# Who Buys and Why
## One platform, four separate budgets
The same telemetry layer is sold into four motions, each with a different owner and a different reason to sign.
| Buyer | Their reason | What they buy first |
| --- | --- | --- |
| **Telcos and ISPs** | revenue and margin | subscriber threat protection, B2B managed security, per-subscriber analytics |
| **Banks and insurers** | risk and compliance | DORA and PSD2 readiness, fraud investigation, insider threat |
| **MSSPs and SOCs** | a new service line | multi-tenant telemetry, client isolation, managed DNS security |
| **Regulated enterprises** | cost and control | SIEM cost optimisation, 7-year archive, forensic replay |
The stated entry rule is to start with acute pain, which is whichever of SIEM spend, audit readiness, fraud forensics or managed security is loudest in that account, and expand into the wider telemetry control plane after ROI is proven.
> [!tip] The most interesting of the four
> Telcos and MSSPs are not end customers, they are ==distribution==. A telco that white-labels subscriber threat protection sells it to its own base, which turns one contract into many deployments without a proportional sales effort.
## Why it matters
Four motions is a strength and a discipline problem at the same time. Four buyer types need four sets of collateral, four reference stories and four sales conversations, from a team of four to six people.
The practical question is which one gets chosen first. On the evidence so far the answer is compliance-led banking and telco channel, which is where the live conversations are.
## Related
- [[Red Onion MOC]]
- [[Go-to-Market Across Three Regions]]
- [[Regulation as the Timing Argument]]
- [[Managed Security Service Providers]]
- [[Telco MoC]]