top of page

Why Managed Service Providers Are Losing More Than Security Revenue

  • Writer: techrug
    techrug
  • Jun 27
  • 4 min read

Seven months into 2026, one trend has become impossible for us to ignore.

For years, we've been telling Managed Service Providers (MSPs) and Managed Security Service Provider (MSSPs) that the relationship between cyber insurance and cybersecurity was changing.


At the time, many providers believed their biggest competitors would always be other MSPs. The focus was on winning against the provider down the street, expanding service offerings, hiring more engineers, and building stronger cybersecurity practices. Those were logical concerns, but we believed the industry was looking in the wrong direction.


Today, we're no longer talking about what might happen. We're watching it happen.

In just the first seven months of 2026, 32 of our MSPs have documented business losses after clients were introduced to competing cybersecurity services through cyber insurance conversations.


These weren't cyber losses or insurance claims.


They were revenue losses tied to cybersecurity services that providers had spent years building into their businesses.


When we first started reviewing these situations, we assumed we were looking at a service problem.


We saw providers losing opportunities around

  • Managed Detection & Response (MDR)

  • Extended Detection & Response (XDR)

  • Security Awareness Training

  • Virtual CISO services

  • Email Security

  • Multi-Factor Authentication (MFA)

  • Vulnerability management


We believed the conversation would revolve around pricing, bundled services, or product comparisons.


The more conversations we had, however, the more we realized we were looking at the symptom rather than the problem.


The real issue wasn't the services. It was the relationship.


One conversation with an MSP illustrates that better than anything we could write.


The provider forwarded us an email from one of their clients asking if they could review information received from their cyber insurance carrier and explain which services they offered that were comparable—or better—than what was included through the policy.


After reviewing the documents, the MSP sent us a simple reply:

"How do I even respond to this?"

That question wasn't really about MDR. It wasn't really about Security Awareness Training. It wasn't really about pricing.


It was about something much more difficult to protect.


For years, MSPs earned their place as the primary cybersecurity advisor for their clients. They learned the business, managed the technology environment, recommended security investments, responded when incidents occurred, and helped leadership make informed decisions around cyber risk.


That position wasn't built because they sold a particular security product. It was built because clients trusted them.


Today, those conversations are changing.


Cyber insurance carriers are expanding cybersecurity ecosystems. Security vendors are working more closely with insurers. Incident response firms are becoming trusted advisors during cyber events. Insurance agents are introducing cybersecurity resources that many business owners were never exposed to before.


None of these organizations are necessarily trying to replace the MSP. In fact, most are doing exactly what they were designed to do. Carriers want to reduce claims. Security vendors want to improve security outcomes. Incident response firms want to help businesses recover faster.


Those objectives make sense. The unintended consequence is that more organizations are participating in cybersecurity conversations that were once led almost entirely by the MSP.


That shift becomes even more apparent after a cyber incident. When a business experiences ransomware, a business email compromise, or another significant cyber event, owners suddenly find themselves surrounded by forensic investigators, breach coaches, legal counsel, cybersecurity specialists, insurance representatives, and incident response teams. Those organizations provide tremendous value during one of the most stressful moments a business will ever experience.


They also build trust.


As we continued studying these situations, one realization became increasingly difficult to ignore. The biggest challenge facing many MSPs is no longer protecting an individual security service. It's protecting the trusted advisor relationship they spent years building.


Once another organization becomes part of that relationship, the conversation naturally changes. Security recommendations change. Budget discussions change. Strategic planning changes. The question is no longer who offers the best MDR platform or the lowest price. The question is who the client trusts when the next cybersecurity decision needs to be made.


That realization is one of the reasons CyberBreach™ was built differently.


From the beginning, we believed cyber insurance should strengthen the MSP's relationship with the client—not compete against it. We never wanted to build a model where the provider lost influence during or after a cyber event or found themselves competing against the very ecosystem surrounding the policy.


We believe the MSP should remain at the center of the client's cybersecurity strategy because no insurance carrier, vendor, or third party understands that client's business the way their trusted technology provider does.


The cybersecurity industry will continue to evolve. New services will emerge. New partnerships will be formed. The market will continue to change. But after years of watching this shift unfold, speaking with MSPs across the country, reviewing real-world situations, and documenting what we've seen firsthand, we've become convinced that the future of the MSP industry won't be defined by who offers the most cybersecurity services.


It will be defined by who earns—and keeps—the trust of the client.


Frequently Asked Questions

Why are MSPs losing cybersecurity revenue?

Many MSPs are seeing increasing overlap between cybersecurity services they traditionally provide and services introduced through cyber insurance ecosystems, security vendors, and incident response providers. This overlap can affect both recurring revenue and long-term client relationships.

Are cyber insurance carriers competing with MSPs?

Yes. As cyber insurance carriers add more cybersecurity resources, some of those services now overlap with work MSPs have traditionally provided.

That can put the carrier closer to the client’s cyber decisions and reduce the MSP’s influence. MSPs need to stay positioned inside the cyber insurance conversation, not outside of it.

Why is the trusted advisor relationship so important?

Technology changes. Security products change. Vendors change. The trusted advisor relationship often determines who influences future cybersecurity decisions, strategic planning, security investments, and long-term client retention.

Why was CyberBreach™ built differently?

CyberBreach™ was built around a simple philosophy: cyber insurance should support MSPs—not compete against them. Our goal is to help MSPs remain central to the client relationship before, during, and after a cyber event.


 
 
bottom of page