Introduction
Key Takeaways
The year is 2024, and Earth’s mightiest managed security providers are struggling to grow their businesses, and in some cases fighting for their very survival.
They face a threat the likes of which the industry has never seen: the invisible aliens of commoditization, margin erosion, and fly-by-night competition.
In this battle to scale their businesses and remain on the cutting edge of tomorrow’s cyber threats, security providers must arm themselves with the best weapons in their arsenals: continuous, high-revenue security and compliance.
To that end, Apptega is empowering security providers to drive differentiated value conversations with clients and stakeholders, improve customer experiences, and facilitate ongoing delivery of security and compliance services to better scale their businesses.
And on October 23, we unveiled major updates to our product roadmap and partner program, showcasing several industry-first developments as part of our fall product launch event, SECURE COMPLY REPEAT.
The action-packed blockbuster highlighted how managed security partners are working alongside Apptega to substantially boost recurring revenue, operating margins, and customer retention.
A transformative redesign of our user experience and interface, expected in 2025, punctuated several partner-focused updates that also included a deep integration with AWS Security Hub and an overhaul of how the Apptega platform equips, through “recurrence,” security firms to deliver world-class compliance and posture management solutions continuously to their clients.
Attendees who came for the product and partner insights were guided through an edge-of-your-seat presentation filled with time loops, alien war easter eggs, and memorable prizes and swag.
What follows is an overview of the product launch event and what was covered. To watch the event in its entirety, check out the on-demand recording.
The Threat & Our Mission
These days, everyone claims to be a security provider. Consulting shops, back-office IT, your brother after a mid-life crisis. From the MSSPs in our partner ranks to the IT services businesses, big accounting shops, and hundreds of firms that say they offer MDR — everyone is in security.
So, what does that mean for security providers? Increased commoditization that leads to pricing pressure, contracting margins, and customers jumping ship for cheaper (but not necessarily better) options.
Those that solve for these challenges face tremendous upside. But facing unprecedented M&A and a consolidation and culling of managed service providers (MSPs), as one industry observer put it, only the strongest balance sheets will survive.
That’s where Apptega comes in.
We’re on a mission to empower security providers to build and go to market with differentiated, lucrative, and continuous managed security and compliance offerings that drive recurring revenue, margins, and retention.
The Apptega platform is the first and only solution purpose-built for providers and their unique challenges, serving as a delivery mechanism for their products and services. And the benefits extend to the end users as well as service providers.
Through continuous security and compliance, providers can help their clients minimize risk, reduce cyber insurance premiums, achieve predictable costs, and gain a competitive advantage.
But Apptega is more than software. We also provide a partner program that serves as a playbook for building and going to market with managed security and compliance offerings. Bundled with security services, our platform and partner program are a powerful way to maximize value for providers and their customers.
From the Front Lines
Our partner program is an essential part of the Apptega offering. It aims to set partners up for success from day one with technical and go-to-market support, helping them better price, package, and deliver continuous security and compliance solutions.
We help our partners differentiate from competitors by sharing proven playbooks informed by our leadership team’s deep roots in cybersecurity and managed services. And we’ve added additional resources this year, including a new Partner Portal, Apptega Community, and Customer Support Portal.
Here’s how real partners are leveraging the Apptega Partner Program to grow their businesses.
Since December 2023, Aqueduct Technologies has partnered with Apptega to power their GRACE platform, selling their first deal within the first 60 days of the partnership and adding five deals and 15 opportunities since.
Through the partner program, Apptega has also sponsored and participated in several co-marketing activities, including Aqueduct’s successful AQ summit. In the first 10 months of our partnership, Aqueduct is nearing a half million dollars in new recurring revenue from services delivered via Apptega.
Foresite Cybersecurity joined forces with Apptega a year ago and has since become one of our most successful partners. So far, Foresite has realized a 43% return on Apptega software sales alone through 12 new deals and 68 sales opportunities.
Three Key Challenges
While managed security and compliance represent a lucrative opportunity for providers, they face three key obstacles to growth:
- Wins are few and far between. Security providers are heroes the handful of times they can show they stopped an attack. But with organizations facing an average of four attacks a year, how do providers prove their worth the rest of the time, connecting their services to tangible business outcomes?
- Dollars stop when the project ends. Providers often struggle to generate high-quality recurring revenue. According to the Apptega State of Continuous Compliance Report, 56% of providers generate less than a quarter of their revenue from ongoing engagements. Most services are delivered as one-off engagements that contribute only temporary revenue.
- Manual work eats margins. Security and compliance work is often manual and time-consuming, which eats away at provider margins. According to the State of Continuous Compliance Report, nearly 9 out of 10 providers face significant challenges maintaining compliance for customers. Nearly 40% lack the right tools and technology, which isn’t surprising with nearly 50% still using spreadsheets to track customer compliance.
Product Updates & Roadmap
SECURE COMPLY REPEAT presented how Apptega is enabling positive security, compliance, and risk outcomes for managed security providers, including several new and upcoming product releases:
Content Updates
In 2024, we delivered new and improved content to better align with the broadest range of industry best practices, standards, and regulations, including four new frameworks in 2024: ISO 42001, PCI DSS 4.0, NIST 800-171 Rev. 3, and NYDFS.
Enhanced Reporting
When it comes to security and compliance programs, showing progress over time is just as important as making progress. That’s why we’ve released new versions of all reporting to help our partners better demonstrate value to clients and internal stakeholders, including executive summary and assessment reports.
AWS Security Hub & MS Defender for Cloud Integrations
Our new AWS Security Hub connector maps relevant evidence from AWS services to Apptega’s common controls, updating scores across all frameworks added to that specific tenant. The MS Defender for Cloud connector helps manage security for Azure services and infrastructure, working in the same way as the AWS Security Hub integration.
Tasks 2.0
Our improved tasking system includes Task Recurrence, a new feature that supports continuous compliance programs by making it easy to create recurring tasks for reviewing relevant controls at the desired frequency.
UX/UI Improvements
Within the Apptega platform, we’ve redesigned key sub-control sections to streamline provider workflows, including intuitive document sections, a new tasks modal, a dedicated control activity modal, cleaner risk tables, a simplified comments section, as well as a reimagined program management dashboard to quickly view compliance scores, benchmarking insights, and recommended next actions.
New Program Management Dashboard
In the first half of 2025, Apptega will release a reimagined program management dashboard to help users quickly view compliance scores, benchmarking insights, and recommended next actions.
In the new program management dashboard, authorized users have everything they need to manage tenants. They can easily view program completion rate, SPRS score, pending tasks, and more. New graphs show how the business is trending toward meeting controls, with benchmarking information to show clients how they compare to peers. And users can view all controls they need to meet, with details on associated tasks that can be explored through multiple views, including KanBan, calendar, and milestones views.
Our new client management view provides a quick summary of pressing tasks and risk, including a list of accounts, associated projects, and key milestones. Partners can also manage documents, assessments, tasks, and more through one comprehensive view.
CMMI Scoring & Harmony Enhancements
We will soon release revamped CMMI scoring that incorporates a Maturity Model for the CSF framework and associated assessments, as well as improved mappings, in-product expectations settings, and a more consistent experience for Harmony users.
Apptega Showcase
Finally, the event introduced the Apptega Showcase, a powerful extension to the Apptega platform that enables partners to easily visualize the impact of their services on client security and compliance maturity. Customer Success and vCISO teams can use it as part of their regular engagement models, underscoring the value of the delivered services and showing where to focus next.
Conclusion
With exciting product reveals, partner playbooks, a partner program deep dive, and more, our SECURE COMPLY REPEAT product launch event demonstrated how security providers are forging a profitable path forward in an increasingly commoditized and competitive industry.
This is the first of many Apptega product launch events, so stay tuned for the next one. Until then, grab your popcorn, get cozy, and watch the full on-demand event recording.
It’s a can’t-miss for heroic security providers (and sci-fi enthusiasts).