The Business of Cyber Security

Managed Security Service Providers (MSSP)

An MSSP operates security on a customer's behalf under recurring, multi-year contracts. The market is fragmented, recurring-revenue, and labor-heavy, and scale is typically assembled by acquisition rather than built. LevelBlue — the carve-out of AT&T's cybersecurity unit, backed by WillJam Ventures — illustrates the pattern: it agreed (Jul 1, 2025) and then closed (Aug 19, 2025) its acquisition of Trustwave, describing the result as "the world's largest pure-play MSSP." It then continued acquiring — Aon's Stroz Friedberg incident-response and IP-litigation practices, and in Jan 2026 the managed-services business (MDR/XDR/WAF) of Alert Logic from Fortra. The strategic prize is being the platform large enough that mid-market customers and channel partners default to it. There are an estimated 40,000–45,000 MSSPs in the US alone, ranging from roll-up fuel to roll-up platforms.

What an MSSP is, and how it differs from MDR

An MSSP operates security on the customer's behalf: it manages the security devices and tooling (firewalls, SIEM, endpoint, email gateways, IAM), monitors the alerts those tools produce, runs compliance reporting, and — in the classic model — hands the customer a ticket to act on. The heritage is telco and device-management: the first MSSPs were carriers (AT&T, BT, Verizon, NTT, Orange) selling "we'll watch your firewall" alongside the network circuit. The defining word is co-managed: the customer keeps ownership and accountability; the MSSP supplies the round-the-clock eyes, the tooling expertise, and the headcount the customer can't hire.

The distinction from MDR (04b) matters because the two are frequently conflated and carry very different economics and multiples:

MSSP (manage) MDR (detect & respond)
What you buy Operation of your security devices + monitoring + alerting An outcome: 24/7 detection and active response, on the provider's platform
Who responds Largely you (MSSP alerts; co-managed) The provider (contains/responds on your behalf)
Tooling Customer's heterogeneous stack ("bring your own SIEM") Provider's own platform + telemetry
Scope Broad: device mgmt, compliance, SIEM, IAM, network Narrow + deep: detection and response
Heritage Telco / device management (1990s–2000s) Endpoint/SaaS-native (2015 onward)
Gross margin Lower (~45–60%) — labor- and tooling-heavy Higher (~65–75%) — platform leverage on labor
Typical multiple EBITDA multiple (services) Higher — blends toward software when platform-led

MDR is the higher-margin, faster-growing slice that grew up inside the MSSP category and is now eating it from above, while the agentic SOC (04c) automates the labor underneath both. An MSSP that does not move up into outcome-based MDR and does not automate its L1 triage is caught in a margin vice, which is what makes sub-scale MSSPs frequent sellers.

The named-player map

Scaled pure-play MSSPs (the consolidators). LevelBlue (AT&T Cybersecurity carve-out + Trustwave + Alert Logic managed services + Stroz Friedberg — the self-declared largest pure-play MSSP); Optiv (KKR-backed, services + reseller hybrid); GuidePoint Security; Kudelski Security; Nuspire; Cybereason (pivoted toward MDR). Secureworks — the long-time pure-play leader (Dell heritage, Taegis platform) — was acquired by Sophos (closed Feb 2025) and folded into Sophos's managed services, removing the largest independent from the board.

Telco / carrier MSSPs. Verizon, BT, NTT Security, Orange Cyberdefense, Telefónica Tech, Telstra — distribution-rich, often sub-scale in pure security margin, periodic carve-out candidates (LevelBlue is the AT&T carve-out).

GSI / consulting-led MSSPs. Accenture Security, IBM (X-Force + managed), Deloitte, Wipro, Infosys, TCS, HCLTech, Atos/Eviden, DXC, Capgemini — they wrap managed security around large transformation contracts; high revenue, structurally lower security-specific margin, and now exposed to AI compressing billable hours (04c).

The long tail (roll-up fuel). Thousands of regional, owner-operated MSSPs at $5–50M revenue, frequently serving a vertical (healthcare, local government, manufacturing) or geography. This is the supply side of the roll-up — sticky local relationships, recurring contracts, but sub-scale on tooling spend and unable to fund an AI-SOC build. They sell because they must.

How an MSSP makes money and where margin leaks

Revenue is recurring: multi-year contracts priced per device, per endpoint/seat, per GB of log ingested, or per "service tier," plus onboarding and professional-services fees. The economics are services economics, not software economics: the cost of goods is analyst and engineer labor plus the underlying tooling licenses (often a SIEM the MSSP pays for per-GB and marks up). That structure caps gross margin in the ~45–60% band and ties cost growth to headcount growth — the "labor-arbitrage treadmill." Three forces leak margin: (1) the SIEM "per-GB tax" the MSSP pays upstream and cannot fully pass through; (2) analyst churn in a chronic talent shortage; and (3) alert volume rising faster than the team. The response — and the reason the agentic SOC is relevant here — is to convert variable analyst cost into fixed software cost, which is what re-rates a services multiple toward a platform multiple.

The roll-up math (why PE targets MSSPs)

MSSP buy-and-build: the multiple-arbitrage engine 10× 14× 18× EV/EBITDA 8–10× sub-scale tuck-in MSSP + integrate cross-sell MDR, automate L1 14–18×+ scaled platform (or strategic exit)
Illustrative (not a quote of any single transaction): the buy-and-build spread between sub-scale acquisition multiples (~8–10× EBITDA) and scaled-platform exit multiples (~14–18×+, or a strategic premium). Margin expansion from cross-selling MDR and automating L1 triage is what closes the gap. Sources: LevelBlue–Trustwave (closed Aug 19, 2025); MSSP Alert — consolidation trends.

The roll-up works because of five structural facts: fragmentation (tens of thousands of owner-operated targets); recurring revenue (MSSP contracts are sticky and renew, so acquired revenue persists); multiple arbitrage (buy at single-digit-to-low-teens EBITDA multiples, exit a scaled platform higher, or to a strategic at a premium); cross-sell (bolt MDR, IR, and offensive services onto a managed base, or vice versa); and scarcity of scaled assets (very few pure-plays above ~$100M revenue, so the platforms that do reach scale command premiums — which is the LevelBlue play). The same global managed-security market is forecast to keep compounding double digits (one industry estimate: ~14% growth toward ~$106B in 2026, a forecast), so the acquired revenue grows organically underneath the arbitrage.

The MSP as the attack surface

The channel's commercial advantage — one provider administering many client tenants — is also its security liability. A single compromised MSP yields access to its entire downstream client base, which makes the provider a higher-value target than any of the businesses it serves and turns the MSP's own administrative tooling into the primary attack path. Telemetry from MSP-managed SMB environments over the 180 days from September 2025 through February 2026, drawn from Microsoft 365 and Google Workspace tenants across North America, EMEA and APAC, gives the pattern empirical shape (Guardz, The 2026 State of MSP Threat Report).

The headline shift is from breaking in to logging in. Malware detections fell 55% over a 50-day window while ransomware behavioural detections rose 190%, consistent with attacker tooling moving away from deployed malware toward living-off-the-land techniques that use legitimate administrative software. Across a 180-day classification set, malware still accounted for 66.3% of threats by volume but ransomware — 4.7% of volume — carried the disproportionate impact, peaking at 8.2% in December 2025, roughly double the period average, matching the known pattern of targeting organisations during holiday staffing shortages.

Identity is where the compromise actually happens. Roughly 31% of users carry a compromised password in any given month; 89% of monitored SMBs have at least one user with confirmed credential compromise at any point in time; and more than 14,000 unique password-spray source IPs per month each targeted ten or more accounts. Session hijacking — stealing session cookies or tokens to resume an authenticated session without credentials or MFA — grew about 23% over the observation window, the fastest-growing identity attack category, while the affected user population stayed near 20,000 accounts, indicating intensification against a stable target set rather than broader targeting. OAuth abuse is the persistence mechanism: consent events rose 45% between October and January and a further 24% from January to February, with Google Workspace OAuth abuse spiking over 2,000% across the period.

Two findings bear directly on the channel's structure. Non-human identities outnumber human users by roughly 25:1 in monitored cloud tenants — service principals, managed identities, OAuth applications and guest accounts that authenticate continuously through APIs, frequently hold elevated privilege, rarely have an owner, and do not trigger user-based monitoring. And the RMM tool is now an impersonation target: spoofed agent installers and remote-access abuse were observed directly, the mechanism by which a single provider compromise propagates downstream.

The commercial reading is that the MSP channel's security requirements are diverging from the SMB's. An MSP must now defend its own administrative plane — RMM integrity, technician identity, tenant isolation, non-human identity governance — as a separate discipline from the security it sells to clients. That is a capability most sub-scale providers do not have and cannot build, and it is a live consolidation driver: it raises the floor on what it costs to operate a credible MSP, pushes providers toward platforms that offer multi-tenant identity monitoring, and gives scaled acquirers a concrete integration thesis beyond headcount. It also sharpens a diligence question for any MSP or MSP-focused vendor transaction — whether the target secures its own control plane, and whether a prior provider-level compromise sits anywhere in its history. See VAR/SI & MSP→MSSP, Threat Economy and Buyer Tiers.

The bear case

The bull story — fragmentation + recurring revenue + multiple arbitrage = an inexhaustible roll-up — has three counterweights. First, services do not re-rate just because they got bigger. Bolting twenty sub-scale MSSPs together can produce a large low-margin business with integration debt (three SIEMs, four ticketing systems, incompatible SOCs) rather than a platform; the multiple expansion is earned by margin and integration, not by revenue scale alone, and many roll-ups stall at the integration step. Second, the agentic SOC cuts both ways (04c): the same automation that can re-rate a forward-leaning MSSP's margin also lets a software vendor (CrowdStrike, Microsoft, Zscaler) deliver "managed" outcomes with far less human labor — compressing the labor-arbitrage spread the MSSP model rents. Third, the customer may disintermediate the MSSP entirely: if the product platform ships a credible built-in managed tier (Falcon Complete, Defender Experts, Cortex), the mid-market buyer can get "managed" from the vendor it already pays, and the independent MSSP's reason to exist thins to compliance paperwork and local support. Falsifiable test: whether scaled pure-play MSSP platforms expand gross margin toward the high-50s/60s as they integrate and automate (thesis holds) or whether margins stay stuck in the 40s–low-50s while the product platforms' managed tiers take mid-market share (thesis weakens, and sub-scale MSSPs are better sold into a strategic before the window closes).

Cross-references: Service Providers, MDR, The Agentic SOC, Channel & Distribution, Private Equity, Deals & Comps, Operator Economics.

Adjacent market: the RMM/PSA platforms that form the MSP's operating stack — and its acquirer set — are mapped on IT Management, RMM & the MSP Stack.


Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.