MSSP, AI/ML

AI is compressing the attack lifecycle. MSSPs need to keep up

COMMENTARY: Attackers are using AI to move faster, so MSSPs have to get faster at deciding what matters and what to do next. More alerts will not solve that. Better context and prioritization will. AI can help with both, but when a response could disrupt a customer’s business, human judgment still matters.


AI is changing cybersecurity, but not in the way many headlines suggest.

The biggest AI impact isn't that it has created entirely new classes of cyberattacks, but that it has dramatically compressed the time attackers take to move from identifying an opportunity to exploiting it. In parallel, attackers are leveraging AI to expand their own skillsets, enabling less experienced actors to perform more sophisticated tactics.

Automated vulnerability discovery and more convincing social engineering tactics that can be personalized at scale are being used to significantly grow the number of potential victims. And AI can now generate unique signatures for each attack, helping threat actors avoid signature-based detection. Once inside the environment, AI can be used to navigate networks, erase its own tracks, and corrupt evidence.

This shift by attackers has important implications for MSSPs. The challenge is translating these compressed attacker timelines into faster decisions across diverse customer environments, where teams must determine what matters most and where resources should be focused.

The stakes are also different for MSSPs because their responsibility extends beyond protecting a single organization. The centralized access, shared services, and management platforms that allow providers to operate efficiently can also create concentration risk if compromised. The 2021 Kaseya incident demonstrated how attackers can exploit trusted provider infrastructure to impact hundreds of downstream customers through a single breach.

For MSSPs responsible for protecting dozens or hundreds of customer environments, that means security operations must improve their ability to evaluate activity, prioritize risk, and respond. AI can help make that possible, but only when it's paired with real-world incident intelligence and experienced human judgment.

Threat actors are benefiting from the AI boom

Previously, the cybersecurity community tracked and recognized threat actor groups based on their attack methodologies and calling cards. Certain groups were known to be more technically skilled and sophisticated than others. Threat actors are now able to leverage AI, like the rest of us, to greatly expand their skillsets. For them, it enables greater capabilities in programming malware, hunting for vulnerabilities, evading defenses, and fortifying their footholds within environments.

The risks posed by data exfiltration tactics have also increased since the wide availability of AI. Threat actor data enumeration and exfiltration within a compromised environment used to involve high-level scans and bulk grabs. There was little risk the threat actor fully understood the data they had accessed. Now, threat actors use AI to scan through their successfully exfiltrated data to provide pressuring summaries and classifications. And internal AI tools like Microsoft CoPilot are starting to be used by threat actors to perform targeted searches for sensitive data types within cloud storage. Attacks will only become more difficult to identify and more impactful regardless of the threat actor at fault.

More data doesn't automatically create better security

Many organizations have responded to these evolving threats by investing in additional security tools. Endpoint detection and response, identity protection, cloud security platforms, SIEMs, and XDR technologies all provide valuable visibility. But visibility alone doesn't create resilience.

Security teams are already overwhelmed by alerts, telemetry, and competing priorities. AI has the potential to improve that situation, not by generating even more information, but by helping analysts determine what deserves attention first. Context matters.

For MSSPs, the same detection can represent very different levels of risk depending on a client's environment, security controls, business operations, and exposure. Prioritization can't rely solely on generic severity scores. It should reflect what's actually being exploited against similar organizations, alongside the vulnerabilities, identities, and assets that matter most within each customer's environment.

For example, a scheduled task created through native Windows tools can look like routine administrative housekeeping, the kind of activity a client's own team would have no reason to flag. The difference only becomes visible once you have seen that specific sequence used to establish persistence in a real investigation.

This kind of prioritization, tuned to each environment and grounded in investigative experience, becomes increasingly valuable as MSSPs are expected to deliver faster detection, investigations, and recommendations across diverse customer environments, where a missed signal in one environment can have implications beyond a single organization.

Real incident response creates better AI

One of AI's greatest opportunities in cybersecurity is helping organizations learn from real incidents. MSSPs don't have to generate this intelligence through their own engagements alone. Patterns identified across thousands of investigations can strengthen detection and prioritization before those attack techniques appear in customer environments.

Security products see what they're configured to monitor. They retain the data they're configured to collect and generate alerts according to predefined logic. That's essential, but it rarely tells the complete story of an intrusion.

During incident response engagements, investigators routinely uncover persistence mechanisms, attacker tooling, credential abuse, deleted artifacts, lateral movement techniques, and other evidence that either generated no alert or wasn’t previously associated with the threat actor.

That forensic evidence provides something AI models need but often lack: operational context grounded in actual adversary behavior.

When AI is informed by real investigations rather than theoretical severity scores or generic threat intelligence alone, it can produce recommendations that better reflect how attacks unfold in practice. Instead of treating every vulnerability as equally urgent, defenders can prioritize the exposures that attackers are actively exploiting. And rather than assuming every security control provides equal value, organizations can evaluate which controls consistently disrupt attacks and which repeatedly fail to provide meaningful detection or response.

AI still can’t lead a crisis

As valuable as AI can be, some aspects of cybersecurity remain fundamentally human. When an organization experiences a ransomware attack or other significant security incident, leaders must make decisions that extend far beyond technical analysis. They need to evaluate business risk, coordinate communications, engage legal counsel, prioritize recovery, manage executive stakeholders, and make difficult operational tradeoffs under pressure. AI cannot yet effectively understand the operational risk of isolating a critical application server that is showing signs of infection and weigh the pros and cons to make the correct decision.

AI can surface relevant information faster. It can organize evidence, identify patterns, summarize investigations, and recommend next steps. But when an MSSP is managing incidents across multiple client environments simultaneously, technology alone cannot coordinate competing priorities, balance customer expectations, or make the judgment calls required as the scope and complexity of a crisis expand.

The organizations that consistently respond well to major incidents aren't simply the ones with the most advanced technology. They're the ones that have established decision-making processes, clearly defined responsibilities, tested response plans, and leadership teams prepared to act when every minute matters. For MSSPs, that leadership becomes even more critical, as every decision can affect multiple customers with different environments, business priorities, and recovery requirements.

Cyber defense is about scaling judgment

For MSSPs, the challenge is not simply responding faster to individual threats. It is reducing risk across an entire client roster, where the impact of a single failure can extend across multiple customers and where trust must be maintained at scale.

The most effective providers will use AI to extend security expertise – applying lessons from real incidents, improving prioritization, and helping analysts focus attention where it matters most. But its value comes from supporting professionals who understand context, risk, and business consequences. In an environment where every customer faces evolving threats, the MSSPs that stand out will be those that can turn intelligence into action consistently at scale: protecting each client with the speed, precision, and judgment that modern attacks demand.


MSSP Alert Perspectives columns are written by trusted members of the managed security services, value-added reseller and solution provider channels or MSSP Alert's staff. Do you have a unique perspective you want to share? Check out our guidelines here and send a pitch to [email protected].

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.
Ryan Ikeler

Ryan Ikeler is the President of MOXFIVE, a cyber incident response and resilience company.

You can skip this ad in 5 seconds