MSSP, AI/ML, SOC

MSSP Market News: AI in security hits two big questions – revenue and responsibility

Black Hat 2026 gave cybersecurity vendors a huge stage for AI in cybersec, but two questions kept coming up all week: who makes money from it, and who is responsible for the outcome?

CISOs want AI in security. That part is pretty clear. But as AI agents start doing more than summarizing alerts and actually move into investigation, response and remediation, the stakes become different. If an agent makes the wrong call, somebody still has to own that decision. That’s why everyone is suddenly talking a lot more about guardrails, permissions, visibility and where humans still need to stay in the loop.

The SOC is where this gets really interesting. Vendors are pushing AI into triage, investigations, threat hunting and response, with the idea that analysts can get through more work without adding people at the same pace. For MSSPs, that could have a direct impact on margins. But nobody wants an autonomous SOC that becomes a black box. The real value will come from getting the balance right between speed and control.

You could also feel the rise of the AI-native security vendors. These companies are building products around agents and AI workflows from day one, rather than adding an assistant to an existing platform. That is forcing older vendors to prove that their AI actually changes how security work gets done.

And then there is the revenue problem. Buyers are tired of huge security stacks. The commercial pressure is pretty straightforward: customers want fewer tools doing more.

That puts a lot more pressure on cybersecurity companies to show outcomes. Faster investigations. Less manual work. Fewer tools. Better response. More customers per analyst for MSSPs. This time, the AI conversation coming out of Black Hat feels a lot more practical now. Everyone wants to know what AI can actually take off their plate, what they should pay for it, and who is accountable when the machine gets something wrong.

Market Pulse: Cybersecurity Deals, Funding, and Platform Shifts

Cribl adds new security capabilities: Cribl added new security capabilities to its AI Platform for Telemetry, giving security teams more ways to manage AI-related activity, telemetry flow and detection engineering. The update includes Cribl App for AI Observability, which is designed to give organizations a unified view of AI activity across models, applications and departments, along with capabilities tied to cost visibility and sensitive data exposure.

Zero Networks launch Least Agency Enforcement: Zero Networks launched Least Agency Enforcement, a new capability built around OWASP’s emerging Least Agency principle for enterprise AI. The product uses identity-based microsegmentation, policy automation and just-in-time MFA to limit which systems AI agents can reach, what resources they can access and when human approval is required for sensitive actions.

Cato Networks introduces Cato Agentic Threat Prevention: Cato Networks introduced Cato Agentic Threat Prevention, a new capability that uses autonomous agents to predict likely attack paths and personalize protections for each customer environment. The system combines Cato’s network and security telemetry, customer activity and threat intelligence to model risk across users, apps, traffic, assets and exposures, then applies protections through Cato’s global points of presence.

Horizon3.ai funding + NodeZero expansion: Horizon3.ai raised $250 million in Series E funding, pushing its valuation above $2 billion and giving the autonomous pentesting company more room to expand NodeZero as security teams move toward continuous validation. Horizon3 also announced NodeZero WebApp Pentesting, extending the platform into autonomous testing for web applications. The company says the capability is designed to show what is actually exploitable, map attack paths to known threat actor tactics and help teams understand the business impact of those paths.

Huntress RMM Guard: Huntress expanded its Managed Endpoint Security Posture Management effort with RMM Guard, making the capability free for customers that already have a Huntress agent deployed. The tool is focused on a problem MSPs know well: attackers abusing remote monitoring and management tools to gain access, maintain persistence or move through customer environments. RMM Guard inventories RMM software on endpoints, lets teams define which tools are approved and blocks unauthorized RMM instances before they can be used for remote control.

Obsidian Security funding: Obsidian Security raised $85 million in Series D funding at a $1.1 billion valuation, with the round tied to growing demand for securing SaaS environments and AI agents that are gaining access to enterprise data. The company’s positioning lands in a timely part of the market as organizations try to understand which users, apps and agents can touch sensitive information across business systems. For MSSPs, the story fits into a broader shift toward SaaS security posture, identity context and AI-agent governance as managed services.

Mimecast Agent Risk Center / Managed Threat Response: Mimecast used Black Hat USA 2026 to introduce Agent Risk Center and a redesigned Managed Threat Response service, giving the company a clearer AI governance and managed-response story. Agent Risk Center is in beta and is designed to help security teams discover, monitor and govern AI agents across the enterprise, including sanctioned and unsanctioned tools. Managed Threat Response combines AI-driven triage with analyst-confirmed remediation for user-reported email threats, with Mimecast saying the service is meant to close the gap around alerts that go uninvestigated.

Proofpoint OEM Program: Proofpoint launched an OEM Program to let technology providers, cybersecurity vendors, MSPs and platform companies embed its threat intelligence and detection capabilities into their own products and services. The program starts with Active Exploits Protection and is designed to give partners a faster way to add threat context, prioritization and AI-ready detection experiences without building global intelligence infrastructure themselves.


Have news to share or just want to connect? Reach anytime at [email protected].

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.
Suparna Chawla Bhasin

Suparna is the Senior Managing Editor for CyberRisk Alliance’s Channel Brands, including MSSP Alert and ChannelE2E. She manages content development, sharpens editorial workflows, and ensures storytelling is tightly aligned with audience needs. With a background in technology, media, and education, she combines strategic insight with creative execution.

You can skip this ad in 5 seconds