The year 2022 seemed to be a tipping point for MSSPs and SOAR. While adoption of automation among managed service providers has been growing for several years, there was a noticeable acceleration in the past 12 months. These days, when we talk to MSSP leadership about SOAR, they’re already paying attention and they usually have plans to implement security automation sooner rather than later.This was also our first year writing guest posts for MSSP Alert, which has allowed us to communicate directly with leaders in the MSSP industry and see what messages resonate most with them. So, as we move into the new year, we wanted to take a quick look back at some of our most popular articles from 2022. All the original articles are linked below, as well as some more-recent content that expands on the same ideas.You can read the entire article here.
Guest blog courtesy of D3 Security. Read more D3 Security guest blogs here. Regularly contributed guest blogs are part of MSSP Alert’s sponsorship program.
Four Ways MSSPs are Improving their Margins with Next-Generation SOAR
Our first guest post on MSSP Alert was one of our most popular, explaining how the new generation of SOAR technology was driving business outcomes for MSSPs. If you want to learn more about this topic, we recently produced a case study video with VerSprite about how they are achieving some of the things described in the article. Here’s an excerpt from the article:NextGen SOAR Enables Higher-Value CapabilitiesMSSPs use SOAR as a differentiator that expands the range of services they can provide, and the revenue they can bring in. Even if you are simply monitoring alerts for your clients, SOAR enables you to integrate with all of your clients’ alert sources as well as threat intelligence sources. So you can drive alerting from more sources and offer more comprehensive triage, correlation, and enrichment.For MSSPs that have wanted to reimagine their offerings and stay ahead of the increasingly competitive field, SOAR’s response capabilities also enable MDR-like functions. With SOAR, you can handle the entire incident lifecycle if necessary — such as enriching alerts with intelligence and orchestrating response actions — even if you don’t have direct access to your client’s tools. Instead of simply alerting their clients of threats, MSSPs that use SOAR are able to resolve threats themselves, allowing them to ‘close the loop’ and maximize the value they provide. The possibilities for ambitious MSSPs are expansive. We have seen MSSPs use SOAR to offer threat hunting services, by collecting IOCs from incidents in the SOAR tool and running playbooks that orchestrate searches for those IOCs across the tech stack. With next-generation SOAR tools, you can also grow revenue through desirable add-ons like MITRE ATT&CK TTP correlation and reporting.You can read the entire post here.How MSSPs can Beat MDRs at their Own Game
In May, we published another popular post, this time about a topic that all MSSPs should be concerned about: MDR. This article had an optimistic message, however, describing the ways MSSPs can leverage SOAR to keep up with the MDR firms they compete with. We recently expanded on some of the features described in this article in a post on our own blog.Here’s an excerpt from the guest post:The Opportunity for MSSPsMSSPs are faced with a choice: keep providing the same services, and risk seeing their client base shrink, or take steps to evolve. Armed with SOAR, MSSPs have the opportunity to present clients with an alternative to the EDR/XDR-based services that major MDRs are promoting. Using SOAR to upgrade your services has several advantages, including:- No vendor lock-in. Adding a vendor-centric solution like XDR isn’t the answer for MSSPs. That will limit you to the clients who use that vendors’ tools. With SOAR, your clients can use whatever tools they want.
- End-to-end, fully configurable playbooks. Not just simple automated actions.
- Go beyond EDR and NDR. With SOAR integrations, you can ingest data from, and orchestrate actions across, cloud systems, SIEM, email servers, and more.
- Efficient use of limited resources. With automation, adding new services isn’t an impossible task for MSSPs. You don’t need to add more staff or learn several new tools. SOAR provides a single interface from which to orchestrate detection and response.