Key Takeaways
- NetWitness and Lumifi introduced a joint MDR service that extends into operational technology environments
- Funding rounds for VulnCheck and Cogent Security highlight rising demand for exposure-based security operations
- Market signals suggest MSSPs are moving toward platform-driven, outcome-linked services rather than tool monitoring
Managed security services providers (MSSPs) are increasingly pivoting from operating discrete tools to delivering scalable, outcome-led services. NetWitness and Lumifi formalized a joint managed detection and response offering that blends the NetWitness analytics platform with Lumifi's 24/7 SOC operations. This mirrors findings from MarketsandMarkets forecasting that global managed security services will grow from $39.47 billion in 2025 to $66.83 billion by 2030. This growth is driven largely by MDR and SOC-as-a-service models replacing tool-centric work that rarely scales.
Service providers are aligning to platform-based models that reduce dependence on staff-heavy operations. The NetWitness and Lumifi service addresses this by packaging analytics and continuous monitoring in a single model aimed at organizations that have tools deployed but lack the personnel to manage them. It extends into operational technology environments, an area many MSSPs have struggled to support without forming separate OT teams. Offering a combined IT and OT monitoring model gives MSSPs a repeatable service across varied customer environments.
FutureSafe recently expanded its work with Cork Cyber to tie cyber risk scoring to financial protection for MSP and MSSP customers. Instead of conversations centered only on alerts and remediation, the focus moves to renewal, client retention, and how recovery support factors into insurance alignment. Providers are finding concrete ways to attach revenue and customer lifetime value to security services rather than treating them as a purely technical function.
Next Dimension is rolling SIEM, EDR, and MXDR delivery onto Todyl's cloud-native platform for all customers. That reduces internal tool sprawl inside the SOC, replacing it with a common operating model that supports consistent service delivery. For MSPs evolving into MSSPs, this type of consolidation helps them scale detection and response without adding headcount. This reflects a broader move noticed by Gartner in its coverage of MDR providers, where endpoint-centric offerings are increasingly paired with cloud analytics and automated investigation.
Booz Allen Hamilton's agreement to acquire Defy Security signals the firm's growing investment in its commercial cyber business. The acquisition adds incident response, threat detection, and cyber operations capabilities built for enterprise customers rather than federal buyers. For mid-market and global enterprises, it means another large services firm is entering a competitive field already populated by established MDR and SOC providers.
In the startup ecosystem, VulnCheck secured new funding to expand its vulnerability and exploit intelligence platform. Demand is rising for real-time visibility into which exposures are actually being weaponized. That insight matters for MSSPs seeking to evolve beyond basic alert triage and move toward exposure prioritization and continuous validation. The capital will support data collection, automation, and workflow integrations, tying into operations where speed and context define value.
Cogent Security also secured funding to develop AI agents that automate vulnerability triage and remediation. Finding vulnerabilities is only part of the challenge, as fixing them is often the slowest stage. Cogent argues that remediation creates a significant scalability problem, and its new capital will fund product development and commercial expansion.
Industry research, including analysis from the NIST Cybersecurity Framework, highlights the importance of standardizing detection and response processes to reduce variability across tenants. When combined with the growing influence of AI-driven analytics, MSSPs are moving into a model where service-level expectations tie directly to measurable outcomes, such as mean time to detection or incident containment, rather than simply operating a list of tools.
Capital continues to flow into tooling that prioritizes exposures and automates remediation workflows, while platform consolidation accelerates among mid-sized providers. Service providers ultimately want repeatable, multi-tenant models that improve margins and reduce labor intensity. Whether achieved through joint MDR offerings, platform consolidation, financial risk alignments, or investments in automation, MSSPs are finding ways to scale in a market that rewards measurable operational resilience.
⬇️