Skip to content

David Barroso on severity scores, published in MSSP Alert

deception technology for MSSPs
Home News & Blogs David Barroso on severity scores, published in MSSP Alert

Read more at “The next MSSP breach may start with a “low” severity alert” by David Barroso, published in MSSP Alert, July 2026

CounterCraft founder and CEO David Barroso has written a Perspectives column for MSSP Alert arguing that the severity scores MSSPs use to triage client vulnerabilities are sorting the wrong queue. Time-to-exploit has collapsed from weeks to hours, and AI agents now chain together the findings those scores told analysts to skip. A Low on an exposed identity system, he argues, outranks a Critical on an air-gapped test box every time.

The column sets out five things Barroso believes every MSSP should already be doing, from treating patching speed as a survival metric to modeling exposure across code, dependencies, identity, and internet-facing surface rather than one CVE at a time. It then makes the case for deception technology for MSSPs as the control that still works when signature-based and behavior-based detection struggle against an adversary that adapts on every attempt.

His argument for deception rests on a single property no other tool in the stack has:

“No legitimate user should ever touch it.”

When something interacts with a decoy asset or credential, the alert is real, whether the thing touching it is a human operator or an autonomous agent. Barroso notes that automated attackers are often the easiest to catch this way, because they touch everything. For a multi-tenant SOC, a small number of alerts that can be trusted beats another stream of ambiguity, and believable decoys need the kind of ongoing specialist attention clients would rather hand to a provider.

deception technology for MSSPs

 


Find out more about deception technology for MSSPs

The CounterCraft MSSP Program

The program page covers what partners get: Advanced Detection & Response and Advanced Threat Intelligence, built to complement the EDR, XDR, NDR, and SIEM services you already run. It also sets out the operational terms MSSPs ask about first, including pay-as-you-go monthly pricing, proof-of-value options, and built-in ticketing and reporting.

MSSP Cybersecurity: Proactive Defense Against Modern Threats

The closest companion piece to Barroso’s column, on why reactive detection leaves clients exposed to AI-enhanced phishing, targeted ransomware, supply chain exploits, and credential misuse. It ends with the platform capabilities that matter in a multi-tenant SOC: massive scalability, minute-scale deployment, isolated per-client intelligence streams, and digital twin environments.

The Three Ps of Threat Intelligence for MSSPs

A practical walkthrough of how deception-powered intelligence combines strategic, tactical, and operational threat intelligence in one feed, and how it plugs into your existing SIEM and SOAR. Useful if the question in front of you is integration effort rather than concept.

Cyber Deception as a Service: Multitenancy and MSSPs

The mechanics of running deception across many clients from a single platform instance in your own SOC, with licensing that scales by deception host rather than by tenant. It also covers the prebuilt campaign templates, so a new client can be live on lateral movement or VPN threat detection without a bespoke build.

What Makes CounterCraft Worth a Place in Your Managed Security Services Portfolio

Written by our UK channel manager for the person asking “so what is in this for me,” and framed around three revenue streams: consultancy, integration, and managed services. The upsell argument at the end is the one partners tend to remember.
 

Frequently Asked Questions

What is managed deception?

Managed deception is a service in which a provider designs, deploys, and monitors decoy assets, credentials, and environments inside a client’s network. Because no legitimate user has any reason to touch a decoy, any interaction is a high-confidence indicator of intrusion rather than an anomaly requiring interpretation.

How do MSSPs deploy deception across multiple clients?

MSSPs run a single multi-tenant platform instance in their own SOC and deliver isolated campaigns to each client from it. Each tenant keeps separate decoys and intelligence streams, and licensing scales by the number of deception hosts deployed rather than by the number of clients served.

Why do severity scores fail against AI-driven attacks?

A severity score rates a vulnerability in isolation, with no view of what is exposed to the internet, what touches sensitive data, or what runs in production. AI agents chain several low-rated weaknesses into a serious compromise, so context determines real priority.

 

Become a CounterCraft MSSP partner

Deception works well as a managed offering because believable decoys need the ongoing specialist attention your clients would rather hand to a provider. If that fits where your service portfolio is heading, start here.

deception technology for MSSPs