From MSSP to MCOP, Part 1: When Free Services End
with Michael Pegues, former CIO, City of Aurora
What municipalities lose when free MS-ISAC services end, and the difference between an MSSP that sends alerts and an MCOP that runs the whole operation.
The first part of this Cyber Resilience Report episode opens with the questions state, local, tribal and territorial (SLTT) leaders raised when free MS-ISAC services began to end. Cyrus Walker and Michael Pegues, former CIO of the City of Aurora, Illinois, describe what municipalities lose in visibility, threat response and proactive tools such as endpoint detection, and the budget strain of replacing those services — especially for governments that run water, power, traffic or health systems. Cyrus then explains the difference between a traditional managed security service provider (MSSP), which sends alerts, and a managed cybersecurity operations provider (MCOP), which runs the operation.
Welcome to the cyber resilience report powered by Data Defenders. While cyber security awareness month may have concluded, the mission of turning awareness into continuous operational resilience remains vital. This episode builds on the foundation laid in our first two installments, from vulnerability to resilience, and the CBS 60-minute brief, expose threats, build solutions. Those conversations revealed a widening gap between policy awareness and operational resilience, especially after the MS-ISAC transition and a CBS 60 Minutes investigation into municipal vulnerabilities. Today, we're taking the next step, showing how the MCOP model, regional SOC utility and Cybersecurity Operations 2.0 framework powered by DataShield Cybersecurity 360 and DataShield Analytics closes the gap by transforming awareness into continuous AI-driven defense because awareness without action leaves communities exposed to ground us into reality.
We recently surveyed SLTT leaders across the country. Here's what we heard most often from a CIO. When those free MS-ISAC services end, what's the biggest operational hit my team will feel on Monday morning? A mayor asked, "What's a single leadership action I can take right now to protect critical services like 911 or water and a CFO? If we start paying for these capabilities, what's our real cost exposure, especially when we factor in the cost of inaction?" These are the questions driving today's discussion and they're also the foundation of our companion resource, the MCOP dependency mapper, a quick visual tool that shows where your defenses depend on MS-ISAC, where new gaps might emerge, and how to plan for continuity.
You'll find these linked in the show notes below. Joining us today are two leaders who live these challenges from different angles. Cyrus Walker, CEO of Data Defenders and architect of the MCOP model, a managed operations first approach to cyber security, and Michael Pegues, president of Aurora Dynamic Solutions and former CIO of the city of Aurora, Illinois, who helped lead one of the most successful municipal cyber security transformations in the country. Together, they'll unpack what every SLTT leader from mayors and CIOs to CFOs needs to know to move from alerts to operations. Now, here is your host, digital strategist for Data Defenders, Tracy Francis.
To all of our listeners, thanks for joining. I'm Tracy Francis, digital strategist for Data Defenders, and our mission is all about turning awareness into continuous resilience. So with those stakes in mind, Cyrus and Michael, what operational realities start surfacing in the weeks after those free services go away? So the potential reality is that there's a loss of critical services that municipalities and other units of government have come to rely on as they have attempted to stand up some semblance of a cyber security operation. And the depending on those services, it could create some significant holes in their visibility and their uh ability to detect malicious activity and in some cases their ability to respond to that activity from a technology perspective.
When I say respond to it, meaning being able to kill threats, kill signals, block ports, you know, do things that are important to keeping the bad guys out. So those loss of services can be impactful that way. Those loss of services can also be impactful in ways of limiting their proactive capabilities. For instance, for vulnerability analysis, being able to identify vulnerabilities that exist on devices and their infrastructure, being able to provide some proactive capabilities like EDR on the endpoint. I I know that particularly here in Illinois, Crowd Strike was being offered as part of a free service to municipalities and CrowdStrike is an EDR application that allows for uh security uh teams to be able to monitor activity happening on the endpoint device, laptop, um server or the endpoints that CrowdStrike was installed on.
So could potentially take away that capability from being able to not only they monitor activity but also keep level of security on each of those endpoints as well. So it makes basically makes them vulnerable to the bad guys again. Yeah, absolutely. Absolutely. And I think if we kind of look at it from a different perspective, so I'm going to put my my former CIO hat back on here.
If you look at I say kind of statewide, we take the state of Illinois in terms of local governments and those municipalities that actually have a a this type of capability. It's probably less than more of those municipalities that have a capability. I would say you know just based on my recent research that although you know more than 98% of you know local governments CIOs or CISOs say that that cyber security capability is a top priority I would say probably about a third of those local governments really have the capabilities to basically to manage off compromise or threats and things of that nature. Especially when you start to look at the smaller municipalities, they tend to rely more on like generalists or like shared services rather than kind of like a formal SOC or MSSP, but you know those tend to exist within the larger cities or the counties right where they have the dedicated resource capabilities to kind of manage that you know so I think just like in short you know nearly all the local governments say that you know the cyber security is a priority in that space but only really one in three have dedicated ated cyber security functions. Mhm.
Right. Right. Right. That that's an important distinction, Mike, because what you're describing shows the scale of the challenge. Even when cyber security is a state priority, most local governments simply don't have the dedicated staff or funding to back it up.
So, let's unpack what that really means in practice. Cyrus, when those free services disappear and smaller municipalities are left to fill the gaps themselves, what kind of financial and operational strain does that actually create? especially for those managing critical infrastructure like water, power, or even health care. No, I think that pretty that pretty much covers what what the reality of losing this this this service is. The the well what there's one thing that that can be negatively impactful to the municipality or unit of government and that is the fact that they now have to spend this money in order to potentially replace these services. money that they might not have had earmarked for cyber security services, you know, had earmarked for something else. Uh but particularly for those units of government that host critical infrastructure like water treatment or power distribution or traffic management in some way, shape or form or or even healthcare, you know, like for Cook County for instance, you know, with their Cook County Health System, losing those services uh can potentially put the protection of those of the critical infrastructure in jeopardy and may require them to have to replace those services with costly services that they might not have allocated budget for.
So, it's a it's a it's a reverberating impact throughout the entire organization. You know, at the end of the day, no politician or or elected official, you know, wants to end up in the news. And so this has to be a serious consideration that they make in order to ensure that they can keep the the residents of their communities or constituents safe. We've seen, you know, where that can be very detrimental. you know, when you look at cities like Atlanta or Baltimore that have uh experienced severe cyber security breaches in the past, you know, how that can result in millions and millions of dollars and losses and expenditures to recover from the incident. So, this is a serious consideration that municipalities have to make in order to show that they can continue to maintain some level of security in their environment.
Now that we've set the stakes, let's take a look at what comes next. The proactive path forward. Our follow-up survey with SLTT leaders revealed that their biggest challenge isn't awareness. In fact, it's transitioning from reactive to proactive cyber security. So, before we dive into that section, Cyrus, can you walk us through what truly separates a managed security service provider or MSSP from a managed cyber security operation provider or MCOP?
So it's starts with the nature of the MSSP and the MCOP and the big difference there is one is naturally reactive the other one is naturally proactive and what that means is the the MSSP model is a 20 plus year old model that was designed to provide some assistance to companies, customers, municipalities, units of government to give them some eyes on what's going on underneath the covers of the infrastructure and that's primarily done by an alerting function. So there's some kind of monitoring function that's set up that for the vendor to capture and identify threat activity uh that then results in an alert being sent out to the customer uh which then requires the customer to respond to that alert uh either by uh making some adjustments to their infrastructure or countering that that that threat that's been identified by that alert. But at the end of the day, it's it's requiring the the customer to take that next step. MP side from a proactive side, not only do you have the proactive threat hunting and threat killing, but you also have the proactive operations management as well. So instead of relying on the relationship between the vendor to provide an alert and the customer to respond to the alert, now you have an MCOP based vendor who is doing all of that.
They are identifying the threat. They are responding to the threat. uh and they're also proactively managing operations to mitigate any vulner state of vulnerability or vulnerabilities that exist in that environment that makes that threat viable. So you have this active 24hour 24x7 by 365 activity happening integrated directly into the customer's environment that's designed to manage the three components of the cyber security life cycle. the aspect of it related to strategy and risk management and compliance and so forth and so on, policy development. Then you have the process and procedure design around vulnerability management, cyber security assessment, incident response, you know, all those things that are required to activate the operation. And then you have the the technical infrastructure management piece which is designed to provide the the the people the expertise necessary to run the operations on a daily basis and also the infrastructure the technical infrastructure necessary to stand up the technical component of the infrastructure.
What I mean by that, I mean your point solutions like your MDR, your EDR, your vulnerability assessment, your um identity management, your cloud security, you know, all those things that that are necessary in today's tech technical environment. So an MCOP is a much more comprehensive delivery of cyber security operations to the customer that allows basically frees up the customer to do what they do best and that's deliver services to and constituents of the communities that they serve instead of them having to focus on doing that and building a cyber security operation to counter this active persistent threat. OG's and municipalities are not designed to uh provide cyber security services. They're they're designed to provide traffic management. They're designed to provide, you know, government related services that constituents rely on, you know.
They're designed to provide law enforcement, shovel sidewalks, right? You know, right, right. Yep. Yep. They're designed to do those things.
They're not designed to hunt threats, hunt mitigate threats. So, uh, frees them up to do what they do best while, uh, the vendor, the MCOP vendor does what it it does best, which is hunt threats, kill threats, build operations, manage those operations on a 247 basis. Yeah. And there's also a 77% savings compared to an in-house SOC, right? Yeah.
So there is definitely a cost savings that's gained as a result of relying on a vendor that delivers this kind of service. You know, for for an entity who's trying to build it on their own, they're going to spend a lot of money doing that. They're going to spend money in hiring the people. They're going to spend money in building the technology or or or procuring the technology and they're going to spend money in operating the technology. Why why go down that road when you can bring in a vendor who can spin up a a cyber security operation very quickly at a fraction of the cost it would take to do that?
Again, um there's there's better economies of scale in working with a vendor who can spend that up as opposed to going to do it on their own. Now, one of the things we've encountered in doing this is the the control syndrome. It makes sense You know, most organizations want to control what they do. I get that. It's in that mindset of control where the challenges happen.
Particularly for technical people, you know, we we naturally have a desire to control. You know, we want to build, we want to see the flashing lights, you know, we want to see things working. You know, we want to pat ourselves on the back that we got this sexy technology solution up and going that's now enabling services for everybody. you know, we want to wear that cape. But for most organizations who are not designed to do that, that's not their charter, that's not their purpose. Um, it it's very hard and very costly to do that.
So, that's what one of the major benefits of working with an MCOP based vendor opposed to an MSSP vendor. the MSSP vendor is just delivering a point solution and the MCOP vendor is delivering the entire comprehensive operation. In this first part, we've drawn a sharp line between two worlds. Traditional MSSPs that send alerts and MCOPs that deliver the entire operation, people, process, and technology working together 24 by7. That difference becomes critical the moment free MS-ISAC and stateup supported services end leaving municipalities to choose between peacemeal tools and true resilience.
In part two we move from theory to practice with the city of Aurora Illinois. A real world look at how the MCOP model transforms daily operations, budgets and public trust.
Key takeaways
- When free MS-ISAC and state-supported services end, municipalities can lose visibility into malicious activity, the ability to respond to it, and proactive tools such as endpoint detection and vulnerability analysis.
- More than 98% of local-government CIOs and CISOs call cybersecurity a top priority, but only about one in three local governments have a dedicated cybersecurity function.
- Replacing lost services means unbudgeted spending, and the risk is highest for governments that run critical infrastructure such as water treatment, power distribution, traffic management or health systems.
- An MSSP is reactive: it sends alerts and leaves the response to the customer. An MCOP is proactive: it hunts and kills threats and manages day-to-day operations 24/7.
- Governments are designed to deliver public services, not to hunt threats. Handing operations to an MCOP lets each side do what it does best — at a cost the episode puts at 77% below running an in-house SOC.