Prevention Got A New Price
Three groups voted independently on the price of security software, and none of them asked an MSP.
Start with the market. CrowdStrike had its best trading day ever after a fiscal second-quarter report that beat expectations. Okta rose nearly twenty-nine percent on the same day after its own beat. Both CEOs attributed the numbers to the same thing — enterprise customers are expanding security spending because artificial-intelligence agents are increasing the volume and sophistication of the attacks landing on them. CrowdStrike said Falcon platform usage doubled year over year. Okta said new AI-related products are now close to a third of total bookings. The market took those two beats as forward-looking and repriced the whole sector inside a single trading session.
Then the analyst. Gartner’s forecast for the market that secures AI, reported by ARN this month, puts spending at four point eight billion dollars by 2027 — a sixty-eight point seven percent jump from this year, and reaching nearly seven point seven billion by 2028. Inside that number, the fastest-growing slice is AI usage control, projected to grow seventy-three percent in a single year. That is analyst pricing on a market that did not exist eighteen months ago, and every one of those figures is a number the buyer has already been told to plan against.
And then the vendors themselves. More than a hundred companies signed an open letter, signed by OpenAI, Anthropic, Amazon Web Services, Microsoft and more than a hundred others, saying organizations have months to strengthen defenses against AI-enabled attacks on critical infrastructure. That letter is a hundred companies telling their own customers to spend money. Take it as what it is. It also names the buying window with a specificity a vendor rarely uses in public. Months.
Three votes. Same direction. Nobody consulted the MSP delivering any of it. None of them touched the other half of the bill, for a different one.
The Half That Doesn’t Move
Nine days from now, on September eleventh, Europe’s Cyber Resilience Act begins requiring manufacturers to report actively exploited vulnerabilities within twenty-four hours of discovery. Full notifications go in within seventy-two. A corrective report is due fourteen days after a fix is available, and severe incidents get a one-month deadline. All of it flows through a single reporting platform coordinated by the European Union Agency for Cybersecurity, which comes online that same day. The Act covers every product with digital elements sold into the EU, so any global vendor with a European customer inherits the clock.
That is one clock. There are two others.
The European Commission has designated ChatGPT under the highest-scrutiny tier of the Digital Services Act at a hundred and fifty-nine million European users. The designation triggers annual systemic-risk assessments — on illegal content, on minors, on mental wellbeing, on electoral processes — and OpenAI’s first assessment is due by the end of November. Fines run to six percent of global turnover. That is a second clock, running against a different vendor with a different set of obligations.
The third is further out. On January twentieth of 2027, the European Union Machinery Regulation extends safety-function oversight to AI-controlled equipment. Anthropic has already released a research-preview standard describing how a model should safely operate a piece of hardware — encoding what a robot arm can and cannot do — as its own answer to that regulation. So the vendors already know the calendar. They are writing the pre-answer.
Notice what all three clocks have in common. Each of them names a specific party who owes something to a regulator by a specific hour. And in every case, the party named is not the model provider. It is whoever deployed the thing.
That is the mechanism. The market can reprice the tool. The vendors can consolidate the tool. Neither of them can consolidate a name on a disclosure report — because the whole point of naming it is that the name doesn’t move.
That name has to land on someone. This is what it looks like when it does.
Where The Call Lands
Last week, hackers weaponized an AI coding agent called Cursor — the product used across the industry to write code, and reportedly deployed at SpaceX — and used it to breach a Belgian chemical company and six other firms. Not through phishing. Not through a stolen password. Through the agent itself, which was already inside the environment doing the work it was hired to do.
Now think about where September eleventh’s clocks land on that story. Under the CRA, Anysphere — which makes Cursor — has twenty-four hours to notify a regulator of the actively exploited vulnerability, and seventy-two hours to file the full report. And under the EU’s separate incident-notification regime for critical-sector operators, the Belgian chemical company has its own reporting duty on its own clock. Two specific parties. Two specific reports. Neither of them is Anthropic, whose model powers the tool. Neither of them is SpaceX, whose engineers were using it. In every case, the regulator named someone specific — and that someone is not the party that shipped the model. That is what the accountability call looks like when it arrives. Now scale it down to the MSP business, where it looks the same but comes at a smaller invoice.
Two weeks ago, a critical bug in N-able’s Passportal browser extension — the password vault used by more than seventy-three thousand MSP techs each week — got rated a nine point four out of ten. N-able patched it within twenty-four hours. Their internal security response team was credited for the speed. And then something else happened, worth naming out loud. Nobody moved off Passportal. There was no ripple. The MSPs running it read the advisory, applied the update, rotated where they had to, and stayed. Which is another way of saying: whatever discount the market once put on N-able for having been part of SolarWinds when Sunburst hit, several years ago, is measurably gone. The vendor sold. The customers stayed. The prevention half of the bill treats vendor history as a rounding error now.
But note what did not go away. Every MSP running Passportal had a follow-on action they owed their own clients — invalidate sessions, rotate high-value credentials, review vault activity. That is the shape of accountability landing at the delivery point. The vendor patched. The deployer answered.
So here is the choice, and it is the same choice regardless of which side of the Atlantic you sit on.
Rebuild your security book around the line that carries the name — the person who owns the disclosure clock, the number the client calls at two in the morning, the incident package that gets handed to a regulator or an insurer — or keep pricing the install line, in a market whose price is being set by an earnings-day rally, a hundred-signatory letter, and a September eleventh deadline that all landed without asking.
There is an objection to all of that a client will raise on the first call. It is worth saying explicitly.
The obvious objection is that clients do not pay for what they cannot see — and until they get an actual incident, an accountability line item looks like padding and the install line looks like the service. But the point of the CRA calendar is that every client with EU exposure now has a fixed date after which they will absolutely see it. September eleventh is the day the invisible half becomes the audited half, and every provider who spent this month billing on install alone is going to be renegotiating that renewal without a compelling answer for what they were doing about the reporting seam.
What to Consider
Anchor the pitch on the date, not the incident. The pitch that lands in September is the one that names September eleventh out loud — because it is the only pitch that flips the objection from “we haven’t had an incident” to “we don’t have to wait for one.” Send a one-page brief this week to every client with EU exposure and every client whose largest supplier has EU exposure, and put the date and the twenty-four-hour reporting cadence in the first paragraph. The window where naming the date is novel closes the day the date arrives.
Bring an incident that already happened. The Belgian chemical company breach is a public example a client can google in thirty seconds — you did not have to invent it, and the deployer named in the story is the same shape of party your client is. Use it. Walk into the review, say the sentence, and let the client picture their own name in the position that company is now in. The objection dies at the moment they see the shape of the party who owes the report and realize the shape is theirs.
Price the pilot around the report, not the retainer. Do not open the accountability line by adding a fee to the existing agreement — open it by pricing a single deliverable, once, at a real number: a tabletop exercise ending in a written incident package the client can hand to counsel or an insurer, priced against the CRA cadence. That converts “padding” into “artifact” in one purchase, and if you get the price right, they buy the retainer next quarter for less than they would have negotiated a fee against a blank page.
If this trend continues: By the middle of 2027, when the Machinery Regulation lands and the DSA assessment cycle has completed a full lap, the accountability line will be a standard schedule inside every professional-services agreement in the sector — and the providers who did not open one this September will be adding it against a benchmark price set by whoever moved first.

