
The story in one page
Most small and mid-sized businesses do not run their own cybersecurity. They hand it to a managed service provider and assume the job is covered. This report tests that assumption against the public evidence.
Security happens across five surfaces. Endpoint, network, cloud, identity, and the IoT and OT devices on the edge of the network. We asked two things of each. Are MSPs watching it for their clients, and how do we know?
The surfaces split into two groups.
Endpoint
The laptops and servers running a security agent. Mature, well documented, and the part MSPs do well.
The rest
Identity, cloud, the inside of the network, and the connected devices no agent ever touches. These are the four surfaces where attacks are growing fastest, and all of them show thin coverage. For two, no neutral source has measured MSP coverage at all.
That last point is the one worth a headline. For the surfaces carrying the most risk, the security industry has not produced a single independent figure for how many MSP-managed clients are covered. The number does not exist. When an industry stops counting a surface, the surface has usually dropped out of normal practice. The silence is itself a finding.
The timing is the other half of the story. The threat moved in the last two years. Edge devices and VPNs went from 3% to 22% of exploitation-based initial access in a single year (Verizon 2025 Data Breach Investigations Report). Destructive cloud campaigns rose 87% (Microsoft Digital Defense Report 2025). Identity attacks rose 32% in the first half of 2025 (Microsoft Digital Defense Report 2025). Monitoring did not move with the threat. It stayed where the mature tools already sat. The attackers went where the watching stopped.
How we built this
This is not a survey, and we did not invent a dataset. We read the credible public evidence, organized it through the five-surface model we use in our own security operations, and marked every place where no one has measured anything. The framework is ours. The field observations are ours. The figures belong to the named sources, each shown with its date and sample size. Where the public data runs out, we say so rather than fill the gap with a number we made up.
Two choices make this more than a clippings file. First, we treat a missing coverage figure as a finding in its own right. When no one has measured whether MSPs watch a surface, the absence tells you something real about where that surface sits. Second, every section closes with what we see when we onboard a new partner and review their client base. No public report holds that view, because no public report comes from inside a security operations center.
Key findings
Endpoint is the most watched surface, and still not universal. 81% of MSPs offer some level of managed detection and response (Sophos MSP Perspectives 2024, n=350, May 2024). Offering a service is not the same as covering a client. The Verizon 2025 DBIR found 46% of compromised systems carrying corporate logins were unmanaged or BYOD devices.
Cloud is the clearest measured gap. Only about one-third of MSPs consistently secure their clients’ Microsoft 365 (ConnectWise, March 2025), while destructive cloud campaigns rose 87% (Microsoft Digital Defense Report 2025).
Identity is the biggest threat and the thinnest coverage data. Credential abuse shows up in 22% of all breaches (Verizon 2025 DBIR), and Huntress found that for more than a third of organizations, identity-based attacks made up over 40% of their security incidents in the past year (Huntress 2025 Managed ITDR report). No neutral source publishes an MFA or identity-monitoring rate for MSP-managed clients. The gap is not MFA adoption. It is what happens after MFA, when no one is watching for account takeover or admin misuse.
The network interior is exposed and under-watched. Edge devices and VPNs jumped from 3% to 22% of exploitation-based initial access in a year (Verizon 2025 DBIR), and lateral movement appeared in 65% of fourth-quarter ransomware cases (Coveware Q4 2025).
IoT and OT is the surface no one measures. No public source reports how many MSPs monitor these devices for clients. The missing number is the finding.
A staffing shortage sits under all of it. 59% of security teams report critical or significant skills gaps, up from 44% a year earlier (ISC2 2025). The structural fix is consolidation and shared security operations, not another tool.
Coverage and threat, by attack surface
Where public data on MSP coverage exists, and how the threat ranks. Coverage is thin or unmeasured on the four highest-risk surfaces.
| Attack Surface | Public Coverage Data | Threat Signal |
|---|---|---|
| Endpoint | Partial. 81% of MSPs offer MDR, but no neutral source publishes a true endpoint coverage rate. | High |
| Network | None published. No public figure for MSP-managed traffic inspection or east-west visibility. | High |
| Cloud | One figure. About 1 in 3 MSPs consistently secure clients’ Microsoft 365. | Rising |
| Identity | None published. No public MFA, ITDR or phishing-resistant MFA rate for MSP-managed SMBs. | Highest |
| IoT and OT | None published. No public figure for how many MSPs monitor IoT or OT devices for clients. | Highest |
Surface 1.
Endpoint, the part MSPs do well
Endpoint is the oldest and most mature part of the MSP security stack, and the data backs it. In Sophos MSP Perspectives 2024 (n=350, May 2024), 81% of MSPs offered some level of managed detection and response, the usual route to managed endpoint coverage. Kaseya’s 2025 Global MSP Benchmark Report (about 1,000 MSPs, April 2025) placed security among the five fastest-growing revenue lines for 67% of MSPs. The category is established and selling well.
The gap sits between the offer and the client. The Verizon 2025 DBIR found 46% of compromised systems carrying corporate logins were unmanaged or BYOD devices. The same research found 54% of ransomware victims had their domains turn up in infostealer credential dumps (Verizon 2025 DBIR SMB Snapshot, June 2025). A program watching only managed devices misses the machines doing the damage. And no neutral source publishes an EDR deployment rate across all MSP-managed small-business endpoints, so the real coverage level stays unknown.
This matches what we see on onboarding. The device count we find rarely matches the count the partner expected, and the difference is almost always the same kind of machine, a Linux box, a Mac, a server set up outside the standard build, none of them running the agent. The estate on the dashboard and the estate on the network are two different things.
81%
67%
46%
Surface 2.
Network and perimeter, demand up, watching flat
Network security sells, but the threat side has moved faster than the monitoring. The Verizon 2025 DBIR found edge devices and VPNs grew from 3% to 22% of exploitation-based initial access in a single year. Exploitation of vulnerabilities reached 20% of breaches, up 34% year over year (Verizon 2025 DBIR). Coveware’s Q4 2025 report found lateral movement in 65% of ransomware cases. The break-in happens at the edge. The damage happens inside.
Most MSP network coverage stops at the perimeter. A managed firewall hardens the edge. It does not show you traffic moving inside the network, and the inside is where ransomware now spreads. No neutral source publishes the share of MSP-managed networks with active traffic inspection, intrusion detection, or east-west visibility. Bundled network, email and endpoint service lines hide how thin the network layer often runs.
On onboarding the pattern is familiar. When we first put a sensor on a partner's network, the firewall often blocks it until we are allowlisted, which tells you nothing inside has been inspecting traffic. Once it is watching, the early days routinely surface what no one had seen, large unscheduled data transfers, scanning behavior, traffic moving sideways between machines with no reason to talk to each other.
22%
65%
34%
Surface 3.
Cloud and SaaS, the clearest measured gap
This is the one surface with a hard coverage number, and it points in a single direction. ConnectWise reported in March 2025 that only about one-third of MSPs consistently provide security services for their clients’ Microsoft 365. Set that against where the work now lives. Destructive cloud campaigns rose 87% (Microsoft Digital Defense Report 2025). Third-party involvement in breaches doubled from 15% to 30% in a year, much of it through SaaS and vendor connections (Verizon 2025 DBIR). Multi-environment breaches, the ones spanning cloud and on-premises, took an average of 276 days to identify and contain and cost $5.05 million, the most expensive category IBM measured (IBM Cost of a Data Breach Report 2025).
Backup is the common answer, and it is the wrong one. Most MSPs back up their clients’ SaaS data, but a restore point does not catch an account takeover while it happens. No neutral source publishes a cloud security posture rate or an audit-log monitoring rate for MSP-managed Microsoft 365 or Google Workspace tenants. The one-third figure is the only direct coverage number in the entire evidence set.
What we see on onboarding lines up. Audit logging is often switched off or unread, so when we turn it on the first week surfaces what it had been missing, a mailbox rule quietly forwarding mail outside the business, an OAuth consent grant no one remembers approving, a sign-in from a location that makes no sense. The evidence was always there. No one was reading it.
87%
30%
$5.05M
Surface 4. Identity, the biggest threat and the thinnest coverage data
Identity is where the threat data is richest and the coverage data is barest. The Verizon 2025 DBIR found credential abuse is the leading way in, present in 22% of all breaches, with stolen credentials the primary hacking method against small businesses (Verizon 2025 DBIR SMB Snapshot). Business email compromise losses reached $6.3 billion in 2024 (FBI IC3 figures, cited in the same snapshot). Identity attacks rose 32% in the first half of 2025, and more than 97% of them are password attacks (Microsoft Digital Defense Report 2025).
There is no clean MSP benchmark to set against that threat. No neutral source in our research window publishes an MFA coverage rate for MSP-managed small businesses. None publishes an identity threat detection and response adoption rate among MSPs. None measures how many run phishing-resistant MFA.
The wider evidence still supports the risk. Microsoft has put identity at the center of its security guidance, with a sustained focus on Conditional Access and proactive identity protection. The 2026 ConnectWise MSP Threat Report describes attackers increasingly exploiting trusted identities, remote access infrastructure and legitimate tools inside MSP-managed environments. Huntress, in its 2025 Managed ITDR report, found that for more than a third of organizations, identity-based attacks made up over 40% of their security incidents in the past year. Read together, the evidence makes identity visibility a frontline MSP issue rather than a nice-to-have add-on.
In our own onboarding reviews the pattern is consistent. In 8 recent MSP onboarding reviews, 7 had MFA enabled but no clear managed identity threat monitoring process beyond the standard Microsoft 365 controls. That means no consistent monitoring for risky sign-ins, MFA abuse, suspicious admin changes, OAuth consent abuse or mailbox compromise indicators.
Surface 5.
IoT and OT, the surface no one measures
Here the public record goes quiet. No neutral source in our research window reports how many MSPs monitor IoT or OT devices for their clients. The closest data sits outside the channel. Claroty’s State of CPS Security 2025 found 75% of organizations running building management systems had at least one known exploited vulnerability, and 51% of those had building systems with ransomware-linked vulnerabilities and exposed internet connections. The study covers large, asset-heavy organizations, not the small businesses MSPs serve, so it signals scale, not coverage. The Verizon 2025 DBIR found manufacturing breaches close to doubling in a year, from 849 to 1,607, with no device-level IoT or OT split. ConnectWise links a rise in attacks on these devices to limited monitoring, without putting a number on it.
Our own onboarding work tells the same story. When we inventory a partner's client networks we routinely find devices with no agent to install on them, building controls, cameras, industrial and medical equipment, often with default credentials and a live internet connection, and almost never on anyone's monitored list. Nothing there was being watched, because nothing there had been found.
75%
51%
0
| Indicator | Change |
|---|---|
| Destructive cloud campaigns | +87% |
| Vulnerability exploitation as an initial access vector | +34% |
| Identity-based attacks, first half 2025 | +32% |
| Indicator | Prior Year | Latest |
|---|---|---|
| Edge devices and VPNs as an initial access vector | 3% | 22% |
| Third-party involvement in breaches | 15% | 30% |
| Security teams reporting critical or significant skills gaps | 44% | 59% |
Why coverage and correlation belong together
The shortage is why the gaps hold. No MSP hires its way across five surfaces. The market response is consolidation. Fewer tools, better integrated, with a security operations center behind them. In N-able’s MSP Horizons Report 2025, third-party MDR topped the list of services MSPs plan to add, and 90% expected their cybersecurity managed services to grow.
We push the point one step further. Five surfaces watched separately produce five blind spots between them. The attacks worth worrying about cross surfaces. A stolen credential becomes a cloud session, becomes lateral movement, becomes encryption. Detection that does not correlate across all five at once sees each step and misses the story.
