Skip to main content

folkfox

Skip to main content
Skip to content
MANAGED SECURITY

Private Equity Bought the Channel, and Every Provider Now Sounds the Same

A fox does not fight the pack for the same carcass. It finds the field the pack forgot. The pack this quarter is private equity, and the forgotten field is managed security services positioning.

Quick answerOutside investors had a role in 80% of tracked managed security services and MSP deals in Q1 2026, per Omdia. Consolidation flattens everyone's positioning, which is precisely where a smaller specialist wins.
Section 01

Who owns whom in managed security services now#

The scent came off a single sentence, filed on 19 August 2026. Channel Dive reported that acquisitions increased 73% year over year globally to 64 deals in Q1 2026, and named its source in the same breath: research by its sister company Omdia. Both sit under Informa TechTarget, and Channel Dive puts that disclosure in its opening line rather than a footnote. The candour deserves credit, and it is also the reason to read the figure slowly.

That 73% is growth in tracked, publicly announced deals that Omdia counts, not a measured rise in acquisitions. The method, stated plainly in Omdia's own full-year 2025 research, tracks publicly announced transactions only, and warns that smaller MSP-to-MSP deals are less frequently announced. Announcement appetite is itself a variable. A sponsor-backed buyer books a press release; a founder selling to the firm down the road often does not.

Who is in the room
cybersecurity m&a: share of managed services deals involving an outside investorOutside investorNo outside investorQ1 2025, Outside investor: 6868%Q1 2025, No outside investor: 3232%Q1 2025FY 2025, Outside investor: 6969%FY 2025, No outside investor: 3131%FY 2025Q1 2026, Outside investor: 8080%Q1 2026, No outside investor: 2020%Q1 2026
Omdia's counts, published by its sister company Channel Dive: outside investors had a role in 80% of tracked MSP and MSSP transactions by Q1 2026, while the 2025 bar is Omdia's own 69% private-equity share, a figure Omdia says overstates true private-equity participation.

Composition matters more than the count. Outside investors had a role in 80% of transactions involving an MSP or MSSP in Q1 2026, up from 68% a year earlier. Guard that phrase: outside investors is broader than private equity, and Channel Dive never defines it, so family offices and operator-aligned funds sit inside it too. In the same quarter Omdia identified 14 managed security services provider deals, seven of them private-equity backed. Exactly half, not four fifths.

Omdia's own published baseline is steadier ground. It tracked 169 publicly announced MSP-related transactions across 2025 and puts private equity in 69% of the disclosed deals, then adds, in the very next sentence, that the percentage likely overstates true participation because smaller MSP-to-MSP transactions are less frequently announced. A source disclosing its own upward bias is the sturdiest sourcing here. Quote the caveat with the figure, or leave the figure alone.

The cybersecurity m&a map is regional, not national#

Of those 169 tracked deals, 95% happened within the same region as the acquirer, and Omdia's regions are North America, EMEA and APAC rather than individual countries. A Boston buyer taking a Toronto target sits inside that 95% while being plainly cross-border, so read the cybersecurity m&a map as regional, not domestic. North America carried 37 of the 64 announced deals in Q1 2026, volume up 28%: a shade under three in five, the rest scattered wider than the telling admits.

Eight dated 2026 transactions, each confirmed in the acquirer's own release or an SEC filing rather than in trade coverage.
BuyerTargetAnnounced
AccentureDragos (majority), runZero, NetRise18 June 2026
IntegrisFirst Focus27 April 2026
Arctic WolfSevco Security23 February 2026
SophosArco Cyber10 February 2026
KyndrylSolvinity Group9 February 2026
AEA InvestorsMagna5, from NewSpring Holdings3 February 2026
LevelBlueFortra's Alert Logic managed services27 January 2026
Integrity360Advantus3606 January 2026

Only one deal in that table carries a published price: Accenture's combined enterprise value of approximately $4.175 billion for a majority stake in Dragos plus all of runZero and NetRise, and that trio is operational-technology security tooling rather than managed security services. Every other 2026 transaction here landed with terms undisclosed, so any confident claim about what a managed security services provider is worth this year rests on nothing published.

Scale is the point of the prowl. Accenture has grown its cybersecurity business to $10 billion of revenue in its 2025 financial year, from $700 million in 2016. Kyndryl, buying the Dutch firm Solvinity, told investors in the same filing it had been designated one of 19 critical third-party providers under the European Union's Digital Operational Resilience Act. These buyers are collecting delivery capacity and regulatory standing, not logos.

Section 02

What consolidation does to managed security services copy#

Here is the part no deal tracker counts. When a sponsor rolls six providers into one platform, the brands do not stay six. They get folded into a single positioning deck, one messaging framework, one approved claim set, because that is what integration means and what integration gets rewarded for. The badges migrate, the boilerplate merges, and six distinct voices flatten into one voice with six logos stacked above it.

managed security services: a fox with a hand-painted sign before identical shuttered shopfronts
One hand-painted sign in a row of identical shutters does more work than a bigger shutter.

Watch how the category describes itself and the flattening is already public. LevelBlue calls itself the world's largest pure-play provider of managed security services in its own release on the purchase of Fortra's Alert Logic managed services. Integris says its acquisition of First Focus will make it the largest MSP for SMBs worldwide. Both are self-descriptions in the acquirer's own press release, with no independent ranking behind either. Superlatives stay cheap because nobody scores them.

The buyer cannot verify any of it, so the buyer stops trying. Ask a security leader to separate three managed security services providers on a shortlist and you get pricing, a logo wall and a vague feeling about responsiveness. That is not inattention. It is what happens when everyone has been handed the same words.

What the collapse looks like from the demand side arrived on Reddit this morning, from a buyer with ten thousand users to protect, quoted exactly as posted.

u/Hole-Specialist-2748
Cisco says they'll reach out in something like 6 hours, and Tenable has signed me up to and sent 4 newsletters yet no response from sales? You'd think a potential customer with 10k users and global infastructure would tempt them, but apparently not.
r/cybersecurity, 20 August 2026View on Reddit

A ten-thousand-seat prospect chasing a callback is the demand-side symptom of a supply side busy integrating acquisitions. Sales capacity gets rebuilt after a deal, territories get redrawn, and the enquiry that would have been Tuesday's priority becomes somebody's unowned queue. None of that is malice. It is what happens when the org chart is the project and the pipeline is the afterthought.

Which is precisely the opening. A specialist that answers within the hour, in a named human voice, about one specific problem, is not competing with a rollup's scale. It is competing with a rollup's silence, and silence is beatable this week. That is a brand strategy problem before it is a sales problem: one line only your firm could truthfully write, then the content marketing to prove it in public.

Section 03

The headcount tell#

Rapid7's 2026 Restructuring Plan, as filed

Workforce reduction

0%

The only workforce figure anywhere in the 8-K.

Estimated charges

$0m

Approximately $10m to $11m, mostly cash: transition, notice, severance.

Headcount at last disclosure

2613

Full-time employees at 31 December 2025, per the annual report.

The filing gives a percentage and a cost, never a job count: the trade press figure of roughly 300 roles is 12% of a headcount last disclosed for 31 December 2025.

Rapid7's board approved the plan on 7 August 2026, and the 8-K filed three days later gives one workforce number and one only: a reduction of approximately 12%. No absolute job count appears anywhere in it. The widely repeated figure of 314 roles is a derivation, not a disclosure, being 12% of the 2,613 full-time employees reported for 31 December 2025. Write about 12%, roughly 300 roles against a reported headcount of 2,613, and you are standing on the filing rather than somebody's arithmetic.

Two qualifiers travel badly through trade coverage. The earnings exhibit says approximately 12% of the workforce was notified that their positions would be affected, and the filing notes country consultation requirements may extend the process beyond the fourth quarter of 2026, so 12% have not all left. And $10 to $11 million is charges, not savings. The filing quantifies no benefit at all.

There is a checkable absence too. The Massachusetts WARN tracker, updated on 14 August 2026, lists no Rapid7 notice, despite the Boston headquarters. Nobody should write that as a finding. Federal WARN triggers on fifty or more losses at a single site, a globally distributed cut of 12% may not reach that threshold anywhere, and notices can be filed later. Absence of evidence is not evidence of absence.

So what does a listed vendor's restructuring tell a managed security services buyer? Margin is moving. When platform companies simplify operations and align resources to a core platform, work that sat inside the vendor gets pushed outward, to partners, to managed security services providers, to whoever carries the labour at a lower cost of delivery. Ownership consolidation and vendor thinning are one pressure seen from both ends of the hedgerow.

That is good news for the channel and dangerous for its copy. Demand drifts towards managed delivery at the moment every provider's positioning converges. More work arriving at a market that cannot tell its suppliers apart is a price war with extra steps.

Section 04

A new thing to sell, and a licence to sell it#

On 12 August 2026 the White House opened a programme letting vetted private firms run cyber operations against transnational cyber-enabled crime, under federal supervision. Read the memorandum itself rather than the headlines. Nothing in it hands anybody a licence to hack back on their own initiative, and nothing in it creates a product a managed security services provider can put on a rate card next quarter.

The requirements are the story. A participating company must maintain a bond or escrow in an amount not less than $1 million, forfeitable for contractual non-compliance. Oversight sits with two co-Executive Directors, one designated by the Attorney General at the Department of Justice and one by the Secretary of Homeland Security, who may approve operations only after coordinating with each other, and never anything producing what the memorandum defines as Critical Outcomes.

The clock matters more than the concept. Consensus operating procedures are due within 60 days, a deadline Debevoise & Plimpton dates to 12 October 2026, and those procedures will define eligibility and permitted conduct. A status report follows at 180 days, then annually. As of today nothing is purchasable, nobody is vetted, and a classified annex sits underneath the whole arrangement.

For marketing, the posture is patience plus preparation. Any firm publishing offensive-cyber capability claims before 12 October is writing cheques against rules that do not exist yet, and critical-infrastructure buyers will notice the gap between the claim and the calendar. Win this category by documenting what you would and would not do under federal supervision, in advance.

Section 05

How a smaller firm actually wins the brief now#

The fox does not out-run the hounds. It changes the ground. A smaller provider cannot out-scale a rollup and should not try, because scale is the one claim a rollup has genuinely bought. What a specialist can do is be specific in a market that has quietly priced specificity at zero.

What the buyer is already carrying
What the buyer is already carryingmanaged security services buyers run 83 security products from 29 vendorsProducts: 83Vendors: 29100755025083Products29Vendors
IBM's Institute for Business Value with Palo Alto Networks, fielded from July to September 2024 with 1,000 executives, found the average organisation juggling 83 security products from 29 vendors.

The buyer's real problem is not vendor scarcity. Research from IBM's Institute for Business Value with Palo Alto Networks, fielded from July to September 2024 with 1,000 executives across 21 industries and 18 countries, found organisations juggling an average of 83 different security solutions from 29 vendors. Date it honestly: that is not current-year data, and Palo Alto Networks sells the platform consolidation the study recommends. Discounted for both, the shape still holds.

Which is why the winning managed security services pitch is subtractive. Name the tools you retire, the alerts you absorb, the rota you free. The same study puts the cost of security fragmentation and complexity at an average of 5% of annual revenue, and 52% of those executives called complexity the biggest impediment to their security operations. A finance director recognises that number instantly.

Market sizing will not settle this for you. Grand View Research puts the global managed security services market at USD 38.0 billion in 2025 and USD 41.8 billion in 2026, growing 10.9% a year to 2033. Omdia forecasts global cybersecurity managed services revenue reaching $106bn in 2026 on 14.4% growth. Those are not rival estimates of one market; the second counts far more of the services stack. Pick a publisher, state its scope, admit the estimates diverge.

The ownership data leaves more room than the headline suggests. Read Omdia's 2025 split the other way round and 52 of the 169 tracked deals involved no private equity at all, just under a third, and Omdia's caveat about unannounced smaller transactions means the true independent share is probably higher rather than lower. Independence is an unmeasured majority hiding in the deals nobody announces.

Four moves that separate you from a rollup
Pick the quarry you can catch

One buyer type, one regulatory context, one stack. A managed security services provider that says mid-market manufacturers with operational technology on site is comparable to nothing else on the list.

Write the claim only you can make

Find the sentence a rolled-up rival cannot copy without lying, usually about who answers and how fast, and put it above the fold.

Publish the proof beside the promise

Response times, analyst names, a redacted incident timeline, the tools you removed from a client's stack.

Answer faster than the integration allows

Post-deal sales teams stay slow for several quarters. Route every enquiry to a named human on a published one-hour clock.

One more signal, from a different geography and a different definition. Gartner's Australian forecast has security services, which it defines as including consulting, professional and managed security services, as that market's largest end-user category at more than AU$3.7 billion in 2026, growing 6.9%. Largest and slowest-growing at once is the mark of a mature category, and mature categories get won on distinctiveness.

None of this needs a bigger budget. It needs a narrower claim, evidenced, published before the rollups get round to it and defended where the buyer already looks: organic search, the answer engines, and the paid terms your competitors bid on without a story behind them. That is the work folkfox does for cybersecurity firms. If you want that sentence found and defended, start the conversation.

Questions

Frequently asked questions#

How should a buyer tell an MSSP apart from an MDR provider?

Buyers still open with the same query, and it is a fair one: what's the difference between mssp and mdr in practice? An MSSP manages security infrastructure broadly: firewalls, alerting, patching, compliance reporting across a wide tool estate. MDR is narrower and outcome-shaped, detecting and responding to threats with human analysts and a defined response mandate. Many managed security services providers now sell both, which is why the two labels no longer separate anyone on a shortlist.

What is the difference between an mdr and a soc?

A SOC is a place and a team, yours or rented. MDR is a service contract with a response commitment attached. You can run a SOC without an MDR agreement, and you can buy MDR from a provider whose SOC sits three time zones away. Ask which one carries the response obligation in writing, because that is what shows up during an incident.

Is private equity ownership of a managed security services provider a problem for buyers?

Not automatically. Sponsor capital funds real investment in tooling and coverage. The risks are practical: service teams get restructured, account owners change, roadmaps bend towards the exit. Ask when the sponsor invested, how many bolt-ons have been integrated since, and who owned your account eighteen months ago. Omdia counted 52 of its 169 tracked 2025 deals with no private equity at all.

How do I tell two managed security services providers apart?

Swap the logos on their homepages. If both claim scale, coverage and expertise, that is category description rather than positioning. Compare on what cannot be copied: named analysts, a written response clock, the tools each would remove from your stack, a redacted incident timeline. Then ask each to say which buyer they are wrong for.

What did the White House actually authorise private firms to do?

Less than the headlines suggested. The memorandum of 12 August 2026 creates a vetted programme in which private firms may conduct cyber operations under federal supervision and legal authority, with written approval for each operation and a bond or escrow of not less than $1 million. The operating procedures defining eligibility are not due until 12 October 2026, so nothing is purchasable yet.

Should a smaller provider try to out-scale a consolidated competitor?

No. Scale is the one claim a rollup has genuinely bought, and matching it means competing on price per seat. Compete instead on what consolidation degrades: response speed, named ownership, one specific buyer type, proof published in public. A rolled-up rival cannot promise a one-hour named response while merging three service desks.

Keep reading

Read more on this topic#

Ready to say the one thing your rivals cannot?

We build positioning and demand for security firms in a category where everyone has been handed the same words. At folkfox we find the claim only your firm can make, then prove it in public.