The dominant structural shift in the cybersecurity market is the relocation of value from security work to financial consequence management, driven by insurers moving directly into the managed services space. A cyber insurer's analysis of 100,000 policyholders revealed that those under constant security monitoring file 70% fewer claims. This data allows carriers to identify effective controls, leading them to offer bundled security services directly to clients and MSPs, as exemplified by Coalition's offerings for managed service providers.
This shift is underscored by the commoditization of specialized security tasks. Capital One released Vulnhunter as open-source, an AI tool that finds exploitable software flaws, a function previously requiring dedicated specialists. Similarly, Deloitte is industrializing vulnerability remediation using AI, and Blackpoint Cyber deploys autonomous agents for rapid threat detection and containment. These developments signify that the "doing" of security is becoming automated and cost-effective, while the ultimate financial responsibility remains with those who bear the risk.
Supporting this core shift, breaches are increasingly originating through third-party vendors, impacting numerous downstream organizations without direct attacker interaction. A software provider serving over 2,000 US hospitals experienced a breach that exposed data for thousands of its clients. This highlights how vendor security failures create cascading impacts, reinforcing the insurer's position as the party ultimately on the hook for losses and incentivizing them to directly manage or provide the preventative security.
For MSPs and IT service providers, this dynamic presents a clear operational imperative. The "insurability floor"—the baseline security controls required by carriers—is rising and being set by insurers, not vendors or clients. MSPs must integrate these evolving carrier requirements into their standard operating procedures to ensure their clients remain insurable. Failure to do so risks making clients ineligible for coverage, creating liability for the MSP, and potentially leading to being bypassed by insurers who are bundling services directly. The value for MSPs now lies in operationalizing this rising floor consistently for all clients, rather than merely providing a static security stack.
00:00 They're Selling the Protection Now
03:24 Why "Secure" Stopped Being Yours
05:57 The Floor Keeps Rising
08:44 Why Do We Care?
Supported by:
Guardz
ScalePad
💼 All Our Sponsors
MSP Radio is supported by our partners:
Transit AI · Guardz · Pax8 · ABC Solutions · Rythmz · ScalePad · CometBackup · TimeZest
Supporting the IT services community through insights, analysis, and transparency.
🚀 Join Business of Tech Plus
Get exclusive access to investigative reports, vendor analysis, leadership briefings, and more.
👉 https://businessof.tech/plus
🎧 Subscribe to the Business of Tech
Want the show on your favorite podcast app or prefer the written versions of each story?
📲 https://www.businessof.tech/subscribe
📰 Story Links & Sources
Looking for the links from today’s stories?
Every episode script — with full source links — is posted at:
🌐 https://www.businessof.tech
🎙 Want to Be a Guest?
Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:
💬 https://www.podmatch.com/hostdetailpreview/businessoftech
🔗 Follow Business of Tech
LinkedIn: https://www.linkedin.com/company/28908079
YouTube: https://youtube.com/mspradio
Bluesky: https://bsky.app/profile/businessof.tech
Instagram: https://www.instagram.com/mspradio
TikTok: https://www.tiktok.com/@businessoftech
Facebook: https://www.facebook.com/mspradionews
Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.