ConnectWise and SentinelOne align on MSP cybersecurity strategy

The two vendors have announced a joint strategy to deepen AI-driven managed security capabilities for MSPs, building on their existing Managed EDR partnership.

A towering glass skyscraper with dark, recessed horizontal bands reflects the clear blue sky and other city buildings under bright daylight.

ConnectWise and SentinelOne have announced a shared strategic framework to expand managed cybersecurity services for managed service providers, unveiled at Black Hat 2026 in Las Vegas. The agreement builds on the companies' existing collaboration around ConnectWise Managed EDR with SentinelOne, and is intended to bring deeper integration between SentinelOne's Singularity platform and the operational workflows ConnectWise provides to its MSP partner base.

The joint vision centres on helping MSPs defend against AI-powered threats while deploying AI to automate threat detection, investigation and response. Both companies have stated a commitment to keeping human analysts in control of autonomous workflows, a design principle that has become increasingly important as regulators and enterprise buyers scrutinise where accountability sits in agentic security systems.

What the partnership covers

ConnectWise chief executive Manny Rivelo described the scale of the challenge facing MSPs: "MSPs are being asked to protect more customers, manage greater complexity and respond to threats that move faster than traditional operating models can support." The strategy is framed around six principles, including building on the existing Managed EDR foundation, making security intelligence easier to operationalise across diverse MSP environments, and preserving partner choice through open ecosystems.

SentinelOne president and chief revenue officer Michael Cremen said MSPs are "critical to expanding access to advanced cybersecurity, particularly for organisations that cannot build extensive security operations of their own." The release does not disclose commercial terms, revenue-sharing arrangements, or specific product release dates. Both companies described new capabilities as arriving "in the coming quarters," leaving the timeline deliberately open.

The existing ConnectWise Managed EDR service combines SentinelOne's technology with continuous monitoring from ConnectWise's Security Operations Centre, allowing MSPs to extend endpoint detection and response without having to staff and operate a SOC independently. That model is the starting point for the deeper integration both companies say they are now planning.

Market context

The MSP security market has attracted significant vendor attention over the past three years as threat actors increasingly target MSPs as a route into multiple downstream customers simultaneously. High-profile supply-chain incidents have made the sector a strategic priority for both attackers and vendors seeking distribution scale. ConnectWise claims more than 100,000 IT provider customers globally, making it one of the larger distribution channels for any security vendor willing to build for the MSP operational model.

SentinelOne competes in the endpoint and extended detection and response market against CrowdStrike, Microsoft Defender for Endpoint, and Palo Alto Networks Cortex, among others. The partnership with ConnectWise gives SentinelOne structured access to the mid-market through MSP channels, a segment where per-seat economics and operational simplicity matter as much as raw detection performance. For ConnectWise, tighter SentinelOne integration strengthens its security stack at a time when PSA and RMM platform vendors are under pressure to demonstrate security depth alongside operational tooling.

Regulatory and standards read-across

The announcement's emphasis on human oversight in autonomous threat response aligns with emerging expectations under the EU AI Act, which classifies certain automated decision-making in security contexts as high-risk, requiring meaningful human control. In the UK, the NCSC has published guidance encouraging MSPs to adopt multi-layered detection capabilities and to document escalation procedures for automated actions. US federal procurement guidance under the Cybersecurity Executive Order similarly stresses auditability of AI-assisted security decisions.

Neither company addressed compliance certifications such as SOC 2 Type II or ISO 27001 in the release, though both are established requirements for MSPs serving regulated industries. The next meaningful milestones to watch will be named product releases, published integration roadmaps, and whether the partnership produces co-sold or co-branded service tiers with defined pricing for MSP partners.