<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="https://www.jain.com/assets/img/6adafce5-1.1"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Operations Center &#8211; Jain.com</title>
	<atom:link href="/tag/security-operations-center/feed/" rel="self" type="application/rss+xml" />
	<link></link>
	<description>Data centers, connectivity, and security — news and analysis</description>
	<lastBuildDate>Wed, 02 Sep 2026 11:36:43 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>/wp-content/uploads/2026/08/jain-com-icon-512-150x150.png</url>
	<title>Security Operations Center &#8211; Jain.com</title>
	<link></link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Tusker Buys Fortress SRM, Adding 50 Staff and a 24/7 SOC</title>
		<link>/tusker-acquires-fortress-srm-managed-security-roll-up/</link>
		
		<dc:creator><![CDATA[Deepak Jain]]></dc:creator>
		<pubDate>Wed, 02 Sep 2026 11:36:43 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Cybersecurity Consolidation]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[Managed Security]]></category>
		<category><![CDATA[Managed Service Providers]]></category>
		<category><![CDATA[mergers and acquisitions]]></category>
		<category><![CDATA[Mid-Market IT]]></category>
		<category><![CDATA[Security Operations Center]]></category>
		<guid isPermaLink="false">/tusker-acquires-fortress-srm-managed-security-roll-up/</guid>

					<description><![CDATA[Tusker has acquired Fortress SRM, a Cleveland cybersecurity firm with about 50 specialists and a 24/7 security operations center, in its fifth deal since 2017. The purchase adds an Ohio Valley hub and illustrates how mid-market IT providers are rolling up regional security specialists to sell detection and response.]]></description>
										<content:encoded><![CDATA[<div class="jain-post-grid">
<div class="jain-post-main">
<section class="jain-tldr" aria-label="Plain-English summary">
<p class="jain-tldr-kicker">TL;DR · 30-second read</p>
<h2>The Short Version</h2>
<p>A Chicago technology company called Tusker has bought Fortress SRM, a Cleveland firm of about 50 people whose job is keeping businesses from being hacked.</p>
<p>Fortress runs an operation staffed around the clock, every day of the year, where analysts watch customers&#8217; computer networks for intruders and step in when one gets through. Most mid-sized companies cannot afford to staff that themselves, so they rent it from firms like this one.</p>
<p>It is Tusker&#8217;s fifth purchase since 2017, and the company says more are planned.</p>
</section>
<p>Tusker, a Chicago-headquartered technology solutions provider, announced on September 2, 2026 that it has acquired Fortress SRM, a Cleveland cybersecurity firm founded in 2018. According to Tusker&#8217;s announcement, the deal adds roughly 50 cybersecurity professionals, a 24/7 Security Operations Center, and a sixth regional hub covering the Ohio Valley. Financial terms were not disclosed.</p>
<p>Fortress SRM serves customers across Ohio, northern Michigan and Wisconsin, with services spanning security consulting and advisory work, virtual CISO leadership, managed security, incident response and digital forensics. The transaction is Tusker&#8217;s fifth acquisition since 2017 and its first since the company consolidated its portfolio businesses under a single brand earlier this year. Tusker says it now has more than 400 employees and hubs in Chicago, Boston, Green Bay, Duluth, Eau Claire and Cleveland, and that further acquisitions are planned.</p>
<h2>Executive Summary</h2>
<p>The headline asset in this deal is not the customer list — it is the round-the-clock watch floor. A Security Operations Center, or SOC, is a team that monitors customer networks continuously for signs of intrusion and coordinates the response when something is found. Building one is a fixed-cost exercise: you need enough trained analysts to staff three shifts, weekends and holidays before you can credibly answer a single alert at 3 a.m. That cost only makes sense when it is spread across many customers, which is precisely why regional security firms that have already paid it are attractive to acquirers who have not.</p>
<p>Tusker&#8217;s position is a common one in the mid-market channel. It has scale in the things that are hard to differentiate — hardware, deployment, help desk, lifecycle management — and comparatively thin capability in the thing customers are currently most anxious about. Buying a 50-person security practice with an operating SOC, a virtual CISO bench and a digital forensics capability is a faster route to that capability than hiring into a labor market where experienced detection-and-response analysts are scarce and expensive.</p>
<p>For the wider market, the deal is a small but legible data point in an ongoing consolidation: independent regional managed security providers are being absorbed into broader IT services platforms, because mid-market buyers increasingly want detection and response as a subscription rather than a staffing problem. What Tusker&#8217;s announcement does not establish is how large or how profitable that practice is, or on what terms it changed hands.</p>
<h2>The Economics of Watching a Network at 3 a.m.</h2>
<p>Continuous security monitoring has an unforgiving cost structure. Coverage that is genuinely 24 hours a day, seven days a week, requires multiple analyst shifts plus slack for holidays, illness and turnover — before any tooling, threat intelligence feeds or escalation playbooks are paid for. A mid-sized manufacturer or hospital system that tried to build this in-house would be hiring a team it can keep busy only intermittently. The managed model works because that same team&#8217;s attention is sold in slices to dozens of organizations at once, and because attacks against one customer generate detection knowledge that protects the rest.</p>
<p>That arithmetic is what makes an existing SOC a genuine asset rather than a line item. Fortress SRM&#8217;s described capability set — consulting and advisory, virtual CISO leadership, managed security, incident response and digital forensics, and the SOC itself — maps onto a full customer lifecycle: assess, advise, monitor, and respond when monitoring finds something. A firm that can only do the assessment half sells projects; a firm that can do the monitoring half sells contracts. Recurring revenue is the reason security practices command attention from acquirers, though Tusker has not said what portion of the acquired business is recurring.</p>
<h2>The Cross-Sell Case Cuts Both Ways</h2>
<p>Jess Walpole, president of Fortress SRM, framed the deal around customer convenience: security clients who also want help with desktops, servers, networks and modernization now get it from one partner. That is a real benefit, and it reflects a genuine mid-market preference for fewer vendors. But the more consequential flow probably runs the other direction. Tusker reports more than 400 employees and clients across the country; selling managed detection and response into an installed base that already trusts the provider with its infrastructure is a cheaper path to growth than winning security deals cold.</p>
<p>Consolidation of this kind does raise a question buyers should ask openly, and it is a question about structure rather than about either company&#8217;s intentions. When the same organization advises on security strategy, supplies the hardware and manages the environment, the advisory function loses some of its natural independence. Virtual CISO services — essentially a fractional security executive rented by organizations too small to employ one — are valuable precisely because they are supposed to represent the customer&#8217;s interests. Providers that combine advisory with product and managed services can manage that tension well, through separate reporting lines, transparent product economics or a willingness to recommend third-party tooling, but customers should ask how it is being handled rather than assume.</p>
<h2>A Great Lakes Roll-Up Reaches the Ohio Valley</h2>
<p>Look at Tusker&#8217;s hub map — Chicago, Boston, Green Bay, Duluth, Eau Claire and now Cleveland — and the strategy reads clearly. With one East Coast exception, this is a Great Lakes and Upper Midwest platform assembled around mid-sized regional markets rather than the coastal metros where national systems integrators concentrate. Those markets have plenty of manufacturers, healthcare providers, municipalities and school districts that face the same regulatory and insurance pressure on cybersecurity as larger firms, with none of the in-house staff. Cleveland extends that footprint into the Ohio Valley and, per the announcement, into a service territory already covering Ohio, northern Michigan and Wisconsin.</p>
<p>The risk in any roll-up is that the acquired capability degrades in transit. Tusker&#8217;s stated asset here is people: roughly 50 specialists whose value is entirely portable if they choose to leave. Integration also has to reconcile monitoring platforms, ticketing systems, escalation procedures and service-level commitments across organizations that built them independently — work that is invisible to customers when it goes right and very visible when it does not. Tusker has done this four times before and completed a brand unification earlier this year, which is evidence of a repeatable process rather than proof of a smooth outcome. The company also says more acquisitions are planned, which means integration capacity, not deal flow, is likely to be the binding constraint.</p>
<h2>Background</h2>
<p>Tusker began as a Chicago IT hardware distributor and has since assembled a broader technology services platform through acquisition, adding capabilities in advisory, professional services, managed services and lifecycle support. Formerly operating as ACP CreativIT, the company brought five regional firms under the single Tusker brand earlier in 2026 and has been named to the Channel Futures MSP 501 list of top managed service providers for 2026, its second appearance. The Fortress SRM deal is its fifth acquisition since 2017.</p>
<p>The market context is a mid-market squeeze. Organizations of a few hundred to a few thousand employees now face the same ransomware exposure, cyber insurance questionnaires and regulatory expectations as large enterprises, without the budget for a standing security team. That gap created a generation of regional managed security providers — Fortress SRM among them, founded in 2018 — and those firms have in turn become acquisition targets for full-stack IT providers seeking recurring security revenue and capabilities that are slow and costly to build from scratch.</p>
<p>Source: <a href="https://www.prnewswire.com/news-releases/tusker-acquires-fortress-srm-to-expand-cybersecurity-services-302867089.html">Tusker Acquires Fortress SRM to Expand Cybersecurity Services</a> — Tusker&#8217;s September 2, 2026 announcement of its acquisition of the Cleveland cybersecurity firm, including headcount, service capabilities and regional hub details.</p>
</div>
<aside class="jain-rail">
<section class="jain-gaps" aria-label="What the release does not say">
<p class="jain-gaps-kicker">⚠ What They Aren’t Saying</p>
<h2>What the Release Doesn&#8217;t Say</h2>
<p><strong>Deal terms and financing.</strong> Tusker disclosed no purchase price, no consideration structure and no financing source. Nothing in the announcement indicates whether the deal was funded from cash flow, debt or outside equity, whether any portion is contingent on future performance through an earn-out, or whether a financial sponsor stands behind the acquisition program. For a company that says further acquisitions are planned, the capital behind that plan is the central unanswered question.</p>
<p><strong>The size and shape of the acquired business.</strong> The companies have not disclosed Fortress SRM&#8217;s revenue, its recurring versus project mix, how many customers or monitored endpoints the SOC covers, or its capacity headroom. Nor have they said whether the SOC is built on proprietary tooling or licensed third-party platforms — a material distinction for margin, portability and what happens at contract renewal. Independent assurance also goes unmentioned: neither company has stated which certifications or audits the SOC holds, such as SOC 2 Type II attestation or ISO 27001, the standard external checks buyers use to verify that a monitoring provider&#8217;s own controls are sound.</p>
<p><strong>Integration, retention and the road ahead.</strong> Tusker has not said whether Fortress SRM&#8217;s leadership is staying, whether retention arrangements cover the roughly 50 specialists the deal is built around, or on what timeline the SOC will be made available to Tusker&#8217;s existing national client base and under what service-level commitments. It has also not addressed whether existing Fortress SRM contracts, pricing or escalation paths change, how it will handle the advisory-independence question where virtual CISO work sits alongside hardware and managed services, or what the pipeline and criteria are for the additional acquisitions it says are coming.</p>
</section>
<section class="jain-faq">
<h2>Frequently Asked Questions</h2>
<h3>What did Tusker announce?</h3>
<p>On September 2, 2026, Tusker said it had acquired Fortress SRM, a Cleveland-based cybersecurity firm. The deal adds about 50 security professionals, a 24/7 Security Operations Center and a sixth regional hub. Financial terms were not disclosed.</p>
<h3>Who is Fortress SRM?</h3>
<p>Fortress SRM is a Cleveland cybersecurity firm founded in 2018, serving customers across Ohio, northern Michigan and Wisconsin with roughly 50 professionals. Its services include security consulting, virtual CISO leadership, managed security, incident response, digital forensics and a 24/7 SOC.</p>
<h3>What is a Security Operations Center?</h3>
<p>A SOC is a team that monitors customer networks continuously for signs of intrusion, investigates alerts and coordinates the response to confirmed incidents. Running one around the clock requires multiple analyst shifts, which is why most mid-sized organizations rent the capability rather than build it.</p>
<h3>How much did Tusker pay for Fortress SRM?</h3>
<p>The purchase price was not disclosed. Tusker&#8217;s announcement includes no financial terms, no consideration structure and no indication of how the transaction was financed.</p>
<h3>How big is Tusker after the acquisition?</h3>
<p>Tusker says it has more than 400 employees. It operates regional hubs in Chicago, Boston, Green Bay, Duluth, Eau Claire and, with this deal, Cleveland.</p>
<h3>Is this Tusker&#x27;s first acquisition?</h3>
<p>No. It is Tusker&#8217;s fifth acquisition since 2017, and the first since the company unified its portfolio businesses under the Tusker brand earlier in 2026. Tusker says additional acquisitions are planned.</p>
<h3>What is a virtual CISO?</h3>
<p>A virtual CISO is a fractional chief information security officer — an experienced security executive shared across several client organizations. It gives companies too small to employ a full-time CISO access to senior security strategy, governance and compliance leadership on a subscription basis.</p>
<h3>Why are mid-market companies outsourcing detection and response?</h3>
<p>Continuous monitoring requires enough trained analysts to cover every shift, plus tooling and threat intelligence. That fixed cost is difficult to justify for a single mid-sized organization but works well when spread across many, so buyers increasingly purchase it as a service.</p>
<h3>What changes for Fortress SRM&#x27;s existing customers?</h3>
<p>Tusker&#8217;s stated intent is that security clients gain access to broader technology services — desktops, servers, networks, planning and managed services — while keeping the same team and service style. The companies have not said whether contracts, pricing or escalation procedures change.</p>
<h3>What does the deal mean for Tusker&#x27;s existing clients?</h3>
<p>It gives Tusker an in-house 24/7 monitoring capability plus incident response and forensics to offer across its client base. Tusker has not specified when those services will be made available nationally or under what service-level commitments.</p>
<h3>Why does the Ohio Valley location matter?</h3>
<p>Cleveland extends Tusker&#8217;s footprint beyond its Great Lakes and Upper Midwest core into a new regional market. Mid-sized markets like these hold manufacturers, healthcare providers and public-sector organizations that face serious security requirements without in-house security staff.</p>
<h3>Is consolidation of regional security providers a broader trend?</h3>
<p>This deal fits a recognizable pattern: broader IT services platforms acquiring regional managed security specialists to add recurring monitoring revenue and capability they would otherwise have to hire for. Whether the pace continues depends on capital availability and integration capacity.</p>
<h3>What are the main risks in an acquisition like this?</h3>
<p>The acquired value is largely people, and security specialists are portable. Integration must also reconcile monitoring platforms, ticketing and escalation procedures across two organizations. Both risks are manageable but neither is automatic.</p>
<h3>Should buyers worry about a provider that both advises on security and sells the products?</h3>
<p>It is worth asking about. Combining advisory work with product and managed services can create tension around independence. Reputable providers address it through transparent product economics, separate reporting lines and willingness to recommend third-party tools; customers should ask how it is handled.</p>
<h3>What should a company evaluating a managed security provider ask?</h3>
<p>Ask about analyst staffing per shift, mean time to detect and respond, whether monitoring runs on proprietary or licensed tooling, contractual service levels, incident response scope, and independent assurance such as SOC 2 Type II or ISO 27001 covering the provider&#8217;s own controls.</p>
</section>
</aside>
</div>
<p><script type="application/ld+json">{"@context": "https://schema.org", "@graph": [{"@type": "NewsArticle", "headline": "Tusker Buys Fortress SRM, Adding 50 Staff and a 24/7 SOC", "description": "Tusker has acquired Fortress SRM, a Cleveland cybersecurity firm with about 50 specialists and a 24/7 security operations center, in its fifth deal since 2017. The purchase adds an Ohio Valley hub and illustrates how mid-market IT providers are rolling up regional security specialists to sell detection and response.", "image": ["/wp-content/uploads/2026/09/tusker-fortress-srm-acquisition-24-7-security-operations-center.png"], "author": {"@type": "Organization", "name": "jain.com Editorial"}, "datePublished": "2026-09-02T11:36:42.047286+00:00"}, {"@type": "FAQPage", "mainEntity": [{"@type": "Question", "name": "What did Tusker announce?", "acceptedAnswer": {"@type": "Answer", "text": "On September 2, 2026, Tusker said it had acquired Fortress SRM, a Cleveland-based cybersecurity firm. The deal adds about 50 security professionals, a 24/7 Security Operations Center and a sixth regional hub. Financial terms were not disclosed."}}, {"@type": "Question", "name": "Who is Fortress SRM?", "acceptedAnswer": {"@type": "Answer", "text": "Fortress SRM is a Cleveland cybersecurity firm founded in 2018, serving customers across Ohio, northern Michigan and Wisconsin with roughly 50 professionals. Its services include security consulting, virtual CISO leadership, managed security, incident response, digital forensics and a 24/7 SOC."}}, {"@type": "Question", "name": "What is a Security Operations Center?", "acceptedAnswer": {"@type": "Answer", "text": "A SOC is a team that monitors customer networks continuously for signs of intrusion, investigates alerts and coordinates the response to confirmed incidents. Running one around the clock requires multiple analyst shifts, which is why most mid-sized organizations rent the capability rather than build it."}}, {"@type": "Question", "name": "How much did Tusker pay for Fortress SRM?", "acceptedAnswer": {"@type": "Answer", "text": "The purchase price was not disclosed. Tusker's announcement includes no financial terms, no consideration structure and no indication of how the transaction was financed."}}, {"@type": "Question", "name": "How big is Tusker after the acquisition?", "acceptedAnswer": {"@type": "Answer", "text": "Tusker says it has more than 400 employees. It operates regional hubs in Chicago, Boston, Green Bay, Duluth, Eau Claire and, with this deal, Cleveland."}}, {"@type": "Question", "name": "Is this Tusker's first acquisition?", "acceptedAnswer": {"@type": "Answer", "text": "No. It is Tusker's fifth acquisition since 2017, and the first since the company unified its portfolio businesses under the Tusker brand earlier in 2026. Tusker says additional acquisitions are planned."}}, {"@type": "Question", "name": "What is a virtual CISO?", "acceptedAnswer": {"@type": "Answer", "text": "A virtual CISO is a fractional chief information security officer \u2014 an experienced security executive shared across several client organizations. It gives companies too small to employ a full-time CISO access to senior security strategy, governance and compliance leadership on a subscription basis."}}, {"@type": "Question", "name": "Why are mid-market companies outsourcing detection and response?", "acceptedAnswer": {"@type": "Answer", "text": "Continuous monitoring requires enough trained analysts to cover every shift, plus tooling and threat intelligence. That fixed cost is difficult to justify for a single mid-sized organization but works well when spread across many, so buyers increasingly purchase it as a service."}}, {"@type": "Question", "name": "What changes for Fortress SRM's existing customers?", "acceptedAnswer": {"@type": "Answer", "text": "Tusker's stated intent is that security clients gain access to broader technology services \u2014 desktops, servers, networks, planning and managed services \u2014 while keeping the same team and service style. The companies have not said whether contracts, pricing or escalation procedures change."}}, {"@type": "Question", "name": "What does the deal mean for Tusker's existing clients?", "acceptedAnswer": {"@type": "Answer", "text": "It gives Tusker an in-house 24/7 monitoring capability plus incident response and forensics to offer across its client base. Tusker has not specified when those services will be made available nationally or under what service-level commitments."}}, {"@type": "Question", "name": "Why does the Ohio Valley location matter?", "acceptedAnswer": {"@type": "Answer", "text": "Cleveland extends Tusker's footprint beyond its Great Lakes and Upper Midwest core into a new regional market. Mid-sized markets like these hold manufacturers, healthcare providers and public-sector organizations that face serious security requirements without in-house security staff."}}, {"@type": "Question", "name": "Is consolidation of regional security providers a broader trend?", "acceptedAnswer": {"@type": "Answer", "text": "This deal fits a recognizable pattern: broader IT services platforms acquiring regional managed security specialists to add recurring monitoring revenue and capability they would otherwise have to hire for. Whether the pace continues depends on capital availability and integration capacity."}}, {"@type": "Question", "name": "What are the main risks in an acquisition like this?", "acceptedAnswer": {"@type": "Answer", "text": "The acquired value is largely people, and security specialists are portable. Integration must also reconcile monitoring platforms, ticketing and escalation procedures across two organizations. Both risks are manageable but neither is automatic."}}, {"@type": "Question", "name": "Should buyers worry about a provider that both advises on security and sells the products?", "acceptedAnswer": {"@type": "Answer", "text": "It is worth asking about. Combining advisory work with product and managed services can create tension around independence. Reputable providers address it through transparent product economics, separate reporting lines and willingness to recommend third-party tools; customers should ask how it is handled."}}, {"@type": "Question", "name": "What should a company evaluating a managed security provider ask?", "acceptedAnswer": {"@type": "Answer", "text": "Ask about analyst staffing per shift, mean time to detect and respond, whether monitoring runs on proprietary or licensed tooling, contractual service levels, incident response scope, and independent assurance such as SOC 2 Type II or ISO 27001 covering the provider's own controls."}}]}]}</script></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
