Flamingo Raises $4.5M Seed Round

Updated: August 2026

As businesses grow and evolve, their needs for IT and security services also change. Managed Service Providers (MSPs) and Managed Security Service Providers (MSSPs) are two distinct types of providers that cater to these needs. While they may appear similar on the surface, their roles and areas of expertise are fundamentally different. Here’s a breakdown of what sets MSPs and MSSPs apart, helping you make an informed choice for your organization.

A Common Scenario: Outsourcing IT and Security Needs

Companies often turn to external providers for IT and security services, especially in their early growth stages or during periods of rapid expansion. For smaller organizations, MSPs are a natural fit, handling essential IT operations such as network management, system support, and infrastructure maintenance.

As companies grow larger and their operations become more complex, their focus on security intensifies. Larger organizations often retain their internal IT teams while turning to MSSPs for specialized cybersecurity expertise. This shift reflects the increasing importance of dedicated threat management and compliance as businesses scale.


Profitability and Market Statistics

The difference between MSPs and MSSPs is not just about services but also their financial structure.

  • MSPs: Gross profit margins typically range between 20% and 30%, reflecting their focus on IT operations that are crucial but often commoditized.
  • MSSPs: With a focus on high-stakes cybersecurity, MSSPs enjoy higher gross profit margins, usually between 30% and 40%. For a deeper look at what managed security service providers actually deliver, see our full breakdown.

In terms of presence, the numbers show a significant divide:

  • MSPs: There are approximately 40,000 MSPs in the United States, serving primarily smaller businesses.
  • MSSPs: The market is more niche, with around 3,500 MSSPs, reflecting the specialized nature of their services and their focus on larger clients.

Service Offerings: IT vs. Security

MSPs and MSSPs focus on entirely different aspects of business operations:

MSPs: Their services are centered around IT management, including:

  • Network monitoring and maintenance
  • Help desk and end-user support
  • Hardware and software management
  • Backup and recovery for IT systems
  • MSPs are ideal for businesses needing day-to-day IT support without the need to build and maintain an internal IT team.

MSSPs: Their expertise lies in cybersecurity, offering services such as:

  • Threat detection and response
  • Endpoint and network security
  • Compliance and risk management
  • 24/7 security operations center (SOC) support
  • MSSPs cater to organizations prioritizing robust security solutions, often working alongside internal IT teams. For example, Black Rabbit built an MSSP stack without the vendor tax using open-source tools.

Customer Size and Focus

Another key distinction is the typical size of the companies these providers serve:

  • MSPs: They generally work with smaller businesses, typically those with 10 to 100 employees, offering scalable IT solutions that fit modest budgets and simpler operations.
  • MSSPs: Their services are tailored for larger companies, often with 100 or more employees, where cybersecurity demands are higher due to the scale and complexity of operations.

Conclusion

MSPs and MSSPs are both essential players in today’s technology landscape, but their focus and expertise cater to very different needs. MSPs are perfect for businesses seeking reliable IT management, while MSSPs provide advanced security solutions for organizations facing growing cybersecurity challenges.

Understanding these distinctions will help your company choose the right partner to enhance operations, reduce risks, and position for long-term success. Whether your priority is IT efficiency or cybersecurity, aligning with the appropriate service provider is a decision that can make all the difference. And with AI agents reshaping IT operations, both MSPs and MSSPs are evolving fast.

Michael Assraf

Founder and CEO

Hey everyone, I'm Michael - founder and CEO of Flamingo. Before this, I built Vicarius, a cybersecurity company focused on vulnerability remediation, where I raised over $60M in funding. Working closely with service providers through that journey, I saw firsthand how MSPs were losing money to vendor payouts and inefficient systems - and that's when the idea for Flamingo clicked. I set out to build an open-source platform that dramatically increases MSP margins while helping them deliver better service to their clients.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

MSP vs MSSP

An MSP manages IT operations broadly: helpdesk, monitoring, patching, backup, and infrastructure. An MSSP focuses on security specifically, covering threat detection, incident response, SIEM, and compliance, usually delivered from a staffed security operations centre. Many businesses use both, and a growing number of MSPs add security services rather than referring them out.
Yes, and it is increasingly common. The practical test is whether security is delivered as a staffed, monitored service with defined response times, or as a set of tools resold alongside IT support. The second is not an MSSP offering regardless of how it is marketed.
MSSP services typically price higher per seat because they carry round-the-clock monitoring, analyst time, and specialised tooling. MSP contracts cover broader operational ground at a lower per-seat rate. Comparing the two on price alone is misleading, because the scope is different.
Security services generally carry higher margins than general IT support, which is why many MSPs expand into them. The barrier is staffing, since analysts and continuous coverage are expensive, and underdelivering on security carries more reputational risk than a slow helpdesk.

Managed Security

Maybe. Businesses under 50 employees often start with an MSP that includes light security, then add an MSSP when regulatory requirements (SOC 2, HIPAA), cyber insurance demands, or an incident push them past what their MSP can deliver. Some MSSPs target the small-business segment with packages built around basic SOC monitoring and EDR.

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
In the cloud, on US soil. Your data stays stateside.
Both. It's built for MSPs and MSSPs alike.

MSP AI Agents

Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.