Empowering Cybersecurity for SMBs: N-able’s Vision | Black Hat 2025
Robert Johnston discusses the acquisition of Ad Lumin and the focus on managed detection and response. Vikram Ramesh shares his experience and the transformation of N-able into a cybersecurity provider. The company aims to become a unified cyber resilience platform for SMBs, addressing the rise in ransomware attacks and the challenges faced by these businesses in managing cybersecurity.
Transcript
Hey everyone, it's Alan Hummel. We're back here at Textron tv covering Black hat on the show floor. We hope it's not too loud, but this is the first video we're doing since they opened the floor.
So it's probably a little louder than what we've done today. We're here at the booth of a company called En Enable. Let me show you how that's spelled N dash A-B-L-E-N Enable.
You get what it says though there. Let me introduce you to Robert Johnston and Vic Vikram Raquesh. Ramesh.
Ramesh, we tried, let me say that again. Let me introduce you to Robert Johnston and Vikram Ramesh, Robert Vikram. Welcome to Tech Drunk tv.
Robert, we're gonna start with you 'cause you have the mic in your hand. Give people a little bit of your background, what you do at Enable, and how you got here. Yeah, absolutely Alan.
Thank you. Um, so Robert Johnston, I'm the general manager of the Ad Lumen Business Unit, uh, here at Enable. Uh, ad Lumen was acquired by Enable in November of 2024, and we, uh, spearhead the managed detection and response and extended detection response product line, uh, here at, at enables broader cyber resiliency platform.
I'm a security practitioner by trade, an engineer by trade. Actually, I was the original founder of Ad Lumen. Great.
And, uh, and you know, we built that business over the years and I I spent about eight years in the Marine Corps doing mostly cyber security intelligence type work, brief stint at CrowdStrike, and then, and then founded, uh, ad Lumen in, in 2017. And it's been a great ride. And now we get to, to, you know, accelerate the incredible journey that we had, uh, at Ad Lumen under the Enable umbrella, uh, into, you know, their customer base worldwide.
Fantastic. I've, I've been down that road as a founder who sold my company and then helped stayed on and helped build it all the way through to IPO, so I I know that journey. Yeah.
Yeah. And it's journey. It's a great ride and there's so many exciting steps along the way and, and to see the product grow, to see the company grow, and then now to see Enable grow as well.
Uh, it's a, it's an amazing experience. We're doing such great things in the marketplace and I can't wait to talk about 'em Today with you. We're gonna talk about it, but first let's introduce Vikram.
Thank you Alan. And, uh, great to be here with Techstrong tv. Uh, Vikram Ramesh, I'm the Chief Marketing Officer here at Enable.
I joined Enable through the Ad Lumen acquisition, where I was the CMO at Ad Lumen as well. My background is about 25 years in cyber. I'm also a security engineer by trade.
Uh, but I went to the dark side, or depending on who you ask, I came from the Dark side. I went to the Dark Side Uhhuh. My background is, um, working at companies like Mandy and where I was A CMO, which led to the Google acquisition, helped build Google Security marketing team.
Uh, been doing a lot of, uh, enterprise mid-market and SMB Security. Really excited to be here at, at Enable, where Enable is in this, uh, stage of transformation to a cybersecurity company. And with Ad Lumen and other awesome solutions that we have in place, we have a phenomenal opportunity to be that cyber resilience provider for the mid-market.
So guys, I gotta tell you, I feel right at home. I have about 30 years in, in, uh, cyber myself. That's amazing.
I started a few cyber companies. It's not often you get, you know, there's a lot of Johnny come lately. Cyber became cool.
We were doing this when we called it security, right? That's right. And, and that's a big difference.
I'm afraid our, I don't wanna confuse our audience, Robert Vikram either one of you give us like top down enable what they do, and then it sounds like there's been a few acquisitions in here with different product categories. Give me that. You're the CMO Vikram, we're gonna make you do this, if it's okay, do alright.
Give me that overview from the top down on Enable. Sure. So Enable, uh, originally started as an IT management and monitoring provider.
So it was a spinoff from SolarWinds and they, they were an MS P business selling to about 25,000 MSPs globally. They also have, uh, we also have a backup and recovery business that is doing, helping customers do cloud-based backups, is a native cloud-based backup solution. Help them recover in case there's an attack and manage the whole entire it.
SA about 18 months back enable o emed ad Lumens XDR and MDR platform. And they sold the security operation solution to their end customers last year when the acquisition happened. Enable, uh, is has this vision of becoming the cyber resilience provider for the SMB and the mid-market.
So what we have is a unified cyber resilience platform that helps customers manage, secure and recover their IT and security estate. So if you break that down, uh, one step further, we have a unified endpoint management business that helps IT teams do one management, patching, monitoring and management of all their endpoints, make sure they're up to date. And they are, they have the highest level of security.
We have a security operations business, which came in through Ad Lumen, which has the XDR platform and we offer that as a managed service. This platform is unique in the sense that it, it is security agnostic or tool agnostic. We wanna meet the customers where they are with the tool they have to drive the best outcome.
So we outta the box, we support about 27 different EDRs. Wow. Right.
So from all the way from, uh, CrowdStrike Falcon to Malwarebytes integrate with environment and provide value as an XD and MDR platform. And then we have a data protection business, which I call as backup recovery. But what we are actually doing is data protection, right?
So if you look at the Lifecycle Protect endpoints, make sure there are no attacks on them in case there's an attack, get them back up and running, delivering resilience across every single stage endpoint. Resilience, security, resilience and data resilience. And that makes our end-to-end cyber resilience platform.
So ransomware proof kind of, uh, business, huh? Yeah, it's important to where we, our fundamental thesis sits is there's, there's a convergence happening and what this company is building of IT operations and security operations are becoming one certainly in the channel and in the mid market. Mm-hmm.
And if you look at Enable as a three pillared platform, that unified Endpoint management, that's doing vulnerability, right? It's doing patching, it's doing endpoint management, proactive security, very proactive in nature, right? You have the data recovery Business cove, right?
Backup and recovery is essential to ransomware recovery, essential to recovery of from any security incident, right? And then the SecOps platform, M-D-R-X-D-R, there's mail assurance, there's a, a variety of threat stopping power. And, and the three pillars we believe make one of the strongest, uh, security platforms, cyber resiliency platforms in the market today.
Love it. com? Is that the website or nothing?
That's right. Just wanna make sure we get that right. Let's talk, we here at Black Hat AI's all over the place.
Everybody's talking about ai, but black, I've been coming to Black Hat for about 25 years over at Caesar's Palace, if you remember in the day. Right. What about this show kinda resonates with Enable and the various lines of business?
Yeah. The, the most significant one to me is probably no surprise. The, the, the rise in AI capabilities that are now making their way into, into every product category that exists in security.
And, and the efficiencies that, that will be gained from that. Mostly the beneficiary of that is, is the customer. When we look at the MDR business, our managed detection response, our job is fundamentally to find threats and stop threats as fast as possible.
It is unequivocally true that an AI operation center, an AI SecOps operations platform can do that faster than a human being, and it can do it more accurately than a human being. And these new capabilities are making their way into, into our platform like many other vendors here, uh, at Black Hat. And I, I think that's gonna fundamentally change the way security is implemented, uh, at at customers.
It'll change, it'll, it'll be as impactful as Cloud was to the way security was delivered. AI it will fundamentally change the way security is delivered as well to end customers. And I think that's the theme this year.
And it will be the theme probably for the next five years, are the leaps forward that, that technology makes. That's Bold. Yeah.
Who could look five years? I I, I'm, I'm lucky in two to three years, five years it might be Quantum, who knows? That's right.
Right. But what, um, so at RSA this year, we launched our state of the SOC report as looking at our SOC with the thousands of customers that we are supporting to see what is the experience they're having. 'cause we have AI built into the tooling before it was called AI soc and we've been leveraging it for threat hunting.
Right. What is interesting is in a production environment with thousands of customers, 70% of threat hunting and all our SOC operations are already automated ai. Right.
And now there are more capabilities that we are seeing where, how do I make my threat hunting team more efficient and more faster? They focus on the things that matter. While the AI SOC focus on other things, I don't think it's, it's gonna replace the human element, but it's AI meets hi or however you wanna call it, but that I see is the future of the soc.
Absolutely. Absolutely. I know that the show Flood just opened, but blackouts been going on now, you know, over the weekend it started.
Um, what are you hearing from people, like from the attendees, the security pros out here? Yeah. It's, it's, uh, this year especially, right?
And, and it's not that it's a big surprise. You, you initially alluded to that it's about ransomware, it's about credential based attacks that keeps in increasing enable as a company is focused on SMB and the mid-market space. Yes.
Right. And we launched our inaugural threat intel report at Blackhead this year. What we've seen is it's almost been a 200 fold increase in attacks to the SMB space.
Right? Now, the attackers are not saying I have to target only enterprises. They're going down market.
And Well, I, I think it's because the enterprises are wise to ransomware. They have the resources to kinda ransomware proof themselves. Unfortunately, Most SMBs don't.
Right. And it's probably the same IT person also managing security. Right.
And that's where I think you, it Stone have need a solution like, which is unified, which can say, you know what? I can manage across the board, still deliver the value you can while improving your posture, giving your enterprise class security at a mid-market price. Right.
Agreed. You know, when I first started in this business, there was no cyber crime. There was no ransomware and ecr, this was a game played, uh, by nation states.
Right Now, today it's much different. Today you almost barely hear about nation states. It's predominantly the criminal side, uh, of cyber that that's broken out.
Some nation states are doing it for the financial state. This is very true. You could come to Lake North Korea, they estimate 30% of their GDP Very True comes from hacking.
Very true. Very true. But the, with that shift, right?
Nation states typically care about hacking other nation states. But with that shift e crime, right. What what has happened is the, the targets have shifted to the SMB in the, in the mid-market.
They're just easier targets. They're easier. I think fundamentally they view them as as weaker long Hanging fruit.
Yeah. Which companies like ours need to make that not a reality. Right?
Yeah. And, and look, for as long as I've been in security, tell you a funny story. I started a company called Still Secure, 2001 outta Boulder.
2007. I went to my board. Security's too hard for most SMBs, it's just too hard.
We should become an MSSP and do it for them. 'cause we, we had something called a NAC network access control, vulnerability management, intrusion prevention, UTM, all that. And we, we bought a, uh, an MSSP and we started looking at buying others and growing organically fundamentally that has, that equation hasn't changed.
The SMBs just they don't have the resources to fight this on their own or The time or the time. Probably the most valuable asset Time's the resource. Yeah.
You got time, you got people, you got tools, people, process, technology. It hasn't changed. So, and it's always been a, uh, a solution starved market at this level.
Yep. If you look at the car customers that we support and how we sell through, we sell, we have 25,000 MSPs as customers that are servicing this market. Right.
So that's your channel and that's a huge value. Right? Absolutely.
If you look at that market, they've traditionally bought IT solutions fifth, uh, with the rate at which MDR is growing, but only 25% of that MSP base is even adopting this. Right. So there's a huge upside to say, you know what, let me secure you with an enterprise class security and also give you resilience by making sure there's data protection so then you can manage it.
Right. And if you look at platformization, which is thrown about with all, every enterprise vendor out there, I think it applies more to the mid-market and SME space because they don't have the resources. They'd love to get a single vendor that can give you back.
Absolutely. And they've been, you know, the, the flip side of it is if you didn't have that 25,000 strong channel going after, I forgot what it was for, or 6 million SMBs in the world, right? It's like herding cats to a certain extent.
But when you have that strong channel you can offer, you know, to the people they're already dealing with, and that, that's a key piece of it. And that channel is important. 'cause when you look at the SM b you, you're talking, uh, a small credit union or a community bank or dentist office, that that individual that's there doesn't under secure understand security doesn't have a clue.
He he does dentistry. Right. I was gonna say doesn't understand it.
Let on Security. Yeah. And, and so they rely on that channel to be their trusted advisor, to be the decision maker that makes the right decision, that protects their business so they can get back to being a dentist or a community bank.
It's funny you said this, I learned this lesson, which, so we became an MSSP, all of a sudden we started signing up all these orthodontists, you know? Yeah. I don't know if your kids ever got braces or if you have kids that the facts.
Yeah. So braces are somewhere between five and $10,000. Where I live in Boca, the kids go through two brace periods, the pre braces and then braces.
Turns out no one pays for their braces in one fell swoop. You pay your orthodontist every month, whatever it is. I figured $150 or whatever, every orthodontist either keeps that credit card number in a spreadsheet or if they're very secure, they write it on paper.
Yeah. And some poor lady pulls out that paper every month that does the billing. We were doing PCI audits.
It's a nightmare. It's a disaster waiting to happen. And, and, but this is the entire orthodontics industry.
This is how they work. So a solution like this, it, it's really is a godsend to them. And what we found out is they had one IT person who's not a full-time, it's a hired IT person, an MSP who comes in and does their it, their security, their email, their network.
And this, this is the state of art. I mean, this is what it Is. And if you back it up, uh, a layer to the MSP, you have the, the, the problem where security is very much a 24 hours a day, seven day a week war.
You're not set for that With, with a very specific set of expertise that you need in order to fight that battle. And the managed service providers, they were providing help desk desktop support. They are security centric now and they're evolving, but they're, they're oftentimes not equipped.
They need 50 partner for that 24 hour a day, seven day week war. Oh yeah. A hundred percent.
Yeah. And it's been an ev ongoing thing. Hey, this sounds like a great market.
I hope you enjoy the rest of Black Hat. Thanks for coming on and, and getting us smart. A little bit about Enable.
Yeah. Thank you. We'll be talking more soon.
Yeah. All right. Wear here at Black Hat at the Enable Booth.
We'll be back with another interview in just a minute. You're watching Tech Drunk TV.