News, Trends, and Insights for IT & Managed Services Providers
News, Trends, and Insights for IT & Managed Services Providers
2ab1c425 ae17 4612 9f78 8c5cf6d84c24

They’re Selling the Protection Now
The company that pays for your client’s breach is now selling the protection against it.

Start with Channel Dive, which reported this week on a shift inside the managed-services market: cyber insurers are moving into the MSP’s own aisle. Carriers like Coalition aren’t just writing policies anymore — they’re bundling security services directly into the coverage, and acquiring security firms to do it. Coalition’s own website now runs a dedicated offering aimed at managed service providers: stop threats, scale your business, with automated detection and response built in. Read that plainly. The party that ultimately writes the check when a client gets hit has decided it would rather deliver the security itself than pay you to do it.

And the thing you were selling — the security work — is getting cheaper. VentureBeat reported that Capital One, a bank, released a tool called VulnHunter and gave it away as open source. It’s an AI system that hunts for exploitable flaws in software before attackers find them — the kind of vulnerability-finding work that used to require a specialist on staff. A major financial institution built it, and then handed it to anyone who wants it, for free. The skilled work of finding the holes is a download.

Meanwhile, the breaches keep landing — and they land through the vendors.  A software provider serving more than two thousand U.S. hospitals disclosed that attackers got into its network and stole employee, customer, and partner data. One vendor, breached, and the exposure ran straight through it to thousands of downstream organizations that never touched the attacker themselves.

The insurer that pays for the breach is now selling the protection. The specialized security work is being given away for free. And the breaches keep arriving, carried in through the supply chain. That’s what’s on the table — three separate corners of the security market, all moving at once. So why is all of this landing at once — the insurer moving in, the work going free, the breaches still getting through? It’s one shift underneath all three.

Why “Secure” Stopped Being Yours
The reason the insurer can walk into the MSP’s aisle comes down to one thing that quietly changed about where the value in security lives. For years, the value was in doing the work — a skilled person who could find the flaw, watch the network, catch the intrusion. That skill was scarce, so it was worth money, and the MSP sold it. But the doing is exactly what’s being commoditized.

Watch it happen. That free tool from Capital One does the flaw-finding. Deloitte — in its own announcement, so weigh it as the vendor’s framing — built a platform on Anthropic’s Claude models that industrializes the next step, automatically remediating vulnerabilities across custom, packaged, and open-source code at a scale no team of humans matches. And Blackpoint Cyber, again in its own release, ships an autonomous agent that detects and contains a credential attack in as little as twenty-one seconds — faster than any analyst could even open the alert. Free, industrialized, autonomous. The control work is turning into a commodity.

And here’s the move that matters: when the doing becomes cheap, the value doesn’t vanish. It relocates to the one thing that can’t be commoditized — carrying the financial consequence when the control fails. Someone still has to be on the hook for the loss. And the party on the hook for the loss, by definition, is the insurer.

That’s why the carrier sets the terms. Coalition’s own claims data — a carrier reading its hundred-thousand-plus policyholders — shows organizations under continuous security monitoring file roughly seventy percent fewer claims. The insurer knows, from the money, which controls actually prevent a payout. And it’s under pressure to act on it. The industry’s cyber loss ratio — how much of every premium dollar gets paid back out in claims — climbed to fifty-three cents on the dollar, the first time it’s crossed fifty since the ransomware crisis, and it’s risen two years running. A carrier watching that number climb tightens. It requires the controls that correlate with not filing a claim, verifies them, denies the payout when they weren’t really in place — and lifts the bar at every renewal.

So the floor a client has to clear to stay insurable isn’t set by the provider anymore. It’s set by the party that pays the loss — and it only moves up.

The Floor Keeps Rising
So now we add the MSP. The floor a client needs to clear to stay insurable is being set by the carrier, and it only climbs — and that turns out to be the whole opportunity, not the whole threat.

Watch where the bar is heading.  Terra Security moved its agentic internal-network penetration testing into preview with design partners, claiming to be the first to run continuous, autonomous testing across all four major attack surfaces — web, applications, AI systems, and now the internal network. Sit with what “continuous” does to the standard. Penetration testing used to be a thing a client did once a year to satisfy an auditor. The tools now run it constantly. And a carrier that can see your client is being tested constantly will price that in — which means “tested once a year” is about to fall below the line that keeps a client covered. The floor just moved, and most clients are still standing where it used to be.

Now watch the carrier’s reach extend past the policy. Barracuda acquired Evo Security, an identity provider built specifically for MSPs, folding managed identity directly into its platform. Read it as the same force from the last few minutes, now buying its way into your stack: the layer that decides who gets in — identity — is being consolidated by a vendor selling the outcome, not the tool. The pieces an MSP used to assemble and own are being bought up and bundled by the parties positioned above them.

So here’s the choice, and it’s about staying on the right side of a line that keeps rising. You can be the provider who keeps every client continuously above what carriers require to stay insurable — treating the insurability floor as your standard, watching it climb, and moving each client up before the renewal or the claim finds them below it. Or you can keep selling a fixed security stack while the floor rises underneath it — and become the vendor the insurer bundles past, the day your client’s coverage, not your contract, is what defines “secure.”

Why Do We Care?
Because staying ahead of the floor isn’t a sales motion — it’s an operating discipline you either run or you don’t. Build the insurability floor into how your shop actually works: pull the current control requirements from the carriers your clients use, turn them into a live checklist you re-run every renewal cycle, and instrument your stack to flag the moment a client drops below the line — before the carrier or the claim finds them there. The provider who operationalizes the floor once, internally, can hold a hundred clients above it. The one improvising it per-client can’t hold ten.

What to Consider

  • Turn the carriers’ requirements into one internal control map, not scattered knowledge. Pull the actual underwriting requirements from the carriers your clients most commonly use — the specific controls they demand, verify, and deny claims over — and consolidate them into a single standard your shop maintains. Most providers carry this as tribal knowledge in one senior person’s head; written down and owned as an internal artifact, it becomes the reference every client gets measured against instead of a memory you hope someone still has.
  • Instrument for the drop, not just the deployment. The failure mode isn’t a control never getting installed — it’s a control quietly falling out of place between renewals, the missed patch or the disabled MFA that voids a payout. Wire your monitoring to flag the moment a client slips below the carrier’s line, and treat that alert like an outage. The whole value of running the floor internally is catching the slip before the carrier’s questionnaire or the claim adjuster does.
  • Re-run the whole map every renewal, because the floor moved since last time. Set a standing cadence tied to each client’s coverage renewal to re-pull the carrier’s current requirements and re-check every client against them — because the bar that was clearing last cycle won’t be the bar this one. Build it as a repeating internal process, not a project you finish, so the discipline renews on its own instead of being rediscovered after a client comes up short.

If this trend continues: Within a year, a client’s renewal readiness — proof they sit above their carrier’s current control requirements — becomes something they expect their provider to already know and hold, and the shop running that check as a standing internal process is answering in minutes while everyone else is scrambling to reconstruct it per client.

Choose your upgrade:

Get the full benefits of Business of Tech Plus

Insider Access

$12/month

Perfect for MSPs and ITSPs that want full interviews, early access, and ad-free listening

  • Programmatic Ad-free private podcast feedSame show, little interruptions
  • Channel Chatter previews1–2 topics with light insights
  • Early access to interview episodesHear it days before public release
  • Monthly Insider BriefTighter analysis you can share internally
  • Extra audio segmentsCut interviews, behind-the-scenes commentary, quick competitive notes
  • Become an Insider for $12/month

    Leadership Access

    $149/month

    Perfect for MSPs and Vendors that run a team and need the extended tactics, executive summaries, and weekly alignment brief

  • All Insider Access benefits plus . . .
  • Invite your teamIncludes access for 5 team members with option to add more
  • Vendor Strategy BriefsThe entire library, plus new analysis every month
  • Channel ChatterAll topics, full insights, complete vendor discussion + sentiment list
  • Quarterly State of the Channel Briefing
  • Monthly AMA submission priorityAsk Dave direct questions, and skip the line
  • Get the Leadership Edge for $149/month

    Vendor Partner

    $500/month

    Perfect for channel companies or vendors looking to deepen their engagement with the show.

  • All Leadership Access benefits plus . . .
  • Get highlighted as a show sponsor You'll get placement in the show notes, throughout the website, and on our dedicated sponsors page.
  • Enjoy regular shout outs You'll be featured in a rotating format during the show
  • Become a show sponsor for $500/month

    Search all stories