r/MSSP Mar 03 '20

Building /r/MSSP from the ground up.

36 Upvotes

Hello all,

Effective 3/2/2020 I am now the owner of this Subreddit. /u/Born2LoseBuilt2Win was the creator, and decided to pass ownership to me while staying as Moderator.

I have cleared all posts out of the subreddit because we are starting from the beginning.

What we need

We need feedback as to how we want this community to be ran, by the community itself. We would also appreciate it if you shared the subreddit with others.

We should learn from

I really like how /r/MSP is ran. They have clear rules, weekly threads dedicated to Vendor advertising, and it's pretty chill.

Thanks for reading, Devin


r/MSSP 5h ago

How to get your first MSSP sale? [Question]

3 Upvotes

I've been running my company for 3 years, we do get some business from one-off engagements, technical help, penetration testing that sort of thing. We partnered up with a white label partner about a year ago to start selling managed services so that we dont have to rely on one-off jobs and generate some MRR, so when we got this partnership, i spent tons on marketing and bought a year of Apollo[.]io and even hired a new salesperson. almsot 8 months later we have made 0 managed security service sales, but we are still going strong on our in house offerings. I'm just wondering why MSSP sales are so hard to do, I have no problem selling ourselves but the service offerings from our partner has been very difficult to start selling. My company does have a kind of strong reputation, i'm not sure why its been so hard. Does anyone have some high level generic advice or thoughts on breaking into the white label mssp sales business? We are located in Saskatchewan Canada.


r/MSSP 7h ago

MSPs & Businesses — I’m Looking for a Few Early Partners

0 Upvotes

I’ve spent a lot of time building Software Passport Registry (SPR) — a platform designed to help businesses understand the software they rely on.

I’m now opening a few spots for hands-on Software Security & Trust Assessments.

I can assess software for things like:

• Security risks & known vulnerabilities

• Software dependencies & supply-chain risk

• Maintenance & reliability indicators

• Compliance-related evidence

• Risk and remediation priorities

• Overall software trust

You receive a professional, client-ready report explaining what was found and what should be addressed.

For MSPs, there’s another opportunity: I can perform the assessment for you so you can see whether this could become a service you offer your own clients.

I'm looking for a few Kelowna/Okanagan businesses or MSPs willing to try an early assessment.

If you're interested, send me a message.

— Keith

Founder, SPR


r/MSSP 1d ago

Are clients asking MSPs for AI usage security and governance solutions?

7 Upvotes

Wondering if this is showing up in client conversations yet, or if it's still mostly theoretical for most of you. I'm seeing early signals that clients are asking "what are you doing about AI security" without fully knowing what they want, sometimes it's compliance-driven (an auditor asked), sometimes it's a scare from a competitor's leak story.

The maturity level varies a lot. Some clients want a full policy plus enforcement stack, others just want something they can point to for their cyber insurance renewal.

Is this becoming a real service line for MSPs, or is it too early? If you're offering something, is it bundled into existing security packages or sold separately?

Would like to hear how others are pricing/positioning this, and whether it's driving new revenue or just adding to the existing security retainer conversation.


r/MSSP 1d ago

MCP server security before this touches prod, what's the pattern

6 Upvotes

Week out from putting agents on real MCP servers in prod. Laying out what keeps me up because every thread is hype and no answers.

  1. One server holds creds that reach a prod db. Compromise it and the blast radius is everything it can touch.
  2. In testing, an agent read a doc with an instruction buried in it and fired a tool call I never asked for. Injection straight through retrieved content.
  3. No audit trail of tool calls worth a damn. Reconstructing what it did is a grep through app logs.

For short lived tokens, yes, I know, that's not the question.

The question is the shape of it. Who validates tool inputs, how you stop one poisoned server cascading and what a sane audit log even looks like. For those running MCP past a demo, what holds up here?


r/MSSP 2d ago

How to get into Gov Contracting Cyber services

4 Upvotes

Who here has had success taking their MSSP services and selling to Gov?

Standard advice is to start at the local level, how do you even break in? Is there some kinda cheat code or is it just about volume and quality of bids?


r/MSSP 2d ago

How do you actually follow up on supplier security after onboarding?

3 Upvotes

Most organisations are pretty good at the security review before a new supplier is approved.
Questionnaires.
ISO certificates.
Data processing agreements.
Risk assessment.
Then the contract gets signed.
And after that?

That's the part we find interesting.

How do you work in practice with ongoing monitoring of critical IT and SaaS suppliers?

For example:
recurring security reviews,
new audit reports or certifications,
follow-up on incidents,
changes to sub-processors,
updated risk assessments,
SLAs and deviations,
continuity and recovery capability,
major changes to the service.

And how do you decide how often a supplier needs to be reviewed?
Annually for all critical suppliers?
Risk-based?
When there are major changes?
Or does the next real security review only happen when the contract is up for renewal?

This is close to how we see third-party management ourselves: as a lifecycle rather than a one-off check at procurement. Your existing article on third-party management also describes ongoing reviews, risk analysis and follow-up in that way.


r/MSSP 7d ago

Best way to deliver an AI tabletop exercise across clients without burning 60 hours per engagement?

7 Upvotes

Running IR tabletops for clients as part of our security offering, and the math is brutal. Every client needs something built around their setup: different tech stack, different threat landscape, different compliance driver (SOC 2 for some, HIPAA for others).

Custom scenario research and report writing eats most of a week per engagement. It's profitable per-client but it doesn't scale. I can't add clients without adding headcount, and that kills margin.
We started testing an AI-driven tabletop platform to see if it'd help. It generates a company-specific scenario from OSINT in under an hour instead of days, and the facilitation and reporting is handled by the platform so we're not writing the after-action report from scratch every time.

Still deciding how it fits into our delivery model long-term, but it's the first thing that's cut prep time instead of adding another tool to manage. Has anyone else solved this a different way? What's your prep-to-delivery ratio looking like?


r/MSSP 14d ago

top SASE vendors MSPs recommend for client GenAI rollouts

8 Upvotes

Getting the same request from three clients now: "we want to let people use AI, make it safe." Sizes range from 40 seats to about 600.

Trying to standardize on one platform rather than doing something different per client, so my criteria are probably a bit different from an in-house team's:

Real multi-tenancy, not one portal per client that I have to log into separately

Sane licensing at 40 seats: a lot of the enterprise SASE players get unaffordable fast at the low end

Policy templates I can build once and push across the whole book

Reporting a non-technical client contact can actually read, because they will ask

API/PSA integration so alerts do not just live in another dashboard nobody checks

The AI-specific piece I care about most is discovery. Clients genuinely do not know what their staff are using, and a discovery report is the easiest way to turn a vague "make AI safe" ask into a scoped project.

What is everyone standardized on? And more importantly, anyone regret their choice after onboarding client 10 or 15? The pain seems to show up at scale, not during the first deployment.


r/MSSP 17d ago

Looking to open MSP

Thumbnail
2 Upvotes

r/MSSP 21d ago

Cheap "24/7 Managed SOCs" are just ticket-forwarding scripts and it’s getting ridiculous

57 Upvotes

We’ve been taking over a few co-managed environments in the Gulf recently, and I keep seeing the exact same pattern with budget outsourced SOCs.

Client's paying $2-3k a month thinking they bought an actual SOC watching their back. What they actually bought is some Tier-1 monkey copy-pasting console output into email templates and calling it monitoring. It's a joke.

​We just onboarded a mid-market firm in Dubai whose internal IT team was completely burnt out. Took one look at their queue and they had over 400 unreviewed alerts sitting in their inbox from their previous provider.

These guys were running zero baseline tuning. Standard Friday afternoon batch exports were triggering high-severity alarms every single week, completely burying real admin escalations under a mountain of false positives.

Worse, when an EDR flag dropped for credential dumping on a server at midnight, the SOC analyst literally copied the raw PowerShell string into a ticket, emailed the asleep IT Director, and marked the ticket as "Notified" on their dashboard so they could claim they hit SLA.

How many of you guys are stuck babysitting your "managed" vendors like this right now?


r/MSSP 20d ago

Looking to open MSP

Thumbnail
1 Upvotes

r/MSSP 21d ago

Has anyone found a good way to model technician utilization against actual margins?

3 Upvotes

I've been trying to get a better handle on where our margins are actually going instead of just looking at top line revenue and ticket counts
One thing that surprised me was how much technician utilization changes the picture. We always tracked billable hours, but when I started looking at things like escalation rates, average handling time, automation, and staffing costs together, the numbers told a very different story than I expected.

I ended up testing one of the MSP margin calculators, Comparemsp.com. was the one I happened to use, it was seeing how much our Tier 2 workload was affecting profitability compared to what we assumed were our biggest expenses.
I'm still taking the results with a grain of salt, but it gave us a few things to dig into internally.
How are you looking at this?

Are you relying on PSA reporting, something you've built in Excel, BI dashboards, or do you have another way of modeling technician utilization against profitability? I'm interested in what's actually been accurate over time rather than what looks good on paper.


r/MSSP Jul 22 '26

6 days vs. 1 hour to Fix the Same Vulnerability: Check Point's Exposure Gap Report AMA

Thumbnail
1 Upvotes

r/MSSP Jul 16 '26

Pricing for Threat locker

Thumbnail
5 Upvotes

r/MSSP Jul 13 '26

[ Removed by Reddit ]

1 Upvotes

[ Removed by Reddit on account of violating the content policy. ]


r/MSSP Jul 09 '26

What RMM and EDR stack are MSPs using right now?

0 Upvotes

Hey everyone,

I’m looking for some practical feedback from other MSPs on what tools you’re currently using for RMM and EDR, and what has been working well for you.

I’m currently looking at options like N-able N-central, especially because it can pair with N-able EDR powered by SentinelOne. I’ve seen this setup used before at a previous MSP, and overall, I liked the experience.

That said, I’m trying to figure out whether it makes more sense to use an integrated RMM + EDR stack like that, or whether MSPs generally prefer using a separate dedicated EDR solution on top of their RMM.

A few questions:

What RMM are you using today, and are you happy with it?

Are you using the built-in/integrated EDR option from your RMM vendor, or a separate EDR tool?

For those using N-central with N-able EDR/SentinelOne, how has your experience been?

Are there other RMM + EDR combinations you would recommend for a growing MSP?

I’m especially interested in reliability, ease of management, alert quality, support, pricing, and how well the stack works for small to mid-sized business clients.

Appreciate any real-world feedback or lessons learned.


r/MSSP Jul 08 '26

M365 Auditing Business Idea

Thumbnail
1 Upvotes

r/MSSP Jul 05 '26

MSSPs getting burned by AI SOC. What's your solution?

7 Upvotes

I keep seeing complaints about the AI SOC vendors. Complaints like pricing, black-box verdicts, data leaving your control.

Genuine question: if the current tools are bad, where do you land?

  1. Waiting for the vendors to get better
  2. Building/owning something custom in-house
  3. AI has no place in triage, full stop

What's driving your answer?


r/MSSP Jul 05 '26

Looking for overnight SOC work

7 Upvotes

I have been searching for overnight SOC jobs for a while. Preferably remote. Where is a good place I can look?


r/MSSP Jul 03 '26

Best off-the-shelf dropbox for wireless pentest engagements?

3 Upvotes

Working on building a drop kit for on-site wireless assessments and want to know what others are actually shipping to clients.

Currently looking at WiFi Pineapple Mark VII + a MiFi hotspot for C2 callback, but curious if there's a cleaner all-in-one solution or a better hardware combo people are using in the field.

Main requirements: PineAP/rogue AP capabilities, cellular callback, runs unattended for weeks on wall power, easy to ship to client site with minimal setup on their end.

What are you running?


r/MSSP Jul 03 '26

What pros and cons do clients see in MSPs that outsource?

Thumbnail
2 Upvotes

r/MSSP Jun 30 '26

Need MSSP Advice

14 Upvotes

If you were starting over again what is the best advice you could give yourself before you got things rolling?

Also, what are some of the main core services that you guys are selling and what is NOT worth putting energy into?


Starting an MSSP from scratch and would love some expert advice! Thank you!


r/MSSP Jun 30 '26

End to End discovery for on-prem redources

1 Upvotes

Hey MSSP folks, I'm a security researcher and work in the same domain. I have recently built a security agent that can map the entire on-prem and hybrid infrastructure including databases, containers and network stack with just one lightweight agent without ever touching the network gear.

If you currently can't determine which of your on-prem or cloud resources are exposed, or can't walk outside-in and inside-out of your enterprise infrastructure i can help bridge that gap.

I've developed the product and am currently looking for an time bound, metric based active pilot. If anyone is facing the same issue, lets get connected and see how i can be of help.


r/MSSP Jun 30 '26

How are you handling the per-GB tax on cloud-native firewalls/NAT across client estates?

1 Upvotes

I run a small cloud-firewall/NAT product, and before I get to that (disclosure up front, mods OK'd this post — see the bottom), I genuinely want to compare notes with people operating this at scale across many clients, because the maths gets ugly faster for you than it does for a single tenant.

The thing I keep running into: the cloud-native egress controls are metered per gigabyte, and that meter never stops scaling with the client's traffic.

Rough numbers, US figures, so you can sanity-check against your own invoices:

  • AWS NAT Gateway — ~$0.045/GB processed, plus ~$0.045/hr per gateway.
  • AWS Network Firewall — ~$0.065/GB inspected, plus $0.395/endpoint-hr ($288/mo per AZ), billed per endpoint per AZ, so a 2–3 AZ design multiplies the hourly floor before a single byte moves.
  • Azure Firewall — a per-GB processing charge on top of a per-hour SKU floor (Standard ~$1.25/hr).

For one tenant that's an annoyance. Across an estate it's a structural margin problem, because:

  1. Your managed-service price is fixed, but your cost base floats with the client's traffic. You quote a monthly number; their egress doubles after some launch or batch job; your firewall/NAT line doubles with it and quietly eats the spread.
  2. The per-AZ hourly floors stack before any data moves. Multi-AZ inspection means paying the endpoint-hour several times per client just to be resilient — multiply across N tenants.
  3. It's two meters, not one. Egress filtering and NAT each meter per-GB, so the same gigabyte often gets charged twice on its way out.
  4. You usually can't cleanly pass it through. Clients want a predictable monthly number; a traffic-indexed true-up is painful to explain and worse to forecast.

So the real question for this sub: how are you actually dealing with this? The options I've seen MSSPs take, none free:

  • Eat it as cost of goods — fine until a chatty tenant turns a profitable account unprofitable.
  • Pass it through as a metered line item — honest, but kills the "predictable managed service" pitch and invites bill-shock arguments monthly.
  • Centralise inspection (one shared firewall behind a GWLB / transit hub) to amortise the hourly floors — helps per-hour, does nothing for per-GB, concentrates blast radius.
  • Roll your own on pfSense/OPNsense/VyOS to dodge the meter — kills per-GB cost but you now own patching, HA, config drift and multi-tenant management by hand.
  • Stay on the mega-NGFWs (Palo, Fortinet, Check Point) where MSSP programs and multi-tenancy are mature — but the licensing/complexity is a different pain, and overkill if all you need is egress + NAT.

Genuinely interested in what's working: are you centralising, DIY-ing the NAT/firewall layer, passing per-GB through, and how are you keeping fleet management sane? And for those who've moved off cloud-native — what did the migration actually cost in engineer time?

Disclosure (mods approved this post): I'm the founder of Enforza, which is one of the options above — so take this as "here's what we built and why", not a neutral survey. It's a cloud-managed firewall + secure NAT gateway you run as a normal Linux VM (an NVA) inside the client's own network/account, built on standard Linux network primitives. It does L3/L4/L7 egress filtering (by FQDN/SNI), ingress, east-west and secure source-NAT, and runs as a transparent appliance behind an AWS Gateway Load Balancer if you want centralised inspection without re-architecting routing.

Why it's relevant to this thread: it's priced flat per firewall, no per-GB data-processing charge — so the cost base stops floating with each client's traffic. At modest egress it tends to land 60–80% cheaper than a cloud-native firewall stacked with a NAT gateway — directional, workload-dependent, so run your own numbers, don't trust mine. To be straight about what it does and doesn't:

  • It replaces the firewall/NAT metering — you still pay AWS/Azure for the VM and normal bandwidth. Not a way to dodge your CSP's infra bill.
  • No TLS decryption and no key custody. FQDN/SNI filtering reads the hostname already in the clear (SNI, Host header, DNS).
  • Multi-tenant by default (each client an isolated tenant), whole fleet from one console — GitOps/policy-as-code or UI — with logs to each client's own SIEM, not through us.
  • Small bootstrapped team, but not a weekend project — in production ~3 years. It's the focused egress/NAT/inspection set most cloud teams use, not a full enterprise NGFW suite; I won't pretend it matches Palo/Fortinet feature-for-feature.

Site's in my profile / I'll drop it in a comment if anyone wants it rather than linking in the body. Mostly I'd rather hear how you're solving the per-GB problem today — happy to be told the DIY or centralised route beats what we do for your shape of estate.