Competition Law And Manufacturing Cloud Competition Issues .

Competition Law and Managed Security Services Competition

1. Introduction

Managed Security Services (MSS) are outsourced cybersecurity services through which a provider continuously or periodically manages a customer's cybersecurity risks. They may include security monitoring, Security Operations Centre (SOC) services, incident response, threat detection, penetration testing, vulnerability management, security audits, managed firewalls, endpoint protection, cloud security and cybersecurity consultancy.

The European cybersecurity framework expressly recognizes managed security services, including incident management, penetration testing, security audits and consultancy. Regulation (EU) 2025/37 enables future European certification schemes for such services.

Competition law becomes important because MSS markets can involve:

  • concentration among large cybersecurity and cloud providers;
  • bundling of security services with cloud or software products;
  • interoperability and API restrictions;
  • access to threat intelligence and security data;
  • switching costs and customer lock-in;
  • exclusive arrangements;
  • interoperability with competing security tools;
  • acquisition of cybersecurity competitors;
  • tying endpoint, cloud, identity and security products;
  • discriminatory access to security platforms;
  • use of proprietary telemetry to disadvantage competitors; and
  • coordination between cybersecurity providers.

The principal legal questions therefore concern market definition, dominance, exclusionary conduct, tying/bundling, refusal of access, data advantages, mergers and coordinated conduct.

2. Relevant Product Markets

An MSS provider may operate across several potentially distinct markets.

A. Managed Security Services

This may include outsourced:

  • SOC monitoring;
  • threat detection;
  • incident response;
  • managed detection and response (MDR);
  • vulnerability management;
  • security information and event management;
  • managed firewall services;
  • endpoint security;
  • identity-security management.

Whether these constitute one market or several depends upon demand substitutability, supply substitutability, customer requirements, technical capabilities and switching possibilities.

B. Cybersecurity Software

Security software may constitute a separate market from MSS because customers can purchase software directly without outsourcing security operations.

C. Cloud Security

Cloud providers may offer security as part of their cloud infrastructure. This creates possible competition-law questions where the cloud provider also competes with independent MSS providers.

D. Security Consultancy

High-level cybersecurity consultancy may be differentiated from continuous managed security operations.

E. Vertical Security Stack

A large technology company could operate simultaneously at several levels:

Cloud infrastructure → operating system → identity → endpoint security → threat intelligence → managed security services.

Competition concerns become particularly significant where dominance at one level is used to restrict competition at another.

3. Relevant Geographic Market

MSS markets can have both national and international characteristics.

Large multinational customers may procure cybersecurity services globally, whereas:

  • government contracts;
  • data-localisation requirements;
  • cybersecurity certification;
  • national security requirements;
  • sectoral regulation;
  • language requirements; and
  • local incident-response capabilities

may make competition substantially national or regional.

The EU's move toward European certification for MSS illustrates the importance of regulatory interoperability and avoiding fragmented certification requirements.

4. Major Competition-Law Concerns

A. Bundling and Tying

A dominant cloud, operating-system or enterprise-software provider may bundle MSS with its primary product.

For example:

Cloud infrastructure + identity management + endpoint security + managed detection

could make it difficult for an independent MSS provider to compete for the security component.

The legal inquiry normally asks:

  1. Are there separate products or services?
  2. Is the supplier dominant in the tying market?
  3. Is there coercion or conditionality?
  4. Does the practice foreclose competitors?
  5. Are there objective technical or security justifications?

5. Self-Preferencing

A platform may operate both:

  • the infrastructure on which security services operate; and
  • its own MSS/security service.

It could potentially favour its own service through:

  • preferred APIs;
  • better telemetry;
  • privileged integration;
  • default installation;
  • preferential ranking;
  • earlier technical access;
  • reduced latency;
  • preferential interoperability; or
  • exclusive access to security signals.

The competition-law issue is whether the conduct merely represents legitimate product integration or instead forecloses competing MSS providers.

6. Access to Cybersecurity Data

Cybersecurity depends heavily upon data.

Important datasets include:

  • threat intelligence;
  • malware signatures;
  • endpoint telemetry;
  • identity data;
  • network logs;
  • vulnerability information;
  • incident information; and
  • behavioural signals.

A dominant platform possessing unique cybersecurity data may create competition concerns if it restricts access to information that competing MSS providers reasonably need to provide interoperable services.

However, cybersecurity data may also involve legitimate:

  • privacy;
  • confidentiality;
  • national-security;
  • intellectual-property; and
  • cybersecurity-risk

considerations.

Competition law therefore requires balancing access against genuine security requirements.

7. Interoperability and APIs

Independent MSS providers frequently need APIs to integrate with:

  • cloud platforms;
  • operating systems;
  • endpoint devices;
  • identity systems;
  • SIEM platforms;
  • network infrastructure; and
  • threat-intelligence databases.

A dominant provider could theoretically discriminate between its own security products and competing MSS providers.

Potential concerns include:

  • delayed API access;
  • discriminatory technical standards;
  • excessive certification requirements;
  • withdrawal of interoperability;
  • discriminatory API pricing;
  • technical degradation; and
  • access conditional upon joining a proprietary programme.

8. Refusal to Deal and Essential Facilities

A cybersecurity platform may become extremely important for competitors where MSS providers cannot realistically operate without access to it.

The traditional essential-facilities/refusal-to-deal framework asks whether:

  • the facility or input is indispensable;
  • duplication is practically or economically impossible;
  • refusal eliminates effective competition;
  • access can be provided without undermining legitimate security interests.

The doctrine must be applied cautiously because mandatory sharing of security infrastructure could itself create cybersecurity risks.

9. Exclusive Dealing

Large technology companies may enter agreements requiring customers to obtain cybersecurity services exclusively from them.

For example:

"Customers purchasing our cloud infrastructure must obtain managed security monitoring exclusively from our security division."

Such arrangements can become problematic where the supplier has substantial market power and the exclusivity materially restricts rivals' access to customers.

Relevant factors include:

  • duration;
  • market coverage;
  • customer dependence;
  • switching costs;
  • availability of alternatives;
  • rebates or discounts;
  • foreclosure percentage; and
  • efficiencies.

10. Mergers and Acquisitions

Cybersecurity is an acquisition-intensive industry.

A major cloud provider acquiring an MSS company could create:

Horizontal effects

Two MSS providers compete directly.

Vertical effects

A cloud infrastructure provider acquires a downstream MSS provider.

Conglomerate effects

A company operating across:

  • cloud;
  • identity;
  • endpoint security;
  • threat intelligence; and
  • MSS

acquires another security provider.

Authorities may examine whether the combined company could:

  • foreclose rivals;
  • deny access to infrastructure;
  • bundle products;
  • increase switching costs;
  • restrict interoperability; or
  • use data obtained in one market to strengthen another.

11. Six Important Case Laws

Because there are relatively few reported decisions specifically titled "Managed Security Services", the most useful authorities are cases involving software security, digital platforms, tying, interoperability, access and technology markets.

Case 1 — XYZ v. Microsoft Corporation & Microsoft Corporation India Pvt. Ltd., CCI, Case No. 03 of 2024, decided 3 March 2025

This is particularly relevant to cybersecurity competition in India.

The complaint concerned Microsoft's inclusion of Microsoft Defender with Windows and the Microsoft Virus Initiative (MVI). The allegations included bundling, tying, foreclosure of rival antivirus providers, restrictions on market access and leveraging Microsoft's operating-system position into cybersecurity.

The CCI treated:

  • licensable desktop operating systems; and
  • computer security/antivirus software for Windows

as distinct relevant markets. It also considered Microsoft's position in the operating-system market.

However, the CCI found that users could install competing antivirus products, OEMs could pre-install alternative products, and established cybersecurity companies continued to operate. It therefore did not find sufficient evidence of coercion or foreclosure at the prima-facie stage.

Significance for MSS

This case demonstrates that:

Integration of security functionality into a dominant technology platform is not automatically unlawful.

The critical questions are choice, coercion, interoperability, foreclosure and competitive harm.

Case 2 — United States v. Microsoft Corp., 253 F.3d 34 (D.C. Cir. 2001)

The Microsoft case is one of the foundational technology-antitrust authorities.

The case concerned Microsoft's conduct involving Windows and competing browser technology.

The court's reasoning is highly relevant to MSS because cybersecurity providers can similarly depend upon access to a dominant operating system or platform.

Competition-law principle

A dominant platform cannot necessarily use control over an essential technological ecosystem to disadvantage complementary products.

MSS application

An analogous problem could arise if a dominant cloud or operating-system provider:

  • restricts APIs;
  • degrades interoperability;
  • prevents competing MSS tools from operating;
  • gives its own security product privileged access; or
  • uses technical restrictions to exclude competing security providers.

The Microsoft litigation therefore provides an important framework for examining platform power and technological foreclosure.

Case 3 — Google Android, European Commission, Case AT.40099

The Google Android proceedings involved Google's conduct concerning the Android mobile ecosystem.

The broader competition-law principles concern the use of dominance in one technological layer to influence competition in related markets.

Relevance to MSS

The same analytical structure can arise where a company controls:

Cloud/operating system → application ecosystem → security functionality.

If the dominant platform gives its own cybersecurity service preferential access while imposing materially more burdensome conditions on independent MSS providers, competition authorities may examine whether this constitutes leveraging or exclusionary conduct.

The important lesson is that competition analysis must consider the ecosystem rather than examining every technological component in isolation.

Case 4 — Slovak Telekom a.s. v. Commission, C-165/19 P

The Slovak Telekom litigation concerned access to telecommunications infrastructure and exclusionary conduct.

The case is important for the principles governing access to infrastructure controlled by a dominant undertaking.

MSS application

Cybersecurity ecosystems increasingly involve infrastructure that competitors need to interoperate with.

Examples include:

  • cloud security APIs;
  • identity platforms;
  • security telemetry;
  • endpoint-management interfaces;
  • threat-intelligence feeds.

If an MSS provider cannot effectively compete without access to a particular platform, competition authorities may examine whether denial or discriminatory restriction of access has exclusionary effects.

12. Case 5 — Bronner v. Mediaprint, C-7/97

The European Court of Justice considered refusal of access to a newspaper-delivery system.

The case is a leading authority concerning the demanding conditions for treating infrastructure as indispensable for competition.

Core principle

Not every commercially important facility becomes an "essential facility."

Indispensability is particularly important.

MSS application

Suppose a dominant cloud provider refuses to provide a security API to independent MSS companies.

A competition-law claimant would need to demonstrate substantially more than:

"The API would make competition easier."

It would potentially need to establish that access is indispensable for effective competition and that realistic alternatives are unavailable.

This protects dominant companies from being forced to share every commercially valuable technological asset while preserving the possibility of intervention where genuine bottleneck infrastructure exists.

13. Case 6 — IMS Health GmbH & Co. OHG v. NDC Health GmbH, C-418/01

The IMS Health case concerned access to intellectual-property-related infrastructure and the circumstances in which refusal of access may become abusive.

The decision is particularly relevant where technology, intellectual property and market access overlap.

MSS application

A dominant cybersecurity platform may possess:

  • proprietary threat intelligence;
  • security APIs;
  • technical protocols;
  • authentication infrastructure;
  • proprietary datasets.

A refusal to license or provide access does not automatically constitute abuse.

The relevant question is whether the strict conditions associated with exceptional compulsory access are satisfied.

14. Additional Important Authority — Intel Corp. v. Commission, C-413/14 P

The Intel litigation is highly relevant to MSS where cybersecurity services are supplied through rebates, discounts or loyalty arrangements.

The case emphasizes the importance of assessing whether a particular rebate system is capable of producing anticompetitive foreclosure.

MSS example

A dominant cloud company could offer:

30% discount on cloud services if the customer purchases its managed security services exclusively.

The competition analysis should not simply stop at the existence of the discount. It should consider:

  • effective price;
  • duration;
  • coverage;
  • customer dependence;
  • rival opportunities;
  • foreclosure;
  • efficiencies.

15. Competition Concerns in MSS — Analytical Framework

ConductPotential competition concern
Bundling MSS with cloud servicesTying/leveraging
Default security serviceForeclosure/self-preferencing
API restrictionsInteroperability foreclosure
Exclusive MSS contractsCustomer foreclosure
Loyalty rebatesExclusionary discounts
Threat-data restrictionsInput foreclosure
Refusal of security telemetryEssential-facility/access issue
Acquisition of MSS rivalHorizontal merger concerns
Cloud provider acquiring MSSVertical foreclosure
Preferential security integrationSelf-preferencing
Proprietary certificationEntry barriers
Data portability restrictionsSwitching costs
Sharing of threat intelligencePossible coordination risks
Joint cybersecurity standardsInformation-exchange concerns

16. Information Exchange and Cartel Risks

Cybersecurity companies routinely exchange information for legitimate security purposes.

For example:

  • malware indicators;
  • attack signatures;
  • vulnerability information;
  • incident reports;
  • threat intelligence.

Such cooperation can produce substantial cybersecurity benefits.

However, competition law may become relevant if cybersecurity cooperation becomes a mechanism for exchanging commercially sensitive information, such as:

  • future prices;
  • customer allocation;
  • commercial strategy;
  • discounts;
  • bids;
  • capacity;
  • customer-specific terms.

Thus:

Cybersecurity information sharing should be structured so that legitimate technical cooperation does not become a vehicle for commercial coordination.

17. Certification and Regulatory Barriers

Certification can improve cybersecurity quality but can also affect market entry.

The EU's 2025 amendment to the Cybersecurity Act specifically enables European certification schemes for MSS, including incident response, penetration testing, security audits and consultancy.

Competition questions may arise if certification requirements:

  • unnecessarily favour incumbent providers;
  • impose disproportionate costs on smaller MSS firms;
  • create discriminatory accreditation procedures;
  • prevent cross-border service provision; or
  • make interoperability unnecessarily difficult.

At the same time, certification may have legitimate objectives because MSS providers can have highly privileged access to customers' systems and security information.

18. Data Advantage and MSS Competition

A large MSS provider may obtain enormous amounts of cybersecurity telemetry.

This can create a data feedback loop:

More customers → more security data → better threat detection → better service → more customers → still more data.

Competition authorities may therefore investigate whether a dominant firm:

  1. obtains unique data because of its platform position;
  2. prevents customers from exporting the data;
  3. denies equivalent access to rivals;
  4. uses competitors' data to improve its own competing service; or
  5. combines datasets across markets to reinforce dominance.

The Microsoft Defender proceedings illustrate why access to security functionality, telemetry and interoperability can become central to competition analysis.

19. Switching Costs

MSS contracts can involve substantial switching costs.

A customer may need to transfer:

  • security logs;
  • incident histories;
  • detection rules;
  • threat models;
  • credentials;
  • security policies;
  • integrations;
  • API configurations.

If switching costs become artificially high, customers may remain with an incumbent despite the availability of competing MSS providers.

Competition authorities may therefore examine:

  • contract duration;
  • termination fees;
  • data portability;
  • technical portability;
  • migration assistance;
  • interoperability;
  • proprietary formats.

20. Small and Innovative MSS Providers

Competition law should also consider barriers facing smaller cybersecurity firms.

Potential barriers include:

  • expensive certifications;
  • access to threat intelligence;
  • API restrictions;
  • cloud dependency;
  • customer switching costs;
  • procurement requirements;
  • minimum-security certifications;
  • reputation effects;
  • access to enterprise customers.

A dominant platform that controls distribution and infrastructure may therefore possess significant gatekeeper power over smaller MSS providers.

21. Indian Competition Act, 2002

For India, the principal provisions are:

Section 3

Deals with anti-competitive agreements.

Relevant MSS issues include:

  • price fixing;
  • market allocation;
  • bid coordination;
  • customer allocation;
  • restrictive vertical agreements.

Section 4

Deals with abuse of dominant position.

Potential MSS theories include:

  • unfair conditions;
  • denial of market access;
  • tying/bundling;
  • leveraging dominance;
  • discriminatory access.

Sections 5 and 6

Concern combinations and merger control.

These may become important when major:

  • cloud providers;
  • cybersecurity companies;
  • MSS firms;
  • threat-intelligence companies

merge or acquire one another.

The 2025 CCI Microsoft decision demonstrates that Indian competition law can directly address competition concerns surrounding cybersecurity software and platform integration.

22. Possible Remedies

Competition authorities may consider remedies such as:

Structural remedies

  • divestiture;
  • separation of business units.

Behavioural remedies

  • non-discriminatory API access;
  • interoperability obligations;
  • prohibition of exclusive dealing;
  • data portability;
  • fair certification procedures;
  • prohibition of tying.

Merger remedies

  • divestiture of overlapping MSS operations;
  • licensing commitments;
  • access commitments;
  • firewall arrangements;
  • interoperability commitments.

The remedy must also account for legitimate cybersecurity considerations.

23. Key Legal Tests

A useful examination framework is:

Step 1 — Define the market

Is the relevant market:

  • MSS generally;
  • MDR;
  • SOC services;
  • cloud security;
  • endpoint security;
  • threat intelligence;
  • cybersecurity consultancy?

Step 2 — Establish market power

Examine:

  • market shares;
  • customer dependence;
  • switching costs;
  • network effects;
  • data advantages;
  • barriers to entry.

Step 3 — Identify conduct

Determine whether the conduct involves:

  • tying;
  • bundling;
  • exclusivity;
  • discrimination;
  • refusal of access;
  • self-preferencing;
  • rebates;
  • data restrictions.

Step 4 — Establish foreclosure

Ask whether rivals are actually or potentially prevented from competing.

Step 5 — Examine efficiencies

Security integration may have legitimate benefits:

  • faster threat detection;
  • reduced vulnerabilities;
  • coordinated incident response;
  • lower cybersecurity costs.

Step 6 — Proportionality

Determine whether the restriction goes beyond what is reasonably necessary to achieve the security objective.

24. Conclusion

Competition in Managed Security Services sits at the intersection of antitrust law, cloud computing, cybersecurity, data governance, interoperability and digital-platform regulation.

The central competition-law risk is not simply that one company provides both technology infrastructure and cybersecurity services. The more significant issue is whether a provider with substantial platform power can use control over infrastructure, APIs, data, distribution, identity systems or cloud ecosystems to disadvantage independent MSS competitors.

The most directly relevant modern Indian authority is XYZ v. Microsoft, where the CCI examined Microsoft Defender, antivirus competition, Windows dominance, tying, market access and interoperability-related allegations. The case illustrates that security integration alone does not establish an antitrust violation; evidence concerning coercion, foreclosure, market access and competitive harm is critical.

The broader authorities—Microsoft, Google Android, Slovak Telekom, Bronner, IMS Health and Intel—provide the principal doctrinal tools for analysing platform leveraging, interoperability, refusal of access, indispensability and exclusionary incentives in MSS markets.

Six core cases to remember

  1. XYZ v. Microsoft Corporation & Microsoft Corporation India Pvt. Ltd., CCI, Case No. 03/2024 (2025) — cybersecurity/antivirus bundling and platform integration.
  2. United States v. Microsoft Corp., 253 F.3d 34 (D.C. Cir. 2001) — technological platform leveraging and foreclosure.
  3. Google Android, European Commission, Case AT.40099 — ecosystem dominance and leveraging.
  4. Slovak Telekom a.s. v. Commission, C-165/19 P — infrastructure access and exclusion.
  5. Bronner v. Mediaprint, C-7/97 — refusal to deal and indispensability.
  6. IMS Health GmbH & Co. OHG v. NDC Health GmbH, C-418/01 — exceptional access to indispensable infrastructure/IP.
  7. Intel Corp. v. Commission, C-413/14 P — exclusionary rebates and foreclosure analysis.

LEAVE A COMMENT