Securonix gives partners ‘incremental SIEM sales opportunity’ with AI-driven top-up model
The company is allowing MSSPs and system integrators to add AI-driven detection capabilities to existing SIEM environments without forcing customers to replace deeply embedded platforms.
Securonix is giving Indian MSSPs and system integrators a way to add AI-driven detection capabilities to existing SIEM deployments without asking customers to replace deeply embedded security platforms, opening an incremental sales opportunity for partners.
Speaking to CRN India, Securonix country director, India & SAARC, Dipesh Kaura, said the approach addresses a fundamental challenge with SIEM technology. Once deployed, a SIEM becomes deeply connected to an organisation’s technology environment and can be difficult and expensive to replace.
The technology connects with multiple products and solutions already deployed inside an organisation, monitoring security events and providing visibility into what is happening across the environment.
According to Kaura, the engineering, re-engineering, configuration and reconfiguration required to stabilise a deployment can take anywhere from around 15 days to three to six months, depending on its size and complexity.
“Replacing a SIEM or a security monitoring tool is one of the most painful tasks for any organisation,” Kaura said.
That creates a problem for customers that want access to newer AI-driven security capabilities but do not want to undertake another major SIEM deployment.
Kaura said customers may have selected a SIEM such as Microsoft Sentinel or another competing platform one or two years earlier, but the emergence of newer AI-driven capabilities does not necessarily make replacement practical.
Securonix is therefore taking a top-up approach. Instead of replacing the existing SIEM, customers can add specific AI-driven capabilities on top of the platform they already use.
“You can take certain specific AI-driven features that can sit on top of your existing solution without disrupting them, and still bring in the advanced detection capabilities,” Kaura said.
For partners, the model changes the sales conversation from replacement to expansion.
Existing SIEM deployments become incremental sales opportunities
An MSSP or system integrator that has already deployed a SIEM does not need to return to the customer and ask it to abandon that investment. Instead, the partner can identify additional security requirements and position Securonix’s capabilities as a layer on top of the existing deployment.
“If he has already sold something, he can go back to the customer and create an incremental sale,” Kaura said.
The opportunity, according to Kaura, is not limited to the immediate additional sale. Partners can demonstrate improvements in detection and response while allowing the customer to continue using its existing platform.
That also creates a larger addressable market for Securonix’s partner ecosystem.
Kaura acknowledged that Securonix does not have a partner base comparable with Microsoft’s, but said the size of the broader Microsoft customer and partner ecosystem gives Securonix partners access to a wider pool of potential accounts.
“Everybody is a Microsoft partner, and everybody is a Microsoft customer also,” he said.
The same principle applies beyond Microsoft Sentinel. Securonix is not asking customers to rip and replace their existing SIEM; partners can approach organisations running different security monitoring platforms and position the new capabilities around specific gaps in their existing environments.
“The market for Securonix becomes bigger and wider because now we don’t want to rip and replace anybody,” Kaura said.
Kaura said the opportunity for the partner and channel community has effectively “quadrupled” because customers that previously may have been difficult to approach due to their existing SIEM investments can now become potential prospects.
The top-up model can also create a longer-term migration opportunity. Once a customer starts using Securonix capabilities alongside its existing SIEM and sees the value, Kaura said Securonix can gradually look at migrating that customer towards its platform for that technology area.
The immediate proposition, however, is to add capabilities without disrupting the existing environment.
The commercial proposition is also supported by Securonix’s approach to SIEM data consumption. Kaura said cloud consumption is a major component of the cost of a cloud-based SIEM because traditional deployments can push the entire volume of generated logs into the cloud.
Securonix’s technology distinguishes between critical and non-critical logs before moving the data to the cloud.
“We are classifying the logs, filtering them, compressing them and then pushing them onto the cloud,” he said.
In an environment where an organisation would traditionally consume 100GB of data, Kaura said the requirement could potentially come down to 50GB to 70GB depending on the organisation and the nature of its data.
The potential reduction varies by industry. BFSI organisations, for example, are likely to have a higher proportion of critical customer and transactional data, while manufacturing and mid-market environments may have more non-critical data.
For partners, the lower consumption requirement can feed directly into their commercial proposal.
Kaura said a competitor could size a customer for 100GB of consumption, while a Securonix partner could propose 50GB to 70GB based on the classification of critical and non-critical data.
“So when my partner is giving or submitting his commercial quotation, he will submit for anything from 60 or 70GB vis-a-vis a competitor over, say, 100GB,” he said.
According to Kaura, the approach can make the commercial proposition more competitive while also improving the efficiency of the analytics engine because it is analysing qualified data rather than processing the entire volume of logs.
He said this can improve detection speed and quality while reducing false positives.
Plans one VAD as partner demand expands
Securonix is also putting additional support around the partner ecosystem as it expects demand for the new proposition to grow in India.
Kaura said the company’s product development, engineering and AI capabilities are centred in India, with centres in Bangalore and Pune employing around 450 people. The presence of these teams enables Securonix to work closely with local partners, particularly MSSPs and security service providers that operate in both cities.
The company is running enablement campaigns with channel partners to help them understand the technology and keep pace with its development. Securonix is also working with partners, MSSPs and selected customers through beta deployments, with partner technical teams shadowing Securonix personnel during implementation and setup.
Kaura said Securonix has already invested in a value-added distributor for India and plans to announce the arrangement by the end of August or early September.
The VAD is expected to provide a second line of availability as demand grows for customer conversations, POCs, deployments, testing and implementation.
Securonix does not currently plan to appoint multiple VADs. Kaura said the company intends to work with one VAD for at least the next 18 to 24 months, giving the distributor time to recover its investment and build the business without creating channel conflict.
“I will keep one VAD for sure, at least for the next 18 to 20 months, 24 months,” he said.
The VAD will primarily support the broader partner ecosystem, particularly smaller partners and lower-consumption customer environments that may require additional day-to-day handholding.
At the same time, Securonix expects its wider partner and MSSP community to expand rapidly as the opportunity grows. Kaura said partners and the VAD will initially work closely with Securonix on opportunities, POCs, training and customer engagements.
The company expects partners to be fully enabled within three to six months as they gain practical experience through POCs and customer deployments.
“We will own it. We will drive it with the partners, with the customer, with the VADs, so that the messaging and the use cases have been displayed correctly and the value is clearly visible for the customer to buy and for the partner to sell,” Kaura said.
The level of direct involvement will depend on the complexity of the customer environment. Smaller partners handling lower-consumption environments can use the VAD as a second line of support, while large banks, IT and IT services companies, power sector organisations, defence customers and other critical environments will receive greater direct involvement from Securonix.
For Securonix, the strategy is ultimately about giving partners a way to monetise existing customer relationships without displacing the incumbent SIEM.
By adding AI-driven capabilities on top of existing deployments, the company is turning SIEM replacement friction into an incremental sales motion for MSSPs and system integrators, allowing partners to expand existing accounts today while creating a potential path towards broader Securonix adoption over time.