Key Takeaways

  • Fig Group has closed a £550,000 seed round after passing 100 customers and securing licenses to deliver NCSC and Ministry of Defence cybersecurity schemes.
  • The platform combines compliance management, cybersecurity monitoring, evidence collection, and an emerging cyber insurance offering for MSPs.
  • Regulatory obligations are moving through supply chains, creating demand for MSP-focused systems that support multiple customers and frameworks.

Fig Group has raised £550,000 to expand its compliance, cybersecurity, and monitoring platform for managed service providers. The UK business is targeting a recurring headache for MSPs: turning a growing collection of regulatory duties, security controls, customer questionnaires, and audit evidence into a service that can be managed at scale.

The seed round comes after Fig Group passed 100 customers and secured licensing to deliver cybersecurity schemes associated with the National Cyber Security Centre and Ministry of Defence. Fig Group has also onboarded several MSPs, is progressing multiple enterprise deals, and is developing a cyber insurance strategy.

That is a broad agenda for a relatively modest seed round. At £550,000, the financing sits toward the smaller end of the seed market. Yet the opportunity Fig Group is chasing is substantial, particularly as compliance becomes part of how customers assess and purchase managed services.

The Business Research Company projects global MSP revenue will increase from about $406.7 billion in 2025 to $489.4 billion in 2026, representing 20.3% growth. Cybersecurity requirements and regulatory pressure are among the factors supporting that expansion.

Still, market growth does not automatically give MSPs the operational capacity to deliver compliance services. CloudSecureTech estimates that only around 20% to 36% of MSPs currently offer formal compliance services (source). That gap leaves considerable room for products designed around the channel's multi-customer operating model.

Conventional governance, risk, and compliance systems have often been designed for one enterprise managing its own controls. An MSP may need to track evidence, remediation work, policies, and reporting across dozens or hundreds of customer environments. Each customer can have a different technology stack, risk profile, contractual requirement, and regulatory exposure.

Fig Group wants to reduce that fragmentation by combining compliance and cybersecurity evidence across multiple frameworks in one platform. The company's founder and managing director argues that regulation is advancing faster than the supporting toolset.

"NIS2, DORA, CMMC, each one pushes obligation down the supply chain until it lands on the MSP," the founder said.

Those regimes differ in scope and jurisdiction, but the commercial effect can look similar. Regulated organizations increasingly ask suppliers to demonstrate security controls and operational resilience. MSPs then inherit much of the evidence burden because they operate infrastructure, manage access, monitor systems, or support critical business processes.

How many separate products should an MSP need to prove that work is being done? The company contends that adding point products can simply move the integration burden onto providers.

"Fig is one end-to-end platform: compliance, cybersecurity and risk transfer," company leadership noted, adding that "an MSP shouldn't have to become a systems integrator in order to become an MSSP."

The timing also reflects a wider consolidation trend in governance technology. Forrester noted in its Q2 2026 coverage of GRC platforms that enterprises are looking to unify evidence collection, control monitoring, and reporting across frameworks. Within the MSP channel, Kaseya/Datto, ConnectWise, and Axcient are also expanding their security and compliance capabilities.

Fig Group's differentiator may depend on how effectively it joins those functions with risk transfer. Fig Group is developing an insurance proposition intended to connect demonstrated cyber maturity and compliance evidence with coverage for MSPs and their customers. In principle, current control data could give insurers a clearer view of risk while helping customers understand which improvements might affect insurability.

That said, combining software, cybersecurity delivery, regulated schemes, and insurance is operationally demanding. Fig Group will need to show that its approach simplifies MSP workflows rather than creating another layer to administer. Integrations, evidence quality, framework updates, and insurer participation will all influence adoption.

The early customer count and enterprise pipeline give Fig Group a base from which to test that proposition. The larger signal is that compliance is becoming a channel service, not merely an annual audit exercise. MSPs capable of managing evidence and controls across customers may gain a stronger commercial position. Fig Group is betting that they will prefer one coordinated system over assembling the pieces themselves.