By Florie Lhuillier, Head of Cybersecurity, Hoffman Agency
Over the past year, the cybersecurity industry has had to continually adapt to geopolitical tensions, economic uncertainty, and also – and most importantly – to AI adoption and advancements.
With frontier AI models such as GPT‑5.5 and Claude Mythos supercharging vulnerability discovery, every organisation is now under pressure to apply patches quickly and prepare for breaches that patching cannot prevent.
Naturally, this is profoundly altering their requirements and having a knock-on effect on how they address their cybersecurity investments. However, these effects are not as you might think.
The current state of UK cybersecurity investments
According to our research, the market for cybersecurity products and services remains buoyant. 69% of UK organisations have plans to increase cybersecurity investment in the next 12 months while 54% are either looking for a new provider, or to switch their current provider.
This is good news for managed services providers (MSPs) looking to grow their business. Even better, 30% of UK organisations are planning to buy from a Managed Services Provider in the next twelve months.
But what’s driving this demand?
59% of UK respondents said their main reason for investing in new cybersecurity solutions is “the need to respond to threats”. Phishing, ransomware, social engineering and malware top the list of threats UK organisations say they are most vulnerable to. AI-powered attacks are also on the radar, even if they sit just outside the top ten. The need to “secure AI systems” is also mentioned by 48% of UK respondents – higher than the need to reduce costs or cope with talent shortages.
What MSPs need to understand are the structural pressures UK organisations are facing. More than half (52%) cite internal skills gaps as a barrier to getting cybersecurity purchases over the line, while 53% cite budget constraints. For organisations that can’t hire their way out of the problem, the answer is to buy their way out of it. That is exactly what a managed services provider can offer: specialist capability, delivered externally, on a predictable cost basis.
It’s also worth noting that given more than half of UK organisations are looking to switch their current provider – loyalty to existing vendors is not protecting anyone’s renewal. In fact, 30% of those seeking change said that the capabilities of their current provider are not meeting their needs and 25% cited dissatisfaction with their current service/set up as a driver.
Selling cybersecurity has notoriously been difficult for MSPs. It requires specialist skills and expertise, the solutions can be complex, and the competitive landscape is crowded with vendors making the same promises. Yet the current market conditions have never been more favourable to MSPs than they have been in years and highlight a second opportunity too.
The bundled platform opportunity
This opportunity requires MSPs to think about their portfolio more strategically.
The top three cybersecurity solutions that UK organisations are planning to purchase in the next 12 months, outside of managed services, are AI security, application security, and security operations. If we look at the solutions they are planning to replace or upgrade, it includes network security, security analytics and endpoint security.
Most of these organisations will likely be managing each of these as a separate purchase which means that each one will have its own supplier relationship, procurement event, or set of integrations to manage. Integration is already a problem. The complexity of integrating with existing systems is citing by 43% of UK respondents as a barrier to getting purchases over the line, while 36% also cited the time required for the integration.
This is where a bundled security offering play comes in. MSPs who can combine all the cybersecurity solutions UK buyers are planning to purchase or replace into one single managed platform are solving a real problem – and building a compelling commercial proposition.
Given the average cybersecurity ticket price in the UK is £554,000, being able to offer a bundled managed service that combines what might otherwise be four or five separate purchases can compete on cost while delivering something that individual point solutions can’t: simplicity. When we look at the attributes that have the biggest impact on selection for UK buyers, ‘simple and easy to integrate’ and ‘value for money’ top the chart. Ease of integration is not just a nice-to-have, it is clearly a deal maker.
This opportunity is also a timely one. Organisations that have increased their cybersecurity budgets are in the best position to consolidate and look for a managed services provider platform as often the economics work better when spend is already growing. With 69% of UK organisations expecting to increase investment in the year ahead, there is a window for MSPs to position a bundled offering before procurement decisions are made and contracts get signed.
How to win the business
Understanding that the opportunities exist is one thing. Getting in front of UK buyers currently “in market” is another. The best way to be successful with their approach is for MSPs to understand what makes their target audiences tick and how they actually make decisions.
First, MSPs need to engage early and quickly. The research shows that the average cybersecurity buying cycle runs from “need identification” to “vendor selection” in just seven months, with many completing the process in under six. What is also worth noting is that 65% of UK buyers make contact with vendors before they reach the shortlisting stage – if a vendor is not in touch with a buyer before the shortlist is being drawn up, it’s already behind.
Second, MSPs need to gather evidence. The number one reason that makes UK buyers reject a supplier is a lack of proof they have delivered for businesses like theirs. Case studies, client wins, and being mentioned in industry analyst reports are not just nice content to have on the website, they can help with active selling throughout the buying process, including at the very top of the funnel. Slow responses to queries are the second biggest reason a vendor ends up being crossed off a shortlist. Being quick and being credible are the two best things MSPs can do to win more business.
Finally, MSPs need to make sure they are visible where UK buyers look. Industry analysts are heavily influential both in terms of building awareness and in shaping shortlists, more so in the UK than other markets. For 43% of UK organisations, industry analysts are the source that has the biggest influence on their awareness of a cybersecurity supplier. Similarly, industry analyst reports featuring the supplier is the content type that has the biggest influence on both buyers’ awareness (56%) and selection (51%) of a supplier. Systems integrators and management consultants also play a strong role in vendor identification. It’s therefore important that MSPs invest in these relationships.
The opportunity is real
It’s clear from our research that the cybersecurity managed services market in the UK is thriving. Buyers are ready to spend, are open to new providers, and want solutions that are simpler to manage and better value for money.
For MSPs, it means that there has never been a better time to build out and sell a security-focused platform offering to buyers who are already “in market”.
A third of UK cybersecurity buyers plan to buy from an MSP this year. This represents a significant number of conversations waiting to happen. The providers that are ready to have these conversations, and are armed with proof points and the right proposition, will be the ones to benefit.