MSP Partner Hub

Sell network security
your customers actually need

Intrusion Shield gives MSPs a proven, inline threat prevention platform that blocks malicious traffic at the network layer - no agents, no complexity, no alert fatigue.

What Intrusion Does

Shield is a full product family - on-premise appliances, endpoint agents, cloud instances, and high-capacity DNS sensors - all powered by 8.5B+ threat indicators updated continuously from government-grade intelligence. Inspect and block malicious traffic inline, at every layer.

Who It's For

MSPs, MSSPs, and VARs serving mid-market and enterprise customers who need proactive network protection - especially those in regulated verticals like government, healthcare, finance, and critical infrastructure.

How It Works

Deploy Shield across four surfaces - all managed from a single dashboard. Cloud instances secure AWS/Azure workloads with the same threat intelligence. OnPremise appliances (500 Mbps–10 Gbps) sit inline at the network edge. Endpoint agents (Basic, ZTNA, Renderer) protect remote users. Sentinel sensors (50–100 Gbps) monitor DNS at scale.

Validate Fit

See where Shield fits
in your customer's stack

Shield deploys inline at the network layer - between the firewall and internal network. No agents, no endpoint changes, no DNS rerouting.

Internet / WAN
ISP Router / Modem
Firewall (Fortinet, Palo Alto, Meraki, etc.)
Intrusion Shield - Inline Threat Prevention
Core Switch / Internal Network
Endpoints, Servers, IoT, OT

Shield doesn't replace your firewall - it augments it. Most firewalls rely on signature-based detection and can miss zero-day C2 callbacks, novel exfiltration channels, and threats from newly compromised IPs. Shield adds a dedicated threat intelligence layer with over 8.5 billion indicators that no firewall includes out of the box.

  • Complements: Firewalls (Fortinet, Palo Alto, SonicWall, Meraki), endpoint management platforms, MDR services, and cloud security tools
  • Can replace: Standalone IDS/IPS appliances that only detect without blocking, and DNS-layer-only filtering products
  • Extends with: Shield Endpoint agents for remote users (Basic, ZTNA, Renderer) and Shield Cloud instances for AWS/Azure workloads

You do - through a multi-tenant MSP dashboard (CommandHub). Shield is designed for MSP-managed delivery: centralized policy, per-customer visibility, and automated threat intel updates. Your customers don't need to touch it.

  • Multi-tenant dashboard with per-customer views
  • Automated threat intelligence updates - no manual rule tuning
  • Alert summaries and monthly reports generated automatically
  • Optional co-managed mode for customers who want visibility

Shield appliances come in multiple form factors and throughput tiers - right-size per customer from a small branch office to a multi-gigabit enterprise core.

  • Small Form Factor (500 Mbps): Branch offices, small businesses, remote sites
  • Large Form Factor (1.5 Gbps): Mid-market offices, regional headquarters
  • Large Form Factor (5 Gbps): Enterprise campus, data center edge
  • Large Form Factor (10 Gbps): Large enterprise, high-throughput environments
  • Sentinel (50–100 Gbps): High-capacity DNS monitoring for ISPs, large networks, and service providers
  • Endpoint: Per-device agents - Basic protection, ZTNA (Ziti), or Renderer - for remote and roaming users
  • Cloud: Per-instance deployment for public and private cloud workloads
  • Flexible subscription terms - monthly, 1-year, and 3-year options available. Wrap Shield into your monthly managed service fee for seamless MRR alignment
💰
Monthly OpEx Billing Available

Ask about monthly OpEx billing to align Shield costs with your client MRR cycle. No large upfront commitment required.

Yes. Shield generates alerts and reports that can be ingested into your existing stack via syslog, API, or email-based ticket creation.

  • Syslog output for SIEM integration (Splunk, Elastic, etc.)
  • API access for custom integrations
  • Email alert rules for PSA ticket auto-creation (ConnectWise, Autotask, etc.)
  • Scheduled PDF reports for QBR and compliance documentation
ConnectWise Autotask HaloPSA Splunk Elastic
Understand Value

The numbers that matter
to your customers

Shield delivers measurable outcomes from day one - fewer incidents, less noise, and a simpler security stack for your team to manage.

0
Alert Reduction
0
Threat Indicators
1ms
Sub-Millisecond Latency
0
Enforcement

Reduce Incidents

Block command-and-control callbacks, ransomware beacons, and data exfiltration attempts before they become incidents your team has to remediate.

Cut Alert Noise

Shield blocks known-bad traffic silently - which means fewer meaningless alerts hitting your SOC or NOC. Your analysts focus on what matters.

Simplify the Stack

Replace patchwork IDS/IPS and DNS-filtering tools with a single inline appliance. Less vendor sprawl, fewer licenses, lower total cost of ownership.

Deliver Reports

Automated monthly threat reports show customers exactly what Shield blocked - perfect for QBRs, compliance audits, and proving your value as their MSP.

Path to Profitability

Shield delivers strong MSP margins with minimal incremental labor. Here's the math:

Per-Client Economics

50%+

$150 avg. cost per client → $300–400 billing.
50%+ gross margin on every seat.

10-Client Scenario

$18K–30K

Annual margin from just 10 Shield clients.
Recurring, predictable revenue.

Labor Savings

4 hrs

Saved per client per month from 90% alert reduction.
Your team focuses on growth, not triage.

MSP Revenue Calculator

Model your Shield revenue based on your practice size. Adjust the inputs to see projected returns.

$2,000
Monthly MRR
$24,000
Annual Revenue
57%
Gross Margin
$6,000
Annual Labor Savings
Trust & Proof

Proven by partners.
Validated by frameworks.

Intrusion has a 20+ year heritage in government-grade threat intelligence. Shield is trusted by MSPs, MSSPs, and VARs across regulated verticals.

Partner Testimonial
Regional MSP Partner
40 Managed Clients
Verified Partner
"We deployed Shield across 12 clients in the first quarter. Alert volume dropped by 85% and we landed 3 net-new accounts using the threat reports as proof of value."
Result: 85% alert reduction, 3 new accounts in Q1
Partner Testimonial
MSSP Partner
Compliance-Focused Verticals
Verified Partner
"Shield gave us a differentiated story for CMMC and NIST prospects. The automated reports map directly to control requirements - our sales cycle shortened by 30%."
Result: 30% shorter sales cycle in compliance verticals
Partner Testimonial
VAR Partner
Federal & SLED Accounts
Verified Partner
"Intrusion's government heritage made the conversation easy. We added Shield to existing firewall refresh deals and increased average deal size by 40%."
Result: 40% increase in average deal size

Quotes shown are illustrative partner scenarios. Real partner attribution with company names and headshots will replace these as testimonials are collected.

Join the Partner Advisory Board

Help shape the Intrusion partner program. We're recruiting 5-10 founding MSP partners to review pricing, portal features, and go-to-market strategy. PAB members get early access to new features and direct input on program direction.

Express Interest

Compliance Alignment

NIST 800-171
CMMC Level 2
CISA KEV
SOC 2 Type II
PCI DSS
HIPAA

How Shield Maps to Compliance Frameworks

CMMC Level 2

Cybersecurity Maturity Model Certification
  • SC.L2-3.13.1 — Boundary protection and monitoring
  • SI.L2-3.14.6 — Monitor inbound/outbound communications for threats
  • SI.L2-3.14.7 — Identify unauthorized use of organizational systems
  • AU.L2-3.3.1 — System audit logging and review

NIST 800-171

Protecting CUI in Non-Federal Systems
  • 3.13.1 — Monitor, control, and protect communications at boundaries
  • 3.14.6 — Monitor organizational systems for attacks and indicators
  • 3.14.7 — Identify unauthorized use via network monitoring
  • 3.13.5 — Implement subnetworks for publicly accessible components

HIPAA

Health Insurance Portability & Accountability Act
  • §164.312(e)(1) — Transmission security and integrity controls
  • §164.312(b) — Audit controls for information system activity
  • §164.308(a)(1) — Security management process and risk analysis

PCI DSS

Payment Card Industry Data Security Standard
  • Req 1 — Install and maintain network security controls
  • Req 5 — Protect all systems against malware
  • Req 10 — Log and monitor all access to network resources
  • Req 11 — Test security of systems and networks regularly

Why Partners Trust Intrusion

Government Heritage

20+ years of research in network threat intelligence originally developed for federal and defense applications.

Publicly Traded

Intrusion Inc. trades on OTCQB under ticker INTZ - transparent financials, accountable governance.

Continuous Intelligence

8.5B+ indicators updated in real time from proprietary research, OSINT feeds, and government-grade sources.

Technical Confidence

Architecture built
for MSP delivery

Shield's architecture is purpose-built for multi-tenant, MSP-managed deployment - from the appliance at the edge to the centralized dashboard.

Four Deployment Surfaces - All Primary, All Equal

Shield Cloud

AWS / Azure / Private

Per-instance deployment

Shield OnPremise

500 Mbps – 10 Gbps

Protect or Observe mode

Shield Endpoint

Basic / ZTNA / Renderer

Per-device protection

Shield Sentinel

50–100 Gbps

High-capacity DNS

Threat Intelligence

Cloud-delivered

8.5B+ indicators

CommandHub

Central management

Policy & reporting

MSP Dashboard

Multi-tenant view

Customer management

Five deployment surfaces - all managed from a single dashboard:

  • Shield OnPremise - Protect Mode: Inline appliance (500 Mbps to 10 Gbps) that actively blocks malicious traffic at the network edge. Small Form Factor for branch sites, Large Form Factor for campus/data center.
  • Shield OnPremise - Observe Mode: Same appliances in passive TAP/SPAN mode - monitor and report without blocking. Ideal for pilots and compliance-driven visibility before enforcement.
  • Shield Endpoint: Per-device agents in three tiers - Basic (network-layer protection), Ziti/ZTNA (zero trust network access), and Renderer (advanced inspection). Covers remote and roaming users beyond the perimeter.
  • Shield Cloud: Per-instance deployment for public and private cloud workloads (AWS, Azure, etc.). Shield Stratus delivers the same threat intelligence in cloud-native form.
  • Sentinel: High-capacity DNS monitoring sensors at 50, 75, and 100 Gbps - purpose-built for ISPs, large enterprises, and service providers who need passive DNS-layer visibility at scale.
  • Sub-millisecond latency - invisible to users and applications
  • Hardware bypass on power failure - network stays up even if the appliance goes down
  • No single point of failure in HA deployments
  • Throughput tiers: 500 Mbps (Small Form), 1.5 / 5 / 10 Gbps (Large Form), 50–100 Gbps (Sentinel)
  • Zero performance impact on existing firewall - Shield handles its own inspection
  • Flexible subscription terms - monthly, 1-year, and 3-year options available for predictable budgeting
  • 8.5B+ threat indicators from proprietary research, OSINT, and government-grade feeds
  • Continuously updated - no manual rule management required
  • Covers IP reputation, domain reputation, URL categorization, and behavioral patterns
  • Tracks C2 infrastructure, ransomware beacons, cryptomining pools, botnets, and more
  • CISA KEV (Known Exploited Vulnerabilities) catalog integrated
  • Single-pane multi-tenant dashboard for all customer appliances
  • Per-customer policy configuration and exception rules
  • Role-based access control - give customers read-only access to their own data
  • Business Value Reports per customer - not just blocked IPs. Shield reports quantify risk prevention in dollars: ransomware beacons stopped, estimated downtime prevented, compliance controls validated. Designed for your clients' CFOs, not just their IT teams. Branded with your logo
  • Centralized firmware updates pushed to all appliances
  • SIEM: Syslog output to Splunk, Elastic, Azure Sentinel, etc.
  • PSA: Email-based ticket creation for ConnectWise, Autotask, Halo
  • RMM: Alert forwarding and status monitoring via SNMP or API
  • MDR / EDR: Complements managed detection and response platforms - Shield handles network-layer blocking while your MDR covers endpoint response
  • Cloud: AWS Gateway Load Balancer integration for Shield Stratus deployments
  • Zero Trust: Shield Endpoint with Ziti provides ZTNA capabilities - extend zero trust network access to remote users
  • Compliance: Automated report generation mapped to NIST, CMMC, PCI, HIPAA controls
  • API: REST API for custom integrations and automation workflows

White-Label Threat Reports

Brand monthly threat reports with your logo. Hand your clients a professional deliverable that proves the value of Shield during QBRs. Reports include ransomware beacons stopped, estimated downtime prevented, and compliance controls validated - all formatted for executive audiences.

ConnectWise Autotask HaloPSA Splunk Elastic
Partner Program

A program designed
for MSP growth

Three tiers with increasing benefits - no shelf-ware minimums, no punitive commitments. Start small and grow into strategic partnership.

Bronze

Getting Started

Evaluate Shield with your first customers and access foundational enablement.

  • Partner portal access
  • Sales & technical onboarding
  • Deal registration protection
  • NFR unit for lab testing
  • Standard support SLA
Gold

Strategic

Full strategic alignment with joint go-to-market, executive sponsorship, and premium benefits.

  • Everything in Silver
  • Executive sponsor pairing
  • Joint go-to-market planning
  • Premium MDF allocation
  • Custom integration support
  • Early access to new products
  • Co-branded case studies

Register deals through the partner portal to lock in protection and margin. Registered deals receive priority pricing and conflict resolution - your investment in the opportunity is protected.

  • Register via partner portal - confirmation within 24 hours
  • 90-day deal protection window (extendable)
  • Conflict resolution process with partner-first bias
  • Visibility into deal status and pipeline

New partners complete a structured 4-week onboarding process that gets your sales and technical teams ready to position, demo, and deploy Shield.

  • Week 1: Sales positioning and competitive differentiation workshop
  • Week 2: Technical deep dive - deployment, configuration, troubleshooting
  • Week 3: Demo environment setup and hands-on lab
  • Week 4: First customer targeting and deal registration
  • Sales playbook with battle cards and objection handling
  • Technical certification lab — self-paced
  • Customer-facing demo guide and talk track
  • Campaign-in-a-box kits for email, social, and webinar
  • ROI calculator for customer presentations
  • Co-brandable presentation templates

Market Development Funds (MDF) support partner demand generation, events, and co-marketing activities. Start with pre-packaged activities today - no proposal required. The formal MDF program with custom proposals launches Q3 2026.

Pre-Packaged MDF Activities (Available Now)

  • Lunch-and-Learn: Bring 10 clients, Intrusion covers $500 catering + provides speaker
  • Webinar Co-Host: Intrusion provides deck, speaker, and follow-up sequence
  • Event Sponsorship: Co-branded booth materials for regional events

No proposal required - select a pre-packaged activity and we handle the rest.

Q3 2026: Custom MDF Program

  • 50/50 cost-share model for Silver and Gold partners
  • Eligible activities: webinars, events, content, paid media, direct mail
  • MDF requests submitted through the partner portal
  • Additional incentive programs
  • Partner-dedicated support queue with faster SLAs
  • Technical escalation path to Intrusion engineering
  • Pre-sales SE support for complex customer environments
  • Post-deployment health checks at 30, 60, and 90 days
  • Reseller / VAR: Buy and resell Shield with margin - traditional transactional model
  • Managed Services (MSP): Include Shield in your managed security stack - recurring revenue model
  • Referral: Introduce opportunities and earn referral fees - no technical investment required
  • Technology Alliance: Integrate your product with Shield - joint go-to-market

Competitive Feature Comparison

CapabilityShieldNDR / XDRDNS FilterFirewallNiche IDS
Inline blocking (active prevention)PartialPartial
8.5B+ threat indicators
Multi-tenant MSP dashboardPartialPartial
Hardware bypass on power failurePartial
Sub-millisecond latencyPartial
Endpoint agents
Cloud deploymentPartial
DNS monitoring (50-100 Gbps)Partial
Compliance reports (NIST, CMMC, PCI, HIPAA)PartialPartial
No manual rule management
Government-grade intelligence

Q2 2026

  • Self-paced certification lab with hands-on deployment exercises
  • Hosted demo environment with pre-loaded sample data
  • 60-minute recorded onboarding walkthrough

Q3 2026

  • Market Development Funds (MDF) - 50/50 cost-share program
  • Customer-facing ROI calculator with branded PDF export
  • Campaign-in-a-box kits for email, social, and webinar

Future

  • Formal partner certification exam with digital badges
  • Co-branded case study templates
  • Partner community forum and peer networking
Apply

Start your partnership

Tell us about your business and we'll set up a conversation with the right team.

What happens next

  1. 1

    Application Review

    We review your submission within 2 business days.

  2. 2

    Discovery Call

    30-minute call to understand your business, customers, and goals.

  3. 3

    Technical Workshop

    Hands-on session with our SE team - deployment, demo, Q&A.

  4. 4

    Agreement & Onboarding

    Sign partner agreement and begin structured onboarding.

    E-Sign Sign your reseller agreement electronically — no third-party accounts required
  5. 5

    Enablement & Lab Access

    Access portal, NFR unit, demo environment, and sales materials.

  6. 6

    First Deal Support

    Dedicated SE and partner manager support through your first registered deal.

Partner Application

All fields marked * are required.

We'll reach out within 2 business days.

Application Received

Thanks for your interest in partnering with Intrusion. Our partner team will review your application and reach out within 2 business days to schedule a discovery call.

Activation

Your first 4 weeks
as an Intrusion partner

A structured onboarding process that gets your sales and technical teams productive fast - ending with your first registered deal.

Week 1

Foundation

  • Partner agreement signed and processed
  • Partner portal access provisioned
  • NFR unit shipped for lab environment
  • Sales positioning workshop scheduled
Week 2

Training

  • Sales team positioning and objection handling session
  • Technical deep dive - deployment and configuration
  • Demo environment provisioned and tested
  • Battle cards and sales collateral distributed
Week 3

Enablement

  • Hands-on lab - install, configure, generate reports
  • Customer talk track and demo rehearsal
  • Target account list review with partner manager
  • Campaign kit setup for outbound prospecting
Week 4

Launch

  • First customer prospect identified
  • Deal registered in partner portal
  • Joint sales call with Intrusion SE support
  • Post-call review and next steps

Enablement Resources

Sales Playbook

Positioning, talk tracks, objection handling, competitive battle cards

Certification Lab

Self-paced technical certification with hands-on deployment exercises

Demo Guide

Step-by-step demo script with customer-facing environment access

Campaign Kit

Email sequences, social content, and webinar templates ready to launch

ROI Calculator

Customer-facing tool to quantify alert reduction and stack consolidation savings

Presentation Templates

Co-brandable slide decks for executive and technical audiences

Activation Milestone: First registered deal submitted = Activation complete. You're officially live as an Intrusion partner.

Already a Partner?

Access your training hub, download resources, register deals, and track your onboarding progress.

Access Training Hub →
Scale

Build a repeatable
Shield practice

Once activated, your partnership shifts to ongoing cadence - regular reviews, pipeline development, and expanded go-to-market support.

Quarterly

QBR

Business review with partner manager - pipeline, performance, program utilization, and goal-setting.

Monthly

Pipeline Review

Review registered deals, identify stalled opportunities, coordinate SE support for upcoming presentations.

Quarterly

Enablement Refresh

New product updates, updated battle cards, competitive intelligence briefing, and new case studies.

Bi-Annual

Co-Marketing Calendar

Plan joint webinars, events, content pieces, and campaigns for the next 6 months.

Your installed base is your best pipeline. Use Shield's reporting to drive expansion conversations across the full product family:

  • Monthly threat reports show value and build the case for additional locations
  • Multi-site customers can deploy Shield at branch offices (Small Form 500 Mbps) and HQ (Large Form up to 10 Gbps)
  • Upsell from Observe mode (monitoring) to Protect mode (inline blocking) for full enforcement
  • Add Shield Endpoint (Basic, ZTNA, or Renderer) for remote and roaming users
  • Add Shield Cloud for customers expanding into AWS or Azure
  • Position Sentinel (50–100 Gbps) for large enterprises and service providers needing DNS-layer visibility
  • Lead with the threat report - offer a free 30-day assessment to prospects
  • Use compliance alignment (NIST, CMMC, PCI) as the door-opener for regulated verticals
  • Position Shield as the "missing layer" in firewall-only environments
  • Leverage Intrusion's brand and government heritage in SLED and federal conversations
  • Campaign kits include email templates, LinkedIn ad copy, and landing page assets
  • Shield subscriptions renew annually - consistent, predictable recurring revenue
  • Automated renewal reminders 90, 60, and 30 days before expiration
  • Renewal QBR with customer - review 12-month threat summary and ROI
  • Multi-year renewal incentives available

Tier advancement is based on revenue milestones and partnership engagement - not arbitrary quotas.

  • Bronze → Silver: Consistent deal flow, technical certification complete, active engagement
  • Silver → Gold: Strategic revenue contribution, co-marketing participation, dedicated practice team
  • Tier reviews conducted quarterly during QBR
  • No punitive demotions - partners maintain tier for 12 months minimum

Scale Milestone: Repeatable deal flow established = Scale achieved. You're building a sustainable Shield practice with Intrusion.