Building MSP Partner Ecosystems That Scale: Naveed Malik, Sophos, on Recurring Revenue

Naveed Mlik

Naveed Malik has spent more than 15 years building the partner engines behind some of the fastest growth stories in cybersecurity and SaaS. At Splunk, he scaled EMEA partner revenue from $17 million to $450 million; at SentinelOne, he grew the region’s partnerships business from $25 million to $200 million in ARR, operationalizing a service-led ecosystem and a usage-based MSP model along the way. Now Senior Director, EMEA MSP Channel Sales at Sophos, Naveed’s test for whether a partner motion will break through or stall is simple: does it help MSPs grow, or does it lock them into complexity?

Prior to our MSP GLOBAL 2026 event, we had the pleasure to chat with Naveed about what MSPs really need from vendor partners today, how marketplace and consumption-based models are rewriting channel economics, why cloud co-sell is harder in practice than on paper, and the operational discipline it takes to build predictable, high-margin recurring revenue. He also shares the debate he thinks the channel most needs to have face to face, and the practical questions every MSP should be putting to vendors and distributors at PortAventura.

You’ve scaled partner ecosystems from tens of millions to hundreds of millions in ARR at Splunk and SentinelOne. What’s the one pattern that shows up every time a partner motion is about to break through versus stall out?

Naveed Malik

The difference is whether the partner motion helps MSPs grow, rather than locks them into complexity. When it breaks through, partners can clearly see how the vendor helps them build predictable, recurring revenue, improve profitability, and deliver services customers genuinely need. That requires openness, not forced full-stack migration; a centralized operational layer; flexible billing that matches how MSPs invoice their own customers; and managed detection capabilities that extend the MSP’s team without replacing it. When it stalls, the motion is too transactional: too much focus on point-of-sale margin or platform lock-in, and not enough on helping MSPs create repeatable, profitable managed services. The best partner ecosystems turn innovation into a scalable services model, with clear control points and room for MSPs to differentiate.

Cybersecurity vendors increasingly lean on MSPs and MSSPs as their primary route to market. From your vantage point at Sophos, what’s changed most about what MSPs need from a vendor partner in the last two to three years?

Naveed Malik

What has changed most is that MSPs need operational leverage. They are being asked by SMB customers to deliver a higher level of security maturity, often without having a full security team or 24/7 SOC in-house. That means they need vendor partners that help them simplify delivery, not add more disconnected tools. A centralized platform such as Sophos Central gives MSPs visibility across the customer environment, including mixed-vendor estates, while MSP Flex aligns billing to the monthly consumption model MSPs already use with their customers. MDR then extends their operational capability with continuous monitoring, threat hunting, investigation, and response, while the MSP keeps ownership of the customer relationship, policy alignment and commercial model. The vendor role is no longer just to provide products: it is to help MSPs deliver security outcomes profitably and at scale.

You introduced AWS CPPO and built usage-based MSP models at SentinelOne. How are marketplace and consumption-based models reshaping the economics of the MSP channel, and are most MSPs actually ready for that shift?

Naveed Malik

Marketplace and consumption-based models are reshaping the MSP channel because they reflect how MSPs actually operate: recurring, flexible, service-led and aligned to customer usage. For MSPs, monthly billing is not a minor operational detail; it is central to profitability. A forced lift-and-shift to a new platform can be disruptive for the MSP, the end customer and the billing model. The MSPs that are ready for this shift are those that understand their unit economics, package services clearly, and can manage usage, pricing and customer success with discipline. The opportunity is significant, but consumption only works if it is supported by a platform and program that let MSPs scale without losing margin. In that sense, marketplace and consumption models should be treated as part of a broader services growth strategy, not simply as a new procurement route.

You’ve operated across hypergrowth startups, public vendors, and platform companies. Does “partner-led growth” mean something fundamentally different depending on company stage, or is the core playbook the same everywhere?

Naveed Malik

The core principles are consistent, but the execution changes with company stage. In a hypergrowth company, partner-led growth is often about building momentum quickly: identifying the right routes to market, creating repeatable programs, and proving that partners can generate scalable revenue. In a larger platform company, it becomes more about orchestration: aligning product, marketplaces, distributors, field teams and partner services around a common growth model. What does not change is the need to make the partner successful. MSPs should be able to grow their own services and customer relationships, not simply become an extension of a vendor’s stack. If the partner cannot make money, differentiate their service, maintain customer ownership, and deliver better security outcomes, the model will not scale. Partner-led growth only works when the vendor’s strategy and the partner’s economics are aligned.

A lot of vendors talk about co-sell with AWS, Azure, and GCP, but MSPs often say it’s harder in practice than on paper. What’s the gap between the co-sell pitch and co-sell reality, and how should MSPs approach vendors about closing it?

Naveed Malik

The gap is usually execution. On paper, co-sell promises broader reach, faster demand generation, and access to cloud ecosystems. In practice, MSPs need clarity on who owns the opportunity, how incentives work, how marketplace offers are packaged, and how the vendor will support the partner through the sales cycle. Without that structure, co-sell can become slow and difficult to navigate. MSPs should approach vendors with a clear services proposition: which customer segment they serve, which security outcomes they can deliver, how they manage the environment, and how flexible billing or consumption models support the customer lifecycle. Vendors also need to make co-sell easier by providing practical enablement, marketplace-ready offers, field alignment and operational models that help MSPs convert interest into recurring revenue.

Predictable, repeatable, high-margin revenue is the goal for any MSP. In your experience, what’s the most common thing MSPs get wrong when trying to build that kind of partner-sourced revenue engine?

Naveed Malik

The most common mistake is trying to build recurring revenue on top of a model that is still too reactive, too fragmented, or too project-based. Predictable, high-margin services require standardisation: fewer platforms, clearer packages, disciplined delivery and measurable outcomes. Many MSPs underestimate the importance of operational hygiene and consistency. They need strict separation of admin privileges, secure use of remote tools, tenant isolation, and continuous monitoring across endpoint, identity, network and email. MSPs have also become targets themselves: compromise one MSP and an attacker can reach dozens of customers. That is why 24/7 detection and response, supported by XDR and MDR, is becoming a baseline requirement. The MSPs that succeed industrialize the service without losing the advisory relationship. They use automation and unified platforms to create efficiency, then reinvest that capacity into higher-value conversations around risk, compliance and cyber maturity.

You’ll be speaking at MSP Global, what’s the conversation or debate happening in the channel right now that you think MSPs most need to hear addressed in person, not just read about?

Naveed Malik

The debate MSPs need to have in person is how their role is changing from outsourced IT or security delivery to strategic cyber leadership. Customers increasingly depend on MSPs to interpret risk, manage compliance expectations, and guide security investment decisions. At the same time, MSPs must protect their own environments with the same discipline they apply to customers, because they are now high-value targets. There is also a practical debate around AI: the question is not whether a product uses AI, but whether it improves detection quality, reduces false positives, speeds up triage, and helps smaller teams act faster. AI should be a means to improve operational capability, not an end in itself. Those conversations are best had face to face because they are about business model evolution, accountability, security maturity, and how the channel can deliver outcomes at scale.

For MSPs attending MSP Global this year looking to strengthen their vendor and distributor relationships, what’s the single most useful thing they can walk away from the event with?

Naveed Malik

The most useful outcome is a clearer growth plan: which vendor and distributor relationships can genuinely help them build differentiated services, improve profitability and scale recurring revenue without locking them into unnecessary complexity. MSPs should leave with a sharper understanding of where they can create value: MDR, XDR, identity protection, compliance services, firewall-as-a-service, marketplace models, or distributor-led scale. They should also ask vendors very practical questions: How will you help me reduce operational burden? How will you help me protect my own environment as well as my customers’? How will you support flexible billing and profitable service delivery? How will you help me move from selling tools to delivering outcomes? The strongest relationships are those that help MSPs grow sustainably, standardize on fewer platforms, automate aggressively, and package higher-value security services their SMB customers can actually consume.

Eugenio Cirmi Avatar

This might also interest you