29 July 2026
TERESEC Partners with Ingram Micro
By Greg Tereszczyn, Founder & Principal Consultant
TERESEC has partnered with Ingram Micro, one of the world's largest technology distributors. The practical effect for our clients is straightforward: we can now source and deliver the hardware and software we recommend, rather than handing a report to a third party and hoping the intent survives the handover.
Closing the Gap Between Advice and Deployment
Consulting engagements have a well-known failure mode. An assessment identifies the exposures, prioritises them, and recommends controls. The client then has to translate that into a procurement exercise - find a reseller, request quotes, reconcile part numbers and licensing tiers, and brief someone new on an environment they have never seen. Weeks pass. The design gets simplified to fit whatever was easiest to quote. The control that eventually lands is not quite the control that was specified.
Access to Ingram Micro's portfolio removes that discontinuity. The same team that assessed the environment can specify, source, licence, deploy, and support the solution. The engineering intent behind a recommendation stays intact because the people who wrote it are the people implementing it.
The Cybersecurity Portfolio
Ingram Micro's Australian vendor line-up spans networking, compute, storage, and endpoint. The part that matters to our practice is the security portfolio, and a few vendors in particular:
- Fortinet - next-generation firewalls, SD-WAN, and SASE. In OT environments this is frequently the practical means of enforcing the zone-and-conduit model that IEC 62443 requires, without re-architecting a plant network from scratch.
- Palo Alto Networks - next-generation firewalls, cloud security, and the Cortex detection and response family, distributed through Ingram Micro across ANZ.
- AlgoSec - application-centric firewall policy management and automation across hybrid environments. Added to Ingram Micro's ANZ line-up in 2025, it addresses a problem almost every mature estate has: years of accumulated firewall rules that nobody is confident enough to remove. AlgoSec makes rule sprawl visible, ties policy back to the applications it serves, and produces the compliance evidence auditors ask for.
- Veeam - backup and recovery. In a ransomware scenario, recovery capability is the control that determines whether an incident is an outage or an existential event. Regular backups is one of the eight ACSC Essential Eight strategies for exactly this reason.
- Cisco - network infrastructure and security, including segmentation and secure access.
- Proofpoint - email and human-layer security. Phishing remains one of the most reliable initial access vectors in real breaches, which makes email controls a frontline concern rather than a hygiene item.
- Acronis - cyber protection, combining data protection with endpoint security controls in a single platform.
- Cohesity - data resilience and recovery at enterprise scale, including immutable snapshots and rapid restore.
- Keeper - credential and secrets management, supporting the Essential Eight strategies around restricting administrative privileges and protecting authentication material.
This is not the full catalogue, and the list is not a recommendation. Which of these belongs in a given environment is a question an assessment answers, not a brochure.
Hardware Is Part of the Control
Security architecture is not purely a software exercise. Firewalls, switches, out-of-band management, endpoint fleets, and the servers and storage that host security tooling all have to be procured, and in operational environments they have to be procured correctly.
Sourcing through an authorised distributor matters more than it appears. It means genuine hardware with valid warranty and vendor support entitlements, correct regional SKUs, and a documented supply chain. For asset owners in critical infrastructure - where provenance, support terms, and long equipment lifecycles are governance concerns, not procurement details - that chain of custody is part of the control, not an administrative footnote.
On Independence
We should address the obvious question directly, because any CISO worth engaging will ask it: does a consultancy that can now resell products still give independent advice?
Our position is explicit. Assessment findings drive the recommendation - not margin. If the answer to a finding is a configuration change, a process fix, or nothing at all, that is what we will say, and we will say it in writing. Where a product genuinely is the right control, clients remain free to procure it wherever they choose; we will provide the specification either way. Reselling is a delivery capability, not a sales motion, and we are happy to be held to that.
What This Means for Our Clients
Most of our clients run lean security teams across IT and OT boundaries, where every additional supplier is another set of meetings, contracts, and handovers to manage. Consolidating assessment, procurement, deployment, and support into a single accountable engagement removes coordination overhead that produces no security value.
The underlying work does not change. We scope the environment, identify what actually carries risk, and design controls that fit the operational constraints - uptime requirements, change windows, safety systems, and legacy equipment that will not be replaced this decade. The partnership simply means we can now carry that design through to a working, supported deployment.
Engaging Us
If your organisation is planning a security uplift, refreshing network or endpoint infrastructure, or wants a single accountable partner from assessment through to deployment, we are available to help.
Contact us to discuss your requirements.
About the author
Greg Tereszczyn
Greg Tereszczyn is the founder and principal consultant of TERESEC, an Australian cyber security consultancy for small and medium business. He turns the Essential Eight, the ISM, ISO/IEC 27001, NIST CSF and IEC 62443 into plain-English advice a business can act on.