely to impact the larger companies the most. </p><p>To adequately prepare, the experts also recommend that building quantum literacy among technical teams and executives is essential. These teams should then devise roadmaps, with budgets over the coming years incorporating more quantum line items. </p><p>This transition is new to almost everyone, meaning that it's a journey of discovery and the best practice is still being formulated. There are, however, companies that are further along the journey than others – and organizations should liaise with one another so that everyone can benefit together.</p><p>"The transition to quantum-safe is new for almost everyone," de Jong adds, "so I would advise enterprise CXOs not to try and reinvent the wheel themselves, but rather work with companies that have been working on it for several years, so everyone can benefit from the collective knowledge."</p><p>The timelines are shrinking with each quantum computing breakthrough, and there's a general acceptance among experts that it won't be possible for businesses to be fully quantum-ready by 2029 – especially if you factor in the HNDL attacks that have already happened. </p><p>That said, it's never too late to act to avoid the very worst of it, and businesses should do what they can to get as far ahead of this threat as possible before it's too late – no matter how tempting it is to route budgets into more appealing areas like AI. </p><p>Should more businesses begin to act faster, when 'Q-Day' begins to take hold, there's still every chance, much like the Y2K bug, that this will become yet another amusing anecdote from the annals of tech history about a massive computing threat that was avoided.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/how-seriously-is-your-business-taking-the-q-day-threat-and-can-you-really-be-ready-by-2029</link>
                                                                            <description>
                            <![CDATA[ The pace of progress on quantum computing isn't slowing down, but so many businesses still haven't prepared for the looming threat – with experts now shifting their rhetoric toward damage limitation ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">GHXSXxUcuJ73QVF6HDKVGA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/L5y7q8MWwZA5LGPEXPTRJM-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Sep 2026 07:00:00 +0000</pubDate>                                                                                                                                <updated>Wed, 02 Sep 2026 11:06:23 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ keumars.afifi-sabet@futurenet.com (Keumars Afifi-Sabet) ]]></author>                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/L5y7q8MWwZA5LGPEXPTRJM-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Quantum computing concept image showing three purple-colored, glowing blocks placed on top of circuit boards with connected data flows.]]></media:description>                                                            <media:text><![CDATA[Quantum computing concept image showing three purple-colored, glowing blocks placed on top of circuit boards with connected data flows.]]></media:text>
                                <media:title type="plain"><![CDATA[Quantum computing concept image showing three purple-colored, glowing blocks placed on top of circuit boards with connected data flows.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/L5y7q8MWwZA5LGPEXPTRJM-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>If you can cast your mind back to 1999, the computing world was in a frenzy over the Y2K bug, or Millennium Bug, a coding flaw where systems abbreviated four-digit years to two digits – so, 99 instead of 1999. </p><p>First identified in 1958, the fear was that computers would read '00' as 1900 instead of 2000, potentially crashing global infrastructure. As such, $300 billion (now worth a staggering $600 billion in today's money) was spent to upgrade computers and application programs so they were Y2K-compliant. Because of this monumental effort over many years, the crisis was largely averted.</p><p>In 2026, a similar panic is simmering at a glacial pace. The fear is Q-Day: a hypothetical moment at which quantum computers become so powerful that they can crack encryption algorithms within seconds. Leading industry figures, quantum computing companies, cybersecurity advisors, and even <a href="https://www.govinfo.gov/content/pkg/DCPD-202200355/html/DCPD-202200355.htm"><u>national government agencies</u></a> have been warning about this moment for years — as far back as 1994, when mathematician Peter Shor first published his paper warning about this exact possibility. </p><p>Since then, the threat has felt far away and abstract – with under-pressure businesses spending their precious IT budgets on more immediate threats. </p><p>But in March 2026, Google Quantum AI published research revealing that quantum computers can crack the encryption underpinning Bitcoin using under 500,000 physical qubits. As such, <a href="https://www.itpro.com/security/google-just-revised-its-q-day-timeline-quantum-computers-could-break-existing-encryption-techniques-within-three-years-and-enterprises-are-nowhere-near-ready"><u>Google accelerated its migration timeline</u></a> from the 2030s to 2029. This is simply one example of the industry ramping up the pace of its migration, with another <a href="https://arxiv.org/html/2603.28627v1"><u>March study</u></a> showing quantum computers may need as few as 10,000 qubits to one day break the most secure encryption algorithms. </p><p>But that doesn't seem to have moved the needle very much, with countless businesses still completely unprotected or in the very earliest stages of exploring moves to implement post-quantum cryptography (PQC) or related countermeasures. With the timelines accelerating, why is the business world still so slow to react to these looming threats that lie over the horizon?    </p><h2 id="how-prepared-are-we-for-a-post-quantum-world">How prepared are we for a post-quantum world?</h2><p>Existing research into business preparedness is incredibly bleak. The vast majority (90%) of companies don't have systems in place to defend against quantum security threats, according to <a href="https://www.itpro.com/security/90-percent-of-companies-are-woefully-unprepared-for-quantum-security-threats-analysts-say-they-need-to-get-a-move-on"><u>Bain & Company analysis</u></a>. It's a similar, albeit less extreme, story with <a href="https://www.itpro.com/security/nearly-half-of-enterprises-arent-prepared-for-quantum-cybersecurity-threats"><u>Keyfactor research</u></a> that shows nearly half (48%) aren't ready. </p><p>Juniper Research found that just 27% of global companies will deploy PQC – but only by 2035. Right now, that figure stands at roughly 0.0009%, or just 35,000. Compound these findings with <a href="https://cdn.prod.website-files.com/643b94c382e84463a9e52264/698a5056aa19e254d8105a24_Part_1_2026_Quantum_Readiness_Survey_Report.pdf"><u>QuEra research</u></a> that showed the level of confidence in quantum preparedness actually fell from 65% to 55% between 2025 and 2026, meaning that as the threats become less abstract, businesses are increasingly aware that the measures they've taken may not be sufficient. </p><p>There's a readiness gap – no matter how you interpret the many and various findings. But what does this actually mean in practice and why is there such a large gap? Knowledge is the primary deficit, says Arjun Kudinoor, a doctoral student and NSF Graduate Research Fellow at MIT, as well as quantum security advisor at Protegrity. Many organizations lack the required expertise to understand the risks, prepare existing systems, and identify valuable applications, according to Kudinoor.</p><p>"Businesses must begin developing quantum literacy across technical and executive teams, assessing their exposure to quantum-enabled cybersecurity threats, and identifying problems for which quantum computing could provide a meaningful advantage," he adds. </p><p>But according to Orange Business' quantum-safe network lead and program director of edge computing, Frank de Jong, awareness has increased significantly in the last few years. </p><p>He tells <em>ITPro</em>: "It is impossible to be quantum-ready today, and in my opinion, it is also questionable if you could be completely quantum-safe before 2029. That's why we advise customers to start planning now and prioritize protecting their most valuable assets first. The key is to begin the journey, not to wait for perfect conditions."</p><p>As things stand, some sectors are more prepared than others. The earliest movers were telecoms providers and infrastructure-heavy organizations, with financial services, healthcare and software providers following suit. But it's also true to say that preparedness varies more based on resources and expertise, adds Kudinoor. He explains that firms with strong technical teams, quantum-related budgets, and executives concerned about planning for the threat are moving the fastest.</p><h2 id="avoiding-a-slow-motion-quantum-disaster">Avoiding a slow-motion quantum disaster</h2><p>Quantum computing is difficult to wrap your head around, and it's long been a technology that's some years away from maturation. For that reason, it might be tempting for many to have kicked the issue deep into the long grass. Suja Viswesan, IBM VP of security software, acknowledges this impact. "It can feel overwhelming at the sheer magnitude of possible impact. But the best place to start is by gaining visibility. You can’t fix what you can’t see." </p><p>Businesses, she says, should start small by mapping cryptographic assets – including certificates, secrets and API keys – across their environments. Then, they should prioritize risk and introduce controls such as proxy layers to, as she puts it, "buy time" before full PQC upgrades are available. </p><p>Kohinoor rejects the notion that quantum computing's threats are abstract, telling <em>ITPro</em>: "Much work has been done to estimate the number of qubits, error rates, and error correction methods required to implement such quantum factoring algorithms on quantum hardware." </p><p>The most powerful quantum computers commercially available are only one or two orders of magnitude away from breaking encryption schemes like RSA-2048. Thankfully, he adds, it's "not yet a disaster" because we are still several difficult breakthroughs away from achieving a fault-tolerant cryptographically relevant quantum computer. </p><p>So what's to explain the general malaise in preparing for this eventuality? The answer may lie on the balance sheet – and the IT and security budgets that so many organizations are under pressure to spend on far more immediate threats.</p><p>Although <a href="https://www.itpro.com/infrastructure/gartner-just-revised-its-global-it-spending-projection-for-2026-heres-why"><u>IT spending is expected to hit $6.37 trillion this year</u></a>, 14.2% higher than last year's spend, much of this has been allocated toward either trendier areas or toward more concrete threats. As de Jong puts it, IT budgets are spent "on where the center of attention is".</p><p>"In recent years, this was predominantly AI, and still today, this is where the majority of the “additional” money gets spent," he explains. </p><p>"Transitioning to quantum-safe infrastructure isn't a simple project. It will require substantial, sustained investment over many years. The most urgent call to action for CXOs today is to start planning and allocating substantial budgets for the coming years. This isn't fear-mongering — it's pragmatism. We cannot afford to wait and see."   </p><h2 id="is-it-too-late-to-prepare-for-the-post-quantum-world">Is it too late to prepare for the post-quantum world? </h2><p>The urgency is certainly there, and many experts fear it's far too late to avoid the damage – especially given the rise of <a href="https://www.itpro.com/security/enterprises-arent-moving-fast-enough-on-post-quantum-cryptography-preparations-harvest-now-decrypt-later-attacks-mean-it-could-cost-them"><u>"harvest now, decrypt later" (HNDL) attacks</u></a> – in which cybercriminals steal encrypted data with the intent of cracking it in the years to come using quantum computers. </p><p>But even if that were the case, there's still far more damage that can be done if businesses are sluggish about getting their defenses sorted. In that vein, the experts we interviewed say it's never too late to prepare.</p><p>"As the saying goes, ‘The best time to plant a tree was 20 years ago. The second-best time is now.’ The challenge with cybersecurity threats is that they may or may not affect you, but the fact that they could is sufficient reason to pay attention," de Jong says, but concedes that many will never be fully prepared. </p><p>"Most organizations face 15 years of work to become quantum-safe, but they may have only three years to do it. This means that they need to prioritize and accept the fact that not every asset can be defended at the same level from the start."</p><p>In the last few years, the mood has certainly shifted away from maximum preparedness to damage limitation as the reality has hit the industry that businesses haven't been moving quickly enough. MIT's Kudinoor advises businesses to upgrade all systems to PQC, beginning with the highest priority and most publicly available systems. </p><p>But the reality is that the threats themselves won't all hit at once – despite the 'Q-Day' label implying there's a single moment in the future beyond which there's no return. As IBM's Viswesan explains: "We’ll see it materialize over time, spanning multiple years as different cryptographic systems become vulnerable at different times." </p><h2 id="quantum-readiness-is-all-about-making-haste-slowly">Quantum readiness is all about making haste slowly</h2><p>Given the gradual and unfolding nature of 'Q-Day',  businesses should avoid rushing their decision-making and adopt a balanced and thoughtful approach, whether that's in assessing their estate or engaging with vendors. </p><p>The name for this dilemma – in which you need to act fast but not so fast that you end up making poor decisions – is "festina lente", a Latin term that roughly translates to "hurry slowly". But that's easier said than done.</p><p>"Organizations shouldn't wait to begin the transformation journey, but they also shouldn't rush into decisions. That’s where crypto-agility comes into play," Viswesan continues. </p><p>"Crypto‑agility is the ability to migrate to post-quantum cryptography (PQC), while maintaining the flexibility to make changes without business disruption. Crypto‑agility allows organizations to scale cryptography‑based data protection with confidence, reduce the operational costs associated with managing cryptography, and meaningfully lower long‑term security risk."</p><p>What about quantum companies themselves? After all, aren't they causing the problem in the first place? As de Jong says, the supply chain is already seeing a lot of countermeasures embedded into products by design, for example, quantum-safe features in the systems that cloud companies provide. </p><p>Pro bono support may also be available to smaller companies without the budgets or expertise to fight this battle. But, he says, the problem is likely to impact the larger companies the most. </p><p>To adequately prepare, the experts also recommend that building quantum literacy among technical teams and executives is essential. These teams should then devise roadmaps, with budgets over the coming years incorporating more quantum line items. </p><p>This transition is new to almost everyone, meaning that it's a journey of discovery and the best practice is still being formulated. There are, however, companies that are further along the journey than others – and organizations should liaise with one another so that everyone can benefit together.</p><p>"The transition to quantum-safe is new for almost everyone," de Jong adds, "so I would advise enterprise CXOs not to try and reinvent the wheel themselves, but rather work with companies that have been working on it for several years, so everyone can benefit from the collective knowledge."</p><p>The timelines are shrinking with each quantum computing breakthrough, and there's a general acceptance among experts that it won't be possible for businesses to be fully quantum-ready by 2029 – especially if you factor in the HNDL attacks that have already happened. </p><p>That said, it's never too late to act to avoid the very worst of it, and businesses should do what they can to get as far ahead of this threat as possible before it's too late – no matter how tempting it is to route budgets into more appealing areas like AI. </p><p>Should more businesses begin to act faster, when 'Q-Day' begins to take hold, there's still every chance, much like the Y2K bug, that this will become yet another amusing anecdote from the annals of tech history about a massive computing threat that was avoided.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The intelligent workplace (part 3): Technology’s next transformation of work ]]></title>
                                                                                                <dc:content><![CDATA[ <h2 id="part-3-preparing-for-the-workplace-of-2030">Part 3: Preparing for the Workplace of 2030</h2><p>The workplace of 2030 will emerge from the convergence of <a href="https://www.itpro.com/technology/artificial-intelligence/what-is-ai"><u>AI</u></a>, <a href="https://www.itpro.com/technology/artificial-intelligence/four-things-you-need-to-know-about-openais-new-workspace-agents-for-chatgpt-including-how-to-build-your-own"><u>autonomous agents</u></a>, <a href="https://www.itpro.com/technology/will-autonomous-robotics-leap-forward-in-2026"><u>robotics</u></a>, <a href="https://www.itpro.com/technology/cognitive-technology/how-to-build-trust-into-automation-at-scale"><u>automation</u></a>, <a href="https://www.itpro.com/business/careers-and-training/what-are-the-minimum-skills-for-ai-use"><u>skills intelligence</u></a> and connected physical and digital environments. Together, they will change how organizations define jobs and create value for their businesses, customers and commercial partners.</p><p>Parts <a href="https://www.itpro.com/technology/artificial-intelligence/the-intelligent-workplace-technologys-next-transformation-of-work"><u>1</u></a> and <a href="https://www.itpro.com/technology/artificial-intelligence/the-intelligent-workplace-part-2-technologys-next-transformation-of-work"><u>2</u></a> of this series consider how intelligent technologies are transforming the employee experience and changing the way organisations manage performance and workforce development. These shifts are also early signals of a much larger transformation that will reshape the structure of work over the remainder of the decade.</p><p>Part 3 looks toward the workplace of 2030. It explores the technologies likely to influence how work is organized and the workforce strategies required to remain competitive. The challenge for organizations is no longer simply adopting AI, but building the adaptability to redesign roles and develop new capabilities as technology continues to evolve.</p><p>The scale of the transition will be substantial. The <a href="https://www.weforum.org/press/2025/01/future-of-jobs-report-2025-78-million-new-job-opportunities-by-2030-but-urgent-upskilling-needed-to-prepare-workforces"><u>World Economic Forum</u></a> expects structural change to affect 22% of today’s jobs by 2030. It forecasts that 170 million roles will be created and 92 million displaced, producing a net gain of 78 million jobs. This is not a simple story of technology eliminating employment. It is a redistribution of tasks and opportunities on a scale that will test every organization’s ability to adapt.</p><p>The question is not whether the <a href="https://www.itpro.com/business/the-future-of-business/tech-leaders-key-workplace-trends-2026"><u>workplace will change,</u></a> but whether companies can change with it. Preparing for 2030 means building an organization capable of <a href="https://www.itpro.com/business/business-strategy/can-microshifting-work-in-the-tech-sector"><u>redesigning work</u></a> and moving skills to where they generate the greatest value.</p><h2 id="emerging-technologies-will-reorganize-work">Emerging technologies will reorganize work</h2><p>AI will become foundational <a href="https://www.itpro.com/infrastructure/future-proofing-ai-infrastructure"><u>workplace infrastructure</u></a>. Adoption is already accelerating. <a href="https://hai.stanford.edu/ai-index/2026-ai-index-report/economy"><u>Stanford’s AI Index</u></a> reports that 88% of surveyed organizations were using AI in 2025, with 70% using <a href="https://www.itpro.com/software/development/developers-are-struggling-to-build-generative-ai-applications-heres-why"><u>generative AI </u></a>in at least one business function. Generative AI reached approximately 53% of the general population within three years—faster than either the personal computer or the internet. <a href="https://www.itpro.com/technology/artificial-intelligence/how-ai-agents-are-being-deployed-in-the-real-world"><u>Agent deployment</u></a>, however, remained in single digits across almost all business functions, showing how early the next stage remains.</p><p>Wendy Harris, VP of EMEA at Rippling, says the real shift will come from “the convergence of AI, automation, skills intelligence and autonomous agents.” Instead of organizing work around fixed jobs and rigid processes, companies will increasingly match people and machines to tasks and outcomes in real time.</p><p>“The real transformation happens when organizations move away from assigning work based solely on headcount and job titles, and instead allocate tasks to the capabilities best suited to deliver an outcome, whether those capabilities are human, machine or a combination of both,” Ciara Harrington, chief people officer at Skillsoft, tells <em>ITPro.</em></p><p>The transition extends beyond office-based generative AI. Robots will work beside people in <a href="https://www.itpro.com/technology/artificial-intelligence/what-is-an-ai-factory-and-what-does-it-mean-for-enterprises"><u>factories</u></a>, <a href="https://www.itpro.com/technology/artificial-intelligence/how-is-ai-improving-healthcare"><u>hospitals</u></a>, <a href="https://www.itpro.com/infrastructure/how-tech-is-changing-the-construction-industry"><u>construction</u></a>, and <a href="https://www.itpro.com/technology/artificial-intelligence/how-can-ai-benefit-supply-chain"><u>logistics</u></a>. Immersive systems will support training and remote maintenance. The opportunity lies in connecting these technologies to redesigned workflows rather than accelerating yesterday’s processes.</p><p>As Part 1 of this series considered, successful workplace transformation depends on more than introducing advanced tools. These technologies must form part of an intelligent employee experience that reduces digital friction and gives people greater capacity for judgment, creativity and collaboration.</p><h2 id="jobs-will-change-faster-than-they-disappear">Jobs will change faster than they disappear</h2><p>Predictions of mass technological unemployment obscure a more complex reality. The <a href="https://webapps.ilo.org/static/english/intserv/working-papers/wp140/index.html"><u>International Labour Organization</u></a> estimates that one in four jobs worldwide has some exposure to generative AI, yet only 3.3% of global employment falls within the highest exposure category. Transformation is more likely than wholesale replacement.</p><p>Even highly exposed occupations may prove difficult to automate completely. Managers, engineers, and other <a href="https://www.itpro.com/technology/artificial-intelligence/how-ai-can-augment-security-professionals-capabilities"><u>professionals</u></a> often depend on social interaction and contextual judgment. AI may take over parts of these roles while increasing the value of the <a href="https://www.itpro.com/business/careers-and-training/what-are-the-minimum-skills-for-ai-use"><u>human capabilities </u></a>surrounding them.</p><p>“Every role is made up of hundreds of tasks,” Harris explained. “AI doesn’t eliminate most roles—it changes the balance of those tasks.” Repetitive, administrative, and analytical work can move to technology, creating more space for judgment, creativity, communication, and problem-solving.</p><p>That requires organizations to design work at the task and capability level rather than making workforce decisions solely through job titles. Oliver Shaw, CEO of Orgvue, warns that many companies have invested in AI without considering its effect on work or the workforce. His company’s research found that 57% of business leaders deployed AI primarily because competitors had done so, while 78% of organizations had seen AI projects fail or remain stuck in pilots.</p><p>“A clear example of this is the PR and marketing industries,” says Shaw. “Both [are] fields that have been at the centre of the conversation on the disproportionate impact of AI adoption on entry-level roles, and what this’ll mean for the future of the industry when entry points are few and far between, and the foundational skills are missing. What these industries are forgetting is to train staff on the critical thinking required to use AI, and the cognitive offloading that occurs when there is too much reliance.”</p><p>Leaders risk automating fragments of work without considering which decisions remain human, or how entry-level workers develop expertise when foundational tasks disappear. Organizations should identify where AI can execute and where collaboration produces greater value.</p><p>This division of responsibilities also has direct implications for the performance and leadership questions explored in Part 2 of this series. Organizations will need to assess how effectively employees delegate to AI and apply human judgment, while ensuring accountability for consequential decisions remains clearly defined.</p><h2 id="continuous-learning-becomes-core-infrastructure">Continuous learning becomes core infrastructure</h2><p>Skills will be the pressure point of the 2030 workplace. Employers expect 39% of workers’ <a href="https://www.itpro.com/software/development/the-biggest-barrier-to-growth-is-not-access-to-technology-it-is-access-to-the-right-people-demand-for-developers-with-ai-skills-has-surged-597-percent-but-enterprises-are-still-struggling-to-find-the-right-talent"><u>core skills</u></a> to change by the end of the decade. AI and <a href="https://www.itpro.com/technology/artificial-intelligence/how-ai-is-transforming-enterprise-data"><u>big data</u></a> are forecast to be the fastest-growing skills area, followed by networks and <a href="https://www.itpro.com/security/cybersecurity-skills-what-can-be-done"><u>cybersecurity</u></a> and then technological literacy. However, creative thinking, resilience, agility, curiosity, and lifelong learning will also increase in importance.</p><p>Technical and human capabilities are not competing categories. According to the <a href="https://www.oecd.org/en/publications/empowering-the-workforce-in-the-context-of-a-skills-first-approach_345b6528-en/full-report/skills-first-in-oecd-countries-concepts-trends-and-implications-for-the-labour-market_0d6ba66f.html"><u>OECD</u></a>, 72% of vacancies in occupations highly exposed to AI already require at least one management skill, while 67% require a business-process skill. The employee who can operate an AI system but cannot question its output will offer limited value.</p><p>Jen Paterno, senior behavioral scientist at CoachHub, emphasised that judgment, adaptability, critical thinking, collaboration, and self-awareness develop through experience, reflection, and feedback—not conventional training alone. </p><p>“These capabilities are difficult to build through conventional training alone because they develop through experience, reflection, and feedback,” Paterno explained to <em>ITPro</em>. </p><p>“Organizations will need more continuous, personalized development models that help employees practice new behaviors in the flow of work. Coaching will also be critical in ensuring people have objective, brave spaces to experiment and ideate with skills that feel more foreign to them.”</p><p>The scale of the challenge is considerable. The <a href="https://www.weforum.org/press/2025/01/future-of-jobs-report-2025-78-million-new-job-opportunities-by-2030-but-urgent-upskilling-needed-to-prepare-workforces"><u>World Economic Forum</u></a> predicts that around 59% of the global workforce will require training by 2030. For every 100 workers, 11 may not receive the upskilling or reskilling they need, leaving more than 120 million people at medium-term risk of redundancy. Although 85% of employers intend to prioritize <a href="https://www.itpro.com/technology/artificial-intelligence/how-to-immerse-your-employees-in-ai-training"><u>workforce upskilling</u></a>, the intention must be converted into accessible learning and credible pathways into new work.</p><p>Annual courses and static competency frameworks are too slow. Harrington says organizations need systems that identify emerging skills and adapt as requirements evolve. <a href="https://insight.skillsoft.com/workforce-readiness-report-ai-edition/p/1"><u>Skillsoft</u></a> found that although 86% of employees use AI at work, fewer than one-quarter feel equipped to use it effectively. Access without capability risks creating <a href="https://www.itpro.com/technology/artificial-intelligence/ai-is-creating-a-two-track-labor-market-with-better-pay-for-human-intensive-skills"><u>two workforces</u></a>.</p><p>Skills-based models can help companies see capability beyond formal qualifications or job titles. They can also support internal mobility. Half of employers plan to move people from declining roles into growing areas, while 29% of workers requiring training could be upskilled in their current positions and 19% retrained and redeployed elsewhere, according to the <a href="https://www.weforum.org/publications/the-future-of-jobs-report-2025/digest"><u>World Economic Forum</u></a>.</p><h2 id="adaptability-will-define-competitive-advantage">Adaptability will define competitive advantage</h2><p>Workforce strategy must become more dynamic. Leaders need shorter review cycles, real-time <a href="https://www.itpro.com/software/development/anthropic-research-ai-coding-skills-formation-impact"><u>skills visibility, </u></a>plus the ability to test new roles and workflows before scaling them.</p><p>David Shrier, Professor of Practice, AI and Innovation at Imperial Business School, argues that annual planning and conventional five-year strategies can no longer support decision-making. He recommends “nimble scenarios” that allow leaders to respond more rapidly to technological and market uncertainty. AI can support that planning, but it cannot determine the organization’s purpose or appetite for change.</p><p>Business leaders must also ensure that opportunity is distributed fairly. Generative AI exposure differs significantly between countries and demographic groups. Around 34% of employment in high-income economies has some AI exposure, compared with 11% in low-income countries. Women are also more highly represented in the most exposed occupations, making inclusive training and transition programs essential, the <a href="https://www.ilo.org/publications/generative-ai-and-jobs-refined-global-index-occupational-exposure"><u>International Labor Organization</u></a> reports.</p><p>Heather Delaney, managing director and founder of Gallium Ventures, emphasised the importance of flexible planning cycles that create room for experimentation. “AI is advancing faster than a lot of us can keep up with, so flexible planning cycles that allow room for experimentation are integral to ensuring decisions made are future-proofing you and your business to grow with emerging technologies.”</p><p>Preparing for 2030 is ultimately an organizational capability rather than a forecasting exercise. No leader can know precisely which tools or roles will dominate at the end of the decade. Companies can, however, build the capacity to sense change, move skills quickly, involve employees in redesigning work, and preserve human agency as machines assume greater responsibility.</p><p>Across this series, one conclusion is clear: the intelligent workplace is not defined by how much technology an organization deploys, but by how effectively it combines technological capability with human judgment. From improving the everyday employee experience to rethinking performance, success depends on using AI to strengthen rather than diminish people’s contribution. </p><p>As 2030 approaches, the workplace of 2030 will not be won by the organization with the most AI. Competitive advantage will belong to businesses that combine technology with judgment and turn disruption into opportunity for both the enterprise and its people. Technology will shape the next generation of work, but the quality of leadership and workforce strategy will determine who benefits from it.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/technology/artificial-intelligence/the-intelligent-workplace-part-3-technologys-next-transformation-of-work</link>
                                                                            <description>
                            <![CDATA[ Emerging technologies, evolving skills, and agile workforce strategies will determine which organizations remain competitive in the workplace of 2030 ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kgMhUhCSE9pM4iKJiiFnM9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4k5sqaFTSYzmJVJsTq3VXE-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 01 Sep 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ David Howell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/RyCMPNysW5pydbG6t9n8Kh-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4k5sqaFTSYzmJVJsTq3VXE-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Sovereign AI concept image showing an artificial digitized brain absorbing data from multiple different directions. ]]></media:description>                                                            <media:text><![CDATA[Sovereign AI concept image showing an artificial digitized brain absorbing data from multiple different directions. ]]></media:text>
                                <media:title type="plain"><![CDATA[Sovereign AI concept image showing an artificial digitized brain absorbing data from multiple different directions. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4k5sqaFTSYzmJVJsTq3VXE-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <h2 id="part-3-preparing-for-the-workplace-of-2030">Part 3: Preparing for the Workplace of 2030</h2><p>The workplace of 2030 will emerge from the convergence of <a href="https://www.itpro.com/technology/artificial-intelligence/what-is-ai"><u>AI</u></a>, <a href="https://www.itpro.com/technology/artificial-intelligence/four-things-you-need-to-know-about-openais-new-workspace-agents-for-chatgpt-including-how-to-build-your-own"><u>autonomous agents</u></a>, <a href="https://www.itpro.com/technology/will-autonomous-robotics-leap-forward-in-2026"><u>robotics</u></a>, <a href="https://www.itpro.com/technology/cognitive-technology/how-to-build-trust-into-automation-at-scale"><u>automation</u></a>, <a href="https://www.itpro.com/business/careers-and-training/what-are-the-minimum-skills-for-ai-use"><u>skills intelligence</u></a> and connected physical and digital environments. Together, they will change how organizations define jobs and create value for their businesses, customers and commercial partners.</p><p>Parts <a href="https://www.itpro.com/technology/artificial-intelligence/the-intelligent-workplace-technologys-next-transformation-of-work"><u>1</u></a> and <a href="https://www.itpro.com/technology/artificial-intelligence/the-intelligent-workplace-part-2-technologys-next-transformation-of-work"><u>2</u></a> of this series consider how intelligent technologies are transforming the employee experience and changing the way organisations manage performance and workforce development. These shifts are also early signals of a much larger transformation that will reshape the structure of work over the remainder of the decade.</p><p>Part 3 looks toward the workplace of 2030. It explores the technologies likely to influence how work is organized and the workforce strategies required to remain competitive. The challenge for organizations is no longer simply adopting AI, but building the adaptability to redesign roles and develop new capabilities as technology continues to evolve.</p><p>The scale of the transition will be substantial. The <a href="https://www.weforum.org/press/2025/01/future-of-jobs-report-2025-78-million-new-job-opportunities-by-2030-but-urgent-upskilling-needed-to-prepare-workforces"><u>World Economic Forum</u></a> expects structural change to affect 22% of today’s jobs by 2030. It forecasts that 170 million roles will be created and 92 million displaced, producing a net gain of 78 million jobs. This is not a simple story of technology eliminating employment. It is a redistribution of tasks and opportunities on a scale that will test every organization’s ability to adapt.</p><p>The question is not whether the <a href="https://www.itpro.com/business/the-future-of-business/tech-leaders-key-workplace-trends-2026"><u>workplace will change,</u></a> but whether companies can change with it. Preparing for 2030 means building an organization capable of <a href="https://www.itpro.com/business/business-strategy/can-microshifting-work-in-the-tech-sector"><u>redesigning work</u></a> and moving skills to where they generate the greatest value.</p><h2 id="emerging-technologies-will-reorganize-work">Emerging technologies will reorganize work</h2><p>AI will become foundational <a href="https://www.itpro.com/infrastructure/future-proofing-ai-infrastructure"><u>workplace infrastructure</u></a>. Adoption is already accelerating. <a href="https://hai.stanford.edu/ai-index/2026-ai-index-report/economy"><u>Stanford’s AI Index</u></a> reports that 88% of surveyed organizations were using AI in 2025, with 70% using <a href="https://www.itpro.com/software/development/developers-are-struggling-to-build-generative-ai-applications-heres-why"><u>generative AI </u></a>in at least one business function. Generative AI reached approximately 53% of the general population within three years—faster than either the personal computer or the internet. <a href="https://www.itpro.com/technology/artificial-intelligence/how-ai-agents-are-being-deployed-in-the-real-world"><u>Agent deployment</u></a>, however, remained in single digits across almost all business functions, showing how early the next stage remains.</p><p>Wendy Harris, VP of EMEA at Rippling, says the real shift will come from “the convergence of AI, automation, skills intelligence and autonomous agents.” Instead of organizing work around fixed jobs and rigid processes, companies will increasingly match people and machines to tasks and outcomes in real time.</p><p>“The real transformation happens when organizations move away from assigning work based solely on headcount and job titles, and instead allocate tasks to the capabilities best suited to deliver an outcome, whether those capabilities are human, machine or a combination of both,” Ciara Harrington, chief people officer at Skillsoft, tells <em>ITPro.</em></p><p>The transition extends beyond office-based generative AI. Robots will work beside people in <a href="https://www.itpro.com/technology/artificial-intelligence/what-is-an-ai-factory-and-what-does-it-mean-for-enterprises"><u>factories</u></a>, <a href="https://www.itpro.com/technology/artificial-intelligence/how-is-ai-improving-healthcare"><u>hospitals</u></a>, <a href="https://www.itpro.com/infrastructure/how-tech-is-changing-the-construction-industry"><u>construction</u></a>, and <a href="https://www.itpro.com/technology/artificial-intelligence/how-can-ai-benefit-supply-chain"><u>logistics</u></a>. Immersive systems will support training and remote maintenance. The opportunity lies in connecting these technologies to redesigned workflows rather than accelerating yesterday’s processes.</p><p>As Part 1 of this series considered, successful workplace transformation depends on more than introducing advanced tools. These technologies must form part of an intelligent employee experience that reduces digital friction and gives people greater capacity for judgment, creativity and collaboration.</p><h2 id="jobs-will-change-faster-than-they-disappear">Jobs will change faster than they disappear</h2><p>Predictions of mass technological unemployment obscure a more complex reality. The <a href="https://webapps.ilo.org/static/english/intserv/working-papers/wp140/index.html"><u>International Labour Organization</u></a> estimates that one in four jobs worldwide has some exposure to generative AI, yet only 3.3% of global employment falls within the highest exposure category. Transformation is more likely than wholesale replacement.</p><p>Even highly exposed occupations may prove difficult to automate completely. Managers, engineers, and other <a href="https://www.itpro.com/technology/artificial-intelligence/how-ai-can-augment-security-professionals-capabilities"><u>professionals</u></a> often depend on social interaction and contextual judgment. AI may take over parts of these roles while increasing the value of the <a href="https://www.itpro.com/business/careers-and-training/what-are-the-minimum-skills-for-ai-use"><u>human capabilities </u></a>surrounding them.</p><p>“Every role is made up of hundreds of tasks,” Harris explained. “AI doesn’t eliminate most roles—it changes the balance of those tasks.” Repetitive, administrative, and analytical work can move to technology, creating more space for judgment, creativity, communication, and problem-solving.</p><p>That requires organizations to design work at the task and capability level rather than making workforce decisions solely through job titles. Oliver Shaw, CEO of Orgvue, warns that many companies have invested in AI without considering its effect on work or the workforce. His company’s research found that 57% of business leaders deployed AI primarily because competitors had done so, while 78% of organizations had seen AI projects fail or remain stuck in pilots.</p><p>“A clear example of this is the PR and marketing industries,” says Shaw. “Both [are] fields that have been at the centre of the conversation on the disproportionate impact of AI adoption on entry-level roles, and what this’ll mean for the future of the industry when entry points are few and far between, and the foundational skills are missing. What these industries are forgetting is to train staff on the critical thinking required to use AI, and the cognitive offloading that occurs when there is too much reliance.”</p><p>Leaders risk automating fragments of work without considering which decisions remain human, or how entry-level workers develop expertise when foundational tasks disappear. Organizations should identify where AI can execute and where collaboration produces greater value.</p><p>This division of responsibilities also has direct implications for the performance and leadership questions explored in Part 2 of this series. Organizations will need to assess how effectively employees delegate to AI and apply human judgment, while ensuring accountability for consequential decisions remains clearly defined.</p><h2 id="continuous-learning-becomes-core-infrastructure">Continuous learning becomes core infrastructure</h2><p>Skills will be the pressure point of the 2030 workplace. Employers expect 39% of workers’ <a href="https://www.itpro.com/software/development/the-biggest-barrier-to-growth-is-not-access-to-technology-it-is-access-to-the-right-people-demand-for-developers-with-ai-skills-has-surged-597-percent-but-enterprises-are-still-struggling-to-find-the-right-talent"><u>core skills</u></a> to change by the end of the decade. AI and <a href="https://www.itpro.com/technology/artificial-intelligence/how-ai-is-transforming-enterprise-data"><u>big data</u></a> are forecast to be the fastest-growing skills area, followed by networks and <a href="https://www.itpro.com/security/cybersecurity-skills-what-can-be-done"><u>cybersecurity</u></a> and then technological literacy. However, creative thinking, resilience, agility, curiosity, and lifelong learning will also increase in importance.</p><p>Technical and human capabilities are not competing categories. According to the <a href="https://www.oecd.org/en/publications/empowering-the-workforce-in-the-context-of-a-skills-first-approach_345b6528-en/full-report/skills-first-in-oecd-countries-concepts-trends-and-implications-for-the-labour-market_0d6ba66f.html"><u>OECD</u></a>, 72% of vacancies in occupations highly exposed to AI already require at least one management skill, while 67% require a business-process skill. The employee who can operate an AI system but cannot question its output will offer limited value.</p><p>Jen Paterno, senior behavioral scientist at CoachHub, emphasised that judgment, adaptability, critical thinking, collaboration, and self-awareness develop through experience, reflection, and feedback—not conventional training alone. </p><p>“These capabilities are difficult to build through conventional training alone because they develop through experience, reflection, and feedback,” Paterno explained to <em>ITPro</em>. </p><p>“Organizations will need more continuous, personalized development models that help employees practice new behaviors in the flow of work. Coaching will also be critical in ensuring people have objective, brave spaces to experiment and ideate with skills that feel more foreign to them.”</p><p>The scale of the challenge is considerable. The <a href="https://www.weforum.org/press/2025/01/future-of-jobs-report-2025-78-million-new-job-opportunities-by-2030-but-urgent-upskilling-needed-to-prepare-workforces"><u>World Economic Forum</u></a> predicts that around 59% of the global workforce will require training by 2030. For every 100 workers, 11 may not receive the upskilling or reskilling they need, leaving more than 120 million people at medium-term risk of redundancy. Although 85% of employers intend to prioritize <a href="https://www.itpro.com/technology/artificial-intelligence/how-to-immerse-your-employees-in-ai-training"><u>workforce upskilling</u></a>, the intention must be converted into accessible learning and credible pathways into new work.</p><p>Annual courses and static competency frameworks are too slow. Harrington says organizations need systems that identify emerging skills and adapt as requirements evolve. <a href="https://insight.skillsoft.com/workforce-readiness-report-ai-edition/p/1"><u>Skillsoft</u></a> found that although 86% of employees use AI at work, fewer than one-quarter feel equipped to use it effectively. Access without capability risks creating <a href="https://www.itpro.com/technology/artificial-intelligence/ai-is-creating-a-two-track-labor-market-with-better-pay-for-human-intensive-skills"><u>two workforces</u></a>.</p><p>Skills-based models can help companies see capability beyond formal qualifications or job titles. They can also support internal mobility. Half of employers plan to move people from declining roles into growing areas, while 29% of workers requiring training could be upskilled in their current positions and 19% retrained and redeployed elsewhere, according to the <a href="https://www.weforum.org/publications/the-future-of-jobs-report-2025/digest"><u>World Economic Forum</u></a>.</p><h2 id="adaptability-will-define-competitive-advantage">Adaptability will define competitive advantage</h2><p>Workforce strategy must become more dynamic. Leaders need shorter review cycles, real-time <a href="https://www.itpro.com/software/development/anthropic-research-ai-coding-skills-formation-impact"><u>skills visibility, </u></a>plus the ability to test new roles and workflows before scaling them.</p><p>David Shrier, Professor of Practice, AI and Innovation at Imperial Business School, argues that annual planning and conventional five-year strategies can no longer support decision-making. He recommends “nimble scenarios” that allow leaders to respond more rapidly to technological and market uncertainty. AI can support that planning, but it cannot determine the organization’s purpose or appetite for change.</p><p>Business leaders must also ensure that opportunity is distributed fairly. Generative AI exposure differs significantly between countries and demographic groups. Around 34% of employment in high-income economies has some AI exposure, compared with 11% in low-income countries. Women are also more highly represented in the most exposed occupations, making inclusive training and transition programs essential, the <a href="https://www.ilo.org/publications/generative-ai-and-jobs-refined-global-index-occupational-exposure"><u>International Labor Organization</u></a> reports.</p><p>Heather Delaney, managing director and founder of Gallium Ventures, emphasised the importance of flexible planning cycles that create room for experimentation. “AI is advancing faster than a lot of us can keep up with, so flexible planning cycles that allow room for experimentation are integral to ensuring decisions made are future-proofing you and your business to grow with emerging technologies.”</p><p>Preparing for 2030 is ultimately an organizational capability rather than a forecasting exercise. No leader can know precisely which tools or roles will dominate at the end of the decade. Companies can, however, build the capacity to sense change, move skills quickly, involve employees in redesigning work, and preserve human agency as machines assume greater responsibility.</p><p>Across this series, one conclusion is clear: the intelligent workplace is not defined by how much technology an organization deploys, but by how effectively it combines technological capability with human judgment. From improving the everyday employee experience to rethinking performance, success depends on using AI to strengthen rather than diminish people’s contribution. </p><p>As 2030 approaches, the workplace of 2030 will not be won by the organization with the most AI. Competitive advantage will belong to businesses that combine technology with judgment and turn disruption into opportunity for both the enterprise and its people. Technology will shape the next generation of work, but the quality of leadership and workforce strategy will determine who benefits from it.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How AI and automation empower MSPs ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Cyberattacks are getting faster, more evasive, and easier to execute with both scale and precision. The window of time it takes for an attack to escalate is often measured in minutes, not hours or days, as attackers use automation, phishing-as-a-service kits, and AI tools to move faster and evade detection.</p><p>Traditional reactive security defences were not designed for this. </p><p>With customers looking to them for protection against ever-evolving threats, Managed Service Providers (MSPs) must learn to navigate this era of generative and agentic AI. This requires continuous visibility and response across the full attack lifecycle. Becoming fluent in AI and combining intelligent automation with human judgement is essential to building cyber resilience in customer environments.</p><p>This is a great opportunity for MSPs. Partners that can move beyond the traditional model of blocking known threats and static signatures will gain a powerful competitive advantage in this new threat environment. </p><h2 id="how-msps-can-get-ahead">How MSPs can get ahead</h2><p>It’s never been easier for threat actors to launch campaigns. Service-based platforms have industrialized credential theft, initial access, malware distribution, and more, lowering the barrier to entry while increasing attack volume and consistency. </p><p><a href="https://www.barracuda.com/reports/2026-email-threats-report"><u>Our research</u></a> found that 90% of high-volume phishing campaigns in 2025 used kits, a significant jump from 30% the year before. We’re also seeing a growing number of attacks incorporating AI tools, such as using generative AI to rapidly craft deceptive messages and quickly shift tactics.  </p><p>When an attack can progress from initial access to persistence and device compromise in five minutes, organizations need partners that can detect and respond in real-time. </p><p>The answer lies in moving from reactive support to proactive resilience. </p><p>That means continuous monitoring, earlier detection, and automated containment of suspicious incidents and anomalies rather than waiting for an incident ticket to land.</p><p>That shift changes the customer relationship, too. When an MSP identifies and addresses a threat before the customer is aware of it, the conversation moves from damage limitation to strategic guidance. That’s a different kind of value, building a stronger and longer-lasting relationship. </p><p>The MSPs best placed to make this transition are those investing now in the tools, workflows, and expertise to deliver security that is proactive by design rather than reactive by default.</p><h2 id="embracing-ai-and-automation">Embracing AI and automation </h2><p>Integrating AI and automation into MSP security offerings isn’t about replacing human expertise, but about making that expertise scale.</p><p>Manual monitoring across fragmented customer environments, including email, identity, endpoints, networks, and cloud infrastructure, isn’t viable at the speed at which modern threats move. </p><p>AI changes that paradigm, with automated monitoring tools providing continuous oversight, correlating signals across the full environment rather than treating each layer in isolation. Anomalies that could take a human analyst hours to qualify can be flagged in seconds. Routine threats can be contained automatically, without an analyst needing to intervene.</p><p>That last point is especially important, as alert fatigue is a pressing problem for security teams managing multiple customer environments simultaneously. When automation handles the high-volume, lower-complexity end of the threat spectrum, analysts can concentrate on the incidents that require business context, judgment, and experience to resolve.</p><h2 id="personalized-solutions">Personalized solutions </h2><p>The strongest security outcomes combine intelligent automation with human expertise, not substituting one for the other. Automation delivers speed and scale. People deliver understanding and context. Together, they allow MSPs to provide protection that is continuous, adaptive and aligned to what customers actually need – oversight that keeps pace with the threat environment rather than perpetually chasing it.</p><p>Predictive AI analytics also has huge potential for helping MSPs anticipate the needs of their customers. With greater insight into resourcing needs, security threats and growth opportunities, MSPs can provide personalized services which align with each customer's business priorities and future needs. </p><h2 id="building-for-what-comes-next">Building for what comes next</h2><p>The gap between the speed of attacks and the speed of defence is widening.</p><p>AI and automation give MSPs a credible path to closing that gap, not by removing the human element, but by ensuring that human expertise is applied where it matters most. Providers that invest in building that capability now will be better positioned to protect their customers, reduce operational strain, and have more meaningful conversations about resilience rather than recovery.</p><p>MSPs that move toward a proactive, AI-augmented security model stand to differentiate themselves in a crowded market, not just as service providers, but as the kind of trusted advisors that customers need against increasingly fast and unpredictable threats. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/technology/artificial-intelligence/how-ai-and-automation-empower-msps</link>
                                                                            <description>
                            <![CDATA[ How intelligent automation helps MSPs deliver stronger, faster cyber resilience. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">LPfBdF5BgkBLjqbk3XdsYG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4k5sqaFTSYzmJVJsTq3VXE-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 31 Aug 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Erin O’Kane ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/xfpnZMWfvGFQRFBX6LxDGA-320-70.webp ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4k5sqaFTSYzmJVJsTq3VXE-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Sovereign AI concept image showing an artificial digitized brain absorbing data from multiple different directions. ]]></media:description>                                                            <media:text><![CDATA[Sovereign AI concept image showing an artificial digitized brain absorbing data from multiple different directions. ]]></media:text>
                                <media:title type="plain"><![CDATA[Sovereign AI concept image showing an artificial digitized brain absorbing data from multiple different directions. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4k5sqaFTSYzmJVJsTq3VXE-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyberattacks are getting faster, more evasive, and easier to execute with both scale and precision. The window of time it takes for an attack to escalate is often measured in minutes, not hours or days, as attackers use automation, phishing-as-a-service kits, and AI tools to move faster and evade detection.</p><p>Traditional reactive security defences were not designed for this. </p><p>With customers looking to them for protection against ever-evolving threats, Managed Service Providers (MSPs) must learn to navigate this era of generative and agentic AI. This requires continuous visibility and response across the full attack lifecycle. Becoming fluent in AI and combining intelligent automation with human judgement is essential to building cyber resilience in customer environments.</p><p>This is a great opportunity for MSPs. Partners that can move beyond the traditional model of blocking known threats and static signatures will gain a powerful competitive advantage in this new threat environment. </p><h2 id="how-msps-can-get-ahead">How MSPs can get ahead</h2><p>It’s never been easier for threat actors to launch campaigns. Service-based platforms have industrialized credential theft, initial access, malware distribution, and more, lowering the barrier to entry while increasing attack volume and consistency. </p><p><a href="https://www.barracuda.com/reports/2026-email-threats-report"><u>Our research</u></a> found that 90% of high-volume phishing campaigns in 2025 used kits, a significant jump from 30% the year before. We’re also seeing a growing number of attacks incorporating AI tools, such as using generative AI to rapidly craft deceptive messages and quickly shift tactics.  </p><p>When an attack can progress from initial access to persistence and device compromise in five minutes, organizations need partners that can detect and respond in real-time. </p><p>The answer lies in moving from reactive support to proactive resilience. </p><p>That means continuous monitoring, earlier detection, and automated containment of suspicious incidents and anomalies rather than waiting for an incident ticket to land.</p><p>That shift changes the customer relationship, too. When an MSP identifies and addresses a threat before the customer is aware of it, the conversation moves from damage limitation to strategic guidance. That’s a different kind of value, building a stronger and longer-lasting relationship. </p><p>The MSPs best placed to make this transition are those investing now in the tools, workflows, and expertise to deliver security that is proactive by design rather than reactive by default.</p><h2 id="embracing-ai-and-automation">Embracing AI and automation </h2><p>Integrating AI and automation into MSP security offerings isn’t about replacing human expertise, but about making that expertise scale.</p><p>Manual monitoring across fragmented customer environments, including email, identity, endpoints, networks, and cloud infrastructure, isn’t viable at the speed at which modern threats move. </p><p>AI changes that paradigm, with automated monitoring tools providing continuous oversight, correlating signals across the full environment rather than treating each layer in isolation. Anomalies that could take a human analyst hours to qualify can be flagged in seconds. Routine threats can be contained automatically, without an analyst needing to intervene.</p><p>That last point is especially important, as alert fatigue is a pressing problem for security teams managing multiple customer environments simultaneously. When automation handles the high-volume, lower-complexity end of the threat spectrum, analysts can concentrate on the incidents that require business context, judgment, and experience to resolve.</p><h2 id="personalized-solutions">Personalized solutions </h2><p>The strongest security outcomes combine intelligent automation with human expertise, not substituting one for the other. Automation delivers speed and scale. People deliver understanding and context. Together, they allow MSPs to provide protection that is continuous, adaptive and aligned to what customers actually need – oversight that keeps pace with the threat environment rather than perpetually chasing it.</p><p>Predictive AI analytics also has huge potential for helping MSPs anticipate the needs of their customers. With greater insight into resourcing needs, security threats and growth opportunities, MSPs can provide personalized services which align with each customer's business priorities and future needs. </p><h2 id="building-for-what-comes-next">Building for what comes next</h2><p>The gap between the speed of attacks and the speed of defence is widening.</p><p>AI and automation give MSPs a credible path to closing that gap, not by removing the human element, but by ensuring that human expertise is applied where it matters most. Providers that invest in building that capability now will be better positioned to protect their customers, reduce operational strain, and have more meaningful conversations about resilience rather than recovery.</p><p>MSPs that move toward a proactive, AI-augmented security model stand to differentiate themselves in a crowded market, not just as service providers, but as the kind of trusted advisors that customers need against increasingly fast and unpredictable threats. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google's Spirit Airlines auction & TrendAI insider threat report ]]></title>
                                                                                                <dc:content><![CDATA[ <iframe allow="clipboard-write" height="200px" width="100%" id="" style="width: 100%; height: 200px;" class="position-center" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/5acca2d1-04a0-490b-b1d3-3a09c19bd511"></iframe><p>This week, Bobby Hellard and Scott Bekker talk with ITPro's news & analysis editor, Ross Kelly, to discuss some of the top stories from August. </p><p>That includes Google acquiring a treasure trove of data from a defunct airline in a bid to bolster AI products. The auction to acquire data from Spirit Airlines hit headlines this month as Google outbid another industry player looking to capitalize on a trove of information. </p><p>We also discuss TrendAI's insider threat report, which looked at how cyber criminals are building increasingly sophisticated insider threat networks. </p><h2 id="highlights-3">Highlights</h2><p>"As a a failed Spirit Airlines customer, I once had a feudal trip where I was trying to get to a Microsoft conference, and I was in line, and they're like, "Yeah, your flight's canceled. We can get you there in four days. I was like, "Yeah, I'm never doing Spirit again. But was there any customer data other than the customer chats in this volume of data?"</p><p>"A big part of the issue here is how do you tackle insider threats? Because it's quite a broad category here in terms of what we're talking about. Insider threats can be just people not doing their job correctly, not following best practices. We've covered stories on that before. Another big thing is that people who are doing this deliberately, research from CFAS last year found that one in eight UK employees have actually sold company logins, or they know someone who has. So, you know that one in eight doesn't sound huge, but I think that's really concerning there."</p><h2 id="links-2">Links</h2><ul><li><a href="https://www.itpro.com/technology/artificial-intelligence/google-just-spent-usd10-million-in-an-auction-for-spirit-airlines-data-100-million-emails-500-million-microsoft-teams-chats-and-30-million-lines-of-code-will-be-used-to-improve-ai-models-and-products"><u>Google just spent $10 million in an auction for Spirit Airlines data</u></a></li><li><a href="https://www.itpro.com/security/the-easiest-way-into-a-company-isnt-always-through-a-vulnerability-anymore-hackers-are-building-a-global-insider-threat-recruitment-network-and-theyre-even-offering-referral-bonuses"><u>Hackers are building a global insider threat recruitment network</u></a></li></ul> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/technology/big-data/googles-spirit-airlines-auction-and-trendai-insider-threat-report</link>
                                                                            <description>
                            <![CDATA[ Google's Spirit Airlines auction & TrendAI insider threat report ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Bibw7JrvG3Y8j3s6m8pXhk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ufsxEZB9QTYhpL23S2VQYa-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 28 Aug 2026 15:34:13 +0000</pubDate>                                                                                                                                <updated>Mon, 31 Aug 2026 10:40:07 +0000</updated>
                                                                                                                                            <category><![CDATA[Big Data]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Bobby Hellard) ]]></author>                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Bobby Hellard&amp;nbsp;is&amp;nbsp;ITPro&#039;s Reviews Editor and has worked on&amp;nbsp;CloudPro and ChannelPro since 2018. In his time at ITPro, Bobby has covered stories for all the major technology companies, such as Apple, Microsoft, Amazon and Facebook, and regularly attends industry-leading events such as AWS Re:Invent and Google Cloud Next.&lt;/p&gt;
&lt;p&gt;Bobby mainly covers hardware reviews, but you will also recognize him as the face of many of our video reviews of laptops and smartphones.&lt;/p&gt;
&lt;p&gt;He has been a journalist for ten years, originally covering sports, before moving into business technology with ITPro. He has bylines in The Independent, Vice and The Business Briefing. Contact him at &lt;a href=&quot;mailto:bobby.hellard@futurenet.com&quot;&gt;bobby.hellard@futurenet.com&lt;/a&gt; or find him on Twitter: &lt;a href=&quot;https://twitter.com/bobbyhellard&quot;&gt;@bobbyhellard&lt;/a&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ufsxEZB9QTYhpL23S2VQYa-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The latest episode title over a plane window]]></media:description>                                                            <media:text><![CDATA[The latest episode title over a plane window]]></media:text>
                                <media:title type="plain"><![CDATA[The latest episode title over a plane window]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ufsxEZB9QTYhpL23S2VQYa-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <iframe allow="clipboard-write" height="200px" width="100%" id="" style="width: 100%; height: 200px;" class="position-center" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/5acca2d1-04a0-490b-b1d3-3a09c19bd511"></iframe><p>This week, Bobby Hellard and Scott Bekker talk with ITPro's news & analysis editor, Ross Kelly, to discuss some of the top stories from August. </p><p>That includes Google acquiring a treasure trove of data from a defunct airline in a bid to bolster AI products. The auction to acquire data from Spirit Airlines hit headlines this month as Google outbid another industry player looking to capitalize on a trove of information. </p><p>We also discuss TrendAI's insider threat report, which looked at how cyber criminals are building increasingly sophisticated insider threat networks. </p><h2 id="highlights-3">Highlights</h2><p>"As a a failed Spirit Airlines customer, I once had a feudal trip where I was trying to get to a Microsoft conference, and I was in line, and they're like, "Yeah, your flight's canceled. We can get you there in four days. I was like, "Yeah, I'm never doing Spirit again. But was there any customer data other than the customer chats in this volume of data?"</p><p>"A big part of the issue here is how do you tackle insider threats? Because it's quite a broad category here in terms of what we're talking about. Insider threats can be just people not doing their job correctly, not following best practices. We've covered stories on that before. Another big thing is that people who are doing this deliberately, research from CFAS last year found that one in eight UK employees have actually sold company logins, or they know someone who has. So, you know that one in eight doesn't sound huge, but I think that's really concerning there."</p><h2 id="links-2">Links</h2><ul><li><a href="https://www.itpro.com/technology/artificial-intelligence/google-just-spent-usd10-million-in-an-auction-for-spirit-airlines-data-100-million-emails-500-million-microsoft-teams-chats-and-30-million-lines-of-code-will-be-used-to-improve-ai-models-and-products"><u>Google just spent $10 million in an auction for Spirit Airlines data</u></a></li><li><a href="https://www.itpro.com/security/the-easiest-way-into-a-company-isnt-always-through-a-vulnerability-anymore-hackers-are-building-a-global-insider-threat-recruitment-network-and-theyre-even-offering-referral-bonuses"><u>Hackers are building a global insider threat recruitment network</u></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The human bridge: why AI can’t replace the trust economy in the channel ]]></title>
                                                                                                <dc:content><![CDATA[ <p>AI is forcing a genuine transformation in cybersecurity, redefining how threats are discovered, triaged, and stopped, and triggering an important question: at what point does automation completely remove the need for human intervention? </p><p>Walking through any major conference, the messaging is pretty much identical. Startups and legacy vendors alike are pitching fully autonomous, ‘AI-first’ architectures, promising that systems can manage threat detection and response with zero human oversight. </p><p>All this noise is making it tricky for channel partners to navigate. Customers are asking tough questions about what these platforms can actually do, forcing partners to provide high-level reassurance amid the noise. But as the hype cycle meets real-world deployment, a distinct sense of fatigue and skepticism is setting in. </p><p>AI is genuinely transforming security operations, and the pace isn’t slowing. But transformation isn’t the same as elimination: the function of the human is changing, not the need for one. For the channel, conflating the two is a fast way to damage the customer relationships that took years to build.</p><h2 id="the-agentic-ai-reality-check">The agentic AI reality check</h2><p>There’s no denying that machine learning and agentic AI are powerful forces for security operations centre (SOC) efficiency. If integrated correctly, automation excels at streamlining daily workflows, parsing datasets, and accelerating threat discovery. It can give defenders a vital edge in an environment where real-world exploitation can happen in minutes, shrinking the time it takes to spot an anomaly. </p><p>However, there is a massive gap between a tool that enhances human capability and a platform that appears to operate all on its own. In fact, we are already seeing an interesting shift in the market. There are lots of ‘fully autonomous’ AI SOC companies that are quietly pivoting their messaging. Their early pitches promised complete human removal; today, they are moving back toward the middle, shifting claims to highlight a dual human and AI approach.</p><p>That’s happening because the market is proving what experienced operators already knew. Cybersecurity is fundamentally a discipline of practical context. An AI model can identify an indicator of compromise, and do it faster than any human, but it can't own the outcome. Things like business impact, localised risk, and the conversation required when something goes wrong. That’s where accountability lives, and accountability is still human.</p><h2 id="mitigating-the-partner-s-reputational-risk">Mitigating the partner’s reputational risk</h2><p>Trust is the ultimate currency in the channel. Partners who deliver the most consistent value are the ones who actually understand their customers’ environments and build sustainable, transparent relationships. </p><p>When a partner recommends and implements a fully automated security solution with zero human safety net, they’re making a big reputational bet on the technology. If that system fails, misinterprets a critical threat, or completely misses a breach, the vendor isn’t the only one who loses. The partner is the one left facing a damaged relationship with an end user who trusted their opinion. </p><p>When an event occurs, whether it’s a ransomware attempt or identity-based attack, these businesses need a dedicated team to guide them through remediation and alleviate future risk. They need a human bridge. </p><h2 id="building-modern-integration-first-partner-programs">Building modern, integration-first partner programs </h2><p>To manage the current wave of market consolidation, partners need to move past the ‘AI-first' hype and focus on customer outcomes. This means vendor partner programmes have to shift. Rather than relying on closed, single-vendor platforms, the sector needs to embrace best-in-breed approaches that work together effectively.</p><p>A successful modern security architecture shouldn’t require an organisation to tear down its existing ecosystem. It should slot into what customers already run, meet them where they are, and grow with them. </p><p>As AI-enabled attacks rewrite how businesses think about security risk management, vendors also have to become translators. Partners can’t confidently brief clients on threats they don’t fully understand themselves, and that’s the responsibility of the vendor. Clear, jargon-free intel briefings are now a part of the value proposition. The partners who will stand out are the ones who learn where AI belongs along the workflow, and where human judgment takes over.</p><h2 id="the-value-of-human-judgment">The value of human judgment</h2><p>Security leaders and CISOs are after resilience, not just tools. While technical hardening is necessary to stop an attacker, the human elements of a partnership determine how smoothly an ecosystem will function under pressure. </p><p>Human relationships are what keep multi-vendor collaborations working in good faith. When a security incident occurs, a partner needs to know that their vendor partners are acting transparently. They should be sharing intelligence and actively supporting the field teams trying to protect the business. </p><p>In practice, that looks like a vendor who checks in consistently —not just before the renewal, and not only after an incident. It also means proactive threat briefings, honest post-incident reviews, and upfront communications when there’s a platform gap. That’s what humans bring to the equation in a B2B security relationship, and what clients remember.</p><p>AI is an incredible tool for driving efficiency and speeding up discovery. But it can’t manage a relationship, and it can’t replace the deep trust required to navigate a crisis. The vendors and partners who figure out how to use AI well — and keep humans accountable for what happens next — will be the ones clients trust as the technology matures.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/technology/artificial-intelligence/the-human-bridge-why-ai-cant-replace-the-trust-economy-in-the-channel</link>
                                                                            <description>
                            <![CDATA[ Transformation and elimination are not the same thing... ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">XJqfXQvLxpT7Ng4GtRmMoM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Y32s5wZcQe4eVjS9uEuJyb-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 28 Aug 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Alex Glass ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/MCbV8pShj9NzvLiSspAe8U-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Y32s5wZcQe4eVjS9uEuJyb-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Abstract image of artificial intelligence robot generated program code.]]></media:description>                                                            <media:text><![CDATA[Abstract image of artificial intelligence robot generated program code.]]></media:text>
                                <media:title type="plain"><![CDATA[Abstract image of artificial intelligence robot generated program code.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Y32s5wZcQe4eVjS9uEuJyb-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>AI is forcing a genuine transformation in cybersecurity, redefining how threats are discovered, triaged, and stopped, and triggering an important question: at what point does automation completely remove the need for human intervention? </p><p>Walking through any major conference, the messaging is pretty much identical. Startups and legacy vendors alike are pitching fully autonomous, ‘AI-first’ architectures, promising that systems can manage threat detection and response with zero human oversight. </p><p>All this noise is making it tricky for channel partners to navigate. Customers are asking tough questions about what these platforms can actually do, forcing partners to provide high-level reassurance amid the noise. But as the hype cycle meets real-world deployment, a distinct sense of fatigue and skepticism is setting in. </p><p>AI is genuinely transforming security operations, and the pace isn’t slowing. But transformation isn’t the same as elimination: the function of the human is changing, not the need for one. For the channel, conflating the two is a fast way to damage the customer relationships that took years to build.</p><h2 id="the-agentic-ai-reality-check">The agentic AI reality check</h2><p>There’s no denying that machine learning and agentic AI are powerful forces for security operations centre (SOC) efficiency. If integrated correctly, automation excels at streamlining daily workflows, parsing datasets, and accelerating threat discovery. It can give defenders a vital edge in an environment where real-world exploitation can happen in minutes, shrinking the time it takes to spot an anomaly. </p><p>However, there is a massive gap between a tool that enhances human capability and a platform that appears to operate all on its own. In fact, we are already seeing an interesting shift in the market. There are lots of ‘fully autonomous’ AI SOC companies that are quietly pivoting their messaging. Their early pitches promised complete human removal; today, they are moving back toward the middle, shifting claims to highlight a dual human and AI approach.</p><p>That’s happening because the market is proving what experienced operators already knew. Cybersecurity is fundamentally a discipline of practical context. An AI model can identify an indicator of compromise, and do it faster than any human, but it can't own the outcome. Things like business impact, localised risk, and the conversation required when something goes wrong. That’s where accountability lives, and accountability is still human.</p><h2 id="mitigating-the-partner-s-reputational-risk">Mitigating the partner’s reputational risk</h2><p>Trust is the ultimate currency in the channel. Partners who deliver the most consistent value are the ones who actually understand their customers’ environments and build sustainable, transparent relationships. </p><p>When a partner recommends and implements a fully automated security solution with zero human safety net, they’re making a big reputational bet on the technology. If that system fails, misinterprets a critical threat, or completely misses a breach, the vendor isn’t the only one who loses. The partner is the one left facing a damaged relationship with an end user who trusted their opinion. </p><p>When an event occurs, whether it’s a ransomware attempt or identity-based attack, these businesses need a dedicated team to guide them through remediation and alleviate future risk. They need a human bridge. </p><h2 id="building-modern-integration-first-partner-programs">Building modern, integration-first partner programs </h2><p>To manage the current wave of market consolidation, partners need to move past the ‘AI-first' hype and focus on customer outcomes. This means vendor partner programmes have to shift. Rather than relying on closed, single-vendor platforms, the sector needs to embrace best-in-breed approaches that work together effectively.</p><p>A successful modern security architecture shouldn’t require an organisation to tear down its existing ecosystem. It should slot into what customers already run, meet them where they are, and grow with them. </p><p>As AI-enabled attacks rewrite how businesses think about security risk management, vendors also have to become translators. Partners can’t confidently brief clients on threats they don’t fully understand themselves, and that’s the responsibility of the vendor. Clear, jargon-free intel briefings are now a part of the value proposition. The partners who will stand out are the ones who learn where AI belongs along the workflow, and where human judgment takes over.</p><h2 id="the-value-of-human-judgment">The value of human judgment</h2><p>Security leaders and CISOs are after resilience, not just tools. While technical hardening is necessary to stop an attacker, the human elements of a partnership determine how smoothly an ecosystem will function under pressure. </p><p>Human relationships are what keep multi-vendor collaborations working in good faith. When a security incident occurs, a partner needs to know that their vendor partners are acting transparently. They should be sharing intelligence and actively supporting the field teams trying to protect the business. </p><p>In practice, that looks like a vendor who checks in consistently —not just before the renewal, and not only after an incident. It also means proactive threat briefings, honest post-incident reviews, and upfront communications when there’s a platform gap. That’s what humans bring to the equation in a B2B security relationship, and what clients remember.</p><p>AI is an incredible tool for driving efficiency and speeding up discovery. But it can’t manage a relationship, and it can’t replace the deep trust required to navigate a crisis. The vendors and partners who figure out how to use AI well — and keep humans accountable for what happens next — will be the ones clients trust as the technology matures.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How to benchmark AI budgets to optimize ROI ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Despite talk of an AI bubble, AI spending is not slowing down. Indeed, companies plan to commit 1.7% of their annual revenue to AI initiatives this year, up from 0.8% last year, according to <a href="https://www.bcg.com/publications/2026/as-ai-investments-surge-ceos-take-the-lead"><u>research from the Boston Consulting Group</u></a>.</p><p>At the same time, however, <a href="https://www.pwc.com/gx/en/ceo-survey/2026/pwc-ceo-survey-2026.pdf"><u>PwC’s 2026 Global CEO Survey </u></a>shows that a growing number of companies are not seeing a return on their investment. A survey of more than 4,400 CEOs found that 56% have yet to see a financial benefit from their AI initiatives, while just 12% have seen both an increase in revenue and a cost reduction. Only a third are confident of revenue growth this year amid struggles to optimize AI’s ROI. </p><p>The disconnect can be put down to the fact that too many companies are buying AI tools, rolling them out to employees or customers, and only wondering several months later why they haven’t seen ROI. The problem is less to do with companies not getting value out of AI and more to do with the fact that they haven’t defined what value actually means for their business. </p><p>“A common mistake is spending heavily on tools before really understanding the problem [that needs to be solved],” says Jack Rickhuss, managing director and co-founder of tech consultancy Journi. </p><p>“AI only delivers real value when it’s in the hands of people who know how to use it properly.”</p><h2 id="tie-ai-investments-to-clear-outcomes">Tie AI investments to clear outcomes </h2><p>Benchmarking AI budgets is becoming a critical discipline that leaders need to master to ensure they’re extracting value from AI deployments. Without benchmarking an AI project’s spend, companies have no objective way of knowing if AI is performing well or poorly and delivering value for money. </p><p>Adam Hofmann, partner (AI and people transformation) at challenger consultancy Elixirr, says that the trap he sees leaders fall into is deploying AI tools and celebrating personal productivity gains while the profit and loss doesn’t move. </p><p>This can happen because companies are “benchmarking off peers that don’t know what they’re doing either, which leaves you behind the curve or overspending on someone else’s confusion.” </p><p>Before getting started on benchmarking AI budgets, leaders should build a clear picture of what they’re currently spending on model API costs, such as per token, infrastructure such as compute, hosting, and storage, human validation, maintenance, and training. Hofmann warns that “if you can't trace the line from spend to outcome, you're measuring activity, not AI."</p><p>Rickhuss agrees, adding that most companies “are still measuring the wrong things”. He advises tying AI investment to clear outcomes, such as improving decision-making, saving employees’ time, and speeding up delivery of projects. “If you can’t link [AI investment] to something tangible, it’s hard to measure success.”</p><h2 id="review-what-industry-peers-are-doing-and-then-pilot">Review what industry peers are doing and then pilot</h2><p>To get started, leaders should compare their spend against the peers that do know what they’re doing. One way they can do this is look at other companies in their industry using their earnings calls and 10-K filings, as well as analyst reports. They could use a large language model to extract data on peers’ AI spend as a percentage of revenue. </p><p>The next step is to break down AI use cases into various categories. This would cover the infrastructure (e.g. cloud compute and GPUs), people (e.g. the salaries for AI talent), licensing (e.g. cost-per-token), and data (e.g. storage). </p><p>Once AI budgets have been broken down, Shiro Theuri, CTO of Spanish on-demand delivery company Glovo, recommends taking “a pilot-and-test approach”. This is because piloting tools in a controlled environment can help to prevent feature creep and shadow IT. Pilots can also surface hidden costs that might otherwise have been overlooked. </p><p>An <a href="https://www.datarobot.com/newsroom/press/the-hidden-ai-tax-idc-research-reveals-nearly-all-organizations-lose-cost-control-when-deploying-genai-and-agentic-workflows-at-scale/"><u>IDC and DataRobot survey</u></a> carried out last year showed that 92% of enterprises deploying agentic AI at scale admitted that the costs incurred were higher than they had projected. The survey of 318 senior decision-makers at companies with more than 1,000 employees found that token consumption and hallucination remediation were the top unexpected costs, while inference was another common issue. </p><h2 id="continue-to-benchmark-throughout-a-project-s-lifecycle">Continue to benchmark throughout a project’s lifecycle </h2><p>To prevent their AI projects from getting stuck in pilot mode, leaders should continuously monitor the cost of running the project and benchmark this against the company’s own expectations.</p><p>Monitoring token consumption can be an effective way to keep budgets under control. AI costs can quite easily skyrocket, especially if employees end up using more tokens than forecast, running up higher bills and leading to companies exceeding their AI budgets. Luke Budka, AI director at marketing and training firm Definition, adds that tracking token usage can “reveal super users and also help identify employees who need support”.</p><p>While token usage can be used as a useful metric for cost management, leaders should be careful of ‘tokenmaxxing’ – the trend of enterprises measuring individual employee token usage and using it to measure productivity. As Budka explains, high token consumption can occur when employees are purposely inflating their usage to look busy, but it can also be a sign that employees are struggling with AI tools and could benefit from more training. </p><p>Ultimately, rather than focusing on the cost-per-token, leaders should measure the cost-per-business outcome. Determining the number of tokens required and tracking the tokens consumed to complete each workflow will help to optimize AI’s ROI.  </p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/technology/artificial-intelligence/how-to-benchmark-ai-budgets-to-optimize-roi</link>
                                                                            <description>
                            <![CDATA[ Research shows that companies are spending more on AI projects, yet they aren’t seeing a return on their investment. Benchmarking can help keep AI budgets under control ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ZYe2BcKYiaxxpyBHFxLT6R</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9QFSDDt4mraQvHKAeodWvV-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 27 Aug 2026 14:43:16 +0000</pubDate>                                                                                                                                <updated>Fri, 28 Aug 2026 08:07:19 +0000</updated>
                                                                                                                                            <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Leadership]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Rich McEachran) ]]></author>                    <dc:creator><![CDATA[ Rich McEachran ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/RRL5GmJQGuXidQxTVcGXXn-320-70.jpeg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9QFSDDt4mraQvHKAeodWvV-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A CGI image of an eye surrounded by stats, metrics, charts, in blue and red, to represent computer vision.]]></media:description>                                                            <media:text><![CDATA[A CGI image of an eye surrounded by stats, metrics, charts, in blue and red, to represent computer vision.]]></media:text>
                                <media:title type="plain"><![CDATA[A CGI image of an eye surrounded by stats, metrics, charts, in blue and red, to represent computer vision.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9QFSDDt4mraQvHKAeodWvV-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Despite talk of an AI bubble, AI spending is not slowing down. Indeed, companies plan to commit 1.7% of their annual revenue to AI initiatives this year, up from 0.8% last year, according to <a href="https://www.bcg.com/publications/2026/as-ai-investments-surge-ceos-take-the-lead"><u>research from the Boston Consulting Group</u></a>.</p><p>At the same time, however, <a href="https://www.pwc.com/gx/en/ceo-survey/2026/pwc-ceo-survey-2026.pdf"><u>PwC’s 2026 Global CEO Survey </u></a>shows that a growing number of companies are not seeing a return on their investment. A survey of more than 4,400 CEOs found that 56% have yet to see a financial benefit from their AI initiatives, while just 12% have seen both an increase in revenue and a cost reduction. Only a third are confident of revenue growth this year amid struggles to optimize AI’s ROI. </p><p>The disconnect can be put down to the fact that too many companies are buying AI tools, rolling them out to employees or customers, and only wondering several months later why they haven’t seen ROI. The problem is less to do with companies not getting value out of AI and more to do with the fact that they haven’t defined what value actually means for their business. </p><p>“A common mistake is spending heavily on tools before really understanding the problem [that needs to be solved],” says Jack Rickhuss, managing director and co-founder of tech consultancy Journi. </p><p>“AI only delivers real value when it’s in the hands of people who know how to use it properly.”</p><h2 id="tie-ai-investments-to-clear-outcomes">Tie AI investments to clear outcomes </h2><p>Benchmarking AI budgets is becoming a critical discipline that leaders need to master to ensure they’re extracting value from AI deployments. Without benchmarking an AI project’s spend, companies have no objective way of knowing if AI is performing well or poorly and delivering value for money. </p><p>Adam Hofmann, partner (AI and people transformation) at challenger consultancy Elixirr, says that the trap he sees leaders fall into is deploying AI tools and celebrating personal productivity gains while the profit and loss doesn’t move. </p><p>This can happen because companies are “benchmarking off peers that don’t know what they’re doing either, which leaves you behind the curve or overspending on someone else’s confusion.” </p><p>Before getting started on benchmarking AI budgets, leaders should build a clear picture of what they’re currently spending on model API costs, such as per token, infrastructure such as compute, hosting, and storage, human validation, maintenance, and training. Hofmann warns that “if you can't trace the line from spend to outcome, you're measuring activity, not AI."</p><p>Rickhuss agrees, adding that most companies “are still measuring the wrong things”. He advises tying AI investment to clear outcomes, such as improving decision-making, saving employees’ time, and speeding up delivery of projects. “If you can’t link [AI investment] to something tangible, it’s hard to measure success.”</p><h2 id="review-what-industry-peers-are-doing-and-then-pilot">Review what industry peers are doing and then pilot</h2><p>To get started, leaders should compare their spend against the peers that do know what they’re doing. One way they can do this is look at other companies in their industry using their earnings calls and 10-K filings, as well as analyst reports. They could use a large language model to extract data on peers’ AI spend as a percentage of revenue. </p><p>The next step is to break down AI use cases into various categories. This would cover the infrastructure (e.g. cloud compute and GPUs), people (e.g. the salaries for AI talent), licensing (e.g. cost-per-token), and data (e.g. storage). </p><p>Once AI budgets have been broken down, Shiro Theuri, CTO of Spanish on-demand delivery company Glovo, recommends taking “a pilot-and-test approach”. This is because piloting tools in a controlled environment can help to prevent feature creep and shadow IT. Pilots can also surface hidden costs that might otherwise have been overlooked. </p><p>An <a href="https://www.datarobot.com/newsroom/press/the-hidden-ai-tax-idc-research-reveals-nearly-all-organizations-lose-cost-control-when-deploying-genai-and-agentic-workflows-at-scale/"><u>IDC and DataRobot survey</u></a> carried out last year showed that 92% of enterprises deploying agentic AI at scale admitted that the costs incurred were higher than they had projected. The survey of 318 senior decision-makers at companies with more than 1,000 employees found that token consumption and hallucination remediation were the top unexpected costs, while inference was another common issue. </p><h2 id="continue-to-benchmark-throughout-a-project-s-lifecycle">Continue to benchmark throughout a project’s lifecycle </h2><p>To prevent their AI projects from getting stuck in pilot mode, leaders should continuously monitor the cost of running the project and benchmark this against the company’s own expectations.</p><p>Monitoring token consumption can be an effective way to keep budgets under control. AI costs can quite easily skyrocket, especially if employees end up using more tokens than forecast, running up higher bills and leading to companies exceeding their AI budgets. Luke Budka, AI director at marketing and training firm Definition, adds that tracking token usage can “reveal super users and also help identify employees who need support”.</p><p>While token usage can be used as a useful metric for cost management, leaders should be careful of ‘tokenmaxxing’ – the trend of enterprises measuring individual employee token usage and using it to measure productivity. As Budka explains, high token consumption can occur when employees are purposely inflating their usage to look busy, but it can also be a sign that employees are struggling with AI tools and could benefit from more training. </p><p>Ultimately, rather than focusing on the cost-per-token, leaders should measure the cost-per-business outcome. Determining the number of tokens required and tracking the tokens consumed to complete each workflow will help to optimize AI’s ROI.  </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Shadow AI is opening a door for the channel. Are we ready to walk through it? ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Walk into almost any business today, and you will find employees using AI tools that IT teams haven’t approved or paid for. The use of unsanctioned applications, known as shadow AI, is coming from the top. </p><p>I’ve heard bosses and senior leaders boast about maxing out on their token limits for personal AI tools at work, some saying they would risk disciplinary action to continue. My opinion, based on <a href="https://trustedtechteam.co.uk/pages/shadow-ai-whitepaper-download"><u>research</u></a> we’ve done, is that sensitive company information is being fed into unsecured platforms with knowing and active encouragement from leadership teams focused on speed and output. </p><p>With Gartner estimating that <a href="https://www.gartner.com/en/articles/ai-cybersecurity-leadership"><u>79%</u></a> of cybersecurity leaders have evidence of unsanctioned AI use, we know reckless behavior isn’t limited to the boardroom. <a href="https://newsroom.ibm.com/2026-06-08-new-ibm-study-finds-cios-and-ctos-face-growing-ai-control-gap-as-enterprise-deployment-scales"><u>IBM's</u></a> research shows a persistent gap between leaders' AI ambition and governance readiness in organizations of all sizes. Employees are using whichever AI most increases their productivity, consequences be damned.  </p><p>Business AI tools aren’t meeting employee needs. Whether that’s because of cost, AI readiness, or lack of understanding, Managed Service Providers (MSPs) and IT providers have a unique window to support businesses needing to adopt correctly. The channel is now reaching wider business managers who direct company culture, not just IT teams. With the way things are going, the channel has an opportunity to become strategic if we can meet the ask. </p><h2 id="the-pressure-point">The pressure point </h2><p>The window for the channel to move from IT vendors to strategic business partners is now. From a product perspective, upcoming licensing changes and cost pressures are likely to force decisions that many organizations have so far delayed. When budgets are tight, downgrading access to AI tools is a logical step. However, this often pushes employees back toward unsanctioned options. </p><p>Employees have already demonstrated that they will seek out tools that help them work more efficiently. Our research found that a significant proportion of employees said they would turn to personal AI tools if their employer restricted access on cost grounds. That’s a small profit gain one year and a data leak, boardroom scandal, and reputation loss the next.  </p><p>For MSPs and Microsoft partners, this represents both a warning and an opportunity. Businesses must respond to employee needs and top-down rule-breaking by optimizing licensing, deploying AI properly, and putting the right software in place. </p><p>For the channel, a renewed focus on adopting AI that fits the budget and the needs of the workforce will open new business opportunities.   </p><h2 id="the-government-is-paying-attention">The government is paying attention</h2><p>It is also worth noting that this is not just a commercial conversation or pandering to employee desires for the latest tech. At London Tech Week, the UK government focused on improving AI adoption among small and midsize businesses, with a caveat that tech transformation needs to happen safely and effectively.  </p><p>To me, these policies and investments are a clear sign that AI enablement for SMBs is a national priority, and the channel is one of the primary routes through which it will be delivered. There has been a buzz in the channel for some time around how MSPs need to move from transactional resellers to trusted and strategic technology advisors. </p><p>Now is the time to meet the needs of providers seeking guidance on adopting quickly and safely. With renewed government focus on scaling AI for all businesses, the channel ecosystem is welcoming more than just IT buyers, presenting a long-term opportunity for the MSP. </p><h2 id="what-good-readiness-actually-looks-like">What good readiness actually looks like </h2><p>When our customers ask us about the latest AI software, financial, structural, and cultural concerns immediately crop up. They are trying to understand whether they are ready to adopt AI in a way that delivers value without introducing unnecessary risk. In most cases, the answer is more complex than a simple technology decision. Most know that the answer is more complicated than a licence purchase. </p><p>The practical work includes an honest AI readiness assessment, a clear policy framework that governs what tools can be used and how, user training that goes beyond a PowerPoint, licensing optimization, and a thorough security and compliance review that accounts for the data risks that shadow AI has already introduced. </p><p>For businesses already suffering from shadow AI use, especially where it’s driven from the top, it might be an uncomfortable conversation. Without it, businesses will keep losing money on poorly implemented and poorly performing software that their employees aren’t using, whilst the leadership team sets an example of risking sensitive data just to hit KPIs. </p><p>This conversation isn’t beyond the capability of a well-positioned MSP. But it requires a trusted relationship and the confidence to have a broader conversation with the customer than MSPs are used to having. </p><h2 id="the-window-is-open">The window is open </h2><p>Businesses have been allowing their AI tools to underperform for a multitude of reasons, but pricing changes, risk, and legislation are all about to force decisions.  </p><p>If they aren’t already, businesses will soon be coming to the channel needing guidance. It’s been talked about for some time, but now really is the moment for partners and channel actors to make themselves known as AI readiness advisors. Now, before the next wave of shadow AI incidents, before a competitor gets there first.   </p><p>The key question is not whether customers need support with AI; that’s obvious. For me, the channel needs to be assessing whether they can take advantage of this window and provide that support and more.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/technology/artificial-intelligence/shadow-ai-is-opening-a-door-for-the-channel-are-we-ready-to-walk-through-it</link>
                                                                            <description>
                            <![CDATA[ Businesses are facing a big challenge in tackling shadow AI use. It’s up to the channel to step in and help ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dm2ZKhL4kvtZzka4gAGYUf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LZaczbyqEbZvgsEb8jX8UZ-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 27 Aug 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Justin Sharrocks ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Q6EDBa6x27KShy5WwZCar9-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/LZaczbyqEbZvgsEb8jX8UZ-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hologram of the artificial intelligence robot showing up from binary code]]></media:description>                                                            <media:text><![CDATA[Hologram of the artificial intelligence robot showing up from binary code]]></media:text>
                                <media:title type="plain"><![CDATA[Hologram of the artificial intelligence robot showing up from binary code]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LZaczbyqEbZvgsEb8jX8UZ-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Walk into almost any business today, and you will find employees using AI tools that IT teams haven’t approved or paid for. The use of unsanctioned applications, known as shadow AI, is coming from the top. </p><p>I’ve heard bosses and senior leaders boast about maxing out on their token limits for personal AI tools at work, some saying they would risk disciplinary action to continue. My opinion, based on <a href="https://trustedtechteam.co.uk/pages/shadow-ai-whitepaper-download"><u>research</u></a> we’ve done, is that sensitive company information is being fed into unsecured platforms with knowing and active encouragement from leadership teams focused on speed and output. </p><p>With Gartner estimating that <a href="https://www.gartner.com/en/articles/ai-cybersecurity-leadership"><u>79%</u></a> of cybersecurity leaders have evidence of unsanctioned AI use, we know reckless behavior isn’t limited to the boardroom. <a href="https://newsroom.ibm.com/2026-06-08-new-ibm-study-finds-cios-and-ctos-face-growing-ai-control-gap-as-enterprise-deployment-scales"><u>IBM's</u></a> research shows a persistent gap between leaders' AI ambition and governance readiness in organizations of all sizes. Employees are using whichever AI most increases their productivity, consequences be damned.  </p><p>Business AI tools aren’t meeting employee needs. Whether that’s because of cost, AI readiness, or lack of understanding, Managed Service Providers (MSPs) and IT providers have a unique window to support businesses needing to adopt correctly. The channel is now reaching wider business managers who direct company culture, not just IT teams. With the way things are going, the channel has an opportunity to become strategic if we can meet the ask. </p><h2 id="the-pressure-point">The pressure point </h2><p>The window for the channel to move from IT vendors to strategic business partners is now. From a product perspective, upcoming licensing changes and cost pressures are likely to force decisions that many organizations have so far delayed. When budgets are tight, downgrading access to AI tools is a logical step. However, this often pushes employees back toward unsanctioned options. </p><p>Employees have already demonstrated that they will seek out tools that help them work more efficiently. Our research found that a significant proportion of employees said they would turn to personal AI tools if their employer restricted access on cost grounds. That’s a small profit gain one year and a data leak, boardroom scandal, and reputation loss the next.  </p><p>For MSPs and Microsoft partners, this represents both a warning and an opportunity. Businesses must respond to employee needs and top-down rule-breaking by optimizing licensing, deploying AI properly, and putting the right software in place. </p><p>For the channel, a renewed focus on adopting AI that fits the budget and the needs of the workforce will open new business opportunities.   </p><h2 id="the-government-is-paying-attention">The government is paying attention</h2><p>It is also worth noting that this is not just a commercial conversation or pandering to employee desires for the latest tech. At London Tech Week, the UK government focused on improving AI adoption among small and midsize businesses, with a caveat that tech transformation needs to happen safely and effectively.  </p><p>To me, these policies and investments are a clear sign that AI enablement for SMBs is a national priority, and the channel is one of the primary routes through which it will be delivered. There has been a buzz in the channel for some time around how MSPs need to move from transactional resellers to trusted and strategic technology advisors. </p><p>Now is the time to meet the needs of providers seeking guidance on adopting quickly and safely. With renewed government focus on scaling AI for all businesses, the channel ecosystem is welcoming more than just IT buyers, presenting a long-term opportunity for the MSP. </p><h2 id="what-good-readiness-actually-looks-like">What good readiness actually looks like </h2><p>When our customers ask us about the latest AI software, financial, structural, and cultural concerns immediately crop up. They are trying to understand whether they are ready to adopt AI in a way that delivers value without introducing unnecessary risk. In most cases, the answer is more complex than a simple technology decision. Most know that the answer is more complicated than a licence purchase. </p><p>The practical work includes an honest AI readiness assessment, a clear policy framework that governs what tools can be used and how, user training that goes beyond a PowerPoint, licensing optimization, and a thorough security and compliance review that accounts for the data risks that shadow AI has already introduced. </p><p>For businesses already suffering from shadow AI use, especially where it’s driven from the top, it might be an uncomfortable conversation. Without it, businesses will keep losing money on poorly implemented and poorly performing software that their employees aren’t using, whilst the leadership team sets an example of risking sensitive data just to hit KPIs. </p><p>This conversation isn’t beyond the capability of a well-positioned MSP. But it requires a trusted relationship and the confidence to have a broader conversation with the customer than MSPs are used to having. </p><h2 id="the-window-is-open">The window is open </h2><p>Businesses have been allowing their AI tools to underperform for a multitude of reasons, but pricing changes, risk, and legislation are all about to force decisions.  </p><p>If they aren’t already, businesses will soon be coming to the channel needing guidance. It’s been talked about for some time, but now really is the moment for partners and channel actors to make themselves known as AI readiness advisors. Now, before the next wave of shadow AI incidents, before a competitor gets there first.   </p><p>The key question is not whether customers need support with AI; that’s obvious. For me, the channel needs to be assessing whether they can take advantage of this window and provide that support and more.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why the print channel is being pulled into board-level business conversations ]]></title>
                                                                                                <dc:content><![CDATA[ <p>For much of the past two decades, conversations about print rarely made it beyond IT, procurement, or facilities teams. Print was viewed as an operational necessity, as decisions centred on devices, consumables, service contracts and cost control. While important, these discussions were largely separate from wider conversations about business strategy.</p><p>Today, that distinction is becoming increasingly difficult to maintain.</p><p>Hybrid working has exposed weaknesses in how information moves through organizations. Documents, data and workflows now flow across offices, homes, cloud platforms and multiple applications, often relying on systems that were never designed to work together. As a result, businesses are taking a much closer look at the processes that sit behind everyday operations.</p><p>Half of UK businesses still rely on legacy workflows, according to <a href="https://www.ricoh.co.uk/insights/reports-whitepapers/uk-digital-transformation-research/"><u>our research,</u></a> while a third struggle to integrate technology into everyday operations. </p><p>In many organizations, print, digital workflows and IT systems continue to operate independently of one another, creating inefficiencies, security challenges and limited visibility over how information moves through the business.</p><p>It’s no secret that boards are increasingly focused on productivity, resilience, security and return on investment. When information is trapped within disconnected systems, manual intervention increases, slowing down decision-making and making governance more difficult to maintain. What may begin as a workflow issue can quickly become a business performance issue.</p><h2 id="the-changing-customer-mindset">The changing customer mindset </h2><p>Customers are no longer looking solely for technology providers. They are increasingly looking for partners who can help simplify operations and deliver measurable outcomes. The discussion is becoming less about individual products and more about how different technologies work together to support the wider business.</p><p></p><p>That is particularly evident in hybrid environments. Many of the challenges organizations face today stem from fragmented processes. Employees often move between digital and physical workflows throughout the day, while information passes through multiple platforms, applications and systems. Without integration, inefficiencies can quickly accumulate, critically affecting employee experience, operational efficiency, security, and business agility.</p><p>At the same time, customers are placing greater emphasis on demonstrating value from technology investments. Rising operational costs, growing expectations around sustainability and increasing pressure to automate processes are forcing organizations to scrutinise investments more carefully. Technology decisions are being assessed against wider business objectives, whether that is improving efficiency, strengthening resilience or supporting long-term growth.</p><p>This is one reason service-led models continue to gain momentum across the channel.</p><p>Rather than purchasing individual products and services separately, organizations are increasingly looking for outcome-focused solutions that bring together hardware, software, analytics, support and ongoing optimisation. </p><p>Sustainability, operational efficiency, and demonstrating return on investment are all becoming part of the same conversation, creating opportunities for partners to act as trusted advisors rather than product suppliers. Long-term partnerships are particularly valuable in this environment, as customers need ongoing support to navigate changing market conditions, evolving regulations, and shifting business priorities.</p><p>To support this, vendors and partners are investing more heavily in market intelligence and education. By working closely with organizations such as Gartner, IDC, and Quocirca, partners can access deeper insight into emerging trends, customer challenges, and best practices, helping them have more informed conversations with customers. In many cases, the role is becoming one of coaching and knowledge-sharing, equipping customers with the information they need to make better decisions and demonstrate value across the business.</p><h2 id="the-channel-and-ai">The channel and AI</h2><p>Another factor drawing the channel into board-level discussions is the growing connection between AI, security, and sustainability. Historically, these priorities were often treated as separate initiatives, owned by different teams and managed under different budgets. Increasingly, organizations are discovering that progress in one area depends on progress in another.</p><p>AI initiatives rely on access to accurate information and effective governance. Security strategies depend on understanding where information resides and how it moves within the organization. Sustainability programmes require greater visibility into processes, resource usage and operational efficiency. However, businesses cannot automate or improve what they cannot see.</p><p>Success is becoming less dependent on individual products and more dependent on understanding customer objectives, identifying inefficiencies, and helping organizations build more resilient operating models. The ability to connect technologies, automate workflows and provide meaningful insight into business processes is becoming increasingly valuable.</p><p>Hybrid working may have exposed the weaknesses in disconnected workflows, but it has also created an opportunity. </p><p>As customers look for greater efficiency, stronger governance and clearer value from technology investments, the channel has a real chance to play a much broader role in helping organizations achieve those goals.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/hardware/printers/why-the-print-channel-is-being-pulled-into-board-level-business-conversations</link>
                                                                            <description>
                            <![CDATA[ How hybrid work has elevated print from a back-office function to a business priority ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kEpoQYWQgNsAZzGpUcbpg8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zRwQ5FX2RTJmdqXdbBAjqn-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 26 Aug 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Printers]]></category>
                                                    <category><![CDATA[Hardware]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rowan Jeffreys-Hoar ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/cPoFbRwXktgfnAAJEfLgNR-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zRwQ5FX2RTJmdqXdbBAjqn-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Male office worker sitting at a desk in a dimly lit room with hands held to his face in frustration with light from screen shining on face.]]></media:description>                                                            <media:text><![CDATA[Male office worker sitting at a desk in a dimly lit room with hands held to his face in frustration with light from screen shining on face.]]></media:text>
                                <media:title type="plain"><![CDATA[Male office worker sitting at a desk in a dimly lit room with hands held to his face in frustration with light from screen shining on face.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zRwQ5FX2RTJmdqXdbBAjqn-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>For much of the past two decades, conversations about print rarely made it beyond IT, procurement, or facilities teams. Print was viewed as an operational necessity, as decisions centred on devices, consumables, service contracts and cost control. While important, these discussions were largely separate from wider conversations about business strategy.</p><p>Today, that distinction is becoming increasingly difficult to maintain.</p><p>Hybrid working has exposed weaknesses in how information moves through organizations. Documents, data and workflows now flow across offices, homes, cloud platforms and multiple applications, often relying on systems that were never designed to work together. As a result, businesses are taking a much closer look at the processes that sit behind everyday operations.</p><p>Half of UK businesses still rely on legacy workflows, according to <a href="https://www.ricoh.co.uk/insights/reports-whitepapers/uk-digital-transformation-research/"><u>our research,</u></a> while a third struggle to integrate technology into everyday operations. </p><p>In many organizations, print, digital workflows and IT systems continue to operate independently of one another, creating inefficiencies, security challenges and limited visibility over how information moves through the business.</p><p>It’s no secret that boards are increasingly focused on productivity, resilience, security and return on investment. When information is trapped within disconnected systems, manual intervention increases, slowing down decision-making and making governance more difficult to maintain. What may begin as a workflow issue can quickly become a business performance issue.</p><h2 id="the-changing-customer-mindset">The changing customer mindset </h2><p>Customers are no longer looking solely for technology providers. They are increasingly looking for partners who can help simplify operations and deliver measurable outcomes. The discussion is becoming less about individual products and more about how different technologies work together to support the wider business.</p><p></p><p>That is particularly evident in hybrid environments. Many of the challenges organizations face today stem from fragmented processes. Employees often move between digital and physical workflows throughout the day, while information passes through multiple platforms, applications and systems. Without integration, inefficiencies can quickly accumulate, critically affecting employee experience, operational efficiency, security, and business agility.</p><p>At the same time, customers are placing greater emphasis on demonstrating value from technology investments. Rising operational costs, growing expectations around sustainability and increasing pressure to automate processes are forcing organizations to scrutinise investments more carefully. Technology decisions are being assessed against wider business objectives, whether that is improving efficiency, strengthening resilience or supporting long-term growth.</p><p>This is one reason service-led models continue to gain momentum across the channel.</p><p>Rather than purchasing individual products and services separately, organizations are increasingly looking for outcome-focused solutions that bring together hardware, software, analytics, support and ongoing optimisation. </p><p>Sustainability, operational efficiency, and demonstrating return on investment are all becoming part of the same conversation, creating opportunities for partners to act as trusted advisors rather than product suppliers. Long-term partnerships are particularly valuable in this environment, as customers need ongoing support to navigate changing market conditions, evolving regulations, and shifting business priorities.</p><p>To support this, vendors and partners are investing more heavily in market intelligence and education. By working closely with organizations such as Gartner, IDC, and Quocirca, partners can access deeper insight into emerging trends, customer challenges, and best practices, helping them have more informed conversations with customers. In many cases, the role is becoming one of coaching and knowledge-sharing, equipping customers with the information they need to make better decisions and demonstrate value across the business.</p><h2 id="the-channel-and-ai">The channel and AI</h2><p>Another factor drawing the channel into board-level discussions is the growing connection between AI, security, and sustainability. Historically, these priorities were often treated as separate initiatives, owned by different teams and managed under different budgets. Increasingly, organizations are discovering that progress in one area depends on progress in another.</p><p>AI initiatives rely on access to accurate information and effective governance. Security strategies depend on understanding where information resides and how it moves within the organization. Sustainability programmes require greater visibility into processes, resource usage and operational efficiency. However, businesses cannot automate or improve what they cannot see.</p><p>Success is becoming less dependent on individual products and more dependent on understanding customer objectives, identifying inefficiencies, and helping organizations build more resilient operating models. The ability to connect technologies, automate workflows and provide meaningful insight into business processes is becoming increasingly valuable.</p><p>Hybrid working may have exposed the weaknesses in disconnected workflows, but it has also created an opportunity. </p><p>As customers look for greater efficiency, stronger governance and clearer value from technology investments, the channel has a real chance to play a much broader role in helping organizations achieve those goals.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How OneLondon is putting data to good use to aid patient services ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Healthcare organizations collect huge amounts of data that can be used to improve operational processes and save patient lives. </p><p>However, exploiting this data is easier said than done. Healthcare professionals face multiple challenges, from stove-piped data to governance hurdles, as they look to turn information into insight.</p><p>It’s in this challenging environment that Dr Joe Zhang, CTO at OneLondon, is aiming to create a new era of interoperability. OneLondon is a specialist healthcare partnership that connects health and care information across the capital to improve patient treatments and plan future medical services – and at the heart of this approach sits the <a href="https://www.itpro.com/technology/artificial-intelligence/snowflake-ceo-many-vendors-sell-you-parts-of-a-car-and-tell-you-to-build-it-yourself-at-snowflake-we-have-a-different-philosophy-we-want-to-give-you-the-car">Snowflake data platform</a>. </p><p>“The data is a lot more complicated in healthcare than [in] other settings; it's highly dimensional, it's multimodal, meaning that you have structured data, free text, but also imaging data, and genomics data,” says Zhang. </p><p>“The value of the data for improving care is enormous, but what you're dealing with on the ground is just a constellation of many siloed systems locked away and managed by different teams.”</p><h2 id="disparate-data">Disparate data </h2><p>Patient data in London is spread across GPs, hospitals, mental health providers, community services, and social care organizations. This data has traditionally been fragmented across disparate systems, making it difficult to create a joined-up view of patient health to predict demand or conduct population health research.</p><p>After an open procurement process that considered other data platforms, OneLondon selected <a href="https://www.itpro.com/technology/artificial-intelligence/enterprises-are-becoming-much-more-rigorous-about-the-economics-of-ai-snowflake-wants-to-help-you-cut-ai-costs-by-choosing-the-right-model-for-the-right-task">Snowflake</a>, with Zhang suggesting the provider’s capabilities meant its technology ticked more boxes than its rivals. Today, Snowflake is helping the organization solve its data interoperability challenges.</p><p>“At a local level, the platform is the layer where we can ingest data that's compliant, secure, and that we can trust,” he says. “It’s also operationally open, which means we can use our own tooling, which is standard things like <a href="https://www.itpro.com/sql/30242/what-is-sql">SQL</a> and <a href="https://www.itpro.com/business-strategy/careers-training/356640/how-to-become-a-python-software-developer">Python</a>, to transform data, ingest it, observe it, standardize it, and turn it into a usable asset for clinicians and analysts on the ground.”</p><p>Zhang, who spoke with <em>ITPro</em> at the recent Snowflake Summit 2026 in San Francisco, says the platform provides a data mesh-like approach, where professionals can share insights securely with others. As a doctor who used to work in the Intensive Care Unit (ICU), Zhang has first-hand experience of the life-changing impact of timely insights. Now, he’s helping professionals in other healthcare organizations to exploit their data.</p><p>“My background is as a doctor, but I've got a technical background in data engineering and data science. I left medicine after COVID. I worked in industry for a while doing biomarker development in real-world data, then came back to London to lead part of the program across London, and then stepped into the <a href="https://www.itpro.com/strategy/28237/cto-job-description-what-does-a-cto-do">CTO </a>role,” he says.</p><p>“This job gives me the best of both worlds. We can make a bigger impact with data, data products, and applications built on data, but it can take a bit longer to see the impact. When I worked in [the] ICU, you’d see the results within 10 minutes or so. This work involves a wider scope and longer timelines, but a potentially bigger impact.”</p><h2 id="a-data-journey-heading-towards-value-recognition">A data journey heading towards value recognition</h2><p>OneLondon’s activity covers about 30 hospitals and more than 1,400 GP practices. Some healthcare organizations are more mature in their data journey than others. While the Snowflake platform provides a core layer for joined-up analytics efforts, the key to long-term success is ensuring that professionals recognize its value.</p><p>“It’s more of an incentivized play rather than saying, ‘This is the pattern we're going for,’” says Zhang. “The organizations that have come on to Snowflake have done so because they think the technology helps with interoperability. A lot of the work has been about unifying opinions across all the organizations in London to make this approach work.”</p><p>The key benefit for professionals is a single patient record. Whether someone spends time in GP services, local hospitals or specialist healthcare centers, Zhang says their pathway is tracked: “If you're a clinician at a point of care, you can start to build applications that say, ‘This patient, based on everything that has happened, is at more risk of renal dysfunction, so we should do something about it.’” </p><p>Work on the platform continues. The major migration process finished in April, with primary care data feeds currently coming online. At least a dozen use cases are in development. While these pioneering projects will produce benefits, Zhang says it’s important to recognize that the core focus so far has been perfecting the underlying technology layer.</p><p>“There are all sorts of infrastructure and networking challenges you must overcome before you think about integration,” he says.</p><p>“But because Snowflake offers an application layer where you can provision resources and scale compute to applications that are deployed, it becomes a highly secure solution for us to deploy all sorts of services.”</p><p>That effort is crucial, as Zhang says ambitious projects in population health or life sciences research won’t be scalable if the right data isn’t available. The long-term aim of this initiative is to create proactive care applications for clinical pathways: “The approach we choose may not work at first, but you iterate, and create a cycle where you constantly learn and improve.”</p><h2 id="future-innovation">Future innovation</h2><p>Another long-term objective, says Zhang, is to use the joined-up view on data to help support the development of new drugs for disease treatments. He says a key reason the UK isn't doing as well as it could in terms of developing new therapies for patients is a lack of data. The Snowflake platform could play a crucial role in supporting progress.</p><p>“We don't know what diseases are there, who is suffering from what disease, and what the trajectories are,” he says. </p><p>“So being able to map that process out, being able to run more clinical trials in this country, and getting new drugs to patients faster, would be a big outcome for me if we can help do that.”</p><p>Reflecting on progress made so far, Zhang says clear long-term objectives and a trusted technology partner are critical to success. As someone well-versed in life-changing decisions in high-pressure environments, he recognizes that digital leaders looking to push data-enabled change must walk before they can run. </p><p>“Often it's not sophisticated things like AI and agents; it's just having the right data in the right place at the right time,” he says. </p><p>“We need to be able to measure outcomes and see what's happening to our patients. Those things sound simple, but they've never really been possible before. So, in that instance, this project is all about trying to prevent preventable things.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/business/data-and-insights/how-onelondon-is-putting-data-to-good-use-to-aid-patient-services</link>
                                                                            <description>
                            <![CDATA[ The healthcare partnership is working with Snowflake to turn data into intelligence and actionable insights ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sNon4d4BPqEWBvuFF2jPQ4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NbjkLyDmULJ5cfMZFyQPa3-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 26 Aug 2026 07:00:00 +0000</pubDate>                                                                                                                                <updated>Thu, 27 Aug 2026 11:05:17 +0000</updated>
                                                                                                                                            <category><![CDATA[Data and Insights]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Mark Samuels ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/rfAoiWsTvmT4koiuWLLZBi-320-70.jpeg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Mark Samuels is a freelance writer specializing in business and technology. For the past two decades, he has produced extensive work on subjects such as the adoption of technology by C-suite executives.&lt;/p&gt;&lt;p&gt;At ITPro, Mark has provided long-form content on C-suite strategy, particularly relating to chief information officers (CIOs), as well as digital transformation case studies, and explainers on cloud computing architecture.&lt;/p&gt;&lt;p&gt;Mark has written for publications including The Guardian, ZDNet, TechRepublic, Times Higher Education, and CIONET. He started working as a staff writer at Computing in 2000, where he later became the publication’s features editor. In 2008, he took charge of the brand’s monthly supplement Computing Business alongside his features responsibilities.&lt;/p&gt;&lt;p&gt;From 2008 to 2014, Mark was also editor of the membership magazine for IT leadership forum CIO Connect. As part of the role, Mark oversaw the editorial content for CIO Connect, edited research reports, and maintained an extensive network of industry experts.&lt;/p&gt;&lt;p&gt;Before his career in journalism, Mark achieved a BA in geography and MSc in World Space Economy at the University of Birmingham, as well as a PhD in economic geography at the University of Sheffield.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NbjkLyDmULJ5cfMZFyQPa3-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A medical professional in a white coat holding a blue clipboard while healthcare-related images, including a full torso skeleton and an icon of some lungs, spring from an open laptop.]]></media:description>                                                            <media:text><![CDATA[A medical professional in a white coat holding a blue clipboard while healthcare-related images, including a full torso skeleton and an icon of some lungs, spring from an open laptop.]]></media:text>
                                <media:title type="plain"><![CDATA[A medical professional in a white coat holding a blue clipboard while healthcare-related images, including a full torso skeleton and an icon of some lungs, spring from an open laptop.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NbjkLyDmULJ5cfMZFyQPa3-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Healthcare organizations collect huge amounts of data that can be used to improve operational processes and save patient lives. </p><p>However, exploiting this data is easier said than done. Healthcare professionals face multiple challenges, from stove-piped data to governance hurdles, as they look to turn information into insight.</p><p>It’s in this challenging environment that Dr Joe Zhang, CTO at OneLondon, is aiming to create a new era of interoperability. OneLondon is a specialist healthcare partnership that connects health and care information across the capital to improve patient treatments and plan future medical services – and at the heart of this approach sits the <a href="https://www.itpro.com/technology/artificial-intelligence/snowflake-ceo-many-vendors-sell-you-parts-of-a-car-and-tell-you-to-build-it-yourself-at-snowflake-we-have-a-different-philosophy-we-want-to-give-you-the-car">Snowflake data platform</a>. </p><p>“The data is a lot more complicated in healthcare than [in] other settings; it's highly dimensional, it's multimodal, meaning that you have structured data, free text, but also imaging data, and genomics data,” says Zhang. </p><p>“The value of the data for improving care is enormous, but what you're dealing with on the ground is just a constellation of many siloed systems locked away and managed by different teams.”</p><h2 id="disparate-data">Disparate data </h2><p>Patient data in London is spread across GPs, hospitals, mental health providers, community services, and social care organizations. This data has traditionally been fragmented across disparate systems, making it difficult to create a joined-up view of patient health to predict demand or conduct population health research.</p><p>After an open procurement process that considered other data platforms, OneLondon selected <a href="https://www.itpro.com/technology/artificial-intelligence/enterprises-are-becoming-much-more-rigorous-about-the-economics-of-ai-snowflake-wants-to-help-you-cut-ai-costs-by-choosing-the-right-model-for-the-right-task">Snowflake</a>, with Zhang suggesting the provider’s capabilities meant its technology ticked more boxes than its rivals. Today, Snowflake is helping the organization solve its data interoperability challenges.</p><p>“At a local level, the platform is the layer where we can ingest data that's compliant, secure, and that we can trust,” he says. “It’s also operationally open, which means we can use our own tooling, which is standard things like <a href="https://www.itpro.com/sql/30242/what-is-sql">SQL</a> and <a href="https://www.itpro.com/business-strategy/careers-training/356640/how-to-become-a-python-software-developer">Python</a>, to transform data, ingest it, observe it, standardize it, and turn it into a usable asset for clinicians and analysts on the ground.”</p><p>Zhang, who spoke with <em>ITPro</em> at the recent Snowflake Summit 2026 in San Francisco, says the platform provides a data mesh-like approach, where professionals can share insights securely with others. As a doctor who used to work in the Intensive Care Unit (ICU), Zhang has first-hand experience of the life-changing impact of timely insights. Now, he’s helping professionals in other healthcare organizations to exploit their data.</p><p>“My background is as a doctor, but I've got a technical background in data engineering and data science. I left medicine after COVID. I worked in industry for a while doing biomarker development in real-world data, then came back to London to lead part of the program across London, and then stepped into the <a href="https://www.itpro.com/strategy/28237/cto-job-description-what-does-a-cto-do">CTO </a>role,” he says.</p><p>“This job gives me the best of both worlds. We can make a bigger impact with data, data products, and applications built on data, but it can take a bit longer to see the impact. When I worked in [the] ICU, you’d see the results within 10 minutes or so. This work involves a wider scope and longer timelines, but a potentially bigger impact.”</p><h2 id="a-data-journey-heading-towards-value-recognition">A data journey heading towards value recognition</h2><p>OneLondon’s activity covers about 30 hospitals and more than 1,400 GP practices. Some healthcare organizations are more mature in their data journey than others. While the Snowflake platform provides a core layer for joined-up analytics efforts, the key to long-term success is ensuring that professionals recognize its value.</p><p>“It’s more of an incentivized play rather than saying, ‘This is the pattern we're going for,’” says Zhang. “The organizations that have come on to Snowflake have done so because they think the technology helps with interoperability. A lot of the work has been about unifying opinions across all the organizations in London to make this approach work.”</p><p>The key benefit for professionals is a single patient record. Whether someone spends time in GP services, local hospitals or specialist healthcare centers, Zhang says their pathway is tracked: “If you're a clinician at a point of care, you can start to build applications that say, ‘This patient, based on everything that has happened, is at more risk of renal dysfunction, so we should do something about it.’” </p><p>Work on the platform continues. The major migration process finished in April, with primary care data feeds currently coming online. At least a dozen use cases are in development. While these pioneering projects will produce benefits, Zhang says it’s important to recognize that the core focus so far has been perfecting the underlying technology layer.</p><p>“There are all sorts of infrastructure and networking challenges you must overcome before you think about integration,” he says.</p><p>“But because Snowflake offers an application layer where you can provision resources and scale compute to applications that are deployed, it becomes a highly secure solution for us to deploy all sorts of services.”</p><p>That effort is crucial, as Zhang says ambitious projects in population health or life sciences research won’t be scalable if the right data isn’t available. The long-term aim of this initiative is to create proactive care applications for clinical pathways: “The approach we choose may not work at first, but you iterate, and create a cycle where you constantly learn and improve.”</p><h2 id="future-innovation">Future innovation</h2><p>Another long-term objective, says Zhang, is to use the joined-up view on data to help support the development of new drugs for disease treatments. He says a key reason the UK isn't doing as well as it could in terms of developing new therapies for patients is a lack of data. The Snowflake platform could play a crucial role in supporting progress.</p><p>“We don't know what diseases are there, who is suffering from what disease, and what the trajectories are,” he says. </p><p>“So being able to map that process out, being able to run more clinical trials in this country, and getting new drugs to patients faster, would be a big outcome for me if we can help do that.”</p><p>Reflecting on progress made so far, Zhang says clear long-term objectives and a trusted technology partner are critical to success. As someone well-versed in life-changing decisions in high-pressure environments, he recognizes that digital leaders looking to push data-enabled change must walk before they can run. </p><p>“Often it's not sophisticated things like AI and agents; it's just having the right data in the right place at the right time,” he says. </p><p>“We need to be able to measure outcomes and see what's happening to our patients. Those things sound simple, but they've never really been possible before. So, in that instance, this project is all about trying to prevent preventable things.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Zero-click email attacks: What businesses need to know ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Zero-click attacks bring to mind the advanced spyware typically targeted at a specific subset of users. Infamous examples, such as the <a href="https://www.amnesty.org/en/latest/news/2021/07/the-pegasus-project-2/"><u>Pegasus spyware</u></a> that targeted the family of murdered Saudi dissident <a href="https://www.bbc.co.uk/news/world-europe-45812399" target="_blank"><u>Jamal Khashoggi</u></a>, saw a user compromised simply by receiving a WhatsApp or iMessage. </p><p>But now, email is being used in a zero-click phishing campaign waged by <a href="https://www.itpro.com/security/cyber-attacks/russian-ddos-whats-the-threat-to-businesses"><u>Russian state-backed hackers,</u></a> according to the UK’s <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do"><u>National Cyber Security Centre (NCSC)</u></a>, which has issued an <a href="https://www.itpro.com/security/phishing/ncsc-issues-alert-over-zero-click-phishing-campaign-hitting-enterprises"><u>alert</u></a>.</p><p>Targeting a vulnerability in the Zimbra Collaboration Suite (ZCS) software, the so-called <a href="https://www.ncsc.gov.uk/news/uk-and-partners-expose-russian-state-supported-actors-for-new-zero-click-phishing-campaign"><u>‘beehive’ attacks</u></a> by Russian group Laundry Bear aim to steal email correspondence from organizations operating in critical sectors, according to the <a href="https://media.defense.gov/2026/Jul/22/2003965244/-1/-1/0/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF"><u>joint advisory</u></a>. </p><p>Similar to the zero-click campaigns involving text messages, users only have to view a malicious email to be compromised.</p><h2 id="zero-click-attack-evolution">Zero-click attack evolution</h2><p>Zero-click used to mean “expensive, highly-targeted <a href="https://www.itpro.com/software/ios/apples-ios-update-cycle-overhaul-how-security-teams-should-react"><u>mobile exploits</u></a>” used by nation-states for “silently dropping spyware” via WhatsApp or iMessage, says Matt Cooke, cybersecurity strategist at Proofpoint. </p><p>In the latest attacks, Laundry Bear – also known as <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a"><u>TA488</u></a> and Void Blizzard – “has taken that mechanic out of the intelligence-gathering niche” and “turned it into a mass espionage tool aimed at the corporate inbox”, says Cooke. </p><p>His company has published a <a href="https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits"><u>detailed breakdown</u></a> of the new campaign. </p><p>Zero-click attacks such as these are concerning because they remove “the one thing firms have spent years training people not to do: Click the link”, says Rich Greene, certified instructor at SANS.</p><p>This type of activity is an evolution of attacks carried out via platforms such as WhatsApp and iMessage in highly targeted spyware campaigns, according to Greene. </p><p>“Moving those same ideas into email makes complete sense from an attacker’s perspective,” he said. Email is everywhere, businesses depend on it, and messages are constantly being processed in the background before the user ever decides whether to interact with them.”</p><h2 id="how-the-email-attacks-work">How the email attacks work </h2><p>In the Laundry Bear campaign, which likely used <a href="https://www.itpro.com/technology/neural-network/after-openai-hugging-face-how-do-it-leaders-need-to-change-the-way-they-think-about-ai"><u>AI</u></a>, viewing a crafted message in a vulnerable version of Zimbra webmail was enough to trigger the exploit. This would provide adversaries access while leaving the victim “with little reason to suspect anything had actually happened”, explains Alexander Leslie, a senior advisor at Recorded Future. </p><p>Analysis of the latest campaign found the techniques could be adapted to exploit vulnerabilities in other email software applications used by Western organizations.</p><p>The attackers initially exploited a flaw tracked as <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376"><u>CVE-2025-66376</u></a> in Zimbra Collaboration Suite, but they later took advantage of a second vulnerability in <a href="https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit"><u>Outlook Web Access</u></a>, according to Cooke. “The group has shown it will scale a working technique, rather than retire it after one campaign,” he says.</p><p>The flaw is architectural, explains Cooke. “Email clients render HTML as browsers do. TA488 doesn't need a phishing hook; it hides malicious script fragments inside standard mail formatting.”</p><p>However, while mobile zero-click attacks often don’t require any interaction at all, the campaign does require users to open an email. Therefore, this would properly be described as a “half-click” exploit by researchers, says Cooke.  </p><h2 id="who-is-a-target">Who is a target?</h2><p>The Zimbra campaign ran for at least five months against Ukrainian government entities and US defence, nuclear and research targets. During this time, adversaries exfiltrated information including 90 days of email, session tokens and saved credentials.</p><p>It’s notable how quickly TA488 moved on, says Cooke. “The day after an advisory on that campaign went public, researchers caught the same group already running the second exploit chain against Outlook Web Access, hitting government, telecoms, finance, hospitality and aerospace targets.”</p><p>The Outlook payload is “a step up in sophistication”, according to Cooke. </p><p>“It steals OAuth tokens through compromised mailbox add-ins and grants itself server-side folder permissions via a low-privilege default account. That access survives password resets and even a full device re-image, because it doesn't live on the endpoint at all.”</p><p>Going forward, the sectors most at risk are those that could be targeted by Russian intelligence. This includes defence, government, energy, law enforcement and media, says Leslie. Any organization holding politically, militarily, or commercially sensitive correspondence could be of interest, he adds. </p><h2 id="tackling-zero-click-email-attacks">Tackling zero-click email attacks</h2><p>As zero-click attacks move from messaging to email, telling users not to click on links is no longer a valid response. Yet there’s no need to panic. The latest attacks are still very targeted and require unpatched flaws to compromise firms. </p><p>If you are in an at-risk sector, or if you use ZCS, there are a few steps you can take to reduce the risk. Greene believes organizations need to focus on the basics and “execute them well”.</p><p>The NCSC has advised ZCS users to patch immediately, as well as follow mitigation advice, <a href="https://www.itpro.com/security/what-do-passkeys-mean-for-your-business"><u>use a third-party authentication service that supports passkeys</u></a> where possible, and boost network monitoring capabilities. </p><p>“Patch quickly, keep email clients and operating systems up to date, reduce unnecessary message preview or content-processing features, monitor endpoints and accounts for unusual behaviour, and use layered email, identity and endpoint security controls,” adds Greene. </p><p>Defence in depth is becoming increasingly important, with many organizations using Microsoft Defender Suite for endpoint, email, application and identity protection, says Peter Jones, cyber security specialist at Conscia UK.</p><p>However, he believes it’s worth complementing these controls with behavior detection across the network and within the data center, using tools such as Cisco’s Secure Network Analytics or Secure Workload capabilities.</p><p> “When implemented correctly, Microsoft and Cisco Security tools can work well to provide the visibility to respond effectively in the event of a breach.”</p><p>As zero-click attacks continue to evolve, Cooke thinks the response must be “architectural”. He advises firms to patch webmail and Exchange promptly, but to also “assume patching will always trail behind zero-days”. </p><p>With this in mind, treat sessions and tokens as “short-lived by design”, he advises. “Shorten token lifetimes, and build identity monitoring that flags anomalous token behavior.”</p><p>Overall, he believes firms should plan for containment speed over prevention. “As TA488's Outlook campaign shows, once persistence is server-side, revoking a password isn't enough. Isolating and revoking the session, and auditing folder permissions and add-in access, is what actually closes the door.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/phishing/zero-click-email-attacks-what-businesses-need-to-know</link>
                                                                            <description>
                            <![CDATA[ Russian state-backed attackers are using email to carry out zero-click phishing campaigns. Here’s the need-to-know information ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">BmMHY9RbzeSYvomJphTmH6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/FEpm7PoPiWegwbyvEVshN7-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 25 Aug 2026 14:34:39 +0000</pubDate>                                                                                                                                <updated>Tue, 25 Aug 2026 19:25:58 +0000</updated>
                                                                                                                                            <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kate O&#039;Flaherty ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LUULv6n7VJ3BHPnaoLHHdg-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/FEpm7PoPiWegwbyvEVshN7-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing attack concept image showing an email symbol with red alert symbol on top of a digital interface.]]></media:description>                                                            <media:text><![CDATA[Phishing attack concept image showing an email symbol with red alert symbol on top of a digital interface.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing attack concept image showing an email symbol with red alert symbol on top of a digital interface.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/FEpm7PoPiWegwbyvEVshN7-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Zero-click attacks bring to mind the advanced spyware typically targeted at a specific subset of users. Infamous examples, such as the <a href="https://www.amnesty.org/en/latest/news/2021/07/the-pegasus-project-2/"><u>Pegasus spyware</u></a> that targeted the family of murdered Saudi dissident <a href="https://www.bbc.co.uk/news/world-europe-45812399" target="_blank"><u>Jamal Khashoggi</u></a>, saw a user compromised simply by receiving a WhatsApp or iMessage. </p><p>But now, email is being used in a zero-click phishing campaign waged by <a href="https://www.itpro.com/security/cyber-attacks/russian-ddos-whats-the-threat-to-businesses"><u>Russian state-backed hackers,</u></a> according to the UK’s <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do"><u>National Cyber Security Centre (NCSC)</u></a>, which has issued an <a href="https://www.itpro.com/security/phishing/ncsc-issues-alert-over-zero-click-phishing-campaign-hitting-enterprises"><u>alert</u></a>.</p><p>Targeting a vulnerability in the Zimbra Collaboration Suite (ZCS) software, the so-called <a href="https://www.ncsc.gov.uk/news/uk-and-partners-expose-russian-state-supported-actors-for-new-zero-click-phishing-campaign"><u>‘beehive’ attacks</u></a> by Russian group Laundry Bear aim to steal email correspondence from organizations operating in critical sectors, according to the <a href="https://media.defense.gov/2026/Jul/22/2003965244/-1/-1/0/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF"><u>joint advisory</u></a>. </p><p>Similar to the zero-click campaigns involving text messages, users only have to view a malicious email to be compromised.</p><h2 id="zero-click-attack-evolution">Zero-click attack evolution</h2><p>Zero-click used to mean “expensive, highly-targeted <a href="https://www.itpro.com/software/ios/apples-ios-update-cycle-overhaul-how-security-teams-should-react"><u>mobile exploits</u></a>” used by nation-states for “silently dropping spyware” via WhatsApp or iMessage, says Matt Cooke, cybersecurity strategist at Proofpoint. </p><p>In the latest attacks, Laundry Bear – also known as <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a"><u>TA488</u></a> and Void Blizzard – “has taken that mechanic out of the intelligence-gathering niche” and “turned it into a mass espionage tool aimed at the corporate inbox”, says Cooke. </p><p>His company has published a <a href="https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits"><u>detailed breakdown</u></a> of the new campaign. </p><p>Zero-click attacks such as these are concerning because they remove “the one thing firms have spent years training people not to do: Click the link”, says Rich Greene, certified instructor at SANS.</p><p>This type of activity is an evolution of attacks carried out via platforms such as WhatsApp and iMessage in highly targeted spyware campaigns, according to Greene. </p><p>“Moving those same ideas into email makes complete sense from an attacker’s perspective,” he said. Email is everywhere, businesses depend on it, and messages are constantly being processed in the background before the user ever decides whether to interact with them.”</p><h2 id="how-the-email-attacks-work">How the email attacks work </h2><p>In the Laundry Bear campaign, which likely used <a href="https://www.itpro.com/technology/neural-network/after-openai-hugging-face-how-do-it-leaders-need-to-change-the-way-they-think-about-ai"><u>AI</u></a>, viewing a crafted message in a vulnerable version of Zimbra webmail was enough to trigger the exploit. This would provide adversaries access while leaving the victim “with little reason to suspect anything had actually happened”, explains Alexander Leslie, a senior advisor at Recorded Future. </p><p>Analysis of the latest campaign found the techniques could be adapted to exploit vulnerabilities in other email software applications used by Western organizations.</p><p>The attackers initially exploited a flaw tracked as <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376"><u>CVE-2025-66376</u></a> in Zimbra Collaboration Suite, but they later took advantage of a second vulnerability in <a href="https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit"><u>Outlook Web Access</u></a>, according to Cooke. “The group has shown it will scale a working technique, rather than retire it after one campaign,” he says.</p><p>The flaw is architectural, explains Cooke. “Email clients render HTML as browsers do. TA488 doesn't need a phishing hook; it hides malicious script fragments inside standard mail formatting.”</p><p>However, while mobile zero-click attacks often don’t require any interaction at all, the campaign does require users to open an email. Therefore, this would properly be described as a “half-click” exploit by researchers, says Cooke.  </p><h2 id="who-is-a-target">Who is a target?</h2><p>The Zimbra campaign ran for at least five months against Ukrainian government entities and US defence, nuclear and research targets. During this time, adversaries exfiltrated information including 90 days of email, session tokens and saved credentials.</p><p>It’s notable how quickly TA488 moved on, says Cooke. “The day after an advisory on that campaign went public, researchers caught the same group already running the second exploit chain against Outlook Web Access, hitting government, telecoms, finance, hospitality and aerospace targets.”</p><p>The Outlook payload is “a step up in sophistication”, according to Cooke. </p><p>“It steals OAuth tokens through compromised mailbox add-ins and grants itself server-side folder permissions via a low-privilege default account. That access survives password resets and even a full device re-image, because it doesn't live on the endpoint at all.”</p><p>Going forward, the sectors most at risk are those that could be targeted by Russian intelligence. This includes defence, government, energy, law enforcement and media, says Leslie. Any organization holding politically, militarily, or commercially sensitive correspondence could be of interest, he adds. </p><h2 id="tackling-zero-click-email-attacks">Tackling zero-click email attacks</h2><p>As zero-click attacks move from messaging to email, telling users not to click on links is no longer a valid response. Yet there’s no need to panic. The latest attacks are still very targeted and require unpatched flaws to compromise firms. </p><p>If you are in an at-risk sector, or if you use ZCS, there are a few steps you can take to reduce the risk. Greene believes organizations need to focus on the basics and “execute them well”.</p><p>The NCSC has advised ZCS users to patch immediately, as well as follow mitigation advice, <a href="https://www.itpro.com/security/what-do-passkeys-mean-for-your-business"><u>use a third-party authentication service that supports passkeys</u></a> where possible, and boost network monitoring capabilities. </p><p>“Patch quickly, keep email clients and operating systems up to date, reduce unnecessary message preview or content-processing features, monitor endpoints and accounts for unusual behaviour, and use layered email, identity and endpoint security controls,” adds Greene. </p><p>Defence in depth is becoming increasingly important, with many organizations using Microsoft Defender Suite for endpoint, email, application and identity protection, says Peter Jones, cyber security specialist at Conscia UK.</p><p>However, he believes it’s worth complementing these controls with behavior detection across the network and within the data center, using tools such as Cisco’s Secure Network Analytics or Secure Workload capabilities.</p><p> “When implemented correctly, Microsoft and Cisco Security tools can work well to provide the visibility to respond effectively in the event of a breach.”</p><p>As zero-click attacks continue to evolve, Cooke thinks the response must be “architectural”. He advises firms to patch webmail and Exchange promptly, but to also “assume patching will always trail behind zero-days”. </p><p>With this in mind, treat sessions and tokens as “short-lived by design”, he advises. “Shorten token lifetimes, and build identity monitoring that flags anomalous token behavior.”</p><p>Overall, he believes firms should plan for containment speed over prevention. “As TA488's Outlook campaign shows, once persistence is server-side, revoking a password isn't enough. Isolating and revoking the session, and auditing folder permissions and add-in access, is what actually closes the door.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Can the UK become Europe’s AI infrastructure hub? Why the answer matters for the channel ]]></title>
                                                                                                <dc:content><![CDATA[ <p>AI is becoming an infrastructure race, not just a software one. Across Europe, governments, hyperscalers and investors are competing to build the compute, connectivity and operational backbone required to support AI at scale. The UK has made clear that it has been and intends to be part of that conversation.</p><p>There are good reasons to take that ambition seriously. Through its UK Compute Roadmap, the government has placed AI infrastructure at the centre of its industrial strategy, with plans to expand public compute capacity, establish AI Growth Zones, accelerate data center planning and invest in compute and semiconductor capabilities. </p><p>Private investment has followed, including Blackstone’s £10 billion AI data center project in Northumberland, CoreWeave’s multi-billion-pound investment in UK AI compute capacity, AWS’s £8 billion commitment to UK data centers and Google’s continued investment in expanding its UK infrastructure footprint.</p><p>But ambition on its own is not enough.</p><h2 id="the-uk-s-competitive-advantages">The UK’s competitive advantages</h2><p>The UK enters this race with several meaningful strengths. It has one of Europe’s largest AI ecosystems, a mature cloud market, an established hyperscale data center footprint and a deep enterprise customer base that is actively exploring AI adoption.</p><p>London remains one of the continent’s leading financial centres, helping attract investment while bringing together organizations with both the capital and appetite to invest in AI initiatives. </p><p>Combined with world-class universities and research institutions that continue to produce talent and innovation, the UK has many of the ingredients needed to position itself as a long-term hub for European AI innovation.</p><h2 id="the-uk-s-infrastructure-challenges">The UK’s infrastructure challenges</h2><p>Power availability may be the UK’s greatest obstacle. Industrial electricity prices remain among the highest in the developed world, while grid connections for major infrastructure projects can take years to secure. The UK’s AI ambitions ultimately depend on a resource that cannot be scaled overnight: energy.</p><p>That matters because AI workloads, particularly GPU-intensive ones, are unusually power-hungry. Over time, energy economics will influence not only where infrastructure is built, but where workloads actually run. As enterprises look more closely at the cost of scaling AI, location becomes an operating decision, not just a property or planning decision.</p><p>The UK also faces growing competition from across Europe. France benefits from strong government backing and abundant nuclear energy. The Nordic countries offer renewable power, cooler climates, and lower operating costs that naturally support large-scale data centers. Germany combines industrial scale with significant enterprise demand for AI, while Ireland continues to attract hyperscale cloud investment even as it grapples with its own energy constraints.</p><p>Rather than competing on identical strengths, each market has the chance to build a compelling proposition. The UK’s competitive edge lies less in offering the cheapest power and more in combining enterprise demand, financial investment, cloud maturity and a growing AI innovation ecosystem. Whether that will be enough to secure long-term advantage remains an open question.</p><h2 id="what-does-this-mean-for-the-channel">What does this mean for the channel?</h2><p>For channel partners, focusing only on which country “wins” risks missing the bigger opportunity.</p><p>As enterprises move from AI experimentation to production deployments, infrastructure decisions are becoming business decisions. Clients are asking where AI workloads should run, how to balance cloud and on-premises environments, control costs, meet sovereignty and compliance requirements, and scale without creating operational drag.</p><p>That shift moves the conversation beyond products and into outcomes. The most relevant partners will be the ones that can help clients make better decisions across architecture, operations, governance, and cost, not just deploy another piece of technology.</p><p>For Managed Service Providers (MSPs), systems integrators, and other channel partners, this creates an opportunity to move further up the value chain. Rather than simply helping clients select and deploy infrastructure for AI, partners can help assess AI readiness, modernize data center environments, design hybrid AI architectures, optimize networking and storage, strengthen security, implement governance, and build a more disciplined approach to long-term AI cost management.</p><p>Energy will remain central to that conversation. GPU-intensive workloads already place significant demands on power and cooling, making infrastructure efficiency a real business concern. As customers seek to understand why AI deployments cost what they do, partners that can connect technology decisions with operational improvements will stand out.</p><p>The bottom line is that the opportunity for channel partners is not tied to a particular postcode or data center location. Instead, it is tied to helping clients navigate the growing complexity of AI infrastructure itself.</p><h2 id="looking-beyond-the-build-out">Looking beyond the build-out</h2><p>While public attention often focuses on where compute capacity will be built, the more durable opportunity lies in supporting AI inference: the day-to-day execution of AI workloads that power business applications and operational decisions. As AI adoption matures, these workloads must run securely, efficiently and cost-effectively, creating sustained demand for the design, integration and managed services that channel partners are well positioned to provide.</p><p>Whether the UK ultimately establishes itself as Europe’s primary AI infrastructure hub remains an open question. The country has clear strengths, but also some constraints that need long-term solutions, such as around power, planning, and long-term capacity. Geography alone will not determine the winners.</p><p>For channel partners, taking a wait-and-see approach would be a mistake. The smarter move is to help clients design and refine AI environments around their operational needs now. Those that bring expertise in AI architecture, workload optimisation, cost management, energy efficiency and governance will be best positioned to lead, regardless of which country comes out ahead.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/technology/artificial-intelligence/can-the-uk-become-europes-ai-infrastructure-hub-why-the-answer-matters-for-the-channel</link>
                                                                            <description>
                            <![CDATA[ The billions pouring into British data centers are real. So are the energy constraints. Here’s what channel partners need to know ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gTuY3R8rzzsYyYx6KQ4ZMT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9hCna3oJCMzCMCug25PcDE-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 25 Aug 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Paul Allen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/WqS66mvYdA5SMMJeNSyorC-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9hCna3oJCMzCMCug25PcDE-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Artificial Intelligence Machine Learning Natural Language Processing Data Technology]]></media:description>                                                            <media:text><![CDATA[Artificial Intelligence Machine Learning Natural Language Processing Data Technology]]></media:text>
                                <media:title type="plain"><![CDATA[Artificial Intelligence Machine Learning Natural Language Processing Data Technology]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9hCna3oJCMzCMCug25PcDE-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>AI is becoming an infrastructure race, not just a software one. Across Europe, governments, hyperscalers and investors are competing to build the compute, connectivity and operational backbone required to support AI at scale. The UK has made clear that it has been and intends to be part of that conversation.</p><p>There are good reasons to take that ambition seriously. Through its UK Compute Roadmap, the government has placed AI infrastructure at the centre of its industrial strategy, with plans to expand public compute capacity, establish AI Growth Zones, accelerate data center planning and invest in compute and semiconductor capabilities. </p><p>Private investment has followed, including Blackstone’s £10 billion AI data center project in Northumberland, CoreWeave’s multi-billion-pound investment in UK AI compute capacity, AWS’s £8 billion commitment to UK data centers and Google’s continued investment in expanding its UK infrastructure footprint.</p><p>But ambition on its own is not enough.</p><h2 id="the-uk-s-competitive-advantages">The UK’s competitive advantages</h2><p>The UK enters this race with several meaningful strengths. It has one of Europe’s largest AI ecosystems, a mature cloud market, an established hyperscale data center footprint and a deep enterprise customer base that is actively exploring AI adoption.</p><p>London remains one of the continent’s leading financial centres, helping attract investment while bringing together organizations with both the capital and appetite to invest in AI initiatives. </p><p>Combined with world-class universities and research institutions that continue to produce talent and innovation, the UK has many of the ingredients needed to position itself as a long-term hub for European AI innovation.</p><h2 id="the-uk-s-infrastructure-challenges">The UK’s infrastructure challenges</h2><p>Power availability may be the UK’s greatest obstacle. Industrial electricity prices remain among the highest in the developed world, while grid connections for major infrastructure projects can take years to secure. The UK’s AI ambitions ultimately depend on a resource that cannot be scaled overnight: energy.</p><p>That matters because AI workloads, particularly GPU-intensive ones, are unusually power-hungry. Over time, energy economics will influence not only where infrastructure is built, but where workloads actually run. As enterprises look more closely at the cost of scaling AI, location becomes an operating decision, not just a property or planning decision.</p><p>The UK also faces growing competition from across Europe. France benefits from strong government backing and abundant nuclear energy. The Nordic countries offer renewable power, cooler climates, and lower operating costs that naturally support large-scale data centers. Germany combines industrial scale with significant enterprise demand for AI, while Ireland continues to attract hyperscale cloud investment even as it grapples with its own energy constraints.</p><p>Rather than competing on identical strengths, each market has the chance to build a compelling proposition. The UK’s competitive edge lies less in offering the cheapest power and more in combining enterprise demand, financial investment, cloud maturity and a growing AI innovation ecosystem. Whether that will be enough to secure long-term advantage remains an open question.</p><h2 id="what-does-this-mean-for-the-channel">What does this mean for the channel?</h2><p>For channel partners, focusing only on which country “wins” risks missing the bigger opportunity.</p><p>As enterprises move from AI experimentation to production deployments, infrastructure decisions are becoming business decisions. Clients are asking where AI workloads should run, how to balance cloud and on-premises environments, control costs, meet sovereignty and compliance requirements, and scale without creating operational drag.</p><p>That shift moves the conversation beyond products and into outcomes. The most relevant partners will be the ones that can help clients make better decisions across architecture, operations, governance, and cost, not just deploy another piece of technology.</p><p>For Managed Service Providers (MSPs), systems integrators, and other channel partners, this creates an opportunity to move further up the value chain. Rather than simply helping clients select and deploy infrastructure for AI, partners can help assess AI readiness, modernize data center environments, design hybrid AI architectures, optimize networking and storage, strengthen security, implement governance, and build a more disciplined approach to long-term AI cost management.</p><p>Energy will remain central to that conversation. GPU-intensive workloads already place significant demands on power and cooling, making infrastructure efficiency a real business concern. As customers seek to understand why AI deployments cost what they do, partners that can connect technology decisions with operational improvements will stand out.</p><p>The bottom line is that the opportunity for channel partners is not tied to a particular postcode or data center location. Instead, it is tied to helping clients navigate the growing complexity of AI infrastructure itself.</p><h2 id="looking-beyond-the-build-out">Looking beyond the build-out</h2><p>While public attention often focuses on where compute capacity will be built, the more durable opportunity lies in supporting AI inference: the day-to-day execution of AI workloads that power business applications and operational decisions. As AI adoption matures, these workloads must run securely, efficiently and cost-effectively, creating sustained demand for the design, integration and managed services that channel partners are well positioned to provide.</p><p>Whether the UK ultimately establishes itself as Europe’s primary AI infrastructure hub remains an open question. The country has clear strengths, but also some constraints that need long-term solutions, such as around power, planning, and long-term capacity. Geography alone will not determine the winners.</p><p>For channel partners, taking a wait-and-see approach would be a mistake. The smarter move is to help clients design and refine AI environments around their operational needs now. Those that bring expertise in AI architecture, workload optimisation, cost management, energy efficiency and governance will be best positioned to lead, regardless of which country comes out ahead.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Unlocking data experience as the new revenue opportunity for channel partners ]]></title>
                                                                                                <dc:content><![CDATA[ <p>For years, channel partners have made their margins on cloud migration and security, helping clients move data somewhere safe and keep it that way. Both have become the default, but solving that problem has quietly created a new one: data that is safe and well governed is not the same as data people can actually use. </p><p>Backend systems have grown more sophisticated while the interfaces sitting on top of them have stayed clunky, fragmented, and largely ignored, leaving valuable information locked away from the people who need it most, and this is where the value has now shifted. </p><p>Relying on cloud migration and baseline security as a primary revenue engine will leave channel partners behind because providers continue to sell infrastructure solutions to an enterprise market that has already moved past the infrastructure phase.</p><p>Storage and security handle yesterday's issues, while data silos resulting in data fragmentation are now the urgent challenges of today. Data silos trap critical information within isolated, non-communicating systems, scattering corporate data unevenly across public clouds and legacy applications. This inevitably leads to data fragmentation: a chaotic state in which corporate data is unevenly distributed across multiple public clouds, legacy systems, and disconnected applications. </p><p>The consequences of this fragmentation are crippling, leaving organizations without a single source of truth. In fact, 77% of respondents in an <a href="https://www.ibm.com/think/topics/data-silos"><u>IBM Institute for Business Value study</u></a> strongly agreed that these silos actively hinder real-time analytics and data-driven decisions.</p><p>For the past decade, managed service providers (MSPs), value-added resellers (VARs), and IT consultants have built highly profitable practices by guiding organizations through cloud infrastructure modernisation. But today, the next margin growth opportunity isn’t where data is stored; it is how that data is experienced: a shift known as the Digital Experience Platform (DXP) space, which helps organizations unify, govern, and present fragmented backend data into usable, front-end interfaces.</p><h2 id="the-multi-million-dollar-data-disconnect">The multi-million dollar data disconnect</h2><p>Organizations continue to pour substantial capital into upgrading their cloud infrastructure. An <a href="https://omdia.tech.informa.com/pr/2026/mar/global-cloud-infrastructure-spending-rose-29percent-in-q4-2025-as-hyperscalers-scaled-ai-infrastructure-investment?utm_source=chatgpt.com"><u>Omdia</u></a> survey shows how spending reached US$110.9 billion in late 2025, a 29% year-on-year surge, with another 27% growth forecast through 2026 on global cloud infrastructure. However, a massive operational problem persists: the data sits perfectly organized in the backend but remains functionally inaccessible to the end user.</p><p>Simply owning data is no longer a competitive advantage; the real value is in how easily people can use it. This structural gap between backend complexity and front-end utility defines the "Data Experience" gap.</p><p>For a business-to-business (B2B) buyer, this gap looks like a frustrating customer portal that cannot display real-time shipping updates because the shipping database does not talk to the web interface. For a supplier, it means relying on manual emails because procurement platforms do not share information.</p><h2 id="transitioning-to-data-experience-architecture">Transitioning to data experience architecture</h2><p>To capture higher profit margins in this landscape, channel partners must transition from storage infrastructure providers into data experience builders. </p><p>This evolution requires moving away from traditional, slow, and expensive data migration methods, such as moving information into the cloud, and instead focuses on building smart, lightweight integration layers. By seamlessly connecting legacy systems to modern cloud environments, partners can consolidate fragmented data into a single, cohesive view without disrupting the underlying storage architecture. </p><p>This ability to deliver integration without interruption represents a highly specialized skill set for which corporate clients are willing to pay a premium.</p><p>Beyond merely connecting these disparate systems, opening the flow of data introduces an urgent need for smart permissions and sophisticated governance. </p><p>A distributor, a B2B customer, and an internal sales representative may all require access to information stored in the same database, yet what actually appears on their respective screens must be uniquely tailored. </p><p>Designing and implementing these complex, context-aware access control systems serves as a high-value advisory service. It establishes a level of security and compliance that basic software resellers simply cannot replicate, deeply embedding the partner into the client's day-to-day operations.</p><p>Ultimately, these seamless backend connections enable the delivery of consumer-style B2B experiences that modern buyers now expect as standard. Digital experience insights tracked by platform providers indicate that the primary hurdle for B2B companies isn't designing an attractive user interface; rather, it is untangling the complex web of integrations sitting right beneath the surface. </p><p>Channel partners who can bridge this gap by building tailored vendor portals and collaborative digital workspaces resolve their clients' most critical technical friction points, effectively making themselves indispensable business allies.</p><h2 id="the-high-margin-advisory-model">The high-margin advisory model</h2><p>When a partner fixes an organization's data experience, they are doing far more than installing software. They are mapping out how the business actually runs, improving daily operations, and building resilient integration systems. </p><p>This results in higher client retention, robust profit protection, and a steady stream of recurring revenue as the client’s digital needs continue to scale.</p><p>Architecting these solutions requires a technology foundation designed specifically for backend complexity. Platforms that act as a unified hub connecting content, workflows, and backend systems to deliver personalized experiences are built for this transition, offering an evolvable architecture that allows partners to bridge the data experience gap across the entire business ecosystem. </p><p>By building security and context-aware compliance directly into the core of the integration layer, partners can safely deliver highly localised, consumer-grade experiences across diverse global markets. Furthermore, utilizing integrated AI and scalable SaaS or PaaS environments ensures that as client traffic and campaign demands fluctuate, the underlying data layer remains resilient.</p><p>The foundational infrastructure of the modern enterprise has already been laid. The channel partners who will win over the next decade will be those who don’t focus solely on storage boxes, but instead upskill their teams in integration governance and start unlocking the value of the data inside them. </p><p>The market has moved past the plumbing phase to build data experience, and channel partners need to move with it.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/business/data-and-insights/unlocking-data-experience-as-the-new-revenue-opportunity-for-channel-partners</link>
                                                                            <description>
                            <![CDATA[ Upskilling in integration governance will separate the channel winners from the channel losers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">u3r5PLrG7rifYrJE5jy9oH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/p6SHUCH4Cp9Ao9UbtkVNMK-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 24 Aug 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data and Insights]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Mike MacAuley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/CpBx8x4vWdjAB8bXrcXsnA-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/p6SHUCH4Cp9Ao9UbtkVNMK-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Digital transformation concept image showing human hand touching digital interface with glowing data points.]]></media:description>                                                            <media:text><![CDATA[Digital transformation concept image showing human hand touching digital interface with glowing data points.]]></media:text>
                                <media:title type="plain"><![CDATA[Digital transformation concept image showing human hand touching digital interface with glowing data points.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/p6SHUCH4Cp9Ao9UbtkVNMK-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>For years, channel partners have made their margins on cloud migration and security, helping clients move data somewhere safe and keep it that way. Both have become the default, but solving that problem has quietly created a new one: data that is safe and well governed is not the same as data people can actually use. </p><p>Backend systems have grown more sophisticated while the interfaces sitting on top of them have stayed clunky, fragmented, and largely ignored, leaving valuable information locked away from the people who need it most, and this is where the value has now shifted. </p><p>Relying on cloud migration and baseline security as a primary revenue engine will leave channel partners behind because providers continue to sell infrastructure solutions to an enterprise market that has already moved past the infrastructure phase.</p><p>Storage and security handle yesterday's issues, while data silos resulting in data fragmentation are now the urgent challenges of today. Data silos trap critical information within isolated, non-communicating systems, scattering corporate data unevenly across public clouds and legacy applications. This inevitably leads to data fragmentation: a chaotic state in which corporate data is unevenly distributed across multiple public clouds, legacy systems, and disconnected applications. </p><p>The consequences of this fragmentation are crippling, leaving organizations without a single source of truth. In fact, 77% of respondents in an <a href="https://www.ibm.com/think/topics/data-silos"><u>IBM Institute for Business Value study</u></a> strongly agreed that these silos actively hinder real-time analytics and data-driven decisions.</p><p>For the past decade, managed service providers (MSPs), value-added resellers (VARs), and IT consultants have built highly profitable practices by guiding organizations through cloud infrastructure modernisation. But today, the next margin growth opportunity isn’t where data is stored; it is how that data is experienced: a shift known as the Digital Experience Platform (DXP) space, which helps organizations unify, govern, and present fragmented backend data into usable, front-end interfaces.</p><h2 id="the-multi-million-dollar-data-disconnect">The multi-million dollar data disconnect</h2><p>Organizations continue to pour substantial capital into upgrading their cloud infrastructure. An <a href="https://omdia.tech.informa.com/pr/2026/mar/global-cloud-infrastructure-spending-rose-29percent-in-q4-2025-as-hyperscalers-scaled-ai-infrastructure-investment?utm_source=chatgpt.com"><u>Omdia</u></a> survey shows how spending reached US$110.9 billion in late 2025, a 29% year-on-year surge, with another 27% growth forecast through 2026 on global cloud infrastructure. However, a massive operational problem persists: the data sits perfectly organized in the backend but remains functionally inaccessible to the end user.</p><p>Simply owning data is no longer a competitive advantage; the real value is in how easily people can use it. This structural gap between backend complexity and front-end utility defines the "Data Experience" gap.</p><p>For a business-to-business (B2B) buyer, this gap looks like a frustrating customer portal that cannot display real-time shipping updates because the shipping database does not talk to the web interface. For a supplier, it means relying on manual emails because procurement platforms do not share information.</p><h2 id="transitioning-to-data-experience-architecture">Transitioning to data experience architecture</h2><p>To capture higher profit margins in this landscape, channel partners must transition from storage infrastructure providers into data experience builders. </p><p>This evolution requires moving away from traditional, slow, and expensive data migration methods, such as moving information into the cloud, and instead focuses on building smart, lightweight integration layers. By seamlessly connecting legacy systems to modern cloud environments, partners can consolidate fragmented data into a single, cohesive view without disrupting the underlying storage architecture. </p><p>This ability to deliver integration without interruption represents a highly specialized skill set for which corporate clients are willing to pay a premium.</p><p>Beyond merely connecting these disparate systems, opening the flow of data introduces an urgent need for smart permissions and sophisticated governance. </p><p>A distributor, a B2B customer, and an internal sales representative may all require access to information stored in the same database, yet what actually appears on their respective screens must be uniquely tailored. </p><p>Designing and implementing these complex, context-aware access control systems serves as a high-value advisory service. It establishes a level of security and compliance that basic software resellers simply cannot replicate, deeply embedding the partner into the client's day-to-day operations.</p><p>Ultimately, these seamless backend connections enable the delivery of consumer-style B2B experiences that modern buyers now expect as standard. Digital experience insights tracked by platform providers indicate that the primary hurdle for B2B companies isn't designing an attractive user interface; rather, it is untangling the complex web of integrations sitting right beneath the surface. </p><p>Channel partners who can bridge this gap by building tailored vendor portals and collaborative digital workspaces resolve their clients' most critical technical friction points, effectively making themselves indispensable business allies.</p><h2 id="the-high-margin-advisory-model">The high-margin advisory model</h2><p>When a partner fixes an organization's data experience, they are doing far more than installing software. They are mapping out how the business actually runs, improving daily operations, and building resilient integration systems. </p><p>This results in higher client retention, robust profit protection, and a steady stream of recurring revenue as the client’s digital needs continue to scale.</p><p>Architecting these solutions requires a technology foundation designed specifically for backend complexity. Platforms that act as a unified hub connecting content, workflows, and backend systems to deliver personalized experiences are built for this transition, offering an evolvable architecture that allows partners to bridge the data experience gap across the entire business ecosystem. </p><p>By building security and context-aware compliance directly into the core of the integration layer, partners can safely deliver highly localised, consumer-grade experiences across diverse global markets. Furthermore, utilizing integrated AI and scalable SaaS or PaaS environments ensures that as client traffic and campaign demands fluctuate, the underlying data layer remains resilient.</p><p>The foundational infrastructure of the modern enterprise has already been laid. The channel partners who will win over the next decade will be those who don’t focus solely on storage boxes, but instead upskill their teams in integration governance and start unlocking the value of the data inside them. </p><p>The market has moved past the plumbing phase to build data experience, and channel partners need to move with it.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The key to a successful IT strategy ]]></title>
                                                                                                <dc:content><![CDATA[ <iframe allow="clipboard-write" height="200px" width="100%" id="" style="width: 100%; height: 200px;" class="position-center" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/88d5a3be-836c-4e42-bd79-02e01fff9cb9"></iframe><p>Poorly implemented IT strategies have a significant impact on businesses. From lackluster growth and financial losses to employee change fatigue, the risks are huge. </p><p>With enterprises ramping up AI adoption, many are failing to learn the lessons from previous change programs and are diving headlong into projects.</p><p>On this week's episode of the ITPro Podcast, Jane and Ross speak with Al Kingsley MBE, CEO of NetSupport, to explore how IT leaders can implement change, lead by example, and deliver successful transformation projects.</p><h2 id="highlights-4">Highlights</h2><p>“First and foremost, we need to make sure that we're not just making changes because, hey, we've just seen online that everyone's using AI now, so hey, we'll go that way. As opposed to, well, what are we trying to mitigate here? Is it about productivity and output? You know, and the data bit is, well, if we don't know how to robustly interrogate our data, and a bit like those who remember Donald Rumsfeld from the U.S. government, it's not the known knowns or the known unknowns; it's the unknown unknowns. You don't have the right questions to ask, you're not going to get the right answers, and the data is not going to help inform your decision-making.”</p><p>“We're seeing more and more agentic AI, AI that's running in parallel and running tasks, being adopted in organizations at pace. But the other thing to balance all that yin and yang with, I think, is the more we're adopting at-pace technology in our organization, it is increasing the value of the human bit. Whether it's the customer service, the engagement with people, the way we think differently, the way we're more creative, and so the real irony is that AI and digital are also amplifying the value of our most human aspects and skills too.”</p><h2 id="links-3">Links</h2><ul><li><a href="https://www.itpro.com/business/digital-transformation/enterprises-just-cant-seem-to-shake-legacy-tech-and-its-seriously-hampering-digital-transformation-goals"><u>Enterprises just can't seem to shake legacy tech – and it’s seriously hampering digital transformation goals</u></a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/ai-was-meant-to-simplify-it-service-management-new-research-shows-its-creating-bigger-workloads-for-teams"><u>AI was meant to simplify IT service management – new research shows it's creating bigger workloads for teams</u></a></li></ul> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/business/digital-transformation/the-key-to-a-successful-it-strategy</link>
                                                                            <description>
                            <![CDATA[ Exploring how IT leaders can implement change, lead by example, and deliver successful transformation projects ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">P4pEZ7TKQVheeGB72vNUXn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/i6Ma9RwPc9ZfycMoKeQumC-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 21 Aug 2026 13:06:25 +0000</pubDate>                                                                                                                                <updated>Mon, 24 Aug 2026 11:17:15 +0000</updated>
                                                                                                                                            <category><![CDATA[Digital Transformation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ jane.mccallion@futurenet.com (Jane McCallion) ]]></author>                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Wq9nnLr7TNkY8gyBRb7YsA-320-70.jpeg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Jane is managing editor at ITPro and ChannelPro. She started out with the brands as a staff writer specializing in cloud computing before going on to become senior writer and reports editor, managing the content and creation of ITPro’s quarterly whitepapers. During this time, she broadened her expertise to include cybersecurity, data centers and enterprise IT infrastructure. In 2016, she became features editor, managing a pool of freelance and internal writers, while continuing to specialize in enterprise IT infrastructure, data centers, and business strategy.&lt;/p&gt;&lt;p&gt;In October 2021, she became the sites’ deputy editor, before moving to the role of managing editor in June 2024. Although she now has a more strategic role,  she is still a specialist in enterprise IT infrastructure, business strategy, and cybersecurity.&lt;/p&gt;&lt;p&gt;Jane holds an MA in journalism from Goldsmiths, University of London, and a BA in Applied Languages from the University of Portsmouth. She is fluent in French and Spanish, and has written features in both languages.&lt;/p&gt;&lt;p&gt;Prior to joining ITPro, Jane was a freelance business journalist writing as both Jane McCallion and Jane Bordenave for titles such as European CEO, World Finance, and Business Excellence Magazine.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/i6Ma9RwPc9ZfycMoKeQumC-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images/Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The pod episode title over lines of code]]></media:description>                                                            <media:text><![CDATA[The pod episode title over lines of code]]></media:text>
                                <media:title type="plain"><![CDATA[The pod episode title over lines of code]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/i6Ma9RwPc9ZfycMoKeQumC-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <iframe allow="clipboard-write" height="200px" width="100%" id="" style="width: 100%; height: 200px;" class="position-center" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/88d5a3be-836c-4e42-bd79-02e01fff9cb9"></iframe><p>Poorly implemented IT strategies have a significant impact on businesses. From lackluster growth and financial losses to employee change fatigue, the risks are huge. </p><p>With enterprises ramping up AI adoption, many are failing to learn the lessons from previous change programs and are diving headlong into projects.</p><p>On this week's episode of the ITPro Podcast, Jane and Ross speak with Al Kingsley MBE, CEO of NetSupport, to explore how IT leaders can implement change, lead by example, and deliver successful transformation projects.</p><h2 id="highlights-4">Highlights</h2><p>“First and foremost, we need to make sure that we're not just making changes because, hey, we've just seen online that everyone's using AI now, so hey, we'll go that way. As opposed to, well, what are we trying to mitigate here? Is it about productivity and output? You know, and the data bit is, well, if we don't know how to robustly interrogate our data, and a bit like those who remember Donald Rumsfeld from the U.S. government, it's not the known knowns or the known unknowns; it's the unknown unknowns. You don't have the right questions to ask, you're not going to get the right answers, and the data is not going to help inform your decision-making.”</p><p>“We're seeing more and more agentic AI, AI that's running in parallel and running tasks, being adopted in organizations at pace. But the other thing to balance all that yin and yang with, I think, is the more we're adopting at-pace technology in our organization, it is increasing the value of the human bit. Whether it's the customer service, the engagement with people, the way we think differently, the way we're more creative, and so the real irony is that AI and digital are also amplifying the value of our most human aspects and skills too.”</p><h2 id="links-3">Links</h2><ul><li><a href="https://www.itpro.com/business/digital-transformation/enterprises-just-cant-seem-to-shake-legacy-tech-and-its-seriously-hampering-digital-transformation-goals"><u>Enterprises just can't seem to shake legacy tech – and it’s seriously hampering digital transformation goals</u></a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/ai-was-meant-to-simplify-it-service-management-new-research-shows-its-creating-bigger-workloads-for-teams"><u>AI was meant to simplify IT service management – new research shows it's creating bigger workloads for teams</u></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ From reactive support to smart services ]]></title>
                                                                                                <dc:content><![CDATA[ <p>As print infrastructure extends across multiple sites, home offices, and hybrid workplaces, maintaining oversight of device fleets has become significantly more complex. Managed Service Providers (MSPs) are under growing pressure to deliver reliable support while controlling costs and maintaining service quality.</p><p>At the same time, organizations are under pressure to monitor and secure expanding device networks against a backdrop of rising cyber threats. Recent research highlights the scale of this challenge, with <a href="https://quocirca.com/content/quocirca-print-security-landscape-2025-press-release/"><u>56% of organizations reporting a print-related data breach in 2024-2025.</u></a></p><p>Without timely insight into device health and performance, IT teams are forced into a reactive approach, responding to faults only after they disrupt workflows, and requiring engineer visits that could potentially have been avoided. </p><p>These pressures have accelerated the shift towards smart services. By combining intelligent monitoring, predictive insights, and AI-powered capabilities, partners can identify and resolve issues earlier, improve fleet reliability, strengthen security, and provide customers with greater visibility and control across increasingly complex print environments. </p><h2 id="why-reactive-support-is-no-longer-enough">Why reactive support is no longer enough </h2><p>Historically, service success was often measured by how quickly someone could arrive on-site to resolve an issue, with engineers responding when faults are reported and once disruption has already occurred.</p><p>These traditional service models built around reactive intervention are struggling to keep pace with how organizations operate today. Now, customers expect issues to be resolved quickly with minimal disruption and downtime, and for every connected device to be properly maintained to avoid faults in the first place. </p><p>For MSPs, relying solely on reactive intervention makes it more difficult to scale operations efficiently, maximize engineering resources, and maintain healthy service margins. Instead, long-term value increasingly depends on proactive service models that keep print ecosystems online. </p><p>For channel partners, the challenge is adapting.</p><h2 id="how-smart-services-are-transforming-support">How smart services are transforming support</h2><p>Importantly, proactive smart services are not about removing engineers entirely from the process. </p><p>Across the channel, condition monitoring and remote access are allowing service teams to assess whether issues can be resolved remotely before allocating resources, while predictive monitoring helps identify components that are likely to fail, enabling preventative maintenance before disruption occurs.</p><p>The result is improved first-time fix outcomes, increased operational efficiency through greater uptime, and fewer unnecessary on-site visits, allowing engineering resources to be deployed more effectively.</p><p>For partners, this is enabling a shift from interrogating the customer to interrogating the device, ensuring partner-customer relationships are maintained, and ensuring engineers have the time to focus on resolving more complex issues and delivering effective long-term support.</p><h2 id="creating-long-term-value-through-smart-services">Creating long-term value through smart services</h2><p>Across the print channel, value is increasingly being demonstrated through services rather than hardware alone. The strength of a partner relationship is not defined by technology alone, but by the trust and expertise that support it over time. </p><p>As AI moves from experimentation to application, the real opportunity lies in practical deployment. The focus shifts from headline innovation to operational value that helps partners support customers more effectively.</p><p>Smart services are intended to sit within that space. Not as a silver bullet, and not as a standalone answer, but as a structured approach to making device support more intelligent, more connected, and more aligned with how businesses now operate.</p><p>In a market that is becoming more connected and more demanding by default, expanding customer relationships beyond reactive support is central for partners to strengthen long-term customer relationships and create sustainable recurring revenue opportunities through higher-value services.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/hardware/printers/from-reactive-support-to-smart-services</link>
                                                                            <description>
                            <![CDATA[ Proactive service models are creating new opportunities for print partners ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tZBDeZVa2LWQBcXa2waQZD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/m65BURH6wVrqP2Qpe34f5W-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 21 Aug 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Printers]]></category>
                                                    <category><![CDATA[Hardware]]></category>
                                                                                                                    <dc:creator><![CDATA[ Stuart Miller ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/XntRDcqCYWfMnJ5gV9qE2k-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/m65BURH6wVrqP2Qpe34f5W-1920-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Woman sat at a desk, working from a laptop and printing a document using her printer]]></media:description>                                                            <media:text><![CDATA[Woman sat at a desk, working from a laptop and printing a document using her printer]]></media:text>
                                <media:title type="plain"><![CDATA[Woman sat at a desk, working from a laptop and printing a document using her printer]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/m65BURH6wVrqP2Qpe34f5W-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>As print infrastructure extends across multiple sites, home offices, and hybrid workplaces, maintaining oversight of device fleets has become significantly more complex. Managed Service Providers (MSPs) are under growing pressure to deliver reliable support while controlling costs and maintaining service quality.</p><p>At the same time, organizations are under pressure to monitor and secure expanding device networks against a backdrop of rising cyber threats. Recent research highlights the scale of this challenge, with <a href="https://quocirca.com/content/quocirca-print-security-landscape-2025-press-release/"><u>56% of organizations reporting a print-related data breach in 2024-2025.</u></a></p><p>Without timely insight into device health and performance, IT teams are forced into a reactive approach, responding to faults only after they disrupt workflows, and requiring engineer visits that could potentially have been avoided. </p><p>These pressures have accelerated the shift towards smart services. By combining intelligent monitoring, predictive insights, and AI-powered capabilities, partners can identify and resolve issues earlier, improve fleet reliability, strengthen security, and provide customers with greater visibility and control across increasingly complex print environments. </p><h2 id="why-reactive-support-is-no-longer-enough">Why reactive support is no longer enough </h2><p>Historically, service success was often measured by how quickly someone could arrive on-site to resolve an issue, with engineers responding when faults are reported and once disruption has already occurred.</p><p>These traditional service models built around reactive intervention are struggling to keep pace with how organizations operate today. Now, customers expect issues to be resolved quickly with minimal disruption and downtime, and for every connected device to be properly maintained to avoid faults in the first place. </p><p>For MSPs, relying solely on reactive intervention makes it more difficult to scale operations efficiently, maximize engineering resources, and maintain healthy service margins. Instead, long-term value increasingly depends on proactive service models that keep print ecosystems online. </p><p>For channel partners, the challenge is adapting.</p><h2 id="how-smart-services-are-transforming-support">How smart services are transforming support</h2><p>Importantly, proactive smart services are not about removing engineers entirely from the process. </p><p>Across the channel, condition monitoring and remote access are allowing service teams to assess whether issues can be resolved remotely before allocating resources, while predictive monitoring helps identify components that are likely to fail, enabling preventative maintenance before disruption occurs.</p><p>The result is improved first-time fix outcomes, increased operational efficiency through greater uptime, and fewer unnecessary on-site visits, allowing engineering resources to be deployed more effectively.</p><p>For partners, this is enabling a shift from interrogating the customer to interrogating the device, ensuring partner-customer relationships are maintained, and ensuring engineers have the time to focus on resolving more complex issues and delivering effective long-term support.</p><h2 id="creating-long-term-value-through-smart-services">Creating long-term value through smart services</h2><p>Across the print channel, value is increasingly being demonstrated through services rather than hardware alone. The strength of a partner relationship is not defined by technology alone, but by the trust and expertise that support it over time. </p><p>As AI moves from experimentation to application, the real opportunity lies in practical deployment. The focus shifts from headline innovation to operational value that helps partners support customers more effectively.</p><p>Smart services are intended to sit within that space. Not as a silver bullet, and not as a standalone answer, but as a structured approach to making device support more intelligent, more connected, and more aligned with how businesses now operate.</p><p>In a market that is becoming more connected and more demanding by default, expanding customer relationships beyond reactive support is central for partners to strengthen long-term customer relationships and create sustainable recurring revenue opportunities through higher-value services.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Off-grid: networks cut the cord ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Businesses of all sizes depend on a mix of technologies to access and move data.</p><p>Wired networks provide the critical data backbones and connections to data centers.</p><p>But more and more enterprise data is carried by alternative networks. Some traffic never even touches the conventional, corporate LAN but goes directly from a mobile user, an IoT device, or a branch office to a cloud provider or a SaaS application. </p><p>Cellular connections through 4G and now 5G routers, and satellite links are already common as backups to fixed lines, for events and emergencies, for hard-to-reach locations, and even for large sites, including warehouses, sports venues and transport hubs.</p><p>But alternative, wide-area network technology is gaining ground for routine use, rather than just edge or temporary use cases.</p><p>Businesses want to make more use of data-rich applications, from video and voice to AI, with high-speed, high-quality connections across their operations.</p><p>Then there is the growing interest in operational resilience. A single network connection is a bottleneck and a potential <a href="https://www.itpro.com/infrastructure/networking/un-b-locking-the-lan"><u>single point of failure</u></a>.</p><p>Increasingly, this means looking at more than one network. And technologies previously viewed as only suitable for edge cases are now moving to the core of the enterprise network.</p><p>“The traffic patterns are becoming very bursty, asymmetric, and highly latency sensitive,” Hardik Ajmera, a vice president at Extreme Networks, told <em>ITPro.</em> It no longer makes sense, he says, to route all network traffic through the corporate office or data center.</p><p>But how do enterprises manage the inevitable complexity this brings?</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/infrastructure/networking/off-grid-networks-cut-the-cord</link>
                                                                            <description>
                            <![CDATA[ Faster, more robust wireless connections offer alternatives to the LAN and public hotspots. But how do IT leaders navigate their way through 5G, 6G, and satellite technology? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iKVdgrrB2Qz5rfuVPkCrDA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/y8aCHjRnG9PbY96LTsUTLW-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Aug 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Networking]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Stephen Pritchard ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/y8aCHjRnG9PbY96LTsUTLW-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Network traffic concept image showing orange-colored flowing data line imposed over a digital interface with binary code.]]></media:description>                                                            <media:text><![CDATA[Network traffic concept image showing orange-colored flowing data line imposed over a digital interface with binary code.]]></media:text>
                                <media:title type="plain"><![CDATA[Network traffic concept image showing orange-colored flowing data line imposed over a digital interface with binary code.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/y8aCHjRnG9PbY96LTsUTLW-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Businesses of all sizes depend on a mix of technologies to access and move data.</p><p>Wired networks provide the critical data backbones and connections to data centers.</p><p>But more and more enterprise data is carried by alternative networks. Some traffic never even touches the conventional, corporate LAN but goes directly from a mobile user, an IoT device, or a branch office to a cloud provider or a SaaS application. </p><p>Cellular connections through 4G and now 5G routers, and satellite links are already common as backups to fixed lines, for events and emergencies, for hard-to-reach locations, and even for large sites, including warehouses, sports venues and transport hubs.</p><p>But alternative, wide-area network technology is gaining ground for routine use, rather than just edge or temporary use cases.</p><p>Businesses want to make more use of data-rich applications, from video and voice to AI, with high-speed, high-quality connections across their operations.</p><p>Then there is the growing interest in operational resilience. A single network connection is a bottleneck and a potential <a href="https://www.itpro.com/infrastructure/networking/un-b-locking-the-lan"><u>single point of failure</u></a>.</p><p>Increasingly, this means looking at more than one network. And technologies previously viewed as only suitable for edge cases are now moving to the core of the enterprise network.</p><p>“The traffic patterns are becoming very bursty, asymmetric, and highly latency sensitive,” Hardik Ajmera, a vice president at Extreme Networks, told <em>ITPro.</em> It no longer makes sense, he says, to route all network traffic through the corporate office or data center.</p><p>But how do enterprises manage the inevitable complexity this brings?</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why resale alone can no longer carry the channel ]]></title>
                                                                                                <dc:content><![CDATA[ <p>For years, much of the relationship was anchored by the renewal itself. Customers turned to partners for help making sense of license positions and vendor terms, and the transaction carried enough margin to support the account work around it.</p><p>With Gartner expecting worldwide IT spending to reach <a href="https://gartner.com/en/newsroom/press-releases/2026-04-22-gartner-forecasts-worldwide-it-spending-to-grow-13-point-5-percent-in-2026-totaling-6-point-31-trillion-dollars"><u>$6.31 trillion</u></a> this year, driven by software and AI infrastructure, the market is still growing around partners. The difficulty is that growth no longer flows through the channel in the same way. </p><p>A license can still open the account. Its value now depends on whether the partner can use that moment to extend their services to support the broader software estate.</p><h2 id="buying-is-moving-around-the-reseller">Buying is moving around the reseller</h2><p>A large part of the traditional reseller model grew around Microsoft licensing and the incentives attached to it. Backend fees historically gave partners dependable income around the customer relationship, often through repeatable work across accounts.</p><p>As those economics have narrowed, customers have gained more ways to buy technology. A reseller may spend months shaping the right solution, then see the purchase move through a marketplace because the customer wants to draw down an existing cloud commitment. The advice remains valuable, even when the transaction lands somewhere else.</p><p>Months of account work can suddenly become detached from the order. Understanding <em>how</em> the customer intends to buy has become just as important as understanding <em>what</em> they intend to buy.</p><p>A renewal now sits on top of a software estate that may have moved faster than the agreement in front of the customer. SaaS spreads through different parts of the business before central teams have a full grip on ownership. Cloud costs shift the economics of tools that once looked predictable. On top of this, AI capabilities are arriving inside the platforms customers use every day.</p><p>By the time the renewal comes around, the agreement today may not show enough about whether spend still accurately reflects how the business operates.</p><h2 id="the-license-should-open-a-wide-view-of-the-estate">The license should open a wide view of the estate</h2><p>To protect the relationship, partners need to turn the renewal into a clearer view of the estate behind it. </p><p>The license position shows what the customer is entitled to use. Usage data shows whether the business still depends on it. The gap between those two things often reveals important opportunities for optimization, cost control, and better decision-making.</p><p>Partners with Software Asset Management (SAM) and IT Asset Management (ITAM) expertise already have much of that capability. They understand how quickly entitlement can drift away from real use, especially when software is purchased centrally and then adopted unevenly across the organization. Turning that knowledge into a managed service gives customers a clearer view before the renewal deadline forces a decision.</p><p>SaaS management builds naturally from there. Applications can spread through teams long before central IT has a clean view of ownership or spend. A partner that can show which tools are active and which contracts no longer reflect use is helping the customer make a better renewal decision.</p><p>AI adds the same pressure in a newer form. Capabilities are being added into platforms customers already run, so the cost can build inside familiar contracts before the business has worked out where the value sits. Connecting that spend back to usage gives partners a stronger role than simply helping the customer process the next agreement.</p><p><a href="https://info.flexera.com/CM-REPORT-State-of-the-Cloud?utm_source=google&utm_medium=paid&utm_campaign=FinOps&lead_source=Paid%20Search%20-%20Google&utm_term=state%20of%20cloud%20report&gad_source=1&gad_campaignid=23424317466&gbraid=0AAAAAD4zmUDSGytA1-b66EePBPqOKUSHM&gclid=CjwKCAjw3ejRBhAdEiwADkqPn12MdLlCHAZ36MVnwhMcv8HAur5XdlT9i-zP3fmtIoqakrJ56f9ioBoCnywQAvD_BwE"><u>Our 2026 State of the Cloud report</u></a> findings suggest the services market is already moving this way, with nearly half of Managed Service Providers (MSPs) planning to offer AI consulting and SaaS management services. Enterprise use of MSPs has also risen year on year, which points to larger organizations looking for specialist help as their estates become harder to manage.</p><h2 id="margin-must-come-from-the-services-around-the-license">Margin must come from the services around the license</h2><p>Partners that stay closest to the customer will be the ones that make the estate clearer between renewals. The license gives them a route into that work, then the service relationship has to carry it forward.</p><p>Account teams need enough visibility into usage and consumption to challenge assumptions before procurement turns the renewal into a price negotiation. Sales teams also need to be measured on the service opportunities created around the license, not only on the order itself.</p><p>Resale remains a key part of the channel, and the license still opens the door. More of the margin now comes from helping customers understand the full technology estate behind it. Understanding what they own, what they use, where costs are increasing, and where technology investments are delivering value. </p><p>In that environment, the most successful partners will be defined by the insight they provide and the outcomes they help customers achieve.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/business/business-strategy/why-resale-alone-can-no-longer-carry-the-channel</link>
                                                                            <description>
                            <![CDATA[ Resale alone no longer sustains partner growth in today's software market ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dihThi94iQaEpV88F8TZY6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/FfHaUTBh9cmW8xYS926Pp-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Aug 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Business Strategy]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Guy McWilliam ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GA8kWygdpAEeLmmV9SKsqS-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/FfHaUTBh9cmW8xYS926Pp-1920-80.jpg">
                                                            <media:credit><![CDATA[champpixs / Getty Images ]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Businessman Sign Terms of use concept, reading terms and conditions of website or service before clicking button agree]]></media:description>                                                            <media:text><![CDATA[Businessman Sign Terms of use concept, reading terms and conditions of website or service before clicking button agree]]></media:text>
                                <media:title type="plain"><![CDATA[Businessman Sign Terms of use concept, reading terms and conditions of website or service before clicking button agree]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/FfHaUTBh9cmW8xYS926Pp-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>For years, much of the relationship was anchored by the renewal itself. Customers turned to partners for help making sense of license positions and vendor terms, and the transaction carried enough margin to support the account work around it.</p><p>With Gartner expecting worldwide IT spending to reach <a href="https://gartner.com/en/newsroom/press-releases/2026-04-22-gartner-forecasts-worldwide-it-spending-to-grow-13-point-5-percent-in-2026-totaling-6-point-31-trillion-dollars"><u>$6.31 trillion</u></a> this year, driven by software and AI infrastructure, the market is still growing around partners. The difficulty is that growth no longer flows through the channel in the same way. </p><p>A license can still open the account. Its value now depends on whether the partner can use that moment to extend their services to support the broader software estate.</p><h2 id="buying-is-moving-around-the-reseller">Buying is moving around the reseller</h2><p>A large part of the traditional reseller model grew around Microsoft licensing and the incentives attached to it. Backend fees historically gave partners dependable income around the customer relationship, often through repeatable work across accounts.</p><p>As those economics have narrowed, customers have gained more ways to buy technology. A reseller may spend months shaping the right solution, then see the purchase move through a marketplace because the customer wants to draw down an existing cloud commitment. The advice remains valuable, even when the transaction lands somewhere else.</p><p>Months of account work can suddenly become detached from the order. Understanding <em>how</em> the customer intends to buy has become just as important as understanding <em>what</em> they intend to buy.</p><p>A renewal now sits on top of a software estate that may have moved faster than the agreement in front of the customer. SaaS spreads through different parts of the business before central teams have a full grip on ownership. Cloud costs shift the economics of tools that once looked predictable. On top of this, AI capabilities are arriving inside the platforms customers use every day.</p><p>By the time the renewal comes around, the agreement today may not show enough about whether spend still accurately reflects how the business operates.</p><h2 id="the-license-should-open-a-wide-view-of-the-estate">The license should open a wide view of the estate</h2><p>To protect the relationship, partners need to turn the renewal into a clearer view of the estate behind it. </p><p>The license position shows what the customer is entitled to use. Usage data shows whether the business still depends on it. The gap between those two things often reveals important opportunities for optimization, cost control, and better decision-making.</p><p>Partners with Software Asset Management (SAM) and IT Asset Management (ITAM) expertise already have much of that capability. They understand how quickly entitlement can drift away from real use, especially when software is purchased centrally and then adopted unevenly across the organization. Turning that knowledge into a managed service gives customers a clearer view before the renewal deadline forces a decision.</p><p>SaaS management builds naturally from there. Applications can spread through teams long before central IT has a clean view of ownership or spend. A partner that can show which tools are active and which contracts no longer reflect use is helping the customer make a better renewal decision.</p><p>AI adds the same pressure in a newer form. Capabilities are being added into platforms customers already run, so the cost can build inside familiar contracts before the business has worked out where the value sits. Connecting that spend back to usage gives partners a stronger role than simply helping the customer process the next agreement.</p><p><a href="https://info.flexera.com/CM-REPORT-State-of-the-Cloud?utm_source=google&utm_medium=paid&utm_campaign=FinOps&lead_source=Paid%20Search%20-%20Google&utm_term=state%20of%20cloud%20report&gad_source=1&gad_campaignid=23424317466&gbraid=0AAAAAD4zmUDSGytA1-b66EePBPqOKUSHM&gclid=CjwKCAjw3ejRBhAdEiwADkqPn12MdLlCHAZ36MVnwhMcv8HAur5XdlT9i-zP3fmtIoqakrJ56f9ioBoCnywQAvD_BwE"><u>Our 2026 State of the Cloud report</u></a> findings suggest the services market is already moving this way, with nearly half of Managed Service Providers (MSPs) planning to offer AI consulting and SaaS management services. Enterprise use of MSPs has also risen year on year, which points to larger organizations looking for specialist help as their estates become harder to manage.</p><h2 id="margin-must-come-from-the-services-around-the-license">Margin must come from the services around the license</h2><p>Partners that stay closest to the customer will be the ones that make the estate clearer between renewals. The license gives them a route into that work, then the service relationship has to carry it forward.</p><p>Account teams need enough visibility into usage and consumption to challenge assumptions before procurement turns the renewal into a price negotiation. Sales teams also need to be measured on the service opportunities created around the license, not only on the order itself.</p><p>Resale remains a key part of the channel, and the license still opens the door. More of the margin now comes from helping customers understand the full technology estate behind it. Understanding what they own, what they use, where costs are increasing, and where technology investments are delivering value. </p><p>In that environment, the most successful partners will be defined by the insight they provide and the outcomes they help customers achieve.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The CISO now owns physical security. Here’s what that means for the channel ]]></title>
                                                                                                <dc:content><![CDATA[ <p>For years, selling physical security meant knowing one buyer. The director of physical security, or facilities, signed off on cameras, locks, and badge readers, and the conversation rarely left that room. That buyer is being moved aside.</p><p>Physical security budgets are rising sharply. EY research found that <a href="https://www.facilitiesdive.com/news/more-money-is-going-to-physical-security-but-its-often-cisos-that-overse/820077/"><u>nearly 80% of organizations</u></a> increased spending in the last budget cycle, and more than a quarter have now shifted oversight to the CISO, a role built for network defense, not card readers and lockdown logic. The money is growing, and the person controlling it has changed. For Value-Added-Resellers (VARs), Managed Service Providers (MSPs) and integrators, that is the most important shift in this market, and the partners who haven’t adjusted their go-to-market are still pitching buyers who no longer control the budget.</p><p>Here is what that looks like on the ground. A reseller who used to walk in with a door schedule now sits across from a CISO who wants to see NIST CSF mappings. An integrator arrives for a campus deployment and finds the cybersecurity team holds policy authority over systems they have never seen up close. Deals that should close stall, because no one in the room feels accountable for a physical incident. The handoff is happening faster than buying committees are used to.</p><p>Four things will determine which partners own this shift - and which get left behind.</p><h2 id="who-actually-owns-the-budget-now">Who actually owns the budget now?</h2><p>Map the buying committee before you pitch anything. In most organizations going through this shift, the CISO owns the budget and the risk, but the physical security or facilities lead still owns day-to-day operations. Both are in the room. </p><p>If you assume the old buyer is still in charge, you will lose to a competitor who figured out the money moved. Your first job on any new opportunity is to establish who signs, who operates, and who is accountable when something goes wrong. In a convergence deal, those are often three different stakeholders.</p><h2 id="how-do-you-earn-credibility-with-a-ciso-who-has-never-run-a-physical-system">How do you earn credibility with a CISO who has never run a physical system?</h2><p>Learn their language. A CISO does not think in door schedules and panel counts; they think in frameworks, risk, and auditability. When you can map a physical access control deployment to NIST CSF, explain how it changes their attack surface, and show how you would prove it works under audit, you stop being a hardware vendor and become someone they can defend a budget line to.</p><p>The mistake we see most often is the reverse: walking a CISO through the technical detail of the physical install. That buyer does not want the schematic. They want to know what risk you remove, what you can attest to, and what happens when something is compromised. Translate physical implementation into security outcomes, and you will be in conversations your competitors never reach.</p><h2 id="where-can-partners-attach-services">Where can partners attach services?</h2><p>The opportunity sits in the gap nobody owns: the space between IT policy and physical implementation.</p><p>In the deployments we work on at Acre, that gap is almost always wider than the organization expects. The CISO sets policy, the facilities team runs the hardware, but almost no one owns the interface between them- the integration that decides what the physical system does when the identity provider is compromised, or what happens to a badge when a credential is exposed. </p><p>That is billable work, and it recurs: assessments that map physical controls to the security framework, integration between access control and identity systems, and managed services that keep the two estates talking and produce the evidence an auditor will ask for. This is where partners move from one-time installers to retained advisors, which is the more durable revenue anyway.</p><h2 id="how-do-you-structure-the-sale-when-the-buying-committee-has-changed">How do you structure the sale when the buying committee has changed?</h2><p>Sell to the committee, not the individual. The deals that stall are the ones pitched to one stakeholder while another quietly holds a veto. Get the CISO, the physical security lead, and, often, IT into the same conversation early, and make accountability explicit. </p><p>Who owns a physical breach? Who owns a credential compromise that has physical consequences? When you name those owners in the room, you remove the ambiguity that kills deals, and you position yourself as the partner who understands the new org chart rather than the one still selling to the old one.</p><p>None of this requires the channel to become a cybersecurity practice overnight. It requires recognizing that the buyer has changed, learning enough of the CISO’s language to be credible, and building services around the integration gap the convergence created. </p><p>The partners who make that shift will own the relationship as physical and digital security keep merging. The ones who don’t will keep pitching to a room that’s already moved on.</p><p>The budgets are there. The question is: Are your conversations reaching the people who control that money?</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/the-ciso-now-owns-physical-security-heres-what-that-means-for-the-channel</link>
                                                                            <description>
                            <![CDATA[ Physical security budgets have moved to CISOs, and partners must adapt to this important shift ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">BnxYQKT4SpVNPTVCqCmzYG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tgkJFyUdDXpZ6K4JudVfCE-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 19 Aug 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kumar Sokka ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/rogaiTcHwVmqEPQqMSJ5m6-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tgkJFyUdDXpZ6K4JudVfCE-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A CGI image of a padlock on a blue background, with glowing data points on top of it to represent cybersecurity.]]></media:description>                                                            <media:text><![CDATA[A CGI image of a padlock on a blue background, with glowing data points on top of it to represent cybersecurity.]]></media:text>
                                <media:title type="plain"><![CDATA[A CGI image of a padlock on a blue background, with glowing data points on top of it to represent cybersecurity.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tgkJFyUdDXpZ6K4JudVfCE-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>For years, selling physical security meant knowing one buyer. The director of physical security, or facilities, signed off on cameras, locks, and badge readers, and the conversation rarely left that room. That buyer is being moved aside.</p><p>Physical security budgets are rising sharply. EY research found that <a href="https://www.facilitiesdive.com/news/more-money-is-going-to-physical-security-but-its-often-cisos-that-overse/820077/"><u>nearly 80% of organizations</u></a> increased spending in the last budget cycle, and more than a quarter have now shifted oversight to the CISO, a role built for network defense, not card readers and lockdown logic. The money is growing, and the person controlling it has changed. For Value-Added-Resellers (VARs), Managed Service Providers (MSPs) and integrators, that is the most important shift in this market, and the partners who haven’t adjusted their go-to-market are still pitching buyers who no longer control the budget.</p><p>Here is what that looks like on the ground. A reseller who used to walk in with a door schedule now sits across from a CISO who wants to see NIST CSF mappings. An integrator arrives for a campus deployment and finds the cybersecurity team holds policy authority over systems they have never seen up close. Deals that should close stall, because no one in the room feels accountable for a physical incident. The handoff is happening faster than buying committees are used to.</p><p>Four things will determine which partners own this shift - and which get left behind.</p><h2 id="who-actually-owns-the-budget-now">Who actually owns the budget now?</h2><p>Map the buying committee before you pitch anything. In most organizations going through this shift, the CISO owns the budget and the risk, but the physical security or facilities lead still owns day-to-day operations. Both are in the room. </p><p>If you assume the old buyer is still in charge, you will lose to a competitor who figured out the money moved. Your first job on any new opportunity is to establish who signs, who operates, and who is accountable when something goes wrong. In a convergence deal, those are often three different stakeholders.</p><h2 id="how-do-you-earn-credibility-with-a-ciso-who-has-never-run-a-physical-system">How do you earn credibility with a CISO who has never run a physical system?</h2><p>Learn their language. A CISO does not think in door schedules and panel counts; they think in frameworks, risk, and auditability. When you can map a physical access control deployment to NIST CSF, explain how it changes their attack surface, and show how you would prove it works under audit, you stop being a hardware vendor and become someone they can defend a budget line to.</p><p>The mistake we see most often is the reverse: walking a CISO through the technical detail of the physical install. That buyer does not want the schematic. They want to know what risk you remove, what you can attest to, and what happens when something is compromised. Translate physical implementation into security outcomes, and you will be in conversations your competitors never reach.</p><h2 id="where-can-partners-attach-services">Where can partners attach services?</h2><p>The opportunity sits in the gap nobody owns: the space between IT policy and physical implementation.</p><p>In the deployments we work on at Acre, that gap is almost always wider than the organization expects. The CISO sets policy, the facilities team runs the hardware, but almost no one owns the interface between them- the integration that decides what the physical system does when the identity provider is compromised, or what happens to a badge when a credential is exposed. </p><p>That is billable work, and it recurs: assessments that map physical controls to the security framework, integration between access control and identity systems, and managed services that keep the two estates talking and produce the evidence an auditor will ask for. This is where partners move from one-time installers to retained advisors, which is the more durable revenue anyway.</p><h2 id="how-do-you-structure-the-sale-when-the-buying-committee-has-changed">How do you structure the sale when the buying committee has changed?</h2><p>Sell to the committee, not the individual. The deals that stall are the ones pitched to one stakeholder while another quietly holds a veto. Get the CISO, the physical security lead, and, often, IT into the same conversation early, and make accountability explicit. </p><p>Who owns a physical breach? Who owns a credential compromise that has physical consequences? When you name those owners in the room, you remove the ambiguity that kills deals, and you position yourself as the partner who understands the new org chart rather than the one still selling to the old one.</p><p>None of this requires the channel to become a cybersecurity practice overnight. It requires recognizing that the buyer has changed, learning enough of the CISO’s language to be credible, and building services around the integration gap the convergence created. </p><p>The partners who make that shift will own the relationship as physical and digital security keep merging. The ones who don’t will keep pitching to a room that’s already moved on.</p><p>The budgets are there. The question is: Are your conversations reaching the people who control that money?</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is AI insurance? ]]></title>
                                                                                                <dc:content><![CDATA[ <p>AI Insurance, also known as affirmative AI insurance, has been developed to specifically address the risks associated with the use and performance of AI technologies and systems, and covers liabilities that are excluded from existing business policies such as general liability, directors and officers, errors and omissions, and cyber insurance.</p><p>“Many of the existing policies companies have in place have AI exclusions,” highlights Lauren Kornutick, senior director analyst, Analytics and AI at Gartner. </p><p>“As AI is used more, and in more strategic and high-stakes use cases, new risks are being introduced. This is a gap in the existing risk management approach that could result in large-scale financial penalties, which could be detrimental.” </p><h2 id="what-does-ai-insurance-cover">What does AI insurance cover?</h2><p>AI insurance can cover a wide range of risks. On the errors and misinformation side, this can include financial losses stemming from AI hallucinations, such as a chatbot dispensing bad advice, or flawed decision-making. </p><p>It can also extend to algorithmic bias and discrimination, picking up legal defense costs and settlements when an AI model inadvertently disadvantages a group in contexts like hiring or lending. </p><p>IP and copyright exposure is another area of coverage, protecting businesses against claims that an AI model was trained on, or generated, copyrighted material without permission.</p><p>Then there’s performance guarantees, which are leading to warranty-style offerings that will refund license fees or cover associated costs if a model fails to hit specific benchmarks like accuracy or fairness. At the more severe end of the risk spectrum, AI insurance can cover large-scale physical damage or property loss resulting from poor AI-generated advice, device hacking, system failures, or harmful actions taken by AI agents.</p><h2 id="why-should-it-leaders-take-notice">Why should IT leaders take notice?</h2><p>AI insurance is still a nascent market, highlights Tomas Novosad, technology analyst and founder of Full Fibre Checker, and one that’s currently a collection of discrete coverage options – standalone, endorsement and exclusionary – instead of a single type of insurance category. </p><p>But while IT leaders may consider AI insurance a matter for the legal or finance departments to attend to, the reality is that AI risk is increasingly becoming an operational responsibility for IT teams.</p><p>“[This is because] once AI is embedded into core systems, accountability sits within the technology stack and the processes that support it,” explains Indranil Roy, managing partner and global head, Industry Solutions Group at IT solutions and consultancy firm Mphasis.</p><p>“In practice, IT teams are already seeing issues such as inconsistent AI-driven decisions across different channels, or difficulty tracing how an output was produced once it passes through multiple legacy and cloud-based systems.”</p><p>For IT leaders, he continues, the key issue isn’t the policy itself, but whether the organization can evidence how AI-driven decisions are made, logged and explained in live production environments, not just in design documentation. If something goes wrong, it’s the system design, data flows, and governance controls that determine whether the issue can be traced, identified, and resolved. </p><p>“This is why AI insurance is becoming directly relevant to enterprise IT governance, because it increasingly reflects how well organizations can operationalize control, not just define it,” Roy states. </p><h2 id="the-growing-importance-of-ai-governance">The growing importance of AI governance </h2><p>To underwrite such policies, insurers must have stringent procedures to evaluate the AI capabilities and risks of those companies seeking to buy insurance, and Gartner predicts that by 2030, they will mandate strong AI risk controls as a condition of coverage.</p><p>We’re already seeing movement in this direction, reflected in more detailed underwriter questions, AI exclusions, and dedicated limits for AI risks. “In financial services, regulators are already requiring explainability and bias audits for AI-driven decisions,” notes Pragati Awasthi, assistant teaching professor at Drexel University’s School of Computer and Information Sciences.</p><p>“Insurers will follow the same logic: if they can’t assess the risk, they won’t cover it.”</p><p>Insurers will look for ways that deployers of AI are addressing the operational complexity of AI governance and not just rely on dated and static governance, risk, and compliance (GRC) controls, notes Kornutick, adding that Gartner recommends IT leaders deploy a hybrid approach consisting of centralized and decentralized policy, team, and system as a complete piece. </p><p>“This includes layered (enterprise and department level) policies and rules, clearly designated responsible teams who deeply understand the application’s operation, and adopting hybrid technical platforms, such as an enterprise-level AI governance platform (AIGP) paired with decentralized, application-specific guardrails,” she says. </p><p>One key factor to consider is whether organizations are deploying AIGPs as part of their governance architecture, she adds. According to Gartner’s 2025 State of AI-Ready Data Survey, organizations that do are three times more likely to achieve ‘high effectiveness’ in their AI governance practices than those that don’t, with 42% of organizations effective in AI governance having already deployed AIGPs. </p><p>“The organizations building governance infrastructure now will have a meaningful competitive advantage in insurability by 2030. The ones waiting will face either exclusions or prohibitive premiums,” Awasthi warns. </p><h2 id="practical-steps-it-leaders-can-take-today">Practical steps IT leaders can take today </h2><p>For those organizations just getting started, Awasthi recommends three priorities. Firstly, build a model register. Know every AI system you're running, what decisions they influence, and who owns them. Secondly, implement logging for automated decisions so you have an audit trail if something goes wrong. Finally, run a bias and drift assessment on any model touching customers or employees.</p><p>"Underwriters are increasingly looking for documented model inventories, human-in-the-loop checkpoints for high-stakes decisions, monitoring for model drift and bias post-deployment, and a clear incident response plan specific to AI failures. Governance that exists on paper but isn't operationalized won't satisfy a serious underwriter."</p><p>As with every technology before it, AI will continue to bring new risks, and those who get ahead of them now will be far better placed than those who wait for something to go wrong. </p><p>With 2030 fast approaching and underwriter requirements only tightening, the window for IT leaders to get ahead of this is narrowing. With this in mind, there’s no better time to build the necessary foundations.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/technology/artificial-intelligence/what-is-ai-insurance</link>
                                                                            <description>
                            <![CDATA[ The introduction of any new technology brings new risks, and AI's rapid expansion into the workplace is no exception. In response, a distinct category of insurance coverage has emerged ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nnTmEHLFTFX9qmdEwKnet8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QhyEKLgYPZws4pjh7QMRZB-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 19 Aug 2026 07:00:00 +0000</pubDate>                                                                                                                                <updated>Wed, 19 Aug 2026 10:39:51 +0000</updated>
                                                                                                                                            <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keri Allan ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/oJZkdPii464j27ff4GCcoT-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QhyEKLgYPZws4pjh7QMRZB-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images / HOLTICHA KRANJUMNONG]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Insurance policy document concept, Businesswomen checklist insurance document online]]></media:description>                                                            <media:text><![CDATA[Insurance policy document concept, Businesswomen checklist insurance document online]]></media:text>
                                <media:title type="plain"><![CDATA[Insurance policy document concept, Businesswomen checklist insurance document online]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QhyEKLgYPZws4pjh7QMRZB-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>AI Insurance, also known as affirmative AI insurance, has been developed to specifically address the risks associated with the use and performance of AI technologies and systems, and covers liabilities that are excluded from existing business policies such as general liability, directors and officers, errors and omissions, and cyber insurance.</p><p>“Many of the existing policies companies have in place have AI exclusions,” highlights Lauren Kornutick, senior director analyst, Analytics and AI at Gartner. </p><p>“As AI is used more, and in more strategic and high-stakes use cases, new risks are being introduced. This is a gap in the existing risk management approach that could result in large-scale financial penalties, which could be detrimental.” </p><h2 id="what-does-ai-insurance-cover">What does AI insurance cover?</h2><p>AI insurance can cover a wide range of risks. On the errors and misinformation side, this can include financial losses stemming from AI hallucinations, such as a chatbot dispensing bad advice, or flawed decision-making. </p><p>It can also extend to algorithmic bias and discrimination, picking up legal defense costs and settlements when an AI model inadvertently disadvantages a group in contexts like hiring or lending. </p><p>IP and copyright exposure is another area of coverage, protecting businesses against claims that an AI model was trained on, or generated, copyrighted material without permission.</p><p>Then there’s performance guarantees, which are leading to warranty-style offerings that will refund license fees or cover associated costs if a model fails to hit specific benchmarks like accuracy or fairness. At the more severe end of the risk spectrum, AI insurance can cover large-scale physical damage or property loss resulting from poor AI-generated advice, device hacking, system failures, or harmful actions taken by AI agents.</p><h2 id="why-should-it-leaders-take-notice">Why should IT leaders take notice?</h2><p>AI insurance is still a nascent market, highlights Tomas Novosad, technology analyst and founder of Full Fibre Checker, and one that’s currently a collection of discrete coverage options – standalone, endorsement and exclusionary – instead of a single type of insurance category. </p><p>But while IT leaders may consider AI insurance a matter for the legal or finance departments to attend to, the reality is that AI risk is increasingly becoming an operational responsibility for IT teams.</p><p>“[This is because] once AI is embedded into core systems, accountability sits within the technology stack and the processes that support it,” explains Indranil Roy, managing partner and global head, Industry Solutions Group at IT solutions and consultancy firm Mphasis.</p><p>“In practice, IT teams are already seeing issues such as inconsistent AI-driven decisions across different channels, or difficulty tracing how an output was produced once it passes through multiple legacy and cloud-based systems.”</p><p>For IT leaders, he continues, the key issue isn’t the policy itself, but whether the organization can evidence how AI-driven decisions are made, logged and explained in live production environments, not just in design documentation. If something goes wrong, it’s the system design, data flows, and governance controls that determine whether the issue can be traced, identified, and resolved. </p><p>“This is why AI insurance is becoming directly relevant to enterprise IT governance, because it increasingly reflects how well organizations can operationalize control, not just define it,” Roy states. </p><h2 id="the-growing-importance-of-ai-governance">The growing importance of AI governance </h2><p>To underwrite such policies, insurers must have stringent procedures to evaluate the AI capabilities and risks of those companies seeking to buy insurance, and Gartner predicts that by 2030, they will mandate strong AI risk controls as a condition of coverage.</p><p>We’re already seeing movement in this direction, reflected in more detailed underwriter questions, AI exclusions, and dedicated limits for AI risks. “In financial services, regulators are already requiring explainability and bias audits for AI-driven decisions,” notes Pragati Awasthi, assistant teaching professor at Drexel University’s School of Computer and Information Sciences.</p><p>“Insurers will follow the same logic: if they can’t assess the risk, they won’t cover it.”</p><p>Insurers will look for ways that deployers of AI are addressing the operational complexity of AI governance and not just rely on dated and static governance, risk, and compliance (GRC) controls, notes Kornutick, adding that Gartner recommends IT leaders deploy a hybrid approach consisting of centralized and decentralized policy, team, and system as a complete piece. </p><p>“This includes layered (enterprise and department level) policies and rules, clearly designated responsible teams who deeply understand the application’s operation, and adopting hybrid technical platforms, such as an enterprise-level AI governance platform (AIGP) paired with decentralized, application-specific guardrails,” she says. </p><p>One key factor to consider is whether organizations are deploying AIGPs as part of their governance architecture, she adds. According to Gartner’s 2025 State of AI-Ready Data Survey, organizations that do are three times more likely to achieve ‘high effectiveness’ in their AI governance practices than those that don’t, with 42% of organizations effective in AI governance having already deployed AIGPs. </p><p>“The organizations building governance infrastructure now will have a meaningful competitive advantage in insurability by 2030. The ones waiting will face either exclusions or prohibitive premiums,” Awasthi warns. </p><h2 id="practical-steps-it-leaders-can-take-today">Practical steps IT leaders can take today </h2><p>For those organizations just getting started, Awasthi recommends three priorities. Firstly, build a model register. Know every AI system you're running, what decisions they influence, and who owns them. Secondly, implement logging for automated decisions so you have an audit trail if something goes wrong. Finally, run a bias and drift assessment on any model touching customers or employees.</p><p>"Underwriters are increasingly looking for documented model inventories, human-in-the-loop checkpoints for high-stakes decisions, monitoring for model drift and bias post-deployment, and a clear incident response plan specific to AI failures. Governance that exists on paper but isn't operationalized won't satisfy a serious underwriter."</p><p>As with every technology before it, AI will continue to bring new risks, and those who get ahead of them now will be far better placed than those who wait for something to go wrong. </p><p>With 2030 fast approaching and underwriter requirements only tightening, the window for IT leaders to get ahead of this is narrowing. With this in mind, there’s no better time to build the necessary foundations.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why software supply chain security is the next accountability challenge for channel partners ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Modern applications rely heavily on open-source packages and third-party dependencies, meaning almost every application organizations run is built on layers of code written by people outside the organization. </p><p>Channel partners are often responsible for recommending, integrating and managing these environments. As a result, when a dependency is compromised, accountability increasingly lands with the partner managing the stack.</p><h2 id="why-vulnerable-and-malicious-packages-remain-in-production">Why vulnerable and malicious packages remain in production</h2><p>Unfortunately, public disclosure does not equal remediation. Organizations continue running outdated or vulnerable dependencies months after Common Vulnerabilities and Exposures (CVEs) become public, and this is increasingly becoming the norm. <a href="https://www.nist.gov/news-events/news/2026/04/nist-updates-nvd-operations-address-record-cve-growth"><u>CVE volume has grown</u></a> by 263% since 2020, with 2026 already seeing a further 33% increase. At this pace, security teams are struggling to digest the volume of vulnerabilities, let alone prioritise and implement effective remediation plans. </p><p>Many Managed Service Providers (MSPs) and consultancies also inherit environments they didn't originally architect. Combined with security frameworks that were designed around infrastructure and endpoints rather than continuously evolving software dependencies, the challenge becomes even greater. Moreover, the growing use of AI-assisted development is adding another layer of complexity, accelerating software creation while increasing the volume of third-party code and dependencies entering production. </p><p>Modern applications can contain hundreds of transitive dependencies, making it difficult to maintain an accurate inventory of what's actually running in production. Limited adoption of Software Bills of Materials (SBOMs), alongside the challenge of auditing applications thoroughly, only compounds the problem. Meanwhile, CVE severity scores don't always reflect real-world exploitability, making triage more difficult and further delaying remediation.</p><h2 id="how-supply-chain-attacks-are-changing-the-threat-model">How supply chain attacks are changing the threat model</h2><p>A single compromised dependency can now create risk across multiple customer environments simultaneously and at speed. Attackers are increasingly targeting shared development tooling and open-source repositories, exploiting assumptions around shared responsibility and the belief that someone else is managing the risk.</p><p>Traditional perimeter-based security was never designed for trusted software components becoming the attack vector. Increasingly, nation-state actors and organized cybercriminal groups are targeting open-source maintainers directly, recognising that compromising a widely used dependency offers far greater scale than attacking individual endpoints.</p><p>Because these attacks are delivered through trusted, signed software components, they can bypass many traditional detection controls. In many cases, organizations receive few, if any, alerts, leaving security teams unaware until the compromise has already spread.</p><h2 id="new-expectations">New expectations</h2><p>Clients increasingly expect partners to explain software supply chain risk in business terms, marking a shift from reactive remediation to demonstrable governance. Visibility, software inventories, and continuous monitoring are quickly becoming baseline expectations rather than value-added services.</p><p>Cyber insurance underwriters are also asking for evidence of SBOM practices and software inventory controls. Partners who cannot demonstrate these capabilities risk creating challenges for clients during policy renewals, which can ultimately affect the services they are trusted to deliver. At the same time, legal and procurement teams are beginning to include software supply chain requirements in vendor contracts, meaning partners need to be prepared for increasingly detailed conversations.</p><p>For partners, this represents more than another security challenge. Clients increasingly need help understanding software supply chain risk, interpreting SBOMs, assessing third-party dependencies, and embedding these practices into procurement and governance. Those who can provide this expertise move from being technology providers to trusted advisors. </p><h2 id="the-responsibility-and-accountability-expansion">The responsibility and accountability expansion</h2><p>Software supply chain security is becoming a defining issue for partners operating across cloud and DevSecOps environments. As responsibility for managing modern development environments expands, so too does accountability when something goes wrong. To retain client trust, partners must move beyond fragmented tooling and demonstrate a clear, structured approach to managing software supply chain risk at scale.</p><p>Partners that get ahead of this have an opportunity to differentiate themselves. Rather than viewing software supply chain security as another compliance exercise, they can provide credible answers to the questions clients and their boards are already asking.</p><p>The conversation is also changing commercially. It has shifted from the value proposition of fixing vulnerabilities after the event to providing continuous assurance. For partners, that's an opportunity to deepen customer relationships while developing new security services that generate recurring revenue. </p><p>Within boardrooms, conversations are increasingly focused on who owns software supply chain risk, what impact it could have on the business, and what the financial implications might be. </p><p>Partners that cannot answer those questions risk losing credibility and, ultimately, customer relationships. Partners that can answer those questions with a proven strategy are much more likely to have stronger client adoption, expanded revenue opportunity, and longer-lasting relationships.  </p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/why-software-supply-chain-security-is-the-next-accountability-challenge-for-channel-partners</link>
                                                                            <description>
                            <![CDATA[ Partners need to be able to confidently answer key client questions relating to supply chain security going forward... ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">CExBMbRkEmJqrFm3PzvZhb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Hr8Z3QGRRnSdJ7oqmTW3V6-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Aug 2026 16:56:40 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Amir Akhtar ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Ztwq8hts48LYRZxB6r87cW-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Hr8Z3QGRRnSdJ7oqmTW3V6-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Digital chain link hologram on future tech background.]]></media:description>                                                            <media:text><![CDATA[Digital chain link hologram on future tech background.]]></media:text>
                                <media:title type="plain"><![CDATA[Digital chain link hologram on future tech background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Hr8Z3QGRRnSdJ7oqmTW3V6-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Modern applications rely heavily on open-source packages and third-party dependencies, meaning almost every application organizations run is built on layers of code written by people outside the organization. </p><p>Channel partners are often responsible for recommending, integrating and managing these environments. As a result, when a dependency is compromised, accountability increasingly lands with the partner managing the stack.</p><h2 id="why-vulnerable-and-malicious-packages-remain-in-production">Why vulnerable and malicious packages remain in production</h2><p>Unfortunately, public disclosure does not equal remediation. Organizations continue running outdated or vulnerable dependencies months after Common Vulnerabilities and Exposures (CVEs) become public, and this is increasingly becoming the norm. <a href="https://www.nist.gov/news-events/news/2026/04/nist-updates-nvd-operations-address-record-cve-growth"><u>CVE volume has grown</u></a> by 263% since 2020, with 2026 already seeing a further 33% increase. At this pace, security teams are struggling to digest the volume of vulnerabilities, let alone prioritise and implement effective remediation plans. </p><p>Many Managed Service Providers (MSPs) and consultancies also inherit environments they didn't originally architect. Combined with security frameworks that were designed around infrastructure and endpoints rather than continuously evolving software dependencies, the challenge becomes even greater. Moreover, the growing use of AI-assisted development is adding another layer of complexity, accelerating software creation while increasing the volume of third-party code and dependencies entering production. </p><p>Modern applications can contain hundreds of transitive dependencies, making it difficult to maintain an accurate inventory of what's actually running in production. Limited adoption of Software Bills of Materials (SBOMs), alongside the challenge of auditing applications thoroughly, only compounds the problem. Meanwhile, CVE severity scores don't always reflect real-world exploitability, making triage more difficult and further delaying remediation.</p><h2 id="how-supply-chain-attacks-are-changing-the-threat-model">How supply chain attacks are changing the threat model</h2><p>A single compromised dependency can now create risk across multiple customer environments simultaneously and at speed. Attackers are increasingly targeting shared development tooling and open-source repositories, exploiting assumptions around shared responsibility and the belief that someone else is managing the risk.</p><p>Traditional perimeter-based security was never designed for trusted software components becoming the attack vector. Increasingly, nation-state actors and organized cybercriminal groups are targeting open-source maintainers directly, recognising that compromising a widely used dependency offers far greater scale than attacking individual endpoints.</p><p>Because these attacks are delivered through trusted, signed software components, they can bypass many traditional detection controls. In many cases, organizations receive few, if any, alerts, leaving security teams unaware until the compromise has already spread.</p><h2 id="new-expectations">New expectations</h2><p>Clients increasingly expect partners to explain software supply chain risk in business terms, marking a shift from reactive remediation to demonstrable governance. Visibility, software inventories, and continuous monitoring are quickly becoming baseline expectations rather than value-added services.</p><p>Cyber insurance underwriters are also asking for evidence of SBOM practices and software inventory controls. Partners who cannot demonstrate these capabilities risk creating challenges for clients during policy renewals, which can ultimately affect the services they are trusted to deliver. At the same time, legal and procurement teams are beginning to include software supply chain requirements in vendor contracts, meaning partners need to be prepared for increasingly detailed conversations.</p><p>For partners, this represents more than another security challenge. Clients increasingly need help understanding software supply chain risk, interpreting SBOMs, assessing third-party dependencies, and embedding these practices into procurement and governance. Those who can provide this expertise move from being technology providers to trusted advisors. </p><h2 id="the-responsibility-and-accountability-expansion">The responsibility and accountability expansion</h2><p>Software supply chain security is becoming a defining issue for partners operating across cloud and DevSecOps environments. As responsibility for managing modern development environments expands, so too does accountability when something goes wrong. To retain client trust, partners must move beyond fragmented tooling and demonstrate a clear, structured approach to managing software supply chain risk at scale.</p><p>Partners that get ahead of this have an opportunity to differentiate themselves. Rather than viewing software supply chain security as another compliance exercise, they can provide credible answers to the questions clients and their boards are already asking.</p><p>The conversation is also changing commercially. It has shifted from the value proposition of fixing vulnerabilities after the event to providing continuous assurance. For partners, that's an opportunity to deepen customer relationships while developing new security services that generate recurring revenue. </p><p>Within boardrooms, conversations are increasingly focused on who owns software supply chain risk, what impact it could have on the business, and what the financial implications might be. </p><p>Partners that cannot answer those questions risk losing credibility and, ultimately, customer relationships. Partners that can answer those questions with a proven strategy are much more likely to have stronger client adoption, expanded revenue opportunity, and longer-lasting relationships.  </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is AWS Trainium? ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Ever since the first groundbreaking microchip was created in the late 1950s, the race has been on to make these components smaller, more powerful, and faster.</p><p>In 2026, the quest for dominance in the AI sector is driving investment and innovation in the processor sector: AI may be software, but the power and speed of these chips will determine the success of the AI platforms.</p><p>AMD, Intel, and Nvidia are all leading producers of GPUs and CPUs for artificial intelligence, but coming up behind this trio is Amazon Web Services (AWS) and its Trainium series of chips. We explain what AWS Trainium is and how the technology industry is adopting these chips to deliver AI models at scale and speed.</p><h2 id="what-is-aws-trainium">What is AWS Trainium?</h2><p>AWS Trainium is the name of a series of computer chips designed to power both the training and the running of artificial intelligence. The name ‘Trainium’ is simply a play on words: machine learning models need to be trained, while the ‘-ium’ part evokes chemical elements, such as titanium. </p><p>According <a href="https://www.aboutamazon.com/stories/ai-chips-aws-trainium2-explain"><u>to Amazon</u></a>, AWS Trainium has been custom-built “to do one thing and one thing only: process massive amounts of data to help advance the development of generative AI”. In fact, Amazon describes AWS Trainium as “a powerhouse of brute computational force,” meaning every microscopic particle of the chip has been refined for the maximum amount of processing capability. </p><p>Amazon says a single AWS Trainium chip can complete trillions of calculations in just one second, and it’s this power the company hopes will see its chips at the core of AI infrastructure in the years ahead.</p><p>With all the major tech giants competing to place their specific chips at the heart of AI, it’s easy to see why this matters so much; a <a href="https://unctad.org/news/ai-market-projected-hit-48-trillion-2033-emerging-dominant-frontier-technology"><u>2025 report from UN Trade and Development</u></a> predicted the AI market would be worth $4.8 trillion by 2033.</p><h2 id="when-was-aws-trainium-launched">When was AWS Trainium launched?</h2><p>AWS Trainium was first announced in late 2020 with a roadmap to arrive in the first half of 2021. The AWS Trainium family is now up to <a href="https://www.itpro.com/cloud/live/aws-re-invent-2025-all-the-news-updates-and-announcements-live-from-las-vegas"><u>Trainium3 (Trn3), unveiled at AWS’s re:Invent expo in December 2025</u></a>. Compared with Trainium2, it doubles the compute performance and has 1.5x the memory capacity. </p><p>AWS Trainium chips are made by Annapurna Labs, an Israeli-based microelectronics company acquired by Amazon Web Services in 2015 for around $350 million.</p><h2 id="who-uses-aws-trainium">Who uses AWS Trainium?</h2><p>Direct Trainium customers are typically organizations that are involved in the training of large language models and other frontier AI.</p><p>Anthropic’s Claude, for example, has been trained – and runs – extensively on AWS Trainium chips. Additionally, Anthropic’s Project Rainier – one of the world’s largest AI compute clusters – is built on more than a million AWS Trainium2 chips.</p><p>Other AWS Trainium customers at present include Databricks, HCL, Hugging Face, PyTorch, and Ricoh. </p><h2 id="what-are-the-benefits-of-aws-trainium">What are the benefits of AWS Trainium?</h2><p>One of the key selling points of Trainium is its reported efficiency.</p><p>Since the launch of AWS Trainium3, Amazon says customers have reduced their AI training costs by up to 50% as well as massively lowering inference latency, which is the time taken between sending a request to an AI model and receiving an answer. Energy efficiency has also been increased by 40%.</p><p>AWS Trainium3 UltraServers consist of 144 Trainium3 chips, and Amazon says these cut the time taken to train AI models from months to weeks, making previously impractical or too expensive projects now a reality.</p><h2 id="how-does-aws-trainium-differ-from-aws-graviton">How does AWS Trainium differ from AWS Graviton?</h2><p>Both AWS Trainium and AWS Graviton are types of computer chips from Amazon Web Services. However, while AWS Trainium is used for the training and running of AI models, AWS Graviton handles the day-to-day cloud computing needs that keep the internet running. </p><p>It’s also the power behind the rollout of agentic AI systems by companies worldwide and is used to manage the workload of these agents to respond automatically to queries from users. AWS Graviton customers include Arm, Crowdtrike, HubSpot, Pinterest, and Snap.</p><h2 id="what-comes-next-for-aws-trainium">What comes next for AWS Trainium?</h2><p>Amazon is already working on AWS Trainium4, which it says will represent <a href="https://www.aboutamazon.com/news/aws/trainium-3-ultraserver-faster-ai-training-lower-cost"><u>a “foundational leap” forward</u></a> in processing power, speed, and efficiency for modern AI workloads. </p><p>This could include offering a 6x performance upgrade over AWS Trainium3. These chips are expected to arrive sometime in 2027 and will have unprecedented interoperability with Nvidia NVLink Fusion high-speed chip interconnect technology.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/infrastructure/what-is-aws-trainium</link>
                                                                            <description>
                            <![CDATA[ Learn about the AI accelerator chips known as AWS Trainium and understand how, where, and why they are used within AI infrastructure... ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">BMPBRpPdY6fc9PhubxsAPB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/re6EmQSf4nMedPZYqUgpcH-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Aug 2026 16:09:38 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jonathan Weinberg ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/re6EmQSf4nMedPZYqUgpcH-1920-80.jpg">
                                                            <media:credit><![CDATA[ITPro/Ross Kelly]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Amazon Web Services (AWS) logo pictured at the exhibitor hall at the 2025 AWS re:Invent conference at the Venetian Hotel and Casino, Las Vegas, Nevada, USA.]]></media:description>                                                            <media:text><![CDATA[Amazon Web Services (AWS) logo pictured at the exhibitor hall at the 2025 AWS re:Invent conference at the Venetian Hotel and Casino, Las Vegas, Nevada, USA.]]></media:text>
                                <media:title type="plain"><![CDATA[Amazon Web Services (AWS) logo pictured at the exhibitor hall at the 2025 AWS re:Invent conference at the Venetian Hotel and Casino, Las Vegas, Nevada, USA.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/re6EmQSf4nMedPZYqUgpcH-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Ever since the first groundbreaking microchip was created in the late 1950s, the race has been on to make these components smaller, more powerful, and faster.</p><p>In 2026, the quest for dominance in the AI sector is driving investment and innovation in the processor sector: AI may be software, but the power and speed of these chips will determine the success of the AI platforms.</p><p>AMD, Intel, and Nvidia are all leading producers of GPUs and CPUs for artificial intelligence, but coming up behind this trio is Amazon Web Services (AWS) and its Trainium series of chips. We explain what AWS Trainium is and how the technology industry is adopting these chips to deliver AI models at scale and speed.</p><h2 id="what-is-aws-trainium">What is AWS Trainium?</h2><p>AWS Trainium is the name of a series of computer chips designed to power both the training and the running of artificial intelligence. The name ‘Trainium’ is simply a play on words: machine learning models need to be trained, while the ‘-ium’ part evokes chemical elements, such as titanium. </p><p>According <a href="https://www.aboutamazon.com/stories/ai-chips-aws-trainium2-explain"><u>to Amazon</u></a>, AWS Trainium has been custom-built “to do one thing and one thing only: process massive amounts of data to help advance the development of generative AI”. In fact, Amazon describes AWS Trainium as “a powerhouse of brute computational force,” meaning every microscopic particle of the chip has been refined for the maximum amount of processing capability. </p><p>Amazon says a single AWS Trainium chip can complete trillions of calculations in just one second, and it’s this power the company hopes will see its chips at the core of AI infrastructure in the years ahead.</p><p>With all the major tech giants competing to place their specific chips at the heart of AI, it’s easy to see why this matters so much; a <a href="https://unctad.org/news/ai-market-projected-hit-48-trillion-2033-emerging-dominant-frontier-technology"><u>2025 report from UN Trade and Development</u></a> predicted the AI market would be worth $4.8 trillion by 2033.</p><h2 id="when-was-aws-trainium-launched">When was AWS Trainium launched?</h2><p>AWS Trainium was first announced in late 2020 with a roadmap to arrive in the first half of 2021. The AWS Trainium family is now up to <a href="https://www.itpro.com/cloud/live/aws-re-invent-2025-all-the-news-updates-and-announcements-live-from-las-vegas"><u>Trainium3 (Trn3), unveiled at AWS’s re:Invent expo in December 2025</u></a>. Compared with Trainium2, it doubles the compute performance and has 1.5x the memory capacity. </p><p>AWS Trainium chips are made by Annapurna Labs, an Israeli-based microelectronics company acquired by Amazon Web Services in 2015 for around $350 million.</p><h2 id="who-uses-aws-trainium">Who uses AWS Trainium?</h2><p>Direct Trainium customers are typically organizations that are involved in the training of large language models and other frontier AI.</p><p>Anthropic’s Claude, for example, has been trained – and runs – extensively on AWS Trainium chips. Additionally, Anthropic’s Project Rainier – one of the world’s largest AI compute clusters – is built on more than a million AWS Trainium2 chips.</p><p>Other AWS Trainium customers at present include Databricks, HCL, Hugging Face, PyTorch, and Ricoh. </p><h2 id="what-are-the-benefits-of-aws-trainium">What are the benefits of AWS Trainium?</h2><p>One of the key selling points of Trainium is its reported efficiency.</p><p>Since the launch of AWS Trainium3, Amazon says customers have reduced their AI training costs by up to 50% as well as massively lowering inference latency, which is the time taken between sending a request to an AI model and receiving an answer. Energy efficiency has also been increased by 40%.</p><p>AWS Trainium3 UltraServers consist of 144 Trainium3 chips, and Amazon says these cut the time taken to train AI models from months to weeks, making previously impractical or too expensive projects now a reality.</p><h2 id="how-does-aws-trainium-differ-from-aws-graviton">How does AWS Trainium differ from AWS Graviton?</h2><p>Both AWS Trainium and AWS Graviton are types of computer chips from Amazon Web Services. However, while AWS Trainium is used for the training and running of AI models, AWS Graviton handles the day-to-day cloud computing needs that keep the internet running. </p><p>It’s also the power behind the rollout of agentic AI systems by companies worldwide and is used to manage the workload of these agents to respond automatically to queries from users. AWS Graviton customers include Arm, Crowdtrike, HubSpot, Pinterest, and Snap.</p><h2 id="what-comes-next-for-aws-trainium">What comes next for AWS Trainium?</h2><p>Amazon is already working on AWS Trainium4, which it says will represent <a href="https://www.aboutamazon.com/news/aws/trainium-3-ultraserver-faster-ai-training-lower-cost"><u>a “foundational leap” forward</u></a> in processing power, speed, and efficiency for modern AI workloads. </p><p>This could include offering a 6x performance upgrade over AWS Trainium3. These chips are expected to arrive sometime in 2027 and will have unprecedented interoperability with Nvidia NVLink Fusion high-speed chip interconnect technology.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sovereignty is the channel’s next trust test ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The <a href="https://www.gov.uk/government/news/a-decisive-shift-to-power-british-ai-new-11-billion-plan-to-back-chip-firms-boost-computing-power-and-skills-for-the-ai-revolution"><u>UK government’s £1.1bn AI sovereignty plan</u></a> has put infrastructure control firmly on the boardroom agenda. With £750m earmarked for a national AI supercomputer and further funding for domestic chip capability, the message is clear: sovereignty has moved way past an abstract policy debate. It is now a practical test of how much control the UK has over the compute, data, networks, and suppliers that increasingly underpin its economy.</p><p>That question is affecting the channel, too, particularly as <a href="https://www.cityam.com/ms-profit-slumps-in-fallout-from-cyber-attack/"><u>major cyber incidents</u></a> have sharpened focus on the resilience of the networks underpinning operations. While buyers continue to care about performance and price, they are placing greater emphasis on the level of control their technology partners have over business-critical infrastructure.</p><h2 id="security-is-now-a-commercial-decision">Security is now a commercial decision</h2><p>The majority (88%) of IT decision makers (ITDMs) say that UK data sovereignty is vital when choosing technology partners, according to our <a href="https://btgroup.foleon.com/future-unlocked/your-key-to-a-future-unlocked/cyber-security"><u>research</u></a>. Some 70% identify cyber risk as one of their top organizational threats. Among resellers, 77% believe customers would switch providers for better protection.</p><p>Cyber resilience, therefore, needs to appear early in the sales conversation, framed around operational risk, customer confidence and the confidence that businesses will be able to keep trading when threats escalate. It also needs to be communicated over time, rather than treated as a one-off assurance during procurement, with 89% of ITDMs saying they want providers to deliver proactive updates on how their networks are being protected.</p><p>In short, as trust has become an even more integral part of the buying decision, partners need to move beyond headline credentials and make the delivery model behind the service much clearer. </p><h2 id="partners-must-deliver-across-data-operations-and-technical-control">Partners must deliver across data, operations and technical control</h2><p>Sales conversations can set the expectation, but the delivery model is what proves it. In practice, partners now need to deliver across three forms of control: data, operational, and technical. That starts with where the data sits, then extends to which suppliers and platforms are involved to support the service and how continuity is maintained if something goes wrong.</p><p>The first question is where information sits and whose legal framework applies to it. Put simply, customers need answers on where data is stored and handled and whether it falls under UK law. For many organizations, this matters because data is tied to regulatory obligations and internal governance, so vague assurances about cloud security do not give them enough to fully understand exposure. </p><p>Customers also need to understand who is involved in running the service. A contract may sit with a UK provider while parts of the support depend on third parties or overseas teams. The priority is knowing who delivers the service and which legal and operational frameworks govern the people and processes behind it. Partners need to be clear about these dependencies, so customers can judge how resilient the service really is beyond the primary contract.</p><p>The final question is what happens when circumstances change. Services have to be adaptable enough to withstand disruption or a shift in business strategy without leaving organizations locked into fragile arrangements. This becomes especially important in environments where downtime has an immediate operational impact. A manufacturer using connected production systems, for example, needs to be sure that the service chain behind that connectivity is recoverable and able to keep pace with changing requirements.</p><p>Working with vendors that can 100% confirm sovereignty of infrastructure – spanning connectivity, cloud, voice and AI – gives partners a strong foundation to address all these concerns with confidence.</p><h2 id="the-network-is-where-sovereignty-meets-delivery">The network is where sovereignty meets delivery</h2><p>Every dependency described above runs across the network.</p><p>It is the layer that connects policy concerns to business outcomes, turning questions about control into decisions about architecture, routing, access, monitoring and recovery. As AI, 5G and hybrid work reshape how organizations operate, customers will look for partners that can help them make sense of the underlying infrastructure. </p><p>For the channel, the prize is stronger commercial traction. Those that can explain how connectivity choices affect productivity, compliance, customer experience, and resilience will build stronger relationships and, ultimately, win more business. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/data-protection/sovereignty-is-the-channels-next-trust-test</link>
                                                                            <description>
                            <![CDATA[ Data sovereignty has become a key channel priority ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6MN27mLroiEwh9rdXAmVHm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2LvDwLLQ8jfBDzQBX5WER9-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 17 Aug 2026 17:21:33 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Gavin Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/JeMgqbizkXh95JHUuJf5oZ-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2LvDwLLQ8jfBDzQBX5WER9-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[IoT security concept image showing network symbols on a blue background.]]></media:description>                                                            <media:text><![CDATA[IoT security concept image showing network symbols on a blue background.]]></media:text>
                                <media:title type="plain"><![CDATA[IoT security concept image showing network symbols on a blue background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2LvDwLLQ8jfBDzQBX5WER9-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The <a href="https://www.gov.uk/government/news/a-decisive-shift-to-power-british-ai-new-11-billion-plan-to-back-chip-firms-boost-computing-power-and-skills-for-the-ai-revolution"><u>UK government’s £1.1bn AI sovereignty plan</u></a> has put infrastructure control firmly on the boardroom agenda. With £750m earmarked for a national AI supercomputer and further funding for domestic chip capability, the message is clear: sovereignty has moved way past an abstract policy debate. It is now a practical test of how much control the UK has over the compute, data, networks, and suppliers that increasingly underpin its economy.</p><p>That question is affecting the channel, too, particularly as <a href="https://www.cityam.com/ms-profit-slumps-in-fallout-from-cyber-attack/"><u>major cyber incidents</u></a> have sharpened focus on the resilience of the networks underpinning operations. While buyers continue to care about performance and price, they are placing greater emphasis on the level of control their technology partners have over business-critical infrastructure.</p><h2 id="security-is-now-a-commercial-decision">Security is now a commercial decision</h2><p>The majority (88%) of IT decision makers (ITDMs) say that UK data sovereignty is vital when choosing technology partners, according to our <a href="https://btgroup.foleon.com/future-unlocked/your-key-to-a-future-unlocked/cyber-security"><u>research</u></a>. Some 70% identify cyber risk as one of their top organizational threats. Among resellers, 77% believe customers would switch providers for better protection.</p><p>Cyber resilience, therefore, needs to appear early in the sales conversation, framed around operational risk, customer confidence and the confidence that businesses will be able to keep trading when threats escalate. It also needs to be communicated over time, rather than treated as a one-off assurance during procurement, with 89% of ITDMs saying they want providers to deliver proactive updates on how their networks are being protected.</p><p>In short, as trust has become an even more integral part of the buying decision, partners need to move beyond headline credentials and make the delivery model behind the service much clearer. </p><h2 id="partners-must-deliver-across-data-operations-and-technical-control">Partners must deliver across data, operations and technical control</h2><p>Sales conversations can set the expectation, but the delivery model is what proves it. In practice, partners now need to deliver across three forms of control: data, operational, and technical. That starts with where the data sits, then extends to which suppliers and platforms are involved to support the service and how continuity is maintained if something goes wrong.</p><p>The first question is where information sits and whose legal framework applies to it. Put simply, customers need answers on where data is stored and handled and whether it falls under UK law. For many organizations, this matters because data is tied to regulatory obligations and internal governance, so vague assurances about cloud security do not give them enough to fully understand exposure. </p><p>Customers also need to understand who is involved in running the service. A contract may sit with a UK provider while parts of the support depend on third parties or overseas teams. The priority is knowing who delivers the service and which legal and operational frameworks govern the people and processes behind it. Partners need to be clear about these dependencies, so customers can judge how resilient the service really is beyond the primary contract.</p><p>The final question is what happens when circumstances change. Services have to be adaptable enough to withstand disruption or a shift in business strategy without leaving organizations locked into fragile arrangements. This becomes especially important in environments where downtime has an immediate operational impact. A manufacturer using connected production systems, for example, needs to be sure that the service chain behind that connectivity is recoverable and able to keep pace with changing requirements.</p><p>Working with vendors that can 100% confirm sovereignty of infrastructure – spanning connectivity, cloud, voice and AI – gives partners a strong foundation to address all these concerns with confidence.</p><h2 id="the-network-is-where-sovereignty-meets-delivery">The network is where sovereignty meets delivery</h2><p>Every dependency described above runs across the network.</p><p>It is the layer that connects policy concerns to business outcomes, turning questions about control into decisions about architecture, routing, access, monitoring and recovery. As AI, 5G and hybrid work reshape how organizations operate, customers will look for partners that can help them make sense of the underlying infrastructure. </p><p>For the channel, the prize is stronger commercial traction. Those that can explain how connectivity choices affect productivity, compliance, customer experience, and resilience will build stronger relationships and, ultimately, win more business. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Stopping supply chain attacks ]]></title>
                                                                                                <dc:content><![CDATA[ <iframe allow="clipboard-write" height="200px" width="100%" id="" style="width: 100%; height: 200px;" class="position-center" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/c2d9c770-6596-467a-91b4-09b2da63f1c2/"></iframe><p>Supply chain attacks are increasingly common and increasingly disruptive, but organizations still struggle to defend against them properly.</p><p>In this episode of the ITPro Podcast, Jane and Ross are joined by Haydn Brooks, CEO of supply chain security firm Risk Ledger, to talk about what threats businesses are facing, what mitigation strategies could work well, and why cyber teams need to work together throughout the supply chain.</p><h2 id="highlights-5">Highlights</h2><p>"Most of the attacks that you find in in kind of the supply chain main are untargeted. So it's where you've had a threat actor launch a lot of attacks against a lot of different targets, they've breached a company without really knowing who that company is or was, and then they've basically passed that access on to somebody else, or they've gone on and leaked data or taken that company offline. And it's not really like a targeted attack against someone else, it's just that other companies who use that supply ... experience that as a supply chain attack, and very few of them are targeted. Where they are targeted, they are very hard to defend against because essentially, as the end target, I'm having to worry about an attack against somebody else, which I have no control over, being able to detect that and then being able to somehow respond to it as well."</p><p>"I think actually the regulation has kind of followed the the movement that we've seen within the industry rather than the other way around ... we're seeing a lot of these regulations also requiring companies to be either taking threat intelligence from others or sharing threat intelligence with others, as well as reporting incidents. So all of the regulation and the way security teams operate is moving in that direction of being more open, sharing more to benefit for the wider industry."</p><h2 id="related-content-2">Related content</h2><ul><li><a href="https://www.itpro.com/security/cyber-resilience-uk-learning-to-take-the-punches">Cyber resilience in the UK: learning to take the punches</a></li><li><a href="https://www.itpro.com/business/policy-and-legislation/dora-and-why-resilience-once-again-matters-to-the-board">DORA and why resilience (once again) matters to the board</a></li><li><a href="https://www.itpro.com/security/securing-the-supply-chain-why-zero-trust-and-recovery-readiness-are-non-negotiable">Securing the supply chain: Why zero trust and recovery readiness are non-negotiable</a></li><li><a href="https://www.itpro.com/security/data-breaches/logistics-firm-supply-chain-breach-hits-valve-and-other-customers">Logistics firm supply chain breach hits Valve and other customers</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/jaguar-land-rover-cyber-attack-financial-impact-cyber-monitoring-centre">Former NCSC head says the Jaguar Land Rover attack was the 'single most financially damaging cyber event ever to hit the UK' as impact laid bare</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/the-litellm-supply-chain-attack-this-year-could-be-the-biggest-ever">The LiteLLM supply chain attack this year could be the biggest ever</a></li><li><a href="https://www.itpro.com/security/why-is-supply-chain-resilience-under-the-spotlight">Why supply chain resilience is under the spotlight</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/jaguar-land-rover-did-the-right-thing-shutting-down-systems-to-thwart-cyber-attack">Jaguar Land Rover “did the right thing” shutting down systems to thwart cyber attack</a></li></ul> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/cyber-attacks/stopping-supply-chain-attacks</link>
                                                                            <description>
                            <![CDATA[ Why cyber teams need to work together to improve everyone's security ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ukzUwtBBi7EdYSg2R7pAFX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/w8NJiNPVH9eTRKENgPJoiT-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 14 Aug 2026 10:12:56 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ jane.mccallion@futurenet.com (Jane McCallion) ]]></author>                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Wq9nnLr7TNkY8gyBRb7YsA-320-70.jpeg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Jane is managing editor at ITPro and ChannelPro. She started out with the brands as a staff writer specializing in cloud computing before going on to become senior writer and reports editor, managing the content and creation of ITPro’s quarterly whitepapers. During this time, she broadened her expertise to include cybersecurity, data centers and enterprise IT infrastructure. In 2016, she became features editor, managing a pool of freelance and internal writers, while continuing to specialize in enterprise IT infrastructure, data centers, and business strategy.&lt;/p&gt;&lt;p&gt;In October 2021, she became the sites’ deputy editor, before moving to the role of managing editor in June 2024. Although she now has a more strategic role,  she is still a specialist in enterprise IT infrastructure, business strategy, and cybersecurity.&lt;/p&gt;&lt;p&gt;Jane holds an MA in journalism from Goldsmiths, University of London, and a BA in Applied Languages from the University of Portsmouth. She is fluent in French and Spanish, and has written features in both languages.&lt;/p&gt;&lt;p&gt;Prior to joining ITPro, Jane was a freelance business journalist writing as both Jane McCallion and Jane Bordenave for titles such as European CEO, World Finance, and Business Excellence Magazine.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/w8NJiNPVH9eTRKENgPJoiT-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[&quot;Stopping supply chain attacks&quot; in yellow and white text overlaid on top of an image of purple and pink neon chain links with one link shattering.]]></media:description>                                                            <media:text><![CDATA[&quot;Stopping supply chain attacks&quot; in yellow and white text overlaid on top of an image of purple and pink neon chain links with one link shattering.]]></media:text>
                                <media:title type="plain"><![CDATA[&quot;Stopping supply chain attacks&quot; in yellow and white text overlaid on top of an image of purple and pink neon chain links with one link shattering.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/w8NJiNPVH9eTRKENgPJoiT-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <iframe allow="clipboard-write" height="200px" width="100%" id="" style="width: 100%; height: 200px;" class="position-center" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/c2d9c770-6596-467a-91b4-09b2da63f1c2/"></iframe><p>Supply chain attacks are increasingly common and increasingly disruptive, but organizations still struggle to defend against them properly.</p><p>In this episode of the ITPro Podcast, Jane and Ross are joined by Haydn Brooks, CEO of supply chain security firm Risk Ledger, to talk about what threats businesses are facing, what mitigation strategies could work well, and why cyber teams need to work together throughout the supply chain.</p><h2 id="highlights-5">Highlights</h2><p>"Most of the attacks that you find in in kind of the supply chain main are untargeted. So it's where you've had a threat actor launch a lot of attacks against a lot of different targets, they've breached a company without really knowing who that company is or was, and then they've basically passed that access on to somebody else, or they've gone on and leaked data or taken that company offline. And it's not really like a targeted attack against someone else, it's just that other companies who use that supply ... experience that as a supply chain attack, and very few of them are targeted. Where they are targeted, they are very hard to defend against because essentially, as the end target, I'm having to worry about an attack against somebody else, which I have no control over, being able to detect that and then being able to somehow respond to it as well."</p><p>"I think actually the regulation has kind of followed the the movement that we've seen within the industry rather than the other way around ... we're seeing a lot of these regulations also requiring companies to be either taking threat intelligence from others or sharing threat intelligence with others, as well as reporting incidents. So all of the regulation and the way security teams operate is moving in that direction of being more open, sharing more to benefit for the wider industry."</p><h2 id="related-content-2">Related content</h2><ul><li><a href="https://www.itpro.com/security/cyber-resilience-uk-learning-to-take-the-punches">Cyber resilience in the UK: learning to take the punches</a></li><li><a href="https://www.itpro.com/business/policy-and-legislation/dora-and-why-resilience-once-again-matters-to-the-board">DORA and why resilience (once again) matters to the board</a></li><li><a href="https://www.itpro.com/security/securing-the-supply-chain-why-zero-trust-and-recovery-readiness-are-non-negotiable">Securing the supply chain: Why zero trust and recovery readiness are non-negotiable</a></li><li><a href="https://www.itpro.com/security/data-breaches/logistics-firm-supply-chain-breach-hits-valve-and-other-customers">Logistics firm supply chain breach hits Valve and other customers</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/jaguar-land-rover-cyber-attack-financial-impact-cyber-monitoring-centre">Former NCSC head says the Jaguar Land Rover attack was the 'single most financially damaging cyber event ever to hit the UK' as impact laid bare</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/the-litellm-supply-chain-attack-this-year-could-be-the-biggest-ever">The LiteLLM supply chain attack this year could be the biggest ever</a></li><li><a href="https://www.itpro.com/security/why-is-supply-chain-resilience-under-the-spotlight">Why supply chain resilience is under the spotlight</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/jaguar-land-rover-did-the-right-thing-shutting-down-systems-to-thwart-cyber-attack">Jaguar Land Rover “did the right thing” shutting down systems to thwart cyber attack</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Voice fraud is the channel's problem, but MSPs can solve It ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Voice remains one of the most effective channels for customer relationships. For customers, having access to a human on the other end of the line, especially in times of confusion or crisis, is increasingly important in an era driven by automation and AI adoption. </p><p>This is exactly why so many Managed Service Providers (MSPs) are involved in running or supporting contact center infrastructure on behalf of their customers. However, despite the rewards, it naturally doesn’t come without some risks.</p><p>In April 2026, the UK government published the findings of its 2025/26 <a href="https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026"><u>Cyber Security Breaches Survey</u></a>, which highlighted some sobering statistics. According to the data, nearly half of all UK businesses (43%) experienced a cyber security breach or attack in the past year. </p><p>Phishing remained the dominant attack vector, cited by 38% of businesses, and rated as the most disruptive incident type by 69% of those affected. However, of those phishing incidents, a growing share is no longer delivered by email. Rather, they’re arriving by phone call, and thanks to AI, they are increasingly convincing.</p><h2 id="the-evolving-threat">The evolving threat</h2><p>Voice phishing, or “vishing”, is not a new phenomenon. Bad actors and criminals have been spoofing voices and using fraudulent calls since the popularization of the telephone. What is new are the features that make voice phishing more convincing. </p><p>The proliferation of AI-generated voice deepfaking, caller ID spoofing tools, and lack of traceability have contributed to a new wave of fraudulent calls that appear more real than ever before.</p><p>Many organizations have spent significant resources securing their email environments, including spam filters, user training, and sandboxing. While this is a sensible investment, fraudsters have noticed and are adapting, which may explain why voice phishing has become an increasingly favored tactic for some bad actors.</p><h2 id="why-voice-is-being-targeted">Why voice is being targeted</h2><p>The basic mechanics of voice phishing have always relied on social engineering. Impersonating a trusted person and creating a sense of urgency help to manipulate victims into taking a malicious action, whether that be authorizing a payment, sharing credentials, or granting undue access to a system. While traditionally a mismatched voice was a potential giveaway to fraud, AI deepfakes have made this process much more convincing. </p><p>Voice cloning tools that once required real technical knowledge can now be replicated by most people with a commercial PC. It’s now easier than ever to create a convincing replica of a known voice from a short audio sample, for example, from a CEO's recorded video message, a support call that was unknowingly captured, or a social media clip.</p><p>If a cloned voice calls a finance team member and asks them to process an urgent payment, citing relevant details such as a live deal, a regulatory deadline, or a supplier relationship, very few red flags are present for the human on the receiving end of the call.</p><p>Number spoofing compounds the issue. Fraudsters may be able to secure the capability to present any caller ID they choose, making a call appear to originate from a trusted source. The result of mixing emerging tech with good due diligence is a call that looks and sounds real.</p><h2 id="msps-can-carry-disproportionate-risk">MSPs can carry disproportionate risk</h2><p>MSPs that support or run contact center infrastructure are in the middle of communications flows for multiple organizations and partners simultaneously. Critically, this also makes them the first port of call for customers when something technical goes wrong, which can offer an easy alibi for fraudsters looking to exploit them.</p><p>There are two distinct risks for MSPs: one operational, one reputational. The operational risk is straightforward: IT help desks control credentials, systems, and sensitive customer data, making them a target for malicious actors. The reputational risk, however, has a wider-reaching impact. If a customer is defrauded through infrastructure managed by an MSP, customers may find the MSP liable. Even if the MSP bears no technical responsibility, they are the supplier in the middle.</p><p>There is also a less visible third risk: the channel as a route of compromise. Fraudsters who have already gained access, whether through an earlier breach, open-source intelligence, or a compromised supplier, will probe the path that offers the least resistance. If an MSP's call handling has not been safeguarded with fraud in mind, that becomes the path of least resistance.</p><h2 id="practical-steps-to-take-right-now">Practical steps to take right now</h2><p>The tools to address this problem exist today, but gaps remain in general adoption and awareness. Firstly, MSPs should be implementing proper caller authentication where it is available. For example, in some markets, protocols exist to authenticate calls before they’re answered, such as the “STIR/SHAKEN” protocols used in the USA. These act as a digital "passport" for telephone calls, ensuring the number a call handler sees on their caller ID is legitimate and matches the actual person or business calling. These act as a strong defense against number spoofing.</p><p>Next, establish comprehensive verification workflows. Agents should never rely on voice recognition alone. Callbacks to verified numbers, challenge questions, and two-factor authentication must be embedded as standard security procedures. Call handlers must verify who is requesting sensitive information and challenge even those who appear familiar.</p><p>Additionally, staff should be trained to recognize the specific warning signs of voice phishing. Most security training currently focuses on email. Staff need scenario-based training covering AI-generated voice hallmarks, such as unnatural pauses and scripted rigidity, alongside classic social engineering tactics: creating a sense of urgency and requesting to bypass usual processes.</p><p>Finally, participate in industry data-sharing. No single provider sees the full picture. In the UK, mechanisms like the <a href="https://www.gov.uk/government/publications/fraud-sector-charter-telecommunications"><u>Home Office's Telecoms Fraud Sector Charter</u></a> seek to improve cross-sector visibility of active campaigns. MSPs engaged in these networks get earlier warnings to ensure they’re not operating with only a partial view. </p><h2 id="voice-is-a-channel-worth-championing">Voice is a channel worth championing</h2><p>Voice is a communication channel with many strengths, and the human touch can be the differentiator between satisfied and dissatisfied customers. For so many reasons, it’s a critical channel that’s worth championing, and worth safeguarding.</p><p>Voice fraud <em>is</em> the channel's problem. But the channel is very well placed to address it. </p><p>Steps such as appropriate due diligence through the supply chain, monitoring for suspicious traffic patterns, and validating caller IDs used by customers are all effective. It’s also crucial that MSPs and contact centers take the appropriate steps now to ensure that criminals can’t get in and customers remain confident. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/infrastructure/networking/voice-fraud-is-the-channels-problem-but-msps-can-solve-it</link>
                                                                            <description>
                            <![CDATA[ How MSPs can fight AI voice fraud through authentication, verification, and training ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">TFbGKR7XesTTjTDrsocmvJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HgFrkbHSaFtRPHicuE7k2k-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 14 Aug 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Networking]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tracey Wright ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3VQ3Pq7VUz2BMQtmGX58km-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/HgFrkbHSaFtRPHicuE7k2k-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Shot of a young woman working in a call center]]></media:description>                                                            <media:text><![CDATA[Shot of a young woman working in a call center]]></media:text>
                                <media:title type="plain"><![CDATA[Shot of a young woman working in a call center]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HgFrkbHSaFtRPHicuE7k2k-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Voice remains one of the most effective channels for customer relationships. For customers, having access to a human on the other end of the line, especially in times of confusion or crisis, is increasingly important in an era driven by automation and AI adoption. </p><p>This is exactly why so many Managed Service Providers (MSPs) are involved in running or supporting contact center infrastructure on behalf of their customers. However, despite the rewards, it naturally doesn’t come without some risks.</p><p>In April 2026, the UK government published the findings of its 2025/26 <a href="https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026"><u>Cyber Security Breaches Survey</u></a>, which highlighted some sobering statistics. According to the data, nearly half of all UK businesses (43%) experienced a cyber security breach or attack in the past year. </p><p>Phishing remained the dominant attack vector, cited by 38% of businesses, and rated as the most disruptive incident type by 69% of those affected. However, of those phishing incidents, a growing share is no longer delivered by email. Rather, they’re arriving by phone call, and thanks to AI, they are increasingly convincing.</p><h2 id="the-evolving-threat">The evolving threat</h2><p>Voice phishing, or “vishing”, is not a new phenomenon. Bad actors and criminals have been spoofing voices and using fraudulent calls since the popularization of the telephone. What is new are the features that make voice phishing more convincing. </p><p>The proliferation of AI-generated voice deepfaking, caller ID spoofing tools, and lack of traceability have contributed to a new wave of fraudulent calls that appear more real than ever before.</p><p>Many organizations have spent significant resources securing their email environments, including spam filters, user training, and sandboxing. While this is a sensible investment, fraudsters have noticed and are adapting, which may explain why voice phishing has become an increasingly favored tactic for some bad actors.</p><h2 id="why-voice-is-being-targeted">Why voice is being targeted</h2><p>The basic mechanics of voice phishing have always relied on social engineering. Impersonating a trusted person and creating a sense of urgency help to manipulate victims into taking a malicious action, whether that be authorizing a payment, sharing credentials, or granting undue access to a system. While traditionally a mismatched voice was a potential giveaway to fraud, AI deepfakes have made this process much more convincing. </p><p>Voice cloning tools that once required real technical knowledge can now be replicated by most people with a commercial PC. It’s now easier than ever to create a convincing replica of a known voice from a short audio sample, for example, from a CEO's recorded video message, a support call that was unknowingly captured, or a social media clip.</p><p>If a cloned voice calls a finance team member and asks them to process an urgent payment, citing relevant details such as a live deal, a regulatory deadline, or a supplier relationship, very few red flags are present for the human on the receiving end of the call.</p><p>Number spoofing compounds the issue. Fraudsters may be able to secure the capability to present any caller ID they choose, making a call appear to originate from a trusted source. The result of mixing emerging tech with good due diligence is a call that looks and sounds real.</p><h2 id="msps-can-carry-disproportionate-risk">MSPs can carry disproportionate risk</h2><p>MSPs that support or run contact center infrastructure are in the middle of communications flows for multiple organizations and partners simultaneously. Critically, this also makes them the first port of call for customers when something technical goes wrong, which can offer an easy alibi for fraudsters looking to exploit them.</p><p>There are two distinct risks for MSPs: one operational, one reputational. The operational risk is straightforward: IT help desks control credentials, systems, and sensitive customer data, making them a target for malicious actors. The reputational risk, however, has a wider-reaching impact. If a customer is defrauded through infrastructure managed by an MSP, customers may find the MSP liable. Even if the MSP bears no technical responsibility, they are the supplier in the middle.</p><p>There is also a less visible third risk: the channel as a route of compromise. Fraudsters who have already gained access, whether through an earlier breach, open-source intelligence, or a compromised supplier, will probe the path that offers the least resistance. If an MSP's call handling has not been safeguarded with fraud in mind, that becomes the path of least resistance.</p><h2 id="practical-steps-to-take-right-now">Practical steps to take right now</h2><p>The tools to address this problem exist today, but gaps remain in general adoption and awareness. Firstly, MSPs should be implementing proper caller authentication where it is available. For example, in some markets, protocols exist to authenticate calls before they’re answered, such as the “STIR/SHAKEN” protocols used in the USA. These act as a digital "passport" for telephone calls, ensuring the number a call handler sees on their caller ID is legitimate and matches the actual person or business calling. These act as a strong defense against number spoofing.</p><p>Next, establish comprehensive verification workflows. Agents should never rely on voice recognition alone. Callbacks to verified numbers, challenge questions, and two-factor authentication must be embedded as standard security procedures. Call handlers must verify who is requesting sensitive information and challenge even those who appear familiar.</p><p>Additionally, staff should be trained to recognize the specific warning signs of voice phishing. Most security training currently focuses on email. Staff need scenario-based training covering AI-generated voice hallmarks, such as unnatural pauses and scripted rigidity, alongside classic social engineering tactics: creating a sense of urgency and requesting to bypass usual processes.</p><p>Finally, participate in industry data-sharing. No single provider sees the full picture. In the UK, mechanisms like the <a href="https://www.gov.uk/government/publications/fraud-sector-charter-telecommunications"><u>Home Office's Telecoms Fraud Sector Charter</u></a> seek to improve cross-sector visibility of active campaigns. MSPs engaged in these networks get earlier warnings to ensure they’re not operating with only a partial view. </p><h2 id="voice-is-a-channel-worth-championing">Voice is a channel worth championing</h2><p>Voice is a communication channel with many strengths, and the human touch can be the differentiator between satisfied and dissatisfied customers. For so many reasons, it’s a critical channel that’s worth championing, and worth safeguarding.</p><p>Voice fraud <em>is</em> the channel's problem. But the channel is very well placed to address it. </p><p>Steps such as appropriate due diligence through the supply chain, monitoring for suspicious traffic patterns, and validating caller IDs used by customers are all effective. It’s also crucial that MSPs and contact centers take the appropriate steps now to ensure that criminals can’t get in and customers remain confident. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Moving SMBs out of the network tool maze ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Most small and mid-sized businesses (SMBs) are grappling with networks that have evolved one tool at a time, as new vendors were added to solve individual challenges as they emerged. </p><p>The result is a patchwork of solutions, from wireless access points and firewalls to monitoring tools, bolted together with little strategic planning. Each one has its own interface, licensing model, and operating expenses. </p><p>This is costing SMBs time, money, and resources. Too often, the IT infrastructure and management tools businesses rely on today were designed for enterprise environments, making them unnecessarily complex for smaller organizations. Disjointed systems and multiple dashboards make it harder to identify issues, and if a problem arises, which support service should a stretched IT team contact first? Add in the licensing cost for supporting multiple tools from multiple vendors, and the burden quickly grows.   </p><p>If SMBs are to escape from the network tool maze, they need to think about how all of their systems fit together and work with managed service partners to move toward a simpler, more effective cloud-based IT infrastructure.</p><h2 id="from-fragmented-tools-to-unified-management">From fragmented tools to unified management </h2><p>No longer reserved for the deep pockets of enterprises, unified, cloud-managed platforms are transforming network operations for SMBs. By bringing together networking, security, and monitoring into one interface, IT teams get a single pane of glass view across their entire environment. </p><p>For businesses, this means clearer visibility across devices such as routers and switches, insights into performance and power consumption, and the ability to identify and resolve issues before they impact operations. </p><p>Many Managed Service Providers (MSPs) are recommending cloud-based systems because they recognize the operational and business benefits they deliver. With less hardware to oversee, time-consuming on-site maintenance visits are reduced, and the path from purchase to deployment is fast and straightforward.</p><h2 id="a-more-strategic-role-for-msps">A more strategic role for MSPs</h2><p>For MSPs, the shift to the cloud also has advantages.</p><p>Remote management and automated software updates save time and costs. The advantages of this can be purely practical – looking after one unified platform will always be easier than overseeing several fragmented ones. </p><p>Moving clients to the cloud also allows MSPs to shift from reactive support when something goes wrong to proactive monitoring, optimization, and vulnerability management. They can deliver technical expertise, helping customers to scale seamlessly to meet market demands, and act as an outsourced IT department that transforms IT from being a burden to a strategic advantage. </p><p>Helping SMBs adopt cloud-managed platforms delivers another significant benefit - security. As compliance requirements and legal regulations change and cyber threats grow exponentially every year, the built-in cyber frameworks of cloud platforms become essential. </p><p>Compliance certifications, automated updates, and integrated monitoring provide a level of protection that was once available primarily to enterprise customers, and without the associated overhead.    </p><h2 id="simplifying-the-path-forward">Simplifying the path forward </h2><p>If SMBs are to simplify their networks, they need to move away from tool sprawl and towards a unified platform with security built-in, not bolted on. The right solution will not only deliver improved visibility and simpler operations, but also the features businesses need without unnecessary complexity. This also makes implementation easier as the company grows. </p><p>MSPs can help identify the right solution for the customer, but vendors must demonstrate how their platforms work in real-world conditions.  </p><p>And while even the best unified platform cannot do everything, integrating specialist tools should be seamless through open APIs and interoperability frameworks. </p><p>The future of networking is about using fewer tools to achieve more through simpler architecture, centralized control, and systems designed for how SMBs and their partners actually operate.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/infrastructure/networking/moving-smes-out-of-the-network-tool-maze</link>
                                                                            <description>
                            <![CDATA[ Netgear addresses how the complexity of networks can be simplified with a unified network management platform ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tFwRffGsUZmtYS5EFPDZCa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/WkbLCYGhP47DFmhkMKNUWo-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Aug 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Networking]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jordan Hobday ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/XyDZv93EEurbx9RDYkPEpM-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/WkbLCYGhP47DFmhkMKNUWo-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Networking concept image showing glowing lights flowing in a uniformed fashion.]]></media:description>                                                            <media:text><![CDATA[Networking concept image showing glowing lights flowing in a uniformed fashion.]]></media:text>
                                <media:title type="plain"><![CDATA[Networking concept image showing glowing lights flowing in a uniformed fashion.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/WkbLCYGhP47DFmhkMKNUWo-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Most small and mid-sized businesses (SMBs) are grappling with networks that have evolved one tool at a time, as new vendors were added to solve individual challenges as they emerged. </p><p>The result is a patchwork of solutions, from wireless access points and firewalls to monitoring tools, bolted together with little strategic planning. Each one has its own interface, licensing model, and operating expenses. </p><p>This is costing SMBs time, money, and resources. Too often, the IT infrastructure and management tools businesses rely on today were designed for enterprise environments, making them unnecessarily complex for smaller organizations. Disjointed systems and multiple dashboards make it harder to identify issues, and if a problem arises, which support service should a stretched IT team contact first? Add in the licensing cost for supporting multiple tools from multiple vendors, and the burden quickly grows.   </p><p>If SMBs are to escape from the network tool maze, they need to think about how all of their systems fit together and work with managed service partners to move toward a simpler, more effective cloud-based IT infrastructure.</p><h2 id="from-fragmented-tools-to-unified-management">From fragmented tools to unified management </h2><p>No longer reserved for the deep pockets of enterprises, unified, cloud-managed platforms are transforming network operations for SMBs. By bringing together networking, security, and monitoring into one interface, IT teams get a single pane of glass view across their entire environment. </p><p>For businesses, this means clearer visibility across devices such as routers and switches, insights into performance and power consumption, and the ability to identify and resolve issues before they impact operations. </p><p>Many Managed Service Providers (MSPs) are recommending cloud-based systems because they recognize the operational and business benefits they deliver. With less hardware to oversee, time-consuming on-site maintenance visits are reduced, and the path from purchase to deployment is fast and straightforward.</p><h2 id="a-more-strategic-role-for-msps">A more strategic role for MSPs</h2><p>For MSPs, the shift to the cloud also has advantages.</p><p>Remote management and automated software updates save time and costs. The advantages of this can be purely practical – looking after one unified platform will always be easier than overseeing several fragmented ones. </p><p>Moving clients to the cloud also allows MSPs to shift from reactive support when something goes wrong to proactive monitoring, optimization, and vulnerability management. They can deliver technical expertise, helping customers to scale seamlessly to meet market demands, and act as an outsourced IT department that transforms IT from being a burden to a strategic advantage. </p><p>Helping SMBs adopt cloud-managed platforms delivers another significant benefit - security. As compliance requirements and legal regulations change and cyber threats grow exponentially every year, the built-in cyber frameworks of cloud platforms become essential. </p><p>Compliance certifications, automated updates, and integrated monitoring provide a level of protection that was once available primarily to enterprise customers, and without the associated overhead.    </p><h2 id="simplifying-the-path-forward">Simplifying the path forward </h2><p>If SMBs are to simplify their networks, they need to move away from tool sprawl and towards a unified platform with security built-in, not bolted on. The right solution will not only deliver improved visibility and simpler operations, but also the features businesses need without unnecessary complexity. This also makes implementation easier as the company grows. </p><p>MSPs can help identify the right solution for the customer, but vendors must demonstrate how their platforms work in real-world conditions.  </p><p>And while even the best unified platform cannot do everything, integrating specialist tools should be seamless through open APIs and interoperability frameworks. </p><p>The future of networking is about using fewer tools to achieve more through simpler architecture, centralized control, and systems designed for how SMBs and their partners actually operate.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 24 hours to recover from a cyber attack ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The way an organization recovers from a cyber attack can be the difference between minimal disruption and going out of business. But while effective recovery can take time, business leaders are increasingly focusing on speed. </p><p>Recent data shows CEOs are placing huge demands on security professionals to be able to get back up and running quickly. Two-thirds of CEOs expect to be notified of a cyberattack within half an hour, according to <a href="https://www.itpro.com/security/with-jobs-on-the-line-ceos-now-demand-cyber-attack-recovery-in-hours-not-days-or-weeks"><u>research</u></a> from Cohesity. While 19% of business leaders think they should be alerted to a breach within five minutes.Around 38% of CEOs expect basic operations to be back up and running within a day, with 14% saying this should happen in just one hour. </p><p>The UK government’s recent <a href="https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026"><u>Cyber Security Breaches Survey</u></a> shows most firms can recover within 24 hours. Is this really possible, and if so, how can firms <a href="https://www.itpro.com/security/data-breaches/businesses-need-to-boost-cyber-resilience-heres-how"><u>harden defences</u></a> so they are able to get back up and running swiftly?</p><h2 id="attack-timelines">Attack timelines</h2><p>After a <a href="https://www.itpro.com/security/cyber-attacks/threat-actors-exploiting-quickly-what-business-leaders-should-do"><u>cyberattack</u></a> hits, some businesses will descend into chaos. “Systems are down, normal tooling doesn’t work – and you may even be isolated from the internet,” says Ade Clewlow MBE, associate director and senior advisor at NCC Group.</p><p>Yet amid this complex and high-stakes environment, experts say the first few hours after discovering an incident are critical. “How companies react to a breach in the first few hours matters,” says Dennis Martin, cyber and crisis resilience specialist at Axians UK.</p><p>He explains how during a live <a href="https://www.itpro.com/security/ransomware/new-ransomware-groups-worrying-security-researchers"><u>ransomware attack</u></a>, for example, the call on whether to disconnect the network and shut down systems needs to be made quickly. “In practice, this means teams monitoring the network need clear pre-authorisation to shut it down if they suspect an attack. It also means there should be a plan on how to restore once the system has been taken down, for both false-positive cases and confirmed attacks.”</p><p>Among the steps required, victims need to rapidly establish what has happened, assess whether the threat actor is still active, and work out which systems are affected. They then need to identify the steps needed to minimize the attack’s impact. “Immediate priorities typically include containing the attack and engaging key stakeholders,” according to Adam Harrison, managing director in the cybersecurity practice at FTI Consulting. </p><p>Speed is important, but acting on incomplete or inaccurate information “can be just as damaging as acting too slowly”, Harrison warns. He says overreacting to a false positive, disconnecting systems in a manner that makes recovery more difficult, or causing unnecessary business disruption “can serve as a self-inflicted wound”.</p><h2 id="understanding-the-scope">Understanding the scope</h2><p>Some steps can be taken straight after an attack, such as the initial containment. While this can often begin within the first hours, understanding the full scope of an incident may “take days or even weeks”, says Harrison.</p><p>Dan Wood, CISO at Cyberfort concurs. He believes recovering quickly and recovering well are “two very different things”. </p><p>“Everybody pats you on the back for getting operations restored in 24 hours after a cyber breach, but if you haven't recovered well, recovering quickly is pointless,” he says.</p><p>Wood says he’s seen organizations seemingly back up and running within hours, but at a cost. “Then they suffer the same attack days later because compromised backups placed the vulnerability and the attacker's back door straight back into live operation.”</p><p>The goal should be to have core services running in a clean environment, and to be able to prove this, Martin advises. “Otherwise, systems may be quickly compromised again, and, if a clean environment can’t be proven, partners won’t allow reactivation of vital interfaces.”</p><p>Yet at the same time, a slow response can be damaging. The impact of this will depend on the phase of the attack, according to Harrison. In the early stages, any delay gives an attacker more opportunity to achieve their objectives, he says. “They may access more systems, steal additional data, deploy ransomware, or establish persistence that makes later eradication significantly harder.”</p><p>Sluggish responses also increase business disruption. “Systems that could have been isolated early may instead require complete rebuilding,” says Harrison. “Recovery costs can also escalate and regulatory obligations will become more complex if additional data is compromised.”</p><p>In the latter stages of an incident, or after the adversary has already performed their <a href="https://www.ncsc.gov.uk/sites/default/files/documents/common_cyber_attacks_ncsc.pdf"><u>‘actions on objective’</u></a>, the focus shifts from preventing compromise and limiting further damage to restoring operations safely and understanding the full extent of the impact, according to Harrison. “At that point, delays can prolong downtime and increase recovery costs.”</p><h2 id="recovery-timelines">Recovery timelines</h2><p>The pressure is on, and the initial response should be rapid. But CEOS must also be realistic about the possibility of recovering too quickly. </p><p>“The number of variables involved in an attack will always dictate the speed of recovery,” Clewlow says. “For example, the threat from AI is moving at pace, so a successful AI-enabled technical attack has the potential to be more damaging in a shorter time.”</p><p>However, an organization that experiences minor disruption, such as a website being defaced, can usually recover relatively quickly, says Clewlow. </p><p>“Although technically a cyber incident, this is at the less severe end of the sliding scale. The larger and more complex the network is, the more severe the incident is likely to be, and the longer it will take to return to business as usual.”</p><p>Meeting the 24-hour benchmark demands “genuine organizational rigour”, according to Tracey Hannan-Jones, consulting director in information security, UBDS Digital. </p><p>“This means documented and rehearsed response plans, clearly assigned roles, pre-approved communication templates, and recovery infrastructure that is tested regularly and never assumed to work.”</p><p>Some of the basics include foundational cyber hygiene and ensuring your network is adequately segmented, according to Clewlow.</p><p>It’s also key to know what the minimum viable operations are for the business and to understand the assets on the network, says Clewlow. He believes rehearsed response plans are a key factor. </p><p>“CISOs should work with colleagues to ensure business continuity plans are shared and verified against information security realities, and that priorities for restoring systems and services after an incident are clearly understood,” he said.</p><p>“Recovery from a cyberattack is a team effort, in which the CISO will play an integral role.” </p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/cyber-attacks/24-hours-to-recover-from-a-cyber-attack</link>
                                                                            <description>
                            <![CDATA[ Two-thirds of CEOs want to be notified of a cyber attack within half an hour, with most expecting basic operations to be back up and running within a day. How can firms speed up their recovery? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7duEk2zWApDg82TDioAbkS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VHuoRHN7D2BMLU3pbN3Xv4-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Aug 2026 07:00:00 +0000</pubDate>                                                                                                                                <updated>Mon, 17 Aug 2026 11:12:57 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kate O&#039;Flaherty ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LUULv6n7VJ3BHPnaoLHHdg-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VHuoRHN7D2BMLU3pbN3Xv4-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A stylized image showing a glowing red cyber attack warning on top of a reflective metal surface bearing the flag of Iran.]]></media:description>                                                            <media:text><![CDATA[A stylized image showing a glowing red cyber attack warning on top of a reflective metal surface bearing the flag of Iran.]]></media:text>
                                <media:title type="plain"><![CDATA[A stylized image showing a glowing red cyber attack warning on top of a reflective metal surface bearing the flag of Iran.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VHuoRHN7D2BMLU3pbN3Xv4-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The way an organization recovers from a cyber attack can be the difference between minimal disruption and going out of business. But while effective recovery can take time, business leaders are increasingly focusing on speed. </p><p>Recent data shows CEOs are placing huge demands on security professionals to be able to get back up and running quickly. Two-thirds of CEOs expect to be notified of a cyberattack within half an hour, according to <a href="https://www.itpro.com/security/with-jobs-on-the-line-ceos-now-demand-cyber-attack-recovery-in-hours-not-days-or-weeks"><u>research</u></a> from Cohesity. While 19% of business leaders think they should be alerted to a breach within five minutes.Around 38% of CEOs expect basic operations to be back up and running within a day, with 14% saying this should happen in just one hour. </p><p>The UK government’s recent <a href="https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026"><u>Cyber Security Breaches Survey</u></a> shows most firms can recover within 24 hours. Is this really possible, and if so, how can firms <a href="https://www.itpro.com/security/data-breaches/businesses-need-to-boost-cyber-resilience-heres-how"><u>harden defences</u></a> so they are able to get back up and running swiftly?</p><h2 id="attack-timelines">Attack timelines</h2><p>After a <a href="https://www.itpro.com/security/cyber-attacks/threat-actors-exploiting-quickly-what-business-leaders-should-do"><u>cyberattack</u></a> hits, some businesses will descend into chaos. “Systems are down, normal tooling doesn’t work – and you may even be isolated from the internet,” says Ade Clewlow MBE, associate director and senior advisor at NCC Group.</p><p>Yet amid this complex and high-stakes environment, experts say the first few hours after discovering an incident are critical. “How companies react to a breach in the first few hours matters,” says Dennis Martin, cyber and crisis resilience specialist at Axians UK.</p><p>He explains how during a live <a href="https://www.itpro.com/security/ransomware/new-ransomware-groups-worrying-security-researchers"><u>ransomware attack</u></a>, for example, the call on whether to disconnect the network and shut down systems needs to be made quickly. “In practice, this means teams monitoring the network need clear pre-authorisation to shut it down if they suspect an attack. It also means there should be a plan on how to restore once the system has been taken down, for both false-positive cases and confirmed attacks.”</p><p>Among the steps required, victims need to rapidly establish what has happened, assess whether the threat actor is still active, and work out which systems are affected. They then need to identify the steps needed to minimize the attack’s impact. “Immediate priorities typically include containing the attack and engaging key stakeholders,” according to Adam Harrison, managing director in the cybersecurity practice at FTI Consulting. </p><p>Speed is important, but acting on incomplete or inaccurate information “can be just as damaging as acting too slowly”, Harrison warns. He says overreacting to a false positive, disconnecting systems in a manner that makes recovery more difficult, or causing unnecessary business disruption “can serve as a self-inflicted wound”.</p><h2 id="understanding-the-scope">Understanding the scope</h2><p>Some steps can be taken straight after an attack, such as the initial containment. While this can often begin within the first hours, understanding the full scope of an incident may “take days or even weeks”, says Harrison.</p><p>Dan Wood, CISO at Cyberfort concurs. He believes recovering quickly and recovering well are “two very different things”. </p><p>“Everybody pats you on the back for getting operations restored in 24 hours after a cyber breach, but if you haven't recovered well, recovering quickly is pointless,” he says.</p><p>Wood says he’s seen organizations seemingly back up and running within hours, but at a cost. “Then they suffer the same attack days later because compromised backups placed the vulnerability and the attacker's back door straight back into live operation.”</p><p>The goal should be to have core services running in a clean environment, and to be able to prove this, Martin advises. “Otherwise, systems may be quickly compromised again, and, if a clean environment can’t be proven, partners won’t allow reactivation of vital interfaces.”</p><p>Yet at the same time, a slow response can be damaging. The impact of this will depend on the phase of the attack, according to Harrison. In the early stages, any delay gives an attacker more opportunity to achieve their objectives, he says. “They may access more systems, steal additional data, deploy ransomware, or establish persistence that makes later eradication significantly harder.”</p><p>Sluggish responses also increase business disruption. “Systems that could have been isolated early may instead require complete rebuilding,” says Harrison. “Recovery costs can also escalate and regulatory obligations will become more complex if additional data is compromised.”</p><p>In the latter stages of an incident, or after the adversary has already performed their <a href="https://www.ncsc.gov.uk/sites/default/files/documents/common_cyber_attacks_ncsc.pdf"><u>‘actions on objective’</u></a>, the focus shifts from preventing compromise and limiting further damage to restoring operations safely and understanding the full extent of the impact, according to Harrison. “At that point, delays can prolong downtime and increase recovery costs.”</p><h2 id="recovery-timelines">Recovery timelines</h2><p>The pressure is on, and the initial response should be rapid. But CEOS must also be realistic about the possibility of recovering too quickly. </p><p>“The number of variables involved in an attack will always dictate the speed of recovery,” Clewlow says. “For example, the threat from AI is moving at pace, so a successful AI-enabled technical attack has the potential to be more damaging in a shorter time.”</p><p>However, an organization that experiences minor disruption, such as a website being defaced, can usually recover relatively quickly, says Clewlow. </p><p>“Although technically a cyber incident, this is at the less severe end of the sliding scale. The larger and more complex the network is, the more severe the incident is likely to be, and the longer it will take to return to business as usual.”</p><p>Meeting the 24-hour benchmark demands “genuine organizational rigour”, according to Tracey Hannan-Jones, consulting director in information security, UBDS Digital. </p><p>“This means documented and rehearsed response plans, clearly assigned roles, pre-approved communication templates, and recovery infrastructure that is tested regularly and never assumed to work.”</p><p>Some of the basics include foundational cyber hygiene and ensuring your network is adequately segmented, according to Clewlow.</p><p>It’s also key to know what the minimum viable operations are for the business and to understand the assets on the network, says Clewlow. He believes rehearsed response plans are a key factor. </p><p>“CISOs should work with colleagues to ensure business continuity plans are shared and verified against information security realities, and that priorities for restoring systems and services after an incident are clearly understood,” he said.</p><p>“Recovery from a cyberattack is a team effort, in which the CISO will play an integral role.” </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The intelligent workplace (part 2): Technology’s next transformation of work ]]></title>
                                                                                                <dc:content><![CDATA[ <h2 id="part-2-managing-performance-in-a-human-ai-workforce">Part 2: Managing performance in a human-AI workforce</h2><p>Managers have traditionally organized work around people: assigning responsibilities and holding individuals accountable for results. AI changes that model. When employees delegate tasks to AI assistants and teams include <a href="https://www.itpro.com/security/enterprises-are-adopting-agents-faster-than-they-can-secure-and-govern-them-experts-warn-its-a-disaster-waiting-to-happen"><u>autonomous agents</u></a>, performance emerges from a system of people, technology, data, processes, and managerial choices.</p><p><a href="https://www.itpro.com/technology/artificial-intelligence/the-intelligent-workplace-technologys-next-transformation-of-work">Part 1 of this series </a>explored the rise of the intelligent employee experience and how AI assistants and connected workplace platforms are changing everyday work. However, as intelligent systems take on a more active role, organizations must reconsider not only how work is performed, but how it is managed and measured.</p><p>Part 2 examines what happens when AI becomes a permanent member of the team. It considers how leaders must manage blended human-AI workflows and how employee development can preserve judgment and accountability as routine tasks move to intelligent systems.</p><p><a href="https://www.microsoft.com/en-us/worklab/work-trend-index/2025-the-year-the-frontier-firm-is-born"><u>Microsoft</u></a> reports that 36% of <a href="https://www.itpro.com/technology/artificial-intelligence/should-workers-prepare-to-become-ai-agent-bosses"><u>managers</u></a> expect to supervise AI agents within five years. <a href="https://www.itpro.com/technology/artificial-intelligence/should-workers-prepare-to-become-ai-agent-bosses"><u>Leaders</u></a> also anticipate that teams will build multi-agent systems and redesign processes. Nearly one-third expect to hire AI agent specialists within 12 to 18 months, while 28% are considering specialist AI workforce managers.</p><p>Yet adding digital workers does not automatically create business value. Only 14% of workers were using generative AI daily in 2025, according to <a href="https://www.pwc.com/gx/en/services/workforce/publications/ceo-survey-workforce-ai.html"><u>PwC</u></a>, while 56% of CEOs said their AI investments had delivered <a href="https://www.itpro.com/technology/artificial-intelligence/why-do-ai-projects-fail"><u>neither revenue growth nor cost savings</u></a>. The gap suggests that managing a human-AI workforce is not primarily a software challenge. It requires organizations to rethink how people develop expertise, and where accountability rests when machines influence decisions.</p><h2 id="performance-moves-beyond-output">Performance moves beyond output</h2><p>Traditional performance systems often reward visible activity: cases closed, documents produced, calls handled, or hours billed. AI can increase all these numbers without necessarily i<a href="https://www.itpro.com/business/business-strategy/ai-productivity-challenges-accenture-generating-impact-study"><u>mproving the work.</u></a> A poorly designed system can generate reports, <a href="https://www.itpro.com/software/development/software-developers-not-checking-ai-generated-code-verification-debt"><u>code</u></a>, marketing copy, or customer responses at extraordinary speed, but greater volume has little value if people must correct inaccuracies or repair damaged trust.</p><p>Dr. Janet Bastiman, chief data scientist at Napier AI, says quality should be the target rather than volume. “It would be trivial to automate slop, and that never results in a good company outcome,” she argues. Performance measures should instead connect work to organizational purpose and assess effectiveness and accuracy, regardless of whether AI was involved.</p><p>Good performance increasingly includes framing the right problem and accepting responsibility for the result. The most productive employee may be the one who prevents a plausible AI error from reaching a client or helps develop a more reliable workflow.</p><p>Margarita Lindahl, head of AI at Panasonic Connect Europe, explained: “The strongest performers will not necessarily be those who produce the most with AI. It will be those who use it to create better decisions, stronger customer outcomes, and build knowledge, ultimately benefiting the wider organization.”</p><p>Existing performance practices may <a href="https://www.itpro.com/technology/artificial-intelligence/ai-is-speeding-up-work-for-individual-employees-but-businesses-wide-productivity-is-floundering"><u>not be ready for this change</u></a>. Only 48% of UK employees report even a basic level of formal performance management, defined as having specific objectives for their roles, according to the <a href="https://www.cipd.org/uk/views-and-insights/thought-leadership/cipd-voice/impact-performance-management-employees"><u>CIPD</u></a>. Meanwhile, nearly half of employees say their work feels chaotic and fragmented. Measuring tasks and activity in that environment risks confusing busyness with contribution.</p><p>Performance frameworks must combine output with quality, judgment, collaboration, customer value, and responsible AI use. Results also depend on suitable tools, reliable data, training, and time for human review—not talent alone.</p><p>These conditions connect directly to the intelligent employee experience covered in Part 1 of this series. Performance cannot be separated from the environment in which employees work. Fragmented platforms and technology that add friction will affect results, regardless of how sophisticated an organization’s performance measures become.</p><h2 id="managers-become-architects-of-human-ai-teams">Managers become architects of human-AI teams</h2><p>AI expands rather than removes <a href="https://www.itpro.com/technology/artificial-intelligence/swamped-with-decisions-to-make-managers-turn-to-ai"><u>managerial responsibility</u></a>. Systems may allocate tasks, recommend priorities, <a href="https://www.itpro.com/business/business-strategy/bossware-monitoring-your-workers-vs-making-them-feel-uncomfortable"><u>monitor work</u></a>, or provide performance insights, but leaders still decide how they operate and when employees can override them. Management becomes less about controlling activity and more about designing complementary human and machine capabilities.</p><p>“Business leaders need to increasingly become architects of human-AI systems,” Lindahl tells ITPro. That requires enough technological literacy to distinguish genuine capability from hype, where human judgment remains essential, and to establish clear accountability. As AI influences more decisions, she says, leaders must create responsible guardrails rather than surrender authority to the technology.</p><p><a href="https://www.deloitte.com/us/en/about/press-room/deloitte-report-aims-to-help-leaders-navigate-complex-workplace-tensions.html"><u>Deloitte</u></a> found that managers spend almost 40% of their time resolving immediate problems and completing administration, but only 13% developing people. More than one-third feel unprepared for the people-management aspects of their roles. AI could return time to coaching, or create another stream of alerts and scores.</p><p>Andrew Avanessian, CEO of Haiilo, emphasized that leaders will need stronger systems thinking because AI often exposes inefficiencies elsewhere rather than solving them. They must also communicate what is changing, why it is changing, and where employees continue to create value.</p><p>Managers must also preserve permission to challenge the machine. If an agent allocates a task or recommends an action, employees should know whether they are expected to follow or overrule it. Otherwise, accountability becomes blurred, and people may defer to a system simply because its recommendation appears <a href="https://www.itpro.com/technology/artificial-intelligence/how-ai-agent-boss-is-reshaping-it-accountability"><u>authoritative</u></a>.</p><h2 id="development-must-protect-human-expertise">Development must protect human expertise</h2><p>As AI absorbs routine and analytical tasks. The larger challenge is ensuring that people still acquire the domain knowledge and practical experience needed to evaluate machine output.</p><p>Employers expect 39% of workers’ core skills to change by 2030, according to the <a href="https://www.weforum.org/publications/the-future-of-jobs-report-2025/in-full/3-skills-outlook"><u>World Economic Forum</u></a>. If the global workforce were represented by 100 people, 59 would require training, yet 11 may not receive it. Although 85% of employers plan to prioritize upskilling, only 33% of UK businesses using or considering AI say they are training or retraining existing employees in AI-related skills.</p><p>This gap particularly threatens early careers. Routine work has served as an apprenticeship: <a href="https://www.itpro.com/technology/artificial-intelligence/entry-level-jobs-ai-anthropic-dario-amodei"><u>junior employees</u></a> gather information, produce drafts, check details, and observe how experienced colleagues turn evidence into decisions. AI may remove those activities, but not the need for underlying knowledge.</p><p>Jenny Briant, director of talent Strategy at Scale Factory, explained that employers must create deliberate opportunities for employees to practice, make decisions, and receive feedback. “Employers cannot assume that people will develop judgement simply because they have access to better tools,” says Briant. “They need to <a href="https://www.itpro.com/technology/artificial-intelligence/how-to-immerse-your-employees-in-ai-training"><u>create deliberate opportunities for employees</u></a> to practise, make decisions and receive feedback. Practitioner-led training, mentoring and supervised work on real problems will become more important because they connect technical knowledge to the situations employees actually face.”</p><p>The goal is not to make people compete with machines on speed. It is to strengthen critical thinking, problem framing, creativity, relationship-building, and contextual judgment. Bastiman emphasized, “Ensuring meaningful human oversight of AI systems through various types of checks will ensure that the employees keep their core skills sharp for the task, but allowing the shift of work into new tasks will allow the building of new skills that were not possible prior to the overload of routine tasks.”</p><p>Employee development must also include the ability to <a href="https://www.itpro.com/technology/artificial-intelligence/workers-cant-identify-work-produced-by-ai-agents-business-risks"><u>explain how AI contributed to an outcome</u></a>. Asking someone why they selected a tool, how they checked its response, and which elements required personal judgment reveals more about professional competence than banning the technology during an assessment.</p><p>Developing this combination of technological fluency and human judgment will become increasingly important as organizations prepare for 2030. Part 3 of this series examines how skills-based workforce planning and internal mobility can help businesses build the capabilities required as AI, automation and other emerging technologies reshape work.</p><h2 id="trust-determines-whether-measurement-improves-work">Trust determines whether measurement improves work</h2><p>AI promises more personalized and evidence-based performance management. It could identify patterns that a busy manager might miss or reveal where <a href="https://www.itpro.com/technology/artificial-intelligence/building-ai-readiness-through-clear-workflows"><u>workflows</u></a> routinely break down. Yet the same technology can intensify surveillance and give questionable judgments a veneer of objectivity.</p><p>Algorithmic management is already widespread. <a href="https://www.oecd.org/en/publications/how-widespread-is-algorithmic-management-in-workplaces_cda7a114-en/full-report.html"><u>OECD</u></a> research found that such tools were used to instruct, monitor, or evaluate workers in 90% of surveyed US firms and an average of 79% across France, Germany, Italy, and Spain. Managers identified unclear accountability, limited explainability, and insufficient protection of employee health among their concerns.</p><p>Bastiman warns that automated evaluation can remove empathy from performance management and <a href="https://www.itpro.com/technology/artificial-intelligence/tech-workers-ai-skills-executives"><u>embed assumptions</u></a> from the culture in which the system was developed. Briant similarly notes that an algorithm may count output or response times but miss an employee who supported a struggling colleague or challenged a poor decision. What is easiest to measure is not always what is most valuable.</p><p>Transparency and consultation are therefore operational requirements, not optional ethics statements. Employees should understand what data is collected and how they can challenge it. OECD evidence indicates that training and consultation are associated with better outcomes when workplace AI is introduced. Trust matters because only 58% of workers currently trust their direct manager and feel able to speak openly with them, according to <a href="https://www.pwc.com/gx/en/issues/workforce/hopes-and-fears.html"><u>PwC</u></a>.</p><p>Organizations that manage human-AI performance successfully will redesign work, protect time for learning, measure the value of outcomes, and keep accountability visibly human. AI can expand capacity, but leadership determines whether it produces better decisions or simply more activity. Performance will depend on how well people and machines work together, and whether employees emerge more capable and responsible.</p><p>Managing today’s human-AI workforce also requires organizations to prepare for the more extensive transformation ahead. The final part of this three-part series looks toward the workplace of 2030, identifying the emerging technologies and workforce strategies that will determine whether businesses can turn continual disruption into lasting competitive advantage.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/technology/artificial-intelligence/the-intelligent-workplace-part-2-technologys-next-transformation-of-work</link>
                                                                            <description>
                            <![CDATA[ As AI becomes part of every team, leaders must rethink performance and employee development across the emerging human-AI workforce ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wFfDL3NEEU6UqZwSKxxu7o</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/3MYdgoHSru8pFz22e58jtQ-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Aug 2026 17:34:28 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ David Howell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/RyCMPNysW5pydbG6t9n8Kh-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/3MYdgoHSru8pFz22e58jtQ-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Futuristic design of artificial Intelligence brain with circuit board.]]></media:description>                                                            <media:text><![CDATA[Futuristic design of artificial Intelligence brain with circuit board.]]></media:text>
                                <media:title type="plain"><![CDATA[Futuristic design of artificial Intelligence brain with circuit board.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/3MYdgoHSru8pFz22e58jtQ-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <h2 id="part-2-managing-performance-in-a-human-ai-workforce">Part 2: Managing performance in a human-AI workforce</h2><p>Managers have traditionally organized work around people: assigning responsibilities and holding individuals accountable for results. AI changes that model. When employees delegate tasks to AI assistants and teams include <a href="https://www.itpro.com/security/enterprises-are-adopting-agents-faster-than-they-can-secure-and-govern-them-experts-warn-its-a-disaster-waiting-to-happen"><u>autonomous agents</u></a>, performance emerges from a system of people, technology, data, processes, and managerial choices.</p><p><a href="https://www.itpro.com/technology/artificial-intelligence/the-intelligent-workplace-technologys-next-transformation-of-work">Part 1 of this series </a>explored the rise of the intelligent employee experience and how AI assistants and connected workplace platforms are changing everyday work. However, as intelligent systems take on a more active role, organizations must reconsider not only how work is performed, but how it is managed and measured.</p><p>Part 2 examines what happens when AI becomes a permanent member of the team. It considers how leaders must manage blended human-AI workflows and how employee development can preserve judgment and accountability as routine tasks move to intelligent systems.</p><p><a href="https://www.microsoft.com/en-us/worklab/work-trend-index/2025-the-year-the-frontier-firm-is-born"><u>Microsoft</u></a> reports that 36% of <a href="https://www.itpro.com/technology/artificial-intelligence/should-workers-prepare-to-become-ai-agent-bosses"><u>managers</u></a> expect to supervise AI agents within five years. <a href="https://www.itpro.com/technology/artificial-intelligence/should-workers-prepare-to-become-ai-agent-bosses"><u>Leaders</u></a> also anticipate that teams will build multi-agent systems and redesign processes. Nearly one-third expect to hire AI agent specialists within 12 to 18 months, while 28% are considering specialist AI workforce managers.</p><p>Yet adding digital workers does not automatically create business value. Only 14% of workers were using generative AI daily in 2025, according to <a href="https://www.pwc.com/gx/en/services/workforce/publications/ceo-survey-workforce-ai.html"><u>PwC</u></a>, while 56% of CEOs said their AI investments had delivered <a href="https://www.itpro.com/technology/artificial-intelligence/why-do-ai-projects-fail"><u>neither revenue growth nor cost savings</u></a>. The gap suggests that managing a human-AI workforce is not primarily a software challenge. It requires organizations to rethink how people develop expertise, and where accountability rests when machines influence decisions.</p><h2 id="performance-moves-beyond-output">Performance moves beyond output</h2><p>Traditional performance systems often reward visible activity: cases closed, documents produced, calls handled, or hours billed. AI can increase all these numbers without necessarily i<a href="https://www.itpro.com/business/business-strategy/ai-productivity-challenges-accenture-generating-impact-study"><u>mproving the work.</u></a> A poorly designed system can generate reports, <a href="https://www.itpro.com/software/development/software-developers-not-checking-ai-generated-code-verification-debt"><u>code</u></a>, marketing copy, or customer responses at extraordinary speed, but greater volume has little value if people must correct inaccuracies or repair damaged trust.</p><p>Dr. Janet Bastiman, chief data scientist at Napier AI, says quality should be the target rather than volume. “It would be trivial to automate slop, and that never results in a good company outcome,” she argues. Performance measures should instead connect work to organizational purpose and assess effectiveness and accuracy, regardless of whether AI was involved.</p><p>Good performance increasingly includes framing the right problem and accepting responsibility for the result. The most productive employee may be the one who prevents a plausible AI error from reaching a client or helps develop a more reliable workflow.</p><p>Margarita Lindahl, head of AI at Panasonic Connect Europe, explained: “The strongest performers will not necessarily be those who produce the most with AI. It will be those who use it to create better decisions, stronger customer outcomes, and build knowledge, ultimately benefiting the wider organization.”</p><p>Existing performance practices may <a href="https://www.itpro.com/technology/artificial-intelligence/ai-is-speeding-up-work-for-individual-employees-but-businesses-wide-productivity-is-floundering"><u>not be ready for this change</u></a>. Only 48% of UK employees report even a basic level of formal performance management, defined as having specific objectives for their roles, according to the <a href="https://www.cipd.org/uk/views-and-insights/thought-leadership/cipd-voice/impact-performance-management-employees"><u>CIPD</u></a>. Meanwhile, nearly half of employees say their work feels chaotic and fragmented. Measuring tasks and activity in that environment risks confusing busyness with contribution.</p><p>Performance frameworks must combine output with quality, judgment, collaboration, customer value, and responsible AI use. Results also depend on suitable tools, reliable data, training, and time for human review—not talent alone.</p><p>These conditions connect directly to the intelligent employee experience covered in Part 1 of this series. Performance cannot be separated from the environment in which employees work. Fragmented platforms and technology that add friction will affect results, regardless of how sophisticated an organization’s performance measures become.</p><h2 id="managers-become-architects-of-human-ai-teams">Managers become architects of human-AI teams</h2><p>AI expands rather than removes <a href="https://www.itpro.com/technology/artificial-intelligence/swamped-with-decisions-to-make-managers-turn-to-ai"><u>managerial responsibility</u></a>. Systems may allocate tasks, recommend priorities, <a href="https://www.itpro.com/business/business-strategy/bossware-monitoring-your-workers-vs-making-them-feel-uncomfortable"><u>monitor work</u></a>, or provide performance insights, but leaders still decide how they operate and when employees can override them. Management becomes less about controlling activity and more about designing complementary human and machine capabilities.</p><p>“Business leaders need to increasingly become architects of human-AI systems,” Lindahl tells ITPro. That requires enough technological literacy to distinguish genuine capability from hype, where human judgment remains essential, and to establish clear accountability. As AI influences more decisions, she says, leaders must create responsible guardrails rather than surrender authority to the technology.</p><p><a href="https://www.deloitte.com/us/en/about/press-room/deloitte-report-aims-to-help-leaders-navigate-complex-workplace-tensions.html"><u>Deloitte</u></a> found that managers spend almost 40% of their time resolving immediate problems and completing administration, but only 13% developing people. More than one-third feel unprepared for the people-management aspects of their roles. AI could return time to coaching, or create another stream of alerts and scores.</p><p>Andrew Avanessian, CEO of Haiilo, emphasized that leaders will need stronger systems thinking because AI often exposes inefficiencies elsewhere rather than solving them. They must also communicate what is changing, why it is changing, and where employees continue to create value.</p><p>Managers must also preserve permission to challenge the machine. If an agent allocates a task or recommends an action, employees should know whether they are expected to follow or overrule it. Otherwise, accountability becomes blurred, and people may defer to a system simply because its recommendation appears <a href="https://www.itpro.com/technology/artificial-intelligence/how-ai-agent-boss-is-reshaping-it-accountability"><u>authoritative</u></a>.</p><h2 id="development-must-protect-human-expertise">Development must protect human expertise</h2><p>As AI absorbs routine and analytical tasks. The larger challenge is ensuring that people still acquire the domain knowledge and practical experience needed to evaluate machine output.</p><p>Employers expect 39% of workers’ core skills to change by 2030, according to the <a href="https://www.weforum.org/publications/the-future-of-jobs-report-2025/in-full/3-skills-outlook"><u>World Economic Forum</u></a>. If the global workforce were represented by 100 people, 59 would require training, yet 11 may not receive it. Although 85% of employers plan to prioritize upskilling, only 33% of UK businesses using or considering AI say they are training or retraining existing employees in AI-related skills.</p><p>This gap particularly threatens early careers. Routine work has served as an apprenticeship: <a href="https://www.itpro.com/technology/artificial-intelligence/entry-level-jobs-ai-anthropic-dario-amodei"><u>junior employees</u></a> gather information, produce drafts, check details, and observe how experienced colleagues turn evidence into decisions. AI may remove those activities, but not the need for underlying knowledge.</p><p>Jenny Briant, director of talent Strategy at Scale Factory, explained that employers must create deliberate opportunities for employees to practice, make decisions, and receive feedback. “Employers cannot assume that people will develop judgement simply because they have access to better tools,” says Briant. “They need to <a href="https://www.itpro.com/technology/artificial-intelligence/how-to-immerse-your-employees-in-ai-training"><u>create deliberate opportunities for employees</u></a> to practise, make decisions and receive feedback. Practitioner-led training, mentoring and supervised work on real problems will become more important because they connect technical knowledge to the situations employees actually face.”</p><p>The goal is not to make people compete with machines on speed. It is to strengthen critical thinking, problem framing, creativity, relationship-building, and contextual judgment. Bastiman emphasized, “Ensuring meaningful human oversight of AI systems through various types of checks will ensure that the employees keep their core skills sharp for the task, but allowing the shift of work into new tasks will allow the building of new skills that were not possible prior to the overload of routine tasks.”</p><p>Employee development must also include the ability to <a href="https://www.itpro.com/technology/artificial-intelligence/workers-cant-identify-work-produced-by-ai-agents-business-risks"><u>explain how AI contributed to an outcome</u></a>. Asking someone why they selected a tool, how they checked its response, and which elements required personal judgment reveals more about professional competence than banning the technology during an assessment.</p><p>Developing this combination of technological fluency and human judgment will become increasingly important as organizations prepare for 2030. Part 3 of this series examines how skills-based workforce planning and internal mobility can help businesses build the capabilities required as AI, automation and other emerging technologies reshape work.</p><h2 id="trust-determines-whether-measurement-improves-work">Trust determines whether measurement improves work</h2><p>AI promises more personalized and evidence-based performance management. It could identify patterns that a busy manager might miss or reveal where <a href="https://www.itpro.com/technology/artificial-intelligence/building-ai-readiness-through-clear-workflows"><u>workflows</u></a> routinely break down. Yet the same technology can intensify surveillance and give questionable judgments a veneer of objectivity.</p><p>Algorithmic management is already widespread. <a href="https://www.oecd.org/en/publications/how-widespread-is-algorithmic-management-in-workplaces_cda7a114-en/full-report.html"><u>OECD</u></a> research found that such tools were used to instruct, monitor, or evaluate workers in 90% of surveyed US firms and an average of 79% across France, Germany, Italy, and Spain. Managers identified unclear accountability, limited explainability, and insufficient protection of employee health among their concerns.</p><p>Bastiman warns that automated evaluation can remove empathy from performance management and <a href="https://www.itpro.com/technology/artificial-intelligence/tech-workers-ai-skills-executives"><u>embed assumptions</u></a> from the culture in which the system was developed. Briant similarly notes that an algorithm may count output or response times but miss an employee who supported a struggling colleague or challenged a poor decision. What is easiest to measure is not always what is most valuable.</p><p>Transparency and consultation are therefore operational requirements, not optional ethics statements. Employees should understand what data is collected and how they can challenge it. OECD evidence indicates that training and consultation are associated with better outcomes when workplace AI is introduced. Trust matters because only 58% of workers currently trust their direct manager and feel able to speak openly with them, according to <a href="https://www.pwc.com/gx/en/issues/workforce/hopes-and-fears.html"><u>PwC</u></a>.</p><p>Organizations that manage human-AI performance successfully will redesign work, protect time for learning, measure the value of outcomes, and keep accountability visibly human. AI can expand capacity, but leadership determines whether it produces better decisions or simply more activity. Performance will depend on how well people and machines work together, and whether employees emerge more capable and responsible.</p><p>Managing today’s human-AI workforce also requires organizations to prepare for the more extensive transformation ahead. The final part of this three-part series looks toward the workplace of 2030, identifying the emerging technologies and workforce strategies that will determine whether businesses can turn continual disruption into lasting competitive advantage.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Can AI fight AI? Where the security gap still exists in cybersecurity, and how MSPs can help. ]]></title>
                                                                                                <dc:content><![CDATA[ <p>As the old saying goes, sometimes “you have to fight fire with fire”. That’s certainly true in 2026, with cyber threats increasingly coming from ever more sophisticated use of AI tools. </p><p>There’s a problem with that, though: most businesses are not yet fully set up to deal with AI-based attacks and don’t trust the tools to do the job. A <a href="https://www.proofpoint.com/uk/resources/threat-reports/ai-human-risk-landscape-report"><u>2026 Proofpoint AI and Human Risk Landscape Report</u></a> revealed that half of organizations using AI-based security controls still experienced suspicious or confirmed AI-related incidents. </p><p>There is a fundamental security gap in many organizations: AI adoption has outpaced the right security measures. In the report, nearly 9 in 10 (87%) organizations had moved AI assistants beyond the pilot stage, and 76% were actively piloting or rolling out autonomous agents. But that activity has outpaced security maturity: 63% had AI security controls in place, but 52% weren’t completely confident those controls would detect a compromised AI. </p><p>AI tools are embedded directly into communications to increase productivity and speed, but in the rush to be efficient and compete, AI permissions and access to sensitive data are being left unchecked. </p><p>These aren’t complex security engineering problems: they are organizational and process gaps that can be addressed without waiting for the tooling market to mature. Currently, only a few organizations have developed their incident response playbooks, logging coverage, or forensic tools needed to investigate a compromised AI agent. </p><p></p><p>For many businesses lacking the in-house skills needed to take on these items, which can be significant, contracting a trusted managed service provider (MSP) can help bridge the gap. Many MSPs have been assisting businesses with AI adoption for some time now, and many have the deep understanding and technical skills needed to help businesses of all sizes see tangible benefits to AI while keeping critical data safe.</p><h2 id="the-origins-of-ai-attacks">The origins of AI attacks </h2><p>Most attacks start with unrestrained access and end with autonomous systems exposing sensitive data from these environments. When threat actors target agentic systems that lack proper controls, they don’t need to trick employees to access internal intelligence; they only need to manipulate the AI. </p><p>Prompt injection attacks are a common way to do this. A bad actor might send a target user seemingly helpful AI instructions while posing as a trusted authority or co-worker. A well-intentioned employee may then ask an AI to answer what seems like a simple inquiry. </p><p>Depending on the attacker’s instructions, the AI agent may instead be tricked into reading manipulated webpages (i.e., white text on a white background) to unwittingly extract internal data and send it to the attacker’s server.</p><p>For prompt injection attacks, it’s important to limit AI agents’ access to only the tools and data they need to complete the designed task. This is a good solution to prevent AI from giving out more information than required. This can limit the scope of an external threat actor’s reach.</p><p>That said, the employee’s role isn’t lost in all AI-based attacks. An ongoing cybersecurity skills gap severely impacts defenses, and threat actors know this. </p><p>Over the last decade, multi-factor authentication (MFA) has been an important step toward stronger security authentication. But today, attackers can pair AI-generated phishing with ‘MFA bypass kits,’ such as open-source Evilginx (known as a penetration testing utility for these styles of attacks) and the W3LL panel (a private phishing kit) to deceive employees into handing over that ‘extra step’ of security. </p><p>Tools like Evilginx and the W3LL phishing kit are used to create realistic sign-in pages that mimic those of Google, Microsoft, and others. Without proper security training, employees may unwittingly be signing into these while attackers capture their session tokens – even those with MFA. </p><p>A good defense against MFA bypass kits is adopting phishing-resistant MFA technologies such as FIDO2 hardware keys, Windows Hello for Business, Certificate-based Authentication (CBA), and Passkeys. These methods are tied to legitimate sign-in pages and don’t work on fake pages. </p><p>However, stopping the threat from ever materializing starts with having proper cybersecurity awareness training. Nearly half of all organizations lack this training or simply adopt a checkbox approach, which is why implementing these programs is an important step to closing the gap. </p><p>These programs teach users to spot a myriad of cyber threats, including AI-based threats. Tools of this type are also a good example of using AI in defensive security, as some can leverage AI to customize the training an end user receives based on their performance in past training. </p><p>This is another area where MSPs are highly qualified to assist. MSPs typically run training programs across a vast number of users and industry types. They understand what training works and what doesn’t, and can help position the best security awareness training for a given organization.</p><h2 id="how-does-ai-enhance-threat-detection">How does AI enhance threat detection?</h2><p>To understand the power and importance of AI-powered cybersecurity, it helps to understand how it works. Once trained, a detection model becomes exceptionally good at spotting the characteristics of malicious activity. It can take into account thousands of different characteristics to spot anomalies, outliers, and similarities that humans are unable to correlate. </p><p>It’s important to have a reliable cybersecurity service provider with REAL AI skills, because machine learning systems aren’t perfect and (while rare) can produce false positives. A strong partner can minimize these false positives while offering real-time threat detection and analysis, as well as faster, well-informed response times. </p><p>A trusted MSP will have a wide range of capabilities and will have a deep understanding of the protection methods that work well within their target industries. By leveraging that deep knowledge from their partner MSPs, businesses will benefit from great protection, even with today’s AI-powered attacks.</p><h2 id="preparedness-in-2026-and-beyond">Preparedness in 2026 and beyond</h2><p>To operate in this new era, businesses must treat every AI agent as a high-risk workload identity. </p><p>In practice, this requires working with reputable MSPs to implement strict least-privilege access to avoid data leaks, constant monitoring to protect the integrity of the data, and comprehensive employee awareness training.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/technology/artificial-intelligence/can-ai-fight-ai-where-the-security-gap-still-exists-in-cybersecurity-and-how-msps-can-help</link>
                                                                            <description>
                            <![CDATA[ Why AI security is failing and how MSPs can close the gap ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">J7MpsYnhGWSkq4qUqQf66T</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/A2eUMwBBjVbDZpzbyz9BrQ-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Aug 2026 17:16:29 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Andy Syrewicze ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aGeMeVu7b6TCqvPzk8mRKJ-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/A2eUMwBBjVbDZpzbyz9BrQ-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[AI security concept image showing a digitized padlock symbol with &#039;AI&#039; symbol, connected to data points with multi-colored data flows emanating from each point.]]></media:description>                                                            <media:text><![CDATA[AI security concept image showing a digitized padlock symbol with &#039;AI&#039; symbol, connected to data points with multi-colored data flows emanating from each point.]]></media:text>
                                <media:title type="plain"><![CDATA[AI security concept image showing a digitized padlock symbol with &#039;AI&#039; symbol, connected to data points with multi-colored data flows emanating from each point.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/A2eUMwBBjVbDZpzbyz9BrQ-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>As the old saying goes, sometimes “you have to fight fire with fire”. That’s certainly true in 2026, with cyber threats increasingly coming from ever more sophisticated use of AI tools. </p><p>There’s a problem with that, though: most businesses are not yet fully set up to deal with AI-based attacks and don’t trust the tools to do the job. A <a href="https://www.proofpoint.com/uk/resources/threat-reports/ai-human-risk-landscape-report"><u>2026 Proofpoint AI and Human Risk Landscape Report</u></a> revealed that half of organizations using AI-based security controls still experienced suspicious or confirmed AI-related incidents. </p><p>There is a fundamental security gap in many organizations: AI adoption has outpaced the right security measures. In the report, nearly 9 in 10 (87%) organizations had moved AI assistants beyond the pilot stage, and 76% were actively piloting or rolling out autonomous agents. But that activity has outpaced security maturity: 63% had AI security controls in place, but 52% weren’t completely confident those controls would detect a compromised AI. </p><p>AI tools are embedded directly into communications to increase productivity and speed, but in the rush to be efficient and compete, AI permissions and access to sensitive data are being left unchecked. </p><p>These aren’t complex security engineering problems: they are organizational and process gaps that can be addressed without waiting for the tooling market to mature. Currently, only a few organizations have developed their incident response playbooks, logging coverage, or forensic tools needed to investigate a compromised AI agent. </p><p></p><p>For many businesses lacking the in-house skills needed to take on these items, which can be significant, contracting a trusted managed service provider (MSP) can help bridge the gap. Many MSPs have been assisting businesses with AI adoption for some time now, and many have the deep understanding and technical skills needed to help businesses of all sizes see tangible benefits to AI while keeping critical data safe.</p><h2 id="the-origins-of-ai-attacks">The origins of AI attacks </h2><p>Most attacks start with unrestrained access and end with autonomous systems exposing sensitive data from these environments. When threat actors target agentic systems that lack proper controls, they don’t need to trick employees to access internal intelligence; they only need to manipulate the AI. </p><p>Prompt injection attacks are a common way to do this. A bad actor might send a target user seemingly helpful AI instructions while posing as a trusted authority or co-worker. A well-intentioned employee may then ask an AI to answer what seems like a simple inquiry. </p><p>Depending on the attacker’s instructions, the AI agent may instead be tricked into reading manipulated webpages (i.e., white text on a white background) to unwittingly extract internal data and send it to the attacker’s server.</p><p>For prompt injection attacks, it’s important to limit AI agents’ access to only the tools and data they need to complete the designed task. This is a good solution to prevent AI from giving out more information than required. This can limit the scope of an external threat actor’s reach.</p><p>That said, the employee’s role isn’t lost in all AI-based attacks. An ongoing cybersecurity skills gap severely impacts defenses, and threat actors know this. </p><p>Over the last decade, multi-factor authentication (MFA) has been an important step toward stronger security authentication. But today, attackers can pair AI-generated phishing with ‘MFA bypass kits,’ such as open-source Evilginx (known as a penetration testing utility for these styles of attacks) and the W3LL panel (a private phishing kit) to deceive employees into handing over that ‘extra step’ of security. </p><p>Tools like Evilginx and the W3LL phishing kit are used to create realistic sign-in pages that mimic those of Google, Microsoft, and others. Without proper security training, employees may unwittingly be signing into these while attackers capture their session tokens – even those with MFA. </p><p>A good defense against MFA bypass kits is adopting phishing-resistant MFA technologies such as FIDO2 hardware keys, Windows Hello for Business, Certificate-based Authentication (CBA), and Passkeys. These methods are tied to legitimate sign-in pages and don’t work on fake pages. </p><p>However, stopping the threat from ever materializing starts with having proper cybersecurity awareness training. Nearly half of all organizations lack this training or simply adopt a checkbox approach, which is why implementing these programs is an important step to closing the gap. </p><p>These programs teach users to spot a myriad of cyber threats, including AI-based threats. Tools of this type are also a good example of using AI in defensive security, as some can leverage AI to customize the training an end user receives based on their performance in past training. </p><p>This is another area where MSPs are highly qualified to assist. MSPs typically run training programs across a vast number of users and industry types. They understand what training works and what doesn’t, and can help position the best security awareness training for a given organization.</p><h2 id="how-does-ai-enhance-threat-detection">How does AI enhance threat detection?</h2><p>To understand the power and importance of AI-powered cybersecurity, it helps to understand how it works. Once trained, a detection model becomes exceptionally good at spotting the characteristics of malicious activity. It can take into account thousands of different characteristics to spot anomalies, outliers, and similarities that humans are unable to correlate. </p><p>It’s important to have a reliable cybersecurity service provider with REAL AI skills, because machine learning systems aren’t perfect and (while rare) can produce false positives. A strong partner can minimize these false positives while offering real-time threat detection and analysis, as well as faster, well-informed response times. </p><p>A trusted MSP will have a wide range of capabilities and will have a deep understanding of the protection methods that work well within their target industries. By leveraging that deep knowledge from their partner MSPs, businesses will benefit from great protection, even with today’s AI-powered attacks.</p><h2 id="preparedness-in-2026-and-beyond">Preparedness in 2026 and beyond</h2><p>To operate in this new era, businesses must treat every AI agent as a high-risk workload identity. </p><p>In practice, this requires working with reputable MSPs to implement strict least-privilege access to avoid data leaks, constant monitoring to protect the integrity of the data, and comprehensive employee awareness training.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why real SaaS resilience means breaking free of the hyperscaler ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Organizations have standardized on Microsoft 365 and a handful of SaaS platforms because it simplifies operations. But that consolidation comes at a cost most businesses have not fully reckoned with: the more workloads, identities, and protection capabilities are concentrated inside a single hyperscaler ecosystem, the less control an organization actually has over its own data.</p><p>For managed service providers (MSPs), that loss of control is becoming the central question in customer conversations.</p><p>Customers are becoming more aware of the operational risks that arise when productivity, collaboration, identity management, storage, and data protection all reside within the same hyperscaler environment. The concern is not that cloud platforms are inherently unreliable. It is that when production and protection both depend on the same provider, the same infrastructure, and the same sub-processors, businesses have effectively handed over control of the one thing they cannot afford to lose: the ability to recover their data on their own terms.</p><p>As a result, many enterprises are re-evaluating how they approach SaaS data protection and recovery. In place of an all-in-one approach, a growing number are insisting on independence: backup, recovery, and long-term data control that sit outside the primary SaaS platform and outside its underlying hyperscaler. That independence is the foundation of data sovereignty, and it is becoming a requirement rather than a preference.</p><h2 id="when-consolidation-creates-new-risks">When consolidation creates new risks</h2><p>The move to SaaS has delivered clear benefits. IT teams can reduce infrastructure complexity, users gain access to powerful collaboration tools, and businesses can scale more easily than ever before.</p><p>Yet consolidation has a trade-off.</p><p>When critical business functions are concentrated within a single ecosystem, resilience becomes entirely dependent on that ecosystem's continued availability, policies, and goodwill. For many companies, this has prompted a sharper conversation about dependency, control, and recoverability, one that goes beyond uptime and asks who ultimately holds the keys to their data.</p><p>Questions that rarely surfaced a few years ago are becoming more common. What happens if access to a platform is disrupted? How quickly can data be recovered? Does recovery depend on the same environment that is being protected?</p><p>These are not necessarily concerns driven by major outages or worst-case scenarios. More often, they reflect a growing understanding that resilience depends on having options when something unexpected happens.</p><h2 id="the-emergence-of-the-layered-protection-model">The emergence of the layered protection model</h2><p>In response, businesses are increasingly looking to separate production environments from protection environments.</p><p>Rather than relying on a single provider for productivity, backup, and recovery, businesses are introducing independent layers of protection that sit outside their primary SaaS platform and outside the hyperscaler infrastructure underneath it. Redundancy within the same provider is not independence. If a backup runs on the same cloud as the SaaS application it protects, there is no real separation between production and protection.</p><p>Most customers are not looking to move away from Microsoft 365. What they're looking for is greater separation between the platforms they use every day and the systems they rely on for recovery. That's why there is increased interest in layered protection approaches that reduce operational dependency on a single ecosystem.</p><p>This approach reflects a broader shift in mindset. Customers are shifting from viewing backup as a standalone requirement and toward viewing protection as part of an overall resilience strategy.</p><p>For MSPs, the layered model provides a practical framework for discussing business continuity, recovery, and operational risk without requiring customers to rethink their existing SaaS investments.</p><h2 id="recovery-is-becoming-part-of-the-buying-decision">Recovery is becoming part of the buying decision</h2><p>One of the most noticeable changes in customer conversations is the growing focus on recovery itself.</p><p>Historically, data protection discussions often centered on storage capacity, retention periods, and feature sets. Today, customers are asking more detailed questions about recoverability.</p><p>Can data be restored independently? How long will recovery take? Has the process been tested? What dependencies exist if access to the primary environment is unavailable?</p><p>These questions reflect a broader shift in purchasing behavior, and the emphasis on recoverability is not theoretical. Recent industry research shows that enterprises are placing greater importance on recovery outcomes, testing, and operational resilience than they did just a few years ago, reflecting a broader shift from protection-focused to recovery-focused decision-making.</p><p>For channel partners, this creates opportunities to deliver services that extend beyond implementation and management. Recovery testing, resilience assessments, continuity planning, and governance support are becoming more prominent as customers seek greater visibility into their recovery posture.</p><p>The conversation is gradually moving from "Is my data backed up?" to "Can I get it back when I need it?"</p><h2 id="why-sovereignty-is-following-the-same-path">Why sovereignty is following the same path</h2><p>Most companies do not begin these conversations by talking about sovereignty.</p><p>More often, sovereignty enters the discussion after customers start examining recovery, resilience, and dependency risks.</p><p>As businesses evaluate where their data resides and how it can be recovered, questions naturally emerge around control, access, jurisdiction, and ownership. What begins as a resilience discussion quickly becomes a sovereignty discussion, and most companies are working with a far narrower definition of sovereignty than the one that actually applies to them.</p><p>This is one reason sovereignty is becoming a more visible consideration in purchasing decisions, not a box to check after the fact. It is increasingly being viewed through the lens of operational resilience and vendor independence rather than as a standalone compliance requirement, because compliance alone does not tell a business who can actually reach its data when it matters most.</p><p>For MSPs, that creates an opportunity to help customers see past the marketing language and understand how recovery, resilience, compliance, and data control intersect, and where the gaps are when all of it sits inside one hyperscaler's walls.</p><p>The businesses pursuing this kind of protection are rarely pursuing a single objective. They want confidence that critical information remains accessible, recoverable, and genuinely under their control, not control as defined by the hyperscaler's terms of service, but control they can verify and exercise themselves, regardless of the circumstances.</p><p>The most significant shift is not the technology itself, but the questions customers are asking.</p><p>As companies become more dependent on SaaS platforms, they are taking a harder look at the assumptions behind their protection strategies. Increasingly, they are unwilling to accept recovery capabilities that depend on the same hyperscaler, the same infrastructure, or the same sub-processors as the environment being protected, and they want clarity around exactly where that dependency still exists.</p><p>That is ultimately what this shift represents: not a rejection of hyperscaler platforms, but a refusal to let them define the limits of recovery. Resilience, and the sovereignty that underpins it, is strongest when the systems a business depends on to get its data back do not answer to the same provider, the same infrastructure, or the same jurisdiction as the systems being protected.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/cloud/saas/why-real-saas-resilience-means-breaking-free-of-the-hyperscaler</link>
                                                                            <description>
                            <![CDATA[ Breaking hyperscaler dependency creates stronger SaaS resilience, recovery, and data sovereignty ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4AnBWaAp3G2rcWYapngjyi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/R6w25DnbMVLjXCWkp7tVkh-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 11 Aug 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[SaaS]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jan Ursi ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/pWsjoNvF6VGwZ2hTrVRPVD-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/R6w25DnbMVLjXCWkp7tVkh-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cloud computing concept image showing a cloud symbol with electricity flowing to it, signifying cloud uptime capabilities. ]]></media:description>                                                            <media:text><![CDATA[Cloud computing concept image showing a cloud symbol with electricity flowing to it, signifying cloud uptime capabilities. ]]></media:text>
                                <media:title type="plain"><![CDATA[Cloud computing concept image showing a cloud symbol with electricity flowing to it, signifying cloud uptime capabilities. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/R6w25DnbMVLjXCWkp7tVkh-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Organizations have standardized on Microsoft 365 and a handful of SaaS platforms because it simplifies operations. But that consolidation comes at a cost most businesses have not fully reckoned with: the more workloads, identities, and protection capabilities are concentrated inside a single hyperscaler ecosystem, the less control an organization actually has over its own data.</p><p>For managed service providers (MSPs), that loss of control is becoming the central question in customer conversations.</p><p>Customers are becoming more aware of the operational risks that arise when productivity, collaboration, identity management, storage, and data protection all reside within the same hyperscaler environment. The concern is not that cloud platforms are inherently unreliable. It is that when production and protection both depend on the same provider, the same infrastructure, and the same sub-processors, businesses have effectively handed over control of the one thing they cannot afford to lose: the ability to recover their data on their own terms.</p><p>As a result, many enterprises are re-evaluating how they approach SaaS data protection and recovery. In place of an all-in-one approach, a growing number are insisting on independence: backup, recovery, and long-term data control that sit outside the primary SaaS platform and outside its underlying hyperscaler. That independence is the foundation of data sovereignty, and it is becoming a requirement rather than a preference.</p><h2 id="when-consolidation-creates-new-risks">When consolidation creates new risks</h2><p>The move to SaaS has delivered clear benefits. IT teams can reduce infrastructure complexity, users gain access to powerful collaboration tools, and businesses can scale more easily than ever before.</p><p>Yet consolidation has a trade-off.</p><p>When critical business functions are concentrated within a single ecosystem, resilience becomes entirely dependent on that ecosystem's continued availability, policies, and goodwill. For many companies, this has prompted a sharper conversation about dependency, control, and recoverability, one that goes beyond uptime and asks who ultimately holds the keys to their data.</p><p>Questions that rarely surfaced a few years ago are becoming more common. What happens if access to a platform is disrupted? How quickly can data be recovered? Does recovery depend on the same environment that is being protected?</p><p>These are not necessarily concerns driven by major outages or worst-case scenarios. More often, they reflect a growing understanding that resilience depends on having options when something unexpected happens.</p><h2 id="the-emergence-of-the-layered-protection-model">The emergence of the layered protection model</h2><p>In response, businesses are increasingly looking to separate production environments from protection environments.</p><p>Rather than relying on a single provider for productivity, backup, and recovery, businesses are introducing independent layers of protection that sit outside their primary SaaS platform and outside the hyperscaler infrastructure underneath it. Redundancy within the same provider is not independence. If a backup runs on the same cloud as the SaaS application it protects, there is no real separation between production and protection.</p><p>Most customers are not looking to move away from Microsoft 365. What they're looking for is greater separation between the platforms they use every day and the systems they rely on for recovery. That's why there is increased interest in layered protection approaches that reduce operational dependency on a single ecosystem.</p><p>This approach reflects a broader shift in mindset. Customers are shifting from viewing backup as a standalone requirement and toward viewing protection as part of an overall resilience strategy.</p><p>For MSPs, the layered model provides a practical framework for discussing business continuity, recovery, and operational risk without requiring customers to rethink their existing SaaS investments.</p><h2 id="recovery-is-becoming-part-of-the-buying-decision">Recovery is becoming part of the buying decision</h2><p>One of the most noticeable changes in customer conversations is the growing focus on recovery itself.</p><p>Historically, data protection discussions often centered on storage capacity, retention periods, and feature sets. Today, customers are asking more detailed questions about recoverability.</p><p>Can data be restored independently? How long will recovery take? Has the process been tested? What dependencies exist if access to the primary environment is unavailable?</p><p>These questions reflect a broader shift in purchasing behavior, and the emphasis on recoverability is not theoretical. Recent industry research shows that enterprises are placing greater importance on recovery outcomes, testing, and operational resilience than they did just a few years ago, reflecting a broader shift from protection-focused to recovery-focused decision-making.</p><p>For channel partners, this creates opportunities to deliver services that extend beyond implementation and management. Recovery testing, resilience assessments, continuity planning, and governance support are becoming more prominent as customers seek greater visibility into their recovery posture.</p><p>The conversation is gradually moving from "Is my data backed up?" to "Can I get it back when I need it?"</p><h2 id="why-sovereignty-is-following-the-same-path">Why sovereignty is following the same path</h2><p>Most companies do not begin these conversations by talking about sovereignty.</p><p>More often, sovereignty enters the discussion after customers start examining recovery, resilience, and dependency risks.</p><p>As businesses evaluate where their data resides and how it can be recovered, questions naturally emerge around control, access, jurisdiction, and ownership. What begins as a resilience discussion quickly becomes a sovereignty discussion, and most companies are working with a far narrower definition of sovereignty than the one that actually applies to them.</p><p>This is one reason sovereignty is becoming a more visible consideration in purchasing decisions, not a box to check after the fact. It is increasingly being viewed through the lens of operational resilience and vendor independence rather than as a standalone compliance requirement, because compliance alone does not tell a business who can actually reach its data when it matters most.</p><p>For MSPs, that creates an opportunity to help customers see past the marketing language and understand how recovery, resilience, compliance, and data control intersect, and where the gaps are when all of it sits inside one hyperscaler's walls.</p><p>The businesses pursuing this kind of protection are rarely pursuing a single objective. They want confidence that critical information remains accessible, recoverable, and genuinely under their control, not control as defined by the hyperscaler's terms of service, but control they can verify and exercise themselves, regardless of the circumstances.</p><p>The most significant shift is not the technology itself, but the questions customers are asking.</p><p>As companies become more dependent on SaaS platforms, they are taking a harder look at the assumptions behind their protection strategies. Increasingly, they are unwilling to accept recovery capabilities that depend on the same hyperscaler, the same infrastructure, or the same sub-processors as the environment being protected, and they want clarity around exactly where that dependency still exists.</p><p>That is ultimately what this shift represents: not a rejection of hyperscaler platforms, but a refusal to let them define the limits of recovery. Resilience, and the sovereignty that underpins it, is strongest when the systems a business depends on to get its data back do not answer to the same provider, the same infrastructure, or the same jurisdiction as the systems being protected.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>