The Business of Cyber Security

IT Management, RMM & the MSP Stack

The software that managed service providers use to run their businesses — remote monitoring and management (RMM), professional services automation (PSA), patching, documentation, and backup — is a market of its own, distinct from security but fused to it at the SMB tier. As Buyer Tiers sets out, SMB security is bought through MSPs; the RMM/PSA stack is the console those MSPs live in, which makes it simultaneously the distribution rail for SMB security products and, as the threat data on MSSP shows, the attack surface adversaries now impersonate to reach downstream client fleets.

The market and its players

Three platforms dominate. Kaseya — owned by Insight Partners — assembled the broadest suite through serial M&A, anchored by the $6.2B acquisition of Datto in 2022 (RMM, backup and networking for MSPs), and holds roughly a quarter of the RMM market. ConnectWise — Thoma Bravo-owned since 2019 — pairs the most established PSA with RMM at a similar share. NinjaOne is the growth story: a reported $12.3B valuation on its Series F, ARR past $500M growing ~70%, and its own move into adjacent capability with the $270M Dropsuite backup acquisition (2025) (Channel Dive · funding coverage). N-able (public), Atera, Syncro, SuperOps and Halo fill the mid-tier, with Tanium and endpoint-management incumbents (Ivanti, ManageEngine) serving the enterprise side of the same discipline.

Player Owner / status The security fusion
Kaseya (+Datto) Insight Partners Bundles AV/EDR, email security, dark-web monitoring into MSP suite
ConnectWise Thoma Bravo PSA+RMM incumbent; security add-ons; heavy debt load reported (~$3.5B financing)
NinjaOne Private, $12.3B Patching-led; Dropsuite backup; positions as the modern stack
N-able / Atera / mid-tier Public / VC-backed AI-assisted RMM; consolidation candidates
Tanium / Ivanti Enterprise endpoint mgmt Converged endpoint management + security posture

The convergence mechanics

Three forces fuse this market to cybersecurity. Bundling: every major RMM now sells security — endpoint protection, email security, backup — inside the same console and invoice, because the MSP wants one pane and one bill; security vendors reach SMBs by integrating into these stacks or being acquired into them (Barracuda's MSP-led email security line, and its 2026 acquisition of Evo for MSP-focused identity, are the vendor-side mirror — 03j, 11). Patching as security: the RMM's core function — deploying software updates — is vulnerability remediation; the line between IT hygiene and exposure management (03k) blurs to nothing at this tier. The RMM as target: spoofed agent installers and remote-access abuse documented in 2026 MSP telemetry make the management plane itself the high-value intrusion path, pushing RMM vendors to build security into their own architecture and pushing MSPs toward platforms that can prove it.

The ownership pattern is notable: this adjacency is already a PE consolidation theater — Insight (Kaseya), Thoma Bravo (ConnectWise), and a heavily funded challenger (NinjaOne) — running buy-and-build math directly comparable to the cyber roll-ups on 06e.


Updated 2026-08-16 18:47 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.