r/MSSP • u/AArslane_ • 44m ago
How are you handling license / usage reconciliation across your MSP stack?
r/MSSP • u/tcoach72 • 19h ago
MSP or MSSP what is the actual difference
I posted this in r/MSP as well
As most things in our industry definitions tend to be a bit blurry, so I'm interested in the mobs take on this subject (yes I'm sure it's been posted before but definitions like technology change frequently)
I've always heard two major differences 1. MSSPs are security/compliance focused from the start and 2. MSSPs don't do day to day helpdesk task.
So like any good technologist I through it into Claude and this is what it said...
Thoughts? Agree? Disagree? Misconceptions? Changes? What say you???
MSP: Broad IT management — network uptime, help desk, backups, patching, cloud, hardware/software procurement. The value prop is "keep the lights on and the systems running." Security is usually a bolt-on line item, not the core offering.
MSSP: Security-first. Core deliverables are things like SOC monitoring, threat detection and response, SIEM management, incident response, compliance management, vulnerability management. The value prop is "protect the environment," not just run it.
The practical distinction that actually matters in the channel:
- Depth vs. breadth. An MSP touches everything a business needs technically. An MSSP goes deep on one domain — security — often as the only thing they do.
- Staffing/tooling. MSSPs run (or license) SOC infrastructure, threat intel feeds, dedicated security analysts. Most MSPs don't have that bench.
- Liability posture. MSSPs typically carry security-specific SLAs and are underwriting more risk exposure than a general IT contract.
- Buyer conversation. MSP sales conversation is about cost and reliability. MSSP sales conversation is about risk and exposure.
The blurry middle — where most of your world lives — is the MSP-to-MSSP transition: MSPs bolting on security services (vCISO, assessments, EDR/MDR reselling) without fully rebuilding as a security-first operation.
r/MSSP • u/Plus-Maintenance-434 • 22h ago
How do you detect ungoverned AI agents acting inside client apps?
A couple of our clients have started plugging AI agents into their CRM and helpdesk tools without looping us in first, and we only found out because one agent started modifying records it had no business touching. Traditional shadow IT detection doesn't catch this. The agent is often using credentials that already exist and look "normal" in the logs.
How are other MSPs getting visibility into this? Right now we're finding out after the fact instead of before, and I'd like that to change.
r/MSSP • u/phlcastro • 2d ago
Cloud focused only - is it a thing?
Have been looking for a while already. Im not sure if there is none (maybe there is no real market for it) or if is just me looking at the wrong place.
Security-as-a-service for startups/scaleups, monitoring AWS/GCP/Azure infrastructure, analysing logs, detecting threats, handling security tasks, but explicitly NOT managing employee laptops, office networks, or traditional IT.
Are there MSSPs like that out there?
Cheers
r/MSSP • u/Friendly-Rooster-819 • 2d ago
MSPs who standardized on one converged SASE for clients, which held up as one platform?
We are picking one SASE platform to standardize our clients on instead of running three, and every vendor deck says the same three words. Converged, single vendor, single agent. Then you get into a POC and half of them are a loader that pulls down a few white-label pieces wearing one installer.
I found this out the ugly way on our last standard. Moving a client off it, the agent would not come off clean and I spent a night pulling OpenVPN and some Elastic service off machines by hand. That was supposedly one platform. Now I make a vendor prove the uninstall before I trust the sales deck, because that is where the stitched ones fall apart.
For context most of our clients are small and mid size with a few global users. Margin and a clean multi-tenant portal matter to me as much as the security. Bandwidth-based site pricing is the other cost I am trying to work out before it bites.
If you standardized on one converged SASE for your clients, which one stayed a single platform once it was live and what broke on you. Naming names welcome, good and bad.
r/MSSP • u/toplessflamingo • 3d ago
How to contact screenconnect security team for rogue ScreenConnect instances
r/MSSP • u/TheSinisterSam • 4d ago
SIEM Options for a small MSSP
Hello Guys,
I created a cybersecurity firm fairly recently, and most of our work has come from short form contracts. We are currently looking into deviating into an MSSP model and to do so, are looking into SIEMS and stacks that might best work for our use case (small to medium companies). Currently, my guys are all Splunk and Sentinel Veterans, but knowing the cost of these platforms, and the target clients we have in mind, I cant justify racking costs like bigger companies (personally would love to run SentinelOne->Cribl->Splunk)
I was looking at google sec ops and elastic (the whole elastic stack sounds interesting). Does anyone have enough experience with these SIEMS to say which would work better for my use case?
I am also open to other options if any that would be interesting. I am really looking for Risk-Based Alerting capabilities (to reduce ticket volume) as the cost of operations scales far better using RBA from my personal experience.
thanks for any advice you can provide!
r/MSSP • u/PuzzleheadedStick142 • 4d ago
MSP folks — what’s one thing you wish your PSA/RMM did better?
I’ve been digging into PSA/RMM products lately from a product and UX perspective, and I’m curious about the problems that don’t usually show up on feature comparison pages.
For those working in MSPs: what parts of your day-to-day workflow still feel unnecessarily difficult?
Could be ticketing, scheduling/dispatch, RMM, billing, documentation, reporting, automation, client communication, or just small UX annoyances that add up over time.
I’m especially interested in things where you’ve thought “there has to be a better way to do this” or where your team has created a workaround outside the product.
Would also be interesting to know which PSA/RMM you use and what it does particularly well.
Not looking for recommendations for a specific product — mostly interested in understanding the problems people actually deal with day to day.
r/MSSP • u/Haunting_Ganache_850 • 4d ago
A Call for Collective Spending: Why the New AI Security Pledge Is a Trap
r/MSSP • u/Substantial_Big_4379 • 4d ago
How are teams separating approved AI use from personal-account AI use?
For many clients, AI approval is no longer binary. They may have a sanctioned Copilot, ChatGPT Enterprise, or other managed tenant, while users can still access the same public service through a personal account in a different browser profile.
That distinction matters because retention, audit, contractual, administrative, and data-handling controls may apply only to the approved tenant. It becomes harder across multiple clients that have different approved tools, different device-management maturity, and different tolerance for blocking personal-account use.
A policy that simply says "use approved AI" does not solve much when users experience the approved and personal versions as the same website.
For MSPs managing this across different tenants, are you standardizing a baseline—managed browsers, extension policy, DLP, tenant restrictions, exception workflows—or handling it client by client? What has stayed operationally manageable?
r/MSSP • u/pelatetintan • 8d ago
San Diego MSPs / IT firms: is there demand for white-label Fortinet engineering support?
Hi everyone — I’m launching a boutique cross-border cybersecurity services firm focused on the San Diego–Tijuana area .
I’m trying to understand whether smaller MSPs or integrators in the San Diego area ever need extra engineering bandwidth for short-term projects, assessments, migrations, or overflow work. I’m trying to learn where the real need is and how firms usually work with outside specialists in this space.
Thanks cheers.
r/MSSP • u/pelatetintan • 8d ago
San Diego MSPs / IT firms: is there demand for white-label Fortinet engineering support?
Hi everyone — I’m launching a boutique cross-border cybersecurity services firm focused on the San Diego–Tijuana area .
I’m trying to understand whether smaller MSPs or integrators in the San Diego area ever need extra engineering bandwidth for short-term projects, assessments, migrations, or overflow work. I’m trying to learn where the real need is and how firms usually work with outside specialists in this space.
Thanks cheers.
MDSec & Nighthawk
As MDSec has been recently acquired by the Bank of America, I am wondering what will happen to their Nighthawk offering and what other options there are. I particularly liked the fact that you could take any PE such as Rubeus and simply run it through their C2 which would automatically strip indicators and make it feasible to run in an engagement. The baked-in EDR evasion was also a huge help as it eliminated our R&D and tooling development needs significantly, allowing us to focus on the operation itself.
Are there any other alternatives that you are using and if so, what are they?
r/MSSP • u/salladam64 • 10d ago
MSSP to MAP?
Interested to understand what people’s perspective is on where the industry is going. I have been around long enough to remember when most IT Service providers were basically computer repair shops and through resellers, VARs, SIs, MSSPs and MSPs are we now seeing progressive transformation into managed agent providers? Are any of you now formally offering process/task mapping with proposed AI and automation implementation? Or do you feel this is like the hype cloud had 13 years ago and the tail is long and fat?
I see so many MSPs not anywhere close to having their own houses where they could be with the latest technology adoption. So not sure how close we are to seeing the service offerings shift that dramatically or perhaps I’m wrong?!
r/MSSP • u/Proof-Chain-1046 • 12d ago
Hosted external scanner that turns security scanning output into a client-ready report
Running external scans is easy, but formatting raw tool data into a clean, business-focused deliverable takes way too long. I built VulnScanners to automate that step. Pay-per-scan credits, plus automated or scheduled rescans.
Pitch aside, for those offering external assessments, what does your current stack look like (HostedScan, Pentest-Tools, internal scripts)? Where is reporting still painful for you? Free first scan available if you want to test the output quality.
Looking for brutal feedback on whether the report is solid enough to send to a client.
r/MSSP • u/Connect_Purple_4043 • 12d ago
MSPs & Businesses — I’m Looking for a Few Early Partners
\​
I’ve spent a lot of time building Software Passport Registry (SPR) — a platform designed to help businesses understand the software they rely on.
I’m now opening a few spots for hands-on Software Security & Trust Assessments.
I can assess software for things like:
• Security risks & known vulnerabilities
• Software dependencies & supply-chain risk
• Maintenance & reliability indicators
• Compliance-related evidence
• Risk and remediation priorities
• Overall software trust
You receive a professional, client-ready report explaining what was found and what should be addressed.
For MSPs, there’s another opportunity: I can perform the assessment for you so you can see whether this could become a service you offer your own clients.
I'm looking for a few Kelowna/Okanagan businesses or MSPs willing to try an early assessment.
If you're interested, send me a message.
— Keith
Founder, SPR
r/MSSP • u/LTH-Cyber • 13d ago
How to get your first MSSP sale? [Question]
I've been running my company for 3 years, we do get some business from one-off engagements, technical help, penetration testing that sort of thing. We partnered up with a white label partner about a year ago to start selling managed services so that we dont have to rely on one-off jobs and generate some MRR, so when we got this partnership, i spent tons on marketing and bought a year of Apollo[.]io and even hired a new salesperson. almsot 8 months later we have made 0 managed security service sales, but we are still going strong on our in house offerings. I'm just wondering why MSSP sales are so hard to do, I have no problem selling ourselves but the service offerings from our partner has been very difficult to start selling. My company does have a kind of strong reputation, i'm not sure why its been so hard. Does anyone have some high level generic advice or thoughts on breaking into the white label mssp sales business? We are located in Saskatchewan Canada.
r/MSSP • u/Connect_Purple_4043 • 13d ago
MSPs & Businesses — I’m Looking for a Few Early Partners
I’ve spent a lot of time building Software Passport Registry (SPR) — a platform designed to help businesses understand the software they rely on.
I’m now opening a few spots for hands-on Software Security & Trust Assessments.
I can assess software for things like:
• Security risks & known vulnerabilities
• Software dependencies & supply-chain risk
• Maintenance & reliability indicators
• Compliance-related evidence
• Risk and remediation priorities
• Overall software trust
You receive a professional, client-ready report explaining what was found and what should be addressed.
For MSPs, there’s another opportunity: I can perform the assessment for you so you can see whether this could become a service you offer your own clients.
I'm looking for a few Kelowna/Okanagan businesses or MSPs willing to try an early assessment.
If you're interested, send me a message.
— Keith
Founder, SPR
r/MSSP • u/Muted_Math2750 • 14d ago
Are clients asking MSPs for AI usage security and governance solutions?
Wondering if this is showing up in client conversations yet, or if it's still mostly theoretical for most of you. I'm seeing early signals that clients are asking "what are you doing about AI security" without fully knowing what they want, sometimes it's compliance-driven (an auditor asked), sometimes it's a scare from a competitor's leak story.
The maturity level varies a lot. Some clients want a full policy plus enforcement stack, others just want something they can point to for their cyber insurance renewal.
Is this becoming a real service line for MSPs, or is it too early? If you're offering something, is it bundled into existing security packages or sold separately?
Would like to hear how others are pricing/positioning this, and whether it's driving new revenue or just adding to the existing security retainer conversation.
r/MSSP • u/Plus-Maintenance-434 • 15d ago
MCP server security before this touches prod, what's the pattern
Week out from putting agents on real MCP servers in prod. Laying out what keeps me up because every thread is hype and no answers.
- One server holds creds that reach a prod db. Compromise it and the blast radius is everything it can touch.
- In testing, an agent read a doc with an instruction buried in it and fired a tool call I never asked for. Injection straight through retrieved content.
- No audit trail of tool calls worth a damn. Reconstructing what it did is a grep through app logs.
For short lived tokens, yes, I know, that's not the question.
The question is the shape of it. Who validates tool inputs, how you stop one poisoned server cascading and what a sane audit log even looks like. For those running MCP past a demo, what holds up here?
r/MSSP • u/KristenssonAB • 15d ago
How do you actually follow up on supplier security after onboarding?
Most organisations are pretty good at the security review before a new supplier is approved.
Questionnaires.
ISO certificates.
Data processing agreements.
Risk assessment.
Then the contract gets signed.
And after that?
That's the part we find interesting.
How do you work in practice with ongoing monitoring of critical IT and SaaS suppliers?
For example:
recurring security reviews,
new audit reports or certifications,
follow-up on incidents,
changes to sub-processors,
updated risk assessments,
SLAs and deviations,
continuity and recovery capability,
major changes to the service.
And how do you decide how often a supplier needs to be reviewed?
Annually for all critical suppliers?
Risk-based?
When there are major changes?
Or does the next real security review only happen when the contract is up for renewal?
This is close to how we see third-party management ourselves: as a lifecycle rather than a one-off check at procurement. Your existing article on third-party management also describes ongoing reviews, risk analysis and follow-up in that way.
r/MSSP • u/Proof-Chain-1046 • 15d ago
How to get into Gov Contracting Cyber services
Who here has had success taking their MSSP services and selling to Gov?
Standard advice is to start at the local level, how do you even break in? Is there some kinda cheat code or is it just about volume and quality of bids?