When you know exactly what you don't want to rebuild, the search for a partner gets a lot clearer.
Jason Rorie has already built a SOC once. He spent 16 years running an MSP before he sold it and started Triad InfoSec, a firm focused entirely on cyber risk, financial impact, and compliance. He knows the staffing, the tooling, and the operational weight that comes with standing up a security operations center, and when he started Triad, he made a decision early: he wasn't doing that again.
"I'm not in the market to build a SOC and become my own MSSP," Rorie says. But Triad's clients still needed the technical side of security to match the compliance requirements Triad was writing policy for. That gap, between the paperwork and the practice, became the problem Rorie needed to solve.
The gap between advisory and technical
Triad handles the administrative backbone of cybersecurity: policy, procedure, insurance, audits, and attorney coordination, all built to satisfy whatever framework a client is working toward. What Triad doesn't do is monitor a network at 2 a.m. or manage an EDR stack. For Rorie's clients to pass an assessment, someone had to own that side, too, and it had to be someone whose work would hold up against the same standards Triad was writing to.
"Looking for a strategic partner became very important for us, as we tried to close the loop for our clients," Rorie says. That meant the continuous monitoring, the EDR, the whole security stack had to line up with compliance and insurance requirements, not just run alongside them.
"I'm not in the market to build a SOC and become my own MSSP."
— Jason Rorie, Founder and CEO, Triad InfoSec
Sixteen years of MSP experience made him a tougher evaluator
Rorie didn't walk into his search blind. He'd used plenty of the vendors in this space himself when he was running an MSP. That familiarity narrowed the field fast, and also raised the bar. What he needed wasn't a good SOC in the abstract, he needed one that fit the specific, heavily regulated environments Triad's clients operate in.
The requirement that mattered most was a SOC staffed entirely in the U.S., with no offshore access to client systems or data. "That US-only presence was really what we were looking for," says Rorie, "because the clients that we deal with can't have people outside of the US with access to their systems and data or monitoring.”
Cyberleaf's compliance-forward posture and CMMC presence lined up with the work Triad was already doing, but it was the U.S.-only SOC that closed the gap Rorie couldn't compromise on.
A referral did what a hundred vendor decks couldn't
Rorie found Cyberleaf through an MSP partner he was already collaborating with on compliance work.
"They did a great job breaking down everything, answering the questions, and we just had a really good conversation," Rorie says. "We kept having the conversations until we put the partnership together."
The relationship came first and the technical fit followed once Rorie got into the details, including a security stack built on established, best-of-breed vendors rather than something homegrown, plus adjacent services like DFIR and CMMC advisory that could extend what Triad already offered.
"All these boxes were just being checked," he says. Layer that onto conversations with both the business and delivery sides of Cyberleaf, and the decision made itself.
What changed once the partnership was in place
What Rorie found after getting into the partnership was a level of support and collaboration he wasn’t expecting. "That's been a game changer from the strategic side," he says. On the business side, Triad can now walk into any conversation, partner or direct client, with a complete answer. If a client needs more than advisory work, Triad already has the MSSP and SOC-level services to back it up.
"It's just helped us grow, scale, add revenue and profitability," Rorie says. "Everything has really worked out well."
What MSPs should screen for in a SOC partner
Asked how he'd build a scoring matrix for evaluating five vendors, Rorie didn't start with features. He started with relationship, trust, and communication, in that order, and he was specific about why trust is the hardest one to verify upfront.
"A lot of that is happening off the radar. It's not in your face every day," he says of SOC operations. "You have to have that trust that all of the information is being funneled and orchestrated into the SOC, that the SOC is doing what they're supposed to do, analyzing these alerts, and escalating anything that's abnormal."
His advice: test it. Run the exercises. Confirm the alerts actually come through before you're relying on them at 2 a.m.
"This is an extremely trustworthy type of relationship. You have to have it. If you can nail the relationship, the trust, and the communication, and you put a solid security stack of tools inside of that, then you have a winning deal."
— Jason Rorie, Founder and CEO, Triad InfoSec
The CMMC myth Rorie wants every OSC to drop
As a compliance advisor working CMMC engagements daily, Rorie sees the same misunderstanding derail organizations before they start: the belief that certification is a paperwork sprint. "A lot of the end clients that need to be certified don't realize how much work is involved in being prepared for the assessment," he says. Thirty days and a logo on a policy template isn't a plan.
The second miss is ownership. Handing the process to an internal team, an MSP, or a co-managed provider doesn't remove the business's own work. Someone inside the organization needs to champion readiness, and few companies budget for how long that takes or what it costs.
"A lot of the end clients that need to be certified don't realize how much work is involved in being prepared for the assessment."
— Jason Rorie, Founder and CEO, Triad InfoSec
The takeaway for MSPs weighing the same decision
Rorie has made this recommendation to peers directly, in the same offline conversations MSPs have with each other about vendors and partners. His answer is consistent: reach out, tell them you were referred, and if it's not the right fit, Triad will help from the partner side instead.
Rorie didn't choose Cyberleaf because it was the biggest name in the SOC market, he chose it because he'd already done the hard version, building and running his own MSP, and he knew precisely which gap needed filling and which requirements weren't negotiable. Any MSP or advisory firm facing the same build-versus-partner decision should start where Rorie did: name the non-negotiables first, then let the relationship and the track record do the rest of the work.
If you're facing that same build-versus-partner decision, the conversation starts here.