The dominant structural shift in the cybersecurity market is the relocation of value from security work to financial consequence management, driven by insurers moving directly into the managed services space. A cyber insurer's analysis of 100,000 policyholders revealed that those under constant security monitoring file 70% fewer claims. This data allows carriers to identify effective controls, leading them to offer bundled security services directly to clients and MSPs, as exemplified by Coalition's offerings for managed service providers.
This shift is underscored by the commoditization of specialized security tasks. Capital One released Vulnhunter as open-source, an AI tool that finds exploitable software flaws, a function previously requiring dedicated specialists. Similarly, Deloitte is industrializing vulnerability remediation using AI, and Blackpoint Cyber deploys autonomous agents for rapid threat detection and containment. These developments signify that the "doing" of security is becoming automated and cost-effective, while the ultimate financial responsibility remains with those who bear the risk.
Supporting this core shift, breaches are increasingly originating through third-party vendors, impacting numerous downstream organizations without direct attacker interaction. A software provider serving over 2,000 US hospitals experienced a breach that exposed data for thousands of its clients. This highlights how vendor security failures create cascading impacts, reinforcing the insurer's position as the party ultimately on the hook for losses and incentivizing them to directly manage or provide the preventative security.
For MSPs and IT service providers, this dynamic presents a clear operational imperative. The "insurability floor"—the baseline security controls required by carriers—is rising and being set by insurers, not vendors or clients. MSPs must integrate these evolving carrier requirements into their standard operating procedures to ensure their clients remain insurable. Failure to do so risks making clients ineligible for coverage, creating liability for the MSP, and potentially leading to being bypassed by insurers who are bundling services directly. The value for MSPs now lies in operationalizing this rising floor consistently for all clients, rather than merely providing a static security stack.
00:00 They're Selling the Protection Now
03:24 Why "Secure" Stopped Being Yours
05:57 The Floor Keeps Rising
08:44 Why Do We Care?
Supported by:
💼 All Our Sponsors
MSP Radio is supported by our partners:
ABC Solutions · CometBackup · GoTo · Guardz · Opentext · Pax8 · Rythmz · ScalePad · TimeZest · Transit AI
Supporting the IT services community through insights, analysis, and transparency.
🚀 Join Business of Tech Plus
Get exclusive access to investigative reports, vendor analysis, leadership briefings, and more.
👉 https://businessof.tech/plus
🎧 Subscribe to the Business of Tech
Want the show on your favorite podcast app or prefer the written versions of each story?
📲 https://www.businessof.tech/subscribe
📰 Story Links & Sources
Looking for the links from today’s stories?
Every episode script — with full source links — is posted at:
🎙 Want to Be a Guest?
Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:
💬 https://www.podmatch.com/hostdetailpreview/businessoftech
🔗 Follow Business of Tech
LinkedIn: https://www.linkedin.com/company/28908079
YouTube: https://youtube.com/mspradio
Bluesky: https://bsky.app/profile/businessof.tech
Instagram: https://www.instagram.com/mspradio
TikTok: https://www.tiktok.com/@businessoftech
Facebook: https://www.facebook.com/mspradionews
Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
[00:00:02] A cyber insurer looked at its 100,000 policyholders and found the ones under constant security monitoring file 70% fewer claims. That means the carrier now knows better than you do which of your controls actually keeps a client from getting hit. And it's starting to sell that knowledge itself. This is the Business of Tech. I'm Dave Sobel.
[00:00:28] The company that pays for your client's breach is now selling the protection against it. So we'll start with Channel Dive, which reported this week on a shift inside the managed services market. Cyber insurers are moving into the MSP's own aisle. Carriers like Coalition aren't just writing policies anymore. They're bundling security services directly into the coverage and acquiring security firms to do it.
[00:01:04] The company that ultimately writes the check when a client gets hit has decided it would rather deliver the security itself than pay you to do it. And the thing you were selling, the security work, is getting cheaper. VentureBeat reported that Capital One, a bank, released a tool called Vulnhunter and gave it away as open source. It's an AI system that hunts for exploitable flaws in software before attackers find them.
[00:01:32] The kind of vulnerability-finding work that used to require a specialist on staff. A major financial institution built it and then handed it to anyone who wants it for free. The skilled work of finding the holes is a download. Meanwhile, the breaches keep landing. And they land through the vendors. A software provider serving more than 2,000 US hospitals disclosed that attackers got into its network and stole employee, customer, and partner data.
[00:02:01] One vendor breached, and the exposure ran straight through it to thousands of downstream organizations that never touched the attacker themselves. The insurer that pays for the breach is now selling the protection. The specialized security work is being given away for free. And the breaches keep arriving, carried in through the supply chain. That's what's moving on the table. Three separate corners of the security market all moving at once. So why is all of this landing at once?
[00:02:29] The insurer moving in, the work going free, and the breaches still getting through? It's one shift underneath all three. If you're listening to this and you haven't hit follow yet, on Apple Podcasts, search the business of tech. It takes five seconds and you'll get the next episode automatically. The MSPs getting ahead in security aren't adding more tools. They're getting the work off their plate.
[00:02:56] Guardz consolidates the stack, endpoint, email identity, and then puts an autonomous analyst on top of it. Triaging the alerts, correlating the signals, drafting the client reporting automatically. It's purpose-built for MSPs protecting S&B clients month to month. Real SecOps without hiring a SecOps team. Start at guards.com. That's G-U-A-R-D-Z dot com.
[00:03:26] The reason the insurer can walk into the MSP's aisle comes down to one thing that quietly changed about where the value in security lives. For years, the value was in doing the work. A skilled person who can find the flaw, watch the network, catch the intrusion. That skill was scarce, so it was worth money. And the MSP sold it. But the doing is exactly what's being commoditized. Watch it happen. That free tool from Capital One does the flaw finding.
[00:03:54] Deloitte, in its own announcement, so weigh in as the vendors framing, built a platform on Anthropic's clawed models that industrializes the next step. Automatically remediating vulnerabilities across custom, packaged, and open source code at a scale no team of human matches. And Blackpoint Cyber, again in its own release, ships an autonomous agent that detects and contains a credential attack in as little as 21 seconds.
[00:04:22] Faster than any analyst could even open the alert. Free, industrialized, autonomous. The control work is turning into a commodity. And here's the move that matters. When the doing becomes cheap, the value doesn't vanish. It relocates to the one thing that can't be commoditized. Carrying the financial consequence when the control fails. Someone still has to be on the hook for the loss.
[00:04:48] And the party on the hook for the loss, by definition, is the insurer. That's why the carrier sets the terms. The insurer knows from the money which controls actually prevent a payout. And it's under pressure to act on it.
[00:05:15] The industry's cyber loss ratio, how much of every premium dollar gets paid back out in claims, climbed to 53 cents on the dollar. The first time it's crossed 50 since the ransomware crisis. And it's risen two years running. A carrier watching that number climb tightens.
[00:05:36] It requires the controls that correlate with not filing a claim, verifies them, denies the payout when they weren't really in place, and lifts the bar at every renewal. So the floor a client has to clear to stay insurable isn't set by the provider anymore. It's set by the party that pays the loss. And it only moves up. So now we add the MSP.
[00:06:02] The floor a client needs to clear to stay insurable is being set by the carrier, and it only climbs. And that turns out to be the whole opportunity, not the whole threat. Watch where the bar is heading. Terra Security moved its agentic internal network penetration testing into preview with design partners, claiming to be the first to run continuous autonomous testing across all major attack surfaces, web applications, AI systems, and now the internal network.
[00:06:31] Think about what continuous does to the standard. Penetration testing used to be a thing a client did once a year to satisfy an auditor. The tools now run it constantly. And a carrier that can see your client is being tested constantly will price that in. Which means, tested once a year, it's about to fall below the line that keeps a client covered. The floor just moved, and most clients are still standing where it used to be.
[00:06:58] Now watch the carrier's reach extend past the policy. Barracuda acquired Evo Security, an identity provider built specifically for MSPs, folding managed identity directly into its platform. Read it as the same force from the last few minutes, now buying its way into your stack. The layer that decides who gets in, identity, is being consolidated by vendors selling the outcome, not the tool.
[00:07:22] The pieces an MSP used to assemble and own are being bought up and bundled by the parties positioned above them. So here's the choice, and it's about staying on the right side of a line that keeps rising. You can be the provider who keeps every client continuously above what carriers require to stay insurable. Treating the insurability floor as your standard, watching it climb, and moving each client up before the renewal or the claim finds them below it.
[00:07:51] Or you can keep selling a fixed security stack while the floor rises underneath it, and become the vendor the insurer bundles past the day your client's coverage, not your contract, is what defines secure. This episode is brought to you by Control Map. Growing MSPs are using Control Map to build recurring revenue by expanding their GRC services.
[00:08:16] Starting now, Control Map is offering a free plan for MSPs looking to get started with providing compliance as a service. Create a free account and run an assessment. Track key items like policies, risks, and evidence in one place. It's a practical way to prove value to a client before deciding to expand your compliance offering. Try Control Map for free today. Visit scalepad.com slash Dave to get started. That's scalepad.com slash Dave.
[00:08:47] Why do we care? Because staying ahead of the floor isn't a sales motion. It's an operating discipline you either run or you don't. Build the insurability floor into how your shop actually works. Pull the current control requirements from the carriers your clients use. Turn them into a live checklist you rerun every renewal cycle. And instrument your stack to flag the moment a client drops below the line. Before the carrier or the claim finds them there.
[00:09:15] The provider who operationalizes the floor once, internally, can hold 100 clients above it. The one improvising it per client can't hold 10. What to consider? Turn the carrier's requirements into one internal control map, not scattered knowledge. Pull the actual underwriting requirements from the carriers your clients most commonly use. The specific controls they demand, verify and deny claims over.
[00:09:43] And consolidate them into a single standard your shop maintains. Most providers carry this as tribal knowledge in one senior person's head. Written down and owned as an internal artifact, it becomes the reference every client gets measured against instead of a memory you hope someone still has. Instrument for the drop, not just the deployment. The failure mode isn't a control never getting installed.
[00:10:08] It's a control quietly failing out of place between renewals, the missed patch or the disabled MFA that voids a payout. Wire your monitoring to flag the moment a client slips below the carrier's line and treat that alert like an outage. The whole value of running the floor internally is catching the slip before the carrier's questionnaire or the claim adjuster does. Rerun the whole map every renewal, because the floor moved since last time.
[00:10:37] Set a standing cadence tied to each client's coverage renewal to re-pull the carrier's current requirements and recheck every client against them. Because the bar that was clearing last cycle won't be the bar this one. Build it as a repeating internal process, not a project you finish, so the discipline renews on its own instead of being rediscovered after a client comes up short.
[00:11:03] If this trend continues, within a year a client's renewal readiness proves they sit above their carrier's current control requirements because something they expect their provider to already know and hold. And the shop running that check as a standard internal process is answering in minutes while everyone else is scrambling to reconstruct it per client. This is the business of tech. Want to go deeper than the news?
[00:11:33] The Small Biz Thoughts community is where MSP owners and operators work on the business, not just in it. Member meetings, a deep resource library, and courses through IT Service Provider University. Everything you need to run the practice you actually want. Join us at smallbizthoughts.org Interested in advertising? Head to mspradio.com slash engage.
[00:11:57] The Business of Tech is written and produced by me, Dave Sobel, under ethics guidelines posted at businessof.tech. Thanks for listening. I'll see you on the next episode. Part of the MSP Radio Network.

