Cybersecurity and the Evolution of Managed Security Services

Jun 20, 2018 | Security

Featured article by Aaron Shaha, Director of Network Defense Operations (NDO) and Data Science, R9B

What can cybersecurity learn from economics? Some might recognize the current skills gap as a product of demand outstripping supply. This is great news for the computer science major hoping to capitalize on years behind the keyboard. Less so for the chief information security officer (CISO) whose budget may not allow for extravagances like hiring a fully-staffed team. Another economic lesson deals with the so-called law of diminishing returns.

Simply put, the impact of an investment increases up to a point, at which it will tend to level off or even decrease over time. For years, cybersecurity practitioners have had to contend with diminishing returns on investments in hardware and software. To complicate matters, some security investments can not only yield less of a return over time, they can complicate operations and even reduce security overall. In response, many companies have turned to managed security services (MSS) to ensure they are getting the most for their money.

Drowning in Data

Given the enormous breadth of cybersecurity products and services that exist today, it seems quaint to think back 30 years to the release of the first commercial antivirus software. Since then, wave after wave of solutions have hit the market. This includes firewalls, intrusion detection systems (IDSs), intrusion prevention systems (IPSs), security information and event management (SIEM) platforms, secure email gateway (SEG) appliances, and of course ever more robust versions of antimalware and antivirus software, generally referred to as endpoint detection suites.

The swelling commercial markets have created two major problems for CISOs. First is a “keeping up with the Joneses” mentality. This is as prudent as it is an aim at due diligence by “buying what Jones has”. In the event of a breach, heaven help the one CISO in the industry who did not implement at least the same security measures as his or her neighbors and competitors. The second problem is far more insidious and speaks directly to difficulties presented by diminishing returns. With so much technology comes ever-increasing complexity. In addition to requiring individual strategic, policy, network and compatibility considerations, firewalls, IDSs, IPSs, SIEMs, SEGs, and endpoint solutions all generate massive amounts of data. This includes raw activity feeds, log files, alerts, and notifications.

The Scalable Solution: Managed Security Services

Security leaders depend of the efficient processing and accurate analysis of all that data for proper decision making. However, the reality is both budgetary and personnel constraints make it nearly impossible to consider all available information, leaving open possible vulnerabilities. Many CISOs have found the solution to these problems in the form of managed security services.

Research firm Gartner defines managed security service providers as those companies that offer, “outsourced monitoring and management of security devices and systems. [They] use high-availability security operations centers…to provide 24/7 services designed to reduce the number of operational security personnel an enterprise needs to hire, train, and retain to maintain an acceptable security posture.” In short, an MSS provider does the heavy lifting when it comes to sorting possible threats from routine data, reducing the number of false positives so security teams are making more effective use of time and energy.

The Next Evolution: Managed Detection and Response

The fact that outsourcing basic monitoring, processing, and analysis of security event data is such a valuable enterprise, both to organizations and MSS providers, is an indicator of the current state of cybersecurity. These essential steps generally only ever aim to alert security teams to the possibility of a threat. They typically do not address threats themselves, let alone how to respond to an attack in progress. For these critical functions, a new market is emerging in so-called managed detection and response (MDR).

MDR is still growing and maturing. To give a sense of time, Gartner only began investigating the MDR space as an independent category in 2016. There are still no hard and fast rules about what a provider should or should not offer. Companies entering the space often have backgrounds in MSS, but new competitors are emerging. One thing is certain, in order to have a seat at the table, MDR providers must offer at least as much as an MSS provider, adding responsive measures as the next step in security. These response measures can include integrated threat intelligence, hunting, and limited on- or offsite forensic analysis. Given current trends, it is likely MDR will overtake the more limited MSS space, promising organizations greater value through managed response measures. A more cynical view is MSS will erode as current providers simply rebrand as MDR specialists.

As budgetary constraints put more pressure on CISOs; as the global cyber skills gap continues to widen; as cyber threats increase in both number and impact severity; and as costs of a security lapse continue to rise, outsourcing expertise to MSS and MDR providers will prove to be the smartest option for ensuring economies of scale. Those organizations that recognize their own limitations and seek outside expertise will find a more focused internal security enterprise. That increases the opportunity to invest existing resources in more profitable endeavors, such as improving preventive measures for cybersecurity. In closing, it was the famed economist Adam Smith who said, “the real price of everything…is the toil and trouble of acquiring it.” The price of cybersecurity will always be higher for those who seek to acquire it on their own.

AARON SHAHA Photo

Aaron Shaha, Director of Network Defense Operations (NDO) and Data Science, R9B

Aaron Shaha is responsible for network defense operations and data science capabilities for R9B’s customers, including Fortune 500 and government organizations. He has over 15 years of experience working in physical and network security within the U.S. Department of Defense.

Prior to joining R9B, Mr. Shaha served as technical director in the National Security Agency NSA/CSS Threat Operations Center (NTOC) where he led a team of advanced cyber analysts responsible for finding the most advanced cyber actors and malicious tools in network traffic. He has also worked on supporting real-time cyber military integration operations and architecting a near real-time Distributed Denial of Service (DDoS) system. Mr. Shaha has been awarded the National Intelligence Award – Exceptional Achievement Medal (EAM) for Computer Network Exploitation (CNE) expertise and problem solving in support of a major operation for the Counterterrorism Production Center. This highly-coveted and very selective award recognized him for making “a single exceptional contribution to the Intelligence community and to the United States of America.” Mr. Shaha holds a master’s degree in security engineering from Southern Methodist University in Dallas, Texas.

 

Top 10 Cybersecurity Stories This Week: Citrix NetScaler Dual Zero-Days Under State-Sponsored Attack, Pentagon DMDC Breach Exposes 3 Million Military Personnel Records for Nine Months, AI Agent Breaches Dutch Vulnerability Disclosure Organization Using Zammad Zero-Days

Top 10 Cybersecurity Stories This Week: Citrix NetScaler Dual Zero-Days Under State-Sponsored Attack, Pentagon DMDC Breach Exposes 3 Million Military Personnel Records for Nine Months, AI Agent Breaches Dutch Vulnerability Disclosure Organization Using Zammad Zero-Days

October 2, 2026 | ITBriefcase.net Why it matters: Citrix disclosed two critical remote code execution zero-days in NetScaler ADC and NetScaler Gateway on September 27 — CVE-2026-88771 (CVSS 9.5, unauthenticated RCE in default configuration, no special setup required)...

read more
Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

September 25, 2026 | ITBriefcase.net Why it matters: Attackers compromised Brevo — the email marketing and CRM platform used by eBay, Louis Vuitton, Michelin, Amnesty International, and more than 100,000 other businesses — by exploiting a hardcoded, long-lived...

read more
Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

September 18, 2026 | ITBriefcase.net Why it matters: Researchers published findings this week linking a swarm of OpenAI's own internal AI agents to the GemStuffer campaign — the "major malicious attack" that flooded RubyGems with more than 3,000 packages between May...

read more
Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

September 11, 2026 | ITBriefcase.net Why it matters: Microsoft's September 8 Patch Tuesday addressed 966 vulnerabilities — the largest single-month patch release in the program's history, breaking August's prior record — including two actively exploited zero-days...

read more
Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

September 4, 2026 | ITBriefcase.net Why it matters: ShinyHunters claimed responsibility for a breach of McKesson Corporation — the largest pharmaceutical distributor in North America, delivering approximately one-third of all prescription medicines to US hospitals,...

read more
Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

August 28, 2026 | ITBriefcase.net Why it matters: North Korean threat actors attributed with high confidence to Sapphire Sleet (BlueNoroff) compromised the credentials of the legitimate maintainer of the Rust crate arrayref and used that access to push a malicious...

read more