
Sign up to save your podcasts
Or


Six months before the largest retail breach in U.S. history, Target's threat detection system worked exactly as it was supposed to. It caught the attack. It fired five separate alerts. Then nothing happened, because the system could watch, but it couldn't act.
That gap between detecting a threat and stopping it is where most MDR contracts fail their buyers. Max Clark recently evaluated a well known provider for ITBroker's own portfolio and found the same gap hiding under the brand name: full "Manage Detection and Response" on paper, watch and email in practice. He breaks down why that one distinction decides whether you're protected or just informed, and the exact questions that expose which one you actually bought.
Find Your Situation
The Playbook
Resources Mentioned
About Signed
Signed is the podcast for buyers in a market built for sellers. Playbooks are the solo format, 10 to 15 minutes, one trigger, one specific play. New episodes weekly at itbroker.com/podcast.
If the trigger in today's Playbook is one you're facing right now, book an intro call at itbroker.com. We help buyers make the right call the first time. Buy tech without regret.
Follow: @itbrokerdotcom
Most Teams Voice buying decisions start with carrier pricing. This conversation argues that's backwards. Before comparing price per seat, you need to know who's actually running the infrastructure, what you're locking yourself into, and which risks stay invisible until after deployment.
Eric Burton runs National Channel at AudioCodes. He spent two decades selling dial tone on the carrier side before moving to the infrastructure side, the seat where most Teams Voice projects actually win or lose.
This is what most providers never walk you through before you sign, whether you're evaluating Teams Voice for the first time or sitting on a renewal right now.
Find the Risk You're Already Dealing With
Chapters
What We Mentioned
About Eric Burton
Eric Burton is National Channel Account Manager at AudioCodes, the company Omdia ranks as the leading global enterprise SBC vendor by revenue market share for three consecutive years, 2021 through 2023. He spent the prior two decades on the carrier side, at Level 3, Nuvox, and Sprint, before joining AudioCodes in 2021 to build its agent channel program.
Connect with Eric: LinkedIn | Audiocodes
About Signed
Signed is the podcast for buyers in a market built for sellers. Host Max Clark, CEO of ITBroker.com, sits down with CIOs, CFOs, operators, and founders who've lived inside real enterprise tech deals. New episodes weekly.
Listen: itbroker.com/podcast
Book an intro call: itbroker.com
Follow: @itbrokerdotcom
Buy tech without regret.
Full Transcript
Click here to view the episode transcript.
Anthropic built Claude Code. Anthropic still couldn't stop its own source code from leaking straight into a competing product. If a coding tool is running behind your VPN right now with full access, this conversation names what that's already costing you.
Thomas Cooper is AI Product Lead at Expedient, where he works daily with enterprises building AI governance after the fact, once a tool is already live and the CISO's original objection has already been overruled.
This episode is what to check before that call happens, starting with why a SOC 2 report that only spans three months doesn't protect you, and ending with the one AI bet CIOs are making right now that they'll likely regret. If you only have ten minutes, start with the SOC 2 check at 35:28.
Find the Risk You're Already Dealing With
Chapters
01:38 What's actually new in AI, and what's just been relabeled
04:33 Why CEOs stopped letting CISOs say no
09:15 Why every vendor's AI slide means less than it looks like
14:40 Why most AI projects never produce a number anyone can defend
35:28 What to actually check before trusting an AI vendor with your data
43:58 Why your AI conversations may not be privileged in a legal dispute
49:36 Why black box AI shouldn't live behind your firewall
1:06:51 Why AI costs become unpredictable at scale
1:35:20 The AI bet CIOs are making today that they'll regret in two years
What We Mentioned
About Thomas Cooper
Thomas Cooper is AI Product Lead at Expedient, where he's spent years helping enterprises move AI from pilot to actual production deployment. He's built out Expedient's own agentic AI tooling and works daily with the governance, security, and cost tradeoffs that come with running AI at enterprise scale, not the version of AI that shows up in a vendor slide.
Connect with Tom: LinkedIn | Expedient
About Signed
Signed is the podcast for buyers in a market built for sellers. Host Max Clark, CEO of ITBroker.com, sits down with CIOs, CFOs, operators, and founders who've lived inside real enterprise tech deals. New episodes weekly.
Listen: itbroker.com/podcast
Book an intro call: itbroker.com
Follow: @itbrokerdotcom
Buy tech without regret.
Full Transcript
Click here to view the episode transcript.
The clause that matters most in your vendor contract is usually the one everyone skips.
It sits there looking harmless until a patent troll shows up. By then you cannot renegotiate it.
In 2025, patent trolls filed more than half of all U.S. patent lawsuits. In high tech, it was over 90%. More than half their targets were companies under $25 million in revenue. They are not chasing Apple. They are chasing companies your size, because companies your size settle.
The average defense cost runs around $4 million. When a demand lands for $100K, the math does itself - whether or not you did anything wrong. Max Clark walks through the one contract clause that decides whether your vendor fights alongside you or hands you the bill.
Questions to Ask Before Signing Your Vendor Contract
The Playbook
00:00 The Wi-Fi lawsuit that turned buyers into targets
01:45 Why trolls sue the user, not just the maker
03:15 Why smaller companies are the real targets
04:30 The clause most buyers skip on the way to signing
05:51 Defend vs. indemnify: the word that decides who pays
06:45 The combination loophole hiding inside normal use
07:30 When the liability cap makes protection meaningless
08:11 Settlement control, notice windows, and calendar traps
Resources Mentioned
One-page buyer field guide: the three clauses in plain English, the questions to ask, and what a buyer-friendly version looks like. Free download linked in show notes and on screen during the episode.
In re Innovatio IP Ventures (N.D. Ill. MDL 2303) — the Wi-Fi troll case from the episode cold open
Unified Patents 2025 Annual Review — source for the NPE filing data cited in the episode
About Signed
Signed is the podcast for buyers in a market built for sellers. Playbooks are the solo format - 10 to 15 minutes, one trigger, one specific play.
New episodes weekly at itbroker.com/podcast. If the trigger in today's Playbook is one you're facing right now, book an intro call at itbroker.com. We help buyers make the right call the first time.
Buy tech without regret.
Follow: @itbrokerdotcom
Full Transcript
Click here to view the episode transcript.
Lumen just announced it's acquiring Alkira. If your network strategy runs through a vendor that just changed hands, or through one that might, this conversation covers what actually happens next.
Ali Shakh, CEO of Graphiant, was part of the Viptela founding team when Cisco acquired them. He was in the room for that integration. Prices went up. Not by a little. The customers who got hurt were the ones who had no hedge and no questions ready.
This episode is those questions, plus what most enterprise network buyers are paying for right now and why 50-60% savings is a consistent finding, not a pitch.
When your vendor gets acquired: six questions to ask before your next renewal
Your vendor just got acquired. The press release says it is great news. The account team says nothing will change.
These questions come from this conversation with Ali Shakh, CEO of Graphiant, who was part of the Viptela team when Cisco acquired them. He watched what happened to the customers who accepted the first answer and never asked the next one. Answer these based on what you know now, not what you were told at signing.
1. Are prices going up, and do you have that in writing?
Verbal reassurance is not a contractual position. Your current agreement may not protect you through the next renewal under new ownership. Get the commitment in writing. If they will not put it in writing, that is your answer.
2. What is the investment plan for this product?
Not the roadmap. The roadmap is a sales document. Ask what headcount is assigned, who owns the product line, and whether it competes with something already in the acquirer's portfolio. If there is overlap, one product usually loses priority. It may not disappear immediately, but development slows, key engineers leave, and support degrades before anyone makes an announcement.
3. What does your current contract actually protect you against?
Auto-renewal clauses, price escalation terms, termination rights, and SLA remedies were written before the acquisition under a different owner with different incentives. Read the contract again against the new ownership structure. What looked standard before may carry more risk now.
4. What is your hedge if this goes sideways?
The worst time to evaluate alternatives is after pricing changes or product direction shifts. By then the vendor knows you are trapped. Run a parallel evaluation while you still have time and leverage. Renewal pressure is not the moment to start learning the market.
5. Could you realistically migrate off this product in 12 months?
Not whether you want to. Whether you could. Migration timeline, cost, team capacity, system dependencies. If the honest answer is no, the vendor knows that math better than you do and will price the renewal accordingly.
6. When did you last pull the invoice apart line by line?
This is where renewal exposure hides. Unused licenses, oversized capacity, bundled features nobody touches, add-ons that were discounted during the original deal and quietly became permanent spend. Ali's consistent finding after two decades of looking at enterprise network spend: buyers are almost always paying for more than they actually need. If you wait until renewal to find that out, you are negotiating from weakness.
If more than two of these do not have a clean answer, that is the exposure talking. The full conversation goes inside what acquisitions look like from the vendor side, how pricing and product investment actually shift, and what IT leaders should be watching before the renewal becomes a forced decision.
Chapters
07:00 — Why being acquired by a carrier changes everything for existing customers
11:00 — Why the contract is always the real problem, even when the technology works
13:00 — The questions to ask when your vendor gets acquired and the signals that tell you what is actually happening
16:00 — What happened to Viptela customers when Cisco took over
18:30 — How acquirers raise prices without killing the product
22:00 — Why infrastructure lock-in is different from any other vendor lock-in
01:23:00 — You are buying 200% of what you actually need
02:20:00 — The question buyers ask that sounds sharp but gets the wrong answer
02:22:00 — How to measure whether your AI mandate is real or just a board conversation
What We Mentioned
About the Ali Shaikh
Ali Shakh is CEO of Graphiant, a Network as a Service company built around contract flexibility, on-demand capacity, and no vendor lock-in. Before Graphiant, he was part of the founding team at Viptela, one of the companies that defined SD-WAN, through its acquisition by Cisco and the full post-acquisition integration. He has been on both sides of what happens when a vendor gets bought and speaks from inside those conversations, not from the outside looking in.
LinkedIn: https://www.linkedin.com/in/alifshaikh/
Company: https://www.graphiant.com/
About Signed
The IT market is built for sellers, not buyers.
Signed is the podcast for the buyers. Host Max Clark, CEO of ITBroker.com, sits down with CIOs, CFOs, operators, and founders who’ve lived inside real enterprise tech deals — the ones who can tell you what actually determined whether the deal worked, not what the deck promised.
New episodes weekly. An ITBroker.com podcast.
Full Transcript
Click here to view the episode transcript.
Dave Chronister has been doing penetration testing and incident response since 2007 — back when Fortune 500 CIOs called it a novel concept.
In the years since, he's walked into breached environments where the EDR was running, the MDR was installed, the SOC 2 audit had passed, and none of it mattered.
This conversation covers the gap between what companies think they bought and what they actually have why tools become the program by default, why compliance audits and security programs are two different things, what AI is actually doing to enterprise risk profiles right now, and what the organizations that survived a ransomware encryption event had that the ones who didn't were missing.
If you're responsible for a security decision, this is the conversation to have before the next one.
Is your security program real, or is it just theater?
The gap between a real security program and a collection of tools doesn't show up in an audit. It shows up during an incident — when it's too late to fix cheaply.
These eight questions come straight out of this conversation with Dave Chronister, founder of Parameter Security. Each one maps to something he's actually walked into. Answer them against what you know to be true right now — not what your vendor told you at signing.
1. Do you know which findings from your last security assessment are still open?
Dave has had a Fortune 100 client for four straight years. He pulled the year-one report and the year-four report side by side. Almost identical findings. Tools were bought, renewed, and re-certified the whole time — and the actual exposure never moved. If your remediation list looks the same as it did a few cycles ago, the program isn't the problem. The follow-through is.
2. When did your EDR last fire — and who responded?
Not whether it's installed. Whether it's being acted on. In recent insurance data, more than 60% of ransomware encryption events happened at organizations running a leading EDR. Detection without response doesn't stop an attack. If you can't say when it last fired and what happened next, you don't know if your coverage is real.
3. Is your MDR running in active response mode, or monitored mode?
These are not the same thing. Monitored means alerts get logged. Active response means someone acts on them. Dave has walked into environments where MDR sat in monitored mode for years while the client believed they had full coverage. Ask your vendor directly which one you're paying for, and get it in writing.
4. What does your SOC 2 certification actually cover — and what does it say nothing about?
SOC 2 audits whether your processes are documented and followed. It does not evaluate whether those processes protect you. A company can pass SOC 2 every year and carry the same critical vulnerability the whole time. If SOC 2 is your primary answer to "are we secure," that's the gap.
5. Do you know which AI tools are already running in your environment — and what data they have access to?
Shadow AI is already inside most organizations. A tool that entered your environment as a productivity assistant may now have access to email, internal documents, customer records, and approval workflows. If you don't have a current inventory of what's running and what it touches, you don't have an AI policy. You have AI usage.
6. Who actually owns the risk when something goes wrong — IT, the CISO, or the board? IT holds the tools. The CISO advises. The board carries the fiduciary responsibility. Dave's seen the scapegoating pattern up close: a CISO with no real authority gets blamed for a decision the board never seriously evaluated. If your C-suite treats security as an IT line item, nobody with budget authority is actually deciding what risk is acceptable.
7. Have you defined what a win looks like before your next renewal? Most companies don't know what "fixed" means before they buy. They implement, assume it worked, and move on. What specific risk reduction is this renewal supposed to buy, and how will you know if you got it? Walking into a renewal without that answer means negotiating blind.
8. What is your responsibility in this — specifically, in your seat?
This is the question Dave wishes every client asked before the engagement even starts. Not "what's the vendor's responsibility" or "what's IT's responsibility" — yours. Most people outsource the answer to a vendor or a department and never come back to it. If you can't state your own responsibility precisely, that's the gap an incident will find for you.
If two or more of these stung, that's the program talking, not the tools.
Tools get bought in response to a checklist or a renewal deadline. Programs get built in response to a defined risk.
The full conversation goes deep on where that gap actually comes from and what it costs the companies that don't close it.
Chapters
00:00 — Why security awareness campaigns don't change buyer behavior
08:14 — Theater clients versus clients who actually want help
14:00 — What the pen test findings look like four years later
19:30 — Why tools become the security program by default
26:35 — What SOC 2 actually audits and what it ignores entirely
37:20 — Why 60% of ransomware victims had a leading EDR installed
44:50 — MDR in monitored mode versus active response — and why it matters
52:00 — The real risk of AI inside your organization
1:01:00 — Why the vendor selling the control shouldn't validate it
1:09:00 — Who actually owns the risk when something goes wrong
1:45:00 — The one question Dave wishes every company asked before buying anything
What We Mentioned
About Dave Chronister
Dave Chronister is the founder of Parameter Security. He started doing penetration testing in 2007 when most companies hadn't heard the term and has spent nearly 20 years walking into environments after the breach to find the things the audit missed. He's unusually direct about what tools actually do and what they don't, and he's seen every version of the gap between what companies think they bought and what they actually have.
LinkedIn: https://www.linkedin.com/in/davechronister
Company: https://www.parametersecurity.com
About Signed
The IT market is built for sellers, not buyers.
Signed is the podcast for the buyers. Host Max Clark, CEO of ITBroker.com, sits down with CIOs, CFOs, operators, and founders who’ve lived inside real enterprise tech deals — the ones who can tell you what actually determined whether the deal worked, not what the deck promised.
New episodes weekly. An ITBroker.com podcast.
Full Transcript
Click here to view...
You've read the post. A CEO goes on LinkedIn. Hard decision. I own this. Because of AI, we'll come out leaner, faster, stronger.
Max Clark has written one of these. He's also been on the receiving end of one.
In this Playbook, he breaks down what that post actually says — and what it's designed to leave out. Not to indict the people who write them, but to hand you one question: whenever a company or a vendor tells you why they're doing something, who was that explanation written for?
It's the same question whether you're reading a layoff announcement or a renewal proposal. You're about to start asking it everywhere.
What This Episode Answers
What We Get Into
00:00 — The post you've read a hundred times
01:10 — Why the four-part format is worth taking apart
03:30 — Why headcount is always the first thing cut
04:15 — Why "AI" works as an explanation — and when it's actually true
05:47 — RTO, unlimited PTO, keep your laptop — same move, different wrapper
08:00 — What to do if you're on the receiving end
09:20 — The one question that changes how you read any explanation
10:20 — Why this is the same skill as reading a vendor pitch
Related Reading
Layoff Announcements and Vendor Price Increases Are Built the Same Way. Here's How to Read Both.
The Vendor's Policy Change Is Solving Their Problem, Not Yours
About Signed
Signed is the podcast for buyers in a market built for sellers. Playbooks are the solo format - 10 to 15 minutes, one trigger, one specific play.
New episodes weekly at itbroker.com/podcast. If the trigger in today's Playbook is one you're facing right now, book an intro call at itbroker.com. We help buyers make the right call the first time.
Buy tech without regret.
Follow: @itbrokerdotcom
Full Transcript
Click here to view the episode transcript.
You bought the platform. You renewed the contract. And 80% of your breach risk is coming from the one thing the platform wasn't built to catch.
Craig Patterson spent years inside the channel ecosystem that sits between what security vendors ship and what enterprise buyers actually receive — and he's unusually direct about where those two things don't match.
In this conversation: the Microsoft "free SIEM" that isn't free once you turn it on, the insider threat blind spot baked into nearly every consolidated platform, and the AI agent problem your security team is about to inherit whether they're ready or not.
If your renewal is coming up and your confidence in your coverage hasn't kept pace with your spend — this is the episode.
One of these is probably on your roadmap right now.
WHAT WE GET INTO
10:30 — What you stop seeing when you consolidate security vendors
18:30 — How to prove security value without relying on tool counts
22:00 — The breach vector responsible for most incidents
29:00 — The four types of insider threats
34:00 — Why AI agents should be treated like insiders
38:00 — Finance bot #7 just accessed source code. Would you know?
43:00 — How AI reduces alert investigations from 60 minutes to 5
47:00 — The one question that exposes AI marketing hype
51:00 — Why every organization still needs a SIEM
53:00 — The CFO conversation: justifying security spend
01:08:00 — Why leading with cost savings is the wrong security strategy
WHAT WE MENTIONED
ABOUT CRAIG PATTERSON
Craig Patterson is the Global Ecosystem Chief at ExaBeam, where he rebuilt the company's entire partner ecosystem following the ExaBeam/LogRhythm merger — unifying two different channel programs across 3,000 partners and six continents.
Before ExaBeam, Craig built and led channel organizations at multiple enterprise security companies. He's worth listening to because he sits at the intersection of what security vendors are building and what enterprise buyers are actually receiving — and he's unusually honest about where those two things don't match.
ABOUT SIGNED
The IT market is built for sellers, not buyers.
Signed is the podcast for the buyers. Host Max Clark, CEO of ITBroker.com, sits down with CIOs, CFOs, operators, and founders who’ve lived inside real enterprise tech deals — the ones who can tell you what actually determined whether the deal worked, not what the deck promised.
New episodes weekly. An ITBroker.com podcast.
Full Transcript
Click here to view the episode transcript.
The average enterprise uses 44% of the Microsoft stack they're paying for.
Denis O'Shea knows because he's measured it — the same 120-point assessment, hundreds of organizations, the number doesn't move. The other 56% is licensed and sitting idle while the same teams buy third-party tools to fill gaps that 365 already covers.
Denis is the founder of Mobile Mentor and has managed 14.5 million enterprise devices across healthcare and financial services. He's seen what the stack looks like from the inside — the sprawl, the overlap, the security tools that got purchased because insurance required it. Never properly deployed.
In this episode, Max and Denis work through the utilization problem, what it actually takes to go passwordless when your legacy apps will fight you, what the Digital Markets Act opened up in your mobile attack surface, and why the best security your employees will ever experience is the kind they never notice.
If you're signing off on a Microsoft renewal in the next 90 days, or your security stack has grown every year and your confidence in it hasn't — this is the episode.
Find your situation. Skip to the answer.
In this conversation:
00:01 — Why you're paying for technology your employees aren't using
08:00 — BYOD vs. corporate-owned: where companies actually get into trouble
14:00 — What the Digital Markets Act broke in your mobile security model
20:00 — Why mobile threat defense is now a requirement, not an option
28:00 — The ROI problem: how to justify security spend that has no obvious return
33:00 — AI in the wrong hands: what unmanaged devices look like in 2026
41:00 — Why the MDM market is disappearing — and what replaces it
46:00 — The DIY trap: why deploying Intune yourself costs more than you think
50:00 — You're using 44% of your Microsoft stack — and buying tools to cover the rest
51:00 — 52 security tools, mostly siloed: how enterprises accumulated the wrong defenses
55:00 — The manual IT problem: two hours per device, every device, still happening
01:12 — Three things to remove from your IT team's plate this year
01:14 — Why going passwordless is a board decision, not an IT project
01:16 — How to explain passwordless to a non-technical leader without acronyms
01:21 — AI-enabled attacks and why your on-prem infrastructure can't keep up
01:23 — Set your own end-of-life date before Microsoft sets it for you
01:27 — How to sell security investment to a board that doesn't want to hear about it
01:29 — Invisible security: what good looks like when it's working
What We Mentioned:
About Denis O'Shea
Denis O'Shea is the founder and CEO of Mobile Mentor, a Microsoft-specialized managed services provider that has enabled 14.5 million devices across enterprise clients in healthcare, financial services, and beyond. He spent 15 years at Nokia running operations across seven countries before building a company around a problem he kept seeing: organizations paying for technology they couldn't fully use. He has served on Microsoft's Intune product advisory board and has spent the last decade helping enterprises close the gap between what they bought and what's actually protecting them.
About the Show
Signed is the podcast for buyers in a market built for sellers. Host Max Clark, CEO of ITBroker.com, sits down with CIOs, CFOs, operators, and founders who've lived inside real enterprise tech deals. New episodes weekly at itbroker.com/podcast.
If you're in the middle of a real tech decision and want someone in your corner, book an intro call at itbroker.com.
Buy tech without regret.
Follow: @itbrokerdotcom
Full Transcript
Click here to view the episode transcript.
MSPs sell their book. The vendors they're authorized on. The platforms they're certified on. The products they have margin on.
The infrastructure they're about to recommend for your business is shaped by all of that before you walk in the room.
This Playbook covers what that actually means for you: how to size the right MSP for your company, what security capabilities a small MSP genuinely cannot deliver regardless of what they tell you, why outsourcing IT decision-making to someone with a vested interest is one of the most expensive mistakes a growing company makes — and the one rule that keeps you from getting locked into the wrong stack for the next three years.
You should be leading the MSP. Not the other way around.
The Playbook
00:00 — The danger of outsourcing IT decisions to someone selling their book
00:45 — Why MSPs sell their book — and why that's the reality, not a criticism
02:00 — Deal registration: how your project gets locked in before you've decided
02:34 — Size mismatch: why a $100K project won't get attention from a large VAR
03:30 — The security capability gap: what sub-50-person MSPs can't actually deliver
04:47 — Platform-on-platform: the tools MSPs resell vs. real capability
05:40 — Truck rolls, multi-site support, and what to ask before you sign
06:10 — Rip and replace: the cost of getting it wrong while under contract
07:00 — The play: define your infrastructure needs first, then find the MSP that fits
Resources Mentioned
About the Show
Signed is the podcast for buyers in a market built for sellers. Playbooks are the solo format — 10 to 15 minutes, one trigger, one specific play. New episodes weekly at itbroker.com/podcast. If the trigger in today's Playbook is one you're facing right now, book an intro call at itbroker.com. We help buyers make the right call the first time.
Buy tech without regret.
Follow: @itbrokerdotcom
Full Transcript
Click here to view the episode transcript.
From the publisher's feed