Rent the SOC, Build It, or Buy It
Every MSP in a private equity portfolio now sells security. Kaseya’s 2026 State of the MSP, a survey of 1,061 providers fielded in November 2025, found that 71 percent grew their cybersecurity revenue last year, more than any other service line. The question for the owner is not whether the company sells security. It is who does the work at three in the morning, and whether the company owns that answer or rents it.
Selling security is not running a SOC
Two different things get called security inside an MSP, and the owner needs them separated before the door question makes sense. The first is the product list: endpoint protection, email filtering, multifactor login, backup, awareness training. Kaseya’s respondents call that “security services,” and 72 percent of them offer it. It is software the MSP licenses, deploys and manages, it earns a margin on every seat, and selling it does not require anyone to be awake at night.
The second is the security operations center, and it is people, not products. The tools raise alerts, thousands a day across a client base. Someone has to read them, decide which three are real, and act on those before the damage spreads. That someone works a shift, the shift never ends, and the desk is staffed on holidays. A SOC is the room where that happens; managed detection and response is the service sold out of it.
An MSP can sell every product on the first list and own nothing on the second. In Barracuda’s 2024 survey of 700 MSPs, fielded by Vanson Bourne, 42 percent said they offer a SOC service, and 43 percent said they outsource the SOC function. Read those together: for many providers the SOC on the price list is a partner’s room with the MSP’s logo on the invoice. That is not a criticism. It is the rent door, and the owner should know which of the two lists the company’s security revenue comes from before deciding anything else.
There are three doors. Rent: a third-party security operations center or detection-and-response provider staffs the screens under the MSP’s brand. Build: hire the analysts, buy the tooling, run the shifts. Buy: acquire a company that already does it. Most MSPs walked through the first door without deciding to, and for a business on a five-year clock that is the problem. The hold period should pick the door, and the owner should pick it on purpose.
The door most companies are already through
Sophos surveyed 350 MSPs in March 2024. Eighty-one percent offered a managed detection and response service. Sixty-six percent delivered it through a third-party vendor, and another 15 percent delivered it jointly with their own SOC. Same shape as the Barracuda numbers: when an MSP says it runs a SOC, more often than not somebody else runs it.
Renting is the right first move. It is fast, it turns on with a contract, and it lets the sales team sell security this quarter. N-able’s 2025 Horizons survey of 451 partners found third-party MDR at the top of the list of services MSPs planned to add. The cost is that the capability belongs to the vendor. The margin is a resale margin, the analysts are the vendor’s, and the same vendor sells the same service to the competitor across town. Scott Steele, chief operating officer at Thrive, said it plainly in Channel Dive in May: MSSPs are partnering with MSPs “in order to stave off a larger MSP building the full stack.” The partner needs you to keep renting.
The door that costs eighteen months
Building looks like ownership and prices like it. Blue Mantis, a New Hampshire provider that Recognize took a majority stake in during September 2024, launched its own managed security service a year later. Its chief information security officer wrote that the service took 18 months to build and test in-house, and that a 24/7 security operations center in the United States now costs more than $1 million in the first year and about $2 million a year after that in staffing, training and software.
The arithmetic behind that number is shifts. Three shifts a day, seven days a week, plus vacations and turnover, takes eight to twelve people before anyone is hunting threats rather than covering the desk; Expel, which sells MDR and has an interest in the answer, publishes the same count. Federal wage data puts the median information security analyst at $129,180 a year. Then find them. In the same Kaseya survey, 39 percent of MSPs reported difficulty hiring skilled cybersecurity professionals, up from 29 percent a year earlier.
Build makes sense in year one of a hold, for a platform with the scale to spread $2 million across enough endpoints, and with a sales motion that will sell the difference. Start it in year three and it finishes as the banker is preparing the book.
The door the buyers are using
Omdia counted 169 publicly announced MSP deals in 2025. Seventeen of them had an MSSP as the target, and the analyst’s read was blunt: “Acquisition is simply the fastest path to closing capability gaps.” The tape agrees. Evergreen Services Group bought ImageQuest, a Nashville MSP and MSSP serving regulated industries, in July 2025, and said its recurring cybersecurity and compliance business had grown more than 20 percent in the prior six months, by its own account. Intelligent Technical Solutions bought Black Breach, an Atlanta MSSP, in May 2025. Virtual IT Group bought Security Centric in April 2026 for, in its chief executive’s words, “managed SOC, security engineering, cyber governance, and penetration testing.”
Even the platforms that say they built often bought. New Charter Technologies runs its security operations under its own Cyber74 brand; Cyber74 was assembled in 2022 from two regional MSSPs. The buy door has its own bill: security engineers are the asset, and they can leave after close. Underwrite the retention plan with the deal.
Ted Brown of Ntiva gave the client’s view in the same Channel Dive piece: “I don’t want somebody managing my computer and somebody managing my security.” That is the case for owning the capability, whichever door leads there.
Pick the door on purpose
Three questions for the next operating review. First, which door is the company in, and did anyone decide? If the security line item is a resold partner service, the company is renting, whatever the deck says. Second, how much of security revenue is the company’s own margin versus pass-through? Buyers will separate the two in diligence whether or not the owner has. Third, how many years remain on the hold? More than three, and building or buying is on the table. Fewer, and buying is the only door that closes in time.
Abe Garver, who runs the MSP practice at Focus Investment Banking, offered the tiebreaker: “Will it help us get new customers?” Renting sells security this quarter. Building or buying sells it as yours. The hold period decides which one the company can afford, and the owner who decides early gets to choose.
Frequently Asked Questions
What is the difference between an MSP offering security services and having a SOC?
Security services are the product list: endpoint protection, email filtering, multifactor login, backup, awareness training. Kaseya's 2026 survey found 72 percent of MSPs offer them; they are software the MSP licenses and manages, and selling them does not require anyone to be awake at night. A security operations center is people on shifts who read the alerts those tools raise, decide which ones are real, and act on them around the clock. Managed detection and response is the service sold out of that room. An MSP can sell every product on the first list and own nothing on the second, and Barracuda's 2024 survey found 43 percent of MSPs outsource the SOC function to a third party.
Should a private equity-owned MSP build a SOC, buy an MSSP, or partner with a third-party provider?
It depends on the years left on the hold. Renting through a third-party MDR or SOC partner is the fastest route and what most MSPs already do, but the capability and most of the margin belong to the vendor. Building is ownership at a price: Blue Mantis, a Recognize-backed provider, built its own managed security service over 18 months, and its security chief put the cost of a 24/7 SOC at more than $1 million in the first year and about $2 million a year after. Buying an MSSP is the route the deal tape shows, with 17 of 169 tracked MSP deals in 2025 involving an MSSP target. With more than three years left, building or buying is on the table; with fewer, buying is the only door that closes in time.
What should a PE owner ask a portfolio MSP about its security operations?
Three questions at the next operating review. Which door is the company in, and did anyone decide: if the security line item is a resold partner service, the company is renting whatever the deck says. How much of security revenue is the company's own margin versus pass-through, because buyers will separate the two in diligence. And how many years remain on the hold, since that decides whether building or buying can finish in time.