Skip to main content
Right of Boom
November 18, 2024

An MSPs M&A journey to Exit & the Role Security Maturity Played

The MSP landscape continues to evolve, and for many providers, mergers and acquisitions are a major opportunity—but only if you’re prepared. During a recent Cyber Call, Tyler and Mark from Pace Technical shared their journey from a growth-focused MSP to a successful acquisition by IT Solutions. What set them apart? A deep commitment to security maturity and operational excellence.

Pace started by treating their own organization like a high-value client, building internal security first. They implemented strong controls, created accountability, and established dedicated security roles. Their culture of security wasn’t limited to the IT team—it was embraced from the top down, with leadership reinforcing the importance of awareness and proactive defense across the business. One of their key drivers was the use of Technology Alignment Managers (TAMs), who focused on identifying risks, aligning clients to best practices, and creating ongoing improvement.

Security wasn’t an upsell—it was built into every offering. Pace positioned cybersecurity as a core differentiator and charged accordingly. They used cyber insurance requirements as a benchmark for both internal alignment and client strategy, recognizing that insurance readiness revealed real risk posture. Their efforts were bolstered by their involvement in peer groups, which provided coaching, collaboration, and accountability. That external input helped refine their processes and kept them ahead of the curve.

Pace also invested heavily in brand building and client education. Through content, webinars, industry events, and a clear vertical focus (especially in legal), they built trust and positioned themselves as thought leaders. Profitability remained a core goal—because being profitable enabled them to invest in people, tools, and security maturity.

The result? A business that was secure, scalable, and valuable—ready for acquisition. Their success shows that security maturity isn’t just about avoiding risk—it’s a lever for growth, profitability, and long-term business success. For MSPs, the lesson is clear: build security into your culture, invest in proactive roles, educate your clients, and lead with value. The payoff is a stronger business, ready for whatever comes next.

Guests

Gary Pica

Video Transcript

All right. And we are live happy to be here today, Phyllis. There's no Andrew Morgan today. So you know what that means. No announcements. So that gives us like 20 minutes more show. Right? Hilarious. Yeah. Awesome. So we today can get right into it. Today we're gonna be talking about an MSP's journey and through m and a, but also in terms of the role that security and security maturity has played, um, in that journey.

So, uh, Phyllis, I'm gonna introduce our guest, Tyler and Mark, uh, from PACE Technical. And, um, Tyler, we'll start with you. Maybe just give us a little background, uh, on, uh, on pace. Yeah, sure. Yeah. Thanks Gary, and, uh, exciting to be here. Thanks for having us. Uh, yeah, quickly, I mean, pace. We're based outta Toronto, Canada, uh, been in the managed services space for about 25 years.

Uh, before pre-acquisition, which was just a couple of weeks ago, we're supporting about 140, 150 businesses. Half of those are law firms. We're 60 to 65 total employees. Um, and, you know, always had this big focus on the legal vertical. So, like I said, it's about 50% of our client base and, um, continue to, continues to be a big part of our marketing efforts and focus. Awesome. Mark, a little about your background.

Yeah, so, um, I, I, you know, started off in technology like, like most of us, I was in on the development side. Uh, got an opportunity to get into the banking system, into enterprise space early in my career, and quickly moved into leadership roles and put away the programming and started focusing on, uh, on leading and managing people and technology.

Uh, I spent about a decade in, uh, the enterprise space, helping to manage data centers and people, uh, joined Tyler at Vertex about three, four years into, uh, Vertex's existence. And, uh, I guess the rest is history, so to speak. Uh, we joined up and, uh, took, you know, small, uh, MSP that was about five or six employees at the time. And, uh, here we are, uh, you know, 12 years later, uh, transacting. And, uh, it's been a great journey.

Yeah, I'll add a couple things to, to their story since I've worked with you guys for, I've been lucky enough to work with you for so long. And, uh, so Tyler, you found it, uh, vertex legal Vertical, MSP, and another one of our peer group members, pace, also in Toronto. Uh, the, the partners decided to merge those companies a few years back, and then just recently announced it was acquired by IT Solutions.

Full disclosure, uh, I'm a board member of IT Solutions, so this is a closely held transaction. Um, but from my standpoint, I've got to watch you, you know, build the company really from scratch, uh, you know, to, to what it is, uh, today. And that has been, um, amazing. So, Tyler, I wanna start with you, uh, and, um, first tell us about like, the recent acquisition in terms of like what, like the journey to get to that point. Well, it certainly has been a journey. You summarized that.

Well, uh, yeah. So quick history, uh, you know, we talk about Vertex, we talk about pace, and having come together in 2022, uh, we, you know, pace and Vertex had known each other for many years through True Methods and Peer group. And, uh, it just started to make more and more sense for us to bring our MSPs together. Coming out of covid. I think a lot of MSPs, a lot of people in the IT space, were having a hard time acquiring new talent, retaining their talent.

Uh, so we could, you know, by coming together, kind of gain some economies of scale, there have a little more protection in our workforce in terms of some more redundancy in roles, deeper skillset. Uh, so we completed, you know, or we started that merge in 2022, and it was sort of, you know, a one year journey. Uh, and then we started thinking, you know, the next chapter would be, uh, looking into acquisitions and, um, looked at, you know, there's a lot of suitors out there.

Anyone in this space probably is getting approached on almost a daily basis. People interested in acquiring your MSP. Uh, but for us, we, you know, took our time, didn't really engage too heavily with, with many, and sort of watch what others in our peer group were doing, uh, so we could kind of get some real world experience on, uh, you know, the type of transaction they had, sort of the reasons that they chose the people that they went with.

Um, for us, it was really important that it was going to be, um, a good structure for our employees, for our clients. None of us wanted this as an exit strategy from the owner's perspective. We all wanted to stay on board, uh, continue the journey, but de-risk, you know, uh, move some of that, you know, broaden our team, uh, as we did in the original merge, but now take it, you know, yeah.

From 60, 65 people to close to 500, uh, and have, uh, a really good opportunity, uh, for our employees and, uh, better protection for our client base. So, Yeah, that's really, IM important. And I hear people often when they talk about, you know, you know, I spend a lot of time in the m and a world, right? Like, and when I talk to people, I hear a lot about valuations and, and multiples and, and like, that's important. Mm-hmm.

But I feel like it's kind of been scienced out, and there's other things, right? Like you mentioned it, what do I want to do? What do I want my, like, what's important to my team and their opportunities? What about my customer base and all those? And, you know, again, and you have the luxury today of being able to prioritize, you know, those things, you know, in terms of, in terms of making a decision. So, um, really good.

I mean, uh, I, I know that you guys are really thoughtful, uh, in terms of how you think through things. And, um, and I've watched you go through this process and you've handled it, you know, with a lot of, uh, with a lot of grace. Um, I, I wanna start talking a little bit about, at a high level, what has, uh, for our cyber nation here, what role has security maturity played in the success of the business? Especially like you're in a vertical that's pretty sensitive to security, right?

For sure. Uh, it's played a huge role and it's, I know everybody says the same thing. It's a journey, not a destination. And it really has been. And I think when we got started to get a lot more serious about security, it started in-house in cleaning up our own MSP and really becoming a sec internally, security conscious MSP, uh, so we treated RMSP is if we were a client to ourselves.

So we got, you know, very structured in having a de designated tam, you know, what we call our technology alignment managers who are aligning our clients and our own business to industry best practices, uh, security controls. So, uh, you know, maybe that was about five years ago, we started to get really focused on treating our business like we would our top clients. Uh, and that helped us by maturing internally.

It helped us to be more mature in presenting to our clients and really understanding, you know, what we needed to do to secure our business more and start to mature security wise, and then be able to do that with our clients and be able to deliver that through VCIO and with new prospects for our sales cycle. You know, it's funny, Tyler, every week we mention, you know, put your, you know, life vest on first, so it's easy to say that, but it is not easy to do, right?

Because clients are demanding service. And so to really treat yourself a hundred percent proactively like a customer from a security standpoint, it is not an easy thing to do, is it? Oh, no, definitely not. And, and it's sort of, you know, what true methods has taught us over the years is having designated proactive roles.

And without that, I don't think we would've ever been able to do it, because there's always, on the reactive side, so much going on so many, you know, urgent pressing issues that are gonna take priority over security alignments and best practices. So the fact that we had already established these proactive roles, proactive departments allowed us to be able to dedicate their time to doing this internally first.

But of course, you've got a, a lineup of projects, you've got a lineup of reactive tickets, things you want to do with clients, so you've gotta, yeah, make a very, um, disciplined decision around how you're gonna control those resources to aligning your business to best practices. So, uh, before I want to, we're gonna, um, hand it over to Phyllis, then I'm gonna come back and talk to Mark, dive deeper into the customer part of it.

But before I do, I, I want to first ask you like, the reaction of your employees, right? So you went by putting the companies together, and then you made this announcement. In general, what were the, and then afterward, what were some of the one-on-one conversations you had with people, fears, excitement, perspectives, all of it.

I think there was more fear in our minds leading up to this than what actually transpired in announcing this to our team when we merged, it was, everybody warned you ahead of time that there's going to be all these unforeseen things that pop up. And no matter how aligned you are with two MSPs coming together and cultures and everything else, there's going to be surprises and there's going to be, you know, some challenges along the way.

So we just kind of come out on the other side of all of that and settled things down where we felt like, okay, now we're really, are this, you know, one new MSP that we've successfully merged. We can kind of put that behind us, but guess what, Hey, now we're, we're being acquired. So it was, uh, you know, mentally for us preparing it was a little daunting just coming, you know, getting everybody in their happy place and then rocking the boat with this.

Um, but the, it was received really well by our people. A lot of them kind of expected, they know the industry well enough to know that this is sort of a natural evolution. Now in the MSP space, a lot of our competitors had gone through this, but it was really important that the three owners and PACE were going to stay on and continue to be involved in this long term. We weren't looking, I mentioned earlier, we weren't looking for an exit strategy here.

Um, we were selling to a true MSP that wanted to continue to commit to the MSP process, you know, help develop and grow in Canada, provide a lot of good career opportunities for our people, and stay committed to, uh, to our client base also. So, some of the things that were disruptive during the merge, we're bringing a couple of teams together, bringing all of our clients together, all the techs having to learn the others, uh, other company's clients.

In this situation, we get to stay focused our team on our clients, uh, from a service interaction perspective. So I think there was a lot of relief in that, that we, you know, and ITS bringing a dedicated integration team that's gone through this and done six of these prior to us. So the, the confidence in knowing that there's some experience backing this up and that we're committed in sticking to this and we're committed to the employee and client experience was received really well. Yeah.

Yeah. You know, it's funny 'cause both, um, when I sold my MSP and when I sold True Methods, it was the same thing. Like, I was really concerned about that day. You know, we announced and each time, um, the fear, the actual fear, once we, you know, were sincere about where we were, why we did things, what would come, what would come was always much less than what I had, you know, uh, laying in bed awake that night before.

Um, because, you know, our self-image are so tied up, you know, in, in our businesses and Yeah. And creating opportunity for people, really, that's what it's about. Yeah. Right. Being able to create opportunity for people. So that's awesome. PHY Ended, opened up a whole new layer of positions, and that was going from whatever, 25, 30 employees on each side to 60, 65. Now going to, you know, uh, just shy of 500 employees.

We know there's just positions we would've never been able to create in a 60, 70 person organization that Exists now. And we, we acquired a few other, uh, true methods peer members that, that you're friends with. So you got to see their teams over the past couple years and the opportunities they have. So it's good when you can look under the covers that way. Helped A lot. Yeah, absolutely. Alright, Phyllis, I'm gonna hand it over to you and then I'm gonna come back and, and talk to Mark.

Yeah, sure. Thanks. Um, so Tyler, you talked about, you know, getting your own house in order first, which as Gary says we always emphasize here. Um, so how important was it for you to have your operational maturity down as well before you actually, um, you know, try to implement security across the enterprise? And then you already talked about how important roles were, right?

So I'm gonna go a little bit off script for my second half of the question would be, um, we often talk about a culture of security. And so how was it that you were able to foster that? Yeah, going to the, uh, you know, addressing the operational maturity question that was really important to have in place first because having really well structured service delivery areas teach you how to, you know, secure and how to deliver security in each of those areas.

I already spoke about the role of the technology alignment managers and, you know, running that department, uh, uh, against our own company. Uh, so having, you know, all of the structure in place prior to, uh, you know, know really maturing on our security side was made it a lot easier to really understand, you know, what are the proactive, dedicated roles towards security.

Um, you know, having a security and compliance team that could help dictate how we're going to manage change throughout the, you know, change control throughout the organization, how, you know, new projects have to get scrutinized from a security perspective, how, um, you know, handling requests on service desks that come in, what security layers need to be, uh, embedded in the process in, in a lot of those, uh, roles and responsibilities. So we, we were already an ISO 9,001 2015 business.

Uh, so why not, you know, that's really focused on the operational side of things, not at all on the security side. Uh, but going back to your question, that helped already having that framework, that ISO in place, so that when we started to layer in the security, it was easier to, uh, to roll out between departments and clearly define roles and responsibility around security. So did you create new roles For Security? I mean, did you have to hire people? Did were pe did people Yes.

Kind of grow into those roles, or dual hatted, or how, how did that come about? Yeah, we did end up hiring a security expert to, to run or to lead our security teams, our security team, and or other departments. Uh, building that, you know, you talk about the culture and we preach this to our clients all the time, that it starts from the top down, having a security minded, uh, company and really developing a culture that security is everybody's responsibility.

Uh, it seems obvious in an MSP that that should exist, but I think people just assume because they're technical, that it doesn't necessarily, those things don't apply to them. And I'm smart enough to know not to give someone admin credentials or to click on a link. I shouldn't. Uh, and I don't need the proper hygiene on my machine.

So I, I think, you know, almost in an MSP, you need to reinforce it more because people just take for granted that they're technical and maybe think that it doesn't apply. So we embed really, you know, security into all of, uh, our conversations around, you know, business goals, business planning, how we deliver our services. Um, every project, you know, has an element of how, what, you know, what's the security risk in deploying this, the change control around it.

Uh, so really making it everybody's responsibility and awareness. So, Phyllis, real quick, I wanted to add on you, you used that word culture. Um, could you feel it when security became part of your culture? Like, can you think about like, okay, it's starting to be in everybody's mind in everything we do? Yes. Especially when, you know, we, we went to discipline change control.

Uh, that's where we saw it a lot more, where people weren't taking shortcuts and just implementing things after hours quickly without a lot of planning and thought around it. Uh, so the, you know, ramifications of, uh, something going wrong after hours we were able to recover from, it happened a lot less. Uh, and people started, it was nice to hear within the company, people talking about, you know, the security maturity and just the controls around security and everything we were doing.

So it starts to, let's say, become somewhat contagious that as soon as some people take that take on that responsibility and are taking it seriously, others feel compelled to as well. I think. I think that's great because often it really is, you know, when you already know about tech, you always think you're, you know, so it's like, it's okay for other people, but I'm the admin and I can do this, and I already know all the roles.

And I think another thing to point out is a lot of organizations that I work with just say, oh, well you also need support from the top. Like, if C-suite doesn't care, then no one else is gonna care.

So I mean, I think you started off by saying, saying that, you know, it was kind of from the top, you know, the first sentence Has to be, and that's what we're constantly preaching to our clients also, is it, it's, it's so ironic when, you know, the CEOs and the, the partners at Affirm and stuff say, exclude me from MFA and I don't need to, I'm not going through security awareness training or any of this.

And they're the prime targets for, you know, people that are going to, uh, try to try to hack in and try to compromise somebody. It's going to be those top people. So without them being on board, uh, it's, it's an uphill battle for, for a company to, to build that security maturity they need. Yes, Gary often talks about That. I was looking, I was looking at a comment from Bob Miller. He knows exactly when they reached that point.

It was during, they did a physical tabletop, uh, and went through those things. So sometimes it literally is something that you do after you've been working that kind of gets everybody to see it in the same way. Yeah, that's, that's actually a great example and a great reason to do those tabletop exercises. It brings that awareness and that allows you to see your maturity as well.

Um, I did wanna say, Gary often says on this call that, um, you know, you have to have the right people in the meeting when you go to try to sell security to a client because it's, you know, you do. And so often, um, I get asked like, well, how do I get money from the board? Where's the set of slides? Where's, where, where is the magic kind of slide deck that I can show the board so I can get additional funding for security? And, and Gary always says, you know, it's, it's the business case.

You have to make the business pace case for security. And we often say that too. So it's nice that you were able to get that support. Yeah, having somebody else relay the message about the importance of security and investment that needs to be made does not go over well. Usually they're not able to, uh, to, to deliver it the same way we would directly to the right people. Yeah.

So you, you are, are a member of true methods, as Gary said, um, earlier, and so you get to see, um, you know, how other MSPs are faring and how everyone's doing over time if you, if you stick with it. So from your view, do you see a direct correlation between security maturity and growth and profitability? Yeah. Yeah. The, that's I'd say the MSPs that are most mature in their security offerings, one, you know, they're able to sell at a higher price for sure.

Uh, they're able to usually add more onto the stack. So you get a lot more NRR or type of, uh, projects or recurring revenue there. Uh, usually there's less reactive problems. If the client is more secure, you have less security remediation to jump into because you've already done the upfront work to, to make them more secure. Uh, you're usually attracting larger clients. Uh, so, uh, in order for it to make sense, you're probably $6,000 and up, uh, on average for your client base.

Uh, and usually I, I would think in a lot of cases, selling over 200 a a seats for more security mature MSPs and programs. So I am gonna go back to, you know, what I mentioned before. 'cause I still do hear it very often. I mean, how hard was it to kind of, I don't wanna say upsell, but upsell organizations on security? Like how was that additional training you gave your folks?

You talked about those roles and those functions, but you know, that is often, um, a topic of conversation as well, um, on the call. Yeah, I, I mean the, the, the two different sales sides. So one new logo business, uh, my partner Mike and I do most of that outside sales. So we believe in what we're preaching and what we're selling. So, so much of it is that belief system and just believing in what you're charging.

Uh, you, you know, you spoke about peer and understanding what other people are successfully selling for helps build your belief and confidence too. If, if all of a sudden you hear people are selling 2, 2 50 a c, you start to believe the fact that you can also, uh, if you don't know that and you're always going up against competitors and the the prospects telling you you're the most expensive, uh, a lot of people want to try to, and they Are right. That's what they're telling You. Yes.

And, and if they're not telling me we're the most expensive, I feel like I haven't quoted enough, because we always should be the most expensive. And that's really our value proposition. And the differentiator is we use that to, to show like if we're whatever, $50 more a seat, well, that's, these are the reasons why you should be spending that. And the reasons not to go to another MSP who cannot afford to deliver the proper security and their service for that price.

Uh, from A-V-C-I-O perspective, it took, you know, it's, it's, it's more employee driven VCIO in our, in our company. So it took more training and understanding of, of what it is. But we have some mature v CIOs that firmly believe that, you know, the importance of security understand it well. So we say in every single VCIO meeting, there needs to be a conversation around security. Even if you spoke about it last time, the same thing.

You wanna always lead with what is the best, in a perfect world, what would you recommend that client adopt from a security perspective, even if it doesn't seem realistic that a smaller client's going to spend another whatever, 2000 a month for the security layer, our job is to advise them of where there's risk, how they can mitigate that risk, what the cost to mitigate that risk is. And ultimately it's their decision.

And if you keep speaking to them about it, you hope one day they'll adopt it. If not, you've at least had those conversations. And if something goes wrong, uh, and that what your recommendation could have at least, uh, alerted to it earlier, or, you know, mitigated that problem, you kind of get a get at a free jail card because you've been preaching that to them over and over and over again. And it was on them to, uh, to not approve that. Oh, okay. That's awesome.

Like, would you ever walk away from a client? I'm totally going off script. I mean, because we've talked about that as well. So I'm just curious. You know, We still, one in our secure, in our security, uh, our MSP program, we bundle a lot of the core security elements into that. So we know if we're taking on a client, they're going to get all these different layers of security as part of it, whether they think they need it or not, whether they already have something or not. That's our program.

You're taking that at a minimum. We know that you at least have to get by, uh, you know, pass a cyber insurance, uh, policy, uh, get, you know, be able to pass those renewals, have all of those com core components in place. Uh, if a client's not willing to, you know, push out MFA to all of their, uh, all of their employees and stuff, we will, uh, threaten to walk away.

And if they're completely delinquent in it over and over, we will have to walk away because it's too much risk for us to assume. Right. So what I'm hearing is we don't even offer that like, zero security package. There's no bronze, silver, gold or anything. There's one platform, one program we offer, and then we'll just add on more security components to it.

But our entry level program is always making sure that all the core things, uh, EDR firewall, um, 365 backup, all of our proactive TAM alignments, all of that is just bundled into our core package. That's awesome. I'm curious, Gary, can we ask a question like how many people on the call today, just as their baseline already offer like a minimum security package and don't have a no security package? Yeah, yeah.

If you, if you only offer pretty much everything Kyler said and, and you don't sell anything, Peter or 10, uh, or Plat, give us a three in the chat. Yeah, that's awesome. That's awesome. So, um, I'm curious, you know, you talked about like looking at your peers, um, and one of the great things about the MSP community is you do have these peer groups, which is one of the only communities that I know of that actually does that and is active in it.

So how has peer groups helped you in your journey and what advice would you give, um, other MSPs about peer groups? Peer for us has, you know, been the, the single most important thing we've done to get to where we are today, without a doubt, right, mark?

I mean, there's, there's just no, no way we would be where we are now without peer, without the, the coaching from true methods, the collaboration with our, with our fellow peer members, uh, the accountability that the, the peer group brings out. Um, you know, the recommendations, the, just understanding, you know, packaging, pricing, what security tools stacks are people using, what's, what are, you know, you, you finding success with what isn't working.

Um, I mean, that's probably been 10 years now and every year it's, we've just continued to develop and grow and mature more because of peer group. Yeah. And I want everyone to hear that, not as a commercial for true methods 'cause we don't need a commercial, um, right now, but a commercial for peer groups and, um, whether it is ours or one, one of the other peer groups that are out there, I I don't know how you're in this industry right now with all the changes.

Um, thinking you're gonna figure it out alone. Yeah, there you gotta be out there. I, you know, what I like is, it seems so interesting 'cause it's always like, oh, but your competitors perhaps, but you're still willing to be in the peer group and help each other out. So I I, that's A big part of it. Yeah.

You, you still have to be able to deliver and you still have to the, like, the one thing I'd say about peer group is, you know, you have to be totally committed, vulnerable, and receptive to it to be successful. I've seen a lot of people join peer over the years and every quarter they're kind of presenting the same challenges.

They're stuck at the same, you know, MRR, uh, they're stuck at the, you know, low profit level and they're not making changes because they, I don't know if they just can't commit to what needs to, the tough decisions that need to be made if they don't truly believe in it or they think they have a better way. But, uh, the people that we see year after year being successful in it are the ones that are, are willing to be vulnerable and say that, you know, I don't have it all figured out.

And when you commit to things and you're collaborating as a peer group, uh, and your suggestions, you go back and you deliver on those and you go back and you come back the next quarter and you say, check, check, check. All of those things I set out to do this quarter got done. Whether they're, you know, really tough decisions that need to be made or just things that need to be implemented and require time.

But if you're not committed to making the change and doing the things you're discussing as a peer group, um, there's, there's a lot less value in it. Definitely. You know, one thing, Phyllis, when you're in a peer group, you talk about people who look and say, well, there's competitors. Well, I mean, look, would you rather have your competitor be be learning more and being part of something and you're not, number one?

Number two, it is less what you learn when you're in peer, it's less about your business is only the result. It's really about the business leaders figuring out the answers to the questions that Tyler just said, which is, why have I been in business for six or seven years and I'm stuck here and everyone's telling me the same thing of what I need to do and I'm not doing it. Like, what is it about me? Like, what's going on with me?

And that's what peer members, and he talks about getting vulnerable to figure out like what are those self-limiting beliefs that we all have? And together you are more likely to be able to break each other's barriers. And when that happens, you end up with a better MSP that grows, is more profitable, not the other way around. Yeah, that's, that's great perspective. That's awesome. Yeah.

So, um, yeah, Just because you tell people how to do something or how you're being successful in doing something doesn't mean they're actually going to do it. And more times than not, they actually don't. And you're like, it's, it's right there. The blueprint. I mean, this is what, uh, true meth has been doing from day one. The blueprint's there, you just have to follow it and, and commit to it.

And you can have success, but so many people find, you know, different ways to creatively implement it, but not really implement it. And it doesn't work that way usually. Yeah. And it's not like you're giving away, you know, trade secrets. Right. They were given to me by the group. Yeah. We're not building the first place. Yeah. I always tell people, we're not building the Adam bomb here folks.

No, But I think it's great you share ideas, you see where people go, you can get expired, I mean, not expired inspired. Mm-hmm. And then, um, and also like, you know, be held accountable too. Like no one wants to go to the next, well hopefully the next meeting and be like, oh, I'm stuck. Right. Well, and then Gary mentioned self-limiting beliefs, and I do think that's a big part of it.

And I remember we were in, uh, when we first joined Pier, we were in a certain group and we started to reach kind of the top of that group. And we were selling at the top of the, uh, you know, the MRR and, uh, we're selling, uh, we were, you know, kind of at the top of profitability. And I said, we've gotta get in a new group. I love my group, but I need a group that's selling twice as much and twice as profitable.

Uh, and within a couple of years of getting transitioned into that new group, guess what, we moved away right up to the top of that group because you just, you know, you cut stuck and then you see how other people have gotten past those hurdles, or all of a sudden somebody's selling a hundred K of MRR in a year. And it was like, wow, I thought 30 40 k was an amazing year.

Now I know that somebody's selling a hundred k, we gotta sell a hundred k or somebody's, you know, up above 20% net profit quarter after quarter. That's where we need to be. So it'll push you like that, and it also just shows you that it can be done. And if you believe in yourself and commit to it, then you can do it just like everyone else in the group. And so much of security is that belief. Do you know what I mean? Um, and we're, I'm gonna get into it with Mark A.

Little in a little bit deeper, but this, I, like, I just was at spent, you know, two weeks with MSPs at, at Pier and, and DattoCon. And if I could tell you how many times, you know, someone said to me when we talked through, we asked 'em some questions about their security posture. And when I asked, well, why don't, why don't all your customers have this? They still say the same things. Well, some customers don't want that. Right. And don't value it.

I'm like, well, that's your belief system, not theirs. Right? And that's really what we've been talking about in here for five years, Phyllis. Yeah. Is that we have to, we have to tell customers not the other way around, and their, and their business depends on it literally. Right? Gary says, if you, Gary always says, if you cannot sell security, then you're not saying the right story.

And Gary, how many times have you heard over the years that, oh, in my market I can't sell for that price, or in my market, I feel they're not gonna adopt those kind of security layers or those security stacks. And, uh, and then lo and behold, somebody else in that same market is doing it. And it's just one of those beliefs that they think they're in a bad market that they can't sell that price. Absolutely. The, the world is round.

I mean, you know, when I first started working with this community, I heard it all the time. I heard it all the time. I mean, I still hear it with big enterprises as well, but like, you know, participating in this call is great because again, like every week Gary is preaching, no, you can, you can, and here and here are the ways why, ways to do it. Not even just saying it, but showing everybody. So it's awesome.

And then we have folks like you, you know, living proof of, you know, the power of that in those peer groups. So, um, let's move on to one of Gary's other favorite subjects is, um, your sales engine. So what's the target? Um, A ISP, I'll have to say it since I was unfamiliar with this acronym. All in seat price, um, for new customers. And what contribution does security play and the overall MRR you just kind of talked about it a little bit at a high level.

Yeah, I mean, our minimum, our minimum lancy price, well per user is 180 minimum. And our minimum deal size is 3,500. Uh, our average customer size is 6,000 now. So we're starting to kind of flush out some of the smaller ones, not take on some of those smaller deals. It's just really hard, uh, especially under, you know, probably 3,500 is too low a number for a, uh, a monthly minimum. Uh, but it allows us to at least, you know, I I mentioned the fact that we don't break up our stack.

We are always at a minimum, we're going to be including all of these security bundles with it. You have to take it if you're coming on board with us.

So our cost to deliver that, you know, is, is at least 3,500, uh, a month, whether, you know, we actually have some clients that are three, four users in paying that much because they have high compliance requirements or, uh, just, you know, a, a very, uh, prestigious type of client base that they need the highest level of service quality and, uh, security protecting them.

Uh, but, you know, being able to move up to, uh, 30 user plus, uh, accounts is, is just, they just get the importance of security a lot more and are willing to invest more in it. So we really try to get, uh, you know, up three 30 to 200 users is sort of that sweet spot that we're trying to play in. Awesome. Well back over to you, Gary. Awesome. So, uh, mark. Mm-hmm. Can I say your nickname? Of course. Gary. Anytime. Man.

You know that Mark someone, and I don't know who came up with the nickname for Mark, the Canadian Lou foro, That was you. Yeah, it might, it might have been me And it stuck. Now everybody calls me Lou, But I'll, I know, but I'm, I'm working on my guns, so. Alright. Gimme another meeting or two and I'll, I can kick your ass. Who knows? Alright, awesome. So from from the security side, you know, running operations, tell us about kind of that security journey, which is different.

Tyler talked about it from a cultural corporate, but you're in the nuts and bolts of, of right of that. So share a little bit about like internally and then we'll go start talking about customers, um, as the second piece to it. Yeah, I, I mean we've all, for our clients and, and for all of us, the, the balancing of security and operations, right? Like how we all know, that's a balancing act.

And you get too much security, you start to handcuff yourself operationally, you start to have a lot of additional steps in order to get to the same result. So especially when this first started, you know, getting implemented back at the Vertex days, when we started getting really serious about this, I certainly had to do a lot of monitoring of our operations and how we were doing things.

When security started to get implemented inside of our MSP, I was getting a lot of pushback and a lot of flack from staff where it was like, geez, I, you know, in order to get to our private cloud before I could just log in, now I gotta log into a jump box and I gotta get a special one-time password and I gotta go to this. So in order to kind of, even for our clients in order to, you know, fix an issue, in order to actually do a task, you were adding on time.

So we really needed to be aware of that and understand one, you know, what is the impact and what is the balance there. So that was an ex, that's something we all just went through. At the end of the day, there's no getting around some of that. And that's important, right? Like learning that internally as you run your business, that really is what the culture you have to bring. 'cause every client, they need to start to see it through that same lens faster. Exactly. Right? Exactly.

And that's where that culture starts. When you have a, when your team is operating within those guidelines, when they have a process that's security based, when they have tools that, and, and everything that they have to follow, you're right, that starts to kind of bleed into like conversations with the clients. They're understanding how we're operating and it's always in everybody's mindset.

So that culture did start to get built, but I will say there was a moment that really triggered us to kind of look at this differently. Tyler touched on it, you know, we, we were in a space where we just had clients that had higher security needs by just naturally with the legal space, uh, law firms get targeted more. We've seen that. No, no doubt at all.

They get more phishing attacks just because of the information and the, and the transactions they do and the client base that they have, you know, um, they just get hit more. So we had all of that going. We also had a strong private cloud presence. So now you have all of these really important law firms with, you know, getting hit and where you're also now hosting them and you're responsible for everything in a private cloud.

So those two pieces really kind of had us even early on, I would say a little ahead of the curve in being security aware, but it was, I think Tyler, what was it, maybe five or six years ago, we got a DDoS attack on our private cloud. And God almighty, if you want to talk about taking years off of our life that d os attack and seeing all those law firms, our firewall just getting throttled and hit, and we were not prepared for it.

You know, we didn't have the, all the different types of IP hiding and all these tools and everything that we didn't even really know about. And we spent the better part of like a week battling this and barely made it out with that client base. And it was a real eye-opener. And I think, you know, like a lot of our clients like us, sometimes it takes a major event to really actually move the needle and unfortunately Takes that reach.

That's the way we, we'd like to deal with the second best way, but that's the best way to move your maturity forward. It really is. Right? You know, you see the clients that we were talking about, you selling them all the advanced stuff, finally something bad happens, guess what? They come back and saying, I should have listened to you. And they're the, they're the ones now signing up for every single tool and hardening all of their processes. Yeah.

So that was a little bit of what happened with us, and it was like Ty said right after that, we really took it seriously. We got a dedicated security focused, uh, staff member. And for us at that size of 25 people that was pretty aggressive. They were doing some other centralized services stuff, but they really kind of helped Tyler and I lead, uh, that security journey internally. We started to tam ourselves. We started to have internal projects. We, We, we use that word here a lot.

And we like, we, you know, Tam it's a, it's a more of a tremendous term technology alignment, uh, manager. Can you explain what that role is to people and then how it plays into what it was originally and now how it's morphed in security? Yeah, so I mean, we all talk about standards and standards in an MSP go across everything from your equipment standards, uh, that you have at your clients or anything like that, or technology standards. And then security has become a big piece of that.

So, um, how do you, uh, figure out where somebody is against your standards and what your standards are? So the first thing is to establish your standards. That's something that peer group has really helped us out with is what are the real standards? What should we be saying is a minimum standard as far as we all know what the low hanging fruit is, is that you should have warranty on your servers and you shouldn't be running 10-year-old PCs.

And you know, so there's just, you know, all these standards that you establish and they're really from the TAM perspective, somebody that's coming in and doing checks and balances, uh, against your clients for that standard. And those are in, whether It's IG one, your standards or, or, or secure general security standards that you're doing that. Yeah. And that's all they do, right? They're, they have, That's all they do. Number of clients, they don't do anything else.

They don't do any tickets. They're constantly going through the client base and looking for what's in outta alignment. That's right. And that's a, that's, that's what feeds kind of that journey of maturity. And for us, that's actually the terminology we used for our libraries. And what our tams went through from a new client to even existing clients was this concept of a maturity level. So we actually created three maturity levels largely defined around security.

And we established that every client we had should be fully, uh, aligned to maturity level one. Um, some of those things we were, So Tyler, I wanna be three. Why are we only one? I want to be three, Right? That's the bare minimum. Let's make sure we're all there. And then the next phase was our opportunity. And this all fed our V CIOs. And that was the conversation pieces of where we could say, Hey, here's where you're vulnerable and here's where we need to get you aligned to.

And that was really kind of fed the journey for our clients as well. Yeah. And so take us through that process. Like I, I want to, I want to like double click into it of how you manage those V CIOs to have those conversations, like to mm-hmm. See that they're talking to the right person, that they're presenting things in the right way, and you can tell, right, based on what's getting accepted or not accepted in the recommendation. So like that's the core of this.

Talk about how you look at how you manage those people to see that they're effective. Well, the easiest piece is, is is where we get started in the life cycle of any new client. Once we've kind of established, it all starts in the sales cycle. So once we have a really great framework and the sales team have done their job and they've really established the right fit client, they set the stage for the VCIO to be more successful.

We know that once we're kind of, what do we do about the old clients, right? Like that's the problem. It's going back in time to the old clients that didn't sign up for all of the new, you know, bells and whistles and don't, and are, didn't get the kind of strategy coming through sales. So now the V CIOs gotta go back and they gotta reframe the industry. They gotta go back and say, Hey, like, I know this is what we sold you six years ago, but things are evolving.

We gotta kind continue to educate and we gotta continue to bring that back. So for our client, for our V CIOs, that TAM process is really important. But as it relates to security, it's really kind of understanding what is the most efficient way to present those advanced security options and features to a client that hasn't adopted them. So what we set up is we were, we just called it, again, like Tai said, advanced security. We understood, hey, this is what is, uh, our baseline.

We made sure that we were able to go back and uniquely include that baseline into old clients, either by a little bit of an uptick or an optout option to make sure that we were trying to move that, uh, that baseline up on all of our client base. But then when we started talking about the advanced security options, that was a tracked initiative for our VCIO. So we tried to get some promotion around it.

We tried, we made sure that there was a dedicated, uh, security presentation meeting, um, made it, you know, got, matured it a little bit up, you know, obviously made it look like we put a lot of effort into it so that the client could realize the importance of it just from a presentation perspective. And then from that point on, like Tyler said, every single technology review meeting after that reverts back to that security conversation for a touch point.

Because it's a journey and it is saying, okay, we're gonna put it on the roadmap, let's return to this. And we kind of keep, we keep coming back to that. So now there's in inside of the clients and they're on their own journey, all of a sudden between one meeting and the next, they've heard about their, their buddy at the other place that just got a new breach and saying, Hey, you know, I remember you were talking to me about that and I just heard somebody, you know, I'm interested in this now.

So it's just a consistent delivery and you keep coming back to it. It's not a, it's not a one and done conversation. Yeah. And I, and I think to me, uh, I know when I ran V CIOs across two MSPs, the, the weekly meeting, just like a weekly sales meetings important, that weekly VCIO meeting where you're talking about, Hey, where were you last week? Did you meet with the decision makers? Yeah. What did you, what recommendations, what was accepted and why, what wasn't accepted?

Can we talk through that? Where are you going this week? What are you gonna be recommending? Exactly. Tell me how you're gonna recommend that. And so did they start to get that pattern recognition right? About what it looks like? And then you hit on it, it's every, whether it's every month or quarter, depending on the, on the customer, it, it really is like, you're not building on anything. You're going at it like it's the first time every time in order to get people to really understand it.

But this is the center, like you can build all you want, but if your customers don't understand it and buy it, it's not helping them. Yep. You know, and that's what we, we see that you have to change the security culture, but you also have to change your sales and VCIO culture. 'cause if that doesn't change, uh, nothing and what you just described and the way you're doing it, I'm hoping everyone is hearing how that feels, right?

That this is like who, this is what your VCIO uh, is almost like vcso, right? Like they're taking security recommendations from your expert and they're just delivering that, you know, delivering that message. Yeah. We, we, we, the other thing we really did early on is we, we, we made a real initiative to really impress the importance of cyber insurance on our client base, almost to the point that if the client was not going to get cyber insurance, that they may not stay on as a client.

So we, that was something we did earlier on as well. And cyber insurance, like for a lot of us, has really been the template to which we kind of present against, right? So now it's not us pulling up, they're seeing the questions they're being asked, they're seeing what they're having to be required in order to get coverage. And that's continued to move that needle. And we've been able to kind of revert back to that and saying, Hey, let's not get caught flatfooted. Right?

Part of this is also making sure you guys have in place what you need to, because this is continuing to evolve. This is a new type of insurance out there. It's not like, you know, property and car automotive that's been around for, you know, for forever. This is new.

So these insurance companies every year are starting to learn about this, and they're learning, Hey, holy crap, if we demanded that that client had this control in place or whatever, we wouldn't have just been paying out all this money. So this continues to evolve and we've really used that, the V CIOs, because we get into that, Hey, who sends the side, who sends the form, they send the form to the, you know, the VCIO saying, oh, I got this new form.

So we've used that a lot as well to say, Hey, let's get, make sure that you're in a good place. These are the things you have to have, and these are the things that are coming, uh, in the near future, like vulnerability scanning and stuff. Some of the new conversations where we're starting to ask this stuff, there's a reason why, because next year when you go to sign up, if you don't have it, then you're not gonna get coverage. Mark. That's really awesome. I hope everybody heard that.

Phyllis, how many, many times have we done a survey and find out, we asked the question, how many of you had a conversation about cyber insurance with every one of your clients? And what are the results? It's never a hundred percent. Right. Exactly. Yeah. I mean, I think that's, because that's also, you know, as we talk about on this call, you're, you're making the business case for organizations. Exactly. Um, you know, it's, it's, it's a little bit the based but not totally fear based.

And it's also Right. It's, it's, you know, you must be insured in case something happens. Um, yeah. Mark, you mentioned you, we've been handed this wedge Yes. To not use it with every account, it would be disrespectful to them and to us. Totally. And it gives us a point, a jumping off point, the way you described it, to have this conversation. And then once they start to see and understand it, then it gets future recommendations. Get easy. Yeah. Yep. Yeah. And experience, right?

Like, I mean, we have this luxury of this huge legal client base. And again, that's, that's, again, it does bring in cheat codes for us because our law firms are aware of this, especially with the BCOs, especially for someone like me who I, I still manage some of our top, most of our top clients and biggest firms. They know that we know kind of what's going on out there and our ability to share our experiences and what some other firms have, like that has weight.

Um, it does come in, there is stories to be told of people who didn't make the right decision. Again, it's not fearmongering, it's just reality. Um, and that goes a long way. And so there is a trust factor that does get built up when you have the luxury of that vertical expertise and all of the other, you know, experiences that you can draw on and pull from. Um, and that's, that's helped a lot too, especially in that vertical.

So tell me a little bit about what role education, thought leadership, customer marketing, all of that, you know, what role does that play, uh, in terms of outside the VCIO of, of changing people's perspective and educating them about the journey? Well, I, I, having a security focused individual or department, depending on the size of your business, where that is their primary means to deliver both internally and to set standards for your clients, that has really helped us.

I mean, somebody's gotta really champion that. So depending on where you guys are at or where any MSP is at in their size or journey, um, if it's a role that can have that as a primary focus and maybe not dedicated, I think that's really important. You do have to have somebody to champion and lead that. It can't always be at the C level. They have to be fully on board and support it, but might not be the right people. Right.

So I think from the perspective of educating kind of internally and continuing to kind of move that and making sure that's a focus point that really helped us. Like I told you and mentioned, even when we were a fraction of the size, we got somebody in in that position who really drove that for Tyler and I, and kind of helped us down that journey. And then of course, we have a department obviously now, and then a now with ITS, a much bigger, very big security department.

But, uh, so that piece has really helped us because again, somebody's gotta keep their finger on the pulse, somebody's gotta understand what's happening in the industry and where it's moving. It's gotta come through that kind of focus point. And then that goes out to the rest of the company. And we make sure that from our own internal tabletop exercises, it's just making sure we're kind of keeping everything in our own backyard, um, where it needs to be.

That's that kind of ongoing education and maturity that happens there. As far as for our clients, we've, you know, made a point to make sure that we're, uh, the webinar content and everything that we're putting out there as far as, uh, newsletters, uh, all of the information that we're putting out through our social media channels. There's just a lot of ongoing security awareness focus there. I'd say that's probably one.

Do You have a process to make sure your clients are following you on LinkedIn and social media? Yeah, yeah. I think that, Yeah. Yeah. Establishing yourself as thought leaders, especially in a vertical, like we've been fortunate enough from the beginning to stay focused on legal. So we have spent year after year, well, month after month, I mean, we're always putting out content and we usually do a legal version of the content and then just a generic business version of it.

But always lots, you know, several webinars a year. We participate in the associations, the trade shows. Uh, we do speaking events at a lot of the, the legal conferences. So we want to be the ones that are perceived as, if you want legal IT expertise, you're going to go to pace. Uh, and that's your warm two 50 right there, year after year. Eventually.

There's so many of these firms I've been speaking to for a decade that, uh, you know, haven't been clients for whatever reason, and they usually come around at some point and we close them because we're always out in front of them with, with relevant content. And for the last several years, that's almost been exclusively, uh, security. That's awesome. So, I, I just as we approach the last few minutes here, I want to recap a few things that I heard.

Um, one is, uh, make sure that you first make security a priority inside your MSP. That is step one. Two, as soon as you have the scale, take those dedicated functions and make them dedicated roles specifically around alignment. Uh, having as when you can, bringing in a security expert, someone who's going to lead that charge is important.

Using your V CIOs, really training them on how to build that relationship and then helping them through, uh, education and thought leadership so that they don't have to do all the work. So that's the main thing that I heard. And again, all of this, to do it, you have to run a, um, a mature operation that's profitable, like without running a profitable business.

And I know you, Tyler, when your business wasn't profitable, and I've known you when it was, um, you're much happier when it was, and you're much more secure. Very important part of the business being profitable. Yes. Yeah. Allows you to Yeah. But it, it's a prerequisite for security, right? Yeah. Yes.

And, and a lot of other things, I, I mean, yes, you've need to be able to invest in your people, be able to invest in some r and d, be able to have a buffer in case, uh, the economy turns you've, you know, big client leaves, whatever it may be. Uh, you need that protection. Yeah.

So this, this has been awesome, and I'm hoping what people heard today was that you have built a very, very successful MSP, you've gotten it now to the next phase with an acquisition and your security focus, your security culture really has been the spark plug, right? That ignite, that ignited everything. And so Phyllis, I always say that security is also good business. Yeah. And I agree. And here are living examples.

And I, I have to point out the one thing that you just kind of mentioned at the end, Tyler and Mark is, is really getting your name out there and mm-hmm. And being seen as a thought leader. You know, not just amongst MSPs, but really amongst the vertical or whoever your clients are. Right? And so, I, I think that's really, um, I, I think that's great and something that everyone should look into is Developing Your brand doesn't mean throwing a ton of money at marketing.

Like, it, it helps, but, and, but it's, it's more getting yourself out there and finding, you know, finding your niche and, and really promoting yourself and adding value. And not always looking just for the quick sale, but really, you know, establishing that brand and recognition. So when people wanna change, you're the first people that they're gonna call. Yeah.

Living where and wherever that is, whether it's a vertical or not, it's living where your customers live, being where your customers are, and, uh, being there first to help, not just to be there. Are you ready to buy yet? Yeah. How can I help you with this? Can I share this with you? Yeah. You know, you get him, you get 'em into your funnel and you get 'em into your, uh, your social media. You've become a, a, an organization of value.

And as you said, when they're ready or something happens, you're, you're gonna get a look. And it's really the way we build MSPs today, because trying to take someone who never met you before and turn 'em into a prospect is very expensive. Very expensive.

Alright, well, listen, we we're at the top of the hour, uh, Phyllis, uh, great job today, Tyler and Mark, thank you so much for sharing and, uh, I, I, I'm hoping everybody gets a great feeling as they go back and listen to this you know about, about your journey. And congratulations on all your success. Yeah. Awesome. Thanks Gary so much. Thank you. Thank you everybody. Make it a great day.

Related Videos