Building a security-first MSP: what it really takes to differentiate, scale, and own your margin

The market is changing fast. Commodity IT services aren’t building long-term relationships. Prices are being squeezed. And customers want more – not less – from their MSP when it comes to security. Four practitioners from across the MSP ecosystem share what’s actually working.

Key Takeaways:

  • Security has become a C-suite buying decision, and SMBs are catching up fast
  • The MSPs growing fastest are those who’ve moved from point solutions to standardised, outcome-led security portfolios
  • Building your own 24/7 SOC is genuinely hard – and often not the right answer
  • Visibility and action: the two things every MSP needs to protect customers and run a scalable business

The market reality in 2026

Something has changed in how customers think about security, and MSPs across Europe are feeling it. The question used to come from IT managers. Now it comes from the board. Cyber risk has become a business risk conversation, and the scrutiny is intensifying as attacks grow more frequent and regulations tighten.

The SMB segment is catching up with where enterprise thinking was a few years ago. NIS2 and similar frameworks are forcing conversations that weren’t happening before – both about direct obligations and supply chain requirements. A customer may not be a NIS2-regulated entity themselves, but if they supply a company that is, they’re being asked what their security posture looks like. That question lands with their MSP.

At the same time, the commodity IT market is under pressure. Prices are being squeezed, customer expectations are rising, and the MSPs built around pure break-fix or basic managed services are finding it harder to differentiate. The growth is happening at the security-capable end of the market – with partners who can have genuine risk conversations at board level and back them up with real capability.

From break-fix to proactive: a 2,000-year-old problem

The history of the break-fix model turns out to be longer than most people realise. Rome’s first fire brigades operated on a familiar logic: arrive at the fire, survey the damage, and negotiate a price with the homeowner before deciding whether to put it out. Reactive, transactional, and distinctly uncomfortable when the house is already burning.

Sound familiar?

Many security engagements still follow this pattern. A customer gets breached, they call around to incident response teams, and the negotiation happens at the worst possible moment – when they’re most vulnerable, most stressed, and least equipped to make clear decisions.

The alternative is preparation. Not just technically, but relationally. The MSPs who retain customers for the long term are typically the ones who were already engaged before something went wrong – who had the trust, the access, and the agreed response plan in place. When the crisis comes, there’s no negotiation. There’s just execution.

Interestingly, going through a serious incident together can actually be one of the strongest customer retention events an MSP experiences. Customers who’ve been through it with a partner they trust tend to invest more in security afterwards, not less – and they don’t go looking for alternatives. The relationship has been tested and it held.

The trust gap is an opportunity

Roughly 70% of customers say they’re not confident their MSP could defend them if targeted. Around half say they’d consider switching providers if their MSP couldn’t demonstrate the necessary skills, guidance, and round-the-clock security capability.

These numbers are uncomfortable. They’re also not surprising to anyone paying attention. A significant portion of the MSP market is still delivering what amounts to basic endpoint protection and calling it a security service. Customers know the difference – or at least, they’re starting to. The ones who’ve watched peers get breached are asking harder questions.

The trust gap is real. But a trust gap means there’s an opportunity. The MSPs who close it – who can genuinely demonstrate 24/7 capability, proactive risk management, and outcomes rather than just effort – are the ones who become very difficult to replace. And in a market where nearly half of customers say they’d switch, being the MSP they’d stay with is a powerful commercial position.

The key to closing that gap is demonstrating what you actually do. Security work is largely invisible when it’s working well. Customers don’t see the vulnerabilities that were found and closed, the alerts that were investigated and dismissed, or the attack paths that were eliminated before anything happened. Making that work visible – through risk reporting, regular reviews, clear documentation of what was found and fixed – changes the conversation from cost to value.

Frameworks like CIS provide a structure for this: a way to show customers exactly what is being done, where gaps still exist, and what the roadmap looks like. It moves the relationship from reactive vendor to strategic adviser.

The SOC problem: build, buy, or partner?

Running a 24/7 security operations centre is genuinely hard. Not theoretically hard – hard in practice, in terms of recruitment, retention, cost, and operational consistency. The security talent market is competitive and shallow. Getting the right people on shifts through weekends and nights, keeping them engaged, and maintaining quality across all hours is a sustained effort that most MSPs aren’t resourced to do well.

The honest assessment from those who’ve done it: it’s a struggle, it’s expensive, and in hindsight, partnering is often the better path.

That doesn’t mean giving up the customer relationship or the revenue. The co-delivery model – where the MSP owns the customer, handles the communication, and builds the relationship, while a specialist partner provides the 24/7 monitoring and response capability behind the scenes – lets MSPs offer genuine SOC-grade security without carrying the full overhead of building it themselves.

The MSPs that have made this work report expanding their security service offering significantly, delivering more capability to their customers for the same or similar cost, and building a defensible 24/7 service without the staffing challenges that come with running it internally.

Visibility and action: the two things that matter most

Strip away the complexity and the answer to ”how do you run a good security practice” comes down to two things.

Visibility. You cannot protect what you cannot see. This applies at every level: visibility into what assets a customer has, what vulnerabilities exist, what’s running in their environment, and – from an MSP operational perspective – what’s happening across all customer environments simultaneously. Lack of visibility is the most common barrier to scaling, and it’s usually the first thing that breaks when MSPs try to grow without improving their operations.

Action. Knowing something is wrong is only useful if you can do something about it quickly. That means having the tooling, the playbooks, the partner relationships, and the agreed response plans in place before they’re needed. Visibility without action is just a better view of a problem you can’t solve.

Both of these capabilities are now being significantly enhanced by AI. Investigation time is collapsing. Alert triage that used to take hours is happening in minutes. The ability to manage more customers with smaller teams is improving. For MSPs who integrate these capabilities deliberately – rather than treating AI as a bolt-on – the operational economics shift meaningfully.

What a scalable security practice actually looks like

The MSPs who are building genuinely scalable, profitable security practices share a few consistent characteristics.

They’ve moved from custom-built, customer-by-customer offerings to standardised bundles with clear tiers. The sales motion is repeatable. The delivery model is consistent. The pricing conversation is simpler.

They’ve integrated their security tooling into the PSA and RMM platforms where their teams actually work. Onboarding is automated. Billing is reconciled automatically. Alerts turn into tickets without manual intervention. The operational overhead of adding a new customer is low.

They’ve stopped selling features and started selling outcomes. Customers at the board level don’t respond to capability lists. They respond to ”here’s what your risk looks like, here’s what we’re doing about it, and here’s the evidence that it’s working.”

And they’ve recognised that they don’t have to build everything themselves. Partnering – with security operations specialists, with co-delivery models, even with other MSPs – is how you extend capability without extending cost.

Practical advice from the field

Four observations that have stood out from conversations with security-focused MSPs building toward this model:

Know your processes before you add people or tools. Most operational inefficiencies aren’t resource problems – they’re visibility problems. Before hiring or deploying, map what you actually do and where the friction is.

Prepare the relationship before the incident happens. Pre-agreed response plans, retained incident response capability, and clear communication protocols with customers change the nature of a crisis when it arrives. Negotiating terms during an active breach is the worst time to have that conversation.

Use frameworks to make your work visible. CIS, ISO, and similar frameworks give customers a legible view of what their security posture covers and where the gaps are. That transparency builds trust more reliably than any sales conversation.

Take AI seriously as an operational multiplier. Not as a marketing angle – as a genuine capability that changes what’s possible with a given team size. MSPs building AI-native operations from the ground up have a structural advantage over those trying to retrofit it. 

This blog is based on a panel discussion at SPHERE2YOU Helsinki in April 2026. Watch the full session at https://youtu.be/t9NT99luTg4.

Share this story

Stop selling locks. Start protecting the whole house.

Most MSPs are still built around endpoint security. But customers aren’t paying you to sell them locks – they’re paying you to protect the whole house. That gap between what MSPs deliver and what customers actually need is both the challenge and the growth opportunity in front of you right now.

Key Takeaways:

  • Endpoint protection covers the door. Everything before and after it is invisible without a broader security portfolio
  • Standardised bundles make security easier to sell, easier to scale, and easier for customers to understand
  • Integrated tooling is where delivery economics are won or lost
  • The MSP co-growth community gives partners everything needed to build, launch, and scale a profitable security practice

The burglar analogy that changes the conversation

Explaining to a customer why they need more than endpoint protection is one of the harder sales conversations in the MSP business. Here’s one way to frame it.

A careful burglar walks down the street, watches the houses, picks their tools, and gets through the door. They don’t run. They learn the layout. They take what they came for. Then – and this is the difference – they don’t leave. A physical burglar leaves a broken door. A cybercriminal leaves no trace, and six months later, they’re still in the building.

Endpoint protection stops the burglar at the door. It does that job. But everything before that moment – the reconnaissance, the approach, the vulnerabilities being mapped – is invisible. And everything after a breach – the persistence, the lateral movement, the ongoing access – is equally invisible without broader coverage.

Customers aren’t paying their MSP to sell them a lock. They’re paying for someone who watches the streets, sets up the alarms, stops the burglar at the door, and – if anything gets through – removes it before real damage is done.

That’s the conversation that moves customers from point products to a security portfolio. And it’s where MSPs earn their place at the table.

The problem with how most stacks are built today

Most MSPs have assembled their security offering over time – a product here, a tool there, each solving a specific problem as it emerged. The result is a stack that works, but doesn’t scale easily and doesn’t have a natural upsell path.

Every new customer means a bespoke conversation about what they need. Pricing is negotiated case by case. The sales motion is inconsistent. And when the threat landscape shifts – which it has, sharply, with AI-powered attacks becoming the norm – updating the offering means renegotiating with each customer individually.

That model generates revenue. It doesn’t generate margin.

The shift that’s making a measurable difference for MSPs is standardisation. When the offering is packaged into clear, tiered bundles that map to customer risk profiles, the whole commercial operation changes. Sales conversations become faster. Onboarding becomes repeatable. Upsell paths become visible. And the business can scale without cost scaling at the same rate.

What the bundles actually cover

WithSecure’s commercial Elements bundles were designed with exactly this in mind, built through a co-design process with MSP partners based on what customers actually need and what MSPs can deliver profitably.

Elements Protect is the baseline. It covers devices, identities, and collaboration platforms, with both the Elements platform and MDR service included. When something happens, you spot it fast and respond fast. It’s the foundation every customer needs.

Elements Proactive adds the Exposure Management layer. Rather than waiting for something to happen, it lets you continuously map a customer’s environment from an attacker’s perspective – identifying and closing gaps before they can be exploited. It also opens a new category of conversations with customers about risk posture, compliance, and proactive resilience. That’s where vCISO-type advisory services begin, and where the most valuable long-term customer relationships are built.

Two tiers. One operating model. Built to scale.

The revenue impact of making this shift is visible in practice. Partners who have moved from scattered endpoint products to standardised bundles see revenue follow the packaging – not because they changed what they deliver, but because they made it easier for customers to buy more of it, and easier for their own teams to sell it consistently.

Where margin is actually won: integrations

Technology is only half the delivery model. The other half is how security operations connect to the PSA tools, RMM platforms, and ticketing systems where MSP teams actually work.

Every manual step between a security alert and a ticket in ConnectWise or Autotask is a cost. Every time someone copies a subscription key between systems, reconciles billing manually, or switches between dashboards to get a complete picture of a customer’s security posture – that’s time and margin being spent on friction, not value.

WithSecure Connect addresses this directly, with three routes for integration: a catalogue of pre-built connectors for the most widely used MSP tools, a standard event-forwarding connector, and APIs for custom integrations where needed.

The practical outcomes: automated customer onboarding from PSA tools, no manual ordering. Automated deployment from RMM tools, with information synchronised between systems. Security operations managed directly from the ticketing or PSA platform, without needing to jump between dashboards.

When friction goes down, adoption goes up. And when adoption goes up, margins follow.

The community piece

Technology and integrations get a security practice operational. The co-growth community is what helps it scale.

Most partner programmes tick boxes. A knowledge base here, a webinar library there. What’s been built here is deliberately different: active peer-to-peer coaching, virtual and in-person meetups, growth paths designed around MSP business models rather than product certifications, and a central hub that brings it together.

Each capability area comes with a full kit – playbooks, marketing programmes, event materials, pitch decks, webinar setups – everything needed to move from internal enablement through to customer conversations and closed deals. Not built in a vacuum, but developed from and with partners who have already worked through the same challenges.

The observation from MSPs who’ve been through the process: eight weeks from first conversation to commercial execution is achievable. That’s not typical in this industry.

Five practices that drive growth

For MSPs looking to build a genuinely profitable security practice, five things consistently make the difference:

  • Sell outcomes, not products. Customers at the board level don’t want a feature list. They want to know what their risk looks like and whether you can reduce it. Lead with that.
  • Use the bundles. Standardised tiers make the sales conversation faster and the delivery model more scalable. EPP and EDR alone are no longer enough – customers and the market both know it.
  • Integrate everything. Delivery economics live in operations. Every manual step is a cost that doesn’t need to exist.
  • Go to market together. Joint campaigns, co-selling, shared enablement materials – these compress the time it takes to build a security revenue line from scratch.
  • Join the community. The MSPs who have already solved the problems you’re facing are in that community. Use them.

This blog is based on Kasper Pöyry’s keynote at SPHERE2YOU Helsinki in April 2026. Watch the full session at https://youtu.be/QoYVCTg-3Qs.

Share this story

The Defender’s Dilemma: Why neither AI nor headcount alone can win the security scale war

AI has industrialised cybercrime. The cost of running a sophisticated, multi-language phishing campaign has dropped from a month of work and significant budget to cheaper than a lunch. The problem for defenders isn’t detection anymore – it’s scale. And the answer isn’t what most people expect.

Key Takeaways:

  • AI has made every tier of attacker more dangerous – script kiddies can now run campaigns that once required serious expertise
  • The core challenge has shifted from detection to scalability: you cannot solve a machine scaling problem with a human scaling solution
  • Neither pure AI nor more headcount is the right answer – the right model is purpose-built AI working alongside human analysts
  • When done correctly, AI-driven investigation reduces average incident investigation time from 3 hours to 3 minutes

Cybercrime has been industrialised

Three years ago, a targeted multi-language phishing campaign required real technical skill. You needed to build the infrastructure, write convincing content in multiple languages, manage the operation day to day, and pay for the tools and the people to run it. Setup alone took roughly a month.

Today, the same campaign costs 16 tokens on a cloud coding tool. That’s cheaper than lunch. And the skills needed have been so thoroughly reduced that amateur attackers can set the whole thing up solo.

That’s the entry-level problem. It gets more serious from there.

The mid-tier attackers – the competent-but-not-elite criminals who have always formed the bulk of the threat landscape – are now genuinely dangerous in ways they weren’t before. AI mentors them, fills the gaps in their skill sets, and lets them execute attacks they couldn’t have mounted independently. And the elite attackers, the ones who were already capable and well-resourced? AI doesn’t make them smarter, but it makes them 10 to 20 times more efficient by removing the grind from their operations. Effectively, there are now 10 to 20 times more of them.

The numbers from European national security agencies reflect this. Cyber attacks nearly doubled in Italy, with three quarters targeting SMEs and SMBs. Significant cyber incidents more than doubled year over year in the UK. Serious cybersecurity incidents more than doubled in Finland. These aren’t isolated data points – they’re a consistent pattern across the continent, and they carry a statistical weight of inevitability: as these numbers rise, more customers will get breached.

The problem isn’t detection – it’s scale

This is the shift that changes everything for defenders.

The core challenge in cybersecurity is no longer whether you can detect something. It’s whether you can match the scale at which attacks are being generated and executed. And that’s a fundamentally different problem.

You cannot solve a machine scaling problem with a human scaling solution. The maths don’t work. Even if you could keep analysts working without rest, the volume of AI-generated threats would outpace them. And the talent pool doesn’t exist to try: Europe currently has a shortfall of 300,000 cybersecurity specialists. You cannot hire people who don’t exist.

This is the Defender’s Dilemma – a structural asymmetry that has always favoured attackers, and that AI has now made significantly sharper. Attackers need to find one exploit. Defenders need to close all of them. Attackers can fail as many times as they like with no consequences. Defenders cannot afford to fail once.

Two wrong answers

Given that framing, the obvious conclusion is: use more AI. And that conclusion is wrong – or at least, incomplete.

Throwing AI at a broken or chaotic security operation doesn’t fix the operation. It produces chaos with an AI layer on top. Replacing a broken workflow with an AI-augmented broken workflow doesn’t improve outcomes – it just adds a confused model and frustrated customers to an existing problem.

But the human-only answer fails just as clearly. The scale problem is mathematical. No amount of analyst hiring closes the gap when attackers are operating at machine speed and the talent pool is already running dry.

The right answer is both – but in the right way. Purpose-built AI models, designed for specific tasks, with the right data and context to do those tasks well, working alongside human analysts who handle what AI genuinely can’t: novel situations, edge cases, accountability, and judgment.

AI is probabilistic. It’s exceptionally good at pattern-heavy, repeatable, well-scoped work. It is genuinely poor at new, unusual, or ambiguous situations. That’s not a flaw to work around – it’s a design constraint to build with. The human in the loop isn’t a liability. It’s a feature. The EU AI Act reflects exactly this: important operational decisions made by AI must be traceable to an accountable human. Customers, procurement teams, and legal departments will ask the same question. ”AI did it” is not an answer that renews contracts.

What this looks like in practice

The proof is in the numbers from WithSecure’s own SOC.

Two cases illustrate the model in action.

In the first, a piece of malware was bypassing standard anti-malware capabilities – a common outcome when AI-generated malware is specifically engineered to evade basic detection. But the artefacts it left behind told a different story. Process injection, credential testing in the payload, hooks into multiple system components, and a connection to a known command-and-control node. AI surfaced these findings clearly, visualised the relationships between them, and allowed the analyst to verify the verdict quickly before acting.

In the second, a similar detection turned out to be a false positive – a recurring pattern the system had seen before. Rather than sending an analyst down a multi-hour investigation path, the AI recognised it immediately: it knew the customer environment, the anomalies, and the historical behaviour. What would have taken hours to verify was resolved in minutes.

The result of applying this model consistently: average investigation time has dropped from 3 hours to 3 minutes. Analysts agree with the AI’s verdict 92% of the time. That’s a 60-fold increase in investigative throughput – not from hiring more analysts, but from giving the analysts working today tools that handle the grind so they can focus on what genuinely requires human judgment.

What this means for MSPs

The trust gap between MSPs and their customers is real and measurable. Around 70% of customers say they don’t feel confident their MSP could defend them if targeted. Around 50% say they’d consider switching providers if their MSP can’t offer the necessary skills, guidance, and round-the-clock security support.

These numbers aren’t just a warning. They’re a map to where the growth opportunity is. The MSP that closes this trust gap becomes very difficult to replace – and starts replacing others.

Closing it requires genuine capability. That means either building your own SOC (expensive, slow, and operationally demanding), acquiring one (expensive, with its own complications), or partnering with a provider who delivers the security operations behind the scenes while you retain the customer relationship, the communication, and the commercial value.

That co-delivery model is how most MSPs can realistically get to 24/7 expert-backed MDR without the overhead of building it themselves. WithSecure’s MDR is fully developed, managed, and delivered from within the EU – meaning NIS2, GDPR, and the AI Act compliance questions your customers are starting to ask are answered by default, not as an afterthought.

Frequently asked questions

Q: If AI can’t solve the scale problem alone, what’s it actually useful for in a SOC context?
A: AI excels at high-volume, pattern-heavy, repeatable work – triage, correlation, investigation of known threat patterns, false positive identification. It frees analysts to focus on the genuinely novel and complex cases that require human judgment.

Q: What’s the risk of relying too heavily on AI in security operations?
A: AI models are probabilistic and bounded by their training data and context. They can be wrong on novel threats, and they cannot carry accountability for decisions. Deploying AI without meaningful human oversight creates both operational risk and compliance exposure.

Q: How does the co-delivery model work for MSPs in practice?
A: The MSP owns the customer relationship, communication, and commercial value. The security operations – monitoring, investigation, response at 2 a.m. – are handled by the partner’s SOC team. The customer sees their MSP as the capable, always-on security partner they need. The MSP delivers that without building the SOC infrastructure themselves.

Q: Is EU-based MDR relevant for compliance purposes?
A: Increasingly, yes. As NIS2, DORA, GDPR, and the AI Act sharpen regulatory scrutiny around where data is processed and who is accountable for security decisions, the jurisdiction of your MDR provider becomes a genuine procurement consideration – particularly for customers in regulated sectors.

The choice ahead

The shape of the threat has changed. The scale at which attacks are launched, the ease with which they’re constructed, and the efficiency of the attackers running them have all shifted in a direction that makes standing still an increasingly costly position.

The security operations model that wins in this environment combines purpose-built AI – doing the work it’s genuinely suited to, quickly and accurately – with human analysts who provide oversight, handle the genuinely hard cases, and carry the accountability that customers and regulators require.

That model already exists and is already delivering a 60x improvement in investigative throughput in production environments. The question for MSPs isn’t whether this is the direction things are heading. It’s whether you help shape it or spend the next few years catching up.

This blog is based on Teemu Myllykangas’ keynote at SPHERE2YOU Helsinki in April 2026. Watch the full session at https://youtu.be/Sg818_mJ9-M.

Share this story

Cybersecurity has reached the boardroom. Here’s what that means for MSPs.

For years, the call to make security a C-suite issue went largely unheard. Boards nodded, then delegated it back to IT. That has now changed – and for MSPs who are ready, the timing could not be better.

The conversation has moved upstairs

Something has shifted in how organisations think about cybersecurity risk. It’s no longer a technical concern sitting quietly in the IT department. Boards are asking questions. Executives are calling their security partners directly. The scrutiny is real, and it’s coming from the top.

This isn’t just a feeling. It’s a pattern that’s emerged clearly from conversations with MSPs across Europe. C-suite leaders are reaching out to their security partners, asking what happens if they get breached, what their exposure looks like, and whether they’re genuinely protected. The demand is active, not passive.

For MSPs, that’s a meaningful shift. Security conversations that used to require convincing the IT manager to escalate now start at the board level. The question has changed from ”do we need this?” to ”can you actually deliver it?”

The product isn’t the whole answer

There’s a temptation in the security industry to answer every challenge with features. More capabilities, deeper detection, faster response. And product quality matters – it has to be competitive.

But partners who are growing their security businesses consistently say the same thing: the conversations that move the needle aren’t about features. They’re about business outcomes. Help us win new customers. Help us train our people. Help us sell this to a board that didn’t use to care but now very much does.

MSPs don’t wake up thinking about cybersecurity. They wake up thinking about how to scale their business, how to retain customers, and how to grow revenue without headcount growing at the same pace. A security partner that understands that framing – and helps address it – is a fundamentally different relationship than one that leads with product updates.

Churn goes down when the portfolio goes up

One of the clearest patterns in MSP customer retention is the relationship between portfolio depth and churn. Customers with a single-point security product are more likely to switch providers. Customers with a fuller, more integrated security portfolio are significantly more likely to stay.

The implication is straightforward: helping customers expand their security coverage isn’t just a revenue conversation, it’s a retention conversation. And the two are connected. As customers move from baseline endpoint protection into exposure management, compliance services, and board-level risk reporting, they become embedded in a relationship that’s harder to replace – and less likely to be challenged on price alone.

Building those upsell paths, identifying the signals that indicate a customer is ready to move up, and equipping MSP teams to have those conversations is where the business impact of a genuine partnership shows up.

From vendor KPIs to partner KPIs

The most important shift in how a security vendor can support MSP growth is also the simplest to describe and the hardest to actually do: stop measuring success by your own metrics and start measuring it by your partners’.

Revenue per seat, churn rate, time-to-close, customer retention – these are MSP KPIs. A vendor that genuinely aligns around those, builds product and support structures that move them in the right direction, and treats partner growth as the primary objective is a different kind of relationship than the traditional vendor model.

That shift – from features to business outcomes, from vendor KPIs to partner KPIs – is what co-growth actually means in practice.

This blog is based on Pilvi Tunturi’s intro chat at SPHERE2YOU Helsinki in April 2026. Watch the full session at https://youtu.be/Rd9YdEtRXFE.

Share this story

The AI you can’t see: securing what’s already running in your customers’ environments

AI has transformed how threat actors operate. At the same time, AI tools and agents are spreading through organisations faster than security teams can track. The challenge isn’t future-proofing – it’s dealing with what’s already here.

Key Takeaways:

  • Threat actors adopted AI quickly and are now using it to run campaigns with minimal human involvement
  • The rush to bring AI into organisations has created serious, under-managed security risks
  • AI security challenges fall into three tiers: tools, infrastructure, and autonomous agents
  • Securing agents requires visibility, guardrails, and a new capability – monitoring agent intent in real time

The threat actor has changed

November 2022 was a turning point. When large language models became accessible through natural language interfaces, AI moved from the domain of specialists to something anyone could use. That included people who had no interest in using it responsibly.

Within months of ChatGPT’s release, threat actors were experimenting. Early uses were relatively familiar: researching targets, running translations to make phishing campaigns viable across language groups, generating code. Useful, but recognisable extensions of what attackers were already doing.

That phase didn’t last long.

What we’re tracking now is meaningfully different. Threat actors are using AI not just to assist individual tasks, but to coordinate, orchestrate, and execute entire campaigns – with near-zero human involvement in the loop. Research published by Anthropic last year documented a Chinese threat actor that used AI to run end-to-end campaigns affecting multiple organisations and government entities.

The threat actor of 2025 is not the threat actor of 2022. The techniques are different. The scale is different. The speed is different. Defending against this requires a different mindset – and different tools.

The other side of the problem

There’s a second challenge that gets less attention, but it’s just as consequential.

In the rush to adopt AI, most organisations didn’t stop to think carefully about how to do it safely. A few months after ChatGPT launched, engineers at Samsung – talented, technically sophisticated people – uploaded sensitive material to the tool, effectively leaking intellectual property. It was an early, high-profile example of a risk that has only grown since.

The technology stack of a typical organisation now includes AI-powered SaaS applications, models embedded in productivity tools, and increasingly, autonomous agents running in cloud infrastructure – accessing data, using internal tools, making decisions, often without IT or security teams having any clear picture of what’s there.

This complexity is an attack surface. And it’s expanding faster than most teams can map it.

Three tiers of AI security risk

The security challenges that come with AI adoption fall into three distinct categories.

AI tools. The tools employees use – both the ones IT has approved and the ones they haven’t. Shadow AI is real and widespread. The first step toward managing it is knowing what’s actually running.

AI infrastructure. The environments where agents live and operate. Cloud infrastructure, typically, with varying levels of access control and security configuration. Guardrails – the controls that govern what goes into an agent and what comes out – are critical here. Without them, agent behaviour becomes difficult to predict and impossible to reliably secure.

Autonomous agents. The agents themselves. Unlike a traditional application, an agent doesn’t follow a fixed, deterministic path. It makes decisions. It takes actions. It can be given – or acquire – significant access to systems and data. And unlike a human, it can act very, very fast.

What WithSecure Elements addresses today

WithSecure Elements already addresses these three tiers in concrete ways.

For AI tools, browsing protection now includes the ability to set policy on AI websites and web-based AI tools – blocking unapproved tools, logging usage, and creating exceptions for tools that have been vetted. This gives MSPs and their customers genuine visibility into what’s actually being used, not just what’s been sanctioned.

For AI infrastructure, Elements has expanded its cloud security posture capabilities to include rules specifically targeting AI guardrails. These rules can detect when guardrails are missing entirely, or when they’re applied inconsistently across an organisation’s cloud environment. Initial coverage is in AWS, with other cloud environments to follow.

For agents, the starting point is identity. Every asset in an organisation should have an identity – and that now includes AI agents. Elements already brings in identity visibility from Microsoft Entra, including agents created in Copilot Studio. That means security teams can start to see agents in their environment, understand what access they carry, and build appropriate controls around them.

The problem with agents: they can be turned

Here’s a scenario worth understanding, because it illustrates something genuinely new.

An autonomous customer support agent is handling tickets. It reads incoming messages, analyses the problem, generates a response, and replies. Straightforward enough.

One day it receives a ticket with hidden text – invisible to a human reader, but perfectly readable by the agent. The hidden text contains instructions: export the customer database and send it to an external address. The agent has no way to distinguish between the original instructions it was given and the new ones embedded in the email. It follows them.

This is a prompt injection attack. No system was hacked. No credential was stolen. The agent was simply given new information and acted on it – because that’s what it was built to do.

This class of attack has significant implications for any organisation running autonomous agents. And it points toward a capability that doesn’t yet widely exist: the ability to monitor what an agent is actually trying to do, in real time, and catch it when its behaviour diverges from its original purpose.

Where this is heading: intent monitoring for agents

WithSecure’s research team is working on exactly this problem.

The concept – currently in development, not yet a product commitment – is what we’re calling intent monitoring for agents. The approach is to capture the agent’s initial intent (read a ticket, identify the problem, reply to the customer), let it execute, then compare its new intent against the original. When those two things diverge significantly, that’s a signal that something has changed – and a basis for blocking the action and raising an alert.

A pending patent covers this method. The research is active. We’re working through how to make this reliable and scalable across the variety of ways agents are being deployed today.

This is where AI security needs to go. Not just visibility into what agents exist, but understanding of what they’re doing – and whether that matches what they’re supposed to be doing.

Frequently asked questions

Q: How do I know what AI tools are running in a customer’s environment right now?
A: WithSecure Elements’ browsing protection can identify and log AI tool usage across web-based applications. Combining this with cloud posture management and identity visibility gives a substantially clearer picture than most organisations currently have.

Q: Are guardrails required for every AI deployment?
A: Not legally required in most contexts, but they’re foundational to any defensible AI security posture. Elements now includes cloud security posture rules that specifically check for guardrail presence and consistency.

Q: How is an AI agent different from a standard application from a security perspective?
A: An application follows deterministic logic – it does what it’s programmed to do. An agent makes decisions, takes actions, and can behave differently depending on the inputs it receives. That non-determinism makes it harder to predict and easier to manipulate.

Q: What’s the practical risk of prompt injection for businesses running agents?
A: Significant. An agent with admin access to a CRM, a cloud environment, or internal systems can cause serious damage if its instructions are manipulated. The risk scales directly with the permissions the agent carries.

AI is here. The question is how you manage it.

There’s no putting this technology back. It’s embedded in the tools organisations use, in the workflows their teams rely on, and increasingly in the autonomous systems running in their infrastructure.

For MSPs, that’s both the challenge and the opportunity. Customers need help understanding what AI assets they have, how those assets are configured, and whether they’re being protected appropriately. Most of them don’t have that picture yet.

WithSecure is building toward a world where MSPs can provide exactly that clarity – and where AI-powered defences are meeting AI-powered threats on equal footing.

This blog is based on Paolo Palumbo and Klas Kindström’s keynote at SPHERE2YOU Helsinki in April 2026. Watch the full session at https://youtu.be/oP10YIU144g.

Share this story

When 24 hours becomes too late: How AI is collapsing the CVE to exploit timeline

A new exploited vulnerability is published every two days. A new exploited zero-day, every three. And in 2026, WithSecure’s threat research predicts the median time from CVE disclosure to active attack will drop below 24 hours.

That is not a future problem. It is today’s operating reality – and reactive security was not built for it.

The old playbook is broken

For years, organisations managed vulnerabilities on a familiar rhythm: monthly patch cycles, Patch Tuesday schedules, periodic audits. That model made sense when attackers needed days or weeks to weaponise a new vulnerability.

AI has changed that equation. Threat actors now use generative AI tools to analyse disclosures, generate working exploits, and launch attacks faster than any human-paced patching process can respond. By the time a critical CVE has been triaged, prioritised, and added to the next maintenance window, exploitation may already be underway.

This is not a tooling gap. It is a mindset problem. Too many organisations – midmarket companies especially – are still operating as though the threat landscape moves at the speed it did five years ago.

Why midmarket organisations are most exposed

Smaller IT teams face a compounding challenge. Unlike large enterprises that have spent years building security infrastructure, midmarket organisations are often left managing an expanding digital attack surface with limited resources, no dedicated SOC, and a growing volume of CVE findings coming in around the clock.

The result: confidence gaps. Organisations assume their existing controls still apply to the most advanced threats. They underestimate their attractiveness as targets. And they remain in reactive mode – responding to incidents that proactive security could have prevented.

CVEs are now competing with compromised identity as the most common initial attack vector. That means exposure management can no longer be an afterthought. It needs to happen continuously, automatically, and ahead of exploitation.

Moving left: from reaction to prevention

Proactive security means closing exposure windows before attackers find them – not after.

WithSecure Elements combines Exposure Management (XM) and Extended Detection and Response (XDR) to do exactly that. Rather than waiting for an incident to trigger a response, the platform continuously reads the threat landscape in real time: surfacing CVEs, flagging misconfigurations, and identifying risky software the moment it appears across the environment.

Crucially, Elements can act before patches even exist. Pre-zero-day vulnerability discovery – a patent-pending capability – uses behavioural telemetry from XDR sensors to detect exploitable vulnerabilities before they have been reported or analysed. When WithSecure identified its first such vulnerability in 2025, the vendor confirmed the fix in their own release notes.

When a new exposure is found, pre-emptive mitigation actions let IT admins respond immediately – isolating devices, resetting credentials, or triggering Outbreak Control to automatically contain high-risk situations – while remediation catches up.

Proactive and reactive, working together

This is not about replacing reactive security. Detection and response still matters. What changes is when and how often it is needed.

When exposure management continuously reduces the attack surface – automatically finding gaps, flagging risky software, and hardening endpoints ahead of known campaigns – fewer incidents reach the stage where reactive response is required. The result is less alert fatigue, faster mean time to detect and respond, and measurable security outcomes that MSPs can demonstrate to customers at every business review.

The 24-hour threshold

When the window from vulnerability to exploitation collapses below 24 hours, waiting is no longer a strategy. Real-time visibility, smart prioritisation, and automated mitigation are the only controls that move fast enough.

Proactive security is not a luxury for well-resourced enterprises. It is the foundation every organisation needs to stay ahead in a threat landscape that no longer waits.

Share this story

IT-palveluntarjoajan opas ennakoivan kyberturvallisuuden ostamiseen – eurooppalaisittain

Adventure Man on a Sea Kayak is kayaking during a vibrant and colorful winter sunset. Taken in Vancouver, British Columbia, Canada. Adventure, Vacation Concept

Fiksuja valintoja. Yksinkertainen vaatimustenmukaisuus. Todellista kasvua.

Kyberturvamarkkinat ovat ruuhkaiset. Monimutkaisuus kasvaa. IT-palveluntarjoajat ja keskisuuret yritykset tarvitsevat ratkaisuja, jotka toimivat ilman päänvaivaa.

Näin valitset teknologian ja palveluita, jotka tarjoavat suojaa, vaatimustenmukaisuutta ja luottamusta.

 

1. Mitä jokainen IT-palveluntarjoaja tarvitsee (Tarkistuslista)

Välttämättömät:

  • Päätelaitteiden suojaus käyttäytymisen tunnistuksella
  • EDR/XDR
  • Verkko- ja pilvinäkyvyys
  • Automaattinen korjaus
  • Identiteettiturvallisuus ja MFA
  • Hyökkäyspintojen hallinta
  • Uhkatiedustelu

Palvelun perusasiat:

  • 24/7 MDR
  • Säännölliset haavoittuvuusskannaukset
  • Incident response -valmius
  • Vaatimustenmukaisuuden tuki
  • Turvallisuustietoisuuskoulutus

Valinnainen (säännellyt toimialat):

  • OT (toimintateknologia) -turvallisuus
  • SIEM/SOAR
  • Zero Trust -kehykset
  • Turvallinen SD-WAN

2. Tee valinta yksinkertaiseksi – niputa se

IT-palveluntarjoaja: Tarjoa modulaarisia paketteja.

Paketti Mitä sisältää Kenelle tarkoitettu
Olennainen Päätelaite, MFA, korjaus Pienyritykset
Ennakoiva + ASM, MDR, käyttäytymisen tunnistus Korkean riskin asiakkaat
Edistynyt + Uhkien metsästys, vaatimustenmukaisuus, IR Säännellyt toimialat

3. Miksi eurooppalainen teknologia voittaa

  • GDPR oletuksena – ei tietovuotoja, ei draamaa
  • Digitaalinen suvereniteetti – hallinta pysyy paikallisena
  • Läpinäkyvä hallinto – luottamus on rakennettu
  • Tuki EU:ssa – nopea, luotettava
  • Kunnioitus EU:n arvoja kohtaan – vastuullinen tekoäly, luotettava telemetria

IT-palveluntarjoajat: Erotu Yhdysvaltojen ja muiden kansainvälisten toimittajien joukosta. Voita säänneltyjä asiakkaita. Rakenna luottamusta.

4. Kysymyksiä, joita kannattaa esittää jokaiselle palveluntarjoajalle

  • Missä tietoni ovat?
  • Mitä sertifikaatteja sinulla on?
  • Toimitetaanko kaikki EU:ssa?
  • Ovatko tunnistusmenetelmät läpinäkyviä?
  • Hinnoittelu – käyttöön perustuva vai kiinteä hinnoittelu?
  • Sopiiko se nykyisiin työkaluihini?

5. Strategiset voitot IT-palveluntarjoajille

  • Korkeammat katteet
  • Markkinoiden erottelu
  • Keskisuurten asiakkaiden luottamus
  • Pienempi laillinen riski
  • Helpompi vaatimustenmukaisuus
  • Pitkäaikainen lojaalisuus MDR:n ja uhkien metsästyksen kautta

Proaktiivinen kyberturvallisuus ei ole ylimääräistä – se on välttämätöntä.

Valitse eurooppalaiset, modulaariset, skaalautuvat ratkaisut. Suojaa asiakkaita, kasvata liikevaihtoa ja rakenna kestävää luottamusta.

Jaa tämä tarina

Miksi keskisuurten yritysten IT-palveluntarjoajat tarvitsevat proaktiivista kyberturvallisuutta – nyt

Side view silhouette of a male caucasian climber helping his female partner to reach a mountain top in a gorgeous sunset.

Kyberhyökkäykset eivät odota, että huomaat ne. Ne hiipivät hiljaa sisään, kohdistuvat tärkeisiin kohteisiin ja iskevät kovaa keskisuuriin yrityksiin. Miksi? Koska olet digitaalinen, arvokas – etkä tarpeeksi suojattu.

Reaktiivinen turvallisuus on eilisen uutisia. Nykyään IT-palveluntarjoajat tarvitsevat ennakoivaa suojaa, joka pitää asiakkaat turvassa, liiketoiminnan käynnissä ja vaatimustenmukaisuuden yksinkertaisena.

 

Ei ammattislangia. Ei draamaa. Vain oikeaa turvaa, joka toimii.

Miksi proaktiivinen voittaa reaktiivisen joka kerta

Keskisuurten yritysten IT-palveluntarjoajat ovat hyökkääjien tutkassa:

  • Automatisoidut valmistus-, logistiikka- ja liiketoimintaohjelmistot
  • Korvaamattoman arvokas IP ja tuotesuunnitelmat
  • Pilvi, etätyö, IoT – enemmän yhteyksiä, enemmän riskiä
  • Käyttökatkot tarkoittavat nopeasti menetettyjä tuloja
  • Liian tiukoille venytetyt IT-tiimit

Hyökkääjät käyttävät tekoälyn, automaation ja toimitusketjun temppuja. Kun huomaat heidät, he ovat olleet sisällä jo kuukausia.

Proaktiivinen turvallisuus kääntää tilanteen päälaelleen.

Miltä proaktiivisuus näyttää?

  • Pienennä hyökkäyspintaa jatkuvasti
  • Huomaa epätavallinen toiminta
  • Etsi ja korjaa haavoittuvuudet ennen hakkereita
  • Tee riski mitattavaksi, hallittavaksi ja yksinkertaiseksi
  • Automatisoi tietoturva, jotta se skaalautuu kanssasi

Miten?

Uhkatiedustelu, hyökkäyspintojen hallinta, jatkuva seuranta, tekoälypohjainen tunnistus, automaattinen reagointi ja MDR todellisen uhkien metsästyksen kanssa.

Miksi IT-paveluntarjoajat voittavat proaktiivisella turvallisuudella

Useimmat keskisuuret yritykset eivät pysty tähän yksin. He tarvitsevat IT-palveluntarjoajia, jotka toimittavat:

  • Skaalautuvaa, hallittua tietoturvaa – ilman ylimääräistä monimutkaisuutta
  • Toistuvaa liikevaihtoa ja todellista arvoa
  • Euroopan vaatimustenmukaisuuden ja datan suvereniteetin
  • Modulaariset, ennakoivat tietoturvapaketit

Lyhyesti:

Proaktiivinen kyberturvallisuus ei ole ylellisyys, se on uusi perustaso. IT-palveluntarjoajat, jotka sijoittavat nyt, suojaavat asiakkaita, kasvattavat liikevaihtoa ja rakentavat kestävää luottamusta.

 

Jaa tämä tarina

Proaktiivisen kyberturvallisuuden rakentaminen – 7-vaiheinen opas IT-palveluntarjoajille

Two men hanging on the rope while belaying from the cliff

Tulipalojen torjunnasta toimintaan, joka toimii myös tulevaisuudessa. Näin se tapahtuu.

Proaktiivinen kyberturvallisuus ei ole työkalu – se on ajattelutapa. Kyse on selkeistä prosesseista, älykkäästä teknologiasta ja tiimistä, joka on aina edellä.

Tämä on oppaasi siihen, miten se onnistuu (ja miten se säilyy).

 

Vaihe 1: Kartoita hyökkäyspintasi

  • Tiedä, mitä suojelet. Jokainen laite, palvelin, pilvipalvelu, SaaS, varjo-IT:t ja avoimet domainit.
  • Attack Surface Management pitää sinut ajan tasalla
  • IT-palveluntarjoaja: Tarjoa tätä palveluna. Se muuttaa pelin.

Vaihe 2: Löydä haavoittuvuudet ennen hyökkääjiä

  • Automaattiset skannaukset, älykäs priorisointi ja tauoton korjaus.
  • Useimmat IT-tiimit ovat ylikuormitettuja – IT-palveluntarjoajat voivat kantaa vastuun ja pitää asiakkaat turvassa.

Vaihe 3: Tunnista uhkat ajoissa

  • Käytä käyttäytymisanalytiikkaa, koneoppimista ja asiantuntijoiden johtamaa uhkien metsästystä (ajattele MDR:ää).
  • IT-palveluntarjoaja: Myy tuloksia, älä pelkästään teknologiaa.

Vaihe 4: Automatisoi kaikki mahdollinen

  • Nopeus on tärkeää. Automatisoi vastaukset, priorisoi hälytykset tekoälyn avulla ja käytä pelikirjoja standardointiin.
  • IT-palveluntarjoaja: Nopeuta kasvua, vähennä kiireistä työtä, nosta katteet.

Vaihe 5: Tee vaatimustenmukaisuudesta helppoa

  • NIS2, ISO 27001, KRITIS, alan standardit – täytä kaikki kriteerit.
  • Ennakoivat toimenpiteet eivät ole pelkästään parasta käytäntöä – ne ovat auditointivalmiita.

Vaihe 6: Rakenna resilienssiä

  • Laadi suunnitelma tapahtumien varalta. Selkeät roolit, hätäviestit, käytännön harjoitukset.
  • IT-palveluntarjoaja: Tarjoa standardoituja malleja, asiakkaat rakastavat sitä.

Vaihe 7: Kehity, aina 

  • Hallintapaneelit, KPI:t, raportit ja strategiset neuvot.
  • IT-palveluntarjoaja: Tule luotetuksi kumppaniksi, älä pelkästään teknologian tarjoajaksi.

 

Valmiina irtautumaan reaktiivisesta tilasta?

Proaktiivinen turvallisuus tarkoittaa tyytyväisempiä asiakkaita, älykkäämpää kasvua ja vähemmän stressiä. Rakennetaan se yhdessä.

Jaa tämä tarina