December 7th, 2020 – Key Metrics & Drivers to Packaging & Pricing
Guests
Video Transcript
All right. Welcome everyone. Week 30, Gary, let's go right into it 'cause you're already getting requests. Hey. Alright, everybody. Happy holidays. Can't believe we're in December here. Um, I'm excited about today because, um, Gary, this is one of the, um, I think for me it's one of my favorite topics. Uh, in the five years I worked for you and with you, this was a really cool thing we're gonna talk about.
So we're gonna be talking about key metrics, drivers cost, revenue, alignment to roles, responsibilities. It's a lot. Uh, I think it's a lot of fun and man, it will take your business to a whole nother level. Joining me as always are the CSO squared. Uh, first Wes Spencer, how are you? I'm doing awesome. How are you Doing? Awesome, bud. Ryan, weeks, how are you? Very Well. Good. Uh, how's the SEC and finra, you know, treating you these days? Ryan, are they off your back?
You know, It's just another day in paradise, man. Alright, good stuff. All right, so, um, with that, let me go into just a few pieces of housekeeping. Gonna, Before they went, wait, before they went public, he had hair. Alright, everybody, um, I got a pull. Everybody see the poll? Yeah. Now, now that we can, okay, so I got a poll up there. Um, Gar as always. Um, would you, I shouldn't say as always, would you just talk a little bit about the MSP Success Summit?
'cause I think that's upon us, right? It is. So, um, you can just click on that link or it's true methods.com/summit. And, uh, our own, very own Wes Spencer's involved with that. Along with, um, uh, it glue and ID agent. Every week there's an asset going out and then it culminates on Friday where we're doing a session, really getting pe MSPs prepared, uh, sales, security operations, business planning, recovering all the key topics. Okay.
Just to, just to be clear, Gary, you said every week, do you mean every day this week, every Day. I'm sorry. Every day. Every, every day. This week there's another asset. And then we're, we have the, uh, session, the live session on Friday. Okay. Nice asset. Gary, what, uh, what is the grand prize, by the way? Because I think that Oh yeah. Thanks Andrew. Uh, we're to one of the registrants, we're giving away a $3,000 home entertainment system. Right. Awesome.
And, and the runner up is gonna get Wes' entire lighting system. I, we'll ship it up, we'll box it to you. And, uh, so we're excited to give that as a consolation prize. You Probably won't get it to work. I can barely get it to work. I need like a dedicated like AV guy. I tell you what. And I just redid my studio, so I'm still fussing and fighting with it. Awesome. Good. Ryan. Um, you have also datto's got a tech day.
Um, yeah, I'm gonna put you on the spot, talk at all about that and I'll put it in chat for anybody as well. What is going on with, uh, Datto's Ms. P Tech day? Yeah, so when, when DA was trying to figure out what to do to replace dacon, okay, we didn't, we decided that, um, it wasn't kind of congruent to try to do DattoCon in a virtual format. So we're doing smaller format targeted technology days. And, um, this one this week is on, uh, security, uh, PSA and RMM. Okay.
Um, and, uh, it's gonna be, you know, there, there's gonna be a session. I'm gonna be speaking about cyber resilience and what that means for MSPs is, you know, basically an abbreviated talk track of the stuff we talk about in long form here. Um, and then I'm gonna have the privilege of interviewing Brian Krebs. Oh, cool. For those of you that don't know, is it nice? Uh, very well known, uh, kind of cybersecurity fraud, uh, researcher and journalist. Um, and so that's gonna be exciting.
There's a morning and afternoon slot, um, so you can pick which one works best for you and come join the conversation. Is Brian and related to Chris, just curious. I dunno, I've, I've wondered this. The, I've had the same question. I'm, I'm gonna go with probably not, but that's, uh, you know, that's not an informed opinion. Got it. Well, very cool. We ask and report back. Tell him the cyber call wants to know right there. Yeah. Yeah. Alright. Alright, well that's, we get on into it here.
What I'd like you to start to think about is your questions around packaging and pricing. Um, anything to do with, you know, sales. We're really gonna focus this last part of the year here on topics that are really germane to you guys kicking off your year in a, um, successful manner. Gary, we were talking about business planning coming up, so that's where we're really gonna be gearing into. Um, so think about the questions, think about if you want to join us on stage, if we have time later.
Um, Gary, as I said, kicking this off, one of my favorite topics. Um, you in your program coined something called Macro and micro economics. Um, I'm gonna use it as a backdrop today. Um, can you share with everybody what it is when you talk about those things and why it's important?
Yeah, so basically when I talk about peak omics, it's taking a pretty complex business that's getting more complex and, uh, trying to simplify it and have IT providers and MSPs, um, see the business in the, the way that they run it. And here's what I mean, that we take and we put e every function into a role, right? Then we see, okay, for each of these roles, what are the factors based on how much revenue right? Rec, especially recurring it can touch.
And then we use those same factors along with tool costs to come up with a more accurate way of knowing your cost per seat. And when you see it, right, you're really connecting your operations and what you do okay to your profitability. That's how much revenue you generate per person. And also making sure your pricing it.
So when you can connect all your decisions through the way you run the business, um, it's a lot more powerful to get results and know how to set priorities than when you're just getting some p and l that says your margins are too low. Okay, now what? Right? You know, because I over here and I have customers and I have tickets and I have tools and I have, you know, new security stuff I have to do. I have all this stuff and I can tell you how you're not gonna do it.
You're not gonna know your costing by looking in your PSA and seeing how much time is attached to customers. That is not the way that you're gonna know how to price things moving forward. It just doesn't work that way. Right. And so with that, what struggles, like in, in, you know, years of doing this, thousands and thousands of MSPs, why is it a struggle to align that stuff?
Like why, why isn't that, why is it counterintuitive or why isn't it just, you know, nomenclature that people, you know, would know? Yeah, because most people, if, let's look at the two big things to tools and labor and now on average like tools and technology, um, is about 25 to 30% of your total seat cost today, right? Which is, again, that's changed. That's about double the percentage it was, you know, four or five years ago. So you look at tools and every one of 'em is priced differently.
I pay per gig per this, per endpoint, per that, per domain, per that, all these different things. But our price is always one thing to our customers monthly price back to them. So we have to figure out how to translate those things. And then in terms of labor is where it gets really complex. We have to manage the tools. We have to provide some VCIO services. Now we have to provide, you know, I call it alignment, but against standards. But your security stuff that's purely proactive.
You have support, you have all these different things and a lot of people have everybody doing everything. And it's hard to take that and say, well what should I charge? Right? So unless you have a lens by which you can see through it, and right now that lens is more important because we've had to make more decisions about changing and upgrading both aspects of that tools and labor over the past year around security.
If you don't have a lens by which to see it, one, you're gonna lower your margins. And then also you're not able to translate the value to prospects and customers when costs go up. And prices don't, that's a bad thing in most businesses Is the per seat cost going up. And I'll just use a very micro example, Gary, where traditional av, you might have bought like a web route and it was a dollar.
I'm using a simple example, but now you're buying CrowdStrike or you know, as a true, you know, an EDR type scenario or sentinel one and your costs have gone to three or as an example. Yeah, Yeah. Plus the additional labor around, you know, uh, again, we've talked so much about standards. So think of it this way. Let's just say that your seat costs, through all that stuff, labor and tools has gone up 10 bucks over the past year, which is not unreasonable.
That means to maintain your margins, your seat price had to go up by $33. Like $33 is a lot on top of, you know, a hundred thirty, a hundred forty, a hundred fifty. If you don't have a way to be able to a, know exactly what that is. So you're making informed decisions and then communicate that in terms of value to customers and prospective customers. Yeah.
And I know we're gonna, when I turn it over to you shortly to kind of talk to Wes and Ryan where you're gonna talk, you know, frameworks and, but again, we, it just, to me, this flows right into having to do this internally to understand that value translation my get. Yeah. And it's interesting 'cause then I want to ask Wes and, and Ryan some questions and, um, you know about it.
'cause parts of it's similar that what what we watched it providers go through with, with backup and disaster recovery some number of years ago. It's just that this time it's more complex because it's not just one vendor where, okay, we got data and they're helping now and they're teaching us and customers are understanding it and it's becoming ubiquitous. Um, this, you have multiple vendors, some of it's stuff you have to change in your process. So the concept is the same.
So I want to kind of, we're gonna talk through that today with, with, with Ryan and, and also what, um, you know, Wes has seen and working with people that are on that journey, so we can really take this apart 'cause it's super important. Yeah, I agree. Last question to you, Gary, and I'll let you take it over.
'cause I think that's really be great for the audience to hear those types of things is, you know, um, we've talked about this, but if, if you could summarize what you've seen the top providers since Covid hit, what are they, what would you say they're doing differently? Why is there such a gap now? If you could summarize it as we lead into, you know, you talking about, you know, these, these differentiations. Yeah.
Here's what I see, and again, I get to watch this across so many MSPs we work with and, and the peer group, right? Those 140 companies we work really closely with. So it's not so much what the top providers are doing differently. It's what's that's affording them. Those top providers, they had a business plan for the last couple years. They're setting priorities. They know how to execute. They have command over their, they have command over their, uh, the drivers that we're talking about.
So for them, they're more easily taking this wedge that covid is presented and they're turning to more sales at a higher price. The more concerning piece is, so doing the, basically the same process for them is getting them better results, but the average providers, the less mature doing the same thing, is getting them worse results. So the way I'd like to say it is, for the past 10 years, you could be an IT provider, an MSP, and not be a, what I would call a professional business person.
You didn't have to have a great business plan. You can really use, you know, your knowledge, the fact that you care about customers, your logic of what you learned about the business. And for 10 years you could run, you know, not a really high performing company, but you know, one that was growing every year and making some money. I think those days now are starting to come to an end.
And that's really why we're here today is to really try to say, how do we get everybody thinking in a way where they can get the same results and the same upside that we see in this marketplace from the, you know, the top third or top 20%. Very cool. As we transition, Gary, and the floor is yours. Ba over to Wes and Ryan, just want to tell you, uh, the, the poll I struggle with packaging and pricing when it comes into layering secure cybersecurity offerings. Uh, 81%. Yes, I do struggle 18 now.
Shocking to you. Yeah, No, because it is hard. It is complex and you know, you've heard, uh, Wes and I say this so many times, like you have to go and figure out how to take that, those things in, how to assimilate them into your packaging, how to cost them, and then how to go to every one of your customers to get them to see it so that you can afford to deliver a higher level of service and a and reduce their risk.
And, you know, again, we wanna try to simplify that, but in general, that's not an easy thing and not something MSPs have really had to be great at for the past, you know, for the past decade. They could get by without being great at it. They could use this before. Yeah. Well, thank, thank, thanks for setting the stage. Um, I'm gonna keep a keen eye on questions. Um, okay. I'll try to wrap them in Gary, if we have time. If not, we'll leave, we'll, we'll get them at the end.
But again, you uh, the floor is yours. Yeah, but I'm, I'm gonna start with Wes, but Ryan, feel free to jump in. I have some questions for you too. So, Wes, um, enablement, let's start with there talking about enablement. So listen at Perch, you know, you're at the forefront of, of where people are trying to get to with their journey, right? And so what are some of the questions you get asked or that you hear from MSPs?
Like what are they looking for from you to help them be able to go to market? Yeah, that's a, that's a good question. And before I answer that, I'm gonna go off script as I always do. And Gary, you said something just a minute ago that really got me thinking.
I you are exactly right that today's business owner, MSP, has really gotta have command and mastery of their business and understand things like their gross margins and understand, go to market movements and understand all of these things that like, um, it, it, we don't typically have to do that.
If you look at the genesis of so many MSPs, it's been somebody that's been good with like it and they say, I can just do this on the side and then grow this from a side hustle into a full-time business and still never truly have mastery command around business. But Gary, wouldn't you agree that that's actually a huge advantage in two ways? One, if you're missing that command and mastery of business, you can learn it. You don't have to go and get an MBA, you just put some blood, sweat and tears.
There's like some really good even online courses I've seen teaching you those things across any business. It doesn't matter if it's it's managed it or not. Yeah. Um, you can go learn what you need on your own. And two, you can actually use that as a competitive differentiator because it does for the first time, make our industry have a little bit more of a barrier to entry.
And that's one thing we've always complained about oftentimes is it seems like any joker off the street can open an IT service shop. Right? So can you talk about that just a bit more before we jump into the other questions? Yeah. And um, definitely what you're saying we already see happening. So, um, the idea that you could, um, you know what, I always laugh about the 10 minute MSP, you know, just go with a credit card and buy a bunch of tools and poof, you're an MSP.
Um, and that's why we've seen, you know, there's probably between four and five times the amount of MSPs in North America then when I launched True methods in 2009. But now that's because that's all you needed. If you had a little bit of knowledge, a little bit of tools, you were there, well now you need process. The costing is more complex, so you're gonna see that harder and harder. And then at the other side, the competition is changing, changing.
You have more mature MSPs that have dedicated sales and marketing, so now they're coming for those little guys', customers. So all of those factors, but again, I don't see that as like trying to scare people wherever you are. I see it like what you're trying to say. This is an opportunity right now because the marketplace is so huge that if you can get down the line on some of what we're talking about, you can control your own destiny better than you ever have before.
'cause there's more opportunity when you know how Yes. Yes. Okay. That that's really you just, Gary, you, you got me thinking about this in a frame of mind that I've never thought through it before and I just wanted to tackle that a little bit more because I, I wondered if some of our audience was thinking the same thing. It's really wise statements. All right. So Gary, you'd asked me about enablement and when I, let's make sure we're level setting on enablement.
The way that I think about enablement is how do I enable my teams to sell position, price, package, what I am trying to get across my security services. It's not just about perch. You know, perch would go into that. And by the way, I'm not here to turn this into a sales pitch. Like you take anyone else that does similar things to perch and the statements I will make today will work with anybody. Right? It is not about that.
Um, so we're just gonna use where I happen or, so, you know, I think about this a lot and one of the things I, I'm very curious, I'm gonna be watching chat 'cause I wanna get people's reactions on this, but I end up on a lot of conversations talking about enablement with our clients. And I think this is an important thing to think through. And one of the things I like to, to get an idea of is how does the partner currently offer what they're doing today?
I see most kind of, I don't know, maybe the 50 percentile of of partners. It's very, very, very, uh, a la carte still. It is still very, yeah. You know what I would call almost the break fix model of cybersecurity where we're sort of saying to the client, these are what we offer in the suite. What would you like? Then you have those that mature a little bit more and they begin to say, Hey, here's a base offering and an advanced offering. And, and I it makes sense. I I see why we do all of that.
And then you have still more that are really have gotten to this point where they're, you can call it a bundle option, but it's really not that they're selling a bundle, Gary, what they're actually selling is an entire service that the MSP is offering, which happens to have vendors inputting into it. Yeah.
But a good litmus test of if you're doing that really well is can you sell your entire service offering your practice, so to speak, without ever having to mention Datto and Perch and you know, SentinelOne and all that kind of stuff. If you can actually sell that way and you can say, Hey, MSP cybersecurity package, whatever you call it, and here's what you get and here's how you map it, you're on the right track to a maturity journey. And I just think, Gary, gimme some feedback.
Do you think that's a good litmus test of saying, can I actually sell it without talking about the vendors behind it, supporting it? Yeah. In fact that we do these peer office hours twice a month for our peer members. And this question came up, someone said, Hey, well we had someone that asked what do you guys use for virus protection?
You know, and what I was trying to make that exact point, and here's how I would make it related back to what you said, that is what I would call in the sales process an inflection point. So instead of answering it, you know, we use, you know, Datto for backup or you know, bit defender, whatever it is. You know what I like to say? Let me ask you a question. Not a lot of people ask me that. Can I ask you why you wanted to know what vendor we used?
Because what that is, is an opportunity to say, it doesn't matter which vendor we use. What matters is you don't want endpoint security, you want secure endpoints, you don't want backup, you wanna make sure you're backed up. And so part, this much of it is the tool we use and the rest of it is the way we administer that across our customer base.
In fact, if someone's willing to use whatever you want, I would disqualify them because I don't know how you can secure somebody or back them up if you have four different backup solutions. This is about you getting us responsibility for the end result. Is that, that's probably, am I on the right track of what you're seeing? Y yes, that's exactly what I'm getting at. And it's not to say that we shouldn't have those vendor discussions and figure out what works best for us. Yeah.
And you know, you might, even with a bank for example, or healthcare, they may have to do vendor due diligence and actually vet those that that's different, right? I'm not talking about that. Yeah. But I'm just talking about how we need to start thinking about offering all of this. So I, I think that's exactly right.
So Gary, maybe quickly to say this, when I think enablement, when I, that's one of the things I'm trying to kind of suss outta the conversation with a partner is how are they doing that? And then when it comes to enablement, you know, the best the best sales teams think about your sales teams that are hitting the, maybe you listening to this call today are the sales team. Uh, you guys know this as well as I do.
What makes a great sales team is people that are able to very easily come in, have a conversation around risk, have a conversation around compliance, where it maps in and where it may be important. And to be able to say, Hey, look, you know, it's not just about stopping threat, threat hackers and the, you know, ski mask, black and red kind of stuff that's out there that we're all scared of.
I mean, yeah, that's an issue, but let's really talk about how this adds into a, into your organization, into your own risk profile. You guys deal with other areas of risk like fire, earthquake, tornado, hurricane, whatever it may be, other types of business risk. Why are we not incorporating cybersecurity inside of all this as well? And let's have a good conversation around it.
And so oftentimes when I do enablement with our partners, and those of you that have seen me do it, I stick to the basics and I stick high level about what does cybersecurity actually look like and how should it be designed in a way that makes sense to everybody. So I talk in languages of risk, I like to simplify things.
Like one of the things I talk about often in analogies, and you guys know I do this over and over, but I use like a home security analogy of like, we should design our cybersecurity offering, like the way we protect a home. We have preventative defenses, we have detective defenses, we have a way to respond to some of those things when that happens. And I love conversations like that because it's not intimidating. People understand what you're doing.
They understand we're going beyond the basics of just door locks of the home. And and I stick to those things, Gary, when we talk through, um, we talk through enablement because again, the idea is to get my team enabled to truly be able to comfortably and confidently sell with command to the clients.
Well, and you know, what happens is, what I've seen happening is, 'cause I've been doing this for so long through so many iterations over 25 years, is you can see with vendors and like obviously people hear how, you know, you're trying to enable your customers, but if I, I, I see some stuff that vendors put out and, and I'm like, oh my God, they're just training the MSPs to be their sales team. Like, you know, because that's what's best for them. It's like, it's great.
Like you could be a software vendor and again, and I'm a software vendor, so I, you know, but, uh, you get like a free sales force. You just, you know, you just give this to MSPs and then for free, they go out and sell more licensing. It's like, as an MSP, I wish I had a free sales force, you know, to do that. So we have to remember right, that every vendor, they're trying to hit their numbers trying to get pulled through.
But as MSPs, we're the ones who have to make, it's our responsibility to make this all work. And I have some other questions for Wes, but Ryan, I kind of look at like, and I want to kind of equate backup a little bit because for a long time there was just no backup vendor really had any, uh, pie in a portion of the pie. And like nobody really emerged like they did in RMM and and and PSA prior to da, right?
And really what changed was Datto was able to help figure, help people go to market, right? Um, you know, with it, do you, do you see it like this is similar but only just more complex about what has to happen with security? Like somehow the providers just need a little bit more help? It is similar, but definitely more complex, right? I think with, with data, we tend to think of our Salesforce as an extension with your Salesforce.
So we'll actually help MSPs sell into their SMBs and have those conversations. Um, and and part of the reason we do that is 'cause we've developed these simplified talk tracks, which is what Wes is saying, right? Keep it high level, keep it simple, keep it focused on outcomes, um, and things we want to develop and, and help the MSPs, um, deliver those when it comes to, to security, right? I, I actually don't even like talking about selling security.
I like talking about selling cyber resilience. Hmm. And 'cause it's a more accessible concept once someone understands what it means, right? It's the ability of your business to continue to operate through an adverse security event, right? And so this, you know, con continuation of operations is not a foreign aspect for a business owner, right?
And so then that becomes a good entry point into the outcomes, well, what do we need to do in order to able to be able to continue to operate our business through an adverse cyber event? And how do I, as the MSP position you to do that? Um, and then that and What's it worth to you? Yeah. And what's it, I mean, that's where the risk conversation comes in. Yeah.
I think that's probably where we, um, the vendors, we, the kind of security professionals that have been in this space for a long time, have more work to do with MSPs is to help them understand how to have those simplified cyber risk conversations, right? Because I could argue at the end of the day, you know, you as an MS P are going to a customer trying to explain risk to them so they can spend a dollar to mitigate risk, right?
As a ciso, Wes and I are doing the same thing every day, except our constituents are the board of directors finance and, uh, the executive team, right? And so you, it's, it's just a skill you have to develop, which is how do you communicate the, the kind of cost of what it is you're trying to do and the overall protection value of that thing. And so I think, you know, again, as vendors, I think we've, we've fallen short a little bit in, in helping MSPs figure out how to have that conversation.
Um, and we focus a lot on compliance. Um, that's because the SMBs focus a lot on compliance, right? And we focus a lot on frameworks, but we don't really ever get into the conversation about like, how do you actually do a risk assessment? How do you determine what your top five focus areas are? How do you determine what your, you know, your loss or your SMBs loss is, and how much you're willing to invest to mitigate that loss? That's a difficult thing.
Like some cyber professionals take years to develop that. And so I think we have to make that more accessible in the sales process for MSPs and SMBs. But, um, yeah, I, so I, I guess to circle all the way back, yeah, I think it's similar, but definitely far more complex because you're, you're talking about something that touches every facet of, of someone's business. Um, and it's, you know, you can't think of it like a pillar.
Like, I'm gonna add another, you know, I'm gonna add another room onto the house and saying, no, I need to like relay a foundation while, while a house or, you know, under a house that already exists. That's why it's more complicated, right? Because you want to add, you wanna, That's a different contractor that would do that. Yeah. You wanna sell bcr like A home improvement guy, home improvement guy On your house. If you wanna sell BCR, REDR, Here you go. We, you can use that one, right?
Like what Ms. PP have to do is kind of lift a house. But today a lot of 'em are just home improvement guys. They don't have engineers that can do that work. They don't have the heavy equipment to lift the house. They don't have the other vendors you need to have in place. The crane guy, they don't have all those relationships. Oh, Wes, that's right up your alley. Hey, Gar, really interesting. Just wanna point something out. Andrew, are you gonna say something? Yeah.
Really, really quickly, both Ryan, well, Wes first touched on it and Ryan secondarily, and this is what I heard, Wes, you said, Hey, look, you know, business owners can, can relate to what kind of risks they want to take in their business. Maybe it's fire as an example. And you went on to say a few other things, Ryan, you talked about how you talked to HR and finance and the board of directors.
Here's the big difference in my opinion in the SMB space, and let's put regulated right here in the overarchingly in SMB space. Yeah. Think about it, the maturity level of an SMB and you talk about governance, right? Let's talk about business impact analysis, right? Right. Over those business owners' heads. Now, why can we sell, again, point in time solution. Don't take this literally, why can I sell a SIM to a bank? Oh, be because they Understand it.
The, the FI they Already have a need for it before you got there, Right? Wes, right? The FFIC has come in several times and they're saying, where are your logs? Oh, by the way, how do you share threats? Oh, by the way, how do you do X, Y, and Z? And there's the maturity difference, even if it's a small community bank, is that, is that fair? Where, where we are here? Yeah. And layer something else on it, layer on why all this is going on. There's all these forces, right?
With the economy and covid and security, um, is that the channel is changing, right? So remember in the beginning it was like most of us who had companies in the channel, we were all ms, we had all been MSPs, like we were all figuring it out together with the community. Today, that's just not the role of a vendor anymore. Like these are PE backed vendors. Their mission is to grow and create value, right? That's why they exist. You're a public company, right? That's why you exist.
And so it, that is not necessarily good or bad, but it means that our responsibility as providers, um, has to change. Like, that's just not what we can expect. I I, I did a blog about, um, to my members just about, uh, perch acquisition. Um, and what I said was, 'cause they wanna know, is this good or bad? And I'm like, it's not good or bad. It's just, think about it. ConnectWise never would've done what Perch did.
It's just that is not how companies like that now are designed and perch would never be able to get the distribution channel right. That ConnectWise has. So what I'm saying is we need to be aware of where we are, not only in the world and the economy, but where we are in maturation o of, of our industry. So we know what responsibilities we have and we can see it. And again, this is the natural progression as as we grow up in our industry.
And it's not necessarily, you can look and say, well, that's bad or that's good. You know, DA go in public isn't necessarily bad or good. I don't know. I wanted to get both Ryan and, and, and Wes' is this coming through the idea what, how I'm trying to get people to change their perspective. It, it is coming through and you're right Gary. Like let's talk about what's happened in the past three years. Cyber attacks have come down market, you know, at the age of ransomware as a service.
And what perch called Buffalo jump attacks without doubt, because attacks have come down, market regulations are following suit, they're now coming down market. You look at what's happened, just CMMC is a great example. Uh, so now that regulations are coming down, market attacks are coming down market, you are going to see investors come down market. You're going to see all of a sudden the green space here of them realizing, wait a second.
So cybersecurity in the SMB industry is a $6 billion business. Like, that's huge. That's a ton of money. Yeah. That's in it. Of course, they're going to come into it. That's the reality. Uh, I can, I can say that I remember when Perch was doing some fundraising, um, about a year ago.
We're in San Francisco talking to all the Sandhill, you know, the, the, the cream of the crop, the best of the best VCs that are out there, the people that invested in companies like Facebook and uh, LinkedIn and, and, and Slack and all these others. And you walk into those places and you see these icons in there like, oh yeah, we were an early a round investor in these guys. Uh, and here they are talking to in my, my little old perch. Why?
Because they'll tell you, Hey, there's a huge, huge opportunity here for them as, as VCs because they're seeing that SMBs must do more either because they're forced to from regulation or they just absolutely need to because they've been hit by an attack.
And so yeah, without doubt, I mean, Ryan, I'm curious your thoughts on it, but for sure attacks are coming down market, which is changing the game significantly and how everybody thinks from, from private equity and VCs all the way into companies like Perch and Datto and, and and what we need to do to design a competent security practice around all that. Brian, what do you think?
Yeah, I mean, I don't, I've lost sight of the question a little bit, but, um, I, I certainly don't, you know, have a, a materially differing opinion. Um, I think bringing it back to sales enablement, right? The, the question we really each of us needs to answer is, how do I communicate what it is that my security program that I've built for my SMBs? Um, what's the differentiator, right? What's, what is my value versus another MSP? And you need to ground that again in outcomes, right?
We will, you know, we will protect you from ransomware, um, in the following ways. Here are wins. Here's an example, right? Um, and, and so those things are, things are difficult. I do agree that regulation is, is coming. Um, I've been warning for years that if we don't figure out how to solve the security challenges in the IT channel, someone is going to come in and prescribe to us how to solve them. And whether it's correct or not, we will then have to live by it.
And so, um, I think we're still in a window of time where we can self-organize around, um, that, you know, communicating that. But I think that the thing that we didn't realize a year ago, which we're realizing now, is it doesn't matter if that if IT channel vendors and MSPs get it, the SMBs need to get it too. We have to involve them in that conversation. If we're gonna move this otherwise, MS. P vendors and MSPs themselves are gonna be subject to regulation in providing services to SMBs.
Um, and so, you know, then that's gonna become an interesting down, you know, downstream thing as well. 'cause now you're gonna be like, well, I have to provide you this technology stack because we're regulated, right? That's gonna create a very bizarre conversation. So I think before we get to that point, you have to figure out how you communicate the value of what you do before someone else makes it a, well, I'm doing this because I have to type of thing.
Ryan, to your point real quick, Gary, to your point with cost, right? Look what's happening with gar Wes, you mentioned CMMC and I know there's a bunch of folks out here that are very, very good borderline experts that are chiming in on chat and that, like, what's that gonna do to the cost of a small manufacturer where it used to be, oh, I'm, yeah, I'll self a test 801 71 and I'm good. Same thing, right Ryan? Yeah, for sure. I mean, it's definitely heating up even from our perspective, right?
The, the kind of S-M-B-N-M-S-P maturity and having those conversations is increasing. I still think there's a little bit of like a, hey vendor, I just want you to tell me that you are x, y, Z compliant when in fact it actually has nothing to do with us. It has to do with how you deploy our technology, um, into those environments. And so, like, those are difficult conversations.
So when you talk about sales enablement, one of the things you can do is work with your vendors that you have adopted for your technology stack and run your pitch and your sales enablement kind of approach with the vendors and make sure that you're communicating that correctly, right? Because the amount of time that my team and I spend educating our sales force on the security challenges of SMBs and thus MSPs and the compliance needs is, is, you know, I have people full-time doing that.
Um, which is kind of crazy to say, right? But that there's such a need for that type of education. Yeah. In order to help right now I'd say, you know, I got, you know, kids in their twenties that do implementations on myd process, I would say they know more about running an MSB than most of the MSPs that they deal with, right? It shouldn't really be that way. It should be, it should be the other way, be the other way around.
But kind of zooming out, like at the highest level, here's what I think people need to do. And we have the math and science underneath that we talked about with, you know, the framework, but kind of look across your customer base and saying, what do we need to be doing all of them we're not doing today? And in terms of tools, in terms of roles and like, what, what does that mean?
Like, I would need another 10 or 20 or $30,000, you know, a month of revenue from this base, how many seats you have. That's probably divide that out. That's about where you are. Like that's the gut check. I come at it from the other way, which is, I know if I have, you know, one support person for every four or 500 seats, uh, that my cost on average is about $10 a seat for support, then I go on to my centralized services.
You know, what are my on, on average my cost for my tools, and then I have someone who manages them. How many seats can they manage by running all those tools? And if you go through, I know A-V-C-I-O costs me about $6 a seat on average, then you can get to that point. 'cause once, you know, it's really hard, I think, Wes, to go in front of a customer and say, oh, you pay me 3000 now, but I need you to pay me 3,500. Okay, for what?
Instead, if you can go out to 'em and say, listen, let me tell you how different things are a year ago. Let me tell you all the things we're doing today that we weren't doing a year ago. Right? And here's what it is. And actually show them how that's an investment and how they're getting more value, not less. You gotta have, you gotta be able to have that command, right? If you're gonna like your people, everyone who's a new customer of yours, they have to figure that out. Yes.
You know, I, I think I mentioned this about a month ago or so, but I was, uh, I had a, one of our MSP clients had a bank that had had connected with me on LinkedIn and they said, uh, hey, can we get Wes on to do like a, uh, like a one hour cybersecurity to small businesses like seminar? I'm like, heck yeah, that sounds like fun. And so I got on with like, I dunno, call it 60 of this bank's clients. This is for cybersecurity, uh, month, which is last month, right?
And I asked this question, I said, Hey, um, do you guys talk to me? Give me, I, I like asking like just one word answers and like, tell me a little bit as a small business owner is your concerns of, of cybersecurity, would you call it high, medium, or low just in whatever terms you would like. And I got tons of mediums, tons of highs, most highs and zero lows. And I said, okay, now here's the key question. I said five years ago, if I had asked you that question, what would you have said?
Would you have said something different or the same? All of them, all of them said different. And I said, okay, tell me what, low, medium, high. They said lows and mediums. I'm like, there you go, right there. You guys yourself understand and believe that the game has changed. And so I would encourage MSPs to think about the same thing.
Work on that modus operandi of your clients already in their heads, whether they say it or not, think cybersecurity is different today than it was five years ago. And if I'm doing the same things and I'm paying the same prices five years ago to today, it's easy for me to get across this idea if the game has changed. Things need to change on your side as well, at least be reactive.
And so if we work off that and we take data that's useful, like, uh, Ryan, in your guys', um, ransomware report, I think you guys said was like 141,000 in damages for small business for ransomware, just in financial payments alone. Am I about right on that? Yeah, it's about right. Yeah. So just take that number right there and say, okay, this is what the damages look like. Just just to put a number on all of this. Do you think we're charging you $141,000?
Just, uh, that that's an easy decision, right? And then on top of that, all the other benefits that you get out of this, but you're right, Gary, like I think it's important for us to get to this point where we've gotta stop being afraid of a no. Yes, it's an increase, but let's learn how to defend it, but operate off that assumption that the game is changed in the assumption that the client understands that the game has changed.
Now it doesn't, I know it doesn't work wholesale every single time, but it is an important thing. I see this all the time when I talk to, to end user clients. I I see this, it drives me crazy. Go, go ahead Ryan. I was gonna say, like, there's, there's three interesting points in that report. Not to tout the report, but like when I was looking at the data, I found it interesting, right? You have that point, which is around 150 grand per ransomware incident, right?
And so then you have to ask yourself, well, what's the annualized likelihood of a ransomware incident across MSPs? Well, MSP dance MSPs answered that, right? Anywhere between six to eight, uh, out of 10 of their SMDs are gonna get a ransomware incident this year, right? So, you know, that's a pretty reasonable likelihood that there's at least one $150,000 incident per year for them, right?
And so you can have cost of controls relative to ransomware prevention, detection, or correction as a product of that, right? Certainly your cost of your control needs to be less than your total loss. But the other thing that I found interesting in that report is last year we were just, you know, beginning of 2019, we were just starting to have the conversation about co-managed security, um, with MSPs and MSPs.
This year's report showed that five out of 10 MSPs are leveraging a relationship with an MSSP to both protect their own business and figure out how to sell security services into SMBs. And so I think that like that idea of like, maybe you don't have to figure out how to do this by yourself. Maybe you go partner up with an MSSP and co-sell into a few clients and figure out, you know, this tech stack and how you position it and how to have that conversation.
And then you kind of go on that path yourself. So there's actually some interesting data in there that actually had kind of nothing to do with it kind of backs up some of this conversation. Terry, Chris? Yeah, go ahead. Just real quick, hit to his point that that price, you know, per incident, you talk about regulation, I think we have a good idea where it could come from, right? The insurance companies. Yeah.
So Sorry Gary, Just Yeah, just, and just to be clear, that's just the cost of the incident itself and the remediation that doesn't include the cost of downtime or loss sales or revenue by the time you add that In, which is the big one in many cases. Yep. Yeah. So a couple, I wrote down a couple points here. Um, you know, I agree with what you said, Ryan, you hit on an awesome point about if I'm a less mature MSP partnering is gonna be real important.
The hard part about that is, you know, Wes, you know, as someone who partners with a lot of people, it's easier for you to sell a more mature MSP that's already down their security journey than it is for you to partner with the people who maybe need you the most, which is the less mature. And we gotta figure out how to close that gap, right? Yeah. We we do. And and that's the truth of the matter is, yeah. And this is not to pick on anybody, it's just to talk about the facts as they are.
Um, those that are highly enabled that understand how to sell this, have maybe been selling it for a while and are looking to change over and make some changes. Yeah. I mean, they get it, right? They, they understand and you see it as well in the kinds of clients that they work with. You know, you see a predominance in regulated companies, but that's not to say that it, you can't also be successful and compete inside of all of that, right?
There's certainly room for anybody to say, you know what, I'm gonna get some mastery around cybersecurity. I don't have to be like an OSCP and understand how to run my own pin tests and then be a, a, a certified security analyst from Chris Sanders, one of our other guests we had on a couple months ago. You don't have to do all of that.
But I think what you do have to do is learn truly what cybersecurity is and, and how to map a solution into all of that and understand how to output that in a way that comes back to the communication of like where I am, you said resilience and risk and how it maps into frameworks and those sorts of things. And I say this over and over on this call ad nauseum, I know that. Um, but those are the things that you can do to differentiate yourself.
And you'll eventually get to this point where not only are you you communicating it clearly, but you're going to have clients that, that see the value. I remember last week, we never got to this person's questions, but there was one person that asked in chat, they said, Hey, I'm struggling with all this because I feel like my margins are already tough as they are. And he said, there's people coming in that are undercutting me.
And I asked him in chat, I said, Hey, can you just gimme an average seat price? And Gary, his seat price was $50 a seat. And I want you to elaborate on that a little bit more quickly if you could. But let me just say this. You know, sometimes I think if we're coming in that low, uh, not only are we, um, one of the problems is we're actually undercutting those that are coming above us in seat prices because they're offering so much more. And so I don't think that's actually the problem.
I think the problem is understanding what goes into my offering and then what the outputs of what that are gonna look like. If I'm looking at 60 to 70% margins, there's no way you can do that on $50 a seat. There's no way you can truly secure client or they need at 50 Yes. Or A hundred if you're 50. Can you talk about that a bit More? Yeah.
If you're at 50 or a hundred dollars a seat, you got a lot of work to do and you're gonna get frustrated because you don't have to worry about if you're at a hundred dollars a seat, the guy at 75 beating you, you gotta worry about the one, the guy at one or gal at 1 75 who's gonna completely eat your lunch because they're in every single, you know, marketplace right now. And the thing that, listen, here's the concept that I live that I feel when I walk into a prospect. Your cost, Mr.
Prospect or Mr. Customer have already changed. I didn't change them. The security landscape changed them. The, the way you use technology change the way you're, the amount of techno they've all read, your costs have already changed. I'm trying to get you to pay in the most predictable way, which is making a little bit more investment so that we can protect that. But whether you pay me 1 75 a C or one 30 is seat your costs are, you can't control your costs by paying your vendor less.
And by the way, hear this, all MSPs, if you're charging them 3000 and needs to be 4,000, a thousand dollars a month to a client who spends that with you is so small, it's us. It's not them, it is not, especially in today's world, it's not that hard to be able to ask a few questions, to have some command for them to be able to see and understand this.
I just did a sales panel on my last webinar with three of our members, and every one of them shared one thing that they said, it's easier to have the conversation to get separation in the marketplace today than it was a year ago. Customers are, have more of an understanding of what those risks are than ever before. Boy, that was a little tirade. It's a good one though. It's a good one. Yeah, that's it. Ryan, you work with people like when they're on the incident response side, right?
Like these are MSPs that are now have had some, you know, issues. Is there anything that stands out of like the maturity of MSPs who've been compromised? Like is there any similarities you see that those people that are in these compromised scenarios, Hey, here's a common thing that I see that they need that they could have addressed ahead of time? Honestly, the trend I'm seeing right now actually has to do with co-managed customers.
Um, for the most part it's MSPs that are managing the customer, but there's also internal it, um, and internal IT is doing something that the MSP wouldn't do, and that's leading a threat actor to come into the environment. Uh, and ultimately, you know, we can help them kind of trace back to certain components in their infrastructure, kind of where those attacks were launched from. And then they figure out that the change that introduced that entry point came from kind of internal it.
And so I think there's, there's definitely a trend there in terms of what I'm seeing on a day-to-day basis, definitely more of these co-managed situations. Um, although be before a year ago it was non-discriminatory, right? It was, um, you know, and that might be just because a lot of MSPs had the same kind of, we were making the same mistakes. Um, but now most MSPs are are getting those things kind of in order.
But, you know, and again, it just pains me because for two years we've been saying the same things. Use MFA monitor for credential breaches, patch your network edges and do not open RDP to the internet. Like, do those three things and you materially reduce your risk surface. So like, you know, you can even make that part of your, you know, your conversation with, um, your customers. Like I wanna go back to what Wes said about frameworks, right?
You don't need to walk them through NCSF and the 110 controls. You can just say we follow a framework. It's roughly breaks itself down into five categories. Here's how my service offering, uh, provides you safety and maturity in these five different areas. Identify, detect, protect, respond, recover, right? And that, and that encompasses all of your tech stack, not just security rate.
You can start rebranding your RMM and your backup, uh, solution as part of your security stack, which it really is right, because it's cyber resilience, it's business operation through an adverse event, which could be security related. And so, I don't know a bit of a tirade there too, but I agree with your tirade too, Gary, for what it's worth. And Then take it one step further and just say to them, say, listen, does it make sense why we do this now for our customers, Mr. Customer or Mr.
Prospect, why we do this for our customers? And if the answer is yes and say, guess when I couldn't do this when I was charging a hundred dollars a seat? Yeah. Can I show you what I can do for a hundred dollars a seat? Yeah. And let me tell you what this looks like. It's a really Yeah. Point because, you know, I'm gonna equate this back to my kind of enterprise experience, right? I just, we're going through end of year budgeting, right?
And I'm figuring out how much money do I need to invest in the security program next year. And before I even talked about investments that I wanted to make, I level set, where are the, where are we at with our investments right now? Where do we have opportunities for improvement? And I le I set that stage before I even start talking about net new spend because it doesn't do any good to show up and say, Hey, I need an extra $500 a seat for security. I have to understand where I'm at now.
Like you said, how things have changed in order to really have that useful conversation with whoever the person is that I'm asking for money, more money from. And so those, you know, that education piece of what's changed, where am I now? Um, even if you can help your customers understand where their spend is in relation to other customers, yep.
That benchmarking exercise can actually be pretty powerful to kind of let them know if they're, you know, under invested, over invested, or kind of just right. And again, that's gonna be different depending on where they are in their security journey, right? If they have no program, they're gonna, they, they're gonna need a lot of fuel 'cause they're gonna burn 80% of it getting outta the atmosphere.
Um, but then eventually they'll, you know, they'll trip back to like normal levels that everyone else. So you, you gotta come up with that framework and have that conversation about where you are and where you need to be. And then one other thing, Wes, I was gonna say is, and you gotta take this one different attitude. It's not a matter of, well, can we charge this month? What?
No, you have to, now I gotta figure out how, and you know, you can 'cause other people do it and you might not be able to do it today. Maybe your value doesn't command that. But every quarter and when you make your quarterly action plan and on your annual plan, you have to have actions that move you in that direction. If you still in your quarterly action plans are fixing symptoms, bridge out, turn back. You need to do the things that you need to do.
And we talk about 'em every week on the cyber call, right? In order to be able to have that, you don't have a price problem. You have a value and a belief problem. And I'm begging people as we go into next year, do not wait any longer to get going with it. You don't have to solve it in a day, but you gotta start making progress on it because things are moving faster and faster. We've never seen it like this before.
You guys know I've said this, but, and I say it a lot, but the best way to get anyone to care is have a breach. It's the worst way, but it's the best way. And that's the reality of it. It works in the enterprise and it works with MSPs as well. I can tell you the MSPs that we work with today that have gone through a breach or their clients have, the game has changed.
And the way they talk about it, the way they discuss it, the way they align it, and the way they draw that thin red line and what is going to be offered and not offered, is it, it's just night and day difference because they've been through it and they understand what happened from it. And they'll say never again. Never again, Ryan. We know a lot of the people right, that have been through that. Right? Yeah.
There's, I mean there's, there's a way to learn from that experience without having to live through it. It's called having someone come in and doing a tabletop exercise with you. Yeah. And auditing where you are as an MSP in terms of your own security journey, just doing something like that. You are going to learn how to have conversations. You're gonna learn about, you know, the value of certain, you know, protection capabilities, whether it's processes, people, or controls.
And you can turn that back into your own sales pitch. You know, when, when, when a lot of MSPs come to me, it used to be the initial conversation is what technology should I buy? Now the question is how do I figure out what I should be doing next in cybersecurity? Which I think is a better question, but there's still a bit of a victim thread there. Like, like it's so complicated. How could little me figure it out? Right?
My argument is go spend five grand, 10 grand, have someone come in and audit you and deeply, deeply engage with that person because what you're gonna learn from them is something that you can reinvest back into your business to grow. Uh, Ryan and I sat on a, on a panel one time and we had someone who came on who said pre they got Buffalo jumped pre breach. They were like $75 a seat plus some add add-ons to it, right?
And I know that if we, I would've asked that person 'cause I ask everybody I meet, you know, they would've told me in my marketplace, I can't command those prices post breach to every customer and prospect. You know, he's up 180, $200 a seat all day long. The marketplace didn't change his understanding of it from what he went through. Our goal is, like you said, Ryan, to start with, with what you explained so that we can get there without going through all of that. That's the trick.
Really, really good stuff. Really really good stuff today. I just threw in there Gary. Um, and, and we, Ryan, thanks for mentioning tabletop. 'cause we, we've done a bunch of them. Uh, unfortunately with C Man, Wes, I love the ones we used to do in person. We had, I, I remember the, like one of the ones we did at IT Nation, they had to open up an entire other room, if you recall. They were awesome.
I do remember, you know, everybody could sit together, we'd give a a nugget of, uh, the information. Everybody would take five minutes, talk about it, come back. But it looks like even though, you know, very percentage wise, not a lot of people have answered, but we've got a a hundred percent yes. Let's do it again. Gar. Um, so let's maybe we gear that up at, uh, Q1. Q1. Sure, sure. Yeah, absolutely.
I, I think, you know, as I listen to all of you, Gary West Ryan again, um, again, we've set this often, but it is about command. I mean, you put any of you in front of a business owner and you know, Gary, you talk about the egg theory, uh, and I want you to tell everybody about it real quick, but there's no egg.
You're gonna sit there and discuss to them, look because you guys have done it internally, and understand the cost to implement security, what the gaps are, how to do gap analysis, what the threats are, how it relates to your overall, uh, governance in your company. But Gary, briefly as we close out here, why is the egg important and why are people holding onto it? Yeah, like every time you go to try to get more money from a customer or close a prospect, it's like you're holding onto an egg.
You're trying not to do anything to drop that egg. Like that represents the sale, it represents making payroll, all those things. But it turns out the very idea of protecting that egg eliminates your chances of getting where you want to get to with that sale. And it goes back to when you're in front of somebody. You have to have that confidence that this situation that they're in already exists.
Our job is not to sell them, it's to explain it to them and how we understand it and how our services address it. Awesome. Way to close it out. So with that, we're at the top of the hour. We had a fantastic group with us today. Thank, thank you everybody. Really appreciate all your participation. Sorry if we didn't get to Yeah, we gotta get people up on stage next time, but we got rolling today. We need it. One of these weeks where we had to get it all out. Yeah, you, you, you rage.
I saw the rage come out. So with that, everybody, Ryan, we, Gary ha have a fantastic week. We'll look forward to next week. I'll communicate to everybody. Tell your friends, family, coworkers, bring 'em all. Have a great day. Thanks.


