IT Solutions Acquires STACK Cybersecurity to Expand Managed IT and AI Capabilities
Quick Answers for Property & Facility Managers
What does the IT Solutions acquisition of STACK Cybersecurity mean for commercial businesses?
The acquisition expands IT Solutions’ managed cybersecurity, AI enablement, and governance capabilities for SMB and mid-market organizations. Businesses may gain access to a broader portfolio of strategic technology services, but buyers should confirm service continuity, support ownership, SLAs, security tooling, escalation procedures, and compliance expertise before changing their managed IT arrangements.
Should an organization evaluate its MSP after a cybersecurity provider acquisition?
Yes. An acquisition is a practical trigger to review the provider’s service scope, staffing, response commitments, security controls, and contract terms. IT leaders should verify whether account teams, help-desk coverage, incident-response procedures, cyber insurance documentation, compliance support, and technology road maps will change after integration.
How could the acquisition affect AI adoption and cybersecurity governance?
IT Solutions stated that combining with STACK Cybersecurity will add AI expertise and cybersecurity governance capabilities. For commercial organizations, that can support safer AI planning, access controls, data protection, vendor review, monitoring, and policy development. The business value depends on implementation quality, measurable controls, and alignment with the organization’s risk and compliance requirements.
IT Solutions’ STACK Cybersecurity Acquisition Expands Commercial Managed IT Capabilities
IT Solutions Technology Partners announced on September 22, 2026, that it completed the acquisition of STACK Cybersecurity, a Detroit-area managed security service provider and AI enablement firm. IT Solutions said the transaction expands its managed security, artificial intelligence, cybersecurity governance, and strategic technology capabilities for businesses across North America.
For IT directors, operations leaders, and business owners at SMB and mid-market companies, the announcement is less about the transaction itself than about what an expanded provider platform can deliver. A larger managed IT partner may be able to combine service desk support, cloud administration, security operations, compliance guidance, and AI planning. However, buyers still need to validate execution details, including SLAs, response times, support hours, certifications, staffing, and industry experience.
What the Acquisition Means for Managed Cybersecurity Buyers
STACK Cybersecurity’s addition strengthens the security side of IT Solutions’ portfolio. Managed cybersecurity commonly includes endpoint detection and response, managed detection and response, security monitoring, email security, multifactor authentication, vulnerability management, security awareness, incident response, and governance services.
The acquisition announcement identifies STACK as both an MSSP and AI enablement firm. It also states that the combination will provide additional cybersecurity governance capabilities and advanced AI expertise. Those capabilities are relevant to organizations that need to manage cyber risk while introducing artificial intelligence into business processes.
Buyers should distinguish between a provider’s stated capabilities and the services included in a specific agreement. During an evaluation, ask whether security monitoring is delivered directly or through a third party, whether coverage is continuous, how alerts are triaged, and who has authority to contain an endpoint or disable a compromised account.
AI Enablement Requires Governance, Not Just New Tools
AI adoption creates operational questions involving confidential information, identity, access, records retention, vendor risk, and acceptable use. An MSP or MSSP supporting AI initiatives should help establish policies and technical safeguards before employees place company data into public or poorly governed applications.
For an SMB or mid-market company, practical AI governance may include approved-use policies, identity-based access, data classification, logging, vendor assessments, human review, and procedures for reporting inaccurate or sensitive outputs. The controls should reflect the organization’s industry, contractual obligations, and risk tolerance.
Organizations handling protected health information should align technology and vendor practices with HIPAA safeguards. Defense contractors may need controls mapped to CMMC 2.0 and NIST SP 800-171. Companies pursuing SOC 2 should document security processes and evidence. Financial institutions and covered organizations should consider the FTC Safeguards Rule, while payment environments require attention to PCI DSS. The acquisition does not establish that every customer will automatically meet any of these requirements; compliance depends on documented controls, implementation, and oversight.
Due Diligence After an MSP or MSSP Acquisition
An acquisition is an appropriate time for IT leadership to request an operating-impact review. The goal is to understand what changes, what remains the same, and how the provider will manage integration without weakening service quality.
- Confirm the legal contracting entity, account ownership, escalation contacts, and renewal terms.
- Request current SLA commitments for help desk, infrastructure incidents, security alerts, and critical outages.
- Verify support hours, after-hours coverage, geographic coverage, and escalation to senior engineers or security specialists.
- Ask whether endpoint, email, identity, backup, vulnerability, and SIEM tools will change.
- Review incident-response responsibilities, notification procedures, forensic support, and coordination with cyber insurance requirements.
- Request relevant certifications, attestations, security policies, and compliance experience without assuming that a provider’s own certification covers the customer.
These questions matter for distributed commercial environments such as property management portfolios, office buildings, healthcare facilities, manufacturing sites, professional-services firms, and multi-location organizations. Service continuity depends on more than a branded platform; it depends on documented processes and accountable personnel.
Evaluating Provider Scale Without Losing Service Quality
A broader North American customer base can provide an MSP with greater technical depth, standardized processes, and access to specialized security or AI personnel. It can also introduce integration risk if teams, tools, or support workflows change quickly.
IT directors should request measurable operating information rather than relying on general claims. Useful buyer criteria include first-response targets, mean time to acknowledge and resolve incidents, ticket-volume capacity, device and user onboarding procedures, change-management practices, backup recovery testing, and customer references from organizations of comparable size and complexity.
For larger projects, clarify who leads discovery, architecture, implementation, documentation, and ongoing management. A Microsoft 365 migration, network modernization, cloud project, compliance remediation program, or security stack consolidation should have a defined scope, assumptions, acceptance criteria, and post-project support model.
Security and Compliance Questions for Commercial Organizations
Organizations should map provider capabilities to business obligations instead of purchasing cybersecurity tools in isolation. A mature managed security program should identify critical assets, privileged identities, sensitive data, external exposure, recovery priorities, and likely attack paths.
NIST Cybersecurity Framework concepts can help structure activities across governance, identification, protection, detection, response, and recovery. NIST SP 800-171 is relevant to protecting controlled unclassified information in applicable defense supply chains. HIPAA, CMMC 2.0, SOC 2, the FTC Safeguards Rule, and PCI DSS have different scopes and requirements, so the provider should explain precisely which services support which control objectives.
Operational resilience also includes backup and disaster recovery. Ask how often backups are tested, whether immutable or isolated copies are used where appropriate, how recovery time and recovery point objectives are defined, and whether manufacturer warranties or software support contracts create dependencies that the MSP must track.
Action Plan for IT Leaders Reviewing Their Provider
Companies that already use IT Solutions or STACK Cybersecurity should request an integration briefing covering service continuity, team structure, technology changes, billing, data handling, and escalation. Companies evaluating a new provider can use the acquisition as a comparison point when assessing the value of integrated managed IT and cybersecurity services.
- Document business-critical applications, locations, users, devices, networks, and compliance obligations.
- Compare the provider’s proposed services with required outcomes, including availability, security monitoring, recovery, and audit evidence.
- Validate response and resolution expectations for both IT support and security incidents.
- Confirm how AI tools will be governed, monitored, and restricted from exposing confidential or regulated information.
- Obtain a written transition plan, service catalog, responsibility matrix, and review cadence.
- Measure performance through ticket trends, SLA attainment, vulnerability remediation, backup tests, phishing results, and incident exercises.
IT Solutions said financial terms of the transaction were not disclosed. The company’s announcement establishes the acquisition and its intended expansion of AI, managed security, and cybersecurity governance capabilities; it does not by itself establish pricing, staffing levels, specific tool deployments, or customer-specific compliance outcomes.
Frequently Asked Questions
Will the IT Solutions and STACK Cybersecurity acquisition automatically improve a customer’s cybersecurity?
No. The acquisition expands the provider’s stated capabilities, but customer outcomes still depend on scope, implementation, staffing, configuration, monitoring, and governance. Customers should verify which services are included, whether security coverage is continuous, how incidents are handled, and whether controls support applicable requirements such as HIPAA, CMMC 2.0, NIST, SOC 2, the FTC Safeguards Rule, or PCI DSS.
What should businesses ask IT Solutions about the STACK Cybersecurity integration?
Ask about account ownership, help-desk and security staffing, support hours, SLA changes, escalation paths, technology changes, contract terms, data handling, incident response, and compliance documentation. Request a written transition plan and confirm whether existing tools, reporting, backup processes, and security policies will continue or be replaced.
Can an MSP acquisition reduce the cost of managed IT and cybersecurity services?
Potentially, but the announcement does not disclose pricing or customer savings. Integrated services can reduce duplicated vendors or administrative effort, yet total value depends on coverage and outcomes rather than vendor count alone. Compare total cost with SLA performance, security monitoring, remediation, compliance support, backup recovery, project services, and vCIO or strategic planning.
How should mid-market companies evaluate AI enablement from a managed service provider?
Evaluate AI enablement as a governance and risk program, not merely a software purchase. The provider should address approved use cases, identity, data classification, access controls, logging, vendor risk, human review, retention, and incident handling. Require documented responsibilities, measurable milestones, and alignment with contractual, regulatory, and industry obligations.
Does STACK Cybersecurity’s acquisition change compliance responsibility for customers?
No. A provider can support implementation, monitoring, documentation, and evidence collection, but the customer remains responsible for its compliance obligations and business decisions. Organizations should map contracted services to specific control objectives, review vendor agreements, maintain internal policies, and validate evidence through audits, assessments, or qualified independent reviewers.
What service metrics should a company monitor after an MSP acquisition?
Track SLA attainment, first response, resolution time, ticket backlog, reopened tickets, critical-alert acknowledgment, vulnerability remediation age, phishing and email-security events, backup success and recovery tests, endpoint coverage, privileged-account reviews, and incident-exercise results. Review trends with the provider regularly and require corrective action when performance or coverage falls below contract expectations.
Related Reading on My MSP Tech
- CMMC for Manufacturers in the Defense Supply Chain
- OT/ICS Security for Manufacturers: Protecting the Plant Floor
Find a Qualified Managed IT & Cybersecurity Contractor
Need help acting on this? Browse managed IT & cybersecurity providers in your area, or explore managed IT services like preventative maintenance, inspections, and emergency response. Are you a contractor? List your business on My MSP Tech to reach IT and operations leaders actively searching for help.
Sources
Originally sourced from IT Solutions Technology Partners
