The Security Services Gap Is Bigger Than You Think, and Automation Alone Won't Close It
I was reading Casey Porter’s interview with Simbian CEO Ambuj Kumar over at CB Insights, and one line stood out: we spend about $120 billion a year on security products, but another $90 billion on services. The services number is surprisingly close to the product number, which suggests an enormous, fragmented market that tech tends to overlook. Kumar’s thesis is that automation can finally eat into that services spend, especially given the talent shortage and AI-driven attacks. He’s not wrong, but after digging into the problem data, I think the real prize is hidden inside a much messier picture—one where integration, not AI capability, is the gating factor.
The numbers from PainSignal back up the urgency. We track 47 cybersecurity problems directly tied to talent shortage or staffing, with an average severity of 3.8 out of 5. That’s a lot of signal. When you filter specifically for incident response staffing, severity jumps to 4.3. That’s a screaming gap. It says the industry doesn’t just need more bodies; it needs expertise in the place where minutes matter most. Automation that reduces the cognitive load on IR teams or extends their hours without burnout could command premium pricing. If you’re a seed investor, look for founders who can articulate the difference between "SOC staffing" and "IR staffing"—the nuance means they already live the problem.
There’s also a dark side to the talent squeeze: 34 problems on PainSignal explicitly say manual security processes can’t keep up, with an average severity of 4.1. These aren’t vague complaints; they’re tied to specific incidents of missed alerts, slow containment, and compliance failures. Top of our cybersecurity problems category, you can see patterns stacking up. Manual effort becomes a compounding risk factor. That’s why Kumar’s vision of automated security services makes strategic sense. But here’s the twist: our data shows the biggest adoption barrier isn’t trust in AI—it’s integration. We see dozens of problems citing integration complexity when trying to layer automation onto existing SOC tools, with severity around 3.9. In plain English, teams are buying automation but then burning weeks making it talk to their SIEM, ticketing, and orchestration layers. If a startup nails the AI but ignores the API plumbing, it fails silently.
Kumar mentions AI-powered attacks as a driver for automation, and the PainSignal data corroborates this vividly. In the last six months, 12 problems specifically cite AI-driven threats: deepfake phishing, adaptive malware, automated vulnerability scanners leveraged by attackers. Their average severity? 4.2 out of 5. That’s even higher than the staffing crisis. It tells me that security leaders feel under-armed against an adversary that’s already using generative AI at scale. Defense-side automation isn’t optional; it’s overdue. But the magic will come from solutions that can match the attackers’ speed without requiring a forklift upgrade of the SOC.
What does this mean for indie hackers or agency devs scanning the landscape? There’s a wedge play here that doesn’t require raising a Series A. Small, focused tools that automate a single IR workflow—say, automated playbook generation from past incidents—could command $500-$2,000/month per midsize company if they plug into existing stacks with zero pain. The big vendors are all trying to own the platform; the gap is the adapter layer that makes automation actually work across Splunk, CrowdStrike, ServiceNow, and whatever else a client has duct-taped together.
For seed investors, I’d add one more data point. The ratio of services-related problems to product-related problems on PainSignal feels even higher than the 90/120 bill split Kumar describes. While we can’t audit his numbers, our problem-intake suggests that organizations are struggling more with the operational side of security—running the tools, tuning alerts, responding—than with feature gaps in the tools themselves. That implies the TAM for services automation might be understated, not overstated. But it also implies that the first generation of AI security copilots, which mostly sit on top of one vendor’s product, will hit a ceiling. The high-growth companies will be those that serve as a workflow orchestration layer, not a feature inside a console.
The cybersecurity market doesn’t need another company telling them AI will save us. It needs quiet infrastructure that makes the 3 a.m. page less terrifying. The interview with Kumar is a great jumping-off point to see how the market is framing the problem. But from where I sit, the data says the biggest returns will go to those who build bridges, not just engines.
This article is commentary on the original article by Casey Porter at CB Insights. We encourage you to read the original.
Explore more problems and app ideas across Technology, Cybersecurity.
Browse App Ideas