MSSP, AI/ML, SOC

MSSP Market News: AI security platforms take on more of the SOC ahead of Black Hat 2026

Adaptive AI ransomware containment lattice isolating critical processes, encrypting decoy files, and neutralizing malicious encryption attempts autonomously

Ahead of Black Hat 2026, cybersecurity vendors are moving beyond AI chatbots and isolated copilots. The bigger push now is toward platforms that can investigate incidents, retain context, and take action with less human intervention. Torq’s SOC Brain learns from past investigations, 7AI’s Federated SIEM lets agents search across security tools without centralizing all the data first, and ReliaQuest is combining AI red teaming with attack-path analysis. Together, these launches challenge the idea that every security workflow must begin and end inside a traditional SIEM.

Data collection and retention remain major SOC expenses, and vendors are betting that agents can work across existing platforms, pull in only the data they need, and move investigations forward without forcing customers to rebuild their security architecture. This could lower operating costs for MSSPs and make it easier to support customers running different combinations of SIEM, cloud, and endpoint tools.

Offensive security is moving in the same direction. Pentera, Novee, Skyhawk Security, and Prescient Security are expanding automated testing across web applications, mobile environments and cloud attack paths. These platforms want to determine whether a weakness is exploitable, understand its wider business impact, and trigger remediation. This gives MSSPs a stronger basis for selling continuous validation and response services instead of periodic reports.

The other major theme is securing AI agents themselves. 1Password is introducing just-in-time privileged access, while Bedrock Data, Backslash Security and Mondoo are tackling data leakage, exposed AI services and shadow AI. SOC automation, identity and data security are starting to converge because the same agent can help defend an organization while also creating a new path to sensitive systems.

However, for MSSPs, the real thing comes down to the practicality of it all. Can the platform support multiple customers, apply different policies to each one, and show how automated decisions were made? It also needs to give MSSPs room to build their own services and pricing around it. That will matter more than broad claims about autonomous security.

Market Pulse: Cybersecurity Deals, Funding, and Platform Shifts

SpecterOps Expands BloodHound Across AWS and AI Identities: SpecterOps has expanded BloodHound Enterprise with support for Amazon Web Services and Microsoft Entra Agent ID, giving security teams a broader view of attack paths across cloud, SaaS, on-premises systems, and AI identities. The company also introduced BloodHound Hunter, an interface built on the Model Context Protocol that connects approved AI agents and internal knowledge sources to BloodHound findings. The new capabilities are designed to help teams trace how attackers could move between systems, identify the most important remediation points, and assess how Copilot agents, delegated identities, service principals and administrative permissions may create indirect routes to privileged access.

Skyhawk Adds AWS Continuum Findings to Cloud Attack Simulations: Skyhawk Security has integrated AWS Continuum with its AI Red Team platform to help security teams identify which application vulnerabilities could be weaponized as part of a broader cloud attack. The integration brings findings from AWS Security Agent into Skyhawk’s continuous attack simulations, where they are evaluated alongside cloud configurations, identities, permissions, network controls, and platform services. Skyhawk runs the simulations against a digital twin of the customer’s environment, allowing teams to trace viable attack paths to sensitive data or critical assets without affecting production systems.

Prophet Security Adds AI Detection Engineering to Its SOC Platform: Prophet Security has launched AI Detection Engineer, a new capability that continuously reviews investigations, threat-hunting results and detection performance to identify coverage gaps, write new detections, and tune existing rules. The product builds a live MITRE ATT&CK coverage map based on completed investigations rather than enabled rule inventories, giving security teams a clearer view of which techniques are actually covered and where blind spots remain. Recommendations are backtested against historical data and include supporting evidence, confidence scores, version control and rollback options, while customers can choose how much autonomy the system receives.

Beazley Security and Halcyon Launch Cyber Resilience Retainer: Beazley Security and Halcyon have launched a joint Cyber Resilience Retainer that combines incident management, digital forensics, recovery support and ransomware defense under a single agreement. The service is designed to give organizations access to breach coaches, technical responders, recovery specialists and Halcyon’s Ransomware Operations Center before an incident occurs, reducing the procurement and coordination delays that can slow response during a crisis. Halcyon will provide ransomware monitoring, containment, decryption support and guidance, while Beazley Security will coordinate the broader technical, legal, regulatory and operational response.

Cyera Plans $1 Billion Oasis Security Acquisition: Cyera has signed a letter of intent to acquire non-human identity security company Oasis Security for about $1 billion, according to TechCrunch. The deal, expected to be paid mostly in cash with the remainder in Cyera shares, would bring Oasis’ technology for monitoring and controlling AI agents and other machine identities into Cyera’s data security platform. Oasis, founded in 2022, has raised about $195 million, while Cyera recently raised $600 million at a $12 billion valuation and surpassed $150 million in annual recurring revenue.

DataBahn Raises $40 Million to Expand Agentic Data Control Platform: DataBahn has raised $40 million in Series B funding to expand its agentic data control plane, bringing its total funding to $59 million. The round was led by Insight Partners, with participation from Forgepoint, GTM Capital and S3 Ventures. The company’s platform collects, governs and routes security, application, operational technology, IoT and observability data across enterprise systems, storage platforms and AI models. DataBahn plans to use the funding to increase research and product development as organizations look for ways to control growing data volumes and send only relevant information to security tools, applications and AI systems.

Frenos Raises $1.52 Million for AI-Based OT Penetration Testing: Frenos has raised a $1.52 million seed extension to expand its AI-powered penetration testing platform for operational technology environments, bringing its total funding to $6.4 million. The round was led by Momenta and Exposition Ventures, with participation from Riptide Ventures, and will support hiring across customer success and AI research. Frenos uses a digital twin of a customer’s OT network to simulate attacker behavior, trace exploitable paths and prioritize vulnerabilities without scanning production systems or disrupting operations. The company is also launching SAIRA Co-Work, an AI assistant designed to analyze live digital-twin data and guide security teams through investigations.

Hush Security Raises $30 Million to Expand AI Agent Governance: Hush Security has raised $30 million in Series A funding to expand its identity and access controls for AI agents and other non-human identities. Akamai joined the round as a strategic investor alongside Battery Ventures and YL Ventures, bringing Hush’s total funding to $41 million. The company’s platform discovers AI agents, registers them centrally and replaces standing credentials with scoped, just-in-time access, while logging activity and giving security teams a central kill switch.

Act Security Launches Cloud Access Platform With $60 Million in Funding: Act Security has emerged from stealth with $60 million in funding and a cloud security platform designed to reduce the access paths available to attackers across cloud environments. The company raised a $20 million seed round led by Team8 and Bessemer Venture Partners, followed by a $40 million Series A led by Notable Capital. Its platform analyzes identity, network and AI access together, then uses existing cloud controls to limit what employees, workloads and AI agents can reach.

Balance Theory Raises $19 Million to Help CISOs Manage Security Spending: Balance Theory has raised $19 million in Series A funding led by SYN Ventures, with participation from DataTribe and TEDCO, to expand its platform for managing cybersecurity investment decisions. The company combines a system of record for security program context, proprietary market intelligence and AI-powered workflows that help CISOs evaluate purchases, coordinate execution and track whether investments continue to deliver value. Balance Theory said its platform currently manages more than $1 billion in cybersecurity spending and that customers see an average first-year return above 300%.

Groundcover Raises $100M as AI Drives Demand for Cloud Observability: Groundcover has raised $100 million in Series C funding to expand its bring-your-own-cloud observability platform as AI workloads drive higher telemetry volumes and demand for more automated operations. The round, led by One Peak with participation from Morgan Stanley Expansion Capital and existing investors, brings the company’s total funding to $160 million. The company plans to use the funding to expand in North America, enter new markets, strengthen its partner and cloud co-sell programs, and add more AI-driven troubleshooting and remediation capabilities to its platform.


Have news to share or just want to connect? Reach anytime at [email protected].

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.
Suparna Chawla Bhasin

Suparna is the Senior Managing Editor for CyberRisk Alliance’s Channel Brands, including MSSP Alert and ChannelE2E. She manages content development, sharpens editorial workflows, and ensures storytelling is tightly aligned with audience needs. With a background in technology, media, and education, she combines strategic insight with creative execution.

You can skip this ad in 5 seconds