MSSP, Managed Security Services, AI benefits/risks, Bug Bounties

MSSPs Must Grow Beyond Monitoring and Detection: Hack the Box Report

Digital shield blocking malware attacks in realtime, cybersecurity, prevention

MSSPs are very good at monitoring their clients’ environments and detecting security threats, but they fall short when it comes to preventing attacks and simulating adversary activities.

That’s what Hack The Box, whose platform allows organizations to assess and develop cyber skills, found when testing the performance of service providers across 40 different challenges.

In a summary of the report, the UK-based company noted that MSSPs “have become indispensable to modern cyber defense. With enterprises facing persistent skills shortages, many are outsourcing core security functions – from monitoring and incident response to threat hunting and adversary emulation.”

That said, “the findings point to a clear narrative: MSSPs are excellent at scaling detection and monitoring across clients, but need deeper preventive and adversary simulation capabilities to keep pace with sophisticated threat actors.”

Security in Multiple Sectors Tested

MSSPs were one of several sectors – such as financial services and healthcare – that were put through the paces for Hack The Box’s Global Cyber Skills Benchmark 2025 report. When including all sectors, the company analyzed performance data from more than 4,500 cybersecurity professionals across 795 security teams worldwide from 40 challenges.

What Hack The Box found were ongoing skill gaps that leaving critical systems vulnerable to cybercriminals, including in highly regulated industries.

“Cyber threats evolve daily, yet many organizations still measure readiness through compliance alone,” Hack The Box founder and CEO Haris Pylarinos said in a blog post. “What the data shows is that resilience comes from capability. We need to rethink how we prepare our teams, not just how we audit them.”

The organization used performance data from IT services and business services teams – which it said were “arguably” the closes proxies to MSSPs – to identify the strengths and weaknesses of MSSPs, and mapped the performance data against the MITRE ATT&CK framework to outline their maximum value and persistent gaps.

Strengths and Weaknesses

The service providers showed strong open source intelligence (OSINT), with a 64.5% rate of solving such challenges, and forensics (62.8%), both of which indicate effective detection and intelligence gathering, according to Hack The Box.

The results for initial access and execution were not as good, with web security and secure coding at about 20%, which the testers said suggest “MSSPs may struggle to prevent exploitation of misconfigurations and custom apps.”

There also were weak offensive skills – 9.8% solve rate for Pwn and less than 15% for Fullpwn – in privilege escalation and persistence, limiting their ability to emulate the real behavior of adversaries. Meanwhile, cloud readiness and AI-assisted workflows are putting MSSPs into a good position for containing incidents, but prevention needs to improve, Hack The Box reported.

An Evolving Landscape

The results come as the landscape for MSSPs is being affected by three converging trends, the first of which – unsurprisingly – AI at scale. At 38.3%, MSSPs are better than average in adopting AI, which gives them the opportunity to cost-efficiently scale their services in such areas as AI-driven monitoring, log parsing, and detection.

However, “weak secure coding means AI-assisted development could amplify vulnerabilities,” the testers wrote.

MSSPs also are in position to operationalize continuous threat exposure management (CTEM), with benchmarking and adversary emulation becoming differentiators by building on their strengths in raw detection by translating that into measurable resilience.

'Capability Pods' Needed

In addition, they need to understand that particular sectors need specific capabilities. For example, financial organizations are looking for blockchain and Web3 security, while those in the energy space are demanding industrial control system (ICS) and operational technology (OT) resilience and retail entities needing strong web and supply chain defenses.

MSSPs need to be able to address these demands buy building “capability pods” – sub-teams with industry-specific skills – to address these needs, according to Hack the Box.

The report found that “MSSPs are strong generalists but lag in niche specialization,” that they’re strong in detection but weak in prevention and offensive depth, and the AI brings both scaling power as well as risks if there remain gaps in secure coding.

Go Beyond the Basics

For Chris Gonsalves, chief research officer at Channelnomics, the results in Hack the Box’s study reflect well what’s going on with MSSPs.

“For an MSSP, being really good at detection is like a pro chef nailing the boiling of water for pasta,” Gonsalves told MSSP Alert. “It's like, ‘Yeah, cool. ... What else ya got?’ The basic security blocking and tackling stuff hasn't been enough for a legit MSSP for quite a while now.”

The research exposes a gap in specialized capabilities that separates security services market leaders from also-rans, he said, adding that “anybody can do monitoring and detection, but can you really keep clients safe from today's sophisticated attackers if you're coming up short in next-level web and code security skills? Or proactive, customized threat assessment and risk management? No. No you cannot.”

An MSSP's Value

The value of MSSP comes from being able to handle high-stakes, specialized defenses and controls that their clients can't because those organizations don’t have the people and skills needed to mount their own defenses.

“An MSSP that isn't solving for those skills and capabilities gaps is ... posing as a service provider in a way that's putting client organizations at real risk,” Gonsalves said. “As this research rightly points out, the smart money is on the MSSP taking a systematic approach to developing their practices, taking advantage of all available force multipliers, to ensure they are ready to defend their customers effectively against all manner of threats, now and tomorrow.”

Jeffrey Burt

Jeffrey Burt has been a journalist for almost 40 years, moving from general-circulation newspapers to IT news sites in 2000. He’s an expert analyst and writer on cybersecurity, data center infrastructure, AI, and a host of other subjects for a range of organizations, including CyberRisk Alliance, eWEEK, Techstrong Group, The Next Platform, and The Register.

You can skip this ad in 5 seconds