Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Sunday, 7 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Over Half of MSPs Admit to Being Breached Multiple Times in Past Year

The role of the MSP is changing as customers turn to them for compliance support, as well as cybersecurity and IT support, according to the CyberSmart MSP Survey 2026

by Guru Writer
May 13, 2026
in Channel News, Editor's News, Featured
Over Half of MSPs Admit to Being Breached Multiple Times in Past Year
Share on FacebookShare on Twitter

Economic pressures are pushing cybersecurity down the priority list for many SMBs according to The CyberSmart MSP Survey 2026. Notably,  46% of MSP customers are more concerned about operational challenges such as rising costs and inflation than cybersecurity risks, despite increasing threats. Meanwhile, MSPs themselves identified AI-driven threats as their top security concern for the second consecutive year.

The 2026 research, conducted by OnePoll, features insights from 350 MSP leaders across the UK and Ireland, spanning a selection of industries and serving customers ranging from 1 to 250+ employees.

Worryingly, three quarters of MSPs admitted to suffering at least one breach in the last 12 months, with 54% reporting being breached two or more times and nearly a third (32%) of respondents admitting to experiencing three or more breaches. Although down on last year, this shows that repeat breaches are still concerningly commonplace and that MSPs remain a valuable target for cybercriminals.

MSPs ranked AI as the top threat facing their organisation for the second year in a row (49%). Notably, inflation and spiralling costs have jumped from 5th to 3rd place (38%) this year. Geopolitical instability may be a contributing factor to this, given its widespread impact on inflation, energy prices and overall economic uncertainty.

Additionally, supply chain risk has risen from 7th (15%) to 6th (19%) among MSPs’ top concerns. This shift likely reflects the growing focus introduced by the Cyber Security and Resilience Bill, which places greater scrutiny on MSPs’ role within the supply chain for the first time and is prompting many to reassess their position and responsibilities.

59% of MSPs feel that their customers are more at risk in the past 12 months than they previously were. This reflects recent data from the UK Government’s Cyber Security Breaches Survey 2025/6, which found that 46% of small and 65% of medium sized businesses in the UK had experienced at least one cyber breach or attack in the past year.

When it comes to threats facing customers, 46% of MSPs ranked inflation and spiralling costs as the top perceived threat. This ranked higher than ransomware or malware infections (41%), emerging AI threats (37%) and supply chain threats (25%). This suggests that for many organisations, day-to-day business pressures and financial stability are taking precedence over emerging or even established cyber threats, highlighting that business resilience is currently being shaped as much by economic conditions as by the cyber threat landscape.

However,  MSPs suggest that the vast majority (87%) of their customers have average or above levels of cyber knowledge.

Jamie Akhtar, CEO and Co-Founder of CyberSmart, said: “Cyber risk and economic pressure are now inseparable. MSPs can no longer sell cybersecurity in isolation when rising costs dominate customer priorities. The real challenge has moved beyond the tech stack into liability, compliance and accountability. For SMEs, the key is embedding security into day-to-day operations and working with trusted partners to maintain resilience without adding unnecessary complexity or cost.”

The share of MSPs reporting increased scrutiny fell from 77% in 2025 to 70% in 2026, suggesting customer expectations are becoming more standardised. Rather than intensifying year-on-year, security scrutiny now appears to be stabilising as a baseline part of procurement, compliance and vendor oversight.

Interestingly, customer expectations of MSPs are changing too, with 61% of customers now expecting support with compliance requirements. In response to this, MSP investment in compliance and regulations has risen from 64% to 72%. MSPs are fast becoming managed compliance services, as well as cybersecurity and IT infrastructure partners.

This is unsurprising given that regulations and certifications, like Cyber Essentials, are changing in favour of keeping companies accountable for a continuous commitment to security. Subsequently, SMEs will likely turn to MSPs to help them maintain compliance and security standards throughout the year. To better support customers, MSPs are prioritising investments in training (51%), continuous monitoring (46%) and proactive risk management (44%) over the next one to three years.

ShareTweet
Previous Post

Huntress and Acrisure Team Up to Offer Zero-Deductible Cyber Insurance for SMBs

Next Post

Q&A: Why Vulnerability Scans Are Giving Businesses a False Sense of Security

Recent News

Frontline Workers Twice as Likely to Use Unapproved AI

Frontline Workers Twice as Likely to Use Unapproved AI

June 4, 2026
Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
data-cloud-security

Building a Digital Fortress: Why Cyber Security Matters More Than Ever

June 5, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol