Home About Speaking Framework Press Podcasts Field Notes Say Hello
The Cyber Resilience Report · Episode 5 · Part 1 of 3

From MSSP to MCOP, Part 1: When Free Services End

with Michael Pegues, former CIO, City of Aurora

What municipalities lose when free MS-ISAC services end, and the difference between an MSSP that sends alerts and an MCOP that runs the whole operation.

← Back to Podcasts Next: Part 2 →

The first part of this Cyber Resilience Report episode opens with the questions state, local, tribal and territorial (SLTT) leaders raised when free MS-ISAC services began to end. Cyrus Walker and Michael Pegues, former CIO of the City of Aurora, Illinois, describe what municipalities lose in visibility, threat response and proactive tools such as endpoint detection, and the budget strain of replacing those services — especially for governments that run water, power, traffic or health systems. Cyrus then explains the difference between a traditional managed security service provider (MSSP), which sends alerts, and a managed cybersecurity operations provider (MCOP), which runs the operation.

Key takeaways

  • When free MS-ISAC and state-supported services end, municipalities can lose visibility into malicious activity, the ability to respond to it, and proactive tools such as endpoint detection and vulnerability analysis.
  • More than 98% of local-government CIOs and CISOs call cybersecurity a top priority, but only about one in three local governments have a dedicated cybersecurity function.
  • Replacing lost services means unbudgeted spending, and the risk is highest for governments that run critical infrastructure such as water treatment, power distribution, traffic management or health systems.
  • An MSSP is reactive: it sends alerts and leaves the response to the customer. An MCOP is proactive: it hunts and kills threats and manages day-to-day operations 24/7.
  • Governments are designed to deliver public services, not to hunt threats. Handing operations to an MCOP lets each side do what it does best — at a cost the episode puts at 77% below running an in-house SOC.

← Back to Podcasts