Monday, 28 September 2026

Where technology leaders come to think out loud

ColumnCybersecurity

Identity, not the SOC, is where the next MSSP premium sits

Integrity360 has bought its way across three continents in nine months, but the CyberIAM deal is the first about capability rather than geography. Jay Janes on why UK MSSPs without an identity practice should worry

Ian Brown, executive chairman of Integrity360
Image: Integrity360
In brief
  • Integrity360’s purchase of CyberIAM on 27 August is its fourth deal since December and the first that buys a capability rather than a country.
  • Every MSSP of scale now has a SOC and a vendor-badged MDR service, so the SOC no longer sets the price a buyer will pay.
  • A UK MSSP without an identity practice has three options – build, partner or sell – and the third gets priced on the SOC alone.

Integrity360 bought CyberIAM on 27 August. The Dublin-headquartered managed security service provider (MSSP) did not disclose the price. What it did disclose, in its release, is the shape of the deal: CyberIAM, founded in 2016, brings about 120 staff in Chester, London and Cape Town and adds approximately €18m (£15.4m) of revenue, taking the group to a run rate of about €230m (£197m) and about 900 employees. Those are the company’s own figures, and it rounds every one of them.

It is the fourth acquisition Integrity360 has announced since December 2025, and its own releases record the pace: Redshift in Johannesburg on 1 December, Cresco in Brussels on 22 December, Advantus360 in Calgary on 6 January and now CyberIAM. When it announced the Cresco deal the group put its headcount at over 750 people in 14 regional locations. Eight months later it says circa 900 in 16. August Equity, the private equity firm that invested in June 2021, is not funding that rate of buying in order to hold.

The first three deals bought geography. Redshift added security testing depth in South Africa, Cresco a base in Benelux, Advantus360 a first foothold in North America. CyberIAM buys something else. The release sets it up as a new strategic services practice alongside the group’s seven existing ones, keeps CyberIAM chief executive Michael Ribaudo in charge of it, folds Integrity360’s own identity people into his team and routes identity managed services through the group’s security operations center (SOC). Executive chairman Ian Brown’s line on why is worth quoting in full: “Identity is now the primary control plane for cybersecurity, and by strengthening our Identity capabilities, we are helping customers build the secure foundation they need to embrace AI with confidence.”

I think Brown is right, and I think that sentence matters more to UK MSSPs than the deal does. For a decade the price of a security provider has been set by its SOC: the analysts, the tooling, the managed detection and response (MDR) contracts. That is no longer where the premium sits. Identity, not endpoint and not the SOC, is where the next round of consolidation money will go, and a UK MSSP without an identity and access management (IAM) practice is about to become either an acquirer’s target or an acquirer’s afterthought.

The SOC no longer sets the price

Every MSSP of scale now has a SOC story, and they all sound alike. Integrity360 itself describes one global SOC operation spanning over seven physical SOCs and more than 225 analysts, consultants and engineers, delivering endpoint, extended and managed detection and response. That is a serious operation. It is also, increasingly, the entry ticket. When every credible bidder can point to round-the-clock monitoring and a vendor-badged MDR service, the SOC stops distinguishing the target from the field. A buyer will pay for the customer contracts attached to it. It will not pay a strategic multiple for a capability it already owns.

Endpoint is a weaker position still. The endpoint agent is the vendor’s product; the MSSP resells and manages it. The margin is set by the vendor’s price list, not by the provider’s engineers, and it moves whenever the vendor decides it should.

Identity is services all the way down

Identity is different because the work is different. The release lists what CyberIAM does: design and architecture, assessment, remediation, integration, deployment, strategy and training, on top of support and managed services, across CyberArk, SailPoint, BeyondTrust and Saviynt. That is consulting-heavy, multi-year and hard to hire for. An identity governance program reaches into HR systems, joiners and leavers, privileged accounts and every AI agent that now needs to be authenticated and governed. Nobody switches that off at renewal.

The vendors have already priced the shift. Palo Alto Networks agreed in July 2025 to buy CyberArk at an equity value of about $25bn (£18.6bn), calling the deal its “formal entry into Identity Security” and “a core pillar” of its strategy, according to its release. Integrity360’s own release now refers to that platform as CyberArk, “now Idira from Palo Alto Networks”. When a vendor of that size pays a strategic premium to get into identity, the services layer underneath it becomes the scarce asset in the channel.

A caution is due. Integrity360 has not said what it paid for CyberIAM, so nobody outside the deal can say it paid up. About €18m of revenue and 120 people is a modest bolt-on for a €230m group. But the language is not modest – an eighth practice, the existing team merged in, a new line in the executive chairman’s script – and four deals in nine months suggest the buying is not finished.

The options are build, partner or sell

So what does a UK MSSP with a good MDR book and no identity bench do about it? There are three options and none is comfortable.

Build it. IAM and privileged access management (PAM) engineers are scarce, expensive and loyal to the platforms they are certified on. CyberIAM took a decade to reach 120 people. A provider that starts hiring after this deal is starting late, and its competitors know it.

Partner for it. White-labeling a specialist works until the specialist is bought, as CyberIAM has just been, by a group that competes with you for the same mid-market accounts. Every identity specialist in the UK worth partnering with is now on someone’s list.

Or sell. A consolidator will still want your contracts. It will price them on your SOC, because that is what it can see, and it will pay nothing for the practice you never built.

The uncomfortable arithmetic is that the identity practice you do not have is the one line on the buyer’s spreadsheet that would have moved the multiple. In the next round of MSSP consolidation, the SOC gets you a meeting. Identity gets you a price.

AdvertisementZoomInfo

Get The VETTDD BriefingThe week in the technology channel, every week.

Subscribe free
Sources
  1. Integrity360, “Integrity360 acquires Identity specialist CyberIAM”, press release, 27 August 2026. https://insights.integrity360.com/the-future-of-security-is-identity-integrity360-acquires-iam-specialist-cyberiam
  2. Integrity360, “Integrity360 expands into North America with Advantus360 Acquisition”, press release, 6 January 2026. https://insights.integrity360.com/integrity360-expands-into-north-america-with-advantus360-acquisition
  3. Integrity360, “Integrity360 expands into Benelux with Cresco Acquisition”, press release, 22 December 2025. https://insights.integrity360.com/integrity360-expands-into-benelux-with-cresco-acquisition
  4. Integrity360, “Integrity360 expands further in Africa with Redshift Acquisition”, press release, 1 December 2025. https://insights.integrity360.com/integrity360-expands-further-in-africa-with-redshift-acquisition
  5. Palo Alto Networks, “Palo Alto Networks Announces Agreement to Acquire CyberArk, the Identity Security Leader”, press release, 30 July 2025. https://www.paloaltonetworks.com/company/press/2025/palo-alto-networks-announces-agreement-to-acquire-cyberark--the-identity-security-leader
Jay Janes
About the author

Jay Janes

Founder and editor of VETTDD. Former chief revenue officer at Giacom and director of growth at intY, where revenue grew from £19m to £40m.

More from Jay Janes →