I sat down recently with Shahin Pirooz, founder of White Dog Cyber, and one word kept surfacing that most MSPs never say out loud: pride.
Pride Is the Real Risk, Not the Competition
The reason wasn’t laziness or a lack of skill. It was pride.
Shahin has earned the right to say it. He started as a software developer, moved through enterprise healthcare and EDS, then in 1999 became CTO of an MSP called Centerbeam, which he helped grow to twenty two million dollars in recurring revenue before it sold to Earthlink. Since then he has built a series of cloud and security companies, landing on White Dog Cyber, a unified security platform built specifically for MSPs.
So when he told me pride is the single biggest risk in the MSP channel today, I didn’t hear a guest reciting a talking point. I heard someone naming his own younger self.
“I certainly was afflicted with that in my youth,” he told me. “People would come and tell me you’re doing this wrong, and I’d tell them they don’t know what they’re talking about.”
Here’s why that matters more now than it ever has. MSPs are being asked to change how they operate, not just what they sell. And when someone built a company from nothing, blood and sweat, being told to do it differently doesn’t land as advice. It lands as an attack.
Shahin’s advice was simple: get out of your own way. Don’t let pride guide the decision. Listen to what’s actually happening in the market before you defend how you’ve always done it.
That’s the shift right there. Anyone can make a decision, but quality decisions are what produce exponential growth, and quality decisions require you to survive hearing something you don’t want to hear.
Which brought us to a second pattern Shahin has watched wreck otherwise smart operators: NIH. Not Invented Here.
The NIH Trap: Why Building It Yourself Isn’t Always the Win
“It’s probably the biggest hindrance for any engineer in any field,” he said, “but specifically in a small business when you are the builder, manager, operator.”
He described his own habit early in his career: disappearing into a closet for six months to build something himself, when a build versus buy analysis would have told him to buy it and move faster. The mindset shift he now preaches to every MSP he meets started with a line he used at his own all-hands meetings at Centerbeam: “This is the way we’ve always done it are words I don’t ever want to hear again.”
That line is the whole conversation in a sentence. Comfort with your current process is not the same as that process still being correct.
We moved from mindset into the technical reality MSPs are facing right now, and this is where the conversation earned its place in this newsletter.
The Real Gap in Cybersecurity Isn’t the Attackers
Shahin’s read on cybersecurity in the AI era splits into two problems. The first is obvious: bad actors now have access to generative AI, so attacks are faster, better disguised, and harder to catch. That risk isn’t going away.
The second problem is the one almost nobody is naming correctly. There are roughly 4,500 security vendors, and Shahin’s observation is blunt. “Every one of them tells you that all you need is me and you will be protected.” But most of what vendors call AI is a beefed up machine learning model, improving hygiene inside its own platform with no visibility into anything happening outside it.
The missing piece, in his words, isn’t another tool. It’s a unifying data model, a data lake that pulls information from every technology, commercial, open source, and proprietary, so that one unified AI is looking for threats across the whole environment instead of one corner of it.
“Security needs to become as ubiquitous as virtualization became,” he said. Nobody thinks about virtualization anymore. It just runs. That’s where security has to go.
Solving MCP Sprawl With a Single Unified Layer
This is the exact problem White Dog Cyber was built to solve, and it’s also the exact problem I see across the agentic shift happening in the MSP channel right now. As MSPs build agents that need to interact with security tools directly, disabling a user, isolating an endpoint, most are heading toward what Shahin calls MCP sprawl. Twenty tools means twenty separate integrations to maintain, and every time a vendor updates their platform, the agent breaks.
White Dog’s answer is a single unified API layer. The underlying technology behind their endpoint detection has changed three times in eight years. Their API has never changed once. That’s the difference between building for today’s tools and building for whatever tools exist five years from now.
Why “We’ve Got Everything” Should Make You More Cautious, Not Less
Shahin was careful to add a caution here that every MSP evaluating a security platform needs to hear. Tool sprawl is not going away. No single vendor can be expert across all five layers of the attack surface: email, DNS, identity, endpoint, and network. So when a vendor claims they’ve got everything covered, the right response is diligence, not relief. Some of the biggest security brands grew entirely through acquisition, and a portfolio of purchased technologies is not the same thing as an integrated platform. Some of those acquired products, as he put it, go straight to the graveyard the moment the deal closes.
The final piece of our conversation is the one I keep coming back to. Shahin sees Shadow AI becoming the new Shadow IT, employees quietly downloading agents and MCPs with no visibility for the business. His fix is a mindset most MSPs haven’t applied to AI yet: treat every agent as a digital employee.
Treat Every AI Agent Like a Digital Employee
Give it an identity. Give it an owner. Give it a job description that defines the scope of what it’s allowed to do. Restrict its access to that scope instead of granting it global admin for convenience. Log everything it does. And build a kill switch, so if something goes wrong, someone can shut it off.
I asked him, half joking, if digital employees get benefits too. His answer landed perfectly. “They get to continue to operate.”
That’s the whole AI governance conversation in one line. The reward for a digital employee that behaves inside its defined scope is trust, and trust is what lets it keep running. The moment it steps outside that scope, the kill switch is the benefit that protects everyone else.
The Takeaway
If you take one thing from this conversation, let it be this. The MSPs who win the next few years won’t be the ones with the most tools. They’ll be the ones willing to hear “you’re doing this wrong” without treating it as a threat to who they are.





