
The global managed-security-services market sits at $38-40 billion in 2026, with Omdia, Gartner, and IDC forecasts converging on $66-94 billion by 2030. The growth is real. The growth is also non-uniform. The MSP value-capture model that worked in 2022 will not work in 2028, and the MSP that does not restructure its pricing in 2026-2027 will be priced out by the MSP that does.
Cognizant signalled the shift in May 2026 with Project Leap, a $270 million programme that includes layoffs of up to 15,000 jobs in an AI-operating-model restructuring. WatchGuard launched Rai, an agentic-AI digital workforce purpose-built for MSPs to scale managed-security delivery without scaling headcount. The MSP industry's labour structure is repricing itself in real time.
For the Indian buyer of managed services, the implication is direct. The procurement question is no longer "what is my MSP's per-FTE rate." The procurement question is "what outcomes is my MSP committing to deliver, what is the operating model that delivers them, and what is the pricing model that aligns my MSP's incentives with my outcomes."
But first, some catch-up on infra this week.
🔍 FTE Pricing, Outcome Pricing, and the Agentic-MSP Question
The managed-services pricing conversation has lived inside three frames for the last decade.

FTE pricing is finishing.
FTE pricing is the model most Indian managed-services contracts still run on. The buyer pays for a certain number of full-time equivalents at a defined rate, with deliverables described in the statement of work. The MSP's revenue scales with the number of people it deploys. The MSP's profit scales with the gap between billing rate and salary cost.
The model worked when the MSP's deliverable was scarce labour. It is finishing because the deliverable is no longer scarce labour. The agentic-AI tooling that WatchGuard, Microsoft, ServiceNow, and the major Indian SIs are deploying allows a single human analyst to cover the workload that previously needed five. The buyer paying for five FTEs is paying for capacity that the MSP no longer needs to deploy. The MSP that does not pass the savings through is being progressively repriced by competitors who do.
Outcome pricing is the model the better MSPs are migrating to. The buyer pays for defined outcomes, with the MSP free to choose the operating model. Examples: a fixed monthly fee for "all critical-severity incidents triaged within 30 minutes, with documented response artefacts," or a per-transaction fee for "every CERT-In notification produced within the 6-hour window with documented chain-of-custody," or a per-endpoint fee for "every endpoint covered by the agreed XDR posture with monthly verification reporting."
The outcome-pricing model puts the operational efficiency on the MSP, where it belongs. If the MSP can deliver the outcome with two FTEs instead of five, the MSP keeps the savings. If the MSP cannot, the MSP loses the contract. The buyer's incentive is aligned with the outcome the buyer wants, not with the labour cost the buyer used to underwrite.
Agentic-MSP delivery is the model that the next 24-36 months will normalise. The MSP runs agentic-AI tooling that handles the bulk of the alert triage, the incident-response runbook execution, the documentation generation, and the reporting-artefact production. The human analysts focus on the exceptions, the strategic-advisory work, and the customer-relationship layer. The MSP's labour structure looks different from the 2022 model: fewer L1 analysts, fewer L2 escalation engineers, more L3 senior architects, more agent-tuning specialists.
The Indian MSP segment is structurally well-positioned for this shift, but only if the pricing model migrates with the operating-model change. The MSP that keeps FTE pricing and adopts agentic delivery is keeping the customer-billing model from 2022 while paying for the operating model of 2028. That gap is short-term margin expansion and medium-term competitive vulnerability.
For the Indian buyer evaluating an MSP renewal in 2026-2027:
✔ Ask the MSP how its pricing model will evolve over the contract term. The 5-year contract signed under FTE pricing will be a procurement-side disadvantage by year 3.
✔ Document the outcomes the MSP is committing to, with measurable verification artefacts.
✔ Validate the MSP's agentic-AI delivery readiness. The agentic-MSP story is real; the agentic-MSP delivery is uneven across vendors.
✔ Negotiate the operational handoff between MSP-delivered agentic capability and customer-side human oversight. Governance does not delegate cleanly.
How we plug in: Our Complete IT Infrastructure Solution practice runs the MSP-evaluation work for Indian BFSI, manufacturing, pharma, and textile buyers. We sit on the buyer side of the renegotiation, with the pricing-model evolution as the centre of the procurement memo. The vendor's sales team leads with FTE rates. The buyer's procurement team needs to read the outcome-pricing alternative.
🔐 Cognizant Project Leap, WatchGuard Rai, and the Operating-Model Repricing
Two May 2026 announcements signal the direction of travel for the broader MSP-services market.

The labour model is repricing.
Cognizant Project Leap allocates $270 million for a workforce restructuring that may include layoffs of up to 15,000 jobs. The reframe is explicit: Cognizant is rebuilding its operating model around AI-augmented delivery, with the labour structure changing to match. The signal for Indian-IT-services buyers is unambiguous. Even the largest, most diversified Indian SI is restructuring its labour pool in anticipation of an operating model where agentic delivery handles the bulk of the alert-triage-and-runbook work that L1 and L2 analysts used to do.
For the BFSI or manufacturing buyer running a managed-services contract with Cognizant, TCS, Wipro, Infosys, or HCL, the procurement-side implication is sharper than the announcement reads. The MSP's revenue model has to change because the MSP's cost model is changing. The buyer either renegotiates now to lock in the labour-rate efficiencies the MSP will be passing through within 18 months, or the buyer signs the renewal at 2022 pricing for an operating model that does not need 2022 labour intensity.
WatchGuard Rai is the platform-side parallel. WatchGuard launched Rai as an agentic-AI digital workforce purpose-built for MSPs to scale managed-security delivery. The pitch: an MSP running Rai can cover more customers, deliver faster response times, and produce better documentation, with fewer human analysts. The implication for the buyer: the MSP's effective per-customer cost goes down. The MSP that passes the savings through expands market share. The MSP that does not pass them through is competed away.
Outcomes are the new line items.
For the Indian buyer evaluating two MSP RFPs in 2026-2027, the questions to ask:
👉 What is your agentic-delivery readiness, by service line? "We have AI" is not an answer. "Our SOC L1 triage runs on agentic tooling that handles 70 percent of incidents end-to-end, with the remainder escalated to human L2 within 5 minutes" is an answer.
👉 What is your per-customer labour profile today, and what is it forecast to be in 2028? The MSP that cannot answer is the MSP that has not budgeted for the operating-model change.
👉 What is your pricing-model commitment for the contract term? Specifically, will the per-FTE rate move down if your effective labour intensity goes down? The MSP that refuses is the MSP whose customers will renegotiate later.
The MSP industry is mid-restructuring. The Indian buyer who signs a 5-year contract in 2026 with the wrong MSP at the wrong pricing model is locking in inefficiency. The buyer who signs the right contract with the right MSP at the right pricing model is locking in advantage.
How we plug in: Our Cyberdefense practice sits on the buyer side of MSSP renegotiations for Indian BFSI, manufacturing, pharma, and textile clients. We have helped buyers migrate from FTE-pricing contracts to outcome-pricing contracts, with the documented verification artefacts that satisfy the audit committee. The vendor's commercial team will defend the existing model. The buyer's procurement memo needs the alternative.
📌 The Indian MSP Landscape: SI Scale, MSSP Specialisation, and the Hybrid Model
Indian managed services has a structural advantage that does not translate cleanly to global pricing comparisons.
The Indian SI / MSSP / channel ecosystem includes the global-scale Indian SIs (TCS, Wipro, Infosys, HCL, Cognizant), the mid-tier Indian MSSPs (eSec Forte, Microland, Wipro CSI), the specialised security boutiques (Lucideus, Kratikal, Niki.ai for AI-augmented offerings), and the regional channel partners running managed-services delivery across Tier-2 and Tier-3 city presence. The Indian buyer evaluating managed services has shortlist options that the global buyer evaluating the same RFP does not.
The hybrid model is increasingly common in 2026: a global vendor as the underlying detection-platform (Microsoft Defender, CrowdStrike Falcon, Palo Alto Cortex), an Indian SI as the contract-counterparty and operational-relationship owner, and the regional channel partner for Tier-2 / Tier-3 city physical-presence work. Three layers, three contracts, with the buyer running the integration in the middle.
For the Indian BFSI or manufacturing buyer, the hybrid model has procurement-side advantages worth naming:
✔ The Indian-resident contract counterparty satisfies DPDP data-residency expectations and CERT-In incident-reporting workflows in ways that a single global vendor cannot.
✔ The Indian SI's labour-rate advantage is real, even with the agentic-delivery repricing in progress. Global SIs charge higher rates for the same scope; the Indian SI's pricing advantage is a structural sector benefit that the buyer should preserve.
✔ The regional channel partner's physical presence is the only realistic operational model for a 5,000-branch banking estate or a 200-plant pharmaceutical manufacturer. The global vendor cannot deliver branch-physical-work; the Indian channel partner can.
The trade-off worth naming: the hybrid model means the buyer is running three vendor relationships rather than one. The operational complexity is real. The buyer's internal IT-procurement capacity has to be able to manage the multi-vendor coordination, or the cost savings disappear into integration overhead.
How we plug in: Our Complete IT Infrastructure Solution practice has run the hybrid MSP-model evaluation for Indian buyers for thirty-five years. We sit on the buyer side of TCS, Wipro, Cognizant, eSec Forte, Microland, and regional-channel RFPs. The vendor-stack architecture is the procurement decision. The integration discipline above it is the operating decision.
📋 The Compliance Layer: CERT-In, RBI, and What an MSP Has to Document
The compliance side of managed-services delivery in Indian BFSI tightened progressively from 2022 through 2026.
The MSP delivering managed-security services to an Indian bank now has documented responsibilities that did not exist in the 2022 contract. The CERT-In 6-hour reporting clock applies to the MSP's detection layer. The RBI Master Directions apply to the MSP's backup-and-recovery posture. The DPDP framework applies to the MSP's data-handling of employee and customer information. The April 2026 RBI authentication mandate applies to the MSP's API-security delivery for the buyer's digital-payments stack.
For the Indian BFSI buyer drafting the 2026-2027 MSP RFP, three compliance-layer contract clauses worth getting right:
👉 What is the MSP's documented incident-reporting workflow for CERT-In notifications, with reference customers who have actually executed it during a real incident?
👉 What is the MSP's data-residency posture for the operational telemetry it collects from the customer's environment? Is the data Indian-resident, and is the contract clause specific about retention and destruction?
👉 What is the MSP's sub-processor disclosure for any portion of the delivery that touches a non-Indian-resident operator? Even if the MSP is Indian, sub-contracted offshore delivery has DPDP exposure.
The compliance layer is not a side conversation. It is increasingly the centre of the procurement memo for any regulated Indian buyer.
There is a fourth question that procurement memos still tend to skip: what is the MSP's liability posture if its agentic-AI tooling produces a documentation artefact that the regulator later finds inadequate? Agentic-delivery is fast and consistent, but it can also be confidently wrong. The MSP that signs a contract committing to agentic-generated reporting artefacts has to also commit to the liability that goes with them. The buyer that does not negotiate the liability allocation before the contract is signed is the buyer that discovers the gap during the next regulator review. The Indian MSP industry has not yet standardised the liability-clause language for agentic delivery, which means the early-adopting buyers are negotiating each clause individually. The buyer that uses a competent procurement counsel here gets a materially better contract than the buyer that does not.
How we plug in: Our Cyberdefense practice reads the compliance-layer contract clauses for Indian BFSI MSP RFPs. We have built the documentation discipline that satisfies both the buyer's audit committee and the regulator's review.
🔍 Links We Liked This Week
Cognizant Project Leap $270M plan
CRN.
The primary-coverage read on the Cognizant restructuring. Useful for the Indian-IT-services-workforce frame.
Channel Brief: AI Is Forcing the MSP Model to Grow Up
ChannelE2E.
The MSP-industry-side read on the operating-model transition. Read alongside WatchGuard Rai coverage for the vendor-side parallel.
MSPs Get AI Workforce to Scale Managed Security
ChannelE2E.
The WatchGuard Rai launch primary source. Useful for the procurement-side framing of the agentic-MSP question.
Omdia: Managed Security Services Revenue $106B by 2026
Omdia.
The market-sizing data behind the MSSP growth trajectory. Pair with Gartner and IDC for triangulation.
5 Things MSPs Should Know Before Adopting EDR
ChannelE2E.
The MSP-side primer on EDR/MDR delivery for buyers. Useful when negotiating the operational handoff with the MSP.
💡 My Take
For most of the last decade, the Indian managed-services market grew on the strength of one structural advantage: labour-cost arbitrage.
The Indian SI could deliver the same scope at a fraction of the global SI's price because the Indian labour pool was larger, lower-cost, and English-speaking. The model worked. The model scaled the Indian IT services industry to a $200-billion sector. The model is finishing.
Labour arbitrage is closing.
Agentic-AI delivery is the technology change. WatchGuard Rai is one example; Microsoft, ServiceNow, IBM, and the major Indian SIs are running parallel investments. The economic logic is unambiguous. The MSP that delivers a given scope with one agentic-AI-augmented analyst captures the margin that the MSP delivering the same scope with five FTEs cannot. The buyer that pays for five FTEs is paying for the old model.
The MSP industry's response is the operating-model restructuring. Cognizant's Project Leap is the most visible. Quietly, every major Indian SI is running parallel programmes. The labour pool that built the Indian IT services sector is being reshaped from L1-and-L2 alert triage into L3-architecture, agent-tuning, and customer-advisory roles. The transition will take 24-48 months. The MSPs that emerge on the other side will look structurally different from the MSPs of 2022.
For the Indian buyer of managed services, the procurement question for 2026-2027 is not "what is my MSP's per-FTE rate."
The procurement question is "what outcomes is my MSP committing to deliver, what is the operating model that delivers them, what is the pricing model that aligns my MSP's incentives with my outcomes, and what is the compliance documentation discipline that satisfies the regulator without depending on labour intensity that is going to be repriced anyway."
Once that question has an answer, the MSP shortlist follows. The pricing-model decision follows. The contract-term decision follows. The audit-committee narrative follows.
VEMIO™ exists because the operational reality of running a managed-services-augmented IT estate needs an observability layer that the MSP's own tooling does not provide. The MSP reports that the SLA was met. The buyer's audit committee needs to see the customer-side measurement of whether the SLA was met, the agentic-delivery audit trail, the human-analyst escalation timestamps, the compliance-documentation artefacts, and the contract-clause verification record. All in one operator view, independent of the MSP's own platform.
The next 18 months are the procurement window where the difference between the right decision and the wrong decision is large enough to matter. The contracts being signed today will run through the operating-model transition. The buyer that gets the pricing model right at signing is buying a structural advantage; the buyer that does not is buying a structural disadvantage at the same nominal cost.
The Indian MSP that prices on FTE will be priced out by the Indian MSP that prices on outcomes.
Reply to this email with the one MSP-contract clause you are revisiting this quarter, and we will feature the most operationally interesting reply (anonymised, with consent) next issue.
Until next time,
Ajay Salvi & the Vinay Enterprises team.
