Tag: Mid-Market IT

  • Tusker Buys Fortress SRM, Adding 50 Staff and a 24/7 SOC

    Tusker Buys Fortress SRM, Adding 50 Staff and a 24/7 SOC

    TL;DR · 30-second read

    The Short Version

    A Chicago technology company called Tusker has bought Fortress SRM, a Cleveland firm of about 50 people whose job is keeping businesses from being hacked.

    Fortress runs an operation staffed around the clock, every day of the year, where analysts watch customers’ computer networks for intruders and step in when one gets through. Most mid-sized companies cannot afford to staff that themselves, so they rent it from firms like this one.

    It is Tusker’s fifth purchase since 2017, and the company says more are planned.

    Tusker, a Chicago-headquartered technology solutions provider, announced on September 2, 2026 that it has acquired Fortress SRM, a Cleveland cybersecurity firm founded in 2018. According to Tusker’s announcement, the deal adds roughly 50 cybersecurity professionals, a 24/7 Security Operations Center, and a sixth regional hub covering the Ohio Valley. Financial terms were not disclosed.

    Fortress SRM serves customers across Ohio, northern Michigan and Wisconsin, with services spanning security consulting and advisory work, virtual CISO leadership, managed security, incident response and digital forensics. The transaction is Tusker’s fifth acquisition since 2017 and its first since the company consolidated its portfolio businesses under a single brand earlier this year. Tusker says it now has more than 400 employees and hubs in Chicago, Boston, Green Bay, Duluth, Eau Claire and Cleveland, and that further acquisitions are planned.

    Executive Summary

    The headline asset in this deal is not the customer list — it is the round-the-clock watch floor. A Security Operations Center, or SOC, is a team that monitors customer networks continuously for signs of intrusion and coordinates the response when something is found. Building one is a fixed-cost exercise: you need enough trained analysts to staff three shifts, weekends and holidays before you can credibly answer a single alert at 3 a.m. That cost only makes sense when it is spread across many customers, which is precisely why regional security firms that have already paid it are attractive to acquirers who have not.

    Tusker’s position is a common one in the mid-market channel. It has scale in the things that are hard to differentiate — hardware, deployment, help desk, lifecycle management — and comparatively thin capability in the thing customers are currently most anxious about. Buying a 50-person security practice with an operating SOC, a virtual CISO bench and a digital forensics capability is a faster route to that capability than hiring into a labor market where experienced detection-and-response analysts are scarce and expensive.

    For the wider market, the deal is a small but legible data point in an ongoing consolidation: independent regional managed security providers are being absorbed into broader IT services platforms, because mid-market buyers increasingly want detection and response as a subscription rather than a staffing problem. What Tusker’s announcement does not establish is how large or how profitable that practice is, or on what terms it changed hands.

    The Economics of Watching a Network at 3 a.m.

    Continuous security monitoring has an unforgiving cost structure. Coverage that is genuinely 24 hours a day, seven days a week, requires multiple analyst shifts plus slack for holidays, illness and turnover — before any tooling, threat intelligence feeds or escalation playbooks are paid for. A mid-sized manufacturer or hospital system that tried to build this in-house would be hiring a team it can keep busy only intermittently. The managed model works because that same team’s attention is sold in slices to dozens of organizations at once, and because attacks against one customer generate detection knowledge that protects the rest.

    That arithmetic is what makes an existing SOC a genuine asset rather than a line item. Fortress SRM’s described capability set — consulting and advisory, virtual CISO leadership, managed security, incident response and digital forensics, and the SOC itself — maps onto a full customer lifecycle: assess, advise, monitor, and respond when monitoring finds something. A firm that can only do the assessment half sells projects; a firm that can do the monitoring half sells contracts. Recurring revenue is the reason security practices command attention from acquirers, though Tusker has not said what portion of the acquired business is recurring.

    The Cross-Sell Case Cuts Both Ways

    Jess Walpole, president of Fortress SRM, framed the deal around customer convenience: security clients who also want help with desktops, servers, networks and modernization now get it from one partner. That is a real benefit, and it reflects a genuine mid-market preference for fewer vendors. But the more consequential flow probably runs the other direction. Tusker reports more than 400 employees and clients across the country; selling managed detection and response into an installed base that already trusts the provider with its infrastructure is a cheaper path to growth than winning security deals cold.

    Consolidation of this kind does raise a question buyers should ask openly, and it is a question about structure rather than about either company’s intentions. When the same organization advises on security strategy, supplies the hardware and manages the environment, the advisory function loses some of its natural independence. Virtual CISO services — essentially a fractional security executive rented by organizations too small to employ one — are valuable precisely because they are supposed to represent the customer’s interests. Providers that combine advisory with product and managed services can manage that tension well, through separate reporting lines, transparent product economics or a willingness to recommend third-party tooling, but customers should ask how it is being handled rather than assume.

    A Great Lakes Roll-Up Reaches the Ohio Valley

    Look at Tusker’s hub map — Chicago, Boston, Green Bay, Duluth, Eau Claire and now Cleveland — and the strategy reads clearly. With one East Coast exception, this is a Great Lakes and Upper Midwest platform assembled around mid-sized regional markets rather than the coastal metros where national systems integrators concentrate. Those markets have plenty of manufacturers, healthcare providers, municipalities and school districts that face the same regulatory and insurance pressure on cybersecurity as larger firms, with none of the in-house staff. Cleveland extends that footprint into the Ohio Valley and, per the announcement, into a service territory already covering Ohio, northern Michigan and Wisconsin.

    The risk in any roll-up is that the acquired capability degrades in transit. Tusker’s stated asset here is people: roughly 50 specialists whose value is entirely portable if they choose to leave. Integration also has to reconcile monitoring platforms, ticketing systems, escalation procedures and service-level commitments across organizations that built them independently — work that is invisible to customers when it goes right and very visible when it does not. Tusker has done this four times before and completed a brand unification earlier this year, which is evidence of a repeatable process rather than proof of a smooth outcome. The company also says more acquisitions are planned, which means integration capacity, not deal flow, is likely to be the binding constraint.

    Background

    Tusker began as a Chicago IT hardware distributor and has since assembled a broader technology services platform through acquisition, adding capabilities in advisory, professional services, managed services and lifecycle support. Formerly operating as ACP CreativIT, the company brought five regional firms under the single Tusker brand earlier in 2026 and has been named to the Channel Futures MSP 501 list of top managed service providers for 2026, its second appearance. The Fortress SRM deal is its fifth acquisition since 2017.

    The market context is a mid-market squeeze. Organizations of a few hundred to a few thousand employees now face the same ransomware exposure, cyber insurance questionnaires and regulatory expectations as large enterprises, without the budget for a standing security team. That gap created a generation of regional managed security providers — Fortress SRM among them, founded in 2018 — and those firms have in turn become acquisition targets for full-stack IT providers seeking recurring security revenue and capabilities that are slow and costly to build from scratch.

    Source: Tusker Acquires Fortress SRM to Expand Cybersecurity Services — Tusker’s September 2, 2026 announcement of its acquisition of the Cleveland cybersecurity firm, including headcount, service capabilities and regional hub details.