Knowledge from our cybersecurity and risk management experts

What separates top MSSPs from the rest

Written by Aaron R. Warner | Aug 26, 2026, 5:33:07 PM
 
  Before I was a lowly CEO, 22 of my 34 years in tech were spent as a customer of cybersecurity services, and the lack of capable MSSPs played a major role in my decision to start ProCircular. It's a topic near and dear to my heart: most cybersecurity firms or MSSPs leave clients wanting, and frequently, CISO teams end up training their cyber vendors. Incredibly frustrating. 
 
The line is action versus alerting. Nobody wants a 2 am call telling them something bad has already happened — they want it handled. The providers pulling ahead have earned real authority to isolate a host, kill a session, roll back a change, without a ticket bouncing around for approvals. That's the easy half of the answer, and it's true. The harder question is what earns a provider that authority in the first place.

I think it comes down to whose judgment actually reaches the client.

Every MSSP can buy the same tooling (most of it is open source or a line item). What can't be bought is knowing which of four hundred findings matters to a rural hospital versus a community bank versus a discrete manufacturer. In most firms, judgment lives in the heads of a handful of senior people who are booked solid, and whoever draws the good analyst that week gets the good answer. The providers who pull ahead are the ones who write that judgment down and encode it so it reaches every client at once. That's the opposite of replacing people — it's the only way a small expert team covers a client base that keeps growing.

That's what we've been building. Ten years and thousands of offensive engagements are the asset, not the scanner. Our continuous exposure platform orchestrates the tooling and validates its findings rather than handing over a list. We're now layering agents on top of it — one that configures the scan going in, one that writes the analysis coming out. The next stage is the part that matters for trust: graduated autonomy and a decision audit trail. The system takes on more over time, and every call it makes stays reviewable afterward. That's the precondition for the authority I opened with. Clients hand over the keys when they can see what you did with them.

Second, AI only works if the fundamentals underneath it are solid. If identity and access are a mess, AI moves faster on a broken foundation and compromises someone more quickly. Clean identity, verified access, documented data, then automation on top. The same goes for shadow AI, which is already in your clients' environments through vendor features enabled by default and tools employees have installed on their own. That belongs on the watch list next to malware and phishing, not on a roadmap.

Third, and almost nobody talks about this one. The industry treats AI as a SOC question, and the SOC is maybe a third of what a security company actually is. The engineers get the best gear - they always have. Meanwhile, project management, finance, contracts, and the front office are running the same tooling they had ten years ago and losing hours every week to questions with known answers. Where's the current version of this? What did we quote this client last year? How do I do this? That's the real tax on a professional services firm, and it lands hardest on the people who never get budgeted for.

So we went at it from the other end. Everyone here has a seat, not just technical staff. We connected the assistant to our systems of record so that product, customer, price, and risk are things anyone can ask about and get a straight answer to. We built shared internal tools on top of it — one that turns plain text into a finished branded deliverable, one that turns a rough draft into a review-ready blog post. We wrote the policy first, including a three-tier framework for client data, so that "can I use this here" is documented rather than left to folklore. And we're protecting time to learn it because you can't ask people to adopt a new way of working on the margins of a fully booked calendar. The goal fits in one line: everyone answers their own questions.

There's a client-facing reason to care about that. A provider that has actually run this transition internally can walk a client through theirs. The ones selling AI governance without having governed their own use of it get found out in the first workshop.
Fourth is about who you're talking to inside the client. We scored 33 sub-industries against 1,580 of our own deals, and the finding that changed how I think about this is that we reliably reach the operator layer and reliably miss the governance and financial layer, the people who authorize and expand budgets. Relationship and reputation win renewals and expansions. They do not win up-market accounts. Breaking into larger ones means leading with risk quantification, board-ready reporting, and financial resilience language. The biggest unlock available to most MSSPs right now costs nothing to fix.

Fifth, the market is changing shape above us and below us at the same time. Federal cyber support is shrinking — CISA is smaller, the Cyber Safety Review Board has been dissolved, and MS-ISAC has moved to a paid membership model. Private firms are now on the front lines, particularly for small- and mid-market organizations that were never going to buy premium threat intel on their own. Meanwhile, CrowdStrike, Microsoft, and Palo Alto are selling managed detection directly and doing it well, which squeezes the middle. That forces a split: get big enough to compete on scale and price, or go narrow and deep into a vertical where real expertise beats a generalist. The providers stuck in the generic middle are the ones I'd worry about.

Going deep has a second benefit people miss. It lets you sell to groups rather than to the company — associations, member networks, and insurance brokers. One conversation, many clients, everybody benchmarked against their peers. Nobody wants to be in the bottom quartile of their OWN association. And you cover the rest of what a client needs by referring the work out rather than hiring for it.

Operationally, many providers are still running a pile of disconnected tools bolted together over the years rather than a single system, and that's expensive and slow. In the long term, you either own a truly unified platform or commit to a small number of deeply integrated tools. Staying vendor-agnostic for every prospect is a harder sell each year.

The last one is trust, which is where it all ends up. As detection and response commoditize, the differentiator moves up the stack: honest incident reporting, explaining risk to a board rather than just a SOC analyst, and security that scales with a client's growth rather than feeling like a tax on it. We're pursuing SOC 2 ourselves, which mostly means living under the controls we sell. And the internal work matters more than it might seem — a firm that has taken the friction out of its operations has more room to invest in client relationships. That's the fit that keeps a client for ten years instead of two.