How to sell a cybersecurity company or MSSP, and what it can license separately
To sell a cybersecurity company or MSSP, document recurring revenue, client contracts, analyst retention, the security tool stack and the firm's own security record, then separate client telemetry from the firm's own records. Client logs, alerts and reports stay out of any data license; the firm's own runbooks, triage guides and internal tickets may be licensable to AI buyers.
What buyers check when a cybersecurity firm or MSSP is sold
Buyers of a cybersecurity services firm, whether a managed security service provider (MSSP), a managed detection and response (MDR) shop or a penetration testing consultancy, focus on the quality of recurring revenue, the stability of the analyst bench and the firm's own security record. An advisor who can show those clearly, along with a clean line between client data and the firm's own records, gives buyers fewer reasons to discount.
| Buyer question | What to prepare | Why it matters in a security deal |
|---|---|---|
| How much revenue recurs? | Managed services versus project revenue (pentests, incident response retainers, assessments) by year | Contracted monitoring revenue is valued differently from one-off projects |
| Who are the clients? | Revenue by client, contract terms, renewal history, regulated-sector exposure | Concentration and termination rights drive risk |
| Can the bench stay? | Analyst headcount, tenure, certifications, clearances, retention agreements | Experienced analysts are the delivery engine |
| What runs the SOC? | SIEM, SOAR, EDR and ticketing stack; vendor partner agreements | Tool contracts may not assign to a buyer |
| Is the firm itself secure? | Its own audit reports, incident history, insurance claims | A breach at a security provider is a reputational event |
| What does the firm own? | Detection content, runbooks, methodology, internal tooling, training material | Separates firm IP from client data |
The last row is where many sale processes stay vague, and it is also the row that decides whether a separate data license is possible.
Client telemetry versus the firm's own records
For most security firms the dividing line is simple: client telemetry belongs to the client and stays out. Logs, alerts, endpoint events, vulnerability scans, pentest findings and forensic images originate in client environments and are governed by client contracts. What a security firm may be able to license is what its own people wrote about how to do the work.
| Record | Whose it is | In scope for a data license? |
|---|---|---|
| SIEM logs, EDR telemetry and alerts from client environments | Client | No |
| Pentest and assessment reports delivered to clients | Client, usually under the statement of work | No |
| Incident response evidence and forensic images | Client | No |
| Detection rules, correlation logic and tuning notes the firm wrote | Firm, if written by employees | Possibly, after a review of vendor and client terms |
| Triage runbooks, escalation playbooks and analyst decision guides | Firm | Often, after removing client references |
| Internal tickets for the firm's own IT, HR and operations | Firm | Often |
| Analyst onboarding curricula, tabletop exercise templates, shift handover templates | Firm | Often |
| PSA service tickets and time entries | Mixed: the firm's operating record, often describing client systems | Only the separable parts, after redaction |
Ownership of the firm's own material also depends on who wrote it. According to the U.S. Copyright Office, a work prepared by an employee within the scope of employment is a work made for hire owned by the employer, while commissioned work from an outside contributor counts as work made for hire only in listed categories and only with a signed written agreement (Copyright Office Circular 30). Firms that rely on contract analysts or subcontracted SOC coverage should check whether those contributors assigned their work in writing.
This is general information, not legal, tax or financial advice. Confirm ownership questions with the firm's own counsel before anything is scoped.
The telemetry line test
Put each candidate record set through three questions. A set that fails any one of them stays out.
- Origin: did the firm's own people create it to describe the firm's own methods, rather than generating it in or copying it from a client environment?
- Authorship: were the authors employees, or contractors who assigned their work to the firm in writing?
- Separation: can client names, IP addresses, hostnames, credentials and client-specific indicators be removed without destroying the record's meaning?
Playbooks and runbooks usually pass. Ticket histories pass in part. Raw client data fails unless the client consents in writing, and few security clients will want their telemetry used anywhere else.
Which security firms fit
The firm needs 50+ full-time employees at peak (contractors excluded), several years of documented operations, clear rights to what it would license, and a sponsor such as the owner, CEO, CFO or another authorized representative. Within that baseline, fit depends on the business model.
| Firm type | Own records with the most value | Main caution |
|---|---|---|
| MSSP and MDR providers | Triage runbooks, escalation decisions, shift handovers, detection tuning history | Ticket bodies often quote client telemetry |
| Penetration testing and red team consultancies | Methodology documents, test plans, internal tooling notes, report templates | Findings and reports belong to clients |
| Incident response firms | Response playbooks, engagement checklists, lessons-learned templates | Case files are client evidence |
| Governance, risk and compliance consultancies | Control mapping frameworks, policy templates, audit preparation workflows | Client policies and audit evidence are client property |
| Security resellers with a services arm | Deployment runbooks, configuration standards, professional services tickets | Vendor license terms on product content |
Security firms that grew out of IT services often run the same professional services automation (PSA) tools as MSPs, so the guide to Autotask PSA records in an MSP sale or data license is a useful reference for how ticket histories are structured. Firms that build their own detection platforms face the code ownership questions covered in selling a software development company.
Where a license fits in a security firm sale
| Moment | Why it matters | Advisor action |
|---|---|---|
| Before going to market | The records inventory doubles as IP diligence preparation | Run the telemetry line test with the CTO or SOC lead |
| Tool consolidation in a roll-up | Old SIEM or ticketing platforms are retired after an add-on | Confirm exports of the firm's own records before cutover |
| After an LOI | Exclusivity and conduct-of-business terms may restrict new contracts | Ask deal counsel before anything is signed |
| Wind-down or failed sale | Systems and staff disappear quickly | Preserve exports; see licensing data from a wound-down company |
Answering the founder's security questions
Security founders ask harder questions than most owners, and they should. The process keeps the firm in control at each stage:
- The advisor introduces the firm through a referral link or the referral form and passes along basic fit information only.
- SourceX qualifies the firm on headcount, history, breadth of records and rights.
- The firm inventories its systems, how far back each one goes and what can be exported.
- De-identification and redaction requirements are agreed before any work begins, and the firm decides the scope.
- Price and terms are agreed, then AI labs and data buyers review the opportunity.
- Nothing is delivered until the agreement is executed and the firm authorizes delivery; the firm then receives a one-time payment.
Nobody outside the firm touches client environments at any point, and the introducer never sees any records.
What to say to a security firm owner
How rewards work, and when to pass
M&A advisors and other partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company, payable only after the buyer pays and SourceX receives its fee. No reward is guaranteed, and it comes out of SourceX's fee rather than the firm's payment. Read your own engagement terms and any professional rules on referral compensation before accepting one.
Pass on the introduction when:
- Almost everything of value is client telemetry or client deliverables.
- Runbooks were written mostly by contractors with no written assignment.
- Peak headcount stayed below 50 full-time employees.
- Client contracts prohibit any secondary use of material related to the engagement.
- The firm's own material has already been licensed for AI training.
Next step
Get a preliminary read with the company fit checker and compare it with who qualifies. If the firm passes, register as a partner and make the introduction, or have the owner apply at sourcex.si/apply with your referral link.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Can an MSSP license anonymized alert data from its clients?
Treat it as out of scope. Alert data originates in client environments and is governed by client contracts, so anonymizing it does not give the MSSP a right to license it. A client could in principle consent in writing, but security clients rarely want their telemetry used anywhere else. The firm's own runbooks, triage guides and internal tickets are the cleaner pool to work with.
Do runbooks written by contract analysts belong to the firm?
Not automatically. Material an employee writes within the scope of the job is generally owned by the employer, but work from outside contractors belongs to the firm only if the contractor assigned it in writing or it falls within the narrow work-made-for-hire categories with a signed agreement. Check contractor agreements before including their runbooks, and ask the firm's counsel to confirm.
Would licensing our playbooks hand our methods to competitors?
The license is granted for AI training under terms the firm approves, and deals are typically exclusive for AI training for an agreed term. The firm sets the scope and the redaction rules before work starts, so anything it treats as a trade secret, such as proprietary detection logic, can be left out entirely. Nothing is binding until the firm signs the agreement.
Can a license close before the security firm's sale signs?
Yes, if the firm wants it to. Closing first means buyers can review a signed, documented agreement rather than an open negotiation. Once an LOI with exclusivity is signed, new contracts may need the bidder's consent, so the advisor should coordinate with deal counsel. A license can also wait until after closing, in which case the new owner makes the decision.
Does a boutique penetration testing firm qualify?
Only if it has 50+ full-time employees at peak (contractors excluded) and several years of documented operations. A boutique that relies on contract testers may fall below that baseline and may also face ownership questions over its methodology documents. A larger consultancy with employed testers, written methodologies and years of internal records is a stronger candidate.
Related pages
- Autotask PSA data export: ticket and project history in an MSP sale or license
- How to sell a software development company, and what you actually own
- Licensing data from a wound-down company
- Referral opportunities for M&A advisors
- Check Company Fit for Data Licensing
- Which US businesses are a fit for a SourceX data licensing introduction
Free resources
- Client data licensing eligibility checker — A transparent preliminary screen for one company.
- Enterprise value calculator — Enterprise value from equity value, debt and cash.
- Earnout scenario calculator — Probability-weighted earnout value and its present value.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment