
Milda Kaklauskaitė is a cybersecurity capacity building and policy expert at NRD Cyber Security. She previously spent six years at the European Cyber Security Organisation (ECSO), working on cybersecurity market development and with start-ups, investors and integrators across the European cybersecurity ecosystem. She has also worked directly with cybersecurity start-ups and scale-ups. We invited Milda to share her expertise and know-how on the drivers of MSSP market in Europe, key trends and observations.
Global cybersecurity spending is expected to double by 2029, exceeding USD 300 billion, up from USD 154.6 billion in 2024.[1] This demand provides a solid foundation for the growth of managed security services (MSS) sector. Unprecedented levels of M&A activity across MSS also signal growing demand for expert-led cybersecurity services.[2] In this piece I will try to go deeper into trends shaping the MSSP market in Europe. While I focus on the European market, similar trends can also be observed elsewhere.
MSSPs have been occupying an increasingly large part of the European cybersecurity market, and with good reason. An increasing number of businesses, and public institutions recognise the need for a strong cybersecurity measure. But it is also more and more apparent that building the necessary cybersecurity practice in-house is expensive and simply too complicated. This is especially relevant in Europe where majority of businesses are small and medium-sized enterprises and building a dedicated security team is often not a viable business option.
The talent shortage is another reason why organisations turn to MSSPs. In short, we do not have a shortage of cybersecurity tools in Europe. What we have is a shortage of people, time and capacity to operate them effectively.
The ever-growing technological complexity, regulatory pressure and number of security incidents that business and organisations must navigate create opportunities for MSSPs. They are increasingly seen as the best way to master cybersecurity challenges and increase organisations’ resilience against cyber threats. However, not all MSS are experiencing the same level of demand. This reflects a broader shift in customer demand. Demand is increasingly moving towards specialised capabilities that customers struggle to build and sustain in-house.
One of the clearest shifts is from monitoring towards detection and response. Traditional MSSPs provide security infrastructure management, monitoring, and compliance services. Modern MSSPs now also offer managed detection and response (MDR). MDR has been one of the faster-growing segments of the market. The reason is relatively simple. Many organisations lack the in-house expertise or capacity to respond to received security alerts, while MDR helps fill this gap. This broader move beyond basic monitoring is also visible in growing demand for cybersecurity governance support, sector-specific expertise, incident response, threat intelligence and OT security services.

AI adds another layer to the transformation of the MSSP market. Automation and AI help to reduce the time and human effort spent on repetitive tasks such as triage. This allows human expertise on critical tasks where human judgement, previous experience and context understanding play a crucial role, such as decision-making and incident response. This is particularly important for MSSP business model. The more customers the MSSP works with, the more people it traditionally needs to hire to serve them. Efficient use of human expertise across the customers is important and automation definitely helps with that.
At the same time, regulation is changing what European customers expect from MSSPs. NIS2, DORA and other European Union regulations that have recently come into force are pushing organisations to review and strengthen their operational cybersecurity capabilities to ensure regulatory compliance. As organisations realise that they may not be able to build these capabilities themselves, they look for external expertise to help them. In other words, regulation is not only driving demand for compliance support, but also for managed security services needed to meet these requirements.
The MSSP market itself is also changing and moving towards greater consolidation. MSSPs are acquiring niche providers with the goal to broaden their service portfolios or increase service capacity, expand into new geographies and acquire new talent. Often, it is a combination of these factors. Market data shows a surge in MSSP acquisitions in the first quarter of 2026[3], but the acquisition trend has been visible for several years now. Think of Orange Cyberdefense acquiring SCRT and Telsys in 2022 and ensec in 2025, or a recent ReeVo acquisition of Hispasec in 2026, for example.
The changing trends and economics of MSS market have not gone unnoticed by investors. Private equity (PE) and strategic buyers have been increasingly active in MSSP M&A deals. However, most venture capital firms (VCs) have traditionally preferred to stay away from this space for a simple reason: MSSPs does not match the VC business model.
VCs usually place their bets on high-risk, early-stage companies with high growth potential and a clear exit path within 5-8 years. These are often product companies whose growth is less dependent on human expertise. MSSPs, on the other hand, tend to be lower-risk businesses with steady cash flows, but with lower growth potential. Scaling the business often means adding more people to the team, and more people means higher operational expenses and lower margins. This makes MSSPs a more natural fit for PE firms and strategic investors, which see opportunities to implement buy-and-build strategies, consolidate the market and acquire necessary talent and capabilities.

However, VCs should not underestimate investments in MSSPs, even if they do not match their preferred growth profile. MSSPs interact with many different customers and see their pain points first-hand. This can provide valuable information on which problems customers are actually willing to pay to solve and spot market trends. For investors, this can provide a useful reality check and help inform investment decisions. Having an MSSP in the portfolio can also benefit other portfolio companies by providing access to customer insights and market validation, which are particularly valuable for early-stage companies.
The European MSSP market will certainly continue to grow as digital complexity and cyber risks grow too. But this growth will be captured by service providers that can create value that customers cannot produce in-house or easily buy elsewhere. Today, organisations expect from MSSPs not only technology management but concrete business outcomes: reduced risks and increased cyber resilience.
Trust will also matter. According to ENISA’s 2025 MSS Market Analysis, customers place significant importance on trust and their relationship with the service provider [4]. In fact, customers place greater importance on this than MSS providers themselves. This creates an opportunity for MSSPs to recognise the gap and make trust a central part of their business strategy.
Regulation creates new expectations. Consolidation produces larger players. But niche specialisation, sector expertise and customer trust will be important differentiators for MSSPs. The next phase of the European MSSP market will be defined not only by how much it grows, but by which services, capabilities and business models grow with it.
[1] https://www.forrester.com/blogs/global-cybersecurity-spending-to-exceed-300b-by-2029/
[2] https://momentumcyber.com/wp-content/uploads/2026/07/Momentum-Cyber-Cybersecurity-Market-Review-H1-2026.pdf , pp. 49
[4] https://www.enisa.europa.eu/sites/default/files/2025-06/ENISA_MSS_Market_Analysis_en_2.pdf , pp. 36-42
The illustrative image used in the article has been generated using AI in post-impressionist style similar to Paul Cézanne.