
The global managed security services market is projected to reach $66.83 billion by 2030, representing an 11 percent compound annual growth rate (CAGR), according to a new report from the research firm MarketsandMarkets.
The survey results are hard to ignore
Separately, a report from IBM notes that managed services now ranks third in a study of 602 organizations conducted by the Ponemon Institute after DevSecOps workflows and identity access management (IAM) among initiatives that enable them to reduce cybersecurity costs.
As the total cost of cybersecurity continues to rise, many organizations are starting to revisit their overall strategy. For example, a survey of 624 respondents who work for organizations that expect to increase cybersecurity budgets, risk management strategy is now the leading growth driver of cybersecurity at 48 percent, followed by modernization (45 percent), digital transformation (37 percent), regulatory compliance (34 percent) and the industry threat landscape (29 percent). Cybersecurity modernization, which was the top driver in the second half of 2025, fell from 56 percent to 45 percent but is now three percentage points behind risk management.
These findings suggest organizations are focusing more on reducing risk and controlling costs. In theory, investments in artificial intelligence (AI) should enable cybersecurity teams to achieve a set of potentially conflicting goals. However, the cost of the tokens used to drive those AI platforms continues to rise. As a result, many organizations find it more cost-effective to rely on managed security service providers (MSSPs) than build and operate their own AI-enabled security operations center (SOC).
Many more organizations are also showing a marked preference for consuming cybersecurity resources as a service rather than hiring full time employees to manage a platform themselves. In theory, an AI platform might reduce the need to rely on as many cybersecurity experts but, even then, the cost of the internal cybersecurity team will be higher than a managed service. In fact, many organizations are starting to shift more responsibility for cybersecurity to internal IT and application development teams that are augmented by an MSSP.
Differentiation is key in a crowded market
The challenge, as always, is that competition among MSSPs remains fierce. Many providers of cybersecurity platforms are also providing managed services. Each MSSP then needs to decide to what degree it might make more economic sense to resell a service provided by a vendor versus developing a particular capability themselves.
Regardless of approach, the providing of managed security services is becoming more nuanced. Organizations no longer view managed security services as an all-or-nothing proposition. Instead, they are embracing a shared responsibility model that combines the expertise of internal teams, cybersecurity vendors, platform providers, and MSSPs. This model is here to stay. The next challenge is determining how each stakeholder contributes as AI-powered threats continue to accelerate and operate at machine speed.
Photo: artin1 / Shutterstock
This post originally appeared on Smarter MSP.

