Full Report
Keep your MSP armed and ready for attacks, hacks and data breaches with the latest trends in cybersecurity.
Analysis Summary
# Industry News: The Shift to SMB Targeting and the Rise of Managed Detection
## Summary
The cybersecurity landscape is undergoing a fundamental shift as threat actors increasingly pivot their focus toward Small and Medium-sized Businesses (SMBs) and their Managed Service Providers (MSPs). This transition highlights a move away from high-barrier enterprise targets toward "low-hanging fruit" where human error and limited security budgets provide easier points of entry.
## Key Details
- **Date:** April 13, 2021 (Analyst Note: Data reflects the post-pandemic shift in remote work security).
- **Companies Involved:** Huntress (Primary Reporter), MSPs, SMBs.
- **Category:** Market Analysis / Trend Report.
## The Story
Current threat intelligence indicates that hackers are no longer exclusively chasing "big game" enterprises. Instead, 28% of data breaches now directly target SMBs, which often lack the sophisticated security posture of larger corporations. A significant trend is the exploitation of the "MSP-as-a-Hub" model: by breaching a single Managed Service Provider, attackers can gain downstream access to dozens or hundreds of SMB clients, effectively turning the MSP into a force multiplier for the attack.
The report identifies a professionalization of the adversary landscape, where hackers operate in B2B-style partnerships, sharing tradecraft to bypass automated prevention tools. Furthermore, the shift to remote work has expanded the attack surface, making traditional perimeter defenses obsolete and necessitating a move toward human-led threat hunting and Managed Detection and Response (MDR).
## Business Impact
### For the Companies Involved (Huntress/MSPs)
- **Revenue Opportunity:** MSPs have a clear mandate to upsell security services from basic antivirus to full MDR suites.
- **Liability Risk:** MSPs face increased legal and reputational risk as they are now primary targets for supply chain attacks.
### For Competitors
- **Feature War:** Prevention-only tools (Legacy AV) are losing market share to vendors offering integrated "human-in-the-loop" detection services.
- **Price Pressure:** Competitors must find ways to offer enterprise-grade security at price points SMBs can absorb.
### For Customers (SMBs)
- **Increased Vulnerability:** SMBs are facing more sophisticated "brute force" attacks (34% of their breaches) compared to large enterprises.
- **Operational Requirements:** Small businesses must now prioritize security awareness training and multi-factor authentication (MFA) as business-critical expenses rather than optional IT add-ons.
### For the Market
- **Standardization of MDR:** Managed Detection and Response is moving from a luxury service to an industry standard for the mid-market.
- **Supply Chain Focus:** The market is placing a higher premium on "secure-by-design" MSP tools to prevent cascading breaches.
## Technical Implications
The report notes a rise in sophisticated tradecraft designed to bypass automated security stacks. This includes "living off the land" techniques where attackers use legitimate system tools to remain undetected, necessitating a shift from signature-based detection to behavioral analysis and manual threat hunting.
## Strategic Analysis
- **Market Positioning:** Huntress is positioning itself as the essential partner for MSPs who lack the internal resources to run a 24/7 Security Operations Center (SOC).
- **Competitive Advantage:** The focus on "human-powered" detection addresses the limitations of AI-only tools that frequently miss subtle, novel attack patterns.
- **Challenges:** The primary obstacle remains the "security gap" in SMB budgets and the talent shortage of qualified analysts to power these services at scale.
## Industry Reactions
- **Analyst Opinion:** The consensus is that the "MSP as an attack vector" is the most significant threat to the digital economy's "long tail" of small businesses.
- **Market Response:** There is an increased demand for cyber insurance providers to require MDR and specific MSP security protocols before issuing policies.
## Future Outlook
- **Consolidation:** Expect further integration between RMM (Remote Monitoring and Management) tools and MDR platforms.
- **Automation vs. Human:** While AI will assist, the "human element" will remain the gold standard for high-fidelity threat detection through 2026.
- **Regulatory Pressure:** Potential for new government standards regarding how MSPs handle client data and security.
## For Security Professionals
Practitioners should focus on closing the "visibility gap" on remote endpoints. The shift from "preventing" to "detecting and responding" is the most critical strategic move an IT professional can make in the current climate. Strengthening RMM access controls and implementing strict MFA across all technician accounts is no longer optional—it is a baseline requirement for survival.