Competition Law And Managed Security Services Competition .

Competition Law and Managed Security Services Competition

1. Introduction

Managed Security Services (MSS) are cybersecurity services supplied by specialised providers that monitor, detect, prevent, investigate, and respond to cyber threats on behalf of customers. Typical services include:

  • Security Operations Centre (SOC) monitoring;
  • Managed Detection and Response (MDR);
  • endpoint detection and response;
  • managed firewalls;
  • intrusion detection and prevention;
  • cloud-security monitoring;
  • identity and access management;
  • vulnerability management;
  • threat intelligence;
  • incident response; and
  • Security Information and Event Management (SIEM).

Competition law becomes important because MSS markets can exhibit high switching costs, network and data advantages, interoperability barriers, vertical integration, bundling, exclusive arrangements, and concentration around major cloud, telecommunications, enterprise-software, and cybersecurity providers.

The central competition-law question is whether security providers compete on the merits or whether control over infrastructure, data, software ecosystems, technical standards, or distribution channels is used to restrict competing MSS providers.

2. Relevant Competition-Law Issues

A. Definition of the Relevant Market

The first issue is determining what constitutes the relevant product market.

Possible market definitions include:

  1. MSS generally;
  2. managed SOC services;
  3. MDR services;
  4. managed endpoint-security services;
  5. cloud-security services;
  6. managed firewall services;
  7. SIEM services;
  8. cybersecurity services for particular sectors; or
  9. integrated enterprise cybersecurity platforms.

A broad market definition may include several cybersecurity products because customers can purchase integrated packages.

A narrower market may be justified where:

  • customers require specialised expertise;
  • MSS providers use dedicated technology;
  • switching between services is difficult;
  • regulatory requirements require specialised providers;
  • service levels differ substantially; or
  • customers cannot easily substitute one cybersecurity service for another.

Geographic market

The geographic market may be:

  • local;
  • national;
  • regional; or
  • global.

Cybersecurity services can be supplied remotely, but data-localisation rules, national-security requirements, procurement restrictions, language, regulatory certification and incident-response requirements may make competition substantially more local.

3. Market Power in MSS

Market power may arise from several sources.

1. Customer data

An MSS provider receives enormous quantities of:

  • logs;
  • network traffic;
  • endpoint telemetry;
  • authentication information;
  • threat indicators;
  • behavioural data; and
  • historical incident information.

Long-term accumulation of this data can improve detection models and threat intelligence.

This can produce a data advantage over smaller competitors.

2. Switching costs

A customer changing MSS providers may need to:

  • migrate security policies;
  • integrate new monitoring systems;
  • retrain employees;
  • transfer historical logs;
  • reconnect APIs;
  • replace security agents;
  • renegotiate incident-response procedures; and
  • conduct extensive security testing.

Consequently, even a technically superior competitor may find customer acquisition difficult.

3. Ecosystem control

A company controlling:

  • cloud infrastructure;
  • operating systems;
  • enterprise productivity software;
  • identity systems;
  • endpoint software; or
  • telecommunications infrastructure

may possess an important distribution advantage when it enters MSS.

4. Bundling and Tying

A major competition concern is bundling cybersecurity services with another product.

For example, a dominant cloud provider could offer:

cloud infrastructure + identity management + endpoint protection + SIEM + MDR

at a package price that an independent MSS provider cannot economically match.

Bundling is not automatically unlawful.

The competition concern becomes stronger where:

  1. the supplier is dominant in the tying market;
  2. the tied MSS market is separately identifiable;
  3. customers are effectively forced to take the bundled security service;
  4. competitors cannot compete on equivalent terms;
  5. the bundle forecloses a substantial portion of the market; and
  6. there is insufficient objective justification.

5. Self-Preferencing

Integrated technology companies may operate both:

  • the underlying infrastructure; and
  • competing MSS services.

For example, a cloud provider could control the cloud environment while also operating its own security-monitoring service.

It might potentially:

  • give its MSS product preferential API access;
  • provide competitors with delayed telemetry;
  • impose technical restrictions on third-party security tools;
  • favour its own security alerts;
  • provide its own service with better integration; or
  • restrict competing providers' access to relevant security data.

Such conduct can raise self-preferencing and discriminatory-access concerns.

6. Refusal of Access to Security Data

Security monitoring depends heavily upon access to data.

A dominant platform could potentially control:

  • API access;
  • endpoint telemetry;
  • authentication data;
  • cloud logs;
  • security-event data;
  • network information; and
  • threat intelligence.

If competitors cannot obtain reasonably necessary information on fair terms, competition may be impaired.

This raises issues analogous to essential-facility and refusal-to-deal doctrines, although the precise legal test varies by jurisdiction.

7. Interoperability

MSS providers frequently need to integrate with:

  • Microsoft-type enterprise environments;
  • cloud platforms;
  • operating systems;
  • firewalls;
  • routers;
  • identity providers;
  • databases;
  • endpoint devices; and
  • third-party applications.

A dominant provider could potentially reduce competition by making interoperability unnecessarily difficult.

Examples include:

  • withholding APIs;
  • changing APIs without adequate notice;
  • imposing discriminatory access terms;
  • restricting third-party agents;
  • limiting data export; or
  • preventing competing security software from communicating with the platform.

8. Exclusive Agreements

MSS providers may enter agreements under which customers agree to obtain all cybersecurity services from one provider.

Exclusivity can create competition concerns where a dominant supplier uses it to foreclose rivals.

Relevant factors include:

  • duration;
  • market coverage;
  • exclusivity percentage;
  • switching costs;
  • availability of alternative suppliers;
  • rebates;
  • customer dependency; and
  • the provider's market position.

An exclusive arrangement negotiated by a small provider is ordinarily different from exclusivity imposed by a dominant infrastructure platform.

9. Loyalty Rebates and Discounts

Suppose an MSS provider offers:

30% discount if the customer obtains 90% of its cybersecurity requirements from the provider.

The arrangement may create foreclosure concerns if the provider has substantial market power.

Competition authorities may examine whether the effective discount makes it commercially irrational for customers to purchase from competitors.

The economic analysis can involve:

  • incremental costs;
  • effective rebate rates;
  • contestable demand;
  • duration;
  • customer coverage; and
  • equally efficient competitor analysis where applicable.

10. Predatory Pricing

Cybersecurity platforms may have substantial fixed costs but relatively low marginal costs.

A large technology company could therefore offer MSS below conventional standalone prices.

Low pricing itself is not unlawful.

The competition issue is whether below-cost pricing is being used strategically to:

  1. eliminate MSS competitors;
  2. prevent market entry;
  3. establish dominance; and
  4. subsequently recover losses through higher prices or reduced competition.

11. Mergers and Acquisitions in MSS

Cybersecurity is highly acquisition-driven.

Large technology companies may acquire:

  • MDR companies;
  • threat-intelligence providers;
  • SIEM platforms;
  • identity-security companies;
  • endpoint-security companies; or
  • cloud-security startups.

A merger may produce efficiencies through:

  • integrated threat detection;
  • reduced duplication;
  • improved incident response;
  • better threat intelligence; and
  • greater security investment.

However, competition authorities may investigate whether the transaction removes an important independent competitor.

Particular concern may arise where a dominant cloud or operating-system company acquires a rapidly growing MSS provider.

12. Vertical Foreclosure

Vertical foreclosure is particularly important.

Consider:

Cloud infrastructure → cybersecurity platform → MSS

If one company operates at all three levels, it could potentially disadvantage independent MSS providers.

Possible mechanisms include:

  • discriminatory API access;
  • preferential pricing;
  • tying;
  • technical interoperability restrictions;
  • data-access restrictions;
  • exclusive contracts; and
  • preferential treatment in procurement.

Competition law therefore examines not only horizontal MSS competition but also vertical relationships between infrastructure and security services.

13. Six Important Case Laws

Because there are relatively few reported decisions dealing specifically with a standalone "managed security services" market, established competition-law decisions from adjacent technology, telecommunications, software, platform and data markets are particularly relevant.

Case 1: United States v. Microsoft Corp. (2001)

The Microsoft litigation is highly relevant to MSS because it concerned the use of control over a dominant technology platform to protect and extend market power.

Microsoft was found liable for unlawful monopolisation, including conduct involving:

  • exclusionary agreements;
  • restrictions affecting competing technologies; and
  • leveraging control over Windows.

Relevance to MSS

A dominant operating-system or cloud platform could theoretically use control over its ecosystem to disadvantage competing security providers.

The case illustrates that competition law can scrutinise conduct designed to preserve platform dominance by restricting competitive alternatives.

Case 2: European Commission v. Microsoft — Windows Media Player

The European Commission's Microsoft proceedings concerned the tying of Windows with Windows Media Player.

The Commission considered whether Microsoft leveraged dominance in the operating-system market into an adjacent market through product integration.

MSS relevance

The same analytical concern can arise where a dominant technology provider combines:

dominant platform + mandatory cybersecurity product.

For example, if a dominant enterprise platform makes competing MSS products technically or commercially inferior through compulsory integration, tying principles may become relevant.

Case 3: Google Shopping — Google Search (European Commission)

The European Commission found that Google had abused its dominant position in general search by favouring its own comparison-shopping service in search results.

The case is significant for the principle of self-preferencing.

MSS relevance

An integrated technology provider could potentially favour its own MSS product through control over:

  • cloud dashboards;
  • enterprise marketplaces;
  • security alerts;
  • application stores;
  • identity platforms; or
  • security-management interfaces.

The competition question would be whether the conduct gives the vertically integrated MSS provider an artificial advantage rather than merely reflecting legitimate technical integration.

Case 4: Bronner v. Mediaprint

The Court of Justice of the European Union developed important principles concerning refusal to provide access to infrastructure controlled by a dominant undertaking.

The Court applied a demanding test concerning when access to an infrastructure can be required under competition law.

MSS relevance

Security platforms increasingly depend upon access to infrastructure and data.

Potential examples include:

  • cloud-security APIs;
  • endpoint telemetry;
  • identity information;
  • security logs; and
  • platform interfaces.

The case demonstrates that not every refusal to deal creates an antitrust violation. Competition law generally requires satisfaction of specific legal conditions before compulsory access is justified.

Case 5: IMS Health v. NDC Health

The IMS Health litigation concerned access to a commercially significant information structure and the circumstances under which refusal to license intellectual property could constitute an abuse of dominance.

The case established important principles concerning compulsory licensing and interoperability-related access.

MSS relevance

The case is useful where a cybersecurity provider controls:

  • proprietary threat intelligence;
  • security databases;
  • specialised data structures;
  • security interfaces; or
  • proprietary interoperability technology.

The central question becomes whether control over the relevant technology is being used legitimately to protect innovation or improperly to exclude competitors.

Case 6: Intel v. European Commission

Intel concerned conditional rebates offered by a dominant undertaking.

The case is important for the assessment of rebates and exclusionary effects.

MSS relevance

Suppose a dominant cloud or cybersecurity provider offers customers substantial discounts conditional upon purchasing most or all of their security services from it.

Competition authorities could examine whether the arrangement produces exclusionary effects.

The case demonstrates that the economic effects of conditional rebates can matter substantially in assessing dominance-related conduct.

14. Additional Relevant Case Law

7. Google Android

The European Commission's Android decision examined Google's conduct concerning mobile operating systems, applications and search services.

MSS significance

The decision is relevant to:

  • tying;
  • ecosystem leverage;
  • default arrangements;
  • interoperability;
  • distribution restrictions; and
  • leveraging dominance between connected technology markets.

A comparable MSS ecosystem might involve:

cloud → identity → endpoint → security monitoring → threat intelligence.

8. Qualcomm — Exclusive Payments

The European Commission's Qualcomm proceedings concerning payments linked to exclusivity demonstrate the competition concerns that can arise when a powerful technology supplier uses financial arrangements to secure customer exclusivity.

MSS significance

Similar arrangements could potentially arise where a major cybersecurity supplier offers:

  • rebates;
  • credits;
  • infrastructure subsidies;
  • migration assistance; or
  • preferential pricing

in return for exclusive MSS purchasing.

9. Bronner and the Essential-Facility Principle

Bronner is particularly useful in MSS because security platforms can become infrastructure-like.

However, the essential-facility doctrine should not be applied mechanically.

A cybersecurity API does not become an "essential facility" merely because competitors would benefit from access.

Authorities would normally examine:

  • indispensability;
  • feasibility of duplication;
  • elimination of effective competition;
  • objective justification; and
  • the particular market circumstances.

15. MSS Competition and Data Advantages

Data can be an important competitive parameter.

A large MSS provider may accumulate:

millions of security events → threat patterns → improved detection → more customers → more data → better detection.

This can create a feedback loop.

However, possessing large amounts of data does not automatically establish dominance.

Competition analysis should examine:

  • uniqueness;
  • quality;
  • timeliness;
  • substitutability;
  • replicability;
  • customer access;
  • duration of the advantage; and
  • whether competitors can obtain equivalent information elsewhere.

16. Algorithmic Competition

Modern MSS increasingly uses:

  • machine learning;
  • automated threat detection;
  • behavioural analytics;
  • AI-assisted incident response;
  • automated vulnerability scoring; and
  • autonomous security remediation.

Competition concerns can emerge if competitors use algorithms trained on substantially different quantities or qualities of data.

There may also be concerns where competing MSS providers use common third-party optimisation systems.

For example:

Provider A + Provider B + Provider C → common algorithm → common pricing recommendations.

If the system facilitates coordination rather than independent competition, traditional rules concerning concerted practices and cartel conduct may become relevant.

17. Algorithmic Collusion

MSS contracts frequently contain variable pricing based on:

  • number of endpoints;
  • log volume;
  • cloud usage;
  • incident volume;
  • response time;
  • geographic coverage; and
  • service level.

If competing suppliers use algorithms that automatically monitor competitors and adjust prices accordingly, authorities may examine whether the system facilitates coordinated pricing.

The legal distinction is important:

Independent algorithmic adaptation ≠ automatically unlawful collusion.

But:

communication, coordination, common instructions, or deliberate facilitation of competitors' pricing decisions can create substantially greater antitrust risk.

18. Cybersecurity Procurement and Competition

Large enterprises and governments frequently procure MSS through tenders.

Competition risks can arise from:

  • bid coordination;
  • market allocation;
  • cover bidding;
  • information exchange;
  • rotation of successful bidders;
  • subcontracting arrangements used to divide markets; and
  • restrictions on consortium participation.

Competition authorities may therefore examine cybersecurity procurement just as they examine other technologically sophisticated procurement markets.

19. Public-Sector MSS Markets

Government cybersecurity contracts can have distinctive characteristics.

National-security requirements may restrict participation to:

  • approved suppliers;
  • domestic companies;
  • certified security providers; or
  • providers meeting particular security classifications.

These requirements can be legitimate.

However, procurement authorities must distinguish between:

legitimate security requirements

and

unnecessary exclusion of competitors.

Competition law may become relevant where technical specifications are designed unnecessarily around a particular supplier's technology.

20. Merger-Control Risks

An MSS transaction may create several theories of harm.

Horizontal effects

Two major MSS providers merge.

Potential concern:

loss of an important independent competitor.

Vertical effects

A cloud provider acquires an MSS company.

Potential concern:

foreclosure of competing MSS providers.

Conglomerate effects

A technology company combines:

  • cloud;
  • operating system;
  • productivity software;
  • identity;
  • endpoint security; and
  • MSS.

Potential concern:

customers become increasingly locked into one ecosystem.

21. Remedies

Competition authorities may consider several remedies.

Structural remedies

  • divestiture;
  • sale of a business unit;
  • separation of competing services.

Behavioural remedies

  • non-discriminatory API access;
  • interoperability obligations;
  • data portability;
  • prohibition of exclusivity;
  • transparent pricing;
  • non-discrimination requirements;
  • firewall arrangements; and
  • monitoring trustees.

Interoperability remedies

Particularly relevant to MSS are:

  • open APIs;
  • security-data portability;
  • standardised log formats;
  • endpoint interoperability;
  • identity interoperability; and
  • access to threat intelligence under fair conditions.

22. Competition Compliance Framework for MSS Providers

An MSS provider should establish controls addressing:

Market conduct

  • pricing;
  • discounts;
  • rebates;
  • exclusivity;
  • bundling.

Platform conduct

  • API access;
  • interoperability;
  • data access;
  • technical restrictions.

Competitor interactions

  • information exchange;
  • industry associations;
  • joint ventures;
  • benchmarking.

M&A

  • acquisition screening;
  • merger-control analysis;
  • integration planning.

Algorithms

  • pricing algorithms;
  • automated bidding;
  • competitor monitoring;
  • common software suppliers.

23. Key Competition-Law Questions

IssueMain competition question
Market definitionAre MSS services a separate market?
DominanceDoes an MSS provider possess substantial market power?
DataDoes accumulated security data create a durable competitive advantage?
BundlingIs cybersecurity being tied to another dominant product?
Self-preferencingIs an integrated provider favouring its own MSS?
APIsAre competitors receiving discriminatory access?
InteroperabilityAre technical restrictions unnecessarily excluding rivals?
ExclusivityDoes exclusive purchasing foreclose competitors?
RebatesDo conditional discounts have exclusionary effects?
PricingIs below-cost pricing intended to eliminate competitors?
AlgorithmsDo automated systems facilitate coordination?
MergersDoes consolidation eliminate effective competition?
ProcurementIs bidding being coordinated?
Data portabilityCan customers realistically switch MSS providers?

24. Conclusion

Competition law in Managed Security Services extends beyond traditional price competition. The most important competitive parameters increasingly include data access, interoperability, APIs, ecosystem control, switching costs, cloud infrastructure, threat intelligence, AI capabilities and distribution channels.

The most significant competition-law theories are likely to involve:

  1. abuse of dominance;
  2. bundling and tying;
  3. self-preferencing;
  4. refusal or discriminatory provision of access;
  5. exclusive dealing;
  6. loyalty rebates;
  7. vertical foreclosure;
  8. predatory pricing;
  9. algorithmic coordination;
  10. anticompetitive mergers; and
  11. collusion in cybersecurity procurement.

The cases of Microsoft, Google Shopping, Google Android, Bronner, IMS Health and Intel provide particularly useful doctrinal frameworks even though they do not all concern MSS directly. Their principles can be applied to the increasingly integrated relationship between cloud infrastructure, enterprise software, cybersecurity platforms and managed security services.

LEAVE A COMMENT