Service Providers
Cybersecurity services are highly fragmented, recurring-revenue, people-plus-platform businesses, typically acquired at EBITDA multiples well below product-vendor ARR multiples. There are an estimated 40,000–45,000 MSSPs in the US alone.
A defining force across the categories below is "software eats services." AI is converting the variable human labor these businesses sell into fixed software cost — re-rating margins up for those who own a moat, compressing prices for those who don't, and moving the boundary between "a service" and "a product feature." Software Eats Services covers this dynamic in full; it governs which of these businesses re-rate up versus get rolled up.
Sub-page deep dives: Software Eats Services (the AI services re-rating thesis) · MSSP (the roll-up engine and multiple arbitrage) · MDR (the higher-margin managed slice — Red Canary at ~4.8× ARR) · The Agentic SOC (automation of the labor model) · Consulting & the Big Four (the billable-hour squeeze and the annuity shift) · Incident Response & DFIR (incident response captured by platforms) · Offensive Security & PTaaS (subscription-based pen-testing) · vCISO & Advisory (productizing the CISO function).
Categories
| Category | What it is | Revenue model | Consolidation |
|---|---|---|---|
| MSSP | Outsourced security operations (monitoring, device mgmt) | Recurring contracts | Highly fragmented |
| MDR | Managed detection & response (24/7 SOC, threat hunting) | Recurring, per-endpoint/seat | Mid; clear leaders emerging |
| Consulting / advisory | Strategy, architecture, vCISO, compliance | Project + retainer | Fragmented |
| Incident response (IR) | Breach response, forensics, recovery | Project + retainer | Captured by platforms |
| Pen-testing / offensive | Pen-test, red team, PTaaS | Project → subscription (PTaaS) | Productizing |
| Staffing / talent | Security talent, fractional teams | Margin on labor | Fragmented |
MDR / MSSP leaders (2025–2026)
- Arctic Wolf — Aurora open-XDR platform, 200+ integrations; 2026 Gartner Peer Insights Customers' Choice; large, late-stage private (Evolution-backed); IPO-track.
- Palo Alto (Unit 42 + Cortex) — platform + human analysis; MDR via Cortex XDR.
- Sophos — acquired Secureworks (Feb 2025), integrating Taegis XDR + Counter Threat Unit; TB-owned.
- Expel — Forrester Wave Leader, MDR Q1 2025; SaaS-style MDR.
- Red Canary — Forrester Wave Leader (→ acquired by Zscaler, 2025).
- Secureworks — Taegis platform (now within Sophos).
- CrowdStrike Falcon Complete, Rapid7 MDR, Critical Start, eSentire, Deepwatch, Huntress (SMB-focused, scaling fast).
- Cisco, Verizon, AT&T/LevelBlue (carve-out), IBM, Accenture, Deloitte, Kroll, Mandiant (Google) at the enterprise/IR end.
Consulting & IR
Big Four (Deloitte, PwC, EY, KPMG), Accenture Security, IBM X-Force, Mandiant (Google), Kroll, Booz Allen, Optiv, GuidePoint, Coalfire, Bishop Fox, NCC Group, Leviathan. Posture: the mid-market (regional cyber consultancies, $5–50M revenue) is the roll-up sweet spot. See Consulting & the Big Four (billable-hour squeeze; compliance/managed-services annuity) and Incident Response & DFIR (the breach moment, captured by platforms).
Offensive / pen-testing
- PTaaS / continuous: Pentera, Cymulate, Cobalt, Synack, HackerOne, Bugcrowd.
- Boutiques: Bishop Fox, NetSPI (Carlyle/KKR), TrustedSec, IOActive.
- Posture: subscription-izing project work; NetSPI is the platform-consolidator model. See Offensive Security & PTaaS (the project→PTaaS→AEV migration and its multiple arbitrage).
- Captive / end-user acquisition — a distinct buyer archetype. Large enterprises that heavily consume offensive-security services occasionally acquire a boutique consultancy outright to internalize the capability. Bank of America agreed to acquire MDSec Consulting (Macclesfield, England; ~65 deeply technical consultants) on Jul 30 2026 (terms undisclosed; close expected Q4 2026), building red-team and adversary-simulation capability in-house near its Chester threat-operations center. Unlike a PE roll-up or a vendor tuck-in, the buyer is the customer: the transaction removes a specialist team from the third-party market rather than consolidating it under another provider. It is a small, recurring pattern (financial institutions and defense primes are the typical acquirers) and a reminder that talent scarcity, not just revenue, can drive services M&A. See Deals.
The autonomous-SOC transition (2026)
The services side faces the same disruption as the vendor side, centered on services economics: the labor-arbitrage model is being automated.
- Market conditions. The MSSP/MDR market faces rising expectations, accelerating threats, shrinking margins, and the chronic talent shortage. The human-led "triage and ticket" model is under pressure — adversaries exfiltrate data in under ~72 minutes, faster than human reaction — and manual SOCs carry a margin-eroding "Silo Tax."
- The agentic SOC. ~39% of organizations have begun adopting agentic AI for security operations (accelerating through 2026). Autonomous platforms investigate alerts, gather forensic evidence, find root cause, and execute response with minimal human intervention — automating the very headcount that capped MSSP/MDR margins.
- Consulting under the AI axe. AI is compressing the billable-hours model that built Accenture, Deloitte, and the rest (Accenture's outlook disappointed on softening time-and-materials demand). The firms are caught selling AI transformation while AI erodes the hours they bill; even McKinsey links only ~25% of fees to outcomes. Incumbents are co-opting the disruptor (e.g., Accenture–Anthropic on AI-driven cyber ops).
- Offensive security productizing. Manual, point-in-time pen-testing is giving way to continuous, AI-driven exposure validation (Gartner: ~60% of large enterprises using continuous automated red teaming by 2026; HackerOne's Agentic PTaaS; AI-native offensive startups like Novee). Consensus is hybrid — AI scales the repetitive work; humans still do exploitation, chaining, and logic-flaw reasoning.
Automation is both a threat to labor-heavy providers and a margin expander for early adopters. A services business that converts labor cost into software-like margin via the autonomous SOC re-rates its multiple — becoming either a stronger roll-up platform or a more attractive target. The shift widens the software-vs-services valuation gap that underpins cyber buy-and-build (below).
The roll-up thesis (why services attract PE)
- Fragmentation — tens of thousands of sub-scale providers, owner-operated.
- Recurring revenue — MDR/MSSP contracts are sticky and renew.
- Multiple arbitrage — acquire at 8–12× EBITDA, integrate, re-rate toward 14×+ or platform multiples at exit.
- Cross-sell — bolt managed services onto product, or vice versa.
- Scarcity of scaled assets — few providers above $100M revenue, so scaled platforms command premiums.
The 2026 tape extends this thesis beyond MDR/MSSP into compliance and GRC services. In July 2026, Coalesce Capital — a services-focused sponsor with more than $1.8B in assets under management — made a strategic growth investment in Workstreet, a provider of AI-native cybersecurity and compliance services: governance, risk, and compliance across more than 35 frameworks (including SOC, ISO, FedRAMP, and CMMC), plus vCISO, penetration testing, vulnerability management, and privacy services, serving more than 1,000 customers. Terms were undisclosed, and the founders and management retained a significant stake. The investment reflects two forces at once: the same fragmentation and recurring-revenue logic that has drawn private equity to managed detection now draws it to compliance-as-a-service, and the "AI-native" positioning maps to the broader re-rating in which services firms adopt automation to earn software-like economics (see Software Eats Services). Sources: PR Newswire, Jul 23 2026 · FinSMEs, Jul 2026.
Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.