Mean Time to Innocence: Why your security stack isn't broken, but the model behind it is


George Just
Head of Channel Sales
5 min read · Aug 10, 2026
By George Just, Head of Channel Sales, RedZone Technologies
I got a call recently from a partner I respect. Sharp guy, been in this business long enough to know better, which is exactly why what he said stuck with me.
His customer had an incident. Nothing catastrophic, but the kind that gets a CEO out of bed at 3am and kicks off a string of uncomfortable conversations. What happened next was this: every vendor on that account, endpoint, firewall, MDR, identity, went into immediate self-preservation mode. Not fix-it mode. Not “we're on it” mode. Every one of them working the problem, not to solve it, but to get off, or stay off, the hook.
Mean-time-to-innocence mode.
I want to say something out loud that I think we've collectively stopped saying: the customer didn't do anything wrong. They bought the right tools. At the time of purchase, every one of those decisions made sense. Endpoint protection from the leader in endpoint protection. Firewall from the company that's been doing firewalls for thirty years. MDR from whoever won the bake-off that quarter.
The stack wasn't assembled carelessly. It was assembled carefully, one smart decision at a time, over several years, by people trying to do the right thing. Then the bill came due, not in licensing costs, but in accountability.
Here's what nobody tells you when you're buying your fifth or sixth best-of-breed point solution: every one of those vendors brought their own SLA, their own escalation path, their own definition of where their responsibility ends and yours begins. And when something goes sideways in the middle of the night, you're not dealing with a security problem. You're refereeing a blame tournament.
I spend a lot of time in the field, with partners and alongside them in customer conversations. The IT directors and security leads I sit across from aren't confused about what they bought. They remember the evaluation. They remember why each tool won. What they didn't see coming was the operational weight of owning all those vendor relationships at once, and what happens when those vendors' priorities stop lining up with theirs.
The MSPs caught in the middle of this know exactly what I'm describing. And the part that actually worries me is that they're not frustrated anymore. They're resigned.
I talk to folks every week who are managing more alerts than any reasonable team could triage. They'll tell you, matter-of-factly, that they're basically playing the odds: hoping the attacker finds someone else's unpatched stack first, buying time to get the fixes in before the bad guy gets there.
That's not a security strategy. That's prayer dressed up in a dashboard.
I get it. When you're staring at a wall of red, whether you're an MSP covering a book of clients or a security team responsible for an entire organization, triage becomes survival. You're getting activity reports from every direction and insight from none of them. But we've normalized something we shouldn't have: the idea that managing security means managing the vendors who are supposed to be handling security.
That's the actual failure. Not any one tool underperforming, not any one vendor dropping the ball in the moment. It's a model that was never built to answer a simple question when it matters most: who's accountable right now?
When you buy five solutions with five SLAs from five vendors, you haven't built a security program. You've built a committee. And committees are where accountability goes to die.
Sales guys love to say “one throat to choke,” like it's a strategy instead of a slogan. I've never liked the phrase, mostly because the people who say it have usually never been the throat. It's a line they memorized, not a problem they've lived.
What actual accountability looks like is someone who holds the rest of the vendor stack to its commitments so the customer doesn't have to: one contract, one escalation path, one person who knows your business well enough that when something happens, you're already ready for it. Not a stack. An operating model.
That's the conversation I find myself having constantly right now. Not “which tool is better,” that's the wrong argument, but “who owns the outcome when it matters?”
I called that partner back a few days later. His customer's incident got resolved, eventually, but it took two weeks and four vendors pointing at each other to get there. He didn't ask me which tool would have caught it sooner. He asked me how he keeps his other clients from ending up in the same spot. I told him the fix isn't a tool at all. It's finding someone willing to own the whole outcome, not just their slice of it, before the incident happens, not after.
That's the difference between a vendor and a partner.
George Just leads Channel Sales at RedZone Technologies, where Passpoint Security and RedZone's managed services operate as a unified platform for mid-market cyber resilience. Before moving into channel leadership, he spent years working directly in cybersecurity and networking, which is part of why he thinks about vendor accountability like an operator, not just a salesperson. This is the first in a series he's writing on the intersection of channel dynamics, cybersecurity reality, and what it actually takes to build a security program that holds.
