
Sign up to save your podcasts
Or


You bought the EDR. You checked every box your insurance renewal asked for. In this Playbook, Max Clark, CEO of ITBroker.com, breaks down why 60% of ransomware victims had a leading EDR product deployed when they got hit, and what the other 40% were doing that they weren't. From the four tools insurance actually requires to the ones nobody budgets for until it's too late, Max walks through the gap between owning a security tool and being protected by one, and the one line item most security budgets are missing entirely.
THE PLAYBOOK
RESOURCES MENTIONED
ABOUT THE SHOW
Signed is the podcast for buyers in a market built for sellers. Playbooks are the solo format — 10 to 15 minutes, one trigger, one specific play. New episodes weekly at itbroker.com/podcast. If the trigger in today's Playbook is one you're facing right now, book an intro call at itbroker.com. We help buyers make the right call the first time. Buy tech without regret. Follow: @itbrokerdotcom
Full Transcript
Click here to view the episode transcript.
Buying Microsoft 365, Google Workspace, or Azure direct feels like the simpler choice, until you need support or get locked out of your own tenant.
In this Playbook, Max Clark breaks down what a Cloud Solution Provider (a CSP) actually does between you and the platform: faster support and escalation, help recovering a locked tenant, engineering and migration support, and access to vendor funding you can't reach on your own, usually at little or no added cost.
If you're deciding whether to buy direct or through a CSP, or renewing that decision without ever having checked it, this one's for you.
The Playbook
About Signed
Signed is the podcast for buyers in a market built for sellers. Playbooks are the solo format, 10 to 15 minutes, one trigger, one specific play. New episodes weekly at itbroker.com/podcast. If the trigger in today's Playbook is one you're facing right now, book an intro call at itbroker.com. We help buyers make the right call the first time. Buy tech without regret. Follow: @itbrokerdotcom
Full Transcript
Which workloads actually belong in public cloud, private cloud, colocation, or bare metal? Jeremy Pease, CEO of Aptum, joins Max Clark to break down how application requirements, infrastructure costs, connectivity, resilience, and scale should determine where your workloads run.
They get into cloud migration and repatriation, why connectivity can cost more than the infrastructure itself, workloads that never needed the scale assumed in the original business case, and a colocation estimate that went from roughly $10,000 a month to $80,000 once the real requirements were modeled.
If you're evaluating a cloud migration, renewal, repatriation, or infrastructure change, this conversation gives you the questions to run before deciding where the next workload belongs.
Before your next migration, renewal, or repatriation decision:
https://www.itbroker.com/blog/cloud-workload-assessment
Jeremy Pease:
https://www.linkedin.com/in/jeremy-pease-a53b972/
Aptum:
https://aptum.com/
More from Signed:
https://www.itbroker.com/podcast
Full Transcript
Click here to view the episode transcript.
You didn't choose your cloud provider. You inherited it, from whoever picked the safe option first and called it a decision. In this Playbook, Max Clark, CEO of ITBroker.com, names what that habit actually costs: three decades of consensus defaults, from the dot com era stack to LAMP to AWS's US East 1, and what the buyers who never questioned any of them paid for it, including the 15 hour outage this past October that took down Snapchat, Venmo, and a foreign government's tax site along with them. One question either ends the habit or exposes that you've never really made this decision at all: compared to what?
The Playbook
Resources Mentioned
About the Show
Signed is the podcast for buyers in a market built for sellers. Playbooks are the solo format, 10 to 15 minutes, one trigger, one specific play. New episodes weekly at itbroker.com/podcast. If the trigger in today’s Playbook is one you’re facing right now, book an intro call at itbroker.com. We help buyers make the right call the first time. Buy tech without regret. Follow: @itbrokerdotcom
Full Transcript
Click here to view the episode transcript.
Approving a technology invoice is not the same as validating it. Tommi Ellis, Channel Director at Intratem, joins Max Clark to explain how companies can tell whether anyone is actually checking telecom and technology bills against contracts, inventory, services, and real usage.
They get into roughly $4,000 a month found sitting unnoticed on a 270-line wireless account, larger audits recovering as much as $1.2 million annually, canceled services that continue getting billed, and why the first invoice after a new contract or service change deserves immediate scrutiny.
They also break down why technology expense management often falls between IT and finance, what happens when years of vendor knowledge leave with one employee, and how a strong contract can quietly stop being a good deal when nobody checks what happens after signature.
Run the six-point technology invoice audit:
https://www.itbroker.com/blog/technology-invoice-audit
Tommi Ellis:
https://www.linkedin.com/in/tommi-ellis-3a92b0112
Intratem:
https://intratem.com/
More from Signed:
https://www.itbroker.com/podcast
Full Transcript
Click here to view the episode transcript.
You're paying an MDR provider to protect you. Most of them will alert you and wait for someone else to act. This conversation names the one question that tells you which one you actually bought. Know the answer before it's 2am and someone's waiting on you to decide.
You signed a contract for managed detection and response. You assumed that meant somebody would step in and stop an attack while it was happening. For a lot of MDR providers, what you actually bought is guided remediation. They find the incident, tell your team what to do, and hand it back to you to execute. That distinction is the entire reason you're paying for this instead of running it yourself, and most buyers don't find out which one they signed for until they're the one on the call at 2am being asked what to do next.
Miles Lowry, Senior Territory Manager at eSentire, has sold cybersecurity from every seat in the market, VAR, Nutanix, Rubrik, and eSentire, and he walks through the one question that exposes the gap before you sign. This conversation also covers where the same blind spot shows up everywhere else in a typical MDR evaluation. Buyers send RFPs to eighteen vendors and get eighteen generic capability dumps back instead of a real fit assessment. Rules of engagement quietly change depending on whether the compromised machine belongs to your CEO or your help desk.
It also gets into DLP requests that get approved without anyone defining what they're actually trying to stop, and security licensing already sitting in your Microsoft contract that almost nobody has turned on. The buyers with the best MDR outcomes never send a broad RFP at all. Miles names the one question he says he'd ask first if he were sitting on the buyer's side of the table.
Know the answer before it's 2am and someone's waiting on you to decide.
Want the exact test to run against your own contract? Read the full breakdown: How to Tell If Your Managed Cybersecurity Provider Will Actually Respond During an Attack.
Find Your Situation
Ten real moments from this conversation. Find the one that's actually happening to you right now, and jump straight there.
What We Get Into
What We Mentioned
About Miles Lowry
Miles Lowry is Senior Territory Manager at eSentire, where he works directly with security leaders on managed detection and response. He's spent 14 years in enterprise technology sales, moving through VAR, Nutanix, Rubrik, and now eSentire, giving him a rare, direct view into where buyers get MDR wrong before they ever sign.
LinkedIn: https://www.linkedin.com/in/cloud-ai-expert/
Company: https://esentire.com
About Signed
Signed is the podcast for buyers in a market built for sellers. Host Max Clark, CEO of ITBroker.com, sits down with CIOs, CFOs, operators, and founders who've lived inside real enterprise tech deals. New episodes weekly.
Listen: itbroker.com/podcast
About Signed
The IT market is built for sellers, not buyers.
Signed is the podcast for the buyers. Host Max Clark, CEO of ITBroker.com, sits down with CIOs, CFOs, operators, and founders who’ve lived inside real enterprise tech deals — the ones who can tell you what actually determined whether the deal worked, not what the deck promised.
New episodes weekly. An ITBroker.com podcast.
Full Transcript
Click here to view the episode transcript.
A VP spent weeks building a plan to cut an eight figure cloud bill. He walked into one meeting with engineering. Three words killed it: not my KPI. The bill lands on whoever gets handed the mandate to cut it, but the authority to actually change it sits with someone else entirely, usually engineering, whose time is already spoken for by other priorities. A FinOps platform will find you the free money, orphaned resources, idle instances, the stuff nobody has to defend. It won't touch the savings that require someone to decide engineering's time is worth spending on this instead of shipping.
Run this before you spend a dollar on another cloud cost initiative
If items one and two name different people, and item five has no answer, you're looking at an org chart gap. No FinOps platform touches that. Map who actually holds the authority before you spend the next dollar. The full checklist, plus the question most teams skip, is here.
You can buy the platform. If the wrong person still owns the decision, the bill doesn't move, and now you've paid for the privilege of watching it not move.
The Playbook
Resources mentioned
About the show
Signed is the podcast for buyers in a market built for sellers. Playbooks are the solo format, 10 to 15 minutes, one trigger, one specific play. New episodes weekly at itbroker.com/podcast. If the trigger in today's Playbook is one you're facing right now, book an intro call at itbroker.com. We help buyers make the right call the first time. Buy tech without regret. Follow: @itbrokerdotcom
Full Transcript
Click here to view the episode transcript.
Every vendor stretches the truth somewhere in your sales process, and most buyers respond to all of it the same way, forgiving everything or torching a good deal over nothing. In this Playbook, Max Clark sorts vendor lies into three categories, a harmless stretch, one rep's invented promise, and a lie the whole company stands behind, and gives a different response for each. Then he turns the mirror on buyers, the shopped quote, the invented deadline, the fake executive sponsorship, because buyers run the same three plays back. Keep guessing which lie you just caught, or put someone neutral in the room who ends the guessing entirely. That's the only fix that actually works.
Run this the next time a vendor claim doesn't sit right
Now run your own last vendor call through the same three buckets, from the vendor's side of the table. Telling three competitors they're each the front runner, that's your version of Bucket 1. Inventing a deadline that doesn't exist to force urgency, that's Bucket 2. Claiming executive sponsorship that doesn't exist because your whole team has quietly agreed to say it, that's Bucket 3.
Keep guessing which lie you just caught, or put someone neutral in the room who ends the guessing entirely. That's the only fix that actually works.
The Playbook
Resources mentioned
SD WAN, the capability category vendors most often mislabel
Public company 10-K filings, used to fact check inflated market share claims
AWS cloud spend, used as the scale comparison that exposes a fake top-customer claim
About the show
Signed is the podcast for buyers in a market built for sellers. Playbooks are the solo format, 10 to 15 minutes, one trigger, one specific play. New episodes weekly at itbroker.com/podcast. If the trigger in today's Playbook is one you're facing right now, book an intro call at itbroker.com. We help buyers make the right call the first time. Buy tech without regret. Follow: @itbrokerdotcom
Full Transcript
Click here to view the episode transcript.
Your security tool says you're protected. Most of the time nothing is lying to you on purpose. It's just reporting what it was configured to report, whether or not anyone ever checked if that setup was correct in the first place.
Zach Stewart, CISO and Director of IT at Steno, spends this conversation walking through exactly where that gap hides, and it's not only the tool. There's the BAA that only protects you if you configured it correctly, and most companies never click the button. The SOC 2 stamp that tells you someone ran a pen test, not that you're secure. An MDR service marketed as round the clock remediation that turns out to only detect, and a maturity score that gets handed to a board and answers a question nobody in the room actually asked.
It also covers the buying side of all of this: what it actually looks like to evaluate a vendor without falling for the slide deck, why nobody wants to buy secure web gateway until it's already saved them, and the exact moment a customer contract forces corporate owned devices with no plan in place.
Go find out right now if your tool, and everything else you're trusting, is actually telling you the truth.
Where to Start
Chapters
What We Mentioned
About Zach Stewart
Zach Stewart is CISO and Director of IT at Steno, where he spends his days doing exactly what this show is about: buying technology in a market built for the people selling it, then fighting to get it funded and adopted inside his own company. Max discloses in the episode that Zach is someone ITBroker.com works with directly, which is part of why he was on the show, no product to pitch, no reason to give a polished answer.
LinkedIn: https://www.linkedin.com/in/zacharykstewart/
Company: https://steno.com
About Signed
Signed is the podcast for buyers in a market built for sellers. Host Max Clark, CEO of ITBroker.com, sits down with CIOs, CFOs, operators, and founders who've lived inside real enterprise tech deals. New episodes weekly at itbroker.com/podcast. If you're in the middle of a real tech decision and want someone in your corner, book an intro call at itbroker.com. Buy tech without regret. Follow: @itbrokerdotcom
Full Transcript
Click here to view the episode transcript.
Your website is no longer read only by people.
Tony Lauro opens this episode with a client whose sequential order numbers let a competitor read their daily volume through a public API. No breach. No alert. Just a number counting up in plain sight.
The same blind spot shows up when a product drop gets sniped by bots in seconds, or when the large language models you're exposing to customers and employees get probed before anyone notices.
Tony has spent 13 years inside Akamai's bot management and API security practice, watching exactly this shift happen. He walks through what replaced the old human-or-machine test, and it comes down to one thing: who decided your defaults, and whether anyone at your company ever checked.
Find the Risk You're Already Dealing With
What We Get Into
What We Mentioned
About the Guest
Tony Lauro, Security Director at Akamai. Thirteen years inside Akamai's bot management and API security practice, working the exact problem this episode covers: telling good traffic from bad without losing customers in the process.
Connect with Tony: Linkedin | Akamai
About Signed
Signed is the podcast for buyers in a market built for sellers. Host Max Clark, CEO of ITBroker.com, sits down with CIOs, CFOs, operators, and founders who've lived inside real enterprise tech deals. New episodes weekly at itbroker.com/podcast. If you're in the middle of a real tech decision and want someone in your corner, book an intro call at itbroker.com. Buy tech without regret. Follow: @itbrokerdotcom
Full Transcript
Click here to view the episode transcript.
From the publisher's feed