Executive summary
Managed security is a strange business: demand keeps growing and margins keep thinning. The reason is structural. An MSSP sells outcomes — monitored, investigated, contained — but buys inputs, and the dominant input is analyst hours. Every new customer adds alert volume; alert volume demands analysts; analysts are scarce, expensive and hard to keep, with 4.8 million security roles unfilled worldwide [1]. Revenue scales per customer while cost scales per alert, and the gap between those two curves is where MSSP profitability goes to die.
Meanwhile the competitive floor is moving. Buyers now ask about AI-driven automation in tenders, and providers without a credible answer lose deals they would have won two years ago. This paper is for MSSP and MDR leadership: it works through why the analyst-hours model stopped scaling, what an AI responder changes in multi-tenant economics, what it makes possible commercially, and what to demand from the technology before trusting it with customer environments — with tenant isolation at the top of the list.
1. The economics that stopped working
Run the unit economics of a managed SOC honestly. A customer generating 1,500 alerts a day would need roughly 92 analysts for full manual coverage, about $8.8 million a year at loaded cost [2]. No customer pays that, so no provider staffs it. Instead the industry converged on the same quiet compromise as internal SOCs: tune aggressively, triage hard, investigate a fraction, and accept that most alerts are never examined — industry-wide, about two-thirds are not [3]. The service is priced on the fraction. The risk lives in the remainder.
The compromise worked commercially while every competitor made it too, but three pressures now squeeze it at once. Labour: analyst salaries keep climbing while churn drains experience, and 24/7 multi-tenant coverage multiplies the rota problem across every time zone served. Customers: procurement teams have learned to ask about coverage percentages, mean time to respond and automation, so the quiet compromise is harder to keep quiet. And attackers: with median access hand-offs at 22 seconds and full compromise cycles inside 72 hours [4], the human-triage model is not just expensive, it is losing the race it is paid to run. An MSSP's answer to all three has historically been the same lever — more analysts — which is exactly the lever that no longer moves.
2. What an AI responder changes in the model
An AI responder — a system that autonomously investigates alerts end to end, reaches verdicts and takes or proposes response actions — changes the input side of the business. Investigation stops being an analyst-hours cost and becomes a compute cost, and compute scales the way MSSP revenue always wanted its costs to scale: per unit, cheaply, without recruitment. In CounterShadow's modelled scenario, a manual investigation consumes about twenty minutes and $31 of loaded analyst time; the same investigation runs end to end in about eight minutes at a fraction of the cost, for an overall operating cost around 2.5 times lower [2].
The margin arithmetic follows directly, but the commercial consequences matter more than the cost line. Coverage becomes a sellable number: 100% of automatable alerts investigated, for every tenant, at 3am as at 3pm — a differentiator in tenders precisely because incumbent economics cannot match it manually. Onboarding stops being a hiring event: absorbing a new customer's alert volume no longer means finding analysts before recognising revenue. Service tiers become real: response SLAs measured in minutes, evidence-backed investigation reports for every alert, per-tenant autonomy policies from fully gated to fully autonomous, priced accordingly. And your senior analysts, the people hardest to hire and easiest to lose, move from queue triage to the L2/L3 escalation, threat hunting and customer-facing work that justifies their cost and keeps them.
What does not change is accountability. The MSSP still owns the customer relationship, the SLAs, the judgment calls. The AI responder is capacity, not a substitute for the service layer — which is why the governance questions in section 4 decide whether this model works or backfires.
3. Multi-tenancy is where this gets decided
Everything attractive about the model collapses if tenant boundaries are soft. An AI responder in a managed context holds investigative access to many customers' telemetry and, depending on autonomy settings, credentials that can act inside their environments. Cross-tenant data exposure is an extinction-level event for an MSSP, so the architecture questions come before the economics questions.
The standard to demand: strict per-tenant isolation, with a dedicated execution environment and action runner per customer, so investigation and response for one tenant runs inside that tenant's boundary and nowhere else. Connectivity should be outbound-only over encrypted channels, with no inbound firewall rules into customer estates. Per-tenant policy: each customer sets its own autonomy dial, SOPs and escalation rules, because a bank and a retailer will not accept the same rules of engagement. Per-tenant audit: every investigation step logged to a timeline the customer can see, which turns transparency into a service feature. And deployment flexibility across the provider's own model — whether the platform is vendor-hosted while the MSSP manages operations, or fully self-hosted inside the MSSP's infrastructure for providers whose positioning demands it [2].
4. Questions to ask any vendor (including us)
The market will fill with AI-SOC claims, and an MSSP's diligence burden is heavier than an enterprise's because customer trust is transitively at stake. Six questions separate substance from branding.
- Does it investigate and act, or summarise? Ask to see a full investigation with the response action executed, not a demo of alert enrichment.
- How is tenant isolation enforced, technically? Dedicated per-tenant runners and execution environments, or logical separation in shared infrastructure?
- Can each customer have its own autonomy policy, SOPs and escalation rules, set without code changes?
- Is every reasoning step logged, and can the tenant see the trail? Your customers' auditors will ask you.
- What are the deployment options for you as the provider — including self-hosting the platform if your positioning requires it?
- Does pricing scale with alerts handled rather than seats, so cost tracks the value delivered and the multi-tenant economics stay coherent as you grow?
Any vendor that stumbles on isolation or auditability is offering you margin improvement in exchange for concentration risk. That is a bad trade at any price.
5. Where CounterShadow fits
CounterShadow built its platform for the managed model from the start, and the design answers map one-to-one onto the questions above. AMI investigates every alert end to end in about eight minutes and executes response through 1,200+ out-of-the-box actions across 100+ integrations, so it works across the mixed customer stacks an MSSP actually inherits — vendor-agnostic by necessity, no rip-and-replace conversations with your customers [2]. Multi-tenant deployments enforce strict tenant isolation with a dedicated action runner per end customer and outbound-only SSL connectivity. Autonomy, SOPs and process flows are set per tenant, in plain language, by your service delivery team. Every investigation produces a logged timeline, report and evidence pack the customer can be shown. And the platform runs in the deployment model that fits your business: CounterShadow-hosted with your team operating it, private cloud, or fully self-hosted inside your own infrastructure, with per-tenant isolation preserved in every variant. Pricing scales with alerts handled, not seats [2].
The result, in the modelled economics: around 2.5 times lower operating cost per tenant, 100% coverage as a line item on your proposals, and growth absorbed without a hiring plan — while your analysts move up the value chain instead of out the door.
Conclusion
The MSSP industry's core problem was never demand. It was that the product is made of analyst hours, and analyst hours stopped scaling years before customers stopped asking for more. AI responders change the input: investigation becomes compute, coverage becomes complete, and the margin curve bends back in the provider's favour — but only for providers who get the trust architecture right, because multi-tenancy raises the stakes on every governance question. Run your own numbers at countershadow.com/roi with a representative tenant's alert volume, and put the six questions in section 4 to every vendor who claims to solve this. Including us.
References
- ISC2, Cybersecurity Workforce Study, 2024–25: 4.8M global workforce gap.
- CounterShadow ROI model (countershadow.com/roi) and platform documentation: worked coverage scenario (1,500 alerts/day, ~92 analysts / ~$8.8M for full manual coverage); ~$31 per manual investigation; ~8 min vs ~20 min investigation; ~2.5× lower operating cost; integration and action counts; multi-tenant deployment models with per-tenant action runners; alert-based pricing.
- Vectra AI, State of Threat Detection, 2023: ~67% of daily alerts never investigated.
- Mandiant / Google Cloud, M-Trends 2026 and July 2026 incident reporting: 22-second median access hand-off; ~72-hour full compromise cycles.
© 2026 CounterShadow. This paper may be shared freely in unmodified form. Modelled figures reflect the stated scenario; individual results depend on environment and configuration.