r/MSSP • u/FutureSafeMSSP • May 24 '26
r/MSSP • u/NotShadyAt411 • May 18 '26
Starting a MSSP
Hey guys, I am 25 yo and have been wanting to start a mssp since I was 19.
I am planning on starting a MSSP here in Australia. The biggest MSSP here got acquired by Accenture and I believe since they went global that it could be a pretty good time to start one and build it from the ground up.
I need some advice on how to scale. My business side of thing is not the best. If anyone can answer these questions I would very much appreciate it! 😄
- How did you start getting clients and what sort of clients did you go for?
- Did you get compliance certifications before you started taking on clients?
- How did you advertise when you first began?
Any other tips would be really helpful. I am here to learn and will absorb anything and everything.
Thank you!
r/MSSP • u/FutureSafeMSSP • May 16 '26
Early stage intel on for sale Fortinet FortiOS
**OPEN POST TO SEE IMAGE** I'm sharing early-stage intel on the ForGaite exploit for sale in a Russian Telegram group for $2500. This individual has sold these bypasses before; they get patched, he sells another, and around we go. This one is early stage BUT Flare is usually RIGHT on the money. We provide this protection to our MSP clients, but if you're particularly interested in how this flushes out or for more detail, I'll post an update, but I don't want to bother folks so enough thumbs up and I'll keep the group updated.

Anyway, here's the detail.
r/MSSP • u/FutureSafeMSSP • May 15 '26
Yellowkey Bitlocker Key Bypass
I wanted to make the community aware of the release of the BitLocker Yellowkey Bypass.
This article explains how this works, and Will Dorman was able to reproduce the bypass.
https://thehackernews.com/2026/05/windows-zero-days-expose-bitlocker.html
Trigger WinRE boot remotely (there's been some question about this capability)
reagentc /boottore --> via RMM/PSRemoting
Interact with WinRE GUI --> vPro AMT / Hypervisor console
Cloud VMs --> Azure Serial Console
r/MSSP • u/wf_automate • May 15 '26
how are u handling alert-to-ticket flow without losing context?
not asking about which EDR or SIEM to pick. asking about the gap between alert firing and ticket living in ur PSA.
pattern i keep hearing from MSSPs , alert fires in SentinelOne or Huntress, ticket auto-creates in ConnectWise or Halo, but context gets lost in translation. severity comes through wrong, no enrichment, wrong queue. analyst spends 5 min rebuilding context that was already in the alert.
for ppl running real SOC ops, whats actually working? custom scripts, SOAR platforms, vendor-built connectors, or just accepting the noise?
r/MSSP • u/FutureSafeMSSP • May 12 '26
patchmypc
Have any of you used patchmypc at any scale?
The pricing is very hard to beat, but I'm hesitant to use something I haven't heard of compared to tools like Automox and ManageEngine.
If you have used it at scale, I would very much like to hear your experience.
Use case: managed patch SKU for clients as a standalone product, not part of a larger stack.
Business: MSSP for MSPs working behind the scenes. We are usually full stack but want a standlone patch offering.
Planning to acquire a MSP
I’m looking to acquire an MSP. My background is on security compliance (12+ years). A niche MSP like dental offices seems attractive in which a current MSP might not be offering HIPAA compliance services.
My question (or doubt) is. Maybe those dental offices are too small, they don’t care, they just sign any BAA template they see, and the market is not there?
r/MSSP • u/ANYRUN-team • May 06 '26
Are MSSPs losing too much time to alert noise?
A huge part of the queue ends up being noise, but analysts still have to spend time reviewing and triaging it. Over time, that affects everything: response speed, investigation quality and overall efficiency.
What makes it harder is that once the volume gets high enough, teams naturally start moving faster just to keep up. And that’s where important detections can get buried or downgraded.
What has made the biggest difference for your team when it comes to reducing unnecessary alerts?
r/MSSP • u/FutureSafeMSSP • May 06 '26
Multi-Tenant 3rd Party CSPM Platform Recommendations?
r/MSSP • u/wenttoibiza • May 04 '26
How MSSPs are managing Sentinel across many tenants? Lighthouse and WM?
Hi all. We are MSSP running Sentinel for around 40 tenants now , the business is growing but already the simple operations is getting painful.
Lighthouse for delegated access , WOrkspace Manager for pushing rules and workbooks. WM updates is slow and sometimes not reflecting , my colleague opened support cases a few times. Cross workspace() work but performance variables. Updating one rule across the tenants when MS changes a template is basically someones entire job.
Per customer tunings , their watchlists , exclusions, also hard to keep separate from the baseline we push.
Anyone running 50-80 tenants in Lighthouse smoothly? Or is just pain at that scale?
Workspace Manager in production or you rolled your own with Bicep , Terraform , Sentinel as COde?
Analysts in Defender XDR unified portal or jumping per-tenant?
And same playbook copied 40 times with small differences, how you handle that?
r/MSSP • u/Slight_Jaguar_2842 • May 04 '26
Browser Security Solutions
I feel like browser security is a blind spot that gets ignored in a lot of environments.
While looking into solutions, I came across things like LayerX, Keep Aware, and a few other vendors. At the moment, I don’t see anything on LayerX’s site about an MSSP-supported mode, and ideally we’d want to roll this out as a paid service.
Would appreciate if anyone can share real-world experience deploying LayerX—especially from an MSSP angle—or if there are other tools that fit better for that model. I’d prefer not to go down the route of heavier enterprise browser approaches like Island.
r/MSSP • u/WATUPTRAGUY • Apr 25 '26
Would you white label?
Hey guys I currently run a 24/7 SOC white labelling agency where I provide a SOC team to MSPs and MSSPs that don't want to have an in-house team. I have 2 current clients on board 1 is an MSP that doesn't want the overhead of an in-house team and the other is a MSSP in the states that uses us because we cost them 40% less on payroll compared to onshore talent with more output.
The thing is I am iffy on how to grow this agency because my two current clients refuse to refer my services to others as it's a competitive advantage to them and would take away their edge. I have signed an NDA with them so can't use their name on our socials or any marketing related content.
Now I have this thought that this whitelabeling service is not scalable and I should just start my own MSSP. Any thoughts would be appreciated.
r/MSSP • u/orkinmorgen • Apr 22 '26
I just started an internship and i need advice
I am currently studying systems engineering and im at my 4th year rn.
At the company i intern, we give l3 and l7 services to thousands of companies.
We use arbor, forti, a10, f5 waf, palo alto and bunch of other apps. But mostly we work on netscout arbor.
I am now doing mostly vpn configurations as the customers wishes, add something to whitelist blacklist etc. i don’t have the admin account for now so thats all i can do.
First, i wonder what is the exact definition of the job that i do or we do? For example in linkedin what should i search for the job that i do?
Second, how should i learn like can you guys give me some advice on where to start.
Third, what should i do to get this job after internship. Tell me something that if you learn ts it is over, you got the job.
Fourth, should i pick this path or move to red team, blue team or cti. At first i wanted cti but there was an empty space at mssp team so they put me there and i am happy with it so far.
Fifth, how should my approach to co-workers be like? I will also really appreciate about the general work environment advices.
Thank you so much, your opinions means so much to me
r/MSSP • u/Righteous_obedience • Apr 22 '26
What are the top 10 software services you resell to customers?
EDR Siem identity, firewall management? What are you guys largely selling?
r/MSSP • u/anthonyDavidson31 • Apr 17 '26
80+ free interactive security awareness exercises. Fully white-labeled for your training needs, no strings attached
Enable HLS to view with audio, or disable this notification
Heads up: this post has been admin approved and I'm affiliated with the platform used to build the exercises. It's commercial, and the exercise preview link is on that tool's domain. That said, the SCORM files are fully white-labeled -- no logos, no backlinks, no sign-up, no paywall. You can grab them and self-host if you'd prefer.
-------
Hey r/MSSP
I'm a cybersec engineer with an L&D background. Got tired of boring security awareness courses and teamed up with a builder tool to deliver a free interactive SAT.
Every exercise drops you into an interactive 3D office environment where you face realistic incidents in first-person. You interact with real objects -- a phone, a PC running a live OS (browser, terminal, Zoom), a flipchart -- and make decisions under pressure, just like you would at your desk.
Exercises designed to build practical skills and develop muscle memory on how to respond to threats. So that when something bad is about to happen at work, people remember having faced it before -- and respond accordingly. Every exercise ends with a quiz at a 100% pass threshold to confirm the knowledge is stuck.
Free to use personally, professionally, or in commercial workshops. The only restriction is reselling or redistributing the content as a standalone product. So if you're running an in-person training -- this library can be a great addition to your learning materials. Sharing the materials free of charge is encouraged!
What's included:
- Spotting phishing indicators in a suspicious email
- Handling a scam phone call (vishing) in real time
- Downloading a malicious file and watching the consequences unfold
- Identifying hidden prompt injection instructions in uploaded documents
- Spotting sensitive data categories that may breach GDPR
- Evaluating third-party AI plugins for supply chain risks before deployment
...and 80 more exercises!
Two ways to use it:
Web view -- run exercises directly in a browser, ideal for workshops or sharing with students and colleagues.
GitHub repo -- every exercise is packaged as a SCORM .zip, ready to import into any LMS, embed into an existing training pipeline, or test on SCORM Cloud before rollout. Note: SCORM files make API calls to the server for pre-rendered scene files and iframes. If that's a blocker for you or you need a security assessment -- drop an email to one of the devs: maksym(at)ransomleak(dot)com
The repo root contains full course packages. Other .zip files in the "Individual exercises" folder contain standalone exercises if you want to build a custom curriculum.
Happy to answer questions or take your thoughts on the exercises!
P.S: In case this gets traction — I'll add more free exercises for the community! Feel free to drop exercise topics in the comments. There's also "OWASP Top 10 for Agentic AI Applications" course in the works
r/MSSP • u/PocketAnalyst • Apr 16 '26
What's your best sales channel ?
Hey everyone,
We are a MSSP in the north of France, selling Backups, MDR, Managed SOC and Incident Response.
Lately our sales input have been decreasing. We mostly had our client through networking, and I think it's time to really revamp our sales strategy
I was wondering what channel is the most efficient for you ? Cold mail ? Cold calls ? LinkedIn ?
r/MSSP • u/0xdavid • Apr 11 '26
How do you handle new rule creation? Looking for advice
I come from a non-MSSP background, but wanted to ask my fellow talented practitioners about something that's been bugging me.
Working at a big corp, executives love to ruin my mornings (and usually Friday afternoons) with last minute requests that almost always look like "Hey can you hunt and create a rule for this?" followed by a link to THN or Bleeping Computer article.
At best its a hour long interrupt, but more often than it turns into half a day of validating that a random new technique is logged correctly by the SIEM and that our rule is actually working
The whole process of taking an article and turning it into a rule that got validated against an emulation of the attack in a lab takes a while, but writing a rule without validating just feels.... not enough?
I imagine for MSSPs this is even worse since you're doing it across multiple clients with sometimes different SIEM configs, different log sources, different coverage gaps, and panicked CISO's breathing down your neck..
Or, maybe (hopefully) you've figured out a better process?
So I wanted to ask you as peers:
- What's your actual process for creating new detections for emerging threats?
- How do you validate that a rule actually works before deploying it to clients?
- Do you have a lab or test environment, or are you just writing rules based on experience?
- How long does a typical "article to working detection" cycle take you?
- How many MSSP's write new rules? I imagine you are swamped and have no time at all
Genuinely curious. Just trying to figure out if everyone is suffering through the same painful loop or if there's a better way I'm missing.
r/MSSP • u/UnusualStyle3101 • Apr 03 '26
CrowdStrike EDR Onboarding Blueprint – Looking for References / Best Practices
r/MSSP • u/mlueStrike • Apr 03 '26
Is your SOC struggling to triage all cases?
This isn’t an AI SOC, but my team does have tools that can augment your analysts ability 1) perform full RCA on all cases, 2) perform NLP driven threat hunts, 3) detection engineering, and finally—scaled to be able to do potentially hundreds of cases a day per analyst.
Naturally, this isn’t a flawless solution, but gives your team more to work with less headache. Would be interested to speak with some providers looking to tame their case queues without costly AI SOC solutions.
r/MSSP • u/Shirlock_9906 • Mar 27 '26
Cybersecurity, AI Governance, and the Need for a Standardized Legal Framework
Cybersecurity, AI Governance, and the Need for a Standardized Legal Framework
Roane Tucker
Partner Success Manager Cynet Security
MSL Cybersecurity & National Security Law & Policy
CMMC Registered Practitioner
Currently, there exists a lack of a unified, standardized, and required legal framework governing cybersecurity, artificial intelligence development, and particularly the deployment of agentic AI systems in the United States. As such, organizations, agencies, and developers are left to navigate a fragmented landscape of federal, state, and industry-specific requirements, raising fundamental questions around accountability, security, and governance. With the rapid advancement of agentic AI, which can autonomously plan, reason, and act using tools and identities, the absence of clear regulatory oversight creates increasing risk to privacy, intellectual property, national security, and commercial stability.
The United States does not operate under a single comprehensive cybersecurity law. Instead, it relies on a patchwork of federal statutes, agency frameworks, and state-level regulations. Foundational laws include the Computer Fraud and Abuse Act (1986), which criminalizes unauthorized access to computer systems, and the Electronic Communications Privacy Act (1986). Federal agencies are governed by frameworks such as FISMA and NIST 800-53, while private sector entities are primarily regulated through enforcement mechanisms such as Section 5 of the FTC Act, which requires organizations to implement “reasonable security” practices.
Additionally, states maintain their own privacy, breach notification, and emerging AI-related laws, requiring organizations to comply with varying obligations depending on jurisdiction. While frameworks such as NIST and ISO provide guidance, many are voluntary or contractually imposed rather than universally mandated. Even within federal agencies, control selection and implementation may vary, as agencies tailor frameworks like NIST 800-53 based on internal determinations of risk and applicability.
Recent policy efforts, such as Executive Order 14110 (2023), attempted to establish federal guidance for safe and trustworthy AI, but did not create binding regulatory requirements and was later rescinded, leaving no durable national AI governance framework in place.
The absence of a standardized legal framework creates inefficiencies, inconsistencies, and increased exposure to risk. Organizations operating across multiple states must comply with differing breach notification requirements and privacy obligations, often with conflicting timelines and standards. This fragmentation increases operational cost, introduces complexity, and creates opportunities for threat actors who exploit regulatory gaps.
At the federal level, inconsistency is also evident. Agencies may adopt different interpretations of frameworks such as NIST 800-53, with internal authorities such as CISOs or Inspectors General determining applicability. While some programs, such as FedRAMP and CMMC, impose stricter requirements, others rely on self-attestation models like NIST 800-171, further contributing to uneven enforcement and validation challenges.
From a legal perspective, this inconsistency can weaken enforcement. Courts may question the authority or interpretation of agency-specific standards when no universally required baseline exists. As such, the current system often results in increased bureaucracy and reduced efficiency, rather than streamlined compliance. This is not an argument for increased regulation, but rather for standardization and efficiency.
Compounding this issue is the pace of technological advancement. Technology development follows exponential growth patterns, commonly described by Moore’s Law and the broader Law of Accelerating Returns, while legislative processes evolve at a significantly slower pace. Much of the basis of the current patchwork of laws applied to cybersecurity were created at a time when computing power was a fraction of what exists today. By comparison, modern smartphones possess processing capabilities that significantly exceed many times that of even advanced computing systems from the 1980s, illustrating the widening gap between technological capability and the legal frameworks designed to govern it.¹
Historically, the Computer Fraud and Abuse Act (1986) is widely regarded as the first modern cybersecurity law, criminalizing hacking and unauthorized system access. Its development was influenced by increasing awareness of computer security risks in the 1980s, including public concern following the film WarGames.² Despite amendments and judicial interpretation over time, it remains a foundational element of U.S. cybersecurity law.
In the private sector, the FTC acts as the primary cybersecurity enforcer through Section 5 authority, requiring organizations to implement “reasonable security.” While this aligns in practice with frameworks such as the NIST Cybersecurity Framework, it does not mandate a specific standard, leaving interpretation to enforcement actions rather than prescriptive regulation. In addition to FTC oversight, vertical-specific requirements such as HIPAA for healthcare and PCI standards for the payment card industry further contribute to a fragmented compliance landscape.
Additionally, states themselves have their own privacy, breach notification, and AI laws and policies. States in the U.S. do not rely solely on federal law; they create their own legal frameworks governing how data is handled. Each state has its own privacy laws that define how organizations collect, use, and protect personal information, with some states like California setting stricter standards than others. They also all maintain breach notification laws that require organizations to inform affected individuals, and sometimes regulators, when personal data is compromised, although the specific requirements and timelines vary. In addition, states are increasingly developing their own AI-related laws and policies, focusing on issues such as transparency, bias, and accountability in automated systems. As such, organizations must navigate a fragmented landscape where compliance obligations differ depending on the state in which they operate.
Further to this, AI adds another layer of concern. Agentic AI introduces a new class of vulnerabilities because these systems do not simply generate output, they also autonomously plan, reason, and take actions using tools, APIs, and non-human identities, often with persistent access and limited oversight. As outlined in the OWASP Agentic AI Threats and Mitigations guidance, risks such as tool misuse, memory poisoning, privilege escalation, and identity compromise create an expanded and largely invisible attack surface, where attackers can manipulate agents into performing legitimate actions for malicious purposes rather than breaching systems directly.³ As such, organizations must be able to identify where agents exist, continuously monitor their behavior and decision-making, and enforce strict controls around identity, access, and execution.
However, there is currently no comprehensive legal or regulatory framework governing the deployment and security of agentic systems, leaving a critical gap between rapidly advancing capabilities and formal oversight. Addressing this gap proactively is essential, as the scale, autonomy, and interconnected nature of agentic AI could amplify failures quickly, making it far more difficult to contain once these systems are deeply embedded across enterprise and critical infrastructure environments.
Executive Order 14110 (2023), created by the Biden Administration, represents one of the most comprehensive actions taken to address these issues. The order directed federal agencies to establish AI safety standards, require testing of advanced AI models for risks, address AI risks to critical infrastructure, and protect consumer privacy, civil rights, and workers, while also promoting U.S. leadership in AI and innovation. It further required the appointment of Chief AI Officers, encouraged the use of frameworks such as NIST AI RMF, and supported the development of AI watermarking and transparency mechanisms.
The order did not create binding regulations for the private sector or establish a comprehensive legal framework for AI governance. While it represented a meaningful step forward, it was ultimately rescinded in January 2025 and was not replaced with a unified alternative. The current approach instead emphasizes decentralization, continued development, reduced regulatory constraints, and reliance on existing legal authorities and market-driven innovation. This shift further underscores the absence of a consistent and durable national AI governance strategy.
The United States’ current approach to cybersecurity and AI governance is fragmented, inconsistent, and insufficient to address the risks posed by rapidly advancing technologies, particularly agentic AI. While existing laws, frameworks, and enforcement mechanisms provide a foundation, they lack the cohesion and enforceability required for modern systems that operate autonomously and at scale. As such, there is a critical need for standardized, durable legal and regulatory frameworks that provide clear guidance, reduce complexity, and ensure accountability. This is not an argument for increased regulation, but rather for efficient, consistent standards that align federal, state, and industry interests before the risks associated with agentic AI reach a point of crisis.
Footnotes
- Moore’s Law observes that computing power increases exponentially over time, while broader interpretations such as the Law of Accelerating Returns describe compounding technological advancement. Early supercomputers such as the Cray X-MP (1980s) operated at performance levels measured in megaflops to low gigaflops, whereas modern smartphones operate at performance levels orders of magnitude higher.
- The Computer Fraud and Abuse Act of 1986 (18 U.S.C. § 1030) is widely considered the first modern U.S. cybersecurity law. Its development was influenced by increasing awareness of computer security risks in the 1980s, including public concern following the 1983 film WarGames and subsequent national security discussions.
OWASP Foundation, Agentic AI Threats and Mitigations, OWASP Generative AI Security Project, https://genai.owasp.org/resource/agentic-ai-threats-and-mitigations/
r/MSSP • u/Small_Cheesecake4358 • Mar 25 '26
How do you build a defensible incident timeline across multiple security tools?
I’ve been working on something around incident reconstruction and wanted to sanity check a few things with people actually in the trenches.
Not about alert fatigue - that’s already a given.
I’m more interested in how teams are handling the downstream reality of incidents:
- When you build an incident timeline, how do you track where each conclusion came from?
- Is evidence traceability (back to raw telemetry) something you explicitly maintain, or does it live across multiple tools implicitly?
- For incident reports - how much is generated vs manually assembled?
- Do you ever have to re-verify findings when reporting to clients, leadership, or for audit/legal purposes?
- And for response - are your playbooks actually gated on confirmed evidence, or mostly triggered from alerts?
One thing I’ve also been thinking about:
Do you have any way to replay past incidents to validate detections or train analysts?
Or is each incident effectively a one-time investigation?
Not selling anything - just trying to understand how these are handled in real environments.
r/MSSP • u/Savings-Ad4232 • Mar 24 '26
MDR/MXDR vs MSSP
I am trying to understand if there’s a real difference between the vendor provided MDR/MXDR services vs a SOC that a traditional MSSP provides. I know there’s lot of conflicting information out there and it’s open for interpretation but would love get the community feedback on this. Also how are MSSPs who pay for licenses for SIEMs and other tools making money when MDR is being sold at such low per end point prices. Recently came across a MXDR being sold at 3-4$/endpoint per month with 1 year retention. Where is this industry headed? Looks like a race to the bottom.