Right now, pretty much everyone is looking to outsource their "security" to a single vendor, disregarding the fact that security is not a product, but a process.
That... won't change! And incumbents will get less-awful about their impact on "protected" systems.
And yet, there's an opportunity here! Do you truly understand Windows? And whatever happens on that platform? And how to monitor that activity for adverse actions? Without taking down your customers on a regular/observable basis?
Step right up! There are a lot of incumbents facing imminent replacement...