<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-GB"
                       href="https://www.itpro.com/uk/feeds/tag/managed-security-service-provider"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from ITPro UK in Managed-security-service-provider ]]></title>
                <link>https://www.itpro.com/uk/tag/managed-security-service-provider</link>
        <description><![CDATA[ All the latest managed-security-service-provider content from the ITPro  UK team ]]></description>
                                    <lastBuildDate>Tue, 23 Jun 2026 07:00:00 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Why MSSPs need to focus on reducing cyber risk, not adding complexity ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/why-mssps-need-to-focus-on-reducing-cyber-risk-not-adding-complexity</link>
                                                                            <description>
                            <![CDATA[ The channel also has a role to play in helping organizations adopt AI-enabled security capabilities responsibly ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">KvFdCgZ5XRhUMDQrXGeVuT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/aXognGP4UVUiWoAxxh57qJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 23 Jun 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Martin Lethbridge ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/XM4r95nttuwGG3G7EMvBHC.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/aXognGP4UVUiWoAxxh57qJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand touching a glowing white padlock in a dark environment, to represent living off the land cyber attacks.]]></media:description>                                                            <media:text><![CDATA[A hand touching a glowing white padlock in a dark environment, to represent living off the land cyber attacks.]]></media:text>
                                <media:title type="plain"><![CDATA[A hand touching a glowing white padlock in a dark environment, to represent living off the land cyber attacks.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/aXognGP4UVUiWoAxxh57qJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cybersecurity spending is increasing, yet many organizations still experience breaches, operational disruption, and ongoing security challenges. </p><p>As businesses expand their digital environments and adopt new technologies such as AI, many are also finding that their larger security budgets are not translating into stronger protection.</p><p>For managed security service providers (MSSPs) and channel partners, this is an important opportunity. Many customers are looking for support that goes beyond simply deploying additional security products. They want a partner who can help them manage cyber risk more effectively, while also helping them operate in a complex security environment.</p><p>This shift in customer priorities is even more visible as organizations are managing increasingly fragmented IT environments. Hybrid working, cloud adoption, remote endpoints, and connected applications have all expanded attack surfaces considerably over the past few years. In addition, many businesses have accumulated multiple security tools across different parts of the organization, often from different vendors and with varying levels of integration.</p><h2 id="too-many-tools">Too many tools</h2><p>Although each tool may exist to address a specific security requirement, the overall result is difficult to manage. Security and IT teams may need to monitor numerous dashboards, respond to large volumes of alerts, and manually correlate information between systems. In some environments, this will create visibility gaps and operational inefficiencies, making it harder to respond quickly to threats.</p><p>For MSSPs, this is likely to be a key focus for customers. Many organizations are reassessing whether adding more standalone tools is the most effective way to improve resilience. And there is growing interest in approaches that simplify management, improve visibility, and support measurable risk reduction.</p><p>This is particularly relevant for mid-market organizations that may not have large in-house security teams. Many smaller IT departments are being asked to manage increasingly sophisticated environments, while also responding to complex threats, regulatory requirements, and user demands. A channel partner that can reduce this operational pressure while also improving security outcomes will be able to demonstrate and deliver greater long-term value to customers.</p><p>Unsurprisingly, AI is also influencing this. Businesses are adopting AI-enabled technologies across their operations, while cybersecurity vendors are increasingly integrating AI into security tools and platforms. Cybercriminals are also using automation and AI-supported techniques to increase the scale and sophistication of phishing campaigns, social engineering, and vulnerability exploitation.</p><h2 id="keeping-safe-and-secure-but-without-spending-more">Keeping safe and secure, but without spending more</h2><p>Organizations are faced with growing pressure to improve detection and response capabilities without significantly increasing operational overhead.</p><p>For MSSPs, this creates the opportunity to help customers manage security more practically and sustainably. Rather than focusing solely on deploying additional technologies, many are positioning themselves around outcomes such as improved visibility, faster response times, and simplified security operations.</p><p>Integrated security platforms are becoming increasingly relevant in this context. Platforms that bring together endpoint protection, identity security, network monitoring, and threat detection capabilities help organizations reduce fragmentation and improve operational efficiency. By consolidating visibility and automating some routine tasks, businesses may be able to reduce alert fatigue and simplify day-to-day security management.</p><p>Automation is also playing a growing role in helping organizations manage their rising security demands. Many MSSPs are using automation to support threat detection, incident response, patch management, and policy enforcement. For customers with limited internal resources, this helps to improve consistency and reduce the burden on internal IT teams.</p><h2 id="technology-alone-is-not-the-solution">Technology alone is not the solution</h2><p>But technology on its own is unlikely to solve every security challenge. Many organizations still require support with prioritisation, governance, and practical risk management. This is where MSSPs can differentiate themselves from those providers who are focused primarily on product deployment.</p><p>Customers are increasingly evaluating cybersecurity investments based on operational effectiveness rather than simply the number of tools deployed. In some cases, this may involve consolidating overlapping products, improving configuration management, or streamlining response processes rather than introducing additional technologies.</p><p>This approach also aligns with the growing industry focus on cyber resilience. Many organizations recognize that security strategies should include detection, response, and recovery capabilities, alongside prevention. MSSPs that can help customers improve resilience and reduce operational disruption will strengthen their role as long-term strategic partners.</p><p>The channel also has an important role to play in helping organizations adopt AI-enabled security capabilities responsibly. While AI may help improve efficiency and threat analysis, it can also introduce additional management challenges if implemented without proper oversight or integration. This means customers will value partners that can help them adopt new technologies in a manageable and commercially practical way.</p><p>Organizations need to balance growing cyber risks with operational and financial pressures. As a result of this, there is likely to be increasing demand for MSSPs and channel partners that can simplify cybersecurity management while supporting stronger resilience outcomes.</p><p>This is an opportunity for the channel to move conversations away from tool proliferation and towards measurable risk reduction. The conversation with customers needs to be about helping them manage complexity, improve operational visibility, and align security more closely with business priorities.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How SMBs can DIY their IT implementation and support ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/business-strategy/how-smbs-can-diy-their-it-implementation-and-support</link>
                                                                            <description>
                            <![CDATA[ For some small and medium-sized businesses, the third-party expertise and support might be out of reach. What’s the alternative? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">t5V6jG4M2XXyM3cirpAW2k</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GsDx8E9oD6ZwGHPXWmeWXC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 30 Dec 2025 08:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Business Strategy]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jonathan Weinberg ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GsDx8E9oD6ZwGHPXWmeWXC-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Business]]></media:description>                                                            <media:text><![CDATA[Business]]></media:text>
                                <media:title type="plain"><![CDATA[Business]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GsDx8E9oD6ZwGHPXWmeWXC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Many small and medium-sized businesses (SMBs) might struggle to afford third-party relationships - like those with channel partners - or have a specific need or capacity for models that see someone closely manage their technology for them.</p><p>Instead, they might want to do it themselves, creating a DIY-style initiative that builds a system with parts from many different platforms, tools, or cloud services. </p><p>Could such an approach be dangerous? Essentially, bringing with it risks to security, among other issues for internal operations such as compliance, delivery, and productivity. Or, is it entirely possible? And, if it can be achieved, how would this be done? </p><p>Eleanor Watson is a member of the IEEE, the world’s largest technical professional organization dedicated to advancing technology for the benefit of humanity. As an AI ethics engineer, she works principally as a machine intelligence researcher.</p><p>Watson is in agreement that for SMBs with limited budgets, the use of channel partners “might not be feasible”. She believes the DIY approach is sound and can work for SMBs but only “when treated as a disciplined strategy, rather than cost-cutting”.</p><p>“As a first step, businesses should map business-essential functions (finance, HR, sales, compliance) and assign clear ownership for each system’s uptime and data security,” she explains.</p><p>“Invest in architecture first: build a clean, modular stack using open standards (SSO, OAuth2, API-first systems), and document relentlessly. Begin with a manageable scope – self-hosted basics or low-code automation – while maintaining flexibility to integrate external providers later.”</p><p>That’s not to say there won’t be any challenges with such an implementation, as Watson is happy to concede. “Achieving interoperability without fragility is the primary challenge,” she warns. “Vendor APIs evolve; dependencies break. Without dedicated integration expertise, SMBs must maintain test environments and version control for configurations.”</p><p>Cybersecurity resilience is “equally demanding”, she adds, stating: “A single ransomware incident or supply-chain compromise can cripple an unsegmented network. Apply zero-trust principles – robust identity management, privilege separation, encrypted backups – as foundational defaults, not afterthoughts.”</p><h2 id="risks-vs-rewards">Risks vs rewards</h2><p>The most common types of IT channel partners are the likes of value-added resellers (VARs), systems integrators (SIs), managed service providers (MSPs), managed security service providers (MSSPs), and consultants. Vendors they use often include AWS, Google, IBM, and Microsoft, and a channel partner usually provides online training and certification to an SMB.</p><p>Ian Anderson, senior director of partner sales at Park Place Technologies, understands the “temptation” of DIY but concurs with Watson, believing the risks must be clearly identified and understood first if SMBs push ahead with this approach.</p><p>He cites how a good partner might “understand the business, environment, and resources in a way a DIY approach never can,” but does admit: “The reality is most channel partners have gaps in their service range. They can’t be experts in everything. This is why the smartest SMBs look for partners who are, in turn, supported by specialist service providers to fill those gaps – whether professional or managed services.”</p><p>However, for those who still wish to go it alone, Watson has more advice to follow. “Meaningful savings come from open-source platforms, consumption-priced cloud services, and internal automation replacing external consultancy,” she explains. “AI copilots for documentation, compliance drafting, or troubleshooting can substantially reduce administrative overheads.”</p><p>Watson also points to the issue of believing you are making savings when actually you might cost yourself more in the long run, adding: “The real economic advantage is agility: direct system control enables rapid iteration without vendor lock-in. However, cheap setups requiring costly rescue operations are common – beware of these false economies.”</p><h2 id="smart-work-vs-hard-work"> Smart work vs hard work</h2><p>The risk of a DIY approach is greater for mid-sized organizations compared to those smaller businesses, according to Matt Fox, chief operating officer at technology consultancy TXP.</p><p>“If mid-sized organizations are to avoid a piecemeal approach to IT modernization, they require a joined-up approach to technology and people,” he says. </p><p>“Mid-sized organizations can work smarter, not harder, by working with an external IT provider that has the skills and resources required to fully address their IT needs.”</p><p>Fox adds: “However, channel providers need to go beyond simply augmenting team numbers or selling products to provide a transformational service. A successful relationship with a channel partner will involve at least some element of knowledge transfer as experts share their expertise with their partner’s team. </p><p>“This ‘teacher-learner’ relationship brings value beyond a simple transaction to working with the channel, and it ought to be the gold standard when working with partners for IT implementation.”</p><p>In the real world, there are no clear rules on when to DIY, when to begin with a channel partner, or when to move from doing it yourself to getting third-party help and guidance.</p><p>But Siyar Isik, CEO of Eskritor, an AI-powered writing assistant tool, believes DIY is possible when the right guardrails are in place. “Not every small business has to lean on channel partners for IT,” he admits. </p><p>“Some can manage on their own, but only if they stay realistic about what is possible.”</p><p>Isik’s first advice would be “to start simple” with tools like Google Workspace or  Microsoft 365, which have been built with small teams in mind. </p><p>“They come with great support communities and plenty of clear documentation. That takes a lot of pressure off the team,” he says.</p><p>While it is possible to reduce overheads by cutting costs and avoiding long contracts, there are clear areas where it would be dangerous to compromise, according to Isik. </p><p>“Data protection, backups, patching, and continuity planning need to be airtight,” he insists. </p><p>“Skipping those is like skipping insurance. A DIY approach can work, but only if a business goes in with clear eyes about its limits and refuses to cut corners on the areas that matter most.”</p><h2 id="weighing-up-the-time-outlay">Weighing up the time outlay</h2><p>Watson is also concerned about other pitfalls. “Most DIY IT failures stem from underestimating complexity debt,” she explains. </p><p>“Integration across accounting, customer relationship management (CRM), and inventory systems can spiral without professional oversight. Security hardening, patch management, and compliance consume more time than expected. Staff turnover erases undocumented expertise, orphaning systems.”</p><p>And although the use of Agentic AI tools in an SMB setting might offer simplified management, these can also “amplify errors when unsupervised”, Watson warns. </p><p>“Autonomous misconfiguration – AI making confident but destructive changes without full context – is an emerging risk,” she highlights. “Governance remains essential regardless of tooling intelligence.”</p><p>There are also real benefits, however, according to Watson. These include full control over architecture, data, and priorities, plus faster iteration and innovation cycles. Deep understanding of your digital infrastructure and reduced dependency on opaque vendor ecosystems are two more.</p><p>“Properly managed, DIY IT builds organisational technological literacy – a durable competitive asset,” she adds.</p><p>At BI Worldwide, a partner with 300+ Fortune 500 clients, there is clearly an appetite for help from customers who do not wish to go down the DIY path or can’t do so. Deborah Watson, its client and solutions strategy director, suggests asking what a good partner might “bring to the table” before choosing one.</p><p>She explains: “This means asking the right questions: is your partner part of a programme that rewards them for investing in training, support, and customer success? If not, you may not be getting the full benefit of what a channel relationship can offer. </p><p>“SMBs should ask whether their chosen partner is part of such a programme – it can be a strong indicator of the quality and reliability of the support they’ll receive. Understanding whether their partner is supported in this way can help assess the long-term viability of a DIY approach versus a channel-supported model.”</p><h2 id="planning-for-growth">Planning for growth</h2><p>For Colin Crow, managing director at digital transformation specialist Nexer Enterprise Applications, the big risk with DIY is “you only know what you know”. </p><p>“You might be fortunate enough to have a small team of tech talent in-house, but that doesn’t necessarily mean they are experts in the specifics of the new system you’re implementing or on how to manage the change across the organization,” he says. </p><p>“With a partner, you can get the best of both worlds: control over your vision, with expertise on tap to keep you on track.”</p><p>However, Zayed Ahmed – who started as a call center agent before founding outsourcing company ASL BPO – believes the go-it-alone route has plenty of positives. They believe it’s just about understanding where the pitfalls are on your journey that might then mean you need greater levels of outsourced help.</p><p>“I see very few who succeed with a pure DIY approach,” he says. “They often start there, setting up basic tools like email platforms, cloud storage, or password managers. It feels manageable at the beginning and helps keep costs down. </p><p>“But as soon as compliance or security comes into the picture, things change quickly. Most internal teams cannot keep up with constant updates in regulations or the latest cyber threats. Missed patches, poor backup routines, or weak access controls can cost far more than what was saved upfront."</p><p>That is why Ahmed suggests SMBs heed this piece of advice: “The question should not be ‘DIY or partner?’ but ‘what mix works best for your stage of growth?’”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why MSSPs must train smarter ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/careers-and-training/why-mssps-must-train-smarter</link>
                                                                            <description>
                            <![CDATA[ Upskilling is key for MSSPs to move from reactive monitoring to measurable risk reduction ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3wVPUkEV46Q8gGXgDURQJY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Jg5QMRtinQRrfPcidyAprh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 23 Dec 2025 08:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Careers and Training]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dimitrios Bougioukas ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y26vChicxzDKSTbezmmxaA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Dimitrios Bougioukas is vice president of training at Hack The Box and a recognized leader in IT security, known for his expertise in creating high-impact training programs for cybersecurity teams. &lt;/p&gt;&lt;p&gt;At Hack The Box, he spearheads the development of advanced training initiatives and certifications that equip cybersecurity professionals worldwide with mission-ready skills.&lt;/p&gt;&lt;p&gt;With extensive experience working alongside leading tech companies, Fortune 100/500 firms, critical infrastructure operators, and government and military agencies, Dimitrios specializes in penetration testing, red teaming, incident response, and threat hunting. &lt;/p&gt;&lt;p&gt;His cutting-edge training programs have been endorsed by intelligence-led frameworks such as TIBER-EU (European Central Bank) and iCAST (Hong Kong Monetary Authority), and are widely adopted across government, military, and enterprise organizations, often appearing as requirements in job postings.&lt;/p&gt;&lt;p&gt;As an informal ENISA expert, he contributes to strengthening the technical capabilities of CSIRTs across Europe, developing training, tools, and strategies that enhance event management and response. Dimitrios’ work continues to play a pivotal role in building resilient cybersecurity infrastructures and elevating workforce readiness on a global scale.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Jg5QMRtinQRrfPcidyAprh-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Education and skills blackboard]]></media:description>                                                            <media:text><![CDATA[Education and skills blackboard]]></media:text>
                                <media:title type="plain"><![CDATA[Education and skills blackboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Jg5QMRtinQRrfPcidyAprh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Managed security service providers (MSSPs) are a vital part of the cybersecurity ecosystem, often serving as the first, and sometimes the only, line of defense across multiple clients. Their role is also growing in importance, largely due to the persistent global skills shortage. However, new benchmarking data reveals blind spots that could limit their strategic value.</p><p>Hack The Box’s Global Cyber Skills Benchmark 2025 analyzed nearly 800 teams and more than 4,500 participants worldwide. While MSSP teams performed strongly in OSINT (64.5%) and forensics (62.8%), they lagged in preventive and offensive disciplines such as secure coding (18.7%), web security (21.1%), and adversary emulation.</p><p>The results, which were mapped to the MITRE ATT&CK framework, show a clear imbalance. Although MSSPs are great at detection and response, they are falling short in prevention and protection. Detection is obviously an essential skill, but it’s reactive only. As adversaries exploit AI automation, supply-chain vulnerabilities, and custom exploits, MSSPs risk the need to be more than reactive responders; they need to become active defenders of an organization’s resilience.</p><h2 id="scale-vs-depth">Scale vs depth</h2><p>The MSSP operating model generally includes standardised tooling, multitenant platforms, and is built for speed and efficiency, but it lacks depth. The problem is that detection scales easily, while prevention needs context-specific expertise and secure engineering fluency. When it comes to prevention tools, they alone can’t compensate for missing skills. And that’s why capability, not tooling, is now the main differentiator for an MSSP.</p><p>Continuous Threat Exposure Management (CTEM), a concept introduced by Gartner, is a useful framework for proving resilience. CTEM reframes the narrative from “How fast can we detect?” to “How much risk did we actually remove?” It scopes attack surfaces, simulates threats, validates controls, and measures improvement. </p><p>For MSSPs, embedding CTEM helps to turn technical skills into business value. It will provide proof that cybersecurity investments are actually reducing risk exposure and by how much.</p><h2 id="skills-as-a-differentiator">Skills as a differentiator</h2><p>To close the gap between detection and prevention, MSSPs should start with data-driven workforce benchmarking. This will help ensure money spent on professional skills development delivers genuine operational impact.</p><p>Generic training won’t help. MSSPs need role-based learning paths aligned to core functions, such as SOC analyst, threat hunter, red team operator, and secure developer. Short, verifiable micro-credentials are also important to support continuous improvement. </p><p>The focus isn’t just about training. It is about implementing carefully planned upskilling and having the ability to prove capability to clients and boards alike.</p><p>MSSPs should also consider building industry-aligned capability pods, where there are specialised teams focused on vertical threat landscapes. A finance pod might prioritize blockchain and application security; energy and manufacturing pods could focus on ICS and OT defence; retail pods might tackle supply chain and web application threats. </p><p>These pods deepen contextual understanding of threats and help to strengthen protection. To avoid siloing skills, pod governance should include a process to ensure structured knowledge transfer and continuous feedback loops.</p><h2 id="offensive-emulation-and-ai-risk">Offensive emulation and AI risk</h2><p>Offensive emulation is one of the weakest areas for many MSSPs, with the benchmarking figures showing Pwn/exploitation solve rates averaging just 9.8%. Regular red teaming exercises and adversary emulation training will help improve and validate defences under real-world conditions and feed directly into CTEM metrics, turning simulations into proactive indicators of resilience.</p><p>MSSPs are early adopters of AI-assisted tooling, with solve rates in the benchmarking averaging 38.3%, which is above the global mean. But AI without a secure engineering discipline is a double-edged sword because it has the potential to accelerate vulnerabilities faster than they can be fixed. </p><p>To mitigate this, MSSPs must reinforce secure-by-design skills and integrate AI governance checklists into development and automation pipelines.</p><h2 id="speaking-the-boardroom-language">Speaking the boardroom language</h2><p>Traditional SOC metrics like MTTD (Mean Time to Detect) or MTTR (Mean Time to Respond) do not accurately reflect investment value. Executives want to see measures of exposure reduction, such as fewer exploitable weaknesses, faster patching, and tangible improvements in secure coding proficiency. </p><p>By combining skills benchmarking with CTEM, MSSPs get the ability to communicate actual progress. For example: “Secure coding proficiency up 20%, with a 25% reduction in client-side web vulnerabilities.” That’s the kind of language that needs to be used in the boardroom to translate technical performance upskilling into trust in the MSSP’s business.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Outgoing Kaseya CEO teases "this is just the beginning" for the company ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/leadership/outgoing-kaseya-ceo-teases-this-is-just-the-beginning-for-the-company</link>
                                                                            <description>
                            <![CDATA[ We spoke to Fred Voccola who remains a key figurehead at the firm as it enters its next chapter... ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">EJbKZvBRmEEEfy6apVi9q3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZxydwhNi7ceteoyS4NmJtm-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 29 Apr 2025 16:56:28 +0000</pubDate>                                                                                                                                <updated>Thu, 01 May 2025 09:05:37 +0000</updated>
                                                                                                                                            <category><![CDATA[Leadership]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ Maggie.holland@futurenet.com (Maggie Holland) ]]></author>                    <dc:creator><![CDATA[ Maggie Holland ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/yR3aBSQeNTZZ8SzoXbFEQ3.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Maggie has been a journalist since 1999. She started her career as an editorial assistant on then-weekly magazine Computing, before working her way up to senior reporter level. After several years on the magazine, she moved to &#039;the other side of the fence&#039; to work as a copywriter for a marketing agency, writing case studies and working on ad and website copy for companies such as eBay, Dell, Microsoft and more. In 2006, just weeks before&amp;nbsp;ITPro&amp;nbsp;was launched, Maggie joined Dennis Publishing as a reporter. Having worked her way up to editor of ITPro, she was appointed group editor of&amp;nbsp;CloudPro&amp;nbsp;and&amp;nbsp;ITPro&amp;nbsp;in April 2012. She became the editorial director and took responsibility for&amp;nbsp;ChannelPro,&amp;nbsp;in 2016.&lt;/p&gt;
&lt;p&gt;Her areas of particular interest, aside from cloud, include management and C-level issues, the business value of technology, green and environmental issues and careers to name but a few.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/ZxydwhNi7ceteoyS4NmJtm-1280-80.png">
                                                            <media:credit><![CDATA[Kaseya]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Profile picture of Kaseya CEO Fred Voccola]]></media:description>                                                            <media:text><![CDATA[Profile picture of Kaseya CEO Fred Voccola]]></media:text>
                                <media:title type="plain"><![CDATA[Profile picture of Kaseya CEO Fred Voccola]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZxydwhNi7ceteoyS4NmJtm-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The tech industry, particularly the channel, is filled with big personalities making even bigger moves and announcements that drive things forward. While the tenure of tech CEOs, on average, ranges wildly between less than four years and up to 15 years (depending on which research you consider), the point at which one leader leaves and another is brought in can be quite a make-or-break moment for the company in question. </p><p>So when Fred Voccola, then co-founder and CEO of Kaseya, announced back in January that he would be stepping down from the top spot – and moving into a vice chairman role – it sent waves of chatter, confusion, and curiosity throughout the market. </p><p>For many, Fred <em>is</em> Kaseya. Since his appointment was announced back in July 2015, Voccola has spent a decade front and center. He’s evangelized about the importance of supporting and empowering MSPs and IT personnel through simple-to-use, cost-effective technology that can be game-changing for small and medium businesses (SMBs). </p><p>During the last decade, Voccola has been at the helm through many acquisitions, personnel changes, technology innovation, and problems ranging from issuettes to slightly bigger challenges. One thing that has remained consistent during that time is his belief that trust and transparency are key. </p><p>“I think we've done it the right way, in an honorable way. We're not a scumbag company. Do we mess up? Oh yeah, but we try to own it,” he told me recently during an interview. </p><p>“We didn't sell our souls. We didn't become a political or social engine. We always stayed focused on our partners, our employees, and on building a sustainable, great company. I think that we've completely accomplished the first phase of our mission – we have changed the unit economics for MSPs.”</p><p>Being an MSP can be an unforgiving, unprofitable, unrewarding experience. Once the bills are paid, there’s little left for anything else, let alone innovation. Kaseya, during Fred’s tenure, set out to change that. Today, he says, MSPs that are “powered by Kaseya” can expect to generate a 35-45% profit margin. </p><p>Given that success and the fact that the role of a CEO is all-encompassing, it seems the right time to exit stage left and leave on a high note. </p><p>“A lot of people say they work an 80-hour week. But this company has been my life for the last 11 years. I was talking to my dad last year a little bit [and said] there's a lot of things that I want to do in life, and you can't do them when you wake up at six in the morning for your first phone call meeting, and you go to bed at 11 at night, and you know, half of your Sunday is spent doing that all day,” he said. </p><p>“You just can't do it. So when we released Kaseya 365 that was a monster moment. And the following day and days [post launch], the adoption of it was a monster moment. So I spoke to my fellow board members to say I think it's time that we start to find the next CEO. </p><p>“There are lots of things I want to do in life. It’s not that I don't love this job. I mean, this,  I LOVE it. It's just there are those other things in life...“</p><p>While there will soon be a change at the helm – although industry insiders are divided as to how quickly that may happen in reality, given the ongoing will they/won’t they whispers of an IPO – Kaseya stakeholders can expect all of the good stuff to continue. </p><p>“We're not changing direction,” Voccola asserted. “One of the cool things about Kaseya is, as a security and IT company, we are mission-driven.. That North Star will not change. </p><p>“I assure the industry, the employees, everyone, they will be 10 times better than I am. Everything that I screw up with, they won't make those mistakes. They will be much better, a much better, more charming, handsome, intelligent person. But that North Star mission will not change.” </p><p>Voccola has also consistently exuded passion for what he does and pride in what the company as a whole, not just himself, has achieved. </p><p>Speaking about just the last financial year, under his leadership, it was a record breaker. Indeed, 2024 was the best financial year in Kaseya’s history, with the firm growing over 17% organically. </p><p>The organization has around 5,000 employees, and more than 7,500 companies have already adopted Kaseya 365 since its launch. Voccola takes the responsibility of supporting both sides of the ecosystem very seriously. He refers to employees as ‘Kaseyans” and reports that there have been up to 50 Kaseyan marriages during his time. </p><p>“I've always taken a lot of pride in how people who have worked in my companies have gone on to do great things. At Kaseya right now, I can tell you there are 20 to 25 tier one CEOs,” he said. </p><p>“Miami, Florida, 10 years ago, was not a technology town. Kaseya has made Miami a permanent tech destination that rivals [other locations]. The talent levels at Kaseya are among the best in the world, and what that means is, for every partner who reads this, you have really smart, capable people working tirelessly to make your profitability better. We have an amazing, amazing bunch of people.”</p><p>When it comes to continuing to service MSP needs, he has his eye firmly on the horizon and the next big thing… </p><p>That next big thing for Kaseya will almost certainly involve AI and automation. Heck, this week plays host to the firm’s Connect event in Las Vegas, so we’re probably mere hours away from the big reveal. </p><p>But to move forward, it’s also important to look back, and Voccola has worked hard to reassure people that while he is changing gears, the next era will also be positive. </p><p>Going back to the early days, he remembers fondly when things clicked. When he and his peers “saw the magic” and how they could really change the unit economics for MSPs. </p><p>“My father used to say, ‘If you want to create something great, find a huge market. Find a problem that the market has, solve it, and then make it easy for people to use your solution, whatever that solution may be.’</p><p>It’s clear from the outside looking in, Kaseya has done just that. And while his time as CEO may be done, Kaseya will long be in his life. </p><p>“Once the new CEO comes on board, I'll be vice chairman. I'm the largest individual shareholder of this company, so I have a huge interest in the company. I love it. It's my baby. It will always be my baby,” he said. </p><p>Voccola added: “There are a couple of highlights. One of them is that we built the company the right way. It’s [like that] rank Sinatra song ‘My way.” My dad loved that song. When I think about what we've done at Kaseya, [we’ve done that]. And by the way, this is just the beginning of Kaseya. This is just the beginning…” </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Schneider Electric joins Nozomi Networks' MSSP Elite Partner Program ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/schneider-electric-joins-nozomi-networks-mssp-elite-partner-program</link>
                                                                            <description>
                            <![CDATA[ Schneider will leverage Nozomi’s security solutions to deliver enhanced managed security services to key industrial sectors ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gDu98VZoAHLd7CtuFUbhDf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QZPkN8TuSPnJJnNkbeFYLk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 14 Feb 2025 14:50:25 +0000</pubDate>                                                                                                                                <updated>Thu, 24 Apr 2025 17:45:28 +0000</updated>
                                                                                                                                            <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QZPkN8TuSPnJJnNkbeFYLk-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Schneider Electric logo and branding pictured in its 4.0 production plant in Le Vaudreuil, northwestern France.]]></media:description>                                                            <media:text><![CDATA[Schneider Electric logo and branding pictured in its 4.0 production plant in Le Vaudreuil, northwestern France.]]></media:text>
                                <media:title type="plain"><![CDATA[Schneider Electric logo and branding pictured in its 4.0 production plant in Le Vaudreuil, northwestern France.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QZPkN8TuSPnJJnNkbeFYLk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Nozomi Networks has announced that energy management and automation specialist Schneider Electric has joined its MSSP Elite Partner Program.</p><p>The move will see Schneider embed Nozomi’s range of security solutions into its platform to deliver enhanced <a href="https://www.itpro.com/security/smb-security-gaps-drive-new-opportunities-for-channel-players">managed security services (MSS)</a> to key global sectors, including energy and chemicals, water, consumer packaged goods, power and grid, data centers, and critical infrastructure.</p><p>Nozomi said the integration will create a full-scale, industrial-focused security management service capable of safeguarding complex operational environments. </p><p>Schneider customers will be able to leverage capabilities such as OT and IoT visibility and vulnerability management, network monitoring, threat detection, and risk management, as well as access bundled offerings that incorporate Nozomi Networks’ Vantage, Guardian, Threat Intelligence, and Arc solutions.</p><p>Jay Abdallah, president of Schneider Electric’s cyber security solutions segment, said the collaboration will help customers minimize their cyber risk and maximize resilience, while complying with regulatory requirements.</p><p>“With the power of <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a>-driven analytics and timely response, our fully managed, end-to-end security solution helps organizations ensure the resilience of their most critical systems,” he explained.</p><p>“As part of a broad range of solutions to help organizations run more efficiently, this certified <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>offering gives customers the ability to focus on their core operations, while we support them with industry leading and continuously evolving cybersecurity defenses.”</p><p>Deployable both on site and in the cloud, Nozomi Networks’ range of solutions span IT, <a href="https://www.itpro.com/security/364189/from-it-to-ot-whats-the-partner-opportunity">OT</a>, and <a href="https://www.itpro.com/cloud-computing/28037/what-is-iot">IoT </a>and leverage AI to automate tasks such as inventorying, visualizing, and monitoring of industrial control networks. </p><p>The firm said these solutions currently support 115 million devices across a range of sectors, from energy and manufacturing, to smart cities and critical infrastructure.</p><p>Launched in 2023, Schneider Electric’s MSS offering has since evolved into a multi-layered cyber security solution, complete with end-to-end security controls management, vulnerability management, advanced threat detection, as well as around-the-clock support.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="YRwEK7F48t5uqGuzdTnavF" name="SANS™ Institute Product Overview_ Safeguard Your Business-Critical Web Apps and APIs with a WAF" caption="" alt="SANS™ Institute Product Overview: Safeguard Your Business-Critical Web Apps and APIs with a WAF" src="https://cdn.mos.cms.futurecdn.net/YRwEK7F48t5uqGuzdTnavF.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Fortinet)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-security/sanstm-institute-product-overview-safeguard-your-business-critical-web-apps-and-apis-with-a-waf"><em>Protect on-premises and cloud application workloads</em></a></p></div></div><p>The firm’s addition to the Nozomi Networks <a href="https://www.itpro.com/security/28879/what-is-an-mssp">MSSP</a> Elite Partner Program builds on a long-standing strategic alliance that has seen the pair collaborate to support customers since 2017. Last year, Schneider also participated in Nozomi’s $100 million Series E funding round.</p><p>“<a href="https://www.itpro.com/channel/368166/schneider-electric-launches-new-partner-programme">Schneider Electric</a> continues to advance the future of sustainable energy management and automation,” commented Chet Namboodri, Nozomi’s SVP of global business development,. “They share Nozomi Networks’ passion for ensuring energy resources are always available, reliable and safe.</p><p>“With an established eight-year track record of collaboration, we firmly believe this partnership accelerates our joint mission to help protect energy management and automation processes around the world.”</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/business/leadership/schneider-electric-names-hanne-sjoberg-as-new-vp-channels-for-europe">Schneider Electric names Hanne Sjøberg as new VP channels for Europe</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/schneider-electric-confirms-breach-after-hacker-claims-to-have-40gb-of-stolen-data">Schneider Electric confirms breach after hacker claims to have 40GB of stolen data</a></li><li><a href="https://www.itpro.com/security/emerson-and-nozomi-networks-announce-expanded-partnership">Emerson and Nozomi Networks announce expanded partnership</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Three secrets to success for the MSSP ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/three-secrets-to-success-for-the-mssp</link>
                                                                            <description>
                            <![CDATA[ MSSPs can capitalize on growing demand to outsource security workloads amid ongoing economic hurdles and skills shortages – here's how ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">XAYC99G67D8YdTjGoRyfHf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zB3YMcgBsLoxJw7XGspzLS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 09 Oct 2024 13:42:43 +0000</pubDate>                                                                                                                                <updated>Thu, 24 Apr 2025 19:17:19 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Innes Muir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/qteuB4yC44jmJjQPw79Vka.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zB3YMcgBsLoxJw7XGspzLS-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Security analyst working with multiple screens in front of them]]></media:description>                                                            <media:text><![CDATA[Security analyst working with multiple screens in front of them]]></media:text>
                                <media:title type="plain"><![CDATA[Security analyst working with multiple screens in front of them]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zB3YMcgBsLoxJw7XGspzLS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The <a href="https://www.itpro.com/uk/tag/managed-security-service-provider">managed security services provider</a> (MSSP) market is burgeoning as organizations look to outsource their cybersecurity, and this is due to a number of factors.The economic downturn has hit security budgets hard and many have had to make cutbacks as a result, with an <a href="https://www.isc2.org/research" target="_blank"><u>ISC2 report</u></a> revealing that 47% have laid off staff, slashed budgets, and/or frozen recruitment drives and promotions.</p><p>Threats continue to escalate, making cyber insurance a must, and premiums frequently require that certain conditions are met, driving organizations to seek external assistance in the form of <a href="https://www.itpro.com/security/cyber-security/357814/a-buyers-guide-to-managed-detection-and-response-mdr-services">managed detection and response</a> (MDR). These challenges are all compounded by an unprecedented skills shortage, with a workforce gap of approximately 4 million worldwide and growing at a rate of 13% per year, according to the same ISC2 report, forcing organizations to plug holes in their teams with external resources.</p><p>Some of these same issues are also making it very difficult for MSSPs to exploit this demand for outsourcing, however, and are even putting them at risk. The <a href="https://www.sophos.com/en-us/whitepaper/msp-perspectives" target="_blank"><u>MSP Perspectives 2024</u></a> survey found the top three challenges experienced by channel providers were keeping pace with innovation in cybersecurity, securing analysts due to the <a href="https://www.itpro.com/business/business-strategy/the-impact-of-it-skills-shortages-on-business">skills shortages</a>, and keeping up with emerging threats. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="FxxwCQMyqyWdnMqqB5xZq6" name="047A149A-EBD4-4358-978A-1FDE5FFC53F7_1_201_a.jpeg" caption="" alt="Man sitting with headset on at desk in office" src="https://cdn.mos.cms.futurecdn.net/FxxwCQMyqyWdnMqqB5xZq6.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/software/business-apps/migrating-to-enterprise-voice-a-strategic-approach-for-modern-businesses">Migrating to enterprise voice: A strategic approach for modern businesses</a></p></div></div><p>In addition, many have a bloated security stack and are struggling to meet demand due to unwieldy systems that make provisioning and management complex. Costs are also rocketing across the board from licensing through to salaries but the MSSP can’t pass those costs onto their customer base. Absorbing them then curtails their ability to invest and expand.</p><p>Not surprisingly, MSSPs are therefore under tremendous pressure to provide round-the-clock support with diminishing human resources. The survey notes that around a third of MSPs offering MDR have an <a href="https://www.itpro.com/server-storage/system-on-chip-soc/359042/samsung-and-marvell-develop-low-power-soc-to-support-5ghttps://www.itpro.com/security/359719/what-is-a-soc-audit">inhouse SOC</a> manned by between 15 – 30 analysts, depending on the size of the customer base, which means there’s the risk of the MSSP becoming short-staffed, jeopardizing operations. It’s becoming increasingly apparent that they will need to make some substantial changes over the course of the next few years if they are to navigate their way through these tough times and emerge intact. So, what should these providers be doing? </p><h2 id="supply-and-demand">Supply and demand</h2><p>To start with, it’s worth considering how demand for managed services is likely to manifest itself during that time frame. In addition to the drivers above, we can also add regulation to the mix, with a raft of new legislation set to come into force such as <a href="https://www.itpro.com/security/nis2-is-a-double-edged-sword-for-the-it-channel">NIS2</a> across the EU (which will also likely be adopted in some form or fashion in the UK) from October and <a href="https://www.itpro.com/business/policy-legislation/368414/eu-digital-operational-resilience-act-dora">DORA</a> in the financial sector in January. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LuaeP2PNFuBCyx3bXyJkuT" name="FFFE237B-3328-4FFB-9711-FD70D00239C4_1_201_a.jpeg" caption="" alt="Shot of two coworkers having a discussion in modern office." src="https://cdn.mos.cms.futurecdn.net/LuaeP2PNFuBCyx3bXyJkuT.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/how-do-you-value-your-expertise-when-selling-to-experts">How do you value your expertise when selling to experts?</a></p></div></div><p>Both will compel organizations to be more proactive in how they assess and address risk and introduce much greater accountability, which means many will seek assistance in meeting those requirements. MSSPs that have positioned themselves to be able to offer that level of support in the form of MDR or have systems specifically attuned to those <a href="https://www.itpro.com/business/business-strategy/keeping-up-with-the-compliance-landscape-in-2024">compliance demands</a> will then be best placed to capitalize on this demand.</p><p>Yet, with analysts in short supply, scaling operations could prove challenging, forcing the MSSP to either miss out or compromise on the quality of delivery. The key here is making the <a href="https://www.itpro.com/business/business-strategy/building-a-sustainable-business-model-in-tech">business model</a> more efficient so that it becomes easier to service multiple tenants. </p><p>So, the MSSP should continue to look at how they can consolidate their cybersecurity stack and reduce the number of vendors they deal with. But they also need to think more creatively about how they provision those services. Having a cyber defense platform in place that can perform numerous functions can significantly reduce complexity in this regard, one example being a security and incident event management (<a href="https://www.itpro.com/security/security-information-and-event-management-siem/367048/six-myths-of-siem">SIEM</a>) platform with additional complementary add-ons such as automation, case management and behavior analytics.</p><h2 id="a-single-pane-of-glass">A single pane of glass</h2><p>To make provisioning easier, those services then need to be overlaid with an MSSP-specific interface. This allows customers to be onboarded and managed collectively while still enabling the analyst to drill down into and customize an individual organization’s requirements or carry out an investigation. Using a <a href="https://www.itpro.com/infrastructure/networking/hpe-s-aruba-channel-overhaul-looks-to-simplify-client-engagement">single interface</a> also makes it possible to enact changes or respond to threats more efficiently by rolling out new rulesets to the entire customer base at the same time. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="QTZGUDotbZBDohXc3vAPtb" name="FD8B4E50-765E-4DF4-A8BD-5F0DEA54FC37_1_201_a.jpeg" caption="" alt="Judge's gavel and with modern blur lined in the background." src="https://cdn.mos.cms.futurecdn.net/QTZGUDotbZBDohXc3vAPtb.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-and-legislation/compliance-how-the-channel-can-deliver-optimal-enterprise-solutions-tailored-to-evolving-regulations">Compliance: How the channel can deliver optimal enterprise solutions tailored to evolving regulations</a></p></div></div><p>Instead of focusing on provisioning the distributed SIEM, the MSSP is then free to monitor incidents, analyze <a href="https://www.itpro.com/security/cyber-attacks/t-mobiles-vm-logs-allegedly-leaked-in-20-gb-capgemini-data-breach">log data</a> and add valuable insights. As a result, valuable human resources are being used as productively as possible and time is not being wasted on so-called ‘swivel chair’ operations which sees the analyst log in and out of systems. It’s important to look at the architecture of any such offering, however, to ensure partitioning is in place that keeps each customer’s data secure, particularly given that the MSP Perspectives 2024 survey notes that stolen access data and credentials are the number one risk keeping MSSPs awake at night.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="trn4ackLzZb7hLT9wy24wL" name="Help skilled workers succeed with Dell Latitude 7030 and 7230 Rugged Extreme tablets" caption="" alt="Help skilled workers succeed with Dell Latitude 7030 and 7230 Rugged Extreme tablets" src="https://cdn.mos.cms.futurecdn.net/trn4ackLzZb7hLT9wy24wL.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Dell)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hardware/help-skilled-workers-succeed-with-dell-latitude-7030-and-7230-rugged-extreme-tablets"><em>Devices that work in extreme weather</em></a></p></div></div><p>It may also be worth going back to the market to look at alternative <a href="https://www.itpro.com/cloud/cloud-security/fortinet-expands-partner-programs-flexible-licensing-options">licensing models</a>. Data throughput pricing models will see costs rise over time as the customer grows and data consumption increases, so being able to keep those costs nailed down can enable the MSSP to shield its customer from any price increases. For this reason, predictable pricing models based on nodes rather than data are gaining in popularity. </p><p>Those MSSPs that address these issues today by <a href="https://www.itpro.com/infrastructure/looking-to-streamline-it-transformation-here-s-how">streamlining their operations</a> will be well placed to exploit demand and also to adapt to changing market conditions as these materialize. Essentially there are three secrets to success. Provided they can manage their own costs and protect their customers from any shock increases, rationalize the stack, and achieve economies of scale, there’s no reason why MSSPs can’t turn the current challenges they’re experiencing into tomorrow’s opportunities. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Logpoint unveils new MSSP and channel partner programs ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/logpoint-unveils-new-mssp-and-channel-partner-programs</link>
                                                                            <description>
                            <![CDATA[ The new Logpoint initiatives aim to help partners navigate the changing security landscape and capture new opportunities ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">e7qpHHWCvUaqGxdog4R9k6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/uKJYWj6P63diudVrHn6bMV-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 11 Apr 2024 08:30:25 +0000</pubDate>                                                                                                                                <updated>Thu, 24 Apr 2025 16:29:36 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/uKJYWj6P63diudVrHn6bMV-1280-80.jpg">
                                                            <media:credit><![CDATA[Logpoint]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Logpoint logo and branding pictured in white lettering on a black background.]]></media:description>                                                            <media:text><![CDATA[Logpoint logo and branding pictured in white lettering on a black background.]]></media:text>
                                <media:title type="plain"><![CDATA[Logpoint logo and branding pictured in white lettering on a black background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/uKJYWj6P63diudVrHn6bMV-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/28133/what-is-cyber-security">Cyber security</a> vendor Logpoint has cut the ribbon on a brace of new partner programs for <a href="https://www.itpro.com/security/28879/what-is-an-mssp">managed security service providers</a> (MSSPs) and channel partners.</p><p>The company said its new initiatives aim to foster successful collaborations and add increased value to both its partner ecosystem and mutual customers during the year ahead.</p><p>Logpoint provides a range of threat detection and investigation response (TDIR) and compliance solutions that work to help customers defend against cyber attacks and meet regulatory demands via a simple licensing model.</p><p>The Logpoint platform combines SIEM, UEBA, SOAR, and SAP security technologies to provide threat detection, minimization of false positives, autonomous risk prioritization, and incident response.</p><p>Now, with its two new programs, the firm has introduced a range of complimentary features to provide tailored support and improved assistance to both MSSPs and channel partners.</p><h2 id="logpoint-shakes-up-its-mssp-program">Logpoint shakes up its MSSP program</h2><p>Logpoint said its dedicated MSSP program will help speed up MSSPs’ time to success with customers through several distinct features, including a predictable pricing model based on nodes as opposed to data volumes.</p><p>Businesses joining the initiative will receive a dedicated starter pack that includes Logpoint Director – a platform designed to help MSSPs operate and manage large and multi-tenant deployments – as well as training resources, onboarding assistance, and enablement opportunities.</p><p>The program also features two flexible commercial models. The first is based around subscription assignments for customers, with subscriptions for each end customer manageable through Logpoint Director.</p><p>The second places a focus on consumption and features quarterly reporting and specific pricing structures that are tailored to consumption levels for flexibility and scalability.</p><p>In an announcement, Antti Vilhunen, Logpoint’s regional director for Northern Europe, said the changing threat landscape is piling more pressure on organizations in the <a href="https://www.itpro.com/business/careers-and-training/majority-of-mid-market-firms-struggle-to-retain-it-talent-for-more-than-two-years-research-shows">mid-market</a> as threats become increasingly more sophisticated.</p><p>“We’re seeing an increased move in that segment towards MSSPs, offering extensive <a href="https://www.itpro.com/security/the-cyber-security-skills-shortage-what-skills-are-missing">cyber security skills</a> and advanced threat intelligence technologies to help improve the security posture and manage risk,” he explained."</p><p>“Our new MSSP program empowers them to capture opportunities and thrive in today’s cyber security landscape, delivering the tools, resources, and support they need.”</p><h2 id="channel-partner-program">Channel partner program</h2><p>Logpoint has also unveiled its new program for channel partners, which includes a simplified tier model for increased clarity on margin benefits. Partners can achieve either silver or gold status for training and sales engineering enablement, with the tiers offering total partner discounts of 20% and 30%, respectively.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Hqd9pR8PmHnnrm8oCLzidj" name="The Forrester Wave API management solutions Q3 2022_listing.jpg" caption="" alt="Whitepaper cover with title, image of contributor, and text" src="https://cdn.mos.cms.futurecdn.net/Hqd9pR8PmHnnrm8oCLzidj.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/ai-decisioning-platforms-q2-2023"><em>Get an overview of AI decisioning platform providers</em></a></p></div></div><p>The <a href="https://www.itpro.com/security/how-to-choose-the-best-cyber-security-vendor-for-your-business">cyber security vendor</a> said it has also streamlined the deal registration process for a consistent experience across regions, while access to its new Extended Success Plan will enable channel partners to offer end customers improved service level agreements (SLAs).</p><p>“In addition to our MSSP Program, we’re delighted to introduce an improved Channel Partner program, offering generous margins in a simple and clear structure, reinforcing our commitment to Channel Partners,” Vilhunen said.</p><p>“We have partners across many different regions. We understand that each region has its distinct challenges and opportunities, which the new Channel Partner Program reflects.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Check Point targets partner growth with MSSP program revamp ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/check-point-targets-partner-growth-with-mssp-program-revamp</link>
                                                                            <description>
                            <![CDATA[ The Check Point partner initiative now offers a “more robust, comprehensive, and flexible” service model ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kAmCAhG4BGHWfZmaQGQP56</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qyypwQ53tpVe4zWHhQg9ne-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 10 Nov 2023 11:23:56 +0000</pubDate>                                                                                                                                <updated>Thu, 24 Apr 2025 18:00:26 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qyypwQ53tpVe4zWHhQg9ne-1280-80.jpg">
                                                            <media:credit><![CDATA[Check Point]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Check Point logo (A stylized pink circle with a series of three nodes drawn against it in white to produce a curcular cutout effect in the top right hand corner of the circle, with a black circle to the top and right of this and the words CHECK POINT to the right of it in black text) against a white background.]]></media:description>                                                            <media:text><![CDATA[The Check Point logo (A stylized pink circle with a series of three nodes drawn against it in white to produce a curcular cutout effect in the top right hand corner of the circle, with a black circle to the top and right of this and the words CHECK POINT to the right of it in black text) against a white background.]]></media:text>
                                <media:title type="plain"><![CDATA[The Check Point logo (A stylized pink circle with a series of three nodes drawn against it in white to produce a curcular cutout effect in the top right hand corner of the circle, with a black circle to the top and right of this and the words CHECK POINT to the right of it in black text) against a white background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qyypwQ53tpVe4zWHhQg9ne-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber security solutions provider Check Point has unveiled a host of enhancements to its MSSP Partner Program, designed to help tackle the <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> workforce shortage and rise in digital threats. </p><p>The initiative has been revamped to offer a more robust and flexible service model, the firm said, featuring simplified onboarding, predictable revenue streams, new solutions, as well as a comprehensive security ecosystem. </p><p>In an announcement, Check Point said the updated program is a direct response to evolving needs in the global <a href="https://www.itpro.com/security/367051/making-the-jump-to-become-an-mssp">managed security services market</a>, which is currently experiencing “unprecedented growth.”</p><p>“MSSPs have a big opportunity to capitalize on the demand for their services, but they face their own challenges in a rapidly changing world,” said Shahar Divon, Check Point’s head of global SMB sales. </p><p>“At the operational level, these teams spend too much time handling hundreds of alerts daily, tying up resources that could be better spent on more urgent requests.</p><p>“That is where our MSSP Partner Program can deliver real value, not only for those that have security as a practice, but also MSPs that are looking for ways to protect their customers.”</p><h2 id="a-x201c-revolutionized-x201d-program">A “revolutionized” program</h2><p>Check Point said its changes are not merely incremental adjustments, but significant additions that “revolutionize” the program. <a href="https://www.itpro.com/security/28879/what-is-an-mssp">MSSPs</a> of various sizes can now take advantage of simplified onboarding, as well as predictable revenue streams.</p><p>The new consumption-based pricing model introduces fixed, pay-as-you-go, and tiered options that have been designed to make Check Point’s services more accessible and convenient through local distribution channels. </p><p>Partners can also leverage the latest managed security services across all vectors, the firm added, including SASE, email security, <a href="https://www.itpro.com/software-defined-wide-area-network-sd-wan/33346/what-is-sd-wan">SD-WAN</a>, and mobile security. </p><p>These security management features are accessible via the Infinity Portal, which leverages Check Point’s ThreatCloud AI solution to integrate all elements of security management for convenient management. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="euY9AaUcm4DemQM7ToEQcc" name="RMM_Made_MSPeasy_listing.jpg" caption="" alt="A whitepaper from Datto for MSPs on RMM" src="https://cdn.mos.cms.futurecdn.net/euY9AaUcm4DemQM7ToEQcc.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Datto)</span></figcaption></figure><p class="fancy-box__body-text"><em>Support remote teams and manage customer environments<br></em><br><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/rmm-solution-made-mspeasy">DOWNLOAD NOW</a></p></div></div><p>Additionally, the program serves up free training for managing PAYG licenses via the portal, distributor support, an agile user management tool for handling user access and customer requirements, as well as a security ecosystem that includes services across all attack vectors, Check Point said. </p><p>“We have now streamlined the business model and simplified the onboarding process, making it easier for partners of any size to access our innovative products and scale their operations as needed,” Divon added. “We believe the simplicity and agility is what sets our program apart in the market.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How MSSPs can leverage dark web intelligence to counter emerging threats ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/how-mssps-can-leverage-dark-web-intelligence-to-counter-emerging-threats</link>
                                                                            <description>
                            <![CDATA[ Dark web intelligence can be a vital tool for MSSPs to bolster security and counter emerging threats ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">HJANMTDBYbkzo8PuGCPQNV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8TbsahzKZ53F2B5cCVYakE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 16 Aug 2023 10:15:00 +0000</pubDate>                                                                                                                                <updated>Thu, 24 Apr 2025 19:40:39 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ben Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/PxLoEXSvhz3MToMZ4pQ7YG.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8TbsahzKZ53F2B5cCVYakE-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A web structure imposed on a black background]]></media:description>                                                            <media:text><![CDATA[A web structure imposed on a black background]]></media:text>
                                <media:title type="plain"><![CDATA[A web structure imposed on a black background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8TbsahzKZ53F2B5cCVYakE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Managed Security Service Providers (MSSP) are at the forefront of emerging market trends, meaning they need to identify and adopt the latest technology to best protect their customers and keep step with competitors. </p><p>The demand for dark web intelligence has skyrocketed over the past few years, as organizations grow ever more aware that cyber attacks originate in marketplaces, forums, and sites they cannot see. It is therefore not surprising that <a href="https://www.slcyber.io/press/report-how-mssps-are-using-dark-web/"><u>most MSSPs</u></a> have already started to address customer demands for dark web threat insights.</p><p>But despite many MSSPs already undertaking dark web monitoring, our latest <a href="https://www.slcyber.io/whitepapers-reports/a-guiding-light-in-the-dark-how-mssps-are-using-dark-web-threat-intelligence/"><u>research</u></a> identified that 35% of MSSPs believe that dark web monitoring is too complex, while nearly one-third (29%) believe it isn’t relevant to their service offering, and 18*+% are yet to be convinced they will be able to sell it.</p><p>With 34% of MSSPs not seeing value in dark web monitoring tools, some providers are potentially missing out on providing essential insights into an online criminal underworld where cyber criminals discuss and plan future attacks. </p><p>MSSPs, therefore, have an opportunity to harness the power of dark web intelligence to protect their customers from cyber threats.</p><h2 id="dark-web-intelligence-and-the-x201c-cyber-kill-chain-x201d">Dark web intelligence and the “cyber kill chain”</h2><p>When we talk about <a href="https://www.itpro.com/security/28133/what-is-cyber-security"><u>cyber security</u></a>, most of a security team’s resources and tools are focused on the late stages of “cyber kill chain” (the sequence of actions a cybercriminal has to take to execute their attacks). </p><p>For instance, email security tools sit at the ‘delivery’ phase of a cyber attack, whilst endpoint, network, and <a href="https://www.itpro.com/security/antivirus/367785/best-business-antivirus"><u>antivirus security solutions</u></a> focus on identifying the subsequent activity as the attacker makes their way across an organization’s infrastructure. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="5bgDiwE8NhRmYj2TybQ4Dk" name="workplace_diversity_GettyImages-1396315043 (1).jpg" caption="" alt="Female business colleagues in meeting discussing project" src="https://cdn.mos.cms.futurecdn.net/5bgDiwE8NhRmYj2TybQ4Dk.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/addressing-the-gender-divide-in-the-channel">Addressing the gender divide in the channel</a></p></div></div><p>As cyber criminals continue to evolve their capabilities and skill sets to be able to bypass existing security solutions, preventing an attack is not always as simple as not clicking a <a href="https://www.itpro.com/security/29093/what-is-phishing"><u>phishing</u></a> link. To give the best chance of disrupting a cyber criminal’s operation in clients systems, MSSPs need to “shift left” and act as early in the cyber kill chain as they can on behalf of their customers. </p><p>Dark web intelligence allows MSSPs to investigate the ‘reconnaissance’ stage, right at the beginning of the “kill chain” when threat actors are planning their cyber attacks on <a href="https://www.itpro.com/security/hacking/367417/authorities-finally-confirm-leading-hacker-platform-raidforums-has-been"><u>dark web hacking forums</u></a>, and buying the exploits and tools they need on malicious marketplaces. </p><p>By starting this early, MSSPs can make a dent in an attack plan and advise their clients on how to take preventative action that stops their network from being breached in the first place. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="6ioYHWRxniA3Ra8werZ8nX" name="Thwart cyberthreats_listing.jpg" caption="" alt="eBook cover with green title text over image of business man wearing glasses and smiling at a workstation" src="https://cdn.mos.cms.futurecdn.net/6ioYHWRxniA3Ra8werZ8nX.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: ServiceNow)</span></figcaption></figure><p class="fancy-box__body-text"><em>See why peers are looking to AI and machine learning to transform their cyber security processes.<br></em><br><a data-analytics-id="inline-link" href="https://www.itpro.com/security/thwart-cyberthreats-fast-with-security-operations-ai-ops">DOWNLOAD FOR FREE</a></p></div></div><p>MSSPs’ position in the market requires them to be early adopters, able to identify the latest tools and technologies to protect their customers. It is no surprise then, that <a href="https://www.slcyber.io/whitepapers-reports/a-guiding-light-in-the-dark-how-mssps-are-using-dark-web-threat-intelligence/"><u>56% of MSSPs</u></a> already undertake dark web intelligence, recognising the benefit. </p><p>Companies of all sizes are increasingly conscious of dark web threats and the opportunity dark web intelligence holds for helping them identify the early warning signs of attack. </p><p>This has created an opportunity for MSSPs to use dark web intelligence as a basis to deliver the analysis, expertise, services, and solutions that help their customers act on the dark web risk they have heard so much about.</p><h2 id="meeting-customer-demand">Meeting customer demand</h2><p>According to our <a href="https://www.slcyber.io/whitepapers-reports/a-guiding-light-in-the-dark-how-mssps-are-using-dark-web-threat-intelligence/"><u>research</u></a>, customer interest in the dark web has been increasing, with 65% of MSSPs stating that their customers have asked for threat intelligence from the dark web. </p><p>Why is that? Well, there are three main reasons for this demand. Firstly, as visibility in cyber security is key, customers want to identify vulnerabilities affecting their organization. Secondly, they want to know if they or their competitors are currently being targeted on the dark web. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="crxdBq2iAVPqTy96onEXeH" name="business_deal_handshake_GettyImages-692570400 (1).jpg" caption="" alt="Two business women shaking hands" src="https://cdn.mos.cms.futurecdn.net/crxdBq2iAVPqTy96onEXeH.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/how-msps-can-create-a-lead-generation-program-that-delivers-results">How MSPs can create a lead generation program that delivers results</a></p></div></div><p>Thirdly, they want to own and act upon intelligence on threat groups including ransomware gangs that are active in the threat environment.</p><p>So, as the topic of dark web monitoring grows in prominence, those MSSPs that have started to build out their capabilities, data sources, and understanding will be able to benefit as more customers look for guidance on the dark web, giving them an advantage in the competitive market of managed security services.</p><h2 id="unlocking-benefits-for-mssps">Unlocking benefits for MSSPs</h2><p>Aside from striking benefits for customers, MSSPs can also take advantage of dark web intelligence from a commercial perspective. When asked about the benefits of using dark web intelligence, <a href="https://www.slcyber.io/whitepapers-reports/a-guiding-light-in-the-dark-how-mssps-are-using-dark-web-threat-intelligence/"><u>37% of MSSPs</u></a> reported that it helps them identify customer details on the dark web, closely followed by giving them new products and services to sell to customers and making their current services more efficient.</p><p>By “shifting left” in the cyber kill chain, MSSPs are enabled to move from reacting to threats to proactively preventing them from happening in the first place. This makes good business sense as it means MSSPs can document and demonstrate value based on attributes exposed and/or being discussed on the dark web. </p><p>It also means that MSSPs don’t have to wait for their clients to be breached before they can prove their worth – they can often find threats that could impact the organization, from day one.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="EXeL4hPNVaTQPuTt2HGWAF" name="Brain_Evolution_Stock_GettyImages-1436010616.jpg" caption="" alt="Digital generated image of multi coloured gear wheels connected together in shape of brain on grey background" src="https://cdn.mos.cms.futurecdn.net/EXeL4hPNVaTQPuTt2HGWAF.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/how-to-bring-your-people-on-your-digital-evolution-journey">How to bring your people on your digital evolution journey</a></p></div></div><p>According to <a href="https://www.slcyber.io/whitepapers-reports/a-guiding-light-in-the-dark-how-mssps-are-using-dark-web-threat-intelligence/"><u>research</u></a>, the most common use for threat intelligence is to inform pentests and security audits (35%) followed by informing incident response (34%). The MSSPs which use dark web intelligence in one-off engagements are missing a trick in integrating dark web intelligence into their value proposition and hence recurring revenues, where they could be capitalizing month-on-month. </p><p>A huge opportunity lies in MSSPs wrapping dark web monitoring into their Managed Security and SOC services to provide customers with an ongoing view of their dark web risk over time and alert them as soon as a serious situation emerges.  </p><p>The turbulent nature of criminal activity means that the dark web shifts and changes at an even faster rate than the clear web. Marketplaces, forums, and criminal groups appear out of nowhere, rise to prominence, jostle with other criminals and law enforcement, and disappear just as quickly as they came. </p><p>Dark web threat prevention is, therefore, not something that can be done on a six monthly or yearly basis. If organizations want to truly understand their threat risk on the dark web, they need their MSSPs to continuously monitor and deliver meaningful insights for effective cyber security protection and healthy cyber posture.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cyware cuts ribbon on new global partner program ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/business-strategy/cyware-cuts-ribbon-on-new-global-partner-program</link>
                                                                            <description>
                            <![CDATA[ The CywareOne initiative aims to equip partners with “the tools they need to differentiate themselves in the market” ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">owyny3Uz9GEKuGbUyoCkhN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/u4dqPobeLPG8tKHTgEAPBC-1280-80.jpeg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 16 Jun 2023 09:59:15 +0000</pubDate>                                                                                                                                <updated>Thu, 24 Apr 2025 18:07:53 +0000</updated>
                                                                                                                                            <category><![CDATA[Business Strategy]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/u4dqPobeLPG8tKHTgEAPBC-1280-80.jpeg">
                                                            <media:credit><![CDATA[Cyware]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cyware logo on white background]]></media:description>                                                            <media:text><![CDATA[Cyware logo on white background]]></media:text>
                                <media:title type="plain"><![CDATA[Cyware logo on white background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/u4dqPobeLPG8tKHTgEAPBC-1280-80.jpeg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber security solutions provider Cyware is looking to grow its partnership with its channel and managed security (MSSP/MDR) partners through its new global partner program, CywareOne.</p><p>The fresh initiative will enable partners to provide customers with Cyware’s advanced threat intelligence automation, security advisory sharing, <a href="https://www.itpro.com/software/development/367576/low-code-vs-no-code"><u>low-code</u></a> vendor-agnostic SOAR, as well as cyber fusion technologies.</p><p>In an announcement, the firm revealed it has already partnered with several globally renowned cyber security providers to deliver security solutions, including GuidePoint Security, Ernst & Young, Optiv, Morado, and SHI.</p><p>"CywareOne represents a significant step forward in our commitment to developing strong partnerships with businesses that share our vision for a safer digital world," said Matt Courchesne, Cyware’s head of channel for North America. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="MtPjjHSEfTqgo7yGoRaypN" name="Accessing the XDR realm_listing.jpg" caption="" alt="Whitepaper cover with title over an image of  XDR in a circle positioned in front of a dark cityscape" src="https://cdn.mos.cms.futurecdn.net/MtPjjHSEfTqgo7yGoRaypN.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: WatchGuard)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Accessing the XDR realm</strong></p><p class="fancy-box__body-text"><em>A guide for MSPs to unleash modern security</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/accessing-the-xdr-realm"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>"Our new program will deliver the resources and support our partners need to succeed in the rapidly evolving cyber security landscape."</p><p>Cyware specializes in unifying threat intelligence, <a href="https://www.itpro.com/automation/33000/how-automation-can-help-digital-transformation"><u>automation</u></a>, threat response, and <a href="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management"><u>vulnerability management</u></a> with a range of data insights. The company’s Cyber Fusion solution integrates SOAR and TIP technology to enable collaboration across siloed security teams. </p><p>The platform is deployed by enterprises, government agencies, and <a href="https://www.itpro.com/security/28879/what-is-an-mssp"><u>MSSPs</u></a> while providing threat intelligence-sharing platforms for the majority of information-sharing and analysis centers (ISACs) around the world.</p><p>With its new partner program, Cyware is now also offering various benefits to its partners, including comprehensive training programs, dedicated support, co-marketing opportunities, and competitive discounts.</p><p>CywareOne has been designed to streamline engagement and opportunity management while facilitating a high level of trust and transparency. </p><p>Ultimately, the aim is to equip partners with the skills and resources to effectively tackle clients’ cyber security issues.</p><p>The company said the program will create a thriving community of partners that are “united by their commitment to excellence”.</p><p>"We designed CywareOne with a clear goal in mind: to facilitate our partners&apos; success," said Amit Patel, SVP of sales at Cyware. </p><p>"We are committed to working collaboratively with our partners to deliver unrivaled cyber security solutions, providing them with the tools they need to excel and differentiate themselves in the market."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Dragos’ new partner program aims to turn resellers into OT experts ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/dragos-new-partner-program-aims-to-turn-resellers-into-ot-experts</link>
                                                                            <description>
                            <![CDATA[ The initiative will help partners fully manage customer deployments with Dragos’ ISC/OT security offerings ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">zdEUBGiYaw3RfS3q2JktJc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/L6DSTHdion3mCrSBkWnF9C-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 14 Jun 2023 11:36:49 +0000</pubDate>                                                                                                                                <updated>Thu, 24 Apr 2025 18:08:28 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/L6DSTHdion3mCrSBkWnF9C-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Dragos: Mockup of a padlock covered in blue and red neon code denoting ransomware, malware, and security]]></media:description>                                                            <media:text><![CDATA[Dragos: Mockup of a padlock covered in blue and red neon code denoting ransomware, malware, and security]]></media:text>
                                <media:title type="plain"><![CDATA[Dragos: Mockup of a padlock covered in blue and red neon code denoting ransomware, malware, and security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/L6DSTHdion3mCrSBkWnF9C-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber security provider Dragos has announced the launch of its new Dragos Global Partner Program, which will enable partners to act as industrial controls systems (ICS) and operational technology (OT) experts and advisors.</p><p>Dragos specializes in cyber security for ICS and <a href="https://www.itpro.com/security/364189/from-it-to-ot-whats-the-partner-opportunity"><u>OT environments</u></a>, providing visibility into ICS/OT assets, <a href="https://www.itpro.com/security/cyber-security/363052/ics-and-ot-vulnerabilities-more-than-doubled-in-2021"><u>vulnerabilities</u></a>, threats, and response actions. </p><p>The firm’s solutions protect organizations across industries such as energy, manufacturing, building automation systems, water, government, food, and more. </p><p>Partners will have access to the Dragos platform for visibility into customer assets, Dragos Professional Services, as well as threat intelligence via the Dragos WorldView offering. Dragos OT Watch also enables managed ICS/OT threat hunts and notification triage, while Neighborhood Keeper provides collective defense.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ZA9hLXndi7rAvoRNaj2ffT" name="IT best practices for accelerating the journey to carbon neutrality_LISTING.jpg" caption="" alt="Whitepaper cover with image of wind turbines and solar farm" src="https://cdn.mos.cms.futurecdn.net/ZA9hLXndi7rAvoRNaj2ffT.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><strong>IT best practices for accelerating the journey to carbon neutrality</strong></p><p class="fancy-box__body-text"><em>Considerations and pragmatic solutions for IT executives driving sustainable IT</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/sustainability/369565/it-best-practices-for-accelerating-the-journey-to-carbon"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Positioned as the only channel program that spans OT, services, and threat intelligence, the initiative provides training to help partners position themselves as specialist advisors able to offer their customers assessment services, resell the Dragos security platform, as well as manage deployment.</p><p>In an announcement, Dragos said partners will be able to offer the full range of ICS/OT cyber security technology and services to increase revenue opportunities and deliver positive results for customers.</p><p>“Market demand for OT cyber security is accelerating as evolving threats, geopolitical dynamics, and regulations shine a spotlight on the need to protect industrial infrastructure,” said Christophe Culine, VP of global sales and CRO at Dragos. </p><p>“With the new Dragos Global Partner Program, we will transfer our knowledge and experience as the industry’s ICS/OT cyber security leader to our channel partners, enabling them to fully manage their customers’ deployments with the industry’s most comprehensive and complete ICS/OT security solution.”</p><p>Partners can access the program’s training via a self-service portal that pulls together automated deal registration, marketing materials, and access to self-paced ICS <a href="https://www.itpro.com/security/28196/the-cybersecurity-skills-your-business-needs"><u>cyber security skills</u></a> training through Dragos Academy training modules.</p><p>There are also market development funds (MDF), including proposal-based MDFs for demand and lead generation, as well as cumulative volume discounts and deal registration with increased margin for identifying opportunities.</p><p>Sean Tufts, practice director of ICS and IoT security at Dragos partner Optiv, said the partner program enables both businesses to achieve joint commercial success.</p><p>“The comprehensive, unparalleled training we get from Dragos and the highly differentiated product offerings allow us to triage and investigate potential incidents for our customers, enabling quicker response and visibility into the breadth and depth of attacks as well as affected devices,” he said. </p><p>“All this allows us to give our customers the confidence that their operational technology and industrial infrastructure are secure, resilient, and compliant.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ MSSPs report a surge in customer demand for dark web intelligence ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/channel/370094/mssps-report-a-surge-in-customer-demand-for-dark-web-intelligence</link>
                                                                            <description>
                            <![CDATA[ Latest research finds that over half of MSSPs in the US and UK are now undertaking dark web monitoring ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jH7itC2pHn6qBmKuKHEnui</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NAEo9aFrDcWStQQY4fKaCC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Feb 2023 11:56:33 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NAEo9aFrDcWStQQY4fKaCC-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A neon blue digital padlock against a black background]]></media:description>                                                            <media:text><![CDATA[A neon blue digital padlock against a black background]]></media:text>
                                <media:title type="plain"><![CDATA[A neon blue digital padlock against a black background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NAEo9aFrDcWStQQY4fKaCC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Dark web intelligence continues to be a hot topic among MSSPs, with the latest research revealing a rapid increase in demand from customers in the US and UK.</p><p>According to the data, around two thirds (65%) of MSSPs said their customers had requested intelligence from the dark web and, among those, 74% said their customers' interest was increasing. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-operations/managed-service-provider-msp/369416/msps-next-biggest-investment-will-be-in-mdr" data-original-url="/business-operations/managed-service-provider-msp/369416/msps-next-biggest-investment-will-be-in-mdr">MSPs' next biggest investment will be in MDR and dark web monitoring</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/32117/what-is-the-dark-web" data-original-url="/security/32117/what-is-the-dark-web">What is the dark web?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28879/what-is-an-mssp" data-original-url="/security/28879/what-is-an-mssp">What is an MSSP?</a></p></div></div><p>This demand is being driven by customers looking to identify vulnerabilities affecting their organisation (39%), to find out whether they are currently being targeted on the dark web (38%), and to gather intelligence on threat groups such as <a href="https://www.itpro.com/security/28084/what-is-ransomware" data-original-url="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> gangs (38%).</p><p>With interest on the rise, a majority of MSSPs have moved to address this customer demand, with more than half (56%) of those surveyed now undertaking dark web monitoring. </p><p>The findings are from dark web security firm Searchlight Cyber, which surveyed more than 500 MSSPs across the US and UK to detail if and how they leverage <a href="https://www.itpro.com/security/32117/what-is-the-dark-web" data-original-url="https://www.itpro.com/security/32117/what-is-the-dark-web">dark web</a> intelligence.</p><p>Ben Jones, CEO and co-founder of the company, praised <a href="https://www.itpro.com/security/28879/what-is-an-mssp" data-original-url="https://www.itpro.com/security/28879/what-is-an-mssp">MSSPs</a> for capitalising on the “rapidly increasing demand” from customers.</p><p>“We see a huge opportunity for MSSPs that are able to integrate dark web intelligence into their services,” he said. “As this topic grows in prominence, those that have started to build out their capabilities, data sources, and understanding will be able to benefit as more customers look for guidance on the dark web, giving them an advantage in the competitive market of managed security services.”</p><p>In terms of its benefits, 37% of surveyed MSSPs said dark web intelligence helps them identify customer details on the dark web, while 35% said it gives them new products and services to sell to customers. 33% revealed that it makes their current services more efficient. </p><p>However, 35% said the main barrier to its adoption was the perceived complexity, while 29% believe it isn’t relevant to their service offering. 18% did not believe they can sell it.</p><p>The findings reinforce <a href="https://www.itpro.com/business-operations/managed-service-provider-msp/369416/msps-next-biggest-investment-will-be-in-mdr" data-original-url="https://www.itpro.com/business-operations/managed-service-provider-msp/369416/msps-next-biggest-investment-will-be-in-mdr">data unearthed from Datto’s <em>Global State of the MSP</em> <em>Report</em></a> in October 2022, which found that dark web monitoring was top of the list of MSP’s next biggest investments, being planned by 30% of respondents.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="x843t8LBGnjwPisTZQURGP" name="x843t8LBGnjwPisTZQURGP.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/x843t8LBGnjwPisTZQURGP.png" mos="https://cdn.mos.cms.futurecdn.net/x843t8LBGnjwPisTZQURGP.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Creating a proactive, risk-aware defence in today's dynamic risk environment</strong></p><p class="fancy-box__body-text">Agile risk management starts with a common language</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/risk-management/370019/creating-a-proactive-risk-aware-defence-in-todays-dynamic" data-original-url="/business-strategy/risk-management/370019/creating-a-proactive-risk-aware-defence-in-todays-dynamic">FREE DOWNLOAD</a></p></div></div><p>Commenting on this latest survey, Matt Hull, global head of threat intelligence at NCC Group, highlighted the importance of understanding how attackers target their victims. </p><p>“As threat actors increasingly publicise and claim responsibility for ransomware attacks, leak breach data, and target executives on hidden sites and forums, there is an increased requirement from organisations to understand how they may be exposed and what they can do to mitigate risk,” he said. </p><p>“Effective and safe research across the dark web requires a degree of skill that is not often present within your average organisation and as such, they are turning to us for help in understanding the threats emanating from the dark web.” </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cloudflare unveils first zero trust SIM for mobile devices ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/369175/cloudflare-unveils-first-zero-trust-sim-for-mobile-devices</link>
                                                                            <description>
                            <![CDATA[ New wireless carrier program will also let carriers integrate Zero Trust security into existing corporate plans ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gPMic2aG5fVpyqkUS1p56L</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9n72AvT5TcQJ8bsYLoUqdE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 27 Sep 2022 09:17:48 +0000</pubDate>                                                                                                                                <updated>Wed, 12 Apr 2023 12:51:59 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9n72AvT5TcQJ8bsYLoUqdE-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A close up of a SIM being placed into a tray slot on a smartphone]]></media:description>                                                            <media:text><![CDATA[A close up of a SIM being placed into a tray slot on a smartphone]]></media:text>
                                <media:title type="plain"><![CDATA[A close up of a SIM being placed into a tray slot on a smartphone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9n72AvT5TcQJ8bsYLoUqdE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cloudflare has announced the development of the Cloudflare Zero Trust SIM, which has been designed to secure every packet of data that leaves a mobile device.</p><p>The first of its kind, the SIM will allow organisations to connect employee devices quickly and securely to Cloudflare’s Global Network, directly integrate devices with the firm’s Zero Trust platform, as well as protect their network and employees.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="tCgzGZNVzmHGYVZhGqErHL" name="tCgzGZNVzmHGYVZhGqErHL.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/tCgzGZNVzmHGYVZhGqErHL.png" mos="https://cdn.mos.cms.futurecdn.net/tCgzGZNVzmHGYVZhGqErHL.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>CIO Priorities: 2020 vs 2023</strong></p><p class="fancy-box__body-text">Zero Trust, SaaS Security, and its impact on SD-WAN being a priority</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/369173/cio-priorities-2020-vs-2023" data-original-url="/security/369173/cio-priorities-2020-vs-2023">FREE DOWNLOAD</a></p></div></div><p>Cloudflare is also launching Zero Trust for Mobile Operators, a new wireless carrier program that will let carriers offer their subscribers comprehensive mobile security tools by tapping into its Zero Trust platform.</p><p>In an announcement, Cloudflare co-founder and CEO Matthew Prince said securing mobile devices at scale is currently one of the biggest issues for CISOs.</p><p>“Effectively securing mobile devices is hard, and we have been working on this problem since we launched our WARP mobile app in 2019, now we plan on going even further,” he said. “With Cloudflare Zero Trust SIM we will offer the only complete solution to secure all of a device’s traffic, helping our customers plug this hole in their Zero Trust security posture.”</p><p>Cloudflare says its Zero Trust SIM will integrate seamlessly with its entire Zero Trust stack, which will allow security policies to be enforced for all traffic leaving the device. That’s on top of its embedded SIM (eSIM) first approach, which allows SIMs to be automatically deployed to both iOS and Android and then locked to a specific device – ultimately mitigating the risk of SIM-swapping attacks.</p><p>Businesses will also be able to deploy the company’s Zero Trust SIM at scale in just minutes, as well as leverage integration with its WARP mobile agent.</p><p>Additionally, Cloudflare says it is developing new tools based on the new SIM, which will extend its connectivity and Zero Trust security perks to the Internet of Things. </p><p>“By combining Cloudflare’s award-winning security tools with the largest mobile networks in the world, businesses can be confident that their devices and data are secure without worrying about performance being impacted,” Cloudflare said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google Cloud unveils new Chronicle MSSP Program ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-computing/367334/google-cloud-unveils-new-chronicle-mssp-program</link>
                                                                            <description>
                            <![CDATA[ Initiative aims to “turbocharge” partners with specialised service offerings via its cloud native SIEM platform ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aKKWUf7VmwMCwn1wuhNZiX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VZRu2qj6nNJz5g2hzREp5K-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 06 Apr 2022 08:43:35 +0000</pubDate>                                                                                                                                <updated>Thu, 24 Apr 2025 18:17:30 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Computing]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VZRu2qj6nNJz5g2hzREp5K-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google Cloud logo on a wooden background with pedestrians walking on a street in front of it]]></media:description>                                                            <media:text><![CDATA[Google Cloud logo on a wooden background with pedestrians walking on a street in front of it]]></media:text>
                                <media:title type="plain"><![CDATA[Google Cloud logo on a wooden background with pedestrians walking on a street in front of it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VZRu2qj6nNJz5g2hzREp5K-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google Cloud has announced a new Chronicle MSSP Program to help Managed Security Service Providers drive customer satisfaction and deliver advanced security capabilities.</p><p>Announcing the move in a blog post, Google said the initiative will offer MSSPs the ability to provide “scalable, differentiated, and effective” detection and response capabilities via its cloud-native Chronicle SIEM offering.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-computing/366980/google-cloud-pricing-increase" data-original-url="/cloud/cloud-computing/366980/google-cloud-pricing-increase">Google Cloud will hike pricing for some storage and data services</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/public-cloud/367014/rightmove-migrates-systems-to-google-cloud" data-original-url="/cloud/public-cloud/367014/rightmove-migrates-systems-to-google-cloud">Rightmove migrates systems to Google Cloud</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/digital-transformation/367196/mizuho-group-rebuild-trust-with-google-cloud" data-original-url="/business-strategy/digital-transformation/367196/mizuho-group-rebuild-trust-with-google-cloud">Troubled Mizuho Group looks to rebuild trust with Google Cloud partnership</a></p></div></div><p>“In a highly competitive environment where customers have little to differentiate between various MSSP providers, we are helping to turbocharge our MSSP partners with specialised services offerings, enabling branded portals and advanced threat detection, investigation, and response capabilities,” explained Sharat Ganesh, Head of Product Marketing at Google Chronicle.</p><p>With the Chronicle MSSP Program, partners will receive more go-to-market tools and support, as well greater controls over margins thanks to its modern licensing model.</p><p>Partners can add their solutions to Chronicle to help make it “unique in the market” and easier to sell, Google says, thanks to branded reporting, unique solutions, as well as advanced threat intelligence.</p><p>As the tech giant looks to stand out in a field that now includes programs from competitors AWS and Microsoft, it also highlighted Chronicle’s key technical differentiators.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="P4x3aTyhBQEcKQEtDASEAC" name="P4x3aTyhBQEcKQEtDASEAC.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/P4x3aTyhBQEcKQEtDASEAC.png" mos="https://cdn.mos.cms.futurecdn.net/P4x3aTyhBQEcKQEtDASEAC.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Microsoft 365 protection made MSPEasy</strong></p><p class="fancy-box__body-text">The cloud protection solution built for MSPs</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/367295/microsoft-365-protection-made-mspeasy" data-original-url="/security/367295/microsoft-365-protection-made-mspeasy">FREE DOWNLOAD</a></p></div></div><p>These include API-driven multi-tenancy to streamline and automate customer management workflows, as well as its ability to “ingest data from any cloud” – even voluminous datasets such as EDR, NDR, and Cloud. Chronicle’s context-aware detections also help to prioritise threats and quickly respond to alerts.</p><p>“Simply put, Google Chronicle will help reduce the MTTR (mean time to respond) for our partners by helping to minimise the need to wait for contextual understanding before making a decision and taking an investigatory action, which can lead to greater customer and cost benefits,” Ganesh added.</p><p>Robert Herjavec, CEO of Herjavec Group and Fishtech Group, said the company was looking forward to helping its customers through the new MSSP program.</p><p>"We are proud to partner with Google Cloud Security to solve functional challenges that exist in security for our customers,” he commented. “As a major partner and a distributor/MSSP, we are excited to leverage this new program, helping our customers and delivering security outcomes"</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Making the jump to become an MSSP ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/367051/making-the-jump-to-become-an-mssp</link>
                                                                            <description>
                            <![CDATA[ What’s driving the demand for managed security services? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uRHoB9z7yE6cD3ERbgFTH9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mCeQ5H8GM4wBRU2ExzwkNn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 09 Feb 2022 11:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jonathan Whitley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mCeQ5H8GM4wBRU2ExzwkNn-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Person jumping through gap between two cliffs]]></media:description>                                                            <media:text><![CDATA[Person jumping through gap between two cliffs]]></media:text>
                                <media:title type="plain"><![CDATA[Person jumping through gap between two cliffs]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mCeQ5H8GM4wBRU2ExzwkNn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>While we all hope for a good year ahead, we can be sure that it’s not going to get any easier or safer for businesses and organisations as cyber threats continue to grow in sophistication and complexity. And as the going gets tougher and the shortage of cyber security skills gets more acute, more companies, particularly SMEs, are turning to their trusted IT solution providers for outsourced support to defend against cyber attacks. Ransomware is what keeps most CISOs awake at night but there is a whole host of old and new attack vectors to lose sleep over. </p><p>The Global Managed Security Services market size is projected to grow from USD 22.8 billion in 2021 to USD 43.7 billion by 2026, according to a report published by<a href="https://www.marketsandmarkets.com/PressReleases/managed-security-services.asp" target="_blank"> MarketsandMarkets</a>. But if you’re a traditional cyber security reseller that wants to embrace the as-a-service opportunity, or if you’re an IT managed service provider (MSP) looking to add the extra S for security, what does it take and what are the things to avoid? </p><h2 id="prevent-detect-respond">Prevent, detect, respond</h2><p>First and foremost, it’s no good offering half the solution. Businesses are looking for a “one-stop-shop” and with a threat landscape that gets scarier by the day, you need a layered approach to managed services that include prevention, detection and response. And it’s not enough to be reactive, relying on signature-based anti-malware solutions, for example. Zero-day protection should not be negotiable. It’s key to certifying all running processes and preventing any program or even lines of code from executing without having been previously certified.</p><p>A complete managed security offering must also include protection for both networks and endpoints along with other services such as Multi-Factor Authentication (MFA) and DNS protection. MFA has traditionally been too costly to implement for SMEs but the cloud has changed that, making it possible to streamline delivery and simplify operations. Users can be added or removed and passwords changed with just a few clicks and without the need for time-consuming and costly site visits. A cloud-based management system can centralise a ton of previously arduous configuration, deployment, and management tasks through a single pane of glass, and help maintain a strong network performance and security posture at scale. And the more offerings you can adopt from a single source, while ensuring that customers get the services they need, the easier it is to keep your total vendor and hassle count down.</p><h2 id="20-20-vision">20/20 vision </h2><p>As IT infrastructures grow in size and complexity, granular visibility into activity across them is crucial, to recognise patterns, threats, and security gaps, and to respond before damage occurs. Some SMEs don’t even know what resources are being consumed by whom, where they reside, and how they interact. </p><p>The problem is that many network platforms deliver large volumes of data, but with little clarity and ranking. If you’re managing multiple companies with multiple sites, it becomes essential to have a clear insight that provides actionable data to quickly and effectively identify, prioritise, investigate, resolve, and report multiple issues. From a remote network admin standpoint, actionable data is about tracking the top users, destinations, applications, domains, and includes things like the top blocked botnet sites, intrusion preventions, advanced malware attack attempts, and blocked malicious destinations.</p><p>With this level of granularity, you can see what’s going on in your customers’ networks and endpoints in real-time, from anywhere. Making sense of all this and actioning the appropriate response requires the MSP to have skilled security professionals. However, advances around AI and machine learning algorithms are increasing threat detection automation, classification of running processes, and prioritisation of alerts. </p><h2 id="flexible-pricing-and-billing">Flexible pricing and billing</h2><p>For traditional resellers, the idea of recurring revenues is one of the great attractions as well as one of the biggest barriers to becoming an MSSP. Consumption-based billing is a major shift from customer billing models but should be a win-win for MSSPs and their customers. The best way to avoid complexity is for vendors to offer flexible pricing models, which could include fixed-term contracts paid upfront or monthly, pay-as-you-go setups, or pre-pay points, all with the ability to scale up and down instantly to meet changing requirements.</p><p>Another aspect to think about is the human touch. Humans are still the weakest link with most breaches starting with a simple click on a malicious link or document. This means that education remains a critical component of an effectively managed security programme. Without an understanding of how attacks happen and a commitment to behaviours and processes that reduce their likelihood, businesses are left exposed.</p><p>Managing IT security can feel like a mountain to climb – that just keeps getting higher. And now, as employees slowly head back to the office, cloud deployment using automation can eliminate many of the on-site headaches involved in setting up and managing customer sites. Having been through the era of Unified Threat Management (UTM) solutions, we’re seeing the emergence of a new Unified Security Platform, that lives in the cloud and gives centralised access to end-to-end security services from the network to the endpoint. It’s these new USPs that will enable and empower a new generation of MSSPs. </p><p><em>Jonathan Whitley is vice president for Northern Europe at WatchGuard Technologies</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ McAfee’s zero trust solution strengthens private applications’ security ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/360465/mcafees-zero-trust-solution-strengthens-private-applications</link>
                                                                            <description>
                            <![CDATA[ MVISION Private Access grants secure access to private resources from any device or location ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iB2ATANbSMFr4uciF1vzY3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hi7t87AjBop3kGL36UuQDF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 03 Aug 2021 17:42:41 +0000</pubDate>                                                                                                                                <updated>Wed, 12 Apr 2023 12:54:25 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Praharsha Anand ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hi7t87AjBop3kGL36UuQDF-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The McAfee company logo hung above the entrance to company offices]]></media:description>                                                            <media:text><![CDATA[The McAfee company logo hung above the entrance to company offices]]></media:text>
                                <media:title type="plain"><![CDATA[The McAfee company logo hung above the entrance to company offices]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hi7t87AjBop3kGL36UuQDF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>McAfee has launched MVISION Private Access to safeguard private applications deployed across hybrid IT environments.</p><p>“As private applications increasingly move to the <a href="https://www.itpro.com/cloud" data-original-url="https://www.itpro.com/tags/cloud">cloud</a>, organizations are rapidly adopting Zero Trust Network Access due to its <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> and flexibility advantages compared to VPN,” explained Christopher Rodriguez, research director at IDC Network Security. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/antivirus/359674/mcafee-to-refund-customers-following-cma-investigation" data-original-url="/security/antivirus/359674/mcafee-to-refund-customers-following-cma-investigation">McAfee to refund customers following CMA auto-renew probe</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/mergers-and-acquisitions/358810/mcafee-to-sell-enterprise-business-to-stg-for" data-original-url="/business-strategy/mergers-and-acquisitions/358810/mcafee-to-sell-enterprise-business-to-stg-for">McAfee to sell enterprise business to STG for £2.8 billion</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/357669/mcafee-75-million-attacks-on-cloud-accounts-recorded-in-q2" data-original-url="/security/357669/mcafee-75-million-attacks-on-cloud-accounts-recorded-in-q2">McAfee: 7.5 million attacks on cloud accounts recorded in Q2</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/357270/mcafee-files-to-go-public-in-sec-submission" data-original-url="/business/business-strategy/357270/mcafee-files-to-go-public-in-sec-submission">McAfee files to go public in SEC submission</a></p></div></div><p>“However, organizations need to recognize that private applications are just as likely to pose a data theft risk as SaaS apps, and that this risk needs to be mitigated.”</p><p>Upending the zero trust network access (ZTNA) arena, McAfee’s MVISION Private Access offers “granular zero trust" access to private applications hosted in private, public, or <a href="https://www.itpro.com/cloud/hybrid-cloud/357216/hybrid-cloud-the-new-architecture-for-todays-business" data-original-url="https://www.itpro.com/cloud/hybrid-cloud/357216/hybrid-cloud-the-new-architecture-for-todays-business">hybrid cloud</a> environments. </p><p>By leveraging McAfee’s <a href="https://www.itpro.com/security/28968/the-importance-of-endpoint-security" data-original-url="https://www.itpro.com/security/28968/the-importance-of-endpoint-security">Endpoint Security</a> for threat detection and remediation, the platform performs continuous risk assessment by monitoring device posture. Furthermore, MVISION Private Access is integrated with MVISION Unified Cloud Edge (UCE), enabling unified visibility and control across clouds, private applications, web, and endpoints.</p><p>MVISION Private Access’s other interesting features include remote browser isolation (RBI), granular controls for unmanaged devices, endpoint security and posture assessment, direct-to-app access, and more.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="4BCvbZowg9SJqNeQxYKsxk" name="4BCvbZowg9SJqNeQxYKsxk.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/4BCvbZowg9SJqNeQxYKsxk.jpg" mos="https://cdn.mos.cms.futurecdn.net/4BCvbZowg9SJqNeQxYKsxk.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>2021 IBM Security X-Force Insider Threat Report</strong></p><p class="fancy-box__body-text">Top discovery methods and recommendations for insider attacks</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/360176/2021-ibm-security-x-force-insider-threat-report" data-original-url="/security/cyber-security/360176/2021-ibm-security-x-force-insider-threat-report">FREE DOWNLOAD</a></p></div></div><p>Lastly, MVISION Private Access includes built-in identity and access management (IAM) and <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" data-original-url="https://www.itpro.com/security/29982/what-is-two-factor-authentication">multi-factor authentication (MFA)</a> solutions, enabling strong authentication and context-based access control. </p><p>“ZTNA is built for cloud-first deployments, simplifying technology stacks, reducing cost and complexity, and improving productivity. However, existing ZTNA solutions lack the data-centric security controls associated with cloud and web security needed to secure today’s increasing remote connections,” said Shishir Singh, chief product officer at McAfee Enterprise. </p><p>Singh added, “MVISION Private Access unlocks secure, seamless and ultra-fast access to private applications for remote workforces and eliminates the additional <a href="https://www.itpro.com/hardware" data-original-url="https://www.itpro.com/hardware">hardware</a> costs, time-consuming setup process and complicated architecture associated with traditional <a href="https://www.itpro.com/security/27098/best-vpn-services" data-original-url="https://www.itpro.com/security/27098/best-vpn-services">VPN</a>s.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Blok launches as UK's first MSSP for micro businesses, self employed ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/365766/blok-launches-as-uks-first-mssp-for-micro-businesses-self-employed</link>
                                                                            <description>
                            <![CDATA[ Company will offer endpoint protection, detection and response, and cloud security to the country's smallest firms ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8fwQJqhL26VKQHrmiH8WxB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NAEo9aFrDcWStQQY4fKaCC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 May 2021 11:04:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NAEo9aFrDcWStQQY4fKaCC-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A neon blue digital padlock against a black background]]></media:description>                                                            <media:text><![CDATA[A neon blue digital padlock against a black background]]></media:text>
                                <media:title type="plain"><![CDATA[A neon blue digital padlock against a black background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NAEo9aFrDcWStQQY4fKaCC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Blok has officially launched to become the UK’s first managed cyber security service provider dedicated to small businesses and the self-employed.</p><p>The Leeds-based firm aims to tackle cyber criminals targeting sole traders, start-ups, and businesses with 49 employees or less.</p><p>As much as 38% of micro and small businesses reported at least one breach or attack in the last twelve months, with 27% hit at least once a week, according to the Government’s Cyber Security Breaches Survey 2021.</p><p>Where a breach has resulted in a loss of data or assets, the average cost of these attacks for micro and small businesses is £8,170, the research found.</p><p>To help tackle this, Blok is offering a range of cyber security subscription packages which are managed by a support team available 365 days a year. These include comprehensive endpoint protection, detection and response, as well as cloud security, malware defence, identity protection, network and perimeter security, plus technical support and training.</p><p>“We have launched Blok as we found that, although there is lots of advice, there was no organisation dedicated to providing managed security services specifically for small businesses and the self-employed,” explained Neil Peacock, co-founder of Blok.</p><p>“Drawing on our experience, knowledge and utilising industry-leading technologies, Blok is taking on the cyber criminals and making it easier and affordable for our clients to help protect their business and reputation.”</p><p>Based in Leeds, Blok has been founded by Peacock alongside business start-up expert Helen Phelan. A Certified Information Systems Security Professional (CISSP), Peacock brings more than 20 years’ experience in the information and cyber security industry, as well as experience in auditing and providing solutions to protect small and medium businesses.</p><p>Phelan joins a pool of just eight percent of cyber security professionals in the UK who are women, and ten percent of females across the world that hold management positions in the industry.</p><p>Drawing on her vast experience of successfully launching and establishing businesses, she will be responsible for operations at Blok, the firm said, including finances, business development plans, recruitment and marketing activity.</p><p>“There is a real lack of female representation in the cyber security industry,” Phelan commented. “I am excited to launch Blok and join a growing number of women breaking the cyber security glass ceiling.</p><p>“Having a more diverse team means we are better placed to engage with our clients and provide the service they need.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Four key benefits Zero Trust can bring to your channel firm ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/366925/four-key-benefits-zero-trust-can-bring-to-your-channel-firm</link>
                                                                            <description>
                            <![CDATA[ Clients need strategic partners rather than those who just throw buzzwords into their sales pitches, claims Scott Walker ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6KJstJBZjBgXR6LZBye3nu</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GXPUCybF5xfZTNWiRCeNu9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 28 Apr 2021 13:10:03 +0000</pubDate>                                                                                                                                <updated>Wed, 12 Apr 2023 12:50:40 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Scott Walker ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GXPUCybF5xfZTNWiRCeNu9-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Abstract visualisation of padlock icon]]></media:description>                                                            <media:text><![CDATA[Abstract visualisation of padlock icon]]></media:text>
                                <media:title type="plain"><![CDATA[Abstract visualisation of padlock icon]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GXPUCybF5xfZTNWiRCeNu9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The IT industry has long had a problem with buzzwords, with marketing teams latching onto the latest trends and using them to push their products as ‘the next big thing’. It’s even more pronounced in cyber security, where buzzwords can be backed up with a dose of fear, uncertainty, and doubt over new threats.</p><p>As a result, it can be difficult for buyers to parse the genuinely valuable solutions from those that simply have the latest buzzwords thrown into their sales pitches. This makes it more challenging for partners to decide which solutions to bring into their portfolio and can also make it more difficult for them to cut through the noise and sell successfully. </p><p>Zero Trust is one such trend, providing increased assurance that only trusted identities are able to access critical networks, systems and data. It’s become particularly beneficial as organisations must now deal with a largely remote workforce that falls outside the scope of normal processes.</p><p>However, there are a few barriers to implementing this model that may have some organisations holding back. Nevertheless, there's a real opportunity for channel firms in adding Zero Trust to their portfolio. While Zero Trust is time and resource-intensive, the value that it adds can make taking the plunge more worthwhile. Based on our experience with our growing channel community, here are four real-world outcomes partners can achieve if they invest in Zero Trust. </p><h3 class="article-body__section" id="section-establishing-strategic-value"><span>Establishing strategic value</span></h3><p>Partners should be striving to create strong, long-term strategic relationships with their clients rather than simply selling products on a transactional basis. Establishing a role as a trusted adviser can vastly improve customer retention and the lifetime value of a customer. </p><p>Zero Trust is ideally suited for forging or strengthening this relationship. Partners have an opportunity to play a major role in the delivery of the Zero Trust model, which will impact the wider security strategy, providing further opportunity to establish their credibility as a trusted adviser and deliver more value. </p><h3 class="article-body__section" id="section-increasing-the-share-of-income"><span>Increasing the share of income</span></h3><p>Zero Trust is not a specific, singular product, but a framework incorporating technology across five main areas: people, data, devices, networks, and workloads. All of these areas are supported by a process of continual improvement that delivers visibility and automation. </p><p>This means that helping to deliver a Zero Trust model creates a huge opportunity to influence and support the wider security strategy of the organisation. Partners with the right services and solutions can significantly increase their share of wallet by providing all the products and services the customer needs to continue on their Zero Trust journey. </p><h3 class="article-body__section" id="section-establishing-39-ztaas-39"><span>Establishing 'ZTaaS'</span></h3><p>Zero Trust is not a “one and done” type of solution that can be delivered and signed off but is a project of continual improvement. Because it spans multiple pillars of technology, channel partners can establish an MSP agreement that delivers service engagements across their portfolio. </p><p>A Zero Trust as a service (ZTaaS) package will both provide the partner with multiple, repeatable streams of revenue, and ensure that the customer has access to best of breed, marketing leading solutions. </p><h3 class="article-body__section" id="section-safeguarding-gross-product-margins"><span>Safeguarding gross product margins</span></h3><p>Achieving and maintaining high gross product margins is always a challenge when rivals are offering competing bids offering like-for-like comparison or undercutting on price. </p><p>The powerful differentiator created by becoming an established, strategic adviser ensures that channel partners are shielded against competing bids that are sold on price alone. The more involved a partner is in the Zero Trust project, the more strategic and financial sense it will make for the customer to expand the existing relationship rather than explore competing bids. </p><h3 class="article-body__section" id="section-seizing-the-opportunity"><span>Seizing the opportunity</span></h3><p>Zero Trust has a huge potential global market, with the majority of security teams planning to adopt the model in future, and many already implementing a framework. Business needs have, of course, changed drastically in recent months due to COVID-19, and the model’s ability to manage user authentication has become more important for dealing with remote workforces. </p><p>Organisations need strategic partners that can genuinely deliver the technology, services and expertise needed to implement a successful Zero Trust model, rather than those that are simply throwing the latest buzzwords into their sales pitches. Partners equipped to meet these needs have a powerful opportunity to create and maintain highly valued and long-lasting strategic relationships.</p><p><em>Scott Walker is senior director for channel and alliances for EMEA at Illumio</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Secureworks adds XDR to security analytics platform and MSSP scheme ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/365642/secureworks-adds-xdr-to-security-analytics-platform-and-mssp-scheme</link>
                                                                            <description>
                            <![CDATA[ Taegis XDR aims to protect users from threats that exploit vulnerabilities in the supply chain ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">afDMPfPJGsW2Jrij9ekaGu</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/3MGAZUpHZnhbVREdhNXuZ4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 10 Feb 2021 10:13:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/3MGAZUpHZnhbVREdhNXuZ4-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A light blue padlock, closed, set in a light blue circle on a dark blue-black background]]></media:description>                                                            <media:text><![CDATA[A light blue padlock, closed, set in a light blue circle on a dark blue-black background]]></media:text>
                                <media:title type="plain"><![CDATA[A light blue padlock, closed, set in a light blue circle on a dark blue-black background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/3MGAZUpHZnhbVREdhNXuZ4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber security provider <a href="https://www.channelpro.co.uk/news/security/1549/secureworks-expands-uk-footprint-dns-acquisition" target="_blank">Secureworks</a> has lifted the lid on its new security analytics platform Secureworks Taegis XDR, as well as the addition of a new global MSSP initiative to its Global Partner Programme. </p><p>With extended threat detection and response (XDR), the new Taegis XDR offering aims to protect users from threats that exploit gaps in point solutions and <a href="https://www.channelpro.co.uk/security" target="_blank">vulnerabilities</a> in the supply chain, the firm says.</p><p>A cloud-native <a href="https://www.channelpro.co.uk/advice/9047/software-as-a-service-a-quick-guide" target="_blank">SaaS</a> solution, it bundles together Secureworks’ security operations expertise with its threat intelligence capabilities to detect and respond to attacks across cloud, endpoint and network environments. </p><p>The platform also helps infoSec teams bridge their cyber security skills gaps while reducing costs where security blind spots previously existed, Secureworks added. </p><p>“When we first began developing Taegis, our original vision on where the market would go aligns squarely with what is now considered an XDR solution,” explained Steve Fulton, chief product officer at Secureworks. “We built a cloud-native security analytics platform and detection & response application—now officially Taegis XDR—from the ground up, with that vision in mind. </p><p>“XDR wasn’t an afterthought for us, or a label we decided to put on a point-product. It was the fundamental design-principle and architecture from where we started.”</p><p>The provider has also launched a new MSSP track within its Secureworks Global Partner Programme, aimed at <a href="https://www.channelpro.co.uk/opinion/11415/why-msps-and-mssps-must-partner-on-security-not-compete" target="_blank">both MSPs and MSSPs</a>.</p><p>Leveraging the firm’s 20-plus years’ experience as an MSSP itself, the programme enables partners to deliver services on the Taegis platform to create additional revenue streams and service offerings to protect customer growth, as well as tackle difficult threats together.</p><p>The initiative offers access to the Secureworks Taegis security platform, which includes financial incentives, a defined enablement path, an assigned partner access manager, as well as dedicated partner support. </p><p>It also provides security operations centre (SOC) development for MSSPs, as well as training and enablement for delivering Taegis XDR, Tageis VDR and premium onboarding services. Additionally, there are financial incentives for partners - such as deal registration discounts and access to marketing development funds.</p><p>Secureworks said it is currently working with four geographically dispersed partners in the programme’s initial phase - including Globe Business, the enterprise arm of Globe Telecom.</p><p>“Globe and Secureworks believe cybersecurity should be supported by a community, as the battle can’t be won by one team alone,” commented Peter Maquera, senior vice president at Globe Business. “Secureworks has enabled us to not only bridge businesses to cybersecurity experts and cyber threat intelligence, but also provide predictive, continuous, and responsive protection.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why now's the time to evolve from MSP to MSSP ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business-operations/managed-service-provider-msp/366813/why-nows-the-time-to-evolve-from-msp-to</link>
                                                                            <description>
                            <![CDATA[ Becoming an MSSP can provide scope for growing revenues at a time where smaller businesses are under pressure from security threats ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wabXT1XWrHRmEfoNtN5MFE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VVDPQE6dQrrfANikzggncS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 29 Jul 2020 12:08:00 +0000</pubDate>                                                                                                                                <updated>Wed, 29 Jul 2020 12:08:57 +0000</updated>
                                                                                                                                            <category><![CDATA[Digital Transformation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jeremy Hendy  ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VVDPQE6dQrrfANikzggncS-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Time for change clockwatch]]></media:description>                                                            <media:text><![CDATA[Time for change clockwatch]]></media:text>
                                <media:title type="plain"><![CDATA[Time for change clockwatch]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VVDPQE6dQrrfANikzggncS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The role of the <a href="https://www.channelpro.co.uk/advice/11483/msps-in-cybercriminals-crosshairs" target="_blank">Managed Service Provider (MSP)</a> is constantly evolving, as businesses seek support from their partners to navigate new challenges. As digital risks continue to increase, cybersecurity is one key area where there is rising demand from businesses for specialist support services from external providers.</p><p>It’s an area which offers significant scope for MSPs to support those businesses – and particularly resource-strapped SMBs – that are less likely to have the technology or skills in-house to block or defend against cyber attacks. The services of an outsourced provider are critical to protecting their business from the fallout of a security incident. Early breach detection is vital and more advanced threat intelligence and breach detection services are enabling MSPs to play a crucial role in identifying and mitigating threats wherever they emerge.</p><p>Making the transition to Managed Security Service Provider (MSSP) can add value to your offering and provides scope for growing revenue and strengthening client relationships, at a time when the threats businesses face are increasing in both scale and sophistication.</p><h3 class="article-body__section" id="section-outsourcing-security"><span>Outsourcing security</span></h3><p><a href="https://www.infosecurity-magazine.com/news/cyberattacks-uk-orgs-up-30-q1">Research suggests</a> the volume of incoming cyber attacks businesses faced in the first quarter of the year was roughly 30% higher than during the same period for 2019. The situation has clearly been exacerbated by COVID-19, creating more challenges for firms seeking to stay secure. Criminals are exploiting the crisis with deceptive emails and phishing sites, preying on the security vulnerabilities that make the remote workforce an easier target. </p><p>Innovation continues to make cyber attacks easier and at volume. As a result, criminals are turning their attention to smaller businesses, hoping they might represent ripe opportunities. It isn’t difficult to see why the cyber risks facing SMBs are considerable, with the latest platforms and dedicated, in-house security specialists, often beyond the budgets of the smallest companies.</p><p>Outsourcing security to a managed service provider offers clear advantages for businesses that simply cannot deal with all the threats they face on their own. Our own research with IT and security decision makers shows that more than half of businesses are now using either totally or partially outsourced services to manage their cyber security needs, and value the expertise of external providers on security decisions. In fact, advice from security resellers, consultants or partners is the preferred way for IT and security professionals to find out about new cybersecurity technology. </p><h3 class="article-body__section" id="section-the-value-of-early-warnings"><span>The value of early warnings</span></h3><p>There is significant scope for MSPs to add value to their offering and help SMBs plug their security gaps with affordable service-based solutions that provide protection against digital risks. The latest services to identify and mitigate threats wherever they emerge, including the dark web, play a vital role in helping businesses to reduce the threat landscape. Monitoring the internet for early warning signs of an attack provides clients with the best chance of taking action to prevent loss of data or business downtime. Threat intelligence can now monitor a variety of sources; scraping data from open sources such as social media or forums on the dark web that can shed light on threats in advance. They can also reveal discussions about the company, including negative chatter that may point to a security risk.</p><p>Such systems can also be used to discover when data has already been leaked or breached. This could include company data that was stolen in a previous breach that went undiscovered, or data that was stolen from a third party such as a supplier or partner. Data leaked or lost due to human error can also be found, if it ends up in the wrong place. </p><p>Understanding the threats to businesses data that exist outside the network gives vital intel which can be used to defend against attackers on a direct, tactical level. It also provides powerful insights for long-term strategic decision making. With the right intelligence, businesses can better invest in their defences to reduce risk in the future. </p><p>New threat intelligence and breach detection services are democratising security by making it affordable and accessible to businesses of all sizes. As with the ongoing impact of coronavirus on security challenges, there’s likely to be increased demand from SMBs for this outsourced expertise to keep their businesses secure, as the level of cyber threat continues to rise. MSPs able to meet this demand will be well-placed to both better support their existing customers, and expand their customer base, providing services to help them survive the risks of the current crisis, and beyond. </p><p><em>Jeremy Hendy is CEO of Skurio</em> <a href="https://skurio.com"></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is an MSSP? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/28879/what-is-an-mssp</link>
                                                                            <description>
                            <![CDATA[ Why appointing an MSSP is becoming the norm for SMBs ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8y3sBo9TBqYjsU9nftpRZY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pXCbVvNzHjKfG3wFAC6vS9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 22 Aug 2019 10:50:00 +0000</pubDate>                                                                                                                                <updated>Fri, 31 Oct 2025 14:14:57 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Rene Millman) ]]></author>                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pXCbVvNzHjKfG3wFAC6vS9-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Female IT programmer working on a desktop computer in data centre]]></media:description>                                                            <media:text><![CDATA[Female IT programmer working on a desktop computer in data centre]]></media:text>
                                <media:title type="plain"><![CDATA[Female IT programmer working on a desktop computer in data centre]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pXCbVvNzHjKfG3wFAC6vS9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The frequency and complexity of cyber attacks continue to escalate, creating a challenging environment for organizations of all sizes. In 2025, cybersecurity<a href="https://www.itpro.com/uk/security"><u> </u></a>is dominated by advanced threats, including AI-powered <a href="https://www.itpro.com/security/29093/what-is-phishing"><u>phishing</u></a>, adaptive malware, and relentless <a href="https://www.itpro.com/security/28084/what-is-ransomware"><u>ransomware </u></a>campaigns. Cybercriminals are leveraging artificial intelligence to automate and personalize attacks, making them harder to detect and more effective at bypassing traditional security measures. For example, <a href="https://www.rapid7.com/blog/post/emerging-trends-in-ai-related-cyberthreats-in-2025-impacts-on-organizational-cybersecurity/"><u>AI-driven phishing</u></a> can now tailor messages to mimic trusted contacts and adapt to avoid detection, while AI-powered malware evolves in real time to evade defenses.</p><p>Recent data underscores the severity of this trend: ransomware attacks are surging, with a notable 84% increase in ransomware incidents over the previous year, and ransomware now accounts<a href="https://www.sentinelone.com/cybersecurity-101/cybersecurity/cyber-security-statistics/"><u> </u></a>for 35% of all cyberattacks in 2025. The<a href="https://www.ibm.com/reports/data-breach"><u> global average cost of a data breach reached an all-time high of $4.88 million in 2024</u></a>, a 10% increase from the prior year. This intensification of threats is further amplified by the rapid adoption of AI by both cybercriminals and state-sponsored actors, who use it to automate reconnaissance, exploit vulnerabilities, and conduct large-scale social engineering attacks.</p><p>For many businesses, especially small and mid-sized organizations, effectively managing security in-house is an increasingly daunting challenge. This difficulty is compounded by a persistent cybersecurity skills gap, with an <a href="https://www.isc2.org/Insights/2024/09/Employers-Must-Act-Cybersecurity-Workforce-Growth-Stalls-as-Skills-Gaps-Widen"><u>estimated 4.8 million person shortage</u></a> in the industry. </p><p>The struggle to keep pace with evolving threats and a lack of specialized talent has made the services of a Managed Security Service Provider (MSSP) more critical than ever. The <a href="https://www.thebrainyinsights.com/report/managed-security-services-market-12638#:~:text=Market%20Introduction,propel%20the%20MSS%20industry%20forward."><u>global market for managed security services is projected to reach nearly $76 billion by 2030</u></a>, reflecting a growing reliance on outsourced expertise to build cyber resilience. An MSSP offers the specialized knowledge and continuous monitoring necessary to protect vital infrastructure, allowing internal teams to focus on core business objectives.</p><h3 class="article-body__section" id="section-what-is-an-mssp"><span>What is an MSSP?</span></h3><p>MSSPs are specialized third-party providers that deliver outsourced cybersecurity services. They handle the security operations for an organization, either in part or in full, and can do so from a remote location or by placing experts on-site.</p><p>An MSSP may offer a broad suite of security capabilities or specialize in core focus areas like <a href="https://www.itpro.com/uk/cloud"><u>cloud </u></a>security or compliance. The majority, however, will manage a business's security infrastructure and monitor systems for threats from their own Security Operations Centers (SOCs). To do this, they implement and manage a sophisticated technology stack that goes far beyond basic <a href="https://www.itpro.com/antivirus/28144/best-antivirus"><u>antivirus </u></a>software. Common tools include Security Information and Event Management (SIEM) platforms, Managed Detection and Response (MDR) services, <a href="https://www.itpro.com/security/27098/best-vpn-services"><u>VPN </u></a>management, and advanced firewall management.</p><p>Ongoing responsibilities also include system upgrades, patch management, and configuration changes, ensuring a client's security posture continuously adapts to new threats and business demands.</p><h3 class="article-body__section" id="section-services-an-mssp-can-provide"><span>Services an MSSP can provide</span></h3><p>MSSPs offer a comprehensive suite of services designed to protect organizations before, during, and after a cyber attack. Proactively, their primary goal is to harden the IT infrastructure and enforce robust security policies to minimize the attack surface. This includes vulnerability assessments, penetration testing, and ensuring systems are configured securely.</p><p>Should an attack occur, an MSSP's role shifts to rapid detection and response. Using advanced security monitoring tools, they can identify threats in real time and take immediate action to neutralize them, preventing or limiting damage to the organization's systems.</p><p>Because MSSPs serve numerous clients, they accumulate a vast amount of experience dealing with a wide variety of attacks. This broad visibility allows them to understand emerging threat patterns and containment strategies. They leverage this collective knowledge to continuously refine and strengthen your security posture.</p><p>Typical services provided by an MSSP include:</p><ul><li><strong>Security infrastructure management:</strong> Implementing and managing firewalls, intrusion detection and prevention systems (IDPS), and other security hardware and software.</li><li><strong>24/7 monitoring and threat detection:</strong> Continuously monitoring networks, systems, and applications for suspicious activity from a Security Operations Center (SOC).</li><li><strong>Vulnerability management:</strong> Regularly scanning for and remediating vulnerabilities in your systems through patching and configuration updates.</li><li><strong>Incident response and remediation:</strong> Developing and executing a plan to contain threats, eradicate them from the network, and <a href="https://www.itpro.com/storage/29803/best-backup-software"><u>recover affected systems</u></a>.</li><li><strong>Security information and event management (SIEM):</strong> Aggregating and analyzing log data from various sources to detect patterns indicative of a cyber attack.</li><li><strong>Compliance management:</strong> Assisting organizations in meeting regulatory requirements such as GDPR, HIPAA, or PCI DSS.</li></ul><p>For a small to medium-sized business (SMB), a good MSSP functions as a seamless extension of the firm's own IT employees, providing specialized expertise that would be difficult and expensive to build in-house.</p><h3 class="article-body__section" id="section-why-use-an-mssp"><span>Why use an MSSP?</span></h3><p>For organizations seeking to alleviate the stress and complexity of building and maintaining robust security infrastructure, partnering with an MSSP is often the optimal choice. An MSSP not only relieves internal IT teams of the bulk of routine security tasks, such as daily threat monitoring and incident response, but also assumes responsibility for maintaining uptime, managing upgrades, and ensuring swift remediation in the event of a breach.</p><p>While some organizations may develop and execute their own security strategies, from deploying necessary software and training staff to allocating adequate resources, this approach can prove overwhelming, particularly for smaller IT teams. In such cases, outsourcing to an MSSP becomes a compelling solution.</p><p>SMBs frequently lack the specialized expertise required to manage a comprehensive security infrastructure independently. Even with strong commitment and resource allocation, the demands of security maintenance can quickly exceed the capacity of limited teams. This strain can result in critical IT functions, like system patching, hardware management, and digital transformation initiatives, receiving insufficient attention. The rise of <a href="https://www.itpro.com/security/357935/top-security-tips-for-employees-working-from-home"><u>remote work</u></a> only compounds these challenges by introducing additional layers of complexity.</p><p>The evolving cybersecurity landscape further complicates matters. Smaller teams may struggle to respond effectively to the full spectrum of threats, especially as cyberattacks become more sophisticated. While in-house staff can handle some known risks, an MSSP provides specialized expertise and round-the-clock monitoring, offering a crucial layer of protection and peace of mind. Leading MSSPs bring a depth of knowledge that is difficult to cultivate internally, with dedicated teams that continuously monitor emerging threats, assess IT environments, and provide actionable recommendations. They also deliver support services, keeping all business units informed and engaged.</p><p>Partnering with an MSSP also addresses the persistent challenge of talent acquisition. Many <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do"><u>CISOs </u></a>report increasing difficulty in recruiting and retaining skilled security professionals, a problem that is especially acute for smaller firms or those located outside major urban centers. MSSPs offer immediate access to a pool of experienced security specialists, eliminating recruitment headaches and ensuring continuous protection.</p><p>MSSPs provide a comprehensive suite of security services delivered remotely, and their pricing models are typically designed to accommodate financial constraints. Most providers charge a predictable, flat monthly fee, enabling businesses to budget effectively and avoid unexpected expenses.</p><p>As technology evolves, MSSPs ensure that security measures scale and adapt alongside your business. Through regular assessments and audits, they deliver strategic insights and recommendations, allowing organizations to focus on core business objectives without compromising security.</p><p>MSSPs can operate either on-site or <a href="https://www.itpro.com/business/business-strategy/356096/remote-working-are-you-ready-for-the-new-normal"><u>remotely</u></a>, but in either scenario, they integrate seamlessly with existing IT teams. This collaboration frees internal staff to concentrate on innovation and other strategic projects, rather than being consumed by security incidents. Ultimately, MSSPs help enhance customer experiences by improving response times and boosting satisfaction.</p><p>By partnering with an MSSP, organizations can overcome resource limitations, access specialized expertise, and achieve scalable, cost-effective security, all while enabling their internal teams to focus on driving business growth.</p><h3 class="article-body__section" id="section-msp-vs-mssp"><span>MSP vs MSSP</span></h3><p>A <a href="https://www.itpro.com/business-operations/31711/what-is-a-managed-it-service"><u>managed service provider </u></a>(MSP) offers a broad range of IT management services, such as network support, application management, system administration, and email management, typically delivered to multiple clients on a recurring, pay-as-you-go basis. While MSPs are essential for maintaining smooth business operations and IT efficiency, their security offerings are generally limited to baseline protections like routine monitoring and patch management.</p><p>In contrast, an MSSP specializes exclusively in cybersecurity, delivering advanced, round-the-clock services such as threat detection, incident response, and compliance monitoring from a dedicated security operations center (SOC). MSSPs are well-positioned to serve as strategic security partners for organizations seeking robust protection as cyber threats grow in both frequency and sophistication.</p><p>As the threat landscape evolves, MSPs that do not expand their security capabilities risk losing business to those that do, or to MSSPs that offer more comprehensive protection. While it is possible for an MSP to transition into an MSSP by enhancing its security offerings, such as adding antivirus, patch management, and web protection, delivering true, enterprise-grade cybersecurity requires specialized expertise, tools, and continuous monitoring that are the hallmark of an MSSP.</p><p>Many MSPs now partner with MSSPs to provide their clients with the best of both worlds: efficient IT management and advanced security. This dual approach ensures organizations can maintain operational efficiency while safeguarding their critical assets from ever-evolving threats.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why MSPs and MSSPs must partner on security, not compete ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business-operations/managed-service-provider-msp/366623/why-msps-and-mssps-must-partner-on-security</link>
                                                                            <description>
                            <![CDATA[ Radical changes across industries mean both parties stand to gain by joining forces, despite some overlap ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pLjhiP4Wpn7T8vM6bSTunt</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PHRbXgcTTmpDqJH8NGUQAA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 03 Jul 2019 09:00:27 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Digital Transformation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tim Brown ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PHRbXgcTTmpDqJH8NGUQAA-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Managed security service provider man in suit behind virtual icons]]></media:description>                                                            <media:text><![CDATA[Managed security service provider man in suit behind virtual icons]]></media:text>
                                <media:title type="plain"><![CDATA[Managed security service provider man in suit behind virtual icons]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PHRbXgcTTmpDqJH8NGUQAA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In a business world increasingly dominated by IT, the demand for <a href="https://www.channelpro.co.uk/tags/msps" target="_blank">managed services providers (MSPs)</a> is showing no signs of slowing down. While many companies, large and small, seek the skills and support that MSPs offer, however, the role that MSPs need to play today is significantly changing.</p><p>The days of MSPs simply managing office devices and hardware are long gone. Innovations in enterprise computing and the rise of remote working are transforming business IT. While they are delivering major benefits for businesses, they are also creating new security risks and vulnerabilities.</p><p>For every business, security has risen to the top of the agenda, with data being the most important asset. Understandably, ambitious MSPs might be tempted to step up to the plate and offer security services on top of their existing services to maximise the new opportunity. After all, MSPs have been delivering some level of security for years.</p><p>The challenge that MSPs face, though, is that a bog-standard antivirus and firewall will not cut it. Businesses need insight on the latest malware threats and cybercriminals' malicious motives. They also need to be able to guarantee protection from a whole host of bad activity.</p><p>Does this mean MSPs should transition into managed security services providers (MSSPs)? Maybe, but doing so will mean delivering brand new services and hiring individuals with security experience - a significant cost for MSPs, both in time and money. For an average-sized MSP making this kind of investment simply isn't feasible.</p><p>Luckily, however, there is a viable alternative. MSPs don't need to become MSSPs themselves - but by partnering with them, MSSPs can instigate changes and help MSPs successfully deliver the security services their clients crave. This can be the perfect antidote to MSPs' problems, but only if approached the right way.</p><h3 class="article-body__section" id="section-striking-up-strong-partnerships"><span>Striking up strong partnerships</span></h3><p>Understandably, MSPs may have reservations about entering into partnerships with MSSPs. Competition in securing and retaining clients is difficult enough without having to share the spoils. It should be considered, however, that partnerships with MSSPs can help MSPs cover the gaps and weaknesses in their security portfolios and create new streams of revenue. Through partnerships, MSPs can strengthen and sell more of their own services while alleviating the pressures of trying to "do" security alone.</p><p>When embarking on partnerships, it's important that MSPs move away from the idea that MSSPs are competitors. While the two operate in the same space and serve the same kind of client base, they are fundamentally different beasts. MSPs often act as the chief information officer (CIO) for a company, responsible for managing devices, raising help desk requests, as well as managing, deploying, configuring, and patching devices. Essentially, an MSP is there to manage, or even be, the IT department.</p><p>An MSSP, on the other hand, is solely focused on security - working to keep the bad guys out and ensuring security programmes are in place. Ultimately, the MSSP doesn't want to take on the role of an MSP, and everything this entails. Therefore, MSPs shouldn't take the cynical view of partnerships as akin to 'sleeping with the enemy'. They should instead see these as opportunities to work with partners that exist outside of the battleground where MSPs so fiercely compete.</p><p>Another important step is selecting the right MSSP to partner with. There are many out there, and going through the process of selecting a prospective partner with can be difficult and time-consuming. A great place to start is for MSPs to think honestly about which security-related services they currently can't deliver. Is it the inability to monitor networks on a 24/7 basis? A lack of an endpoint management solution? Gaps in specialist crisis management knowledge? Once MSPs have an idea of what they want from an MSSP, finding the right one to partner with will be much easier. With a strategic approach and the correct attitude, MSPs can set things off on the right foot and forge the very strongest of MSSP partnerships.</p><h3 class="article-body__section" id="section-differentiating-in-an-overcrowded-playing-field"><span>Differentiating in an overcrowded playing field</span></h3><p>It's evident that partnering with MSSPs can help MSPs deliver the security services clients need without having to break the bank. While this alone is enough justification for MSPs to consider entering MSSP partnerships, it's also worth noting that these partnerships can deliver great benefits to the overall business of both parties involved.</p><p>Establishing a competitive differentiator is particularly difficult for MSPs and MSSPs alike. Companies across the industry are quick to mirror each other's services and products in a bid to one-up each other. By embarking on partnerships, MSPs and MSSPs not only serve their own clients better, but they can differentiate their businesses by effectively delivering both sets of services.</p><p>MSPs and MSSPs have traditionally operated separately, but vast changes in business IT means the line dividing the two is blurring. This doesn't mean MSPs and MSSPs need to completely overhaul their businesses to the point where they're replicate each other. MSPs and MSSPs will always have specialist knowledge in the areas they have years of experience in, and this is why it makes so much sense for the two forces to come together and combine their expertise. Doing so will help both develop into the businesses their clients increasingly need.</p><p><em>Tim Brown is vice president for security with SolarWinds MSP</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GDPR for MSSPs: are you sure you're compliant? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/366141/gdpr-for-mssps-are-you-sure-youre</link>
                                                                            <description>
                            <![CDATA[ With less than a year until GDPR, it's time for every MSSP to move away from outdated SIEM platforms, says Exabeam's Brett Candon ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8d1eYR6dy6dD9FzB96bugx</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rW7QoyA7gKqb7AcvPEjuB6-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 09 Nov 2017 12:58:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GDPR]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Data Protection]]></category>
                                                                                                                    <dc:creator><![CDATA[ Brett Candon ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rW7QoyA7gKqb7AcvPEjuB6-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[GDPR depicted by binary code in a European flag formation]]></media:description>                                                            <media:text><![CDATA[GDPR depicted by binary code in a European flag formation]]></media:text>
                                <media:title type="plain"><![CDATA[GDPR depicted by binary code in a European flag formation]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rW7QoyA7gKqb7AcvPEjuB6-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Given that the 1995 Data Protection Directive was written well before the advent of cloud and managed IT services, the protections are now unable to cope with the pace of technological change. However, unlike its predecessor, GDPR will soon fill in those gaps, encompassing not only those collecting the data but any third parties that also access, process and store that data.</p><p>With organisations increasingly turning to external service providers for help with their security needs, in the run-up to GDPR MSSPs must ensure that the services they offer meet the regulations. Failing to do so could place them in the firing line.</p><p><strong>MSSPs' role as a processor</strong></p><p>In GDPR terminology, MSSPs are classified as "processors," in that they hold and use personal data on behalf of their customers, the "controllers". Under GDPR, MSSPs will have to provide various assurances to their customers that they meet the legislation's new requirements, particularly around the technologies and processes in place to protect sensitive data.</p><p>Yet this is easier said than done. With the absence of a recognised accreditation, it will be up to individual MSSPs to make sure that their existing processes and tools can keep them compliant.</p><p><strong>Are your security management tools up to the job?</strong></p><p>The GDPR states that both processors and controllers are required to implement "technical and organisational measures" to mitigate the risk to individuals incurred when handling personal data (Articles 25 and 32). These measures should include those that protect against the purposeful or accidental access, transmission, destruction, loss, alteration, or disclosure of personal data leading to physical or reputational damage of any EU citizen (Article 32).</p><p>Organisations opting for a managed service model for security are pushing some of the regulatory burden onto their MSSP. Since monitoring of access to customer data will become a function of GDPR compliance, MSSPs will have responsibility for ensuring they can effectively track user activities, such as access to sensitive data.</p><p>However, existing technical tools used by MSSPs fall short in two ways. Firstly, they do not provide the context to determine if a hacker is accessing confidential data. Secondly, if a breach does occur, they often miss the full picture, enabling a hacker to stay in the network and potentially cause further damage.</p><p>Post-breach reporting is another area of concern for MSSPs. The new Data Protection Officer (DPO) role created under GDPR will be obliged to report breach incidents to local authorities within 72 hours (Article 33), and to affected persons as soon as possible. To provide accurate information to both the authorities and customers, these DPOs must ascertain the full scope and impact of the breach, and so MSSPs must make sure that their existing technical measures can provide timely and complete post-breach forensic information.</p><p><strong>Rethinking security</strong></p><p>MSSPs typically use traditional SIEM (Security Information & Event Management) technologies as the main vehicle to manage data security in their Security Operations Centres. SIEM technology was fit for purpose a decade ago when data was relatively small, attacks were single incidents and the infrastructure was fairly simple. For example, there was less remote working, very few companies had BYOD policies, and emerging cloud applications were hardly used by larger organisations.</p><p>Today the style of attack has changed considerably; instead of perimeter probing, compromised insiders and zero-day internal attacks are now the norm. These styles of attack are hard for traditional SIEM technologies to detect with their correlation-based approach to detection. Advances in analytics and data science are the future for this market.</p><p>The need to be able to clearly show how a breach started, and identify everything an attacker touched during the incident, poses a big issue for MSSPs utilising a traditional SIEM. Visibility is poor, meaning cloud applications are effectively a blind spot, and there are many rules that create lots of noise, making it difficult to automate response and reduce risk exposure.</p><p>MSSPs are starting to understand that they need to rethink security management in light of GDPR. Greater visibility will enable them to identify threats to customers much quicker and with higher accuracy, and will provide a better understanding of how a breach started and the path it took, without hours or days of manual work. With this higher degree of visibility and understanding, automated controls can be applied to remediate an attack before it grows out of control.</p><p>Ultimately, the MSSP will be able to demonstrate to current and future customers that they have the correct controls in place to limit data getting into the wrong hands. Not only that, they'll avoid some nasty fines in the process.</p><p><em>Brett Candon is EMEA channel director at Exabeam</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why European businesses are partnering with MSSPs to improve IT security ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/366380/why-european-businesses-are-partnering-with-mssps-to-improve-it-security</link>
                                                                            <description>
                            <![CDATA[ Although many companies have been forced to look for outside help, trust remains an issue ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vF92o8HYmE5iAjx7Z6q4Ep</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Xtx8rK72HcYorinhyiM3Ma-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 06 Sep 2017 05:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Michael Clifford ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Xtx8rK72HcYorinhyiM3Ma-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hand hovering over laptop with padlock graphic superimposed]]></media:description>                                                            <media:text><![CDATA[Hand hovering over laptop with padlock graphic superimposed]]></media:text>
                                <media:title type="plain"><![CDATA[Hand hovering over laptop with padlock graphic superimposed]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Xtx8rK72HcYorinhyiM3Ma-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In the face of WannaCry, NotPetya and numerous other high-profile data breaches, European businesses are seriously re-evaluating how they manage their cybersecurity. They are looking for solutions that succeed in safeguarding critical data, but also serve all their other business and IT needs. There are still barriers to overcome and buyers will need to to be convinced if they are to part with cash for that initial managed security services provider (MSSP) adoption.</p><p>Rising cybercrime, digital disruption and increased compliance demands are threatening the stability of businesses across Europe. Dealing with cybercrime alone is a challenge, but as businesses look for a competitive edge through digitisation, and with the General Data Protection Regulation (GDPR) just over the horizon, many are looking for outside help.</p><p>Increasingly, that help comes in the form of an MSSP. For some areas of an organisation, particularly in the UK where outsourcing has long been practiced, it might come as a surprise that MSSPs are still seen as a relatively new concept and one that's still treated with suspicion by security chiefs. The issues are trust and control -- handing over the security keys of a business is not something to be taken lightly.</p><p>However, there has been a clear growth in MSSP adoption across Europe as the triple pressures of cybercrime, skills shortages and compliance begin to take their toll on under-pressure IT departments and boardrooms fret about the business impact of data breaches. So outside help is being sought, but that doesn't mean that any MSSP is going to get an easy ride.</p><p>Recent Reliance acsn research <a href="https://relianceacsn.co.uk/managing-security-in-the-digital-era" target="_blank">highlighted</a> that 66% of European businesses are already using an MSSP, with a further 24% planning to invest. The remaining 10% are in the process of evaluating the prospect. This demonstrates that across the board industry sectors are putting aside their reservations about using an outsourced security service. That said, the results within the sectors show that there's still some reluctance to accept the idea of fully outsourced security.</p><p>We can see that the idea of outsource is catching on, but there is still some way to go before end users completely trust an MSSP to manage security. As a result, 53% are at an early stage of planning, with only 12% at an advanced stage.</p><p>The results show the trends they are most concerned about also tend to be the drivers of change and innovation across European businesses, and confirm the feeling that the better things get in terms of digital transformation, the worse they get for security. Mobile (74%), cloud (67%) and IoT (58%) were the most frequently mentioned concerns in our report, while other major IT trends such as digital transformation (50%) and shadow IT (34%) were also frequently mentioned. These results give a reflection of what end users are thinking about and dealing with right now.</p><p>Client organisations have a mixed view of the benefits that an MSSP can provide, and different parts of the organisation have different expectations. The board looks initially to save money, whereas security teams look for help and technology that they cannot deliver in-house. An MSSP is not for life, or even for a whole organisation. Businesses are taking a pick-and-mix approach, and even taking some functions back in-house. In an age of pay-as-you go cloud and SaaS, MSSPs need to be flexible in terms of outlook and delivery, and agile enough in the face of frequent policy changes and new threats.</p><p><em>Michael Clifford is the managing director at Reliance acsn</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Specialised security detection services threaten traditional MSSPs ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/365617/specialised-security-detection-services-threaten-traditional-mssps</link>
                                                                            <description>
                            <![CDATA[ CISOs and security managers want to bring security management platforms in-house ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">v24D7pbZDyyN3kVZtVS4WC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/C54HWHE4vVqpJMRGv6YYTn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Mar 2017 09:24:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/C54HWHE4vVqpJMRGv6YYTn-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Safe]]></media:description>                                                            <media:text><![CDATA[Safe]]></media:text>
                                <media:title type="plain"><![CDATA[Safe]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/C54HWHE4vVqpJMRGv6YYTn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Gartner research has revealed that although security spending is set to top $113 billion by 2020, it's at the detriment of MSSPs, which are likely to see a hit to their business.</p><p>The reason for this is CISOs and security managers will turn to management platforms and services that are tailored to their market sector to bring into their business rather than seeking support from a provider.</p><p>"CISOs are keen to communicate the return on investment of their security strategy in terms of the business value associated with quick damage limitation, in addition to threat prevention and blocking," said Lawrence Pingree, research director at Gartner.</p><p>"The key enabler for CISOs in this endeavor is to get visibility across their security infrastructure to make better decisions during security incidents. This visibility will enable them to have a more strategic and risk-based conversation with their board of directors, CFO and CEO about the direction of their security program."</p><p>This trend will also go hand-in-hand with businesses changing their security strategy from prevention-only to detection and response. This has allowed new sub-sectors to emerge, including deception, endpoint detection and response (EDR), software-defined segmentation, cloud access security brokers (CASBs), and user and entity behavior analytics (UEBA).</p><p>Although these aspects of security are contributing to the growth of the overall security market, they are causing to the data security, enterprise protection platform (EPP) network security and security information and event management (SIEM) sectors to contract.</p><p>"The shift to detection and response approaches spans people, process and technology elements and will drive a majority of security market growth over the next five years," said Sid Deshpande, principal research analyst at Gartner.</p><p>"While this does not mean that prevention is unimportant or that chief information security officers (CISOs) are giving up on preventing security incidents, it sends a clear message that prevention is futile unless it is tied into a detection and response capability."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>