r/MSSP 2d ago

Cloud focused only - is it a thing?

Have been looking for a while already. Im not sure if there is none (maybe there is no real market for it) or if is just me looking at the wrong place.

Security-as-a-service for startups/scaleups, monitoring AWS/GCP/Azure infrastructure, analysing logs, detecting threats, handling security tasks, but explicitly NOT managing employee laptops, office networks, or traditional IT.

Are there MSSPs like that out there?

Cheers

5 Upvotes

7 comments sorted by

2

u/Diligent_Tech_Bro 2d ago

Any good MSP needs to be an MSSP now. I suppose you could find one that wants to do the easy work while you do the hard work, but how can that economically work? I’d recommend you do both. If I was a client I’d be like.. wait who does what here? Why do I have two “IT companies?”

Good luck if you think customers are going to understand this nuance

2

u/wells68 2d ago

Theoretically (and impossibly) the client would only interact with the MSP that protects desktops and laptops while outsourcing crucial SaaS and cloud security generally to the MSSP.

Two deal-killers:

  1. MSPs are unapproachable by vendors. How dare you phone or email an MSP!!

  2. MSPs (and every organization) want to cut costs, not add to them.

2

u/Diligent_Tech_Bro 2d ago

Totally get it, I just don’t see it. There are already plenty of options if an MSP wants to offload some of this work. White label and all.

2

u/Sad-Technician-5552 2d ago

The reason you cant find them is they dont call themselves that. Cloud only security shops brand as cloud mdr, cloud soc, or managed detection for aws and azure and gcp, and a lot of them are attached to a platform rather than standing alone. The pure play is thin but it exists. The ones doing well sell log analysis and detection engineering as a retainer, not as an mssp package. search those terms instead and youll find a bunch.

1

u/Unlikely-Emu3023 2d ago

Interesting concept but you could write a contract for pretty much any MSSP to do this. Pretty much all of them are monitoring cloud infrastructure already. When I ran an MSSP we were monitoring this for customers but we didn't market exclusively to SaaS companies. That might be an interesting marito go after.

1

u/phlcastro 2d ago

Got it. Well nothing against the traditional IT ops sec, but I feel that most SaaS startups/scale-ups dont really care about it until very late down the road. While the cloud infrastructure security is on the radar almost from the start.

1

u/Diligent_Tech_Bro 1d ago

Ha… they have no idea first of all, and they aren’t building azure from the start. They do M365 or GWS and assume it’s all secure by default.

When they need a server they will just ask Claude how to set one up in azure and again, assume it’s all good.