Pressure mounts on MSPs as enterprises flock to managed cybersecurity services
Expected to handle security for clients as well as themselves, MSPs feel they're battling on the front line
Stay up to date with the latest Channel industry news and analysis with our twice-weekly newsletter
You are now subscribed
Your newsletter sign-up was successful
Organizations are relying more than ever on managed service providers (MSPs) for security as cyber risks skyrocket, and many are feeling the pressure.
More than half (58%) of MSP leaders believe customers are at more risk today than this time last year, and 84% said that customers now expect them to manage either their cybersecurity infrastructure or their cybersecurity and IT estate combined.
This marks a significant increase from last year, when the figure stood at just 65%.
30% off Keeper Security's Business Starter and Business plans
Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?
More than three-quarters (77%) of MSP leaders told CyberSmart researchers that they're experiencing increased scrutiny of their own businesses’ security capabilities over the past 12 months - meaning that MSPs need to choose their cybersecurity partners carefully.
“In light of the recent uptick of cyber incidents targeting MSPs, it is unsurprising that customers are scrutinizing MSPs more,” said Jamie Akhtar, CEO and Co-Founder of CyberSmart.
“This means that it’s critical for MSPs to work with cybersecurity partners that are able to provide a high level of confidence and security for both their own and their customers’ cybersecurity to align with increasingly stringent expectations and rising threats.”
Just over eight-in-ten MSPs have increased their spending on specialist cybersecurity hires, researchers found, while 78% have upped spending on their security capabilities.
Stay up to date with the latest Channel industry news and analysis with our twice-weekly newsletter
Similarly, six-in-ten have invested in specialist regulatory hires while 64% have increased spending on regulatory compliance capabilities.
AI tops the list of worries for MSPs
The biggest security worry is AI, CyberSmart found, which is now the main headache for 38% of MSPs. Ransomware or malware topped the list for the same number.
Meanwhile, 35% were most concerned about insider threats and 32% flagged concerns over unpatched vulnerabilities.
This is a big change from last year, when malware and ransomware were the top worry for 55%, and inflation and spiraling costs for 43%.
However, the study also indicated that MSP customers may be underestimating the threat of supply chain attacks, which are now viewed as a significant risk by just one-in-five.
Over the last year, there have been a number of high-profile breaches of MSPs, including the Advanced Computer Software Group, fined £3 million by the UK's Information Commissioner's Office (ICO) over security failings that led to a ransomware attack on the NHS.
More recently, the DragonForce ransomware gang breached an MSP’s remote monitoring and management (RMM) tool in order to carry out a supply chain attack.
Of the 900 MSP leaders surveyed by CyberSmart, 69% reported being breached at least twice in the last 12 months - slightly up on last year - while 47% said they'd had three or more breaches in the last year.
"As trusted partners to millions of businesses across the globe, MSPs typically have access to clients’ infrastructure and inner workings," the researchers warned. "This renders them a highly lucrative target, whether for their own data or their clients."
MORE FROM CHANNELPRO
- ManageEngine debuts new MSP platform to streamline IT operations
- SonicWall CEO Bob VanKirk hails ‘pivotal moment’ as firm unveils new MSP cyber solutions
- MSP security confidence remains high despite rising breaches, research finds
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
Ransomware gangs are sharing virtual machines to wage cyber attacks on the cheapNews Thousands of attacker servers all had the same autogenerated Windows hostnames, according to Sophos
-
SME hybrid working requires a rethink when it comes to network designIndustry Insights SMEs have embraced hybrid working but their networks lag behind
-
Redefining resilience: Why MSP security must evolve to stay aheadIndustry Insights Basic endpoint protection is no more, but that leads to many opportunities for MSPs...
-
Ransomware is on the rise. AgainIndustry Insights Ransomware resurges with AI-driven sophistication, challenging defenders and creating opportunities for MSPs
-
Poised for the future: Key cybersecurity growth opportunities for MSPsIndustry Insights There are myriad opportunities on the horizon for partners who can tap into customer needs
-
1,800 MSPs impacted in Pax8 data leak after company shared partner information via emailNews More than a thousand MSPs have been alerted that competitors may now have access to sensitive business data
-
The changing role of the MSP: What does this mean for security?Industry Insights Smaller businesses are more reliant on MSP support, but this also puts providers under increased scrutiny...
-
How to MFA everywhereIndustry Insights Identity online is not who you are; it is what the system accepts as proof of you, and that gap is exactly what the attackers take advantage of
-
How the channel weakened ransomware’s gripIndustry Insights What tools and techniques are empowering businesses to say no to ransomware demands?
-
NinjaOne expands availability on CrowdStrike MarketplaceNews CrowdStrike Falcon customers now have simplified access to NinjaOne’s automated endpoint management capabilities

