MSSP, Managed Security Services, Mergers and Acquisitions, MDR, SOC

MSSP Market News: AI Governance Is Becoming a Security Services Differentiator

There's a pretty clear signal from the market: customers want AI in security operations, but they want it used carefully. There is real interest but also real concerns around control. Cyware’s latest survey makes that pretty obvious. Buyers are open to agentic AI, but they do not want it operating without oversight. This means that the market is moving past the excitement phase and into the more practical question of how AI actually gets used safely in live security operations.

Operational data reflects this as well. Cyware found that effective automation between CTI and SecOps tools rose from 13% to 26%, while real-time threat intelligence sharing increased from 17% to 32%. Those numbers are still early, but they show that teams are starting to connect workflows in a more useful way. For MSSPs, that is the real opening. This is not just about adding AI into the stack. It is about turning intelligence, automation, and governance into something customers can actually buy as a managed service.

Again, Sysdig’s latest report pushes the point further. The numbers say that AI-specific packages grew 25% year over year, more than 70% of security teams are using behavior-based detections, and 140% more organizations are automatically terminating suspicious processes when detections fire. Just as important, human users now account for only 2.8% of managed identities, which shows how much cloud risk is shifting toward machines, workloads, and automation itself.

Both reports are pointing in the same direction. MSSPs clearly have an opportunity here, but it is not just about moving faster or adding more AI. What will really set them apart is whether they can run security operations at machine speed without losing control, context, or customer trust.

Market Pulse: Cybersecurity Deals, Funding, and Platform Shifts

Horizon3.ai expands channel push: Horizon3.ai is clearly putting more weight behind the channel. At its partner conference this week, the company said 32% of Q4 bookings came through partners and about 70% of its customers are supported by MSSPs. It is also adding a Partner Advisory Board and expanding partner programs, which shows this is becoming a more structured channel effort, not just a branding exercise. Horizon3.ai wants partners to play a bigger role in delivering continuous security validation services as demand grows for more measurable security outcomes.

Tenable launches an OT asset discovery engine for its exposure management and vulnerability: Tenable has launched a new OT asset discovery engine that brings operational technology, IoT, and shadow IT assets into its exposure management platform without requiring extra hardware or agents. The company is positioning it as a faster way for security teams to get visibility into cyber-physical systems, which have often been harder to monitor than traditional IT environments. Tenable says the tool is designed to reduce blind spots, support compliance efforts, and help organizations unify exposure data across IT, cloud, identity, AI, and OT.

Capsule Security exits stealth with $7M: Capsule Security has emerged from stealth with $7 million in seed funding to build a runtime security layer for AI agents. The startup says its platform monitors agent behavior in real time to catch unsafe actions, abnormal behavior, and data exfiltration, aiming to give enterprises more control as AI agents start acting more like privileged users inside production environments. The company, founded in 2025 and based in Tel Aviv, supports platforms including Cursor, Claude Code, Copilot Studio, ServiceNow, and Salesforce Agentforce. The funding round was led by Lama Partners and Forgepoint Capital International, underscoring continued investor interest in tools built to govern and secure agentic AI.

Artemis launches with AI-Native SecOps platform: Artemis has emerged from stealth with $70 million in funding and a platform designed to address AI-driven attacks that move faster than traditional security operations can handle. The company is positioning its approach around real-time detection and automated response, built for environments where threats evolve continuously and execute within minutes. The platform centers on a dynamic data model that pulls telemetry from across cloud, identity, endpoint, and application environments, then layers in business context to assess whether activity is normal for a given organization. This allows Artemis to generate detections tailored to each customer and correlate signals into a single narrative, reducing the need for manual investigation across multiple tools.


Have news to share or just want to connect? Reach anytime at [email protected].

Suparna Chawla Bhasin

Suparna is the Senior Managing Editor for CyberRisk Alliance’s Channel Brands, including MSSP Alert and ChannelE2E. She manages content development, sharpens editorial workflows, and ensures storytelling is tightly aligned with audience needs. With a background in technology, media, and education, she combines strategic insight with creative execution.

You can skip this ad in 5 seconds