ClearSkies iISOC for MSSPs
Your Brand. Your Clients.Your Margin.
The ClearSkies iISOC platform packaged for multi-tenant delivery: many isolated client tenants in one deployment, run from a single console, delivered under your brand and licensed on daily ingestion volume rather than seats.
- 1
deployment carries the whole client base
- 6
native add-ons, activated per tenant
- 30+
countries running the platform in production
- 2
decades of production security operations
The provider operating problem
Four structural failures, and what each one costs
Each compounds with client count, and none is solved by adding another point product.
| Failure mode | What it costs |
|---|---|
| Replication instead of multi-tenancy | Every client adds a deployment to patch and a console to hold open, so growth arrives as fixed cost the contract price never covered. Enterprises run around 45 security tools, and you inherit that sprawl once per client. |
| Alert volume without correlation | 46% of alerts are false positives, and flooding them is a catalogued adversary technique, ATT&CK T1562. Noise is an attack surface rather than an operational annoyance. |
| No cross-layer visibility | A credential-theft chain across exposure, DNS, identity and endpoint leaves four alerts and no incident. Between 42% and 63% of alerts go uninvestigated, and those are the low-severity ones that only matter in combination. |
| The cost of the workaround | Fragmented operations spend around 40% more on operational labor, and on an open meter cost to serve climbs with every noisy log source while the contract price stays fixed. |
Sources: Gartner; Microsoft and Omdia, State of the SOC 2026; Vectra AI and Omdia, 2026.
The answer, as mechanism
Telemetry normalized at collection, entities resolved across sources, one incident on one explainable score, separation enforced below the application, one console across the whole book.
Build or buy
Three routes to a managed detection practice
| Criterion | Assemble open source | Resell another service | Productize on ClearSkies MSSP |
|---|---|---|---|
| Value at exit | Real, if truly proprietary | Limited. Not your capability | Real. Practice, clients and operating data are yours |
| Margin | Improves only if engineering cost stops growing | Capped by the wholesale price | Improves as automation cuts analyst hours |
| Client ownership | Complete | Shared with the supplier | Complete, under your brand |
| Time to revenue | Longest. Quarters | Shortest. Weeks | Short. Weeks once the first tenants are live |
| Capital and setup | Low license, high engineering | Low. Live on day one | Moderate. Volume up front or per tenant |
| Detection engineering | Yours in full | The supplier's, and invisible to you | Ours, with your tuning retained |
A framework, not a claim that one route suits everyone. Reselling really is the fastest route to revenue.
What you buy
The platform, plus what a service business needs
Same engine, same six add-ons, same detection content as a direct enterprise deployment. The MSSP tier adds the operator layer.
The commercial model
Licensed on what you carry, not on what your clients own
How it is measured
Volume
Daily ingestion volume rather than endpoints or seats, so analyst hours removed by automation stay with you instead of becoming a discount
Capacity
Held as a pool and reallocated across tenants as clients sign or churn, or bought one tenant at a time
Console
Billed once a year whatever the tenant count, so a second tenant costs a bundle and no new infrastructure
Scoped to real exposure
Each native add-on is licensed on the unit that reflects the surface it protects and is activated per tenant, so a client carries what its exposure justifies and nothing more.
Attack Surface Monitoring measures that exposure continuously, which turns the next increment into an evidenced proposal rather than a bundle the client has to grow into.
Volume is bought in bands rather than metered without a ceiling, and low-value telemetry is filtered at collection, so a noisy client meets a known band.
Objections, answered
The three questions asked first
Microsoft Sentinel is already covered by the E5 license
It covers one infrastructure, not multi-tenant delivery. Tenancy, cross-client operations, correlation beyond Microsoft and the branding layer remain yours to build.
An existing white-label MDR arrangement already works
It does, and it will continue to. The question is what it is worth in three years: efficiency accrues to the supplier, the client is shared, nothing is proprietary at exit.
The market has not heard of ClearSkies
True in some markets. The platform has run production security operations across more than 30 countries for two decades, and the evidence is available before contract.
ClearSkies MSSP, in one line
One deployment, many isolated tenants, your brand on every client touchpoint
Licensed on volume you hold, so the efficiency you automate stays with you.
