Coffee with Craig and James · 2025-12-02 · 26 min
Key moments - from our scoring
Substance score
36 / 100
Five dimensions, 20 points each
With cybercrime projected to cost $10.5 trillion annually - equivalent to the world's third-largest economy - IT leaders face mounting pressure to do more with constrained budgets and smaller teams. Neil Burton argues that the traditional approach of layering point products creates dangerous blind spots, alert fatigue, and burnout rather than stronger defenses. Instead, he advocates for platform consolidation built on identity and access management, zero-trust networking, unified visibility, and AI-driven analytics. The episode emphasizes that SMBs are particularly vulnerable due to underserved vendor offerings, while enterprise teams waste resources managing disconnected tools. Burton provides a concrete framework for IT leaders pitching consolidation to executives: lead with TCO analysis and license savings quantification, highlight operational efficiency gains (freeing security talent from tool babysitting), then layer in risk reduction and breach response improvements. He addresses common concerns that simplification means cutting corners - arguing that most security tools use identical data and engines, so consolidation doesn't degrade efficacy. Partners and MSPs gain specific advantages: resellers can guide customers through platform journeys while retiring redundant products, while MSPs can onboard more customers faster using single-tenant platforms where AI learnings transfer across accounts.
Professionalization of cybercrime (ransomware-as-a-service, organized specialized skills), cloud adoption and remote working (expanding attack surface and insecure endpoints), and generative AI enabling highly personalized large-scale phishing and social engineering attacks.
Identity and access management for continuous verification; zero-trust networking replacing VPNs; enhanced visibility consolidating fragmented tool data into a single data lake with context; and AI and analytics at the core for faster detection and automated response.
Lead with financial metrics showing current TCO and licensing sprawl, project specific savings (e.g., consolidating four tools into one platform saves X million), then highlight operational efficiencies like reallocating security talent from tool management to proactive risk management, and finally address risk reduction through faster breach detection and response times.
No - most security products use the same underlying data, intelligence, and logic, so paying more for fragmented tools doesn't provide better detection or trap more threats than a consolidated platform; efficacy remains consistent while costs and operational burden decrease.
MSPs can onboard more customers faster using a single multi-tenant platform, and AI learnings from one customer transfer to reduce time-to-value with new accounts; resellers can guide customers through platform consolidation journeys that retire redundant tools and simplify management.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains a reasonable density of statistics (breach costs, ransomware figures, cybercrime-as-economy framing) and a structured framework for executive buy-in, but most of the core content - tool sprawl bad, platform good, reduce noise with AI - is standard cybersecurity vendor narrative with little that a B2B IT leader hasn't encountered before.
By consolidating these four current tools into a single platform, we will save X million dollars in license fees. You have a CFO leaning forward then
by reducing this tool management overhead by 30% allows us to reallocate $100,000 of salary cost from babysitting tools to proactive risk management
Platform consolidation versus point-solution sprawl is one of the most recycled narratives in enterprise cybersecurity; the cybercrime-as-third-largest-economy comparison is a widely circulated stat, and the advice to lead with TCO then pivot to risk is textbook. The one mildly candid observation - that most security tools use the same underlying data and logic - is the only moment that cuts against typical vendor self-interest.
If cybercrime was an economy, for example, it would be the third largest economy in the world
the data, the intelligence behind many of these security products is the same data, the same rules, and the same logic. So you're not really missing anything out
Neil Burton is VP/GM EMEA at Coro Cybersecurity with a go-to-market and partner ecosystem background - relevant but positioned as a vendor executive selling a platform story rather than a CISO or IT operations leader who has lived the problem at scale; his insights skew toward GTM and sales framing rather than deep practitioner experience.
He's a top performing business leader with a proven history in driving IT services and solutions growth
He's known for the development of compelling go-to-market strategies for either in-house sales teams or with partner or alliance ecosystems
The guest cites several concrete figures (average breach cost near $5M, SMB breach range of $120K - $1.24M, 30% of breaches from phishing, $2M average ransomware payout, ransomware every two seconds by 2031) which add credibility, but no sources are named and the numbers are standard Cybersecurity Ventures industry figures; the executive-pitch example uses hypothetical placeholders rather than real named cases.
The average cost of a breach now is about just under $5 million for one breach
Last year, we kind of topped out $2 million for the average ransomware payout
The host asks long, multi-part leading questions that telegraph the desired answer and never challenges the guest on any claim; there is no pushback, no probing follow-up, and no productive tension - the conversation functions as a structured vendor briefing rather than an interview.
What fundamental shift in security strategy must IT leaders adopt in order to move away from simply adding tools and instead consolidate their defense and mitigate staff burnout?
And that makes sense because it's a matter of getting, not just stacking layer upon layer, but getting that efficiency
Computed from the transcript - who did the talking, and the words that came up most.
Transcribed and scored by The B2B Podcast Index.
Hello and thank you for joining us today. It's no secret that we live in a business environment of increased threats and resource scarcity that imposes unsustainable pressure on global IT teams. In fact, the cost of cybercrime is projected to reach $10.5 trillion in the not-too-distant future.
And that's further complicated by widespread budget constraints and the cybersecurity skills gap. On top of all this, security teams are struggling with tool overload and vendor sprawl. Simplification is more important than ever before. There's an imminent need to shift away from a collection of separate tools in favor of a unified platform that enables organizations to select necessary functionalities and scale cost effectively.
We'll discuss these topics and explore a number of best practices. I'm your host, Ken Presti. Our guest today has built a career out of leveraging partner ecosystems to generate hyper growth in targeted markets. He's a top performing business leader with a proven history in driving IT services and solutions growth, as well as in near-term and long-term strategic planning.
He's known for the development of compelling go-to-market strategies for either in-house sales teams or with partner or alliance ecosystems. He's the vice president and general manager for Europe, Middle East, and Africa at Coro Cybersecurity. I want to welcome Neil Burton. Neil, thanks for joining us today.
Glad to have you on board. Thanks for taking time out to field some of these questions for us. Thank you, Ken. Thanks for inviting me and a great introduction.
I almost didn't recognize myself. Anyway, in the challenging climate of do more with less, and we see that all the time, budgets are getting cut, expectations are raising. What fundamental shift in security strategy must IT leaders adopt in order to move away from simply adding tools and instead consolidate their defense and mitigate staff burnout? Wow.
That's a question. I put it all in one giant question. Yeah. Well, let's unpack that a little bit.
You talk about doing more with less. You mentioned $10.5 trillion cyber crime costs. Trillion with a T.
That's $255,000 a second. Now, 10 years ago, that was only $3 trillion, not $10.5 trillion. So this is huge.
The average cost of a breach now is about just under $5 million for one breach. You're given the fact that 99% of companies out there are SMB companies. Now, their costs, the cost of a breach for them is a lot smaller, maybe $120,000 to a 1.24 million, but the impact is much higher for them because it puts them out of business.
Phishing scams with AI is getting significantly easier, and they're hooking more. Nearly 30% of all global breaches come from a phishing scam now. Ransomware, which has got to be the most lucrative attack. Last year, we kind of topped out $2 million for the average ransomware payout.
By 2031, it's predicted that ransomware attacks will hit businesses every two seconds. So this is not do a little bit more with less. This is doing a hell of a lot more because of the because of the growth in cybercrime. If cybercrime was an economy, for example, it would be the third largest economy in the world.
You've got the US economy, was it 28, 29 trillion? You've got China's economy, maybe 18, 19 trillion. And then you've got cybercrime. The number four and five in Japan and Germany is a mere 4.
3 trillion. So you could see the size of the problem that organizations have to deal with. Right. Right.
And we're seeing a lot of that, like you said, at the SMB level, because I think the cyber criminals look at SMB and think, OK, well, these people don't necessarily have the same level of assets. They don't have the same level of expertise. Some of them, they don't even have a real IT person there. It's just somebody who kind of knows this stuff and chips in to take care of things while they're doing other jobs.
Is that what you see is what's primarily fueling those attacks on SMB? I guess, yes. And I think we can unpack that a little bit more later on. The SMB customers have been underserved by the vendors in the market that sell.
that enterprise-class vendors selling at enterprise organizations almost leave SMBs wanting. It's too expensive for these tools to be bought by SMB. It's too hard to administer. In terms of what's fueling this growth, I think there's a few things.
I think the professionalism of crime is a driver. Cybercrime is a really lucrative thing. If it wasn't massively illegal, then I'm sure it will grow quicker. But it's a very lucrative business, highly organized with specialized skills.
You could buy a ransomware as a service offering on the dark web if you knew where to look for dollars. It's a professionalized industry now. Another thing that's driving it is cloud adoption and remote working, which is applicable to SMB and enterprise with the rapid adoption of cloud and people working from home The attack surface for a nasty is much wider and it provided a lot more secure insecure endpoints And I guess the last thing for me and I only seen it in the last couple of years, is generative AI is creating very highly personalized, large-scale attacks, particularly phishing attacks or social engineering attacks.
So it's kind of increasing the performance of cyber attacks. So those three things are probably fueling the drive of cybercrime. So you've outlined a pretty steep hill to climb. And I think a lot of companies have kind of approached this by filling in the gaps as they go, because it appears to be the closest way to connect the dots as they find issues that things go wrong.
So what would you say is the most significant and often overlooked operational risk or hidden cost of security stack complexity? And let's go beyond licensing fees that you see impacting global business today. And why is platform consolidation the way to go? Yeah, and I don't think it's just, I don't think we should completely leave license fees, because I think that's got a place to play.
But in terms of the overlooked, let's come back to the complexity of how people are having to manage that. A complex security stack with many, many tools creates this myriad of alerts and this sea, this flood of alerts that come into an organization. And with multiple tools, you have gaps between each one of them that attackers are trying to exploit. So not only is the buy multiple tools potentially adding to the problem because it's directing attacks between the tools, but it's also having an effect on employees.
So one of the overlooked implications are employees in this market are just getting burnt out. The problem is not having too many tools. I guess the problem is having too many disjointed tools that don't natively communicate with each other. And I think it just drives blind spots within an organization's security platform that can be exploited.
So as you look at multifunction platforms as a solution to this disjointedness that you're talking about, if I'm an IT guy and I'm looking at all this, what are some of the key capabilities that I should be looking at in terms of seeing this unified platform come together and making sure that I've got my bases covered? Yeah, and I think that's a good question, because what we're looking at now is moving away from the proliferation of tools into more of a platform approach to cybersecurity, a singular platform, a platformization.
If that is such a word, if it's not a word, I want to make it a word, platformization of your security posture. And I think if you start moving from disparate tools into a platform basis, a few things need to manifest itself. Firstly, identity and access management. So the thing that you're looking for is really solid identity and access management.
So the continuous verification of every user, of every device, attempts to gain access, regardless of its location. That's one thing. The second thing that these platforms need to deliver you is effectively a zero-trust network, something that replaces typical VPNs, that allows access to, you know, least privileged access to the parts of an application and the data rather than the whole thing. And once you kind of look for that in a platform, you're looking for things that help, that then help you do the job that you're supposed to do.
Enhanced visibility and context, bringing together everything that's going on, everything that's going on in fragmented tools and bringing it into a single data lake is one thing. Because then you can apply context to it. So just having someone, having a failed login over here means nothing, or a data access over there means that you bring it in and then you've got AI began. Actually there's 50 failed attempts to log in there.
And then that user logged in at two o'clock in the morning and downloaded 10 meg of data. Then to get those things together, create a high fidelity event that you should work on. separate and not jointed would never show the story. So there's a few things that a platform needs to drive.
That in advance, the bit of busy AI and analytics at its core allows you to faster detect and automate responses, allows you to drive consistent policy that is more than just one tool at a time. There's many benefits that you'd get from a platform in this space. Neil, how can I discern what should be automated through AI and what shouldn't be? I mean, obviously, I'm going to be looking at efficiencies, but I also want to make sure that I'm preserving the safety and the security of the infrastructure and any of the people issues even that go on.
What are some of the things that I should be looking at and saying, okay, I'll automate this, but maybe not that thing over there? Yeah. I guess that becomes a little bit more customer by customer specific. I think in terms of noise reduction if your platform with AI doesn reduce 90 of the noise then you bought the wrong one First thing I was like, let's get 90% of the noise away from people.
So you don't have to that. I heard the phrase the other day of swivel cherry. You can imagine a security analyst with multiple consoles all being thrown alerts and swinging from one to the other. It's just an overload onto people.
So firstly, get rid of the noise. The second thing is just to establish a set of policy-based runbooks that you can get AI to act on your behalf. Half of resets are simple. Sandboxing particular endpoints is simple.
You really want to get to the point where the only manual intervention is for 1%, 2%, 3% of the events that are going on. But then it just becomes very, very customer specific. RAOUL PAL, Customer specific or vertical specific, do you think? Yeah, I think both go hand in hand.
I think customers, I think vertically, are you exposed to a different sort of attack if you're a bank than if you're a shop? I don't know whether you are, but certainly different customers based on their risk profile And based on the framework, the foundation they've chosen to guide them, will have different propensities to automate than others, in my opinion. I understand. Yeah, yeah.
That makes sense. So here I am. I'm an IT leader, and I'm thinking about the things we've been discussing up until now. And now I'm going to have to go to my executive leadership and get budget for the changes that I want to make.
And this comes down to the age old question of I.T. security. We've been struggling with this one for decades now, but I've got to go in there and I've got to make a pitch for the expenditure of money on something that may not have happened before.
But I need to take my executive leadership and convert them into true believers in order to get them to spend this money. What are some of the things that you would recommend that I do to bring this across the line? What do I need to explain to them? What do I need to make them see?
Yeah, it's a great scenario to play out in my head. So if the question is, how do I gain that strategic buying on my exec for my leadership group in order to make the changes? It's not to buy something new. It's to make kind of strategic and fundamental changes that increase the security posture.
There's a few things. If you look into frame, you've got to frame the discussion around security simplification. focusing on business value, predominantly financial benefit, and risk reduction. Yeah, the people in the room that you're presenting to are going to want facts.
They're not going to want stories necessarily. They're going to want facts. And my advice would be start with something that's facts-based. Start with the reduction in complexity and cost.
So do a piece of assessment that says the current state and how you measure the cost there. TCO, present the current state highlighting the sprawl of overlapping tools. Quantify the cost of ownership of the current multi-vendor stack, including licensing, maintenance, support contracts. You want to be showing the projected cost savings.
So if you're standing there and saying, by consolidating these four current tools into a single platform, we will save X million dollars in license fees. You have a CFO leaning forward then, clearly. Then you move on to operational efficiencies, highlight the hidden costs associated with running complex multiple tools, show how a simplified unified stack with a single console or free up highly paid security people's talent. Can you imagine that the simplification of, by reducing this tool management overhead by 30% allows us to reallocate $100,000 of salary cost from babysitting tools to proactive risk management.
You've got potential CFO high-fiving you at the table there. I guess then once you've established the case with financial metrics, then you can move on to the long-term values. So this is where you pivot towards conversations around enhanced risk reduction through integration gives you this. So cyber attacks exploit the gaps between these security tools, therefore a consolidated stack enables you to share intelligence, et cetera, move that onto an improved breach response and resilience allows us to, you know, a consolidated stack allows us to respond faster and reduce breach and reduce the time that attackers are inside our systems.
And this goes to quite a nice insurance payout metric. So you need to be looking at industry data to say that by taking this journey we can detect quicker we can save days or hours in finding nefarious people in our systems which translates into tens of millions of dollars in the event of a major incident or long investment or brand protection So I would say you start with finance and move on to the long protective value Sure And I hearing that the C is becoming more they're more open to these discussions than they were some time ago, because it's become so pervasive.
IT security issues have become so pervasive. Yet at the same time, they're getting pulled in a lot of different directions financially, and they're looking for ways to cut costs. Let's change the subject a little bit to something about the channel partners with respect to how does this unified approach help the partners to onboard and manage their clients more effectively? And I think this is especially important in the SMB space where they're looking to collect more customers than, say, a large integrator that can focus on a couple of key accounts and build a very solid business from there.
No, it's a good point. And I think when you use the word partners, slightly different whether you're talking about reseller partners or MSPs. But fundamentally, there is value from a consolidated platform-based business model. If you look at the cybersecurity market at the moment.
There's thousands of vendors that you can base your stack on if you're a partner, if you're an MSP, or base your advice on if you're a trusted advisor as a reseller. How do you get your head around trying to work out what's the best products to use or to propose? When there's a thousand different cybersecurity companies out there, or selling snake oil to customers for problems that that customer doesn't know they've got yet? And how do you mitigate yourself with one of those vendors that you propose changes its licensing model, like a Broadcom did recently, and then shifts the whole demographic of that, the dynamic of that market?
So I think a couple of things. If you're a partner, it depends on your persona. If you're a reseller partner, your approach should be take the customer on the journey we've just talked about. Take the customer on a platform journey, which helps each individual customer retire redundant and unused point products and take advantage of AI and centralised management of a platform.
If you're an MSP, build your stack on a platform-based approach rather than lots of best-of-breed tools, because you can onboard a lot more customers quicker and simpler is you've just got one platform to manage that is multi-tenant, that is visual, that you're using AI. Lessons that AI have learned with customer one can be transformed into time to value and customer two. So I think there's two answers to that question. In the few moments we've got left, I'm wondering if you can help me crystallize something.
And that is the notion of simplification. simplification can be looked at in a couple of different ways. In one respect, it can be a favorable thing for obvious reasons. On the other hand, there could be the implication that you're cutting corners and you don't want that concern to permeate the people either in the executive suite or even the people that are working for the company.
What's the main thing that you can do in terms of selling the concept of simplification as a good thing and an effective thing? I think some of the things that we spoke about already, which is around simplification, effectively, complexity is the enemy of IT organizations. You're spending far too much of your time with far too many tools to be really productive. And simplifying that with a single tool set has hard and soft financial benefits and risk profiles.
I think also if you kind of look at simplifications, if you look at the security market as a whole, efficacy is a big thing as well. So do I trap more things with product A than I trap with product B? Can I solve more things with product C than I can with product D? Largely, a lot of the tools out there use the same engines and data and lists.
So pretty much products are as efficient as everything else. Just because you're paying a million dollars for something, it doesn't make it more efficient in trapping things than something you've paid 100,000 for. And I think people probably need to understand that, that the data, the intelligence behind many of these security products is the same data, the same rules, and the same logic. So you're not really missing anything out.
You're not degrading your security posture by adopting a more simplified platform story. If that, in my opinion. Right. And that makes sense because it's a matter of getting, not just stacking layer upon layer, but getting that efficiency, getting that cost efficiency, getting that functionality efficiency.
All of those things are really highly important. So Neil Burton, Vice President and General Manager for Europe, Middle East, and Africa at Coro Cybersecurity. Thank you very much for joining us today. I've really enjoyed talking to you.
And thanks to all of our viewers for tuning in. Thank you.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.