Full Report
A lot of companies use the word managed, leading to the idea that all solutions are the same when it comes to being managed; however, similar doesn’t mean the same.
Analysis Summary
# Industry News: Deconstructing the "Managed" Security Market
## Summary
In an increasingly crowded cybersecurity market, Huntress is challenging the homogenization of the term "managed" by highlighting critical distinctions between service delivery models. The focus is on defining the operational nuances between MSSP, MDR, and managed EDR solutions to help organizations move beyond "acronym soup."
## Key Details
- **Date:** February 14, 2023
- **Companies Involved:** Huntress
- **Category:** Market Analysis / Strategic Positioning
## The Story
The cybersecurity industry is currently saturated with "managed" offerings, leading to a false perception among buyers that all managed services provide equal levels of protection. Huntress addresses this confusion by breaking down the specific human-led components of modern security operations.
The narrative distinguishes between several key categories:
1. **MSSP (Managed Security Services Provider):** Generalists focusing on tool maintenance and alerting across a broad stack.
2. **MDR (Managed Detection and Response):** Specialists focused on threat hunting and active compromise mitigation, heavily reliant on human analysts supported by AI.
3. **Third-Party Managed EDR:** Services that oversee another vendor’s tools (e.g., managing SentinelOne or CrowdStrike).
4. **First-Party Managed EDR:** A vertically integrated approach where the provider manages their own proprietary technology (the Huntress model).
The core of the "managed" promise lies in the element of human interaction—active investigation and curated reporting rather than just automated alert forwarding.
## Business Impact
### For the Companies Involved
- **Huntress:** Positions itself as a transparent educator in the market, building brand equity by simplifying complex procurement decisions for SMBs and MSP partners.
### For Competitors
- **Legacy MSSPs:** Face pressure to demonstrate "true" MDR capabilities (active hunting) rather than just passive monitoring.
- **Pure-play Tool Vendors:** Must contend with the rising demand for services bundled with software, rather than selling "unmanaged" tools alone.
### For Customers
- **Improved Decision-Making:** Greater clarity allows buyers to align their internal resources with the right external service level, potentially reducing "shelfware" or redundant security spend.
- **Risk Mitigation:** Understanding that "managed" doesn't always include "remediation" helps customers close security gaps they didn't know existed.
### For the Market
- **Shift to Outcomes:** The market is moving away from selling "features" toward selling "outcomes" (e.g., stopping a breach rather than just detecting one).
- **Service Verticalization:** We are seeing a trend toward first-party managed solutions where the software and the human analyst come from the same vendor to reduce friction.
## Technical Implications
The distinction between third-party and first-party managed EDR is technically significant. First-party management (Huntress managing Huntress EDR) allows for deeper telemetry access and faster development cycles, as the analysts have a direct feedback loop with the software engineering team.
## Strategic Analysis
- **Market Positioning:** Huntress is moving to own the "human-led" narrative for the SMB and Mid-Market sectors, distancing itself from purely automated, low-cost competitors.
- **Competitive Advantage:** By advocating for first-party managed EDR, Huntress highlights its ability to provide a more cohesive user experience and potentially lower total cost of ownership (TCO) compared to multi-vendor stacks.
- **Challenges:** The ongoing "acronym soup" remains a barrier; convincing a market that is already overwhelmed by terminology to learn more nuanced definitions is an uphill battle.
## Industry Reactions
- **Analyst Opinions:** Market analysts generally agree that the MDR market is consolidating and that "true" MDR—which includes response and remediation—is becoming the baseline requirement for businesses.
- **Market Response:** There is an increasing shift toward providers who can handle the "last mile" of security—not just telling a client they have a problem, but helping fix it.
## Future Outlook
- **Acquisition Trends:** Expect to see more M&A activity where software vendors acquire service capabilities (and vice versa) to offer a unified "managed" experience.
- **Insurance Integration:** As noted in the context, managed security is becoming a prerequisite for cyber insurance, and providers who offer "managed" services will increasingly partner with insurers to offer lower deductibles.
## For Security Professionals
Practitioners should audit their current "managed" contracts. It is vital to determine if your provider is merely forwarding alerts (essentially becoming a "glorified inbox") or if they are performing deep tradecraft analysis and providing actionable remediation steps. If your team is still doing the heavy lifting after an alert is triggered, you are likely using an MSSP model rather than a true MDR service.