MSP cybersecurity: thirty networks, and none of them yours
A provider is not defending one network. It is defending thirty, each belonging to somebody else, each with its own promises. What scales is not another tool: it is one console, policy you can replicate, and separation you can show client by client.
None of those are tooling problems. They are multiplication problems.
Every good idea gets multiplied by thirty
A managed provider lives with a hard arithmetic. A change that takes ten minutes for one client takes a week across the base, and a mistake that would be embarrassing once becomes an incident when it is repeated everywhere.
The other half is trust. A provider holds access to networks it does not own, usually with more reach than anyone inside those organisations has. That access is the thing clients ask about, insurers ask about, and attackers look for, because it is the shortest path to thirty targets.
So the useful question is narrow again: how do you give a technician what they need, on one client, for as long as the job lasts, and prove afterwards exactly what that was?
Onboarding is the product
How fast a new client is protected decides whether the contract is profitable. A setup that needs a designer each time does not scale.
Separation has to be provable
A single client’s auditor will ask whether another client, or another technician, can reach their systems. Saying no is easy; showing it is the work.
Staff turnover is constant
Technicians join and leave. Revocation has to be one action, not a tour of thirty environments changing shared passwords.
One console, a gateway per client, a certificate per person
QS-WAN runs a private network from one console and QNova Client puts it on the device. For a provider, three properties do the work.
A gateway per client network
Each client sits behind its own gateway, hardware or software, with its own VLANs, address space and firewall rules. Their network keeps its shape, and yours stays out of it.
A technician holds one membership per client
A device carries a separate certificate for each gateway it belongs to. Somebody who looks after eight clients has eight memberships, and revoking one leaves the other seven untouched, which is the difference between a leaver process and a fire drill.
One agent instead of a stack per client
QNova Client is one signed agent covering VPN, endpoint protection, remote support, a password manager and encrypted file transfer, under a company policy the user cannot quietly switch off. Fewer moving parts is the only thing that scales across a base.
Post-quantum by default
Everything between a device, a gateway and the control plane is post-quantum by default, aligned with FIPS 203, FIPS 204 and CNSA 2.0, and hybrid by design, for every client at once.
Runs where you decide
License the control plane onto your own infrastructure, take gateways we ship configured, or let us host it. Providers who keep client data inside their own boundary keep the console there too.
The four questions a client asks about their provider
Sooner or later one client’s auditor looks at you rather than at them. These are the questions, and the console holds the answers per client.
Can another client reach our systems?
The gateways and the edges between segments, each one way, two way, disabled or zero trust, drawn per client rather than described.
Which of your people can reach us?
User profiles, their devices and one certificate per gateway membership, with a CSV export for the client’s file.
What happens when one of them leaves?
Revocation of that membership in the console, without touching the other clients or changing a shared credential.
Is our environment checked?
Assessments per gateway return pass, fail, partially satisfied or not tested, next to a risk score built from 19 indicators.
What a green tick means across a base. A green confirmation means the change was recorded. Gateways that were offline apply it on reconnect, so a rollout across thirty sites is finished when they are all online, not when the console says saved.
What this is not, for a provider
Providers are sold platforms constantly. Here is the honest edge of this one.
It does not do your monitoring
QuantumNova is a product, not a managed service. You are the service. The platform produces the risk score and the evidence, and your team reads them.
Commercial terms live elsewhere
How the partnership works is on the partners page, not here. This page is about how the technology behaves when you run many client networks.
It does not replace your RMM or ticketing
Provisioning, ticketing and billing stay with the tools you already run.
Coverage differs by platform
Windows is the complete implementation, Linux is a genuine port with gaps we declare, and macOS and iOS are planned. Plan a mixed base by column, not by tick.
Test it on one client, then count the minutes
The number that decides this is how long a new client takes to go from nothing to protected. Run that once with us. A demonstration is free.
NEWSLETTER
Get weekly tips, product news and early access, straight to your inbox.