Industries · Managed service providers

MSP cybersecurity: thirty networks, and none of them yours

A provider is not defending one network. It is defending thirty, each belonging to somebody else, each with its own promises. What scales is not another tool: it is one console, policy you can replicate, and separation you can show client by client.

What breaks first as you grow
01
A console per client
02
Policy that drifts apart
03
Credentials nobody can revoke cleanly

None of those are tooling problems. They are multiplication problems.

The constraint

Every good idea gets multiplied by thirty

A managed provider lives with a hard arithmetic. A change that takes ten minutes for one client takes a week across the base, and a mistake that would be embarrassing once becomes an incident when it is repeated everywhere.

The other half is trust. A provider holds access to networks it does not own, usually with more reach than anyone inside those organisations has. That access is the thing clients ask about, insurers ask about, and attackers look for, because it is the shortest path to thirty targets.

So the useful question is narrow again: how do you give a technician what they need, on one client, for as long as the job lasts, and prove afterwards exactly what that was?

Your access to a client is the most valuable thing you hold.
Where the multiplication hurts
01

Onboarding is the product

How fast a new client is protected decides whether the contract is profitable. A setup that needs a designer each time does not scale.

02

Separation has to be provable

A single client’s auditor will ask whether another client, or another technician, can reach their systems. Saying no is easy; showing it is the work.

03

Staff turnover is constant

Technicians join and leave. Revocation has to be one action, not a tour of thirty environments changing shared passwords.

How QS-WAN handles many clients

One console, a gateway per client, a certificate per person

QS-WAN runs a private network from one console and QNova Client puts it on the device. For a provider, three properties do the work.

01

A gateway per client network

Each client sits behind its own gateway, hardware or software, with its own VLANs, address space and firewall rules. Their network keeps its shape, and yours stays out of it.

02

A technician holds one membership per client

A device carries a separate certificate for each gateway it belongs to. Somebody who looks after eight clients has eight memberships, and revoking one leaves the other seven untouched, which is the difference between a leaver process and a fire drill.

03

One agent instead of a stack per client

QNova Client is one signed agent covering VPN, endpoint protection, remote support, a password manager and encrypted file transfer, under a company policy the user cannot quietly switch off. Fewer moving parts is the only thing that scales across a base.

Underneath, the same everywhere

Post-quantum by default

Everything between a device, a gateway and the control plane is post-quantum by default, aligned with FIPS 203, FIPS 204 and CNSA 2.0, and hybrid by design, for every client at once.

Runs where you decide

License the control plane onto your own infrastructure, take gateways we ship configured, or let us host it. Providers who keep client data inside their own boundary keep the console there too.

When a client audits you

The four questions a client asks about their provider

Sooner or later one client’s auditor looks at you rather than at them. These are the questions, and the console holds the answers per client.

Q1

Can another client reach our systems?

The gateways and the edges between segments, each one way, two way, disabled or zero trust, drawn per client rather than described.

Q2

Which of your people can reach us?

User profiles, their devices and one certificate per gateway membership, with a CSV export for the client’s file.

Q3

What happens when one of them leaves?

Revocation of that membership in the console, without touching the other clients or changing a shared credential.

Q4

Is our environment checked?

Assessments per gateway return pass, fail, partially satisfied or not tested, next to a risk score built from 19 indicators.

What a green tick means across a base. A green confirmation means the change was recorded. Gateways that were offline apply it on reconnect, so a rollout across thirty sites is finished when they are all online, not when the console says saved.

Where it stops

What this is not, for a provider

Providers are sold platforms constantly. Here is the honest edge of this one.

It does not do your monitoring

QuantumNova is a product, not a managed service. You are the service. The platform produces the risk score and the evidence, and your team reads them.

Commercial terms live elsewhere

How the partnership works is on the partners page, not here. This page is about how the technology behaves when you run many client networks.

It does not replace your RMM or ticketing

Provisioning, ticketing and billing stay with the tools you already run.

Coverage differs by platform

Windows is the complete implementation, Linux is a genuine port with gaps we declare, and macOS and iOS are planned. Plan a mixed base by column, not by tick.

Test it on one client, then count the minutes

The number that decides this is how long a new client takes to go from nothing to protected. Run that once with us. A demonstration is free.

NEWSLETTER

Get weekly tips, product news and early access, straight to your inbox.

Scroll to Top