#MSSPs
Not all expensive MSSPs are good.

But all good MSSPs are expensive. <—

#mss #mdr #soc #cybersecurity
January 31, 2025 at 10:07 PM
First hallway con chat of Summer Camp: how much MSSPs are a pain. 😂 We all have Opinions on this one.
August 2, 2026 at 3:29 AM
We desperately need them .. some of the MSSPs are providing resources that can follow a script but can’t process logically, so you have tickets closed without any thought to the potential to deviate from the script.

We must mentor, train and if possible onboard these young people!
February 14, 2025 at 4:23 PM
MSSPs don’t want you to know this one simple trick…
September 5, 2025 at 2:45 AM
📣 Exciting update! 📣 Judy Security named a Top 250 MSSP by @MSSPAlert! hubs.la/Q02VTTkf0

Judy is an all-in-one platform designed for MSPs that is gaining significant attention. She's the 1st AI-powered cybersecurity assistant offering comprehensive protection. #MeetJudy #msp
Top 250 MSSPs: Cybersecurity Company List and Research for 2024 - MSSP Alert
Top 250 MSSPs: Cybersecurity Company List and Research for 2024 - MSSP Alert
hubs.la
November 16, 2024 at 2:34 AM
@eric.zip connected Claude Code to LimaCharlie and ran a live Cobalt Strike investigation. Every step was logged, auditable, and human-authorized.

The ASW gives AI agents full platform access. For MSSPs, that means scaling operations without scaling headcount.

limacharlie.io/blog/when-cl...
May 8, 2026 at 3:45 PM
So Microsoft is forcing everyone to migrate their Sentinel SIEM from Azure to Defender and it's a PITA, especially if you've got arrangements with MSSPs to like run your SOC and stuff. Currently that's just done through B2B and Azure Lighthouse but now there's allll this other shit.
July 28, 2026 at 9:27 AM
Recorded Future’s Hatching is currently hiring for a malware analyst and software engineer: hatching.io/jobs/
Hatching - Automated malware analysis solutions
Automated malware analysis with Hatching Triage, the high-volume sandbox solution for SOCs, CERTs, SOARs, and MSSPs.
hatching.io
November 26, 2024 at 11:11 AM
Sarà passato nella vostra TL ventimila volte, ma visto che exNano sta facendo un controllo lo riposto. C'è anche la possibilità di ricevere un avviso in caso di violazione dei dati
Have I Been Pwned: Check if your email address has been exposed in a data breach
Search tens of billions of breached records, monitor corporate domains via API, and get alerted when credentials are exposed. Trusted by security teams, MSSPs, and government agencies worldwide.
haveibeenpwned.com
September 5, 2026 at 11:58 AM
Dallas fam! Come hang with industry vets Ken Westin and @bromiley.io for a FREE hands-on workshop. We're diving into Okta detection & IR automation - perfect for MSSPs and IR teams. Plus, drinks after! Limited spots, don't miss out!

lu.ma/st0hr2mx

#cybersecurity #mssp #infosec
January 8, 2025 at 7:45 PM
How is your organization planning the #cybersecurity budget for 2025? Stats I found
Software: 32% : 21% off-prem, 11% on-prem
Services: 28% : MSSPs, consulting
Hardware: 15% : cloud infrastructure, on-prem systems
Personnel: 37% including salaries, benefits, training

www.elisity.com/blog/cyberse...
Cybersecurity Budget Benchmarks for 2025: Essential Planning Guide for Enterprise CISOs
Discover essential cybersecurity budget benchmarks for 2025. Learn key allocation strategies, emerging tech investments, and justification tactics for CISOs planning enterprise security budgets. Exper...
www.elisity.com
November 18, 2024 at 3:52 PM
Not all expensive MSSPs are good.

But all good MSSPs are expensive. <—

#mss #mdr #soc #cybersecurity
January 11, 2025 at 12:02 PM
AWS vetted security MSSPs
June 17, 2025 at 2:59 PM
The Cyber Resilience Corps has been presenting at BSidesLV and DEF CON and publishing research. New work from @cltcberkeley.bsky.social Nonresident Fellow Michael Razeeq on the role of low-cost MSPs and MSSPs in community cyber defense: #CyberCivilDefense #Take9 cltc.berkeley.edu/publication/...
A Path to Long-Term Cyber Resilience for Under-Resourced Organizations - CLTC
Across the United States, state, local, tribal, and territorial governments (“SLTTs”), small- and medium-sized businesses (“SMBs”), and nonprofits are frequently targeted in cyber attacks, leading to ...
cltc.berkeley.edu
August 14, 2025 at 7:23 PM
Not all expensive MSSPs are good.

But all good MSSPs are expensive. <—

#mss #mdr #soc #cybersecurity
February 1, 2025 at 10:26 AM
Not all expensive MSSPs are good.

But all good MSSPs are expensive. <—

#mss #mdr #soc #cybersecurity #ValueOverPrice
March 27, 2025 at 3:10 AM
No Blind Spots: How Top MSSPs Prevent Incidents withLive Threat Visibility
No Blind Spots: How Top MSSPs Prevent Incidents withLive Threat Visibility
Every incident that damages a client starts with a moment of invisibility: a connection the SIEM didn’t flag, a domain the detection rules didn’t know about, an IOC that was active for two days before any feed registered it. Top-performing MSSPs have learned that preventing incidents isn’t primarily a matter of analyst skill or tooling sophistication. It is, first and foremost, a matter of data. Specifically: how fresh it is, how accurate it is, and where it actually comes from. The Visibility Problem at the Heart of Managed Security MSSPs operate in an environment where speed and scale collide daily: Thousands of endpoints, Multiple customer environments, Constant alert fatigue, Aggressive SLAs, Attackers iterating faster than signature updates. An average SOC handles roughly 11,000 alerts per day, yet only about 19% are worth investigating. The rest consume analyst time, dilute focus, and slow down the decisions that actually matter. At the same time, the threats that cause the most damage are often the ones that generate no alert at all, because no indicator of compromise in the detection stack was current enough to catch them. This is the blind spot problem. And it is structural, not accidental. Static detection rules, stale IOC databases, and intelligence that lags behind active campaigns by days or weeks all create windows of undetected exposure. For MSSPs, those windows translate directly into client risk, SLA breaches, and reputational damage. The answer isn’t more alerts. It’s better data: continuously updated, behaviorally grounded, and operationalized across every core workflow. This is where live Threat Intelligence Feeds become operationally critical. Why Data Quality and Speed Are Non-Negotiable An IOC discovered days after a campaign launches may still help with retrospective analysis, but it often arrives too late to prevent compromise. MSSPs need intelligence generated during active campaigns, not after attackers already moved laterally through client environments. The best threat intelligence pipelines prioritize: Real-time collection; Continuous malware detonation; Automated IOC extraction; Rapid feed distribution; Context-rich enrichment; Validation against live attacks. Threat intelligence generated directly from live malware analysis environments provides visibility into attacker infrastructure while campaigns are still active. For MSSPs, that timing difference can mean: stopping credential theft before domain compromise, detecting ransomware staging before encryption, identifying phishing infrastructure before user interaction, uncovering C2 communications before persistence is established. ANY.RUN’s Threat Intelligence Feeds are built directly on top of live malware analysis performed by security teams at more than 15,000 organizations worldwide. This captures the full breadth of what is actually hitting organizations right now — across industries, geographies, and attack types — and extracts indicators from real execution environments rather than static analysis. TI Feeds: key feature, data sources Every IOC (malicious IP, domain, or URL) is extracted from actual sandbox executions and linked back to the analysis session that produced it. The result is intelligence that is not only current but also contextualized: each indicator carries behavioral data showing how the associated malware communicates, spreads, and behaves in a real environment. Detect emerging threats faster, prioritize alerts smarter, and respond before incidents escalate with Threat Intelligence Feeds Covering Critical Blind Spots in Key SOC/MSSP Processes MSSPs and SOCs face recurring visibility gaps in core workflows. Live TI Feeds close them effectively. 1. Detection and Proactive Blocking Traditional signature-based or internal telemetry often lags behind new campaigns, creating windows of exposure. Fresh IOC feeds enable immediate correlation in SIEM, IDS/IPS, firewalls, and SOAR systems. Solution : Integrate TI Feeds via API (STIX, MISP, or native connectors for platforms like Elastic, Splunk, or Rapid7). As new malicious infrastructure appears in sandbox analyses, it streams into detection rules. MSSPs block phishing domains or C2 IPs hours after they activate, often before widespread exploitation. One documented example showed ransomware infrastructure appearing in ANY.RUN data nearly a month before public reports, giving early-mover advantage. This expands threat coverage, reduces blind spots in perimeter and endpoint monitoring, and improves MTTD. 2. Alert Triage and Prioritization SOC analysts drown in alerts, many lacking context. Generic IOCs trigger noise; without enrichment, teams waste time on false positives or miss severity. Solution: TI Feeds provide high-fidelity IOCs paired with sandbox links. When an alert fires on a matching IP or domain, analysts click through to the full session: observed behaviors, dropped files, network calls, and TTPs. This accelerates triage enabling junior analysts to handle more cases confidently and freeing seniors for complex threats. Teams report faster investigations, fewer escalations, and better MTTR. 3. Incident Response and Scoping When an incident is live, every minute of dwell time costs money and increases damage. The most common cause of slow response is not a lack of process. It is context gaps. Analysts must validate indicators, understand attacker intent, assess scope, and make containment decisions, often using multiple disconnected tools and data sources. Solution: Pre-validated, high-confidence IOCs that arrive with behavioral context support instant containment decisions. When an incident is underway, responders can immediately verify whether flagged indicators are linked to known threat actors, understand how the associated malware behaves, and act decisively rather than spending hours on manual enrichment. TI Feeds’ impact &amp; outcome For MSSPs managing multiple client environments simultaneously, this matters at scale. TI Feeds in STIX/TAXII format can be channeled into per-client SIEM instances with consistent formatting and attribution, giving responders the same quality of intelligence across every client environment regardless of their individual tooling. Use case: Microsoft Sentinel integration. ANY.RUN’s TI Feeds deliver directly into Microsoft Sentinel via an out-of-the-box STIX/TAXII connector. Sentinel playbooks, powered by Azure Logic Apps, automatically correlate incoming IOCs with client logs and trigger actions — blocking IPs, isolating endpoints, generating alerts — without manual analyst intervention. Integrating TI Feeds with Microsoft Sentinel The result is response automation that operates at machine speed while still grounded in intelligence derived from human-conducted attack analysis. 4.Reporting, Client Assurance, and Continuous Improvement MSSPs must demonstrate value through metrics and proactive recommendations. Outdated intel undermines credibility. Live feeds deliver measurable gains: higher detection rates (up to 58% more threats in some cases), reduced analysis time, and evidence-based reports showing blocked emerging threats. This strengthens client relationships and competitive positioning. The conversation turns from incident response (reactive, hard to price) to threat prevention (proactive, clearly valuable). For security leaders needing to justify budget to boards and executives, it provides the language they need: concrete evidence of threats stopped, not abstract assurances of coverage. How TI Feeds Fit Without Disrupting Existing Workflows A persistent concern among security leaders considering new intelligence sources is integration complexity. Every new data source that requires custom development, schema translation, or dedicated tooling adds operational overhead — and MSSPs cannot afford to disrupt the workflows serving active clients. ANY.RUN’s TI Feeds address this directly. Delivery in STIX/TAXII and MISP formats means they integrate natively with the platforms already in use: Microsoft Sentinel, Google SecOps, OpenCTI, ThreatConnect, and most SIEM, TIP, IDS/IPS, and EDR solutions. API access and SDK support allow teams to automate indicator ingestion and build custom workflows without dedicated engineering effort. Ti Feeds integration and connection options For MSSPs managing multiple client environments, feed data can be channeled into per-client SIEM instances with consistent formatting — meaning the same intelligence infrastructure serves all clients simultaneously, with per-client customization possible at the delivery layer. Strengthen every SOC workflow with fresh, sandbox-generated threat intelligence from ANY.RUN The gap between MSSPs that consistently prevent incidents and those that mostly respond to them is not a technology gap. It is an intelligence gap — specifically, a gap in the freshness, accuracy, and behavioral depth of the threat data underpinning every SOC process. Blind spots in detection, triage, hunting, response, and reporting all share a common root: intelligence that is too slow, too noisy, or too shallow to support the decisions analysts need to make. Closing those blind spots requires a continuous feed of verified, contextualized indicators derived from real attacks — delivered fast enough to matter, validated thoroughly enough to trust, and integrated seamlessly enough to act on without friction. That is what top MSSPs build their operations on. Not more alerts. Better data. The post No Blind Spots: How Top MSSPs Prevent Incidents withLive Threat Visibility appeared first on Cyber Security News .
cybersecuritynews.com
May 12, 2026 at 5:53 PM
@mariegardiner.bsky.social Can't reply but you might find the answer at haveibeenpwned.com The Manchester/Stansted Airport hack recently caught a lot of people.
Have I Been Pwned: Check if your email address has been exposed in a data breach
Search tens of billions of breached records, monitor corporate domains via API, and get alerted when credentials are exposed. Trusted by security teams, MSSPs, and government agencies worldwide.
haveibeenpwned.com
September 26, 2026 at 9:56 PM
I think I might catch a break contracting with MSSPs in the bay area. I seem to have caught one MSSP's attention with my corporate offerings on Upwork. Let's just hope they wanna close the deal! I am oddly hopeful.
July 16, 2026 at 5:53 AM
MSSPs play a crucial role in today's cybersecurity landscape. Our solutions empower MSSPs to deliver robust security services to their clients.

https://deviceauthority.com/partners/solutions-for-mssps-channel/

#MSSP #CyberSecurityServices #IoTSecurity #OTSecurity
April 30, 2025 at 5:04 PM
Great article, totally agree. We have to realize that some offshore MSSPs are hiring L1 and L2 SOC folks with about the same experience level for 1/5 the cost, so we don’t even hire any entry level SOC folks state side. That’s where some of those entry level jobs have gone.
April 2, 2025 at 5:00 AM