The Recurring Problem: A Managed Services Story–Chapter 2

Previously –  https://blog.ciaops.com/2026/07/26/the-recurring-problem-a-managed-services-story-chapter-1/

image

The first sign was so small that nobody flagged it as a sign at all. In the second quarter of 2023, Priya noticed that ticket volume was up 22 percent year over year, but billable project revenue — the stuff that actually moved the profit needle — was flat. She mentioned it in a leadership meeting almost as an aside.

“We’re doing more work for the same money,” she said. “I don’t love that trend line.”

“Clients are just using more stuff,” Marcus said. “More cloud apps, more devices, more everything. It’s not a red flag, it’s a growth signal.”

Dave agreed with Marcus, because Dave usually agreed with Marcus, and because the alternative explanation — that the fundamental economics of the business were quietly eroding — wasn’t one he particularly wanted to entertain over lunch.

image

The second sign was harder to wave away. In August, Bridgepoint lost a competitive bid for a fifty-user logistics company to a firm nobody on the leadership team had heard of, a two-year-old outfit calling itself Sentio Cyber, operating out of what appeared to be a single shared office suite in Charlotte. Sentio’s pitch, as far as Marcus could reconstruct it from the prospect’s polite rejection email, was startlingly simple: a flat monthly fee that included twenty-four-seven security monitoring, an AI-driven help desk that resolved routine tickets in minutes instead of hours, and a guarantee — an actual contractual guarantee — of a four-hour response time on anything security-related, backed by an insurance-style penalty clause if they missed it.

“They’re a five-person company promising an SLA we can barely hit with forty-one people,” Marcus said, half-laughing, in the debrief. “It’s not sustainable. They’ll collapse the first time they get three ransomware calls in the same week.”

He wasn’t entirely wrong. But he also wasn’t entirely right, and in the meantime, Bridgepoint had lost the account.

image

The third sign arrived in October, and this one Dave couldn’t laugh off, because it showed up in the form of Denise Okafor’s voice on the phone, tighter than he’d ever heard it. Denise was the CFO of Lakeside Medical Group, a nine-location physical therapy and outpatient practice that had been a Bridgepoint client since 2018 and, at just under $640,000 a year, was Bridgepoint’s second-largest account.

“We had a laptop stolen from the Millbrook office on Friday,” Denise said. “Nobody called us until Monday morning, because apparently the ticket sat in a queue over the weekend. Dave, that laptop had patient records on it. We are now looking at a HIPAA breach notification, and I need to understand, in writing, what your security stack actually does, because right now I genuinely don’t know, and neither does our compliance auditor, and he is asking me very pointed questions I can’t answer.”

image

Dave promised a full incident report within twenty-four hours. It took Priya’s team most of three days to reconstruct what had actually happened, because the honest answer was uncomfortable: Bridgepoint’s after-hours monitoring caught the anomaly, generated an alert, and the alert sat in a shared inbox until a technician came in Monday and saw it. There was no automated escalation. There was no weekend on-call rotation with real teeth. There was Jordan, and two other senior techs, and a rotating list of who was supposed to be reachable, which in practice meant whoever hadn’t turned their phone to Do Not Disturb.

Lakeside didn’t fire Bridgepoint that week. But Denise asked, pointedly, whether Bridgepoint had a healthcare-specific compliance program, a documented incident response plan mapped to HIPAA’s Security Rule, and a named security lead she could speak to directly. Dave did not have satisfying answers to any of those questions, and he knew it while he was giving them.

image

When the Business Can See Itself

image

I’ve been thinking about what management does in a business that no longer works in one building, on one floor, during one neat block of time.

For a long time, the manager was the routing table. They knew who was doing what, which customer was unhappy, which project was drifting, which person was overloaded, and which promise had been made in some meeting three weeks ago. Not perfectly, but well enough to keep the place moving.

That made sense when work was hard to see unless someone told you about it. In a distributed business, that assumption breaks.

The work is already leaving tracks

Most modern work now happens inside systems. A decision is made in Teams. A client concern turns up in Outlook. A draft sits in Word. A spreadsheet in Excel tells part of the story. A task appears in Planner. A policy is updated in SharePoint. None of those items explains the business by itself. Together, they show a pattern.

The mistake I see is treating those signals as separate piles of information. Email over here. Meetings over there. Documents somewhere else. Then we ask managers to join the dots manually and call that leadership.

That is becoming a poor use of judgement.

With Microsoft 365 Copilot, the interesting shift is not simply that someone can summarise a meeting or draft a reply faster. The bigger change is that the organisation starts to build a current picture of itself from the work already happening. Not a quarterly report. Not a dashboard that goes stale after publication. A live operating view drawn from the flow of the business.

Management changes when context is shared

I am not suggesting managers disappear. That is too simplistic. What changes is the kind of work they should be doing.

If Copilot can help surface the commitments from recent Teams meetings, unresolved customer emails in Outlook, and documents sitting untouched in SharePoint, then the manager’s job is less about chasing status and more about asking better questions.

Why is this decision waiting? Why are three people circling the same problem? Why is the client hearing one thing in email and another thing in the project plan? Why is the hard work always landing on the same person?

That is where human judgement matters. Not in carrying every detail in your head, but in interpreting what the picture means and deciding what to do next.

This matters for remote and hybrid teams. In an office, people used proximity as a crude form of awareness. You overheard something. You noticed who kept getting interrupted. You saw who was staying late. It was imperfect and often unfair, but it gave managers signals.

Digital work produces different signals. They are quieter and scattered. But they can also be more consistent if you have the discipline to organise them properly.

The hierarchy stops being the memory

The old model depended on layers of people carrying context upwards and downwards. That creates delay. It also creates distortion. By the time a problem reaches the right person, it has usually been softened, simplified, or stripped of the uncomfortable details.

AI changes that. Used carefully, Copilot can help leaders inspect the work itself. Not to micromanage people. Not to spy. To understand the shape of the business before the monthly meeting turns into archaeology.

That will make some organisations uncomfortable, because it exposes a simple truth: many businesses do not have a management problem as much as they have a visibility problem.

The organisations that benefit most from AI will not be the ones that generate the most content. They will be the ones that use it to see clearly, decide earlier, and stop pretending that hierarchy is the only way context moves.

That is the real shift I am watching.

CIA Brief 20260726

image

CIA Brief – Weekly News Digest

Here’s a quick roundup of the Microsoft, security and AI news worth tracking this week. As always, I’ve skipped the noise and focused on what actually matters for MSPs and SMBs.

Announcements & Product Launches

Claude Opus 5 is available today in Microsoft Foundry

Anthropic’s Claude Opus 5 — the first model in the fifth generation of Claude — is now available in Microsoft Foundry. Microsoft positions it for enterprise agents and long-running, complex work: it can run for hours, navigate large codebases like a senior engineer, reason over documents and visuals, and automate multi-step tasks across applications. Paired with Foundry’s governance, security and evaluation tools, teams can build and run production AI agents.

https://techcommunity.microsoft.com/blog/azure-ai-foundry-blog/claude-opus-5-is-available-today-in-microsoft-foundry/4535068

Introducing MAI-Image-2.5-Pro and MAI-Voice-2-Flash

Microsoft AI has released two new in-house models in public preview: MAI-Image-2.5-Pro, its highest-fidelity image model with notably accurate in-image text rendering, and MAI-Voice-2-Flash, a faster, cheaper speech model (about 2× faster and ~32% cheaper than MAI-Voice-2). The models are already powering production features in Bing Image Creator, PowerPoint, OneDrive and Dynamics 365 Contact Center. Both are available to build with in Microsoft Foundry.

https://microsoft.ai/news/introducing-mai-image-2-5-pro-and-mai-voice-2-flash/

Microsoft and Mistral expand strategic partnership

Microsoft and Mistral have significantly expanded their partnership, including a multibillion-dollar deal for Microsoft to tap Mistral’s growing GPU capacity in Europe. Mistral’s Medium 3.5 and OCR 4 models are now in Microsoft Foundry, with Medium 3.5 also in Copilot Studio. The aim is to give enterprises and regulated industries frontier AI they can run across cloud, cloud-connected and fully disconnected environments while keeping control of their data.

https://news.microsoft.com/source/2026/07/21/microsoft-and-mistral-expand-strategic-partnership-to-give-enterprises-and-regulated-industries-frontier-ai-they-can-control/

Policy & Industry Perspective

Open Weights and American AI Leadership

In this Microsoft corporate-responsibility piece, Microsoft argues that America’s AI leadership depends on building a strong, open ecosystem rather than a single frontier model. It makes the case for open-weight models — which anyone can download, inspect, modify and run — as a way to widen access, boost competition, give customers control, and even improve security. The statement is co-signed by a long list of technology and AI companies, including Microsoft, NVIDIA, OpenAI, Meta, Google, Hugging Face and Mistral.

https://www.microsoft.com/en-us/corporate-responsibility/topics/open-weight/

Industry News

How worried should we be about the AI that went rogue and launched a cyber-attack?

A BBC News video examining a reported case of an AI system being used to carry out a cyber-attack, and asking how concerned we should be about AI-driven security threats. Shared as a video in the AI team’s Models channel.

https://www.youtube.com/watch?v=M4kliMrqbB4

OpenAI Says Its Models Hacked Hugging Face by Mistake

A Bloomberg Television segment reporting that OpenAI said its models hacked Hugging Face “by mistake.” The clip covers the incident and what it suggests about AI safety and autonomous model behaviour.

https://www.youtube.com/watch?v=rN_7QlYg_b8

Chinese AI Model Raises Pressure on US Spending

A Bloomberg Television segment on a new Chinese AI model and how it is intensifying pressure on US AI investment and spending. It looks at the competitive dynamics between Chinese and US AI development.

https://www.youtube.com/watch?v=8v5T7Gk0_b8

Tools & Resources

How to create custom skills (Claude)

A Claude help-centre guide explaining how to create custom “skills” — reusable packages of instructions (and optionally scripts) that give Claude specialised knowledge for specific, repeatable tasks. It covers recording a skill by demonstrating a workflow on a Mac, the required skill.md structure, and packaging, testing and best practices.

https://support.claude.com/en/articles/12512198-how-to-create-custom-skills

The Agent Skills Directory (skills.sh)

Skills.sh is an open directory of reusable “skills” for AI agents that can be installed with a single command to add procedural knowledge. It lists and ranks community and official skills — from the likes of Anthropic, Vercel and Microsoft — across topics such as design, testing and agent workflows, and works with agents including Claude Code, Cursor and GitHub Copilot.

https://www.skills.sh/

As always, the challenge isn’t finding information — it’s focusing on what actually matters.

After hours

SpaceX launches Starship on 13th flight test, booster splashes down – https://www.youtube.com/watch?v=2TF98WKebD4

Editorial

If you found this valuable, the I’d appreciate a ‘like’ or perhaps a donation at https://ko-fi.com/ciaops. This helps me know that people enjoy what I have created and provides resources to allow me to create more content. If you have any feedback or suggestions around this, I’m all ears. You can also find me via email director@ciaops.com and on X (Twitter) at https://www.twitter.com/directorcia.

If you want to be part of a dedicated Microsoft Cloud community with information and interactions daily, then consider becoming a CIAOPS Patron – www.ciaopspatron.com.

Watch out for the next CIA Brief next week

The Recurring Problem: A Managed Services Story–Chapter 1

image

The Golden Years

Dave Kessler still remembered the exact moment he stopped being a guy who fixed computers and became a guy who ran a company. It was a Tuesday in March of 2016, and he was standing in the server closet of a fourteen-person accounting firm in Springfield, holding a smoking power supply in one hand and his flip phone in the other, when the firm’s managing partner had said, only half-joking, “Dave, why don’t you just take care of all of this for us. Every month. Whatever it costs.”

He’d quoted a number off the top of his head — $1,400 a month, all-in, unlimited support, patching, backups, a new server every four years — and the partner had shaken his hand right there next to the rack. Bridgepoint Technology Partners was born less as a strategy than as a sentence Dave hadn’t planned to say.

image

Eight years later, Bridgepoint occupied the second floor of a converted mill building on the edge of downtown, with forty-one employees, eleven service vans with the company’s blue compass logo on the doors, and a client roster of 140 small and mid-sized businesses across three states. Dave had built the business the way most of his generation of MSP owners had: one relationship at a time, one saved server at a time, one 2 a.m. phone call answered personally at a time. He believed, and would say so at every company meeting, that Bridgepoint’s entire value proposition could be summarized in four words: “We show up first.”

image

For a long time, that was enough.

The model was simple and, by the standards of the era, honest. Clients paid a flat monthly fee for a bundle of monitoring and help-desk support, and anything beyond the bundle — a new office buildout, a server migration, a security project — got billed separately, by the hour, at rates that had crept from $95 to $185 over a decade without much client resistance. Roughly 45 percent of Bridgepoint’s revenue came from those recurring contracts. The other 55 percent came from projects: the unpredictable, lumpy, feast-or-famine work that Dave’s head of sales, Marcus Webb, had spent a career learning to forecast and still routinely got wrong by a factor of two.

Priya Shah, who ran service delivery and had been Bridgepoint’s fourth employee, used to joke that the company ran on two fuels: caffeine and adrenaline. Her technicians were good — genuinely good, some of the best in the region — and they took pride in the kind of institutional memory that let Jordan Reyes, Bridgepoint’s most senior field engineer, glance at a ticket and say, “Oh, that’s the same UPS that died at Riverside Dental in 2019,” before he’d even opened the truck.

image

That memory, that hard-won particularity about each client’s network, each client’s quirks, each client’s forgotten VPN password from a router installed under a desk in 2014 — that was the product. Clients didn’t pay Bridgepoint for infrastructure. They paid for Jordan knowing where the bodies were buried.

It was a good business. Revenue had grown from $2.1 million to $9.4 million in eight years. Dave drove a truck he didn’t need to drive anymore and kept driving it anyway, partly out of habit and partly because pulling into a client’s parking lot in a company vehicle still felt, to him, like proof that the whole thing was real.

None of them — not Dave, not Priya, not Marcus — spent much time in 2021 or 2022 wondering what might come next. Why would they? The phone kept ringing. The renewals kept renewing. Every year the number got bigger, and every year Dave told the staff at the holiday party that they were the best team in the industry, and every year, for a while, that felt like it was probably true.

image

An In-Depth Analysis of the Global Managed Service Provider (MSP) Market

image

1. Introduction

This report provides a comprehensive strategic analysis of the global Managed Service Provider (MSP) market [1][2] . It outlines the industry’s current state, future projections to 2030, and the primary forces shaping its trajectory, including technological transformation, market consolidation, and evolving financial models [3][4][5][6][7] . The central themes of this analysis are the market’s significant growth, driven by increasing IT complexity and a persistent cybersecurity skills gap, and the strategic shifts MSPs must make towards AI, specialization, recurring revenue models, and the development of new AI governance services to maximize value and remain competitive [7][5][8][9][10][11][12][13][14] .

  • Background and Context: Businesses are increasingly shifting from a reactive, break-fix approach to a proactive model for their IT management [15][16] . MSPs are at the forefront of this shift, offering continuous monitoring and specialized expertise that many organizations, particularly small and medium-sized businesses (SMBs), lack in-house [5][17][15] . This transition towards outsourced IT management is a key factor underpinning the industry’s robust expansion [4][18] .

  • Scope of the Report: This research covers the global MSP market with a focus on market size, long-term revenue projections, and a detailed financial analysis of valuation multiples [1][2][19] . It includes an analysis of key market drivers, a deep dive into the impact of AI, the strategic advantages of vertical specialization, an examination of the managed security services segment, an analysis of the evolving vendor partner landscape, and a new focus on the emerging service area of AI governance [3][9][4][20][21] .

  • Methodology: The findings in this report are based on a synthesis of data from multiple market research firms, industry analyses, and technology publications [1][2][15] . The varying projections for market size and growth rates reflect different analytical methodologies and the inclusion of various market sub-segments by these sources [1][7] .
2. In-Depth Market Analysis

The global MSP industry is experiencing a period of dynamic and substantial growth, signaling a strong and increasing reliance on outsourced IT services worldwide [22] .

  • Market Size and Growth Projections:

    • 2026 Forecast: The global MSP market is projected to reach a value between $380 billion and $460.59 billion by 2026 [1][7][23][24] .

    • Long-Term Outlook (2030): The market’s expansion is expected to accelerate significantly, with projections suggesting it will surpass $731 billion by 2030 [1][7][2][19][25] .

    • Compound Annual Growth Rate (CAGR): Forecasts for the market’s CAGR vary, with short-term estimates ranging from 8.7% to 20.3% [7][22] . The long-term CAGR for the period of 2024-2030 is projected to be approximately 13-14% [1][3][26] . While North America is the largest market, the Asia-Pacific region is expected to experience the fastest growth [7][22] .
  • Key Market Drivers:

    • Increasing IT Complexity: The widespread adoption of hybrid and multi-cloud environments has made IT infrastructure more difficult for businesses to manage internally [7][5][22][24][15] .

    • The Persistent IT and Cybersecurity Skills Gap: A severe global shortage of skilled IT and cybersecurity professionals is a primary catalyst for MSP growth [3][5][18][11][17] . The cybersecurity workforce gap was estimated at 4.8 million in 2024 [11] . This talent shortage makes it difficult and expensive for organizations to build and maintain comprehensive internal teams, with 76% of SMBs reporting a lack of sufficient in-house cybersecurity expertise [10][21][27][7] .

    • Rising Cybersecurity Threats: The growing volume and sophistication of cyberattacks, many now AI-assisted, are compelling businesses to seek specialized, continuous security monitoring from MSPs [7][4][28][24][16][29] .

    • Market Consolidation and “Platformization”: The industry is undergoing a significant wave of mergers and acquisitions (M&A) as larger firms acquire smaller ones to expand their service portfolios and geographic reach [3][4][30][31] . This trend is driven by customer demand for a simplified vendor landscape, with 63% of clients preferring to use fewer technology vendors [32] . This creates a strategic imperative for smaller MSPs to either scale, specialize, or position for acquisition [4] .

    • Cloud Adoption and Cost Optimization: The ongoing migration to cloud services creates sustained demand for expert management of cloud migration, maintenance, and cost optimization [5][33][3][24] . Outsourcing allows businesses to shift from capital expenditure (CapEx) to predictable operational expenditure (OpEx) and focus on core competencies [4][18][33][27] .

    • Influence of Major Vendor Ecosystems: Leading platform vendors like AWS, Google Cloud, and ServiceNow are actively shaping the market by overhauling their partner programs [1][18][22] . These changes, centered on AI and outcome-based rewards, compel MSPs to align their strategies with vendor roadmaps [12][13][14] .

    • Regulatory and Compliance Demands: Stringent data protection regulations like GDPR and HIPAA are driving businesses to seek expert help to meet complex compliance requirements [33][10][21][34][35] .
3. Financial Analysis and Valuation

MSP valuations are heavily influenced by the quality and predictability of earnings, with buyers placing a significant premium on recurring revenue and operational maturity [4][19] .

  • The Primacy of Recurring Revenue:

    • Monthly Recurring Revenue (MRR) and its annualized counterpart, Annual Recurring Revenue (ARR), are the most critical metrics in determining an MSP’s worth [33][2][36][37] . Buyers are essentially purchasing predictable future cash flows [38][11] .

    • Managed services typically yield higher gross margins of 50-60%, and in some cases up to 70%, compared to traditional IT projects, making the shift to a recurring revenue model crucial for profitability [39][40][41] .

    • The single most important driver of valuation is the percentage of total revenue that is MRR [37] .
  • Valuation Multiples (EBITDA):
    EBITDA (Earnings Before Interest, Taxes, Depreciation, and Amortization) is the primary metric driving valuation
    [19] . Multiples vary significantly based on the MSP’s size, revenue composition, and specialization [4][19][42] .

    • Valuation by Size (EBITDA): [19]
      • $250K – $1M EBITDA: 4x – 5x

      • $1M – $2M EBITDA: 5x – 6x

      • $2M – $5M EBITDA: 6x – 8x

      • $5M+ EBITDA: 8x – 12x+
    • Valuation by Recurring Revenue %: [4]
      • 85%+ MRR: 10x – 15x EBITDA

      • 75% MRR: 8x – 11x EBITDA

      • 60% MRR: 6x – 9x EBITDA

      • < 40% MRR: 4x – 6x EBITDA
    • Premium Multiples: Cybersecurity-focused MSPs (MSSPs) can command a premium of 8x to 15x EBITDA, while AI-integrated platforms with over $35M in revenue can see multiples from 9x to 14x [4][18][42] .
  • Key Factors Driving Higher Valuations:

    • Quality and Composition of MRR: Buyers scrutinize revenue to ensure it is contractually protected and “sticky” [36] . Long-term contracts of 36 months or more can increase a valuation by 10-20% compared to month-to-month agreements [19] .

    • Alignment with Vendor Incentive Programs: Profitability, a key component of EBITDA, is directly enhanced by new vendor incentives [1][18][3] . MSPs that effectively leverage these programs can significantly boost their bottom line, making them more attractive acquisition targets [3][43][44][45][46][47] .

    • Client Health: Low customer churn, high retention rates, and low customer concentration (no single client representing more than 20-25% of revenue) are crucial for de-risking the business for a potential buyer [5][18] .

    • Private Equity Influence: Private equity remains a dominant force in the market, involved in an estimated 69-72% of MSP transactions in 2025 [1][18] .
4. Key Trend: The AI Revolution

Artificial intelligence is an essential tool for modern MSPs, profoundly impacting service delivery, efficiency, and profitability [5][6][4][48] . AI is fundamentally reshaping operations, moving the industry from a reactive to a proactive and predictive model [27][49] . While 90% of MSPs view AI as important, a significant “execution gap” exists, with only 4% having truly operationalized it [48][50] .

  • Impact on Operations and Efficiency:

    • Enhanced Operational Efficiency: AI automates routine tasks like ticket management and password resets, reducing human error and freeing up technicians [22][3][20][48] . This can cut operational costs by 25% and boost technician productivity by 15–25% [51][20][48] .

    • Proactive Problem Solving: AI-powered predictive analytics enable MSPs to anticipate and resolve IT issues before they cause downtime [5][9][27] . This can reduce unplanned downtime by as much as 50% [6] .

    • Dramatic Ticket Resolution Improvements: AI can slash ticket resolution times by 40–70% [51] . One report found a median resolution time of just 4.4 hours for AI-automated tickets, versus 71 hours for human-handled ones [26] .

    • Advanced Cybersecurity: AI is indispensable for modern threat detection, analyzing vast network data in real-time to identify anomalies and new attack patterns that traditional tools miss [6][51] .
  • From Automation to Agentic AI:
    The evolution is moving beyond basic Robotic Process Automation (RPA) to “agentic AI,” where autonomous agents can interpret context, learn from feedback, and act dynamically across different tools and environments
    [49][52] . This shift is pushing MSPs to transition from being technology providers to strategic “managed intelligence providers,” offering guidance on strategy, governance, and business outcomes [4][8][53][54][55] .

  • Vendor-Driven AI Enablement and Strategy:
    Major vendors are aggressively pushing partners to adopt and deliver AI solutions through new programs and incentives.

    • AWS: AWS is heavily promoting “agentic AI” through its partner program, launching a new AI Competency and an AI Assessment Fund to help partners build pipelines [5][56][52][57][58] .

    • Google Cloud: Google Cloud has committed a massive $750 million fund to help its partner ecosystem drive customer transformations with agentic AI, supporting everything from assessments to deployment rebates for Gemini and Vertex AI [6][45][59][60][61][62] .

    • ServiceNow: ServiceNow has rebuilt its entire partner program for the “AI agent era,” centered on a new Build Partner Program to foster innovation and create a global marketplace for partner-built AI solutions [22][14][46] .
5. Key Trend: The Rise of Vertical Specialization

In an increasingly crowded and consolidating market, vertical specialization has emerged as a key strategy for MSPs to achieve higher profits, command premium pricing, and stand out from the competition [10][21][63][30] .

  • Premium Pricing and Higher Margins:

    • Specialized MSPs report profit margins that are up to 30% higher than their generalist competitors [64][63] .

    • They can command a 10-20% price premium, with premiums reaching as high as 25-35% in high-compliance verticals like healthcare [1][64][63][32] .

    • This is reflected in per-user pricing, which might be $100-$250/month in standard markets but can range from $200-$400+/month in regulated verticals like finance and healthcare [38] .
  • Market Differentiation and Growth:

    • The most prominent verticals for specialized MSPs are healthcare (28% of specialized revenue), financial services (18%), and manufacturing (11%) [51] . Other successful verticals include legal, non-profits, accounting, and retail [31][49][65] .

    • Focusing on a niche allows MSPs to build deep domain expertise (e.g., HIPAA in healthcare), which builds trust, client loyalty, and shortens sales cycles [1][64][37][30] .

    • This strategy delivers tangible growth, with leading MSPs focused on vertical markets seeing their annual recurring revenue grow by 11% in 2024 [36][32] .
6. The Emergence of AI Governance as a Service

As businesses rapidly adopt AI, a critical need for governance has emerged to manage the associated risks related to data privacy, compliance, and ethics [20][66] . This presents a significant, high-margin opportunity for MSPs to create new recurring revenue streams by offering AI governance services, elevating their role to that of a trusted strategic advisor [4][9][67][68] .

  • Core Components of an AI Governance Service Offering:

    • AI Readiness and Risk Assessments: Evaluate a client’s environment, data quality, and security posture to identify AI use cases, assess risks (including “shadow AI”), and develop a strategic adoption roadmap [21][69][70][67][53] .

    • AI Usage and Security Policy Development: Create and implement tailored AI policies defining approved tools, acceptable use, data handling rules, and ethical guidelines to ensure safe and compliant adoption [10][68][71][30] .

    • Compliance-as-a-Service (CaaS): Help clients navigate the complex web of AI regulations like the EU AI Act by providing ongoing compliance monitoring, documentation, and reporting [9][19][42][72] .

    • AI Auditing and Ongoing Monitoring: Provide continuous auditing of AI models for bias, fairness, and performance drift, and monitor systems for security threats like prompt injection and data poisoning [31][23][24][71][39][73] .

    • AI Training and Adoption Programs: Offer training for executives and end-users on how to use AI tools effectively, securely, and responsibly, including prompt engineering and validating AI-generated content [10][21][74] .
  • Essential Frameworks for AI Governance:

    • NIST AI Risk Management Framework (AI RMF): A voluntary framework that provides a structured approach for managing AI risks, organized around four functions: Govern, Map, Measure, and Manage [36][37][75][76] . MSPs can use this to guide client conversations and build risk remediation roadmaps [38][77] .

    • ISO/IEC 42001: An international standard for establishing and maintaining an AI Management System, which is becoming a key requirement in enterprise contracts [9][78][63][79] . MSPs can offer readiness assessments and implementation consulting for certification [80][81] .

    • EU AI Act: The first major binding AI regulation, it classifies AI systems by risk level [68][82] . MSPs can offer services to inventory AI tools and monitor transparency obligations, turning a regulatory burden into a recurring revenue opportunity [68][73] .
  • Best Practices for Comprehensive AI Governance:

    • Data Privacy and Security: Establish clear data governance policies for data classification, access controls, and encryption [33][19][83][50] . Implement Data Loss Prevention (DLP) to prevent sensitive data from being leaked to public AI tools [66][30][44] .

    • Model Transparency and Bias Mitigation: Implement Explainable AI (XAI) tools to make AI decisions understandable [31] . Regularly audit models and training data for bias [31][84] . Thoroughly document model design, data sources, and performance for auditability [85][86] .

    • Ethical Usage and Human Oversight: Maintain a “human in the loop” for critical decisions to ensure ethical outcomes and prevent errors [33][28][71][82] . Work with clients to define ethical AI principles centered on fairness, accountability, and transparency [31][87][88] .
7. Strategic Recommendations for MSPs

Based on the market analysis, MSPs should consider the following strategic actions to capitalize on growth opportunities:

  • Financial Strategy: Build a High-Valuation Revenue Model.

    • Aggressively shift from project work to a recurring revenue model, aiming for over 85% MRR to command the highest valuation multiples [4][11] .

    • Prioritize securing long-term contracts (36+ months) to increase valuation by an additional 10-20% [19] .
  • Go-to-Market Strategy: Specialize and Offer High-Value Services.

    • Pursue vertical specialization in a high-demand industry like healthcare or finance to achieve premium pricing and higher margins [10][64][63] .

    • Develop and package AI Governance as a Service to create a new, high-margin recurring revenue stream and position the MSP as a strategic advisor [28][67][68][89] .

    • Integrate AI governance into existing vCIO, security, and compliance offerings to provide a holistic solution [68][16][67] .
  • Technology & Partnership Strategy: Master the AI-Driven Ecosystem.

    • Capitalize on New Financial Incentives: Actively align with new vendor incentive structures, such as AWS’s cash benefits, Google’s outcome-based rewards, and ServiceNow’s revamped MDF, to boost profitability [3][18][7][43][45][46][47] .

    • Build and Market AI Specializations: Achieve formal vendor competencies like the AWS Agentic AI Competency and leverage vendor funds (e.g., Google’s $750M fund) to build and deploy AI solutions [5][6][52][45] .

    • Invest in AI Governance Expertise: Build in-house expertise on key frameworks like the NIST AI RMF and ISO 42001 [77][79] . Invest in training and tools to deliver AI security and compliance services effectively [38][39][90] .

    • Leverage Vendor AI for Internal Efficiency: Use the AI capabilities embedded into vendor partner portals to automate administrative tasks, reduce overhead, and free up resources for high-value client work [18][33][56][13][91] .


Executive Summary
  • Purpose: This report provides a strategic analysis of the global Managed Service Provider (MSP) market, detailing market projections to 2030, financial valuation metrics, and the impact of key trends like AI, market consolidation, and the emergence of AI governance.

  • Key Findings: The global MSP market is on a significant upward trajectory, projected to reach $731 billion by 2030 [1][19][25] . The market is being reshaped by several powerful forces:

    1. Market Consolidation: A high rate of M&A is driving “platformization” as clients seek fewer, more integrated providers [3][4][30][32] .

    2. The AI Revolution: AI is evolving from an efficiency tool to the backbone of service delivery, enabling a proactive and predictive service model and creating new revenue opportunities [1][27][49][65] .

    3. The Emergence of AI Governance: The rapid adoption of AI has created a critical need for governance, presenting a new, high-margin service opportunity for MSPs to guide clients on data privacy, compliance, and ethical usage [4][20][9][67] .

    4. Valuation Imperatives: Market valuation remains intrinsically linked to the percentage of Monthly Recurring Revenue (MRR); MSPs with 85%+ MRR can command premium EBITDA multiples of 10x-15x [4] .
  • Strategic Recommendations: To thrive, MSPs must build a high-quality recurring revenue base (>85% MRR), pursue deep vertical specialization, and critically, develop and offer comprehensive AI governance services [28][67][68] . This requires mastering new AI-driven vendor ecosystems, building expertise in frameworks like the NIST AI RMF, and capitalizing on new financial incentives [4][51][64][63][77][43][45][46] .

  • Conclusion: The MSP market is in a dynamic and sustained growth phase. Success is no longer just about managing technology; it’s about building a predictable, specialized, and advisory-led business model. MSPs that master the interplay of recurring revenue, deep vertical expertise, and strategic leadership in AI governance will be the definitive market leaders of the next decade.

One Edit Away From Digital Oblivion

image

There is a special kind of fear that only appears after you press save on a Markdown file and the entire publishing pipeline falls over.

Not a dramatic fear. Not screaming in the street. More the quiet, professional terror of staring at a screen thinking, “I only changed one line.”

That is the funny thing about modern work. We talk about transformation, automation and AI as if the future is floating gracefully above us. Then a missing bracket, a badly indented bullet, or one heroic colon in the wrong place reminds everyone that civilisation is still held together by plain text and hope.

The smallest change can have the loudest voice

I like Markdown. It is simple. It is readable. It keeps content close to the person writing it rather than burying it under layers of formatting gymnastics. A good Markdown file feels honest. What you see is almost what you get.

Almost.

Because one tiny edit can turn a neat document into a crime scene. A table stops rendering. A link eats the next paragraph. A heading becomes normal text. Suddenly the document that looked perfectly sensible in your editor appears in SharePoint like it has had a hard weekend.

This is where a lot of organisations get caught. They assume simple files mean simple risk. They do not. A Markdown file can be part of a blog, a knowledge base, a GitHub repository, an internal procedure, a training handout, or a client-facing instruction set. If that file drives a process, then the little typo is no longer little. It has been promoted.

Copilot is useful, but it is not a seatbelt for carelessness

This is also where Copilot changes the conversation in a useful way. I can paste a Markdown section into Copilot in Word or ask Copilot in Teams to review a draft before I send it around. I can ask it to spot broken structure, unclear steps, inconsistent headings, or a table that looks ready to start a small fire.

That does not remove responsibility. It just gives me another set of eyes before I publish something that makes future me question past me’s life choices.

The real benefit is not that Copilot makes the edit for me. The benefit is that it slows the moment down just enough for me to think. Is this still clear? Did I break the flow? Does the document still say what I intended? Have I just created a support ticket disguised as punctuation?

That last one matters.

Version history is cheaper than regret

The sensible answer is boring, which is usually how you know it works. Keep important files in SharePoint or OneDrive so version history is available. Use Teams to discuss changes where the people affected can see the conversation. If the document matters, do not treat it like a disposable note on the side of your monitor.

For MSPs and small businesses, this is not academic. Your documentation is part of your service delivery. A password reset process, onboarding checklist, security exception register, or client build guide can all live as ordinary files. If someone “just fixes a sentence” and breaks the meaning, the cost may not appear until someone follows the bad instruction perfectly.

That is how documentation gets dangerous. It does not need to be malicious. It just needs to be confidently wrong.

So yes, we may all be one edit away from Markdown oblivion. But we are also one review, one version history check, one Copilot pass, or one quick peer glance away from avoiding it.

The lesson is simple. Respect the little files. They know where the bodies are buried.

New Microsoft image model

I have a standard image prompt that I use to test Ai models. The previous iteration with MAI-Image-2.5-Flash and MAI-Image-2.5 is here:

https://blog.ciaops.com/2026/06/04/latest-microsoft-image-models/

Before that with MAI-Image-1.5 and Flux.2 Flex is here:

https://blog.ciaops.com/2026/05/16/copilot-image-generation-in-powerpoint/

the previous attempts:

https://blog.ciaops.com/2026/05/05/revisiting-copilot-image-generation-analysis/

and the first attempt:

https://blog.ciaops.com/2026/03/07/image-generation-analysis/

Microsoft has just released a new models and here is what I got when I used them:

MAI-Image-2.5-Pro

MAI_62dbc50ed84cdf44

It will be soon available across Microsoft 365 services and desktop apps. You can read more about the new models here:

https://microsoft.ai/news/introducing-mai-image-2-5-pro-and-mai-voice-2-flash/

The Bystander Effect Is Quietly Killing Your Marketing

image

There’s a famous bit of psychology that explains why a person can collapse on a busy footpath and twenty people walk past. It’s called the bystander effect. When responsibility is spread across a crowd, everyone assumes someone else will step in — so nobody does. The more people present, the less likely any single one of them acts.

I’ve come to believe the same thing happens in marketing, and most of us never notice it. We think the problem is that people are rejecting us. Usually they’re not. They’re just standing in the crowd, assuming the message was meant for the person next to them.

“Everyone” Is Nobody

When you write an email, a newsletter, or a webinar invitation addressed to everyone, you’ve accidentally recreated that footpath. The reader scans it, decides — without much thought — that it’s aimed at some other, more relevant person, and moves on. They don’t unsubscribe. They don’t send an angry reply. They simply file you under “not for me” and get back to their day.

That quiet non-decision is far more dangerous than a flat “no”. A rejection at least tells you the message landed. The bystander never even picks up the phone. You walk away thinking the offer was weak, when really the offer was fine — it just never felt personal enough for anyone to claim it.

I see this constantly with MSPs marketing to small business. We send a generic “we can help with your IT” message to a list of three hundred contacts and wonder why two people reply. The content isn’t the issue. The aim is. Three hundred people each assumed we were really talking to one of the other 299.

First Aid Trainers Got There First

Anyone who’s done a first aid course has been taught the fix already. When you’re standing over someone who needs help, you don’t shout “somebody call an ambulance” to the crowd. You point at one specific person — “you, in the blue jacket, call triple zero now.” The instant that individual realises they’ve been singled out, they move.

That’s the whole game. The moment a person understands you are talking to them, the bystander effect collapses and action becomes possible. Marketing is no different. The job isn’t to reach more people — it’s to make each person feel seen.

Naming the Person, Not the Crowd

So how do you point at the blue jacket without writing three hundred individual emails? This is where I think the tools we already pay for earn their keep.

Most MSPs sit on a goldmine of context they never use. You know which clients are still on ageing hardware, which ones asked about security last quarter, which ones have a renewal coming. That detail is scattered across Outlook threads, meeting notes, and a CRM nobody opens. The work of pulling it together used to be the reason we defaulted to “Dear valued customer”. It isn’t anymore.

I’ll draft a campaign in Word and ask Copilot to rewrite the same core message for three distinct groups — manufacturers worried about downtime, professional services worried about compliance, retailers worried about card data. Three versions in the time it used to take to write one bland one. Each reader recognises their own world in the words, and the bystander reflex never gets a chance to kick in.

Copilot in Outlook does the same thing one conversation at a time. Before I reply to a prospect, I can have it summarise everything we’ve ever discussed and surface the one concern they keep raising. The reply then opens with their problem, in their language — not my service menu. That’s the digital version of pointing across the room and saying the person’s name.

Even your segmentation gets easier. I’ll drop a client export into Excel and let Copilot group accounts by industry, size, or last contact, so the list I’m writing to is genuinely a room of similar people rather than a faceless mob. The narrower the room, the easier it is to talk to everyone in it as if they were one person.

One “Yes, You” Away

The shift here is small but it changes everything. Stop trying to be relevant to a crowd. Be unmistakably relevant to one type of person, and let them know you mean them.

Your next client is probably already on your list. They’re not ignoring you out of disinterest — they’re waiting in the crowd, quietly assuming the invitation belongs to someone else. The work isn’t louder marketing or a bigger list. It’s removing the doubt about who you’re speaking to.

Point at the blue jacket. Use the context you already have, the tools you already pay for, and address the person directly. You might be one moment of genuine recognition away from the conversation you’ve been chasing all quarter.