Tarian Labs Launches Partner Programme for MSPs, Cloud Providers, and IT Consultancies
Today we are launching the Tarian Labs Partner Programme, and it feels like the right moment to explain why.
Tarian was built to solve a straightforward problem. Scaling businesses were being sold automated scans dressed up as penetration tests. They were receiving compliance checklists passed off as real assurance. They were getting point-in-time reports that were out of date before the ink dried. We built Tarian to fix that. To take the standards and the rigour from the highest levels of UK cyber defence and make them accessible to businesses that could not previously afford them.
The partner programme is the next step in that. Because the businesses that need this most are not always going to find us directly. They are going to ask their MSP. They are going to ask the consultancy that just finished their cloud migration. They are going to ask whoever is already in the room when a compliance requirement lands or an investor asks a difficult question.
This programme puts a certified answer in the hands of the people those businesses are already talking to.
Three ways to work with us
We have structured the programme around three models because the right fit depends on how involved a partner wants to be.
Referral. The lightest arrangement. A client comes to you with a security testing requirement. You make the introduction and step back. We handle the scoping call, the engagement, and the reporting directly with the client. You receive a referral fee when the engagement closes. No delivery responsibility, no ongoing involvement required.
Reseller. For businesses that want certified penetration testing sitting properly inside their portfolio. You own the client relationship from start to finish. You quote the engagement, set the margin, and present the deliverables. We operate behind you, delivering to the same standard as any direct Tarian engagement, under your brand or ours. Your clients see a joined-up service. You control what they see and what they pay.
Strategic Alliance. For technology vendors and platform providers where security is a persistent thread running through the work. We build a formal commercial arrangement together: joint go-to-market, shared pipeline development, co-marketing, designed around a long-term relationship rather than a transaction.
If you are not sure which model fits, that is what the first conversation is for.
What sits behind every engagement
Every test we deliver combines automated tooling with practitioner-led analysis. The tools map the surface quickly and consistently. The practitioners go deeper, working manually through the findings, tracing the paths a real attacker would take, and surfacing the vulnerabilities that no automated tool will find on its own. The combination is what makes a penetration test worth commissioning in the first place.
The credentials behind every engagement are CSTL-INF, CREST CRT, OSCP, and OSEP. The CSTL-INF is worth understanding specifically. It is recognised by NCSC and the UK Cyber Security Council as a mandatory requirement for Principal and Chartered status in security testing. There are not many practitioners in the UK operating at this level. Every Tarian engagement is led by one. When your client asks who is doing the work, that is the answer.
How the client relationship works
This is the first question every potential partner asks, so it is worth being direct.
On a referral arrangement, the client relationship moves to us for the duration of the engagement. You have made the introduction. We handle everything from there. Your fee arrives when the engagement closes.
On a reseller arrangement, the client relationship stays with you throughout. You are the primary contact. We never communicate with your client independently, and you receive copies of all reporting and client-facing documentation as standard. You are never out of the loop on an engagement that started with you.
On a strategic alliance, the relationship is built jointly from day one. Commercial terms, boundaries, pipeline ownership, and go-to-market responsibilities are all agreed in writing before any joint activity begins.
For reseller and strategic alliance arrangements, we do not market to clients you have introduced, contact them after an engagement ends, or accept inbound enquiries from them outside the agreed arrangement. That commitment is in the partner agreement before anything starts.
Why now
The regulatory environment around security is tightening. The UK Cyber Security and Resilience Bill is moving through Parliament. DORA is live for financial services. Cyber Essentials is appearing more frequently in procurement requirements. Insurers are asking harder questions. Investors are running security due diligence earlier in the process.
The businesses that are going to feel that pressure most acutely are the ones already working with MSPs and IT consultancies. They trust those relationships. They will turn to them first. This programme means that when they do, the answer is there.
Who we are looking to work with
MSPs whose clients are starting to face compliance or regulatory requirements they have not encountered before. Cloud providers whose migrations have opened up security questions the client needs answered independently. IT consultancies that keep running into security gaps on project work. Professional services businesses in the room when a client faces investor or insurer scrutiny.
If your clients are asking the question, you should be the one with the answer.
Most arrangements are in place within a week of first contact. Get in touch and we can work out which model fits your business.
Your clients are already asking the question.
Get in touch to discuss which partnership model fits your business.