Thrive, a global technology outsourcing provider specializing in AI, cybersecurity, cloud and managed IT services, has expanded its NextGen managed services platform with new security architecture powered by Elastic and Cato Networks. The investments are designed to strengthen Thrive’s Managed Detection and Response capabilities, improve threat visibility and introduce a more modern Zero Trust approach to secure access for mid-market organizations.
The enhancements represent a broader modernization of the technology underlying Thrive’s managed security services rather than the introduction of standalone security products. Thrive is integrating Elastic more deeply into its MDR technology foundation while adding Cato Networks’ Universal Zero Trust Network Access technology to its managed security portfolio.
The strategy is intended to give customers enterprise-grade security capabilities without requiring them to build, integrate and operate the underlying security infrastructure internally.
That proposition is particularly relevant for smaller and mid-sized organizations that face many of the same cybersecurity threats as large enterprises but typically operate with smaller IT and security teams. Thrive pointed to Gartner research indicating that nearly three-quarters of CISOs say their cybersecurity teams lack sufficient staffing.
Thrive’s approach is to combine technology from specialized cybersecurity vendors with its own managed services organization, allowing customers to consume sophisticated security tools through a managed platform.
A major part of the latest investment involves Elastic.
Thrive has enhanced the technology foundation supporting its Managed Detection and Response service with Elastic to improve how security information is collected, analyzed and prioritized across customer environments.
The expanded architecture enables Thrive to ingest and analyze security information from a wider variety of sources, including cloud infrastructure, software-as-a-service applications, endpoints, networks and on-premises systems.
Bringing those data sources together can provide security teams with a more complete picture of activity across an organization’s technology environment instead of requiring analysts to investigate isolated security systems independently.
Thrive is also applying AI and machine learning to the collected security information to identify emerging threats and reduce false positives.
False positives remain a significant operational challenge in cybersecurity because automated tools can generate large volumes of alerts that ultimately do not represent genuine attacks. That can consume analyst time and potentially make it harder to identify the threats requiring immediate attention.
By using AI and machine learning to help prioritize the information flowing into its MDR environment, Thrive is seeking to direct its security personnel toward activity carrying the greatest potential risk.
The Elastic-based infrastructure is also designed to scale as customers generate larger quantities of security telemetry. Thrive said the platform can support growing customer environments and increasing security-data volumes without sacrificing performance or visibility.
Those capabilities feed into Thrive’s 24×7 security operations, where human security professionals investigate and respond to suspicious activity.
The combination reflects a broader trend in cybersecurity toward using AI as an augmentation layer for analysts rather than attempting to remove people entirely from security operations.
Elastic described the model as keeping a “human on the loop,” with AI helping automate routine analytical work while security specialists remain responsible for evaluating adversarial behavior and responding to threats.
The second major element of Thrive’s platform investment focuses on secure access.
Thrive is incorporating Cato Networks Universal Zero Trust Network Access, or UZTNA, into its managed security portfolio as an alternative to traditional virtual private networks.
Traditional VPNs generally provide remote users with connectivity into a corporate network. Zero Trust architectures instead focus more heavily on continuously evaluating users, devices, applications and the context surrounding each access request.
Cato’s technology continuously validates identity and context rather than relying primarily on whether a user has successfully connected to a corporate network.
That enables Thrive to provide secure access for employees regardless of where they are working while reducing dependence on traditional remote-access infrastructure.
Under the model, employees can access applications from different locations without using conventional VPN architecture. Organizations can apply continuous identity validation and application-specific access controls intended to prevent unauthorized access and limit lateral movement through corporate systems.
The platform can also provide access for contractors and employees using personally owned devices while attempting to minimize additional complexity for internal IT organizations.
Because the Zero Trust platform is cloud-native, Thrive said it can also reduce the management overhead associated with maintaining legacy remote access systems.
That shift is increasingly important as corporate environments become more distributed.
Applications may now operate across public clouds, SaaS platforms, private data centers and traditional on-premises infrastructure, while employees can connect from offices, homes or other remote locations.
In that environment, the traditional security model of treating everything inside the corporate network as trusted becomes less effective.
Zero Trust architectures instead assume that access should continually be verified based on factors such as identity, device and the specific application being accessed.
For Thrive, combining Cato’s access technology with its MDR capabilities creates an opportunity to manage multiple parts of the cybersecurity lifecycle through the same broader NextGen services platform.
The MDR system focuses on collecting security information, detecting potentially malicious activity and supporting incident response, while the Cato integration addresses how users securely connect to corporate applications and resources.
The investments are also consistent with Thrive’s positioning as a managed technology provider rather than simply a reseller of individual security products.
Thrive provides services spanning AI, cybersecurity, cloud infrastructure, compliance and traditional MSP and MSSP functions. Its operations include a 24x7x365 Security Operations Center and Network Operations Center.
The company’s strategy centers on standardizing, scaling and automating technology environments for small and mid-market customers that may not have the resources to operate comparable technology stacks internally.
The latest integrations therefore expand the technology available behind Thrive’s managed services while keeping much of the implementation and ongoing management responsibility within Thrive.
Rather than requiring customers to separately purchase an analytics platform, build a security operations workflow, deploy Zero Trust access infrastructure and staff teams capable of operating each component, Thrive is seeking to deliver those capabilities as an integrated managed service.
The approach could become increasingly relevant as security architectures grow more complex and organizations attempt to manage expanding volumes of data without proportionally expanding their cybersecurity teams.
Thrive said its broader objective is to avoid forcing customers to choose between sophisticated enterprise security and operational simplicity.
Continually updating the technology underlying its NextGen platform allows the company to introduce newer cybersecurity capabilities while insulating customers from some of the implementation and management complexity that normally accompanies them.
KEY QUOTES:
“Building a truly NextGen managed services platform requires us to continually evaluate every layer of the technology stack and invest where we can meaningfully improve the client experience. By bringing together best-of-breed technologies with the expertise we’ve built across thousands of client environments, we’re delivering enterprise-grade capabilities in a way that’s simpler to consume, easier to scale, and designed around better business outcomes.”
Bill McLaughlin, CEO of Thrive
“Security is fundamentally a data problem, but for too long, legacy constraints have forced organizations to make risk-based decisions on budget, dropping critical data and leaving blind spots where adversaries hide. Elastic gives Thrive the high-speed foundation to ingest and analyze security data at scale without compromise, and apply transparent, ‘show-your-work’ AI to automate away the mundane analyst toil. By combining our open platform with Thrive’s managed expertise, we keep a critical ‘human on the loop’ to cut through the noise, focus on actual adversarial behavior, and respond to threats at machine speed.”
Mike Nichols, General Manager, Security at Elastic
“Secure access needs to follow the user, not the network. As security and networking continue to converge, organizations are looking for platforms that apply consistent, risk-based access policies across users, devices, and applications without increasing operational burden. Together with Thrive, we’re helping customers simplify secure access with a Zero Trust approach designed for today’s distributed environments.”
Addie Finch, Vice President of Channels, Americas at Cato Networks