ProBackend
agentic ai security risks
just now4 min read

Beyond Microsoft 365 Governance: Why Inforcer Raised $50M to Shield MSPs from AI Threats

London-based Inforcer raised a $50M Series C led by Insight Partners, bringing its total funding to $110M as managed service providers face rapid AI attacks and shadow AI risks across Microsoft 365 environments.

Capital Influx in the Managed Service Bottleneck

Small businesses rarely run their own internal security operations centers. They can't afford them. Instead, millions of small and medium-sized enterprises outsource their entire IT infrastructure to Managed Service Providers (MSPs). That structural reality makes MSPs the primary target and defense line for enterprise security—and venture investors are taking notice.

London-based startup Inforcer announced a $50 million Series C round led by Insight Partners, alongside existing investors Dawn Capital and Meritech Capital. The round caps an intense funding run: founded in 2023, Inforcer has raised $110 million across three funding rounds in just 18 months. Co-founder and CEO Jamie Daum reported that business grew 300% year-over-year while the company's valuation doubled between its Series B and C rounds, though he declined to specify the exact valuation figure.

The underlying driver is operational complexity. MSPs manage hundreds of individual client tenants concurrently. Without unified multi-tenant automation platforms, keeping Microsoft 365 security configurations consistent across independent client environments becomes an administrative nightmare. Inforcer solves this by offering a centralized platform that lets MSPs manage and configure Microsoft 365 accounts for all their SMB clients from one dashboard.

Attacks in Minutes: How LLMs Shifted the SMB Risk Profile

The threat environment hitting smaller organizations has transformed completely. Cyber attacks no longer spend months in quiet planning phases. Attackers now launch automated reconnaissance and execute targeted campaigns in minutes rather than months.

As Inforcer co-founder and chief community officer William Connor noted, malicious actors routinely use artificial intelligence to analyze corporate target surfaces while relying on large language models (LLMs) to craft believable phishing messages. For an SMB without dedicated security analysts, an AI-generated phishing campaign easily tricks employees and bypasses standard filters.

That shift creates a harsh speed asymmetry for defenders. Daum emphasized that SMBs now face threats that are more automated, more scalable, and significantly harder to defend against than anything seen previously. Traditional MSP operations relied on scheduled manual audits or periodic configuration reviews. When threat actors automate attack campaigns with LLMs, periodic audits are useless. When Attackers Move at AI Speed, Legacy Security Stacks Can't Keep Up. Security controls must run continuously directly inside the tenant.

Defending Microsoft 365 Against Shadow AI and Data Leakage

To keep pace with faster attack cycles, Inforcer allocated most of its capital into rapid product development. The team introduced a real-time threat detection and response tool designed to catch live security risks as they occur across client Microsoft 365 environments.

Alongside active threat monitoring, Inforcer introduced dedicated Shadow AI detection. Employees at small companies frequently paste sensitive business data, client records, or internal code into unvetted consumer AI services and web tools. They aren't trying to compromise their employers; they just want to speed up daily work. But unmonitored AI usage leaks proprietary information outside governed perimeters.

Inforcer's platform monitors endpoints to detect when staff access unauthorized AI software on company devices. Connor pointed out that organizational risk extends beyond external threat actors to internal data governance and agent management. As companies deploy autonomous agents and third-party tools within their workflows, setting firm access permissions and tracking agent behavior becomes just as critical as stopping external intrusions.

Business Model Evolution: Per-User and Token-Based Pricing

New platform capabilities naturally push changes in how software is sold. Inforcer initially launched its flagship 365 Manager product using a per-client pricing model. While simple for getting started, it didn't align cleanly with how MSPs bill their own end customers.

With the introduction of its real-time threat detection product, Inforcer is shifting toward a per-user pricing structure. This model aligns directly with standard seat-based MSP billing practices, eliminating financial friction for channel partners reselling the service.

As AI capabilities expand further across the platform, commercial models will likely keep evolving. Daum indicated that future feature releases could adopt consumption-based or token-based pricing structures. As security tools process larger telemetry volumes and run inline AI models for threat response, token pricing ties software costs straight to computational workload and customer usage.

The Enterprise Blindspot: Why Microsoft Needs Ecosystem Partners

Building software dedicated exclusively to Microsoft 365 raises a reasonable question: Why wouldn't Microsoft build these multi-tenant management features internally?

Inforcer's leadership views their software as complementary to Microsoft rather than competitive. Microsoft historically focuses its native management tools on large enterprise customers with dedicated internal IT teams. That strategic focus leaves a wide operational gap for mid-market and SMB organizations that rely entirely on channel partners.

MSPs need multi-tenant capabilities, cross-tenant policy enforcement, and specialized MSP billing workflows that giant platform providers rarely prioritize. By sticking tightly to the Microsoft ecosystem and building exclusively for MSP workflows, Inforcer targets a resilient distribution model. The $50 million investment from Insight Partners reinforces that as AI-driven threats expand to smaller businesses, the MSP security stack remains a critical growth sector.

Capital Influx in the Managed Service Bottleneck

More blogs