Coro CEO Joe Sykora on the case against Frankenstein security stacks

The former solution provider owner turned cybersecurity chief executive makes the case for platform consolidation - and acknowledges the limits of his own argument

Joe Sykora, CEO of Coro

The debate between platform consolidation and best-of-breed point solutions has been running in the MSP community for years. But with -driven attack volumes up three to four times year over year, and clients unwilling to absorb price increases, the operational stakes are getting harder to ignore.

In this episode of , host Robert Dutt speaks with Joe Sykora, chief executive officer of Coro, the Chicago-based cybersecurity platform built for lean IT environments and the MSPs who serve them. Coro’s platform spans 14 modules – endpoint, email, , app security, data protection, and more – running on a single agent and a shared data engine. The company is 100% channel, past Series D, and recently recognized by Gartner as a representative vendor in the emerging Workspace Protection category.

Sykora brings an unusual background to the CEO chair. He started out running solution provider businesses before moving vendor-side, holding channel leadership roles at Fortinet, Bitdefender, and Proofpoint. One of his first acts as CEO was eliminating Coro’s direct sales motion entirely.

The conversation covers Coro’s core consolidation argument – and what Sykora calls the “Frankenstein stacks” that result from stitching together point solutions via API integrations – alongside the platform’s 92-93% automated alert remediation rate, with some partners pushing toward 96%. It also gets into harder territory: Sykora acknowledges on the record that not every Coro module is best in class, and addresses the vendor concentration risk that comes with consolidating that much of a client’s security posture in one place.

The episode closes on Coro’s recently launched MCP server integration, which brings security operations directly into AI agent workflows, and the question Sykora took from RSA: is it cybersecurity with AI protection, or AI with cyber?

Read Full Transcript

Robert Dutt: Hello and welcome to In The Channel from ChannelBuzz.ca, bringing news and information to the Canadian IT channel community for the last 16 years. I’m Robert Dutt, editor of ChannelBuzz.ca and your host for the show. The question of how to build a security stack for small or mid-sized businesses, or for the MSP serving one, hasn’t gotten any simpler. If anything, it’s more crowded than ever. Best-of-breed point solutions for every threat vector, each with their own agent, their own dashboard, and their own data silo. There is no such thing as a single pane of glass in security. My guest today has a different answer, though. Joe Sykora is chief executive officer at Coro, an 11-year-old cybersecurity platform purpose-built for lean IT environments and the MSPs that serve them. Coro covers 14 security functions—from endpoint to email to network, cloud app security, and data protection—under a single agent and a single data engine. The company is 100 percent channel, past Series D funding, and has made no secret of its ambition to be a platform that consolidates what Joe himself called the “Frankenstein stacks” that so many MSPs have been managing for years on the security side. What makes him an interesting person to have this conversation with is that he isn’t coming at it from the product or the engineering side. He started out running solution provider businesses in the 90s, exited two of them, and spent the better part of 15 years in channel leadership roles at Fortinet, Bitdefender, and Proofpoint before taking the CEO chair at Coro last year. Let’s get right into it. My chat with Joe Sykora. Joe, thanks for taking the time. I appreciate it.

Joe Sykora: Robert, great to see you.

Robert Dutt: You know, most cybersecurity CEOs come up through product, through engineering, or through finance. Your background involves running a solution provider before going vendor-side. I’m curious what the industry looks like from a CEO’s seat when your formative years were on the partner side of the table.

Joe Sykora: Sure. Well, it’s been an exciting ride. It started back in the 90s and I’ve been very, very fortunate. I was one of the early adopters. The first company I had was an company; we quickly pivoted to security and became a managed security provider in the 90s. I still have a lot of friends that are still out there doing it, but I was one of the early adopters. I was very, very fortunate to be able to exit both of those companies and that got me to the manufacturer side. I started with a little-known company—at the time it was unknown, but most people now know Fortinet. I joined them in 2010 during their IPO and, man, I like to say the rest is history. My role at Fortinet was a little bit different because I did cover primarily the channel, the partner side, which was a huge, huge part of Fortinet’s success. But I also got to dabble on a few other things like operations and the marketing piece. In fact, when we made some of those acquisitions, I got to be the interim CEO as we integrated those in. I never lost my entrepreneurial spirit; if there’s a problem, I like to fix it. I don’t like to just say “that’s the way it’s always been.” I always challenge things no matter where I go. I have the attitude where if the garbage needs to be taken out, I’ll take out the garbage too, right? Because that’s the way I was brought up—very humble beginnings in Ohio. I grew up in farm country, believe it or not. I was one of the first children to get to play around with a Mac and programming in fourth grade. So at a very early age, I got a little bit addicted to computers. The seat right now as CEO is what I’ve been brewing myself for throughout my career. I’ve led go-to-market strategies and I’ve been involved very much on the backend. When this opportunity came up, it was something that I felt I was ready for. I’ve put in a lot of international experience over the last 10 years or so, meeting with partners all over the world and really listening to the different needs they have. But more importantly, I love the channel. I came from the channel. So for me to be able to run a 100 percent channel motion is very unique. One of the first things I did as CEO was kind of kill the direct motion. We had a mixed model and it didn’t make sense for us. So it’s exciting. Of course, there’s other challenges—I spend a lot of my time with boards and financial institutions now—but I still love getting in front of the partners and talking about our story and how we’re different. Sometimes it even leads to giving advice on how to exit companies and what’s important there.

Robert Dutt: No doubt a topic of interest for the MSPs listening. For you guys, the platform consolidation pitch is a big one and it’s compelling on paper. One agent, one dashboard, 14 modules. But there’s always that MSP who comes up and says, “All right, the jack of all trades, master of none thing.” How do you answer an MSP who says, “I see your point, but my EDR vendor or my specialist is doing better in that particular lane than what Coro can do”? What’s the message to that skeptic?

Joe Sykora: Yeah, well, I think things have definitely changed. Again, this is coming from a guy who’s been in cyber now for almost 30 years. For the partners out there, everyone has their tech stack. This isn’t anything new. When I was an MSP, my pitch was “you can’t afford an platform—not only the licensing, but really managing the platform.” I’m sure a lot of people out there today are doing the same thing. Coro’s different because of the advancements of using AI. I know that’s a topic—I think last week I said we should make a drinking game out of anytime anyone says “AI.” But AI is moving faster than anything we’ve seen out there. Coro is not a new company; we’re 11 years old. Coro was purpose-built for the MSP and SMB—or “Lean IT,” as I like to refer to it. We help operationalize things. Coro is not about looking at each individual module and saying “I have it, I don’t have it.” It’s about putting it all in one agent to stop agent sprawl and putting it all in one dataset. Because it is all our own IP that we spent the last 11 years developing, having clean data going into it is so important. That’s why we’re seeing, on average, about a 92 to 93 percent automation rate of correlating and then remediating automatically. That’s pretty good, and it’s getting better. A year ago we were in the high 80s; we’re now closing in on the mid-90s. I was talking to a partner the other day who was seeing about 96 percent. What that translates to is operational efficiencies. That is time back, and that is money to you as an MSP. We know that the attacks aren’t slowing down—in fact, we’re seeing about a 3X increase already this year. The bad guys are also using AI. If we want to go head-to-head versus your endpoint and EDR vendor, we can. We still test out at five nines. The difference is it’s simpler. I’ve talked to many “enterprise” MSPs who are very proud of their stack, and that’s fine. But then they look at someone like Coro—100 percent channel, guaranteed margins, a lot of support—and it makes sense. The “aha” moment is when they see the operational efficiency of an analyst being able to look at 100 or more clients instead of 20 or 30. We did introduce Coro AI within the product for MSPs who want to look at reporting across all their customers. We’re not an NDR, but we give you NDR results. If you want to do some threat hunting and see what’s going on, you just talk to our AI. The concept is the same as the old UTM or Next-Gen Firewall days, except now I have more modules and I’m in the cloud. And we can coexist. If you have a solution in place, that’s okay. We are a very lightweight client. You can get the results and then, when it comes up for renewal, you can decide if you still need that enterprise point product or not.

Robert Dutt: That 92 percent automated alerts figure has to be one that gets a lot of attention. Can you walk me through what that automation means for an MSP day-to-day? And maybe more interestingly, what does the other 8 percent look like? Is that still where human judgment matters most?

Joe Sykora: There is no way I’m going to get to 100 percent. Will it increase? Yes, of course. The difference we have is that since it is all one database, you don’t have a true single pane of glass when you’re doing API integrations. Some of the big platforms out there have kind of “Frankensteined” things together through acquisitions and APIs. I have a very elegant solution. The 8 percent that you need to look at is because we can’t make a judgment call at that point. But let us be defense-in-depth; let us see that data because that’s how you get better results. Gartner actually came out with a new category last year called “Workspace Protection,” and Coro is mentioned as a representative vendor there. Our direct connections into Microsoft and Google Workspaces are key because then we can start doing the compliance, the DLP, and answering those questions about protecting confidential information. Same thing with —being able to truly stop smishing carrier-independently is a challenge, and we’ve got a way to do that. You’re always going to need that human level. Our job in security is not only stopping the bad stuff, but managing the false positives. Our false positive rates are very low, which saves the MSP a lot of time.

Robert Dutt: One of the latest things you guys have launched is an MCP server. Can you explain what that actually does in practical terms—how the workflow changes for an MSP when the security data is feeding directly into an AI agent?

Joe Sykora: Depending on who you talk to, it could be controversial. I was at RSA, and the big talk was: is it cybersecurity with AI protection, or is it AI with cyber? That is the question. What we’re starting to see is more partners building things around AI platforms. We wanted to give them the flexibility to do that. On the technical side, some of the stuff we’re doing is really cool. The other of Coro is that this is all about operational efficiencies and consuming our tech where you want to. If you don’t want to interface with my UI, you don’t have to. If you want to communicate with our platform via Slack, Teams, or text to resolve things, you can. If Coro can be where you want it to be in your business, that unlocks efficiency. We’re mostly a development house at our core. We have excellent people on the channel side, but we’re not out there hiring teams and teams of salespeople to go direct. I think partners should provide all the services. Some manufacturers are tempted to do direct-to-end-user sales; I have no desire to do that. It helps me focus on being good at developing the products.

Robert Dutt: Let’s talk about vendor concentration risk. The great thing for an MSP is having 14 security functions under one roof, but that’s also the challenge. What’s the answer to a partner who asks: what happens to my clients if something goes sideways—a bad update, an outage, or a longer-term event like an acquisition?

Joe Sykora: We all make business decisions. On the manufacturer side, it used to be all about best-of-breed. Now everyone is talking about “platform.” The cleaner the data into an AI model, the better. Do all of my 14 modules—are they the best out there? You could challenge me on a few. I think the core products we have are very, very good and test out at five nines. Do I have all the enterprise features of some other things? If you look at our network module, you might want more, but we’ll interface with that. We’re built for “Lean IT.” As for the big question—will we get acquired?—that’s not our plan. Coro is late-stage; we’re past Series D. It’s a very solid company and I was brought in to become the biggest cybersecurity company out there. It was not a “come in and let’s get acquired” play. But for partners, you do need to make those business decisions. We have three different bundles—good, better, best—so you don’t have to take all the modules if you don’t want to. It’s something you have to evaluate as a business owner.

Robert Dutt: You guys opened a Canadian data center a couple of years ago. I’m curious what your read is on the Canadian MSP market and how the regulatory conversation looks for your Canadian partners.

Joe Sykora: We’re partnered with Amazon (AWS), and we’ve had a Canadian presence for many years. There are a lot of regulatory things we need to comply with for Canada. If I didn’t believe in the Canadian MSP market, I don’t think we’d have a server there and local presence. In the past, at other manufacturers, I’ve had to fight for that and justify it. Coro is set up for that. We also have dedicated people in Canada—actual Canadians—helping our partners. It’s a fantastic market. On the DLP side, there are differences between US data and Canadian data, and we fully support those. As for differences between MSPs, I deal with them across the world and some things are consistent: the need to operationalize and give predictability to business owners. We’ve built a true consumption model where you have the keys to the kingdom—grandparent, parent, child tiers—and you only have to pay for what you use. It’s complete flexibility. I have advisory councils that provide a constant feedback loop. People who know me know that I take feedback from partners seriously. In our January release, we had a lot of updates because of what our MSP partners asked for. We’re here to listen.

Robert Dutt: You’ve said that 2025 was a foundational year for Coro and that 2026 is about execution. What does that execution mean for the one or two things you’ve got to get right this year?

Joe Sykora: When I took over as CEO, I had to put my CEO hat on. We had so much opportunity that we were being spread too thin. You have to have some focus. I had to switch out some backend systems—nothing to do with the product, but how we ran the business to improve the partner experience. We brought in a lot of new people—familiar faces in channel sales. This year is about executing on a very focused plan and stress-testing all the work we did. 2027 is all about scale, so I need to make sure the machine doesn’t break. For example, when I took over, we had a project for a consumer app. I put a timeout on that because I’ve been in a mixed environment before and it’s a different type of support and service. I want to focus on the primary platform. We’re not hiring teams of salespeople; I want our partners to do that.

Robert Dutt: Last question from me. MSPs are being pulled in a dozen directions. If you could give one piece of concrete advice on how MSPs should be thinking about their security stack over the next 12 to 18 months, what would that be?

Joe Sykora: Automation. You need to be prepared. Like I said, we’re seeing three to four times the number of attacks already this year. If you don’t think it’s going to happen to you, you’re wrong. You need to make sure whatever you’re doing is efficient and effective. You can’t change your price model to the customer—if anything, they want it to go down—so you need to deliver first-class services more efficiently. That’s why you need to always be evaluating what’s new, but you want to be with a platform that has put the work in over many revisions. Buckle up, because the next few months are going to move fast.

Robert Dutt: Never a dull moment in this industry, that’s for sure.

Joe Sykora: Never, Robert. Never a dull moment.

Robert Dutt: Joe, I appreciate you taking the time. Thank you.

Joe Sykora: Thank you. You take care. Thanks, Robert.

Robert Dutt: There you have it, Joe Sykora from Coro. I’d like to thank Joe for his time—good conversation. If you’re an MSP evaluating your security stack, there are a few things worth thinking about here. The core of Coro’s argument, pardon the pun, isn’t really about individual module quality—and to Joe’s credit, he acknowledged on the record that not every one of those 14 modules is, in and of itself, best-in-class. The argument is about what happens when all of them share a single data engine. The 92 to 93 percent automated alert remediation rate—with some partners seeing 96—is the claimed payoff of that architecture. And he’s right that in an environment where attacks are up three to four times year over year and you simply cannot raise prices on clients, the only lever MSPs really have left is efficiency. Not a new observation, but it really lands well when the guy saying it used to run solution providers himself. Another thing we’re thinking about is the question Joe raised from RSA: is it cybersecurity with AI protection, or is it AI with cyber? That has real implications for how MSPs think about building their service delivery around AI platforms going forward, and it’s a conversation we’re going to have a lot more of on this show. If you found this useful, please follow or subscribe to the podcast wherever you get your podcasts. We’re on Apple Podcasts, Spotify, YouTube, all the major directories. Ratings and reviews are always appreciated and always noticed. Until next time, I’m Robert Dutt for ChannelBuzz.ca and I’ll see you in the channel.

About Robert Dutt 1781 Articles
Robert Dutt is the founder and head blogger at ChannelBuzz.ca. He has been covering the Canadian solution provider channel community for a variety of publications and Web sites since 1997.

Be the first to comment

Leave a Reply

Your email address will not be published.


*