FREQUENTLY ASKED QUESTIONS

Questions MSPs actually ask before they run security with Cyflare

You’ve heard the pitches. Here’s what partners actually ask before they sign, and the straight answers, no sales deck required.

1,500+

partner-led accounts

400+

integrations, no forced stack

8.3 min

MTTR on critical cases

40%+

partner margins

ABOUT CYFLARE

What Cyflare is actually is

What is Cyflare?

Cyflare is a managed cybersecurity provider for MSPs and service providers. We staff and run the SOC, the detection and response, and the compliance reporting, operating on the Prevent, Respond, Govern model so every client gets the same discipline no matter who’s on shift. You can offer security services under your own brand whether you’re starting from zero or already run a security practice and want to extend it.

How is Cyflare different from a typical MSSP or SOC-as-a-service vendor?

No. Cyflare is tool-agnostic. We integrate with what you already run through 400+ supported integrations, so your clients keep their existing EDR, email security, or identity tools while Cyflare’s SOC handles the monitoring and response layer on top of them. If you’d rather not maintain a stack at all, we provide the managed technology too, and the SOC, playbooks, and reporting work the same either way.

Do I have to replace my existing security stack to use Cyflare?

You don’t have to replace your existing security stack to use Cyflare. It’s tool-agnostic and integrates with what you already run through 400+ supported integrations, so your clients keep their existing EDR, email security, or identity tools while Cyflare’s SOC handles the monitoring and response layer on top of them. If you’d rather not maintain a stack at all, we provide the managed technology too, and the SOC, playbooks, and reporting work the same either way.

What does "Prevent, Respond, Govern" actually mean?

It’s shorthand for the three things Cyflare does for every client, and they run continuously rather than as separate phases. Prevent means identifying root causes and closing exploitable gaps, ranked by exploitability and impact, before they turn into incidents. Respond means validating detections with full context and containing real threats through predefined decision paths, not guesswork. Govern means keeping an audit-ready record of what happened, what was decided, and why, generated as the work happens instead of reconstructed after the fact.

What is Cyflare ONE?

Cyflare ONE is the platform where you and Cyflare’s SOC work together: one screen for alerts, case notes, analyst decisions, and compliance reports, instead of switching between separate tools for each. It correlates telemetry from endpoint, identity, email, cloud, and network sources into a single view, so you can see exactly what the SOC saw and did on any case rather than taking our word for it. 

Why should an MSP trust an outside SOC with client relationships?

Because it’s sold and delivered under your brand. Your clients experience Cyflare as your SOC, not a subcontractor they’ve never heard of, and the relationship, billing, and communication stay yours. That’s backed by a $500K Service Warranty, which puts financial accountability into the service itself rather than a line in the fine print. See the partner program for how that works in practice.

SERVICES

What we run for you, service by service

What does Managed Detection and Response include?

Continuous monitoring, validated alerts instead of raw noise, and coordinated containment across endpoint, cloud, and identity, with an 8.3 minute mean time to respond on critical cases. Detections go through validation before anyone acts on them, which is a large part of why the false positive rate stays under 1%. See how MDR runs.

How do Vulnerability Scanning Services work?

Continuous scanning across your client environments rather than a one-time snapshot, with remediation ranked by exploitability and impact instead of a raw CVSS score dump. That means your team fixes what’s actually likely to get exploited first, not just whatever scores highest on a report nobody reads. Findings come formatted as evidence your clients can hand to an auditor. Inside Vulnerability Scanning Services, or read the full overview.

How does Managed Email Security stop account takeover and phishing?

It combines phishing detection, account takeover prevention, and collaboration platform protection (think Teams and SharePoint, not just inbox) at the point clients are most exposed. 52% of attacks targeting MSPs in 2025 were phishing, up from 30% in 2024 (ConnectWise 2026 MSP Threat Report), so this is usually where the first incident starts, not the endpoint. Inside Managed Email Security.

What's the $0 Breach Response Retainer?

On-call access to privileged legal counsel the moment a breach is confirmed, with no retainer fee sitting on the books until it’s needed. The SOC and breach counsel are pre-aligned before an incident happens, so when one does, response starts immediately and under attorney-client privilege instead of losing the first critical hours figuring out who to call. See the Breach Response Retainer, or read the overview.

How accurate is Cyflare's detection, really?

Under 1% false positive rate across the partner base. See how MDR runs.

Can Cyflare support compliance frameworks like CMMC, HIPAA, or NIST?

Cyflare supports compliance frameworks including CMMC, HIPAA, PCI, NIST CSF, and CIS controls, with reporting and control mapping generated as part of daily operations rather than assembled the week before an audit. Cyflare itself holds CMMC Level 2 certification with a perfect 110/110 assessment score, one of roughly 250 organizations worldwide with that C3PAO-verified certification. Get the CMMC framework mapping guide or the NIST CSF mapping guide.

SOLUTIONS

Solutions built around the situation you're in, not just your industry

What industries does Cyflare build solutions for?

Cyflare works with clients across a wide range of industries, including nonprofit, insurance, construction and engineering, healthcare, financial services, education, and legal, each with security and compliance needs that look different depending on the sector.

What if the problem isn't a specific industry, it's that my team is drowning in alerts?

For alert fatigue, Cyflare combines validated detection, so fewer alerts require action, with prioritized escalation and consistent playbooks, cutting the noise your team has already learned to tune out instead of adding another layer of alerts on top of the ones getting ignored. See alert fatigue for how those pieces work together.

Can Cyflare help before an audit, not just after an incident?

Ahead of an audit, Cyflare combines compliance reporting, control mapping, and documented incident history to get evidence in place before an auditor asks for it, instead of scrambling to reconstruct documentation against a deadline. See audit pressure for how that comes together.

What about a client who's already had a phishing incident or email account takeover?

For a phishing incident or account takeover, Cyflare combines Managed Email Security, SOC-led containment, and post-incident reporting to close the gap and document what happened, since email is still the most common way attackers get in first, at 52% of MSP-targeted attacks in 2025 (ConnectWise 2026 MSP Threat Report). See phishing and email takeover for the full picture.

Is there a solution built specifically around ransomware?

For ransomware, Cyflare combines endpoint detection and response, validated containment, and the $0 Breach Response Retainer for legal support if it escalates, rather than one tool trying to do all of that on its own. See ransomware protection for how those pieces fit together.

How is the vulnerability exposure solution different from Vulnerability Scanning Services?

For an exposure a client already knows about, Cyflare combines targeted scanning, prioritized remediation guidance, and evidence proving it’s closed, the same capabilities behind Vulnerability Scanning Services, just applied to one known exposure instead of ongoing monitoring. See vulnerability exposure for that scenario.

PARTNER PROGRAM

What MSPs ask before they sign

Why partner with Cyflare instead of building an internal SOC?

Building and staffing an internal SOC runs $2.5M or more a year once you account for 24/7 coverage, tooling, and analyst headcount (Todyl, State of MSP Security Maturity Report 2025). Partnering gets you the SOC, MDR, and compliance evidence without carrying that cost on your own books, so margin holds instead of getting buried in headcount every time the client list grows. See the MSP partner program.

What kind of margins can partners expect?

Cyflare partners run 40%+ margins on average, built for repeatable profitability across the whole book rather than just the first few flagship clients. Pricing scales per-user and per-endpoint, so margin doesn’t erode as you add accounts the way it can with a headcount-based delivery model. Apply to partner.

How long does onboarding take for a new client?

About 30 days from signed agreement to live, using standardized intake and baseline assessment instead of rebuilding the process from scratch for every new client. That means billing can start sooner, and your team isn’t reinventing the onboarding checklist every time. See the partner program.

Do I need my own SOC analysts to be a Cyflare partner?

You don’t need your own SOC analysts to be a Cyflare partner. Cyflare runs 24/7 SOC operations under your brand, which works whether you’re launching your first security offering with no analysts at all or you already have a team and want to extend coverage into nights and weekends without hiring for it. See how it works for MSPs or for resellers.

How many MSPs does Cyflare work with?

Cyflare works with dozens of MSP partners, who together protect over 1,500 client accounts through Cyflare’s platform. That’s a smaller number of partners each running a growing book of clients on the same system, not thousands of one-off relationships. Why partners choose Cyflare.

What happens if something goes wrong on Cyflare's side?

The $500K Service Warranty puts financial accountability into the service itself, not as a marketing line buried in a contract you never reread. It’s shared responsibility built into the agreement up front, so you’re not the only one on the hook if something on Cyflare’s end falls short. Talk to us about the specifics.

COMPLIANCE AND GOVERNANCE

Governance, audits, and proof

What's the difference between prevention and governance in Cyflare's model?

Prevention closes the gaps that turn into incidents, like an unpatched exposure or a misconfigured control, before anything happens. Governance is the audit-ready record of what happened, what was decided, and why, produced after the fact for anything that does. You need both: a tool that only alerts doesn’t produce defensible evidence, and evidence alone doesn’t stop the next incident.

Is Cyflare's own environment CMMC certified?

Yes. Cyflare holds CMMC Level 2 certification with a perfect 110/110 assessment score, verified by a C3PAO and putting Cyflare among roughly 250 organizations worldwide with that certification. That matters because you’re not asking a vendor to help you clear a compliance bar it hasn’t cleared itself.

How does Cyflare help with cyber insurance requirements?

Documented MTTR, audit-ready reporting, and control mapping give clients the specific evidence insurers increasingly ask for before binding or renewing a policy, not just a general assurance that “security is handled.” That matters more every renewal cycle: cyber insurance premiums are projected to rise roughly 15% in 2026, and over 40% of claims get rejected for missing documentation.

What does a data breach cost if a client isn't prepared?

The global average cost of a data breach hit $4.44M in 2025, and U.S. breaches average $10.22M, the highest of any country (IBM Cost of a Data Breach 2025). That number doesn’t include the renewal conversations and reputational damage that follow, which is usually the part that actually costs a provider the relationship. Get the NIST CSF mapping guide to see where the gaps usually are.

Didn't see your question here? Let's talk it through.

Schedule a working session with someone who can answer what’s specific to your book.