Thought Leadership by André Kannemeyer, CEO Technology Officer at Duxbury Networking
Every cybersecurity recommendation carries the reseller’s name with it. When a platform performs well, the customer sees a sound technology decision. When it generates noise, misses activity, requires constant specialist tuning, or slows the response to an incident, the reseller’s judgement comes under scrutiny alongside the product.
That makes evidence increasingly important in channel conversations. Security vendors all promise better detection, broader visibility, faster response, and simpler operations. Feature lists can show what a platform contains, but they offer limited insight into how effectively those capabilities work together when an attacker begins moving through a real environment.
Proof must reflect operating reality
A security platform rarely enters a laboratory-perfect customer environment. It may need to protect Windows endpoints, Linux servers, cloud workloads, identities, email, mobile devices, and third-party systems. The customer may have a small internal team, limited time for configuration, and little appetite for months of fine-tuning before the technology delivers useful protection.
Independent evaluations can help the channel examine performance under defined conditions. The 2025 MITRE ATT&CK Enterprise Evaluations used adversary behaviour associated with Scattered Spider and Mustang Panda across multiple platforms and attack stages. Participating technologies were assessed on the visibility, depth, and accuracy of their detections, along with their ability to prevent simulated malicious activity.
The value lies in examining what a platform could see, how precisely it explained that activity, what it prevented, and how much configuration was required during the process.
Default performance deserves attention
Cynet recorded 100% detection visibility, 100% technique-level coverage, and 100% protection in the initial run of the 2025 evaluation. It also recorded zero detection false positives and required zero configuration changes. The evaluation included Windows, Linux, and AWS environments. Each measure speaks to a different operational concern.
Detection visibility shows whether the platform collected the relevant telemetry during the simulated attacks. Technique-level coverage indicates whether it converted that activity into useful, contextual detections rather than relying on vague or general alerts. Protection indicates whether adversary actions were stopped, while the false-positive result reflects the accuracy of the alerts produced during the evaluation.
The absence of configuration changes is especially relevant for resellers serving customers with lean security teams. Strong performance that depends on extensive specialist intervention can be difficult to reproduce consistently across several customer environments. A platform that performs effectively in its default state can shorten deployment effort and reduce the operational burden placed on the partner and customer.
These results should never replace a proper assessment of the customer’s environment. They do, however, give the channel something more useful than a marketing claim. They provide transparent evidence that can be examined, challenged, and placed alongside the customer’s own requirements.
Alert quality affects service delivery
Visibility alone does not give a customer an effective security operation. A platform may collect large volumes of data and still leave the team struggling to understand which activity is dangerous and what should happen next.
Poor alert quality creates work. Analysts investigate benign events; urgent signals compete with background noise; and response slows as teams move between products and consoles. For an MSP supporting several customers, that inefficiency becomes difficult to absorb at scale.
The channel should therefore consider the relationship between detection accuracy and the work required after an alert appears. High-fidelity detections can help partners focus their resources, respond with greater confidence, and build services that remain manageable as the customer base grows.
Technology still needs an operating model
Validated platform performance is one part of the decision. Customers also need the people, processes, and response authority required to act when a threat is confirmed.
Cynet combines its unified, AI-powered platform with CyOps, a 24×7 managed detection and response team that monitors, investigates, and responds across protected environments. The platform spans endpoints, users, identities, networks, email, SaaS, cloud, and mobile security, enabling the assessment of signals from different parts of the attack path.
The CyOps service gives customers different levels of operational control. In a collaborative model, analysts validate threats and provide a remediation plan for the customer to execute. ProActive CyOps can perform pre-approved containment actions, including isolating a host or disabling a compromised Active Directory or Microsoft 365 user, without waiting for approval during the incident.
That flexibility helps resellers match the response model to the customer’s internal capability rather than assuming that every organisation has a staffed security operations centre ready to act around the clock.
Evidence strengthens the channel relationship
Duxbury Cybersecurity can help partners interpret technical evidence, assess customer risk, and connect platform capabilities to a supportable operating model. Independent results should form part of a disciplined recommendation process rather than being treated as a complete customer decision.
The strongest channel partners understand what the customer needs the platform to detect, how much tuning the environment can support, who will investigate alerts, and who has authority to contain an active threat. Those considerations turn test performance into a practical security service.
Cybersecurity claims will continue to multiply because producing them is easy. Resellers protect their reputation by asking for evidence, understanding what the evidence shows, and recommending protection they can defend with confidence.
