Partnership · MSSP
Fighting Over the Wrong Customers: How Vigilia Is Winning the Market Most MSSPs Ignore

A growing cybersecurity paradox
From the outside looking in, you would assume anyone selling cybersecurity right now is having the time of their life. Barely a week goes by without another major headline: “OpenAI models escape containment and hack Hugging Face”, “Claude used to orchestrate a large-scale cyber espionage campaign”, “Jaguar Land Rover cyberattack shuts down production for five weeks”. The attention surrounding cybersecurity has never been higher.
And yet, something isn't quite adding up.
The industry has never attracted this much attention or investment, nor seen this many vendors and AI cybersecurity startups enter the market. Yet breaches continue to rise, while many of the businesses responsible for managing cybersecurity on behalf of other companies, Managed Security Service Providers (MSSPs), are quietly struggling. Part of the problem becomes clearer when you look at what most MSSPs are actually selling, and how difficult it has become to stand out from the competition.
The reality is that their offerings are remarkably similar. Many MSSPs sell and manage security products from the same major vendors, such as CrowdStrike, Fortinet, Cisco and Microsoft, perhaps with a few different solutions around the edges. Whether the customer is a 50-person business or a 5,000-person enterprise, the vendors and services being offered often remain largely the same from one MSSP to another.
That creates a fundamental problem: differentiation.
When MSSPs are selling the same products to the same market, competition increasingly comes down to price. Margins get squeezed, while the cost of delivering and managing those services remains high. Unlike a software vendor, an MSSP cannot simply add hundreds of customers without also adding the people and resources required to support them.
It makes for a model that can be difficult to scale, particularly at the smaller end of the market.
When the model breaks
Adarma is a good example of how challenging this landscape can become. In July 2025, one of the UK's most established independent cybersecurity providers entered administration, resulting in 173 job losses.
The immediate pressure came from losing significant customer contracts and other clients reducing their spending. With already tight margins, high operating costs and intense competition, those losses ultimately pushed the business beyond what it could sustain.
For other MSSPs, Adarma served as a warning. When too much revenue depends on a handful of large customers, losing even one can have serious consequences. It also raised a broader question for businesses relying on MSSPs: how financially resilient is the company responsible for your security, and what happens to that protection if the provider suddenly disappears?
Vigilia and the Italian market
One MSSP we've met that recognised these dynamics in its own market is Vigilia Cybersecurity.
Part of a Swiss-headquartered technology group with operations across Italy and Poland, Vigilia launched in 2025 with a focus on mid-market businesses. They quickly ran into a familiar problem: many of the cybersecurity solutions available were designed neither for SMBs nor for the MSSPs trying to serve them. They were often too expensive, too complex or required too many resources to manage effectively. Italy is a particularly interesting market in which to face that problem.
Italy ranks among the countries most affected by cyberattacks and first in Europe, yet half of Italian SMBs report being underprepared in the event of a cyber attack. At the same time, NIS2 is pushing cybersecurity requirements further down supply chains, making security increasingly important not only from a risk perspective, but also from a contractual and compliance standpoint. On paper, it should be an ideal market for MSSPs. Millions of businesses need better protection, while regulatory pressure is pushing them to invest. Yet a large part of that market remains underserved.
According to Vigilia, the reason so many smaller businesses remain underserved comes down to simple arithmetic.
The traditional MSSP model and many of the tools behind it were built with larger organisations in mind. When you try to apply the same model to smaller businesses, the economics quickly become difficult for several reasons:
- The work doesn't shrink with smaller customers: a 50-person company still needs to be onboarded, monitored and supported, just like a much larger organisation.
- The technology stack remains expensive: smaller customers still need endpoint protection, firewalls, monitoring, vulnerability management and other core security capabilities, each bringing its own licensing, deployment and management costs.
- The revenue opportunity is smaller: smaller businesses have smaller security budgets, while many of the MSSP's costs remain largely the same.
Eventually, the numbers stop working: below a certain customer size, the MSSP either accepts very thin margins, charges a price the customer cannot afford, or reduces the level of service.
With such a large underserved market in front of them, Vigilia decided to approach the problem differently, both in how they operated internally and in the technology they offered customers. Rather than trying to squeeze an enterprise security model into a market that couldn't afford it, they started building one around the SMB.
A different MSSP model: Vigilia's approach
In practice, this meant rethinking three key parts of the traditional MSSP model.
1. A leaner SOC team
Rather than the traditional L1/L2/L3 structure, where alerts move through different levels of analysts, Vigilia built a leaner team that keeps its specialists focused on incidents that actually require human expertise.
2. Automating the repetitive work
Instead of having analysts manually review every security alert, Vigilia uses Sekoia to analyse and classify them automatically, filter out the noise and escalate genuine threats. This makes 24/7 monitoring far more scalable without requiring a large team around the clock.
3. Rethinking their security stack and partnering with Chimera
This is where our partnership with Vigilia comes in. By implementing Chimera, an all-in-one cybersecurity platform built for SMBs, Vigilia can bring together capabilities such as firewall protection, vulnerability scanning, network monitoring, threat detection and more, within a single platform, rather than deploying and managing multiple separate products.
This allows Vigilia to offer broader protection at a price smaller businesses can afford, while keeping the service commercially viable. It opens the door to businesses that need cybersecurity but have historically struggled to afford it, as well as mid-sized companies looking for stronger protection without the cost and complexity of an enterprise security stack.
More importantly, it gives Vigilia a way to differentiate. While much of the MSSP market continues to compete around the same vendors and services, Vigilia is building its model around a segment that has traditionally been underserved, from how its SOC operates to the technology it deploys.
Looking beyond the enterprise
Vigilia's approach also highlights a broader challenge facing the cybersecurity industry: who its products and services have traditionally been built for.
There are many reasons why cyberattacks continue to rise despite record levels of investment and awareness. But one of them may simply be that the industry has spent decades building increasingly sophisticated and expensive solutions for companies with the deepest pockets, while struggling to build a model that works for everyone else.
SMEs represent around 90% of businesses worldwide and roughly 99% in Europe, yet many remain underserved when it comes to cybersecurity. The problem isn't that these businesses don't need protection. It's that the tools designed to protect businesses were never built with them in mind, and the traditional economics of delivering those tools haven't always worked.
For MSSPs willing to rethink that model, this isn't just a problem to solve. It represents an enormous market still waiting to be served. For decades, the cybersecurity industry has focused on building for the few. The bigger opportunity may lie in finally building for the many.
