I've been tasked with evaluating endpoint security solutions for my organization, and like many, we're deep into a formal RFP process. Given our scale and the critical nature of this purchase, we were strongly advised by our internal procurement team to work through a major, well-regarded partner/reseller. The logic was solid: they could provide a unified throat to choke, help with contract negotiation, bundle services, and theoretically offer a higher-touch support layer.
After a few months of a pilot with CrowdStrike Falcon (via the partner), I'm starting to form a potentially controversial opinion that's making me question this whole channel strategy. My observation, which has become a significant operational pain point, is this: **going through a partner for technical support has introduced a tangible and frustrating delay compared to what I hear and see from peers who engage with CrowdStrike directly.**
Here's a breakdown of my experience with the support flow:
* **The Added Layer is a Bottleneck:** Every single support ticket, even for what I'd consider a "P3" or "P4" query, must be logged with our partner's helpdesk first. They have a stated SLA for initial response (e.g., 4 business hours), which sounds okay on paper.
* **The Triage Black Box:** The partner then triages and forwards the issue to CrowdStrike on our behalf. We have zero visibility into this queue. We don't get a CrowdStrike support ticket number. We can't see if it's sitting with a junior analyst at the partner or if it's been escalated within CrowdStrike's own systems.
* **The Communication Lag:** All communication filters back through the partner account manager or their support lead. This means clarifications asked by CrowdStrike engineers come to us a day later. Our detailed technical responses then get paraphrased (sometimes inaccurately) back to them. It adds at least one full business day to every single interaction loop.
* **Contrast with Direct Experience:** A colleague at another company, similar size, who went direct, showed me their support portal. They open a ticket and get a CrowdStrike engineer assigned directly, often with a same-day callback for anything urgent. They can attach logs directly, have live chat, and reference a knowledge base we don't seem to have access to.
This has real consequences during evaluation. For instance, we had a specific question about Falcon's behavior with a legacy application during a containment event. A direct answer was crucial for our risk assessment. Through our channel, it took five business days to get a definitive answer. My colleague's direct contact got an answer from a solutions engineer in under 24 hours.
I'm now wrestling with a big procurement dilemma:
* Is the value of the partner (on price, contract management, onboarding services) worth this degradation in technical support responsiveness?
* Are we, as a larger enterprise, actually getting a *worse* support experience by following the "preferred" channel?
* Is this a common experience, or did we just pick a partner with a suboptimal support process?
My procurement side says the partner channel is the way to go for TCO and negotiation leverage. My operational security side is screaming that slower support in a live incident scenario is an unacceptable risk. I'd really appreciate any insights from others who have gone through either route.
Your experience lines up with mine. We ran into the exact same thing with a different vendor (SentinelOne). Partner support is a ticket forwarding service, not a triage layer. They can't escalate to the vendor's engineering team without first doing their own internal paperwork. "Unified throat to choke" becomes "two throats that blame each other."
The only advantage I've seen is during procurement, not post-sales. Once the contract is signed, the partner's margin is locked in. They have zero incentive to invest in deep technical expertise on your specific stack. If you have a P1 incident at 2 AM, you're waiting for the partner's L1 to read a script.
If your procurement team insists on a channel partner, try to negotiate direct vendor support access as a contractual addendum. Some vendors will allow it if you meet a minimum spend. Otherwise, budget for a third-party incident response retainer instead.
latency kills
I see your point about procurement being the only advantage, but it's also the trap. The "minimum spend" to go direct is often just the partner's markup. Finance likes the bundled discount, but they're not the ones waiting on hold during a breach.
A third-party IR retainer is a smart hedge, but it's another cost layer. The real fix is bypassing the procurement dogma that a single line item is always safer.
Don't panic, have a rollback plan.