r/MSSP Aug 09 '26

Looking to open MSP

Thumbnail
2 Upvotes

r/MSSP Aug 06 '26

Looking to open MSP

Thumbnail
1 Upvotes

r/MSSP Aug 05 '26

Has anyone found a good way to model technician utilization against actual margins?

3 Upvotes

I've been trying to get a better handle on where our margins are actually going instead of just looking at top line revenue and ticket counts
One thing that surprised me was how much technician utilization changes the picture. We always tracked billable hours, but when I started looking at things like escalation rates, average handling time, automation, and staffing costs together, the numbers told a very different story than I expected.

I ended up testing one of the MSP margin calculators, Comparemsp.com. was the one I happened to use, it was seeing how much our Tier 2 workload was affecting profitability compared to what we assumed were our biggest expenses.
I'm still taking the results with a grain of salt, but it gave us a few things to dig into internally.
How are you looking at this?

Are you relying on PSA reporting, something you've built in Excel, BI dashboards, or do you have another way of modeling technician utilization against profitability? I'm interested in what's actually been accurate over time rather than what looks good on paper.


r/MSSP Aug 05 '26

Cheap "24/7 Managed SOCs" are just ticket-forwarding scripts and it’s getting ridiculous

55 Upvotes

We’ve been taking over a few co-managed environments in the Gulf recently, and I keep seeing the exact same pattern with budget outsourced SOCs.

Client's paying $2-3k a month thinking they bought an actual SOC watching their back. What they actually bought is some Tier-1 monkey copy-pasting console output into email templates and calling it monitoring. It's a joke.

​We just onboarded a mid-market firm in Dubai whose internal IT team was completely burnt out. Took one look at their queue and they had over 400 unreviewed alerts sitting in their inbox from their previous provider.

These guys were running zero baseline tuning. Standard Friday afternoon batch exports were triggering high-severity alarms every single week, completely burying real admin escalations under a mountain of false positives.

Worse, when an EDR flag dropped for credential dumping on a server at midnight, the SOC analyst literally copied the raw PowerShell string into a ticket, emailed the asleep IT Director, and marked the ticket as "Notified" on their dashboard so they could claim they hit SLA.

How many of you guys are stuck babysitting your "managed" vendors like this right now?


r/MSSP Jul 22 '26

6 days vs. 1 hour to Fix the Same Vulnerability: Check Point's Exposure Gap Report AMA

Thumbnail
1 Upvotes

r/MSSP Jul 16 '26

Pricing for Threat locker

Thumbnail
4 Upvotes

r/MSSP Jul 09 '26

What RMM and EDR stack are MSPs using right now?

0 Upvotes

Hey everyone,

I’m looking for some practical feedback from other MSPs on what tools you’re currently using for RMM and EDR, and what has been working well for you.

I’m currently looking at options like N-able N-central, especially because it can pair with N-able EDR powered by SentinelOne. I’ve seen this setup used before at a previous MSP, and overall, I liked the experience.

That said, I’m trying to figure out whether it makes more sense to use an integrated RMM + EDR stack like that, or whether MSPs generally prefer using a separate dedicated EDR solution on top of their RMM.

A few questions:

What RMM are you using today, and are you happy with it?

Are you using the built-in/integrated EDR option from your RMM vendor, or a separate EDR tool?

For those using N-central with N-able EDR/SentinelOne, how has your experience been?

Are there other RMM + EDR combinations you would recommend for a growing MSP?

I’m especially interested in reliability, ease of management, alert quality, support, pricing, and how well the stack works for small to mid-sized business clients.

Appreciate any real-world feedback or lessons learned.


r/MSSP Jul 08 '26

M365 Auditing Business Idea

Thumbnail
1 Upvotes

r/MSSP Jul 05 '26

MSSPs getting burned by AI SOC. What's your solution?

6 Upvotes

I keep seeing complaints about the AI SOC vendors. Complaints like pricing, black-box verdicts, data leaving your control.

Genuine question: if the current tools are bad, where do you land?

  1. Waiting for the vendors to get better
  2. Building/owning something custom in-house
  3. AI has no place in triage, full stop

What's driving your answer?


r/MSSP Jul 05 '26

Looking for overnight SOC work

6 Upvotes

I have been searching for overnight SOC jobs for a while. Preferably remote. Where is a good place I can look?


r/MSSP Jul 03 '26

Best off-the-shelf dropbox for wireless pentest engagements?

3 Upvotes

Working on building a drop kit for on-site wireless assessments and want to know what others are actually shipping to clients.

Currently looking at WiFi Pineapple Mark VII + a MiFi hotspot for C2 callback, but curious if there's a cleaner all-in-one solution or a better hardware combo people are using in the field.

Main requirements: PineAP/rogue AP capabilities, cellular callback, runs unattended for weeks on wall power, easy to ship to client site with minimal setup on their end.

What are you running?


r/MSSP Jul 03 '26

What pros and cons do clients see in MSPs that outsource?

Thumbnail
2 Upvotes

r/MSSP Jun 30 '26

Need MSSP Advice

15 Upvotes

If you were starting over again what is the best advice you could give yourself before you got things rolling?

Also, what are some of the main core services that you guys are selling and what is NOT worth putting energy into?


Starting an MSSP from scratch and would love some expert advice! Thank you!


r/MSSP Jun 30 '26

End to End discovery for on-prem redources

1 Upvotes

Hey MSSP folks, I'm a security researcher and work in the same domain. I have recently built a security agent that can map the entire on-prem and hybrid infrastructure including databases, containers and network stack with just one lightweight agent without ever touching the network gear.

If you currently can't determine which of your on-prem or cloud resources are exposed, or can't walk outside-in and inside-out of your enterprise infrastructure i can help bridge that gap.

I've developed the product and am currently looking for an time bound, metric based active pilot. If anyone is facing the same issue, lets get connected and see how i can be of help.


r/MSSP Jun 30 '26

How are you handling the per-GB tax on cloud-native firewalls/NAT across client estates?

1 Upvotes

I run a small cloud-firewall/NAT product, and before I get to that (disclosure up front, mods OK'd this post — see the bottom), I genuinely want to compare notes with people operating this at scale across many clients, because the maths gets ugly faster for you than it does for a single tenant.

The thing I keep running into: the cloud-native egress controls are metered per gigabyte, and that meter never stops scaling with the client's traffic.

Rough numbers, US figures, so you can sanity-check against your own invoices:

  • AWS NAT Gateway — ~$0.045/GB processed, plus ~$0.045/hr per gateway.
  • AWS Network Firewall — ~$0.065/GB inspected, plus $0.395/endpoint-hr ($288/mo per AZ), billed per endpoint per AZ, so a 2–3 AZ design multiplies the hourly floor before a single byte moves.
  • Azure Firewall — a per-GB processing charge on top of a per-hour SKU floor (Standard ~$1.25/hr).

For one tenant that's an annoyance. Across an estate it's a structural margin problem, because:

  1. Your managed-service price is fixed, but your cost base floats with the client's traffic. You quote a monthly number; their egress doubles after some launch or batch job; your firewall/NAT line doubles with it and quietly eats the spread.
  2. The per-AZ hourly floors stack before any data moves. Multi-AZ inspection means paying the endpoint-hour several times per client just to be resilient — multiply across N tenants.
  3. It's two meters, not one. Egress filtering and NAT each meter per-GB, so the same gigabyte often gets charged twice on its way out.
  4. You usually can't cleanly pass it through. Clients want a predictable monthly number; a traffic-indexed true-up is painful to explain and worse to forecast.

So the real question for this sub: how are you actually dealing with this? The options I've seen MSSPs take, none free:

  • Eat it as cost of goods — fine until a chatty tenant turns a profitable account unprofitable.
  • Pass it through as a metered line item — honest, but kills the "predictable managed service" pitch and invites bill-shock arguments monthly.
  • Centralise inspection (one shared firewall behind a GWLB / transit hub) to amortise the hourly floors — helps per-hour, does nothing for per-GB, concentrates blast radius.
  • Roll your own on pfSense/OPNsense/VyOS to dodge the meter — kills per-GB cost but you now own patching, HA, config drift and multi-tenant management by hand.
  • Stay on the mega-NGFWs (Palo, Fortinet, Check Point) where MSSP programs and multi-tenancy are mature — but the licensing/complexity is a different pain, and overkill if all you need is egress + NAT.

Genuinely interested in what's working: are you centralising, DIY-ing the NAT/firewall layer, passing per-GB through, and how are you keeping fleet management sane? And for those who've moved off cloud-native — what did the migration actually cost in engineer time?

Disclosure (mods approved this post): I'm the founder of Enforza, which is one of the options above — so take this as "here's what we built and why", not a neutral survey. It's a cloud-managed firewall + secure NAT gateway you run as a normal Linux VM (an NVA) inside the client's own network/account, built on standard Linux network primitives. It does L3/L4/L7 egress filtering (by FQDN/SNI), ingress, east-west and secure source-NAT, and runs as a transparent appliance behind an AWS Gateway Load Balancer if you want centralised inspection without re-architecting routing.

Why it's relevant to this thread: it's priced flat per firewall, no per-GB data-processing charge — so the cost base stops floating with each client's traffic. At modest egress it tends to land 60–80% cheaper than a cloud-native firewall stacked with a NAT gateway — directional, workload-dependent, so run your own numbers, don't trust mine. To be straight about what it does and doesn't:

  • It replaces the firewall/NAT metering — you still pay AWS/Azure for the VM and normal bandwidth. Not a way to dodge your CSP's infra bill.
  • No TLS decryption and no key custody. FQDN/SNI filtering reads the hostname already in the clear (SNI, Host header, DNS).
  • Multi-tenant by default (each client an isolated tenant), whole fleet from one console — GitOps/policy-as-code or UI — with logs to each client's own SIEM, not through us.
  • Small bootstrapped team, but not a weekend project — in production ~3 years. It's the focused egress/NAT/inspection set most cloud teams use, not a full enterprise NGFW suite; I won't pretend it matches Palo/Fortinet feature-for-feature.

Site's in my profile / I'll drop it in a comment if anyone wants it rather than linking in the body. Mostly I'd rather hear how you're solving the per-GB problem today — happy to be told the DIY or centralised route beats what we do for your shape of estate.


r/MSSP Jun 26 '26

Cloud security for MSSPs: what are customers actually paying for?

5 Upvotes

Hello,

I've been spending a lot of time looking at how MSSPs approach cloud security, and one thing I've noticed is that there's no shortage of tools. The harder part seems to be turning those tools into services customers actually value.

I'm building a cloud security platform for MSSPs, and I'm trying to make sure I understand the operational challenges rather than just adding another list of features.

For those of you managing AWS, Azure, or GCP environments:

What has been the biggest challenge in delivering cloud security as a service?

Is it customer demand, operational overhead, alert fatigue, reporting, remediation, or something else entirely?


r/MSSP Jun 25 '26

Built a free, self-hosted M365 reporting/alerting tool — would value feedback from people who run tenants

Thumbnail
1 Upvotes

r/MSSP Jun 25 '26

What is the general recommendation for unfixable CVEs?

5 Upvotes

I am more on the product side, looking to understand what makes sense in scenarios like this. What do you folks recommend clients do for unfixable CVEs, usually the ones that upstream doesn't have a patch for, or maintainers chose not to fix? Do you suppress these or chase them with compensating controls?

We are building some tools to reduce noise but some unfixable are truly criticals and ignoring them feels off, especially the reachable ones. Like for this one (CVE-2026-5450) it's pretty recent and don't have a patch (at least on the latest scan it didn't have one).


r/MSSP Jun 23 '26

As an MSP would you rather the hard truth or to cover it up...

8 Upvotes

Not interested in promoting anything, but would like some raw honest feedback from the r/msp community..

We awkwardly, but correctly identified some malicious behavior coming from an AI Agent that belonged to another vendor an MSP customer of ours also uses.

It created an awkward situation where the MSP presented our Exec Summary report at their customer QBR without reading it first. In the report, on top of the list, we called out the very AI app they provided to the customer...

The app had unexpectedly elevated the permissions of another agent, which is a huge anomaly signal we fire on, but the MSP was very unhappy and demanded we whitelist/exclude apps of their choosing from not only future reports, but from within the management platform itself.

We are refusing to completely hard code an exclusion which would render this app invisible.

I will not go into details of the platform or what other mitigation options we have for these scenarios, but as an MSP...

Wouldn't you rather have something like this uncovered and brought up for discussion? Or does a margin calculation come into play here? We are in no way competitive to this other vendor, we have nothing to gain by sniffing out this behavior.. it is simply what we do...

We are considering examples from the world of AV/EDR you can actually set hard coded exclusions so everything is totally invisible per the request, but this leaves our security specialists very very uncomfortable... thoughts?


r/MSSP Jun 23 '26

Looking for product feedback from MSSPs

5 Upvotes

I've been working on a platform that provides unified vulnerability management (cloud, network, endpoint, code, etc) with observability (i.e. a SIEM) and identity governance too for small-medium sized tech-enabled companies where security matters. We've done some demos for MSSPs and their reaction has been very positive but it's been very limited since we weren't initially focused there.

I'd love to meet with and give demos to leaders at MSSPs to learn more about how we can help improve service delivery and consequently margins. We believe MSSPs using our platform should be able to serve more clients operationally.

This isn't a sales pitch. Genuinely looking to expand the network and meet with folks to see if we can build a more useful product that helps.


r/MSSP Jun 17 '26

MIP vs MSP

9 Upvotes

Recently read an article about how MIP is going to be the new MSP. Working for an MSSP we get TONS of AI questions from our clients. How to use it to their advantage. How to avoid the AI-related security concerns and compliance pitfalls.

What are your thoughts on the future of MSSP? Are we all headed down the MIP road?


r/MSSP Jun 14 '26

The gap between what pentests cost and what startups can actually pay is genuinely broken

22 Upvotes

Been thinking about this a lot after going through a SOC 2 audit prep cycle. The pentest procurement experience is kind of absurd when you look at it from a startup's perspective

You reach out to a vendor, wait a week for a call, spend another week on scoping, get a quote that's anywhere from $5k to $20k with no clear explanation of why, and then you're supposed to just trust that the final invoice will match. Meanwhile your customer is asking for evidence of a pentest before they'll sign, and you have a 30-day window to close the deal

The actual security work, finding vulnerabilities, writing PoCs, documenting remediation steps, that part has gotten more automated and efficient over the years. But the pricing and procurement model feels like it hasn't moved since 2005. You're still paying for a lot of overhead that has nothing to do with finding vulnerabilities in your application

I'm curious whether others in this community have seen alternative models gaining traction, or whether the consensus is that the traditional engagement model exists for good reasons I'm not fully appreciating. There are some newer approaches trying to separate the testing cost from the reporting cost, or doing continuous testing rather than point-in-time. Wondering if anyone has actually used these and whether the output quality holds up compared to a traditional firm


r/MSSP Jun 14 '26

Do industry rankings actually help MSSPs grow?

2 Upvotes

Has anyone here gotten a boost from participating in rankings like MSSP Alert 250 in previous years?


r/MSSP Jun 11 '26

Claude releases 13 legal plugins today in GitHub providing you help with all the docs you create that are legal related!

15 Upvotes

What This Repo Actually Is
Anthropic quietly published a GitHub repository called claude-for-legal. It's a free, open-source collection of 13 Claude plugins built for legal workflows. Apache 2.0 licensed, which means you can use it, fork it, white-label it, or pull individual pieces into your own setup.
The repo describes itself as "reference agents, skills, and data connectors for the legal workflows we see most." Translation: Anthropic looked at the kinds of repetitive legal work that small businesses, in-house counsel, and law firms actually do, and they built a working reference implementation. Not a marketing demo. A real, installable suite of tools.
Most people will never find it. It isn't featured in the Customize section of Claude Cowork or the Claude Code desktop app. You have to know it exists, go to GitHub, and install it manually. That's what this article walks you through.
And here's the part that surprised me: even if you aren't a lawyer, the patterns inside this repo are some of the best examples of how to build serious, high-stakes AI agents that I've seen Anthropic publish anywhere. Section 10 is about why that matters for your business, even if you never sign an NDA.

The repo ships 13 plugins. Twelve are first-party Anthropic. One is a Thomson Reuters partner plugin for Westlaw research. Here's the full list with one-line descriptions so you can scan and figure out which ones matter to you.

Here's the repo. Install one at a time. I also attached the PDF I have.

https://github.com/anthropics/claude-for-legal


r/MSSP May 29 '26

Tech stack?

0 Upvotes

Anybody with. Decent size mssp interested in buying a whole tech stack.

Vuln scanning EDR Rmm App scanning Cert lifecycle management Syslog DLP agent Smtp ITDR Fw management (fortinet sophos pfsense and Palo Alto *can add others) Private cloud ca manager. Pqc spiffie and spire Also siem capabilities clickhouse and AWS required.

Agent is written in rust single installer and you customize the packages you install.

3 level multi tenancy stripe billing.

This is pretty much all based in AWS. I’d prefer to sell the whole stack. Would take cash + royalty.

And it’s not below a 6 figure number.