Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

What Does It Mean To Be A ‘True’ MSSP?

CRN by CRN
June 3, 2025
Home News
Share on FacebookShare on Twitter


Thrive CEO Bill McLaughlin says that while it’s smart for an MSP to transition to an MSSP if they believe they are ready for that type of expansion, it’s concerning to see some providers calling themselves MSSPs without actually managing their customers’ security themselves.

For MSPs that are looking to make the wise move of going deeper on cybersecurity services, expanding to become an MSSP is one notable option that many are considering right now.

But to be a “true” MSSP requires a major investment that not all MSPs are going to be positioned to make, according to Bill McLaughlin, CEO of Foxborough, Mass.-based service provider Thrive. The company operates multiple Security Operations Center (SOC) locations worldwide, allowing it to provide 24×7 managed security services to customers.

In 2025, many customers “want somebody who’s got expertise in being able to provide security around their enterprise, have the ability to manage it with a SOC 24 hours a day, 365 days a year,” McLaughlin said.

[RELATED: Staying On The Right Path: Partner Enablement Needs To Be A ‘Continuous Journey’]

Crucially, Thrive does not outsource any of its MSSP work to other providers, and every individual working in its three worldwide SOCs is an employee of the company, he said.

A SOC typically provides managed security services—delivered by a team of security analysts—including threat monitoring and detection as well as response and remediation of cyberattacks.

Such services are increasingly provided across the full spectrum of IT environments and devices used by an organization, in contrast to MDR (managed detection and response) offerings that traditionally focus on detection and response for threats targeting endpoints.

While MSPs are smart to consider moving to becoming an MSSP if they believe they are ready for that type of expansion, it’s concerning to see some providers calling themselves MSSPs without actually managing their customers’ security themselves, according to McLaughlin.

“If you’re going to be a true MSSP, you’ve got to have the technology. And the technology is more than just MDR and EDR [endpoint detection and response],” he said. “It’s a complete framework around various components that are going to address all the different areas within the enterprise—then having the team to be able to respond, manage, react and remediate.”

By contrast, McLaughlin said, many service providers today are signing up with a major MDR provider with the premise that “they will outsource the SOC to [the vendor]—and then they’ll call themselves an MSSP.”

Without a doubt, amid the massive demand for managed security services, “a lot of smaller MSPs are leveraging a third party and outsourcing because they don’t have the financial backing or wherewithal to be able to build out a true SOC,” he said.

The technology to do so is not inexpensive, and neither is the hiring and training of security analysts, McLaughlin said. Ultimately, Thrive has positioned itself to “bring in a top-tier product, to have a top-tier platform, to have it truly integrated—and then have the right talent behind it to provide the services that are required to be a true MSSP,” he said.

For an MSP to provide managed security services the minimum number of seats it should be managing is 5,000, according to Charles Everette, a cybersecurity veteran who was recently named field CISO at Slovakia-based security vendor ESET.

Apart from having a certain scale, it’s also crucial for an MSSP to be taking on clients that already have achieved a level of maturity in their cybersecurity posture, Everette said.

“If you go in and try to provide it to companies that are immature, that don’t have the cybersecurity understanding, you’re not going to be able to manage it properly. And that’s the key thing,” he said. “It’s not just about getting it up and running; it’s [also] about is this the right customer?”

One MSP that undertook the expansion into an MSSP is Milford, Conn.-based Vancord, which opened its own SOC in 2023 and manages roughly 6,000 endpoints, said Lou Ardolino, vice president of client success at Vancord.

While the move to become an MSSP may not make sense for all MSPs, Vancord had the built-in advantage of already having security engineers on staff, Ardolino said.

Notably, a key growth area for the company has been to work with other MSPs and VARs that are not in a position to offer MSSP services themselves by providing its own SOC services to those partners and their end customers, he said.

“They’ll leverage us because they might not be as large of a shop as we are,” Ardolino said, and the MSSP-MSP partnerships have been “very beneficial” for both sides.



Source link

Tags: Application and Platform SecurityCloud SecurityCybersecurityEndpoint SecurityManaged Security
CRN

CRN

Next Post
OneTrust Activates Consented Data for AI Use with Snowflake Native App for Consent Management

OneTrust Activates Consented Data for AI Use with Snowflake Native App for Consent Management

Recommended.

10 Key AI Security Controls For 2026

10 Key AI Security Controls For 2026

January 26, 2026
TELUS unveils the world’s first smart home AI assistant with Generative UI, unifying the entire connected home

TELUS unveils the world’s first smart home AI assistant with Generative UI, unifying the entire connected home

March 19, 2026

Trending.

Spirit of openness helps banks get serious about stopping scams | Computer Weekly

Spirit of openness helps banks get serious about stopping scams | Computer Weekly

April 10, 2025
Microsoft Q3 Earnings Preview: What To Watch On Azure, Copilot, OpenAI

Microsoft Q3 Earnings Preview: What To Watch On Azure, Copilot, OpenAI

April 29, 2026
Weibo Publishes 2025 Environmental, Social and Governance Report

Weibo Publishes 2025 Environmental, Social and Governance Report

April 28, 2026
It Takes 2 Minutes to Hack the EU’s New Age-Verification App

It Takes 2 Minutes to Hack the EU’s New Age-Verification App

April 18, 2026
Chunghwa Telecom 2025 Form 20-F filed with the U.S. SEC

Chunghwa Telecom 2025 Form 20-F filed with the U.S. SEC

April 15, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio