In March 2024, a Sacramento law firm called Mastagni Holstedt sued its managed service provider for more than $1 million. Black Basta ransomware went through the firm, the backups got deleted, and the firm says it was forced to pay. The suit doesn't claim the MSP launched the attack. It claims the MSP failed to adequately protect the firm — that stopping the attack was the IT provider's job.
That assumption is the story. If you run an MSP or any managed IT shop, your clients have already assigned you the security job. The open questions are whether you're getting paid for it and whether you can deliver it.
The clients decided without you
In ConnectWise's 2024 SMB research, 62% of small and mid-size businesses said they'd definitely consider switching providers for the right security offering, up from 40% in 2020, and respondents were willing to pay 47% more on average to get it. At the top of the market the verdict is already in. Among MSPs clearing $10 million in revenue, 97% sell managed security.
Insurers reached the same conclusion. Carriers that spent the early 2020s forcing MFA onto small businesses are now doing the same with managed detection and response, and when an incident happens anyway, some have started suing the IT provider to recover the payout. A Chubb company filed exactly that suit last September: $500,000 from an IT services firm that, the insurer says, was contractually required to set up multi-factor authentication and didn't. Hunton's write-up of the case adds that carriers now routinely pull vendor contracts after an incident to evaluate whom they can pursue. Your MSA is being read by people looking for someone to bill.
You're also the front door
A 2022 joint advisory from CISA, the NSA, the FBI, and their UK, Australian, Canadian, and New Zealand counterparts warned that malicious actors, state-sponsored groups included, would "step up their targeting of MSPs" to exploit "provider-customer network trust relationships." The record: Kaseya's 2021 VSA attack reached as many as 1,500 downstream businesses through roughly 50 MSPs. Last year, DragonForce operators went through an MSP's SimpleHelp instance to push ransomware onto the MSP's clients, and CISA published an advisory on SimpleHelp exploitation running since January 2025. ConnectWise itself disclosed a nation-state intrusion. This spring, Huntress watched attackers exploit a critical Bomgar flaw at an MSP, an incident that forced the isolation of 78 businesses and led to follow-on exploitation at four downstream customers. Remote-management tooling concentrates a hundred networks behind one login, and At-Bay's claims data now pegs remote-access tools as the entry point in 80% of direct ransomware claims.
The rules arrive through your clients
There's no federal MSP regulator in the US, and it doesn't matter. Europe's NIS2 directive names managed service providers as a high-criticality sector outright, with fines for the largest reaching €10 million or 2% of global turnover, whichever is higher. The CMMC acquisition rule took effect last November — if your clients touch Defense Department contracts, their certification obligations flow down to whoever handles their data, including you. And the FTC's Safeguards Rule tells covered businesses to pick service providers with the skills to maintain safeguards, to write security expectations into the contract, and to monitor those providers. Each of those makes "we don't really do security" a disqualifying answer in a client's vendor review.
The build math
A US security analyst runs a median $124,910 in salary before benefits, and Expel's staffing math says safe 24/7 coverage takes about a dozen analysts, which puts the staffing floor above $1 million a year before you've bought a single tool. Arctic Wolf's all-in estimate for a real SOC lands between $2 million and $7 million annually. Both are vendors selling the alternative, so season to taste, but neither estimate comes in low. In Sophos's survey of 350 MSPs, the shortage of in-house security skills ranked as the single biggest risk to their own business and their clients', ahead of the attackers themselves. The same survey found 81% of MSPs offer managed detection and response, and two-thirds of those deliver it through a third party. Most of the industry already rents the wing instead of building it.
Where Sythe fits
Disclosure before the pitch: security wings for lean teams are the business we're in, so discount the pitch accordingly. We run penetration tests billed per engagement with the retest included; vulnerability management that scans continuously with humans doing the triage; monitoring and detection that keeps eyes on logs and endpoints around the clock; incident response you can call without being on a plan; and compliance coverage that includes CMMC Levels 1 and 2. Today our clients are mostly startups and SMBs who come to us direct. If you're an MSP that would rather put a real wing behind your service than staff one, talk to us.
The pushback we take seriously
MSP margins are thin, security talent has priced itself out of reach, and reselling someone else's operation has its own risk, because the client relationship is yours and you take the blame when a partner slips. No argument from us on any of that. Some shops can and do run security in-house, and the $10 million-plus tier sells it almost universally. What the data has closed off is the middle position, the MSP that neither sells security nor clearly disclaims it. That's the position the Mastagni suit was aimed at, and the one clients tell surveyors they're leaving.
Read your MSA
Pull up your standard agreement and find the section that says what you actually promise on security. The Mastagni complaint shows what a client will assume if the agreement says nothing. Write down what you deliver, price it, and line up the capacity to deliver it, whether it sits on your payroll or somebody else's.
Sources: MSSP Alert on Mastagni Holstedt v. LanTech; Vanson Bourne / ConnectWise State of SMB Cybersecurity 2024 and the ConnectWise release; Kaseya State of the MSP; Coalition on MDR and insurers; Hunton on the ACE American subrogation suit; CISA AA22-131A and AA25-163A; Kaseya on the 2021 VSA attack; Sophos on DragonForce/SimpleHelp; BleepingComputer on the ConnectWise breach; Huntress on Bomgar exploitation; At-Bay 2025 InsurSec Report; NIS2, Directive (EU) 2022/2555; BDO on the CMMC acquisition rule; FTC Safeguards Rule guidance; BLS on information security analysts; Expel and Arctic Wolf on SOC build costs; Sophos MSP Perspectives 2024.
