Biggest MSP Challenge Isn’t Security—It’s Capacity: Cavelo Exec
The ability to prioritize where to focus the efforts of limited staff on addressing cyber risk is a massive struggle in the MSP sector right now, says Cavelo’s Larry Meador.
The major struggle for MSPs in 2026 is less about how to address security risks with technology and more about how to prioritize where to focus the efforts of limited staff on addressing cyber risk, according to Cavelo Channel Chief Larry Meador.
“The new MSP challenge isn’t security—it’s capacity,” Meador said during a session Monday at XChange August 2026, which is hosted by CRN parent The Channel Company and being held this week in National Harbor, Md.
[Related: 10 Hot Security Products For MSPs In 2026]
“Don’t get me wrong, security is still hard. We know that,” he said. “But the new constraint facing most of you is capacity. Because every MSP that we speak with is being asked to deliver more—more clients, more exposure, more proof.”
And with each new client that the MSP adds, that brings more security findings, reports and follow-up work, Meador said.
Meanwhile, customers increasingly are expecting evidence that their cyber risk is being decreased, he noted.
“It’s no longer enough to just tell a client that you’ve got tools that are protecting them,” Meador said. “They want and they need to see evidence that their risk is actually going down.”
At the same time, the work of prioritizing efforts around security remediation has continued to depend heavily on staffing, which is frequently in short supply, he said.
Without a doubt, analysts are already overwhelmed by the work of reviewing log files and determining whether findings are actionable, false positives, standard alerts or new vulnerabilities, according to Donald Monistere, president and CEO of Baton Rouge, La.-based General Informatics.
“There’s a lot of moving parts. And being able to pull that in and look at it very quickly and very easily is pretty helpful,” said Monistere, whose firm is evaluating Cavelo alongside other vulnerability management tools.
There’s no question that there is a major gap right now between identifying a problem and having the resources to resolve it, he said.
For instance, during an assessment for a customer, General Informatics went through and thoroughly documented the organization’s vulnerabilities—only to later find out that the customer didn’t have the budget or the staffing necessary to fix the issues, Monistere said.
“‘My IT team can’t take the time—we’re just trying to keep the lights on,’” Monistere recalled being told by the company.
The experience was eye-opening, he said, and underscored why tools that help to prioritize and make the most of constrained staffing can be so pivotal in security.
The ideal would be “finding a way for them to utilize toolsets that can help with that whole capacity conversation,” Monistere said. “Addressing capacity would definitely be a plus.”
Cavelo is aiming to help alleviate such bottlenecks with capabilities such as Cora, its AI security analyst embedded within its platform, Meador said.
Cora is aimed at presenting IT and security teams with a prioritized view of what to fix and how to fix it, he said.
Cora “helps analyze, prioritize, guide the work today,” Meador said. In the future, however, Cora is “going to help perform more of that work.”