Live alertsSource: CISA
OCT 4ExploitedCitrix NetScaler is under active attackCVE-2026-88779. CISA orders federal agencies to patch by Oct 7.OCT 2ExploitedZammad GmbH Zammad is under active attackCVE-2026-102490. CISA orders federal agencies to patch by Oct 5.OCT 2ExploitedZammad GmbH Zammad is under active attackCVE-2026-102489. CISA orders federal agencies to patch by Oct 5.OCT 1AdvisoryCISA MalcolmCISA advisoryOCT 1AdvisoryJohnson Controls EasyIO Neo Series EC and CW ControllersCISA advisoryOCT 1AdvisoryABB Protection and Control IED Manager PCM600CISA advisoryOCT 1AdvisoryArmatura LLC Armatura OneCISA advisoryOCT 1AdvisoryMonta monta.appCISA advisoryOCT 1AdvisoryMeari IoT Cloud Platform OpenAPI ServiceCISA advisoryOCT 1AdvisoryJohnson Controls EasyIO Neo Series EC and CW ControllersCISA advisoryOCT 1ExploitedFortinet FortiMail is under active attackCVE-2026-104286. CISA orders federal agencies to patch by Oct 4.SEP 30ExploitedCisco Catalyst SD-WAN Manager is under active attackCVE-2026-76504. CISA orders federal agencies to patch by Oct 3.SEP 29AdvisoryViidure Dashcam Android ApplicationCISA advisorySEP 29AdvisoryToptech TMS7 and TopHATCISA advisorySEP 29AdvisoryLantronix G520 Series Cellular GatewayCISA advisorySEP 29ExploitedApple Multiple Products is under active attackCVE-2026-86950. CISA orders federal agencies to patch by Oct 2.SEP 27ExploitedCitrix NetScaler is under active attackCVE-2026-88772. CISA orders federal agencies to patch by Sep 30.SEP 27ExploitedCitrix NetScaler is under active attackCVE-2026-88771. CISA orders federal agencies to patch by Sep 30.SEP 25ExploitedMikroTik RouterOS is under active attackCVE-2026-67279. CISA orders federal agencies to patch by Sep 28.SEP 25ExploitedMicrosoft SharePoint is under active attackCVE-2026-65660. CISA orders federal agencies to patch by Sep 28.OCT 4ExploitedCitrix NetScaler is under active attackCVE-2026-88779. CISA orders federal agencies to patch by Oct 7.OCT 2ExploitedZammad GmbH Zammad is under active attackCVE-2026-102490. CISA orders federal agencies to patch by Oct 5.OCT 2ExploitedZammad GmbH Zammad is under active attackCVE-2026-102489. CISA orders federal agencies to patch by Oct 5.OCT 1AdvisoryCISA MalcolmCISA advisoryOCT 1AdvisoryJohnson Controls EasyIO Neo Series EC and CW ControllersCISA advisoryOCT 1AdvisoryABB Protection and Control IED Manager PCM600CISA advisoryOCT 1AdvisoryArmatura LLC Armatura OneCISA advisoryOCT 1AdvisoryMonta monta.appCISA advisoryOCT 1AdvisoryMeari IoT Cloud Platform OpenAPI ServiceCISA advisoryOCT 1AdvisoryJohnson Controls EasyIO Neo Series EC and CW ControllersCISA advisoryOCT 1ExploitedFortinet FortiMail is under active attackCVE-2026-104286. CISA orders federal agencies to patch by Oct 4.SEP 30ExploitedCisco Catalyst SD-WAN Manager is under active attackCVE-2026-76504. CISA orders federal agencies to patch by Oct 3.SEP 29AdvisoryViidure Dashcam Android ApplicationCISA advisorySEP 29AdvisoryToptech TMS7 and TopHATCISA advisorySEP 29AdvisoryLantronix G520 Series Cellular GatewayCISA advisorySEP 29ExploitedApple Multiple Products is under active attackCVE-2026-86950. CISA orders federal agencies to patch by Oct 2.SEP 27ExploitedCitrix NetScaler is under active attackCVE-2026-88772. CISA orders federal agencies to patch by Sep 30.SEP 27ExploitedCitrix NetScaler is under active attackCVE-2026-88771. CISA orders federal agencies to patch by Sep 30.SEP 25ExploitedMikroTik RouterOS is under active attackCVE-2026-67279. CISA orders federal agencies to patch by Sep 28.SEP 25ExploitedMicrosoft SharePoint is under active attackCVE-2026-65660. CISA orders federal agencies to patch by Sep 28.
Tech Signal IQ™ Cascade Assessment Exposure Window Pricing Field Results Request Access Log in
Tech Signal IQ
Market intelligence for managed service providers

Walk in
already
knowing.

Your competitors open with a pitch. You open with a finding — the unpatched edge device, the spoofable domain, the compliance regime the prospect is quietly out of step with. TechMarketIQ™ finds it before the first call.

Passive · nothing touched, nothing probed Evidence · every claim carries a source Named · decision makers, not switchboards
VRELDONXA DENTAL GROUP vreldonxadental .com · 78 employees HOT LEAD CYBERREADINESS 31 /100 EXPOSURE WINDOW CRITICAL 412 DAYS OPEN DRIVING FINDING CVE-2023-4966 · CISA KEV Confirmed exploited in the wild POTENTIAL BUSINESS IMPACT HIPAA HIPAA BREACH FTC 5 SEVERE — civil penalty · notification cost Nrla Vixfeld · Practice Administrator
One lead record · identity withheldSample card, identifying details redacted. Every figure a real card shows is measured or cited — never estimated, inferred from a lookalike, or generated to fill a gap.
0
Packets sent to the prospect. Every finding is externally observable.
5
Exposure bands, from Baseline to Shut
16
Assessment domains · 377 cascading questions
100%
Findings traceable to a named public source

§ 01  The problem with cold

Every MSP is
selling the same
invisible product.

Managed services is a market where the buyer cannot see what they are buying, and cannot see what they are missing. So the pitch collapses into price, logos, and response-time promises that every competitor also makes.

The prospect is not indifferent. They simply have no reason to believe today is different from yesterday. Nothing has visibly broken. Their current provider says everything is fine — and from the inside, it looks fine.

What changes the conversation is not a better pitch. It is a specific, verifiable fact about their business that they did not know — and that their current provider should have caught.

EVERY COMPETITOR "24/7 monitoring." "Enterprise-grade security." "Trusted local partner." RESULT · price comparison YOU CVE-2023-4966 Exposed 412 days. Confirmed exploited in the wild. HIPAA · SEVERE "Your remote-access gateway has been publicly vulnerable since last spring." RESULT · a meeting
The asymmetryOne side is a claim about you. The other is a fact about them.

§ 02  Tech Signal IQ™

The prospect list
that arrives pre-armed.

Tech Signal IQ™ does not hand you companies. It hands you companies plus the reason to call them today — a buying event, a measured security posture, a closing window, and the regulation that turns a technical finding into a board-level problem.

Buying signals
WHEN

A new CIO. An IT job posting. A funding round. A second location. Events that open a window in which budget, authority and urgency briefly line up.

CyberReadiness™
HOW BAD

A 0–100 measurement built from email authentication, transport security, attack surface, software currency and breach history. Measured, never estimated.

Named contacts
WHO

The practice administrator, the operations director, the CFO. The person whose problem this actually is — with the title that proves it.

WIDE SHUT BASELINE ELEVATED HIGH CRITICAL DAY 412 DISCLOSURE TODAY
Exposure Window™The window narrows as attacker tooling matures. A vulnerability public for 412 days on a live perimeter is not a warning about attackers — it is evidence about the operator.

The instrument

How long they have — and what it costs if the window shuts.

Severity scores tell you how bad a vulnerability is in the abstract. They do not tell you how long this company has been carrying it, whether anyone is actually exploiting it, or what it would cost this business specifically.

The Exposure Window does. It bands every prospect by evidence of real-world exploitation, escalates on elapsed time, and pairs the result with the consequence mechanism that applies to their industry.

SHUT Exploitation likely under way EPSS ≥ .50
CRITICAL Confirmed exploited in the wild CISA KEV
HIGH Admin service exposed to the internet OPEN PORT
ELEVATED Spoofable domain · weak transport DNS / TLS
BASELINE No exploitable path found CLEAN

The translation

Turn a technical finding into a regulatory one.

A practice administrator does not lose sleep over an unauthenticated mail domain. They lose sleep over a HIPAA breach notification, a FINRA examination, a CMMC score that costs them a contract.

Potential Business Impact™ maps each finding to the regimes that actually govern that company — by industry, by name — and states the consequence mechanism in the language their regulator uses. Not a loss estimate. A cited ceiling.

  • HealthcareHIPAA Security Rule · Breach Notification · civil penalty, notification cost
  • Financial & advisoryFINRA · SEC Reg S-P · GLBA Safeguards · regulatory examination
  • Defense & aerospaceCMMC 2.0 · ITAR · DFARS · loss of eligibility to bid
  • Legal & professionalABA Model Rule 1.6 · state bar duties · professional discipline
  • Any business taking cardsPCI DSS 4.0 · FTC Act §5 · market access, civil penalty
TECHNICAL FINDING No DMARC enforcement · p=none Anyone can send mail as this domain GOVERNING REGIME HIPAA SECURITY RULE §164.312(e) Transmission security · integrity controls CONSEQUENCE MECHANISM CIVIL PENALTY Enforced by HHS Office for Civil Rights Plus mandatory breach notification cost THE SENTENCE THAT OPENS THE MEETING
Finding → regime → consequenceThe same chain the regulator would walk. Named, not implied.

§ 03  Tech Cascade Assessment™

From first meeting
to signed scope —
without the guesswork.

The signal gets you in the room. The Cascade Assessment is what you run once you are there — a branching discovery instrument that maps the prospect's entire technology estate, then prices it.

Sixteen domains. Three hundred and seventy-seven questions, of which the prospect answers only the ones their earlier answers make relevant. Each response opens the next branch and closes the ones that no longer apply.

  • Cascade gatingAsk only what matters. A prospect with no on-premise servers never sees a server question.
  • Automatic pricingAnswers carry weights. The scope prices itself as the assessment is completed.
  • SOW completenessNothing reaches proposal with an unanswered dependency — the gap that turns a signed deal into a margin leak.
  • Client-completedSend a link. They fill it in. It comes back scored, priced and ready to review.
START ON-PREM SERVERS? NO RACK POWER HYPERVISOR NO ON-PREM → 14 QUESTIONS SKIPPED CLOUD M365 TENANTS MFA COVERAGE BACKUP RETENTION · RPO SCOPE PRICED · SOW COMPLETE DOMAINS COVERED 16 / 16 ONE ANSWER OPENS THE NEXT BRANCH — AND PRICES IT
Branch, gate, priceWatch the run: each answer opens the next branch and closes the dead ones — the NO branch takes fourteen irrelevant questions with it, and the scope prices itself on arrival.

§ 04  In the field

What winning
looks like.

Two patterns come up again and again: the door that opens because you knew something, and the incumbent who loses the account because you showed what they had been missing.

Pattern 01 · The door opener

A dental group that had ignored four MSPs

A 78-employee multi-site dental practice. Every MSP in the metro had called them. The practice administrator had a standing answer: "We're happy with our provider."

01
Signal

Job posting for an IT coordinator — first internal IT hire in six years.

02
Scan

Remote-access gateway on a version disclosed 412 days earlier. Listed in CISA KEV.

03
Translate

Patient records behind that gateway. HIPAA Security Rule. Civil penalty plus notification cost.

04
Open

One sentence naming the finding, the duration, and the regime.

Outcome

The fifth call was not a pitch. It was a disclosure. The administrator forwarded it to the managing partner within the hour, because it had stopped being an IT question the moment HIPAA was named — and what followed is a meeting the incumbent was never invited to.

Pattern 02 · The displacement

Taking an account from the incumbent MSP

A regional accounting firm, two years into a contract with a competitor. Renewal eight weeks out. No complaints on file — because nothing had visibly failed.

01
Measure

CyberReadiness 34/100. Domain fully spoofable — no DMARC enforcement at all.

02
Date it

Weak transport and an exposed admin service, both unchanged across repeat scans.

03
Frame

Not "your MSP is bad" — "here is what has been publicly visible the whole time."

04
Assess

Cascade Assessment run in the meeting. Scope and price on the table same week.

Outcome

The partners did not need to be told their provider was underperforming. They needed one externally verifiable fact that contradicted the reassurance they had been given for two years. The trend line across repeat scans — flat, unchanged, unattended — did the rest.

ILLUSTRATIVE · These are representative patterns showing how the intelligence is used in the field, not named customer accounts. Company details are composite. Findings, bands and regimes shown are the real outputs the platform produces.


§ 05  Why it holds up in the room

Nothing fabricated
EVIDENCE

If a source cannot be confirmed, the platform reports unknown — never a plausible guess. A finding you cannot defend in the meeting is worse than no finding at all, so the pipeline is built to withhold rather than fill.

Nothing intrusive
PASSIVE

Every measurement comes from what the prospect already publishes to the internet — DNS, certificates, headers, disclosed vulnerabilities, public breach records. No scanning of their systems. No packets they did not invite.

Request access

Stop opening with
a pitch.

TechMarketIQ™ is provisioned per firm, with your own workspace, your own pipeline and your own scan history. Tell us the territory and the verticals you sell into, and we will show you who needs your services.