CrowdStrike is expanding the reach of its Project QuiltWorks cyberdefense alliance. Just four months after launching the initiative for large enterprises, the cybersecurity vendor wants to reach small and midsized businesses through distributors, managed service providers and other channel firms.
Project QuiltWorks’s launch partners included Accenture, EY, IBM, Kroll and OpenAI. The aim was to integrate CrowdStrike’s AI-driven vulnerability discovery capabilities with systems integration expertise and input from LLM labs OpenAI and Anthropic to deploy enterprise-grade protection. In early August, the company corralled Arrow Electronics, Pax8, TD Synnex and several other channel firms to mobilize the midmarket push.
The move comes amid a wave of interest in SMB opportunities. Earlier this year, Accenture rolled out a business unit focused on midmarket organizations to compete with smaller MSPs. CrowdStrike and other large security vendors have tailored cyber management platforms for smaller enterprises, leaning on partners to reach customers they can’t efficiently serve on their own.
For CrowdStrike, the calculation comes down largely to reaching more organizations and capitalizing on the specialized services its partners provide.
“The core of what we’re trying to unlock here is scale,” Dan Danielli, CrowdStrike VP of scale partnerships, told Channel Dive. “We can’t be in every single conversation in every corner of the globe.”
Partners have rapport and opportunities with SMBs that CrowdStrike wants to tap as those organizations adopt AI.
“What we also understood was that we needed to put the partner at the forefront of the conversation because they were having multiple touchpoints with customers that oftentimes went way beyond security,” Danielli said.
Platform support
CrowdStrike’s Falcon platform provides the common technology layer underneath QuiltWorks.
The cloud-native security platform covers endpoints and cloud workloads, identity and data. Within QuiltWorks, partners use Falcon and their own services to assess customers’ security posture, identify and prioritize vulnerabilities, remediate problems, and subsequently build consulting or managed services around the technology. In addition, CrowdStrike expects partners to layer their own intellectual property and services into those offerings.
That’s significant for SMBs because many have IT staff but no dedicated security team, Danielli said. Rather than asking those businesses to buy enterprise security technology and develop the expertise to operate it themselves, the QuiltWorks model lets MSPs combine CrowdStrike’s technology with the security expertise and ongoing services those customers lack.
“The easiest way for them to go and take on enterprise-grade security was by buying the outcome,” Danielli said. “What we mean by buying the outcome is having MSPs come in who have integrated CrowdStrike as the operating backbone of their security services.”
The initiative could generate conflicts. One QuiltWorks participant — Zip Security — illustrates a potential problem. The vendor already sells a managed security platform that deploys, configures and runs enterprise-grade protection for SMBs. Zip Security may gain leverage via QuiltWorks, but it risks getting pushed aside as other ecosystem providers package similar security capabilities.
Channel Dive reached out to Zip Security for comment and did not receive a response.
MSP expertise
MSP domain expertise is the special sauce that will keep QuiltWorks from reducing partners to fulfillment arms.
“The MSPs that are succeeding are the ones that are taking enterprise-grade security from CrowdStrike and making it digestible and easy for the customers to consume,” he said. “The opportunity for an MSP is to wrap their expertise around the platform, their additional services, and essentially they act as the outsourced security arm for the SMB.”
There’s also money to make beyond the initial technology sale. Danielli cited Omdia research that found every dollar of CrowdStrike sold creates “a little over $7 of partner services opportunity” over the customer lifecycle. That cycle spans consulting and design, transformation, implementation, migration and other services.
As CrowdStrike introduces more AI-driven and agentic capabilities, partners can implement those technologies for customers or incorporate them into managed offerings of their own.
“There has never been a greater time for a partner to earn dollars, not just on selling the CrowdStrike platform, but on building services around the full customer success lifecycle,” Danielli said.
While CrowdStrike’s SMB strategy broadens partner opportunities, building services around a vendor-defined platform may limit differentiation.
Security first
Danielli expects the expanded role for partners to simply bring more capabilities to customers.
“The shared mission is stopping breaches,” he said. “It’s not about anyone gaining leverage over one or the other.”
CrowdStrike will look partly to its MSP partners to determine whether the model is successful. Service providers standardized on Falcon are one of the company’s fastest-growing routes to market, according to Danielli. CrowdStrike will look for partner innovations around Falcon to gauge the program’s ongoing performance.
“We’ve got partners seeing that there is so much economic opportunity to be earned off the CrowdStrike platform that they’re taking some of their capabilities and working with other partners in the ecosystem, which is exactly what we want to see,” Danielli said.