MSSPs are focusing less on running more tools and more on delivering services that scale and keep customers long term. Platform-based models like the NetWitness-Lumifi and Next Dimension-Todyl moves are about standardizing how detection and response is delivered across all clients so margins improve without adding staff, including for IT and OT together. FutureSafe’s Cork alignment pushes security into financial outcomes, where recovery support and measurable risk help drive renewals, not just incident response. At the same time, Booz Allen’s entry into the commercial market increases competition from large service providers with full-stack cyber offerings, while the VulnCheck and Cogent funding rounds show that the next growth area is exposure prioritization and automated remediation. The common direction is clear: MSSPs are building repeatable, multi-tenant services tied to business outcomes, not standalone monitoring.
Market Pulse: Cybersecurity Deals, Funding, and Platform Shifts
NetWitness, Lumifi Roll Out IT/OT MDR Service:
NetWitness and Lumifi launched a joint managed detection and response offering that combines the NetWitness analytics platform with Lumifi’s 24×7 SOC operations, targeting organizations that have deployed security tools but lack the staff to run them. The service extends into operational technology environments, reflecting growing MSSP demand for IT/OT coverage and giving providers a packaged way to address converged threat monitoring without building dedicated OT teams from scratch.
FutureSafe Expands Cork Cyber Partnership Around Financial Outcomes:
FutureSafe updated its relationship with Cork Cyber to deliver unified cyber-risk visibility tied to financial protection for MSP and MSSP customers. The model shifts the conversation from alerting and remediation to client retention after an incident, using measurable risk scoring and recovery support to anchor renewals and cyber-insurance alignment. The move highlights how providers are attaching revenue and retention strategy to security services rather than positioning protection as a stand-alone technical control.
Next Dimension Standardizes Security Stack on Todyl Platform:
Next Dimension is consolidating SIEM, EDR and MXDR delivery onto Todyl’s cloud-native platform across its customer base to create a single operating model for detection and response. The approach reduces tool sprawl inside the SOC and enables consistent, repeatable service delivery across tenants, a key requirement for margin improvement as MSPs transition into full MSSP offerings and look to scale without adding headcount.
Booz Allen Hamilton to acquire Defy Security:
Booz Allen Hamilton agreed to acquire Defy Security to expand its commercial cyber business beyond federal and into enterprise delivery, adding deeper incident response, threat detection and cyber operations capabilities. The deal reflects how large services firms are scaling full-stack security practices that look increasingly similar to MDR and cyber transformation offerings sold to the mid-market and global enterprise.
VulnCheck raises $25M Series B: VulnCheck raised $25 million to scale its exploit and vulnerability intelligence platform as demand grows for real-time visibility into which exposures are actually being weaponized. The funding is aimed at expanding data collection, automation and integrations into security operations workflows, which matters for MSSPs that are shifting from alert handling to exposure prioritization and continuous validation.
Cogent Security raises $42M Series A:
Cogent Security secured $42 million in Series A funding to build AI agents that automate vulnerability triage and remediation workflows, targeting one of the biggest operational bottlenecks inside SOC and risk teams. The thesis is that fixing exposures, not finding them, is the real scalability problem, and the capital will go toward product development and enterprise go-to-market.
Have news to share or just want to connect? Reach us anytime at [email protected] or [email protected].