The MSP Security Coverage Report 2026
Edition One

Five attack surfaces. Two questions. Which ones do managed service providers monitor for their clients in 2026? And which ones does no one measure?

By enhanced.io. Analysis with commentary from Kristian Wright, founder and CEO. June 2026.

The MSP Security Coverage Report 2026
Edition One

Five attack surfaces. Two questions. Which ones do managed service providers monitor for their clients in 2026? And which ones does no one measure?

By enhanced.io. Analysis with commentary from Kristian Wright, founder and CEO. June 2026.

The MSP Security Coverage Report 2026
Edition One

Five attack surfaces. Two questions. Which ones do managed service providers monitor for their clients in 2026? And which ones does no one measure?

By enhanced.io. Analysis with commentary from Kristian Wright, founder and CEO. June 2026.

The story in one page


Most small and mid-sized businesses do not run their own cybersecurity. They hand it to a managed service provider and assume the job is covered. This report tests that assumption against the public evidence.


Security happens across five surfaces. Endpoint, network, cloud, identity, and the IoT and OT devices on the edge of the network. We asked two things of each. Are MSPs watching it for their clients, and how do we know?


The surfaces split into two groups.

Endpoint


The laptops and servers running a security agent. Mature, well documented, and the part MSPs do well.

The rest


Identity, cloud, the inside of the network, and the connected devices no agent ever touches. These are the four surfaces where attacks are growing fastest, and all of them show thin coverage. For two, no neutral source has measured MSP coverage at all.


That last point is the one worth a headline. For the surfaces carrying the most risk, the security industry has not produced a single independent figure for how many MSP-managed clients are covered. The number does not exist. When an industry stops counting a surface, the surface has usually dropped out of normal practice. The silence is itself a finding.


The timing is the other half of the story. The threat moved in the last two years. Edge devices and VPNs went from 3% to 22% of exploitation-based initial access in a single year (Verizon 2025 Data Breach Investigations Report). Destructive cloud campaigns rose 87% (Microsoft Digital Defense Report 2025). Identity attacks rose 32% in the first half of 2025 (Microsoft Digital Defense Report 2025). Monitoring did not move with the threat. It stayed where the mature tools already sat. The attackers went where the watching stopped.

How we built this


This is not a survey, and we did not invent a dataset. We read the credible public evidence, organized it through the five-surface model we use in our own security operations, and marked every place where no one has measured anything. The framework is ours. The field observations are ours. The figures belong to the named sources, each shown with its date and sample size. Where the public data runs out, we say so rather than fill the gap with a number we made up.


Two choices make this more than a clippings file. First, we treat a missing coverage figure as a finding in its own right. When no one has measured whether MSPs watch a surface, the absence tells you something real about where that surface sits. Second, every section closes with what we see when we onboard a new partner and review their client base. No public report holds that view, because no public report comes from inside a security operations center.

Key findings


Endpoint is the most watched surface, and still not universal. 81% of MSPs offer some level of managed detection and response (Sophos MSP Perspectives 2024, n=350, May 2024). Offering a service is not the same as covering a client. The Verizon 2025 DBIR found 46% of compromised systems carrying corporate logins were unmanaged or BYOD devices.


Cloud is the clearest measured gap. Only about one-third of MSPs consistently secure their clients’ Microsoft 365 (ConnectWise, March 2025), while destructive cloud campaigns rose 87% (Microsoft Digital Defense Report 2025).


Identity is the biggest threat and the thinnest coverage data. Credential abuse shows up in 22% of all breaches (Verizon 2025 DBIR), and Huntress found that for more than a third of organizations, identity-based attacks made up over 40% of their security incidents in the past year (Huntress 2025 Managed ITDR report). No neutral source publishes an MFA or identity-monitoring rate for MSP-managed clients. The gap is not MFA adoption. It is what happens after MFA, when no one is watching for account takeover or admin misuse.


The network interior is exposed and under-watched. Edge devices and VPNs jumped from 3% to 22% of exploitation-based initial access in a year (Verizon 2025 DBIR), and lateral movement appeared in 65% of fourth-quarter ransomware cases (Coveware Q4 2025).

IoT and OT is the surface no one measures. No public source reports how many MSPs monitor these devices for clients. The missing number is the finding.


A staffing shortage sits under all of it. 59% of security teams report critical or significant skills gaps, up from 44% a year earlier (ISC2 2025). The structural fix is consolidation and shared security operations, not another tool.

Coverage and threat, by attack surface


Where public data on MSP coverage exists, and how the threat ranks. Coverage is thin or unmeasured on the four highest-risk surfaces.

Attack Surface Public Coverage Data Threat Signal
Endpoint Partial. 81% of MSPs offer MDR, but no neutral source publishes a true endpoint coverage rate. High
Network None published. No public figure for MSP-managed traffic inspection or east-west visibility. High
Cloud One figure. About 1 in 3 MSPs consistently secure clients’ Microsoft 365. Rising
Identity None published. No public MFA, ITDR or phishing-resistant MFA rate for MSP-managed SMBs. Highest
IoT and OT None published. No public figure for how many MSPs monitor IoT or OT devices for clients. Highest

Surface 1.
Endpoint, the part MSPs do well


Endpoint is the oldest and most mature part of the MSP security stack, and the data backs it. In Sophos MSP Perspectives 2024 (n=350, May 2024), 81% of MSPs offered some level of managed detection and response, the usual route to managed endpoint coverage. Kaseya’s 2025 Global MSP Benchmark Report (about 1,000 MSPs, April 2025) placed security among the five fastest-growing revenue lines for 67% of MSPs. The category is established and selling well.


The gap sits between the offer and the client. The Verizon 2025 DBIR found 46% of compromised systems carrying corporate logins were unmanaged or BYOD devices. The same research found 54% of ransomware victims had their domains turn up in infostealer credential dumps (Verizon 2025 DBIR SMB Snapshot, June 2025). A program watching only managed devices misses the machines doing the damage. And no neutral source publishes an EDR deployment rate across all MSP-managed small-business endpoints, so the real coverage level stays unknown.


This matches what we see on onboarding. The device count we find rarely matches the count the partner expected, and the difference is almost always the same kind of machine, a Linux box, a Mac, a server set up outside the standard build, none of them running the agent. The estate on the dashboard and the estate on the network are two different things.


81%

of MSPs offer some level of managed detection and response

Sophos MSP Perspectives 2024

of MSPs offer some level of managed detection and response

Sophos MSP Perspectives 2024

of MSPs offer some level of managed detection and response

Sophos MSP Perspectives 2024

67%

rank security among their five fastest-growing revenue lines

Kaseya 2025 Benchmark

rank security among their five fastest-growing revenue lines

Kaseya 2025 Benchmark

rank security among their five fastest-growing revenue lines

Kaseya 2025 Benchmark

46%

of compromised systems with corporate logins were unmanaged or BYOD

Verizon 2025 DBIR

of compromised systems with corporate logins were unmanaged or BYOD

Verizon 2025 DBIR

of compromised systems with corporate logins were unmanaged or BYOD

Verizon 2025 DBIR

"The endpoint tools are usually already bought by the time we arrive. The gap is rarely the tool. It is the machines the tool never reaches. The device count we get on day one is always low, because someone forgot the Linux boxes, the Macs the mainstream agent handles badly, a director’s personal laptop, a server stood up two years ago and left running. A clean dashboard means the managed devices are quiet. It does not mean the client is safe."

Kristian Wright, founder and CEO of enhanced.io

"The endpoint tools are usually already bought by the time we arrive. The gap is rarely the tool. It is the machines the tool never reaches. The device count we get on day one is always low, because someone forgot the Linux boxes, the Macs the mainstream agent handles badly, a director’s personal laptop, a server stood up two years ago and left running. A clean dashboard means the managed devices are quiet. It does not mean the client is safe."

Kristian Wright, founder and CEO of enhanced.io

"The endpoint tools are usually already bought by the time we arrive. The gap is rarely the tool. It is the machines the tool never reaches. The device count we get on day one is always low, because someone forgot the Linux boxes, the Macs the mainstream agent handles badly, a director’s personal laptop, a server stood up two years ago and left running. A clean dashboard means the managed devices are quiet. It does not mean the client is safe."

Kristian Wright, founder and CEO of enhanced.io

Surface 2.
Network and perimeter, demand up, watching flat


Network security sells, but the threat side has moved faster than the monitoring. The Verizon 2025 DBIR found edge devices and VPNs grew from 3% to 22% of exploitation-based initial access in a single year. Exploitation of vulnerabilities reached 20% of breaches, up 34% year over year (Verizon 2025 DBIR). Coveware’s Q4 2025 report found lateral movement in 65% of ransomware cases. The break-in happens at the edge. The damage happens inside.


Most MSP network coverage stops at the perimeter. A managed firewall hardens the edge. It does not show you traffic moving inside the network, and the inside is where ransomware now spreads. No neutral source publishes the share of MSP-managed networks with active traffic inspection, intrusion detection, or east-west visibility. Bundled network, email and endpoint service lines hide how thin the network layer often runs.


On onboarding the pattern is familiar. When we first put a sensor on a partner's network, the firewall often blocks it until we are allowlisted, which tells you nothing inside has been inspecting traffic. Once it is watching, the early days routinely surface what no one had seen, large unscheduled data transfers, scanning behavior, traffic moving sideways between machines with no reason to talk to each other.


22%

of exploitation-based access uses edge devices & VPNs, up from 3%

Verizon 2025 DBIR

of exploitation-based access uses edge devices & VPNs, up from 3%

Verizon 2025 DBIR

of exploitation-based access uses edge devices & VPNs, up from 3%

Verizon 2025 DBIR

65%

of Q4 ransomware cases showed lateral movement inside the network

Coveware Q4 2025

of Q4 ransomware cases showed lateral movement inside the network

Coveware Q4 2025

of Q4 ransomware cases showed lateral movement inside the network

Coveware Q4 2025

34%

rise in vulnerability exploitation as an initial access vector

Verizon 2025 DBIR

rise in vulnerability exploitation as an initial access vector

Verizon 2025 DBIR

rise in vulnerability exploitation as an initial access vector

Verizon 2025 DBIR

"Ask an MSP if they cover the network and most say yes. Ask what cover means and it is a managed firewall and a monthly patch report. That is hardware on the perimeter. It is not someone watching traffic move inside the network. The first time we turn that visibility on, the things always there start to show. Large data transfers no one scheduled. Scans. Failed logins from a brand-new account. East-west blindness is the gap we find most often, and the one clients understand the least."

Kristian Wright, founder and CEO of enhanced.io

"Ask an MSP if they cover the network and most say yes. Ask what cover means and it is a managed firewall and a monthly patch report. That is hardware on the perimeter. It is not someone watching traffic move inside the network. The first time we turn that visibility on, the things always there start to show. Large data transfers no one scheduled. Scans. Failed logins from a brand-new account. East-west blindness is the gap we find most often, and the one clients understand the least."

Kristian Wright, founder and CEO of enhanced.io

"Ask an MSP if they cover the network and most say yes. Ask what cover means and it is a managed firewall and a monthly patch report. That is hardware on the perimeter. It is not someone watching traffic move inside the network. The first time we turn that visibility on, the things always there start to show. Large data transfers no one scheduled. Scans. Failed logins from a brand-new account. East-west blindness is the gap we find most often, and the one clients understand the least."

Kristian Wright, founder and CEO of enhanced.io

Surface 3.
Cloud and SaaS, the clearest measured gap


This is the one surface with a hard coverage number, and it points in a single direction. ConnectWise reported in March 2025 that only about one-third of MSPs consistently provide security services for their clients’ Microsoft 365. Set that against where the work now lives. Destructive cloud campaigns rose 87% (Microsoft Digital Defense Report 2025). Third-party involvement in breaches doubled from 15% to 30% in a year, much of it through SaaS and vendor connections (Verizon 2025 DBIR). Multi-environment breaches, the ones spanning cloud and on-premises, took an average of 276 days to identify and contain and cost $5.05 million, the most expensive category IBM measured (IBM Cost of a Data Breach Report 2025).


Backup is the common answer, and it is the wrong one. Most MSPs back up their clients’ SaaS data, but a restore point does not catch an account takeover while it happens. No neutral source publishes a cloud security posture rate or an audit-log monitoring rate for MSP-managed Microsoft 365 or Google Workspace tenants. The one-third figure is the only direct coverage number in the entire evidence set.


What we see on onboarding lines up. Audit logging is often switched off or unread, so when we turn it on the first week surfaces what it had been missing, a mailbox rule quietly forwarding mail outside the business, an OAuth consent grant no one remembers approving, a sign-in from a location that makes no sense. The evidence was always there. No one was reading it.


87%

rise in destructive cloud campaigns

Microsoft MDDR 2025

rise in destructive cloud campaigns

Microsoft MDDR 2025

rise in destructive cloud campaigns

Microsoft MDDR 2025

30%

of breaches involve a third party, up from 15%

Verizon 2025 DBIR

of breaches involve a third party, up from 15%

Verizon 2025 DBIR

of breaches involve a third party, up from 15%

Verizon 2025 DBIR

$5.05M

average cost of a multi-environment breach

IBM 2025

average cost of a multi-environment breach

IBM 2025

average cost of a multi-environment breach

IBM 2025

"SaaS security lagged because it did not look like security. Email and files moved into Microsoft 365 and everyone assumed Microsoft had the rest handled. Backup sold well, because losing data is easy to picture. Watching the sign-in logs for a takeover is harder to picture and harder to price, so most teams skipped it. We find the result the moment the connector goes live on a new client. A forwarding rule no one set up. A login from a country the client has never worked in. It had been running for weeks with no one watching."

Kristian Wright, founder and CEO of enhanced.io

"SaaS security lagged because it did not look like security. Email and files moved into Microsoft 365 and everyone assumed Microsoft had the rest handled. Backup sold well, because losing data is easy to picture. Watching the sign-in logs for a takeover is harder to picture and harder to price, so most teams skipped it. We find the result the moment the connector goes live on a new client. A forwarding rule no one set up. A login from a country the client has never worked in. It had been running for weeks with no one watching."

Kristian Wright, founder and CEO of enhanced.io

"SaaS security lagged because it did not look like security. Email and files moved into Microsoft 365 and everyone assumed Microsoft had the rest handled. Backup sold well, because losing data is easy to picture. Watching the sign-in logs for a takeover is harder to picture and harder to price, so most teams skipped it. We find the result the moment the connector goes live on a new client. A forwarding rule no one set up. A login from a country the client has never worked in. It had been running for weeks with no one watching."

Kristian Wright, founder and CEO of enhanced.io

Surface 4. Identity, the biggest threat and the thinnest coverage data


Identity is where the threat data is richest and the coverage data is barest. The Verizon 2025 DBIR found credential abuse is the leading way in, present in 22% of all breaches, with stolen credentials the primary hacking method against small businesses (Verizon 2025 DBIR SMB Snapshot). Business email compromise losses reached $6.3 billion in 2024 (FBI IC3 figures, cited in the same snapshot). Identity attacks rose 32% in the first half of 2025, and more than 97% of them are password attacks (Microsoft Digital Defense Report 2025).


22%

22%

22%

22%

of all breaches involve credential abuse

Verizon 2025 DBIR

of all breaches involve credential abuse

Verizon 2025 DBIR

of all breaches involve credential abuse

Verizon 2025 DBIR

$6.3bn

$6.3bn

$6.3bn

$6.3bn

in business email compromise losses in 2024

FBI IC3 / Verizon 2025

in business email compromise losses in 2024

FBI IC3 / Verizon 2025

in business email compromise losses in 2024

FBI IC3 / Verizon 2025

97%

97%

97%

97%

of identity attacks are password attacks

Microsoft MDDR 2025

of identity attacks are password attacks

Microsoft MDDR 2025

of identity attacks are password attacks

Microsoft MDDR 2025

40%+

40%+

40%+

40%+

of incidents were identity-based, for over a third of organizations surveyed 

Huntress 2025 ITDR

of incidents were identity-based, for over a third of organizations surveyed 

Huntress 2025 ITDR

of incidents were identity-based, for over a third of organizations surveyed 

Huntress 2025 ITDR

There is no clean MSP benchmark to set against that threat. No neutral source in our research window publishes an MFA coverage rate for MSP-managed small businesses. None publishes an identity threat detection and response adoption rate among MSPs. None measures how many run phishing-resistant MFA.


The wider evidence still supports the risk. Microsoft has put identity at the center of its security guidance, with a sustained focus on Conditional Access and proactive identity protection. The 2026 ConnectWise MSP Threat Report describes attackers increasingly exploiting trusted identities, remote access infrastructure and legitimate tools inside MSP-managed environments. Huntress, in its 2025 Managed ITDR report, found that for more than a third of organizations, identity-based attacks made up over 40% of their security incidents in the past year. Read together, the evidence makes identity visibility a frontline MSP issue rather than a nice-to-have add-on.


In our own onboarding reviews the pattern is consistent. In 8 recent MSP onboarding reviews, 7 had MFA enabled but no clear managed identity threat monitoring process beyond the standard Microsoft 365 controls. That means no consistent monitoring for risky sign-ins, MFA abuse, suspicious admin changes, OAuth consent abuse or mailbox compromise indicators.

"The gap is not MFA adoption. The gap is what happens after MFA: who is watching for account takeover, admin misuse and identity abuse once the user gets in?"

Kristian Wright, founder and CEO of enhanced.io

"The gap is not MFA adoption. The gap is what happens after MFA: who is watching for account takeover, admin misuse and identity abuse once the user gets in?"

Kristian Wright, founder and CEO of enhanced.io

"The gap is not MFA adoption. The gap is what happens after MFA: who is watching for account takeover, admin misuse and identity abuse once the user gets in?"

Kristian Wright, founder and CEO of enhanced.io

Surface 5.
IoT and OT, the surface no one measures


Here the public record goes quiet. No neutral source in our research window reports how many MSPs monitor IoT or OT devices for their clients. The closest data sits outside the channel. Claroty’s State of CPS Security 2025 found 75% of organizations running building management systems had at least one known exploited vulnerability, and 51% of those had building systems with ransomware-linked vulnerabilities and exposed internet connections. The study covers large, asset-heavy organizations, not the small businesses MSPs serve, so it signals scale, not coverage. The Verizon 2025 DBIR found manufacturing breaches close to doubling in a year, from 849 to 1,607, with no device-level IoT or OT split. ConnectWise links a rise in attacks on these devices to limited monitoring, without putting a number on it.


Our own onboarding work tells the same story. When we inventory a partner's client networks we routinely find devices with no agent to install on them, building controls, cameras, industrial and medical equipment, often with default credentials and a live internet connection, and almost never on anyone's monitored list. Nothing there was being watched, because nothing there had been found.


75%

of building-management-system organizations had a known exploited vulnerability

Claroty 2025

of building-management-system organizations had a known exploited vulnerability

Claroty 2025

of building-management-system organizations had a known exploited vulnerability

Claroty 2025

51%

of those had ransomware-linked vulnerabilities and exposed internet connections

Claroty 2025

of those had ransomware-linked vulnerabilities and exposed internet connections

Claroty 2025

of those had ransomware-linked vulnerabilities and exposed internet connections

Claroty 2025

0

independent figures for how many MSPs monitor IoT or OT environments for clients

The missing number

independent figures for how many MSPs monitor IoT or OT environments for clients

The missing number

independent figures for how many MSPs monitor IoT or OT environments for clients

The missing number

"Most MSPs do not know what sits on their clients’ networks at the device level. Cameras, door controllers, building panels, machines on a factory floor. None of it runs an agent, so none of it shows up in an endpoint console. Our work here is not theory. We monitor industrial machines that will never run an agent by watching the network around them. One smart-buildings client had a single problem underneath everything else. No one had ever inventoried the devices. Find the device first, or it stays invisible."

Kristian Wright, founder and CEO of enhanced.io

"Most MSPs do not know what sits on their clients’ networks at the device level. Cameras, door controllers, building panels, machines on a factory floor. None of it runs an agent, so none of it shows up in an endpoint console. Our work here is not theory. We monitor industrial machines that will never run an agent by watching the network around them. One smart-buildings client had a single problem underneath everything else. No one had ever inventoried the devices. Find the device first, or it stays invisible."

Kristian Wright, founder and CEO of enhanced.io

"Most MSPs do not know what sits on their clients’ networks at the device level. Cameras, door controllers, building panels, machines on a factory floor. None of it runs an agent, so none of it shows up in an endpoint console. Our work here is not theory. We monitor industrial machines that will never run an agent by watching the network around them. One smart-buildings client had a single problem underneath everything else. No one had ever inventoried the devices. Find the device first, or it stays invisible."

Kristian Wright, founder and CEO of enhanced.io

The cross-surface picture


Rank the five surfaces by the weight of public monitoring data, and the order runs endpoint first, network second, cloud third on the strength of one figure, identity fourth, and IoT and OT last with no figure at all. That order tracks the age and tooling maturity of each surface. It does not track the risk. Identity is the leading threat. Cloud attack volume is climbing fastest. IoT and OT is the surge no one is measuring. Monitoring has followed the tools, not the threat.

Recent rate of change

The threat moved fastest on the surfaces with the least coverage.

The cross-surface picture


Rank the five surfaces by the weight of public monitoring data, and the order runs endpoint first, network second, cloud third on the strength of one figure, identity fourth, and IoT and OT last with no figure at all. That order tracks the age and tooling maturity of each surface. It does not track the risk. Identity is the leading threat. Cloud attack volume is climbing fastest. IoT and OT is the surge no one is measuring. Monitoring has followed the tools, not the threat.

Recent rate of change

The threat moved fastest on the surfaces with the least coverage

Indicator Change
Destructive cloud campaigns +87%
Vulnerability exploitation as an initial access vector +34%
Identity-based attacks, first half 2025 +32%

Microsoft Digital Defense Report 2025 (destructive cloud campaigns; identity attacks, first half 2025); Verizon 2025 DBIR (vulnerability exploitation, year over year).

Microsoft Digital Defense Report 2025 (destructive cloud campaigns; identity attacks, first half 2025); Verizon 2025 DBIR (vulnerability exploitation, year over year).

The staffing shortage underneath


Under every surface is a hiring problem. The ISC2 2025 Cybersecurity Workforce Study (n=16,029, December 2025) found 59% of security professionals reporting critical or significant skills shortages on their teams, up from 44% the year before, and 88% reporting at least one security consequence from a skills gap in the past year. GTIA’s SMB Technology and Buying Trends 2025 found only about 4 in 10 small businesses treat cybersecurity as a spending priority. In Sophos MSP Perspectives 2024, the shortage of in-house security skills ranked as the single biggest risk MSPs named, ahead of ransomware and supply-chain attacks.

Year over year shifts

Prior year compared with the latest reading.

The staffing shortage underneath


Under every surface is a hiring problem. The ISC2 2025 Cybersecurity Workforce Study (n=16,029, December 2025) found 59% of security professionals reporting critical or significant skills shortages on their teams, up from 44% the year before, and 88% reporting at least one security consequence from a skills gap in the past year. GTIA’s SMB Technology and Buying Trends 2025 found only about 4 in 10 small businesses treat cybersecurity as a spending priority. In Sophos MSP Perspectives 2024, the shortage of in-house security skills ranked as the single biggest risk MSPs named, ahead of ransomware and supply-chain attacks.

Year over year shifts

Prior year compared with the latest reading.

Indicator Prior Year Latest
Edge devices and VPNs as an initial access vector 3% 22%
Third-party involvement in breaches 15% 30%
Security teams reporting critical or significant skills gaps 44% 59%

Verizon 2025 DBIR (initial access, third-party involvement); ISC2 2025 Cybersecurity Workforce Study (skills gaps).

Verizon 2025 DBIR (initial access, third-party involvement); ISC2 2025 Cybersecurity Workforce Study (skills gaps).

Why coverage and correlation belong together


The shortage is why the gaps hold. No MSP hires its way across five surfaces. The market response is consolidation. Fewer tools, better integrated, with a security operations center behind them. In N-able’s MSP Horizons Report 2025, third-party MDR topped the list of services MSPs plan to add, and 90% expected their cybersecurity managed services to grow.


We push the point one step further. Five surfaces watched separately produce five blind spots between them. The attacks worth worrying about cross surfaces. A stolen credential becomes a cloud session, becomes lateral movement, becomes encryption. Detection that does not correlate across all five at once sees each step and misses the story.

"Here is the chain we watch every day. A credential turns up in a breach dump. It works on a Microsoft 365 account, because the password was reused. The session moves to a second machine. Then someone reaches for the backups. Watch one surface and you see one step. Watch all five and you see the whole story while there is still time to stop it. The other daily reality is noise. Most of what lands in a SOC queue does not matter. The work is filtering it down to the few alerts that do, fast, before the chain finishes. A stretched MSP team has no hours left for that."

Kristian Wright, founder and CEO of enhanced.io

"Here is the chain we watch every day. A credential turns up in a breach dump. It works on a Microsoft 365 account, because the password was reused. The session moves to a second machine. Then someone reaches for the backups. Watch one surface and you see one step. Watch all five and you see the whole story while there is still time to stop it. The other daily reality is noise. Most of what lands in a SOC queue does not matter. The work is filtering it down to the few alerts that do, fast, before the chain finishes. A stretched MSP team has no hours left for that."

Kristian Wright, founder and CEO of enhanced.io

"Here is the chain we watch every day. A credential turns up in a breach dump. It works on a Microsoft 365 account, because the password was reused. The session moves to a second machine. Then someone reaches for the backups. Watch one surface and you see one step. Watch all five and you see the whole story while there is still time to stop it. The other daily reality is noise. Most of what lands in a SOC queue does not matter. The work is filtering it down to the few alerts that do, fast, before the chain finishes. A stretched MSP team has no hours left for that."

Kristian Wright, founder and CEO of enhanced.io

What this means for MSPs


The evidence supports a short, practical list. No inflation.



  • Endpoint. Stop trusting the dashboard. Inventory the devices first. The machines outside the managed estate are where the credentials get stolen.


  • Network. Separate the firewall from the monitoring in your own offer. If no one is watching traffic move inside the network, say so, then fix it.


  • Cloud. Treat Microsoft 365 as a security surface, not a productivity tool you back up. Turn on the audit logs. Watch the sign-ins.


  • Identity. Move here first. The threat data is overwhelming and the coverage is the thinnest of any surface. Enforce MFA everywhere, watch the identity events, or accept this as the open door.


  • IoT and OT. Find the devices before you promise to monitor them. Discovery is the whole first step.


  • Across all of it. The answer is not another point tool. It is fewer tools, watched together, with a named person accountable for the client. Start there.


The numbers above are the public half of the story. The half no one measures is the half putting MSP clients at risk. That is the gap this report sets out to name, and the reason enhanced.io exists.

Methodology and sources


What this is. A synthesis of public evidence, organized through enhanced.io’s five-surface model, with field observations from our own partner onboarding and security operations. The framework and the observations are ours. The figures belong to the named sources.


Research window. Reports published between January 2024 and June 2026.


How we used sources. Neutral authorities lead the evidence. Verizon, Microsoft, IBM, ISC2, Coveware, GTIA and Claroty. Channel-vendor data from ConnectWise, Sophos, Kaseya, N-able and Huntress appears where it is the closest available source of MSP-market evidence, and it is labeled as vendor data. No section rests on a single vendor’s threat report.


Guardrails. Only publicly available figures we are able to cite. Every figure carries its named source, date and sample size. No statistic estimated, inferred, rounded or invented. Every percentage stays tied to the denominator in its original source. Percentages from different surveys are never added together. Where no reliable public data exists, we say so.


Field observations. Statements about what we see on onboarding, or across the environments we monitor, are qualitative and directional. We offer them as practitioner observation, not as measured rates.


Sources


Each link points to the publisher’s own page.

What this means for MSPs


The evidence supports a short, practical list. No inflation.


Endpoint. Stop trusting the dashboard. Inventory the devices first. The machines outside the managed estate are where the credentials get stolen.


Network. Separate the firewall from the monitoring in your own offer. If no one is watching traffic move inside the network, say so, then fix it.


Cloud. Treat Microsoft 365 as a security surface, not a productivity tool you back up. Turn on the audit logs. Watch the sign-ins.


Identity. Move here first. The threat data is overwhelming and the coverage is the thinnest of any surface. Enforce MFA everywhere, watch the identity events, or accept this as the open door.


IoT and OT. Find the devices before you promise to monitor them. Discovery is the whole first step.

  

Across all of it. The answer is not another point tool. It is fewer tools, watched together, with a named person accountable for the client. Start there.


The numbers above are the public half of the story. The half no one measures is the half putting MSP clients at risk. That is the gap this report sets out to name, and the reason enhanced.io exists.

Methodology and sources


What this is. A synthesis of public evidence, organized through enhanced.io’s five-surface model, with field observations from our own partner onboarding and security operations. The framework and the observations are ours. The figures belong to the named sources.


Research window. Reports published between January 2024 and June 2026.


How we used sources. Neutral authorities lead the evidence. Verizon, Microsoft, IBM, ISC2, Coveware, GTIA and Claroty. Channel-vendor data from ConnectWise, Sophos, Kaseya, N-able and Huntress appears where it is the closest available source of MSP-market evidence, and it is labeled as vendor data. No section rests on a single vendor’s threat report.


Guardrails. Only publicly available figures we are able to cite. Every figure carries its named source, date and sample size. No statistic estimated, inferred, rounded or invented. Every percentage stays tied to the denominator in its original source. Percentages from different surveys are never added together. Where no reliable public data exists, we say so.


Field observations. Statements about what we see on onboarding, or across the environments we monitor, are qualitative and directional. We offer them as practitioner observation, not as measured rates.

Sources



Each link points to the publisher’s own page.

Permissions. Figures in this report belong to the cited sources and should be attributed to them. The enhanced.io analysis, the five-surface framing, and the quotes from Kristian Wright may be reproduced with attribution to enhanced.io. 

Permissions. Figures in this report belong to the cited sources and should be attributed to them. The enhanced.io analysis, the five-surface framing, and the quotes from Kristian Wright may be reproduced with attribution to enhanced.io. 

Ready to deliver a complete cybersecurity solution?

Ready to deliver a complete cybersecurity solution?

Let’s talk