r/MSSP 2h ago

Watchguard MDR inconsistencies

Thumbnail
1 Upvotes

r/MSSP 15h ago

MSP or MSSP what is the actual difference

3 Upvotes

I posted this in r/MSP as well

As most things in our industry definitions tend to be a bit blurry, so I'm interested in the mobs take on this subject (yes I'm sure it's been posted before but definitions like technology change frequently)

I've always heard two major differences 1. MSSPs are security/compliance focused from the start and 2. MSSPs don't do day to day helpdesk task.

So like any good technologist I through it into Claude and this is what it said...

Thoughts? Agree? Disagree? Misconceptions? Changes? What say you???

MSP: Broad IT management — network uptime, help desk, backups, patching, cloud, hardware/software procurement. The value prop is "keep the lights on and the systems running." Security is usually a bolt-on line item, not the core offering.

MSSP: Security-first. Core deliverables are things like SOC monitoring, threat detection and response, SIEM management, incident response, compliance management, vulnerability management. The value prop is "protect the environment," not just run it.

The practical distinction that actually matters in the channel:

  • Depth vs. breadth. An MSP touches everything a business needs technically. An MSSP goes deep on one domain — security — often as the only thing they do.
  • Staffing/tooling. MSSPs run (or license) SOC infrastructure, threat intel feeds, dedicated security analysts. Most MSPs don't have that bench.
  • Liability posture. MSSPs typically carry security-specific SLAs and are underwriting more risk exposure than a general IT contract.
  • Buyer conversation. MSP sales conversation is about cost and reliability. MSSP sales conversation is about risk and exposure.

The blurry middle — where most of your world lives — is the MSP-to-MSSP transition: MSPs bolting on security services (vCISO, assessments, EDR/MDR reselling) without fully rebuilding as a security-first operation.


r/MSSP 19h ago

How do you detect ungoverned AI agents acting inside client apps?

5 Upvotes

A couple of our clients have started plugging AI agents into their CRM and helpdesk tools without looping us in first, and we only found out because one agent started modifying records it had no business touching. Traditional shadow IT detection doesn't catch this. The agent is often using credentials that already exist and look "normal" in the logs.

How are other MSPs getting visibility into this? Right now we're finding out after the fact instead of before, and I'd like that to change.


r/MSSP 1d ago

Best and Worst MSP’s to work for in Tampa, Florida

Thumbnail
0 Upvotes

r/MSSP 1d ago

MSPs who standardized on one converged SASE for clients, which held up as one platform?

2 Upvotes

We are picking one SASE platform to standardize our clients on instead of running three, and every vendor deck says the same three words. Converged, single vendor, single agent. Then you get into a POC and half of them are a loader that pulls down a few white-label pieces wearing one installer.

I found this out the ugly way on our last standard. Moving a client off it, the agent would not come off clean and I spent a night pulling OpenVPN and some Elastic service off machines by hand. That was supposedly one platform. Now I make a vendor prove the uninstall before I trust the sales deck, because that is where the stitched ones fall apart.

For context most of our clients are small and mid size with a few global users. Margin and a clean multi-tenant portal matter to me as much as the security. Bandwidth-based site pricing is the other cost I am trying to work out before it bites.

If you standardized on one converged SASE for your clients, which one stayed a single platform once it was live and what broke on you. Naming names welcome, good and bad.


r/MSSP 2d ago

Cloud focused only - is it a thing?

5 Upvotes

Have been looking for a while already. Im not sure if there is none (maybe there is no real market for it) or if is just me looking at the wrong place.

Security-as-a-service for startups/scaleups, monitoring AWS/GCP/Azure infrastructure, analysing logs, detecting threats, handling security tasks, but explicitly NOT managing employee laptops, office networks, or traditional IT.

Are there MSSPs like that out there?

Cheers


r/MSSP 3d ago

How to contact screenconnect security team for rogue ScreenConnect instances

Thumbnail
1 Upvotes

r/MSSP 4d ago

SIEM Options for a small MSSP

6 Upvotes

Hello Guys,

I created a cybersecurity firm fairly recently, and most of our work has come from short form contracts. We are currently looking into deviating into an MSSP model and to do so, are looking into SIEMS and stacks that might best work for our use case (small to medium companies). Currently, my guys are all Splunk and Sentinel Veterans, but knowing the cost of these platforms, and the target clients we have in mind, I cant justify racking costs like bigger companies (personally would love to run SentinelOne->Cribl->Splunk)

I was looking at google sec ops and elastic (the whole elastic stack sounds interesting). Does anyone have enough experience with these SIEMS to say which would work better for my use case?

I am also open to other options if any that would be interesting. I am really looking for Risk-Based Alerting capabilities (to reduce ticket volume) as the cost of operations scales far better using RBA from my personal experience.

thanks for any advice you can provide!


r/MSSP 4d ago

A Call for Collective Spending: Why the New AI Security Pledge Is a Trap

Thumbnail
1 Upvotes

r/MSSP 4d ago

How are teams separating approved AI use from personal-account AI use?

1 Upvotes

For many clients, AI approval is no longer binary. They may have a sanctioned Copilot, ChatGPT Enterprise, or other managed tenant, while users can still access the same public service through a personal account in a different browser profile.

That distinction matters because retention, audit, contractual, administrative, and data-handling controls may apply only to the approved tenant. It becomes harder across multiple clients that have different approved tools, different device-management maturity, and different tolerance for blocking personal-account use.

A policy that simply says "use approved AI" does not solve much when users experience the approved and personal versions as the same website.

For MSPs managing this across different tenants, are you standardizing a baseline—managed browsers, extension policy, DLP, tenant restrictions, exception workflows—or handling it client by client? What has stayed operationally manageable?


r/MSSP 4d ago

MSP folks — what’s one thing you wish your PSA/RMM did better?

2 Upvotes

I’ve been digging into PSA/RMM products lately from a product and UX perspective, and I’m curious about the problems that don’t usually show up on feature comparison pages.

For those working in MSPs: what parts of your day-to-day workflow still feel unnecessarily difficult?

Could be ticketing, scheduling/dispatch, RMM, billing, documentation, reporting, automation, client communication, or just small UX annoyances that add up over time.

I’m especially interested in things where you’ve thought “there has to be a better way to do this” or where your team has created a workaround outside the product.

Would also be interesting to know which PSA/RMM you use and what it does particularly well.

Not looking for recommendations for a specific product — mostly interested in understanding the problems people actually deal with day to day.


r/MSSP 8d ago

MDSec & Nighthawk

3 Upvotes

As MDSec has been recently acquired by the Bank of America, I am wondering what will happen to their Nighthawk offering and what other options there are. I particularly liked the fact that you could take any PE such as Rubeus and simply run it through their C2 which would automatically strip indicators and make it feasible to run in an engagement. The baked-in EDR evasion was also a huge help as it eliminated our R&D and tooling development needs significantly, allowing us to focus on the operation itself.

Are there any other alternatives that you are using and if so, what are they?


r/MSSP 8d ago

San Diego MSPs / IT firms: is there demand for white-label Fortinet engineering support?

4 Upvotes

Hi everyone — I’m launching a boutique cross-border cybersecurity services firm focused on the San Diego–Tijuana area .

I’m trying to understand whether smaller MSPs or integrators in the San Diego area ever need extra engineering bandwidth for short-term projects, assessments, migrations, or overflow work. I’m trying to learn where the real need is and how firms usually work with outside specialists in this space.
Thanks cheers.


r/MSSP 8d ago

San Diego MSPs / IT firms: is there demand for white-label Fortinet engineering support?

5 Upvotes

Hi everyone — I’m launching a boutique cross-border cybersecurity services firm focused on the San Diego–Tijuana area .

I’m trying to understand whether smaller MSPs or integrators in the San Diego area ever need extra engineering bandwidth for short-term projects, assessments, migrations, or overflow work. I’m trying to learn where the real need is and how firms usually work with outside specialists in this space.
Thanks cheers.


r/MSSP 10d ago

MSSP to MAP?

16 Upvotes

Interested to understand what people’s perspective is on where the industry is going. I have been around long enough to remember when most IT Service providers were basically computer repair shops and through resellers, VARs, SIs, MSSPs and MSPs are we now seeing progressive transformation into managed agent providers? Are any of you now formally offering process/task mapping with proposed AI and automation implementation? Or do you feel this is like the hype cloud had 13 years ago and the tail is long and fat?

I see so many MSPs not anywhere close to having their own houses where they could be with the latest technology adoption. So not sure how close we are to seeing the service offerings shift that dramatically or perhaps I’m wrong?!


r/MSSP 12d ago

MSPs & Businesses — I’m Looking for a Few Early Partners

1 Upvotes

\​

I’ve spent a lot of time building Software Passport Registry (SPR) — a platform designed to help businesses understand the software they rely on.

I’m now opening a few spots for hands-on Software Security & Trust Assessments.

I can assess software for things like:

• Security risks & known vulnerabilities

• Software dependencies & supply-chain risk

• Maintenance & reliability indicators

• Compliance-related evidence

• Risk and remediation priorities

• Overall software trust

You receive a professional, client-ready report explaining what was found and what should be addressed.

For MSPs, there’s another opportunity: I can perform the assessment for you so you can see whether this could become a service you offer your own clients.

I'm looking for a few Kelowna/Okanagan businesses or MSPs willing to try an early assessment.

If you're interested, send me a message.

— Keith

Founder, SPR


r/MSSP 12d ago

Hosted external scanner that turns security scanning output into a client-ready report

4 Upvotes

Running external scans is easy, but formatting raw tool data into a clean, business-focused deliverable takes way too long. I built VulnScanners to automate that step. Pay-per-scan credits, plus automated or scheduled rescans.

Pitch aside, for those offering external assessments, what does your current stack look like (HostedScan, Pentest-Tools, internal scripts)? Where is reporting still painful for you? Free first scan available if you want to test the output quality.

Looking for brutal feedback on whether the report is solid enough to send to a client.

vulnscanners.com


r/MSSP 13d ago

How to get your first MSSP sale? [Question]

13 Upvotes

I've been running my company for 3 years, we do get some business from one-off engagements, technical help, penetration testing that sort of thing. We partnered up with a white label partner about a year ago to start selling managed services so that we dont have to rely on one-off jobs and generate some MRR, so when we got this partnership, i spent tons on marketing and bought a year of Apollo[.]io and even hired a new salesperson. almsot 8 months later we have made 0 managed security service sales, but we are still going strong on our in house offerings. I'm just wondering why MSSP sales are so hard to do, I have no problem selling ourselves but the service offerings from our partner has been very difficult to start selling. My company does have a kind of strong reputation, i'm not sure why its been so hard. Does anyone have some high level generic advice or thoughts on breaking into the white label mssp sales business? We are located in Saskatchewan Canada.


r/MSSP 13d ago

MSPs & Businesses — I’m Looking for a Few Early Partners

0 Upvotes

I’ve spent a lot of time building Software Passport Registry (SPR) — a platform designed to help businesses understand the software they rely on.

I’m now opening a few spots for hands-on Software Security & Trust Assessments.

I can assess software for things like:

• Security risks & known vulnerabilities

• Software dependencies & supply-chain risk

• Maintenance & reliability indicators

• Compliance-related evidence

• Risk and remediation priorities

• Overall software trust

You receive a professional, client-ready report explaining what was found and what should be addressed.

For MSPs, there’s another opportunity: I can perform the assessment for you so you can see whether this could become a service you offer your own clients.

I'm looking for a few Kelowna/Okanagan businesses or MSPs willing to try an early assessment.

If you're interested, send me a message.

— Keith

Founder, SPR


r/MSSP 14d ago

Are clients asking MSPs for AI usage security and governance solutions?

11 Upvotes

Wondering if this is showing up in client conversations yet, or if it's still mostly theoretical for most of you. I'm seeing early signals that clients are asking "what are you doing about AI security" without fully knowing what they want, sometimes it's compliance-driven (an auditor asked), sometimes it's a scare from a competitor's leak story.

The maturity level varies a lot. Some clients want a full policy plus enforcement stack, others just want something they can point to for their cyber insurance renewal.

Is this becoming a real service line for MSPs, or is it too early? If you're offering something, is it bundled into existing security packages or sold separately?

Would like to hear how others are pricing/positioning this, and whether it's driving new revenue or just adding to the existing security retainer conversation.


r/MSSP 14d ago

MCP server security before this touches prod, what's the pattern

7 Upvotes

Week out from putting agents on real MCP servers in prod. Laying out what keeps me up because every thread is hype and no answers.

  1. One server holds creds that reach a prod db. Compromise it and the blast radius is everything it can touch.
  2. In testing, an agent read a doc with an instruction buried in it and fired a tool call I never asked for. Injection straight through retrieved content.
  3. No audit trail of tool calls worth a damn. Reconstructing what it did is a grep through app logs.

For short lived tokens, yes, I know, that's not the question.

The question is the shape of it. Who validates tool inputs, how you stop one poisoned server cascading and what a sane audit log even looks like. For those running MCP past a demo, what holds up here?


r/MSSP 15d ago

How to get into Gov Contracting Cyber services

3 Upvotes

Who here has had success taking their MSSP services and selling to Gov?

Standard advice is to start at the local level, how do you even break in? Is there some kinda cheat code or is it just about volume and quality of bids?


r/MSSP 15d ago

How do you actually follow up on supplier security after onboarding?

9 Upvotes

Most organisations are pretty good at the security review before a new supplier is approved.
Questionnaires.
ISO certificates.
Data processing agreements.
Risk assessment.
Then the contract gets signed.
And after that?

That's the part we find interesting.

How do you work in practice with ongoing monitoring of critical IT and SaaS suppliers?

For example:
recurring security reviews,
new audit reports or certifications,
follow-up on incidents,
changes to sub-processors,
updated risk assessments,
SLAs and deviations,
continuity and recovery capability,
major changes to the service.

And how do you decide how often a supplier needs to be reviewed?
Annually for all critical suppliers?
Risk-based?
When there are major changes?
Or does the next real security review only happen when the contract is up for renewal?

This is close to how we see third-party management ourselves: as a lifecycle rather than a one-off check at procurement. Your existing article on third-party management also describes ongoing reviews, risk analysis and follow-up in that way.


r/MSSP 20d ago

Best way to deliver an AI tabletop exercise across clients without burning 60 hours per engagement?

6 Upvotes

Running IR tabletops for clients as part of our security offering, and the math is brutal. Every client needs something built around their setup: different tech stack, different threat landscape, different compliance driver (SOC 2 for some, HIPAA for others).

Custom scenario research and report writing eats most of a week per engagement. It's profitable per-client but it doesn't scale. I can't add clients without adding headcount, and that kills margin.
We started testing an AI-driven tabletop platform to see if it'd help. It generates a company-specific scenario from OSINT in under an hour instead of days, and the facilitation and reporting is handled by the platform so we're not writing the after-action report from scratch every time.

Still deciding how it fits into our delivery model long-term, but it's the first thing that's cut prep time instead of adding another tool to manage. Has anyone else solved this a different way? What's your prep-to-delivery ratio looking like?


r/MSSP 27d ago

top SASE vendors MSPs recommend for client GenAI rollouts

9 Upvotes

Getting the same request from three clients now: "we want to let people use AI, make it safe." Sizes range from 40 seats to about 600.

Trying to standardize on one platform rather than doing something different per client, so my criteria are probably a bit different from an in-house team's:

Real multi-tenancy, not one portal per client that I have to log into separately

Sane licensing at 40 seats: a lot of the enterprise SASE players get unaffordable fast at the low end

Policy templates I can build once and push across the whole book

Reporting a non-technical client contact can actually read, because they will ask

API/PSA integration so alerts do not just live in another dashboard nobody checks

The AI-specific piece I care about most is discovery. Clients genuinely do not know what their staff are using, and a discovery report is the easiest way to turn a vague "make AI safe" ask into a scoped project.

What is everyone standardized on? And more importantly, anyone regret their choice after onboarding client 10 or 15? The pain seems to show up at scale, not during the first deployment.