August 5, 2025

Why the fall of Adarma signals the rise of cloud native, API-driven MDR

The fall of SOC provider, Adarma, plus the rise of Hornetsecurity is more than business news; it signals a major leap in cyber security

Navigating the Evolution of Cybersecurity: The Fall of Adarma and the Rise of cloud-native, API-driven MDR

The UK cybersecurity landscape has recently witnessed significant shifts. Adarma, a prominent SOC provider, has entered into liquidation. Simultaneously, Hornetsecurity, a German SaaS security company, was acquired by Proofpoint for approximately $1 billion. These events, though seemingly disparate, highlight a clear trend in the cybersecurity industry as clients jump towards scalable, automation-driven SaaS solutions.

The Downfall of Adarma: A Sign of the Times

Adarma's downfall was prefaced by several indicators of trouble:

·     Leadership changes

·     Financial instability rumours

·     A decreasing number of projects

Historically, Adarma was known for its bespoke, Splunk-intensive SOC services tailored to major UK banks and public sector clients. This model was effective in 2018 but did not align with the rapid onboarding, predictable pricing, and quick value realisation that clients seek today. Unfortunately, Adarma's inability to adapt promptly to these market shifts led to its decline.

Hornetsecurity: A Beacon of Scalability and Innovation

In stark contrast to Adarma, Hornetsecurity has excelled by adopting a SaaS model from the outset, focusing on Microsoft 365 protection, email security, backups, archiving, and awareness training. The company’s design for multi-tenancy and scalability allowed it to serve MSPs and SMBs effectively, achieving year-on-year growth of over 20%.

 

Proofpoint's acquisition of Hornetsecurity underscores the value and potential profitability of SaaS enterprises in the cybersecurity realm. Such companies successfully tackle significant industry challenges without the need for extensive manpower increases or operational complexities.

 

The SaaS Paradigm Shift

Today, CISOs and IT leaders value solutions that offer:

 

·     Less friction

·     Increased automation

·     Direct outcomes rather than operational hassles

 

Rapid7's Managed Detection and Response (MDR) is a prime example of the cybersecurity market’s direction, and ITHQ’s recommended CTEM solution (over 11,000 businesses across the world rely on Rapid7's exceptional MDR. For complex deployments, we offer an extended service, MDR-X - ensuring projects with requirements that fall beyond typical SLAs are deployed to the highest standards.)

As a SaaS-delivered, agent-based service backed by a global 24/7 SOC, MDR allows companies to become operational within 30 days without the burden of managing their own SIEM systems and includes built-in incident triage and response capabilities.

In contrast to the traditional, tailored engagement models with complex logistics, Rapid7 is simple and efficient. The need for extensive infrastructure is eliminated and setup complexity reduced, making it a preferred choice for modern businesses.

 

Predictability is the New Benchmark

In many SOC environments, financial unpredictability due to ingestion-based pricing leads to significant cost management challenges. Services like Splunk (now part of Cisco) and Microsoft Sentinel often result in unexpected expenses due to their data ingestion and storage pricing models. Rapid7 InsightIDR, however, offers a predictable, flat monthly rate per endpoint or user, ensuring full visibility without unforeseen costs.

 

Strategic Implications for Security Leaders

For organisations continuing to utilise traditional MSSPs, it is crucial to reconsider several aspects:

·     Whether these providers can scale and deliver quick outcomes effectively

·     Their compatibility with modern, cloud-first approaches

·     The overall cost-effectiveness, especially concerning data visibility.

 

SaaS models such as Hornetsecurity and Rapid7 not only prove the scalability and profitability of streamlined, less resource-intensive solutions but also reflect a broader shift within the industry towards services that are agile and efficient.

 

End note …

The cybersecurity services market is rapidly evolving. Businesses today demand solutions that are cloud-native, API-driven, and capable of supporting multiple tenants with minimal complexity. The future favours those who can pivot to meet these emerging needs, while those unable to adapt are likely to falter.

Lastest blog posts

View all posts
August 5, 2025
Cyber Resilence
Why the fall of Adarma signals the rise of cloud native, API-driven MDR

The fall of SOC provider, Adarma, plus the rise of Hornetsecurity is more than business news; it signals a major leap in cyber security

Read On
July 15, 2025
Cyber Resilence
Shadow IT: The Perils of Invisible SaaS

Which platforms are your teams using everyday that you don't know about? You can't secure or measure what you can't see ...

Read On
July 10, 2025
Cyber Resilence
6 Reasons Why Embracing DORA is a Smart Move for All Businesses

David Thomas, Head of Cyber Resilience at ITHQ, shares why DORA doesn't have to be exclusive to the financial sector

Read On

Want to know more? Let's talk.

Contact Us