Post Black Hat 2026, as things are starting to settle down, many conversations are simmering - AI in the SOC is still one of them, but now there is more doubt. Is AI in the SOC actually capable of doing anything? Or are vendors just bolting AI onto products they already had and calling themselves AI-native? A lot of AI SOC tools still need multiple integrations and humans checking the output - and the biggest of all - clean data. And then there’s the cost question. AI can get expensive at scale. So if an MSSP is using it across thousands of alerts every day, the real question is: is it actually lowering the cost of the service, or just adding another bill?
That leads into something I think is even more interesting: what does it actually cost to run an MSSP in 2026? Analysts, tooling, 24/7 coverage, insurance, compliance, onboarding, integrations, AI. It adds up very quickly. And there’s only so much customers are willing to pay. So where does the margin come from? Which tools are genuinely helping an MSSP do more with fewer resources, and which ones are just adding more complexity?
And then there’s the stack question. How many cybersecurity vendors does an MSSP actually need? Everyone talks about consolidation, but I’d really like to hear from MSSPs themselves. Show me what your stack looked like three years ago versus today. What did you get rid of? What did you consolidate? Where are you still sticking with best-of-breed? And where does vendor lock-in start becoming a bigger headache than managing another integration?
Market Pulse: Cybersecurity Deals, Funding, and Platform Shifts
CrowdStrike expands Project QuiltWorks to SMBs:
CrowdStrike is expanding Project QuiltWorks to smaller businesses through MSPs, MSSPs, distributors and marketplaces, giving partners another way to package vulnerability discovery, prioritization, remediation and cyber risk services around the Falcon platform. This takes capabilities that were largely aimed at larger organizations and makes them easier to bring into SMB accounts, where MSPs often handle both the technology stack and ongoing security operations.
Sophos brings OpenAI models into Sophos Fusion: Sophos is integrating OpenAI models into Sophos Fusion as it looks to give MSPs more automation across detection, investigation and response. Fusion connects security data across areas including endpoint, network, email, cloud and identity, and the OpenAI integration is designed to help partners work across that information faster.
SonicWall expands endpoint security options for MSPs: SonicWall has expanded its endpoint security portfolio with new options aimed at MSPs that want more flexibility in how they deliver EDR and managed detection services. Partners can manage endpoint security themselves, use SonicWall's managed security operations, or combine the two depending on the customer.
CBTS adds AI-enabled penetration testing services: CBTS has added AI-enabled penetration testing to its security services portfolio, combining automated testing with expert validation to identify weaknesses on a more continuous basis. The approach reflects a broader shift toward treating penetration testing and exposure management as ongoing services rather than annual projects.
Palo Alto Networks extends Cortex into data security: Palo Alto Networks is expanding the Cortex platform with data security capabilities designed to help organizations discover and protect sensitive information across cloud, SaaS and AI environments. The expansion pushes Cortex further beyond traditional SOC workflows and into areas such as data exposure and AI-related risk.
Corma raises $60 million for defensive cybersecurity AI: Corma raised $60 million in seed funding to build an AI foundation model designed specifically for defensive cybersecurity. The company is targeting security operations work such as detection, investigation and threat analysis, putting it in the growing group of startups trying to automate more of the SOC.
Cytix raises €6 million to expand software security platform: Cytix raised €6 million, or about $7 million, in Series A funding to expand its platform for identifying security risks created by software changes. The company is focusing in part on the faster pace of development driven by AI coding tools and already works with managed-service partners including NCC Group and KPMG.
Have news to share or just want to connect? Reach anytime at [email protected].