As the IT channel braces for another year of rapid transformation, few voices command more attention than Matt Lee, senior director of security and compliance at Pax8—one of the industry’s most respected cybersecurity thought leaders and GTIA’s 2024-2025 Member of the Year. In his latest set of predictions for 2026, Matt cuts through the hype to outline the opportunities, risks and emerging realities MSPs must prepare for, from the rise of agentic AI to the growing importance of security frameworks and trustmarks. His insights offer a clear roadmap for MSPs navigating an increasingly complex—and high‑stakes—digital landscape.
>> Read: Advancing the Tech Industry Through Deep Human Connection
Agentic AI Will Offer Big Benefits—But Also Bite Unprepared MSPs
Agentic AI will help MSPs automate more of their workflows, but many will adopt it before they’re ready. As AI agents start making autonomous API calls and connecting deeply into production systems, poorly restricted APIs and weak governance will create new attack paths. In 2026, expect MSPs to accidentally break things through flawed automations—and for attackers to exploit agent-based vulnerabilities such as rug-pull attacks or compromised packages. The opportunity is huge, but so is the risk if MSPs don’t slow down and implement guardrails.
Middleware Will Become a Billion‑Dollar Fix for Today’s AI Security Gaps
Most APIs today weren’t designed with AI-driven automation in mind. They lack granular permissions, human‑in‑the‑loop controls and hardened restrictions. Since vendors won’t rebuild their entire API infrastructures overnight, a new market will emerge. Matt predicts an explosion of third‑party middleware—tools designed to sit between AI agents and existing APIs, filtering and restricting what agents can do. Think of it like a new generation of WAFs built specifically for AI workflows. Entire SaaS categories focused on AI governance, AI data security and agent behavior restriction will be created in 2026.
New AI Vendors Will Flood the Channel—and MSPs Must Vet Them Carefully
A wave of brand-new AI companies is coming, and MSPs will need to evaluate them quickly and thoughtfully. The challenge? Many MSPs aren’t used to “building software,” yet agentic workflows are essentially coded systems that must be secured, maintained and priced appropriately over time. Agents break when models update. APIs change. New security layers must be added. MSPs that underprice these services—or skip the hardening work—will introduce significant risk into their own environments and their clients’. In 2026, MSPs must think like software builders, not just IT providers.
Standards and Trustmarks Will Gain Real Traction—and Financial Benefits
No MSP can eliminate all risk, but customers and insurers increasingly want proof of maturity. Matt believes 2026 will be the year more MSPs adopt formal frameworks and trustmarks—whether it’s GTIA’s Cybersecurity Trustmark, CIS, ISO, NIST-derived standards or SMB-focused frameworks. And there’s a financial incentive. Insurers are beginning to reduce premiums for organizations that follow standardized, verifiable security practices. As the industry moves toward unified insurance questionnaires anchored in frameworks like CIS, MSPs with validated maturity will stand out—and save money. Framework adoption won’t be universal overnight, but momentum is unmistakable.
SMB Success Will Divide into “Haves” and “Have Nots”—Depending on Their MSP
SMBs are fragile: They churn, close, or restart all the time. Their survival will increasingly depend on whether their MSP understands their business deeply enough to identify risky workflows, outdated software and data exposure points. MSPs that help customers modernize legacy technologies, eliminate technical debt and adopt more secure cloud-native systems will put those businesses on a path to resilience. MSPs that treat security as a commodity—without understanding the customer’s operational realities—will watch clients fail after cyber incidents, rising insurance costs or compliance requirements they’re unprepared for. 2026 will mark the start of a widening gap between SMBs that mature—and those that disappear.
>> Watch Matt Lee’s GTIA 2024-2025 Member of the Year video
GTIA Members, access a library of cybersecurity resources and the Cyber Hub on the Member Portal.
Not a member? Join now.

