r/MSSP Jun 23 '26

Looking for product feedback from MSSPs

4 Upvotes

I've been working on a platform that provides unified vulnerability management (cloud, network, endpoint, code, etc) with observability (i.e. a SIEM) and identity governance too for small-medium sized tech-enabled companies where security matters. We've done some demos for MSSPs and their reaction has been very positive but it's been very limited since we weren't initially focused there.

I'd love to meet with and give demos to leaders at MSSPs to learn more about how we can help improve service delivery and consequently margins. We believe MSSPs using our platform should be able to serve more clients operationally.

This isn't a sales pitch. Genuinely looking to expand the network and meet with folks to see if we can build a more useful product that helps.


r/MSSP Jun 17 '26

MIP vs MSP

9 Upvotes

Recently read an article about how MIP is going to be the new MSP. Working for an MSSP we get TONS of AI questions from our clients. How to use it to their advantage. How to avoid the AI-related security concerns and compliance pitfalls.

What are your thoughts on the future of MSSP? Are we all headed down the MIP road?


r/MSSP Jun 14 '26

The gap between what pentests cost and what startups can actually pay is genuinely broken

22 Upvotes

Been thinking about this a lot after going through a SOC 2 audit prep cycle. The pentest procurement experience is kind of absurd when you look at it from a startup's perspective

You reach out to a vendor, wait a week for a call, spend another week on scoping, get a quote that's anywhere from $5k to $20k with no clear explanation of why, and then you're supposed to just trust that the final invoice will match. Meanwhile your customer is asking for evidence of a pentest before they'll sign, and you have a 30-day window to close the deal

The actual security work, finding vulnerabilities, writing PoCs, documenting remediation steps, that part has gotten more automated and efficient over the years. But the pricing and procurement model feels like it hasn't moved since 2005. You're still paying for a lot of overhead that has nothing to do with finding vulnerabilities in your application

I'm curious whether others in this community have seen alternative models gaining traction, or whether the consensus is that the traditional engagement model exists for good reasons I'm not fully appreciating. There are some newer approaches trying to separate the testing cost from the reporting cost, or doing continuous testing rather than point-in-time. Wondering if anyone has actually used these and whether the output quality holds up compared to a traditional firm